Tìm được cái trang này chuyên decode các loại mã hóa PHP, thấy nó được chuẩn bị rất tốt và có khả năng giải mã những file php bị mã hóa đủ kiểu, đã test thử với hầu hết các con shell được mã hóa của rất nhiều thành viên thì tỉ lệ thành công gần như trên 95% nên bạn nào có nhu cầu thì vào sài ké nó nhé: http://www.unphp.net/
Tuesday, June 24, 2014
Sock 5 Vip !!(24/06/2014)
1.36.186.217:6923
103.247.157.3:35389
119.247.168.8:10119
121.150.193.39:19942
140.117.163.142:52848
142.255.77.162:47731
169.130.9.90:51362
173.23.165.114:28358
174.60.216.175:30947
178.150.134.218:45360
184.20.121.129:12497
190.112.101.139:7880
193.136.60.26:443
194.247.12.11:9335
194.247.12.11:9614
199.191.120.205:49073
199.201.126.67:443
201.26.63.135:20607
103.247.157.3:35389
119.247.168.8:10119
121.150.193.39:19942
140.117.163.142:52848
142.255.77.162:47731
169.130.9.90:51362
173.23.165.114:28358
174.60.216.175:30947
178.150.134.218:45360
184.20.121.129:12497
190.112.101.139:7880
193.136.60.26:443
194.247.12.11:9335
194.247.12.11:9614
199.191.120.205:49073
199.201.126.67:443
201.26.63.135:20607
Monday, June 23, 2014
BẢO MẬT HƠN CHO PASSWORD – WEB PROGRAMER
Hiện nay, nhiều bạn học lập trình rất giỏi, cực kì xuất sắc nữa là khác, nhưng các bạn đó có bao giờ chú ý để việc đặt 1 password sao cho BẢO MẬT.
- Thú thật, khi mình khai thác sqli, nhiều site đặt password chẳng mã hóa lun, chắc điều này các bạn cũng biết nhỉ????
- Một số khác, lại mã hóa cái password ấy, nhưng cực kì sơ sài, bởi vì, họ chỉ quan tâm tới vẻ bên ngoài sao cho bắt mắt, đẹp và … chạy được, nhưng đó lại là sự thật
vd 1 cách đặt pass phổ biến như:
$password = md5($_POST["pass"]);
Facebook Comment's Picture Hijacking
Link: http://1337day.com/exploit/20915
Description:
Today Facebook rollouts for FB users to comment with picture on any status. But the feature has a bug which allows malicious user to hijack the picture from any comments if the picture is share by uploading for comment.
After Malicious user hijack the picture, malicious person can change picture description as well as delete the picture.
Let's get started! all you need are status ID and victim's uploaded picture for comment ID.
Once you have both, we can simply comment on any status with that uploaded picture iD with the help of little javascript or you can use tampa data (attached_photo_fbid) to post with comment picture ID.
-----Javascript Facebook Picture Hijack PoC----
var yourMessage = "check out my pic"; // your msg
var photofbID = XXXXXXXXXX; // victim photo ID
Today Facebook rollouts for FB users to comment with picture on any status. But the feature has a bug which allows malicious user to hijack the picture from any comments if the picture is share by uploading for comment.
After Malicious user hijack the picture, malicious person can change picture description as well as delete the picture.
Let's get started! all you need are status ID and victim's uploaded picture for comment ID.
Once you have both, we can simply comment on any status with that uploaded picture iD with the help of little javascript or you can use tampa data (attached_photo_fbid) to post with comment picture ID.
-----Javascript Facebook Picture Hijack PoC----
var yourMessage = "check out my pic"; // your msg
var photofbID = XXXXXXXXXX; // victim photo ID
Sock 5 Vip!! (23/06/2014)
100.42.168.86:6629
108.167.78.172:35208
108.34.170.52:22251
109.67.132.133:44468
109.73.216.94:32251
114.80.136.222:7780
122.118.111.130:5127
140.116.109.79:10113
141.135.111.233:5813
142.255.77.162:47731
162.243.105.128:6170
173.12.63.13:43952
173.14.92.165:15761
108.167.78.172:35208
108.34.170.52:22251
109.67.132.133:44468
109.73.216.94:32251
114.80.136.222:7780
122.118.111.130:5127
140.116.109.79:10113
141.135.111.233:5813
142.255.77.162:47731
162.243.105.128:6170
173.12.63.13:43952
173.14.92.165:15761
Subscribe to:
Posts (Atom)