| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| 1 | 2 | |||||
| 3 | 4 | 5 | 6 | 7 | 8 | 9 |
| 10 | 11 | 12 | 13 | 14 | 15 | 16 |
| 17 | 18 | 19 | 20 | 21 | 22 | 23 |
| 24 | 25 | 26 | 27 | 28 | 29 | 30 |
| 31 |
Browse archives
Random MediaRecent blog posts
|
SecurityAuthentication bypass in Cyberix Internet Management SystemA mohali based company http://www.cyberix.in/ has an otherwise good Internet Management Software Product by the name Cyberix, is vulnerable to a very simple authentication bypass vulnerability (rather it is more of a software design issue). Cyberix IMS when authenticating a user using, the web login via a popup window, sends the MD5 hash of the users password in the GET request. As all URLs, along with the GET variables and their values, are saved in the browser's history, thus any user who has access to the system, used by a previous user, can simply check the browser history and click on the login URL to login as the other user, without providing any password. Defeating the purpose of an IMS where different users may have different access levels as promised by Cyberix IMS.
Submitted by Ajay Pal Singh Atwal on March 19, 2007 - 3:10pm. categories [ Bug Reports | Security ]
Ajay Pal Singh Atwal's blog | add new comment | read more | 754 reads
Daddy Says Puttar No XSSThese days I am having too much fun with XSS. It is no good wishing happy holi by manipulating other peoples websites, even though it is harmless. You never know when you will come across some crazy hippocrat who believes that its website has been defaced and then tries to grab the poor fun loving XSSer by neck. Note to Self
Submitted by Ajay Pal Singh Atwal on March 4, 2007 - 4:19am. categories [ Bug Reports | Humor | Security ]
Ajay Pal Singh Atwal's blog | add new comment | read more | 770 reads
Why cant there be a Secure and Perfect Version of MS Windows ever?The title for this post can be considered a misnomer. I think it should read: Well if you do write perfect software you are kicking yourself in your er.. belly, and sitting on the branch side of the saw. For any commercial company/ enterprise writing perfect and bug free software would mean:
Submitted by Ajay Pal Singh Atwal on August 23, 2006 - 12:01am. categories [ GNU/ Linux | Humor | Security | Windows ]
Ajay Pal Singh Atwal's blog | 1 comment | read more | 573 reads
PTU Jalandhar Website XSS VulnerabilityThese days Full Disclosure mailing list is being dominated by XSS vulnerabilities. It is time I should put up my contribution too, for an XSS vulnerability I have known for around 7-8 months.
Submitted by Ajay Pal Singh Atwal on May 29, 2006 - 10:31am. categories [ Bug Reports | Exposed | Security ]
Ajay Pal Singh Atwal's blog | add new comment | read more | 2038 reads
A Legitimate? way to SPAM using yahoogroups.comSPAM, I sort of dislike it and prefer my mail box to be free of SPAM. Spam filters like spamassin are very much effective against it. But for around past three-four months I have been receiving a new form of SPAM, in the form of yahoo groups invitations. All sort of marriage alliance invitations, hey I am happily married, please stay away. If I block one another one pops out, even I am helpless.
Submitted by Ajay Pal Singh Atwal on March 18, 2006 - 8:02pm. categories [ Exposed | Security ]
Ajay Pal Singh Atwal's blog | add new comment | read more | 948 reads
Script Kidding for the BlindThis is the error log of httpd (apache) on one of the server machines that is about to be replaced very soon, interesting thing is to see how the script kiddy goes about locating vulnerable web applications:
Submitted by Ajay Pal Singh Atwal on March 7, 2006 - 2:09pm. categories [ Exposed | GNU/ Linux | Security ]
Ajay Pal Singh Atwal's blog | add new comment | read more | 566 reads
FTP across a FirewallMy home computer has GNU/ Linux (FC4 to be precise) behind the IPTables firewall. The way it has been configured allows very limited incoming connections (port 80 only) and more or less no limit on outgoing connections.
Submitted by Ajay Pal Singh Atwal on March 6, 2006 - 1:36am. categories [ GNU/ Linux | Security ]
Ajay Pal Singh Atwal's blog | add new comment | read more | 568 reads
Here is Another Crack AttemptNow this is something annoying (not interesting) some script kiddy, who may have either compromised 207.157.58.25 or maybe is some silly script kiddie student of http://www.wallace.edu attempted a PHP injection attack on this server. The kid came from 207.157.58.25 and the kiddo has the scripts stored here. The store house of kiddo seems to be some server of ipower web inc a web hosting company. He has a load of cracking tools stored on the server. I will try to report this to ipower people. Hope they will listen. One more thing, this service is an almost a regular, you will see this in your logs just before the attack is about to begin. Almost all kiddos use this before they start their dirty work.
Submitted by Ajay Pal Singh Atwal on November 7, 2005 - 2:02am. categories [ Exposed | Security ]
Ajay Pal Singh Atwal's blog | add new comment | 539 reads
Confusing the Script KiddieOk I am running ssh on this server, and there are plenty of script kiddies out there who are just too eager to run scripts, trying maybe a brute force attack, and after such an attempt I dont like the look of my system log.
Submitted by Ajay Pal Singh Atwal on October 11, 2005 - 2:08am. categories [ GNU/ Linux | Security ]
Ajay Pal Singh Atwal's blog | add new comment | read more | 353 reads
Cracking AttemptsWell here is some script kidddo acting funny on ajaypal.com:
Kiddo Orignating IP: 200.164.108.163 (maybe, if not a launching pad)
201.9.105.163 (maybe, if not a launching pad)
Attack Type: PHPBB CMD Vulnerability
From Where The Kiddo tried To Download the Crack: http://mi.verizon.net.do/carlos18/tool25.dot
Try downloading this file and renaming it to .txt and read
Some other exploits that were tried: Kiddo Orignating IP: 200.164.108.163 (maybe) Attack Type: xGallery Update Exploit Script for the Kiddo: http://newton.100free.com/newcmd.gif?&cmd=id Seems to have been removed from the server.
Kiddo Orignating IP: 200.164.108.163 (maybe)
201.9.105.163 (maybe)
Attack Type: My eGallery Display Catagory Exploit
Script for the Kiddo: http://pharoeste.net/x/out.gif?&cmd=id
Seems to have been removed from the server.
Get over it kid ;-(, do something usefull like patching the exploitable software.
Submitted by Ajay Pal Singh Atwal on August 5, 2005 - 11:22am. categories [ GNU/ Linux | Security ]
Ajay Pal Singh Atwal's blog | add new comment | 424 reads
|