How I Hacked Facebook, and Found Someone's Backdoor Script
Foreword As a pentester, I love server-side vulnerabilities more than client-side ones. Why? Because it’s way much ...
![]()
Foreword
As a pentester, I love
server-side vulnerabilities more than client-side ones. Why? Because it’s way
much cooler to take over the server directly and gain system SHELL
privileges. <( ̄︶ ̄)>Of course, both vulnerabilities from the server-side and the client-side are indispensable in a perfect penetration test. Sometimes, in order to take over the server more elegantly, it also need some client-side vulnerabilities to do the trick. But speaking of finding vulnerabilities, I prefer to find server-side vulnerabilities first. With the growing popularity of Facebook around the world, I’ve always been interested in testing the security of Facebook. Luckily, in 2012, Facebook launched the Bug Bounty Program, which even motivated me to give it a shot. |
DecFlooder-v1.00 Effective Flood Tool
It is time to make some attacks which like ddos but from only one PC :D DecFlooder-v1.00 Hack Tools easy to use as you see from the p...
It is time to make some attacks which like ddos but from only one PC :DDecFlooder-v1.00 Hack Tools
easy to use as you see from the picture
- just select your connection speed
- add victim URL
- then pust the Enjoy Button :D ( FLOOD !!!)
Download Link:
https://app.box.com/s/gzk0gbsuneixsoixss19
Florida voting system LEAKED...
Below are the inside details of Florida voting systems. If the United States government can't even keep their ballot systems secure, why...
- Below are the inside details of Florida voting systems. If the United States government can't even keep their ballot systems secure, why trust them at all? Everyone knows voting is rigged, but if you don't here you go.
- Twitter - @AnonymousWiki
RFI over SQL Injection/Cross-Site Scripting
An amusing attack was demonstrated in the course of the last penetration testing. It is a good example of practical application of Cross-Si...
- User segment with an attacker (me) operating from it;
- Technological network with strictly restricted outgoing traffic;
- A web application in the technological network that is vulnerable to Remote File Including (RFI);
- A web application in the technological network that is vulnerable to SQL Injection.
Another fine method to exploit SQL Injection and bypass WAF
A method that I discovered today in MySQL documentation struck me with its simplicity and the fact that I haven’t noticed it before. Let me ...
MySQL servers allow one to use comments of the following type:
/*!sql-code*/ and /*!12345sql-code*/
As can be noticed, SQL code will be executed from the comment in both cases! The latter construction means that "sql-code" should be executed only if the DBMS version is later than the given value.
Some WAFs skip comments during signature search. Among such WAFs, there is the latest stable assembly of Mod_Security (v. 2.5.9).
Here is a simple example:
How to capture data and passwords of unsecured wireless networks with SniffPass and SmartSniff
A few months ago, I released a new version of both SmartSniff and SniffPass with support for using them with Microsoft Network Monitor 3.x...
DRIL - Domain Reverse IP Lookup Tool
DRIL (Domain Reverse IP Lookup) Tool is a Reverse Domain Tool that will really be useful for penetration testers to find out the domain na...
- FindDomains v0.1.1 Released – Discover Domains/Sites/Hosts (This would be the most similar to DRIL).
- FOCA – Network Infrastructure Mapping Tool (Also contains this feature amongst others).
- hostmap 0.2 – Automatic Hostname & Virtual Hosts Discovery Tool (Does the same job but uses multiple techniques.)
Gaining Administrative Privileges on any Blogger.com Account
"The vulnerability that I want to share first, Is a critical vulnerability in Blogger (Google Service), That vulnerability could be us...
That vulnerability could be used by an attacker to get administrator privilege over any blogger account (Permission Issue),Yes I know it sound kind of crazy but it's true :),
Here are the details regarding the issue in Blogger service,
I found a HTTP Parameter Pollution vulnerability in Blogger that allow an attacker to add himself as an administrator on the victim's blogger account,"
Sql Poison v1.1
After a very successfull release of Sql Poizon v1.0, The Exploit Scanner Tool, I am hereby introducing you with the new release which is m...
How To Use Trial Software's For Ever...
One of my blog readers asked me "How can i use trial version software's forever" .Instead of answering him i taught i can wr...
Concept :-
When you install a software for the first time it makes an entry into the Windows Registry with details such as Installed Date and Time, installed path etc.After installation every time you run the software it compares the current system date and time with the installed date and time.So with this it can make out whether the trial period is expired or not. So if we make software think that the trial period is not over we can use the software for ever
Download "deleted" files from HotFile!
Recently HotFile.com got itself in big legal trouble which forced them to start (really) deleting "copyrighted" material, and ...
Anyway, enough blah bla. Lets get to the point!
Some uploaders still dare to upload files to HotFile and on average those files get deleted withing 30 minutes, but do they really delete files? Aperently not, and we found out how to download "deleted" files. this trick is superb easy and you need now knowledge aside how to use a browser!Let me show you: Here we have a link which is "deleted"
http://hotfile.com/dl/109695738/8cec3a0/...e.avi.html
Now the trick. You simply have to place new before the URL and then it will work again! :woohoo:
http://new.hotfile.com/dl/109695738/8cec3a0/national.geographic.kkk.inside.american.terror.hdtv.xvid-diverge.avi.html
Yeah, that simple! Enjoy while it lasts!
It looks like a bug, so I expect it to be "fixed" soon
Hakin9: Identity Theft!
Hakin9 is a free, online, monthly publication on IT Security. The magazine is published in English and is available in the Internet a...
Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition...
Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition http://www.amazon.com/Gray-Hacking-Ethical-Hackers-Handbook/dp/0071742557/ * ...
* Develop and launch exploits using BackTrack and Metasploit
* Employ physical, social engineering, and insider attack techniques
* Build Perl, Python, and Ruby scripts that initiate stack buffer overflows
* Understand and prevent malicious content in Adobe, Office, and multimedia files
* Detect and block client-side, Web server, VoIP, and SCADA attacks
* Reverse engineer, fuzz, and decompile Windows and Linux software
* Develop SQL injection, cross-site scripting, and forgery exploits
* Trap malware and rootkits using honeypots and SandBoxes
About
Network security blog.
Follow Us
Popular Posts
-
context: https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation writeup: https://www.trustedsec.com/blog/equation-group-...
-
Eternalromance is another SMBv1 exploit from the leaked NSA exploit collection and targets Windows XP/Vista/7 and Windows Server 2003 and 2...
-
Learn how to hack Wi-Fi password of modern routers Wifi password hacking has become popular as people are always in search of the free i...
-
A week or so ago, I read the news of a new backdoor on several devices, including those made by Belkin , Cisco , NetGear , Linksys , an...
-
After a very successfull release of Sql Poizon v1.0, The Exploit Scanner Tool, I am hereby introducing you with the new release which is m...
-
Using Meterpreter Commands Since the Meterpreter provides a whole new environment, we will cover some of the basic Meterpreter comman...
-
A few months ago, I released a new version of both SmartSniff and SniffPass with support for using them with Microsoft Network Monitor 3.x...
-
In the last article we introduced some of the useful features that Burpsuite has to offer when performing a Web Application Penetration Te...
-
Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to...
-
BruteSploit is a collection of method for automated Generate, Bruteforce and Manipulation wordlist with interactive shell. That can be use...
Labels
Total Pageviews
Popular Posts
-
This article aims to introduce the framework that has been disclosed through an article posted by ShadowBrokers , focusing on two...
-
A web application firewall (WAF) is an appliance, server plugin, or a software filter that applies a set of rules to an HTTP conversatio...
-
Elite Proxy Switcher The Best Tool That I Ever Find on The Internet For Finding And Checking Huge Proxy Lists You Can Find Elite and A...
-
context: https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation writeup: https://www.trustedsec.com/blog/equation-group-...
-
Hi guys, today i am goint to tell you a perfect program which makes Effective DoS Attacks Easly :D Name of the Program is DoS-Pro v 2.0 R...
-
It is time to make some attacks which like ddos but from only one PC :D DecFlooder-v1.00 Hack Tools easy to use as you see from the p...
-
Below are the inside details of Florida voting systems. If the United States government can't even keep their ballot systems secure, why...




