XNUXER.OR.ID





XNUXER


Xnuxer Research Laboratory of Internet Security and Open Source

www.xnuxer.or.id - we are concern to research technology about internet security and open source
 WebDAV Detection, Vulnerability Checking  
The WebDAV implementation in Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder.
Reviews (3)  Read more
 
 Bypassing Anti-Virus with Metasploit  
This video from John Strand shows how to bypass anti virus tools utilizing the new tricks in Metasploit 3.2
Reviews (2)  Read more
 
 Deploying Metasploit's Meterpreter with MITM and an Ettercap filter  
In this video, Bigmac shows how to redirect web traffic and trick users into downloading Meterpreter and running it on their box.
Reviews (2)  Read more
 
 Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via "Man in the Middle"  
In this video IronGeek'll be showing how Cain can pull off a "Man in the Middle" attack against the Remote Desktop Protocol. While RDP versions 6.0 and later are less susceptible to these attacks because of the verification schemes added, there is still a risk since so many users just click yes to all warning messages.
Reviews (1)  Read more
 
 BeEF: Browser Exploitation Framework XSS Fun  
John Strand of Black Hills Security sent me another awesome video on using BeEF, cross site scripting and
other fun.
Reviews (1)  Read more
 
 Using Metasploit to create a reverse Meterpreter payload EXE by John Strand  
John Strand of Black Hills Security sent me an awesome video on using Metasploit to create an EXE with the Meterpreter payload that creates a reverse TCP connection outbound, blowing through many NAT boxes and firewalls. This goes great with a previous video I did on EXE Binders/Joiners.
Reviews (1)  Read more
 
 John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008  
John Strand gave this presentation for the Kentuckiana ISSA at the Louisville Infosec 2008 conference. He gives a fascinating talk about why "security in depth" is dead, and lives again. John then goes on to demo Evilgrade, using msfpayload and obscuring it against signature based malware detection, dumping SAM hashes with the Metasploit Meterpreter and using a patched Samba client to pass the hash and compromise a system. I'd like to thank John for letting me record his talk.
Reviews (1)  Read more
 
 Weak Hashing Algorithms: Outlook PST file CRC32 password cracking example  
In this tutorial, I'll be giving an example of why weak hashes are bad. The example I'll be using is the CRC32 hash that Outlook uses to store a PST archive's password with. The CRC32 algorithm as implemented by Microsoft Outlook is easy to generate hash collisions for, so even if you can't find the original password you can find an alternate one that works just as well.
Reviews (1)  Read more
 
 Problems with HTTP Authentication  

The HTTP protocol offers us a challenge-response authentication mechanism which can be used by a Web or proxy server to grant or refuse access to resources on the network.

Nowadays, the Net is witness to millions of transactions, as well as providing both public and confidential data. The network makes it all possible, but in order to maintain security we must know who has got access to our sensitive data and who can perform privileged operations.

Reviews (1)  Read more
 
 Google Tricks and hacks *UPDATED*  
Google.com is undoubtedly the most popular search engine in the world. It offers multiple search features like the ability to search images and news groups.However it's true power lies in it's powerful commands that can be used and misused.I am writing this article on the basis of my experience using google and trying out ideas when i am bored.Now enough of lecturing...let's get down to business ;)
Reviews (1)  Read more
 

Welcome

Welcome to XNUXER.OR.ID, by visit our site we like to help you to get main information about internet security and opensource so dont forget to update your knowledge every time using our website.

Archives

To access file download or private information here you must register, please register here.

The Best News - Top 10

Calendar

«    February 2012    »
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
 

Site Statistics

Top Contributors:
  1    webmaster 166


Articles:
  This Hour: 0
  Today: 0
  This Month: 0
  All Time: 164


Membership:
  Registered Today :17
  This Hour:0
  This Month:332
  Total:4539
  Banned:0

Site Survey

What do you think about our website?

Excellent
Good
Fair
Poor
Bad

Security Tracker

Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability
Pligg CMS 'status' Parameter SQL Injection Vulnerability

Vuln: Joomla! Multiple Information Disclosure Vulnerabilities
Joomla! Multiple Information Disclosure Vulnerabilities

Vuln: QEMU KVM CVE-2012-0029 Local Privilege Escalation Vulnerability
QEMU KVM CVE-2012-0029 Local Privilege Escalation Vulnerability

Vuln: Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability
Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability

Bugtraq: [ MDVSA-2012:013 ] mozilla
[ MDVSA-2012:013 ] mozilla

Visitor


Translator

Whois Info

IP