<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ethical hacking and cyber security</title>
	<atom:link href="http://hackingethics.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackingethics.wordpress.com</link>
	<description>Ethical hacking, Penetration Testing And Information Security Blog</description>
	<lastBuildDate>Mon, 20 Jun 2011 17:51:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackingethics.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Ethical hacking and cyber security</title>
		<link>http://hackingethics.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackingethics.wordpress.com/osd.xml" title="Ethical hacking and cyber security" />
	<atom:link rel='hub' href='http://hackingethics.wordpress.com/?pushpress=hub'/>
		<item>
		<title>XSS in Sonyericsson.com</title>
		<link>http://hackingethics.wordpress.com/2011/06/20/xss-in-sonyericsson-com/</link>
		<comments>http://hackingethics.wordpress.com/2011/06/20/xss-in-sonyericsson-com/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 04:45:11 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[News and Research]]></category>
		<category><![CDATA[website hacking]]></category>
		<category><![CDATA[Sony]]></category>
		<category><![CDATA[web application security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=412</guid>
		<description><![CDATA[Sony has been in the news for the past few months. Its leading Play station network was hacked and  information of millions of customers was stolen. After that, Sony&#8217;s networks and sites worldwide are facing attacks and data theft are being made. Be it hacktivist group Anonymous or notorious hacking group Lulzsec, none has left [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=412&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sony has been in the news for the past few months. Its leading Play station network was hacked and  information of millions of customers was stolen. After that, Sony&#8217;s networks and sites worldwide are facing attacks and data theft are being made. Be it hacktivist group Anonymous or notorious hacking group Lulzsec, none has left Sony untouched. But after all this security breaches, Sony isn&#8217;t learning from the mistakes it made. A few days back, I was just going through Sonyericsson&#8217;s official website looking for some handsets. So just thought of doing some manual audit of the website. And believe me, even a high school kid with hacking skills can find a vulnerability in the site within a minute!</p>
<div id="attachment_413" class="wp-caption aligncenter" style="width: 650px"><a href="http://hackingethics.files.wordpress.com/2011/06/sony_server.png"><img class="size-full wp-image-413" title="sony_server" src="http://hackingethics.files.wordpress.com/2011/06/sony_server.png?w=640&#038;h=287" alt="" width="640" height="287" /></a><p class="wp-caption-text">HTTP header response using my python script</p></div>
<p>&nbsp;</p>
<div id="attachment_414" class="wp-caption aligncenter" style="width: 650px"><a href="http://hackingethics.files.wordpress.com/2011/06/sony.png"><img class="size-full wp-image-414" title="sony" src="http://hackingethics.files.wordpress.com/2011/06/sony.png?w=640&#038;h=497" alt="" width="640" height="497" /></a><p class="wp-caption-text">And Finally the XSS !</p></div>
<p>A search box tempted me and I got the most common and most used vulnerability in web applications, Cross site scripting aka XSS.  Cross site scripting or XSS is a vulnerability in web applications and websites where an attacker can execute malicious script in the website during the run time and can use the website for phishing and stealing cookies etc. The attacker can execute malicous scripts on the webiste, thus tricking users and putting up traps like ajax keyloggers etc. The site didn&#8217;t have much to search for. Though a complete audit may result in more bugs and vulnerabilities. I think now Sony must gear up now. Its better to be secure then banging head on aftermath. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/412/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/412/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/412/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/412/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/412/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/412/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/412/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/412/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/412/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/412/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/412/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/412/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/412/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/412/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=412&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2011/06/20/xss-in-sonyericsson-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/sony_server.png" medium="image">
			<media:title type="html">sony_server</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/sony.png" medium="image">
			<media:title type="html">sony</media:title>
		</media:content>
	</item>
		<item>
		<title>Linux Log Eraser v0.2</title>
		<link>http://hackingethics.wordpress.com/2011/06/11/linux-log-eraser-v0-2/</link>
		<comments>http://hackingethics.wordpress.com/2011/06/11/linux-log-eraser-v0-2/#comments</comments>
		<pubDate>Sat, 11 Jun 2011 09:34:00 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[Tools and softwares]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[log earsing]]></category>
		<category><![CDATA[penetration testing]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=407</guid>
		<description><![CDATA[Many of us need to clear our tracks and logs after hacking a server or penetration testing. Keeping this in mind, b0nd bro from Hackers Garage has coded a script in bash to earse logs and traces left on a Linux machine while or after compromising it. Author: b0nd site: http://garage4hackers.com Features in ver 0.2: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=407&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Many of us need to clear our tracks and logs after hacking a server or penetration testing. Keeping this in mind, b0nd bro from Hackers Garage has coded a script in bash to earse logs and traces left on a Linux machine while or after compromising it.</p>
<p>Author: b0nd</p>
<p>site: http://garage4hackers.com</p>
<p>Features in ver 0.2:</p>
<p>1. Script has been redesigned from scratch. It&#8217;s more customizable now. Pay attention to the global variables declared and initialized at the top of code.<br />
2. <strong>Non-interactive script</strong>: The interactive features might be painful on a remote connect or reverse shell.<br />
3. Included features to <strong>Erase user activity logs</strong> from logs files (wtmp, utmp, lastlog etc)<br />
4. Fetch the IP, spoof_ip, and user name to it. The script will take care to remove all entries of them from &#8220;editable&#8221; ascii files and would spoof all of them in binary files.<br />
5. Fixed the error in deleting the log entries for the web back door shell from web logs.<br />
6. Restore the time stamping for all the log files which have been accessed and edited.<br />
7. Get some basic system info<br />
8. Verify-IP: To inform user if by mistake he has entered invalid IP (It includes 3 different checks on user input)</p>
<p>This time, script being non-interactive, please play safe. The script is ready to go and can be used in your ventures!<br />
Couple more things are running in back of my mind for the same concept. I will try to incorporate them soon in the existing code. Screen shots:</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/06/lg1.png"><img class="aligncenter size-full wp-image-408" title="lg1" src="http://hackingethics.files.wordpress.com/2011/06/lg1.png?w=600&#038;h=484" alt="" width="600" height="484" /></a></p>
<p style="text-align:center;"><a href="http://hackingethics.files.wordpress.com/2011/06/lg2.png"><br />
</a><a href="http://hackingethics.files.wordpress.com/2011/06/lg2.png"><img class="aligncenter size-full wp-image-409" title="lg2" src="http://hackingethics.files.wordpress.com/2011/06/lg2.png?w=600&#038;h=445" alt="" width="600" height="445" /></a></p>
<p style="text-align:left;">
<p style="text-align:left;">Download it from here: http://www.garage4hackers.com/showthread.php?979-Project-Linux-Log-Eraser-v0.2&amp;p=4184#post4184</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/407/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=407&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2011/06/11/linux-log-eraser-v0-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/lg1.png" medium="image">
			<media:title type="html">lg1</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/lg2.png" medium="image">
			<media:title type="html">lg2</media:title>
		</media:content>
	</item>
		<item>
		<title>Quick way to root your android phone</title>
		<link>http://hackingethics.wordpress.com/2011/06/10/quick-way-to-root-your-android-phone/</link>
		<comments>http://hackingethics.wordpress.com/2011/06/10/quick-way-to-root-your-android-phone/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 18:48:35 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Mobile]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=399</guid>
		<description><![CDATA[Sorry to all my readers , I was not able to blog for a long time as I was busy in personal life. But now I have come back and will try to update you all with interesting information security practices. Many of us have android mobile phones. And experimenting with new things is what [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=399&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sorry to all my readers , I was not able to blog for a long time as I was busy in personal life. But now I have come back and will try to update you all with interesting information security practices. Many of us have android mobile phones. And experimenting with new things is what we love to do. Few weeks back I was also searching something spicy to root my android device. Its just 1 and half month old, but still took the risk of playing with it. Many of us are confused that what will rooting do? Will it change the interface ! ?</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/06/andro.png"><img class="aligncenter size-full wp-image-400" title="andro" src="http://hackingethics.files.wordpress.com/2011/06/andro.png?w=256&#038;h=320" alt="" width="256" height="320" /></a></p>
<p>Well I don&#8217;t think so ! Rooting your device will help you in installing non Market apps or just unlock your device easily. So lets move on further. While googling and going through some of the blogs, I got a tool &#8220;SuperOneClick root tool&#8221; to root android devices. (You can google it to download, else I&#8217;ll be posting my skydrive link in the end of post for convince) So no huge steps, just a few to go!</p>
<p>1. Connect your device to your system. Note: USB Debugging Mode should be on on your device.</p>
<p>2. Open the SuperOneClick root tool. Note: This will work only for 2.1 or 2.2 version. For gingerbread and honeycomb, you need to do some digging</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/06/andro1_pc.png"><img class="aligncenter size-full wp-image-401" title="andro1_pc" src="http://hackingethics.files.wordpress.com/2011/06/andro1_pc.png?w=640&#038;h=341" alt="" width="640" height="341" /></a></p>
<p>3. Click root button, and the rooting process will start after that</p>
<p>4. After the completion , all must be curious to know whether our device got rooted or not.Well here&#8217;s the solution for it. Browse to android market on your device and search for &#8220;terminal emulator&#8221;</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/06/andro-1.png"><img class="aligncenter size-full wp-image-402" title="andro-1" src="http://hackingethics.files.wordpress.com/2011/06/andro-1.png?w=256&#038;h=320" alt="" width="256" height="320" /></a></p>
<p>5. Install the application and open it. Now type in su in the console. If you get # symbol and a message flashing &#8220;granted super user privileges&#8221; , Congrats !!! your device has been rooted !!</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/06/andro-2.png"><img class="aligncenter size-full wp-image-403" title="andro-2" src="http://hackingethics.files.wordpress.com/2011/06/andro-2.png?w=256&#038;h=320" alt="" width="256" height="320" /></a></p>
<p>6. Further, you can check for updates, non market apps on your phone as &#8220;super user&#8221; gets installed on your phone too. Browse your phone to view it</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/06/andro-22.png"><img class="aligncenter size-full wp-image-404" title="andro-22" src="http://hackingethics.files.wordpress.com/2011/06/andro-22.png?w=256&#038;h=320" alt="" width="256" height="320" /></a></p>
<p>So this was a quick guide for beginners like me trying to play and root their device ! Hope it will help others too. Meanwhile the tool SuperOneClick is not available for Linux users <img title="Frown" src="http://www.garage4hackers.com/images/smilies/frown.png" alt="" border="0" /> For windows,You can download it form my skydrive <a href="http://cid-ba72d122117ce3a9.office.live.com/self.aspx/.Public/SuperOneClick.zip" target="_blank">here</a></p>
<p><strong>Note:</strong> I have confirmed it from the service center that on rooting your device, you loose the warranty of it.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/399/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/399/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/399/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=399&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2011/06/10/quick-way-to-root-your-android-phone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/andro.png" medium="image">
			<media:title type="html">andro</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/andro1_pc.png" medium="image">
			<media:title type="html">andro1_pc</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/andro-1.png" medium="image">
			<media:title type="html">andro-1</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/andro-2.png" medium="image">
			<media:title type="html">andro-2</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/06/andro-22.png" medium="image">
			<media:title type="html">andro-22</media:title>
		</media:content>

		<media:content url="http://www.garage4hackers.com/images/smilies/frown.png" medium="image">
			<media:title type="html">Frown</media:title>
		</media:content>
	</item>
		<item>
		<title>XSS and SQLi in tech2 website</title>
		<link>http://hackingethics.wordpress.com/2011/01/06/xss-and-sqli-in-tech2-website/</link>
		<comments>http://hackingethics.wordpress.com/2011/01/06/xss-and-sqli-in-tech2-website/#comments</comments>
		<pubDate>Thu, 06 Jan 2011 05:39:38 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=394</guid>
		<description><![CDATA[Tech2 is a famous tech show broadcasted on the CNN-IBN network channels. Long time back, I had found XSS and SQL injection in their  site and had informed them. Again, I have got XSS and SQL injection bug in their site. site: http://tech2.in.com vulnerable xss links: http://tech2.in.com/forums/index.php?sid=da6fea08c9b152d11604d9de6d1c67a6%22%3E%3Cscript%3Ealert%28%22LOXIans%22%29%3C/script%3E http://tech2.in.com/seller_login_new.php?sourceurl=http://tech2.in.com/seller/seller_form_new.php%22%3E%3Cscript%3Ealert%28%22LOXIans%22%29%3C/script%3E http://tech2.in.com/seller_login_new.php?sourceurl=http://tech2.in.com/seller/seller_detail.php?id=2475%22%3E%3Cscript%3Ealert%28%22LOXIans%22%29%3C/script%3E Vulnerable SQLi link: http://tech2.in.com/contest.php?contestid=832 Details: Web [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=394&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Tech2 is a famous tech show broadcasted on the CNN-IBN network channels. Long time back, I had found XSS and SQL injection in their  site and had informed them. Again, I have got XSS and SQL injection bug in their site.</p>
<p>site: http://tech2.in.com</p>
<p>vulnerable xss links:</p>
<p>http://tech2.in.com/forums/index.php?sid=da6fea08c9b152d11604d9de6d1c67a6%22%3E%3Cscript%3Ealert%28%22LOXIans%22%29%3C/script%3E</p>
<p>http://tech2.in.com/seller_login_new.php?sourceurl=http://tech2.in.com/seller/seller_form_new.php%22%3E%3Cscript%3Ealert%28%22LOXIans%22%29%3C/script%3E</p>
<p>http://tech2.in.com/seller_login_new.php?sourceurl=http://tech2.in.com/seller/seller_detail.php?id=2475%22%3E%3Cscript%3Ealert%28%22LOXIans%22%29%3C/script%3E</p>
<p>Vulnerable SQLi link:</p>
<p>http://tech2.in.com/contest.php?contestid=832</p>
<p>Details:</p>
<p>Web Server: WEB18 SERVER SOFTWARE</p>
<p>DB Server:  MySQL &gt;=5</p>
<p>DB: qtech</p>
<p>Table names:</p>
<p>F1Y08022009,activity,adlogger_adcheck_logs,adlogger_blocklogs,adlogger_channels,adlogger_logfiles,adlogger_quickstats,adlogger_users,admin_action_log,admin_action_log_nov2010,allsitestechbox,apcbanner,author,bannerautorefr</p>
<p>Pics:</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/01/t1.jpg"><img class="aligncenter size-full wp-image-396" title="t1" src="http://hackingethics.files.wordpress.com/2011/01/t1.jpg?w=640&#038;h=500" alt="" width="640" height="500" /></a></p>
<p><a href="http://hackingethics.files.wordpress.com/2011/01/t2.jpg"><img class="aligncenter size-full wp-image-397" title="t2" src="http://hackingethics.files.wordpress.com/2011/01/t2.jpg?w=640&#038;h=500" alt="" width="640" height="500" /></a></p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/394/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=394&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2011/01/06/xss-and-sqli-in-tech2-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/01/t1.jpg" medium="image">
			<media:title type="html">t1</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/01/t2.jpg" medium="image">
			<media:title type="html">t2</media:title>
		</media:content>
	</item>
		<item>
		<title>BANG&#8212;-&gt; NASA again !!</title>
		<link>http://hackingethics.wordpress.com/2011/01/06/bang-nasa-again/</link>
		<comments>http://hackingethics.wordpress.com/2011/01/06/bang-nasa-again/#comments</comments>
		<pubDate>Thu, 06 Jan 2011 04:34:06 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[website hacking]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=388</guid>
		<description><![CDATA[Yep. LOXians have hit NASA again. Last year &#8220;vinnu&#8221; bro had disclosed many SQL injection  and XSS bugs in NASA and other US government departments. This time its NASA again with XSS and SQL injections bugs in their site. Server: Jet Propulsion Laboratory, NASA Bugs: SQL injection and XSS Database Type: Mysql Pics:<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=388&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Yep. LOXians have hit NASA again. Last year &#8220;vinnu&#8221; bro had disclosed many SQL injection  and XSS bugs in NASA and other US government departments. This time its NASA again with XSS and SQL injections bugs in their site.</p>
<p>Server: Jet Propulsion Laboratory, NASA</p>
<p>Bugs: SQL injection and XSS</p>
<p>Database Type: Mysql</p>
<p>Pics:</p>
<p><a href="http://hackingethics.files.wordpress.com/2011/01/jpl.jpg"><img class="aligncenter size-full wp-image-389" title="jpl" src="http://hackingethics.files.wordpress.com/2011/01/jpl.jpg?w=640&#038;h=501" alt="" width="640" height="501" /></a></p>
<p><a href="http://hackingethics.files.wordpress.com/2011/01/jpl1.jpg"><img class="aligncenter size-full wp-image-390" title="jpl1" src="http://hackingethics.files.wordpress.com/2011/01/jpl1.jpg?w=640&#038;h=500" alt="" width="640" height="500" /></a></p>
<p><a href="http://hackingethics.files.wordpress.com/2011/01/jpl2.jpg"><img class="aligncenter size-full wp-image-391" title="jpl2" src="http://hackingethics.files.wordpress.com/2011/01/jpl2.jpg?w=640&#038;h=489" alt="" width="640" height="489" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/388/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/388/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/388/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/388/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/388/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/388/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/388/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/388/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/388/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/388/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/388/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/388/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/388/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/388/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=388&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2011/01/06/bang-nasa-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/01/jpl.jpg" medium="image">
			<media:title type="html">jpl</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/01/jpl1.jpg" medium="image">
			<media:title type="html">jpl1</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2011/01/jpl2.jpg" medium="image">
			<media:title type="html">jpl2</media:title>
		</media:content>
	</item>
		<item>
		<title>Micromax mobile&#8217;s website xssed</title>
		<link>http://hackingethics.wordpress.com/2010/12/10/micromax-mobiles-website-xssed/</link>
		<comments>http://hackingethics.wordpress.com/2010/12/10/micromax-mobiles-website-xssed/#comments</comments>
		<pubDate>Fri, 10 Dec 2010 17:58:03 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=385</guid>
		<description><![CDATA[Hello Friends. I was just browsing micromax&#8217;s website for their latest release, an android mobile A-60, the cheapest Android phone in the market. While browsing the site got few xss vulnerabilities. Hope they get patched soon before evil minds use them. Earlier many telecommunication giants like !dea cellular and sony ericsson etc. have been xssed [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=385&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hello Friends. I was just browsing micromax&#8217;s website for their latest release, an android mobile A-60, the cheapest Android phone in the market. While browsing the site got few xss vulnerabilities. Hope they get patched soon before evil minds use them. Earlier many telecommunication giants like !dea cellular and sony ericsson etc. have been xssed and gone under sql injection attacks (check null|con for !dea sqli report)</p>
<p>Vulnerable links:  http://www.micromaxinfo.com/product.php?product=modu-t&amp;cat=Touch_Screen&#8221;&gt;&lt;script&gt;alert(1)&lt;/script&gt;</p>
<p>http://www.micromaxinfo.com:80/product.php?cat=Touch_Screen&amp;product=modu-t&#8221;&gt;&lt;marquee&gt;&lt;h1&gt;XSSED(Legion Of XTRemers and Garage 4 hackers&lt;/h1&gt;&lt;/marquee&gt;</p>
<p>pics:</p>
<p><img src="http://img26.imageshack.us/img26/7987/90498212.jpg" alt="" width="1280" height="1024" /></p>
<div class="wp-caption aligncenter" style="width: 1290px"><img src="http://img255.imageshack.us/img255/3091/57783237.jpg" alt="" width="1280" height="1024" /><p class="wp-caption-text"> </p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/385/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/385/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/385/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=385&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2010/12/10/micromax-mobiles-website-xssed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://img26.imageshack.us/img26/7987/90498212.jpg" medium="image" />

		<media:content url="http://img255.imageshack.us/img255/3091/57783237.jpg" medium="image" />
	</item>
		<item>
		<title>Man-In-The-Middle attack (MITM)</title>
		<link>http://hackingethics.wordpress.com/2010/12/02/man-in-the-middle-attack-mitm/</link>
		<comments>http://hackingethics.wordpress.com/2010/12/02/man-in-the-middle-attack-mitm/#comments</comments>
		<pubDate>Thu, 02 Dec 2010 04:41:57 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[News and Research]]></category>
		<category><![CDATA[website hacking]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=381</guid>
		<description><![CDATA[What is MITM ? Lets have an example first. An attacker puts up a fake bank website and entices user to that website. User types in his password, and the attacker in turn uses it to access the bank&#8217;s real website. Done right, the user will never realize that he isn&#8217;t at the bank&#8217;s website. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=381&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><img class="aligncenter" src="http://www.owasp.org/images/2/21/Main_the_middle.JPG" alt="" width="569" height="316" /></p>
<p><strong>What is MITM ?</strong><br />
Lets have an example first. An attacker puts up a fake bank website and  entices user to that website. User types in his password, and the  attacker in turn uses it to access the bank&#8217;s real website. Done right,  the user will never realize that he isn&#8217;t at the bank&#8217;s website. Then  the attacker either disconnects the user and makes any fraudulent  transactions he wants, or passes along the user&#8217;s banking transactions  while making his own transactions at the same time.</p>
<p>Here&#8217;s what Wikipedia says &#8220;In cryptography, the man-in-the-middle  attack (often abbreviated MITM), or bucket-brigade attack, or sometimes  Janus attack, is a form of active eavesdropping in which the attacker  makes independent connections with the victims and relays messages  between them, making them believe that they are talking directly to each  other over a private connection when in fact the entire conversation is  controlled by the attacker. The attacker must be able to intercept all  messages going between the two victims and inject new ones, which is  straightforward in many circumstances (for example, an attacker within  reception range of an unencrypted Wi-Fi wireless access point, can  insert himself as a man-in-the-middle).&#8221;</p>
<p>A Man-in-the-middle attack can only be successful when the attacker can  impersonate each endpoint to the satisfaction of the other. Most  cryptographic protocols include some form of endpoint authentication  specifically to prevent MITM attacks. For example, SSL authenticates the  server using a mutually trusted certification authority.</p>
<p><strong>Techniques</strong><br />
Various defenses against MITM attacks use authentication techniques that are based on:  Public key infrastructures</p>
<p>Stronger mutual authentication</p>
<p>Secret keys (high information entropy secrets)</p>
<p>Passwords (low information entropy secrets)</p>
<p>Other criteria, such as voice recognition or other biometrics</p>
<p>Off-the-Record Messaging for instant messaging</p>
<p>Off-channel verification</p>
<p>Carry-forward verification</p>
<p>The integrity of public keys must generally be assured in some manner,  but need not be secret. Passwords and shared secret keys have the  additional secrecy requirement. Public keys can be verified by a  Certificate Authority, whose public key is distributed through a secure  channel (for example, with a web browser or OS installation). Public  keys can also be verified by aweb of trust that distributes public keys  through a secure channel (for example by face-to-face meetings).</p>
<p><strong>Tools For Hacking</strong></p>
<p>dsniff &#8211; A tool for SSH and SSL MITM attacks monkey6.</p>
<p>Cain &#8211; A Windows GUI tool which can perform MITM attacks, along with sniffing and ARP poisoning</p>
<p>Ettercap &#8211; A tool for LAN based MITM attacks</p>
<p>Karma &#8211; A tool that uses 802.11 Evil Twin attacks to perform MITM  attacks AirJack &#8211; A tool that demonstrates 802.11 based MITM attacks</p>
<p>wsniff &#8211; A tool for 802.11 HTTP/HTTPS based MITM attacks an additional  card reader and a method to intercept key-presses on an Automated teller  machine</p>
<p>The MITM attack could also be done over an https connection by using the  same technique; the only difference consists in the establishment of  two independent SSL sessions, one over each TCP connection. The browser  sets a SSL connection with the attacker, and the attacker establishes  another SSL connection with the web server. In general the browser warns  the user that the digital certificate used is not valid, but the user  may ignore the warning because he doesn’t understand the threat. In some  specific contexts it’s possible that the warning doesn’t appear, as for  example, when the Server certificate is compromised by the attacker or  when the attacker certificate is signed by a trusted CA and the CN is  the same of the original web site.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/381/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=381&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2010/12/02/man-in-the-middle-attack-mitm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://www.owasp.org/images/2/21/Main_the_middle.JPG" medium="image" />
	</item>
		<item>
		<title>Fusion of Xploits &#8211; Multiplexing exploitation</title>
		<link>http://hackingethics.wordpress.com/2010/11/13/fusion-of-xploits-multiplexing-exploitation/</link>
		<comments>http://hackingethics.wordpress.com/2010/11/13/fusion-of-xploits-multiplexing-exploitation/#comments</comments>
		<pubDate>Sat, 13 Nov 2010 09:56:06 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=378</guid>
		<description><![CDATA[Author : &#8220;vinnu&#8221; Team : &#8220;Legion Of Xtremers&#8221; Greeatz : Secfence team, Lord Deathstorm, Happy T3rminat0r, fb1h2s, b0nd The worthiness of a single chance to exploit a specific victim cannot be compared with anything else. And a hacker by hook-or-crook will never tend to loose even a little probability of such a chance. In such [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=378&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://hackingethics.files.wordpress.com/2010/11/exploitlogo.jpg"><img class="aligncenter size-full wp-image-379" title="ExploitLogo" src="http://hackingethics.files.wordpress.com/2010/11/exploitlogo.jpg?w=640&#038;h=210" alt="" width="640" height="210" /></a></p>
<p style="text-align:left;">Author : &#8220;vinnu&#8221;<br />
Team : &#8220;Legion Of Xtremers&#8221;<br />
Greeatz : Secfence team, Lord Deathstorm, Happy T3rminat0r, fb1h2s, b0nd</p>
<p>The worthiness of a single chance to exploit a specific victim cannot be compared with<br />
anything else. And a hacker by hook-or-crook will never tend to loose even a little probability<br />
of such a chance.</p>
<p>In such scenarios, normal exploitation strategies fail to cash-up such precious chances of exploitation.</p>
<p>But, why normal exploitation fail?</p>
<p>In kill-all type situation several exploits are bundled togather so as to achieve more chances of success of<br />
remote code execution. But in some cases we cannot infer what vulnerable products are loaded on target victim box.</p>
<p>So in case of certain type of exploits; which need exclusive resources, one non-legitimate contender exploit<br />
will cause failure of the eligible exploit. Such a situation is mostly faced with heap spray type exploits.<br />
Though there are several other types also which behave in similar fashion.</p>
<p>In this paper, we&#8217;ll discus about the fusion of multiple heap spray based exploits in such a way that they will<br />
execute under same roof (shared resource among them).</p>
<p>Some vulnerabilities, which gets trigerred by javascript and do not need any extra plugin or activeX component<br />
are simplest cases to get triggerred in sequence.</p>
<p>But in case of fusion of exploits which use activeX components or plugins, we have to tackle few problems first<br />
before triggering the vulnerability.</p>
<p>In this paper I am going to fuse Apple QuickTime Marshalled pUnk exploit and a zeroday of Adobe.</p>
<p style="text-align:left;">The whole paper can be read at garage 4 hackers forum.  <a href="http://www.garage4hackers.com/showthread.php?475-Fusion-of-Xploits-Multiplexing-exploitation" target="_blank">Click here </a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/378/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=378&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2010/11/13/fusion-of-xploits-multiplexing-exploitation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2010/11/exploitlogo.jpg" medium="image">
			<media:title type="html">ExploitLogo</media:title>
		</media:content>
	</item>
		<item>
		<title>D4rk-cracker : A md5 cracker in python</title>
		<link>http://hackingethics.wordpress.com/2010/11/13/d4rk-cracker-a-md5-cracker-in-python/</link>
		<comments>http://hackingethics.wordpress.com/2010/11/13/d4rk-cracker-a-md5-cracker-in-python/#comments</comments>
		<pubDate>Sat, 13 Nov 2010 09:43:40 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=374</guid>
		<description><![CDATA[My friend D4rk357 made another brilliant tool in python. This time its &#8220;D4rk-cracker, a md5 hash cracker coded in python. This tool can easily be expanded by adding more online md5 crack resources .Below is the source code of the tool: #!/usr/bin/python # D4rk-cracker-- A small python code for MD5 cracking # Coded By D4rk357[2010] [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=374&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://hackingethics.files.wordpress.com/2010/11/desktop2f.png"><img class="aligncenter size-full wp-image-375" title="desktop2f" src="http://hackingethics.files.wordpress.com/2010/11/desktop2f.png?w=640&#038;h=367" alt="" width="640" height="367" /></a></p>
<p>My friend D4rk357 made another brilliant tool in python. This time its &#8220;D4rk-cracker, a md5 hash cracker coded in python. This tool  can easily be expanded by adding more online md5  crack resources .Below is the source code of the tool:</p>
<pre>#!/usr/bin/python

# D4rk-cracker-- A small python code for MD5 cracking
# Coded By D4rk357[2010]

import urllib,urllib2, re,sys,cookielib
from socket import*

if len(sys.argv) != 2:
	print "\n|-----------------------------------------------------------------|"
        print "|          lastman100[@]gmail[dot]com                             |"
        print "|           10/2010     MD 5 Cracker    v0.1                      |"
	print "| Visit   : www.garage4hackers.com                                |"
        print "|-----------------------------------------------------------------|\n"

mhash= raw_input('please enter the hash to crack :')
params =  urllib.urlencode({'term':mhash})
f=urllib.urlopen("http://md5crack.com/crackmd5.php", params)
tas= f.read()
link=re.compile('Found: md5'+'\S+'+'\s+'+'\S+'+'\s+'+'\w+')

if link.search(tas):
	a= link.search(tas).group()
	print("[+]cracking...\n \n[+]Hash Cracked from md5crack.com \n")
	print a.strip('[Found,:]')
else:
	print "[+] Hash not found on md5crack.com\n"

params=urllib.urlencode({'oc_check_md5':mhash})
f=urllib.urlopen("http://opencrack.hashkiller.com/",params)
tas=f.read()
link=re.compile('result'+'.*'+'\S')
if link.search(tas):
	a= link.search(tas).group()
	print("\n[+]Hash Cracked from hashkiller.com \n")
	print a.strip('[result,",&gt;,&lt;br/&gt;]')
else:
	print "[+] \nHash not found on hashkiller.com\n"

params=urllib.urlencode({'search_field':mhash})
f=urllib.urlopen("http://hashchecker.com/index.php?_sls=search_hash",params)
tas=f.read()
link=re.compile('Your md5 hash is :'+'\S+'+'\s+'+'\S+'+'\s+'+'\S+')

if link.search(tas):
	a= link.search(tas).group()
	print("\n[+]Hash Cracked from hashchecker.com \n")
	print a.strip('[Your md5 hash is :,&lt;br&gt;,&lt;li&gt;,&lt;b&gt;,&lt;/b&gt;]')
else:
	print "[+] \nHash not found on hashchecker.com\n"</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/374/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/374/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/374/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=374&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2010/11/13/d4rk-cracker-a-md5-cracker-in-python/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2010/11/desktop2f.png" medium="image">
			<media:title type="html">desktop2f</media:title>
		</media:content>
	</item>
		<item>
		<title>Link Extractor in Python</title>
		<link>http://hackingethics.wordpress.com/2010/11/10/link-extractor-in-python/</link>
		<comments>http://hackingethics.wordpress.com/2010/11/10/link-extractor-in-python/#comments</comments>
		<pubDate>Wed, 10 Nov 2010 11:45:46 +0000</pubDate>
		<dc:creator>Prashant</dc:creator>
				<category><![CDATA[Tools and softwares]]></category>

		<guid isPermaLink="false">http://hackingethics.wordpress.com/?p=369</guid>
		<description><![CDATA[D4rk357, my friend made a Link Extractor in python. A very useful tool to extratct links form website: #!/usr/bin/python  #A small link extractor program . import os,sys,urllib,re,httplib if len(sys.argv) != 2: print "\n&#124;-----------------------------------------------------------------&#124;" print "&#124; lastman100[@]gmail[dot]com &#124;" print "&#124; 10/2010 Link Extractor v0.1 &#124;" print "&#124; Visit : www.garage4hackers.com &#124;" print "&#124;-----------------------------------------------------------------&#124;\n" ab=raw_input("enter URL to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=369&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://hackingethics.files.wordpress.com/2010/11/lnk1.jpg"><img class="aligncenter size-full wp-image-370" title="lnk1" src="http://hackingethics.files.wordpress.com/2010/11/lnk1.jpg?w=640&#038;h=225" alt="" width="640" height="225" /></a></p>
<p>D4rk357, my friend made a Link Extractor in python. A very useful tool to extratct links form website:</p>
<pre>
<pre>#!/usr/bin/python
 #A  small link extractor program .
import os,sys,urllib,re,httplib</pre>
<p>if len(sys.argv) != 2:<br />
print "\n|-----------------------------------------------------------------|"<br />
print "|          lastman100[@]gmail[dot]com                             |"<br />
print "|           10/2010     Link Extractor    v0.1                      |"<br />
print "| Visit   : www.garage4hackers.com                                |"<br />
print "|-----------------------------------------------------------------|\n"</p>
<p>ab=raw_input("enter URL to extract the link\n")<br />
ht=re.compile("http://")<br />
if ht.search(ab):<br />
sa=urllib.urlopen(ab)<br />
else:<br />
sa=urllib.urlopen('http://'+ab)</p>
<p>st=sa.read()</p>
<p>link=re.compile('http\S\W+'+'\S+')</p>
<p>y =link.finditer(st)</p>
<p>for i in y:<br />
print i.group()</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackingethics.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackingethics.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackingethics.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackingethics.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackingethics.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackingethics.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackingethics.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackingethics.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackingethics.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackingethics.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackingethics.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackingethics.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackingethics.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackingethics.wordpress.com/369/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackingethics.wordpress.com&amp;blog=9824402&amp;post=369&amp;subd=hackingethics&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackingethics.wordpress.com/2010/11/10/link-extractor-in-python/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5379cc4833d5ce1bb3c3a2887322de76?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Prashant</media:title>
		</media:content>

		<media:content url="http://hackingethics.files.wordpress.com/2010/11/lnk1.jpg" medium="image">
			<media:title type="html">lnk1</media:title>
		</media:content>
	</item>
	</channel>
</rss>
