Tampilkan postingan dengan label vulnerability. Tampilkan semua postingan
Tampilkan postingan dengan label vulnerability. Tampilkan semua postingan

Rabu, 21 Maret 2012

WordPress Remote File Upload Vulnerability with Asset Manager Hack Web sites

In WordPress we can upload our deface page using Remote File Upload Vulnerability with Asset Manager. Asset Manager is a plugin that allows you to upload your files Just simply follow the simple steps to hack the wordpress website.
1. Open google and search inurl:Editor/assetmanager/assetmanager.asp
2. Now open any result you will found look like bellow snapshot.
3. Just click on browse and upload your deface page.

wordpress hacking

Demo: Asset Manager Deface page

Selasa, 13 Maret 2012

Find Shells Using "Index of /sh3llZ" Google Dork

shells

After getting the admin access hackers are Uploading their control penal (that’s call shell). Shell allows hackers to hack/deface the website and using the shell hacker can get root access. Sometime hackers left the shell in vulnerable sits. And here is some Google dorks which helps you to find the shells.

intitle:index of/sh3llZ

"Index of /sh3llZ"

"/sh3llZ/uploadshell/uploadshell.php

You can see in the above figure there are some shells like c99.php , c100.php etc. using that shell u can upload your shell and you can also deface that site.

Credits:
Devils cafe

Selasa, 10 Januari 2012

vBulletin 3.8.4 & 3.8.5 Registration Bypass Vulnerability

Software Link: http://www.vbulletin.org
Version: 3.8.4 & 3.8.5
Google dork 1 : powered by vBulletin 3.8.4
Google dork 2 : powered by vBulletin 3.8.5
Platform / Tested on: Multiple
Category: webapplications
BUG :
1 . Go to Http://[localhost]/path/register.php
2 . Assume that forum admin user name is ADMIN
3 . Type this at User Name ===> ADMIN&#00
4 . &#00 is an ASCII Code

5 . And complete the other parameters
6 . Then click on Complete Registrarion
7 . Now you see that your user name like admin user name After this time the private messages to the user (ADMIN) to sending see for you is sending .

Patch :
1 . Go to AdminCP
2 . Click on vBulletin Options and choose vBulletin Options
3 . Choose Censorship Options
4 . type &# in Censored Words section
5 . Then click on Save

This works only with vBulletin 3.8.4 and 3.8.5 ,if it doesnt work,that means some other has already used that username u want also ,try to use an other admins username,if it wont work still,then that means they have fixed this problem !!

Kamis, 05 Januari 2012

EzFilemanager Deface Upload vulnerability

CaptureGoogle dork for EzFilemanager is “ inurl:ezfilemanager/ezfilemanager.php

(you can modify this dork for getting mor results from Google )

Exploit : http://[xxx]/xxx/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file

Go to this url : website.com/lap/includes/tiny_mce/plugins/ezfilemanager/ezfilemanager.php and

put ?sa=1&type=file after URL

now url will be : http://website/PATCH/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file
now see the upload option and you can upload ,html ,pdf ,ppt ,txt ,doc ,rtf ,xml ,xsl ,dtd ,zip ,rar ,jpg ,png files

live Demo
result

Rabu, 21 Desember 2011

China Software Developer Network (CSDN) 6 Million user data Leaked


The "Chinese Software Developer Network" (CSDN), operated by Bailian Midami Digital Technology Co., Ltd., is one of the biggest networks of software developers in China. A text file with 6 Million CSDN user info including user name, password, emails, all in clear text leaked on internet.

The Download Link (use xunlei to download the file) of the File is available on various social Networks. Now Chinese programmers are busy changing their password now.(lol)
Just did some data ming on CSDN leaked user data. Some interesting findings. Here are the results of Top 100 email providers form 6M CSDN user emails :
@qq.com, 1976190
@163.com, 1766919
@126.com, 807893
@sina.com, 351590
@yahoo.com.cn, 205487
@hotmail.com, 202944
@gmail.com, 186843
@sohu.com, 104735
@yahoo.cn, 87048
@tom.com, 72360
@yeah.net, 53292
@21cn.com, 50709
@vip.qq.com, 35119
@139.com, 29207
@263.net, 24778
@sina.com.cn, 19155
@live.cn, 18920
@sina.cn, 18601
@yahoo.com, 18452
@foxmail.com, 16432
@163.net, 15173
@msn.com, 14211
@eyou.com, 13372
@yahoo.com.tw, 10810
@huiseo.cn, 8493
@csoftmail.cn, 7121
@citiz.net, 6605
@vip.sina.com, 5378
@189.cn, 5004
@etang.com, 4236
@chinaren.com, 3973
@yahoo.com.hk, 3899
@neusoft.com, 2930
@wormsoft.cn, 2780
@sogou.com, 2567
@bdqnok-cp.com.cn, 2551
@live.com, 2528
@mail.china.com, 2177
@china.com, 2169
@mail.ustc.edu.cn, 2038
@huawei.com, 1921
@vip.163.com, 1882
@sjtu.edu.cn, 1881
@371.net, 1805
@10pig.com.cn, 1782
@zte.com.cn, 1681
@cp-bdqnok.com.cn, 1632
@company-mail.cn, 1555
@msn.cn, 1522
@netease.com, 1499
@uggsrock.com, 1363
@bjtu.edu.cn, 1342
@hotmail.com.tw, 1313
@owlpic.com, 1277
@siteposter.net, 1275
@x263.net, 1183
@2008.sina.com, 1180
@elong.com, 1172
@yahoo.co.jp, 1049
@chongseo.com, 1033
@bofthew.com, 1022
@tyldd.com, 992
@fudan.edu.cn, 987
@marketnet.com.cn, 963
@newline.net.cn, 955
@stu.xjtu.edu.cn, 931
@online.sh.cn, 928
@msa.hinet.net, 927
@zju.edu.cn, 878
@king.com, 870
@cmmail.com, 844
@123.com, 838
@56.com, 836
@cpok-bdqn.com.cn, 818
@zj.com, 804
@china.com.cn, 803
@fm365.com, 763
@71mail.com.cn, 751
@avl.com.cn, 748
@bdqncpok.com.cn, 720
@mails.tsinghua.edu.cn, 719
@bit.edu.cn, 693
@mail.nankai.edu.cn, 640
@lzu.cn, 622
@xnmsn.cn, 602
@wo.com.cn, 599
@ah163.com, 598
@yahoo.ca, 594
@263.com, 563
@eastday.com, 561
@stu.edu.cn, 559
@188.com, 556
@mobile.csdn.net, 539
@csdn.net, 533
@sian.com, 519
@ymail.com, 518
@km169.net, 490
@emails.bjut.edu.cn, 488
@pp.com, 483
@pchome.com.tw, 480
 

Kaspersky Internet Security Memory Corruption Vulnerability



Vulnerability-Lab Team discovered a Memory & Pointer Corruption Vulnerability on Kaspersky Internet Security 2011/2012 & Kaspersky Anti-Virus 2011/2012. A Memory Corruption vulnerability is detected on Kaspersky Internet Security 2011/2012 & Kaspersky Anti-Virus 2011/2012.


The vulnerability is caused by an invalid pointer corruption when processing a corrupt .cfg file through the kaspersky exception filters,which could be exploited by attackers to crash he complete software process.The bug is located over the basegui.ppl & basegui.dll when processing a .cfg file import.
Affected Version(s):
  • Kaspersky Anti-Virus 2012 & Kaspersky Internet Security 2012
    • KIS 2012 v12.0.0.374
    • KAV 2012 v12.x
  • Kaspersky Anti-Virus 2011 & Kaspersky Internet Security 2011
    • KIS 2011 v11.0.0.232 (a.b)
    • KAV 11.0.0.400
    • KIS 2011 v12.0.0.374
  • Kaspersky Anti-Virus 2010 & Kaspersky Internet Security 2010
The kaspersky .cfg file import exception-handling filters wrong or manipulated file imports like one this first test . (wrong-way.png). The PoC is not affected by the import exception-handling & get through without any problems. A invalid pointer write & read allows an local attacker to crash the software via memory corruption. The technic & software to detect the bug in the binary is private tool.

Backdoor in Android for No-Permissions Reverse Shell


Thomas Cannon working at viaForensics as the Director of R&D has demonstrated a custom-developed app that installs a backdoor in Android smartphones – without requiring any permissions or exploiting any security holes.Thomas built an app which requires no permissions and yet is able to give an attacker a remote shell and allow them to execute commands on the device remotely from anywhere in the world. The functionality they are exploiting to do this is not new, it has been quietly pointed out for a number of years, and was explained in depth at Defcon 18.

It is not a zero-day exploit or a root exploit. They are using Android the way it was designed to work, but in a clever way in order to establish a 2-way communication channel. This has been tested on Android versions ranging from 1.5 up to 4.0 Ice Cream Sandwich, and it works in a similar way on all platforms.

The application operates by instructing the browser to access a particular web page with specific parameters. This web page, and the server behind it, will, in turn, control the app by forwarding the browser to a URL that starts with a protocol prefix that is registered as being handled by the app, for example app://. This process can then be repeated and in doing so it enables two-way communication.

"In this demonstration Android’s power and flexibility were perhaps also its downfall. Other smartphone platforms may not offer the controls we are bypassing at all, and the multi-tasking capabilities in Android allowed us to run the attack almost transparently to the user. This power combined with the open nature of Android also facilitates the customisation of the system to meet bespoke security requirements. This is something we have even been involved in ourselves by implementing a proof of concept Loadable Kernel Module to pro-actively monitor and defend a client’s intellectual property as it passed through their devices. It is no surprise that we have seen adoption of Android research projects in the military and government as it can be enhanced and adapted for specific security requirements, perhaps like no other mobile platform before it." Thomas Cannon said.

Senin, 05 Desember 2011

Google, Gmail, YouTube, Yahoo, Apple hacked using DNS cache poisoning attack

Google, Gmail, YouTube, Yahoo, Apple hacked using DNS cache poisoning attack

google

Hacker with Codname AlpHaNiX deface Google, Gmail, Youtube, Yahoo, Apple etc domains of Democratic Republic of Congo. Hacker use strategy so-called DNS cache poisoning.

DNS cache poisoning is a security or data integrity compromise in the Domain Name System (DNS). The compromise occurs when data is introduced into a DNS name server's cache database that did not originate from authoritative DNS sources. It may be a deliberate attempt of a maliciously crafted attack on a name server.google3

Picture show you how hacker insert fake records into the cache of DNS servers.

google2

List of hacked websites:
http://apple.cd/
http://yahoo.cd/
http://gmail.cd/
http://google.cd/
http://youtube.cd/
http://linux.cd/
http://samsung.cd/
http://hotmail.cd/
http://microsoft.cd/

15 Years Old Expert found XSS Vulnerability On Twitter !!

Untitled

 

A 15 years old XSS Expert "Belmin Vehabovic(~!White!~)" discovered XSS Vulnerability On Twitter and report us. The Vulnerable link is here. Even He also Discovered XSS Vulnerability in Facebook also as tweeted by him Yesterday &Facebook is offering him $700 as Bounty.