<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-2776533298599940650</id><updated>2009-12-06T20:34:43.649-08:00</updated><title type='text'>Hackers Group Of India</title><subtitle type='html'>" THEY MAKE IT,WE BREAK IT "</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default?orderby=updated'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default?start-index=26&amp;max-results=25&amp;orderby=updated'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>150</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-8330427313329711804</id><published>2009-12-02T11:45:00.000-08:00</published><updated>2009-12-02T11:50:58.277-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Turbodiff v1.01 BETA Released – Detect Differences Between Binaries</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;Turbodiff is a binary diffing tool developed as an &lt;/span&gt;&lt;a href="http://www.hex-rays.com/idapro/"&gt;&lt;span style="color:#33ff33;"&gt;IDA plugin&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#33ff33;"&gt;. It discovers and analyzes differences between the functions of two binaries.&lt;br /&gt;&lt;br /&gt;Requirements&lt;br /&gt;&lt;br /&gt;“Turbodiff 1.01 beta release 1″ works with IDA starting from v5.0.&lt;br /&gt;&lt;br /&gt;Instructions&lt;br /&gt;&lt;br /&gt;For the binaries:&lt;br /&gt;Download the plugin and store it at the directory “..\IDA\plugins”.&lt;br /&gt;&lt;br /&gt;If you want to compile it on your own: We have compiled it and tested it using Borland C. For the free version of IDA Pro (4.9) you’ll need to first:&lt;br /&gt;&lt;br /&gt;1.Generate the ida_free.lib library. To do this execute: “implib -c ida_free.lib ida_free.def”&lt;br /&gt;2.Next, you must have the linker use this library.&lt;br /&gt;3.Compile.&lt;br /&gt;Comparing two files:&lt;br /&gt;&lt;br /&gt;1.Open the first file to be compared with IDA and run /Option 1 (take info from this idb)/ from the plugin. Close.&lt;br /&gt;2.Open the second file to be compared with IDA and run /Option 1 (take info from this idb)/ from the plugin.&lt;br /&gt;Use /Option 2 (compare with…)/ from the plugin, and when prompted to select a file, select the first file.&lt;br /&gt;3.Chose if you want a log file to be genreated and run. Once finished a functions table will popup (watch Figure 1) describing results. The results are then saved for later usage.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Turbodiff here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://corelabs.coresecurity.com/index.php?module=Wiki&amp;amp;action=attachment&amp;amp;type=tool&amp;amp;page=turbodiff&amp;amp;file=turbodiff-for-free-ida_v1.0.1b2.zip"&gt;&lt;span style="color:#ffff00;"&gt;IDA PRO v4.9 Sources and plugin&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#ffff00;"&gt; (Free version)&lt;br /&gt;IDA starting with version v5 &lt;/span&gt;&lt;a href="http://corelabs.coresecurity.com/index.php?module=Wiki&amp;amp;action=attachment&amp;amp;type=tool&amp;amp;page=turbodiff&amp;amp;file=turbodiff_v1.0.1b2.zip"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;Sources and plugin&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-8330427313329711804?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/8330427313329711804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=8330427313329711804' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8330427313329711804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8330427313329711804'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/12/turbodiff-v101-beta-released-detect.html' title='Turbodiff v1.01 BETA Released – Detect Differences Between Binaries'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-6830665439478832943</id><published>2009-12-02T11:39:00.000-08:00</published><updated>2009-12-02T11:45:19.828-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Window Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Cain &amp; Abel v4.9.35 – Password Sniffer, Cracker and Brute-Forcing Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Cain &amp;amp; Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, recovering wireless network keys, revealing password boxes, uncovering cached passwords and analyzing routing protocols. The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort. It covers some security aspects/weakness present in protocol’s standards, authentication methods and caching mechanisms; its main purpose is the simplified recovery of passwords and credentials from various sources, however it also ships some “non standard” utilities for Microsoft Windows users.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cain &amp;amp; Abel has been developed in the hope that it will be useful for network administrators, teachers, security consultants/professionals, forensic staff, security software vendors, professional penetration tester and everyone else that plans to use it for ethical reasons. The author will not help or support any illegal activity done with this program. Be warned that there is the possibility that you will cause damages and/or loss of data using this software and that in no events shall the author be liable for such damages or loss of data. Please carefully read the License Agreement included in the program before using it.&lt;br /&gt;&lt;br /&gt;The latest version is faster and contains a lot of new features like APR (Arp Poison Routing) which enables sniffing on switched LANs and Man-in-the-Middle attacks. The sniffer in this version can also analyze encrypted protocols such as SSH-1 and HTTPS, and contains filters to capture credentials from a wide range of authentication mechanisms. The new version also ships routing protocols authentication monitors and routes extractors, dictionary and brute-force crackers for all common hashing algorithms and for several specific authentications, password/hash calculators, cryptanalysis attacks, password decoders and some not so common utilities related to network and system security.&lt;br /&gt;&lt;br /&gt;Most recently added is the support for Windows 2008 Terminal Server in APR-RDP sniffer filter.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Cain &amp;amp; Abel v4.9.35 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;a href="http://www.oxid.it/downloads/ca_setup.exe"&gt;&lt;span style="color:#ffff00;"&gt;ca_setup.exe&lt;/span&gt; &lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-6830665439478832943?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/6830665439478832943/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=6830665439478832943' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6830665439478832943'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6830665439478832943'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/12/cain-abel-v4935-password-sniffer.html' title='Cain &amp; Abel v4.9.35 – Password Sniffer, Cracker and Brute-Forcing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-616772370670850659</id><published>2009-12-02T11:34:00.000-08:00</published><updated>2009-12-02T11:39:35.488-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Cracking'/><title type='text'>Katana v1 (Kyuzo) – Portable Multi-Boot Security Suite</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;The Katana: Portable Multi-Boot Security Suite is designed to fulfill many of your computer security needs. The idea behind this tool is to bring together many of the best security distributions and applications to run from one USB Flash Drive. Instead of keeping track of dozens of CDs and DVDs loaded with your favorite security tools, you can keep them all conveniently in your pocket.&lt;br /&gt;&lt;br /&gt;Katana includes distributions which focus on Penetration Testing, Auditing, Password Cracking, Forensics and Honey Pots. Katana comes with over 100 portable Windows applications, such as Wireshark, HiJackThis, Unstoppable Copier, Firefox, and OllyDBG. It also includes the following distributions:&lt;br /&gt;&lt;br /&gt;•Backtrack 4 pre&lt;br /&gt;•the Ultimate Boot CD&lt;br /&gt;•Ophcrack Live&lt;br /&gt;•Damn Small Linux&lt;br /&gt;•the Ultimate Boot CD for Windows&lt;br /&gt;•Got Root? Slax&lt;br /&gt;•Organizational Systems Wireless Auditor (OSWA) Assistant&lt;br /&gt;•Damn Vulnerable Linux&lt;br /&gt;&lt;br /&gt;Katana is also highly customizable. You can modify Katana by adding or removing distributions and portable apps with ease. You can add functionality to distributions like the Ultimate Boot CD, Got Root? Slax and UBCD4Win. You can also load your personal scripts and documents to keep them conveniently with you on your flash drive to use in concert with the provided tools.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;You can download Katana v1 here:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://mirror.cc.vt.edu/pub/katana/katana-v1.rar"&gt;&lt;span style="color:#ffff00;"&gt;katana-v1.rar &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.hackfromacave.com/torrents/katana-v1.torrent"&gt;&lt;span style="color:#ffff00;"&gt;katana-v1.torrent&lt;/span&gt;&lt;/a&gt;&lt;a href="http://www.hackfromacave.com/torrents/katana-v1.torrent"&gt; &lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-616772370670850659?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/616772370670850659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=616772370670850659' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/616772370670850659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/616772370670850659'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/12/katana-v1-kyuzo-portable-multi-boot.html' title='Katana v1 (Kyuzo) – Portable Multi-Boot Security Suite'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-2718425040758633193</id><published>2009-12-02T11:16:00.000-08:00</published><updated>2009-12-02T11:32:11.382-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Metasploit 3.3 Released! Exploitation Framework</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;What is Metasploit?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Metasploit Framework is a development platform for creating security tools and exploits. The framework is used by network security professionals to perform penetration tests, system administrators to verify patch installations, product vendors to perform regression testing, and security researchers world-wide. The framework is written in the Ruby programming language and includes components written in C and assembler.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;What does it do?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The framework consists of tools, libraries, modules, and user interfaces. The basic function of the framework is a module launcher, allowing the user to configure an exploit module and launch it at a target system. If the exploit succeeds, the payload is executed on the target and the user is provided with a shell to interact with the payload.&lt;br /&gt;&lt;br /&gt;It’s come a long way since it’s early versions and has picked up huge supports from the community.&lt;br /&gt;&lt;br /&gt;•Metasploit now has 445 exploit modules and 216 auxiliary modules (from 320 and 99 respectively in v3.2)&lt;br /&gt;•Metasploit is still about twice the size of the nearest Ruby application according to Ohloh.net (375k lines of Ruby)&lt;br /&gt;•Over 180 tickets were closed during the 3.3 development process &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;br /&gt;&lt;a href="http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_33"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color:#ff0000;"&gt;Full release notes for v3.3 are here.&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Metasploit v3.3 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;Windows – &lt;/em&gt;&lt;/span&gt;&lt;a href="http://www.metasploit.com/releases/framework-3.3.exe"&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;framework-3.3.exe &lt;/em&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;Linux – &lt;/em&gt;&lt;/span&gt;&lt;a href="http://www.metasploit.com/releases/framework-3.3.tar.bz2"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;framework-3.3.tar.bz2&lt;/em&gt;&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-2718425040758633193?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/2718425040758633193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=2718425040758633193' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/2718425040758633193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/2718425040758633193'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/12/metasploit-33-released-exploitation.html' title='Metasploit 3.3 Released! Exploitation Framework'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3139874611610372755</id><published>2009-09-27T13:15:00.000-07:00</published><updated>2009-09-27T13:21:48.671-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Websecurify – Web Security Testing Framework</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Websecurify is a web and web2.0 security initiative specializing in researching security issues and building the next generation of tools to defeat and protect web technologies.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Key Features&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1.JavaScript – Websecurify Security Testing Framework is the first tool of its kind to be written entirely in JavaScript using only standard technologies adopted by the leading browsers.&lt;br /&gt;2.Multiple Environments – The core technology can run in normal browsers, xulrunner, xpcshell (command line), inside Java or as part of a custom V8 (Chrome’s JavaScript Engine) build. The core is written with extensibility in mind so that more environments can be supported without changing even a single line of code.&lt;br /&gt;3.Multi-platform – The tool is available and successfully runs on Windows, Mac OS, Linux and other operating systems.&lt;br /&gt;4.Automatic Updates – Every single piece of the tool is subjected to automatic updates. This means that newer and more advanced versions of the tool can be shipped to your front door without you lifting your finger. This however is completely optional. The automatic update can be turned off if needed.&lt;br /&gt;5.Extensions – Because the tool comes wrapped in xulrunner by default (keep in mind that we can support any other JavaScript environment) we benefit from all cool features that Firefox has, such as extensions. Extensions are easy to write and maintain and can customize every single aspect of the tool and there are already tones of resources and documentation, including books and what not, out there to teach you exactly how to do that. We will be providing documentation as well.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download Websecurify 0.3 here:&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Windows – &lt;/span&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.exe"&gt;&lt;span style="color:#ffff00;"&gt;Websecurify 0.3.exe &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Linux – &lt;/span&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.tgz"&gt;&lt;span style="color:#ffff00;"&gt;Websecurify 0.3.tgz&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#ffff00;"&gt;&lt;br /&gt;Mac – &lt;/span&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.dmg"&gt;&lt;span style="color:#ffff00;"&gt;Websecurify 0.3.dmg&lt;/span&gt;&lt;/a&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.dmg"&gt; &lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3139874611610372755?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3139874611610372755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3139874611610372755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3139874611610372755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3139874611610372755'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/09/websecurify-web-security-testing.html' title='Websecurify – Web Security Testing Framework'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4605380051093900563</id><published>2009-08-03T02:20:00.000-07:00</published><updated>2009-08-03T02:43:34.819-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Database Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><title type='text'>bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;This perl script allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections.&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Bsqlbf first hit the net back in April 2006 with bsqlbf v1.1, then the v2.0 update in June 2008 .This new update adds much better Oracle support.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;color:#ffff00;"&gt;Databases supported:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;•MS-SQL&lt;br /&gt;•MySQL&lt;br /&gt;•PostgreSQL&lt;br /&gt;•Oracle&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:130%;color:#ffff00;"&gt;The 6 Attack Models&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;•Type 0: Blind SQL Injection based on true and false conditions returned by back-end server &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 1: Blind SQL Injection based on true and error(e.g syntax error) returned by back-end server. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 2: Blind SQL Injection in “order by” and “group by”. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 3: extracting data with SYS privileges (ORACLE dbms_export_extension exploit) &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 4: is O.S code execution (ORACLE dbms_export_extension exploit) &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 5: is reading files (ORACLE dbms_export_extension exploit, based on java)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;&lt;span style="font-size:130%;"&gt;New additions&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;-type: Type of injection:&lt;br /&gt;&lt;br /&gt;3: Type 3 is extracting data with DBA privileges&lt;br /&gt;(e.g. Oracle password hashes from sys.user$)&lt;br /&gt;4: Type 4 is O.S code execution(default: ping 127.0.0.1)&lt;br /&gt;5: Type 5 is Reading O.S files(default: c:\boot.ini)&lt;br /&gt;&lt;br /&gt;Type 4 (O.S code execution) supports the following sub types:&lt;br /&gt;&lt;br /&gt;-stype: How you want to execute command:&lt;br /&gt;&lt;br /&gt;0: SType 0 (default) is based on java,&lt;br /&gt;universal but won’t work against XE&lt;br /&gt;1: SType 1 against oracle 9 with plsql_native_make_utility&lt;br /&gt;2: SType 2 against oracle 10 with dbms_scheduler&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download bsqlbf v2.3 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;a href="http://bsqlbf-v2.googlecode.com/files/bsqlbf-v2-3.pl"&gt;&lt;span style="color:#ffff00;"&gt;bsqlbf-v2-3.pl&lt;/span&gt; &lt;/a&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4605380051093900563?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4605380051093900563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4605380051093900563' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605380051093900563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605380051093900563'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/bsqlbf-v23-released-blind-sql-injection.html' title='bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-8689350656500651229</id><published>2009-08-03T02:27:00.000-07:00</published><updated>2009-08-03T02:34:06.466-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Wireshark 1.2.1 Released – Network Protocol Analyzer</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;Wireshark is the world’s foremost network protocol analyzer, and is the de facto (and often de jure) standard across many industries and educational institutions.&lt;br /&gt;&lt;br /&gt;Wireshark development thrives thanks to the contributions of networking experts across the globe. It is the continuation of a project that started in 1998. Many of you will know it as Ethereal.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;&lt;span style="font-size:180%;"&gt;Features&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•Deep inspection of hundreds of protocols, with more being added all the time &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Live capture and offline analysis &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Standard three-pane packet browser &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•The most powerful display filters in the industry &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Rich VoIP analysis &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Capture files compressed with gzip can be decompressed on the fly&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can see the full changelog for version 1.2.1 here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.wireshark.org/docs/relnotes/wireshark-1.2.1.html"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;Wireshark 1.2.1 Release Notes&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download Wireshark 1.2.1 here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#ffff00;"&gt;Windows 32-bit – &lt;/span&gt;&lt;a href="http://wireshark.osmirror.nl/download/win32/wireshark-win32-1.2.1.exe"&gt;&lt;span style="color:#ffff00;"&gt;wireshark-win32-1.2.1.exe &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Source code – &lt;/span&gt;&lt;a href="http://wireshark.osmirror.nl/download/src/wireshark-1.2.1.tar.bz2"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;wireshark-1.2.1.tar.bz2&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-8689350656500651229?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/8689350656500651229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=8689350656500651229' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8689350656500651229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8689350656500651229'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/wireshark-121-released-network-protocol.html' title='Wireshark 1.2.1 Released – Network Protocol Analyzer'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-7740575855969023497</id><published>2009-08-03T01:50:00.000-07:00</published><updated>2009-08-03T02:19:26.385-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Window Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><title type='text'>GFI LANguard 9 Review – Network Security Scanner &amp; Vulnerability Management Tool</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_07QkubFT5Lo/Snaoy8EJ9oI/AAAAAAAAAG0/Q6rsEC_g5ow/s1600-h/3.jpg"&gt;&lt;/a&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;GFI released version 9 of their scanner (&lt;a href="http://www.gfi.com/lannetscan"&gt;&lt;span style="color:#ffff00;"&gt;overview here&lt;/span&gt;&lt;/a&gt;) with improvements to the scanning engine and the interface (including the monitoring dashboard which gives you a good heads-up of the scan results).&lt;br /&gt;&lt;br /&gt;One of the big positives with LANguard was the ability to detect patch levels and automatically roll out patches over the network. This makes it a very comprehensive solution, the recent versions also include checks to ensure 3rd party software such as Anti-virus solutions are also up to date (&lt;a href="http://www.gfi.com/lannetscan/lanscanfeatures.htm"&gt;&lt;span style="color:#ffff00;"&gt;full features here&lt;/span&gt;&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;It’s as easy to install and get up and running as ever, if you do have any issues the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.gfi.com/lanss/lanscan9installation.pdf"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;Installation Guide is here&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;[PDF].&lt;br /&gt;&lt;br /&gt;Getting started with a scan is as easy as clicking 1 button, the interface has been simplified and it’s a lot more attractive . In fact it’s simple enough that non-security IT folks could use it without much problem. &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 188px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5365660396057131874" border="0" alt="" src="http://1.bp.blogspot.com/_07QkubFT5Lo/Snans6Rd-2I/AAAAAAAAAGk/0ooVSaIjgH4/s320/1.jpg" /&gt;&lt;br /&gt;After a scan is complete you have a choice to Analyze or Remediate. The Analysis section will give you fairly detailed instructions on any vulnerabilities found (including a vulnerability level) and full system information including shares, patch levels and so on. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 321px; DISPLAY: block; HEIGHT: 147px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5365661091212577554" border="0" alt="" src="http://2.bp.blogspot.com/_07QkubFT5Lo/SnaoVX7cSxI/AAAAAAAAAGs/efYqY-dujC0/s320/2.jpg" /&gt;&lt;br /&gt;The Remediate section will inform you of missing patches and allow you to apply these. Other than the standard MS patches and service packs you can also deploy 3rd party applications and uninstall rogue software. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 184px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5365662387143037554" border="0" alt="" src="http://1.bp.blogspot.com/_07QkubFT5Lo/SnapgzpV0nI/AAAAAAAAAG8/IN9mIQ2gOdc/s320/3.jpg" /&gt;&lt;br /&gt;Most things in the scanner can be scheduled too so for example if you want to scan outside of office ours or roll out software/patches at the weekend you can set LANguard to do that.&lt;br /&gt;&lt;br /&gt;The dashboard is a nice addition which gives you an overview of the network security and the changes in vulnerabilities over time.&lt;br /&gt;&lt;br /&gt;It also comes with the generic network utilities like Whois, DNS Lookup, Traceroute &amp;amp; SNMP Walk.&lt;br /&gt;&lt;br /&gt;All in all it’s a great tool, especially for those managing Windows based networks. It makes your life a LOT easiest and it makes it easier to manage patches and software across the Domain.&lt;br /&gt;&lt;br /&gt;It’s not a hardcore security tool, which means it also appeals to people more in the Sys Admin &amp;amp; Network areas of the industry. If you have any Windows machines do give it a look, perhaps start with the free version below.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download the latest version here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.gfi.com/downloads/register.aspx?pid=lanss&amp;amp;lid=EN"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;GFI LANguard 9 Download&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.gfi.com/products/gfi-languard/pricing"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;Pricing&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; is done on a per-IP basis with prices starting from around $32USD per IP for a 10-24 IP block. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;&lt;em&gt;There is also a FREE version available here:&lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.gfi.com/lannetscan/free-network-security-scanner"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;GFI LANguard 9 5-IP Freeware edition&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-7740575855969023497?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/7740575855969023497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=7740575855969023497' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7740575855969023497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7740575855969023497'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/gfi-languard-9-review-network-security.html' title='GFI LANguard 9 Review – Network Security Scanner &amp; Vulnerability Management Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_07QkubFT5Lo/Snans6Rd-2I/AAAAAAAAAGk/0ooVSaIjgH4/s72-c/1.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-1568548950525353288</id><published>2009-08-03T01:39:00.000-07:00</published><updated>2009-08-03T01:50:02.308-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber News'/><category scheme='http://www.blogger.com/atom/ns#' term='Articles'/><title type='text'>Chinese Firm Writes First SMS Worm</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Once again China is at the forefront! A group of Chinese companies has managed to develop the first SMS worm!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;"&lt;/span&gt; Three Chinese companies — XiaMen Jinlonghuatian Technology, ShenZhen ChenGuangWuXian Technology, and XinZhongLi TianJin — created the &lt;span style="color:#ff0000;"&gt;‘Sexy Space’&lt;/span&gt; worms or Yxe Worm (Worm:SymbOS/Yxe.D) and submitted to Symbian OS-based phones through the express signing procedure, said F-Secure Security Labs recently.&lt;br /&gt;&lt;br /&gt;“The worm is the first text message worm in history,” said Chia Wing Fei, security response senior manager at F-Secure. “Our labs have received few confirmed reports from China and Middle East at the moment.”&lt;br /&gt;&lt;br /&gt;The first stage of Symbian’s signing process is done automatically using an antivirus engine, said Chia, adding that once an application has been submitted and scanned, random samples are then submitted for human audit.&lt;br /&gt;&lt;br /&gt;However, most applications are not inspected by humans through the express signing procedure, he noted.&lt;br /&gt;&lt;br /&gt;An attacker can therefore put a web link pointing to the worm’s web site into a text message and invite the user to download the worm by clicking the link, Chia said. Once activated, the worm will install itself on the device, and send a similar text messages to all phonebook contacts listed, he added.&lt;br /&gt;&lt;br /&gt;“These messages are sent in your name and from your phone. It means you will pay for each SMS sent by the worm. A typical cost for a single text message might be 5 cents. If you have 500 contacts in your phone, an infection would cost you 500 times 5 cents,” Chia noted. &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:180%;"&gt;"&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Source: &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.networkworld.com/news/2009/072709-f-secure-chinese-firms-write-worlds.html"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Network World&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-1568548950525353288?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/1568548950525353288/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=1568548950525353288' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1568548950525353288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1568548950525353288'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/chinese-firm-writes-first-sms-worm.html' title='Chinese Firm Writes First SMS Worm'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-2580769177844863184</id><published>2009-08-03T01:08:00.000-07:00</published><updated>2009-08-03T01:37:44.470-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Database Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux Hacking'/><title type='text'>sqlmap 0.7 Released – Automatic SQL Injection Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications.&lt;br /&gt;&lt;br /&gt;Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user’s specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color:#ffff00;"&gt;Recent Changes&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;Along all the takeover features introduced in sqlmap 0.7 release candidate 1, some of the new features include:&lt;br /&gt;&lt;br /&gt;•Adapted Metasploit wrapping functions to work with latest 3.3 development version too.&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;br /&gt;•Adjusted code to make sqlmap 0.7 to work again on Mac OSX too. &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Reset takeover OOB features (if any of –os-pwn, –os-smbrelay or –os-bof is selected) when running under Windows because msfconsole and msfcli are not supported on the native Windows Ruby interpreter. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•This make sqlmap 0.7 to work again on Windows too. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Minor improvement so that sqlmap tests also all parameters with no value (eg. par=). &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•HTTPS requests over HTTP proxy now work on either Python 2.4, 2.5 and 2.6+.&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;For a complete list of changes view the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://sqlmap.sourceforge.net/doc/ChangeLog"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;ChangeLog&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The manual is available here – &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://sqlmap.sourceforge.net/doc/README.pdf"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;README.pdf &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;[PDF]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download sqlmap 0.7 here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;Linux Source: &lt;/em&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7.tar.gz"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;&lt;em&gt;sqlmap-0.7.tar.gz &lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;&lt;em&gt;Windows Portable: &lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7_exe.zip"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;sqlmap-0.7_exe.zip&lt;/em&gt;&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-2580769177844863184?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/2580769177844863184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=2580769177844863184' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/2580769177844863184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/2580769177844863184'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/sqlmap-is-open-source-command-line.html' title='sqlmap 0.7 Released – Automatic SQL Injection Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4500013113824356628</id><published>2009-07-21T01:55:00.000-07:00</published><updated>2009-07-21T02:07:43.062-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Window Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux Hacking'/><title type='text'>Kon-Boot – Reset Windows &amp; Linux Passwords</title><content type='html'>&lt;div align="justify"&gt;&lt;font color="#33ff33" face="arial"&gt;&lt;strong&gt;Kon-Boot is an prototype piece of software which allows to change contents of a Linux kernel (and now Windows kernel also!!!) on the fly (while booting).&lt;br /&gt;&lt;br /&gt;In the current compilation state it allows to log into a Linux system as ’root’ user without typing the correct password or to elevate privileges from current user to root. For Windows systems it allows to enter any password protected profile without any knowledge of the password.&lt;br /&gt;&lt;br /&gt;It was mainly created for Ubuntu, later the author has made a few add-ons to cover some other Linux distributions.&lt;br /&gt;&lt;br /&gt;Entire Kon-Boot was written in pure x86 assembly, using old grandpa-geezer TASM 4.0.&lt;br /&gt;&lt;br /&gt;Latest Updates – Kon-Boot for Windows&lt;br /&gt;&lt;br /&gt;Kon-Boot was moved to Windows platforms. So now it provides support for Microsoft Windows systems and also the Linux systems listed below. Kon-Boot for Windows enables logging in to any password protected machine profile without without any knowledge of the password. This tool changes the contents of Windows kernel while booting, everything is done virtually – without any interferences with physical system changes. So far following systems were tested to work correctly with Kon-Boot:&lt;br /&gt;&lt;br /&gt;   •Windows Server 2008 Standard SP2 (v.275)&lt;br /&gt;   •Windows Vista Business SP0&lt;br /&gt;   •Windows Vista Ultimate SP1&lt;br /&gt;   •Windows Vista Ultimate SP0&lt;br /&gt;   •Windows Server 2003 Enterprise&lt;br /&gt;   •Windows XP&lt;br /&gt;   •Windows XP SP1&lt;br /&gt;   •Windows XP SP2&lt;br /&gt;   •Windows XP SP3&lt;br /&gt;   •Windows 7&lt;br /&gt;&lt;br /&gt;No special usage instructions are required for Windows users, just boot from Kon-Boot CD/Floppy, select your profile and put any password you want. You lost your password? Now it doesnt matter at all.&lt;br /&gt;&lt;br /&gt;It has been tested with the following Linux distributions:&lt;br /&gt;&lt;br /&gt;   •Gentoo 2.6.24-gentoo-r5 GRUB 0.97&lt;br /&gt;   •Ubuntu 2.6.24.3-debug GRUB 0.97&lt;br /&gt;   •Debian 2.6.18-6-6861 GRUB 0.97&lt;br /&gt;   •Fedora 2.6.25.9-76.fc9.i6862 GRUB 0.97 &lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;font face="arial"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;font color="#33ff33"&gt;&lt;em&gt;&lt;font color="#ff6600"&gt;You can download Kon-Boot here:&lt;/font&gt;&lt;/em&gt;&lt;br /&gt;&lt;/font&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;font color="#ffff00"&gt;Floppy Image – &lt;/font&gt;&lt;a href="http://www.piotrbania.com/all/kon-boot/data/FD0-konboot-v1.1-2in1.zip"&gt;&lt;font color="#ffff00"&gt;FD0-konboot-v1.1-2in1.zip &lt;/font&gt;&lt;/a&gt;&lt;br /&gt;&lt;font color="#ffff00"&gt;CD ISO Image – &lt;/font&gt;&lt;a href="http://www.piotrbania.com/all/kon-boot/data/CD-konboot-v1.1-2in1.zip"&gt;&lt;font color="#ffff00"&gt;CD-konboot-v1.1-2in1.zip &lt;/font&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4500013113824356628?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4500013113824356628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4500013113824356628' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4500013113824356628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4500013113824356628'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/kon-boot-is-prototype-piece-of-software.html' title='Kon-Boot – Reset Windows &amp; Linux Passwords'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3032260576602314496</id><published>2009-07-21T01:47:00.000-07:00</published><updated>2009-07-21T01:54:00.374-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>The Middler – User Session Cloning &amp; MITM Tool</title><content type='html'>&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;The Middler is a Man in the Middle tool to demonstrate protocol middling attacks. Led by Jay Beale, the project involves a team of authors including InGuardians agents Justin Searle and Matt Carpenter. The Middler is intended to man in the middle, or “middle” for short, every protocol for which we can create code.&lt;br /&gt;&lt;br /&gt;The current codebase is in the alpha state, but a beta release is coming soon, with better documentation , easier installation, and even more plug-ins.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ffff00;"&gt;Plug-ins&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;•plugin-beef.py – inject the Browser Exploitation Framework (BeEF) into any HTTP requests originating on the local LAN&lt;br /&gt;•plugin-metasploit.py – inject an IFRAME into cleartext (HTTP) requests that loads Metasploit browser exploits&lt;br /&gt;•plugin-keylogger.py – inject a JavaScript? onKeyPress event handler to cleartext forms that get submitted via HTTPS, forcing the browser to send the password character-by-character to the attacker’s server, before the form is submitted.&lt;br /&gt;The author team has done a tremendous amount of research, design and pseudo-code work, fleshing out attacks on web-based e-mail systems and social networking sites.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ffff00;"&gt;Dependencies&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Middler depends on the following Python modules:&lt;br /&gt;&lt;br /&gt;•scapy&lt;br /&gt;•libpcap&lt;br /&gt;•readline&lt;br /&gt;•libdnet&lt;br /&gt;•beautifulsoup &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download The Middler here:&lt;br /&gt;&lt;/span&gt;&lt;/em&gt;&lt;a href="http://inguardians.com/tools/middler-alpha-2009022301.tgz"&gt;&lt;span style="color:#ffff00;"&gt;middler-alpha-2009022301.tgz&lt;/span&gt; &lt;/a&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3032260576602314496?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3032260576602314496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3032260576602314496' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3032260576602314496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3032260576602314496'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/middler-user-session-cloning-mitm-tool.html' title='The Middler – User Session Cloning &amp; MITM Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4298926931210704584</id><published>2009-07-21T01:41:00.000-07:00</published><updated>2009-07-21T01:47:16.322-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>MultiISO LiveDVD v1.0 – BackTrack, Knoppix &amp; Ophcrack</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;MultiISO LiveDVD is an integrated Live DVD technology which combines some of the very popular Live CD ISOs already available on the internet. It can be used for security reconnaissance, vulnerability identification, penetration testing, system rescue, media center and multimedia, system recovery, etc. It’s a all-in-one multipurpose LiveDVD put together. There’s something in it for everyone.&lt;br /&gt;&lt;br /&gt;MultiISO LiveDVD Version 1.0 consists of:&lt;br /&gt;&lt;br /&gt;•Backtrack 3&lt;br /&gt;•Damn Small Linux (DSL) 4.2.5&lt;br /&gt;•GeeXboX 1.1&lt;br /&gt;•Damn Vulnerable Linux (Strychnine) 1.4 edition&lt;br /&gt;•Knoppix 5.1.1, MPentoo 2006.1&lt;br /&gt;•Ophcrack 1.2.2 (remastered to contain SSTIC04-5k [720MB] table sets)&lt;br /&gt;•Puppy Linux 3.01&lt;br /&gt;•Byzantine OS i586-20040404&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download MultiISO LiveDVD here (to conserve bandwidth only a Torrent link is available, please seed after downloading):&lt;/span&gt;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Torrent: &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://badfoo.net/linux/EmErgEs_MultiBOOT_ISO.torrent.torrent"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;EmErgEs_MultiBOOT_ISO.torrent &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;(4.03GB)&lt;br /&gt;&lt;br /&gt;MD5SUM: 1b1f37ed6b6f958cde0529a8a1f06637&lt;br /&gt;SHA1SUM: 593ffbfa3c4b665220dcd63b2e4b77bacde5237d&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4298926931210704584?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4298926931210704584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4298926931210704584' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4298926931210704584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4298926931210704584'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/multiiso-livedvd-v10-backtrack-knoppix.html' title='MultiISO LiveDVD v1.0 – BackTrack, Knoppix &amp; Ophcrack'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3647587043967343329</id><published>2009-07-21T01:25:00.000-07:00</published><updated>2009-07-21T01:31:40.330-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Damn Vulnerable Web App – Learn &amp; Practise Web Hacking</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be light weight, easy to use and full of vulnerabilities to exploit. Used to learn or teach the art of web application security.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="color:#ffff00;"&gt;Vulnerabilities&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•SQL Injection&lt;br /&gt;•XSS (Cross Site Scripting)&lt;br /&gt;•LFI (Local File Inclusion)&lt;br /&gt;•RFI (Remote File Inclusion) &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;•Command Execution &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;•Upload Script&lt;br /&gt;•Login Brute Force&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="color:#ffff00;"&gt;Changes &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•Added Acunetix scan report.&lt;br /&gt;•All links use http://hiderefer.com to hide referrer header.&lt;br /&gt;•Updated/added ‘more info’ links.&lt;br /&gt;•Moved change log info to CHANGELOG.txt.&lt;br /&gt;•Fixed the exec.php UTF-8 output.&lt;br /&gt;•Moved Help/View source buttons to footer.&lt;br /&gt;•Fixed phpInfo bug.&lt;br /&gt;•Made DVWA IE friendly.&lt;br /&gt;•Fixed html bugs.&lt;br /&gt;•Improved README.txt and fixed typos.&lt;br /&gt;•Made SQL injection possible in sqli_med.php. &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="font-size:180%;"&gt;WARNING&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;em&gt;It should come as no shock..but this application is damn vulnerable! Do not upload it to your hosting provider’s public html folder or any working web server as it will be hacked. It’s recommend that you download and install XAMP onto a local machine inside your LAN which is used solely for testing.&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download DVWA 1.0.4 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/dvwa/files/dvwa/dvwa_v1.0.4.zip/download"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;dvwa_v1.0.4.zip&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3647587043967343329?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3647587043967343329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3647587043967343329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3647587043967343329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3647587043967343329'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/damn-vulnerable-web-app-learn-practise.html' title='Damn Vulnerable Web App – Learn &amp; Practise Web Hacking'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-6734639496966064425</id><published>2009-07-21T01:07:00.000-07:00</published><updated>2009-07-21T01:23:58.375-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><title type='text'>bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;This perl script allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Databases supported:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•MS-SQL&lt;br /&gt;•MySQL&lt;br /&gt;•PostgreSQL&lt;br /&gt;•Oracle &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; &lt;/div&gt;&lt;/strong&gt;&lt;/span&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color:#ffff00;"&gt;&lt;span style="font-size:180%;"&gt;The 6 Attack Models&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;•Type 0: Blind SQL Injection based on true and false conditions returned by back-end server&lt;br /&gt;•Type 1: Blind SQL Injection based on true and error(e.g syntax error) returned by back-end server.&lt;br /&gt;•Type 2: Blind SQL Injection in “order by” and “group by”.&lt;br /&gt;•Type 3: extracting data with SYS privileges (ORACLE dbms_export_extension exploit)&lt;br /&gt;•Type 4: is O.S code execution (ORACLE dbms_export_extension exploit)&lt;br /&gt;•Type 5: is reading files (ORACLE dbms_export_extension exploit, based on java)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ffff00;"&gt;New additions&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-type: Type of injection:&lt;br /&gt;&lt;br /&gt;3: Type 3 is extracting data with DBA privileges&lt;br /&gt;(e.g. Oracle password hashes from sys.user$)&lt;br /&gt;4: Type 4 is O.S code execution(default: ping 127.0.0.1)&lt;br /&gt;5: Type 5 is Reading O.S files(default: c:\boot.ini)&lt;br /&gt;&lt;br /&gt;Type 4 (O.S code execution) supports the following sub types:&lt;br /&gt;&lt;br /&gt;-stype: How you want to execute command:&lt;br /&gt;&lt;br /&gt;0: SType 0 (default) is based on java,&lt;br /&gt;universal but won’t work against XE&lt;br /&gt;1: SType 1 against oracle 9 with plsql_native_make_utility&lt;br /&gt;2: SType 2 against oracle 10 with dbms_scheduler&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download bsqlbf v2.3 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://bsqlbf-v2.googlecode.com/files/bsqlbf-v2-3.pl"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;bsqlbf-v2-3.pl&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-6734639496966064425?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/6734639496966064425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=6734639496966064425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6734639496966064425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6734639496966064425'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/bsqlbf-v23-released-blind-sql-injection.html' title='bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3006856733827318487</id><published>2009-05-18T12:03:00.000-07:00</published><updated>2009-05-18T12:27:12.624-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Fiddler - Web Debugging Proxy For HTTP(S)</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Fiddler&lt;/span&gt; is a Web Debugging Proxy which logs all HTTP(S) traffic between your computer and the Internet. Fiddler allows you to inspect all HTTP(S) traffic, set breakpoints, and “fiddle” with incoming or outgoing data. Fiddler includes a powerful event-based scripting subsystem, and can be extended using any .NET language. &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 397px; DISPLAY: block; HEIGHT: 267px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5337243236801486578" border="0" alt="" src="http://2.bp.blogspot.com/_07QkubFT5Lo/ShGycilonvI/AAAAAAAAAF8/ZeMkd6A9SGw/s320/hgi1.jpg" /&gt;&lt;br /&gt;Fiddler is freeware and can debug traffic from virtually any application, including Internet Explorer, Mozilla Firefox, Opera, and thousands more.&lt;br /&gt;&lt;br /&gt;If you want some info on how to use Fiddler for debugging you can check here: &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Fiddler Can Make Debugging Easy&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Fiddler here:&lt;br /&gt;&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Fiddler2Setup.exe&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3006856733827318487?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3006856733827318487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3006856733827318487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3006856733827318487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3006856733827318487'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/fiddler-web-debugging-proxy-for-https.html' title='Fiddler - Web Debugging Proxy For HTTP(S)'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_07QkubFT5Lo/ShGycilonvI/AAAAAAAAAF8/ZeMkd6A9SGw/s72-c/hgi1.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-1595480674416452960</id><published>2009-05-18T11:56:00.000-07:00</published><updated>2009-05-18T12:02:37.980-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><title type='text'>FBController - The Ultimate Utility to Control Facebook Accounts</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Just to put a downer on all the script kiddies, this utility WILL NOT hack/crack Facebook passwords or accounts.&lt;br /&gt;&lt;br /&gt;You need to feed it biscuits (cookies) before you can do anything.&lt;br /&gt;&lt;br /&gt;You can get the target’s cookie by sniffing, XSS, social engineering, ARP Poison-Sniffing, &lt;a href="http://www.scroogle.org/"&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="color:#ffff00;"&gt;Scroogle&lt;/span&gt; &lt;/span&gt;&lt;/a&gt; search or however you like.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once you have the cookies you can use FBController to have Full control over the target’s Facebook account.&lt;br /&gt;&lt;br /&gt;Login to your Facebook account and sniff your own cookie OR collect a few live Facebook Biscuit/s of your Target/s.&lt;br /&gt;&lt;br /&gt;Till now FBController version 1.0 uses your Target’s provided cookie and only :&lt;br /&gt;&lt;br /&gt;A &gt; Downloads the HomePage.&lt;br /&gt;B &gt; Allows you to Update the Target’s Wall and&lt;br /&gt;C &gt; Retrieve your Target’s Friend’s List&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There are many APIs available to write apps and 3rd party Tools for FB in Java, Perl, .NET, etc.&lt;br /&gt;&lt;br /&gt;FBConTroller was entirely written without knowing any of Facebook’s Dev API’s. Considering the above along with Facebook’s complexity, the next version might take some time to get released&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download FBController here:&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;FBConTroller.RAR&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-1595480674416452960?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/1595480674416452960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=1595480674416452960' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1595480674416452960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1595480674416452960'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/fbcontroller-ultimate-utility-to.html' title='FBController - The Ultimate Utility to Control Facebook Accounts'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-8726505718699483333</id><published>2009-05-18T11:49:00.000-07:00</published><updated>2009-05-18T11:54:21.791-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Durzosploit v0.1 - JavaScript Exploit Generation Framework</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Durzosploit&lt;/span&gt; is a JavaScript exploit generation framework that works through the console. This goal of that project is to quickly and easily generate working exploits for cross-site scripting vulnerabilities in popular web applications or web sites.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Please note that Durzosploit does not find browser vulnerabilities, it only is an framework containing exploits you can use.&lt;br /&gt;&lt;br /&gt;At present there aren’t many exploits:&lt;br /&gt;&lt;br /&gt;•twitter.com/update_status - Updates a target’s status&lt;br /&gt;•twitter.com/update_settings - Updates your target’s settings&lt;br /&gt;•facebook.com/what_is_on_your_mind - Write your message in your target’s mind&lt;br /&gt;•drupal/edit_user_profile - Drupal 6.x - edit the profile of the user&lt;br /&gt;•drupal/logout - Drupal 6.x - makes target logout&lt;br /&gt;So far the author’s focus has been on the framework itself; allowing people to quickly write their exploits and adding some automated obfuscators.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Durzosploit provides some obfuscators to automatically pack/minify your generated exploit.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download the latest version from the Durzosploit SVN here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;svn co svn://www.engineeringforfun.com/svn/durzosploit/trunk&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-8726505718699483333?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/8726505718699483333/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=8726505718699483333' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8726505718699483333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8726505718699483333'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/durzosploit-v01-javascript-exploit.html' title='Durzosploit v0.1 - JavaScript Exploit Generation Framework'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-5974858071999064154</id><published>2009-05-18T11:43:00.000-07:00</published><updated>2009-05-18T11:47:36.825-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Pangolin - Automatic SQL Injection Tool</title><content type='html'>&lt;p align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Pangolin&lt;/span&gt; is an automatic SQL injection penetration testing tool developed by NOSEC. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user’s specific DBMS tables/columns, run his own SQL statement, read specific files on the file system and more.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Database Support&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;•Access: Informations (Database Path; Root Path; Drivers); Data&lt;br /&gt;•MSSql: Informations; Data; FileReader; RegReader; FileWriter; Cmd; DirTree&lt;br /&gt;•MySql: Informations; Data; FileReader; FileWriter;&lt;br /&gt;•Oracle: Inforatmions (Version; IP; Database; Accounts ……); Data; and any others;&lt;br /&gt;•Informix: Informatons; Data&lt;br /&gt;•DB2: Informatons; Data; and more;&lt;br /&gt;•Sybase: Informatons; Data; and more;&lt;br /&gt;•PostgreSQL: Informatons; Data; FileReader;&lt;br /&gt;•Sqlite: Informatons; Data&lt;br /&gt;&lt;br /&gt;At present, most of the functions are directed at MSSQL and MySql coupled with Oracle and Access. Other small and medium-sized companies are using DB2, Informix, Sybase, PostgreSQL, as well as Sqlite which isn’t so common.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Pangolin here: &lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;pangolin_free_edition_2.1.2.924.rar (Download Page)&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-5974858071999064154?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/5974858071999064154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=5974858071999064154' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5974858071999064154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5974858071999064154'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/pangolin-automatic-sql-injection-tool.html' title='Pangolin - Automatic SQL Injection Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4083077089931728360</id><published>2009-05-18T11:39:00.000-07:00</published><updated>2009-05-18T11:43:22.436-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Samurai Web Testing Framework 0.6 Released - Web Application Security LiveCD</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;" The authors of Samurai have updated and fixed a number of issues with the environment as well as improved performance of the java based tools. They have also included a virtual machine of the environment. This VM requires VMWare. "&lt;br /&gt;&lt;br /&gt;For those that don’t know, Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. There are tools used in all four steps of a web pen-test.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;&lt;strong&gt;You can download SamuraiWTF 0.6 here:&lt;br /&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;samurai-0.6.iso&lt;/span&gt;&lt;/strong&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4083077089931728360?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4083077089931728360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4083077089931728360' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4083077089931728360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4083077089931728360'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/samurai-web-testing-framework-06.html' title='Samurai Web Testing Framework 0.6 Released - Web Application Security LiveCD'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4605374314161966865</id><published>2009-04-22T14:30:00.001-07:00</published><updated>2009-04-22T14:38:00.952-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Charles Web Debugging Proxy - HTTP Monitor &amp; Reverse Proxy</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;&lt;strong&gt;Charles is an HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP traffic between their machine and the Internet. This includes requests, responses and the HTTP headers (which contain the cookies and caching information).&lt;br /&gt;&lt;br /&gt;Charles can act as a man-in-the-middle for HTTP/SSL communication, enabling you to debug the content of your HTTPS sessions.&lt;br /&gt;&lt;br /&gt;Charles simulates modem speeds by effectively throttling your bandwidth and introducing latency, so that you can experience an entire website as a modem user might (bandwidth simulator).&lt;br /&gt;&lt;br /&gt;Charles is especially useful for Adobe Flash developers as you can view the contents of LoadVariables, LoadMovie and XML loads. Charles also has native support for Flash Remoting (AMF0 and AMF3).&lt;br /&gt;&lt;br /&gt;Charles is also useful for XML development in web browsers, such as AJAX (Asynchronous Javascript and XML) and XMLHTTP, as it enables you to see the actual XML that is flowing between the client and the server. Charles natively supports JSON, JSON-RPC and SOAP; displaying each in a simplified tree format for easy viewing and debugging.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download Charles Proxy here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Windows - charles_setup.exe&lt;br /&gt;Linux / Unix - charles.tar.gz&lt;br /&gt;Mac OS X - charles_macosx.zip&lt;/span&gt;&lt;/strong&gt;&lt;strong&gt;&lt;/strong&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4605374314161966865?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4605374314161966865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4605374314161966865' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605374314161966865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605374314161966865'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/04/charles-web-debugging-proxy-http.html' title='Charles Web Debugging Proxy - HTTP Monitor &amp; Reverse Proxy'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-7003374011265214432</id><published>2009-04-22T14:22:00.000-07:00</published><updated>2009-04-22T14:30:02.969-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Cracking'/><title type='text'>EFIPW - Modify Apple EFI Firmware Passwords</title><content type='html'>&lt;p&gt;&lt;strong&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;EFIPW is a tool that can be used to decode and modify Apple EFI firmware passwords via the command line. It is designed after the non open source OFPW utility and is designed to work on Intel machines running Leopard or newer. Useful for lab deployments (setting the firmware password of machines as a post install item) and pen tests (recovering the EFI firmware password).&lt;br /&gt;&lt;br /&gt;Tested on:&lt;br /&gt;•Core Duo (1st gen) Macbook Pro 15″&lt;br /&gt;•Core 2 Duo Macbook Pro 15″ &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;strong&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;p&gt;Technical details on how it works here.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download EFIPW v0.1a here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;efipw_v0.1a.zip&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-7003374011265214432?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/7003374011265214432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=7003374011265214432' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7003374011265214432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7003374011265214432'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/04/efipw-modify-apple-efi-firmware.html' title='EFIPW - Modify Apple EFI Firmware Passwords'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-6624734687456317268</id><published>2008-11-25T05:20:00.000-08:00</published><updated>2008-11-25T05:29:55.959-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>ike-scan - IPsec VPN Scanning, Fingerprinting and Testing Tool</title><content type='html'>&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;ike-scan is a command-line tool for discovering, fingerprinting and testing IPsec VPN systems. It constructs and sends IKE Phase-1 packets to the specified hosts, and displays any responses that are received.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;br /&gt;ike-scan allows you to:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Send IKE packets to any number of destination hosts, using a configurable output bandwidth or packet rate. (This is useful for VPN detection, when you may need to scan large address spaces.) &lt;/li&gt;&lt;li&gt;Construct the outgoing IKE packet in a flexible way. (This includes IKE packets which do not comply with the RFC requirements.) &lt;/li&gt;&lt;li&gt;Decode and display any returned packets. &lt;/li&gt;&lt;li&gt;Crack aggressive mode pre-shared keys. (You can use ike-scan to obtain the PSK hash data, and then use psk-crack to obtain the key.) &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;You can read more in depth about ike-scan and how to use it - in the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/wiki/index.php/Ike-scan_User_Guide"&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;User Guide&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;ike-scan is free software, licensed under the GPL. It runs on Windows, Linux and most Unix systems. If you don’t already have ike-scan installed on your system, read the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/wiki/index.php/Ike-scan_Installation_Guide"&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;installation guide&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;p&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download ike-scan 1.9 here:&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#ffff00;"&gt;Source distribution: &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/tools/ike-scan/download/ike-scan-1.9.tar.gz"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;ike-scan-1.9.tar.gz&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;Windows binary: &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/tools/ike-scan/download/ike-scan-win32-1.9.zip"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;ike-scan-win32-1.9.zip&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-6624734687456317268?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/6624734687456317268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=6624734687456317268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6624734687456317268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6624734687456317268'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/11/ike-scan-ipsec-vpn-scanning.html' title='ike-scan - IPsec VPN Scanning, Fingerprinting and Testing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-732233319028823510</id><published>2008-11-25T05:12:00.000-08:00</published><updated>2008-11-25T05:19:55.233-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Browser Rider - Web Browser Exploitation Framework</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Browser Rider is a hacking framework to build payloads that exploit the browser. The project aims to provide a powerful, simple and flexible interface to any client side exploit.&lt;br /&gt;Browser Rider is not a new concept. Similar tools such as &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;BeEF&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; or &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Backframe&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; exploited the same concept. However most of the other existing tools out there are unmaintained, not updated and not documented. Browser Rider wants to fill those gaps by providing a better alternative.&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-size:130%;color:#ff6600;"&gt;Features&lt;/span&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;Easily create powerful payloads and plugins &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Manage payloads automatically with plugins &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;All data can be saved in a database &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Obfuscation &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Polymorphism &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Control more than one zombie at a time &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Simple administration panel &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="justify"&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;Requirements&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;PHP 5, with json installed &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Mysql &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Apache with url_rewrite on &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Targets must have Javascript turned on &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="justify"&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Browser Rider here:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;p align="justify"&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.engineeringforfun.com/cave/browserrider/BrowserRider.20081124.tar.bz2"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;Browser Rider v20081124&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt; (&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.engineeringforfun.com/wiki/index.php/Browser_Rider_Changelog#Browser_Rider_v20081124"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;changelog&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-732233319028823510?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/732233319028823510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=732233319028823510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/732233319028823510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/732233319028823510'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/11/browser-rider-web-browser-exploitation.html' title='Browser Rider - Web Browser Exploitation Framework'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-1580229789329888296</id><published>2008-10-26T13:09:00.000-07:00</published><updated>2008-11-25T05:11:40.350-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>XSS-Proxy - Cross Site Scripting Attack Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:130%;color:#ff6600;"&gt;XSS-Proxy&lt;/span&gt; is an advanced Cross-Site-Scripting (XSS) attack tool. The documents, tools and other content on this site assume you have a basic understanding of &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;XSS&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; issues and existing exploitation methods. If you are not famliar with XSS, then I recommend you check out the primer links/docs below to get a better of idea of what XSS is and how to detect it, fix it, and exploit it.&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.cert.org/advisories/CA-2000-02.html"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;CERT info on XSS&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href="http://www.cgisecurity.com/articles/xss-faq.shtml"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;CGISecurity’s Cross Site Scripting FAQ&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.technicalinfo.net/papers/CSS.html"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;Gunter Ollmann’s XSS paper&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.securityfocus.com/archive/1/191390"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;PeterW’s Cross Site Request Forgery (CSRF) Concept&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.securenet.de/papers/Session_Riding.pdf"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;SecureNet’s Session Riding paper&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Some Common Misconceptions about XSS&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;“A user has to click a link to be impacted by XSS.” No - if you visit a page that has&lt;br /&gt;stuff_to_run your browser will run it regardless of you clicking a link. I carefully crafted this example so it would not be run by your browser, but I could have put real script tags/commands here and made you run then transparently.&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;“XSS only matters with bulliten boards, blogs, and other sites where an attacker can upload script content.” That is one way the attack can happen, but an attacker can also leverage sites that allow HTML/SCRIPT tags to be reflected back to the same user (like a search form that repeats what it was told to look for in the response). These flaws are commonly combined with public site redirects or emails to attack a second site. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;“Don’t XSS attacks just create popup windows, alerts and other pesky things?” No - They are commonly used to reveal your cookies or form based login info to attackers. After havesting this info, the attacker uses it to log into the same site as you. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;“I understand XSS, but I don’t think it’s a huge issue“. I think you’ll change your mind once you understand this advanced attack. Read the advanced stuff below and play with XSS-Proxy to see how evil XSS really can be. &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="justify"&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download XSS-Proxy here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/project/showfiles.php?group_id=130402&amp;amp;package_id=142941&amp;amp;release_id=545299"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;XSS-Proxy_0_0_12-book.pl&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-1580229789329888296?l=hackersgroupofindia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/1580229789329888296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=1580229789329888296' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1580229789329888296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1580229789329888296'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/10/xss-proxy-cross-site-scripting-attack.html' title='XSS-Proxy - Cross Site Scripting Attack Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>