Showing posts with label Vulnerability scanner. Show all posts
Showing posts with label Vulnerability scanner. Show all posts
Burp Suite Pro v1.4.03 released - CSRF generator, SSL strip Added
0
comments
vic
-
There is a new CSRF generator, which produces proof-of-concept HTML for generating virtually any HTTP request. You can access this feature by right-clicking any item within Burp, and using the engagement tools context menu to select "generate CSRF PoC".
Some useful features are:
- Support for all form encoding types: standard URL encoding, multipart encoding, and plain text encoding.
- Auto-detection of the optimal encoding type, with manual override.
- Ability to edit both the request and response in-place, to fine tune attacks.
- In-browser testing, by pasting a URL into your browser that will cause Burp Proxy to serve up the CSRF PoC in its response.
myOpenID XSS : One of the Largest OpenID provider is Vulnerable
One of the One of the Largest Independent OpenID provider "myOpenID" is Vulnerable to Cross Site Scripting (XSS) ,Discovered by "SeeMe" - Member of Inj3ct0r Team. Cross Site Scripting (or XSS) is one of the most common application-layer web attacks.
What Hacker can do - "The attackers can steal the session ID of a valid user using XSS. The session ID is very valuable because it is the secret token that the user presents after login as proof of identity until logout. If the session ID is stored in a cookie, the attackers can write a script which will run on the user's browser, query the value in the cookie and send it to the attackers. The attackers can then use the valid session ID to browse the site without logging in. The script could also collect other information from the page, including the entire contents of the page".
Proof Of Concept - Click Here
Internet Explorer and Safari first to fall at Pwn2Own 2011, Chrome and Firefox still standing !
Pwn2Own, the annual three-day browser hackathon, has already claimed its first two victims: IE8 on Windows 7 64-bit, and Safari 5 on Mac OS X. Google Chrome looks set to survive for its third year in a row.
Internet Explorer 8 was thoroughly destroyed by independent researcher Stephen Fewer. "He used three vulnerabilities to bypass ASLR and DEP, but also escape Protected Mode. That's something we've not seen at Pwn2Own before," said Aaron Portnoy, the organizer of Pwn2Own.
Safari 5, running on a MacBook Air, was compromised in just five seconds by French security company Vupen. Both attackers netted $15,000 for successfully compromising a browser.
The contest continues today and tomorrow. Firefox 3.6 is yet to be attacked, and tomorrow will see the very first mobile browser deathmatch. Windows Phone 7, iOS, Android and RIM OS, all with their stock browsers, will be attacked by security researchers to find out just how secure mobile browsing is. Again, $15,000 is available for the first person or team to compromise each of the browsers.
Google and Mozilla, incidentally, both rolled out updates to their browsers just before Pwn2Own. It was not a coincidence.
EgY SpIdEr ShElL : Shell strongest in the history the hacker !
The toolkit provides you with templates to hack various software programs:
Brute force attacks:
HTTP form cracks:
Encoding:
Database queries:
SQL injection tool:
The origin of this toolkit seems to point to Arabic countries. It is just one of many similar hack shells that criminals use. A future blog post about other tools might be necessary
Exploitsearch.net - Exploit & Vulnerability Search Engine
This is a online search for currently utilizing data from NVD, OSVDB, SecurityFocus, Exploit-DB, Metasploit, Nessus, OpenVAS, and PacketStorm.Well search engine does the work but this is a specific search engine for better results. There not much to write about just visit the site and all your queries will be answered.
VISIT : http://www.exploitsearch.net/
WD TV Live Hub Compromised - Multiple Vulnerabilities Found By Dr. Alberto Fontanella
Dr. Alberto Fontanella found on (Western Digital) WD TV Live Hub appliance with the last firmware installed (2.06.10) and 3 exploits to get admin password, deface appliance and get root shell:
Author: Dr. Alberto Fontanella
E-mail: itsicurezza<0x40>yahoo.it
Web: www.fulgursec.com
Vendor: Western Digital
Vendor Web: www.wdc.com
Version: WD TV Live Hub <= 2.06.10 (firmware) ALL VERSIONS
Type: Appliance
Issues: Storage Anonymous Access, Full Path Disclosure, Bypass Authentication Schema, Appliance Command Execution, DoS, OS , Command Execution, Root Shell ;-)
* AF - Owning WD TV Live Hub
FILE: AF-Owning_WD_TV_Live_Hub.pdf
INFO: Paper that shows all issues found on WD TV Live Hub and how use it to get Root!
* AF - PoC/Exploit WD TV Live Hub Get Admin Password
FILE: AF-WD_TV_Live_Hub_password.sh
INFO: Exploit (Bypass Authentication Schema) to Get Admin Password of Web Console
* AF - PoC/Exploit WD TV Live Hub Deface
FILE: AF-WD_TV_Live_Hub_deface.sh
INFO: Exploit (Appliance Command Execution) to Deface WD TV Live Hub
*AF - PoC/Exploit WD TV Live Hub Get Root Shell
FILE: AF-WD_TV_Live_Hub_root_shell.sh
INFO: Exploit (OS Command Execution) to Get Root Shell
Download all Files Here
Introduction to Web Application Firewall (WAF) ~ Website Security
What is WAF?WAF is expanded as Web Application Firewall. WAF is server side application that controls the input and output(filter the HTTP communication). It controls network traffic on any OSI Layer up to Application Layer. The main purpose of WAF is to provide better protection over the top Wep Application vulnerability such as XSS(Cross Site Scripting), SQL Injection,RFI. Daily lot of websites hacked because of these vulnerability. Read Our Security News Section to know about the Security Risks in Interent. Standard firewall blocks Non-HTTP attacks(restriction of ports,access..). This WAF blocks HTTP attack.
The Most common Web Application Vulnerabilities:
- SQL Injection(SQLi)
- Cross-Site Scripting (XSS)
- Broken Authentication and Session Management
- Insecure Direct Object References
- Cross-Site Request Forgery (CSRF)
- Security Misconfiguration
- Insecure Cryptographic Storage
- Failure to Restrict URL Access
- Insufficient Transport Layer Protection
- Unvalidated Redirects and Forwards
The Wep Application Firewall(WAF) must meat the following features:
- Protection Against Top Vulnerability(XSS,SQLi,..etc)
- Very Few False Positives (i.e., should NEVER disallow an authorized request)
- Strength of Default (Out of the Box) Defenses
- Power and Ease of Learn Mode
- Types of Vulnerabilities it can prevent.
- Detects disclosure and unauthorized content in outbound reply messages, such as credit-card and Social Security numbers.
- Both Positive and Negative Security model support.
- Simplified and Intuitive User Interface.
- Cluster mode support.
- High Performance (milliseconds latency).
- Complete Alerting, Forensics, Reporting capabilities.
- Web Services\XML support.
- Brute Force protection.
- Ability to Active (block and log), Passive (log only) and bypass the web trafic.
- Ability to keep individual users constrained to exactly what they have seen in the current session
- Ability to be configured to prevent ANY specific problem (i.e., Emergency Patches)
- Form Factor: Software vs. Hardware (Hardware generally preferred)
Top 10 Open Source Web Application Firefwall(WAF):
WebCruiser Web Vulnerability Scanner Enterprise 2.4.2
WebCruiser Web Vulnerability Scanner Enterprise 2.4.2 telah diselipi dan keygen nya sekarang avialable untuk men-download silahkan dibawah sobat.
Download Here
Sponsor
Cyber Security, News & Support, and Technology. Follow Us, Stay Connected and Be Safe.
Share It With Friends
Blog Archive
About Me
Tag Cloud
Admin Tools
(16)
Adobe
(1)
Adsense
(12)
Airtel Hacks
(1)
Android
(9)
Anonymous Hackers
(2)
Apple
(14)
Applications
(3)
ATM Machine
(1)
Backtrack
(3)
Batch Files
(1)
Blackberry
(1)
Blogger
(17)
Browsers
(1)
Bugs
(2)
Business
(1)
C source code
(2)
Camera Hack
(1)
Chat
(1)
Chrome Os
(1)
computer_tricks
(122)
Computing
(4)
Corporate
(9)
Cracks
(5)
Crimes
(2)
Cyber Attacks
(12)
Cyber Crimes
(4)
Cyber Security
(51)
Cyber Threat
(19)
cyber_news
(30)
Database Hacking
(8)
Defaced
(2)
Dos
(1)
Dos Commands
(1)
Dos Tricks
(2)
Downloads
(7)
E_Books
(8)
Easy Applications
(6)
Email Security
(1)
Emails
(2)
Encryption Tools
(2)
Entrepreneur
(3)
Ethical Hacking Tools
(53)
Ethical Hacking Tutorial
(134)
Ethical Hacking Videos'
(12)
examples
(5)
Exploit
(19)
Facebook
(36)
Fakes
(1)
Featured
(19)
Footprinting
(3)
Gadgets
(20)
Gadgets_news
(14)
games
(3)
Gmail
(5)
Google
(32)
Google Dorks
(2)
Google+
(17)
Hacked
(3)
Hackers
(16)
Hacking
(74)
Hacking News
(4)
Hacking Softwares
(139)
Hacking Techniques
(112)
Hacking Tools
(144)
Hacking_news
(45)
Hacking_terms
(38)
Hackng with Mobile
(4)
Internet_Tricks
(3)
Java-Script Hacks
(1)
Keyloggers
(2)
Keys
(1)
Laptops
(1)
Latest Mobile Phones
(3)
Lecture
(1)
Linux
(6)
Loophole
(10)
Making Applications
(1)
Metasploit
(1)
Mobile
(11)
Mobile Applications
(3)
Mobile_tricks
(15)
Network Security
(6)
news
(50)
Nokia
(2)
Notepad Hacks
(1)
Operating Systems
(11)
Oracle
(1)
Password Cracking
(9)
Pendrive
(3)
penetration testing
(32)
phase_hacking
(9)
phishing
(6)
Photoshop
(11)
Programs
(1)
Protection Tools
(17)
Proxy
(2)
Scripting
(1)
Secure Computing
(38)
Security Bleach
(5)
Seminars_Work Shops_Demo
(5)
SEO
(15)
shell
(2)
shortcuts
(2)
Social Networking
(6)
Software
(70)
source
(4)
source code
(4)
SQL Injection
(9)
System security
(30)
Techie
(4)
Technology
(5)
The Pirate Bay
(1)
Torrent
(1)
Touch
(5)
Ubuntu
(3)
Updates
(2)
Video Tutorials
(4)
Virus
(20)
Vulnerability scanner
(9)
Vulnerable
(11)
Web Security
(13)
Web Traffic
(1)
Wifi Cracking
(2)
Windows
(7)
Windows Xp Tricks
(4)
Wireless hacking
(7)
workshop
(2)
Workshops and Seminars
(2)
worms
(1)
Xss Attack
(2)
Yahoo Messenger
(1)
















