<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>DDoSed.com - An IT security information blog</title>
	
	<link>http://www.ddosed.com</link>
	<description />
	<lastBuildDate>Sat, 04 Oct 2008 07:21:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/ddosed" /><feedburner:info uri="ddosed" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nc/2.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc/2.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><item>
		<title>Arrest Footage Of Notorious Turkish ATM hacker</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/tXioCsH4T7g/</link>
		<comments>http://www.ddosed.com/2008/10/04/arrest-footage-of-notorious-turkish-atm-hacker/#comments</comments>
		<pubDate>Sat, 04 Oct 2008 07:19:30 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Hardware Hacks]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Spamming & Scamming]]></category>
		<category><![CDATA[arrested]]></category>
		<category><![CDATA[atm fraud]]></category>
		<category><![CDATA[atm hacker chao]]></category>
		<category><![CDATA[atm hacking]]></category>
		<category><![CDATA[cagatay evyapan]]></category>
		<category><![CDATA[chao]]></category>
		<category><![CDATA[cloning atm cards]]></category>
		<category><![CDATA[credit-card-fraud]]></category>
		<category><![CDATA[turkey]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/?p=55</guid>
		<description><![CDATA[A notorious professional ATM hacker from Turkey got busted early last month. &#8220;ChaO&#8221; (Cagatay Evyapan) was well-known in the underground carding community.  Watch the footage below, you will be very impressed how this fraudster converted his villa into a high profile ATM skimming device production factory. ChaO&#8217;s fraud devices in action: The attached skimming device [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">A notorious professional ATM hacker from Turkey got busted early last month.</p>
<p style="text-align: justify;">&#8220;ChaO&#8221; (Cagatay Evyapan) was well-known in the underground carding community.  Watch the footage below, you will be very impressed how this fraudster converted his villa into a high profile ATM skimming device production factory.<br />
</br><br />
<iframe src="http://www.vidomodo.com/play.video.php?id=1650" framespacing="0" frameborder="no" scrolling="no" width="415" height="280"></iframe><br />
</br><br />
<span id="more-55"></span></p>
<p style="text-align: justify;">
<p>ChaO&#8217;s fraud devices in action:<br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/H3Yqd7H08CA&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x006699&amp;color2=0x54abd6" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/H3Yqd7H08CA&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x006699&amp;color2=0x54abd6" allowfullscreen="true"></embed></object></p>
<p style="text-align: justify;">The attached skimming device copies all 3 tracks from the magnetic stripe of a credit/debit card, the keypad captures the PIN.  After is really easy for the fraudster to copy all collected info to  <strong><a title="ISO 7812 " href="http://en.wikipedia.org/wiki/ISO_7812" target="_blank">ISO 7812</a> </strong>blank cards  and eventually be able to cash out the money.</p>
<p>His hacking tips are the following (did not prove to be the best tips in his case):</p>
<blockquote><p><em>* don’t install a skimmer in the morning, because people are more vigilant then;<br />
* determine where a person would have to stand to keep an eye on everything happening on that block;<br />
* avoid blocks where more than 250 people per day walk through, because of the danger of detection;<br />
* don’t install skimmers in towns with fewer than 15,000 people, because people in those towns know what their ATMs look like;<br />
* avoid areas with small shops open 24 hours a day, because there may be surveillance cameras and vigilant shopkeepers;<br />
* don’t set up in areas where a lot of illegal immigrants live;<br />
* places with a lot of tourist traffic are good;<br />
* look for affluent neighborhoods and drive-through ATMs;<br />
* ATMs near cash-only bars are a good bet for lots of customer activity.</em></p></blockquote>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2008%2F10%2F04%2Farrest-footage-of-notorious-turkish-atm-hacker%2F';
  addthis_title  = 'Arrest+Footage+Of+Notorious+Turkish+ATM+hacker';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2008/10/04/arrest-footage-of-notorious-turkish-atm-hacker/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2008/10/04/arrest-footage-of-notorious-turkish-atm-hacker/</feedburner:origLink></item>
		<item>
		<title>Jun 2007 – Feb 2008 U.S. Gov Website Defacements + Commentary</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/5bedYr2Gi1Q/</link>
		<comments>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/#comments</comments>
		<pubDate>Sat, 05 Apr 2008 12:32:10 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[crackers]]></category>
		<category><![CDATA[frontpage extensions]]></category>
		<category><![CDATA[gov defaces]]></category>
		<category><![CDATA[mirror archive]]></category>
		<category><![CDATA[php inclusion]]></category>
		<category><![CDATA[script kiddies]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[website defacements]]></category>
		<category><![CDATA[zone-h]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/?p=51</guid>
		<description><![CDATA[Below is a list of US governmental websites which were defaced by crackers &#8211; or elite hackers as the media would say &#8211; since 26th of June 07 until late February 2008. It is quite interesting to know that most of the security vulnerabilities affecting the following *.gov websites are known for some years now. [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Below is a list of US governmental websites which were defaced by crackers &#8211; or elite hackers as the media would say &#8211; since 26th of June 07 until late February 2008. It is quite interesting to know that most of the security vulnerabilities affecting the following *.gov websites are known for some years now.</p>
<p align="justify"><span id="more-51"></span></p>
<p align="justify"><a title="buckinghamcounty.virginia.gov - Archived at Zone-H.org" href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6529007" target="_blank">buckinghamcounty.virginia.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by a Turkish cracker. Possibly he successfully exploited the FrontPage extensions misconfiguration vulnerability. He added his e-mail address. Of course if you contact him to ask what was the method used to deface, most probably he is going to reply that was a 0day vulnerability. What a stupid thing to do (add contact details). I am not going to explain why. He should work his own mind. I&#8217;m sure that at some point he is going to check this blog post because his nickname (<span class="category">UyuSsman</span>) will be soon enough indexed in search engines&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p align="justify"><a title="genome.nasa.gov/delivery/affy-C2wPDrGz - Archived at Zone-H.org" href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6514459">genome.nasa.gov/delivery/affy-C2wPDrGz</a> &#8211; Apache on Linux &#8211; Defaced by an Algerian cracker. Exploited an open door left in a web application. It is NASA! Automatically becomes teh uber h4x0r. LOL. Worths admiring l33t skills that even my grandma could use.</p>
<p align="justify"><a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6555137" target="_blank">williamsburgva.gov/uk/4ever.htm</a> &#8211; IIS6.0 on Win 2003 &#8211; Another deface by a Turkish cracker. You can contact him via MSN, just add turkishmember@yahoo.com.br!!! Obviously he is collaborating with Brazilian defacers. Without collaboration he wont be able to climb his way up on Zone-H&#8217;s hall of shame board for special defacements.</p>
<p align="justify"><a href="http://www.zone-h.org/index2.php?option=com_mirrorwrp&amp;Itemid=44&amp;id=6499258" target="_blank">cncsoig.gov/cum.htm</a> &#8211; IIS6.0 on Win 2003 &#8211; Defaced by a cracker from Panama. Silly him, named the defaced page &#8220;cum.htm&#8221;. Notice to how many people sends greets. You can find him at <a href="irc://irc.gigachat.org:6667">irc.GigaChat.net</a> [<em>Now down for some reason</em>] #core-project, #whackerz, #Xtech, #Segfault &#8211; where all the l33t peeps are idling and privately exchanging messages about their achievements. In this defacement there is a reference to the recent <a title="Chilean Crackers Caught - Zone-H.org News - November 2006" href="http://www.zone-h.org/content/view/14321/30/" target="_blank">arrest</a> of four Chilean crackers who were members of the &#8220;Byond Hackers Team&#8221;. Most probably the defaced page was influenced from watching too many h4x0r movies! h0h0.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6469760/" target="_blank">dialog.cancer.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by crackers from the Dominican Republic. They seem to know how to exploit basic SQL injection vulnerabilities. They just defaced the page with the message &#8220;D.O.M TEAM 2007 === xarnuz === &#8220;. No specific reason for their deface. Just for fun I guess. Surely showing off their team and nicknames to the defacers underground community.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6469685/" target="_blank">ncilistens.cancer.gov</a> &#8211; IIS5.0 on Win 2000 &#8211; Defaced by Brazilian crackers. Exploited an SQL injection vulnerability to add &#8220;Hacked by AciDmuD &#8211; RitualistaS GrouP&#8221;. They also added a contact e-mail address.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6498853/" target="_blank">cncsig.gov</a> &#8211; IIS6.0 on Win 2003 &#8211; Defaced by Brazilian crackers. Funny thing they call their team &#8220;<span class="defaulttext">linuXploit_crew&#8221;. That means they exploit Linux boxes as well. OMG! Those guys must be uber-l33t0r. So ultimate respect for them. They support that hacking is not a crime. I certainly agree, but what they did is not hacking but cracking, and this is illegal aka a crime. </span></p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6457557/" target="_blank">whitecounty-il.gov</a><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6457557/" target="_blank">/index.html</a> Win 2003<br />
woolwichnj.gov &#8211; Apache on Linux &#8211; Defaced by Brazilian crackers. Possibly exploited a PHP inclusion vulnerability, called a remote command shell script, checked with &#8220;uname -a&#8221; that the kernel is vulnerable to a local root exploit, run wget to download a backdoor to a writable directory, run the backdoor, telneted to the specific backdoor port, run wget to download <a title="h00lyshit.c" href="http://archives.neohapsis.com/archives/fulldisclosure/2006-07/att-0310/h00lyshit.c" target="_blank">h00lyshit</a> or <a title="raptor_prctl2.c" href="http://www.milw0rm.com/exploits/2031" target="_blank">prctl</a> local root kernel exploits, tested successfully one of the local root exploits, got root, owned the web server. They didn&#8217;t even spell right the word &#8220;owned&#8221; in the defaced page. Quite possibly, maybe they even tried to deceive by changing the kernel version in the defaced page. They would look more l33t that way: &#8220;2.6.16-1.2111_FC5smp #1 SMP Thu May 4 21:35:09 EDT 2006 &#8220;.</p>
<p align="justify"><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6406440/" target="_blank">armenia.ca.gov</a> &#8211; Apache on Linux &#8211; Defaced by a cracker from Saudi Arabia. This guy seems to know who he is, not a hacker, but a &#8220;R00T Cracker&#8221;. ROFL! Even that, maybe he is lying. Could be a &#8220;UID=APACHE Cracker&#8221;. You can contact him &#8220;For Mor Security&#8221; at S4curity@HotMail.Com and Admin@611.Com. This cracker used the same exploitation methodology as the Brazilian group above. No further commentary for this deface&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> <span style="color: #c0c0c0; font-size: large;"> </span></p>
<p><a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6399444/" target="_blank">arb.ca.gov/research</a> &#8211; Apache on Linux &#8211; Defaced by crackers from Brazil.</p>
<p>Concluding this commentary, all of the above defacements were a result of the following security vulnerabilities which were already known &#8211; some for many years now.</p>
<p>- <a title="SQL Injection Cheat Sheet" href="http://ferruh.mavituna.com/makale/sql-injection-cheatsheet/" target="_blank">SQL injections</a> (programming mistake)</p>
<p>- <a title="PHP Undergroud Security - PlayHack.net" href="http://www.playhack.net/view.php?type=1&amp;id=22" target="_blank">PHP inclusion</a> (programming mistake)</p>
<p>- <a href="http://www.ddosed.com/uploads/penetration_testing/webfolders.txt" target="_blank">FrontPage Extensions</a> (misconfiguration)</p>
<p align="justify">Windows or Unix with enabled FrontPage extensions could be vulnerable due to misconfiguration. If vulnerable, open the target domain or ip as web folder and you are in its webroot. It is very possible that you have write access. What if such misconfiguration exists in a web server which hosts thousand of sites and supports server side languages as ASP and PHP? Attackers can upload scripts which allow them to mass deface in few seconds all the hosted sites, run backdoors, download confidential data if any, use server as part of their botnet and erase all the log files. The best solution is to totally disable FrontPage extensions.</p>
<p align="justify"><a title="Written by soznic" href="http://www.ddosed.com/uploads/penetration_testing/webfolders.txt" target="_blank">Read this text</a> for more detailed information about web folders and FrontPage extensions.</p>
<p>- <a href="http://seclists.org/fulldisclosure/2005/Jan/0032.html" target="_blank">Microsoft Data Access Internet Publishing Provider DAV 1.1</a> and <a title="mod_dav: a DAV module for Apache" href="http://www.webdav.org/mod_dav/" target="_blank">mod_dav</a> (misconfiguration)</p>
<p align="justify">Attackers can import a list of high-profiled domains and check against if they allow PUT requests. Using the PoC for this vuln, they can PUT /theirdeface.htm to the webroot of the vulnerable domains. They can even PUT /ntdaddy.asp or other shorter in size web administration scripts in order to grant complete access to the web server. Also Linux web servers with mod_dav could be vulnerable.</p>
<p>The sysadmins, webmasters and web developers surely learnt their lesson. It is always the human factor to blame first for any occurrence  of security breaches.</p>
<p>Quite ironic that gov systems are consistently attacked by confused script-kiddies. After all for them is just &#8220;show off&#8221; game.</p>
<p>More U.S. governmental defacements submitted to Zone-H by the crackers:</p>
<blockquote><p>DigitalMind       woolwichnj.gov              Linux<br />
ArREs           vil.prentice.wi.gov             Linux<br />
S4udi-S3curity-T3rror   armenia.ca.gov          Linux<br />
Apocalypse        cncsoig.gov/cum.htm       Win 2003<br />
D.O.M            dialog.cancer.gov             Win 2000<br />
RitualistaS       ncilistens.cancer.gov     Win 2000<br />
linuXploit_crew   cncsig.gov                     Win 2003<br />
Kript3X        bowmar.gov/hacked.htm      Win 2003<br />
soyletmez        https://sc-isac.sc.gov      Win 2003<br />
SegmentationFault ops.sgp.arm.gov             Win 2000<br />
SegmentationFault nevadatreasurer.gov             Win 2000<br />
SuZuki        commerce.idaho.gov              Win 2003<br />
SuZuki            community.idaho.gov             Win 2003<br />
XTech Inc       lmhc.la.gov                     Win 2003<br />
XTech Inc       lmhc.louisiana.gov             Win 2003<br />
Phantom Orchid       cstx.gov/home             Win 2000<br />
BiyoSecurityTeam  roundrocktexas.gov             Win 2003<br />
S4t4n1c_s0uls        csac.ca.gov/doc.asp              Win 2003<br />
RootDamages       vacsp.gov/news.cfm             Win 2003<br />
beyrut-KaI3uS       vivote.gov                     Win 2003<br />
PowerDream        leesburgva.gov/pwd.htm      Win 2003<br />
SuZuki            remember.gov                     Win 2000<br />
S4udi-S3curity-T3rror     armenia.usaid.gov     Linux<br />
sinaritx        doe.nv.gov                      Win 2003<br />
s@bun           secure.sc.gov//LexSheriff     Win 2003<br />
W4n73d_H4ck3r       senegal.usaid.gov             Win 2000<br />
DigitalMind       seagrantdev.noaa.gov             Linux<br />
W4n73d_H4ck3r       admin.fmcs.gov             Win 2003<br />
W4n73d_H4ck3r       fmcs.gov                     Win 2003<br />
DigitalMind       seagrantdev.noaa.gov             Win 2000<br />
DigitalMind       seagrantdev.noaa.gov             Win 2000</p></blockquote>
<p>and many other that we don&#8217;t know about&#8230;</p>
<p>View the mirrors of the defaced sites on Zone-H and if you want add a comment below:<br />
<a title="U.S. Governmental Website Defacements on Zone-H.org" href="http://old.zone-h.org/en/defacements/special/filter/filter_domain=gov " target="_blank">http://old.zone-h.org/en/defacements/special/filter/filter_domain=gov </a></p>
<p>Clearly they &#8220;promoted&#8221; themselves to the script kiddies scene with a &#8220;wannabe an elite defacer, thats why I deface .gov/s and publish them on Zone-H&#8221; attitude. Of course they will never admit to this and continue to feed their bogus pride until is jail time!! <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>Nuff said.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2008%2F04%2F05%2Fjun-2007-to-feb-2008-us-gov-website-defacements-commentary%2F';
  addthis_title  = 'Jun+2007+%26%238211%3B+Feb+2008+U.S.+Gov+Website+Defacements+%2B+Commentary';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2008/04/05/jun-2007-to-feb-2008-us-gov-website-defacements-commentary/</feedburner:origLink></item>
		<item>
		<title>Regarding New Updates On This Blog And Contribution Matters</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/rlC4kLk2QWg/</link>
		<comments>http://www.ddosed.com/2007/10/31/regarding-new-updates-on-this-blog-and-contribution-matters/#comments</comments>
		<pubDate>Wed, 31 Oct 2007 14:31:14 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Site News]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/10/31/regarding-new-updates-on-this-blog-and-contribution-matters/</guid>
		<description><![CDATA[I know I haven&#8217;t posted on this blog for a long time, you can tell that! Other important projects in digital and real life kept me really busy. Soon enough will join the navy for a 9 months period, though will keep on blogging whenever I have free time. If you would like to contribute [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">I know I haven&#8217;t posted on this blog for a long time, you can tell that! <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Other important projects in digital and real life kept  me really busy. Soon enough will join the navy for a 9 months period, though will keep on blogging whenever I have free time. If you would like to <strong>contribute or suggest improvements for this blog</strong>, then please do not hesitate to <a href="mailto:dimitris.pagkalos@xssed.com">e-mail</a> me with the following details:</p>
<p>Full name:<br />
Handle:<br />
Nationality:<br />
Security projects participated/currently participating:<br />
Programming knowledge:<br />
Certifications if any:</p>
<p>Thank you,<br />
d1m</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F10%2F31%2Fregarding-new-updates-on-this-blog-and-contribution-matters%2F';
  addthis_title  = 'Regarding+New+Updates+On+This+Blog+And+Contribution+Matters';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/10/31/regarding-new-updates-on-this-blog-and-contribution-matters/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2007/10/31/regarding-new-updates-on-this-blog-and-contribution-matters/</feedburner:origLink></item>
		<item>
		<title>TXDNS v2.1.5 – A Multithreaded Digger/Brute Forcer For DNS</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/v3tWqg148ss/</link>
		<comments>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 12:01:27 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-diggerbrute-forcer-for-dns/</guid>
		<description><![CDATA[Arley Silveira has released the 1 year anniversary version of TXDNS. Very soon he will release the version 2.2 of TXDNS. This release implements DNS queries against multiple DNS servers, a more efficient threading algorithm and some minor bug fixes. Quoting from the tool&#8217;s official website: TXDNS main goal is to expose a domain namespace [...]]]></description>
			<content:encoded><![CDATA[<p>Arley Silveira has released the 1 year anniversary version of <a href="http://www.txdns.net" target="_blank" title="TXDNS official website">TXDNS</a>. Very soon he will release the version 2.2 of TXDNS.</p>
<blockquote>
<p align="justify">This release implements DNS queries against multiple DNS servers, a more efficient threading algorithm and some minor bug fixes.</p>
</blockquote>
<p><span id="more-53"></span> Quoting from the tool&#8217;s official website:</p>
<blockquote>
<p align="justify">TXDNS main goal is to expose a domain namespace trough a number of techniques:</p>
<p>-Typos<br />
-TLD rotation<br />
-Dictionary attack<br />
-Brute force</p>
<p>TXDNS may be used to:</p>
<p align="justify">- Fill the reconnaiscence gap left due to DNS servers hardening, as dns-zone transfers are much like to fail.<br />
- Dig a given domain name for possible phishing variations based on common well-known typo algorithms and return dns queries on both used and not used names.<br />
- Stress-test DNS servers due is configurable aggressive behaviour.</p>
<p>TXDNS provides some cool options, such as:</p>
<p>- Perform queries only for a given Resource Record type:<br />
A, CNAME, HINFO, NS, TXT &amp; SOA<br />
- Perform non-recursive queries.<br />
- Perform queries against a given DNS server.</p></blockquote>
<p><a href="http://www.txdns.net/" target="_blank" title="Read more about the latest version of TXDNS - v2.1.5">Read more</a> about the latest version.</p>
<p><a href="http://www.txdns.net/content/download.htm" target="_blank" title="Download TXDNS v2.1.5">Download TXDNS v2.1.5</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Ftxdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns%2F';
  addthis_title  = 'TXDNS+v2.1.5+%26%238211%3B+A+Multithreaded+Digger%2FBrute+Forcer+For+DNS';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2007/08/21/txdns-v215-a-multithreaded-digger-and-brute-forcer-for-dns/</feedburner:origLink></item>
		<item>
		<title>SSHatter v0.2 – A Password Brute Forcer For SSH</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/FaOAp3puU-Q/</link>
		<comments>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 11:33:25 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/</guid>
		<description><![CDATA[Tim Brown from Nth Dimension has coded a cool password brute forcer for SSH called SSHatter. It is multi threaded and can audit more than one system and account in a given session. Download SSHatter-0.2]]></description>
			<content:encoded><![CDATA[<p align="justify">Tim Brown from <a href="http://www.nth-dimension.org.uk" title="Nth Dimension">Nth Dimension</a> has coded a cool password brute forcer for SSH called SSHatter.</p>
<blockquote>
<p align="justify">It is multi threaded and can audit more than one system and account in a given session.</p>
</blockquote>
<p><a target="_blank" href="http://www.nth-dimension.org.uk/downloads.php?id=34" title="SSHatter v0.2 download from Nth Dimension">Download SSHatter-0.2</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F21%2Fsshatter-a-password-brute-forcer-for-ssh%2F';
  addthis_title  = 'SSHatter+v0.2+%26%238211%3B+A+Password+Brute+Forcer+For+SSH';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2007/08/21/sshatter-a-password-brute-forcer-for-ssh/</feedburner:origLink></item>
		<item>
		<title>How Crackers Deface Websites? Why They Do It?</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/9SzvHcSNFi8/</link>
		<comments>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/#comments</comments>
		<pubDate>Thu, 09 Aug 2007 01:33:04 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Personal Opinions]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</guid>
		<description><![CDATA[Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done. Almost everyday I visit Zone-H&#8217;s archive of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Through the following post I am not purposing to influence you to start defacing, but to briefly give you a better understanding of how and why it is done.</p>
<p align="justify">Almost everyday I visit Zone-H&#8217;s <a target="_blank" href="http://www.zone-h.org/component/option,com_attacks/Itemid,43/" title="Zone-H.org Digital Attacks Archive">archive</a> of special digital attacks, I find that at least 1 or 2 attacks were done against US governmental web servers. The domain suffix of the defaced websites was *.gov. Does this fact means that they are totally secure? I don&#8217;t think so&#8230; Obviously the web servers may host very confidential data. In this case the web server administrators seemed to have allowed threats against governmental assets. Any unwanted consequences that a breach of security can lead to, are mainly caused by the irresponsibility and lazyness of system administrators and web developers.</p>
<p align="justify"><span id="more-50"></span></p>
<p align="justify">The methodology for defacing a website is pretty standard. Here is the standard sequence of tasks that normally the crackers/defacers would follow: <a target="_blank" href="http://en.wikipedia.org/wiki/Footprinting" title="Wikipedia.org - Footprinting">Footprinting</a>, <a href="http://netsecurity.about.com/cs/hackertools/a/aa030404.htm" title="Introduction to Vulnerability Scanning">scanning</a>, enumeration, penetration, attack, covering of tracks and installation of backdoors. As I mentioned before, the motivations for defacing any website are various, whereas when defacing governmental websites, could be a promotion of an ideology, revenge, or just a challenge.</p>
<p align="justify">I don&#8217;t believe that people who are serial website defacers hold good real-life jobs, or any job at all. This is just my personal opinion which is based on the fact that defacing is illegal in most countries &#8211; thus involving a high risk of getting arrested - and requires some basic knowledge, time, and patience. Advanced knowledge of technical and theoretical network security issues is not always required to deface. I think that understanding IT security theories, enhances intelligently your logical application of related practicalities. Achieving a deface could require the application of a complex exploitation methodology. This is enough reason to give up for some defacers without patience and with incomplete knowledge.</p>
<p align="justify">Tools assisting each step mentioned in the last paragraph are widely available for free on the internet. Most of the authors coded them for ethical, legal and educational use. Of course some were specifically coded for easily generating domain lists, exploiting security vulnerabilities, and mass-defacing websites. These are not easy to find on the web, nor are that difficult to code. Instead, individual defacers and groups exchange them in IRC channels, private forums  and servers, and through instant messengers.</p>
<p>One example of such an IRC server is irc.gigachat.net.</p>
<p align="justify">Script kiddies who deface, prefer to use fancy GUIs for tools rather than command line. Command line tools seem to exceed their learning and memory capabilities, or they don&#8217;t have the will and patience to research and analyze effective methodologies used by professionals in netsec pen-testing. They would be more technically skilled and better exercise their brain to remember simple and complex command sequences in multi-OS environments. Plus they would develop their practical skill-set which may be necessary if they choose to follow an IT career at some point &#8211; if they don&#8217;t end up in jail.</p>
<p align="justify">Depending on their ethical and legal attitudes, usually what they want is to quickly accomplish breaking in a network, maybe lookup for confidential data, download them and deface the home pages of hosted sites. Always counting in exceptions, most probably they didn&#8217;t use their own exploits, but what was already public.</p>
<p>Now I&#8217;m going to quote from another of my posts the following:</p>
<p align="justify">&#8220;In the mind and soul of the crackers who deface high-profiled websites, there is a false sense of pride. They think that it reflects their cracking skills and status in the defacers scene. For them defacing is more like a game. The messages shown in their defacements are more like an excuse for taking part in this game. The real motivation and reasoning behind their attacks, in most of the cases is not political, patriotic or other; but is just to show off themselves and their country to the world…</p>
<p align="justify">They attach a nickname to their personalities and cracking abilities, and they try to raise its status in the scene. They like searching for their nicknames in news websites and showing off the link to other crackers in their IRC channel, other channels, or through their websites.&#8221;</p>
<p align="justify">You will be ignored if you request mentioned tools or help to deface a website. Comments are welcome of course. <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p align="justify">&nbsp;</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F08%2F09%2Fhow-crackers-deface-websites-why-they-do-it%2F';
  addthis_title  = 'How+Crackers+Deface+Websites%3F+Why+They+Do+It%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2007/08/09/how-crackers-deface-websites-why-they-do-it/</feedburner:origLink></item>
		<item>
		<title>Cross-Site Framed?</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/yhuYv2m7t0s/</link>
		<comments>http://www.ddosed.com/2007/03/28/cross-site-framed/#comments</comments>
		<pubDate>Wed, 28 Mar 2007 02:59:34 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/28/cross-site-framed/</guid>
		<description><![CDATA[Have you heard of cross-site framing? The past few days I saw listed on our archive, several websites vulnerable to cross-site framing &#8211; listed as frame redirection. I will briefly describe a possible exploitation scenario, concluding with more emphasis on the negative impact that this type of vulnerability can have to the privacy of innocent [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Have you heard of cross-site framing? The past few days I saw listed on our <a href="http://www.xssed.com/archive">archive</a>, several websites vulnerable to cross-site framing &#8211; listed as frame redirection. I will briefly describe a possible exploitation scenario, concluding with more emphasis on the negative impact that this type of vulnerability can have to the privacy of innocent individuals who are users of the affected websites.</p>
<p align="justify"><span id="more-49"></span></p>
<p align="justify">Using google-dorks, the attackers can search for frame scripts allowing the inclusion of any url. This search reveals thousands of results with too many websites vulnerable to cross-site framing:</p>
<p><a href="http://www.google.com/search?hl=us&amp;q=allinurl%3A%22url%3Dhttp%22+%22frame%22">allinurl:&#8221;url=http&#8221; &#8220;frame&#8221;</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Aasp+inurl%3A%22url%3D%22">inurl:frame filetype:asp  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Aaspx+inurl%3A%22url%3D%22">inurl:frame filetype:aspx inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Aphp+inurl%3A%22url%3D%22">inurl:frame filetype:php  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Acfm+inurl%3A%22url%3D%22">inurl:frame filetype:cfm  inurl:&#8221;url=&#8221;</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Aasp++inurl%3A%22url%3D%22">inurl:iframe filetype:asp  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Aaspx++inurl%3A%22url%3D%22">inurl:iframe filetype:aspx inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Aphp++inurl%3A%22url%3D%22">inurl:iframe filetype:php  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Acfm++inurl%3A%22url%3D%22">inurl:iframe filetype:cfm  inurl:&#8221;url=&#8221;</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.asp">allinurl:http frame.asp</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.aspx">allinurl:http frame.aspx</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.php">allinurl:http frame.php</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.cfm">allinurl:http frame.cfm</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Aframe.php%3Furl%3Dhttp">allinurl:frame.php?url=http</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Aframe.asp%3Furl%3Dhttp">allinurl:frame.asp?url=http</a></p>
<p align="justify">Phishing and other scams are now easier to perform due to cross-site framing.<br />
Having found such frame scripts, allows the attackers to include a webpage which is hosted somewhere else. This webpage can be designed to look like the original website and can be any cross-platform server-side script. It can contain a fake login form which on submit parses the inputted usernames and passwords and sends them to the attacker&#8217;s mailbox in cleartext format.</p>
<p align="justify">It is also possible to perform XSS attacks as in most cases there is no filtering of special characters, script or other common tags in the URL parameter.</p>
<p align="justify">Daniel Hugh mailed us about a cross-site framing and scripting vulnerability affecting <a href="http://www.gov.mt/">Gov.MT</a> (Official website of the Government of Malta):</p>
<p><a href="http://www.xssed.com/mirror/4987/">Gov.MT with Frame Redirect and XSS</a></p>
<p align="justify">The XSS vulnerabilities affecting websites can also be used to perform frame redirects, but not the contrary. So if you <a href="http://www.xssed.com/submit">submit </a>a website vulnerable to cross-site framing along with a XSS attack vector, we will publish it as XSS.</p>
<p align="justify">The above news were written in order to heighten the awareness of potential privacy threats to users of the web.</p>
<p align="justify">You can also access this blog post  from XSSed.com &#8211; a project I run with Kevin Fernandez.</p>
<p align="justify">Here is the link:</p>
<p align="justify"><a href="http://www.xssed.com/news/26/Cross-site_framed/">http://www.xssed.com/news/26/Cross-site_framed/</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F28%2Fcross-site-framed%2F';
  addthis_title  = 'Cross-Site+Framed%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/28/cross-site-framed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2007/03/28/cross-site-framed/</feedburner:origLink></item>
		<item>
		<title>Pen-Test Paper: How An Internal Network Becomes External</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/2WZYzTHmSlo/</link>
		<comments>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/#comments</comments>
		<pubDate>Sat, 17 Mar 2007 16:15:16 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/</guid>
		<description><![CDATA[My friend SuRGeoN from Greece wrote a very interesting pen-test paper which explains how easy is to convert an internal network into an external with the port redirection technique. He demonstrates the attack scenarios &#8211; including network architecture diagrams &#8211; and goes into great technical details about them. Furthermore, here are the steps which the [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">My friend SuRGeoN from Greece wrote a very interesting pen-test paper which explains how easy is to convert an internal network into an external with the port redirection technique. He demonstrates the attack scenarios &#8211; including network architecture diagrams &#8211; and goes into great technical details about them.</p>
<p> <span id="more-45"></span></p>
<p>Furthermore,  here are the steps which the attacker would follow:</p>
<blockquote><p>1. Information gathering for the external network<br />
2. Seeking for vulnerabilities &amp; misconfigurations<br />
3. Using flaws to get a shell<br />
4. Information gathering for the internal network<br />
5. Escalating privileges for the internal network<br />
6. Converting internal network to external</p></blockquote>
<p>Download SuRGeoN&#8217;s paper from here: [ <a href="http://www.ddosed.com/uploads/penetration_testing/srgn-pentest-01.pdf" title="SuRGeoN - Paper: How an Internal Network Becomes External">srgn-pentest-01.pdf</a> ]</p>
<p align="justify">This information is provided to you ONLY for educational purposes. The way that the information in this paper will be used, depends on the individual’s legal and ethical attitudes. YOUR choice!&#8230; YOUR risk!&#8230; <img src='http://www.ddosed.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p align="justify">Comments on the paper are of course welcome.  You can also contact SuRGeoN via e-mail: surgeony/\gmail.com (replace /\ with @).</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F17%2Fpen-test-paper-how-an-internal-network-becomes-external%2F';
  addthis_title  = 'Pen-Test+Paper%3A+How+An+Internal+Network+Becomes+External';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2007/03/17/pen-test-paper-how-an-internal-network-becomes-external/</feedburner:origLink></item>
		<item>
		<title>Internet Explorer 7: Phishing Using Local Resource Vulnerability</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/ckR77o8K56o/</link>
		<comments>http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/#comments</comments>
		<pubDate>Thu, 15 Mar 2007 08:56:13 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/</guid>
		<description><![CDATA[Aviv Raff has published on his blog an interesting proof of concept of the vulnerability affecting Internet Explorer v7: a cross-site scripting in the navcancl.htm local resource. This resource is called when the navigation to a page has been canceled, it displays an error message with a link to reload the current page, however the [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Aviv Raff has published on his blog an interesting proof of concept of the vulnerability affecting Internet Explorer v7: a cross-site scripting in the navcancl.htm local resource.</p>
<p><span id="more-44"></span></p>
<blockquote><p>This resource is called when the navigation to a page has been canceled, it displays an error message with a link to reload the current page, however the link is not filtered before being used (successful exploitation requires the user to click on the link). The researcher also explains how the browser does not show in the URL the local resource when it is called, this design flaw can thus be combined with the XSS vulnerability to conduct very dangerous phishing attacks.</p></blockquote>
<p>A PoC is available on the Aviv Raff&#8217;s website:<br />
<a href="http://www.raffon.net/research/ms/ie/navcancl/cnn.html">http://www.raffon.net/research/ms/ie/navcancl/cnn.html</a><br />
For those who do not have Internet Explorer 7, a video is also provided:<br />
<a href="http://raffon.net/videos/ie7navcancl.wmv">http://raffon.net/videos/ie7navcancl.wmv</a></p>
<p><strong>Original News #1:</strong> <a href="http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx">http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx </a> by Aviv Raff</p>
<p><strong>Original News #2:</strong> <a href="http://www.xssed.com/news/23/IE7_users_beware_of_Navigation_Canceled_errors/">http://www.xssed.com/news/23/IE7_users_beware_of_Navigation_Canceled_errors/</a> by Kevin Fernandez</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F15%2Finternet-explorer-7-phishing-using-local-resource-vulnerability%2F';
  addthis_title  = 'Internet+Explorer+7%3A+Phishing+Using+Local+Resource+Vulnerability';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://raffon.net/videos/ie7navcancl.wmv" length="483881" type="video/x-ms-wmv" />
		<feedburner:origLink>http://www.ddosed.com/2007/03/15/internet-explorer-7-phishing-using-local-resource-vulnerability/</feedburner:origLink></item>
		<item>
		<title>XSSed.com: What, Who, Why?</title>
		<link>http://feedproxy.google.com/~r/ddosed/~3/K2NAmNrQ1fQ/</link>
		<comments>http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/#comments</comments>
		<pubDate>Tue, 06 Mar 2007 13:28:35 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Defacements]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/</guid>
		<description><![CDATA[The goals of XSSed.com are to provide informative resources on cross-site scripting(XSS) vulnerabilities and exploitation methodologies, and to archive XSS vulnerable websites for statistic purposes. Mirroring websites is a way to prove to vendors and webmasters that the vulnerability really existed &#8211; in case of denial. Users will become more aware on protecting themselves on [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">The goals of <a href="http://www.xssed.com" title="XSSed.com - XSS information and vulnerable websites archive" target="_blank">XSSed.com</a> are to provide informative resources on cross-site scripting(XSS) vulnerabilities and exploitation methodologies, and to archive XSS vulnerable websites for statistic purposes. Mirroring websites is a way to prove to vendors and webmasters that the vulnerability really existed &#8211; in case of denial. Users will become more aware on protecting themselves on some websites, as XSS vulnerabilities are mostly targeting the users and not the websites.</p>
<p align="justify">XSSed.com is also an attempt to spread education and awareness about XSS to IT professionals and amateurs involved or interested in secure web application development.</p>
<p><span id="more-40"></span></p>
<p>The project is run by Kevin Fernandez and Dimitris Pagkalos.<br />
There are still a lot of improvements in the TODO list including the ones listed below:<br />
<strong> -RSS feeds.<br />
-Search filters.<br />
-More statistics.<br />
-Submit POST data in the submission page.<br />
-Add public and protected informations with the submitted XSS (more details will soon be available).<br />
-Additional informations will be published on the mirror page (for instance the use of a specific browser to reproduce the vulnerability).</strong></p>
<p align="justify"><a href="http://www.xssed.com/submit" title="XSSed.com - Submit XSS vulnerable websites" target="_blank">Submitting XSS</a> vulnerable websites, should not be seen as a game for getting the lead in total submissions. Nevertheless we encourage you to submit XSS vulnerable websites for the greater good of a secure web. As RSnake <a href="http://ha.ckers.org/blog/20070209/yet-another-xss-archive/#comment-17259" title="RSnake's comment on XSSed.com" target="_blank">commented on his blog post about XSSed.com</a>, &#8220;It’s not who finds the most, it’s about the ease of finding them, the difficulty in stopping them, the various vectors, etc…&#8221;. We seriously take in consideration such comments and suggestions for improvements by people with significant experience and expertise in the web application security field.</p>
<p>We call for papers and video tutorials that focus on exploiting XSS vulnerabilities and on preventing them.</p>
<p>Since the launch of <a href="http://www.xssed.com" title="XSSed.com" target="_blank">XSSed.com</a>, we received many <a href="http://www.xssed.com/submit" title="XSSed.com - Submit XSS vulnerable websites" target="_blank">notifications</a> of high-profiled websites that got XSS&#8217;ed.</p>
<p>Here is a list of notable XSS&#8217;ed websites in the <a href="http://www.xssed.com/archive/special=1/" title="XSSed.com - Special XSS'ed websites archive" target="_blank">archive</a>:</p>
<p><a href="http://www.xssed.com/mirror/158/">hushmail.com</a><br />
<a href="http://www.xssed.com/mirror/197/">youtube.com</a><br />
<a href="http://www.xssed.com/mirror/138/">members.microsoft.com</a><br />
<a href="http://www.xssed.com/mirror/418/">netscape.com</a><br />
<a href="http://www.xssed.com/mirror/1316/" target="_blank">*.search.yahoo.com</a><br />
<a href="http://www.xssed.com/mirror/899/">my.screenname.aol.com</a><br />
<a href="http://www.xssed.com/mirror/139/">my.imageshack.us</a><br />
<a href="http://www.xssed.com/mirror/876/">register.go.com</a><br />
<a href="http://www.xssed.com/mirror/739/">cafepress.com</a><br />
<a href="http://www.xssed.com/mirror/646/">thawte.com</a><br />
<a href="http://www.xssed.com/mirror/617/">verisign.com</a><br />
<a href="http://www.xssed.com/mirror/642/">zonelabs.com</a><br />
<a href="http://www.xssed.com/mirror/374/">www4.symantec.com</a><br />
<a href="http://www.xssed.com/mirror/290/">domaintools.com</a><br />
<a href="http://www.xssed.com/mirror/201/">controlpanel.netfirms.com</a><br />
<a href="http://www.xssed.com/mirror/97/">2600.com</a><br />
<a href="http://www.xssed.com/mirror/306/">sun.com</a><br />
<a href="http://www.xssed.com/mirror/1197/">*.globo.com</a> &#8211; Famous portal in Brazil<br />
<a href="http://www.xssed.com/mirror/256/">*.mynet.com</a> &#8211; Famous portal in Turkey<br />
<a href="http://www.xssed.com/mirror/1000/">login.pathfinder.gr</a> &#8211; Famous portal in Greece</p>
<p>plus many other &#8220;special&#8221; websites, including governmental and military&#8230;</p>
<p align="justify">So far we have had visitors and submitters from &#8211; in order of number of visits &#8211; Turkey, Italy, United Kingdom, United States, Brazil, France, Russia, Germany, Czech Republic and Pakistan. We would like to thank you for supporting our project.</p>
<p>The XSS attack vectors used on the <a href="http://www.xssed.com/archive" title="XSSed.com - Archive of XSS'ed websites" target="_blank">archived websites</a>, were from RSnake&#8217;s XSS <a href="http://ha.ckers.org/xss.html" title="Ha.ckers.org - XSS cheat sheet by RSnake" target="_blank">cheat sheet</a>.</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F06%2Fxssedcom-what-who-why%2F';
  addthis_title  = 'XSSed.com%3A+What%2C+Who%2C+Why%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.ddosed.com/2007/03/06/xssedcom-what-who-why/</feedburner:origLink></item>
	</channel>
</rss>
