<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nukeitdotorg &#187; security</title>
	<atom:link href="http://nukeit.org/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://nukeit.org</link>
	<description>Digital Medication</description>
	<lastBuildDate>Wed, 08 Sep 2010 02:41:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1-alpha</generator>
		<item>
		<title>CFIR and REAPER Security and Forensics Live CDs</title>
		<link>http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/</link>
		<comments>http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 02:00:42 +0000</pubDate>
		<dc:creator>fuzion</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[CFIR]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[distro]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[REAPER]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=4617</guid>
		<description><![CDATA[<a href="http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/" alt="CFIR and REAPER Security and Forensics Live CDs"><img src="http://cdn.nukeit.org/nuke34.jpg" align="left" alt="CFIR and REAPER Security and Forensics Live CDs" hspace="5" vspace="5" border="0" /></a>Linux Computer Forensics & Incident Response LIVECD or CFIR is a pretty straightforward forensics distro. 


http://sourceforge.net/projects/cfirproject/

<strong>Azril Azam on Facebook</strong>

http://www.facebook.com/people/Azril-Azam/1128729650


REAPER is an interesting forensics distro that aims to automate the gathering of documents from a host machine.
Rapid Evidence Acquisition Project for Event Reconstruction (REAPER) - Open Source forensic environment for the complete automation of the digital investigation process. At its core is Debian... <a href="http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p>Linux Computer Forensics &#038; Incident Response LIVECD or CFIR is a pretty straightforward forensics distro. </p>
<pre>

http://sourceforge.net/projects/cfirproject/
</pre>
<p><strong>Azril Azam on Facebook</strong></p>
<pre>

http://www.facebook.com/people/Azril-Azam/1128729650
</pre>
<p>REAPER is an interesting forensics distro that aims to automate the gathering of documents from a host machine.</p>
<blockquote><p>Rapid Evidence Acquisition Project for Event Reconstruction (REAPER) &#8211; Open Source forensic environment for the complete automation of the digital investigation process. At its core is Debian Live and the Open Computer Forensics Architecture (OCFA).</p></blockquote>
<pre>

http://sourceforge.net/projects/reaperforensics/

http://cybercrimetech.com/projects/reaper/reaper.php
</pre>
<p>Here are a few screens I took from a VM.<br />

<a href='http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/cfir-boot/' title='cfir-boot'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/11/cfir-boot-250x250.png" class="attachment-thumbnail" alt="cfir-boot" title="cfir-boot" /></a>
<a href='http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/cfir-desktop-2/' title='cfir-desktop-2'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/11/cfir-desktop-2-250x250.png" class="attachment-thumbnail" alt="cfir-desktop-2" title="cfir-desktop-2" /></a>
<a href='http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/cfir-desktop/' title='cfir-desktop'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/11/cfir-desktop-250x250.png" class="attachment-thumbnail" alt="cfir-desktop" title="cfir-desktop" /></a>
<a href='http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/cfir-boot-2/' title='cfir-boot-2'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/11/cfir-boot-2-250x250.png" class="attachment-thumbnail" alt="cfir-boot-2" title="cfir-boot-2" /></a>
<a href='http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/reaper-desktop/' title='reaper-desktop'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/11/reaper-desktop-250x250.png" class="attachment-thumbnail" alt="reaper-desktop" title="reaper-desktop" /></a>
<a href='http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/reaper-evidence/' title='reaper-evidence'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/11/reaper-evidence-250x250.png" class="attachment-thumbnail" alt="reaper-evidence" title="reaper-evidence" /></a>
<a href='http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/reaper-evidence-2/' title='reaper-evidence'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/11/reaper-evidence1-250x250.png" class="attachment-thumbnail" alt="reaper-evidence" title="reaper-evidence" /></a>
</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/cfir-and-reaper-security-and-forensics-live-cds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VIPER Lab VAST</title>
		<link>http://nukeit.org/viper-lab-vast/</link>
		<comments>http://nukeit.org/viper-lab-vast/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 22:46:52 +0000</pubDate>
		<dc:creator>fuzion</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vast]]></category>
		<category><![CDATA[viperlab]]></category>
		<category><![CDATA[voip]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=4544</guid>
		<description><![CDATA[<a href="http://nukeit.org/viper-lab-vast/" alt="VIPER Lab VAST"><img src="http://cdn.nukeit.org/nuke34.jpg" align="left" alt="VIPER Lab VAST" hspace="5" vspace="5" border="0" /></a>Back in June, Mike Jones posted about a new distro customized for use in VoIP security testing:
I have been working on a Linux distribution that penetration testers can utilize in their VoIP testing and have come up with VAST (VIPER Assessment Security Tools).
VIPER tools included:

	UCSniff
	VideoJak
	ACE
	VoipHopper

This distribution will be a vital part of any VoIP penetration tester’s arsenal.  The tools included on the dvd are an important part of VIPER assessments.  Along with the VoIP tools, it will also include basic... <a href="http://nukeit.org/viper-lab-vast/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p>Back in June, Mike Jones posted about a new distro customized for use in VoIP security testing:</p>
<blockquote><p>I have been working on a Linux distribution that penetration testers can utilize in their VoIP testing and have come up with VAST (VIPER Assessment Security Tools).<br />
VIPER tools included:</p>
<ul>
<li>UCSniff</li>
<li>VideoJak</li>
<li>ACE</li>
<li>VoipHopper</li>
</ul>
<p>This distribution will be a vital part of any VoIP penetration tester’s arsenal.  The tools included on the dvd are an important part of VIPER assessments.  Along with the VoIP tools, it will also include basic penetration testing tools such as NMAP and the password brute force application, Hydra.  VIPER will be constantly adding more features such as an open source PBX, sipXecs, and other network penetration tools and vulnerability scanners.  VIPER is also providing a class which will cover VoIP assessment methodology and tool usage. There will also be a lab portion of the training where students will have the chance to use the tools in a simulated corporate environment just as they would encounter in a VoIP vulnerability assessment.</p>
<p>VAST is built on Ubuntu 9.04 framework and has the option to install to a hard drive or USB.</p></blockquote>
<p>I found it on sourceforge and took a few screens in VirtualBox:</p>

<a href='http://nukeit.org/viper-lab-vast/viper-vast-boot/' title='viper-vast-boot'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/09/viper-vast-boot-250x250.png" class="attachment-thumbnail" alt="viper-vast-boot" title="viper-vast-boot" /></a>
<a href='http://nukeit.org/viper-lab-vast/viper-vast-desktop/' title='viper-vast-desktop'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/09/viper-vast-desktop-250x250.png" class="attachment-thumbnail" alt="viper-vast-desktop" title="viper-vast-desktop" /></a>
<a href='http://nukeit.org/viper-lab-vast/viper-vast-securelogix/' title='viper-vast-securelogix'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/09/viper-vast-securelogix-250x250.png" class="attachment-thumbnail" alt="viper-vast-securelogix" title="viper-vast-securelogix" /></a>
<a href='http://nukeit.org/viper-lab-vast/viper-vast-ucsniff/' title='viper-vast-ucsniff'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/09/viper-vast-ucsniff-250x250.png" class="attachment-thumbnail" alt="viper-vast-ucsniff" title="viper-vast-ucsniff" /></a>
<a href='http://nukeit.org/viper-lab-vast/viper-vast-videojak/' title='viper-vast-videojak'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/09/viper-vast-videojak-250x250.png" class="attachment-thumbnail" alt="viper-vast-videojak" title="viper-vast-videojak" /></a>
<a href='http://nukeit.org/viper-lab-vast/viper-vast-voiphopper/' title='viper-vast-voiphopper'><img width="250" height="250" src="http://cdn.nukeit.org/wp-content/uploads/2009/09/viper-vast-voiphopper-250x250.png" class="attachment-thumbnail" alt="viper-vast-voiphopper" title="viper-vast-voiphopper" /></a>

<p>Homepage:</p>
<pre>http://www.viperlab.net</pre>
<p>SF:</p>
<pre>http://sourceforge.net/projects/vipervast/</pre>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/viper-lab-vast/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Adobe ColdFusion websites being compromised</title>
		<link>http://nukeit.org/adobe-coldfusion-websites-being-compromised/</link>
		<comments>http://nukeit.org/adobe-coldfusion-websites-being-compromised/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 20:38:24 +0000</pubDate>
		<dc:creator>fuzion</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=4176</guid>
		<description><![CDATA[<a href="http://nukeit.org/adobe-coldfusion-websites-being-compromised/" alt="Adobe ColdFusion websites being compromised"><img src="http://cdn.nukeit.org/nuke34.jpg" align="left" alt="Adobe ColdFusion websites being compromised" hspace="5" vspace="5" border="0" /></a>Adobe Systems Inc. is warning users of its ColdFusion application development platform of a vulnerability being actively targeted by attackers to compromise websites.

A zero-day vulnerability in the ColdFusion FCKeditor rich text editor enables users to compromise websites and view and edit files, Adobe said in its Adobe Product Security Incident Response Team (PSIRT) blog. The rich text editor is installed with ColdFusion 8. It is also used in earlier versions. A patch is expected to be released next week, Adobe said.

The SANS Internet Storm Center reported last week that attackers have... <a href="http://nukeit.org/adobe-coldfusion-websites-being-compromised/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p>Adobe Systems Inc. is warning users of its ColdFusion application development platform of a vulnerability being actively targeted by attackers to compromise websites.</p>
<p>A zero-day vulnerability in the ColdFusion FCKeditor rich text editor enables users to compromise websites and view and edit files, Adobe said in its Adobe Product Security Incident Response Team (PSIRT) blog. The rich text editor is installed with ColdFusion 8. It is also used in earlier versions. A patch is expected to be released next week, Adobe said.</p>
<p>The SANS Internet Storm Center reported last week that attackers have been exploiting websites which have older installations of some ColdFusion applications.</p>
<p>&#8220;The vulnerable installations allow the attackers to upload ASP or Cold Fusion shells which further allow them to take complete control over the server,&#8221; wrote Bojan Zdrnja, a SANS ISC handler.</p>
<p>Zdrnja said a common application that has been seen in attacks is CFWebstore, a popular e-commerce application for ColdFusion.</p>
<p>The application development platform was acquired by Adobe in 2005. It is used in many websites that use rich forms to collect and share data. It supports Ajax applications and frameworks and integrates with dynamic PDF documents. Popular websites run by Simon &amp; Schuster Inc., Crayola LLC and FAO Schwarz Inc. are run using ColdFusion.</p>
<p>The software maker issued a workaround until a fix is released.</p>
<p>* Disable connectors by setting config.Enabled to false in the editor/filemanager/connectors/cfm/config.cfm file.</p>
<p>* Remove unused cfm files under editor/filemanager/connectors/cfm directory of the FCKeditor.</p>
<p>* Inspect FCKeditor directories for content that has already been uploaded. The uploaded files go under the directory specified in the config.UserFilesPath set in config.cfm.</p>
<p>via <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1361022,00.html?track=sy160">Adobe ColdFusion websites being compromised</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/adobe-coldfusion-websites-being-compromised/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adblock Plus v. NoScript</title>
		<link>http://nukeit.org/adblock-plus-v-noscript/</link>
		<comments>http://nukeit.org/adblock-plus-v-noscript/#comments</comments>
		<pubDate>Sun, 03 May 2009 00:43:26 +0000</pubDate>
		<dc:creator>nukeit</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[about]]></category>
		<category><![CDATA[advertising]]></category>
		<category><![CDATA[automatic]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[Dark]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[forums]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[no]]></category>
		<category><![CDATA[no Vulnerabilities]]></category>
		<category><![CDATA[posts]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=3930</guid>
		<description><![CDATA[<a href="http://nukeit.org/adblock-plus-v-noscript/" alt="Adblock Plus v. NoScript"><img src="http://cdn.nukeit.org/wp-content/uploads/2009/05/apbvnoscript.jpg" align="left" alt="Adblock Plus v. NoScript" hspace="5" vspace="5" border="0" /></a>
Wladimir Palant wrote an interesting post on the Adblock Plus blog yesterday that explains some details of an relatively unseen war going on between Adblock plus and NoScript. Both of these Firefox extensions are on my "Always installed" list, and I've never had anything bad to say about either one until now. Here's a small excerpt of Wladimir's post that highlights the issues ABP has with NoScript


 <a href="http://nukeit.org/adblock-plus-v-noscript/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p><img src="http://cdn.nukeit.org/wp-content/uploads/2009/05/apbvnoscript.jpg" alt="apbvnoscript" title="apbvnoscript" width="500" height="500" class="aligncenter size-full wp-image-3931" /><br />
Wladimir Palant wrote an interesting post on the Adblock Plus blog yesterday that explains some details of an relatively unseen war going on between Adblock plus and NoScript. Both of these Firefox extensions are on my &#8220;Always installed&#8221; list, and I&#8217;ve never had anything bad to say about either one until now. Here&#8217;s a small excerpt of Wladimir&#8217;s post that highlights the issues ABP has with NoScript</p>
<blockquote><p>&#8230; And to make sure that somebody sees these ads it goes pretty far. For example, it opens the changelog webpage (full of ads of course) on every single update of the extension, even though the NoScript FAQ claim that it happens only on major updates (yes, if you dig into it you will find the preference to disable this behavior – but how many people do that?). And updates coming roughly each week ensure that this page is opened fairly often. A problem is of course that NoScript will usually disable scripting and consequently also most advertising. That problem is being worked around by putting NoScript’s domains, Google AdSense and a few others on NoScript’s default whitelist (again, the overwhelming majority of users won’t go hunting for bogus entries in their whitelist). Given that NoScript proudly calls itself a security extension this means putting users at risk — for example, a while ago I demonstrated how an XSS vulnerability on a NoScript domain can be used to run JavaScript from any website, despite NoScript. This was countered by implementing anti-XSS measures rather than removing anything unnecessary from the whitelist.</p></blockquote>
<p>As a web guy with more than a few ads, I can fully understand where the NoScript guys are coming from. What I don&#8217;t understand is the lengths they are going to make money here. They aren&#8217;t paying for the extension download bandwidth, in fact the only costs they are incurring are from forcing the update page to load&#8230;. Basically, they are just being greedy here.</p>
<p>And it gets worse:</p>
<blockquote><p>What followed was a small war — the website would add various tricks to prevent Adblock Plus with EasyList from blocking ads, EasyList kept adjusting filters. Then, a week ago a new NoScript version was released. A few days later I noticed first bug reports — apparently, Adblock Plus “glitches” were observed with this NoScript version, especially around NoScript’s domains (but not only those). When I investigated this issue I couldn’t believe my eyes. NoScript was extended by a piece of obfuscated (!) code to specifically target Adblock Plus and disable parts of its functionality. The issues caused by this manipulation were declared as “compatibility issues” in the NoScript forum, even now I still didn’t see any official admission of crippling Adblock Plus. Clearly, NoScript is moving from the gray area of adware into dark black area of scareware, making money at user’s expense at any cost.</p></blockquote>
<p>NoScript released an update as I wrote this:</p>
<blockquote><p>
v 1.9.2.6<br />
NoScript now automatically removes the controversial &#8220;NoScript Development Support Filterset&#8221; deployed with NoScript 1.9.2.3 and above on startup, permanently and with no questions asked.
</p></blockquote>
<p>Amazing what a few hundred Diggs will do for your cause, eh?</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/adblock-plus-v-noscript/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Perishable Press 4G Blacklist Released</title>
		<link>http://nukeit.org/perishable-press-4g-blacklist-released/</link>
		<comments>http://nukeit.org/perishable-press-4g-blacklist-released/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 06:09:15 +0000</pubDate>
		<dc:creator>nukeit</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[4g]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[htaccess]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=3840</guid>
		<description><![CDATA[<a href="http://nukeit.org/perishable-press-4g-blacklist-released/" alt="Perishable Press 4G Blacklist Released"><img src="http://cdn.nukeit.org/wp-content/uploads/2009/03/pp.jpg" align="left" alt="Perishable Press 4G Blacklist Released" hspace="5" vspace="5" border="0" /></a><p style="text-align: center;"></p>

The next generation of optimized .htaccess protection has been released. Jeff from Perishable Press just announced the availability of his highly optimized 4G Blacklist.

Description:
The 4G Blacklist is a next-generation protective firewall that secures your website against a wide range of malicious activity. Like its 3G predecessor, the 4G Blacklist is designed for use on... <a href="http://nukeit.org/perishable-press-4g-blacklist-released/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="size-full wp-image-3839 aligncenter" title="4g blacklist" src="http://cdn.nukeit.org/wp-content/uploads/2009/03/pp.jpg" alt="4g blacklist" width="300" height="250" /></p>
<p>The next generation of optimized .htaccess protection has been released. Jeff from Perishable Press just announced the availability of his highly optimized 4G Blacklist.</p>
<p>Description:</p>
<blockquote><p>The 4G Blacklist is a next-generation protective firewall that secures your website against a wide range of malicious activity. Like its 3G predecessor, the 4G Blacklist is designed for use on Apache servers and is easily implemented via HTAccess or the httpd.conf configuration file.</p></blockquote>
<p>I&#8217;ve used many forms of .htaccess protection, but most were either incomplete or too bulky to give decent performance. Coming in at just 130 lines (incl. comments), the 4G is just a fraction of the size of other blacklists/combinations of lists I have laying around. Give it a try today.</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/perishable-press-4g-blacklist-released/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook Hack &#8211; Access Any Users Photo Albums</title>
		<link>http://nukeit.org/facebook-hack-access-any-users-photo-albums/</link>
		<comments>http://nukeit.org/facebook-hack-access-any-users-photo-albums/#comments</comments>
		<pubDate>Thu, 12 Mar 2009 20:52:03 +0000</pubDate>
		<dc:creator>nukeit</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[about]]></category>
		<category><![CDATA[bruteforce]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[features]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ing]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[posts]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=3823</guid>
		<description><![CDATA[<a href="http://nukeit.org/facebook-hack-access-any-users-photo-albums/" alt="Facebook Hack - Access Any Users Photo Albums"><img src="http://cdn.nukeit.org/wp-content/uploads/2009/03/1928400593_32be93d099-300x244.jpg" align="left" alt="Facebook Hack - Access Any Users Photo Albums" hspace="5" vspace="5" border="0" /></a><p style="text-align: center;"></p>
<p style="text-align: left;">Dave from Security Ninja shows how you can easily bruteforce a certain parameter to allow access to any user's Facebook photo album using Burp Suite. Here are the basics:</p>

Access to albums in Facebook is controlled by three parameters of a... <a href="http://nukeit.org/facebook-hack-access-any-users-photo-albums/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="size-medium wp-image-3828 aligncenter" title="http://www.flickr.com/photos/noneck/" src="http://cdn.nukeit.org/wp-content/uploads/2009/03/1928400593_32be93d099-300x244.jpg" alt="http://www.flickr.com/photos/noneck/" width="300" height="244" /></p>
<p style="text-align: left;">Dave from Security Ninja shows how you can easily bruteforce a certain parameter to allow access to any user&#8217;s Facebook photo album using Burp Suite. Here are the basics:</p>
<blockquote style="text-align: left;"><p>Access to albums in Facebook is controlled by three parameters of a URL, you can see them here:</p>
<p>http://www.facebook.com/album.php?aid=-3&amp;id=1508034566&amp;l=aad9c</p>
<p>aid=-3 (-3 for every public profile album)<br />
id=0123456789 (Obtained by searching for the user and hovering over the add friend button)<br />
l=? (all we know is its 5 characters from the 0123456789abcdef range)</p></blockquote>
<p style="text-align: left;">Dave uses Burp Suite, but there are many ways you can go about it. I think a dictionary of possible values might be marginally faster (untested) so I&#8217;ll use that.</p>
<p style="text-align: left;">First is one of my favorite methods, w3af&#8217;s Fuzzy Requests and Clustered Response tools.<br />
<code><br />
GET http://www.facebook.com/album.php?aid=-3&amp;id=targetsid&amp;l=$[l.strip() for l in file('fbhex.dic').readlines()]$ HTTP/1.0<br />
Host: www.facebook.com<br />
User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-us) AppleWebKit/312.1 (KHTML, like Gecko) Safari/312<br />
Pragma: no-cache<br />
Content-Type: application/x-www-form-urlencoded<br />
</code>
</p>
<p style="text-align: left;">Here&#8217;s the dictionary (1.1MB, zipped), extract it to your w3af directory.</p>
<p style="text-align: left;">After the run is finished, run the Cluster tool and wait. The valid page should show up far away from the rest of them.</p>
<p style="text-align: left;">Another tool that could be used for this is Edge Security&#8217;s WebSlayer:<br />
URL:<br />
<code>http://www.facebook.com/album.php?aid=-3&amp;id=targetsid&amp;l=FUZZ</code><br />
Set it to ignore lines so you can find your valid request faster. Currently, the error page contains 71 lines, but this may be different for you. Just run the scan for a few seconds and look at the number of lines that each error page contains, then stop the scan, enter the number in the ignore lines box and start again.
</p>
<p style="text-align: center;"><img class="size-medium wp-image-3826 aligncenter" title="webslayer" src="http://cdn.nukeit.org/wp-content/uploads/2009/03/webslayer-300x233.jpg" alt="webslayer" width="300" height="233" /></p>
<p style="text-align: left;">
<p style="text-align: left;">Other useful features of WebSlayer are the ability to control the rate and set proxy options.</p>
<p style="text-align: left;">There are likely MANY other tools that you can use to accomplish this task, but these seem to be the simplest.<br />
Good luck, and remember:
</p>
<p style="text-align: center;"><img class="aligncenter" title="gtfo" src="http://cdn.nukeit.org/wp-content/uploads/2009/03/gtfo.png" alt="" width="480" height="274" /></p>
<p style="text-align: left;">Check out Dave&#8217;s post for the Burp Suite method he uses to generate the needed parameter.</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/facebook-hack-access-any-users-photo-albums/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>Firefox 3.0.7</title>
		<link>http://nukeit.org/firefox-307/</link>
		<comments>http://nukeit.org/firefox-307/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 01:36:49 +0000</pubDate>
		<dc:creator>nukeit</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=3809</guid>
		<description><![CDATA[<a href="http://nukeit.org/firefox-307/" alt="Firefox 3.0.7"><img src="http://cdn.nukeit.org/wp-content/uploads/2009/03/firefox_by_fo2-300x250.jpg" align="left" alt="Firefox 3.0.7" hspace="5" vspace="5" border="0" /></a><p style="text-align: center;"></p>
Firefox 3.0.7 is now available.
Notable improvements:
Fixed missing cookies bug (I hated that)
Official releases for the Estonian, Kannada, and Telugu languages are now available.
Misc stability and security improvements.
Known Vulnerabilities Fixed
Other Release Notes
Complete List of Fixes... <a href="http://nukeit.org/firefox-307/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="size-medium wp-image-3810 aligncenter" title="firefox_by_fo2 - fo2.deviantart.com" src="http://cdn.nukeit.org/wp-content/uploads/2009/03/firefox_by_fo2-300x250.jpg" alt="firefox_by_fo2 - fo2.deviantart.com" width="300" height="250" /></p>
<p>Firefox 3.0.7 is now available.<br />
Notable improvements:</p>
<blockquote><p>Fixed missing cookies bug (I hated that)<br />
Official releases for the Estonian, Kannada, and Telugu languages are now available.<br />
Misc stability and security improvements.</p></blockquote>
<p>Known Vulnerabilities Fixed<br />
Other Release Notes<br />
Complete List of Fixes</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/firefox-307/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Gmail Password Change Vulnerability</title>
		<link>http://nukeit.org/gmail-password-change-vulnerability/</link>
		<comments>http://nukeit.org/gmail-password-change-vulnerability/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 22:57:55 +0000</pubDate>
		<dc:creator>nukeit</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[automatic]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[posts]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=3800</guid>
		<description><![CDATA[<a href="http://nukeit.org/gmail-password-change-vulnerability/" alt="Gmail Password Change Vulnerability"><img src="http://cdn.nukeit.org/wp-content/uploads/2009/03/3020393537_97be20e01f-300x225.jpg" align="left" alt="Gmail Password Change Vulnerability" hspace="5" vspace="5" border="0" /></a><p style="text-align: center;"></p>

Security researcher Vicente Aguilera Diaz from ISecAuditors has released a proof of concept for a Gmail vulnerability dating back to Aug. 1, 2007.

Details of the attack:

<p style="text-align: justify;">
GMail is vulnerable to CSRF attacks in the "Change Password" functionality. The only token fo... <a href="http://nukeit.org/gmail-password-change-vulnerability/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="size-medium wp-image-3801 aligncenter" title="http://www.flickr.com/photos/fristle/" src="http://cdn.nukeit.org/wp-content/uploads/2009/03/3020393537_97be20e01f-300x225.jpg" alt="http://www.flickr.com/photos/fristle/" width="300" height="225" /></p>
<p>Security researcher Vicente Aguilera Diaz from ISecAuditors has released a proof of concept for a Gmail vulnerability dating back to Aug. 1, 2007.</p>
<p>Details of the attack:</p>
<blockquote>
<p style="text-align: justify;">
GMail is vulnerable to CSRF attacks in the &#8220;Change Password&#8221; functionality. The only token for authenticate the user is a session cookie, and this cookie is sent automatically by the browser in every request. An attacker can create a page that includes requests to the &#8220;Change password&#8221; functionality of GMail and modify the passwords of the users who, being authenticated, visit the page of the attacker. The attack is facilitated since the &#8220;Change Password&#8221; request can be realized across the HTTP GET method instead of the POST method that is realized habitually across the &#8220;Change Password&#8221; form.
</p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/gmail-password-change-vulnerability/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Security Stuff &#8211; 0223</title>
		<link>http://nukeit.org/security-stuff-0223/</link>
		<comments>http://nukeit.org/security-stuff-0223/#comments</comments>
		<pubDate>Tue, 24 Feb 2009 02:47:38 +0000</pubDate>
		<dc:creator>nukeit</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[fud]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[site]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[test]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=3791</guid>
		<description><![CDATA[<a href="http://nukeit.org/security-stuff-0223/" alt="Security Stuff - 0223"><img src="http://cdn.nukeit.org/wp-content/uploads/2009/02/stickemup-300x199.jpg" align="left" alt="Security Stuff - 0223" hspace="5" vspace="5" border="0" /></a><p style="text-align: center;"></p>

<strong>Tools and Projects</strong>

jeriko - a set of scripts which help with the automation of common penetration testing tasks. (gnucitizen)

osg2 - OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project.

Webshag - multi-threaded, multi-platform web server audit tool written in Python.

SEAT 0.3 - uses search engine databases and other... <a href="http://nukeit.org/security-stuff-0223/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="size-medium wp-image-3795 aligncenter" title="stickemup" src="http://cdn.nukeit.org/wp-content/uploads/2009/02/stickemup-300x199.jpg" alt="stickemup" width="300" height="199" /></p>
<p><strong>Tools and Projects</strong></p>
<p>jeriko &#8211; a set of scripts which help with the automation of common penetration testing tasks. (gnucitizen)</p>
<p>osg2 &#8211; OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project.</p>
<p>Webshag &#8211; multi-threaded, multi-platform web server audit tool written in Python.</p>
<p>SEAT 0.3 &#8211; uses search engine databases and other public resources to scan a site for vulnerabilities.</p>
<p>Bonsai &#8211; Andres Riancho (of w3af fame) provides professional information security services and training.</p>
<p><strong>MMM&#8230; FUD</strong></p>
<p>SSL Screwed<br />
Twitter Twitdown</p>
<p><strong>Recently Hacked</strong></p>
<p>Hotmail<br />
Paypal<br />
Zone-h<br />
F-Secure<br />
Gears<br />
You?</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/security-stuff-0223/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>BackTrack 4 Beta</title>
		<link>http://nukeit.org/backtrack-4-beta/</link>
		<comments>http://nukeit.org/backtrack-4-beta/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 05:28:55 +0000</pubDate>
		<dc:creator>nukeit</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[about]]></category>
		<category><![CDATA[Backtrack]]></category>
		<category><![CDATA[DVD]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[live]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[unicornscan]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://nukeit.org/?p=3772</guid>
		<description><![CDATA[<a href="http://nukeit.org/backtrack-4-beta/" alt="BackTrack 4 Beta"><img src="http://cdn.nukeit.org/wp-content/uploads/2009/02/desktopkde-300x225.jpg" align="left" alt="BackTrack 4 Beta" hspace="5" vspace="5" border="0" /></a><p style="text-align: center;"></p>
<p style="text-align: center;"></p>

What could make BackTrack better? How about making it Debian based with a repository chock full of security tool goodness? Maybe even use Ubuntu's repos for regular system updates? Well that's just what the team at Remote Exploit have done with the fourth incarnation of their infamous live pentesting distribution:
Now based o... <a href="http://nukeit.org/backtrack-4-beta/">Read more..</a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<p style="text-align: center;"><img class="size-medium wp-image-3781 aligncenter" title="desktopkde" src="http://cdn.nukeit.org/wp-content/uploads/2009/02/desktopkde-300x225.jpg" alt="desktopkde" width="300" height="225" /></p>
<p>What could make BackTrack better? How about making it Debian based with a repository chock full of security tool goodness? Maybe even use Ubuntu&#8217;s repos for regular system updates? Well that&#8217;s just what the team at Remote Exploit have done with the fourth incarnation of their infamous live pentesting distribution:</p>
<blockquote><p>Now based on Debian core packages and utilizing the Ubuntu software repositories, BackTrack 4 can be upgraded in case of update. When syncing with our BackTrack repositories, you will regularly get security tool updates soon after they are released.</p></blockquote>
<p><strong>New Features</strong></p>
<ul>
<li> Kernel 2.6.28.1 with better hardware support.</li>
<li> Native support for Pico e12 and e16 cards.</li>
<li> Support for PXE Boot</li>
<li> SAINTexploit</li>
<li> MALTEGO</li>
<li> Custom rtl8187 patches</li>
<li> Broader wireless injection support</li>
<li> Unicornscan</li>
<li> RFID support</li>
<li> Pyrit CUDA</li>
<li> Other new and updated tools</li>
</ul>
<p><strong>Screenshots</strong></p>

<p>BT4 is available as a DVD ISO [854MB] or VMware Image [1GB]<br />
Download<br />
<strong>Hint:</strong> Use a download manager or something with resume. Their mirrors are getting hit pretty hard as you can imagine.</p>
]]></content:encoded>
			<wfw:commentRss>http://nukeit.org/backtrack-4-beta/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
