Description: LFI ATTACK WITH FIMAP, target DVWA, arm BACKBOX LINUX.
First
you need to install DVWA*, then run Apache server (comes with BackBox
Linux), then read how to use FIMAP (terminal fimap -h), one c99 shell
script (to find one type inurl:c99.txt in Google search box).You will
need to set Apache directory permissions, for this you can use this bash
script : http://www.linux.re.rs/files/scripts/dirbash.sh. I will show you how to upload shell to vulnerable server and exploit the vulnerability.
Description: URLCrazy is a tool that can generate and test domain
typos and variations to detect and perform typo squatting, URL
hijacking, phishing, and corporate espionage. It generates 15 types of
domain variants, knows over 8000 common misspellings, supports multiple
keyboard layouts, can check if a typo is a valid domain, tests if domain
typos are in use, and estimates the popularity of a typo.
Description: Vega is an open source platform to test the security
of web applications. Vega can help you find and validate SQL
Injections, Cross-Site Scripting (XSS), inadvertently disclosed
sensitive information, and other vulnerabilities. It is written in Java,
GUI based, and runs on Linux, OS X, and Windows.
Description: This official tutorial for DroidSheep for Android shows how to use DroidSheep to capture sessions in your local network.
DroidSheep runs on your Android device and listens to the networks traffic. If it captures a cookie, it shows a list with the cookies and the user can simply use the victims account without knowing his user credentials.
Video The password protection of an iPad 2 running iOS 5 can be circumvented in less than five seconds with just three simple steps.
Bypassing the unlock screen on iPad 2 can be accomplished by first pressing the power button until the power-off screen is displayed. Users then need only to close and reopen the fondleslab's 'smart cover' before, finally, pressing the cancel button to unlock the device.
After dodging the password protection, you can access the foreground application running at the time the device was locked, potentially exposing corporate email in the process. You can't use the home button, so access is limited to foreground applications. As enterprise IT blog BringYourOwnIT.com notes, one obvious workaround would be to instruct users to close any foreground application before locking their iPad.
Below is a video posted by BringYourOwnIT.com illustrating the easy unlock process.
The security weakness comes days after it emerged that locked iPhone 4S could be accessed using Siri, the voice-activated personal assistant built into the device.
There's an easy way for security-conscious users to disable Siri when their phone is locked but this option isn't applied by default, net security firm Sophos
Read More...
Whatever the nature of the disguise used by phishing attacks on Twitter, the modus operandi is always the same. Scammers will send you a message, possibly from the compromised account of one of your Twitter followers, and use a social engineering lure to trick you into clicking on the link.
And that link will, inevitably, lead to a fake Twitter login page - designed to grab your username and password which can then be used to send out more spam, or to break into your other online accounts.
Here's the latest attack, which arrives in the form of a Direct Message (DM) from one of your Twitter pals, claiming that they have searched for you on Google and found some "really funny stuff" about you.
so i googled your name and found some really funny stuff about you lol its archived here [LINK]
Would you click on the link? Well, if you were tempted to do so your web browser would end up on a fake Twitter page just waiting for you to enter your username and password.
And if you do enter your details, you've been phished. Ouch.
Hopefully, you're not one of the many people who use the same password on multiple websites - otherwise cybercriminals might not just be able to send spam from your Twitter account, they may also have just been handed the skeleton keys for other parts of your online existence.
That could mean that scammers can now steal your personal information for financial gain.
If you found your Twitter account was one of those sending out the phishing messages, you shouldn't just change your password and consider if you are using the same password elsewhere. It's also a sensible time to look again at how you choose your passwords.
For instance, it's important that you don't use a word from the dictionary as your password. It's easy to understand why computer users pick dictionary words as they're much easier to remember, but as I explain in this video a good trick is to pick a sentence and just use the first letter of every word to make up your password.
Password security is becoming more important than ever. Make sure that you're taking the issue seriously, or suffer the consequences.
There's some other house-cleaning you should do on your Twitter account too. Visit the Applications tab in "Account Settings", and revoke access for any third-party application that you don't recognise.
Follow me on Twitter if you want to keep up-to-speed with the latest threats, and learn how to protect yourself.
Description: This video shows some of the new features in Armitage for Metasploit 4.1. You'll see improved tab management features, more exploit feedback, VNC, brute forcing, token stealing, and an export data feature to aid reporting. You can learn more about Armitage at rel="nofollow">http://www.fastandeasyhacking.com/
Description: I'm bad at make videos but my cousin help me soon and then we have audio and much more. Okay, so... This is video #1 in "Knube Howto". It is about patching your wireless drivers to work better with aircrack suite of tools. This will get rid of the annoying "channel: loacked -1" on most modern wirelss "things". As I am new to security I and others run into problems which... Plainly put the experts do not cover. So I begin a series of exploration and describing things to knubes such as myself. I hope you enjoy
Description: Fuzzing is a process of sending deliberately malformed data to a program in order to generate failures, or errors in the application. When performed by those in the software exploitation community, fuzzing usually focuses on discovery of bugs that can be exploited to allow an attacker to run their own code, and along with binary and source code analysis fuzzing is one of the primary ways in which exploitable software bugs are discovered.
There are a number of popular and free software based fuzzers available, but during this article we will focus on one of the first fuzzers to become popular within the Information Security community -- SPIKE.
In this part.. i have used pearl to exploit the victim... and used metasploit to investigate the cause of the crash... using the offset finder.. and other cool tools..
Description: Fuzzing is a process of sending deliberately malformed data to a program in order to generate failures, or errors in the application. When performed by those in the software exploitation community, fuzzing usually focuses on discovery of bugs that can be exploited to allow an attacker to run their own code, and along with binary and source code analysis fuzzing is one of the primary ways in which exploitable software bugs are discovered.
There are a number of popular and free software based fuzzers available, but during this article we will focus on one of the first fuzzers to become popular within the Information Security community -- SPIKE.
In this part.. i have used wireshark to analyse what caused it to crash the .exe file..
Description: OsCommerce suffers of few vulnerabilities that can lead an attacker to upload files and execute remote code. What i want to show you is how probably an attacker has infected a site running an old copy of osCommerce to spread malware.
Millions of BlackBerry owners around the world have been feeling the pain this week as messaging and email systems collapsed in a service outage.
With many turning to social networks to vent their anger, and even newspaper cartoonists making fun of the situation, bosses at Research in Motion (RIM) have clearly been feeling the heat.
RIM founder Mike Lazaridis has appeared on video explaining that although services are "approaching normal BlackBerry service levels in Europe, the Middle East, India and Africa" the company can not give an estimated time for systems to have recovered globally.
Lazaridis has also warned that there could be more instability to come. Clearly BlackBerry users aren't entirely out of the woods yet.
Things aren't helped, of course, when nonsensical BlackBerry-related hoax messages are spread. A message has been distributed via BlackBerry Messenger (BBM) claiming that users have to forward the message to all of their contacts, or else their BlackBerry account will be disabled.
Broadcast this message to every single contact on your BBM to reset your display picture, sorry for any inconvenience. This message is to inform all of our users, that our servers have recently been really full, so we are asking for your help to fix this problem. We need our active users to re-send this message to everyone on your contact list in order to confirm our active users that use BlackBerry Messenger, if you do not send this message to all your BlackBerry Messenger contacts then your account will remain inactive with the consequence of losing all your contacts Symbol will automatic update in your BBM ,when you broadcast this message. Your blackberry will be updated within 24 hours it will have a new lay out and a new color for chat.
Of course, the message is nonsense - and it should not be forwarded.
If you need some cheering up, and want a more humorous take on a blackberry not working, check out this sketch by British comedy veteran Ronnie Corbett:
Update: RIM is now reporting that its services are "fully restored." The BBC reports that at a press conference, RIM said they would begin a full investigation into what went wrong and caused the biggest crash in the company's history.
It's impossible to express how sad many people in the technology world feel at the news of the death of Steve Jobs.
Sickeningly, as with the deaths of other figures in the public eye, there are scammers waiting to take advantage of bad news.
Here's a scam we have seen on Facebook, claiming that free iPads are being given away "in memory of Steve Jobs".
In memory of Steve, a company is giving out 50 ipads tonight. R.I.P. Steve Jobs [LINK]
The cool-sounding link sucks you in, tricking you into believing that you may get a free iPad but then goes on to get you to complete online surveys to "qualify".
The link goes through the bit.ly short url service (we have asked our friends at bit.ly to shut the link down) and we can see that over 15,000 people have already clicked on the link which was set up within hours of Steve Jobs's death first being announced.
Of course, if you were one of those people who clicked on the link you may be wondering what the chances are that you will receive a free iPad. I hate to disappoint you, but it's pretty unlikely.
The webpage you are taken to is very similar to ones we have seen pointed to by other scammers. Here's what I saw:
I am writing this article from the Virus Bulletin conference in Barcelona, and you can see that the page has automagically determined where I am in the world and adjusted its language and wording as appropriate.
Below you'll see how the survey pages look if you visit them from Sydney, Australia, for instance.
If you don't click through within a few seconds, it plays an audio message urging you to do so:
You'll notice that the audio message spectacularly fails to mention the 50 free iPads, which have by this time been reduced to the promise of "an exclusive reward", whatever that might be.
My colleague Paul Ducklin captured the audio and - being a fountain of interesting but not always entirely relevant information - tells me that the speaker is an Australian who grew up in South Africa.
When Duck visited the page a second time from Sydney, this is what he saw:
How do the scammers make money? Well, they are earning affiliate cash - in a nutshell, they make more money the more traffic they can direct to websites, driving more people to become customers, or take online surveys and competitions.
Cynically, they exploited the death of Steve Jobs in the hope of driving large numbers of internet users to websites offering content such as contests, surveys and online gambling. The fact is, of course, that they could just as easily have taken those users to a webpage containing malicious code or a phishing page designed to steal credentials.
Chances are that this won't be the only scam we see regarding the untimely death of Steve Jobs. It wouldn't be a surprise, for instance, to see scams which might try to take advantage of those moved by the loss of Apple's founder with lures like "Donate to Steve's favourite charities as a tribute".
If you do want to pay tribute to Steve Jobs, the most appropriate place it seems to me would be Apple's website itself.
The truth is that the scammers are not geniuses like Jobs, and they don't contribute anything to the world of technology or wider society as Steve Jobs did. It's a shame that they can't be inspired by speeches like the one Jobs gave at Stanford University in 2005, and make something better of their lives.
I think that's how we should remember Steve Jobs today.
Starting today, we have implemented a partnership with Facebook, arguably the largest, most important platform on the globe, to better protect users against malicious links leading to malware-embedded websites and fraud.
A platform as popular as Facebook is naturally a target for attackers. We have been working with Facebook and their security teams for a number of years in order to keep their users safe, but now we have integrated directly into the platform for an unprecedented security combination.
Soon, when a user clicks on a URL that has been posted within Facebook, that link will be sent to Websense for security classification. The Websense® ThreatSeeker® Cloud, an advanced classification and malware identification platform, will then analyze the link in real time. If the destination site is considered unsafe, the user is presented with a warning page that offers the choice to continue at their own risk, return to the previous screen, or get more information on why it was flagged as suspicious.
In this way, we are helping Facebook continue their proactive fight to keep malicious links off of their platform and allow safe use for all of its members.
At Websense, we are all about innovation and changing the security game. We were the first company to promote and enable our customers to embrace safe, productive use of social with our web security gateway, the first to deliver security and anti-spam to protect companies presence within Facebook with Defensio, and now we are assisting in the protection of all users on the platform with our cloud integration.
This is the same technology that already powers our industry-leading TRITON™ solutions, and it now extends that same protection to consumers and other users of Facebook.
For more information, you can view the news release here, or check out the infographic below.