<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2442688623759178220</id><updated>2012-02-15T22:39:14.780-08:00</updated><category term='solr'/><category term='flash'/><category term='NetWitness'/><category term='0 day'/><category term='Account'/><category term='solution'/><category term='Airport'/><category term='ATM'/><category term='Hack'/><category term='HTTPS'/><category term='neXpose'/><category term='eden'/><category term='bug'/><category term='development'/><category term='art of hacking'/><category term='CyberCriminal'/><category term='whitepaper'/><category term='Windows'/><category term='google appengine cloud paas authorization authentication security'/><category term='Free Internet'/><category term='Ban'/><category term='presentation'/><category term='Web'/><category term='Administration'/><category term='HTTP'/><category term='vulnerable'/><category term='ActiveX'/><category term='Threat'/><category term='flaw'/><category term='Vulnerability'/><category term='xss'/><category term='secops'/><category term='Video'/><category term='2008'/><category term='News'/><category term='scripting'/><category term='scanner'/><category term='recon'/><category term='Policies'/><category term='SiteHoster'/><category term='Javascript'/><category term='Data Mining'/><category term='RAT'/><category term='rig veda'/><category term='Cyber'/><category term='philosophy'/><category term='banned'/><category term='vulnerablity'/><category term='ADS'/><category term='lingo'/><category term='puppet'/><category term='Ransomware'/><category term='POSIX'/><category term='Failure'/><category term='scribd.com'/><category term='Accounts'/><category term='Firefox'/><category term='sun tzu'/><category term='dns'/><category term='Conficker'/><category term='Sidejacking'/><category term='sslstrip'/><category term='worm'/><category term='Stream'/><category term='operations'/><category term='Reconnaissance'/><category term='Trojan'/><category term='AbhishekKr'/><category term='Site'/><category term='Critics'/><category term='virtualization'/><category term='NTFS'/><category term='csrf'/><category term='Twitter'/><category term='devopsdays'/><category term='Microsoft'/><category term='human factor'/><category term='Passive Reconnaissance'/><category term='Remote'/><category term='Zero Day'/><category term='FB'/><category term='hacking'/><category term='Attack'/><category term='conference'/><category term='Security'/><category term='curl'/><category term='webhoudini'/><category term='nullcon'/><category term='short talk'/><category term='download'/><category term='scareware'/><category term='Bank'/><category term='Mozilla'/><category term='internet'/><category term='concept'/><category term='script'/><category term='domain'/><category term='BEAST'/><category term='SSL'/><category term='devops'/><category term='kvm'/><category term='bypass'/><category term='Facebook'/><category term='India'/><category term='PoC'/><category term='apache'/><category term='Network'/><category term='cross'/><category term='subvert'/><category term='guide'/><category term='research'/><category term='social engineering'/><category term='howto'/><category term='document'/><category term='aBionic'/><category term='Server'/><category term='Kneber'/><category term='audit'/><category term='Exploit'/><category term='website'/><category term='Alternate'/><category term='short urls'/><category term='0Day'/><category term='hackers'/><category term='OSINT'/><category term='Open Intelligence'/><category term='Google'/><category term='source'/><category term='PHP'/><category term='ABK'/><category term='Malware'/><category term='Data'/><category term='n00bRAT'/><category term='appengine'/><category term='adsense'/><category term='rconnaisance'/><category term='dnssec'/><category term='GreaseMonkey'/><category term='log'/><category term='search'/><category term='Rapid7'/><category term='Zeus'/><category term='Botnet'/><category term='DoS'/><category term='IE'/><category term='Orkut'/><category term='TLS'/><category term='Europe'/><category term='Addon'/><category term='WiFi'/><category term='WebServer'/><title type='text'>Hacker's e-Mag</title><subtitle type='html'>[leave comments for topic want to be covered]   
old/new tools, breaches, exploits, bugs...
how to do... what not to do...
some video... some text... some audio...
'n the best part... all legal</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>29</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-321808184983842125</id><published>2011-10-03T09:09:00.000-07:00</published><updated>2011-10-03T09:11:19.574-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='human factor'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Threat'/><category scheme='http://www.blogger.com/atom/ns#' term='howto'/><category scheme='http://www.blogger.com/atom/ns#' term='rconnaisance'/><category scheme='http://www.blogger.com/atom/ns#' term='guide'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='recon'/><title type='text'>Social Engineering [from Eden Guide to Hacking &gt;&gt; Active Recon]</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace; font-size: large;"&gt;&lt;span style="font-size: x-small;"&gt;Eden Guide To Hacking&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: x-small;"&gt; : &lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking"&gt;https://github.com/abhishekkr/eden_guide_to_hacking&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace; font-size: large;"&gt;&lt;b&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace; font-size: large;"&gt;&lt;b&gt;Social Engineering&lt;/b&gt;&lt;/span&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking/blob/master/part1_Hacking_Cycle/chapter4_Reconnaissance/section1_Active_Recon/article2_Social_Engineering.txt"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;direct link :&amp;nbsp; https://github.com/abhishekkr/eden_.....&amp;nbsp; ineering.txt&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;Most creative non-technical hacker practice known to mankind.&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; a.) &lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;It's Art of Communication with People for '&lt;b&gt;Information Leakage&lt;/b&gt;'.&lt;/span&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;You have a 'Victim' identified by now and wanna collect more&lt;/span&gt; &lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;and more available information related to them.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; Not just any relevant information, but sensitive details, that&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; Victim or related people handover to you in confidence.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; You think like a con-artist, assess weakness of your victim &amp;amp;&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; the possibilities of make-believe for them.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; Then you come up with an entire scenario to pose yourself a &lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;reliable savior for your Victim to be saved; a benefactor.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; And you will find them revealing such discreet and sensitive&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; information so that they can encash the situation to its max.&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; And let you gather all sensitive information that you can.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; b.) &lt;b&gt;Example&lt;/b&gt;: "The pretend employee loosing access at critical time"&lt;/span&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;You are a management personnel on client location in middle of&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; a very life-changing deal.&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;You need to get some files from your organization's machine or&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; file-share; but can't access them due to firewall policies on &lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;either side.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;If you can't seal the deal, the failure will take away your job&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; and the person refusing you such crucial-moment help.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; And there are many chances that you'll get the data fetched from&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; your pretended 'Employee', mailed to you.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; c.) &lt;b&gt;Example&lt;/b&gt;: "I'm here to check your Network from Agency"&lt;/span&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;You are at home of your Victim when some family member, hopefully&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; not much security aware is in-charge and pose as the Network Guy&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; from the Telecom Agency they use.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;Offering new organization customer satisfaction mumble-jumble,&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; you try to get access to check health status of network devices&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; installed there, and more computing devices if possible.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;Now, if the devices are tweakable without any credential request&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; from the family member there... try that first.&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;If it doesn't work and even they don't have access, then pose as&lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt; attempting the 'Master Password' so they don't inform the Victim.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;d.) &lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;For ultimate case studies, read "&lt;b&gt;Art of Deception&lt;/b&gt;" &lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;by "Kevin Mitnick", the most famous Social Engineering &lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;Hacker 'known'.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-321808184983842125?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/321808184983842125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/10/eden-guide-to-hacking-httpsgithub.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/321808184983842125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/321808184983842125'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/10/eden-guide-to-hacking-httpsgithub.html' title='Social Engineering [from Eden Guide to Hacking &gt;&gt; Active Recon]'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-1117041953081916977</id><published>2011-09-23T09:25:00.000-07:00</published><updated>2011-09-26T14:11:06.441-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSL'/><category scheme='http://www.blogger.com/atom/ns#' term='TLS'/><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='research'/><category scheme='http://www.blogger.com/atom/ns#' term='Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTPS'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='BEAST'/><title type='text'>BEAST beating SSL &amp; TLS :: What You Can do to be Secured</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;b&gt;B.E.A.S.T.?&lt;/b&gt;&lt;br /&gt;Browser Exploit Against SSL/TLS Tool [B.E.A.S.T.], is the new Javscript utility created by J. Rizzo &amp;amp; T. Duong capable of breaking SSL3.0 &amp;amp; TLS1.0 level protection for HTTPS connections and deciphering the secure connection data.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;What It Does?&lt;/b&gt;&lt;br /&gt;There have been previous mention of cryptanalysis attacks over&lt;br /&gt;+ SSL3.0 &lt;br /&gt;&amp;nbsp;| &amp;nbsp; &lt;span style="font-size: x-small;"&gt;&lt;i&gt;(a Paper 'Analysis of SSL3.0 Protocol' by D.Wagner &amp;amp; B.Schneier in 1999 )&lt;/i&gt;&lt;/span&gt;, &amp;amp;&lt;br /&gt;+ TLS1.0&lt;br /&gt;&amp;nbsp;| &amp;nbsp; &lt;span style="font-size: x-small;"&gt;&lt;i&gt;(a Paper 'Renegotitating TLS' by Marsh Ray in 2009)&lt;/i&gt;&lt;/span&gt;.&lt;br /&gt;B.E.A.S.T. is a pure exploit tool built over these (or similar) visions.&lt;br /&gt;B.E.A.S.T. is based upon &lt;i style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Chosen-plaintext_attack"&gt;&lt;b&gt;blockwise-adaptive chosen-plaintext&lt;/b&gt;&lt;/a&gt; &lt;/i&gt;attack approach exploited on victim's end via &lt;b&gt;&lt;i style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack"&gt;man-in-the-middle&lt;/a&gt;&lt;/i&gt;&lt;/b&gt; attack.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Point-to-Note!&lt;/b&gt;&lt;br /&gt;It's a MitM over Browser, javascript injected does all harvesting of plaintext attack (which currently takes around 30 minutes for useful data) and then enables you to break the encrypted session.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Security Measures until F!XED&lt;/b&gt;&lt;br /&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;Use a different browser (totally different, i.e. just not a new instance of same browser but a new browser, as in FireFox &amp;amp; Chrome are different) for browsing your Secured Connection. And a different browser for you general web surfing experience, even any external links from your secured session used browser should be copied and opened in the general web-surfing browser.&lt;/li&gt;&lt;li&gt;It's better if the browser used for secured session is used in Private Browsing Mode.&lt;/li&gt;&lt;li&gt;Don't keep log-in active in any service if you are not using it currently.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;b&gt;Something you should already be doing, if not start now...&lt;/b&gt;&lt;br /&gt;Use browser extensions like &lt;a href="https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/"&gt;&lt;i style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;AdBlock&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; &amp;amp; &lt;a href="http://noscript.net/"&gt;&lt;i style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;NoScript&lt;/b&gt;&lt;/i&gt;&lt;/a&gt;, to protect your browser from injected IFrames and infected AdServices which are the major source channel for BEAST also.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;To get a more detailed insight at the exploit Paper &amp;amp; Code, get your hands over&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; font-size: 15px; line-height: 19px;"&gt;&lt;a href="http://www.insecure.cl/Beast-SSL.rar"&gt;http://www.insecure.cl/Beast-SSL.rar&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;What to do at Server Side&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://isc.sans.edu/diary/SSL+TLS+part+3+/11635"&gt;http://isc.sans.edu/diary/SSL+TLS+part+3+/11635&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-1117041953081916977?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/1117041953081916977/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/09/beast-beating-ssl-tls-what-you-can-do.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1117041953081916977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1117041953081916977'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/09/beast-beating-ssl-tls-what-you-can-do.html' title='BEAST beating SSL &amp; TLS :: What You Can do to be Secured'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total><georss:featurename>Pune, Maharashtra, India</georss:featurename><georss:point>18.5204303 73.8567437</georss:point><georss:box>18.3999798 73.6988152 18.6408808 74.01467219999999</georss:box></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-3970892199091155924</id><published>2011-09-13T09:00:00.000-07:00</published><updated>2011-09-13T09:02:51.874-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web'/><category scheme='http://www.blogger.com/atom/ns#' term='Reconnaissance'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='scanner'/><category scheme='http://www.blogger.com/atom/ns#' term='Open Intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='guide'/><category scheme='http://www.blogger.com/atom/ns#' term='Passive Reconnaissance'/><category scheme='http://www.blogger.com/atom/ns#' term='OSINT'/><category scheme='http://www.blogger.com/atom/ns#' term='Data Mining'/><category scheme='http://www.blogger.com/atom/ns#' term='ABK'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><title type='text'>Open Intelligence Gathering FOR Passive Reconnaissance FROM "Eden Guide To Hacking"</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;pre style="font: normal normal normal 12px/normal 'Bitstream Vera Sans Mono', Courier, monospace; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;div class="line" id="LC2" style="background-color: transparent; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 1em; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;&lt;b&gt;Open Intelligence Gathering&lt;/b&gt;&amp;nbsp;: &lt;/span&gt;&lt;/span&gt;&lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking/blob/b00ef1502b9f91953f5d734efd4a03c3a0f04002/part1_Hacking_Cycle/chapter4_Reconnaissance/section0_Passive_Recon/article0_Open_Intelligence_Gathering.txt"&gt;github.com/abhishekkr.....Open_Intelligence..&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="line" id="LC2" style="background-color: transparent; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 1em; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;FOR&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="line" id="LC2" style="background-color: transparent; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 1em; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;&lt;b&gt;Passive Reconnaissance&lt;/b&gt;&amp;nbsp;: &lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking/tree/b00ef1502b9f91953f5d734efd4a03c3a0f04002/part1_Hacking_Cycle/chapter4_Reconnaissance/section0_Passive_Recon"&gt;github.com/abhishekkr.....section0_Passive_Recon&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="line" id="LC2" style="background-color: transparent; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 1em; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;FROM&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="line" id="LC2" style="background-color: transparent; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 1em; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;"&lt;b&gt;Eden Guide To Hacking&lt;/b&gt;" : &lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking"&gt;github.com/abhishekkr/eden_guide_to_hacking&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="line" id="LC2" style="background-color: transparent; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 1em; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;b&gt;The following content structure is discussed in detail&lt;/b&gt;&lt;/span&gt; @&lt;/pre&gt;&lt;pre style="font: normal normal normal 12px/normal 'Bitstream Vera Sans Mono', Courier, monospace; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking/blob/b00ef1502b9f91953f5d734efd4a03c3a0f04002/part1_Hacking_Cycle/chapter4_Reconnaissance/section0_Passive_Recon/article0_Open_Intelligence_Gathering.txt"&gt;https://github.com/abhishekkr/eden_guide_to_hacking/blob/b00ef1502b9f91953f5d734efd4a03c3a0f04002/part1_Hacking_Cycle/chapter4_Reconnaissance/section0_Passive_Recon/article0_Open_Intelligence_Gathering.txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~[+] Open Intelligence Gathering&lt;br /&gt; |&lt;br /&gt; |[+] What Is Open Intelligence?&lt;br /&gt; |&lt;br /&gt; |[+] Legal Documents Got Them&lt;br /&gt; |&lt;br /&gt; |[+] Search Engines Sort Them&lt;br /&gt; |&lt;br /&gt; |[+] Web Activity Caught Them&lt;br /&gt; | |&lt;br /&gt; | |[+] You Blog/Comment&lt;br /&gt; | |[+] You Socialize&lt;br /&gt; | |[+] You Subscribe&lt;br /&gt; | |[+] You Show/Click Ads&lt;br /&gt; | |[+] Even If You Surf Web&lt;br /&gt; | |_&lt;br /&gt; |&lt;br /&gt; |[+] Automating the Act&lt;br /&gt; | |&lt;br /&gt; | |[+] Paterva Maltego CE&lt;br /&gt; | | |[+] URL&lt;br /&gt; | | |[+] What it does?&lt;br /&gt; | | |[+] Example Usage&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] The Harvester&lt;br /&gt; | | |[+] URL&lt;br /&gt; | | |[+] What it does?&lt;br /&gt; | | |[+] Example Usage&lt;br /&gt; | | |_&lt;br /&gt; | |_&lt;br /&gt; |_&lt;br /&gt;&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-3970892199091155924?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/3970892199091155924/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/09/open-intelligence-gathering-for-passive.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3970892199091155924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3970892199091155924'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/09/open-intelligence-gathering-for-passive.html' title='Open Intelligence Gathering FOR Passive Reconnaissance FROM &quot;Eden Guide To Hacking&quot;'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-562091610671335320</id><published>2011-08-29T05:47:00.000-07:00</published><updated>2011-08-29T05:47:20.414-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='development'/><category scheme='http://www.blogger.com/atom/ns#' term='puppet'/><category scheme='http://www.blogger.com/atom/ns#' term='virtualization'/><category scheme='http://www.blogger.com/atom/ns#' term='kvm'/><category scheme='http://www.blogger.com/atom/ns#' term='secops'/><category scheme='http://www.blogger.com/atom/ns#' term='presentation'/><category scheme='http://www.blogger.com/atom/ns#' term='devops'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='log'/><category scheme='http://www.blogger.com/atom/ns#' term='operations'/><category scheme='http://www.blogger.com/atom/ns#' term='short talk'/><category scheme='http://www.blogger.com/atom/ns#' term='devopsdays'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>"DevOps with SecOps" ~ short intro to Security Implications in DevOps Process</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;It's a &lt;i&gt;&lt;b&gt;short introduction to Security Implications in&lt;/b&gt;&lt;/i&gt; the new emerging &amp;amp; highly required &lt;i&gt;&lt;b&gt;domain of DevOps&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div id="__ss_9052938" style="width: 340px;"&gt;&lt;b style="display: block; margin: 12px 0pt 4px;"&gt;&lt;a href="http://www.slideshare.net/AbhishekKr/devops-with-secops" target="_blank" title="DevOps with Sec-ops"&gt;DevOps with Sec-ops&lt;/a&gt;&lt;/b&gt; &lt;iframe frameborder="0" height="284" marginheight="0" marginwidth="0" scrolling="no" src="http://www.slideshare.net/slideshow/embed_code/9052938" width="340"&gt;&lt;/iframe&gt; &lt;br /&gt;&lt;div style="padding: 5px 0pt 12px;"&gt;View more &lt;a href="http://www.slideshare.net/" target="_blank"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/AbhishekKr" target="_blank"&gt;Abhishek Kumar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;As currently, the major &lt;i&gt;&lt;b&gt;concern around&lt;/b&gt;&lt;/i&gt; DevOps world is &lt;i&gt;&lt;b&gt;'The Mantra of Automation'&lt;/b&gt;&lt;/i&gt; at the level of&lt;br /&gt;+ System/Environments &lt;b&gt;Provisioning&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (easy &amp;amp; fast using Cloud Support)&lt;br /&gt;+ Idempotent &lt;b&gt;Configuration&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (using Automated Configuration Services)&lt;br /&gt;+ Logging &amp;amp; &lt;b&gt;Analytics&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (using automated detailed logging and clever analysis )&lt;br /&gt;&lt;br /&gt;This presentation just mentions the &lt;i&gt;&lt;b&gt;security considerations related to all these 3 DevOps processes&lt;/b&gt;&lt;/i&gt;...&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;+ Provisioning being affected by&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|=+ Non-Robust Cloud Frameworks,&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|=+ Vulnerable Service APIs, &amp;amp;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|=+ Virtualization BreakOuts&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;+ Configuration Management threatened by&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|=+ Non-Robust Services, &amp;amp;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|=+ Non-preferred storage of sensitive&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; configuration data&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;| &lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;+ Analytics&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|=+  Log Analysis frameworks have been&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; several times attacked by infecting&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the received logs resulting in service&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; level non-sanitized input  attacks.&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&amp;nbsp;|_ &lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-562091610671335320?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/562091610671335320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/08/devops-with-secops-short-intro-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/562091610671335320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/562091610671335320'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/08/devops-with-secops-short-intro-to.html' title='&quot;DevOps with SecOps&quot; ~ short intro to Security Implications in DevOps Process'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-101009680988647512</id><published>2011-08-11T15:37:00.000-07:00</published><updated>2011-08-11T15:37:21.236-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='curl'/><category scheme='http://www.blogger.com/atom/ns#' term='short urls'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='webhoudini'/><category scheme='http://www.blogger.com/atom/ns#' term='appengine'/><title type='text'>howto check for safety of Shorten URLs before opening them in your browsers</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;Short URLs were in fashion a while back and now they are in requirement.&lt;br /&gt;No matter which social, professional or public web portal you browse, you get to see short url.&lt;br /&gt;&lt;br /&gt;But Short URLs from so many sources are not secure as a carefully planted short url redirecting (sometimes single redirection and sometimes multiple) to an infected web portal.&lt;br /&gt;So, all the short links from non-reliable sources must be first traced back to original links and only visited if they cross-check successfully.&lt;br /&gt;&lt;br /&gt;So, how to know the actual portal to be visited without using that URL and following it to final location.&lt;br /&gt;&lt;br /&gt;[] &lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;from your shell&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;$ curl --head -L &lt;i&gt;http://short.en/url&lt;/i&gt; | grep Location:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;so, place the short url to be checked in place of "&lt;i&gt;&lt;b&gt;http://short.en/url&lt;/b&gt;&lt;/i&gt;" in the command provided above and then you can see the entire url trace and the final url to be visited...&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;[] &lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;from the web-app&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;Link:&amp;nbsp;&lt;b&gt;&lt;a href="http://webhoudini.appspot.com/"&gt;http://webhoudini.appspot.com/&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;At this portal paste in the link in Short URL text box and click the 'Unshorten' button to see the actual redirected URL.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://webhoudini.appspot.com/"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-adr6Pc7Tb3c/TkRXrd7QfpI/AAAAAAAAAvo/qWGYsGmEUOU/s1600/webhoudini_screenie1.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-101009680988647512?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/101009680988647512/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/08/howto-check-for-safety-of-shorten-urls.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/101009680988647512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/101009680988647512'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/08/howto-check-for-safety-of-shorten-urls.html' title='howto check for safety of Shorten URLs before opening them in your browsers'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-adr6Pc7Tb3c/TkRXrd7QfpI/AAAAAAAAAvo/qWGYsGmEUOU/s72-c/webhoudini_screenie1.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-3368074473104569172</id><published>2011-07-28T01:24:00.000-07:00</published><updated>2011-07-28T01:27:02.957-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='art of hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='sun tzu'/><category scheme='http://www.blogger.com/atom/ns#' term='eden'/><category scheme='http://www.blogger.com/atom/ns#' term='philosophy'/><category scheme='http://www.blogger.com/atom/ns#' term='guide'/><category scheme='http://www.blogger.com/atom/ns#' term='google appengine cloud paas authorization authentication security'/><category scheme='http://www.blogger.com/atom/ns#' term='rig veda'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>[Eden Guide to Hacking] 'Hacking Philosophy' ~ from Rig Veda and Sun Tzu's Art of War</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;This is a part of "Eden Guide to Hacking" which is my writing attempt for a quick to read, broadway guide to HACKING ~ for anyone to have grasp of important concepts and skills which makes up the knowledge base of a hacker.&lt;br /&gt;W.I.P. @&amp;nbsp;&lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking/"&gt;https://github.com/abhishekkr/eden_guide_to_hacking/&lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="color: lime; font-family: Verdana; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody style="background-color: black;"&gt;&lt;tr&gt;&lt;td style="font-family: Verdana; font-size: 10pt;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/td&gt;&lt;td class="title" style="font-family: Verdana; font-size: 10pt;"&gt;&lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking/blob/master/part0_Fundamentals/chapter2_Hacking_Philosophy/article1_Art_of_Hacking.txt" rel="nofollow" style="text-decoration: none;"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&lt;b&gt;'&lt;i&gt;Hacking Philosophy&lt;/i&gt;' ~ &lt;/b&gt;from &lt;b&gt;Rig Veda &lt;/b&gt;and&lt;b&gt; Sun Tzu's Art of War&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/blockquote&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;[+] Art of Hacking&lt;br /&gt; |&lt;br /&gt; |[+] from 'Rig Veda'&lt;br /&gt; | |&lt;br /&gt; | |[+] "Who so would kill us, &lt;br /&gt; | |  whether he be a strange foe or one of us."&lt;br /&gt; | |  Means: "The security parameters could be defeated by&lt;br /&gt; | |   (un/mis)-handled feature or an already compromised&lt;br /&gt; | |   component present within an un-breakable system."&lt;br /&gt; | |&lt;br /&gt; | |[+] "Loosed from the Bowstring fly away, thou arrow,&lt;br /&gt; | |   sharpened by our Prayer.&lt;br /&gt; | |  Go to the foemen, strike them home, and let not one&lt;br /&gt; | |   be left alive."&lt;br /&gt; | |  Means: "Make an exploit robust, accurate, infectious&lt;br /&gt; | |   and untraceable."&lt;br /&gt; | |_&lt;br /&gt; |&lt;br /&gt; |[+] skills could be seen as 13 chapters of Sun Tzu's&lt;br /&gt; | | 'Art of War' ~&lt;br /&gt; | |&lt;br /&gt; | |[+] Laying Plans&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Exploit the parameter never thought to be a&lt;br /&gt; | | |  part of the security implications of the system.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Waging War&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Don't overburden yourself with complex routes,&lt;br /&gt; | | |  if there exist less techie but more easy options.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Strategic Attack Planning&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Exploit the parameter never thought to be a&lt;br /&gt; | | |  part of the security implications of the system.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Tactical Disposition&lt;br /&gt; | | |&lt;br /&gt; | | |[+] First secure your own location &amp;amp; technologies,&lt;br /&gt; | | |  then you are in safe &amp;amp; stronger place to attack.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Directed Energy&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Attacking a complex security infrastrucure is&lt;br /&gt; | | |  no different than a simple one. Break it down.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Weaknesses &amp;amp; Strengths&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Analyze the system well to aim its vulnerability&lt;br /&gt; | | |  and leave it's alarm system untouched.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Engaging the Force&lt;br /&gt; | | |&lt;br /&gt; | | |[+] One can't defeat an opponent without knowledge&lt;br /&gt; | | |  of opponent's security &amp;amp; service design.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Variations &amp;amp; Adaptability&lt;br /&gt; | | |&lt;br /&gt; | | |[+] The system, service &amp;amp; security could be set up&lt;br /&gt; | | |  with any kind of tweaking and hence makes the &lt;br /&gt; | | |  pre-analysis for attack a failure.&lt;br /&gt; | | |  Attacker must be always ready to amend its ways.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] The Army on the March&lt;br /&gt; | | |&lt;br /&gt; | | |[+] When to attack, and when to wait.&lt;br /&gt; | | |  Instincts to stay out of trap &amp;amp; sense enemies.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Situational Positioning&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Access, attack &amp;amp; safety parameters involved.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] The 9 Battlegrounds&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Different types of security parameters lead to&lt;br /&gt; | | |  different attack or sometimes no attack practices.&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] 5 Ways of Attacking with Fire&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Break-in target's system with deception&lt;br /&gt; | | |[+] Starve the resources powering security&lt;br /&gt; | | |[+] Attack availability of service&lt;br /&gt; | | |[+] Defeat the implemented security system&lt;br /&gt; | | |[+] Infect reachable systems related to target&lt;br /&gt; | | |_&lt;br /&gt; | |&lt;br /&gt; | |[+] Intelligence &amp;amp; Espionage&lt;br /&gt; | | |&lt;br /&gt; | | |[+] Gather as much information possible and &lt;br /&gt; | | |  try attacks like spear phishing to have a slave.&lt;br /&gt; | | |_&lt;br /&gt; | |_&lt;br /&gt; |&lt;br /&gt; |[+] It's your Dharma to Hack, if you are a Geek.&lt;br /&gt; |&lt;br /&gt; |[+] &amp;amp; it all starts in following part of this Eden Guide&lt;br /&gt; |_&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/pre&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Link:&amp;nbsp;&lt;a href="https://github.com/abhishekkr/eden_guide_to_hacking/blob/master/part0_Fundamentals/chapter2_Hacking_Philosophy/article1_Art_of_Hacking.txt"&gt;https://github.com/abhishekkr/eden_guide_to_hacking/blob/master/part0_Fundamentals/chapter2_Hacking_Philosophy/article1_Art_of_Hacking.txt&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-3368074473104569172?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/3368074473104569172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/07/eden-guide-to-hacking-hacking.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3368074473104569172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3368074473104569172'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/07/eden-guide-to-hacking-hacking.html' title='[Eden Guide to Hacking] &apos;Hacking Philosophy&apos; ~ from Rig Veda and Sun Tzu&apos;s Art of War'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-495052797323712903</id><published>2011-06-30T09:19:00.000-07:00</published><updated>2011-06-30T09:19:06.718-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='google appengine cloud paas authorization authentication security'/><title type='text'>User Authentication &amp; Authorization [AT] Google AppEngine</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div&gt;&lt;b&gt;AppEngine&lt;/b&gt;, a &lt;b&gt;PaaS&lt;/b&gt; provided with a '&lt;b&gt;limited free&lt;/b&gt;' version to all GMail users (&lt;i&gt;Google Account Owners&lt;/i&gt;). So, you can host your WebContent their making use of Python, Java or Go.&lt;br /&gt;&lt;br /&gt;AppEngine enables you to use existing Google A/c of your Web-App users to be used for their authentication &amp;amp; authorization at your AppEngine-hosted Web-App also.&lt;br /&gt;&lt;br /&gt;So, there are two main ways to acieve that:&lt;br /&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;to import google.appengine.api.&lt;a href="http://code.google.com/appengine/docs/python/users/"&gt;&lt;b&gt;users&lt;/b&gt;&lt;/a&gt; &lt;br /&gt;this &lt;a href="http://code.google.com/appengine/docs/python/users/"&gt;USERS module&lt;/a&gt; from AppEngine APIs enables your Web-App to identify the users on the basis of their Google A/c ID (GMail ID) and then make the decision of routing the user to secured Resource or forbidden resource error message. &lt;br /&gt;[ &lt;a href="http://code.google.com/appengine/docs/python/users/loginurls.html"&gt;An Example on Usage&lt;/a&gt; ]&lt;br /&gt;&lt;/li&gt;&lt;li&gt;to specify '&lt;a href="http://code.google.com/appengine/docs/python/config/appconfig.html#Requiring_Login_or_Administrator_Status"&gt;&lt;b&gt;login&lt;/b&gt;&lt;/a&gt;' under '&lt;a href="http://code.google.com/appengine/docs/python/config/appconfig.html"&gt;&lt;b&gt;app.yaml&lt;/b&gt;&lt;/a&gt;'&lt;br /&gt;so the major basic configuration about your Web-App and routing configuration reside in 'app.yaml' file which has default location of Web-App root location.&lt;br /&gt;So, you can specify at secured '&lt;b&gt;url&lt;/b&gt;' specifications to enforce user for a Google A/c (GMail) login. &lt;br /&gt;[ &lt;a href="http://code.google.com/appengine/docs/python/config/appconfig.html#Requiring_Login_or_Administrator_Status"&gt;An Example Of Usage&lt;/a&gt; ]&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;In, both of these implementations whenever a user tries to visit a 'secured url' on your Web-App, they are automatically redirected to Google A/c Log-In page further redirecting them back to your Web-App on succesful log-in.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;The &lt;i&gt;Curious Case&lt;/i&gt; of &lt;/b&gt;&lt;b&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=2442688623759178220&amp;amp;postID=495052797323712903"&gt;static_dir&lt;/a&gt; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;Initially while working for my newly initiated opensource project 'py-gae-legs',&lt;b&gt; I added entire 'secure URL' logic by method#1&lt;/b&gt; i.e. using 'users' api.&lt;br /&gt;It was all working fine &amp;amp; secured until I added some &lt;a href="http://code.google.com/appengine/docs/python/gettingstarted/staticfiles.html"&gt;static-content using static_dir&lt;/a&gt; and tried securing it's url using the same tactic.&lt;br /&gt;&lt;br /&gt;But, there was a thing about '&lt;a href="http://code.google.com/appengine/docs/python/gettingstarted/staticfiles.html"&gt;static_dir&lt;/a&gt;' which I investigated after my &lt;b&gt;supposed-to-be secure&lt;/b&gt; static_dir's content &lt;b&gt;was all publicly availabl&lt;/b&gt;e if someone could enumerate/know the complete url.&lt;br /&gt;&lt;i&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;{I'm in the category of people who keep their learning pace up along with working over it... and anyway I wasn't gonna read the entire #^(&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;The thing about it was... the &lt;b&gt;directories marked to be 'static_dir'&lt;/b&gt; in 'app.yaml' are &lt;b&gt;no more located&lt;/b&gt; on the AppEngine Server &lt;b&gt;in the same location after you update your Web-App&lt;/b&gt;.&lt;br /&gt;So, the entire directory structure would remain same... it's just that the &lt;b&gt;'static_dir' marked locations&lt;/b&gt; would somehow &lt;b&gt;vanish from&lt;/b&gt; it on your &lt;b&gt;Web-App's location at AppEngine &lt;/b&gt;and &lt;b&gt;served from some other provision&lt;/b&gt; made by Google which maps back to the location.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;So, to secure&lt;/b&gt; the 'static_dir' located urls... the only way ( that I know of ) is to implement it at the very core of Web-App configurations i.e. in 'app.yaml' &lt;b&gt;using the Method#2&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;So, you can enforce Google Login to be mandatory by setting 'login:required' for that 'url' setting. If you want only a selected Users to see that, then you'll have to add all those Google A/c (GMail) IDs by doing following&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;[a.] &lt;b&gt;goto Dashboard of your GoogleAppEngine Web-App&lt;/b&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;the URL-Box link would look like: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt; &lt;span style="color: yellow;"&gt;https://appengine.google.com/permissions?app_id=s%7E$GAE_APPLICATION_NAME&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;[b.] &lt;b&gt;click the link 'Permission'&lt;/b&gt; from Right-Menu-Column,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;[c.] now, &lt;b&gt;invite all those user's by providing their e-mail ID &lt;/b&gt;and changing their role to 'Viewer'&lt;/span&gt;and at app.yaml provide '&lt;b&gt;login:admin&lt;/b&gt;' instead of '&lt;b&gt;login:required&lt;/b&gt;'.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ &lt;br /&gt;Lately, I've been involved at starting an &lt;b&gt;OpenSource&lt;/b&gt; project '&lt;b&gt;&lt;a href="https://github.com/abhishekkr/py-gae-legs" title="created a basic architecture, wokring on automated generation part"&gt;py-gae-legs&lt;/a&gt;&lt;/b&gt;'.&lt;br /&gt;&lt;br /&gt;It's a very &lt;i&gt;&lt;b&gt;basic subset&lt;/b&gt;&lt;/i&gt; of &lt;i&gt;&lt;b&gt;WebApp-Framework&lt;/b&gt;&lt;/i&gt; &lt;b&gt;for the lovers of &lt;a href="http://rubyonrails.org/" title="Ruby On Rails"&gt;RoR&lt;/a&gt;&lt;/b&gt; (have been working on it for past few months, love the ease it gives but hate the convention being the soul) style of web-app creation.&lt;br /&gt;&lt;br /&gt;This project just aims web-development &lt;b&gt;specifically aimed to be hosted over AppEngine&lt;/b&gt; (&lt;i&gt;currently&lt;/i&gt;).&lt;br /&gt;Almost done with &lt;b&gt;it's basic starters&lt;/b&gt; to look at:&lt;br /&gt;[] &lt;b&gt;&lt;a href="https://github.com/abhishekkr/gae-flat-web"&gt;gae-flat-web&lt;/a&gt;&lt;/b&gt; : to create an architecture hosting your already created static website, &lt;a href="http://gae-flat-web.appspot.com/"&gt;http://gae-flat-web.appspot.com&lt;/a&gt;&lt;br /&gt;[] &lt;b&gt;&lt;a href="https://github.com/abhishekkr/gae-private-web"&gt;gae-private-web&lt;/a&gt;&lt;/b&gt; : [&lt;b&gt;W.I.P.&lt;/b&gt;] to host all your private content hosted securely (by Google) in an by-invite only website&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-495052797323712903?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/495052797323712903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/06/user-authentication-authorization-at.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/495052797323712903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/495052797323712903'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/06/user-authentication-authorization-at.html' title='User Authentication &amp; Authorization [AT] Google AppEngine'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-6395771997111151938</id><published>2011-05-25T16:05:00.000-07:00</published><updated>2011-05-25T16:05:42.102-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hack'/><category scheme='http://www.blogger.com/atom/ns#' term='bypass'/><category scheme='http://www.blogger.com/atom/ns#' term='banned'/><category scheme='http://www.blogger.com/atom/ns#' term='adsense'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Ban'/><title type='text'>How I got "2 Time Life-Time Banned" From Google Adsense</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;A Life-Time&lt;/span&gt; Ban from Google Adsense&lt;/b&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;I kin'of registered for Google Adsense service on my portal [ http://www.alwayspost.cjb.net/ (it's dead now, no more belongs to me) ] in very initial days, probably starting 2004&lt;/i&gt;.&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-Ws378ilC9dI/Td2H4iPyAcI/AAAAAAAAAtU/7tv1YDvSilA/s1600/1banned.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-Ws378ilC9dI/Td2H4iPyAcI/AAAAAAAAAtU/7tv1YDvSilA/s1600/1banned.jpg" /&gt;&lt;/a&gt;I used to have &lt;b&gt;few newbie blogs&lt;/b&gt; (not these, other newbie blogs) on blogger related to movies, wallpapers &amp;amp; technology.&lt;br /&gt;&lt;b&gt;&lt;i&gt;So, in a very honest way I added the provided AdSense code to my blogs and started posting regularly. &lt;/i&gt;&lt;/b&gt;It was working at a sloooow rate but I was Ok with it.&lt;br /&gt;&lt;br /&gt;I recently moved over from C++ to play &lt;b&gt;with VB6&lt;/b&gt; and was &lt;b&gt;trying all fun stuff &lt;/b&gt;I could get my hands on.&lt;br /&gt;One of the fun things I found was making mouse-clicks at desired locations.&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;&amp;amp; zooom~click~drag~code~drag~adjust~code...&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;there was an&lt;b&gt; ie-ocx-control&lt;/b&gt; in a &lt;b&gt;form&lt;/b&gt;,&lt;b&gt; loading&lt;/b&gt; all my &lt;b&gt;blogs&lt;/b&gt; one-by-one &lt;b&gt;and code&lt;/b&gt; (pre-loaded with specific locations of X-Y locations of Ads on the pages)&lt;b&gt; forging mouse-left-clicks on all Ads&lt;/b&gt;... all &lt;b&gt;repeated with&lt;/b&gt; a simple &lt;b&gt;Timer&lt;/b&gt;.&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Just left it on for a night... had LOADS of Ad Clicks and never tried it again.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;One week later, there was a mail from AdSense in my GMail A/c &lt;b&gt;stating I've been banned for life-time &lt;/b&gt;from Google's AdSense service&lt;b&gt;.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;~~~~~~~~~~~&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;'Second Life'&lt;/span&gt; in Google AdSense&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I signed-up for a &lt;b&gt;new e-mail address and&lt;/b&gt; tried registering with&lt;b&gt; a new mailing address&lt;/b&gt;, and there it &lt;b&gt;was... my new AdSense account&lt;/b&gt;.&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-6gVkKvV5zrU/Td2IK3YgocI/AAAAAAAAAtc/fHWPmDr-yBI/s1600/2banned.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-6gVkKvV5zrU/Td2IK3YgocI/AAAAAAAAAtc/fHWPmDr-yBI/s1600/2banned.jpg" /&gt;&lt;/a&gt;&lt;i&gt;This time I did nothing against the rules&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;Google released Page Creator (which is closed now) and I &lt;i&gt;registered a new portal &lt;/i&gt;on my mailing-address at [ http://abhikumar163.googlepages.com ] &lt;i&gt;and start linking it on forums with nice technological content to get valid page hits.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;b&gt;And, I made a mistake.&lt;/b&gt; I placed &lt;i&gt;a link to my old-&amp;amp;-no-more-existing-portal&amp;nbsp;[ http://www.alwayspost.cjb.net/ ] &lt;/i&gt;which was the portal registered with my earlier AdSense account.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Google&lt;/b&gt;'s Crawler &amp;amp; Staff &lt;b&gt;noticed it after I attained some amount&lt;/b&gt; in my account, &lt;b&gt;and&lt;/b&gt; blocked my account and &lt;b&gt;banned me for life-time &lt;i&gt;Second time&lt;/i&gt;&lt;/b&gt;.&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;~~~~~~~~~~~&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;Currently, I'm on my Second Life-time Ban... and don't wanna Third Play, may be when I get bored again.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-6395771997111151938?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/6395771997111151938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/05/how-i-got-2-time-life-time-banned-from.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6395771997111151938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6395771997111151938'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/05/how-i-got-2-time-life-time-banned-from.html' title='How I got &quot;2 Time Life-Time Banned&quot; From Google Adsense'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-Ws378ilC9dI/Td2H4iPyAcI/AAAAAAAAAtU/7tv1YDvSilA/s72-c/1banned.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-1987897425329604870</id><published>2011-03-30T04:28:00.000-07:00</published><updated>2011-03-30T04:40:03.285-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web'/><category scheme='http://www.blogger.com/atom/ns#' term='SSL'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><category scheme='http://www.blogger.com/atom/ns#' term='Free Internet'/><category scheme='http://www.blogger.com/atom/ns#' term='sslstrip'/><category scheme='http://www.blogger.com/atom/ns#' term='Sidejacking'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTPS'/><category scheme='http://www.blogger.com/atom/ns#' term='ABK'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Full site SSL-ification is not an option, need to make SSL secure first</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;I have&amp;nbsp; heard (Recently and in past) security aware lives wasting a lot of their potential over the argument like&amp;nbsp; &lt;br /&gt;+ '&lt;b&gt;Basic HTTP is insecure&lt;/b&gt;' {sometimes in novice past} &lt;br /&gt;+ '&lt;b&gt;SSL-ify entire web service&lt;/b&gt;' {still a lot push is there} &lt;br /&gt;&lt;br /&gt;Now, '&lt;b&gt;Basic HTTP&lt;/b&gt;' being insecure is not a flaw by design... but a flaw by choice.&lt;br /&gt;First of all, when foundation of HTTP were laid attackers were not in the scene. The only concern was ultra productive usability and that is not possible putting all kind of security checks on the service.&lt;br /&gt;Secondly, HTTP wasn't meant to be secure, it was just meant to transfer data in adhering to a protocol which can be used by web-services to recieve user's requests and deliver requested content, that's all.&lt;br /&gt;Cryptography mixed into it will destroy the ease and speed it has. Cryptography over it is instead a necessary (in some cases) and correct (design) option.&lt;br /&gt;Though it has been haunting the websites by attacks like&lt;br /&gt;+[] &lt;i&gt;&lt;b&gt;SSL Stripping&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_p3XIipv981Y/S88RVdmcG1I/AAAAAAAAAEA/g3d5W2XJFFs/s1600/MITM.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="150" src="http://3.bp.blogspot.com/_p3XIipv981Y/S88RVdmcG1I/AAAAAAAAAEA/g3d5W2XJFFs/s200/MITM.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;It's due to a flaw in the way Security is implemented in a web application. For example, you visit Facebook Login page at facebook.com which have a HTTPS link in its unprotected page-content to send over the credentials in a protected manner. But what if some attacker using Monkey-in-the-Middle strategy changed that HTTPS link to a HTTP link and sniff your sent credentials... w00t right.&lt;/blockquote&gt;+[] &lt;i&gt;&lt;b&gt;Sidejacking&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;blockquote&gt;It occurs due to web-application sending cookie information over non-ssl links. This allows any Man-in-the-Middle to sniff the cookie then replicate in his/her own browser and use the service identifying user just on basis of cookie information... it pwn3d services like GMail, Y!Mail, Hotmail, etc. until Q1-2010.&lt;/blockquote&gt;&lt;br /&gt;Then, '&lt;b&gt;Full Site SSL-ification&lt;/b&gt;' is a good choice from theoretical security point-of-view, but just in theory. &lt;br /&gt;Different SSL-Defeating attacks involving &lt;br /&gt;+[] &lt;i&gt;&lt;b&gt;Flaws in Libraries like NSS&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;blockquote&gt;There was a (earlier exploited, later) famous flaw in libraries with the case of NULL inclusion in URLs used for Domain name on which SSL Certificate is being issued. Mozilla Engine used NSS Cryptography libraries purely written in C and using basic insecure string functions for comparisons were tricked by certificates for domain name like &amp;lt;&amp;lt;www.paypal.com\0innocent.com&amp;gt;&amp;gt; stopping at first null after &amp;lt;&amp;lt;www.paypal.com&amp;gt;&amp;gt;. Webkit, Opera used null-stripping but they were tricked in just reversed attack using certificates for domain-name like &amp;lt;&amp;lt;www.pay\0pal.com&amp;gt;&amp;gt; stripping out usefull null.&lt;/blockquote&gt;&lt;a href="http://static.technorati.com/11/03/24/29977/comodo-hack.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="168" src="http://static.technorati.com/11/03/24/29977/comodo-hack.jpg" width="200" /&gt;&lt;/a&gt;+[] &lt;i&gt;&lt;b&gt;Fake SSL Certificate generation&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;blockquote&gt;Not a flaw in SSL, neither in its implementation but in the authorities enforcing it. &lt;br /&gt;In a recent disclosure, Comodo Inc (a major issuer of SSL Certificate) accepted that an attacker was able to get credentials of 'Comodo Registration Authority' based in Southern Europe. &lt;br /&gt;An Iranian attacker used the privilege to issue 9 fraud SSL certificates to 7 web domains including those for Google, Yahoo and Skype.&lt;/blockquote&gt;&lt;br /&gt;&lt;div style="background-color: #cccccc; color: purple; font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp; So, if you will look deeper into serial-murder case file of &lt;br /&gt;&amp;nbsp; SSL Certificates, you'll see it ain't safe...&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;span style="background-color: #cccccc; color: purple; font-size: small;"&gt;&amp;nbsp; and so there is no point in argument over its mixed/full &lt;br /&gt;&amp;nbsp; implementation.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-1987897425329604870?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/1987897425329604870/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/03/full-site-ssl-ification-is-not-option.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1987897425329604870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1987897425329604870'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/03/full-site-ssl-ification-is-not-option.html' title='Full site SSL-ification is not an option, need to make SSL secure first'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_p3XIipv981Y/S88RVdmcG1I/AAAAAAAAAEA/g3d5W2XJFFs/s72-c/MITM.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-5087350940206373958</id><published>2011-03-15T23:16:00.000-07:00</published><updated>2011-03-15T23:16:17.509-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Policies'/><category scheme='http://www.blogger.com/atom/ns#' term='India'/><category scheme='http://www.blogger.com/atom/ns#' term='bypass'/><category scheme='http://www.blogger.com/atom/ns#' term='Free Internet'/><category scheme='http://www.blogger.com/atom/ns#' term='WiFi'/><category scheme='http://www.blogger.com/atom/ns#' term='Failure'/><category scheme='http://www.blogger.com/atom/ns#' term='Airport'/><title type='text'>Indian Airport Internet ~ Hacking Policies Not Tweaking Systems</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;Few Indian Airport avail WiFi Internet Connectivity to Customers... and what I'm going to discuss about is&lt;b&gt; not hacking the WiFi Network but&lt;/b&gt; a simple naive way to hack the &lt;b&gt;Service Scheme instead&lt;/b&gt; and gain much more free access than provided little i.e. 30min&lt;br /&gt;&lt;br /&gt;I found it in two cities (Delhi, Bengaluru among visited Indian Airports) till now. Both have different hardware supporting it but the same service scheme.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh5.googleusercontent.com/--XxUxDk6THE/TYBVOo_ahmI/AAAAAAAAAtQ/C8jl15kD8dU/s1600/weakpoliciesWifi.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh5.googleusercontent.com/--XxUxDk6THE/TYBVOo_ahmI/AAAAAAAAAtQ/C8jl15kD8dU/s1600/weakpoliciesWifi.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;i&gt;&lt;b&gt;The Service Acts in following way:&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;Step.1:&lt;/b&gt;&lt;br /&gt;You'll get an Open WiFi Network by the name of Airport which lets you to connect without any credentials.&lt;br /&gt;Connect to it.&lt;br /&gt;&lt;b&gt;Step.2:&lt;/b&gt;&lt;br /&gt;Open web-browser and hit any URL; this will redirect you to a single page provided by Service Provider with details of how you can get credentials for free-demo WiFi-access.&lt;br /&gt;Here, you'll have to submit your Mobile Phone number, which will receive SMS of credentials for demo access.&lt;br /&gt;Get the credentials.&lt;br /&gt;&lt;b&gt;Step.3:&lt;/b&gt;&lt;br /&gt;Use those credentials on the same page, under login section.&lt;br /&gt;You are connected to WiFi for internet access until demo-time (30 minutes) pass.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif; font-size: large;"&gt;&lt;b&gt;Loopholes in Service Scheme:&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;[] Continuous Access For Longer Duration&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The more mobile numbers you can have access to...&lt;br /&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&amp;nbsp;give your friends/family/personal/official Mobile Numbers to gain more demo credentials...&amp;nbsp;&lt;/li&gt;&lt;li&gt;&amp;nbsp;and simply ask them to forward respective SMS to you&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;...the more duration you can have demo WiFi access.&lt;br /&gt;&lt;br /&gt;Now, the system don't check your MAC Address for earlier demo privileged machines...&lt;br /&gt;so you don't even require anything as simple as mac-changer.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;[] Parallel Access For Same Credential Set&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;As, I already said MAC is not checked... so suppose you have multiple WiFi enabled devices.&lt;br /&gt;You can use the same credentials on all devices at the same time.&lt;br /&gt;Just need to consider what is the time-frame for that credential to expire.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-5087350940206373958?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/5087350940206373958/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/03/indian-airport-internet-hacking.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/5087350940206373958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/5087350940206373958'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/03/indian-airport-internet-hacking.html' title='Indian Airport Internet ~ Hacking Policies Not Tweaking Systems'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh5.googleusercontent.com/--XxUxDk6THE/TYBVOo_ahmI/AAAAAAAAAtQ/C8jl15kD8dU/s72-c/weakpoliciesWifi.gif' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-2550490697271204573</id><published>2011-03-04T07:23:00.000-08:00</published><updated>2011-03-04T07:24:18.274-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='conference'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='research'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='nullcon'/><category scheme='http://www.blogger.com/atom/ns#' term='presentation'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Presentation on "XSS Defeating Concept in (secure)SiteHoster" : 'nullcon-2011'</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;this is the work that I presented in 'nullcon - 2011' an security conference held at Goa by an emerging Security Community of India known as 'null'&lt;br /&gt;it's mainly regarding preventing XSS Attacks with an entire new Concept based on 'Bug-As-A-Service' and 'Attacking-The-Attacker'...&lt;br /&gt;any views/questions/comments/critics/confusions&lt;br /&gt;----------&lt;br /&gt;&lt;b&gt;Presentation:&lt;/b&gt;&lt;br /&gt;&lt;div id="__ss_7147884" style="width: 595px;"&gt;&lt;b style="display: block; margin: 12px 0pt 4px;"&gt;&lt;a href="http://www.slideshare.net/AbhishekKr/null-con2tiya" title="Presentation on &amp;quot;XSS Defeating Concept in (secure)SiteHoster&amp;quot; : 'nullcon-2011'"&gt;Presentation on "XSS Defeating Concept in (secure)SiteHoster" : 'nullcon-2011'&lt;/a&gt;&lt;/b&gt; &lt;br /&gt;&lt;object height="497" id="__sse7147884" width="595"&gt; &lt;param name="movie" /&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;embed width="430" height="340" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=nullcon2tiya-110304063235-phpapp02&amp;amp;stripped_title=null-con2tiya&amp;amp;userName=AbhishekKr" name="__sse7147884" type="application/x-shockwave-flash" allowfullscreen="true"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;br /&gt;&lt;div style="padding: 5px 0pt 12px;"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/AbhishekKr"&gt;Abhishek Kumar&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;----------&lt;br /&gt;&lt;b&gt;Concept-Part-1 WhitePaper:&lt;/b&gt;&lt;br /&gt;&lt;div id="__ss_5137259" style="width: 382px;"&gt;&lt;b style="display: block; margin: 12px 0pt 4px;"&gt;&lt;a href="http://www.slideshare.net/AbhishekKr/whitepaper-abktrick-to-subvert-xss" title="XSS Defeating Trick ~=ABK=~ WhitePaper"&gt;XSS Defeating Trick ~=ABK=~ WhitePaper&lt;/a&gt;&lt;/b&gt; &lt;br /&gt;&lt;object height="408" id="__sse5137259" width="382"&gt; &lt;param name="movie" /&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;embed width="382" height="408" src="http://static.slidesharecdn.com/swf/doc_player.swf?doc=whitepaperabktricktosubvertxss-100906042821-phpapp02&amp;amp;stripped_title=whitepaper-abktrick-to-subvert-xss&amp;amp;userName=AbhishekKr" name="__sse5137259" type="application/x-shockwave-flash" allowfullscreen="true"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;br /&gt;&lt;div style="padding: 5px 0pt 12px;"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;documents&lt;/a&gt; from &lt;a href="http://www.slideshare.net/AbhishekKr"&gt;Abhishek Kumar&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;----------&lt;br /&gt;&lt;b&gt;Concept-Part-2 WhitePaper:&lt;/b&gt;&lt;br /&gt;&lt;div id="__ss_6822045" style="width: 382px;"&gt;&lt;b style="display: block; margin: 12px 0pt 4px;"&gt;&lt;a href="http://www.slideshare.net/AbhishekKr/xss-defeating-conceptpart2" title="XSS Defeating Concept - Part 2"&gt;XSS Defeating Concept - Part 2&lt;/a&gt;&lt;/b&gt; &lt;br /&gt;&lt;object height="408" id="__sse6822045" width="382"&gt; &lt;param name="movie" /&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;embed width="382" height="408" src="http://static.slidesharecdn.com/swf/doc_player.swf?doc=xssdefeatingconcept-part2-110205085203-phpapp02&amp;amp;stripped_title=xss-defeating-conceptpart2&amp;amp;userName=AbhishekKr" name="__sse6822045" type="application/x-shockwave-flash" allowfullscreen="true"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;br /&gt;&lt;div style="padding: 5px 0pt 12px;"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;documents&lt;/a&gt; from &lt;a href="http://www.slideshare.net/AbhishekKr"&gt;Abhishek Kumar&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;----------&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-2550490697271204573?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/2550490697271204573/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/03/presentation-on-xss-defeating-concept.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/2550490697271204573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/2550490697271204573'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/03/presentation-on-xss-defeating-concept.html' title='Presentation on &quot;XSS Defeating Concept in (secure)SiteHoster&quot; : &apos;nullcon-2011&apos;'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-7620285846564837100</id><published>2011-02-18T11:14:00.000-08:00</published><updated>2011-02-18T11:14:20.328-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerable'/><category scheme='http://www.blogger.com/atom/ns#' term='Server'/><category scheme='http://www.blogger.com/atom/ns#' term='csrf'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='solr'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><category scheme='http://www.blogger.com/atom/ns#' term='search'/><category scheme='http://www.blogger.com/atom/ns#' term='apache'/><title type='text'>Apache SOLR ~ a talented yet careless server</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;SOLR&lt;/span&gt;&lt;/b&gt;... what it is?&lt;br /&gt;link:&amp;nbsp;&lt;a href="http://wiki.apache.org/solr/FAQ#What_is_Solr.3F"&gt;http://wiki.apache.org/solr/FAQ#What_is_Solr.3F&lt;/a&gt;&lt;br /&gt;in short... &lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;it's an enterprise class search server&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;SOLR Security Consideration&lt;/span&gt;&lt;/b&gt;... are clearly stated&lt;br /&gt;link:&amp;nbsp;&lt;a href="http://wiki.apache.org/solr/SolrSecurity"&gt;http://wiki.apache.org/solr/SolrSecurity&lt;/a&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;[] Solr does not concern itself with security either at the document level or the communication level.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;[] It strongly recommends that the application server containing Solr be firewalled such that the only clients with access to Solr are your own&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;[] Default installation of Solr allows any client with access to it to add, update, and delete documents (and of course search/read too), including access to the Solr configuration and schema files and the administrative user interface.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;[] Even if firewalled, it might be vulnerable to CSRF because Solr's basic behavior is to receive updates and deletes via HTTP...&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;So if you restricted Solr's /update handler to accept connections from approved hosts/clients... then also approved clients can be tricked to open another page with malicious script while they are authenticated at Solr.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;[] Basic technique to mitigate this risk is to configure Servlet Container to server speicifc IPs or with HTTP-Authentication.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', sans-serif;"&gt;[] Solr doesn't aim to for Document Level Security, recommended way is through Apache Lucene Connector Framework.&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;SOLR is a very capable search server, but if you need to use it... be sure to make it unreachable.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-7620285846564837100?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/7620285846564837100/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2011/02/apache-solr-talented-yet-careless.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/7620285846564837100'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/7620285846564837100'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2011/02/apache-solr-talented-yet-careless.html' title='Apache SOLR ~ a talented yet careless server'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-6156490062349952483</id><published>2010-12-29T05:09:00.000-08:00</published><updated>2010-12-29T05:09:00.722-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Mozilla'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='Critics'/><category scheme='http://www.blogger.com/atom/ns#' term='Accounts'/><title type='text'>Weak Excuses after Weak Security :: Mozilla's user a/c on Public Server</title><content type='html'>&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;now this year has been filled with loads of news related to user-data getting leaked from different websites... but it wasn't much disturbing as web-vulnerabilities in Facebook are well known and accepted as cons of the deal and neither 1.3m a/c details leaked from Gawker came as a shock (it was more of a Tweet-Flood)&lt;/div&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;but&lt;/span&gt;&lt;br /&gt;&lt;b&gt;On &lt;/b&gt;&lt;b&gt;&lt;span style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;Dec-17-2010&lt;/span&gt;, Mozilla was reported about availability of its user-accounts (&lt;span style="font-size: x-small;"&gt;&lt;i&gt;partially, which were used on addons.mozilla.org&lt;/i&gt;&lt;/span&gt;) over a public server.&lt;/b&gt;&lt;br /&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;They have projects like Firefox (super famous web-browser), NSS (one of the most famous libraries for developing secured client-server application), and more... if an organization like them do a mistake like this, oh yeah... hackers paradise&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;it's how they defend themselves...&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;database included 44,000 inactive accounts using older&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;but don't you think... &lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif; font-size: small;"&gt;even inactive users on a site deserve their privacy, and if they were inactive and not important then better purge the information pertaining to account... why keep it instead&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/li&gt;&lt;li&gt;md5-based password hashes&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;they don't use it now... &lt;/i&gt;&lt;/b&gt;&lt;span style="font-size: small;"&gt;&lt;i style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;for active users they support SHA-512 per-user-salt mechanism; now that's good&lt;/i&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/li&gt;&lt;li&gt;current addons.mozilla.org users and  accounts are not at risk&lt;blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;so if I don't use Mozilla anymore... &lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif; font-size: small;"&gt;they wouldn't respect my a/c details anymore and still keep it... so that in future they could 'arrrrgh sorrry' me, brutally nice&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/li&gt;&lt;li&gt;incident did not impact any  of Mozilla’s infrastructure&lt;blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;it was available on a public server and not a hacked-n-fetched... &lt;/i&gt;&lt;/b&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif; font-size: small;"&gt;&lt;i&gt;bravo&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/li&gt;&lt;li&gt;&lt;span id="intelliTxt"&gt;only outsider who accessed the data was the security researcher that reported the mistake to Mozilla&lt;/span&gt; &lt;blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;how are they so sure... &lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif; font-size: small;"&gt;if none else reported it doesn't mean that none else saw it, and it is not necessary that everyone accessing it will 'remain in' logs.&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size: x-small;"&gt;References:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;a href="http://blog.mozilla.com/security/2010/12/27/addons-mozilla-org-disclosure/"&gt;http://blog.mozilla.com/security/2010/12/27/addons-mozilla-org-disclosure/&lt;/a&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;a href="http://www.thetechherald.com/article.php/201052/6620/Mozilla-password-disclosure-a-non-event"&gt;http://www.thetechherald.com/article.php/201052/6620/Mozilla-password-disclosure-a-non-event&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-6156490062349952483?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/6156490062349952483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/12/weak-excuses-after-weak-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6156490062349952483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6156490062349952483'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/12/weak-excuses-after-weak-security.html' title='Weak Excuses after Weak Security :: Mozilla&apos;s user a/c on Public Server'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-4161935183068710449</id><published>2010-12-21T00:59:00.000-08:00</published><updated>2010-12-21T01:02:58.505-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='download'/><category scheme='http://www.blogger.com/atom/ns#' term='bypass'/><category scheme='http://www.blogger.com/atom/ns#' term='website'/><category scheme='http://www.blogger.com/atom/ns#' term='bug'/><category scheme='http://www.blogger.com/atom/ns#' term='source'/><category scheme='http://www.blogger.com/atom/ns#' term='flash'/><category scheme='http://www.blogger.com/atom/ns#' term='scribd.com'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='document'/><title type='text'>bypass of user level restrictions, a case of bug in 'Scribd.com'</title><content type='html'>http://www.youtube.com/watch?v=g-ETsFjRhqsFew weeks back, saw &lt;b&gt;Scribd.com&lt;/b&gt; &lt;b&gt;offering me to buy/upload something for downloading a Document uploaded on it. &lt;/b&gt;Second time when I opened some document, in another browser &lt;b&gt;it shows disabled 'download', 'print', and 'mobile' option.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;As I didn't get that Document to download, I didn't felt like reading it online also... &lt;b&gt;so just thought why not try to download it and if I succeed, then I'll read it online.&lt;/b&gt;&lt;br /&gt;And I read it online :)&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;i&gt;&lt;b&gt;So, here is a bug (which&amp;nbsp; has now been fixed) in Scribd.com... that allowed users to get a local copy of documents which were devoid of download and print options.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;b style="background-color: #f1c232; color: #990000; font-family: Verdana,sans-serif;"&gt;It's how layered limitation can be broken, and why restrictions must be implemented root-level-up and not just as user-level module.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=g-ETsFjRhqs"&gt;@&lt;b&gt;YouTube&lt;/b&gt;: http://www.youtube.com/watch?v=g-ETsFjRhqs&lt;/a&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;&lt;span style="font-size: large;"&gt;How-To&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;[&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;download the not-allowed ]&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;example: Bypass Scribd.com disabling Downloading/Print/Mobile on some links&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;iframe frameborder="0" height="225" src="http://player.vimeo.com/video/18020569" width="400"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/18020569"&gt;Example Website Bug : a bug of Scribd.com (reported &amp;amp; got fixed)&lt;/a&gt; from &lt;a href="http://vimeo.com/abionic"&gt;aBionic@Vimeo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;so, now you can either Print the document or create a PDF/image printing this document using softwares like PDFCreator.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-4161935183068710449?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/4161935183068710449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/12/bypass-of-user-level-restrictions-case.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/4161935183068710449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/4161935183068710449'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/12/bypass-of-user-level-restrictions-case.html' title='bypass of user level restrictions, a case of bug in &apos;Scribd.com&apos;'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-3321486149139801951</id><published>2010-12-17T05:08:00.000-08:00</published><updated>2010-12-17T05:16:52.802-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='domain'/><category scheme='http://www.blogger.com/atom/ns#' term='Server'/><category scheme='http://www.blogger.com/atom/ns#' term='dns'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='dnssec'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>only '.org' and '.net' domains under DNSSEC protection till now, WHAT ABOUT YOU</title><content type='html'>Are you protected with DNSSEC:&lt;br /&gt;[] in mid-2010, DNSSEC got deployed over 'root-DNS-server' and '.org' domain&lt;br /&gt;[] on 10-Dec-2010, Verisign deployed DNSSEC in '.net' zone too&lt;br /&gt;&lt;i&gt;&amp;nbsp;&amp;nbsp; {securing more than 13million registrations online}&lt;/i&gt;&lt;br /&gt;[] preparations are up to sign the '.com' zone in first quarter of 2011&lt;br /&gt;&lt;div style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="background-color: #fff2cc; color: #134f5c; font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: small;"&gt;Verisign has even launched a cloud based DNSSEC implementation service to ease its implementation in organisations.&lt;/span&gt;&lt;/div&gt;&lt;b style="background-color: #fff2cc; color: #134f5c;"&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif; font-size: x-small;"&gt;Refer to &lt;a href="http://www.securityweek.com/verisign-launches-new-dnssec-signing-service"&gt;http://www.securityweek.com/verisign-launches-new-dnssec-signing-service &lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;For those who are not much familiar with DNSSEC, its a security layer standardized to be implemented over traditional DNS services... it will help the users counter DNS vulnerabilities exposed by researchers like 'Dan Kaminsky' including DNS poisoning attacks. &lt;br /&gt;&lt;b&gt;Refer to &lt;a href="http://www.dnssec.net/"&gt;http://www.dnssec.net&lt;/a&gt; &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Its implementation would require more processing power, bandwidth usage and more storage needs as it uses intensive encryption mechanism over all DNS traffic.&lt;br /&gt;&lt;br /&gt;Though, I was surprised hearing initially of its implementation over root DNS server as its alterantive DNSCURVE (suggested by Dan Kaminsky) was conceptually better in security and easy on resources too. Don't know it was fair selection or just another political/community-biased decision.&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #0b5394; color: #cfe2f3; font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;=begin :footer&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="background-color: #0b5394; color: #cfe2f3; font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;#&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: x-small;"&gt; waited about a week to have time doing this post in detail...&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: #0b5394; color: #cfe2f3; font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;&lt;span style="font-size: x-small;"&gt;# but more delay would deny its usability... so its here&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: #0b5394; color: #cfe2f3;"&gt;&lt;i&gt;&lt;span style="font-family: Georgia,&amp;quot;Times New Roman&amp;quot;,serif; font-size: x-small;"&gt;=end :footer&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-3321486149139801951?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/3321486149139801951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/12/only-org-and-net-domains-under-dnssec.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3321486149139801951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3321486149139801951'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/12/only-org-and-net-domains-under-dnssec.html' title='only &apos;.org&apos; and &apos;.net&apos; domains under DNSSEC protection till now, WHAT ABOUT YOU'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-7117791070650954775</id><published>2010-09-26T12:49:00.000-07:00</published><updated>2010-09-26T12:49:04.900-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='Twitter'/><category scheme='http://www.blogger.com/atom/ns#' term='scripting'/><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Orkut'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='cross'/><category scheme='http://www.blogger.com/atom/ns#' term='FB'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>XSSed Orkut after Twitter after Facebook &lt;xss/&gt;</title><content type='html'>'&lt;b&gt;&lt;i&gt;Are you social?&lt;/i&gt;&lt;/b&gt;'&lt;br /&gt;ohhh... let me rephrase it '&lt;b&gt;&lt;i&gt;Are you net-social?&lt;/i&gt;&lt;/b&gt;'&lt;br /&gt;yeah... &lt;b&gt;&lt;i&gt;then how much socially secure are you when the plain-text attacks are htting millions&lt;/i&gt;&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;2 months back with Facebook&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;now almost treated as synonym of Social Networking, and more than 400 million active users... Facebook was exposed to be vulnerable of a XSS vulnerability instead of proper implementation of HTTPOnly cookie protection as that doesn't count for XSS. The PoC video is being linked below along with article.&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;Article:&lt;/span&gt;&amp;nbsp;&lt;/i&gt;&lt;/b&gt;h&lt;a href="ttp://www.acunetix.com/blog/news/cross-site-scripting-xss-facebook/"&gt;ttp://www.acunetix.com/blog/news/cross-site-scripting-xss-facebook/&lt;/a&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;Video:&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;a href="http://www.youtube.com/watch?v=iTddmr_JRYM&amp;amp;hl&amp;amp;fmt=22"&gt;http://www.youtube.com/watch?v=iTddmr_JRYM&amp;amp;hl&amp;amp;fmt=22&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;Last Week with Twitter&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;the microblogging favorite of masses, and offering a newer promising UX... Twitter accidently resurfaced the XSS hole while site update procedure. Famous as 'onMouseOver' flaw simply injected the XSS code as tweet to execute the function on mouse hover event by victim&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;Article:&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;a href="http://blog.twitter.com/2010/09/all-about-onmouseover-incident.html"&gt; http://blog.twitter.com/2010/09/all-about-onmouseover-incident.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;Previous Day with Orkut&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;previous day was a 'Good Saturday' (i.e. what 'Bom Sabado' means in Portugese) 'scrapping' off the privacy of Orkut Users. This attack is supposed to originate from Brazil and compromised enormous Orkut accounts in a span of few hours. The code with details can be viewed at the link below.&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;Article:&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&amp;nbsp;&lt;a href="http://antrix.net/posts/2007/orkut-xss/"&gt;http://antrix.net/posts/2007/orkut-xss/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-7117791070650954775?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/7117791070650954775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/09/xssed-orkut-after-twitter-after.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/7117791070650954775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/7117791070650954775'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/09/xssed-orkut-after-twitter-after.html' title='XSSed Orkut after Twitter after Facebook &amp;lt;xss/&amp;gt;'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-3045074819068618638</id><published>2010-09-06T06:45:00.000-07:00</published><updated>2010-09-06T06:45:42.878-07:00</updated><title type='text'>Problem with IEEE 802.1x implementation's fallback option</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Xxl3TD2AA1M/TITwRHxVCAI/AAAAAAAAAmo/sNdPx_3vc_Y/s1600/IEEE802.1x_MAB.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="46" src="http://4.bp.blogspot.com/_Xxl3TD2AA1M/TITwRHxVCAI/AAAAAAAAAmo/sNdPx_3vc_Y/s320/IEEE802.1x_MAB.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: large;"&gt;Problem with IEEE 802.1x implementation's fallback option&lt;/span&gt;&lt;br /&gt;---------------------------------------------------------&lt;br /&gt;I was just looking over some gyan for 802.1x implementation on Cisco's Portal.&lt;br /&gt;They have a very nice guide over Phase Deployment Model for Identity Based Network Services.&lt;br /&gt;While learning a bit, I saw mention of fallback option for IEEE 802.1x. Then I checked whether Juniper has it or not and it supports it too.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;MAB i.e. MAC Authnetication Bypass&lt;/b&gt; porviding support for Legacy Devices (say Printers) which are not capable of IEEE 802.1x and hence require some other method of authentication.&lt;br /&gt;And the method provided to them is adding the incapable device's MAC Address to a static (or even dynamic based on implementation) MAC list on 802.1x provider.&lt;br /&gt;&lt;br /&gt;There goes the cocroach surviving Nuclear Attack. The super-strong 802.1x bypassed by a MAC ...are they really having faith on this, or have it implemented in super-man style. Though currently I can't think of any super-man for MAC Authentication. All I see is Sipper-Man :( sipping my security away.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attacker just have to DUPLICATE allowed MAC, and enjoy the falling security.&lt;/b&gt;&lt;i&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;Seriously, I'm afraid... if anyone know the manner of its implementation hidden to me till now, which makes it secure. Please, let me know asap. &lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;If you want their support to make your environment vulnerable:&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;Cisco Support: &lt;a href="http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/standalone_mab.html"&gt;http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/standalone_mab.html&lt;/a&gt;&lt;br /&gt;Juniper Support: &lt;a href="http://kb.juniper.net/KB11429"&gt;http://kb.juniper.net/KB11429&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-3045074819068618638?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/3045074819068618638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/09/problem-with-ieee-8021x-implementations.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3045074819068618638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3045074819068618638'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/09/problem-with-ieee-8021x-implementations.html' title='Problem with IEEE 802.1x implementation&apos;s fallback option'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Xxl3TD2AA1M/TITwRHxVCAI/AAAAAAAAAmo/sNdPx_3vc_Y/s72-c/IEEE802.1x_MAB.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-2376106299198044259</id><published>2010-09-06T02:54:00.000-07:00</published><updated>2010-09-06T03:08:00.691-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='aBionic'/><category scheme='http://www.blogger.com/atom/ns#' term='concept'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='bug'/><category scheme='http://www.blogger.com/atom/ns#' term='whitepaper'/><category scheme='http://www.blogger.com/atom/ns#' term='SiteHoster'/><category scheme='http://www.blogger.com/atom/ns#' term='Site'/><category scheme='http://www.blogger.com/atom/ns#' term='AbhishekKr'/><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='subvert'/><category scheme='http://www.blogger.com/atom/ns#' term='flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='solution'/><category scheme='http://www.blogger.com/atom/ns#' term='ABK'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='PoC'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='script'/><title type='text'>XSS Defeating PoC : if have any time for Experimentation</title><content type='html'>&lt;span class="Apple-style-span" style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;&lt;span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;i&gt;&lt;b&gt;It's still in experimental state, if you find some time please try it and let me know of your experience.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;&lt;i&gt;&lt;span style="border-collapse: separate; font-family: arial; font-size: small; font-style: normal; font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Video Demo of the same PoC:&amp;nbsp;&lt;a href="http://www.youtube.com/watch?v=ENiiAccY1v0" style="color: #ed1c24;" target="_blank"&gt;http://www.youtube.com/watch?v=ENiiAccY1v0&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;Project Base:&amp;nbsp;&lt;a href="http://sourceforge.net/downloads/sitehoster/v1.0beta%20RC1/" style="color: #ed1c24;" target="_blank"&gt;http://sourceforge.net/downloads/sitehoster/v1.0beta%20RC1/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;WhitePaper is also available at SourceForge link above&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;&amp;nbsp;and at :&amp;nbsp;&lt;a href="http://www.slideshare.net/AbhishekKr/whitepaper-abktrick-to-subvert-xss" style="color: #ed1c24;" target="_blank"&gt;http://www.slideshare.net/AbhishekKr/whitepaper-abktrick-to-subvert-xss&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;I was working on a XSS-Patch PoC, which I now feel works proper enough to prove its point.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;&lt;b&gt;This neither require Web-Developers for any Filtering/Validation, nor any javascript blocking add-on on user's browser.&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;I'm not good at explaining still I've tried to do that in the above linked WhitePaper.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;And the ZIP file can be extracted, having 'StartDemo.bat' to be executed to start the server already patched with XSS Subverting Module.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: separate; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px;"&gt;&lt;span style="font-family: arial; font-size: small;"&gt;Then browse, '&lt;a href="http://localhost/tweet.htm" style="color: #ed1c24;" target="_blank"&gt;http://localhost/tweet.htm&lt;/a&gt;' in any browser... and it lets you Submit any text to Server w/o validation which is as it is saved there. But when retrieved on 'Read...' remains inactive for any &lt;script&gt; inserted.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;It would be great if any expert advice/comment could be given... Usable, Waste, Failure, etc.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;blockquote style="margin: 0px 0px 0px 40px; border-style: none; padding: 0px;"&gt;&lt;div&gt;&lt;b&gt;NOTE:&lt;/b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;for PoC to execute properly it requires 'PYTHON' to be installed and added to SYSTEM PATH&lt;/div&gt;&lt;div&gt;as server-side logic is coded in Python&lt;/div&gt;&lt;div&gt;If you don't have Python installed, then too you can check it by, opening '&lt;a href="http://localhost/test1.htm" target="_blank" style="color: rgb(237, 28, 36);"&gt;http://localhost/test1.htm&lt;/a&gt;' which would make the &lt;SCRIPT/&gt; injected in it's &lt;BODY/&gt; inactive. Or, you can yourself write any quick HTML+JS, where none of the JS injected in BODY would work when browsed over this Server.The Server Side Scripting implementation currently is not standard CGI, its a quick approach to achieve script execution at server based on GET Request Variables and get MarkUp Output.&lt;br clear="all"&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;/span&gt;&lt;br clear="all"&gt;&lt;/div&gt;&lt;span style="font-family: arial,sans-serif; font-size: 13px; border-collapse: collapse;"&gt;&lt;b&gt;&lt;i&gt;Note: its there to subvert user-level JS functions&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;div&gt;&lt;font&gt;&lt;span style="border-collapse: collapse;"&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font&gt;&lt;span style="border-collapse: collapse;"&gt;&lt;b&gt;&lt;i&gt;Once this completes, I'll be implementing my SQL-Injection Counter-measure to the server.&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/script&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-2376106299198044259?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/2376106299198044259/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/09/xss-defeating-poc-if-have-any-time-for.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/2376106299198044259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/2376106299198044259'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/09/xss-defeating-poc-if-have-any-time-for.html' title='XSS Defeating PoC : if have any time for Experimentation'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-455444678332477050</id><published>2010-08-26T17:20:00.000-07:00</published><updated>2010-08-27T11:53:35.088-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web'/><category scheme='http://www.blogger.com/atom/ns#' term='PHP'/><category scheme='http://www.blogger.com/atom/ns#' term='flaw'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='DoS'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='ABK'/><title type='text'>hrberry.com :: php flaw self-inviting DoS, leaked framework and server info [by, ABK]</title><content type='html'>&lt;a href="https://sites.google.com/site/abklabs/home/secured/posts.xml"&gt;Posted@ https://sites.google.com/site/abklabs/home/secured/posts.xml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;[]Patched: &lt;/b&gt;&lt;br /&gt;Yes &lt;br /&gt;&lt;br /&gt;&lt;b&gt;[]Product Name:&lt;/b&gt;&lt;br /&gt;http://www.hrberry.com&lt;br /&gt;Payroll Helpdesk, serving several prestigious companies &lt;br /&gt;&lt;br /&gt;&lt;b&gt;[]Victim Name:&lt;/b&gt;&lt;br /&gt;Ascent Consulting Services Pvt. Ltd. &lt;br /&gt;[http://ascent-online.com]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;[]Vuln Summary:&lt;/b&gt;&lt;br /&gt;There were validation flaws for GET Request Parameters sent to CAPTCHA image generating PHP script on the Portal.&lt;br /&gt;This allowed attacker to trick the app to generate any number of characters consuming processing power.&lt;br /&gt;It had a timout after 30 seconds (too much) and generated error message with full PATH of PHP file.&lt;br /&gt;Also worked on older un-patched version of OpenSSL.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://sites.google.com/site/abklabs/home/secured/hrberrycom"&gt;to read detailed Description... click here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-455444678332477050?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/455444678332477050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/08/hrberrycom-php-flaw-self-inviting-dos.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/455444678332477050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/455444678332477050'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/08/hrberrycom-php-flaw-self-inviting-dos.html' title='hrberry.com :: php flaw self-inviting DoS, leaked framework and server info [by, ABK]'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-7104208418485954477</id><published>2010-06-19T13:31:00.000-07:00</published><updated>2010-08-03T04:16:44.498-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerablity'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='scanner'/><category scheme='http://www.blogger.com/atom/ns#' term='neXpose'/><category scheme='http://www.blogger.com/atom/ns#' term='Rapid7'/><category scheme='http://www.blogger.com/atom/ns#' term='audit'/><title type='text'>Rapid7's neXpose</title><content type='html'>&lt;span class="Apple-style-span" style="font-size: x-large;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;span class="Apple-style-span" style="color: yellow;"&gt;Rapid7's neXpose&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.rapid7.com/vulnerability-scanner.jsp"&gt;http://www.rapid7.com/vulnerability-scanner.jsp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can download the Community Edition of this famous and highly efficient Network Vulnerability Scanner by Rapid7.&lt;br /&gt;&lt;br /&gt;[] NeXpose Community Edition provides users with:&lt;br /&gt;&amp;nbsp;&amp;gt; vulnerability scanning for up to 32 IPs at a time&lt;br /&gt;&amp;nbsp;&amp;nbsp; {limited, but for free it's nice}&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Regular vulnerability updates&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;{everytime I start it, updates get checked}&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Accurate scan results&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;{it gives real detailed analysis of flaws found}&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Prioritized risk assessment&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;{though its priorities don't match mine most of times}&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Remediation guidance&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;{yeah it's good, with required tweaks}&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Out-of-the box Metasploit integration&lt;br /&gt;&amp;nbsp;&amp;nbsp; {from the Metasploit v3.31 it can be fully integrated with NeXpose}&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;Link:&lt;a href="http://www.metasploit.com/redmine/projects/framework/wiki/NeXpose_Plugin"&gt;&amp;nbsp;http://www.metasploit.com/redmine/projects/framework/wiki/NeXpose_Plugin&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Extensive community support at http://community.rapid7.com&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;{it's so easy, you wouldn't require it}&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Simple deployment&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;{if you can browse through a new website, you can use it}&lt;br /&gt;&amp;nbsp;&amp;gt;&amp;nbsp;No cost start-up security solution&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;{Community edition afterall}&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-7104208418485954477?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/7104208418485954477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/06/rapid7s-nexpose.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/7104208418485954477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/7104208418485954477'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/06/rapid7s-nexpose.html' title='Rapid7&apos;s neXpose'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-6141722963757802822</id><published>2010-02-18T22:11:00.000-08:00</published><updated>2010-08-03T04:19:53.616-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kneber'/><category scheme='http://www.blogger.com/atom/ns#' term='NetWitness'/><category scheme='http://www.blogger.com/atom/ns#' term='Zeus'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><title type='text'>on 18-Feb-2010 :: NetWitness reported 'Kneber Botnet' {CRITICAL}</title><content type='html'>&lt;span style="color: #ffd966; font-size: large;"&gt;On &lt;b&gt;18-Feb-2010&lt;/b&gt;; &lt;b&gt;NetWitness&lt;/b&gt; has reported of new &lt;b&gt;malware 'Kneber botnet'&lt;/b&gt;; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;its a&lt;b&gt; variant of Zeus &lt;/b&gt;and mainly target &lt;b&gt;stealing Credentials, Key-logging, etc.&lt;/b&gt;&lt;br /&gt;&lt;i style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;... has affected more than 2500 organizations;&lt;br /&gt;&lt;br /&gt;... currently no IPS/IDS have adequate signatures detecting it.&lt;br /&gt;&lt;br /&gt;... it can also act with other malwares, fav noticed is Waledac (a P2P Trojan)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;[] A try to check if Machine is infected by a Kneber (Zeus Variant)&lt;/b&gt;, is&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The registry key can be found by following this path, he said:&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normally will have an entry like "C:\WINDOWS\system32\userinit.exe,"&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ZeuS will add itself to the list, typically as 'ntos.'&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; But could always change its name; so if any un-relevant entries found here... may be machine is infected.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If any more entries found, or suspicion is there scan the file listed here.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;[] Its suggested to patch all latest MS10-* and Adobe releases on all the machines;&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; and as always not open suspicious e-mails&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;b&gt;[]NetWitness said that Kneber was primarily found on corporate and government computers&lt;/b&gt;, however home users are likely to attract the infestation as well.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[] more details @&lt;br /&gt;&lt;br /&gt;*** &lt;a href="http://www.netwitness.com/resources/pressreleases/feb182010.aspx"&gt;http://www.netwitness.com/resources/pressreleases/feb182010.aspx&lt;/a&gt; ***&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.networkworld.com/news/2010/021810-kneber-botnet-faq.html?hpg1=bn"&gt;http://www.networkworld.com/news/2010/021810-kneber-botnet-faq.html?hpg1=bn&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.nytimes.com/2010/02/19/technology/19cyber.html?em"&gt;http://www.nytimes.com/2010/02/19/technology/19cyber.html?em&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.technewsworld.com/rsstory/69372.html"&gt;http://www.technewsworld.com/rsstory/69372.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-6141722963757802822?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/6141722963757802822/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/02/on-18-feb-2010-netwitness-reported.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6141722963757802822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6141722963757802822'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/02/on-18-feb-2010-netwitness-reported.html' title='on 18-Feb-2010 :: NetWitness reported &apos;Kneber Botnet&apos; {CRITICAL}'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-1370780877141906757</id><published>2010-01-16T05:21:00.000-08:00</published><updated>2010-01-16T05:24:27.097-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web'/><category scheme='http://www.blogger.com/atom/ns#' term='Network'/><category scheme='http://www.blogger.com/atom/ns#' term='Server'/><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP'/><category scheme='http://www.blogger.com/atom/ns#' term='ABK'/><category scheme='http://www.blogger.com/atom/ns#' term='WebServer'/><category scheme='http://www.blogger.com/atom/ns#' term='SiteHoster'/><category scheme='http://www.blogger.com/atom/ns#' term='Site'/><title type='text'>ABK SiteHoster -=[developing a HTTP Network Server to be secure at implementation]=-</title><content type='html'>&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; white-space: pre;"&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;b&gt;&lt;span style="color: #ffe599;"&gt;ABK SiteHoster&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-family: Arial; font-size: 13px; white-space: pre;"&gt;&lt;span style="color: #ffe599;"&gt;&amp;nbsp;   &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #ffe599; font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; white-space: pre;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;span style="color: #f9cb9c;"&gt;Sourceforge&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt; Link : &lt;a dir="ltr" href="http://sourceforge.net/projects/sitehoster/" rel="nofollow" target="_blank" title="http://sourceforge.net/projects/sitehoster/"&gt;http://sourceforge.net/projects/sitehoster/&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-family: Arial; font-size: 13px; white-space: pre;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;span style="color: #f9cb9c;"&gt;Google Code&lt;/span&gt;&lt;/span&gt; Link : &lt;a dir="ltr" href="http://code.google.com/p/sitehoster/" rel="nofollow" target="_blank" title="http://code.google.com/p/sitehoster/"&gt;http://code.google.com/p/sitehoster/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; white-space: pre;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;span style="color: #f9cb9c;"&gt;Youtube&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt; &lt;b&gt;Demo&lt;/b&gt; Link: &lt;a href="http://www.youtube.com/watch?v=CogPa646vi8"&gt;http://www.youtube.com/watch?v=CogPa646vi8&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;Currently in it's BETA stage and can only serve URL as per HTTP v0.9, so not secure but basic WebServer&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-family: Arial; font-size: 13px; white-space: pre;"&gt;Actually developing it as a HTTP Network Server to be secure at its implementation, normally all WebServer present out there are vulnerable cuz they didn't implemented Security at their very core but as an extra sheild outside.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;Here in this project I'll be aiming at making it secure from the core itself and making it self-secured by immunizing it from all kinds of Web-App attacks.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-family: arial, helvetica, clean, sans-serif; line-height: 18px; white-space: normal;"&gt;&lt;span style="color: #d5a6bd;"&gt;ABK SiteHoster is aLEHNS (a Lightweight Extensible HTTP Network Server). Developed in pure Java. Currently supports HTTP 0.9, easily delivering normal HTML oriented WebSites. Aiming to be a full-fledged WebSite Server with all Web Services.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/CogPa646vi8&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/CogPa646vi8&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-1370780877141906757?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/1370780877141906757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2010/01/abk-sitehoster-developing-http-network.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1370780877141906757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1370780877141906757'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2010/01/abk-sitehoster-developing-http-network.html' title='ABK SiteHoster -=[developing a HTTP Network Server to be secure at implementation]=-'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-2034462545883291148</id><published>2009-12-12T08:01:00.000-08:00</published><updated>2010-08-03T04:22:05.778-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Administration'/><category scheme='http://www.blogger.com/atom/ns#' term='Remote'/><category scheme='http://www.blogger.com/atom/ns#' term='POSIX'/><category scheme='http://www.blogger.com/atom/ns#' term='n00bRAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan'/><title type='text'>n00bRAT -[Linux Remote Admin Tool]- (Use as Trojan to test your Firewall/IDS)</title><content type='html'>&lt;span style="font-size: large;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;b&gt;n00bRAT &lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt;-[Linux Remote Admin Tool]-&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;I am working on an open-source undetectable TuX.RAT project, currently in its Beta stage, released at Sourceforge at following link.&lt;br /&gt;Give feedback of how to grow this project... what our geek community wants.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;URL :: &lt;a href="http://sourceforge.net/projects/n00brat/"&gt;http://sourceforge.net/projects/n00brat/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;::Description::&lt;br /&gt;An undetectable Remote Administration Tool -OR- trojan, an all new approach. Easily usable, Client just requires any Web Browser to control remote machine via WebPage. Fooling firewalls/ids/ips security solutions, as it operates like any web-site.&lt;br /&gt;&lt;br /&gt;::Usage::&lt;br /&gt;* Remote Administration Tool for Linux/Unix (POSIX Based Machines)&lt;br /&gt;* Can use it like a Trojan to test your Firewall / IDS / IPS&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A Demo Video of Why This? What Code Is? How it Works?&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Jnx7nD0qU7M"&gt;http://www.youtube.com/watch?v=Jnx7nD0qU7M&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Jnx7nD0qU7M&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Jnx7nD0qU7M&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-2034462545883291148?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/2034462545883291148/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2009/12/i-am-working-on-open-source.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/2034462545883291148'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/2034462545883291148'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2009/12/i-am-working-on-open-source.html' title='n00bRAT -[Linux Remote Admin Tool]- (Use as Trojan to test your Firewall/IDS)'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-1283591982088274119</id><published>2009-10-10T02:16:00.000-07:00</published><updated>2009-10-10T02:50:40.637-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Ransomware'/><category scheme='http://www.blogger.com/atom/ns#' term='lingo'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><title type='text'>Scareware / Ransomware [Know Ur Lingo]</title><content type='html'>&lt;span style="color: rgb(255, 204, 0); font-weight: bold; font-style: italic;font-size:130%;" &gt;[Know Ur Lingo]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0);font-family:verdana;font-size:180%;"  &gt;&lt;span style="font-weight: bold;"&gt;Scareware&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;are the rogue security softwares i.e. malicious softwares pretending to be security solutions working against viruses and worms. It pranks user to feel its need to make the machine secure against some attack or virus infection and gets installed.&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0);font-family:verdana;font-size:180%;"  &gt;&lt;span style="font-weight: bold;"&gt;Ransomware&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;are the malwares which hold the infected machine/service/data as hostage, and demand ransom for disinfecting the hostage. ;)&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:georgia;font-size:180%;"  &gt;&lt;span style="color: rgb(255, 255, 0); font-weight: bold;"&gt;COUNTERMEASURES&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;if you think you have been infected by such malwares, or wanna minimize the risk of getting infected beforehand... you can use security solutions like&lt;br /&gt;&lt;a style="font-weight: bold; color: rgb(51, 204, 255); font-family: trebuchet ms;" href="http://www.microsoft.com/security/malwareremove/default.aspx"&gt;&lt;span&gt;&lt;span style="font-size:100%;"&gt;Microsoft Malicious Software Removal Tool&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(51, 204, 255);font-family:trebuchet ms;" &gt; &lt;/span&gt;&lt;span style="color: rgb(51, 204, 255);font-family:trebuchet ms;" &gt;: &lt;/span&gt;&lt;a style="font-family: trebuchet ms; color: rgb(51, 204, 255);" href="http://www.microsoft.com/security/malwareremove/default.aspx"&gt;http://www.microsoft.com/security/malwareremove/default.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Or you could get your file scanned by &lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Kaspersky Free Online Virus Scan &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.kaspersky.com/scanforvirus"&gt;http://www.kaspersky.com/scanforvirus&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-1283591982088274119?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/1283591982088274119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2009/10/scareware-know-ur-lingo.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1283591982088274119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/1283591982088274119'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2009/10/scareware-know-ur-lingo.html' title='Scareware / Ransomware [Know Ur Lingo]'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-411047842631857774</id><published>2009-09-06T20:44:00.000-07:00</published><updated>2010-08-03T04:23:08.259-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='NTFS'/><category scheme='http://www.blogger.com/atom/ns#' term='Data'/><category scheme='http://www.blogger.com/atom/ns#' term='Alternate'/><category scheme='http://www.blogger.com/atom/ns#' term='ADS'/><category scheme='http://www.blogger.com/atom/ns#' term='Stream'/><title type='text'>ADS [ Alternate Data Stream ] : NTFS - The Dark Side</title><content type='html'>&lt;span style="color: rgb(255, 255, 0);font-size:180%;" &gt;&lt;span style="font-weight: bold;"&gt;ADS &lt;span style="font-style: italic;"&gt;[ Alternate Data Stream ]&lt;/span&gt; : NTFS - The Dark Side&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The feature of NTFS from WinNT v3.1 onwards which is very dangerous as can be used to hide files on your system even undetected from several Antivirus, and other Security Products.&lt;br /&gt;&lt;br /&gt;This ADS can even be used to hide malicious files, so to counter such covert attacks one need to figure out the the unwanted files in ADS on their disk drives.&lt;br /&gt;&lt;br /&gt;To hide files in ADS (say adsF.ext into ADS of mainF.ext), at command prompt&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 204, 153);"&gt; cmd:\&gt; type adsF.ext &gt; mainF.ext:adsFile.ext&lt;/span&gt;&lt;br /&gt;Now to access it (say it opens in Notepad)&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 204, 153);"&gt; cmd:\&gt; notepad mainF.ext:adsFile.ext&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For this several professional tools can be used, like&lt;br /&gt;&lt;span style="color: rgb(255, 204, 204);"&gt;HijackThis (from Trend Micro) : &lt;/span&gt;&lt;a style="color: rgb(255, 204, 204);" href="http://free.antivirus.com/"&gt;http://free.antivirus.com/&lt;/a&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 204, 204);"&gt;Lads (from Heysoft) : &lt;/span&gt;&lt;a style="color: rgb(255, 204, 204);" href="http://www.heysoft.de/en/software/lads.php?lang=EN"&gt;http://www.heysoft.de/en/software/lads.php?lang=EN&lt;br /&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 204, 204);"&gt;SFind (in Forensic Toolkit) : &lt;/span&gt;&lt;a style="color: rgb(255, 204, 204);" href="http://www.foundstone.com/us/resources/"&gt;http://www.foundstone.com/us/resources/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here we discuss how to use ADS to hide files... and how to secure yourself from files in ADS.&lt;br /&gt;&lt;br /&gt;To get a live demo Video on this stuff watch the video below:&lt;br /&gt;&lt;a href="http://blip.tv/file/2565748"&gt;http://blip.tv/file/2565748&lt;/a&gt;&lt;br /&gt;or&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=h96meoDYWSg"&gt;http://www.youtube.com/watch?v=h96meoDYWSg&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;embed src="http://blip.tv/play/AYGd6UsC" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="390"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-411047842631857774?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/411047842631857774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2009/09/ads-alternate-data-stream-ntfs-dark.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/411047842631857774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/411047842631857774'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2009/09/ads-alternate-data-stream-ntfs-dark.html' title='ADS [ Alternate Data Stream ] : NTFS - The Dark Side'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-8194017581154445362</id><published>2009-07-07T22:34:00.000-07:00</published><updated>2009-07-08T03:02:05.977-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerablity'/><category scheme='http://www.blogger.com/atom/ns#' term='0Day'/><category scheme='http://www.blogger.com/atom/ns#' term='IE'/><category scheme='http://www.blogger.com/atom/ns#' term='Remote'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber'/><category scheme='http://www.blogger.com/atom/ns#' term='Zero Day'/><category scheme='http://www.blogger.com/atom/ns#' term='Video'/><category scheme='http://www.blogger.com/atom/ns#' term='0 day'/><category scheme='http://www.blogger.com/atom/ns#' term='Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='CyberCriminal'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='ActiveX'/><title type='text'>Vulnerable Microsoft's Video ActiveX Control Allows Remote Access [ 0-day attacks]</title><content type='html'>&lt;span style="color: rgb(255, 204, 0); font-weight: bold;font-size:180%;" &gt;Vulnerable Microsoft's Video ActiveX Control Allows Remote Access &lt;/span&gt;&lt;span style="color: rgb(255, 204, 0); font-style: italic;font-size:180%;" &gt;[ 0-day attacks]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;As made public on June 6'2009, Microsoft's Video ActiveX has Remote Code Exploit threat, where using a malformed web-page Remote code execution could be enabled on the target machine. Cybercriminals are using the vulnerability to install a data stealing trojan on target machine affecting Microsoft Directshow.&lt;br /&gt;&lt;br /&gt;If the &lt;span style="font-weight: bold;"&gt;target user is using IE&lt;/span&gt;, then &lt;span style="font-weight: bold;"&gt;attacker could get local user rights using exploits by without any user-intervention&lt;/span&gt;. So, the &lt;span style="font-weight: bold;"&gt;CyberCriminal just need to pursue victim to view it's malformed web-page&lt;/span&gt; and the victim's machine gets compromised.&lt;br /&gt;&lt;br /&gt;Microsoft states it is aware of the vulnerability and suggests Kill-bit MPEG2TuneRequest ActiveX Control Object (CLSID 0955AC62-BF2E-4CBA-A2B9-A63F772D46CF) as the workaround to avoid the threat.&lt;br /&gt;The defense it would provide is more than the minor side-effects it would cause.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(51, 204, 255);font-family:verdana;font-size:130%;"  &gt;To Avoid Threat&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;This kill-bit to avoid the threat can be automatically applied to your windows machine by "Microsoft Fix It" from online utility provided by Microsoft.com @ &lt;/span&gt;&lt;a style="font-weight: bold;" href="http://support.microsoft.com/kb/972890"&gt;http://support.microsoft.com/kb/972890&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://go.microsoft.com/?linkid=9672398"&gt;Microsoft's Link : Enable The Fix || Workaround&lt;/a&gt;&lt;br /&gt;&lt;a href="http://go.microsoft.com/?linkid=9672398"&gt;Microsoft's &lt;/a&gt;&lt;a href="http://go.microsoft.com/?linkid=9672397"&gt;Link : Disable The Fix || Workaround&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(51, 204, 255);font-family:verdana;font-size:130%;"  &gt;Data 'bout Threat&lt;/span&gt;&lt;br /&gt;Can be exploited via any kind of HTML document, a website or e-mail, etc. . This vulnerability is not a risk if you are using Windows Vista.&lt;br /&gt;&lt;br /&gt;. 967 Chinese websites replorted to successive redirecting to finally download a JPG file containing the exploit, detected by &lt;a href="http://apac.trendmicro.com/apac/threats/microsoft-mpeg-vulnerability/index.html?WT.mc_id=0907_MSFTMPEG_APAC_HOME_bar"&gt;Trend Micro&lt;/a&gt; as JS_DLOADER.BD., that downloads another malware detected as WORM_KILLAV.AI. This malware disables and terminates AV processes, and drops other malware on the affected system.&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt;&lt;br /&gt;Detailed Info from &lt;span style="font-weight: bold;"&gt;Microsoft&lt;/span&gt;&lt;/a&gt;&lt;a style="font-weight: bold;" href="http://www.microsoft.com/technet/security/advisory/972890.mspx"&gt; Security Advisory&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-8194017581154445362?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/8194017581154445362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2009/07/vulnerable-microsofts-video-activex.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/8194017581154445362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/8194017581154445362'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2009/07/vulnerable-microsofts-video-activex.html' title='Vulnerable Microsoft&apos;s Video ActiveX Control Allows Remote Access [ 0-day attacks]'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-3172733437208418355</id><published>2009-07-03T20:53:00.000-07:00</published><updated>2009-07-08T03:07:52.045-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Addon'/><category scheme='http://www.blogger.com/atom/ns#' term='Hack'/><category scheme='http://www.blogger.com/atom/ns#' term='Javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Mozilla'/><category scheme='http://www.blogger.com/atom/ns#' term='Bank'/><category scheme='http://www.blogger.com/atom/ns#' term='Threat'/><category scheme='http://www.blogger.com/atom/ns#' term='GreaseMonkey'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Account'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>First Firefox Malware : Trojans Stealing Passwords Typed in Firefox using Firefox Add-on Disguise</title><content type='html'>&lt;span style="color: rgb(255, 255, 0);font-size:180%;" &gt;First Firefox Malware : Trojans  using Firefox Add-on Disguise&lt;/span&gt;&lt;br /&gt;Roll your mouse over topics to expand them... :)&lt;br /&gt;&lt;span style="border: medium groove ;" onmouseover="document.getElementById('post3Info').style.display='block';"&gt;Information On Malware&lt;/span&gt;&lt;br /&gt;&lt;div id="post3Info" style="display: none;"&gt;&lt;div onclick="document.getElementById('post3Info').style.display='none';"&gt;Click Here [ Hide Me / Collapse ]&lt;/div&gt;&lt;br /&gt;( Trojan-Spy:W32/Banker.IVX, Win32/Inject.NBT trojan, Troj/Bancos-BEX, TR/Drop.Small.abw )        &lt;div style="border: 1px solid rgb(236, 236, 236); margin: 5px; padding: 5px; font-size: 12px;"&gt;       &lt;table width="400"&gt;    &lt;tbody&gt;&lt;tr&gt;        &lt;td&gt;     &lt;b&gt;Spreading:&lt;/b&gt;            &lt;/td&gt;        &lt;td&gt;     very low            &lt;/td&gt;        &lt;td rowspan="4" width="200"&gt;             &lt;br /&gt;&lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;        &lt;td&gt;     &lt;b&gt;Damage:&lt;/b&gt;            &lt;/td&gt;        &lt;td&gt;     very high            &lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;        &lt;td&gt;     &lt;b&gt;Size:&lt;/b&gt;            &lt;/td&gt;        &lt;td&gt;     22kB            &lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;        &lt;td&gt;     &lt;b&gt;Discovered:&lt;/b&gt;            &lt;/td&gt;        &lt;td&gt;     2008 Nov 28            &lt;/td&gt;    &lt;/tr&gt;       &lt;/tbody&gt;&lt;/table&gt;    &lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="border: medium groove ;" onmouseover="document.getElementById('post3Symptom').style.display='block';"&gt;Symptoms of Infection&lt;/span&gt;&lt;br /&gt;&lt;div id="post3Symptom" style="display: none;"&gt;&lt;div onclick="document.getElementById('post3Symptom').style.display='none';"&gt;Click Here [ Hide Me / Collapse ]&lt;/div&gt;&lt;br /&gt;Presence of the:&lt;br /&gt;"%ProgramFiles%\Mozilla Firefox\plugins\npbasic.dll"&lt;br /&gt;"%ProgramFiles%\Mozilla Firefox\chrome\chrome\content\browser.js"&lt;br /&gt;files in the Mozilla Firefox's plugins and chrome folders.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="border: medium groove ;" onmouseover="document.getElementById('post3Victim').style.display='block';"&gt;List of Accounts mainly under attack&lt;/span&gt;&lt;br /&gt;&lt;div id="post3Victim" style="display: none;"&gt;&lt;div onclick="document.getElementById('post3Victim').style.display='none';"&gt;Click Here [ Hide Me / Collapse ]&lt;/div&gt;&lt;br /&gt;It filters the URLs within the Mozilla Firefox browser and whenever encounter the following addresses opened in the Firefox browser it captures the login credentials.&lt;br /&gt;&lt;br /&gt;akbank.com&lt;br /&gt;caixasabadell.net&lt;br /&gt;credem.it&lt;br /&gt;areasegura.banif.es&lt;br /&gt;banca.cajaen.es&lt;br /&gt;openbank.es&lt;br /&gt;poste.it&lt;br /&gt;banesto.es&lt;br /&gt;carnet.cajarioja.es&lt;br /&gt;gruposantander.es&lt;br /&gt;intelvia.cajamurcia.es&lt;br /&gt;net.kutxa.net&lt;br /&gt;bancopastor.es&lt;br /&gt;bancamarch.es&lt;br /&gt;caixamanlleu.es&lt;br /&gt;elmonte.es&lt;br /&gt;ibercajadirecto.com&lt;br /&gt;bancopopular.es&lt;br /&gt;bancogallego.es&lt;br /&gt;bancajaproximaempresas.com&lt;br /&gt;caixa*.es&lt;br /&gt;caja*.es&lt;br /&gt;ccm.es&lt;br /&gt;bancoherrero.com&lt;br /&gt;bankoa.es&lt;br /&gt;bbvanetoffice.com&lt;br /&gt;bgnetplus.com&lt;br /&gt;bv-i.bancodevalencia.es&lt;br /&gt;clavenet.net&lt;br /&gt;fibancmediolanum.es&lt;br /&gt;sabadellatlantico.com&lt;br /&gt;arquia.es&lt;br /&gt;banking.*.de&lt;br /&gt;westpac.com.au&lt;br /&gt;adelaidebank.com.au&lt;br /&gt;pncs.com.au&lt;br /&gt;nationet.com&lt;br /&gt;online.hbs.net.au&lt;br /&gt;www.qccu.com.au&lt;br /&gt;boq.com.au&lt;br /&gt;banksa.com&lt;br /&gt;anz.com&lt;br /&gt;suncorpmetway.com.au&lt;br /&gt;quiubi.it&lt;br /&gt;cariparma.it&lt;br /&gt;bancaintesa.it&lt;br /&gt;popso.it&lt;br /&gt;fmbcc.bcc.it&lt;br /&gt;secservizi.it&lt;br /&gt;bancamediolanum.it&lt;br /&gt;csebanking.it&lt;br /&gt;fineco.it&lt;br /&gt;gbw2.it&lt;br /&gt;gruppocarige.it&lt;br /&gt;in-biz.it&lt;br /&gt;isideonline.it&lt;br /&gt;iwbank.it&lt;br /&gt;bancaeuro.it&lt;br /&gt;bancagenerali.it&lt;br /&gt;bcp.it&lt;br /&gt;unibanking.it&lt;br /&gt;uno-e.com&lt;br /&gt;unipolbanca.it&lt;br /&gt;carifvg.com&lt;br /&gt;cariparo.it&lt;br /&gt;carisbo.it&lt;br /&gt;islamic-bank.com&lt;br /&gt;banking.first-direct.com&lt;br /&gt;natwestibanking.com&lt;br /&gt;itibank.co.uk&lt;br /&gt;co-operativebank.co.uk&lt;br /&gt;lloydstsb.co.uk&lt;br /&gt;mybankoffshore.alil.co.im&lt;br /&gt;abbeynational.co.uk&lt;br /&gt;mybusinessbank.co.uk&lt;br /&gt;barclays.com&lt;br /&gt;online.co.uk&lt;br /&gt;my.if.com&lt;br /&gt;anbusiness.com&lt;br /&gt;hsbc.co&lt;br /&gt;anbusiness.com&lt;br /&gt;co-operativebankonline.co.uk&lt;br /&gt;halifax-online.co.uk&lt;br /&gt;ibank.cahoot.com&lt;br /&gt;smile.co.uk&lt;br /&gt;caterallenonline.co.uk&lt;br /&gt;tdcanadatrust.com&lt;br /&gt;schwab.com&lt;br /&gt;wachovia.com&lt;br /&gt;bankofamerica&lt;br /&gt;kfhonline.com&lt;br /&gt;wamu.com&lt;br /&gt;wellsfargo.com&lt;br /&gt;procreditbank.bg&lt;br /&gt;chase.com&lt;br /&gt;53.com&lt;br /&gt;citizensbankonline.com&lt;br /&gt;e-gold.com&lt;br /&gt;paypal.com&lt;br /&gt;usbank.com&lt;br /&gt;suntrust.com&lt;br /&gt;banquepopulaire.fr&lt;br /&gt;onlinebanking.nationalcity.com&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="border: medium groove ;" onmouseover="document.getElementById('post3Cure').style.display='block';"&gt;What To Do If Infected&lt;/span&gt;&lt;br /&gt;&lt;div id="post3Cure" style="display: none;"&gt;&lt;div onclick="document.getElementById('post3Cure').style.display='none';"&gt;Click Here [ Hide Me / Collapse ]&lt;/div&gt;&lt;br /&gt;Step1of2.&lt;br /&gt;Close Your Firefox&lt;br /&gt;&lt;br /&gt;Step2of2.&lt;br /&gt;Install latest BitDefender (as they found it) and let it search and destroy the malware.&lt;br /&gt;&lt;/div&gt;__________________________________________________&lt;br /&gt;Bitdefender released information on this threat naming it as&lt;strong&gt; Trojan.PWS.ChromeInject.A, &lt;span style="font-family:lucida grande;"&gt;&lt;/span&gt;&lt;/strong&gt;which spawns with the execution of Firefox and poses as a Plug-in to it, mainly works on Key Banking... can get access to all your passwords entered in the Password boxes opened in Firefox Browser.&lt;br /&gt;&lt;br /&gt;The &lt;strong&gt;ChromeInject&lt;/strong&gt; suffix refers to the Chrome component Firefox has. This malware infects your machine via drive-by download or download duping.&lt;br /&gt;Once installed on the machine it &lt;span style="font-weight: bold;"&gt;registers itself as a fake 'GreaseMonkey'&lt;/span&gt; (a great firefox add-on for website customization using javascripts), and using javascript checks your machine for mainly banking passwords of more than 100 sites (like PayPal, etc.).&lt;br /&gt;All this sensitive data collected by it is then transferred online to a &lt;span style="font-weight: bold;"&gt;server supposed to be located in Russia&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;So, don't stop using Greasemonkey... but make sure you download it from &lt;a href="http://www.mozilla.com/"&gt;Mozilla.com&lt;/a&gt;, so that you don't fall pray to malware.&lt;br /&gt;__________________________________________________&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-3172733437208418355?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/3172733437208418355/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2009/07/first-firefox-malware-trojans-stealing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3172733437208418355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/3172733437208418355'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2009/07/first-firefox-malware-trojans-stealing.html' title='First Firefox Malware : Trojans Stealing Passwords Typed in Firefox using Firefox Add-on Disguise'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-6098152482917642577</id><published>2009-06-13T18:18:00.000-07:00</published><updated>2009-07-08T03:19:07.234-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hack'/><category scheme='http://www.blogger.com/atom/ns#' term='Threat'/><category scheme='http://www.blogger.com/atom/ns#' term='Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='ATM'/><category scheme='http://www.blogger.com/atom/ns#' term='Europe'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan'/><title type='text'>ATMs under Trojan Attack in Eastern Europe</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 153, 0);font-family:verdana;font-size:180%;"  &gt;ATMs under Trojan Attack in Eastern Europe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;security experts revealed a family of data-stealing trojans is infecting automatic teller machines in Eastern Europe over the past 18 months&lt;br /&gt;&lt;br /&gt;It monitors transaction message queue for track 2 data stored on inserted cards. If it contains data belonging to a banking customer, it logs it, along with the PIN code that was entered.&lt;br /&gt;&lt;br /&gt;The software works with Controller Cards... in its Primary Menu the main features it provide are&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;1. Print Collected Data&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. Restore logged files before malware infected the machine&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3. Uninstallling the malware&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;there is a secomdary menu with main features as&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;1. Dispensing all Cash in ATM&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. Upload data to a chip on cotroller card&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-6098152482917642577?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/6098152482917642577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2009/06/atms-under-trojan-attack-in-eastern.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6098152482917642577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/6098152482917642577'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2009/06/atms-under-trojan-attack-in-eastern.html' title='ATMs under Trojan Attack in Eastern Europe'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2442688623759178220.post-4119384445863317922</id><published>2009-06-11T19:30:00.000-07:00</published><updated>2009-07-08T03:20:44.761-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hack'/><category scheme='http://www.blogger.com/atom/ns#' term='Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='2008'/><title type='text'>Conficker : one of most dreaded worm of 2008</title><content type='html'>&lt;span style="color: rgb(255, 255, 51);font-size:180%;" &gt;&lt;span style="font-weight: bold;"&gt;Conficker&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;(also known as Downup, Downadup and Kido)&lt;br /&gt;targets Microsoft Windows operating system, first detected in November 2008.&lt;br /&gt;Believed to be the largest computer worm infection since the 2003 SQL Slammer.&lt;br /&gt;&lt;br /&gt;If got infected try it:&lt;br /&gt;&lt;a href="http://onecare.live.com/site/en-us/default.htm?s_cid=sah"&gt;Microssoft's Live Online Scan&lt;/a&gt;&lt;br /&gt;or&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;amp;displaylang=en"&gt;download and run this utility on your infected machine&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Its Nature:&lt;br /&gt; * Extracts all of its files to the %System% directory with random DLL file names, which can wreak havoc on your computer.&lt;br /&gt; * Deletes the user's Restore Points.&lt;br /&gt; * Registers a services called Netsvcs&lt;br /&gt; * Creates scheduled tasks that execute all of the DLL files.&lt;br /&gt; * Creates it's own simple HTTP server on the infected computer and spreads the worm to other computers in the network through file shares.&lt;br /&gt; * Creates an Autorun.inf file in file shares to execute the warm files once the share is accessed by another computer.&lt;br /&gt; * Connects to external sites to download additional files.&lt;br /&gt;&lt;br /&gt;This exploits vulnerability called MS08-067 in Windows 2000, XP, and Server 2003.&lt;br /&gt;Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability.&lt;br /&gt;&lt;br /&gt;Click Image To Enlarge It&lt;br /&gt;&lt;a src="http://www.microsoft.com/protect/images/viruses/diagram.jpg"&gt;&lt;img style="cursor: pointer; width: 431px; height: 319px;" src="http://www.microsoft.com/protect/images/viruses/diagram.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx"&gt;For Detailed Information : Click Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2442688623759178220-4119384445863317922?l=hackersmag.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersmag.blogspot.com/feeds/4119384445863317922/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackersmag.blogspot.com/2009/06/conficker-one-of-most-dreaded-worm-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/4119384445863317922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2442688623759178220/posts/default/4119384445863317922'/><link rel='alternate' type='text/html' href='http://hackersmag.blogspot.com/2009/06/conficker-one-of-most-dreaded-worm-of.html' title='Conficker : one of most dreaded worm of 2008'/><author><name>AbhishekKr a.k.a ~=ABK=~</name><uri>http://www.blogger.com/profile/06276198262605731980</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_Xxl3TD2AA1M/TJugz8QWxVI/AAAAAAAAAps/V4_Eqc-ccXk/S220/abk01_small.jpg'/></author><thr:total>0</thr:total></entry></feed>
