<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DDoSed.com - An IT security information blog &#187; Exploits</title>
	<atom:link href="http://www.ddosed.com/category/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ddosed.com</link>
	<description></description>
	<lastBuildDate>Sat, 04 Oct 2008 07:21:19 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Jun 2007 &#8211; Feb 2008 U.S. Gov Website Defacements + Commentary</title>
		<link>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/</link>
		<comments>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/#comments</comments>
		<pubDate>Sat, 05 Apr 2008 12:32:10 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[crackers]]></category>
		<category><![CDATA[frontpage extensions]]></category>
		<category><![CDATA[gov defaces]]></category>
		<category><![CDATA[mirror archive]]></category>
		<category><![CDATA[php inclusion]]></category>
		<category><![CDATA[script kiddies]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[website defacements]]></category>
		<category><![CDATA[zone-h]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/?p=51</guid>
		<description><![CDATA[Below is a list of US governmental websites which were defaced by crackers &#8211; or elite hackers as the media would say &#8211; since 26th of June 07 until late February 2008. It is quite interesting to know that most of the security vulnerabilities affecting the following *.gov websites are known for some years now.

buckinghamcounty.virginia.gov [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Below is a list of US governmental websites which were defaced by crackers &#8211; or elite hackers as the media would say &#8211; since 26th of June 07 until late February 2008. It is quite interesting to know that most of the security vulnerabilities affecting the following *.gov websites are known for some years now.</p>
<p align="justify"><span id="more-51"></span></p>
<p align="justify"><a title="buckinghamcounty.virginia.gov - Archived at Zone-H.org" href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6529007" target="_blank">buckinghamcounty.virginia.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by a Turkish cracker. Possibly he successfully exploited the FrontPage extensions misconfiguration vulnerability. He added his e-mail address. Of course if you contact him to ask what was the method used to deface, most probably he is going to reply that was a 0day vulnerability. What a stupid thing to do (add contact details). I am not going to explain why. He should work his own mind. I&#8217;m sure that at some point he is going to check this blog post because his nickname (<span class="category">UyuSsman</span>) will be soon enough indexed in search engines&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p align="justify"><a title="genome.nasa.gov/delivery/affy-C2wPDrGz - Archived at Zone-H.org" href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6514459">genome.nasa.gov/delivery/affy-C2wPDrGz</a> &#8211; Apache on Linux &#8211; Defaced by an Algerian cracker. Exploited an open door left in a web application. It is NASA! Automatically becomes teh uber h4&#215;0r. LOL. Worths admiring l33t skills that even my grandma could use.</p>
<p align="justify"><a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6555137" target="_blank">williamsburgva.gov/uk/4ever.htm</a> &#8211; IIS6.0 on Win 2003 &#8211; Another deface by a Turkish cracker. You can contact him via MSN, just add turkishmember@yahoo.com.br!!! Obviously he is collaborating with Brazilian defacers. Without collaboration he wont be able to climb his way up on Zone-H&#8217;s hall of shame board for special defacements.</p>
<p align="justify"><a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6499258" target="_blank">cncsoig.gov/cum.htm</a> &#8211; IIS6.0 on Win 2003 &#8211; Defaced by a cracker from Panama. Silly him, named the defaced page &#8220;cum.htm&#8221;. Notice to how many people sends greets. You can find him at <a href="irc://irc.gigachat.org:6667">irc.GigaChat.net</a> [<em>Now down for some reason</em>] #core-project, #whackerz, #Xtech, #Segfault &#8211; where all the l33t peeps are idling and privately exchanging messages about their achievements. In this defacement there is a reference to the recent <a title="Chilean Crackers Caught - Zone-H.org News - November 2006" href="http://www.zone-h.org/content/view/14321/30/" target="_blank">arrest</a> of four Chilean crackers who were members of the &#8220;Byond Hackers Team&#8221;. Most probably the defaced page was influenced from watching too many h4&#215;0r movies! h0h0.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6469760/" target="_blank">dialog.cancer.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by crackers from the Dominican Republic. They seem to know how to exploit basic SQL injection vulnerabilities. They just defaced the page with the message &#8220;D.O.M TEAM 2007 === xarnuz === &#8220;. No specific reason for their deface. Just for fun I guess. Surely showing off their team and nicknames to the defacers underground community.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6469685/" target="_blank">ncilistens.cancer.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by Brazilian crackers. Exploited an SQL injection vulnerability to add &#8220;Hacked by AciDmuD &#8211; RitualistaS GrouP&#8221;. They also added a contact e-mail address.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6498853/" target="_blank">cncsig.gov</a> &#8211; IIS6.0 on Win 2003 &#8211; Defaced by Brazilian crackers. Funny thing they call their team &#8220;<span class="defaulttext">linuXploit_crew&#8221;. That means they exploit Linux boxes as well. OMG! Those guys must be uber-l33t0r. So ultimate respect for them. They support that hacking is not a crime. I certainly agree, but what they did is not hacking but cracking, and this is illegal aka a crime. </span></p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6457557/" target="_blank">whitecounty-il.gov</a><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6457557/" target="_blank">/index.html</a> Win 2003<br />
woolwichnj.gov &#8211; Apache on Linux &#8211; Defaced by Brazilian crackers. Possibly exploited a PHP inclusion vulnerability, called a remote command shell script, checked with &#8220;uname -a&#8221; that the kernel is vulnerable to a local root exploit, run wget to download a backdoor to a writable directory, run the backdoor, telneted to the specific backdoor port, run wget to download <a title="h00lyshit.c" href="http://archives.neohapsis.com/archives/fulldisclosure/2006-07/att-0310/h00lyshit.c" target="_blank">h00lyshit</a> or <a title="raptor_prctl2.c" href="http://www.milw0rm.com/exploits/2031" target="_blank">prctl</a> local root kernel exploits, tested successfully one of the local root exploits, got root, owned the web server. They didn&#8217;t even spell right the word &#8220;owned&#8221; in the defaced page. Quite possibly, maybe they even tried to deceive by changing the kernel version in the defaced page. They would look more l33t that way: &#8220;2.6.16-1.2111_FC5smp #1 SMP Thu May 4 21:35:09 EDT 2006 &#8220;.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6406440/" target="_blank">armenia.ca.gov</a> &#8211; Apache on Linux &#8211; Defaced by a cracker from Saudi Arabia. This guy seems to know who he is, not a hacker, but a &#8220;R00T Cracker&#8221;. ROFL! Even that, maybe he is lying. Could be a &#8220;UID=APACHE Cracker&#8221;. You can contact him &#8220;For Mor Security&#8221; at S4curity@HotMail.Com and Admin@611.Com. This cracker used the same exploitation methodology as the Brazilian group above. No further commentary for this deface&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> <span style="color: #c0c0c0; font-size: large;"> </span></p>
<p><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6399444/" target="_blank">arb.ca.gov/research</a> &#8211; Apache on Linux &#8211; Defaced by crackers from Brazil.</p>
<p>Concluding this commentary, all of the above defacements were a result of the following security vulnerabilities which were already known &#8211; some for many years now.</p>
<p>- <a title="SQL Injection Cheat Sheet" href="http://ferruh.mavituna.com/makale/sql-injection-cheatsheet/" target="_blank">SQL injections</a> (programming mistake)</p>
<p>- <a title="PHP Undergroud Security - PlayHack.net" href="http://www.playhack.net/view.php?type=1&amp;id=22" target="_blank">PHP inclusion</a> (programming mistake)</p>
<p>- <a href="http://www.ddosed.com/uploads/penetration_testing/webfolders.txt" target="_blank">FrontPage Extensions</a> (misconfiguration)</p>
<p align="justify">Windows or Unix with enabled FrontPage extensions could be vulnerable due to misconfiguration. If vulnerable, open the target domain or ip as web folder and you are in its webroot. It is very possible that you have write access. What if such misconfiguration exists in a web server which hosts thousand of sites and supports server side languages as ASP and PHP? Attackers can upload scripts which allow them to mass deface in few seconds all the hosted sites, run backdoors, download confidential data if any, use server as part of their botnet and erase all the log files. The best solution is to totally disable FrontPage extensions.</p>
<p align="justify"><a title="Written by soznic" href="http://www.ddosed.com/uploads/penetration_testing/webfolders.txt" target="_blank">Read this text</a> for more detailed information about web folders and FrontPage extensions.</p>
<p>- <a href="http://seclists.org/fulldisclosure/2005/Jan/0032.html" target="_blank">Microsoft Data Access Internet Publishing Provider DAV 1.1</a> and <a title="mod_dav: a DAV module for Apache" href="http://www.webdav.org/mod_dav/" target="_blank">mod_dav</a> (misconfiguration)</p>
<p align="justify">Attackers can import a list of high-profiled domains and check against if they allow PUT requests. Using the PoC for this vuln, they can PUT /theirdeface.htm to the webroot of the vulnerable domains. They can even PUT /ntdaddy.asp or other shorter in size web administration scripts in order to grant complete access to the web server. Also Linux web servers with mod_dav could be vulnerable.</p>
<p>The sysadmins, webmasters and web developers surely learnt their lesson. It is always the human factor to blame first for any occurrence  of security breaches.</p>
<p>Quite ironic that gov systems are consistently attacked by confused script-kiddies. After all for them is just &#8220;show off&#8221; game.</p>
<p>More U.S. governmental defacements submitted to Zone-H by the crackers:</p>
<blockquote><p>DigitalMind       woolwichnj.gov              Linux<br />
ArREs           vil.prentice.wi.gov             Linux<br />
S4udi-S3curity-T3rror   armenia.ca.gov          Linux<br />
Apocalypse        cncsoig.gov/cum.htm       Win 2003<br />
D.O.M            dialog.cancer.gov             Win 2000<br />
RitualistaS       ncilistens.cancer.gov     Win 2000<br />
linuXploit_crew   cncsig.gov                     Win 2003<br />
Kript3X        bowmar.gov/hacked.htm      Win 2003<br />
soyletmez        https://sc-isac.sc.gov      Win 2003<br />
SegmentationFault ops.sgp.arm.gov             Win 2000<br />
SegmentationFault nevadatreasurer.gov             Win 2000<br />
SuZuki        commerce.idaho.gov              Win 2003<br />
SuZuki            community.idaho.gov             Win 2003<br />
XTech Inc       lmhc.la.gov                     Win 2003<br />
XTech Inc       lmhc.louisiana.gov             Win 2003<br />
Phantom Orchid       cstx.gov/home             Win 2000<br />
BiyoSecurityTeam  roundrocktexas.gov             Win 2003<br />
S4t4n1c_s0uls        csac.ca.gov/doc.asp              Win 2003<br />
RootDamages       vacsp.gov/news.cfm             Win 2003<br />
beyrut-KaI3uS       vivote.gov                     Win 2003<br />
PowerDream        leesburgva.gov/pwd.htm      Win 2003<br />
SuZuki            remember.gov                     Win 2000<br />
S4udi-S3curity-T3rror     armenia.usaid.gov     Linux<br />
sinaritx        doe.nv.gov                      Win 2003<br />
s@bun           secure.sc.gov//LexSheriff     Win 2003<br />
W4n73d_H4ck3r       senegal.usaid.gov             Win 2000<br />
DigitalMind       seagrantdev.noaa.gov             Linux<br />
W4n73d_H4ck3r       admin.fmcs.gov             Win 2003<br />
W4n73d_H4ck3r       fmcs.gov                     Win 2003<br />
DigitalMind       seagrantdev.noaa.gov             Win 2000<br />
DigitalMind       seagrantdev.noaa.gov             Win 2000</p></blockquote>
<p>and many other that we don&#8217;t know about&#8230;</p>
<p>View the mirrors of the defaced sites on Zone-H and if you want add a comment below:<br />
<a title="U.S. Governmental Website Defacements on Zone-H.org" href="http://old.zone-h.org/en/defacements/special/filter/filter_domain=gov " target="_blank">http://old.zone-h.org/en/defacements/special/filter/filter_domain=gov </a></p>
<p>Clearly they &#8220;promoted&#8221; themselves to the script kiddies scene with a &#8220;wannabe an elite defacer, thats why I deface .gov/s and publish them on Zone-H&#8221; attitude. Of course they will never admit to this and continue to feed their bogus pride until is jail time!! <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Nuff said.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2008%2F04%2F05%2Fjun-2007-to-feb-2008-us-gov-website-defacements-commentary%2F';
  addthis_title  = 'Jun+2007+%26%238211%3B+Feb+2008+U.S.+Gov+Website+Defacements+%2B+Commentary';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>TXDNS v2.1.5 &#8211; A Multithreaded Digger/Brute Forcer For DNS</title>
		<link>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/</link>
		<comments>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 12:01:27 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-diggerbrute-forcer-for-dns/</guid>
		<description><![CDATA[Arley Silveira has released the 1 year anniversary version of TXDNS. Very soon he will release the version 2.2 of TXDNS.

This release implements DNS queries against multiple DNS servers, a more efficient threading algorithm and some minor bug fixes.

 Quoting from the tool&#8217;s official website:

TXDNS main goal is to expose a domain namespace trough a [...]]]></description>
			<content:encoded><![CDATA[<p>Arley Silveira has released the 1 year anniversary version of <a href="http://www.txdns.net" target="_blank" title="TXDNS official website">TXDNS</a>. Very soon he will release the version 2.2 of TXDNS.</p>
<blockquote>
<p align="justify">This release implements DNS queries against multiple DNS servers, a more efficient threading algorithm and some minor bug fixes.</p>
</blockquote>
<p><span id="more-53"></span> Quoting from the tool&#8217;s official website:</p>
<blockquote>
<p align="justify">TXDNS main goal is to expose a domain namespace trough a number of techniques:</p>
<p>-Typos<br />
-TLD rotation<br />
-Dictionary attack<br />
-Brute force</p>
<p>TXDNS may be used to:</p>
<p align="justify">- Fill the reconnaiscence gap left due to DNS servers hardening, as dns-zone transfers are much like to fail.<br />
- Dig a given domain name for possible phishing variations based on common well-known typo algorithms and return dns queries on both used and not used names.<br />
- Stress-test DNS servers due is configurable aggressive behaviour.</p>
<p>TXDNS provides some cool options, such as:</p>
<p>- Perform queries only for a given Resource Record type:<br />
A, CNAME, HINFO, NS, TXT &amp; SOA<br />
- Perform non-recursive queries.<br />
- Perform queries against a given DNS server.</p></blockquote>
<p><a href="http://www.txdns.net/" target="_blank" title="Read more about the latest version of TXDNS - v2.1.5">Read more</a> about the latest version.</p>
<p><a href="http://www.txdns.net/content/download.htm" target="_blank" title="Download TXDNS v2.1.5">Download TXDNS v2.1.5</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Ftxdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns%2F';
  addthis_title  = 'TXDNS+v2.1.5+%26%238211%3B+A+Multithreaded+Digger%2FBrute+Forcer+For+DNS';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSHatter v0.2 &#8211; A Password Brute Forcer For SSH</title>
		<link>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/</link>
		<comments>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 11:33:25 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/</guid>
		<description><![CDATA[Tim Brown from Nth Dimension has coded a cool password brute forcer for SSH called SSHatter.

It is multi threaded and can audit more than one system and account in a given session.

Download SSHatter-0.2

  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Fsshatter-a-password-brute-forcer-for-ssh%2F';
  addthis_title  = 'SSHatter+v0.2+%26%238211%3B+A+Password+Brute+Forcer+For+SSH';
  addthis_pub    = 'dpan';

]]></description>
			<content:encoded><![CDATA[<p align="justify">Tim Brown from <a href="http://www.nth-dimension.org.uk" title="Nth Dimension">Nth Dimension</a> has coded a cool password brute forcer for SSH called SSHatter.</p>
<blockquote>
<p align="justify">It is multi threaded and can audit more than one system and account in a given session.</p>
</blockquote>
<p><a target="_blank" href="http://www.nth-dimension.org.uk/downloads.php?id=34" title="SSHatter v0.2 download from Nth Dimension">Download SSHatter-0.2</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Fsshatter-a-password-brute-forcer-for-ssh%2F';
  addthis_title  = 'SSHatter+v0.2+%26%238211%3B+A+Password+Brute+Forcer+For+SSH';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pen-Test Paper: How An Internal Network Becomes External</title>
		<link>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/</link>
		<comments>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/#comments</comments>
		<pubDate>Sat, 17 Mar 2007 16:15:16 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/</guid>
		<description><![CDATA[My friend SuRGeoN from Greece wrote a very interesting pen-test paper which explains how easy is to convert an internal network into an external with the port redirection technique. He demonstrates the attack scenarios &#8211; including network architecture diagrams &#8211; and goes into great technical details about them.
 
Furthermore,  here are the steps which [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">My friend SuRGeoN from Greece wrote a very interesting pen-test paper which explains how easy is to convert an internal network into an external with the port redirection technique. He demonstrates the attack scenarios &#8211; including network architecture diagrams &#8211; and goes into great technical details about them.</p>
<p> <span id="more-45"></span></p>
<p>Furthermore,  here are the steps which the attacker would follow:</p>
<blockquote><p>1. Information gathering for the external network<br />
2. Seeking for vulnerabilities &amp; misconfigurations<br />
3. Using flaws to get a shell<br />
4. Information gathering for the internal network<br />
5. Escalating privileges for the internal network<br />
6. Converting internal network to external</p></blockquote>
<p>Download SuRGeoN&#8217;s paper from here: [ <a href="http://www.ddosed.com/uploads/penetration_testing/srgn-pentest-01.pdf" title="SuRGeoN - Paper: How an Internal Network Becomes External">srgn-pentest-01.pdf</a> ]</p>
<p align="justify">This information is provided to you ONLY for educational purposes. The way that the information in this paper will be used, depends on the individual’s legal and ethical attitudes. YOUR choice!&#8230; YOUR risk!&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p align="justify">Comments on the paper are of course welcome.  You can also contact SuRGeoN via e-mail: surgeony/\gmail.com (replace /\ with @).</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F17%2Fpen-test-paper-how-an-internal-network-becomes-external%2F';
  addthis_title  = 'Pen-Test+Paper%3A+How+An+Internal+Network+Becomes+External';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Explorer 7: Phishing Using Local Resource Vulnerability</title>
		<link>http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/</link>
		<comments>http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/#comments</comments>
		<pubDate>Thu, 15 Mar 2007 08:56:13 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/</guid>
		<description><![CDATA[Aviv Raff has published on his blog an interesting proof of concept of the vulnerability affecting Internet Explorer v7: a cross-site scripting in the navcancl.htm local resource.

This resource is called when the navigation to a page has been canceled, it displays an error message with a link to reload the current page, however the link [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Aviv Raff has published on his blog an interesting proof of concept of the vulnerability affecting Internet Explorer v7: a cross-site scripting in the navcancl.htm local resource.</p>
<p><span id="more-44"></span></p>
<blockquote><p>This resource is called when the navigation to a page has been canceled, it displays an error message with a link to reload the current page, however the link is not filtered before being used (successful exploitation requires the user to click on the link). The researcher also explains how the browser does not show in the URL the local resource when it is called, this design flaw can thus be combined with the XSS vulnerability to conduct very dangerous phishing attacks.</p></blockquote>
<p>A PoC is available on the Aviv Raff&#8217;s website:<br />
<a href="http://www.raffon.net/research/ms/ie/navcancl/cnn.html">http://www.raffon.net/research/ms/ie/navcancl/cnn.html</a><br />
For those who do not have Internet Explorer 7, a video is also provided:<br />
<a href="http://raffon.net/videos/ie7navcancl.wmv">http://raffon.net/videos/ie7navcancl.wmv</a></p>
<p><strong>Original News #1:</strong> <a href="http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx">http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx </a> by Aviv Raff</p>
<p><strong>Original News #2:</strong> <a href="http://www.xssed.com/news/23/IE7_users_beware_of_Navigation_Canceled_errors/">http://www.xssed.com/news/23/IE7_users_beware_of_Navigation_Canceled_errors/</a> by Kevin Fernandez</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F15%2Finternet-explorer-7-phishing-using-local-resource-vulnerability%2F';
  addthis_title  = 'Internet+Explorer+7%3A+Phishing+Using+Local+Resource+Vulnerability';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://raffon.net/videos/ie7navcancl.wmv" length="483881" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>MSN.co.uk Money Related Websites Hacked And Defaced</title>
		<link>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/</link>
		<comments>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/#comments</comments>
		<pubDate>Thu, 01 Feb 2007 00:14:28 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/02/01/msncouk-money-related-websites-hacked-and-defaced/</guid>
		<description><![CDATA[Two websites belonging to MSN (Microsoft Network) in the United Kingdom, were defaced today by an attacker who goes by the nickname &#8220;DARK LORD&#8220;. It looks like someone who is unethically testing  his SQL injection  skills, and &#8220;feeding&#8221; himself with a false sense of pride, just by leaving the message &#8220;DARK LORD WAZ [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Two websites belonging to <a href="http://www.msn.co.uk" target="_blank" title="MSN.co.uk">MSN</a> (Microsoft Network) in the United Kingdom, were defaced today by an attacker who goes by the nickname <em>&#8220;<a href="http://www.zone-h.org/component/option,com_attacks/Itemid,44/filter_defacer,DARK%20LORD/" target="_blank" title="Zone-H.org - ">DARK LORD</a>&#8220;</em>. It looks like someone who is unethically testing  his <a href="http://www.governmentsecurity.org/articles/SQLInjectionModesofAttackDefenceandWhyItMatters.php" target="_blank" title="SQL Injection: Modes of Attack, Defence, and Why It Matters - Stuart McDonald">SQL injection</a>  skills, and &#8220;feeding&#8221; himself with a false sense of pride, just by leaving the message <em>&#8220;DARK LORD WAZ HERE&#8221;</em>.</p>
<p align="justify">No. I am not a defacer psychologist. I am just  expressing my personal opinion on the matter, which is this: If a website defacement doesn&#8217;t convey a meaningful message, then it is done for selfish reasons.</p>
<p>A bit of an embarassment for Microsoft&#8217;s sysadmins&#8230;</p>
<p><span id="more-26"></span></p>
<p align="justify">The cracker exploited an SQL injection vulnerability in the <em>story.asp</em> file and thus was able to deface the following websites:</p>
<p><em>http://whatinvestment.money.msn.co.uk Win 2003<br />
http://personalfinance.money.msn.co.uk Win 2003</em></p>
<p>Screenshot of the defaced website (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/msncoukdefaced.JPG" title="MSN.co.uk money websites defaced" class="imagelink" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/msncoukdefaced.thumbnail.JPG" style="width: 140px; height: 103px" alt="MSN.co.uk money websites defaced" id="image27" /></a></p>
<p align="justify">The most surprising thing &#8211; actually not very suprising, judging from past cracking incidents of Microsoft&#8217;s systems &#8211; is that the website remained defaced for more than 8 hours and the <a href="http://www.governmentsecurity.org/articles/SQLInjectionModesofAttackDefenceandWhyItMatters.php" title="SQL Injection: Modes of Attack, Defence, and Why It Matters - Stuart McDonald" target="_blank">SQL injection</a> vulnerability has not been fixed yet.</p>
<p>Screenshot (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/msncouksqlinjection.JPG" class="imagelink" title="MSN.co.uk - SQL injection vulnerability" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/msncouksqlinjection.thumbnail.JPG" style="width: 140px; height: 106px" id="image28" alt="MSN.co.uk - SQL injection vulnerability" /></a></p>
<p align="justify">You can view the above website defacements and 2.092.360 &#8211; as for today at 23:00 GMT &#8211; archived digital attacks at <a href="http://www.zone-h.org" title="Zone-H.org - Largest digital attacks archive" target="_blank">Zone-H.org</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F02%2F01%2Fmsn-uk-money-related-websites-hacked-and-defaced%2F';
  addthis_title  = 'MSN.co.uk+Money+Related+Websites+Hacked+And+Defaced';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/02/01/msn-uk-money-related-websites-hacked-and-defaced/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Britney Spears&#8217;s Official German Website Got Hacked And Defaced</title>
		<link>http://www.ddosed.com/2007/01/30/britney-spears-official-german-website-got-hacked-and-defaced/</link>
		<comments>http://www.ddosed.com/2007/01/30/britney-spears-official-german-website-got-hacked-and-defaced/#comments</comments>
		<pubDate>Tue, 30 Jan 2007 19:37:24 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/30/britney-spearss-official-german-website-got-hacked-and-defaced/</guid>
		<description><![CDATA[Was time for the website defacers to hit the music industry!  Yesterday, visitors of the BritneySpears.de website could read &#8220;XTech Inc Onwed the Music Industry&#8230; and the rest of it  &#8221; at the top of the home page. It appears to me though, that they just did it for fun and not for [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Was time for the website defacers to hit the music industry!  Yesterday, visitors of the <a href="http://www.britneyspears.de" title="Britney Spears - Official Website in Germany" target="_blank">BritneySpears.de</a> website could read <em>&#8220;XTech Inc Onwed the Music Industry&#8230; and the rest of it <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> &#8221;</em> at the top of the home page. It appears to me though, that they just did it for fun and not for any serious reason.</p>
<p align="justify">Apparently it was hosted in the same webserver with other official german websites of <a href="http://www.sonybmg.de" title="SonyBMG.de - Official German Website" target="_blank">Sony BMG</a> entertainment.</p>
<p align="justify">The attackers exploited a web application vulnerability &#8211; probably <a href="http://www.securityfocus.com/columnists/427" title="SecurityFocus.com - PHP apps: Security's Low-Hanging Fruit" target="_blank">php inclusion</a> &#8211; in order to get access to the Solaris 9/10 webserver.</p>
<p align="justify"><span id="more-24"></span> The most probable attack scenario was this: Initially a backdoor through a php shell script was run, then shell access through a terminal to the attackers specified port was aquired. Having done this, if a local root exploit is successful, then the attackers have complete access to the webserver, leaving it vulnerable to other cracking teams, usually for a short time span.</p>
<p>Screenshot of the deface (Click thumbnail to view it):</p>
<p><a href="http://www.ddosed.com/wp-content/uploads/2007/01/britneyspearsdeface.JPG" class="imagelink" title="BritneySpears.de defaced" rel="thumbnail"><img src="http://www.ddosed.com/wp-content/uploads/2007/01/britneyspearsdeface.thumbnail.JPG" id="image25" alt="BritneySpears.de Defaced" height="84" width="116" /></a></p>
<p>Here is the list of all the affected websites, along with the OS that they run:</p>
<p><em>http://britneyspears.de   SolarisSunOS<br />
http://stuff.sonybmg.de   SolarisSunOS<br />
http://dms.sonybmg.de   SolarisSunOS<br />
http://stats.bmg.de   SolarisSunOS<br />
http://forum.bmg.de   SolarisSunOS<br />
http://research.sonybmg.de  SolarisSunOS<br />
http://live.bmg.de  SolarisSunOS<br />
http://mediaplayer.sonybmg.de  SolarisSunOS</em></p>
<p>All of the above defacements are archived at <a href="http://www.zone-h.org" title="Zone-H.org - Largest digital attacks archive" target="_blank">Zone-H.org</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F30%2Fbritney-spears-official-german-website-got-hacked-and-defaced%2F';
  addthis_title  = 'Britney+Spears%26%238217%3Bs+Official+German+Website+Got+Hacked+And+Defaced';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/30/britney-spears-official-german-website-got-hacked-and-defaced/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Remote Root Exploit For Linux Kernel 2.6.x. At Auction!</title>
		<link>http://www.ddosed.com/2006/12/02/remote-root-exploit-for-linux-kernel-26x-at-auction/</link>
		<comments>http://www.ddosed.com/2006/12/02/remote-root-exploit-for-linux-kernel-26x-at-auction/#comments</comments>
		<pubDate>Sat, 02 Dec 2006 04:48:18 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2006/12/02/remote-root-exploit-for-linux-kernel-26x-at-auction/</guid>
		<description><![CDATA[It pays to get 0day remote root exploits for vulnerabilities! Digital Armaments Inc. &#8211; an IT security company based in the US &#8211; launched a hacking challenge on the 1st of November on the topic of “Remote Kernel Exploitation” . The challenge will end on the 31st of December and prizes will be given to [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">It pays to get 0day remote root exploits for vulnerabilities! <a href="http://www.digitalarmaments.com" target="_blank">Digital Armaments Inc.</a> &#8211; an IT security company based in the US &#8211; launched a <a href="http://www.digitalarmaments.com/challanges_open.html" title="Kernel Remote Hacking Challenge" target="_blank">hacking challenge</a> on the 1st of November on the topic of “Remote Kernel Exploitation” . The challenge will end on the 31st of December and prizes will be given to the authors of the official advisory reporting the identified vulnerabilities which must result to remote code execution.  The winning advisory will be then sold in an auction.</p>
<p align="justify">Although the official rules of the challenge forbid the disclosure of any vulnerability related information before the end of the challenge, according to the organizers,  news information about important vulnerabilities that worth the early attention of the IT community should be made known before public disclosure of the related exploits. <span id="more-7"></span></p>
<p align="justify">When I visited their website, <a href="http://www.digitalarmaments.com/news_news.shtml" target="_blank">their latest news</a> read that &#8220;EXCLUSIVE Linux Kernel 2.6.x unpatched remote exploit is available at auction to the Platinum Subscription&#8221;.  The fee for the <a href="http://www.digitalarmaments.com/services_platinum.html">Platinum Subscription</a> is 80,000 $ for a year!</p>
<p>My question is: Is the vulnerability so important or the early news about it are for the promotional purposes of the company?</p>
<p align="justify"> I believe is quite obvious that the early news about this vulnerability, were publicized in order to get more people interested in subscribing to their &#8211; in my opinion &#8211; very very expensive services&#8230; Let&#8217;s see what will happen after the 31st of December!</p>
<p>Rumors say that the vulnerability affects the Linux Kernel IPv4 and IPv6.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2006%2F12%2F02%2Fremote-root-exploit-for-linux-kernel-26x-at-auction%2F';
  addthis_title  = 'Remote+Root+Exploit+For+Linux+Kernel+2.6.x.+At+Auction%21';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2006/12/02/remote-root-exploit-for-linux-kernel-26x-at-auction/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
