<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Hacking Tricks</title><link>http://www.hackingtricks.in/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/blogspot/csAFg" /><description></description><language>en</language><managingEditor>noreply@blogger.com (Deepanker Verma)</managingEditor><lastBuildDate>Wed, 01 May 2013 01:43:13 PDT</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">651</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><feedburner:info uri="blogspot/csafg" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>blogspot/csAFg</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>A new Android Malware BadNews Discovered, Downloaded More than 9 Million Times</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/2mmaEuOmRw8/a-new-android-malware-badnews.html</link><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sun, 21 Apr 2013 06:51:07 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-3300587103721380214</guid><description>

A new bad news comes in the form of new Android Malware called BadNews. This new malware has been found in more than 9 million downloads. Security Firm Lookout found this malware in 32 apps. Most of these 32 apps were available in Google Play and target Russian users.



Company posted the name and download numbers in blog post. Most downloaded Malware appw as a game called Savage Knife. This </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-21T19:21:07.373+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-i4uZPn1tqpw/UXPuRuA76HI/AAAAAAAAH9c/kYVHVKnVM18/s72-c/android-malware.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/04/a-new-android-malware-badnews.html</feedburner:origLink></item><item><title>How to Start Web Application Penetration testing With Websecurify</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/_PfBl-HfSWg/how-to-start-web-application.html</link><category>smartphone penetration testing</category><category>penetration testing</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Mon, 15 Apr 2013 11:57:21 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-2162222304878220402</guid><description>

If you are a developer, owner of a software firm or a testing engineer, you must know the importance of security testing. Hackers are everywhere and they always try to intrude in the system, network and applications. If we talk about Web application penetration testing, there are so many tools available. In this post, we will see how to use Websecurify for penetration testing of web </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-16T00:27:21.605+05:30</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-0ef65CacrR4/UWxJF3SqEPI/AAAAAAAAH7k/V-rWe7cMqBI/s72-c/websecurify.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/04/how-to-start-web-application.html</feedburner:origLink></item><item><title>Popular online Document Sharing website Scribd Hacked</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/KpnHAm1GcBc/popular-online-document-sharing-website.html</link><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Fri, 05 Apr 2013 00:30:48 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-5854521625226559338</guid><description>

World's most popular online document sharing website Scribd is the latest member of cyber attacker. Company has posted a security announcement in which it claims that attackers try to access users' information. Company is also asking users to change their passwords. Scribd has already sent mail to all affected users.

“Earlier this week, Scribd’s Operations team discovered and blocked </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-05T13:00:48.290+05:30</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/04/popular-online-document-sharing-website.html</feedburner:origLink></item><item><title>Methods of Finding Admin Login Page of a Website</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/9Yvyec1qbYY/methods-of-finding-admin-login-page-of.html</link><category>Website hacking</category><category>password cracking</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sun, 17 Mar 2013 03:52:22 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-449108687142462401</guid><description>


Sometimes it is hard to find admin login pages on the website because they are not linked with main website. Once I found SQL injection vulnerability in a website and easily got the admin user name, password. Next step was finding the admin login page and try the password. But it took hours to get the page.




Sometimes, it is really hard to find the admin login pages. This is because admin </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-17T16:22:22.790+05:30</app:edited><media:thumbnail url="http://3.bp.blogspot.com/-5RKQRs8EBDQ/UUWgKL41p_I/AAAAAAAAHwA/pACDWqd0Lu4/s72-c/admin.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/03/methods-of-finding-admin-login-page-of.html</feedburner:origLink></item><item><title>WordPress Security Scanning With WpScan Android App</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/gGsgJPNHNRU/wordpress-security-scanning-with-wpscan.html</link><category>wordpress</category><category>Web Application Security Scanner Framework</category><category>android</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Fri, 15 Mar 2013 01:55:51 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-8556779737356393825</guid><description>

With the increasing popularity of Android devices, security companies are developing penetration testing tools for this platform. If you own a WordPress website, now you can scan it for known security vulnerabilities with WpScan Android app. 



Wpscan is a blackbox WordPress security scanner written in Ruby. This app was also available on Google Play store, but now it is unavailable. You can </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-15T14:25:51.128+05:30</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-7pFlHHxrliA/UULZZAwMOUI/AAAAAAAAHvU/NmKKeVSd5xQ/s72-c/WPScan.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/03/wordpress-security-scanning-with-wpscan.html</feedburner:origLink></item><item><title>Evernote Hacked, Emails and Encrypted Passwords Leaked</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/FlOD5dO4w2w/evernote-hacked-emails-and-encrypted.html</link><category>webiste hacking</category><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sat, 02 Mar 2013 21:56:14 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-4062583921748702186</guid><description>

Few hours ago, Popular tech company Evernote has also confirmed that hackers have broken into their systems. Company revealed that hackers have access the emails addresses and encrypted passwords.




Now, Company is forcing users to change their account password before accessing the service. Company is also sending emails to all registered users and requesting them to change password as soon </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-03T11:26:14.670+05:30</app:edited><media:thumbnail url="http://3.bp.blogspot.com/-h6l3q3ikDzQ/UTLlQ2NhGkI/AAAAAAAAHrM/8Hqe4Ym7JYM/s72-c/Evernote_thumb.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/03/evernote-hacked-emails-and-encrypted.html</feedburner:origLink></item><item><title>Which Tool Should I use for Pentesting And How?</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/mY_OEd8x2rI/which-tool-should-i-use-for-pentesting_23.html</link><category>hacking tutorial</category><category>penetration testing</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sat, 23 Feb 2013 08:54:17 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-978058915508708669</guid><description>


Penetration testing is the process of finding of security vulnerabilities in web application. It can also be seen as security testing. To make the testing process simple, there are many manual tools and automatic tools available. By using these tools, we can find vulnerabilities faster than manual testing methods. 

There are so many penetration testing tools available. You can find most of </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-23T22:24:17.676+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-_nQxtXEhqvU/USYfbzPYJSI/AAAAAAAAHcA/B61h0YawoIo/s72-c/penetration-testing-1.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/02/which-tool-should-i-use-for-pentesting_23.html</feedburner:origLink></item><item><title>Twitter Hacked, Change your Password Now</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/p_yhwOwasRo/twitter-hacked-changed-your-password-now.html</link><category>twitter hacking</category><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sat, 23 Feb 2013 03:25:01 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-6027810781783108090</guid><description>



Its a bad news for Twitter users. Today, Twitter has announced that some hackers gained access to its network and compromised few user accounts. According to Twitter, 250,000 Twitter accounts may be compromised. Twitter has also started sending notification emails to all compromised account users.

If you are a regular Twitter user, I will advise you to change your Twitter password now. 

“</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-23T16:55:01.452+05:30</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-fz6w4w2CPwI/UQy-992NXbI/AAAAAAAAHSI/Jf8PSXPRqUU/s72-c/twitter-big.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/02/twitter-hacked-changed-your-password-now.html</feedburner:origLink></item><item><title>Password Cracking With Cain &amp; Able Password Cracker</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/dLcxDBDZdac/password-cracking-with-cain-able.html</link><category>Hacking Tools</category><category>Hacking tutorials</category><category>password cracking</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sat, 26 Jan 2013 01:42:29 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-929058994461338670</guid><description>

If you have few knowledge about password cracking and know few password crackers, I am sure you already know about Cain and Able. Cain and Able is one of the most popular password cracking tools. You can learn more about this tool in our security tools gallery.

Officially, Cain and Able is a password recovery tool available for Windows operating systems and supports all available version of </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-26T15:12:29.351+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-FMGlCDZqFuE/UQOgMGDtYcI/AAAAAAAAHIA/YYHbU_qwANY/s72-c/cain-able.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/01/password-cracking-with-cain-able.html</feedburner:origLink></item><item><title>What is Cross Site Scripting or XSS</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/mL_4R2rr8hg/what-is-cross-site-scripting-or-xss.html</link><category>XSS</category><category>Hacking tutorials</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Fri, 18 Jan 2013 00:11:44 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-6132357509877079722</guid><description>

Cross Site Scripting is also a well known vulnerability and it can be found in most of the popular websites. If you are regular reader of Hacking Tricks, you already know that I found XSS in Amazon, Adobe, eBay, PandaSecurity, Symantec, QuickHeal, K7Antivirus and many other popular websites.

Cross Site Scripting (abbrivated as XSS) is a web application vulnerability that allows attackers to </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-18T13:41:44.686+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-zpEbtIfAhLs/UPj-gSi0v_I/AAAAAAAAG5Q/hMh3WommUGc/s72-c/xss.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/01/what-is-cross-site-scripting-or-xss.html</feedburner:origLink></item><item><title>Most Hidden dangers of Facebook</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/W9kulBculcU/most-hidden-dangers-of-facebook.html</link><category>facebook hacking</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Thu, 17 Jan 2013 00:42:53 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-718395219346027191</guid><description>


The last 3-4 years have
observed a tremendous positive growth ladder in the success rate of Facebook, a
social networking website. Phenomenal success of Facebook has made it the No.1
social networking website presently. In fact, it has beat Google by the maximum
number of visitor visits for one entire week. But things always go the same way
as one may think of. Both positive and negative </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-17T14:12:53.524+05:30</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-HQZmud39GXg/TOLAYX3zcZI/AAAAAAAAAUg/7kn3Ylqq8Rs/s72-c/fb.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/01/most-hidden-dangers-of-facebook.html</feedburner:origLink></item><item><title>Download "The Windows 8 eBook" For free</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/WzialSlktp4/download-windows-8-ebook-for-free.html</link><category>windows 8</category><category>ebooks</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Wed, 16 Jan 2013 06:00:23 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-7670218103263279205</guid><description>

Hello readers, Although I am not active enough now due to less availability of time. But I try my best to provide best resource to you all. Today, I got a nice ebook on Windows 8 that costs $9.95 but you can download it for free from Hacking Tricks.







This book covers most of the problems users are facing with Windows 8. Windows 8 is totally different from older version of Windows and it </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-16T19:30:23.527+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-xOHuQGs6USA/UPayMIjGViI/AAAAAAAAGvw/13OMBVDBjy4/s72-c/windows-8.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/01/download-windows-8-ebook-for-free.html</feedburner:origLink></item><item><title>Microsoft's Delish.com Vulnerable to XSS </title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/bHLZ6_rZ7Hw/microsofts-delishcom-vulnerable-to-xss.html</link><category>Website hacking</category><category>XSS</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Fri, 11 Jan 2013 03:04:31 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-5570170034672612819</guid><description>

I have noticed some XSS vulnerabilities to Microsoft's Delish.com and notified to Microsoft about this. Microsoft has also responded quickly and assured me to patch this vulnerability soon.

See the POC below:



You can see the snapshot where cookies are there in the Javascript alert box. 


XSS vulnerability is very harmful for websites. It can be used to execute malicious scripts when users </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-11T16:34:31.600+05:30</app:edited><media:thumbnail url="http://3.bp.blogspot.com/-X9b5OGcT4yQ/UO_v9oTRRbI/AAAAAAAAGqo/cuDOcw43omU/s72-c/delish.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/01/microsofts-delishcom-vulnerable-to-xss.html</feedburner:origLink></item><item><title>How to send Self Destructing Password Protected Messages and Emails</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/Tw6SDi1DwGU/how-to-send-self-destructing-password.html</link><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Fri, 11 Jan 2013 02:04:18 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-815606543440331236</guid><description>

Privacy and data security is always an important thing which we care while using the Internet. We also know that hackers more active these days and they always try to hack into our emails and other accounts. So it is always risky to share important messages. Sometimes we wish to send emails that also have password protection. In case the other user's account  has been hacked, important email is</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-11T15:34:18.012+05:30</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-otlvI5p0Otk/UO_f4r0YDGI/AAAAAAAAGnY/bE8TwqMz-4A/s72-c/notedip.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/01/how-to-send-self-destructing-password.html</feedburner:origLink></item><item><title>Block Porn Websites On Your Computer With Porn Blocker</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/z4VAFacSHFo/block-porn-websites-on-your-computer.html</link><category>porn blocker</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sun, 06 Jan 2013 06:45:02 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-2754961264707823356</guid><description>
Do You want to protect your children from watching porn movies online? 

You are not the only one. Almost all parents want to protect their children from watching porn online. But Internet has made it easy to get in touch with porn content. With the growth of Internet usage, average age of Internet exposure to pornography is going down. Now its only 11 years.

If you also want to protect your </description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-06T20:15:02.637+05:30</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-AeUpxlcprek/UOmNSar8crI/AAAAAAAAGis/T7gdOe9zcaE/s72-c/group1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2013/01/block-porn-websites-on-your-computer.html</feedburner:origLink></item><item><title>5 Best Books to Learn Web Application Hacking and Penetration testing</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/R-KcS2OIowg/5-best-books-to-lean-web-application.html</link><category>Hacking tutorials</category><category>ebooks</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Mon, 31 Dec 2012 09:01:13 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-3340489383043195833</guid><description>
Year 2012 is about to end and we are waiting to celebrate new year 2013. In 2012, we have seen so many hacking incidents, data breach  password leaks and website deface that belongs to popular websites. All these happens because of web application vulnerabilities that could be patched but developer failed to notice vulnerabilities. This is the reason why Application security field is booming and</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-31T22:31:13.254+05:30</app:edited><media:thumbnail url="http://3.bp.blogspot.com/-zpvrv7AZcgg/UOFMEkhccsI/AAAAAAAAGSY/3UMZUMYacQI/s72-c/book1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/5-best-books-to-lean-web-application.html</feedburner:origLink></item><item><title>Ask Your Problems And Solve Others, Join Free</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/R6mNgs3nB5Q/ask-your-problems-and-solve-others-join.html</link><category>Hacking tutorials</category><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Mon, 24 Dec 2012 05:36:15 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-4344456748332720475</guid><description>

My readers have been requesting me to start a forum for past few months. But I am not prepare for that. Actually I am running few blogs and also work as a freelancer security researcher and a web developer. So answering each email and comment is not so easy for me. You can see that I am also less active on my blog.

Still I care for my readers and try to solve their computer and tech related </description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-24T19:06:15.638+05:30</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/ask-your-problems-and-solve-others-join.html</feedburner:origLink></item><item><title>What is HTTP Header Injection Vulnerability</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/kAnUh3oB3_M/what-is-http-header-injection.html</link><category>XSS</category><category>vulnerability</category><category>Hacking tutorials</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sat, 22 Dec 2012 03:50:51 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-3875602231491598212</guid><description>
On this security blog, I have discussed so many web application vulnerabilities in details. But there are still many which we have not discussed. Today, I am going to explain few things about HTTP header injection.

HTTP Header
HTTP Header is the component of HTTP requests and responces. Header fields are transimitted with each request and responce and carry additional data about the requests </description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-22T17:20:51.597+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-yVOc1Kc8rTA/UNWcUNubYXI/AAAAAAAAGKk/ky4mrcKy71w/s72-c/network-security-auditing.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/what-is-http-header-injection.html</feedburner:origLink></item><item><title>Glass Door is Vulnerable to XSS and IFRAME Injection</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/hlJXpdk7Pyg/glass-door-is-vulnerable-to-xss-and.html</link><category>Deepanker</category><category>Website hacking</category><category>XSS</category><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Wed, 19 Dec 2012 22:56:06 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-294722753555290400</guid><description>

LinkedIn rival Glass Door is now one of the most popular website that connects employer to employees. Yesterday, I noticed some serious XSS and Iframe injection vulnerabilities on Glass door website. This vulnerability can be used to hijack sessions and malware spreading.

Although, I can not see much danger because there is nothing like payment on the website. Still, It is very harmful for the</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-20T12:26:06.452+05:30</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-DcoZcgQak3E/UNK1HRc540I/AAAAAAAAGF0/BpNA647ymqs/s72-c/glassdoor.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/glass-door-is-vulnerable-to-xss-and.html</feedburner:origLink></item><item><title>Symantec is Vulnerable to URL Redirection, Can be Used in Spreading Malware</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/2pQVisuhx0o/symantec-is-vulnerable-to-url.html</link><category>Deepanker</category><category>XSS</category><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Tue, 18 Dec 2012 01:37:46 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-7689629273374064732</guid><description>

Website of security giant, Symantec is vulnerable to unvaidated URL redirection. This potentially dangerous redirection vulnerability affects the main website of Symantec that can be used to redirect users to protentially harmful websites.

This link is able to redirect users to any website. Attacker can use this vulnerbility to redirect users to perform phishing or malware spreading.

We all </description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-18T15:07:46.270+05:30</app:edited><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/symantec-is-vulnerable-to-url.html</feedburner:origLink></item><item><title>AOL Badly Affected with XSS and IFRAME Injection, Reported</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/52dzXhXsz5k/aol-badly-affected-with-xss-and-iframe.html</link><category>Deepanker</category><category>XSS</category><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Sat, 15 Dec 2012 01:50:28 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-5464173954647590746</guid><description>

AOL is a reputed company with so many popular online brand. Today, I noticed few XSS and Inframe injection vulnerabilities in its shopping website.

Yes, AOL Shopping website is badly affected with XSS and IFRAME injection. Attacker can use this vulnerability to steal users cookie and then hijack session. See the proof of concept with cookies in alert box.




I was also able to add a hyperlink</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-15T15:20:28.837+05:30</app:edited><media:thumbnail url="http://1.bp.blogspot.com/-l_WyEuFRZ24/UMxGQ2M4uhI/AAAAAAAAGBI/YnnyjFsBkmM/s72-c/AOL_cookie.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/aol-badly-affected-with-xss-and-iframe.html</feedburner:origLink></item><item><title>Got DOM Based POST XSS on Quick Heal Website</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/wwrW60IeYcg/got-dom-based-post-xss-on-quick-heal.html</link><category>Deepanker</category><category>XSS</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Fri, 14 Dec 2012 04:04:26 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-5761038357486230107</guid><description>

This time again XSS on a high profile website. Its not so complicated but it can be used to trick users and redirect them to some malicious websites. So attacker can redirect users to some phishing website or some fake website spreading malware.

See the proof of concept:



XSS is known as Cross Site Scripting that allows attackers to inject malicious client side code in innocent websites in </description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-14T17:34:26.432+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-mBtftfKv8jc/UMsUFMtcb_I/AAAAAAAAGA4/7thNMSvXUxw/s72-c/quick-heal.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/got-dom-based-post-xss-on-quick-heal.html</feedburner:origLink></item><item><title>Multiple XSS Vulnerabilities on K7 Antivirus Website</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/dl3_t-TUd5c/multiple-xss-vulnerabilities-on-k7.html</link><category>Deepanker</category><category>XSS</category><category>Cyber News</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Wed, 12 Dec 2012 00:57:39 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-7278530098976671415</guid><description>

In recent days, I was busy in some projects so could not do much in security field. Now I am back with some of my other high profile finding. This time, XSS in K7 Antivirus website. K7computing.com is vulnerable to XSS vulnerable that can redirect users to some other malicious websites or execute client side code on users' browser.

Vulnerability is found on some critical pages that i can not </description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-12T14:27:39.309+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-OUhcvKngwUc/UMhG22LsNeI/AAAAAAAAF8w/6fvcDpUOsPE/s72-c/fb.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/multiple-xss-vulnerabilities-on-k7.html</feedburner:origLink></item><item><title>Remote computer hacking with SniperSpy</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/wJoqRy0ygcU/remote-computer-hacking-with-sniperspy.html</link><category>Hacking Tools</category><category>keyloggers</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Tue, 04 Dec 2012 04:24:05 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-8423840768181334579</guid><description>
Are you looking to hack a remote computer? Do you wan to hack passwords of your friends? I am here with a leading remote computer hacking software.



SnipeSpy (Best Rated Remote hacking software)



SniperSpy is the best Remote hacking Software that also features remote installation and remote control.



Once installed on the remote computer, you only need to login on your sniper spy account </description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-04T17:54:05.341+05:30</app:edited><media:thumbnail url="http://2.bp.blogspot.com/-HP8GszBK-zo/UL3iSwK-1OI/AAAAAAAAF0U/mkVPxek5ZvQ/s72-c/SniperSpy.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/remote-computer-hacking-with-sniperspy.html</feedburner:origLink></item><item><title>Tutorial on Cookie Stealing Via XSS and Account Hijacking</title><link>http://feedproxy.google.com/~r/blogspot/csAFg/~3/HnPE6k4dJIw/tutorial-on-cookie-stealing-via-xss-and.html</link><category>cookie</category><category>XSS</category><category>Hacking tutorials</category><author>noreply@blogger.com (Deepanker Verma)</author><pubDate>Mon, 03 Dec 2012 06:17:28 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-5009365634130283389.post-5124664321416351286</guid><description>

I have already posted much about cookies and its usage in my older article on cookie poisoning attack. Cookies are used to remember sessions because HTTP is a stateless protocol. If you manage to get the cookies of a active session of user, you can use that session and the account of the user.




Here the attack involve mainly two things. Finding XSS vulnerable websites and then stealing.
I </description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-03T19:47:28.487+05:30</app:edited><media:thumbnail url="http://4.bp.blogspot.com/-92NFJQqb_s8/ULywQoxp55I/AAAAAAAAFyA/Vw7BoIwa_BM/s72-c/cookiesteal.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.hackingtricks.in/2012/12/tutorial-on-cookie-stealing-via-xss-and.html</feedburner:origLink></item><media:rating>nonadult</media:rating></channel></rss>
