Geographic Information Systems visual tracert tool

0 Comments

http://www.yougetsignal.com/tools/visual-tracert/

The visual tracert tool displays the path Internet packets traverse to reach a specified destination. The tool works by identifying the IP addresses of each hop along the way to the destination network address. The estimated geophysical location of each hop is identified using MaxMind’s GeoIP database. After all of the hops locations’ are identified, the path to the destination is plotted on a Google Map. More about this tool.

Security Havij 1.08 – Advanced SQL Injection Tool released

1 Comment

Havij
—–


Version 1.08
Copyright © 2009-2010
By r3dm0v3

http://r3dm0v3.persianblog.ir

r3dm0v3[4t]yahoo[.]com
Please tell me your offers and report bugs.
Check for updates!

Licence
——-
This program is free software. I hope it be useful for you.
This software is provided “as is” without warranties.
Feel free to share and distribute it anywhere but please keep the files original!

Disclaimer
———-
I am NOT responsible for any damage or illegal actions caused by the use of this program. So don’t blame me.

What’s New?
———–
-MySQL Blind Injection
-Auto injection type detection
-Admin list, Table list and Column list improved.
-Some errors fixed.

Features
——–
Data Bases: MsSQL 2000/2005 with error, MsSQL 2000/2005 no error, MySQL, MysqlBlind Oracle, MsAccess
Find admin page
Getting Information
Auto type detection (string or integer)
Getting Tables, Columns, Data
Command Executation (mssql only)
Reading Files (mysql only)
insert/update/delete data
Proxy support
Guessing tables and columns in mysql<5
Fast getting tables and columns for mysql.
Checking different injection syntaxes.
Changing http headers
Bypass illegal union.
Avoid using strings.

Security removing traces of hack/log files

1 Comment

Removing traces of unix system is very important issue for offensive security.
That needs to be cleaned a portion of the log files I’ve shared below.

Solaris System Logs
==
cat /dev/null > /var/adm/wtmpx
cat /dev/null > /var/adm/utmpx
cat /dev/null > /var/adm/loginlog
cat /dev/null > /var/adm/lastlog
cat /dev/null > /var/adm/sulog
cat /dev/null > /var/adm/messages

Redhat System Logs
==
Located in /etc/syslog.conf

Common Linux log files name and usage
==
/var/log/message: General message and system related stuff
/var/log/auth.log: Authenication logs
/var/log/kern.log: Kernel logs
/var/log/cron.log: Crond logs (cron job)
/var/log/maillog: Mail server logs
/var/log/qmail/ : Qmail log directory (more files inside this directory)
/var/log/httpd/: Apache access and error logs directory
/var/log/lighttpd: Lighttpd access and error logs directory
/var/log/boot.log : System boot log
/var/log/mysqld.log: MySQL database server log file
/var/log/secure: Authentication log
/var/log/utmp or /var/log/wtmp : Login records file
/var/log/yum.log: Yum log files

Apache Logs
==

errorlogs
accesslogs

Shell Logs
==

.bash_history

Application Logs
Database Logs

Suggestions for the development of the document, Email: knyuksel@gmail.com,
Ali Okan YÜKSEL 22.03.2010 – izmir

Security ICQ hacking /5digit-6digit primary mail address

0 Comments

http://elite.bombing.ru/pub/

90ların sonu gibi oldukca populer bir yarıştı icq numaralarıyla ugraşmak, artık popülerliğini yitirmiş gibi gözüksede hala kurcalayan meraklıları varsa yukarıdaki adresde değerli kayıtlar var, güncel bilgilerde mevcut…

5digits 6digits good digits primary mail address

meraklılarına

Linux, Solaris Konsol’da belli bir zamandan önceki dosyalarla işlem yapmak

0 Comments

# find . -type d -mtime +720 -exec echo "mv " {} "/home/okan/okandosyayedekpath/" {} \; | sed 's/path\/ /path\//g' > islemyap.sh
 
# sh islemyap.sh

Binlerce dosyanın yer aldığı bir klasördeki dosyaların bir kısmını başka bir dizine yedekleme ihtiyacı duyabilirsiniz. find komutu ile beraber kullanabileceğiniz mtime parametresi size bu konudaki zaman kısıtını belirlemenizi sağlıyor, exec parametresini kullanarak istediğimiz direktifleri ekrana ekrana yazdırıyoruz ve sed ile gelen sonuçları replace ederek komutu istediğiniz biçime sokuyoruz ve çıkan sonucu isleyap.sh dosyasına aktarıyoruz…

sonuç olarak “mv dosya yenipath/dosya” şeklinde oluşturduğumuz script dosyamızı çalıştırması kalıyor…

Linux Ubuntu 9.10(Karmic) compiz fusion

0 Comments

Ubuntu 9.10 masaüstü efeklerini kullanabilmeniz için ayarlamaların anlatıldığı bağlantı: http://www.ubuntugeek.com/how-to-install-and-configure-compiz-fusion-in-ubuntu-9-10karmic.html

Security Ters mühendislik öğrencileri için tek sayfa notlar

0 Comments

X86/Win32 Reverse Engineering Cheat-Sheet
A one page cheat sheet for people learning to reverse engineer. by nickharbour
http://rnicrosoft.net/docs/X86_Win32_Reverse_Engineering_Cheat_Sheet.pdf

Security En çok karşılaşılan ve yapılmaması gereken kodlama hataları

0 Comments

http://cwe.mitre.org/top25/#Listing

Security Richtext editors – vulnerable sample files

0 Comments

FCKeditor

- http://victim.com/FCKeditor/editor/filemanager/browser/default/connectors/test.html
- http://victim.com/FCKeditor/editor/filemanager/connectors/test.html
- http://victim.com/FCKeditor/upload/test.html
- http://victim.com/FCKeditor/_samples/samplelist.html
- http://victim.com/FCKeditor/_samples/default.html

CHeditor

- http://victim.com/cheditor/insert_image.html
- http://victim.com/cheditor/example/basic.html

gmEditor

- http://victim.com/gmEditor/demo.php
- http://victim.com/gmEditor/upfile.php
- http://victim.com/gmEditor/upfile.htm

Seditor (Smart Editor)

- http://victim.com/SEditor/imgupload.aspx
- http://victim.com/SEditor/imgupload.html

Zeditor

- http://victim.com/zEditor/zEditor.html

cmEditor

- http://victim.com/cmEditor/Editor.html

Source: http://moriper.egloos.com/3516630

FreeBSD FreeBSD 8.0 released

0 Comments

http://www.freebsd.org

The FreeBSD Release Engineering Team is pleased to announce the availability of FreeBSD 8.0-RELEASE. This release starts off the new 8-STABLE branch which improves on the functionality of FreeBSD 7.X and introduces many new features. Some of the highlights:

  • Xen Dom-U, VirtualBox guest and host, hierarchical jails.
  • NFSv3 GSSAPI support, experimental NFSv4 client and server.
  • 802.11s D3.03 wireless mesh networking and Virtual Access Point support.
  • ZFS is no longer in experimental status.
  • Ground-up rewrite of USB, including USB target support.
  • Continued SMP scalability improvements in many areas, especially VFS.
  • Revised network link layer subsystem.
  • Experimental MIPS architecture support.