RSS

Tutorial Hackin9

Video : advance LFI

Video : http://www.mediafire.com/?csk8n405n181hx5

PHP filesystem attack vectors

http://www.ush.it/2009/02/08/php-filesystem-attack-vectors/ <—- link cho các bạn kham thảo :)

nội dung chủ yếu xoay quanh vấn đề :

(more…)

VN:F [1.9.3_1094]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)

SQL Column Truncation

Lâu quá không post bài, nay post 1 bug nhỏ nhưng cũng khá nhiều coder mắc phải,tuy nhỏ nhưng không nhỏ nếu biết kết hợp nhiều bug lại với nhau
ok, tên bug là SQL Column Truncation.Tớ có một table user với 2 column như sau :
Field Type
username varchar(10)
password varchar(32)
tớ insert vào 2 giá trị : (more…)

VN:F [1.9.3_1094]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)
09 August 2010 | Tips & Tricks,Tutorial Hackin9 | | 0 Comments   

Acunetix Web Vulnerability Scanner updated 6/7/2010

acunetix web vulnerability scanner
Acunetix là một công cụ cực kỳ hữu ích dành cho :
  • Các webmaster để kiểm tra lỗi cho ứng dụng web của mình
  • Các nhà quản trị server dùng để kiểm lỗi cho ứng dụng web chạy trên server để đưa ra các cảnh báo kịp thời cho các webmaster Acunetix có thể hổ trợ bạn.
  • Tìm kiếm lỗi của một website: SQL Injection, XSS…
  • Tìm kiếm cấu trúc của một website.
  • Tìm kiếm lỗi của server chứa website và các thông tin liên quan đến server của website.
  • Báo cáo cũng như gợi ý chỉnh sửa các lỗi của website.
  • Lưu các kết quả báo cáo cho việc fix lỗi sau này.
  • Lập lịch tiến hành scan lỗi cho website.
  • Cùng nhiều công cụ hổ trợ fix lỗi website khác.
VN:F [1.9.3_1094]
Rating: 7.0/10 (3 votes cast)
VN:F [1.9.3_1094]
Rating: +1 (from 1 vote)

Acunetix Web Vulnerability Scanner Enterprise Edition v6.5.20090917

Một tool quá nỗi tiếng, chắc không có gì để giới thiệu nhiều về tool này, bạn nào cần thì google để tìm thêm các thông tin nhé.

Update version v6.5 2010/07/06 : http://www.mediafire.com/?icapdgt44d95t7n
Password unzip : 123456

(more…)

VN:F [1.9.3_1094]
Rating: 10.0/10 (1 vote cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)

SSHatter SSH Brute Forcer

SSHatter is an SSH brute force utility available from http://freshmeat.net/projects/sshatter/?branch_id=70781&release_id=263196. Essentially the tool is comprised of a small Perl file. The utility requires a few non-standard Perl libraries but these are easily installed. You must have Perl installed to use SSHatter.

Installing SSHatter

First download and unpack the tool:

$ wget http://freshmeat.net/urls/4545c53ceab532b77fcfe92e075a6828
$ tar -xvzf SSHatter-0.6.tar.gz
SSHatter-0.6/
SSHatter-0.6/src/
SSHatter-0.6/src/INSTALL
SSHatter-0.6/src/SSHatter.pl
SSHatter-0.6/src/passwords
SSHatter-0.6/src/TODO
SSHatter-0.6/src/md5.asc
$ cd SSHatter-0.6/src (more…)

VN:F [1.9.3_1094]
Rating: 10.0/10 (1 vote cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)

Hakin9 – Hard Core IT Security Magazine

Hakin9 - Hard Core IT Security Magazine

Hakin9 - Hard Core IT Security Magazine

About hakin9

hakin9 is bimonthly magazine about hacking and IT security, covering techniques of breaking into computer systems, defence and protection methods. Our magazine is useful for all those interested in hacking – both professionals (system administrators, security specialists) and hobbyists. The magazine is published in other countries and language versions:

  • in English(in the USA, Australia, Holland, Singapore),
  • in German (in Germany, Austria, Switzerland, Luxembourg and Belgium),
  • in French (in France, Canada, Luxembourg, Belgium, Marocco),
  • in Spanish (in Spain, Argentina, Portugal, Mexico),
  • in Italian (in Italy),
  • in Czech (in Czech Republic and Slovakia),
  • in Polish (in Poland).

hakin9 offers an in-depth look at both attack and defense techniques and concentrates on difficult technical issues.

hakin9‘s target readers are those responsible for IT system security, programmers, security specialists, professional administrators, as well as people taking up security issues in their free time.

NEW! hakin9 starterkit bimonthly magazine is step-by-step guide to hacker techniques. It covers basic techniques of breaking into computer systems. This magazine starts with entry level examples of the most popular security topics.
More details here

hakin9 is published by Software-Wydawnictwo Sp. z o. o.
Editors: hakin9 team
Editorial Advisory Board: Clement Dupuis, Matt Jonkman, Jay Ranade, Terron Williams, Shyaam Sundhar R. S.
Translators: Marek Szuba
Proofreaders: Kelley Dawson, Nicholas Potter, Dustin F. Leer
Top Betatesters: Steven Roddis, Steve Lape, Sieng Chye Oh, Satish Chandra, Roderick Lucas, Richard Chamberlain, Rene Heinzl, Renato Borseti, Petko Petkov, Peter Howe, Paul Bakker, Pastor Adrian, Pablo Fernandez, Juan Bidini, Stavros Lekkas, Jan Feyereisl, Johan Ericsson, J.Ignacio Toledo, Felipe Lora, Wendel Guglielmetti Henrique, David Stow, Alicia Asin Perez, Andrej Bielko, Antonio Merola, Carl Sampson, Clancey McNeal, Damian Szewczyk

Postal address: Software-Wydawnictwo Sp. z.o.o ul. Bokserska 1, 02-682 Warsaw, Poland

Whilst every effort has been made to ensure the high quality of the magazine, the editors make no warranty, express or implied, concerning the results of content usage.
All trade marks presented in the magazine were used only for informative purposes. All rights to trade marks presented in the magazine are reserved by the companies which own them.

DISCLAIMER!
The techniques described in our articles may only be used in private, local networks. The editors hold no responsibility for misuse of the presented techniques or consequent data loss.

Software-Wydawnictwo Sp z o.o. is looking for partners from all over the World. If you are interested in cooperating with us, please contact us by email.

Hakin9′s issue cover (5/2009) – 21st Century Hacking Techniques

21st Century Hacking Techniques

21st Century Hacking Techniques

  • Windows Timeline Analysis…
  • Analyzing Malware Introduction to Advanced Topics…
  • Hacking ASLR & Stack Canaries on Modern Linux…
  • Mashup Security…
  • My ERP Got Hacked – An Introduction to Computer Forensics, Part II…
  • First Password Shooters…
  • RSA & AES in JAVA…
  • AV Scanner 101…
  • The Underworld of CVV Dumping…
  • It’s All About Reputation…
  • Interview with Andrey Belenko…
  • DefenseWall Pure Policy-Based Sandbox Application…
  • Interview with Alexandre Dulaunoy & Fred Arbogast…
VN:F [1.9.3_1094]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)

Extract username from /etc/passwd file

In the previous publication I had pointed to the passwd file , a few days ago , I saw a person discussing about secluding the users from the binary file indicated . you might know the structure of passwd file :

AAAAAA:x:1156:1156::/home/AAAA:/usr/local/cpanel/bin/noshell
BBBBBB:x:1157:1157::/home/BBBB:/usr/local/cpanel/bin/noshell
CCCCCC:x:1158:1158::/home/CCCC:/usr/local/cpanel/bin/noshell (more…)

VN:F [1.9.3_1094]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)

Slowloris Apache HTTP DoS

Ngay sau khi tool http DoS slowloris release http://ha.ckers.org/slowloris/ đã có mod_antiloris release.

Trước khi cài mod antiloris thử khai thác lỗi này thì hầu như các server chạy apache mà k0 có hình thức bảo về thi đều bị “đơ” cả. Lý do apache giới hạn max_client. trong khi loris gửi tới server những http request k0 hoàn chỉnh, apache phải wait cho http request này time out, default là 120s ( build cho CentOS). Nếu loris gửi liên tục các request này tới webserver thì chỉ trong vài giây apache đã đạt max_client, từ chống phục vụ các client khác. (more…)

VN:F [1.9.3_1094]
Rating: 10.0/10 (1 vote cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)

ORACLE SQL Injection

// SQL Injection Notes for Oracle Db systems //

In ORACLE you can not just SELECT stuff you have to SELECT them from some table. For this purpose you can use special table called DUAL.

i.e. SELECT ‘dummydata’ || ‘x’ FROM DUAL;

You have to close comments if you used /* comment */ style comments (more…)

VN:F [1.9.3_1094]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)

Restores carries out xp_cmdshell

The common situation restores carries out xp_cmdshell.

1. has not been able to find the memory process ‘ master. .xpcmdshell’.
Restores the method: After inquiry separator connection,
The first step execution: EXEC sp_addextendedproc xp_cmdshell,@dllname = ‘ xplog70.dll’declare @o int
The second step execution: sp_addextendedproc ‘xp_cmdshell’, ‘xpsql70.dll’
Then pressed the F5 key order execution to finish (more…)

VN:F [1.9.3_1094]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.3_1094]
Rating: 0 (from 0 votes)
Page 1 of 3123»