Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts

Thursday, July 18, 2013

0

Critical JAVA Sandbox Bypass Vulnerability in Java 7 Update 25

  • Thursday, July 18, 2013
  • Nauman Ashraf
  • Security Explorations – A polish company has found a critical Java vulnerability that bypass Java sandbox. Vulnerable versions are Java 7 and its previous ones.


    What’s interesting about the attack is that it’s not new. Experts say the attack method has been known for over 10 years and it should have been mitigated with the Reflection API introduced in Java SE 7. It's one of those risks one should protect against in the first place when new features are added to Java at the core VM level. According to Softpedia.

    The vulnerability, dubbed “issue 69,” can be exploited via a “very classic attack” for a complete Java sandbox bypass.  According to Adam Gowdiak, the CEO of Security Explorations.

    The details and Proof of Concept of the vulnerability have been submitted to Oracle and Oracle fixed it in the June 2013 Java SE CPU, and POCs for nine IBM Java vulnerabilities addressed in early July 2013.

    Previously, Security Explorations found and submitted flaws to Oracle and IBM, which have been fixed now.

    Read More..

    Saturday, March 16, 2013

    0

    Multiple SQL Injection Vulnerabilities on Web Cookbook found by Security Researcher

  • Saturday, March 16, 2013
  • Nauman Ashraf

  • An Independent Pakistani Security Researcher Saadat Ullah found Multiple SQL Injection Vulnerabilities on Web Cookbook. Security Researcher also found SQL Injection and XSS vulnerabilities on nconf-1.3, Plogger Gallery and on Mybb Plugin PRO STAT.



    Vulnerabilities details are given below:

    # Exploit Title: Web Cookbook Multiple SQL Injection
    # Date: 2013/3/12
    # Exploit Author: Saadat Ullah , saadi_linux@rocketmail.com
    # Software Link: http://sourceforge.net/projects/webcookbook/
    # Author HomePage: http://security-geeks.blogspot.com/
    # Tested on: Server: Apache/2.2.15 (Centos) PHP/5.3.3

    # SQL Injection

    http://localhost/cook/searchrecipe.php?sstring=[SQLi]
    http://localhost/cook/showtext.php?mode=[SQLi]
    http://localhost/cook/searchrecipe.php?mode=1&title=[SQLi]&prefix=&preparation=&postfix=&tipp=&ingredient=


    http://localhost/cook/showtext.php?mode=[SQLi]

    #Proof Of Concept
    In showtext.php
    Code:
    $mode = $_GET["mode"];
    .
    .
    showText($mode, $art);//sending $mode to a function without sanitizing it
    .
    .
    function showText($kategorie, $art) {
        initDB();
        echo "<div class=\"rdisplay\">\n";
        $query = "SELECT * FROM dat_texte WHERE id = $kategorie"; //using a non sanitize field in the querry
        $result = mysql_query($query);
    .
    .
    All GET Fields Are Vuln To SQLi
    http://localhost/cook/searchrecipe.php?mode=1&title=[SQLi]&prefix=&preparation=&postfix=&tipp=&ingredient=

    #POC
    In searchrecipe.php
        $title = $_GET['title'];
        $prefix = $_GET['prefix'];
        $preparation = $_GET['preparation'];
        $postfix = $_GET['postfix'];
        $tipp = $_GET['tipp'];
        $ingredient = $_GET['ingredient'];
        .
        .
        .
        if ($title != "") {
            $sstring = "a.title LIKE '%$title%' ";
        }
        .
        .
        searchRecipe($mode, $sstring);
        .
        .
        In Function SearchRecipe
                    $query = "SELECT DISTINCT a.id, a.title FROM das_rezept a, dat_ingredient b WHERE a.title LIKE '%$sstring%' OR b.description LIKE '%$sstring%' AND a.id = b.recipe ORDER BY a.title";


    http://localhost/cook/searchrecipe.php?sstring=[SQLi]
    #POC
    $sstring = $_GET['sstring'];
            if ($sstring != "") {
                searchRecipe(0, $sstring);
    .
    .
    .
        $query = "SELECT DISTINCT a.id, a.title FROM das_rezept a, dat_ingredient b WHERE a.title LIKE '%$sstring%' OR b.description LIKE '%$sstring%' AND a.id = b.recipe ORDER BY a.title";


    A simple Non-Presistent XSS
    http://localhost/cook/searchrecipe.php?mode=1&title=<script>alert('hi');</script>&prefix=&preparation=&postfix=&tipp=&ingredient=


    Read More..
    0

    Pakistani Security Researcher gets 500$ Reward for Facebook Bug Bounty Program

  • Nauman Ashraf
  • A Pakistani Security Researcher, Former Black Hat - Haider Mehmood Qureshi, gets 500$ reward from Facebook under Facebook Bug Bounty Program for reporting HTML Injection flaw on Facebook mobile site.

    Below are the details of Bug provide by the Researcher to The Hackers Post.

    [#] - Vulnerability Title:
                               HTML Injection

    [#] - Vendor homepage: 
                              http://m.facebook.com

    [#] - Remote/Local: 
                             Remote

    [#] - Tested on: 
                            Windows 7 64 bit Firefox browser  (but should have worked on other OS and browsers                      (not sure about IE))

    [#] - Vulnerability Submitted:  
                            12/1/2013

    [#] - Vulnerability Status: 
                             FIXED

    [#] - Vulnerable  Parameter: 
                            https://m.facebook.com/survey.php?incorrect_brand&params=

    Facebook mobile provides a survey to evaluate the mobile user experience as they surf facebook mobile site. Here is the survery  link: https://m.facebook.com/survey.php .

    While entering the mobile phone brands , it provides a list of brands in case you didn't type the correct brand.


    The list that was provided contained their HTML code inside the parameter

    https://m.facebook.com/survey.php?incorrect_brand&params=[HTML code of Brands and Radio Buttons]

    Remote User can add any brand Name and Radio buttons, hence allowing Remote HTML injection. It was as simple as it sounds. This could also result in adding junk entries into to database hence causing spam, because remote user can add entries and submit.

    Below is the screenshot of a  portion of exact POC Researcher submitted to Facebook:



    Below my the first reply from Facebook and they acknowledged the issue



    below is their reply after 2 months when they fixed the issue



    below is their email regarding my eligibility of bug bounty and details.



    There is increase rise in black hats changing their dimensions towards bug reporting rather than exploiting them. Yesterday, we reported the youngest security researcher found XSS flaw on Amazon Site.

    About Security Researcher Haider:
    Haider Mehmood Qureshi is a BS Computer Sciences Student from Comsats Intitute of information technology Islamabad, He do freelancing as Penetration Tester, Started learning pentesting/hacking in 2009. Initially, he was into defacing websites just for fun, later realized to make Pentesting/Security auditing as my career. You can contact security researcher here.
    Read More..

    Wednesday, March 13, 2013

    0

    Amazon vulnerable to XSS flaw found by Security Researcher

  • Wednesday, March 13, 2013
  • Nauman Ashraf
  • Ali Hasan Ghauri - 14 Years old , The Youngest Security Researcher found XSS vulnerability on Amazon (www.amazon.com) main site. Vulnerability is fixed by Amazon Security Team.


    The Security researcher told The Hackers Post that he reported XSS flaw to Amazon security team. He got immediate response with appreciation and vulnerablity fixed by them.
    Amazon Secuity Team immediately patched the XSS flaw which was reported by me. They didnot offer  any reward to me because they dont have bug bounty program.

    [#] - Website:
                        http://www.amazon.com/

    [#] - Vulnerable link (POC):
    http://www.amazon.com/Thomas-Calculus-Multivariable-12th-George/dp/0321643690/%22ns=%22alert%280x000308%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert%28%22XSS%20By%20Ghauri%22%29%3C/script%3E
    [#] - Vulnerability Type: 
                       XSS (Cross Site Scripting)

    [#] - Status:
                        Fixed [Critical]

    [#] -  Tested on:
                      Firefox 19.0.1

    -->
    The Youngest Security Researcher " Ali Hasan Ghauri " also found XSS Vulnerabilities on OLX , EBAY , BrainTree Payments , GitLab & many more.

    Ebay POC Screen Shot:

    Ebay Acknowledged his name in Responsible Disclosure Acknowledgements Page.
    GitLab also Acknowledged his name in Vulnerability Acknowledgement Disclosure.

    According to Security Researcher, BrainTree Payments sent him a Cool T-shirt for finding bugs.
    Read More..

    Wednesday, February 20, 2013

    0

    FileHippo Vulnerable to XSS flaw found by Security researcher

  • Wednesday, February 20, 2013
  • Nauman Ashraf

  • A Pakistani Security Researcher Ali Hasan Ghauri - founder of AHPT has discovered XSS Vulnerability on Filehippo.com main site. Vulnerability still exists


    Security Researcher told The Hackers Post that In December 2012, the Filehippo entire domain was vulnerable and reported XSS flaw to Filehippo team but did not get any response from the company, so i decided to make it public.

    Last time we published news of W3Schools vulnerable to same XSS flaw reported by the security researcher.


    [#] - Website:
                        http://www.sify.com

    [#] - Vulnerable link (POC):
                       http://www.filehippo.com/it/download_ccleaner/%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert%28%22XSS%20By%20Ali%20Hasan%20Ghauri%22%29%3C/script%3E

    [#] - Vulnerability Type: 
                       XSS (Cross Site Scripting)

    [#] - Status:
                       Not Fixed [Critical]

    [#] -  Tested on:
                      Firefox 18.0.1

    The Youngest Pakistani Security Researcher "Ali Hasan Ghauri" (AHPT) also Found Vulnerabilities on Big Tech Sites on Skype , Adobe, Asia Cnet, Yellowpages, visualstudiomagazine ,Filehippo ,CnetDownloads, US.Acer, W3Schools, Hamariweb & Many More.

    About Filehippo:

    FileHippo is an Internet download website that offers open source, freeware, and shareware programs for Windows. It does not accept user uploaded files.The website also offers its own software, FileHippo Update Checker, a free program that scans a computer and then reports out-dated software in a web-page, offering links to updated versions.
    According to Quantcast, FileHippo receives more than three million US visitors each month and Alexa lists FileHippo among the 700 most visited websites worldwide.

    More News of XSS flaw can be found here.


    Read More..

    Saturday, February 16, 2013

    0

    RIM Fixes Remote Code Execution Flaws in BlackBerry

  • Saturday, February 16, 2013
  • Nauman Ashraf
  • BSRT-2013-003 advisory released for Vulnerabilities in BlackBerry Enterprise Server components that process images could allow remote code execution. In order to address the issues, RIM has released BlackBerry Enterprise Server 5.0.4 MR2, according to Blackberry.


    According to the advisory published by the company, the security holes affect the components that process TIFF images for rendering on BlackBerry smartphones.

     In some cases, the security holes could also be leveraged to allow the attacker to extend access to other parts of the network.

    In order to exploit the vulnerabilities that affect the Mobile Data System’s Connection Service component, the attacker would have to create a malicious webpage and convince the victim to access it.

    The flaws that affect the BlackBerry Messaging Agent or the BlackBerry Collaboration Service components are more dangerous because there’s no user interaction required for the attack to be successful. The attacker must simply attach a specially-crafted TIFF image to an email or an instant message and send it to a BlackBerry smartphone.

    “The user does not need to click a link or an image, or view the email message or instant message for the attack to succeed in this scenario,” the company explained.

    RIM is not aware of any attacks that have leveraged these vulnerabilities, but taking into account the fact that they are considered to be of high severity, the company advises customers to update to the latest version to ensure they’re fully protected.

    In addition to BlackBerry Enterprise Server 5.0.4 MR2, which can be applied to all supported versions of the product, RIM has also released an interim security update.
    Read More..

    Thursday, February 14, 2013

    0

    Sify.com vulnerable to SQL Injection

  • Thursday, February 14, 2013
  • Nauman Ashraf
  • Indian Ethical Hackers found a SQL injection flaw at Sify( sify.com). SQLi Vulnerability still exist in the site.

    Ethical Hackers from India found a SQL Injection vulnerability at the high profile website sify.com. According to Ethical Hackers, they reported bug to site administration but they didnot respond to the vulnerability.

    Website:
    http://www.sify.com
    Vulnerable link:
    http://www.sify.com/imagegallery/gallery/img_view_sentcard.php?card_number=ss 
    Vulnerability Type: 
    SQL Injection
    Status: 
    Not Fixed [Critical]

    About Sify:

    Sify is an Internet service provider in India. Seventy five per cent of the 1.6 million visitors in 2008 to the web site sify.com hail from India. It was rated as one of "The ten top technology companies world-wide recommended for investment" by Fortune in 1999.

    Sify was one of the first private sector player to offer internet access, when internet access was opened to private sector (until then the state run VSNL had a monopoly in providing internet access). It leased international bandwidth from global vendors, domestic connectivity from telecom players and set up last mile connectivity by multiple methods: wi-fi connections using roof top antennae, copper connections using phone lines or cable TV connections. Sify also started providing internet network connectivity for business enterprises in India. Sify set up a chain of franchised internet cafes (today a network of over 3,300+ cybercafes).


    Read More..

    Sunday, February 3, 2013

    0

    Adobe Vulnerable to XSS flaw

  • Sunday, February 3, 2013
  • Nauman Ashraf


  • One of the subdomain (http://groups.adobe.com) of Abode site is vulnerable to XSS. The vulnerability is still not fixed by Adobe. Ethical hackers reported vulnerability a few days ago but they failed to respond. We got email from Ethical Indians.

    Since the Bug Bounty Program started by companies, hackers are continually hunting different types of vulnerabilities of different top profile sites. Some site lists hacker on hall of fame page for the Bug Bounty and other offer reward for Bug bounty.

    Web site:
    http://groups.adobe.com

    Vulnerability Type:
    Cross Site Scripting (XSS)

    Vulnerable Link:
    http://groups.adobe.com/index.cfm?event=page.badpage&pageid=%3Cscript%3Ealert%28/Ethicalindians/%29%3C%2Fscript%3E

    Status:
    Not Fixed (No Reply)
    Read More..

    Saturday, February 2, 2013

    0

    W3Schools XSS vulnerability Found by the youngest Security Researcher

  • Saturday, February 2, 2013
  • Nauman Ashraf
  • A Pakistani Student "Ali Hasan Ghauri" (AHPT) who is 14 years old, The Youngest Security Researcher has discovered XSS (Cross-Site Scripting) Vulnerability on http://www.w3schools.com main site. Below is the Screen Shot of XSS.

              
    The Youngest Pakistani Security Researcher "Ali Hasan Ghauri" (AHPT) also Found Vulnerabilities on Big Tech Sites on Skype , Adobe, Asia Cnet, Yellowpages, visualstudiomagazine ,Filehippo ,CnetDownloads, US.Acer, W3Schools, Hamariweb & Many More.

    Above just polpular sites are mentioned But The Youngest Security Researcher "Ali Hasan Ghauri" (AHPT) has found 250+ Vulnerable Sites & reported to them by giving the Security as well .



    About W3Schools:

    W3Schools is a web developer information website, with tutorials and references relating to web development topics such as HTML, CSS, JavaScript, PHP, and SQL.

    Update:

    XSS flaw on W3Schools fixed now.
    Read More..

    Friday, January 18, 2013

    0

    Java Zero Day sells on Black market for $5000

  • Friday, January 18, 2013
  • Nauman Ashraf


  • It is recommended that users should disable the Java program in their Web browsers, because it remains vulnerable to attacks that could result in identity theft and other cyber crimes. Some browsers by default have disabled the JAVA Program. On Sunday, Oracle released a security update that addresses two critical zero-day vulnerabilities in Java that are being actively exploited by attackers, an online vulnerability seller began offering a brand-new Java bug for sale.

    According to a report, a Java exploits was being advertised for $5,000 a piece in an underground Internet forum and the new zero-day vulnerability was apparently already in at least one attacker's hands.

    The thread has since been deleted from the forum indicating a sale has been made, something sure to bring more concern to Oracle.Oracle can’t predict the future, and its engineers obviously can’t predict what exploits are going to be found in its software.

    The most recent hold Java fixed to allow hackers to enter a computer by using compromised websites as the entry-point into Java. Once in the system, they could steal any information, or hook up the computer to a botnet or a string of infected computers that can be used to launch attacks against other computers.

    The exploit is valuable because not only is it usable on the most up-to-date version of Java, which could remain vulnerable for weeks, if not months.
    Read More..

    Tuesday, January 8, 2013

    0

    Facebook password reset vulnerability found by a security researcher

  • Tuesday, January 8, 2013
  • Nauman Ashraf
  • An independent vulnerability researcher, Sow Ching Shiong, found a way to change the password of any facebook username without knowing his last password. Facebook have fixed this very critical vulnerability. This flaw allow an attacker to change any facebook user's password easily.



    Facebook have a recovery page for compromised accounts "https://www.facebook.com/hacked". when clicked, it redirected to another page
    "https://www.facebook.com/checkpoint/checkpointme?f=[userid]&r=web_hacked"
    the parameter f equals to the user id, if any user id is given, password can be changed without any proper authentication.





    The vulnerability was very simple to execute. This vulnerability has been confirmed and patched by Facebook Security Team.
    Read More..

    Saturday, January 5, 2013

    0

    Symantec PGP Desktop Zero Day Vulnerability

  • Saturday, January 5, 2013
  • Nauman Ashraf

  • Symantec product PGP Whole Disk Encryption which is used to encrypt all the contents on the disk on a block-by-block basis having Zero-Day Vulnerability, Exploitation of this issue allows an attacker to execute arbitrary code within the kernel. An attacker would need local access to a vulnerable computer to exploit
    this vulnerability.according to a pastebin note.

    Note was posted on 25th Dec by Nikita Tarakanov, claiming that pgpwded.sys kernel driver distributed with Symantec PGP Desktop contains an arbitrary memory overwrite vulnerability. Affected version of software is Symantec PGP Desktop 10.2.0 Build 2599 (up-to date).

    Symantec confirmed Through a blog post that its a potential issue, but it cannot easily be exploited. Vulnerability is limited to systems running Windows XP and Windows 2003 only. An attacker would need local access to a vulnerable computer to exploit this vulnerability.

    Note posted by Nikita also provide technical details on the issue, that help Symantec encryption engineering team to understand the issue.
     "However, the exploit would be very difficult to trigger as it relies on the system entering an error condition first. Once in this error condition, the exploit could allow an attacker with lower privileges to run some arbitrary code with higher privileges." Kelvin Kwan said.

    Vendor is planning a fix in an upcoming maintenance pack in February.


    Read More..

    Saturday, December 29, 2012

    0

    Hello World

  • Saturday, December 29, 2012
  • Nauman Ashraf
  • In the Name of Allah, the Benificent, the Merciful.

    Hello World ..!!
    Read More..

    Subscribe