Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts

Monday, September 6, 2010

XSS Defeating PoC : if have any time for Experimentation


It's still in experimental state, if you find some time please try it and let me know of your experience.

Video Demo of the same PoC: http://www.youtube.com/watch?v=ENiiAccY1v0


I was working on a XSS-Patch PoC, which I now feel works proper enough to prove its point.
This neither require Web-Developers for any Filtering/Validation, nor any javascript blocking add-on on user's browser.

I'm not good at explaining still I've tried to do that in the above linked WhitePaper.

And the ZIP file can be extracted, having 'StartDemo.bat' to be executed to start the server already patched with XSS Subverting Module.
Then browse, 'http://localhost/tweet.htm' in any browser... and it lets you Submit any text to Server w/o validation which is as it is saved there. But when retrieved on 'Read...' remains inactive for any

Thursday, August 26, 2010

hrberry.com :: php flaw self-inviting DoS, leaked framework and server info [by, ABK]

Posted@ https://sites.google.com/site/abklabs/home/secured/posts.xml

[]Patched:
Yes

[]Product Name:
http://www.hrberry.com
Payroll Helpdesk, serving several prestigious companies

[]Victim Name:
Ascent Consulting Services Pvt. Ltd.
[http://ascent-online.com]

[]Vuln Summary:
There were validation flaws for GET Request Parameters sent to CAPTCHA image generating PHP script on the Portal.
This allowed attacker to trick the app to generate any number of characters consuming processing power.
It had a timout after 30 seconds (too much) and generated error message with full PATH of PHP file.
Also worked on older un-patched version of OpenSSL.

to read detailed Description... click here

Saturday, June 13, 2009

ATMs under Trojan Attack in Eastern Europe

ATMs under Trojan Attack in Eastern Europe

security experts revealed a family of data-stealing trojans is infecting automatic teller machines in Eastern Europe over the past 18 months

It monitors transaction message queue for track 2 data stored on inserted cards. If it contains data belonging to a banking customer, it logs it, along with the PIN code that was entered.

The software works with Controller Cards... in its Primary Menu the main features it provide are
1. Print Collected Data
2. Restore logged files before malware infected the machine
3. Uninstallling the malware

there is a secomdary menu with main features as
1. Dispensing all Cash in ATM
2. Upload data to a chip on cotroller card