<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-2776533298599940650</id><updated>2009-10-13T03:39:08.557-07:00</updated><title type='text'>Hackers Group Of India</title><subtitle type='html'>" THEY MAKE IT,WE BREAK IT "</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default?start-index=26&amp;max-results=25'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>146</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3139874611610372755</id><published>2009-09-27T13:15:00.000-07:00</published><updated>2009-09-27T13:21:48.671-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Websecurify – Web Security Testing Framework</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Websecurify is a web and web2.0 security initiative specializing in researching security issues and building the next generation of tools to defeat and protect web technologies.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Key Features&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1.JavaScript – Websecurify Security Testing Framework is the first tool of its kind to be written entirely in JavaScript using only standard technologies adopted by the leading browsers.&lt;br /&gt;2.Multiple Environments – The core technology can run in normal browsers, xulrunner, xpcshell (command line), inside Java or as part of a custom V8 (Chrome’s JavaScript Engine) build. The core is written with extensibility in mind so that more environments can be supported without changing even a single line of code.&lt;br /&gt;3.Multi-platform – The tool is available and successfully runs on Windows, Mac OS, Linux and other operating systems.&lt;br /&gt;4.Automatic Updates – Every single piece of the tool is subjected to automatic updates. This means that newer and more advanced versions of the tool can be shipped to your front door without you lifting your finger. This however is completely optional. The automatic update can be turned off if needed.&lt;br /&gt;5.Extensions – Because the tool comes wrapped in xulrunner by default (keep in mind that we can support any other JavaScript environment) we benefit from all cool features that Firefox has, such as extensions. Extensions are easy to write and maintain and can customize every single aspect of the tool and there are already tones of resources and documentation, including books and what not, out there to teach you exactly how to do that. We will be providing documentation as well.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download Websecurify 0.3 here:&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Windows – &lt;/span&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.exe"&gt;&lt;span style="color:#ffff00;"&gt;Websecurify 0.3.exe &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Linux – &lt;/span&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.tgz"&gt;&lt;span style="color:#ffff00;"&gt;Websecurify 0.3.tgz&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#ffff00;"&gt;&lt;br /&gt;Mac – &lt;/span&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.dmg"&gt;&lt;span style="color:#ffff00;"&gt;Websecurify 0.3.dmg&lt;/span&gt;&lt;/a&gt;&lt;a href="http://websecurify.googlecode.com/files/Websecurify%200.3.dmg"&gt; &lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3139874611610372755?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3139874611610372755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3139874611610372755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3139874611610372755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3139874611610372755'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/09/websecurify-web-security-testing.html' title='Websecurify – Web Security Testing Framework'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-8689350656500651229</id><published>2009-08-03T02:27:00.000-07:00</published><updated>2009-08-03T02:34:06.466-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Wireshark 1.2.1 Released – Network Protocol Analyzer</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;Wireshark is the world’s foremost network protocol analyzer, and is the de facto (and often de jure) standard across many industries and educational institutions.&lt;br /&gt;&lt;br /&gt;Wireshark development thrives thanks to the contributions of networking experts across the globe. It is the continuation of a project that started in 1998. Many of you will know it as Ethereal.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;&lt;span style="font-size:180%;"&gt;Features&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•Deep inspection of hundreds of protocols, with more being added all the time &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Live capture and offline analysis &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Standard three-pane packet browser &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Multi-platform: Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Captured network data can be browsed via a GUI, or via the TTY-mode TShark utility &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•The most powerful display filters in the industry &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Rich VoIP analysis &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Capture files compressed with gzip can be decompressed on the fly&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can see the full changelog for version 1.2.1 here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.wireshark.org/docs/relnotes/wireshark-1.2.1.html"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;Wireshark 1.2.1 Release Notes&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download Wireshark 1.2.1 here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#ffff00;"&gt;Windows 32-bit – &lt;/span&gt;&lt;a href="http://wireshark.osmirror.nl/download/win32/wireshark-win32-1.2.1.exe"&gt;&lt;span style="color:#ffff00;"&gt;wireshark-win32-1.2.1.exe &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Source code – &lt;/span&gt;&lt;a href="http://wireshark.osmirror.nl/download/src/wireshark-1.2.1.tar.bz2"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;wireshark-1.2.1.tar.bz2&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-8689350656500651229?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/8689350656500651229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=8689350656500651229' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8689350656500651229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8689350656500651229'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/wireshark-121-released-network-protocol.html' title='Wireshark 1.2.1 Released – Network Protocol Analyzer'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4605380051093900563</id><published>2009-08-03T02:20:00.000-07:00</published><updated>2009-08-03T02:43:34.819-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Database Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><title type='text'>bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;This perl script allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections.&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Bsqlbf first hit the net back in April 2006 with bsqlbf v1.1, then the v2.0 update in June 2008 .This new update adds much better Oracle support.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;color:#ffff00;"&gt;Databases supported:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;•MS-SQL&lt;br /&gt;•MySQL&lt;br /&gt;•PostgreSQL&lt;br /&gt;•Oracle&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:130%;color:#ffff00;"&gt;The 6 Attack Models&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;•Type 0: Blind SQL Injection based on true and false conditions returned by back-end server &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 1: Blind SQL Injection based on true and error(e.g syntax error) returned by back-end server. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 2: Blind SQL Injection in “order by” and “group by”. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 3: extracting data with SYS privileges (ORACLE dbms_export_extension exploit) &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 4: is O.S code execution (ORACLE dbms_export_extension exploit) &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Type 5: is reading files (ORACLE dbms_export_extension exploit, based on java)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;&lt;span style="font-size:130%;"&gt;New additions&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;-type: Type of injection:&lt;br /&gt;&lt;br /&gt;3: Type 3 is extracting data with DBA privileges&lt;br /&gt;(e.g. Oracle password hashes from sys.user$)&lt;br /&gt;4: Type 4 is O.S code execution(default: ping 127.0.0.1)&lt;br /&gt;5: Type 5 is Reading O.S files(default: c:\boot.ini)&lt;br /&gt;&lt;br /&gt;Type 4 (O.S code execution) supports the following sub types:&lt;br /&gt;&lt;br /&gt;-stype: How you want to execute command:&lt;br /&gt;&lt;br /&gt;0: SType 0 (default) is based on java,&lt;br /&gt;universal but won’t work against XE&lt;br /&gt;1: SType 1 against oracle 9 with plsql_native_make_utility&lt;br /&gt;2: SType 2 against oracle 10 with dbms_scheduler&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download bsqlbf v2.3 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;a href="http://bsqlbf-v2.googlecode.com/files/bsqlbf-v2-3.pl"&gt;&lt;span style="color:#ffff00;"&gt;bsqlbf-v2-3.pl&lt;/span&gt; &lt;/a&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4605380051093900563?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4605380051093900563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4605380051093900563' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605380051093900563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605380051093900563'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/bsqlbf-v23-released-blind-sql-injection.html' title='bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-7740575855969023497</id><published>2009-08-03T01:50:00.000-07:00</published><updated>2009-08-03T02:19:26.385-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Window Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><title type='text'>GFI LANguard 9 Review – Network Security Scanner &amp; Vulnerability Management Tool</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_07QkubFT5Lo/Snaoy8EJ9oI/AAAAAAAAAG0/Q6rsEC_g5ow/s1600-h/3.jpg"&gt;&lt;/a&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;GFI released version 9 of their scanner (&lt;a href="http://www.gfi.com/lannetscan"&gt;&lt;span style="color:#ffff00;"&gt;overview here&lt;/span&gt;&lt;/a&gt;) with improvements to the scanning engine and the interface (including the monitoring dashboard which gives you a good heads-up of the scan results).&lt;br /&gt;&lt;br /&gt;One of the big positives with LANguard was the ability to detect patch levels and automatically roll out patches over the network. This makes it a very comprehensive solution, the recent versions also include checks to ensure 3rd party software such as Anti-virus solutions are also up to date (&lt;a href="http://www.gfi.com/lannetscan/lanscanfeatures.htm"&gt;&lt;span style="color:#ffff00;"&gt;full features here&lt;/span&gt;&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;It’s as easy to install and get up and running as ever, if you do have any issues the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.gfi.com/lanss/lanscan9installation.pdf"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;Installation Guide is here&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;[PDF].&lt;br /&gt;&lt;br /&gt;Getting started with a scan is as easy as clicking 1 button, the interface has been simplified and it’s a lot more attractive . In fact it’s simple enough that non-security IT folks could use it without much problem. &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 188px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5365660396057131874" border="0" alt="" src="http://1.bp.blogspot.com/_07QkubFT5Lo/Snans6Rd-2I/AAAAAAAAAGk/0ooVSaIjgH4/s320/1.jpg" /&gt;&lt;br /&gt;After a scan is complete you have a choice to Analyze or Remediate. The Analysis section will give you fairly detailed instructions on any vulnerabilities found (including a vulnerability level) and full system information including shares, patch levels and so on. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 321px; DISPLAY: block; HEIGHT: 147px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5365661091212577554" border="0" alt="" src="http://2.bp.blogspot.com/_07QkubFT5Lo/SnaoVX7cSxI/AAAAAAAAAGs/efYqY-dujC0/s320/2.jpg" /&gt;&lt;br /&gt;The Remediate section will inform you of missing patches and allow you to apply these. Other than the standard MS patches and service packs you can also deploy 3rd party applications and uninstall rogue software. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 184px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5365662387143037554" border="0" alt="" src="http://1.bp.blogspot.com/_07QkubFT5Lo/SnapgzpV0nI/AAAAAAAAAG8/IN9mIQ2gOdc/s320/3.jpg" /&gt;&lt;br /&gt;Most things in the scanner can be scheduled too so for example if you want to scan outside of office ours or roll out software/patches at the weekend you can set LANguard to do that.&lt;br /&gt;&lt;br /&gt;The dashboard is a nice addition which gives you an overview of the network security and the changes in vulnerabilities over time.&lt;br /&gt;&lt;br /&gt;It also comes with the generic network utilities like Whois, DNS Lookup, Traceroute &amp;amp; SNMP Walk.&lt;br /&gt;&lt;br /&gt;All in all it’s a great tool, especially for those managing Windows based networks. It makes your life a LOT easiest and it makes it easier to manage patches and software across the Domain.&lt;br /&gt;&lt;br /&gt;It’s not a hardcore security tool, which means it also appeals to people more in the Sys Admin &amp;amp; Network areas of the industry. If you have any Windows machines do give it a look, perhaps start with the free version below.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download the latest version here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.gfi.com/downloads/register.aspx?pid=lanss&amp;amp;lid=EN"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;GFI LANguard 9 Download&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.gfi.com/products/gfi-languard/pricing"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;Pricing&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; is done on a per-IP basis with prices starting from around $32USD per IP for a 10-24 IP block. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;&lt;em&gt;There is also a FREE version available here:&lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.gfi.com/lannetscan/free-network-security-scanner"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;GFI LANguard 9 5-IP Freeware edition&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-7740575855969023497?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/7740575855969023497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=7740575855969023497' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7740575855969023497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7740575855969023497'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/gfi-languard-9-review-network-security.html' title='GFI LANguard 9 Review – Network Security Scanner &amp; Vulnerability Management Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_07QkubFT5Lo/Snans6Rd-2I/AAAAAAAAAGk/0ooVSaIjgH4/s72-c/1.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-1568548950525353288</id><published>2009-08-03T01:39:00.000-07:00</published><updated>2009-08-03T01:50:02.308-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber News'/><category scheme='http://www.blogger.com/atom/ns#' term='Articles'/><title type='text'>Chinese Firm Writes First SMS Worm</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Once again China is at the forefront! A group of Chinese companies has managed to develop the first SMS worm!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;"&lt;/span&gt; Three Chinese companies — XiaMen Jinlonghuatian Technology, ShenZhen ChenGuangWuXian Technology, and XinZhongLi TianJin — created the &lt;span style="color:#ff0000;"&gt;‘Sexy Space’&lt;/span&gt; worms or Yxe Worm (Worm:SymbOS/Yxe.D) and submitted to Symbian OS-based phones through the express signing procedure, said F-Secure Security Labs recently.&lt;br /&gt;&lt;br /&gt;“The worm is the first text message worm in history,” said Chia Wing Fei, security response senior manager at F-Secure. “Our labs have received few confirmed reports from China and Middle East at the moment.”&lt;br /&gt;&lt;br /&gt;The first stage of Symbian’s signing process is done automatically using an antivirus engine, said Chia, adding that once an application has been submitted and scanned, random samples are then submitted for human audit.&lt;br /&gt;&lt;br /&gt;However, most applications are not inspected by humans through the express signing procedure, he noted.&lt;br /&gt;&lt;br /&gt;An attacker can therefore put a web link pointing to the worm’s web site into a text message and invite the user to download the worm by clicking the link, Chia said. Once activated, the worm will install itself on the device, and send a similar text messages to all phonebook contacts listed, he added.&lt;br /&gt;&lt;br /&gt;“These messages are sent in your name and from your phone. It means you will pay for each SMS sent by the worm. A typical cost for a single text message might be 5 cents. If you have 500 contacts in your phone, an infection would cost you 500 times 5 cents,” Chia noted. &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:180%;"&gt;"&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Source: &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.networkworld.com/news/2009/072709-f-secure-chinese-firms-write-worlds.html"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Network World&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-1568548950525353288?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/1568548950525353288/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=1568548950525353288' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1568548950525353288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1568548950525353288'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/chinese-firm-writes-first-sms-worm.html' title='Chinese Firm Writes First SMS Worm'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-2580769177844863184</id><published>2009-08-03T01:08:00.000-07:00</published><updated>2009-08-03T01:37:44.470-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Database Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux Hacking'/><title type='text'>sqlmap 0.7 Released – Automatic SQL Injection Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications.&lt;br /&gt;&lt;br /&gt;Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user’s specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color:#ffff00;"&gt;Recent Changes&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;Along all the takeover features introduced in sqlmap 0.7 release candidate 1, some of the new features include:&lt;br /&gt;&lt;br /&gt;•Adapted Metasploit wrapping functions to work with latest 3.3 development version too.&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;br /&gt;•Adjusted code to make sqlmap 0.7 to work again on Mac OSX too. &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Reset takeover OOB features (if any of –os-pwn, –os-smbrelay or –os-bof is selected) when running under Windows because msfconsole and msfcli are not supported on the native Windows Ruby interpreter. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•This make sqlmap 0.7 to work again on Windows too. &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•Minor improvement so that sqlmap tests also all parameters with no value (eg. par=). &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;•HTTPS requests over HTTP proxy now work on either Python 2.4, 2.5 and 2.6+.&lt;br /&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;div align="justify"&gt;For a complete list of changes view the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://sqlmap.sourceforge.net/doc/ChangeLog"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;ChangeLog&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The manual is available here – &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://sqlmap.sourceforge.net/doc/README.pdf"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;README.pdf &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;[PDF]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download sqlmap 0.7 here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;Linux Source: &lt;/em&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7.tar.gz"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;&lt;em&gt;sqlmap-0.7.tar.gz &lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;&lt;em&gt;Windows Portable: &lt;/em&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7_exe.zip"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;&lt;em&gt;sqlmap-0.7_exe.zip&lt;/em&gt;&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-2580769177844863184?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/2580769177844863184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=2580769177844863184' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/2580769177844863184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/2580769177844863184'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/08/sqlmap-is-open-source-command-line.html' title='sqlmap 0.7 Released – Automatic SQL Injection Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4500013113824356628</id><published>2009-07-21T01:55:00.000-07:00</published><updated>2009-07-21T02:07:43.062-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Window Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux Hacking'/><title type='text'>Kon-Boot – Reset Windows &amp; Linux Passwords</title><content type='html'>&lt;div align="justify"&gt;&lt;font color="#33ff33" face="arial"&gt;&lt;strong&gt;Kon-Boot is an prototype piece of software which allows to change contents of a Linux kernel (and now Windows kernel also!!!) on the fly (while booting).&lt;br /&gt;&lt;br /&gt;In the current compilation state it allows to log into a Linux system as ’root’ user without typing the correct password or to elevate privileges from current user to root. For Windows systems it allows to enter any password protected profile without any knowledge of the password.&lt;br /&gt;&lt;br /&gt;It was mainly created for Ubuntu, later the author has made a few add-ons to cover some other Linux distributions.&lt;br /&gt;&lt;br /&gt;Entire Kon-Boot was written in pure x86 assembly, using old grandpa-geezer TASM 4.0.&lt;br /&gt;&lt;br /&gt;Latest Updates – Kon-Boot for Windows&lt;br /&gt;&lt;br /&gt;Kon-Boot was moved to Windows platforms. So now it provides support for Microsoft Windows systems and also the Linux systems listed below. Kon-Boot for Windows enables logging in to any password protected machine profile without without any knowledge of the password. This tool changes the contents of Windows kernel while booting, everything is done virtually – without any interferences with physical system changes. So far following systems were tested to work correctly with Kon-Boot:&lt;br /&gt;&lt;br /&gt;   •Windows Server 2008 Standard SP2 (v.275)&lt;br /&gt;   •Windows Vista Business SP0&lt;br /&gt;   •Windows Vista Ultimate SP1&lt;br /&gt;   •Windows Vista Ultimate SP0&lt;br /&gt;   •Windows Server 2003 Enterprise&lt;br /&gt;   •Windows XP&lt;br /&gt;   •Windows XP SP1&lt;br /&gt;   •Windows XP SP2&lt;br /&gt;   •Windows XP SP3&lt;br /&gt;   •Windows 7&lt;br /&gt;&lt;br /&gt;No special usage instructions are required for Windows users, just boot from Kon-Boot CD/Floppy, select your profile and put any password you want. You lost your password? Now it doesnt matter at all.&lt;br /&gt;&lt;br /&gt;It has been tested with the following Linux distributions:&lt;br /&gt;&lt;br /&gt;   •Gentoo 2.6.24-gentoo-r5 GRUB 0.97&lt;br /&gt;   •Ubuntu 2.6.24.3-debug GRUB 0.97&lt;br /&gt;   •Debian 2.6.18-6-6861 GRUB 0.97&lt;br /&gt;   •Fedora 2.6.25.9-76.fc9.i6862 GRUB 0.97 &lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;font face="arial"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;font color="#33ff33"&gt;&lt;em&gt;&lt;font color="#ff6600"&gt;You can download Kon-Boot here:&lt;/font&gt;&lt;/em&gt;&lt;br /&gt;&lt;/font&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;font color="#ffff00"&gt;Floppy Image – &lt;/font&gt;&lt;a href="http://www.piotrbania.com/all/kon-boot/data/FD0-konboot-v1.1-2in1.zip"&gt;&lt;font color="#ffff00"&gt;FD0-konboot-v1.1-2in1.zip &lt;/font&gt;&lt;/a&gt;&lt;br /&gt;&lt;font color="#ffff00"&gt;CD ISO Image – &lt;/font&gt;&lt;a href="http://www.piotrbania.com/all/kon-boot/data/CD-konboot-v1.1-2in1.zip"&gt;&lt;font color="#ffff00"&gt;CD-konboot-v1.1-2in1.zip &lt;/font&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4500013113824356628?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4500013113824356628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4500013113824356628' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4500013113824356628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4500013113824356628'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/kon-boot-is-prototype-piece-of-software.html' title='Kon-Boot – Reset Windows &amp; Linux Passwords'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3032260576602314496</id><published>2009-07-21T01:47:00.000-07:00</published><updated>2009-07-21T01:54:00.374-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>The Middler – User Session Cloning &amp; MITM Tool</title><content type='html'>&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;The Middler is a Man in the Middle tool to demonstrate protocol middling attacks. Led by Jay Beale, the project involves a team of authors including InGuardians agents Justin Searle and Matt Carpenter. The Middler is intended to man in the middle, or “middle” for short, every protocol for which we can create code.&lt;br /&gt;&lt;br /&gt;The current codebase is in the alpha state, but a beta release is coming soon, with better documentation , easier installation, and even more plug-ins.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ffff00;"&gt;Plug-ins&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;•plugin-beef.py – inject the Browser Exploitation Framework (BeEF) into any HTTP requests originating on the local LAN&lt;br /&gt;•plugin-metasploit.py – inject an IFRAME into cleartext (HTTP) requests that loads Metasploit browser exploits&lt;br /&gt;•plugin-keylogger.py – inject a JavaScript? onKeyPress event handler to cleartext forms that get submitted via HTTPS, forcing the browser to send the password character-by-character to the attacker’s server, before the form is submitted.&lt;br /&gt;The author team has done a tremendous amount of research, design and pseudo-code work, fleshing out attacks on web-based e-mail systems and social networking sites.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ffff00;"&gt;Dependencies&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The Middler depends on the following Python modules:&lt;br /&gt;&lt;br /&gt;•scapy&lt;br /&gt;•libpcap&lt;br /&gt;•readline&lt;br /&gt;•libdnet&lt;br /&gt;•beautifulsoup &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download The Middler here:&lt;br /&gt;&lt;/span&gt;&lt;/em&gt;&lt;a href="http://inguardians.com/tools/middler-alpha-2009022301.tgz"&gt;&lt;span style="color:#ffff00;"&gt;middler-alpha-2009022301.tgz&lt;/span&gt; &lt;/a&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3032260576602314496?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3032260576602314496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3032260576602314496' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3032260576602314496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3032260576602314496'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/middler-user-session-cloning-mitm-tool.html' title='The Middler – User Session Cloning &amp; MITM Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4298926931210704584</id><published>2009-07-21T01:41:00.000-07:00</published><updated>2009-07-21T01:47:16.322-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>MultiISO LiveDVD v1.0 – BackTrack, Knoppix &amp; Ophcrack</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;MultiISO LiveDVD is an integrated Live DVD technology which combines some of the very popular Live CD ISOs already available on the internet. It can be used for security reconnaissance, vulnerability identification, penetration testing, system rescue, media center and multimedia, system recovery, etc. It’s a all-in-one multipurpose LiveDVD put together. There’s something in it for everyone.&lt;br /&gt;&lt;br /&gt;MultiISO LiveDVD Version 1.0 consists of:&lt;br /&gt;&lt;br /&gt;•Backtrack 3&lt;br /&gt;•Damn Small Linux (DSL) 4.2.5&lt;br /&gt;•GeeXboX 1.1&lt;br /&gt;•Damn Vulnerable Linux (Strychnine) 1.4 edition&lt;br /&gt;•Knoppix 5.1.1, MPentoo 2006.1&lt;br /&gt;•Ophcrack 1.2.2 (remastered to contain SSTIC04-5k [720MB] table sets)&lt;br /&gt;•Puppy Linux 3.01&lt;br /&gt;•Byzantine OS i586-20040404&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download MultiISO LiveDVD here (to conserve bandwidth only a Torrent link is available, please seed after downloading):&lt;/span&gt;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Torrent: &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://badfoo.net/linux/EmErgEs_MultiBOOT_ISO.torrent.torrent"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;EmErgEs_MultiBOOT_ISO.torrent &lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;(4.03GB)&lt;br /&gt;&lt;br /&gt;MD5SUM: 1b1f37ed6b6f958cde0529a8a1f06637&lt;br /&gt;SHA1SUM: 593ffbfa3c4b665220dcd63b2e4b77bacde5237d&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4298926931210704584?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4298926931210704584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4298926931210704584' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4298926931210704584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4298926931210704584'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/multiiso-livedvd-v10-backtrack-knoppix.html' title='MultiISO LiveDVD v1.0 – BackTrack, Knoppix &amp; Ophcrack'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3647587043967343329</id><published>2009-07-21T01:25:00.000-07:00</published><updated>2009-07-21T01:31:40.330-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Damn Vulnerable Web App – Learn &amp; Practise Web Hacking</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be light weight, easy to use and full of vulnerabilities to exploit. Used to learn or teach the art of web application security.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="color:#ffff00;"&gt;Vulnerabilities&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•SQL Injection&lt;br /&gt;•XSS (Cross Site Scripting)&lt;br /&gt;•LFI (Local File Inclusion)&lt;br /&gt;•RFI (Remote File Inclusion) &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;•Command Execution &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;•Upload Script&lt;br /&gt;•Login Brute Force&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="color:#ffff00;"&gt;Changes &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•Added Acunetix scan report.&lt;br /&gt;•All links use http://hiderefer.com to hide referrer header.&lt;br /&gt;•Updated/added ‘more info’ links.&lt;br /&gt;•Moved change log info to CHANGELOG.txt.&lt;br /&gt;•Fixed the exec.php UTF-8 output.&lt;br /&gt;•Moved Help/View source buttons to footer.&lt;br /&gt;•Fixed phpInfo bug.&lt;br /&gt;•Made DVWA IE friendly.&lt;br /&gt;•Fixed html bugs.&lt;br /&gt;•Improved README.txt and fixed typos.&lt;br /&gt;•Made SQL injection possible in sqli_med.php. &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="font-size:180%;"&gt;WARNING&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;em&gt;It should come as no shock..but this application is damn vulnerable! Do not upload it to your hosting provider’s public html folder or any working web server as it will be hacked. It’s recommend that you download and install XAMP onto a local machine inside your LAN which is used solely for testing.&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download DVWA 1.0.4 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/dvwa/files/dvwa/dvwa_v1.0.4.zip/download"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;dvwa_v1.0.4.zip&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3647587043967343329?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3647587043967343329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3647587043967343329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3647587043967343329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3647587043967343329'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/damn-vulnerable-web-app-learn-practise.html' title='Damn Vulnerable Web App – Learn &amp; Practise Web Hacking'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-6734639496966064425</id><published>2009-07-21T01:07:00.000-07:00</published><updated>2009-07-21T01:23:58.375-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><title type='text'>bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;This perl script allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Databases supported:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;•MS-SQL&lt;br /&gt;•MySQL&lt;br /&gt;•PostgreSQL&lt;br /&gt;•Oracle &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; &lt;/div&gt;&lt;/strong&gt;&lt;/span&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color:#ffff00;"&gt;&lt;span style="font-size:180%;"&gt;The 6 Attack Models&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;•Type 0: Blind SQL Injection based on true and false conditions returned by back-end server&lt;br /&gt;•Type 1: Blind SQL Injection based on true and error(e.g syntax error) returned by back-end server.&lt;br /&gt;•Type 2: Blind SQL Injection in “order by” and “group by”.&lt;br /&gt;•Type 3: extracting data with SYS privileges (ORACLE dbms_export_extension exploit)&lt;br /&gt;•Type 4: is O.S code execution (ORACLE dbms_export_extension exploit)&lt;br /&gt;•Type 5: is reading files (ORACLE dbms_export_extension exploit, based on java)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ffff00;"&gt;New additions&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;-type: Type of injection:&lt;br /&gt;&lt;br /&gt;3: Type 3 is extracting data with DBA privileges&lt;br /&gt;(e.g. Oracle password hashes from sys.user$)&lt;br /&gt;4: Type 4 is O.S code execution(default: ping 127.0.0.1)&lt;br /&gt;5: Type 5 is Reading O.S files(default: c:\boot.ini)&lt;br /&gt;&lt;br /&gt;Type 4 (O.S code execution) supports the following sub types:&lt;br /&gt;&lt;br /&gt;-stype: How you want to execute command:&lt;br /&gt;&lt;br /&gt;0: SType 0 (default) is based on java,&lt;br /&gt;universal but won’t work against XE&lt;br /&gt;1: SType 1 against oracle 9 with plsql_native_make_utility&lt;br /&gt;2: SType 2 against oracle 10 with dbms_scheduler&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download bsqlbf v2.3 here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://bsqlbf-v2.googlecode.com/files/bsqlbf-v2-3.pl"&gt;&lt;span style="color:#33ff33;"&gt;&lt;span style="color:#ffff00;"&gt;bsqlbf-v2-3.pl&lt;/span&gt; &lt;/span&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-6734639496966064425?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/6734639496966064425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=6734639496966064425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6734639496966064425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6734639496966064425'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/07/bsqlbf-v23-released-blind-sql-injection.html' title='bsqlbf v2.3 Released – Blind SQL Injection Brute Forcing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3006856733827318487</id><published>2009-05-18T12:03:00.000-07:00</published><updated>2009-05-18T12:27:12.624-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Fiddler - Web Debugging Proxy For HTTP(S)</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Fiddler&lt;/span&gt; is a Web Debugging Proxy which logs all HTTP(S) traffic between your computer and the Internet. Fiddler allows you to inspect all HTTP(S) traffic, set breakpoints, and “fiddle” with incoming or outgoing data. Fiddler includes a powerful event-based scripting subsystem, and can be extended using any .NET language. &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 397px; DISPLAY: block; HEIGHT: 267px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5337243236801486578" border="0" alt="" src="http://2.bp.blogspot.com/_07QkubFT5Lo/ShGycilonvI/AAAAAAAAAF8/ZeMkd6A9SGw/s320/hgi1.jpg" /&gt;&lt;br /&gt;Fiddler is freeware and can debug traffic from virtually any application, including Internet Explorer, Mozilla Firefox, Opera, and thousands more.&lt;br /&gt;&lt;br /&gt;If you want some info on how to use Fiddler for debugging you can check here: &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Fiddler Can Make Debugging Easy&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Fiddler here:&lt;br /&gt;&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Fiddler2Setup.exe&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3006856733827318487?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3006856733827318487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3006856733827318487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3006856733827318487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3006856733827318487'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/fiddler-web-debugging-proxy-for-https.html' title='Fiddler - Web Debugging Proxy For HTTP(S)'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_07QkubFT5Lo/ShGycilonvI/AAAAAAAAAF8/ZeMkd6A9SGw/s72-c/hgi1.jpg' height='72' width='72'/><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-1595480674416452960</id><published>2009-05-18T11:56:00.000-07:00</published><updated>2009-05-18T12:02:37.980-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><title type='text'>FBController - The Ultimate Utility to Control Facebook Accounts</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Just to put a downer on all the script kiddies, this utility WILL NOT hack/crack Facebook passwords or accounts.&lt;br /&gt;&lt;br /&gt;You need to feed it biscuits (cookies) before you can do anything.&lt;br /&gt;&lt;br /&gt;You can get the target’s cookie by sniffing, XSS, social engineering, ARP Poison-Sniffing, &lt;a href="http://www.scroogle.org/"&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="color:#ffff00;"&gt;Scroogle&lt;/span&gt; &lt;/span&gt;&lt;/a&gt; search or however you like.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once you have the cookies you can use FBController to have Full control over the target’s Facebook account.&lt;br /&gt;&lt;br /&gt;Login to your Facebook account and sniff your own cookie OR collect a few live Facebook Biscuit/s of your Target/s.&lt;br /&gt;&lt;br /&gt;Till now FBController version 1.0 uses your Target’s provided cookie and only :&lt;br /&gt;&lt;br /&gt;A &gt; Downloads the HomePage.&lt;br /&gt;B &gt; Allows you to Update the Target’s Wall and&lt;br /&gt;C &gt; Retrieve your Target’s Friend’s List&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There are many APIs available to write apps and 3rd party Tools for FB in Java, Perl, .NET, etc.&lt;br /&gt;&lt;br /&gt;FBConTroller was entirely written without knowing any of Facebook’s Dev API’s. Considering the above along with Facebook’s complexity, the next version might take some time to get released&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download FBController here:&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;FBConTroller.RAR&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-1595480674416452960?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/1595480674416452960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=1595480674416452960' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1595480674416452960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1595480674416452960'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/fbcontroller-ultimate-utility-to.html' title='FBController - The Ultimate Utility to Control Facebook Accounts'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-8726505718699483333</id><published>2009-05-18T11:49:00.000-07:00</published><updated>2009-05-18T11:54:21.791-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Durzosploit v0.1 - JavaScript Exploit Generation Framework</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Durzosploit&lt;/span&gt; is a JavaScript exploit generation framework that works through the console. This goal of that project is to quickly and easily generate working exploits for cross-site scripting vulnerabilities in popular web applications or web sites.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Please note that Durzosploit does not find browser vulnerabilities, it only is an framework containing exploits you can use.&lt;br /&gt;&lt;br /&gt;At present there aren’t many exploits:&lt;br /&gt;&lt;br /&gt;•twitter.com/update_status - Updates a target’s status&lt;br /&gt;•twitter.com/update_settings - Updates your target’s settings&lt;br /&gt;•facebook.com/what_is_on_your_mind - Write your message in your target’s mind&lt;br /&gt;•drupal/edit_user_profile - Drupal 6.x - edit the profile of the user&lt;br /&gt;•drupal/logout - Drupal 6.x - makes target logout&lt;br /&gt;So far the author’s focus has been on the framework itself; allowing people to quickly write their exploits and adding some automated obfuscators.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Durzosploit provides some obfuscators to automatically pack/minify your generated exploit.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download the latest version from the Durzosploit SVN here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;svn co svn://www.engineeringforfun.com/svn/durzosploit/trunk&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-8726505718699483333?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/8726505718699483333/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=8726505718699483333' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8726505718699483333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/8726505718699483333'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/durzosploit-v01-javascript-exploit.html' title='Durzosploit v0.1 - JavaScript Exploit Generation Framework'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-5974858071999064154</id><published>2009-05-18T11:43:00.000-07:00</published><updated>2009-05-18T11:47:36.825-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Pangolin - Automatic SQL Injection Tool</title><content type='html'>&lt;p align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:180%;color:#ff0000;"&gt;Pangolin&lt;/span&gt; is an automatic SQL injection penetration testing tool developed by NOSEC. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user’s specific DBMS tables/columns, run his own SQL statement, read specific files on the file system and more.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Database Support&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;•Access: Informations (Database Path; Root Path; Drivers); Data&lt;br /&gt;•MSSql: Informations; Data; FileReader; RegReader; FileWriter; Cmd; DirTree&lt;br /&gt;•MySql: Informations; Data; FileReader; FileWriter;&lt;br /&gt;•Oracle: Inforatmions (Version; IP; Database; Accounts ……); Data; and any others;&lt;br /&gt;•Informix: Informatons; Data&lt;br /&gt;•DB2: Informatons; Data; and more;&lt;br /&gt;•Sybase: Informatons; Data; and more;&lt;br /&gt;•PostgreSQL: Informatons; Data; FileReader;&lt;br /&gt;•Sqlite: Informatons; Data&lt;br /&gt;&lt;br /&gt;At present, most of the functions are directed at MSSQL and MySql coupled with Oracle and Access. Other small and medium-sized companies are using DB2, Informix, Sybase, PostgreSQL, as well as Sqlite which isn’t so common.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Pangolin here: &lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;pangolin_free_edition_2.1.2.924.rar (Download Page)&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-5974858071999064154?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/5974858071999064154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=5974858071999064154' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5974858071999064154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5974858071999064154'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/pangolin-automatic-sql-injection-tool.html' title='Pangolin - Automatic SQL Injection Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4083077089931728360</id><published>2009-05-18T11:39:00.000-07:00</published><updated>2009-05-18T11:43:22.436-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Samurai Web Testing Framework 0.6 Released - Web Application Security LiveCD</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;" The authors of Samurai have updated and fixed a number of issues with the environment as well as improved performance of the java based tools. They have also included a virtual machine of the environment. This VM requires VMWare. "&lt;br /&gt;&lt;br /&gt;For those that don’t know, Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. There are tools used in all four steps of a web pen-test.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;&lt;strong&gt;You can download SamuraiWTF 0.6 here:&lt;br /&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;samurai-0.6.iso&lt;/span&gt;&lt;/strong&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4083077089931728360?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4083077089931728360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4083077089931728360' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4083077089931728360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4083077089931728360'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/05/samurai-web-testing-framework-06.html' title='Samurai Web Testing Framework 0.6 Released - Web Application Security LiveCD'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-4605374314161966865</id><published>2009-04-22T14:30:00.001-07:00</published><updated>2009-04-22T14:38:00.952-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Charles Web Debugging Proxy - HTTP Monitor &amp; Reverse Proxy</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;&lt;strong&gt;Charles is an HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP traffic between their machine and the Internet. This includes requests, responses and the HTTP headers (which contain the cookies and caching information).&lt;br /&gt;&lt;br /&gt;Charles can act as a man-in-the-middle for HTTP/SSL communication, enabling you to debug the content of your HTTPS sessions.&lt;br /&gt;&lt;br /&gt;Charles simulates modem speeds by effectively throttling your bandwidth and introducing latency, so that you can experience an entire website as a modem user might (bandwidth simulator).&lt;br /&gt;&lt;br /&gt;Charles is especially useful for Adobe Flash developers as you can view the contents of LoadVariables, LoadMovie and XML loads. Charles also has native support for Flash Remoting (AMF0 and AMF3).&lt;br /&gt;&lt;br /&gt;Charles is also useful for XML development in web browsers, such as AJAX (Asynchronous Javascript and XML) and XMLHTTP, as it enables you to see the actual XML that is flowing between the client and the server. Charles natively supports JSON, JSON-RPC and SOAP; displaying each in a simplified tree format for easy viewing and debugging.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download Charles Proxy here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;Windows - charles_setup.exe&lt;br /&gt;Linux / Unix - charles.tar.gz&lt;br /&gt;Mac OS X - charles_macosx.zip&lt;/span&gt;&lt;/strong&gt;&lt;strong&gt;&lt;/strong&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-4605374314161966865?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/4605374314161966865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=4605374314161966865' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605374314161966865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/4605374314161966865'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/04/charles-web-debugging-proxy-http.html' title='Charles Web Debugging Proxy - HTTP Monitor &amp; Reverse Proxy'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-7003374011265214432</id><published>2009-04-22T14:22:00.000-07:00</published><updated>2009-04-22T14:30:02.969-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Cracking'/><title type='text'>EFIPW - Modify Apple EFI Firmware Passwords</title><content type='html'>&lt;p&gt;&lt;strong&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;EFIPW is a tool that can be used to decode and modify Apple EFI firmware passwords via the command line. It is designed after the non open source OFPW utility and is designed to work on Intel machines running Leopard or newer. Useful for lab deployments (setting the firmware password of machines as a post install item) and pen tests (recovering the EFI firmware password).&lt;br /&gt;&lt;br /&gt;Tested on:&lt;br /&gt;•Core Duo (1st gen) Macbook Pro 15″&lt;br /&gt;•Core 2 Duo Macbook Pro 15″ &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;strong&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;p&gt;Technical details on how it works here.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download EFIPW v0.1a here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ffff00;"&gt;efipw_v0.1a.zip&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-7003374011265214432?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/7003374011265214432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=7003374011265214432' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7003374011265214432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/7003374011265214432'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2009/04/efipw-modify-apple-efi-firmware.html' title='EFIPW - Modify Apple EFI Firmware Passwords'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-6624734687456317268</id><published>2008-11-25T05:20:00.000-08:00</published><updated>2008-11-25T05:29:55.959-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>ike-scan - IPsec VPN Scanning, Fingerprinting and Testing Tool</title><content type='html'>&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;ike-scan is a command-line tool for discovering, fingerprinting and testing IPsec VPN systems. It constructs and sends IKE Phase-1 packets to the specified hosts, and displays any responses that are received.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;br /&gt;ike-scan allows you to:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Send IKE packets to any number of destination hosts, using a configurable output bandwidth or packet rate. (This is useful for VPN detection, when you may need to scan large address spaces.) &lt;/li&gt;&lt;li&gt;Construct the outgoing IKE packet in a flexible way. (This includes IKE packets which do not comply with the RFC requirements.) &lt;/li&gt;&lt;li&gt;Decode and display any returned packets. &lt;/li&gt;&lt;li&gt;Crack aggressive mode pre-shared keys. (You can use ike-scan to obtain the PSK hash data, and then use psk-crack to obtain the key.) &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;You can read more in depth about ike-scan and how to use it - in the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/wiki/index.php/Ike-scan_User_Guide"&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;User Guide&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;ike-scan is free software, licensed under the GPL. It runs on Windows, Linux and most Unix systems. If you don’t already have ike-scan installed on your system, read the &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/wiki/index.php/Ike-scan_Installation_Guide"&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;installation guide&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ff6600;"&gt;&lt;strong&gt;. &lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;p&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download ike-scan 1.9 here:&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#ffff00;"&gt;Source distribution: &lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/tools/ike-scan/download/ike-scan-1.9.tar.gz"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;ike-scan-1.9.tar.gz&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;Windows binary: &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.nta-monitor.com/tools/ike-scan/download/ike-scan-win32-1.9.zip"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;ike-scan-win32-1.9.zip&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-6624734687456317268?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/6624734687456317268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=6624734687456317268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6624734687456317268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/6624734687456317268'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/11/ike-scan-ipsec-vpn-scanning.html' title='ike-scan - IPsec VPN Scanning, Fingerprinting and Testing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-732233319028823510</id><published>2008-11-25T05:12:00.000-08:00</published><updated>2008-11-25T05:19:55.233-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Browser Rider - Web Browser Exploitation Framework</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Browser Rider is a hacking framework to build payloads that exploit the browser. The project aims to provide a powerful, simple and flexible interface to any client side exploit.&lt;br /&gt;Browser Rider is not a new concept. Similar tools such as &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;BeEF&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; or &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Backframe&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; exploited the same concept. However most of the other existing tools out there are unmaintained, not updated and not documented. Browser Rider wants to fill those gaps by providing a better alternative.&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-size:130%;color:#ff6600;"&gt;Features&lt;/span&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;Easily create powerful payloads and plugins &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Manage payloads automatically with plugins &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;All data can be saved in a database &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Obfuscation &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Polymorphism &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Control more than one zombie at a time &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Simple administration panel &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="justify"&gt;&lt;br /&gt;&lt;span style="color:#ff6600;"&gt;Requirements&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;PHP 5, with json installed &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Mysql &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Apache with url_rewrite on &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Targets must have Javascript turned on &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="justify"&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download Browser Rider here:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;p align="justify"&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.engineeringforfun.com/cave/browserrider/BrowserRider.20081124.tar.bz2"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;Browser Rider v20081124&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt; (&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.engineeringforfun.com/wiki/index.php/Browser_Rider_Changelog#Browser_Rider_v20081124"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;changelog&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-732233319028823510?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/732233319028823510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=732233319028823510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/732233319028823510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/732233319028823510'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/11/browser-rider-web-browser-exploitation.html' title='Browser Rider - Web Browser Exploitation Framework'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-1580229789329888296</id><published>2008-10-26T13:09:00.000-07:00</published><updated>2008-11-25T05:11:40.350-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>XSS-Proxy - Cross Site Scripting Attack Tool</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="font-size:130%;color:#ff6600;"&gt;XSS-Proxy&lt;/span&gt; is an advanced Cross-Site-Scripting (XSS) attack tool. The documents, tools and other content on this site assume you have a basic understanding of &lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;XSS&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; issues and existing exploitation methods. If you are not famliar with XSS, then I recommend you check out the primer links/docs below to get a better of idea of what XSS is and how to detect it, fix it, and exploit it.&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.cert.org/advisories/CA-2000-02.html"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;CERT info on XSS&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;a href="http://www.cgisecurity.com/articles/xss-faq.shtml"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;CGISecurity’s Cross Site Scripting FAQ&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.technicalinfo.net/papers/CSS.html"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;Gunter Ollmann’s XSS paper&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.securityfocus.com/archive/1/191390"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;PeterW’s Cross Site Request Forgery (CSRF) Concept&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.securenet.de/papers/Session_Riding.pdf"&gt;&lt;span style="font-family:arial;font-size:130%;color:#ffff00;"&gt;&lt;strong&gt;SecureNet’s Session Riding paper&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Some Common Misconceptions about XSS&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;“A user has to click a link to be impacted by XSS.” No - if you visit a page that has&lt;br /&gt;stuff_to_run your browser will run it regardless of you clicking a link. I carefully crafted this example so it would not be run by your browser, but I could have put real script tags/commands here and made you run then transparently.&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;“XSS only matters with bulliten boards, blogs, and other sites where an attacker can upload script content.” That is one way the attack can happen, but an attacker can also leverage sites that allow HTML/SCRIPT tags to be reflected back to the same user (like a search form that repeats what it was told to look for in the response). These flaws are commonly combined with public site redirects or emails to attack a second site. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;“Don’t XSS attacks just create popup windows, alerts and other pesky things?” No - They are commonly used to reveal your cookies or form based login info to attackers. After havesting this info, the attacker uses it to log into the same site as you. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;“I understand XSS, but I don’t think it’s a huge issue“. I think you’ll change your mind once you understand this advanced attack. Read the advanced stuff below and play with XSS-Proxy to see how evil XSS really can be. &lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p align="justify"&gt;&lt;em&gt;&lt;span style="color:#ff6600;"&gt;You can download XSS-Proxy here:&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/project/showfiles.php?group_id=130402&amp;amp;package_id=142941&amp;amp;release_id=545299"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;XSS-Proxy_0_0_12-book.pl&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-1580229789329888296?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/1580229789329888296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=1580229789329888296' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1580229789329888296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/1580229789329888296'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/10/xss-proxy-cross-site-scripting-attack.html' title='XSS-Proxy - Cross Site Scripting Attack Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-5969206306582132847</id><published>2008-09-27T13:52:00.000-07:00</published><updated>2008-09-27T14:05:42.200-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Psad - Intrusion Detection and Log Analysis with iptables</title><content type='html'>&lt;div align="justify"&gt;&lt;font face="arial" color="#33ff33"&gt;&lt;strong&gt;psad is a collection of three lightweight system daemons (two main daemons and one helper daemon) that run on Linux machines and analyze iptables log messages to detect port scans and other suspicious traffic. A typical deployment is to run psad on the iptables firewall where it has the fastest access to log data. &lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;font face="arial" color="#33ff33"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;psad incorporates many signatures from the Snort intrusion detection system to detect probes for various backdoor programs (e.g. EvilFTP, GirlFriend, SubSeven), DDoS tools (mstream, shaft), and advanced port scans (FIN, NULL, XMAS) which are easily leveraged against a machine via nmap.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;When combined with fwsnort and the Netfilter string match extension, psad is capable of detecting many attacks described in the Snort rule set that involve application layer data. In addition, psad makes use of various packet header fields associated with TCP SYN packets to passively fingerprint remote operating systems (in a manner similar to p0f) from which scans originate.&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;For more information, see the &lt;/strong&gt;&lt;/font&gt;&lt;a href="http://www.cipherdyne.org/psad/docs/features.html"&gt;&lt;font face="arial" color="#ff6600"&gt;&lt;strong&gt;complete list of features offered by psad&lt;/strong&gt;&lt;/font&gt;&lt;/a&gt;&lt;font face="arial" color="#33ff33"&gt;&lt;strong&gt;&lt;font color="#ff6600"&gt;.&lt;/font&gt; &lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;font face="arial" color="#33ff33"&gt;&lt;strong&gt;&lt;div align="justify"&gt;&lt;br /&gt;psad is developed around three main principles:&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;Good network security starts with a properly configured firewall. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;A significant amount of intrusion detection data can be gleaned from firewalls logs, especially if the logs provide information on nearly every field of the network and transport headers (and even application layer signature matches as in Netfilter’s case). &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;Suspicious traffic should not be detected at the expense of trying to also block such traffic. &lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;font face="arial" color="#ff6600"&gt;&lt;strong&gt;&lt;em&gt;You can download psad v2.1.4 here:&lt;/em&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;a href="http://www.cipherdyne.org/psad/download/psad-2.1.4.tar.gz"&gt;&lt;font face="arial" color="#ffff00"&gt;&lt;strong&gt;psad-2.1.4.tar.gz&lt;/strong&gt;&lt;/font&gt;&lt;/a&gt;&lt;font face="arial" color="#ffff00"&gt;&lt;strong&gt; (Source tar)&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;a href="http://www.cipherdyne.org/psad/download/psad-2.1.4-1.i386.rpm"&gt;&lt;font face="arial" color="#ffff00"&gt;&lt;strong&gt;psad-2.1.4-1.i386.rpm&lt;/strong&gt;&lt;/font&gt;&lt;/a&gt;&lt;font face="arial" color="#ffff00"&gt;&lt;strong&gt; (i386 binary RPM).&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-5969206306582132847?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/5969206306582132847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=5969206306582132847' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5969206306582132847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5969206306582132847'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/09/psad-intrusion-detection-and-log.html' title='Psad - Intrusion Detection and Log Analysis with iptables'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-648216355245094898</id><published>2008-09-27T13:46:00.000-07:00</published><updated>2008-09-27T13:51:52.815-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Web Application Security Statistics for 2008</title><content type='html'>&lt;div align="justify"&gt;&lt;strong&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="font-size:180%;color:#ff6600;"&gt;Purpose&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;strong&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="font-size:180%;"&gt;&lt;/span&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2007. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about the web application vulnerability landscape. We ascertain which classes of attacks are the most prevalent regardless of the methodology used to identify them. Industry statistics such as those compiled by Mitre CVE project provide valuable insight into the types of vulnerabilities discovered in open source and commercial applications, this project tries to be the equivalent for custom web applications.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ff6600;"&gt;Goals&lt;/span&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;Identify the prevalence and probability of different vulnerability classes &lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;Compare testing methodologies against what types of vulnerabilities they are likely to identify. &lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ff6600;"&gt;Methodology&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;The statistics was compiled from web application security assessment projects which were made by the following companies in 2007 (in alphabetic order):&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="color:#33ff33;"&gt;Booz Allen HamiltonBTCenzic with Hailstorm and ClickToSecured&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;blogic.it&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;HP Application Security Center with WebInspect&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;Positive Technologies with MaxPatrol&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;Veracode with Veracode Security Review&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="color:#33ff33;"&gt;WhiteHat Security with WhiteHat Sentinel&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;Read the full report here:&lt;/em&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;a href="http://www.webappsec.org/projects/statistics/"&gt;&lt;strong&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;http://www.webappsec.org/projects/statistics/&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-648216355245094898?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/648216355245094898/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=648216355245094898' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/648216355245094898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/648216355245094898'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/09/web-application-security-statistics-for.html' title='Web Application Security Statistics for 2008'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-5123668935392911858</id><published>2008-09-27T13:42:00.000-07:00</published><updated>2008-09-27T13:46:19.170-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking web services'/><category scheme='http://www.blogger.com/atom/ns#' term='Web-applications-security'/><title type='text'>Surf Jack - Cookie Session Stealing Tool</title><content type='html'>&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;A tool which allows one to hijack HTTP connections to steal cookies - even ones on HTTPS sites! Works on both Wifi (monitor mode) and Ethernet.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:180%;color:#ff6600;"&gt;&lt;strong&gt;Features:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Does Wireless injection when the NIC is in monitor mode &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Supports Ethernet &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Support for WEP (when the NIC is in monitor mode) &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:180%;color:#ff6600;"&gt;&lt;strong&gt;Known issues:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Sometimes the victim is not redirected correctly (particularly seen when targeting Gmail) &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Cannot stop the tool via a simple Control^C. This is a problem with the proxy &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:180%;color:#ff6600;"&gt;&lt;strong&gt;Requires:&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Python 2.4 &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.darknet.org.uk/2007/05/scapy-interactive-network-packet-manipulation/"&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;Scapy&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download Surf Jack here:&lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://surfjack.googlecode.com/files/surfjack-0.2b.zip"&gt;&lt;span style="font-family:arial;color:#ffff00;"&gt;&lt;strong&gt;surfjack-0.2b.zip&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-5123668935392911858?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/5123668935392911858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=5123668935392911858' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5123668935392911858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/5123668935392911858'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/09/surf-jack-cookie-session-stealing-tool.html' title='Surf Jack - Cookie Session Stealing Tool'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2776533298599940650.post-3692062235968839772</id><published>2008-09-27T13:33:00.000-07:00</published><updated>2008-09-27T13:42:14.908-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Hacking'/><title type='text'>Ohrwurm - RTP Fuzzing Tool (SIP Phones)</title><content type='html'>&lt;strong&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="color:#33ff33;"&gt;ohrwurm is a small and simple RTP fuzzer, it has been tested it on a small number of SIP phones, none of them withstood the fuzzing.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;color:#ff6600;"&gt;Features:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;reads SIP messages to get information of the RTP port numbers &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;reading SIP can be omitted by providing the RTP port numbers, so that any RTP traffic can be fuzzed &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;RTCP traffic can be suppressed to avoid that codecs learn about the “noisy line”&lt;br /&gt;special care is taken to break RTP handling itself &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;the RTP payload is fuzzed with a constant BER &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;the BER is configurable &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;requires arpspoof from dsniff to do the MITM attack &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:arial;color:#33ff33;"&gt;&lt;strong&gt;requires both phones to be in a switched LAN (GW operation only works partially) &lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:arial;"&gt;&lt;span style="color:#ff6600;"&gt;&lt;em&gt;You can download ohrwurm 0.1 here:&lt;/em&gt;&lt;/span&gt; &lt;a href="http://mazzoo.de/d/ohrwurm-0.1.tar.bz2"&gt;&lt;span style="color:#ffff00;"&gt;ohrwurm-0.1.tar.bz2&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2776533298599940650-3692062235968839772?l=hackersgroupofindia.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackersgroupofindia.blogspot.com/feeds/3692062235968839772/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=2776533298599940650&amp;postID=3692062235968839772' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3692062235968839772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2776533298599940650/posts/default/3692062235968839772'/><link rel='alternate' type='text/html' href='http://hackersgroupofindia.blogspot.com/2008/09/ohrwurm-rtp-fuzzing-tool-sip-phones.html' title='Ohrwurm - RTP Fuzzing Tool (SIP Phones)'/><author><name>Hackers Group Of India</name><uri>http://www.blogger.com/profile/08146437810773797683</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='16820016427909477224'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>