<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7832887832011382499</id><updated>2011-12-27T21:08:58.275+08:00</updated><category term='Python'/><category term='shellcode'/><category term='Backdoored'/><category term='reverse engineering'/><category term='Aplication'/><category term='Meterpreter'/><category term='metasploit'/><category term='Windows'/><category term='Security'/><category term='Movie'/><category term='forensics'/><category term='Web'/><category term='Rootkits'/><category term='Exploitation'/><category term='Stuxnet/Duqu'/><category term='Malware'/><category term='Browser'/><category term='ios'/><category term='Linux'/><category term='Virus'/><category term='Wifi'/><category term='Networking'/><category term='Vulnerability'/><category term='Exploits'/><category term='Honeypot'/><category term='Jailbreak'/><category term='Hacking'/><category term='Hijacking'/><category term='password attack'/><category term='Android'/><category term='Facebook'/><category term='News'/><category term='Cloud'/><category term='HTML5'/><title type='text'>c0decstuff</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default?start-index=101&amp;max-results=100'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>137</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7435695919551414303</id><published>2011-12-20T02:58:00.001+08:00</published><updated>2011-12-20T03:08:14.933+08:00</updated><title type='text'>Hacking VLAN</title><summary type='text'>Introduction

In Virtual LAN or VLAN is a group of hosts communicate with each other, even thoughthey are in different physical location. Virtual LAN provides location independence to the users, able to save the bandwidth, manage the device, cost effective for the organization are some of the facilities provided by the Virtual LAN.

VLAN is based on Layer 2 “Data link” of the OSI Model. The OSI </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7435695919551414303/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/12/hacking-vlan.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7435695919551414303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7435695919551414303'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/12/hacking-vlan.html' title='Hacking VLAN'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-imaJronnR78/Tu-CwP9R4UI/AAAAAAAAAMA/t_kgWrqZwtg/s72-c/120711_2318_VLANHacking1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3374929443742905966</id><published>2011-12-20T02:13:00.000+08:00</published><updated>2011-12-20T02:13:07.224+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='shellcode'/><title type='text'>Bypassing EMET’s EAF with custom shellcode using kernel pointer</title><summary type='text'>Recently I have been testing out Microsoft’s “Enhanced Mitigation Experience Toolkit” (EMET) tool for exploit mitigation. This is a free tool and is designed to harden or secure applications without having to recode them. One exploit I used to test was Adobe Flash’s “Action script type confusion” vulnerability (CVE-2010-3654). This vulnerability affects version 10.1.53.64 and below. I used the </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3374929443742905966/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/12/bypassing-emets-eaf-with-custom.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3374929443742905966'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3374929443742905966'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/12/bypassing-emets-eaf-with-custom.html' title='Bypassing EMET’s EAF with custom shellcode using kernel pointer'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Jox4O8TtYd0/Tu96ZC_uilI/AAAAAAAAALo/W-rKqK-RVrM/s72-c/mamank.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1901194523696184107</id><published>2011-12-05T03:28:00.001+08:00</published><updated>2011-12-05T03:29:54.102+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>AndroidMalwareAnalysis</title><summary type='text'>Foncy
Foncy is a sms android malware which targets european countries, with few analysis :

kaspersky
We can analyze it (sample sha256: 98a402d885cdb941dca8b45a4bbcbbe7f44ba62910d519bc1c2161dba117ebd2) with Androguard, and Ded decompiler:


And we can obtain easily where permissions are used:


The sendTextMessage method is called 5 times in the bytecodes. If you would like to have a better view </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1901194523696184107/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/12/androidmalwareanalysis_05.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1901194523696184107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1901194523696184107'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/12/androidmalwareanalysis_05.html' title='AndroidMalwareAnalysis'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-7xF__o-QjiM/TtvGxZH1_jI/AAAAAAAAAJ4/1Wy57HgoeOk/s72-c/foncy1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7427929927471048247</id><published>2011-11-27T22:31:00.000+08:00</published><updated>2011-11-27T22:31:23.832+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><title type='text'>How to Fix iOS 5 Errors</title><summary type='text'>How to fix iOS 5 Problems ? Believe me almost every user of iOS 5 must have been faced with such errors while updating to iOS 5. The problem might have been a result of excessive phone calls, downloading, updating and pinging Apple’s servers.
There is nothing much to worry about, but the only solution is to carry on with the updating trials. The following tips work and all only for those who are </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7427929927471048247/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/how-to-fix-ios-5-errors.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7427929927471048247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7427929927471048247'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/how-to-fix-ios-5-errors.html' title='How to Fix iOS 5 Errors'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-QPEBbUww5nQ/TtJJXsKRAhI/AAAAAAAAAJw/e84bsKBV1pU/s72-c/images.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6813974949822409993</id><published>2011-11-27T22:04:00.000+08:00</published><updated>2011-11-27T22:04:42.970+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='Jailbreak'/><title type='text'>Jailbreak iOS 5.0/iOS 5.0.1 Using Ac1dSn0w</title><summary type='text'>Wait, don’t get your hopes up! Yes, Ac1dSn0w is a new jailbreak tool but it doesn’t bring a new “jailbreak” for iPhone 4S, iPad 2 or untethers iOS 5. Ac1dsn0w jailbreak tool developed by PwnDevTeam which makes jailbreaking much easier. Below we’ll explain more.

Ac1dSn0w beta version is now available which is currently available only for Mac OS X users. It does a tethered jailbreak of iOS 5 and </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6813974949822409993/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/jailbreak-ios-50ios-501-using-ac1dsn0w.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6813974949822409993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6813974949822409993'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/jailbreak-ios-50ios-501-using-ac1dsn0w.html' title='Jailbreak iOS 5.0/iOS 5.0.1 Using Ac1dSn0w'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-caBBF37ne0U/TtJCH28-4OI/AAAAAAAAAJY/LAnQm8AHRx4/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1682844380054039564</id><published>2011-11-17T06:50:00.013+08:00</published><updated>2011-11-17T07:34:18.207+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><title type='text'>Anatomy of Self Inflicted Javascript Injection "facebook"</title><summary type='text'>Facebook: Anatomy of Self-Inflicted Javascript InjectionMany are already familiar with "likejacking" (a form of "clickjacking") in which a user is tricked into clicking on and interacting with the Facebook "like" button -- this has been one of the most common vectors of abusing Facebook. For example, the "like" button may be hidden behind an image such as a picture of an embedded YouTube video </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1682844380054039564/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/facebook-anatomy-of-self-inflicted.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1682844380054039564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1682844380054039564'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/facebook-anatomy-of-self-inflicted.html' title='Anatomy of Self Inflicted Javascript Injection &quot;facebook&quot;'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-4o_XBmGt5TI/TsPZ0xkYL_I/AAAAAAAAAzI/-AOsZsJLbpA/s72-c/Screen+shot+2011-11-16+at+10.34.08+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6816922455361544871</id><published>2011-11-14T23:52:00.000+08:00</published><updated>2011-11-14T23:52:59.118+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud'/><title type='text'>Understanding Private Clouds</title><summary type='text'>




   </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6816922455361544871/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/understanding-private-clouds.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6816922455361544871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6816922455361544871'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/understanding-private-clouds.html' title='Understanding Private Clouds'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8188105985813409996</id><published>2011-11-14T05:02:00.004+08:00</published><updated>2011-11-14T05:14:18.687+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HTML5'/><title type='text'>HTML5, Local Storage, and XSS</title><summary type='text'>A nice new feature of HTML 5 is local storage. Briefly, this is a client side storage option that can be easily accessed via JavaScript. The benefit of local storage over other client side storage options is that local storage allows more storage space than other options (cookies, flash obj, etc). In addition, unlike cookies, the data is not automatically appended to every request by the browser.</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8188105985813409996/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/html5-local-storage-and-xss.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8188105985813409996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8188105985813409996'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/html5-local-storage-and-xss.html' title='HTML5, Local Storage, and XSS'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1289562704091471538</id><published>2011-11-13T00:26:00.000+08:00</published><updated>2011-11-13T00:26:25.066+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Honeypot'/><title type='text'>Honey Potting for MS11-083</title><summary type='text'>MS11-083  has arrived and people are getting both excited and scared, it looks  like its going to be the next MS08-067. Which if you remember, Conficker  used to bend windows over and have a jol. Time for a honeypot?

In anycase I took a moment and decided to write a script that would  capture potential MS11-083 traffic in an attempt to capture this exploit  in the wild (once its out there, might</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1289562704091471538/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/honey-potting-for-ms11-083.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1289562704091471538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1289562704091471538'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/honey-potting-for-ms11-083.html' title='Honey Potting for MS11-083'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4566862311568469462</id><published>2011-11-09T08:40:00.003+08:00</published><updated>2011-11-09T08:43:17.997+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Stuxnet/Duqu'/><title type='text'>Duqu Installer Contained Microsoft Word Zero-Day Exploit</title><summary type='text'>Earlier this week Symantec released an update on Duqu. Apparently an installer was found for Duqu (dubbed Stuxnet II) that used a Microsoft Zero-day:
   
“The installer file is a Microsoft Word document (.doc) that exploits a previously unknown kernel vulnerability that allows code execution. We contacted Microsoft regarding the vulnerability and they’re working diligently towards issuing a patch</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4566862311568469462/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/duqu-installer-contained-microsoft-word.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4566862311568469462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4566862311568469462'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/duqu-installer-contained-microsoft-word.html' title='Duqu Installer Contained Microsoft Word Zero-Day Exploit'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8704829854445616340</id><published>2011-11-09T08:35:00.000+08:00</published><updated>2011-11-09T08:35:38.008+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>The History of Computer Viruses</title><summary type='text'>   </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8704829854445616340/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/history-of-computer-viruses.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8704829854445616340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8704829854445616340'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/history-of-computer-viruses.html' title='The History of Computer Viruses'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5969310280548542244</id><published>2011-11-09T08:14:00.000+08:00</published><updated>2011-11-09T08:15:00.000+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><title type='text'>Memory Forensics</title><summary type='text'>Pull Process &amp; Network Connections from a Memory Dump   

In the previous article, we learned how to pull passwords from a memory dump file. This time, we will cover viewing a process list and network connections out of captured memory files.
Volatility’s “pslist” command can be used to view the processes that were running on a Windows system:
volatility pslist -f memdumpfilename.raw –profile=</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5969310280548542244/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/memory-forensics.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5969310280548542244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5969310280548542244'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/memory-forensics.html' title='Memory Forensics'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2669656539718275386</id><published>2011-11-07T19:38:00.002+08:00</published><updated>2011-11-07T19:44:02.709+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hijacking'/><title type='text'>Hijacking Google Analytics</title><summary type='text'>The Rambling IntroThis is a fun one I came up with while looking at a site this week. I  feel sure that somebody else must have come up with this before me, but  I’ve never seen anyone blog about it or anything, so here goes.
The back story is that somebody posted a link to some “password  strength checker” website, in which of course you type your password and  it tells you how long it thinks it</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2669656539718275386/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/hijacking-google-analytics.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2669656539718275386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2669656539718275386'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/hijacking-google-analytics.html' title='Hijacking Google Analytics'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7876493468375842726</id><published>2011-11-07T06:08:00.000+08:00</published><updated>2011-11-07T06:08:06.117+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>RemoteExec Computers List Buffer Overflow ROP Exploit</title><summary type='text'>In this post I’ll be writing about a ROP (Return Object Programming)  exploit that I had recently developed for a vulnerability I had  discovered in an application called “RemoteExec”. The vulnerability is  caused when opening a .rec file containing an overly long line  triggering a stack-based buffer overflow. It was first published in  March 2010 reported in version 4.04 and fixed in version </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7876493468375842726/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/remoteexec-computers-list-buffer.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7876493468375842726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7876493468375842726'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/remoteexec-computers-list-buffer.html' title='RemoteExec Computers List Buffer Overflow ROP Exploit'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3856611305670101223</id><published>2011-11-04T22:14:00.000+08:00</published><updated>2011-11-04T22:14:50.213+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jailbreak'/><title type='text'>Jailbreak iOS 5.0.1 On Windows Using Sn0wbreeze 2.8b9 – video</title><summary type='text'>Sn0wbreeze  v2.8b9 has been released by iH8snow the well known hacker to jailbreak  iOS 5.0.1 beta, the new jailbreaking tool fixes ibooks sandbox crashing  issues,  location services issues with iPhone 3GS users running the iPad  baseband finally Sn0wbreeze v2.8b9 fixes many issues and bugs.
Notes: Don’t forget it’s a tethered jailbreak for all device expect iPhone 3G old bootrom and it does not</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3856611305670101223/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/jailbreak-ios-501-on-windows-using.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3856611305670101223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3856611305670101223'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/11/jailbreak-ios-501-on-windows-using.html' title='Jailbreak iOS 5.0.1 On Windows Using Sn0wbreeze 2.8b9 – video'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4267974489916765732</id><published>2011-10-29T01:37:00.000+08:00</published><updated>2011-10-29T01:37:33.383+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Stuxnet/Duqu'/><title type='text'>Win32/Duqu analysis: the RPC edition</title><summary type='text'>My Russian colleagues Aleksandr Matrosov and Eugene Rodionov have  found some time to do some more analysis on Win32/Duqu. (Don’t you guys sleep?)
In the previous post (http://blog.eset.com/2011/10/25/win32duqu-it%e2%80%99s-a-date)  they concentrated on analyzing the Duqu configuration file format and  extracting the exact date on which the system was infected. This time  they investigated Duqu’s</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4267974489916765732/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/10/win32duqu-analysis-rpc-edition.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4267974489916765732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4267974489916765732'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/10/win32duqu-analysis-rpc-edition.html' title='Win32/Duqu analysis: the RPC edition'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4917163774155083650</id><published>2011-10-28T04:45:00.007+08:00</published><updated>2011-10-28T04:56:35.677+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><title type='text'>Facebook Attach EXE Vulnerability</title><summary type='text'>1. Summary:
When using the Facebook 'Messages' tab, there is a feature to attach a  file. Using this feature normally, the site won't allow a user to attach  an executable file. A bug was discovered to subvert this security  mechanisms. Note, you do NOT have to be friends with the user to send  them a message with an attachment.
--------------------------------------------------------------------</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4917163774155083650/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/10/facebook-attach-exe-vulnerability.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4917163774155083650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4917163774155083650'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/10/facebook-attach-exe-vulnerability.html' title='Facebook Attach EXE Vulnerability'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-nK7L1bL6W3Y/Tqjerfrk9hI/AAAAAAAAACs/6drfxevKiIc/s72-c/error_uploading.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2537378782923773108</id><published>2011-08-19T07:08:00.000+08:00</published><updated>2011-08-19T07:08:07.093+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Vulnerabilities in DNS Server Could Allow Remote Code Execution</title><summary type='text'>Released MS11-058  to address two vulnerabilities in the Microsoft DNS Service. One of the  two issues, CVE-2011-1966, could potentially allow an attacker who  successfully exploited the vulnerability to run arbitrary code on  Windows Server 2008 and Windows Server 2008 R2 DNS servers having a  particular DNS configuration. We’d like to share more detail in this  blog post and help you make a </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2537378782923773108/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/08/vulnerabilities-in-dns-server-could.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2537378782923773108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2537378782923773108'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/08/vulnerabilities-in-dns-server-could.html' title='Vulnerabilities in DNS Server Could Allow Remote Code Execution'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7724782383335328944</id><published>2011-08-19T07:03:00.000+08:00</published><updated>2011-08-19T07:03:17.435+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>SANS Investigate Forensic Toolkit (SIFT) Workstation v.2.1 Released</title><summary type='text'>An international team of forensics  experts, led by SANS Faculty Fellow Rob Lee, created the SANS  Investigative Forensic Toolkit (SIFT) Workstation and made it available  to the whole community as a public service. The free SIFT toolkit, that  can match any modern forensic tool suite, is also featured in SANS'  Advanced Computer Forensic Analysis and Incident Response course (FOR  508). It </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7724782383335328944/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/08/sans-investigate-forensic-toolkit-sift.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7724782383335328944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7724782383335328944'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/08/sans-investigate-forensic-toolkit-sift.html' title='SANS Investigate Forensic Toolkit (SIFT) Workstation v.2.1 Released'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5507486253490186648</id><published>2011-07-08T04:48:00.002+08:00</published><updated>2011-07-08T05:13:53.108+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>Breaking MailEnable 2.34: A lesson in security featuring Metasploit, Immunity Debugger, and mona.py</title><summary type='text'>Not that this is any major feat, but I thought it would do as a nice primer to investigating bugs Immunity Debugger and mona.py and exploiting them with Metasploit.


I  was researching a vulnerability today, Metasploit has a module called  mailenable_login with a target of MailEnable 2.35. Doing some research  into the exploit, it is a buffer overflow, and not just 2.35 is  vulnerable to this </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5507486253490186648/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/breaking-mailenable-234-lesson-in.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5507486253490186648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5507486253490186648'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/breaking-mailenable-234-lesson-in.html' title='Breaking MailEnable 2.34: A lesson in security featuring Metasploit, Immunity Debugger, and mona.py'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-4zhrzO4K3Lw/ThUKgMTxBYI/AAAAAAAAAKI/cD1nSlXwt3A/s72-c/MailEnable%2B%2540%2B2011-07-06%2B19%253A25%253A21.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7904356551869371839</id><published>2011-07-08T04:29:00.001+08:00</published><updated>2011-07-08T04:32:55.682+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Meterpreter'/><title type='text'>Meterpreters new reverse_http and reverse_https options</title><summary type='text'>So we’ve all been unlucky enough to have a meterpreter session die on  us, and then we’ve all been unlucky enough that we cannot re-exploit  the box using the same vulnerability for some reason or another.
No one I know in the White Hat scene likes to use any form of  persistence with a payload; and you’d be nuts to use the bind_tcp option  through fear of leaving it running. (I’ve heard horror </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7904356551869371839/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/so-weve-all-been-unlucky-enough-to-have.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7904356551869371839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7904356551869371839'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/so-weve-all-been-unlucky-enough-to-have.html' title='Meterpreters new reverse_http and reverse_https options'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4008579918724939139</id><published>2011-07-08T04:18:00.004+08:00</published><updated>2011-07-08T04:35:30.151+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>Capture all metasploit input/output</title><summary type='text'>I know how we all have our own way of copy/paste from console windows but metasploit has just introduced a new feature as of r13028.
You can now save all of the output of metasploit (including meterpreter) to a file using the spool command:

spool /root/msf3_output.txt
[OWNAGE GOES HERE]
spool off
Or to ensure you always have a log of what you are doing add to the ~/.msf3/msfconsole.rc file (</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4008579918724939139/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/capture-all-metasploit-inputoutput.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4008579918724939139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4008579918724939139'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/capture-all-metasploit-inputoutput.html' title='Capture all metasploit input/output'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1017223207593200898</id><published>2011-07-08T02:15:00.000+08:00</published><updated>2011-07-08T02:15:40.185+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Pwning Mac OS X with evilgrade + MacPorts</title><summary type='text'>The idea of this post is to show the flaws in the packages distribution of the project MacPorts for Mac OS XThe MacPorts use:a) To update your repository rsync serverb) The packages are distributed via http / ftpc) Before installing a new package it is checked with the MD5/SHA1 in the local repository
To perform the attack we need to do the following tasks:1) Prepare the rsync server on the </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1017223207593200898/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/pwning-mac-os-x-with-evilgrade-macports.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1017223207593200898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1017223207593200898'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/pwning-mac-os-x-with-evilgrade-macports.html' title='Pwning Mac OS X with evilgrade + MacPorts'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-YkPlTox6RQA/ThXFDaVUREI/AAAAAAAAAEs/YZRYWV1-hs0/s72-c/Screen%2Bshot%2B2011-07-06%2Bat%2B6.37.42%2BPM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8095801834868636830</id><published>2011-07-05T08:37:00.001+08:00</published><updated>2011-07-05T08:40:25.380+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>reverse engineering the google +1 button-using-firebug</title><summary type='text'>When Google released its +1 button, I wanted to be able to use it in a  PHP application. Specifically,I wanted to be able to obtain the counter  for a series of links in order to rank the links by popularity.  Unfortunately, Google did not offer a Google +1 true API at the time  (and still does not offer one as far as I know).  However, given that  the button are being displayed all over the web </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8095801834868636830/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/reverse-engineering-google-1-button.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8095801834868636830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8095801834868636830'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/reverse-engineering-google-1-button.html' title='reverse engineering the google +1 button-using-firebug'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1349952781268856868</id><published>2011-07-04T06:40:00.001+08:00</published><updated>2011-07-04T06:47:01.040+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>Advanced Nmap</title><summary type='text'>Some of the guys I hack with and I have been talking about the “core”  toolset in pentesting… like what could you absolutely not go in  without? What we came up with is:nmap
metasploit
ettercap
burp
Wireshark


There are tons of tools that came close to that bracket, other proxies,  scanners, other MiTM tools, but these tools have a special place in our  hearts. These tools have encompassed so </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1349952781268856868/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/advanced-nmap.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1349952781268856868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1349952781268856868'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/advanced-nmap.html' title='Advanced Nmap'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7512075127247136670</id><published>2011-07-04T06:31:00.000+08:00</published><updated>2011-07-04T06:31:51.868+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Fiddling with Chromium's new certificate pinning</title><summary type='text'>Over the past few years, there have been various high-profile incidents  and concerns with the Certificate Authority-based infrastructure that  underpins https connections. Various different efforts are underway to  tackle the problem; many are enumerated here:

http://googleonlinesecurity.blogspot.com/2011/04/improving-ssl-certificate-security.html

And in terms of things baked directly into the</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7512075127247136670/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/fiddling-with-chromiums-new-certificate.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7512075127247136670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7512075127247136670'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/fiddling-with-chromiums-new-certificate.html' title='Fiddling with Chromium&apos;s new certificate pinning'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7297283864439173395</id><published>2011-07-04T06:24:00.001+08:00</published><updated>2011-07-04T06:26:50.626+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploitation'/><title type='text'>Journey into Exploitation: awbo2.exe</title><summary type='text'>In this series of blog posts, I will be documenting my journey into  the art of exploitation.  My goal for this series is to experiment with  some of the challenges that are out there and hopefully provide some  guidance for others in my shoes.  I am targeting those of you with  moderate amount experience in exploitation.  Hopefully, I will further  my own knowledge and yours (the reader).What </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7297283864439173395/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/journey-into-exploitation-awbo2exe.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7297283864439173395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7297283864439173395'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/journey-into-exploitation-awbo2exe.html' title='Journey into Exploitation: awbo2.exe'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4420288831848842845</id><published>2011-07-03T04:34:00.000+08:00</published><updated>2011-07-03T04:34:22.758+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Extracting Files from a tcpdump</title><summary type='text'>Occasionally I have to analyze tcp-streams, and occasionally I came  to a point where i had to extract files out of huge dumps. What I found  during my last research about a year ago was not really usable - i  hacked together a few lines of perl to extract exactly what i wanted -  this didn't deliver exact files, but was enough to help me solve a  problem.
Jim Clausing, one of the more practical </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4420288831848842845/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/extracting-files-from-tcpdump.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4420288831848842845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4420288831848842845'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/extracting-files-from-tcpdump.html' title='Extracting Files from a tcpdump'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-462979593663050369</id><published>2011-07-03T04:31:00.000+08:00</published><updated>2011-07-03T04:31:27.935+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>How security-teams deal with leaking passwords</title><summary type='text'>Finally: I have "The List" - I even  posted where it is to find, for what I read was, that the security-teams  of the major providers affected did their work properly deactivating  all the affected accounts. http://windowslivewire.spaces.live.com/blog/cns!2F7EB29B42641D59!41528.entry?wa=wsignin1.0&amp;sa=363915619http://news.bbc.co.uk/2/hi/technology/8292928.stm
This  is currently, three days after (</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/462979593663050369/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/how-security-teams-deal-with-leaking.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/462979593663050369'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/462979593663050369'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/how-security-teams-deal-with-leaking.html' title='How security-teams deal with leaking passwords'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_L52Vgx7c_mo/Ss5it_1Eg8I/AAAAAAAACBk/eNjPTIyfVbI/s72-c/pw_ebay.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1766744082917362404</id><published>2011-07-03T04:27:00.000+08:00</published><updated>2011-07-03T04:27:05.014+08:00</updated><title type='text'>Transfer Files and Data via DNS-Requests</title><summary type='text'>Most of you might know dnstunnel. Johannes Ullrich from Sans lists a poor mans dns-filetransfer using xxd which i think is a nice idea working on most unix boxes for xxd seems to be commonly installed. </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1766744082917362404/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/transfer-files-and-data-via-dns.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1766744082917362404'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1766744082917362404'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/07/transfer-files-and-data-via-dns.html' title='Transfer Files and Data via DNS-Requests'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4644641135717138056</id><published>2011-06-23T23:27:00.001+08:00</published><updated>2011-06-23T23:27:09.719+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Passive Analysis of SSH Traffic</title><summary type='text'> by Solar Designer and Dug Song
March 19, 2001
Last revised: June 6, 2010
  This article demonstrates several weaknesses in implementations of SSH (Secure Shell) protocols.  When exploited, they let the attacker obtain sensitive information by passively monitoring encrypted SSH sessions.  The information can later be used to speed up brute-force attacks on passwords, including the initial login </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4644641135717138056/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/passive-analysis-of-ssh-traffic.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4644641135717138056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4644641135717138056'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/passive-analysis-of-ssh-traffic.html' title='Passive Analysis of SSH Traffic'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8514312214714645995</id><published>2011-06-23T00:56:00.000+08:00</published><updated>2011-06-23T00:56:27.819+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>DotDotPwn v2.1 - The Traversal Directory Fuzzer</title><summary type='text'>These are the new features included in v2.1 (transcription of CHANGELOG.txt):
----------------
DotDotPwn v2.1
Release date: 29/Oct/2010 (PUBLIC Release at BugCon Security Conferences 2010)
Release date: 14/Oct/2010 (NON-PUBLIC Version)

Changes / Enhancements / Features:

* STDOUT module implemented to be used as you wish (Read the EXAMPLES.txt to
see some examples)
* TFTP Module implemented
* -k</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8514312214714645995/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/dotdotpwn-v21-traversal-directory.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8514312214714645995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8514312214714645995'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/dotdotpwn-v21-traversal-directory.html' title='DotDotPwn v2.1 - The Traversal Directory Fuzzer'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_yWd4rUkBABM/TMdMQ3W6hYI/AAAAAAAAAIA/POBHG9JBpHQ/s72-c/ddpwn21+stdout.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3067535020826310391</id><published>2011-06-23T00:54:00.000+08:00</published><updated>2011-06-23T00:54:27.625+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>DotDotPwn - The Directory Traversal Fuzzer</title><summary type='text'>Hell Yes !!!! B-), a few weeks ago, my brother chr1x from CubilFelino Security Labs  (published a tool to detect directory traversal vulnerabilities in  FTP/HTTP servers. It only relied upon 2 .txt files (databases) with the  payloads to be lauched to the target. Then, some cool ideas came into my  mind, so, I wrote the c0de from the skratch and in a modular basis, as  well as, I included a lot </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3067535020826310391/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/dotdotpwn-directory-traversal-fuzzer.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3067535020826310391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3067535020826310391'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/dotdotpwn-directory-traversal-fuzzer.html' title='DotDotPwn - The Directory Traversal Fuzzer'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_yWd4rUkBABM/TIm-iu0BIAI/AAAAAAAAAGw/_4Ei2KCsgQs/s72-c/ddpwn+usage.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6727873032232013774</id><published>2011-06-23T00:22:00.001+08:00</published><updated>2011-06-23T00:25:21.894+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Python'/><title type='text'>mitmproxy</title><summary type='text'>an SSL-capable intercepting proxy      
mitmproxy is an SSL-capable, intercepting HTTP proxy. It provides a console interface that allows traffic flows to be inspected and edited on the fly.
mitmdump is the command-line version of mitmproxy, with the same functionality but without the frills. Think tcpdump for HTTP.
FeaturesIntercept and modify HTTP traffic on the fly
Save HTTP conversations for </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6727873032232013774/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/mitmproxy.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6727873032232013774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6727873032232013774'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/mitmproxy.html' title='mitmproxy'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3813708020287651705</id><published>2011-06-22T01:58:00.001+08:00</published><updated>2011-06-22T01:58:54.087+08:00</updated><title type='text'>Introducing WPScan – WordPress Security Scanner</title><summary type='text'>After creating the WordPress Brute Force Tool last weekend, I decided to create a bigger project out of it, called WPScan.  WPScan is a black box WordPress Security Scanner written in Ruby  which attempts to find known security weaknesses within WordPress  installations. Its intended use it to be for security professionals or  WordPress administrators to asses the security posture of their  </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3813708020287651705/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/introducing-wpscan-wordpress-security.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3813708020287651705'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3813708020287651705'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/introducing-wpscan-wordpress-security.html' title='Introducing WPScan – WordPress Security Scanner'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1291352882809766451</id><published>2011-06-22T01:53:00.000+08:00</published><updated>2011-06-22T01:53:19.019+08:00</updated><title type='text'>Tomahawk, your IDS/Firewall Best Friend</title><summary type='text'>“Tomahawk” is the name of a popular cruise missile  developed by General Dynamics in the seventies. But it is also the name  of a free tool which helps to stress test security devices like  firewalls or IDS. It has been written by Brian Smith from TippingPoint. This is well-known manufacturer of IDS solutions, acquired by HP in 2010.
Testing IDS solutions has always been a  nightmare. Just </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1291352882809766451/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/tomahawk-your-idsfirewall-best-friend.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1291352882809766451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1291352882809766451'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/tomahawk-your-idsfirewall-best-friend.html' title='Tomahawk, your IDS/Firewall Best Friend'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2429589920235041791</id><published>2011-06-22T01:26:00.001+08:00</published><updated>2011-06-22T01:32:06.636+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>Introducing DOM Snitch, our passive in-the-browser reconnaissance tool</title><summary type='text'>Every day modern web applications are becoming increasingly  sophisticated, and as their complexity grows so does their attack  surface. Previously we introduced open source tools such as Skipfish and Ratproxy to assist developers in understanding and securing these applications.
As existing tools focus mostly on testing server-side code, today we are happy to introduce DOM Snitch  — an </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2429589920235041791/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/introducing-dom-snitch-our-passive-in.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2429589920235041791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2429589920235041791'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/introducing-dom-snitch-our-passive-in.html' title='Introducing DOM Snitch, our passive in-the-browser reconnaissance tool'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1712788865909750360</id><published>2011-06-21T22:38:00.002+08:00</published><updated>2011-06-22T01:40:25.700+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>Metasploit 3.7.2 adds 11 new exploits</title><summary type='text'>Metasploit is a free, open source penetration testing solution.

Metasploit now ships with 698 exploit modules, 358 auxiliary modules, and 54 post modules.

11 new exploits, 1 new auxiliary module, and 15 new post modules have been added since the last release.

New features include remote registry commands for Meterpreter, import  parsers moved to nokogiri streaming parsers (for quicker parsing </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1712788865909750360/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/metasploit-372-adds-11-new-exploits.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1712788865909750360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1712788865909750360'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/metasploit-372-adds-11-new-exploits.html' title='Metasploit 3.7.2 adds 11 new exploits'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6067511354303397724</id><published>2011-06-21T22:30:00.001+08:00</published><updated>2011-06-22T01:41:14.854+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>IM worm targeting Brazilian Facebook users</title><summary type='text'>There’s nothing new in Brazilian cybercriminals exploiting social  networks to distribute their malicious code. Orkut was first, followed  by Twitter, and now it’s Facebook’s turn.
Facebook is becoming increasingly popular in Brazil and we are  witnessing more and more Brazilian bad guys switching their focus to it.  We received some proof this weekend: a Brazilian instant message (IM)  worm </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6067511354303397724/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/im-worm-targeting-brazilian-facebook.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6067511354303397724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6067511354303397724'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/im-worm-targeting-brazilian-facebook.html' title='IM worm targeting Brazilian Facebook users'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7449415786613195003</id><published>2011-06-21T22:20:00.001+08:00</published><updated>2011-06-21T22:32:37.254+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>LulzSec Suspect Taken Into Custody</title><summary type='text'>Rumors and news regarding hacker group LulzSec have been afloat on Twitter today.

The rumors circle around this Pastebin post which claims that LulzSec had acquired the UK's 2011 census data.Note that anybody can post to pastebin.com.

Soon after, news came that Scotland Yard has arrested a 19-year-old in Essex.

Should be interesting to see what comes next…

Will the UK's census data be </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7449415786613195003/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/lulzsec-suspect-taken-into-custody.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7449415786613195003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7449415786613195003'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/lulzsec-suspect-taken-into-custody.html' title='LulzSec Suspect Taken Into Custody'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7615696459476058910</id><published>2011-06-21T01:38:00.000+08:00</published><updated>2011-06-21T01:38:37.248+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Backdoored'/><title type='text'>Creating a 13 line backdoor worry free of A/V</title><summary type='text'>When writing the SET interactive shell for the Social-Engineer  Toolkit, I had to ponder what the best route in creating a flexible  reverse shell. This backdoor had to be a familiar programming language  (to me) and be modular for me to add new things onto it. Python being my  strongest language posed some significant challenges as it was not a  compiled language. Fortunately there is a way to </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7615696459476058910/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/creating-13-line-backdoor-worry-free-of.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7615696459476058910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7615696459476058910'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/creating-13-line-backdoor-worry-free-of.html' title='Creating a 13 line backdoor worry free of A/V'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5167679411006119334</id><published>2011-06-19T23:20:00.000+08:00</published><updated>2011-06-19T23:20:29.810+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><title type='text'>Searching the Registry using PowerShell</title><summary type='text'> 
On a cold and rainy Thursday morning, I thought that it would be a good time to write a post on searching the Windows registry using PowerShell.  In an Incident Response scenario you may want or need to do some live analysis on a compromised system, and part of this analysis may be to search the registry for some sort of artifact that is appropriate.  Using PowerShell can help you do this in a </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5167679411006119334/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/searching-registry-using-powershell.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5167679411006119334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5167679411006119334'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/06/searching-registry-using-powershell.html' title='Searching the Registry using PowerShell'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4979186686940532258</id><published>2011-04-11T02:22:00.001+08:00</published><updated>2011-06-19T23:38:02.580+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>pooftooph-the-bluetooth-spoofer-v0-4-released</title><summary type='text'>Spooftooph is designed to automate spoofing or cloning Bluetooth device Name, Class, and Address. Cloning this information effectively allows Bluetooth device to hide in plain site. Bluetooth scanning software will only list one of the devices if more than one device in range shares the same device information when the devices are in Discoverable Mode (specificaly the same Address)



Spooftooph </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4979186686940532258/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/04/pooftooph-bluetooth-spoofer-v0-4.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4979186686940532258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4979186686940532258'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/04/pooftooph-bluetooth-spoofer-v0-4.html' title='pooftooph-the-bluetooth-spoofer-v0-4-released'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5762021253241982978</id><published>2011-04-07T03:24:00.001+08:00</published><updated>2011-06-19T23:39:59.727+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Movie'/><title type='text'>Tron Legacy</title><summary type='text'>   
I spent a half year writing software art to generate special effects for Tron Legacy, working at Digital Domain with Bradley "GMUNK" Munkowitz, Jake Sargeant, and David "dlew" Lewandowski. This page has taken a long time to be published because I've had to await clearance. A lot of my team's work was done using Adobe software and Cinema 4D. The rest of it got written in C++ using </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5762021253241982978/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/04/tron-legacy.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5762021253241982978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5762021253241982978'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/04/tron-legacy.html' title='Tron Legacy'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6139162566250963881</id><published>2011-03-11T14:57:00.001+08:00</published><updated>2011-06-19T23:42:50.856+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><title type='text'>Desynchronization Issues in Windows Message Handling</title><summary type='text'>
This week, Microsoft issued MS11-012 to resolve yet another batch of vulnerabilities in win32k.sys. The bulletin addressed three elevation of privilege vulnerabilities in window class data handling (somewhat related to those patched in MS10-073) and an additional two in window message handling. The latter were quite interesting as they were not your typical vulnerability class, but rather subtle</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6139162566250963881/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/03/desynchronization-issues-in-windows.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6139162566250963881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6139162566250963881'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/03/desynchronization-issues-in-windows.html' title='Desynchronization Issues in Windows Message Handling'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-VyyG8N0yl0Y/TXnHTbzatlI/AAAAAAAAAJI/7fpEfmj5XNQ/s72-c/flow.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8208009505706602933</id><published>2011-02-27T17:12:00.001+08:00</published><updated>2011-06-19T23:57:47.344+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Peeling Apart TDL4 and Other Seeds of Evil Part I</title><summary type='text'>This is the first in an intended series discussing analysis on a compromised XP SP3 machine. Multiple malware components were found on the system and I shall try to describe the analysis processes I used in an attempt to provide something of interest.

Emerging Threats signature-based alert

The first indicator of any issue was the firing of an Emerging Threats signature ET 2010823 on an </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8208009505706602933/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/02/peeling-apart-tdl4-and-other-seeds-of_27.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8208009505706602933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8208009505706602933'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/02/peeling-apart-tdl4-and-other-seeds-of_27.html' title='Peeling Apart TDL4 and Other Seeds of Evil Part I'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_M2IZWfA-R60/TQr6lZXKoeI/AAAAAAAAAFI/0ICFGfLZnIE/s72-c/memorydd_bat.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3140414679609889269</id><published>2011-02-27T17:01:00.001+08:00</published><updated>2011-06-20T00:09:54.456+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Peeling Apart TDL4 and Other Seeds of Evil Part II</title><summary type='text'>Peeling Apart TDL4 and Other Seeds of Evil Part II

(please excuse the lousy formatting, blogger doesn't handle these posts too well)

This is the second in an intended series discussing analysis on a compromised XP SP3 machine. Multiple malware components were found on the system and I shall try to describe the analysis processes I used in an attempt to provide something of interest. In some </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3140414679609889269/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/02/peeling-apart-tdl4-and-other-seeds-of.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3140414679609889269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3140414679609889269'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/02/peeling-apart-tdl4-and-other-seeds-of.html' title='Peeling Apart TDL4 and Other Seeds of Evil Part II'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh4.googleusercontent.com/-uY7YipocB2M/TWlohst84lI/AAAAAAAAAF4/JW0ieKxg7WY/s72-c/clickserver_parms.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4152793195542763016</id><published>2011-01-17T12:15:00.013+08:00</published><updated>2011-06-20T00:11:07.169+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Good Memory Adware Removal Instructions</title><summary type='text'>Good Memory is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

Variants of the rogue defragmenter:

* Fast Disk
* Disk OK
* My Disk
* Memory Fixer
* HDD Fix
* Scanner
* HDD Low
* Disk </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4152793195542763016/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/good-memory-adware-removal-instructions.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4152793195542763016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4152793195542763016'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/good-memory-adware-removal-instructions.html' title='Good Memory Adware Removal Instructions'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-9085067873155068047</id><published>2011-01-13T11:16:00.002+08:00</published><updated>2011-06-20T00:13:25.355+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>In-memory extraction of SSL private keys</title><summary type='text'> by Nicolas Collignon et Jean-Baptiste Aviat (04/06/10) ------------[ In-memory extraction of SSL private keys ]----------------


Cet article est disponible en francais à passe-partout.html.fr.

The tool passe-partout presented all along this tip can be found at passe-partout.


--[ 1. Introduction ]---------------------------------------------------

Asymetric cryptography usage is growing for </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/9085067873155068047/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/in-memory-extraction-of-ssl-private.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/9085067873155068047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/9085067873155068047'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/in-memory-extraction-of-ssl-private.html' title='In-memory extraction of SSL private keys'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1708573124113565481</id><published>2011-01-03T17:13:00.002+08:00</published><updated>2011-06-20T00:18:52.083+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Bypass Windows 7 x86/x64 UAC Fully Patched – Meterpreter Module</title><summary type='text'>Happy New Year everyone! Here is a nice new addition to bypass UAC  through meterpreter. It all came about when Kevin Mitnick was on a  pentest and needed to bypass Windows 7 UAC. We stumbled upon an old post  from Leo Davidson  (http://www.pretentiousname.com/misc/win7_uac_whitelist2.html) on  bypassing Windows UAC. This method takes advantage of process injection  that has a trusted Windows </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1708573124113565481/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/happy-new-year-everyone-here-is-nice.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1708573124113565481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1708573124113565481'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/happy-new-year-everyone-here-is-nice.html' title='Bypass Windows 7 x86/x64 UAC Fully Patched – Meterpreter Module'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1601548758214027646</id><published>2011-01-03T03:41:00.001+08:00</published><updated>2011-06-20T01:08:59.185+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootkits'/><title type='text'>Ring 0f Fire : Rootkits and DKOM</title><summary type='text'>Many books and papers cover the subject of Rootkits. I wrote this article to describe my first steps.
Here, you will learn what a rootkit is and how does it work. Also you will find an attack using DKOM.For this article I’m using:
Windows XP SP3
WDK Windows Driver Kit
Some debuggers: WinDbg, DebugView
Coffee and good cakes
1. Rootkits1.1. What is a Rootkit?First and foremost, a rootkit is not a  </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1601548758214027646/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/ring-0f-fire-rootkits-and-dkom.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1601548758214027646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1601548758214027646'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/ring-0f-fire-rootkits-and-dkom.html' title='Ring 0f Fire : Rootkits and DKOM'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8991544152778148491</id><published>2011-01-02T18:10:00.004+08:00</published><updated>2011-06-20T01:14:46.426+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Configuration Setting: safemodehack</title><summary type='text'>This tries to solve bug 179 where DokuWiki can not write to directories it created itself. It does so by using FTP to log into your server and creating the directory that way. It requires the FTP PHP module to be installed on the server. 
Type: Boolean
Default: 0
As the name suggests, this is a hack and not recommended. Safemode itself is a setting that even the developers of PHP despise, it will</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8991544152778148491/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/configuration-setting-safemodehack.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8991544152778148491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8991544152778148491'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2011/01/configuration-setting-safemodehack.html' title='Configuration Setting: safemodehack'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-550083250515628684</id><published>2010-12-29T01:18:00.006+08:00</published><updated>2011-06-20T01:16:17.453+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Reverse Engineering Malware</title><summary type='text'>I recently got the opportunity to sit in on (fellow SANS instructor) Lenny Zeltser's "Reverse Engineering Malware" class.  It's a terrific course, and I highly recommend it.


During  the material on memory analysis, we were comparing the output of  "volatility pslist" and "volatility psscan2".  It's relatively  straightforward for rootkits to hide themselves from pslist, but psscan2  does a much</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/550083250515628684/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/reverse-engineering-malware.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/550083250515628684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/550083250515628684'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/reverse-engineering-malware.html' title='Reverse Engineering Malware'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5211946291881673707</id><published>2010-12-22T07:47:00.001+08:00</published><updated>2011-06-20T01:26:41.057+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>Administrator account VS. SYSTEM account</title><summary type='text'>I've encountered one trojan who ran already as Administrator and tried  to run privilege escalation exploit against himself, so he can run as  SYSTEM.
This is what made me write this post : 

Let's say there are 2 programs vulnerable to remote-code-execution bug.
1. One is running as SYSTEM
2. One is running as Administrator.

Little pre-post-information regarding exploitation : If you run  your </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5211946291881673707/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/administrator-account-vs-system-account.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5211946291881673707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5211946291881673707'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/administrator-account-vs-system-account.html' title='Administrator account VS. SYSTEM account'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Kde3g35OnUQ/S0iEdNKFS3I/AAAAAAAAAEQ/hQGyaBKJILI/s72-c/at1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7858132184344543616</id><published>2010-12-22T06:31:00.001+08:00</published><updated>2011-06-20T01:37:54.632+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>ad_1_.jpg unpacking/analysis - Aurora</title><summary type='text'>In this post we'll try to run Aurora as non-administrative user, and  debug ad_1_.jpg which used by the attackers right after the attack.  Well, I was very curious about other files in the attack, after not able  to unpack the msconfig32.sys, and thought, maybe other files will give  me clues on msconfig32.sys and might give me a way of unpacking it.

I've looked into USCERT advisory regarding </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7858132184344543616/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/ad1jpg-unpackinganalysis-aurora.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7858132184344543616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7858132184344543616'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/ad1jpg-unpackinganalysis-aurora.html' title='ad_1_.jpg unpacking/analysis - Aurora'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Kde3g35OnUQ/S8njxstzsJI/AAAAAAAAAGo/LRI04scXMPE/s72-c/Screen+shot+2010-04-17+at+7.32.21+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1400610897748897158</id><published>2010-12-21T06:34:00.001+08:00</published><updated>2011-06-20T01:41:00.461+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wifi'/><title type='text'>Hack into computers through WiFi</title><summary type='text'>In this tut you'll be learning how to access someone's facebook/youtube and many other accounts who is using the same WiFi as you.

You need Mozilla Firefox. Firesheep - firefox add-on: http://codebutler.github.com/firesheep/
WinPcap if you have Windows: http://www.winpcap.org/install/default.htm
 
Install wincap then drag the Firesheep add on and put it on the Firefox icon.
Firefox will open and</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1400610897748897158/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/hack-into-computers-through-wifi.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1400610897748897158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1400610897748897158'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/hack-into-computers-through-wifi.html' title='Hack into computers through WiFi'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3687893555996517976</id><published>2010-12-21T03:43:00.002+08:00</published><updated>2010-12-21T03:43:41.777+08:00</updated><title type='text'>DotDotPwn v2.1 - The Directory Traversal Fuzzer</title><summary type='text'>It's  a very flexible intelligent fuzzer to discover traversal directory  vulnerabilities in software such as Web/FTP/TFTP servers,Web platforms  such as CMSs,ERPs,Blogs,etc.Also,it has a protocol independent module to  send the desired payload to the host and port specified. On the other  hand,it also could be used in a scripting way using the STDOUT  module.It's written in perl programming </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3687893555996517976/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/dotdotpwn-v21-directory-traversal.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3687893555996517976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3687893555996517976'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/dotdotpwn-v21-directory-traversal.html' title='DotDotPwn v2.1 - The Directory Traversal Fuzzer'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_xJ5LrusWfss/TP1WVPqPKwI/AAAAAAAAAts/gMVefapDzfg/s72-c/ddpwnasciiart.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-895256849450896085</id><published>2010-12-21T03:00:00.004+08:00</published><updated>2010-12-21T03:13:54.201+08:00</updated><title type='text'>Beef - v0.4.2-alpha Browser Exploitation Framework</title><summary type='text'>BeEF, the Browser Exploitation Framework is a professional security tool  provided for lawful research and testing purposes. It allows the  experienced penetration tester or system administrator additional attack  vectors when assessing the posture of a target. The user of BeEF will  control which browser will launch which command module and at which  target. 

BeEF hooks one or more web browsers</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/895256849450896085/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/beef-v042-alpha-browser-exploitation.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/895256849450896085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/895256849450896085'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/beef-v042-alpha-browser-exploitation.html' title='Beef - v0.4.2-alpha Browser Exploitation Framework'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2101904004150390512</id><published>2010-12-21T02:42:00.001+08:00</published><updated>2011-06-20T01:44:14.478+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>Samurai WTF v0.95 Released</title><summary type='text'>Samurai Web Testing Framework - Web penetration testing live CD built on open source software

The  Samurai Web Testing Framework is a live linux environment that has been  pre-configured to function as a web pen-testing environment. The CD  contains the best of the open source and free tools that focus on  testing and attacking websites. In developing this environment, we have  based our tool </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2101904004150390512/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/samurai-wtf-v095-released.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2101904004150390512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2101904004150390512'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/samurai-wtf-v095-released.html' title='Samurai WTF v0.95 Released'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2204582259823595035</id><published>2010-12-21T02:25:00.002+08:00</published><updated>2011-06-21T00:45:39.149+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>Secunia Personal Software Inspector v2.0 Released</title><summary type='text'>FREE PC Security for Home Users 

The  Secunia PSI is aFREE security tool designed to detectvulnerable  andout-dated programs and plug-ins which expose your PC to attacks.  Attacks exploiting vulnerable programs and plug-ins are rarely blocked  by traditional anti-virus and are therefore increasingly "popular" among  criminals. 
The only solution to block these kind of attacks is to  apply </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2204582259823595035/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/secunia-personal-software-inspector-v20.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2204582259823595035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2204582259823595035'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/secunia-personal-software-inspector-v20.html' title='Secunia Personal Software Inspector v2.0 Released'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xJ5LrusWfss/TQ-JtF7GWoI/AAAAAAAAAuw/stBmZBYzC-w/s72-c/psi-19e36dde43062df3.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4001685344693533868</id><published>2010-12-16T22:45:00.004+08:00</published><updated>2011-06-21T00:46:52.708+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>ARP Land Attack</title><summary type='text'>Yeah, you know the deal.
Another network-based attack! This time, a LAND-attack (Local Area Network Denial – attack).
I know the first thing that comes to your mind is:
“LAME. With a MITM (Man-in-the-Middle), you can at least steal data, with this you simply DoS someone…”Not so fast.
I’ve actually found this quite useful.
It requires a very small amount of packets to null-route a remote computer </summary><link rel='related' href='http://c0decstuff.blogspot.com/2010/12/yeah-you-know-deal.html' title='ARP Land Attack'/><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4001685344693533868/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/yeah-you-know-deal.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4001685344693533868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4001685344693533868'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/yeah-you-know-deal.html' title='ARP Land Attack'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rIh95t1bhWM/TQonKUwnMVI/AAAAAAAAAIY/ml7XBREaSRQ/s72-c/ARP_Land_Attack.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2787813740123171480</id><published>2010-12-06T02:40:00.002+08:00</published><updated>2011-06-21T00:43:59.836+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web'/><title type='text'></title><summary type='text'>Finding Backdoor Site
To find backdoor site go toCode:http://www.domaintools.com/and in Whois Lookup enter your TARGET site


 As a result you'll get Whois Record

Look for Reverse IP
In our case 25 other sites hosted on this server.
Click on it to see names of the hosted sites on the same server. You will see few of them, to see all, click on more... 

To see them all you must be a member.
You </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2787813740123171480/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/finding-backdoor-site-to-find-backdoor.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2787813740123171480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2787813740123171480'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/12/finding-backdoor-site-to-find-backdoor.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3992218326142931536</id><published>2010-11-30T17:17:00.004+08:00</published><updated>2011-06-20T01:42:33.846+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'></title><summary type='text'>http://c0decstuff.blogspot.com/2010/11/armitage-v11.html


Armitage - Cyber Attack Management for Metasploit 
Armitage  is a graphical cyber attack management tool for Metasploit that  visualizes your targets, recommends exploits, and exposes the advanced  capabilities of the framework. Armitage aims to make Metasploit usable  for security practitioners who understand hacking but don't use  </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3992218326142931536/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/armitage-v11.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3992218326142931536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3992218326142931536'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/armitage-v11.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xJ5LrusWfss/TPIjkS-6P1I/AAAAAAAAAtU/3DdD6nKn0PA/s72-c/armitage4.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1676984103436721599</id><published>2010-11-30T17:15:00.001+08:00</published><updated>2011-06-20T01:02:12.885+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'></title><summary type='text'>Arachni v0.2.1 - Web Application Security Scanner Framework

Arachni is a feature-full, modular,  high-performance Ruby framework aimed towards helping penetration  testers and administrators evaluate the security of web applications.
Arachni  is smart,it trains itself by learning from the HTTP responses it  receives during the audit process.Unlike other scanners,Arachni takes  into account the </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1676984103436721599/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/arachni-v0.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1676984103436721599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1676984103436721599'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/arachni-v0.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4013974720720097443</id><published>2010-11-23T05:45:00.009+08:00</published><updated>2011-06-20T00:56:31.713+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'></title><summary type='text'>Play With Routers, &amp; Node EnnumerationThis article describes how I was able to find linksys routers open to  vulnerability.  If you have a Linksys router make sure you have taken  the proper steps to  securing yourself.  There is a follow up to this article here. I scanned a rather large portion of IP's (2 class C IP ranges).  If you don't know what port scanning is click here.   There are </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4013974720720097443/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/hacking-linksys-routers-node.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4013974720720097443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4013974720720097443'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/hacking-linksys-routers-node.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://i54.tinypic.com/2gtu1xf_th.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8747548284639486123</id><published>2010-11-20T23:57:00.001+08:00</published><updated>2011-06-21T23:17:21.936+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'></title><summary type='text'>Backward disassembler for ROP exploitation

bdasm is  a PyCommand that I wrote for Immunity Debugger (v 1.73) which can  search the address space of a process for a certain opcode/instruction  and dissasemble backward and forward for a  specified number of  instructions.
This is especially useful in the exploit development process when  existing gadget finding tools do not produce the results you</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8747548284639486123/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/backward-disassembler-for-rop.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8747548284639486123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8747548284639486123'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/backward-disassembler-for-rop.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8718571707454102799</id><published>2010-11-20T23:47:00.001+08:00</published><updated>2011-06-21T00:59:18.519+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'></title><summary type='text'>Application Layer DDoS Simulator

https://sourceforge.net/projects/ddosim/.

ddosim  is a tool that can be used in a laboratory environment to simulate a  distributed denial of service (DDOS) attack against a target server. The  test will show the capacity of the server to handle application  specific DDOS attacks. ddosim simulates several zombie hosts  (having random IP addresses) which create </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8718571707454102799/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/application-layer-ddos-simulator.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8718571707454102799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8718571707454102799'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/11/application-layer-ddos-simulator.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8170990796471132247</id><published>2010-10-05T16:59:00.002+08:00</published><updated>2011-06-21T23:03:13.824+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Browser'/><title type='text'></title><summary type='text'>Google Chome + Google SSL default search engineHere's just a short and simple tutorial for those looking to set google's ssl search as their default search engine in Google Chrome. I found it to be pretty useful, and I hope that you do as well.


1) Go to Chrome's option menu (top right wrench-&gt;options [in the latest Chrome beta])
2) Under the "Basics" tab, click the "Manage" button next to the "</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8170990796471132247/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/google-chome-google-ssl-default-search.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8170990796471132247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8170990796471132247'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/google-chome-google-ssl-default-search.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3648577828257685545</id><published>2010-10-03T09:07:00.004+08:00</published><updated>2010-10-03T09:12:01.553+08:00</updated><title type='text'></title><summary type='text'>Methods to block SSH attacksMethods:
1. Allow the IPs you would like to have access to SSH through your firewall.
Example:   iptables -A INPUT -i eth0 -s 10.10.10.10 -p tcp --dport 22 -j ACCEPT 2. Change SSH port.

Example:

Edit your ssh configuration file under /etc/ssh/sshd_config and add/replace this line:
Port 6445 3. Use a utility like BFD, BlockHosts and DenyHosts
4. Use ip tables to limit</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3648577828257685545/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/methods-to-block-ssh-attacks-methods-1.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3648577828257685545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3648577828257685545'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/methods-to-block-ssh-attacks-methods-1.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2579611841379798375</id><published>2010-10-03T07:09:00.001+08:00</published><updated>2011-06-20T01:29:49.595+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><title type='text'></title><summary type='text'>Configuring Granular Password Settings in Windows Server 2008 � The Easy WayThis article will demonstrate �The Easy Way� of how to handle Granular Password Policies � also known as Fine-Grained Password Policies - in a Windows Server 2008 domain environment. Different approaches

Like with many other areas of Windows administration you have several  different options when it comes to handling the</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2579611841379798375/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/configuring-granular-password-settings.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2579611841379798375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2579611841379798375'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/configuring-granular-password-settings.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2654944189213863426</id><published>2010-10-03T05:45:00.002+08:00</published><updated>2010-10-03T05:56:10.940+08:00</updated><title type='text'></title><summary type='text'>FREE: Win IP Config – GUI replaces ipconfig, route, and netstatping command is the main reason why I still use the command prompt regularly. Well, that is not really true. Another command, I use frequently, is ipconfig. I usually need it whenever I have connection problems. It is the fastest way to get an overview of a PC’s network configuration. When I had to use it again recently, I thought it </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2654944189213863426/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/win-ip-config-gui-replaces-ipconfig.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2654944189213863426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2654944189213863426'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/10/win-ip-config-gui-replaces-ipconfig.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2108067746076485807</id><published>2010-09-21T15:52:00.003+08:00</published><updated>2010-09-21T15:54:06.298+08:00</updated><title type='text'></title><summary type='text'>idsecconf 2010 Bali -- Call of paper
Kami dari komite idsecconf 2010 Bali memberi kesempatan pada rekan-rekanpenggiat keamanan komputer di seluruh Indonesia untuk berpartisipasilewat penyerahan paper. Topik utama yang kami cari adalah yang berkaitandengan:"Keamanan dalam bertransaksi electronic banking dan electronic payment"
Secara explisit, ini mencakup (namun tidak terbatas) pada:- pengamanan </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2108067746076485807/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/09/idsecconf-2010-bali-call-of-paper-kami.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2108067746076485807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2108067746076485807'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/09/idsecconf-2010-bali-call-of-paper-kami.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_rIh95t1bhWM/TH6zGZVYfwI/AAAAAAAAAIM/Bw9p0mufjJo/s72-c/bgx.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-123992992219231046</id><published>2010-09-21T15:48:00.001+08:00</published><updated>2011-06-21T23:32:45.687+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'></title><summary type='text'>RIPS version 0.33 Released
RIPS - A static source code analyser for vulnerabilties in PHP scripts   Especially the code viewer has been improved (variable highlighting,drag+dropable,resizeable window,active jumping between function calls and declarations) and is not only good for analyzing vulnerabilities manually but also for understanding foreign code quickly.also a lot of new features like </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/123992992219231046/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/09/rips-version-0.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/123992992219231046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/123992992219231046'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/09/rips-version-0.html' title=''/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-827944672589475768</id><published>2010-08-15T20:45:00.002+08:00</published><updated>2011-06-20T00:27:53.547+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><title type='text'>Honeynet  Memory Forensics Challenge</title><summary type='text'>The Honeynet project released a memory  forensics challenge a few months ago.  I read over the winning  three submissions and was very impressed with the creative solutions  they came up with.  The submitters used freeware tools and clearly spent  a significant amount of time putting their answers together.  These  sort of academic challenges are fun and a great way to hone your skills.   In a </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/827944672589475768/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/honeynet-memory-forensics-challenge.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/827944672589475768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/827944672589475768'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/honeynet-memory-forensics-challenge.html' title='Honeynet  Memory Forensics Challenge'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4014132050041526963</id><published>2010-08-15T19:47:00.001+08:00</published><updated>2010-08-15T19:52:34.793+08:00</updated><title type='text'>Jailbreak SSH horrors strike back</title><summary type='text'>Back in 2009 the “ikee”  rick-rolling worm went around the iPhone world via the password of  ‘alpine’ on the root account. You are now warned to change your root  password when you pop into Cydia and Rock the first time. But this thing  just wont stay down.
If you have jailbroken your iPad you might  want to check out a little file called “master.passwd”. In it, there is  another user called ‘</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4014132050041526963/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/jailbreak-ssh-horrors-strike-back.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4014132050041526963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4014132050041526963'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/jailbreak-ssh-horrors-strike-back.html' title='Jailbreak SSH horrors strike back'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-377197380033575882</id><published>2010-08-13T03:29:00.001+08:00</published><updated>2011-06-21T00:56:03.196+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><title type='text'>In Defense of UAC</title><summary type='text'>This is me, editorializing - not an activity I prefer to use this blog  for. But occasionally something seems so nonsensical to me that I just  have to speak up. And today it's UAC that has me speaking up.
I'm  greatly disappointed by the number of true techies and semi-techies who  have gone into a sort of 'hate UAC' mode. I understand their  frustrations; UAC can slow down routine sysadmin </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/377197380033575882/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/in-defense-of-uac.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/377197380033575882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/377197380033575882'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/in-defense-of-uac.html' title='In Defense of UAC'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_rIh95t1bhWM/TGRKwThBvcI/AAAAAAAAAH0/xsc7WAWqU-A/s72-c/c0decstuff.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1140731472558376472</id><published>2010-08-13T03:21:00.003+08:00</published><updated>2010-08-13T03:22:06.997+08:00</updated><title type='text'>Don't cache 'negative' DNS lookups on Windows systems</title><summary type='text'>This one is a little bit esoteric. Scenario:
You try to connect to somesystem.yourdomain.com and fail - the name cannot be looked up. 
You discover that the DNS record is missing in your DNS server, and you fix it by adding the correct record. 
... but you still can't connect to somesystem.yourdomain.com from your workstation! 
What's  happening here is that your system has cached a 'negative </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1140731472558376472/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/dont-cache-negative-dns-lookups-on.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1140731472558376472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1140731472558376472'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/dont-cache-negative-dns-lookups-on.html' title='Don&apos;t cache &apos;negative&apos; DNS lookups on Windows systems'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4543911797097487444</id><published>2010-08-12T15:28:00.002+08:00</published><updated>2011-06-21T00:54:10.051+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Improving HTTPS Side Channel Attacks</title><summary type='text'>In regards to the previous post and the impending Blackhat speech  with Josh Sokol, I thought I’d spend some time enumerating some of the  possibilities for reducing the chatter over SSL/TLS that the browser  introduces.  There are a few things that an attacker generally doesn’t  care about (not always, but generally).  They generally don’t care about  images, CSS, JavaScript, favicons, and most </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4543911797097487444/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/improving-https-side-channel-attacks.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4543911797097487444'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4543911797097487444'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/improving-https-side-channel-attacks.html' title='Improving HTTPS Side Channel Attacks'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3075738629967664732</id><published>2010-08-12T15:26:00.002+08:00</published><updated>2011-06-21T00:54:38.747+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Side Channel Attacks in SSL</title><summary type='text'>For those of you who may not have seen it there is a very good paper  partially by Microsoft Research and partially by Indiana.edu called Side-Channel  Leaks in Web Applications: a Reality Today, a Challenge Tomorrow.    Initially it really upset me off that this paper was written, not  because it’s not excellent, but because it’s partially what I was going  to be speaking about at Blackhat.  </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3075738629967664732/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/side-channel-attacks-in-ssl.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3075738629967664732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3075738629967664732'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/side-channel-attacks-in-ssl.html' title='Side Channel Attacks in SSL'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1924379272153048799</id><published>2010-08-11T17:19:00.000+08:00</published><updated>2010-08-11T17:19:45.943+08:00</updated><title type='text'>Remote Thread Execution in System Process using NtCreateThreadEx for Vista &amp; Windows7</title><summary type='text'>Contents
Introduction
Vista  &amp; Session      Separation
About       NtCreateThreadEx Function
Executing  Remote Thread into System Process using      NtCreateThreadEx.
Limitations       of NtCreateThreadEx Method
Alternative  Techniques
Conclusion
References
IntroductionWindows provides API function     called, CreateRemoteThread [Reference  2]     which allows any process to execute thread in the</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1924379272153048799/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/remote-thread-execution-in-system.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1924379272153048799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1924379272153048799'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/08/remote-thread-execution-in-system.html' title='Remote Thread Execution in System Process using NtCreateThreadEx for Vista &amp; Windows7'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6188262675656564910</id><published>2010-06-22T22:10:00.002+08:00</published><updated>2011-06-21T22:50:54.966+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>Fierce Domain Scan</title><summary type='text'>Originally written by RSnake  with input from id, Vacuum and Robert E Lee. A special thanks to  IceShaman to porting it to use multi-threading and to Jabra for several patches and porting  it into Backtrack  3.0.  A huge thanks to Jabra for taking this to the next level with  2.x!
Fierce domain scan was born out of personal frustration after  performing a web application security audit.  It is </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6188262675656564910/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/fierce-domain-scan.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6188262675656564910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6188262675656564910'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/fierce-domain-scan.html' title='Fierce Domain Scan'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2064927585672465331</id><published>2010-06-22T21:43:00.000+08:00</published><updated>2010-06-22T21:43:35.066+08:00</updated><title type='text'>Firefox DoS</title><summary type='text'>      With Blackhat impending, and given how many individual issues  I’ll be discussing, I thought I should start posting them here.  That  and the fact that I’m quickly approaching my 1000′th post (which, if I  have my way will be my last on ha.ckers.org) means that I need to start  wrapping up these issues into a neat little bow.  I have 43 more, as of  this post, so the clock is ticking.  </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2064927585672465331/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/firefox-dos.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2064927585672465331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2064927585672465331'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/firefox-dos.html' title='Firefox DoS'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-10945827311460166</id><published>2010-06-22T21:36:00.000+08:00</published><updated>2010-06-22T21:36:57.167+08:00</updated><title type='text'>Hardening HTAccess, Part One</title><summary type='text'>  Introduction

Htaccess can be used to manage multiple usernames/passwords, thereby enhancing information protection on the web server by controlling access through HTTP protocols. When used in conjunction with a browser encryption method such as SSL, it is possible to make htaccess authentication a robust method of protecting directories. However, out of the box, htaccess is prone to several </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/10945827311460166/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/hardening-htaccess-part-one.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/10945827311460166'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/10945827311460166'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/hardening-htaccess-part-one.html' title='Hardening HTAccess, Part One'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-1205598816206797042</id><published>2010-06-08T00:43:00.003+08:00</published><updated>2010-06-08T16:58:26.991+08:00</updated><title type='text'>ONE CLICK OWNAGE</title><summary type='text'>ONE CLICK OWNAGEhttp://english.mavituna.com 
Idea of this attack is very simple. Getting a reverse shell from an SQL Injection with one request without using an extra channel such as TFTP, FTP to upload the initial payload.
For example the following text will throw a reverse shell to 192.168.0.1:1;exec master..xp_cmdshell 'echo 
try download link down for complate Similar attacks have been around</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/1205598816206797042/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/one-click-ownage.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1205598816206797042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/1205598816206797042'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/06/one-click-ownage.html' title='ONE CLICK OWNAGE'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_rIh95t1bhWM/TA0fcHTI-xI/AAAAAAAAAHk/KyNTs4d-z68/s72-c/xx.GIF' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7405035507228256391</id><published>2010-05-30T08:31:00.000+08:00</published><updated>2010-05-30T08:31:57.716+08:00</updated><title type='text'>New search engine: heaven for skiddies</title><summary type='text'>There's a new search called SHODAN, which can look for servers, routers and printers using your search query, and get their response banners.

This is what you can search for:

    * country:2-letter country code
    * hostname:full or partial host name
    * net:IP range using CIDR notation (ex: 18.7.7.0/24 )
    * port:21, 22, 23 or 80
As you can see, anyone can easily find vulnerable hosts </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7405035507228256391/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/new-search-engine-heaven-for-skiddies.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7405035507228256391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7405035507228256391'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/new-search-engine-heaven-for-skiddies.html' title='New search engine: heaven for skiddies'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8923874292137624412</id><published>2010-05-25T09:12:00.001+08:00</published><updated>2010-05-25T09:14:27.296+08:00</updated><title type='text'>Cracking Wep Wpa Wireless Network</title><summary type='text'>Covers wep &amp; wpa password/passphrase recovery using the aircrack-ng suite http://docs.alkaloid.net/index.php/Cracking_WEP_and_WPA_Wireless_Networks 
   </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8923874292137624412/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/cracking-wep-wpa-wireless-network.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8923874292137624412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8923874292137624412'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/cracking-wep-wpa-wireless-network.html' title='Cracking Wep Wpa Wireless Network'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3652880462133838077</id><published>2010-05-24T05:52:00.000+08:00</published><updated>2010-05-24T05:52:01.694+08:00</updated><title type='text'>ipv6hackit</title><summary type='text'>Managed byipsecs.comYou may download all ipv6 hackit oncore.ipsecs.com or tarball version onipv6hackit-v0.1.tar.gz  </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3652880462133838077/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/ipv6hackit.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3652880462133838077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3652880462133838077'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/ipv6hackit.html' title='ipv6hackit'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-562834782466943640</id><published>2010-05-10T09:21:00.008+08:00</published><updated>2011-06-21T00:53:03.927+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Aplication'/><title type='text'>PenTBox : simple n smart security tools</title><summary type='text'>  
Yes... simple, smart n powerfull... ;) not just push button hacker....PenTBox is a Security Suite with programs like Password Crackers, Denial of Service testing tools (DoS and DDoS), Secure Password Generators, Honeypots and much more. Destined to test security/stability of networks and more. Programmed in Ruby, and oriented to GNU/Linux systems (but compatible with Windows, MacOS and more).</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/562834782466943640/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/pentbox-simple-n-smart-security-tools.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/562834782466943640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/562834782466943640'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/pentbox-simple-n-smart-security-tools.html' title='PenTBox : simple n smart security tools'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_rIh95t1bhWM/S-cvR9Uf2gI/AAAAAAAAAGU/bKf02e7yONc/s72-c/logo2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4315513263168992067</id><published>2010-05-08T18:02:00.005+08:00</published><updated>2010-05-08T18:22:31.951+08:00</updated><title type='text'>"The Finger Server" execute shell commands</title><summary type='text'>Vulnerability
  "The Finger Server"
Affected
"The Finger Server"
Description
Iain  Wade  found  following.   In  1999.  he was tinkering w/ The Finger  Server  v0.82  and  came  across  some  bugs which let you execute shell  commands under  the privileges  of the  web server.It's available at
glazed.org  It's just another case of perl doing it's magic on an open() call.There  is  undoubtably  </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4315513263168992067/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/finger-server-execute-shell-commands.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4315513263168992067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4315513263168992067'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/finger-server-execute-shell-commands.html' title='&quot;The Finger Server&quot; execute shell commands'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-2995321471211951527</id><published>2010-05-07T06:22:00.001+08:00</published><updated>2010-05-07T06:24:03.097+08:00</updated><title type='text'>Mail Crawler</title><summary type='text'>#!/usr/bin/perl
# emailzz.pl by TheLeader
# Searches google and gathers e-mail adresses from search results
# Credit to Sro for the idea and the inspiration.. keep it up dude ^^
# http://forums.hacking.org.il/viewtopic.php?p=49414#49414

# When patterns are broken, new worlds emerge ~Tuli Kupferberg
# DISCALIMER:
# Using this script may violate Google's Terms of Service.
# I take no </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/2995321471211951527/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/mail-crawler.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2995321471211951527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/2995321471211951527'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/mail-crawler.html' title='Mail Crawler'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6004437311178417290</id><published>2010-05-05T04:41:00.004+08:00</published><updated>2010-05-05T04:51:14.409+08:00</updated><title type='text'>effective SQL Injection Tool (mysql&amp;mssql)</title><summary type='text'> This was several days I tried a source for penetration, and I think I can just incredible to thank my wisdom from evilzc0de&gt;black hat Indonesia&gt;jasakom.I just think this compilation has the structure of the algorithm and extraordinary at the time of inspection.we are all grateful for mywisdom open enough to share .hopefully continue to be developed!-----------------------------------------------</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6004437311178417290/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/effective-sql-injection-tool-mysql.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6004437311178417290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6004437311178417290'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/effective-sql-injection-tool-mysql.html' title='effective SQL Injection Tool (mysql&amp;mssql)'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_rIh95t1bhWM/S-CFcmQv63I/AAAAAAAAAGE/KJRJdcxW_Sg/s72-c/d1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4270805775850237283</id><published>2010-05-03T10:10:00.001+08:00</published><updated>2010-05-04T17:14:08.951+08:00</updated><title type='text'>HowTo: Windows XP VPN Into Remote Location</title><summary type='text'>This entry goes along with HowTo: Windows XP VPN Server Setup. Having a Secured VPN (Virtual Private Networking) server is great, especially for businesses with many offices or if you own two homes. How can you connect to these VPNs free? Well I will tell you. With Windows XP Networking you can connect to any VPN site for free and with ease. There is even a way to Automate the VPN connection on </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4270805775850237283/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/howto-windows-xp-vpn-into-remote.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4270805775850237283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4270805775850237283'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/howto-windows-xp-vpn-into-remote.html' title='HowTo: Windows XP VPN Into Remote Location'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-8932170243634028659</id><published>2010-05-02T23:56:00.001+08:00</published><updated>2010-05-02T23:58:13.390+08:00</updated><title type='text'>BruteMonkey Gmail Bruteforce/Dictionary Attack</title><summary type='text'> 
Disclaimer:This program is intended for educational purposes only. Please use on your OWN e-mail. The author of this program is not responsible for whatever possible trouble you get into. Use at own risk!

Intro:
Brutemonkey is a Gmail Account bruteforcer/dictionary attack application. It will successfully crack any Gmail account. The bruteforce option may take longer than the dictionary method</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/8932170243634028659/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/brutemonkey-gmail-bruteforcedictionary.html#comment-form' title='1 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8932170243634028659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/8932170243634028659'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/brutemonkey-gmail-bruteforcedictionary.html' title='BruteMonkey Gmail Bruteforce/Dictionary Attack'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_rIh95t1bhWM/S92faAU26OI/AAAAAAAAAF8/oBVy1MoJby8/s72-c/Picture.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5359492729501510821</id><published>2010-05-02T13:24:00.001+08:00</published><updated>2011-06-20T01:22:51.740+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>securing Web with application firewall</title><summary type='text'>2006 wasc(web application security consurtium)releaseWeb Application Firewall Evaluation Criteria 
for detailed criteria of the desired web application firewall. Web application firewall implementation service(appliance, plugins, set of HTTP rules)created specifically to address the various types of attacks on web security,web application firewall specifically to cope with various kinds of </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5359492729501510821/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/securing-web-with-application-firewall.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5359492729501510821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5359492729501510821'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/05/securing-web-with-application-firewall.html' title='securing Web with application firewall'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5050667824380270987</id><published>2010-04-30T02:40:00.002+08:00</published><updated>2010-04-30T02:47:30.730+08:00</updated><title type='text'>ipv6-hackit/</title><summary type='text'> Subject      : kecoak-elektronik.net,ipsecs.comSubject      : Exploiting Future Internet - Defeating IPv6
Writer       : Ph03n1X (return?)
Contact      : staff@kecoak-elektronik.netlanguage ver : IndonesiaTOKET - Terbitan Online Kecoak Elektronik
Defending the classical hackers mind since 1995  IPv6 merupakan protokol internet masa depan yang dikenalkan oleh IETF
sejak tahun 1998. Standar </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5050667824380270987/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/04/ipv6-hackit.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5050667824380270987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5050667824380270987'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/04/ipv6-hackit.html' title='ipv6-hackit/'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-5625114529259488335</id><published>2010-03-22T07:17:00.002+08:00</published><updated>2011-06-21T22:52:10.989+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Oracle XDB FTP service UNLOCK buffer overflow</title><summary type='text'>[+] vulnerabilities network level/stack based buffer overflow
[+] special network layer attack
[+] implemented over http/XML-db/ftp==&gt;windows XDB
[+] connecting:8080
[=] operation: win 32--&gt;xdb overflow
[+] author mc2_s3lector
[+] yogyacarderlink.web.id/KeDai Computerworks.com


exploit win32
#include 
#include 
#include 

int GainControlOfOracle(char *, char *);
int StartWinsock(void);
int </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/5625114529259488335/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/03/oracle-xdb-ftp-service-unlock-buffer.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5625114529259488335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/5625114529259488335'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/03/oracle-xdb-ftp-service-unlock-buffer.html' title='Oracle XDB FTP service UNLOCK buffer overflow'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-4546715876491229973</id><published>2010-03-10T16:41:00.001+08:00</published><updated>2010-03-10T16:41:00.378+08:00</updated><title type='text'>Thanks for the malware sample!</title><summary type='text'>Here at the X-Force, we catch our fair share of malware from random  spammers and phishers just as any corporate or home user does. Today we  dive into one of these attacks to show how it works and what these guys  are after.
This poorly crafted email phising attack was sent to us courtesy of: 
Received: from  XXX.cpe.vivax.com.br ([189.55.XXX.XXX])
It contained a simple link to a website hosting</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/4546715876491229973/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/03/thanks-for-malware-sample.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4546715876491229973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/4546715876491229973'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/03/thanks-for-malware-sample.html' title='Thanks for the malware sample!'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rIh95t1bhWM/S5dYSqyLdpI/AAAAAAAAAFI/KFaHp3kCk2c/s72-c/jscript_001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-3052036586308839555</id><published>2010-03-10T16:09:00.003+08:00</published><updated>2011-06-21T00:48:35.553+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Creating News for Blackhat SEO</title><summary type='text'>Spammers and scammers are no longer content with exploiting real news  events for their personal gain - they're now creating their own news to  earn money through affiliate programs using blackhat SEO techniques.Blackhat SEO is when spammers and scammers use various dirty tricks  to get links to their pages to show up near the top of search results on  search engines. It's been a problem for a </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/3052036586308839555/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/03/creating-news-for-blackhat-seo.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3052036586308839555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/3052036586308839555'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/03/creating-news-for-blackhat-seo.html' title='Creating News for Blackhat SEO'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rIh95t1bhWM/S5dRmFL9gOI/AAAAAAAAAE4/5qFBc67GNkw/s72-c/cn_hosts_01.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-7017286828920336677</id><published>2010-02-17T13:58:00.003+08:00</published><updated>2011-06-20T01:30:52.606+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>How to Prevent Joomla from being hacked or exploited</title><summary type='text'>Along these growing years in the development of Joomla,Joomla has came over to be the best and most reliable Content management System. But in recent news coverage we have seen that things can be exploited if you don't take the right precautions ,Joomla sites can be easily hacked by some little tweaks also.
So how to prevent yourself from being hacked??


While installing Joomla, make sure you </summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/7017286828920336677/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/02/how-to-prevent-joomla-from-being-hacked.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7017286828920336677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/7017286828920336677'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/02/how-to-prevent-joomla-from-being-hacked.html' title='How to Prevent Joomla from being hacked or exploited'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7832887832011382499.post-6269929156008801981</id><published>2010-02-12T12:13:00.002+08:00</published><updated>2010-02-12T12:15:34.111+08:00</updated><title type='text'>HOW TO COVER YOUR TRACKS</title><summary type='text'>PART ONE : THEORY &amp; BACKGROUND



                              I. INTRODUCTION
                             II. MENTAL
                            III. BASICS
                             IV. ADVANCED
                              V. UNDER SUSPECT
                             VI. CAUGHT
                            VII. PROGRAMS
                           VIII. LAST WORDS




     I. INTRODUCTION</summary><link rel='replies' type='application/atom+xml' href='http://c0decstuff.blogspot.com/feeds/6269929156008801981/comments/default' title='Poskan Komentar'/><link rel='replies' type='text/html' href='http://c0decstuff.blogspot.com/2010/02/how-to-cover-your-tracks.html#comment-form' title='0 Komentar'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6269929156008801981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7832887832011382499/posts/default/6269929156008801981'/><link rel='alternate' type='text/html' href='http://c0decstuff.blogspot.com/2010/02/how-to-cover-your-tracks.html' title='HOW TO COVER YOUR TRACKS'/><author><name>c0decstuff</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_rIh95t1bhWM/TTPOkIOeclI/AAAAAAAAAIk/bvBhYC2j5BU/S220/LKM3_512.png'/></author><thr:total>0</thr:total></entry></feed>
