Sunday, March 04, 2007

Site: www.techworks.in
Multiple XSS bugs
Risk: Medium-High



They're ""Official EC-Council distributor, India""



Full-Disclosure - We believe in it ;)

/Quit

Thursday, March 01, 2007

Originally posted on the 14th of Feb, Yeah, Iam sorry, late by 2 weeks. Still worth a laugh.

Acunetix survey says : 70% of websites, out of it's 3200 scanned ones were vulnerable to attacks.

Then, Network world and it's "go-to-guy" Joel Snyder, a.k.a Security expert, replies back

Thomas Ptacek, a guru at Matasano, gives his take on the issue.

Acunetix gives back some statistics and it's report...

I learnt to laugh like an Italian friend of mine, UAUAUAUAUAUAUAUAUAUAUAUAUA !!
You must try it too ... it's fun to laugh, it's the best way to forget all your worries...

Jokes apart, the truth is conveyed here humorously... You must note that somewhere in the context is mentioned, Acunetix's numbers are low ...

/Ale vide

Monday, February 26, 2007

Site: www.tcs.com (Tata Consultancy Services)
Multiple SQL Injection/XSS bugs
Risk: Medium-High



The company which can't secure it's site is providing services on Security. WOW !!!
http://www.tcs.com/esecurity => Check this out ;)



SQL Injection - Do you want me to be the DBA ;) ??



Cross Site Scripting - Do you see phishing coming your way ;) ??




I sent an email back in December 2006, they're so responsible not to fix their bugs even after 2 months. I sent the email to their Information Security Manager, Chennai, not to admin/webmaster/or any default address. No response until date (see picture)

Email sent to "Full-Disclosure - We believe in it ;)"

Cheers :)

Sunday, February 18, 2007



Got a reply from them, they want to fix it now :)



My reply for their email.
With this, Iam closing this issue. Seems they've come to terms with me :)

Full-Disclosure - We believe in it ;)

Cheers :)
Posted to Full-Disclosure list, copied to LegionSec



Full-Disclosure - We believe in it

On a sidenote, this post got dugg !

Cheers :)

Saturday, February 17, 2007



I never expected them to reply but they did ! What a surprise ;)




So here's my reply... to them.

Full-Disclosure - We believe in it

Cheers :)

Update to my previous post :)

Possibility to fetch files such as /etc/passwd
http://www.flconferences.com/download.php?file=/legionsec_1/archive/LegionSec'06___Vicente.pdf => Example

Click on the above link to see "Function.fopen"

When it lists out "fopen(/hsphere/local/home/flconf/flconferences.com/user_conference/legionsec_1/archive/LegionSec\'06___Vicente.pdf"

What amount of time will it take for an attacker, to manipulate this function and retrieve critical files as /etc/passwd or /etc/shadow

With this kind of information in hand, the extent of damage that can be done is "maximum"

Documentation for Function.fopen from PHP Website.

Full-Disclosure - We believe in it.


Cheers :)

Advisory by Kishfellow

Site: www.flconferences.com (LegionSec)
Multiple XSS vulnerabilities
Risk: Medium-High




Picture says it all ...

Full-Disclosure - We believe in it.

/Quit

Wednesday, January 10, 2007

Whoa ! ... I just can't believe that I got myself a BOSE headfone [considered to be really the best money can buy, for a headfone or any sound equipment]

You have the "Right to laugh ;)" ... >> See this post <<
I don't believe that he is such a geek, he uses V=IR to describe parallel dating ;))
~ Hats off to you bro ~

Cheers :)

Tuesday, January 02, 2007

The new HD-DVD [High definition DVD] already cracked ?

Rumors arose early on the new year that a hacker named muslix64 has compromised the encryption called AACS [both blu-ray & hd-dvd use the same encryption]

Read the news brief from three sources :)

NewYork Times - >> Read more <<
ComputerWorld - >> Read more <<
ZDnet - >> Read more <<

On a side note, happy new year to all of you :)

I heard from a friend of mine, that this year starts and ends with a monday, it has the most number of saturdays & sundays... and no public holidays fall on sunday. Hence, this is a new year with least working days according to the anonymous friend who informed me :)

/Quit

Thursday, December 28, 2006

Today as usual I booted in windows 2000 and inspected this "strange" piece of malware [a trojan].

I must really compliment the author of this malware, since he does a good job by deleting important files like mp3,mpeg,pr0n and other illegal stuff that people download off p2p software ;))

Credits fly to you, whoever you are !!

Read more here ...


/Quit

Tuesday, December 26, 2006

Santa gave me a lot of gifts for christmas of which two were very good,
so Iam sharing with you people ;))

Trust me, he gave me an oppurtunity to see the power of RainbowTables [ >>Here << ]

Ofcourse, he gave me toys to play too ... Check this out ...

Cheers :)

Saturday, December 23, 2006

I was doing a bit of wifi-hacking recently... playing with toys ;-)

Recommended reading => Blackhat Slides [Laurent Butti and Franck Veysett]

/me (Quit :)

Wednesday, December 20, 2006

I've not been with my computer for the last few days ... went out shopping, spotting and doing stuff that I don't do regularly ;)

The surprising thing is I couldn't withstand touching my laptop everyday for emails. . .

I just signed off the internet 8 days ago, and here Iam, back ... Back with a bang ?! Probably.

I just re-energized myself and feels good to be ranting here :)

/Pull D' Plug

Tuesday, December 05, 2006


Muscles & Fitness - Training system library is worth every penny you invest in it ...

I just bought the 5 DVDs for 40 US Dollars, I think it's an incredible source for body building.

I'll write more about this dvd shortly ...

On a side note, weight that we gain is reversible ... Lots of things are "reversible" in life, and reversing comes naturally ;)

GPS is having it's gcc toolkit ready. I have been examining the board for a while now, and coding the processor module for nintendo with the opcodes.

If someone needs the opcodes for v831 processor, let me know through email.

Cheers :)

Monday, November 06, 2006

http://www.videojug.com/film/how-to-fold-a-t-shirt-in-2-seconds

Amazing piece of "work" ... I saw the comments section, and many people complaining about the video's speed. Use the pause button around 10-12 times in the 2 seconds when they show the folding ;)

100% working, try it

Thursday, November 02, 2006

Couple of neat pen-tests were done in the last month. This month I have a mighty big cake in my hand with over a thousand desktops and a few servers, from an organization. ;)

Now about the new reverse-engg project at hand, the GPS unit. It runs on Nintendo processor.

Manufacturer : NEC Corporation
Processor Model : v831
Addn Info: 32 bit Microprocessor



Iam still working on the details of this circuit's datasheet, as of now Iam building a GCC kit for this thingy.

/Ale vide

Sunday, October 29, 2006

Today , thoughts that traverse through my mind almost daily has come to a stop.
Seems there is something I failed to realize ... Yes, I have realized "an important" thing
about life. I slept the whole day and Iam blogging now. The SL33P factor has been missing
for the past few years of my life ... which I think has bothered me enough. So Iam planning
to compensate for my misdoings now ;) ...

/part

Friday, October 20, 2006

News... warezov variants are making a lot of headlines in AV blogs.

Today being Diwali, here is a traditional way of saying happy diwali to all my friends here.

जलते जगमगाते रहे, हम आपको आप हमको याद आते रहे जब तक जिन्दगी है, दुआ है हमारी "आप चाँद की तरह जगमगाते रहे" दीपों के पर्व दीपावली की हार्दीक शुभकामनाएँ !!!

Ofcourse, I've got my English version too ... ;))

I wish you all a very Happy Diwali and an even prosperous New Year

Then I've got new toys coming my way for a fresh reverse-engineering challenge.

GPS - Global Positioning system , this time is my target. Seems there is some kinda DVD unit that won't play regular DVDs. After the car ecu and tv hacks, I've started to get a firm grasp on embedded stuff and hardware hacking.

I think this project will go well ;)

I will keep you all posted.

Cheers :D

Wednesday, October 18, 2006

http://www.gizmodo.com/gadgets/gadgets/mcdonalds-im-lovin-malware-207639.php

Story from Gizmodo on McDonald's malware ;))

Iam loving it !!

/Quit