Saturday, January 9, 2016

How to Create a Complete WordPress Backup for Free with BackWPup

Backups are one of the best defense against any sort of security threat toward your site. Regular backups are one thing that every blogger/webmaster should have. In past we showed you how to keep your content safe with BackupBuddy, and how to manually create WordPress database backups. However, BackupBuddy costs money and manual backups take time. What if we told you that you can create complete WordPress backup for free? Not only that, you can also store them on the cloud, and schedule to do this automatically. In this article we will show you how to create a complete WordPress backup for free with BackWPup.

First thing you need to do is install and activate BackWPup plugin. Upon activation, the plugin will display a welcome page. It will also add a BackWPup menu item in your WordPress admin sidebar.

Creating Backup Jobs with BackWPup

Click on Add New Job to create an automated backup job for your WordPress website. Under General tab, provide a name for this job. This name will be used internally and will help you identify each backup instance. Under the Job Tasks section, select the type of tasks you want this to perform. Available tasks include database backup, file backup, WordPress XML export, Installed plugins list, optimize database tables and check database tables. If you just want to create backup of your website, then you can select all options except for optimize and check database tables.

Under backup file creation section, choose an archive type. The default option is tar.gz, however you can choose zip archive if you want. Below this, you will see Job Destination section. This is where your backups will be stored. BackWPup provides multiple options to store your backup files. It can store backup file on your server, send it via email, backup to FTP, backup to dropbox, amazon S3, Windows Azure, Rackspace, and Sugarsync. Whatever you do, DO NOT store the backups on your server. we will be using DropBox.


Scheduling Automated Backup in WordPress using BackWPup

Click on Schedule tab and choose how often do you want to backup your site. You can schedule it to run monhtly, weekly, or daily basis by choosing WordPress Cron option. Alternatively, you can choose to manually run the job, so that you can create on-demand backups of your site. For advance level users there are more choices like using a URL to start the job externally using some other software or starting the job using WP-CLI, a command line interface for WordPress. For beginner level users we would highly recommend scheduling a daily or weekly backup by choosing WordPres Cron option.

What to Backup?

Click on DB Backup tab to select which tables you want to be included in the backup. Sometimes WordPress plugins create their own tables into your database, most of the time this data is not crucial and you may not need it. Unchecking these tables will reduce your backup size. However if you don’t know what you are doing, then keep all tables selected.
Under the Files tab you can select which directories and files you want to include in the backup job. We would recommend that you do not backup core WordPress files. Instead, only backup your wp-content/uploads folder. Uncheck Backup root folder. Exclude any folders in wp-content folder that you don’t want. For example, sometimes plugins will create their own directories inside wp-content folder to store plugin data. You can exclude these folders if you want.

Saving WordPress Backups To Dropbox

Depending on what you chose as destination for your backup, you will see a tab for it. In this tutorial we will show you how to automatically upload your WordPress backup to Dropbox using BackupWP plugin. So click on Dropbox tab and then click on Reauthenticate (full Dropbox).
This will take you to the Dropbox website where you will be asked to provide your username and password. After signing in, DropBox will ask for your permission to grant BackWPup access to your DropBox account.
After that, the plugin will take care of the rest.

Creating Multiple WordPress Backup Jobs using BackWPup

You can create multiple backup jobs with BackWPup. For example, you can create a scheduled job to run on a daily or weekly basis to backup your WordPress Database and another job to run manually for backing up your WordPress files only. You can see all jobs created by you on BackWPup » Jobs page. You can run any of the backup jobs by clicking on Run Now link below the job, even for scheduled jobs. You can also edit settings for a job or delete it entirely.

Running a Backup Job

When you execute a Backup Job manually by clicking on Run Now link, BackWPup will display the backup progress. Clicking on display working log, you can see what is going on in the background. If for some reason the backup job fails, then this log will also display the reason. You can also abort a job during the progress by clicking on abort button.

Troubleshooting WordPress Backup Jobs in BackWPup

Running a backup job may cause extra load on your hosting server. This may result in unfinished backup jobs. Also on most shared hosting services, there is a limit on how much time or memory a script can consume. When your server stops BackWPup for crossing the time or memory limit, it waits for 5 minutes and then resumes the process. In this case, it would take a while for a backup job to finish.
The first thing you should do is increase your PHP memory limit, then go to BackWPup » Settings and click on the Jobs tab. Increase Maximum number of restries for job steps option. The default value is 3, you can increase it to 5 and see if this works for you. After that scroll down to Reduce server load option and select medium or minimum server load options.

Final Thoughts

You are probably wondering if a good free plugin like BackWPup exist, then why do people pay for plugins like BackupBuddy or VaultPress. One of the reason is support. When you pay for a product, then you are guaranteed to get support. Another thing that we notice with both BackupBuddy and VaultPress is that they offer malware scanning. We use VaultPress because it is a 100% managed service. The backup is stored in their cloud server, and it is a pretty fool-proof setup.

We can not stress this enough that you need to back up your site regularly. Do not wait for your WordPress site getting hacked or infected with malware, start backing up now, so that you can swiftly restore WordPress from backup when the time comes. We hope that this guide helped you automate your WordPress backups. Let us know which WordPress backup solution you use by leaving a comment below.








Friday, January 8, 2016

UK cheat website admits hacking fears as Brits pile in for post-Xmas affairs


The shocking revelation will leave more than a million Illicit Encounters members fearing the worst.

Last year US married dating site Ashley Madison hit the headlines after its online security was breached.
Several suicides and scores of divorces were linked to the hacking after 33 million members' personal information was leaked online for the world to see.

Now Illicit Encounters chief executive Simon Francis has admitted to Daily Star Online that no one is completely safe.


Far from the wake-up call some expected, the data breach that aired the personal dealings and financial information of Ashley Madison clients has yet to spur concrete changes in web security or the online dating industry.


The details were published online by hackers calling themselves The Impact Team, who stole the data and threatened to make it public unless Ashley Madison was taken down. They said they had acted because they claimed the company had failed to delete the details of users who had paid to have their profiles erased.
 



The hackers' online message with the leak
Ashley Madison’s parent company, Avid Life Media, subsequently shelved plans to float on the London Stock Exchange, whilea class action lawsuit has already been launched in the US, seeking more than £3m in damages.
There have also been claims that the vast majority of Ashley Madison subscribers are men, and many of the female profiles on the site were created by staff.
In 2013 an employee at Ashley Madison’s headquarters in Toronto claimed that after being hired to help launch a Portuguese language version of the site she was ordered to create 1,000 fake female profiles to reel in men who wanted to have affairs.
Ashley Madison has denied creating fake female accounts.

Thursday, January 7, 2016

How to hack whatsapp account of girlfiend



You can do this using whatsapp Restore  function .

1> you need to get hands on her phone .
2> you need her phons memory card and sim card .
2> obviously phone is locked .
3> when she goes to washroom or sleeping get her memory card .
 .
4> turn of you internet connction .
5> uninstall whats app
6> reinstall whats app
7> copy SdCard/WhatsApp/Media   to your phone

8> not out her sim card in ur phone .
9> open whatsapp .
10 > job done 



Whatsapp will ask you to restore messages Ho it happily and see with whome your girlfirend or wife doing chat .






Sunday, September 11, 2011

BUG IN XP EXPLANATION!!

act. if you:

1. Load Notepad in Windows (in my case XP Pro)

2. Type "bush hid the facts" (all in lowercase, no quotes)

3. Save this file under a name of your choice

4. Re-open the file

you will not see the text that you typed, but instead you will see a bunch of squares (or, as I later found out, some Chinese characters - that is, if you have the Chinese fonts installed, which is not my case).

Most people think it's a Windows Notepad easter egg (I thought so myself, to be honest), but in fact, it isn't. It's just a lousy Notepad bug. Let me explain...

I was myself curious about the cause of this phenomenon, and I found out that this text is not the only one to cause problems. There are other strings that cause Notepad to screw up, including "this app can break", which was another version of the bug that generated a lot of buzz. I've personally tested a series of strings that have the same effect, including "this api can break", "this cat can split", "jane can not dance", "text wit hou tcaps" and even "abcd efg hij klmno" and "xxxx xxx xxx xxxxx". What do these phrases have in common? They are made up by four words made up by four, three, three and five letters, all lowercase. So, by induction, all "4-3-3-5" strings should work.
Now, let's get to why this thing happens. First of all, it seems that Notepad writes the files just fine, it just can't read them again correctly. As a proof, try opening your saved file, the one that Notepad screws up, with another text editor. I used EditPlus and it turned out to be OK. So why the Notepad thing then? Well, it's a Windows thing. Notepad uses a Windows function that allows it to figure out whether a text file is Unicode or not. And that function, my friends, is the one that screws it up. Because the way it checks can easily be described as "guessing". And it guesses that the file is actually Unicode, and not Ascii, as it is supposed to be.
CONTD....

UG IN XP EXPLANATION!!

Now, two different but similar explanations can be given.

The first is that, after the ASCII-to-hex conversion of the string, Notepad rearranges the hex codes not according to ASCII standards, but to Unicode, and that messes it up. Here's the example:

Take "bush hid the facts". The hex codes (they can be seen with any hex editor you want to download) for the string are:

62 75 73 68 20 68 69 64 20 74 68 65 20 66 61 63 74 73

Arrange the codes to make up Unicode characters and you get:

7562 6873 6820 6964 7420 6568 6620 6163 7473

You'll notice that every code is hyperlinked. If you click on each one of them, you'll see that each one represents a Chinese (I think) "letter".

So this whole thing's cause is the coincidence that the 18 ASCII characters happen to represent 9 Unicode characters. And, of course, Windows' inability to determine the right encoding of the file.

The second explanation is slightly different, but the basics are the same: the difference between ASCII and Unicode. It's just a matter of Notepad defaults. You see, when you save the file, in the "Encoding" field, the default drop-down is set to ANSI. So, by default, Notepad saves as ANSI. But if you do a File -> Open, the default Encoding is set to Unicode. That's exactly what happens when you double click a saved file. Notepad knows the path, but not the Encoding. So it uses the default Unicode encoding, which spits the Chinese characters as explained above.

And that's about it. No easter eggs, no conspiracies, no Bush interventions. Just plain old Microsoft.
BY,

Saturday, September 10, 2011

Free Megaupload Premium Link Generator Service (100 % Legit and Working)

During the Past month i got many emails from my blog readers especially from A.Hossain asking me to post an article on some kind of hack which will enable us to download  megaupload files Like a premium user  , Most of us know that there are lots of  free premium link generators which claim to generate Premium links for your downloads but about 90 % of those generators are fake , That's why i always advice my blog readers to use torrents , But yesterday when i was surfing the net i came across Megakey service which claims to generate premium links for Megaupload. So i decided to test it, and i found out that it was a 100 % legit and working service , So today i wanted to share this hack with you. Follow the steps given below to download Megaupload files like a premium User   It is a free service provided by magakey it removes limitations on megaupload files and megaupload videos ,Its a 100 % legit  and working service ,Its free from malware and viruses 1. To use this service you have to first install megakey software ,You can Download megakey software From Here & to get the password click Here 2. Extract the file using Winrar or Winzip and Install the megakey software 3. After installing you will see a Small  Megakey icon on the task bar  as shown , Right click and  select megakey benefits
4. Now check all the boxes and enter your information as shown
5. Now open your browser, paste your megaupload link that you want to download,  Now You will see a premium download button as shown
Note :- This service only works two hours a day (9.00 AM to 11.00 AM GMT ). Use the GMT Time converter to know your corresponding local time ,You can also check it by going to megaupload .com, If your with in the particular time you will see a small smiley icon on the top right corner near login saying its happy hour

Hope you like the Post , If you have any doubts regarding the Article please fell free to post a comment  

Arachni v0.3 Released – Web Application Security Scanner Framework

It’s been a while since we last mentioned Arachni, it was back in February – Arachni v0.2.2.1 – Web Application Security Scanner Framework.


For those who are not aware, Arachni is a fully automated system which tries to enforce the fire and forget principle. As soon as a scan is started it will not bother you for anything nor require further user interaction. Upon completion, the scan results will be saved in a file which you can later convert to several different formats (HTML, Plain Text, XML, etc.)


The project was initially started as an educational exercise though it has since evolved into a powerful and modular framework allowing for fast, accurate and flexible security/vulnerability assessments..


More than that, Arachni is highly extend-able allowing for anyone to improve upon it by adding custom components and tailoring most aspects to meet most needs.


The author notified us of a major new release (v0.3) which has some great new features, a few of those being:


A new custom-written, lightweight SpiderAdd-on support for the WebUI Scan schedulerAutoDeploy — Convert any SSH enabled Linux box into a DispatcherImproved accuracy of differential analysis auditsImproved accuracy of timing attack auditsHighly optimized timing attacks

If you are interested in the WebUI aspect you can check out some screenshots here, the more comprehensive ChangeLog is also available here.


For those of you into benchmarking and testing you might be interested to know that during a recent test Arachni was the only (from a long list of commercial and F/OSS systems) that hit 100% on both XSS and SQLi tests in the WAVSEP benchmark:


Commercial Web Application Scanner Benchmark


The author is doing a great job with this tool and rapidly closing the gap between free security scanners and the very expensive commercial options. If you do have any feedback on Arachni v0.3 drop a comment here or hit up the Arachni Google Group.


You can download Arachni v0.3 here:


arachni-v0.3-cde.tar.gz


Or read more here.

winAUTOPWN v2.7 Released – Windows Autohacking Tool

I’ve always been skeptical about this tool, especially seen as though the first version was released on April Fools day in 2009, anyway it’s 2 years later now and it still seems to be around so I think it’s worth publishing an update.


If any of you have actually tested this tool out, do drop a comment below.


winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan for TCP ports 1 to 65535. Exploits capable of giving Remote Shells, which are released publicly over the Internet by active contributors and exploit writers are constantly added to winAUTOPWN/bsdAUTOPWN. A lot of these exploits are written in scripting languages like python, perl and php. Presence of these language interpreters is essential for successful exploitations using winAUTOPWN/bsdAUTOPWN.


Exploits written in languages like C, Delphi, ASM which can be compiled are pre-compiled and added along-with others. On successful exploitation winAUTOPWN/bsdAUTOPWN gives a remote shell and waits for the attacker to use the shell before trying other exploits. This way the attacker can count and check the number of exploits which actually worked on a Target System.


New in v2.7


This version covers almost all remote exploits up-till mid-July 2011 and a few older ones as well. This version incorporates a few new commandline parameters: -perlrevshURL (for a PERL Reverse Shell URL), – mailFROM (smtpsender) and -mailTO (smtpreceiver). These are the commandline arguments required for a few exploits which require remote connect-back using a perl shell and email server exploits requiring authentication respectively. This version also tackles various internal bugs and fixes them.


A complete list of all Exploits in winAUTOPWN is available in CHANGELOG.TXT
A complete list of User Interface changes is available in UI_CHANGES.txt


Also, in this version :

BSDAUTOPWN has been upgraded to version 1.5.In this release you will also find pre-compiled binaries for :FreeBSD x86FreeBSD x64DragonFly BSD x86

You can download winAUTOPWN v2.7 here:


winAUTOPWN_2.7.RAR


Or read more here.

Agnitio v2.0 Released – Code Security Review Tool

It’s been a while since we’ve mentioned Agnitio, it was earlier this year in March: Agnitio v1.2 – Manual Security Code Review Tool.


The author notified me of a new version that was recently released with quite a few additions. For those not familiar with it, Agnitio is a tool to help developers and security professionals conduct manual security code reviews in a consistent and repeatable way. Agnitio aims to replace the adhoc nature of manual security code review documentation, create an audit trail and reporting.


Changes in V2.0


The major changes in v2.0 is the addition of a code analysis module which comes with Android and iOS rules, an editor for the checklist questions and the ability to create/edit/remove code analysis rules.

Fixed verify report button bug. It used to make the app crash if the report path field was empty because it didn’t check if it was empty before trying to use the field value.Delete profile functionality added on the “view profiles” tab. Some users requested this functionality.Removed hard coded filesystem paths and database names/locations from the code and make them configuration items.Data editor for both principles and checklist guidance sections. This allows users to customise the guidance using their own languages, guidance text etc.Increase the max size value of the text boxes on the principles guidance tab to allow more information to be entered by users.More accurate error on the profile creation tab – specify exactly what fields have been missed rather than listing all.Added “About” form with info, license, credits etcRegular expressions expanded to include a wider range of characters including non English characters.Turn the “other” language box red if the user clicks save with the other check box ticked but not language entered on the create and view profile tabs.Metrics tab now “returns” if only one app is available rather than trying to load all graphs and throwing a separate error for each one.

The author is always interested in feedback and has integrated a lot of it into v2.0 of Agnitio, if you want to give some suggestions/bug reports or whatever after using the tool you can do so via the Security Ninja blog here, or on Twitter @securityninja.


You can download Agnitio v2.0 here:


Agnitio v2.zip


Or read more here.

Mediggo – Tool To Detect Weak Or Insecure Cryptosystems Using Generic Cryptanalysis Techniques

Mediggo is an opensource cryptanalysis library. This library implements generic cryptanalysis techniques to detect weak or insecure cryptosystems or learn and practice with cryptanalysis.


This library is open source (LGPL licence) and written in C programming language. Samples and test cases are provided with each techniques:

the solution is not always given to make people practicethe solution can always be obtained by contacting the development team

Current Features

Detection and cryptanalysis of weakly implemented or trapped systems

Future Features

Automatic detection of statistical biases in cryptographic algorithms.Specific cryptanalysis tools.

You can download Mediggo here:


megiddo-0.4.0.tar.gz


Or read more here.

WebSurgery – Web Application Security Testing Suite

WebSurgery is a suite of tools for security testing of web applications. It was designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer, Fuzzer for advanced exploitation of known and unusual vulnerabilities such as SQL Injection, Cross site scripting (XSS), Brute force for login forms, identification of firewall-filtered rules, DOS Attacks and WEB Proxy to analyze, intercept and manipulate the traffic between your browser and the target web application.


WEB Crawler


WEB Crawler was designed to be fast, accurate, stable, completely parametrable and the use of advanced techniques to extract links from Javascript and HTML Tags. It works with parametrable timing settings (Timeout, Threading, Max Data Size, Retries) and a number of rules parameters to prevent infinitive loops and pointless scanning (Case Sensitive, Dir Depth, Process Above/Below, Submit Forms, Fetch Indexes/Sitemaps, Max Requests per File/Script Parameters). It is also possible to apply custom headers (user agent, cookies etc) and Include/Exclude Filters. WEB Crawler come with an embedded File/Dir Brute Forcer which helps to directly brute force for files/dirs in the directories found from crawling.


WEB Bruteforcer


WEB Bruteforcer is a brute forcer for files and directories within the web application which helps to identify the hidden structure. It is also multi-threaded and completely parametrable for timing settings (Timeout, Threading, Max Data Size, Retries) and rules (Headers, Base Dir, Brute force Dirs/Files, Recursive, File’s Extension, Send GET/HEAD, Follow Redirects, Process Cookies and List generator configuration).
By default, it will brute force from root / base dir recursively for both files and directories. It sends both HEAD and GET requests when it needs it (HEAD to identify if the file/dir exists and then GET to retrieve the full response).


WEB Fuzzer


WEB Fuzzer is a more advanced tool to create a number of requests based on one initial request. Fuzzer has no limits and can be used to exploit known vulnerabilities such (blind) SQL Inections and more unsual ways such identifing improper input handling, firewall/filtering rules, DOS Attacks.


WEB Editor


A simple WEB Editor to send individual requests. It also contains a HEX Editor for more advanced requests.


WEB Proxy


WEB Proxy is a proxy server running locally and will allow you to analyze, intercept and manipulate HTTP/HTTPS requests coming from your browser or other application which support proxies.


You can download WebSurgery here:


Setup – setup.msi
Portable – websurgery.zip


Or read more here.

Friday, September 9, 2011

Uniscan 4.0 Released - vulnerability scanner


Uniscan 4.0 Released 


The Uniscan vulnerability scanner is aimed at information security, which aims at finding vulnerabilities in Web systems and is licensed under the GNU GENERAL PUBLIC LICENSE 3.0 (GPL 3). The Uniscan was developed using the Perl programming language to be easier to work with text, has an easy to use regular expressions and is also multi-threaded.


Uniscan Features Identification of system pages through a Web Crawler.Use of threads in the crawler.Control the maximum number of requests the crawler.Control of variation of system pages identified by Web Crawler.Control of file extensions that are ignored.Test of pages found via the GET method.Test the forms found via the POST method.Support for SSL requests (HTTPS).Proxy support.


Official Change Log : Uniscan is now Modularized.Added directory checks.Added file checks.Added PUT method enabled check.Bug fix in crawler when found ../ directory.Crawler support POST method.Configuration by file uniscan.conf.Added checks for backup of files found by crawler.Added Blind SQL-i checks.Added static RCE, RFI, LFI checks.Crawler improved by checking /robots.txt.improved XSS vulnerability detection.improved SQL-i vulnerability detection.


Download Here:
http://sourceforge.net/projects/uniscan/files/4.0/uniscan.tar/download

winAUTOPWN v2.7 – Windows Autohacking Tool


winAUTOPWN v2.7 – Windows Autohacking Tool


This version covers almost all remote exploits up-till mid-July 2011 and a few older ones as well. This version incorporates a few new commandline parameters: -perlrevshURL (for a PERL Reverse Shell URL), – mailFROM (smtpsender) and -mailTO (smtpreceiver). These are the commandline arguments required for a few exploits which require remote connect-back using a perl shell and email server exploits requiring authentication respectively. This version also tackles various internal bugs and fixes them.
A complete list of all Exploits in winAUTOPWN is available in CHANGELOG.TXT
A complete list of User Interface changes is available in UI_CHANGES.txt
Also, in this version :


BSDAUTOPWN has been upgraded to version 1.5.
In this release you will also find pre-compiled binaries for :
FreeBSD x86
FreeBSD x64
DragonFly BSD x86


Download winAUTOPWN v2.7
http://27.106.39.229/w/Downloads.html

Yersinia - tool for analyzing and testing networks and systems.


Yersinia - tool for analyzing and testing networks and systems.




Yersinia is a network tool designed to take advantage of some weakeness in different network protocols. It pretends to be a solid framework for analyzing and testing the deployed networks and systems.


Currently, there are some network protocols implemented, but others are coming (tell us which one is your preferred). Attacks for the following network protocols are implemented (but of course you are free for implementing new ones):


Spanning Tree Protocol (STP)
Cisco Discovery Protocol (CDP)
Dynamic Trunking Protocol (DTP)
Dynamic Host Configuration Protocol (DHCP)
Hot Standby Router Protocol (HSRP)
IEEE 802.1Q
IEEE 802.1X
Inter-Switch Link Protocol (ISL)
VLAN Trunking Protocol (VTP)




Download Here:
http://www.yersinia.net/download.htm

tutorial on Session hijacking attack




When a user log in to the acccount, it starts a session with that account and this session ends up with logout. In a running session, user is given a session id which is unique identifier of the user for that session and is only valid for that session. Session hijacking is the type of attack in which hacker gain access to the session id to gain unauthorized access to information or services.


Session hijacking can be done at 2 levels: Network level (TCP and UDP session hijacking)Application level (HTTP session hijacking)


Network level (TCP and UDP session hijacking)


TCP session hijacking
TCP session hijacking is when a hacker takes over a TCP session between two machines. Since most authentication only occurs at the start of a TCP session, this allows the hacker to gain access to a machine. It can be done by following ways. IP Spoofing: Assuming the identityMan in the Middle attack using Packet SniffersBlind attacks which involves bruteforcing of session id.


UDP session hijacking
It is similar to TCP session hijacking but easier than that because UDP does not use packet sequencing and synchronizing.


Hijacking Application Levels
In HTTP session hijacking hacker tries to get access to the session ID used in the session to identify the user. HTTP is state less so it need session ID with each request. If hacker get the session id, he can hijack the victim's session. XSSMan in the middle attackBruteforcing session idMan in the browser attack
Session hijacking is widely used for hacking into website accounts. In websites, session id is stored in the form of cookies in the client browser. If you want to hijack some one's session, you have to steal the session informations of that user.
Session hijacking has been an ongoing problem for web browser developers and security experts for at least 5 years.


Prevention: Use of ArpON which is used to prevent Man In The Middle Attack through ARP Spoofing.Use of HTTPS protocol for secure sessions. It uses an encrypted sessions.Set the expiry time of cookies as less as possible.

WebSurgery v.0.6 Released - Web application testing suite




WebSurgery is a suite of tools for security testing of web applications. It was designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer, Fuzzer for advanced exploitation of known and unusual vulnerabilities such as SQL Injections, Cross site scripting (XSS), Brute force for login forms, identification of firewall-filtered rules, DOS Attacks and WEB Proxy to analyze, intercept and manipulate the traffic between your browser and the target web application.


download Here:
http://www.surgeonix.com/blog/index.php/archives/117

XPath injection tutorial




X-path injection is a type of web attack which target a website that create XPath queries from user-supplied data. Querying XML is done with XPath, a type of simple descriptive statement that allows the XML query to locate a piece of information.  By sending intentionally malformed information into the web site, an attacker can find out how the XML data is structured, or access data that he may not normally have access to.


XPath Injections might be even more dangerous than SQL Injections since XPath lacks access control and allows querying of the complete database (XML document), whereas many SQL databases have meta tables that cannot be accessed by regular queries.


Now i am going to give a demo of this.. It is similar to SQL Injection attack


See this user.xml file

 
 
       
          Ben
          Elmore 
          abc 
          test123 
       
       
          Shlomy
          Gantz
          xyz 
          123test 
       
       
          Jeghis
          Katz
          mrj 
          jk2468 
       
       
          Darien
          Heap
          drano 
          2mne8s 
       
 


       
          Ben
          Elmore 
          abc 
          test123 
       
       
          Shlomy
          Gantz
          xyz 
          123test 
       
       
          Jeghis
          Katz
          mrj 
          jk2468 
       
       
          Darien
          Heap
          drano 
          2mne8s 
       





Xpath query              
//users/user[loginID/text()='abc' and password/text()='test123']


Now bypassing authentication in the query
//users/user[LoginID/text()='' or 1=1  and password/text()='' or 1=1]




See the link for detail demonstration.
link


Prevention


XPATH Injection can be prevented in the same way as SQL injection. Some of the
Input ValidationParametrized Queries

Packet Sniffer for Android phones


Packet Sniffer for Android phones

This is a nice app to capture and display WiFi and bluetooth traffic on Android phones. But for using this app, you have to root your phone and have "su" command install.



This app is based on the tcpdump package therefor it have to be installed manually.
1. Download and Install PacketSniffer App from the market or from the following link.
http://dl.dropbox.com/u/3775726/PacketSniffer/PacketSniffer.apk
2. Copy the precompiled TCPDUMP file to the "/data"  library on your phone:  
             first make sure your "/data" library has READ and WRITE privileges. if not use:  "chmod 777 data"
             in order to copy use the following command if you have ADB :"adb push c:\locationOfTheTcpdumpFile /data"
            in case you don't have ADB you can copy the tcpdump file to the SD card and do:  "cat /sdcard/tcpdump > /data/tcpdump
3. Give the tcpdump file Read Write and Exec privileges :    "chmod 777 /data/tcpdump"


Before you start to capture you can pick weather to save the captured data on a local SQL DB on the device
or on to a file on the SD card.


Read More on
https://sites.google.com/site/androidarts/packet-sniffer

download Sniffjoke - Anti-sniffing Framework & Tool For Session Scrambling


download Sniffjoke - Anti-sniffing Framework & Tool For Session Scrambling

SniffJoke is an application for Linux that handle transparently your TCP connection, delaying, modifying and injecting fake packets inside your transmission, make them almost impossible to be correctly read by a passive wiretapping technology (IDS or sniffer).


An Internet client running SniffJoke injects in the transmission flow some packets able to seriously disturb passive analysis like sniffing, interception and low level information theft. No server support is needed!


The internet protocols have been developed to allow two elements to communicate, not some third-parts to intercept their communication. This will happen, but the communication system has been not developed with this objective. SniffJoke uses the network protocol in a permitted way, exploiting the implicit difference of network stack present in an operating system respect the sniffers dissector.


How Does It Work?
It works only under Linux (at the moment), creates a fake default gateway in your OS (the client or a default gateway) using a TUN interface check every traffic passing thru it, tracks every session and
applyies two concepts: the scramble and the hack.


The scramble is the technology to bring:


A sniffer to accept as true a packet who will be discarded by the server, or
A sniffer to drop a packet who will be accepted by the server.
The scramble technology brings in desynchronisation between the sniffer flow and the real flow.


The bogus packet accepted by the sniffer is generated by the “plugin” is a C++ simple class, which in a pseudo statefull tracking will forge the packet to be injected inside the flow. is pretty easy to develop
anew one, and if someone wants to make research on sniffers attack (or fuzzing the flow searching for bugs) need to make the hand inside its.


The configuration permits to define blacklist/whitelist ip address to scramble, a degree of aggressivity for each port, which plugin will be used.


download here:
http://www.delirandom.net/sniffjoke/sniffjoke-howto-usage/

DarkComet-RAT v.4.0 released


DarkComet-RAT (Remote Administration Tool) is the most complete and one of the most stable RAT in the scene.this software is design for people that have a very good knowledge in computer security, it can be userfull in many case. 


Remote control your network computers (LAN / WAN) 
Remote assist your clients if you manage a company 
Find your lost passwords in your computers 
Spy your home networks (For your childs,Wife,Husband...) 
Test the security of your computers or your company 
To develop your knowledge in RAT softwares 


Change log: 
DarkComet-RAT is now compiled on Delphi XE instead of Delphi 2010. 
Synthax highlighter added in remote keylogger. 
Get hard drive information added in file manager 
Bot logs in main form had change, it is more efficient / fast and user friendly 
Whole system parser is now far stable and faster 
No-IP was moded and is now better ;) 
Flags manager has been ported to the main client settings form 
Now you can change the default size Width and Height of the users thumbnails 
No more menu in the top of the SIN (Main Window - Users list)so it is more clear 
and much more 


Download Here:
http://www.darkcomet-rat.com/process_download.php?id=5

Tutorial on Arbitrary File uploading Vulnerability


Tutorial on Arbitrary File uploading Vulnerability

Arbitrary File uploading vulnerabilities are the type of vulnerabiliy which occurs in web applications in which there is a file uploading form but file format is not checked or filtered during file upload.
Now you are thinking that what is the problem in that. Now think that the website has a uploader form which do not check for file type and you have a malicious  PHP, ASP script. You can upload the script using this form and then you can execute your malicious script on the website server. You can run any kind of commands on the server using your script which would lead to a full compromise of the server.
If you do not know how to create a malicious script, you can simly download those scripts from internet and use it on any server having this type of vulnerability.


Some PHP Shells :-


Ani-Shell
R57 Shell
C99 Shell


Note: This tutorial and script is only for educational purpose. Use of these scripts on web servers in illegal.