H_acktivis_T

The art of c0ding


  • Home
  • Blogger’s Wall
  • Delphi Source Codes
  • Download
  • Exploits
  • Links
  • SiteMap
  • Visual Basic
  • WordPress Land


MS (finally) confirms unpatched SQL Server flaw

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

Microsoft came clean and admitted its SQL Server database software is vulnerable to code injection attacks. It’s not a new flaw but the same bug in the database software that emerged around the time of Microsoft’s monthly Patch Tuesday update earlier this month.

In an advisory, Redmond’s security gnomes confirmed that code has been produced that exploits a security bug affecting Microsoft SQL Server 2000, Microsoft SQL Server 2005 and Windows Internal Database, in certain configurations.

On the plus side, Microsoft SQL Server 7.0 Service Pack 4, Microsoft SQL Server 2005 Service Pack 3, and Microsoft SQL Server 2008 are immune from the flaw. Third party apps that make use of the vulnerable code also appear to be in the clear.

…..Click here to read more

No Comment
under: News


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

MultiInjector v0.3 released

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

So, if i’ve posted about this tool Here a few months ago. But today we have the latest version of this program.

Features

  • Receives a list of URLs as input
  • Recognizes the parameterized URLs from the list
  • Fuzzes all URL parameters to concatenate the desired payload once an injection is successful
  • Automatic defacement - you decide on the defacement content, be it a hidden script, or just pure old “cyber graffiti” fun
  • OS command execution - remote enabling of XP_CMDSHELL on SQL server, subsequently running any arbitrary operating system command lines entered by the user
  • Configurable parallel connections exponentially speed up the attack process - one payload, multiple targets, simultaneous attacks
  • Optional use of an HTTP proxy to mask the origin of the attacks

CHANGELOG

  • Automatic defacement - Try to concatenate a string to all user-defined text fields in DB
  • Run any OS command as if you’re running a command console on the DB machine
  • Execute SQL commands of your choice
  • Enable OS shell procedure on DB - Revive the good old XP_CMDSHELL where it was turned off
  • Add administrative user to DB server with password: T0pSeKret
  • Enable remote desktop on DB server
  • Fixed nvarchar cast to varchar. Verified against MS-SQL 2000
  • Added numeric / string parameter type detection
  • Improved defacement content handling by escaping quotation marks
  • Improved support for Linux systems
  • Fixed the “invalid number of concurrent connections” failure due to non-parameterized URLs

Download: Here

Read more: Here

Rate this:
2.8 (1 person)
No Comment
under: Hacking Tools, SQL Injection


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

Penetration Test

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

In today’s increasingly interconnected business world, vulnerabilities present in an organisation’s technical infrastructure can lead to serious problems – the loss of trade secrets, damage to reputation or even breach of legal obligations to protect confidential information. A penetration test is designed to emulate real life attack motivations and techniques in order to provide a comprehensive register of vulnerabilities, weaknesses and exposures based on a specific scenario or threat, or focused on a subset of technical infrastructure.

The service can be tailored to meet the particular requirements of your organisation. In the most straightforward case a penetration test will take the form of a focused attack against a defined localised target such as a specific network. Our tests can also be modified to emulate a specific scenario, such as assessing the damage that a disgruntled employee could cause within your corporate network or determining the extent of access a completely anonymous attacker might be able to obtain without any prior knowledge of the target. Options such as social engineering, where appropriate, add the important human factor into the assessment and may also be incorporated.

Download: Here

Rate this:
2.8 (1 person)
No Comment
under: Articles, Penetration Testing


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

Back to the Future: A Framework for Automatic Malware Removal and System Repair

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

Malware is software with malicious intent. Besides viruses and worms, spyware, adware, and other newer forms of malware have recently emerged as widely-spread threats to system security. It is difficult to detect malware reliably because new and polymorphic ones appear frequently. It is also difficult to remove malware and repair its damage to the system because some malware programs can extensively modify a system.

The authors propose a novel framework for automatically removing malware and repairing its damage to a system. The primary goal of their framework is to preserve system integrity.

Download: Here

Rate this:
2.8 (1 person)
1 Comment
under: Articles


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

Application Security Test

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

Businesses evolve, grow and change. As part of this evolution IT applications are deployed, improved and optimised. These applications, be they websites, transactional systems or data entry applications, often deal with sensitive information and have a key role in marketing the brand of an organisation.
IRM’s Application Security Test provides a comprehensive assessment of the security posture of the application, detailing all vulnerabilities discovered, along with recommendations for mitigation and a clear indication of the risk posed by each issue.

Download: Here

Rate this:
2.8 (1 person)
No Comment
under: Articles


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

Bluediving v0.7

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

A Bluetooth penetration testing suite. It implements attacks like Bluebug, BlueSnarf, BlueSnarf++, BlueSmack and has features such as Bluetooth address spoofing, an AT and a RFCOMM socket shell and a L2CAP packetgenerator.

Download: Here

Rate this:
2.8 (1 person)
No Comment
under: Penetration Testing


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

Biologger - A Biometric Keylogger

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

Biometric systems comprise electronic devices and as such can utilise common electronic transports for the transmission of biometric related data. With biometric access control and indentification systems, users will typically present their biometric to a sensing device, which in turn may transmit data pertaining to that biometric to a server or secondary processing unit to perform biometric comparisons and auditing functions.

In this paper the authors realise a a proof-of-concept implementation of a biometric keylogger , or “Biologger”. While conventional keyloggers are typically used to obtain password or encryption keys to circumvent specific security measurs, the Biologger will aim to capture biometric-related data between a biometric device and other processing unints.

Download: Here

Rate this:
2.8 (1 person)
No Comment
under: Articles, Tutorials


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

Cpanel Password Brute Forcer

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

Here is the nice script written in Perl:

Rate this:
2.8 (1 person)
No Comment
under: Hacking Tools, Perl


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

Rapidshare.com Bruteforcer

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

Features:

  • Bruteforce Attacks.
  • List checker. (Check a list of words for premium account names.)
  • AutoSave.
  • More…

This require the .NET 2.0 Framework installed!

Download: Here

Rate this:
2.8 (1 person)
No Comment
under: Hacking Tools, NetWork Hack


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati

InfoSecurity 2008 Threat Analysis

Posted by User ImageH_acktivis_T (Who am I?) in December 28th 2008  

An all-star cast of authors analyze the top IT security threats for 2008 as selected by the editors and readers of Infosecurity Magazine. This book, compiled from the Syngress Security Library, is an essential reference for any IT professional managing enterprise security. It serves as an early warning system, allowing readers to assess vulnerabilities, design protection schemes and plan for disaster recovery should an attack occur. Topics include Botnets, Cross Site Scripting Attacks, Social Engineering, Physical and Logical Convergence, Payment Card Industry (PCI) Data Security Standards (DSS), Voice over IP (VoIP), and Asterisk Hacking.

Download: Here

Rate this:
2.8 (1 person)
No Comment
under: Articles


Your Ad Here

Digg it Add to del.icio.us Stumble it add to technorati
Newer Entries »
« Older Entries

Feeds

feeds
get latest updates on news and subscribes to our feeds

Categories

    Articles (55)
    ASM (5)
    BlackZone (60)
    Blogger Trips (1)
    BugTraq (9)
    C# Express Edition (30)
    General (18)
    General FAQ (25)
    Hacker Games (2)
    Hacking Tools (61)
    Hacking Videos (4)
    Keys / Serials (2)
    Mobile (5)
    MSN Area (7)
    My Cracks (1)
    Net FAQ (8)
    NetWork Hack (35)
    News (76)
    Penetration Testing (16)
    Perl (5)
    PHP (19)
    Programming (7)
    Programs (58)
    Releases (58)
    Reversing (33)
    Scanners (17)
    Scripts (5)
    Security Tools (69)
    Source Codes (6)
    SQL Injection (19)
    Tutorials (62)
    Visual Basic (16)
    Webmaster Tools (3)
    Windows (8)
    Windows Tips and Tricks (7)
    WordPress Hacks (5)

    WP Cumulus Flash tag cloud by Roy Tanck requires Flash Player 9 or better.

SQL Injection White Paper

  • Blindfolded SQL Injection
  • Advanced SQL Injection
  • SQL Injection White Paper
  • SQL Injection Signatures Evasion
  • Error Based SQL Injection.
  • SQL Injection via Cookie
  • SQL Injection Attacks
  • Introduction to SQL Injection

Reversing Tutorials

  • VB Tricks
  • Unpacking TheMida 1.3
  • NET Licence Check
  • DotNet Tips -Tools & OPcodes
  • Primer On.NET Applicationss
  • ASProtect VM Analyze
  • Anti-Cracking Techniques
  • Dictionary of computing
  • Exploiting software

Page Info

  • Operative system:
  • IP address: 38.103.63.62
  • Members Online: 1
  • Online Now: 6
  • Users: H_acktivis_T, 6 Guests
  • 1 User Browsing This Page.
    Users: 1 Guest

Advertisment

Blogs I Read

  • Suspekt
  • Lucian's weblog
  • Ha.ckers.org
  • Recurity Labs
  • ADD / XOR / ROL
  • MS Security Response Center
  • BlogSecurity
  • CiscoZine

Online Tools

  • PhpBB Checker
  • Base64 Coder/Decoder
  • Htpasswd Maker
  • HTML Encoder
  • URL Encoder/Decoder
  • 80x15 Brilliant Button Maker
  • Pop UP Window Creator

Advertisment

Want to put your ad here, contact us

Voting

  • Who's Online
  • Vote for this site!
    Click here to Vote!
  • Software
  • Top Blogs
  • Rate Me on BlogHop.com!
    the best pretty good okay pretty bad the worst help?

  • Vote for Us: Dmegs Web Directory
  • technorati

Search

Pages

  • Blogger’s Wall
  • Delphi Source Codes
  • Download
  • Exploits
  • Links
  • SiteMap
  • Visual Basic
  • WordPress Land

Advertisment

    <

Links

  • Development Blog
  • Documentation
  • Plugins
  • Suggest Ideas
  • Support Forum
  • Themes
  • WordPress Planet

Archives

  • January 2009 (6)
  • December 2008 (164)
  • November 2008 (175)
  • October 2008 (78)
  • September 2008 (56)
  • August 2008 (3)

Meta

  • Log in
  • Valid XHTML
  • Valid CSS
  • WordPress

Recent Entries

  • Complemento-0.4b
  • Kismet
  • NetworkMiner-0.87
  • SMS bug: Nokia’s Conversation goes mute
  • Burpsuite v1.2
  • Nipper 0.12.6
  • Happy New Year
  • C#. FileStream Class. Seek() Method
  • Exploitable Vulnerability in Windows Media Player Revealed
  • Hidden IP Addresses Not Hidden Anymore
  • MS (finally) confirms unpatched SQL Server flaw
  • MultiInjector v0.3 released
  • Penetration Test

Recent Comments

  • SIlvia in Happy New Year
  • data security s… in TrueCrypt – Free Open-Source Disk…
  • .ShAd0w. in Happy New Year
  • Hackills in Exploits
  • ANGEL in Happy New Year
  • Search Engine O… in Back to the Future: A Framework for…
  • MultiInjector v… in MultiInjector - Automated Stealth S…
  • Great Printing … in WordPress Land
  • objetroge in Remotely managed secure flash drive…
  • Introducing Dal… in IP-Tools 2.50

Most Comments

  • My New Release - Magma Chat Client (19)
  • VB Tricks. Express edition and VB6.0 (7)
  • Advanced BootUser (7)
  • Getting Administrator Privileges in XP (5)
  • Office 2007 Genuine Advantage (4)
  • Flud2Mail (F2M) 0.1 (4)
  • BaKo's SQL Injection Scanner v2.2 (3)
  • WinSCP 4.1.8 (3)
  • Happy New Year (3)
  • Ten Security Checks for PHP (2)
  • HTML Converter (2)
  • WordPress Land (2)
Box-Tube Box Modulize WordPress Theme By Dezzain Studio
©2006-2009 H_acktivis_T
Powered by WordPress 2.7    Valid XHTML    Valid CSS