<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DUMBQ3o9fip7ImA9WhRXFEk.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260</id><updated>2011-12-20T22:04:12.466-08:00</updated><category term="Phishing" /><category term="Affiliates Fraud" /><category term="NASA SQL Injection" /><category term="User Interface Redressing" /><category term="National Infrastructures" /><category term="User Interface Rendering" /><category term="ClickJacking Advertisement" /><category term="SQL Injection" /><category term="Hacking Citrix" /><category term="Banner default passwords" /><category term="PathTraversal" /><category term="Frame Busting" /><category term="ClickJacking Facebook" /><category term="Google Dorks" /><category term="TabNabbing" /><category term="Yahoo SQL Injection" /><category term="personal security" /><category term="TinKode" /><category term="NASA XSS" /><category term="Station Hardening Bypass" /><category term="UI Rendering" /><category term="Defeating Frame Busting" /><category term="IRANGE" /><category term="Apple.com SQL Injection" /><category term="Source-Link-Phishing" /><category term="UI Redressing" /><category term="Hacking Terminal Server" /><category term="Kaspersky SQL Injection" /><category term="SCADA Exploitation" /><category term="ClickJacking" /><category term="Gdorks" /><category term="PPC Fraud" /><category term="Directory Traversal Fuzz List" /><category term="Hacking Cockpit" /><category term="ClickJacking Online Demo" /><category term="Stuxnet worm" /><category term="Directory Traversal" /><category term="Army.mil SQL Injection" /><title>Shlomi Narkolayev</title><subtitle type="html">Cutting Edge Information Security Posts.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://narkolayev-shlomi.blogspot.com/" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/NarkolayevShlomi" /><feedburner:info uri="narkolayevshlomi" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>NarkolayevShlomi</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;DkUAQXc9eCp7ImA9WhdVFE8.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-1036310398055736049</id><published>2011-09-18T04:38:00.000-07:00</published><updated>2011-09-19T02:24:00.960-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-19T02:24:00.960-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="personal security" /><category scheme="http://www.blogger.com/atom/ns#" term="IRANGE" /><title>IRANGE - Pays close attention to your valueable items</title><content type="html">This isn't an information security post, but definitely in the personal security field.&lt;br /&gt;
&lt;br /&gt;
I want to present an idea that I have developed with a help from two of my friends, it's called - i-Range.&lt;br /&gt;
&lt;br /&gt;
Unfortunately, I didn't had a time yet to develop this product.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; font-family: arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;I hope you will enjoy watching the video:&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; font-family: arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/-eT3RGgBqd8/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/-eT3RGgBqd8&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="576" height="479"  src="http://www.youtube.com/v/-eT3RGgBqd8&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; font-family: arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;i-Range is a product that gives support in the field of personal security.&lt;br /&gt;
His main goal is to protect every day items, which are considered to be valueable.&lt;br /&gt;
&lt;br /&gt;
The product consists of two end points; The Master unit, the user wears, could be a watch or a braclet and the Slave unit which is a tiny sticker, that can be easily glued on any item.&lt;br /&gt;
&lt;br /&gt;
The i-Range will pay close attention to the valueable items such as: wallet, keys, cell phone, laptop, passport, etc.&lt;br /&gt;
&lt;br /&gt;
The user will glue the sticker on the valueable item.&lt;br /&gt;
Both end-points constantly communicate with each other wirelessly, while the Slave unit sends the signals and the Master unit receives them.&lt;br /&gt;
The user can configure the reception range, which allows the user to change the secure radius.&lt;br /&gt;
When an item exits the secure radius, the system immediately and constantly alerts the user by vibrating and beeping to the user.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-1036310398055736049?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Rnv1I4AZEBYwVB2K6xCbwgPx_O0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rnv1I4AZEBYwVB2K6xCbwgPx_O0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Rnv1I4AZEBYwVB2K6xCbwgPx_O0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rnv1I4AZEBYwVB2K6xCbwgPx_O0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/DN1_gl3u8zU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/1036310398055736049/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2011/09/irange-pays-close-attention-to-your.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/1036310398055736049?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/1036310398055736049?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/DN1_gl3u8zU/irange-pays-close-attention-to-your.html" title="IRANGE - Pays close attention to your valueable items" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2011/09/irange-pays-close-attention-to-your.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUAMR3c8cCp7ImA9Wx9RE0w.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-2208404188474792758</id><published>2010-12-13T23:58:00.000-08:00</published><updated>2010-12-14T00:03:06.978-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-14T00:03:06.978-08:00</app:edited><title>Linkedin ViewLink and ViewArticle mechanism opens new kind of Phishing attacks</title><content type="html">In this post I'll explain how it's possible to execute Phishing attacks on LinkedIn users while the attacked users will see in the address bar the LinkedIn.com domain.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
LinkedIn users allowed to attach links to their posts in linkedIn website.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
User that will click on these links will open the links using the LinkedIn ViewLink mechanism that will open the link in a iFrame.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Attackers can upload a regular LinkedIn phishing page and abuse this ViewLink mechanism and fool users and steal their passwords, all they need to is to attach a link to this phishing page in their posts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I did this POC (proof of concept) today, here is what I got:&lt;br /&gt;
Step1:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_7SGegaFwNsA/TQcgPApqDxI/AAAAAAAAADs/W6j2brt_1Dw/s1600/step1.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="http://4.bp.blogspot.com/_7SGegaFwNsA/TQcgPApqDxI/AAAAAAAAADs/W6j2brt_1Dw/s400/step1.bmp" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Step2:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_7SGegaFwNsA/TQchAnDVubI/AAAAAAAAADw/rDFF6kscpJM/s1600/step2.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="http://3.bp.blogspot.com/_7SGegaFwNsA/TQchAnDVubI/AAAAAAAAADw/rDFF6kscpJM/s400/step2.bmp" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Step3: &lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_7SGegaFwNsA/TQchkb3l9rI/AAAAAAAAAD4/Keo0v8JZUPc/s1600/step3.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="http://4.bp.blogspot.com/_7SGegaFwNsA/TQchkb3l9rI/AAAAAAAAAD4/Keo0v8JZUPc/s400/step3.bmp" width="400" /&gt;&amp;nbsp;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;So now the poor users need not just to verify the domain on the address bar, they also need to verify they are not entering their credentials on ViewLink or on ViewArticle pages.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-2208404188474792758?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/59FAjtafruI-vW4zH8kDwAevQs0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/59FAjtafruI-vW4zH8kDwAevQs0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/59FAjtafruI-vW4zH8kDwAevQs0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/59FAjtafruI-vW4zH8kDwAevQs0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/bnG2dmW8Ukg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/2208404188474792758/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/12/linkedin-viewlink-and-viewarticle.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2208404188474792758?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2208404188474792758?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/bnG2dmW8Ukg/linkedin-viewlink-and-viewarticle.html" title="Linkedin ViewLink and ViewArticle mechanism opens new kind of Phishing attacks" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_7SGegaFwNsA/TQcgPApqDxI/AAAAAAAAADs/W6j2brt_1Dw/s72-c/step1.bmp" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/12/linkedin-viewlink-and-viewarticle.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEMSHs4eSp7ImA9WhdREko.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-2845701908023515170</id><published>2010-11-17T03:26:00.000-08:00</published><updated>2011-08-02T00:38:09.531-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-02T00:38:09.531-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Banner default passwords" /><category scheme="http://www.blogger.com/atom/ns#" term="National Infrastructures" /><category scheme="http://www.blogger.com/atom/ns#" term="SCADA Exploitation" /><category scheme="http://www.blogger.com/atom/ns#" term="Stuxnet worm" /><title>SCADA Exploitation - Hacking into national infrastructures</title><content type="html">Hackers find their next target using SHODAN search engine&lt;br /&gt;
&lt;br /&gt;
SHODAN (&lt;a href="http://www.shodanhq.com/"&gt;http://www.shodanhq.com/&lt;/a&gt;)&amp;nbsp;is a search engine that allows find specific computers (routers, servers, etc.) using a variety of filters. They grad this "horrible" data from (routers, servers, etc.) 'banners'.&lt;br /&gt;
&lt;br /&gt;
Using this DB, hackers can find SCADA Internet-facing Web interfaces, default passwords for web servers and network devices, IP cameras, vulnerable systems (filtering by IIS 5, windows 200, etc), and many more.&lt;br /&gt;
&lt;br /&gt;
Some interesting SCADA information (took from SHODAN DB):&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_7SGegaFwNsA/TOO12Z1TluI/AAAAAAAAADk/LqV75cPw77U/s1600/simense_US.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/_7SGegaFwNsA/TOO12Z1TluI/AAAAAAAAADk/LqV75cPw77U/s320/simense_US.bmp" width="153" /&gt;&lt;/a&gt;&lt;/div&gt;By the way, Simatic S7 SCADA like mention above, are the same systems that were targeted and penetrated by Stuxnet worm.&lt;br /&gt;
&lt;br /&gt;
Using this information, H4ck3rs can locate these critical national infrastructures systems and try to penetrate them, what can be sometimes very easy.&lt;br /&gt;
&lt;br /&gt;
Here is one nice example:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/--WRx-hueho?fs=1&amp;amp;hl=iw_IL"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/--WRx-hueho?fs=1&amp;amp;hl=iw_IL" allowscriptaccess="never" allowfullscreen="true" wmode="transparent" type="application/x-shockwave-flash" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;
Here are some default password in use:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_7SGegaFwNsA/TOO6XYErdhI/AAAAAAAAADo/SenDvLeTEz4/s1600/defaultPasswords.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/_7SGegaFwNsA/TOO6XYErdhI/AAAAAAAAADo/SenDvLeTEz4/s320/defaultPasswords.bmp" width="284" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Please don't use this data to hack these systems, this is illegal !!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-2845701908023515170?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/J2YtMvm9pbgVrs-l3q7J-jX69wE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/J2YtMvm9pbgVrs-l3q7J-jX69wE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/J2YtMvm9pbgVrs-l3q7J-jX69wE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/J2YtMvm9pbgVrs-l3q7J-jX69wE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/38uVWJ2md88" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/2845701908023515170/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/11/scada-exploitation-hacking-into.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2845701908023515170?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2845701908023515170?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/38uVWJ2md88/scada-exploitation-hacking-into.html" title="SCADA Exploitation - Hacking into national infrastructures" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_7SGegaFwNsA/TOO12Z1TluI/AAAAAAAAADk/LqV75cPw77U/s72-c/simense_US.bmp" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/11/scada-exploitation-hacking-into.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEENRXc5fip7ImA9WhdaFkw.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-32337950968363175</id><published>2010-09-22T03:22:00.000-07:00</published><updated>2011-10-26T01:11:34.926-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-26T01:11:34.926-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="Source-Link-Phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="TabNabbing" /><title>Source-Link-Phishing (A.K.A. TabNabbing) - New technique for phishing attacks</title><content type="html">I would like to demonstrate a new technique that could be used for phishing attacks.&lt;br /&gt;
&lt;br /&gt;
Using this technique, Phishers can more easily fool naive users and steal there login credentials.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Attack scenario:&lt;/u&gt;&lt;br /&gt;
Let's suppose that a Phisher wants to get some bank's (Or any other "Interesting" online system) users credentials and this bank allows posting links as comments on some pages.&lt;br /&gt;
The Phisher just need to post this link: http://shlominar.50webs.com/Source-Link-Phishing.html&lt;br /&gt;
and anyone that will click on this link will open new tab and after a few seconds the "Source" tab will be changed to a Phishing page.&lt;br /&gt;
&lt;br /&gt;
I call this technique: Source-Link-Phishing&lt;br /&gt;
&lt;br /&gt;
&lt;a target="_blank" href="http://shlominar.50webs.com/simpleLink.html"&gt;Demo&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-32337950968363175?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Orw5EoiXKlbCOdeWRGJ8r01k3qA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Orw5EoiXKlbCOdeWRGJ8r01k3qA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Orw5EoiXKlbCOdeWRGJ8r01k3qA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Orw5EoiXKlbCOdeWRGJ8r01k3qA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/OyS1oUc0Ius" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/32337950968363175/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/09/source-link-phishing-aka-tabnabbing-new.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/32337950968363175?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/32337950968363175?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/OyS1oUc0Ius/source-link-phishing-aka-tabnabbing-new.html" title="Source-Link-Phishing (A.K.A. TabNabbing) - New technique for phishing attacks" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/09/source-link-phishing-aka-tabnabbing-new.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkIGQ347eip7ImA9WhRTFUs.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-3351198260328666325</id><published>2010-04-06T22:24:00.000-07:00</published><updated>2011-11-06T00:28:42.002-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-06T00:28:42.002-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Directory Traversal" /><category scheme="http://www.blogger.com/atom/ns#" term="PathTraversal" /><category scheme="http://www.blogger.com/atom/ns#" term="Directory Traversal Fuzz List" /><title>Directory Traversal Cheat Sheet</title><content type="html">You can use this cheat sheet for exploiting web servers and application servers for directory traversal.&lt;br /&gt;
&lt;br /&gt;
This is eight level of deep Directory Traversal. There are 880 variants of Directory Traversal attack signatures.&lt;br /&gt;
&lt;br /&gt;
To use this list effectively, you need to replace the "(Filename)" phrase to the desired file - Depending by the attacked web server OS.&lt;br /&gt;
&lt;br /&gt;
Be my guest to suggest more variants to this awesome list.&lt;br /&gt;
&lt;br /&gt;
Enjoy ;-)&lt;br /&gt;
&lt;br /&gt;
Credits to&lt;span dir="ltr"&gt;&lt;i&gt;&lt;/i&gt; Luca "ikki" Carettoni&lt;/span&gt; for this list.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://" onmousedown="loadList();"&gt;Open the cheat sheet&lt;/a&gt; (this will take few seconds to load this long list)&lt;br /&gt;
&lt;br /&gt;
&lt;script type="text/javascript"&gt;
function loadList()
{
document.write('Press back to go back &lt;br/&gt; &lt;iframe height="777" id="frmList" scrolling="yes" src="http://shlominar.50webs.com/dirTraversal.html" width="100%"&gt;&lt;/iframe&gt;');
}
&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-3351198260328666325?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/W0qht49JQevWCodnkYnoF_-lUyI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/W0qht49JQevWCodnkYnoF_-lUyI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/W0qht49JQevWCodnkYnoF_-lUyI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/W0qht49JQevWCodnkYnoF_-lUyI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/RTQ-ObgvMyo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/3351198260328666325/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/04/directory-traversal-fuzz-list.html#comment-form" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/3351198260328666325?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/3351198260328666325?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/RTQ-ObgvMyo/directory-traversal-fuzz-list.html" title="Directory Traversal Cheat Sheet" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>6</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/04/directory-traversal-fuzz-list.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkIHQH8-fSp7ImA9WhdQE0w.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-2604207868519980777</id><published>2010-02-19T05:05:00.000-08:00</published><updated>2011-08-14T02:35:31.155-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-14T02:35:31.155-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Affiliates Fraud" /><category scheme="http://www.blogger.com/atom/ns#" term="PPC Fraud" /><category scheme="http://www.blogger.com/atom/ns#" term="ClickJacking Advertisement" /><title>ClickJacking Advertisement</title><content type="html">I want to present you JavaScript scheme that I wrote in recent days.&lt;br /&gt;
&lt;br /&gt;
This demo presents how it can possible to “steal” users clicks and force them to click on your advertisements for example.&lt;br /&gt;
&lt;br /&gt;
Using these advanced methods, the “bad guys” can make a lot of money using PPC (Pay per Click) and other affiliates programs that are very popular in these days.&lt;br /&gt;
&lt;br /&gt;
Here's my &lt;a href="http://shlominar.50webs.com/ppc-Fraud.html"&gt;&lt;b&gt;online demo&amp;nbsp;&lt;/b&gt;(Click here)&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-2604207868519980777?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_bgr6J6zqh0jc0ZXpMnbnvZHKi8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_bgr6J6zqh0jc0ZXpMnbnvZHKi8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_bgr6J6zqh0jc0ZXpMnbnvZHKi8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_bgr6J6zqh0jc0ZXpMnbnvZHKi8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/ZoPDyUQJmyw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/2604207868519980777/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/02/clickjacking-advertisement.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2604207868519980777?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2604207868519980777?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/ZoPDyUQJmyw/clickjacking-advertisement.html" title="ClickJacking Advertisement" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>3</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/02/clickjacking-advertisement.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4HRXszfSp7ImA9WhdbFUU.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-6522444827313815431</id><published>2010-02-03T10:08:00.000-08:00</published><updated>2011-10-14T02:02:14.585-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-14T02:02:14.585-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Station Hardening Bypass" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking Terminal Server" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking Citrix" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking Cockpit" /><title>Hacking Citrix and Terminal Server Techniques</title><content type="html">Friend of mine is security consultant and from time to time he's asking my help for hacking Citrix and Terminal Servers.&lt;br /&gt;
So I decided to write a list of my hacking techniques that I use in case someone tries to close some registry keys ;-)&lt;br /&gt;
&lt;br /&gt;
I'll try regularly update this list:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Basic shortcuts:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Open file: Ctrl + o&lt;/li&gt;
&lt;li&gt;Save File: Ctrl + s&lt;/li&gt;
&lt;li&gt;Open New Browser: Ctrl + n, Shift (or Ctrl) + Left Click on link&lt;/li&gt;
&lt;li&gt;Browser History: Ctrl + h&lt;/li&gt;
&lt;li&gt;Task Manager: Ctrl+Shift+Esc&lt;/li&gt;
&lt;li&gt;File manager: Windows + E&lt;/li&gt;
&lt;li&gt;Run commands: Windows + R&lt;/li&gt;
&lt;li&gt;Utility Manager: Windows + U&lt;/li&gt;
&lt;li&gt;Windows search: Windows + F&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Open Internet browser:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Press F1 – Click on any URL to open.&lt;/li&gt;
&lt;li&gt;Click on help on the language bar.&lt;/li&gt;
&lt;li&gt;Windows + U -&gt; Help&lt;/li&gt;
&lt;li&gt;Run calc -&gt; Help -&gt; Help Topics -&gt; Mouse right click on the window blue frame -&gt; &lt;b&gt;Jump to URL&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Get local files (like cmd.exe):&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Printing window (Ctrl + p) -&gt; print to file -&gt; filename=* -&gt; Enter -&gt; and browse to system32&lt;/li&gt;
&lt;li&gt;Right Mouse Click (or Shift + F10) -&gt; Save Picture As -&gt; filename=* -&gt;…&lt;/li&gt;
&lt;li&gt;                                                                  View Source -&gt; filename=* -&gt;…&lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;If the right mouse click is forbidden:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Use Shift + F10&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Run Command Shell:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Run command.com&lt;/li&gt;
&lt;li&gt;Drag other file on cmd.exe or command.com&lt;/li&gt;
&lt;li&gt;Shortcut to cmd.exe or command.com&lt;/li&gt;
&lt;li&gt;Batch file with: c:\windows\system32\cmd /c (Or /K) any_command&lt;/li&gt;
&lt;li&gt;VBS script: &lt;/li&gt;
Dim shlomi ShellSet shlomiShell= WScript.CreateObject ("WScript.shell") oShell.run "cmd /K CD C:\ &amp;amp; Dir" Set shlomiShell= Nothing&lt;/ul&gt;&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Open file manager using IE:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Favorites -&gt; Drag any folder to browser’s window.&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;span style="font-weight: bold;"&gt;Using office applications:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Insert Picture -&gt; filename=* -&gt;…&lt;/li&gt;
&lt;li&gt;Insert Hyper Link - &gt; file://c:\windows\system32\cmd.exe&lt;/li&gt;
&lt;li&gt;Insert object -&gt; Create from File -&gt; cmd.exe or command.com&lt;/li&gt;
&lt;li&gt;Run VB (or VB Macro).&lt;/li&gt;
&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;
If you can't run shell:&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Rename cmd.exe (or command.com) to applicationName_uCanRun.exe.&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;Use Debug.exe, using this you can run almost any exe you like. You just need to upload the Assembly code or write by yourself.&lt;/li&gt;
&lt;li&gt;Run VB compiler, using office applications.&lt;/li&gt;
&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-6522444827313815431?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_rXUHn0nVFJw06vT6waFFq0V7zk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_rXUHn0nVFJw06vT6waFFq0V7zk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_rXUHn0nVFJw06vT6waFFq0V7zk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_rXUHn0nVFJw06vT6waFFq0V7zk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/6fB6qPzbQfc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/6522444827313815431/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/02/hacking-citrix-and-terminal-server.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/6522444827313815431?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/6522444827313815431?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/6fB6qPzbQfc/hacking-citrix-and-terminal-server.html" title="Hacking Citrix and Terminal Server Techniques" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>4</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/02/hacking-citrix-and-terminal-server.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU4FSXs5fCp7ImA9WxFRFU4.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-6379026066207553300</id><published>2010-01-29T00:30:00.000-08:00</published><updated>2010-04-29T03:45:18.524-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-29T03:45:18.524-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Kaspersky SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="TinKode" /><category scheme="http://www.blogger.com/atom/ns#" term="Army.mil SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="Yahoo SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="Apple.com SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="NASA SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="NASA XSS" /><title>Hacking the Planet - By TinKode</title><content type="html">This post isn't technological, but still I want point you to TinKode’s recent nice hacks, among them:&lt;br /&gt;
NASA - &lt;a href="http://tinkode.insecurity.ro/tag/the-center-for-aerosol-research-nasa-website-security-issues/" target="_blank"&gt;SQL Injection&lt;/a&gt;, &lt;a href="http://tinkode.insecurity.ro/tag/how-to-find-xss-in-nasa/" target="_blank"&gt;XSS&lt;/a&gt;, &lt;a href="http://tinkode.insecurity.ro/tag/nasa-vulnerable-to-mssql-injection/" target="_blank"&gt;SQL Injection (MSSQL)&lt;/a&gt;,&lt;br /&gt;
&lt;a href="http://tinkode.insecurity.ro/tag/us-army-full-disclosure/" target="_blank"&gt;Army.mil&lt;/a&gt;, &lt;a href="http://tinkode.insecurity.ro/tag/yahoo-blind-sql-injection/" target="_blank"&gt;Yahoo&lt;/a&gt;, &lt;a href="http://tinkode.insecurity.ro/tag/kaspersky-thailand-full-access/" target="_blank"&gt;Kaspersky&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
These critical systems recent hacks was executed by one person in less then 2 month.&lt;br /&gt;
Cases like these outlines today's systems security reality.&lt;br /&gt;
&lt;br /&gt;
He didn't used any sophisticated attack vectors or any 0-day exploit, just discovered on the right time and on the right place some SQLi and XSS holes.&lt;br /&gt;
&lt;br /&gt;
Don't worry: Secure SDLC (Systems Development Life Cycle) + Good Configured WAF (Web Application Firewall) + Advanced VA (Vulnerability Assessments) and Security awareness may solve this problem ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-6379026066207553300?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/8IHVLLAm-pdRLNWHvS2MAYTfdwA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8IHVLLAm-pdRLNWHvS2MAYTfdwA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/8IHVLLAm-pdRLNWHvS2MAYTfdwA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8IHVLLAm-pdRLNWHvS2MAYTfdwA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/j7oj3txwk6A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/6379026066207553300/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/01/hacking-planet-by-tinkode.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/6379026066207553300?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/6379026066207553300?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/j7oj3txwk6A/hacking-planet-by-tinkode.html" title="Hacking the Planet - By TinKode" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/01/hacking-planet-by-tinkode.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMBRnszeCp7ImA9WhdQE0w.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-2500078155550504031</id><published>2010-01-15T00:47:00.000-08:00</published><updated>2011-08-14T02:34:17.580-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-14T02:34:17.580-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ClickJacking Online Demo" /><category scheme="http://www.blogger.com/atom/ns#" term="UI Redressing" /><category scheme="http://www.blogger.com/atom/ns#" term="ClickJacking" /><category scheme="http://www.blogger.com/atom/ns#" term="User Interface Rendering" /><category scheme="http://www.blogger.com/atom/ns#" term="User Interface Redressing" /><category scheme="http://www.blogger.com/atom/ns#" term="UI Rendering" /><category scheme="http://www.blogger.com/atom/ns#" term="ClickJacking Facebook" /><title>ClickJacking Facebook</title><content type="html">I discovered that websites like Facebook and many others "protected" websites are vulnerable to ClickJacking attack.&lt;br /&gt;
I have informed some mass users websites like Facebook with my findings.&lt;br /&gt;
&lt;br /&gt;
Here is Facebook response:&lt;br /&gt;
&lt;span style="font-size: 85%;"&gt;Our team looked at this. It's standard clickjacking and not unique to Facebook. We're building some additional protections for these types of attacks and reminding people to be cautious of any message, post, or link they find on Facebook or elsewhere on the Internet that looks suspicious. &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
This demo video presenting how can I fool Facebook users to add applications to their account.&lt;br /&gt;
&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/93uciX4eUbQ&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;hd=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/93uciX4eUbQ&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
I could write malicious application that steals users personal info or even simple application that build for me a bot net users for malicious purposes like hacking systems for SQL Injections and DDOS attacks.&lt;br /&gt;
&lt;br /&gt;
Using ClickJacking i also could fool users to click whatever I want: adding me as their friend, delete their account, and even open their camera and microphone using flash (Older versions then 10.x), or install Facebook applications that posting their web camera and microphone every time they connected to Facebook - Just use your imagination on what you want others to click on...Transfer to you poker chips???&lt;br /&gt;
&lt;br /&gt;
Here's my &lt;a href="http://shlominar.50webs.com/ClickJacking.html"&gt;&lt;b&gt;online demo&lt;/b&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;(Click here)&lt;/a&gt;.&lt;br /&gt;
Using this demo you can check if your website is vulnerable to ClickJacking attacks. If you were able to click on links and buttons and other active objects in the hidden iFrame - so your website is vulnerable.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://backoffice.comitari.com/qwerty/comitari-free.exe"&gt;Comitari Free - Bullet proof protection against ClickJacking and UI Redressing attacks&lt;/a&gt;&lt;br /&gt;
Comitari website: &lt;a href="http://www.comitari.com/"&gt;http://www.comitari.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-2500078155550504031?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iQZRcKhBwVlZaadk9H04MX64gGY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iQZRcKhBwVlZaadk9H04MX64gGY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iQZRcKhBwVlZaadk9H04MX64gGY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iQZRcKhBwVlZaadk9H04MX64gGY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/DfVUPcF_hgQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/2500078155550504031/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/01/clickjacking-facebook.html#comment-form" title="9 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2500078155550504031?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/2500078155550504031?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/DfVUPcF_hgQ/clickjacking-facebook.html" title="ClickJacking Facebook" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>9</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/01/clickjacking-facebook.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUARnk_fCp7ImA9WhdREko.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-5651633690617624541</id><published>2010-01-13T09:18:00.000-08:00</published><updated>2011-08-02T01:37:27.744-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-02T01:37:27.744-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SQL Injection" /><category scheme="http://www.blogger.com/atom/ns#" term="Google Dorks" /><category scheme="http://www.blogger.com/atom/ns#" term="Gdorks" /><title>Find SQL Injection using Google Dorks</title><content type="html">MSSQL:&lt;br /&gt;
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'&lt;br /&gt;
[Microsoft][ODBC SQL Server Driver][SQL Server]Unclosed quotation mark before the character string&lt;br /&gt;
Microsoft Jet Database&lt;br /&gt;
VbScript&lt;br /&gt;
&lt;br /&gt;
MySQL:&lt;br /&gt;
mysql error&lt;br /&gt;
mysql_query&lt;br /&gt;
mysql_fetch&lt;br /&gt;
mysql_connect&lt;br /&gt;
&lt;br /&gt;
Oracle:&lt;br /&gt;
ORA-00921: unexpected end of SQL command&lt;br /&gt;
&lt;br /&gt;
PostgreSQL:&lt;br /&gt;
Warning: pg_query(): Query failed: ERROR: Argument&lt;br /&gt;
pg_connect&lt;br /&gt;
pg_exec&lt;br /&gt;
pg_fetch_object&lt;br /&gt;
pg_fetch_array&lt;br /&gt;
&lt;br /&gt;
Here are some examples:&lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: mysql_fetch_assoc() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: mysql_fetch_array() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: mysql_num_rows() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: session_start() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: getimagesize() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: is_writable() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: getimagesize() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: Unknown() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: session_start() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: mysql_result() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: pg_exec() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: mysql_result() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: mysql_num_rows() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: mysql_query() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: array_merge() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: preg_match() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: ilesize() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: filesize() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: filesize() &lt;br /&gt;
inurl:"id=" &amp;amp; intext:"Warning: require()&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-5651633690617624541?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Zi-K1_-5xekD0YjoAXmQaYbtrhM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zi-K1_-5xekD0YjoAXmQaYbtrhM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Zi-K1_-5xekD0YjoAXmQaYbtrhM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zi-K1_-5xekD0YjoAXmQaYbtrhM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/PcVgFrAp1SU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/5651633690617624541/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/01/find-sql-injection-using-google-dorks_13.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/5651633690617624541?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/5651633690617624541?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/PcVgFrAp1SU/find-sql-injection-using-google-dorks_13.html" title="Find SQL Injection using Google Dorks" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/01/find-sql-injection-using-google-dorks_13.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcCSXkyfSp7ImA9WxFTFk8.&quot;"><id>tag:blogger.com,1999:blog-8929972703129982260.post-831715183680358886</id><published>2010-01-13T08:53:00.000-08:00</published><updated>2010-04-07T00:41:08.795-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-07T00:41:08.795-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="UI Redressing" /><category scheme="http://www.blogger.com/atom/ns#" term="Frame Busting" /><category scheme="http://www.blogger.com/atom/ns#" term="ClickJacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Defeating Frame Busting" /><title>Defeating Frame Busting Scripts</title><content type="html">One of the most used solutions for ClickJacking is to setup JavaScript in your page that you want to protect, that forbids to be framed.&lt;br /&gt;
&lt;br /&gt;
Here is an example to this script:&lt;br /&gt;
&lt;textarea cols="50" rows="2" scrolling="yes"&gt;&lt;script type="text/javascript"&gt;if(top != self) top.location.href = location.href;&lt;/script&gt;&lt;/textarea&gt;&lt;br /&gt;
&lt;span style="font-family:webdings;"&gt; &lt;/span&gt;&lt;br /&gt;
Here is how we can bypass this protection:&lt;br /&gt;
We need to set the I-Frame tag property by Microsoft's security restriction method.&lt;br /&gt;
Using this property we will not allow the JavaScript code inside the I-Frame to execute.&lt;br /&gt;
&lt;span&gt; &lt;/span&gt;&lt;br /&gt;
Here is an example:&lt;br /&gt;
&lt;textarea cols="50" rows="2" scrolling="yes"&gt;&lt;iframe id="frm" src="http://facebook.com" security="restricted"&gt;&lt;/iframe&gt;&lt;/textarea&gt;&lt;br /&gt;
&lt;span&gt; &lt;/span&gt;&lt;br /&gt;
&lt;span&gt;Some notes:&lt;br /&gt;
• This will block running all JavaScript in the I-Frame (It could brake some applications that uses JS).&lt;br /&gt;
• This works only for IE and Opera users (So Mozzila and Crome users are protected).&lt;br /&gt;
&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8929972703129982260-831715183680358886?l=narkolayev-shlomi.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xhP-tTS79CJJyMSH1mxWGu8oMZk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xhP-tTS79CJJyMSH1mxWGu8oMZk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xhP-tTS79CJJyMSH1mxWGu8oMZk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xhP-tTS79CJJyMSH1mxWGu8oMZk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/NarkolayevShlomi/~4/koixtkvMrdo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://narkolayev-shlomi.blogspot.com/feeds/831715183680358886/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://narkolayev-shlomi.blogspot.com/2010/01/defeating-frame-busting-scripts-one-of.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/831715183680358886?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8929972703129982260/posts/default/831715183680358886?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/NarkolayevShlomi/~3/koixtkvMrdo/defeating-frame-busting-scripts-one-of.html" title="Defeating Frame Busting Scripts" /><author><name>Narkolayev Shlomi</name><uri>http://www.blogger.com/profile/10811940969497558110</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="http://4.bp.blogspot.com/_7SGegaFwNsA/S0wsNtJDxbI/AAAAAAAAAAM/PkuyuWnTPq4/S220/0afddb7.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://narkolayev-shlomi.blogspot.com/2010/01/defeating-frame-busting-scripts-one-of.html</feedburner:origLink></entry></feed>

