Thursday, October 20, 2011

Adobe Flash Bug | Spy On The Webcams of Your Website Visitors

A slight variation of a previously designed clickjacking attack that used a Adobe Flash vulnerability has once again made it possible for website administrators to surreptitiously spy on their visitors by turning on the user's computer webcam and microphone.
It works in all versions of Adobe Flash that the researcher have tested . He’ve confirmed that it works in the Firefox and Safari for Mac browsers. Use one of those if you check out the live demo. There’s a weird CSS opacity bug in most other browsers (Chrome for Mac and most browsers on Windows/Linux).
Clickjacking + Adobe Flash = Sad Times!
This attack works by using a neat variation of the normal clickjacking technique that spammers and other bad people are using in the wild right now. For the uninitiated:
Combine clickjacking with the Adobe Flash Player Setting Manager pageand you have a recipe for some sad times.

How the attack works ?

Instead of iframing the whole settings page (which contains the framebusting code), Just  iframe the settings SWF file. This  bypasses the framebusting JavaScript code, since we don’t load the whole page — just the remote .SWF file. I was really surprised to find out that this actually works!
 A bunch of clickjacking attacks in the wild,  never any attacks where the attacker iframes a SWF file from a remote domain to clickjack it — let alone a .SWF file as important as one that controls access to your webcam and mic!
The problem here is the Flash Player Setting Manager, this inheritance from Macromedia might be the Flash Player security Achilles heel.
This is a screenshot of what the Settings Manager .SWF file looks like:

Adobe Flash Settings Manager


| Source | 

Monday, October 17, 2011

WiFi Manager

WiFi Manager v5.6 - A must have for every network administrator

ManageEngine WiFi Manager is an integrated and centralized management
and security solution for wireless networks (WLANs) for enterprises.

It enhances the availability and security of your WLANs by continuously
monitoring the network as well as the airspace.

Features:
+ WiFi Manager offers wireless device monitoring, one-click configuration, access point firmware management, wireless security management and a variety of reports that remove the complexity of wireless network management.
+ WiFi Manager can detect almost all major wireless threats including rogue attacks, intrusions, sniffers, DoS attacks, and vulnerabilities.
+ With WiFi Manager you'll have complete control over your wireless devices as well as your airspace, and more time to focus on core IT operations.

Bonus tools: Air crack, hack wifi and wireless key, does support WAP, WAP2, WEP encryption.

Unlock With WiFi

Unlock With WiFi v2.1.1

Hate entering your password every time you turn on your phone?
When you’re at home, or work, you don’t need to worry about losing your
phone, so why should you have to enter your password?


Unlock your phone when you’re connected to your home
WiFi network. What does “unlock” mean? It means you don’t have to
enteryour password/pattern/PIN when you turn on your phone.

How does it work?
When you get home and connect to your WiFi network, your device will unlock. Then when you leave, and the WiFi disconnects, the device will lock again. You have to enter your password the first time after you connect to your WiFi network. This is so that if someone steals or finds your phone, they can’t just bring it to your house to unlock it.

After you enter your password once while connected to your WiFi network, you won’t have to enter it again until you leave/disconnect. This is great for SMS texting!

What else does it do?
You can also set a lock delay, for when you’re not at home. The default delay is set to 5 seconds (you can adjust it), so when you turn the screen off, the device won’t lock until 5 seconds have
passed. That way, if you remember something you forgot to do, you can turn it back on without entering your password. This feature is considered experimental at this time. It works on most devices, but isn’t guaranteed to work on all devices.

There are also battery saving options to:
+ Turn off WiFi when you leave home
+ Turn on GPS when you leave home
+ Turn off GPS when you get home
+ Turn on Bluetooth when you leave home
+ Turn off Bluetooth when you get home
+ Turn off Auto Sync when you leave home
+ Turn on Auto Sync when you get home
+ This feature is experimental, and not guaranteed to work on all devices. Works on tablets too!

Tuesday, October 11, 2011

Apache mod_proxy Proof of Concept (CVE-2011-3368)

A recent Apache vulnerability has been made public whereby an attacker could gain unauthorised access to content in the DMZ network:



Description
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.


SECFORCE has developed a proof of concept for this vulnerability .The script exploits the vulnerability and allows the user to retrieve arbitrary known files from the DMZ. The tool can also be used to perform a port scan of the web server using the Apache proxy functionality, and therefore bypassing any firewall. Click here to download the POC.


Usage :- 
rmacros@laptop2: python apache_proxy_scanner.py
CVE-2011-3368 proof of concept by Rodrigo Marcos
http://www.secforce.co.uk
usage():
python apache_scan.py [options]
 [options]
-r: Remote Apache host
-p: Remote Apache port (default is 80)
-u: URL on the remote web server (default is /)
-d: Host in the DMZ (default is 127.0.0.1)
-e: Port in the DMZ (enables 'single port scan')
-g: GET request to the host in the DMZ (default is /)
-h: Help page
examples:
 - Port scan of the remote host
python apache_scan.py -r www.example.com -u /img/test.gif
 - Port scan of a host in the DMZ
python apache_scan.py -r www.example.com -u /img/test.gif
-d internalhost.local
- Retrieve a resource from a host in the DMZ
python apache_scan.py -r www.example.com -u /img/test.gif
-d internalhost.local -e 80 -g /accounts/index.html
The following screenshot shows the result of the command above:
| source | 

Monday, October 10, 2011

Optima DDOS 10a Botnet Download

Do

"Optima DDOS 10a Botnet" full version posted for all to download and use. Complete new version of the acclaimed DDoS bot Optima Darkness. In this new version 10a according to the author was raised in secrecy bot system and optimized grabber passwords. It cost about $ 600 worth.


Features of the bot :-

  • DDoS attacks of three types - http flood, icmp-flood, syn-flood.
  • Theft of stored passwords from some applications installed on the victim's system, details below.
  • Opening on the infected system proxy Socks5.
  • The possibility of cheating various counters on the websites (http-access the sites).
  • Hidden download and run the specified file to the affected systems.
  • Installed in the system as a service
  • Weight bot - 95.5 kb, written in Delphi.



Saturday, October 8, 2011

fuse.microsoft.com Defaced by Hmei7

Microsoft FUSE Labs Sub-domain defaced by Hmei7

fuse.microsoft.com The official sud-domain of Microsoft FUSE Labs was defaced by a hacker named "Hmei7". Mirror of hack at Zone-H can be found here.