|
|
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : One good thing is that I am a multitasker, because often I tend to juggle multiple things, many, many things infact, in my life all at once and still keep sane. Yay for me. School is starting back and the pre-test for a This could be painful class titled Computer Literacy is a joke. Of 130 questions, around 50 were how to do this and that in sometimes vague format but many details on microsoft office products. A lot of the rest were an unusual form of redundancy, and quite honestly, I don't see Bill Gates breezing through this pre-exam. At least I should have gotten all the networking and How to click on an icon -like questions correct. I guess I'll be taking advantage of the full course this semester and learn ... stuff... ARG. Oh well, my other classes seem alright though.. I'll have some fun I'm sure. Browser Fuzzer 2 was recently released. I will be releasing some things under Krakow Labs now, so you may want to check there every once in a while or look for new releases on the security sites. By the way, what is up with people turning in DoS vulns as full blown buffer overflow exploits .. its slightly confusing when I'm seeing them come in and my eyes light up just to be let down when theres literally no possibility of useful code getting executed. Its not too bad when there is at least a possibility of code execution, but when you have no control of the registers and you paste output that clearly shows you haven't got a clue.. thats.. I'm going to do another Wow. , ok. Alright, that should do it .. much better now On another note, Xmail on debian sarge etch logs POP3 usernames and passwords in readable and writeable logs. The versions they both use don't even support the 'fix' for the 'feature', so happy harvesting. Ubuntu's latest version has only username logging enabled by default. I believe they implemented this 'feature' the one that defines password logging or not.. HMMM in 1.25 or something. bugs debian nc localhost 110 OK XMail 1.21 POP3 Server service ready Sun, 18 Jan 2009 01 59 32 -0500 USER boxer OK Password required for boxer localhost PASS superman OK Maildrop has 0 messages 0 bytes LIST OK 0 0 . QUIT OK XMail 1.21 POP3 Server closing session bugs debian grep boxer var log xmail pop tail -1 localhost.localdomain localhost 127.0.0.1 2009-01-18 01 59 37 boxer superman bugs debian Note superman really isn't my password, lol. Above is the example on sarge, tested on Etch too. Here is some interesting uri stuff to play with on IE res ieframe.dll preview.dlg res ieframe.dll dnserror.htm res ieframe.dll 24 123 res ieframe.dll MUI 1 res ieframe.dll TYPELIB 1 res ieframe.dll UIFILE 20481,20482,20483,20484,20484,20485,20486,20487,39216,41555 res ieframe.dll WEVT_TEMPLATE 1 res ieframe.dll Version Info 1 res ieframe.dll 23 ABOUT.js res ieframe.dll 23 ANALYZE.js res ieframe.dll 23 ANCHBRWS.js res ieframe.dll 23 DOCBROWS.js res ieframe.dll 23 ERROR.js res ieframe.dll 23 HTTPERRORPAGESSCRIPTS.js res ieframe.dll 23 IEERROR.js res ieframe.dll 23 IMGBROWS.js res ieframe.dll 23 INVALIDCERT.js res ieframe.dll 23 ORGFAV.js res ieframe.dll 23 PHISHSITE.js res ieframe.dll 23 POLICY.js res ieframe.dll 23 PREVIEW.js res ieframe.dll preview.dlg dialog res ieframe.dll 23 PSTEMPLATES.js res ieframe.dll 24 123 XML file Some I got myself but most I found here a while back when I was researching IE. Thanks to that guy for most of them. Research continues, the show must go on.. I am in a deep development mind set right now and my fingers won't let me stop typing.. HACKER GET WHAT HACKER WANT like that one commercial.. lol Get Unique.
Les derniers articles du site "Jeremy's Computer Security Blog" :
- What did they fix - Adobe Flash Temporary Filename Scheme - Reverse Engineering File Formats - Browser Fuzzer 3 - Writing Code that Breaks Code - Mozilla Code sighs - From Static Analysis to 0day Exploit - Some vendors are 'unconcerned' - Firefox Local Download Manager Vulnerability - Desktop Management Interface DMI
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|