Tuesday, June 29, 2010

Sweetness beta 0.8 released

This release has better message formatting, and set up relationships for full archiving. If you already have an older version installed, there is no need to download the update, it should get pushed to your system soon.

DOWNLOAD: HERE

Sunday, June 27, 2010

Messing around with CVE-2009-1299

CVE-2009-1299:

The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.

So what happens? well first touch /home/$user$/test.txt, then make a symlink in the tmp dir called .esd-0 "0 is the uid for root" to /home/$user$/test.txt. now sudo su and run pulseaudio. exit your root shell and check out /home/$user$/test.txt and you will see its ownership has changed from the user you created it under to root:root.

The worst you could do with this little guy is DoS the server and maybe have a little fun :D

Sunday, June 13, 2010

iPillage

iPillage is a chrome extension that scans any page you are browsing for SQL injection, Local file injection. It has useful information gathering tools like reverse DNS, hashing, and more!

DOWNLOAD: HERE
Report bugs and stuff: HERE

Wednesday, June 9, 2010

Sweetness beta 0.7 released

Fixed a few rendering bugs and made a few cosmetic changes as well. If you already have an older version installed, there is no need to download the update, it should get pushed to your system soon.

DOWNLOAD: HERE

Friday, June 4, 2010

Stuff of the week.

Here is a list of cool/fun stuff i found this week.

A reminder that CSRF affects more than websites - READ IT HERE

Flag execution for easy local privilege escalation. - READ IT HERE

Cross Site URL Hijacking by using Error Object in Mozilla Firefox. - READ IT HERE

Thursday, June 3, 2010

Sweetness info video

Here is a nice little vid i made, its a howto for installing, setup and use of Sweetness

Check it out HERE

Tuesday, June 1, 2010

Getting your Gmail ID for Sweetness.

In order for Sweetness to operate you need to provide it with some vital information, like you sugar username, password, and server address but it also asks for something called a GMail ID. Getting your GMail ID is nice and easy, just access your gmail account and goto any email, then on the right hand side of the page look for the "Print all" link and click it. It should take you to a URL similar to this:
https://mail.google.com/mail/?ui=2&ik=g56532809b&view=pt&search=inbox&th=132h510466b7hb5f

Your GMail ID is the "ik=xxx..." part of the above url so in this case your GMail ID would be:
g56532809b