Re: [Full-disclosure] GeoIPgen version 0.4 released - country-to-IPs generator

2010-03-10 Thread Adrian P
On Tue, Mar 9, 2010 at 5:17 AM, Andrew Horton and...@morningstarsecurity.com wrote: I've just released a new version of GeoIPgen Description: GeoIPgen is a country-to-IPs generator. It's a geographic IP generator for IPv4 networks that uses the MaxMind GeoLite Country database. Geoipgen is

Re: [Full-disclosure] Chuck Norris Botnet and Broadband Routers

2010-02-24 Thread Adrian P.
It's no secret that there are tons of broadband routers/modems with exposed admin interfaces (HTTP/SSH/Telnet/whatever) using default/weak credentials. While the Chuck Norris botnet is interesting in that it shows that the problem is real, it shouldn't surprise anyone who has researched the

Re: [Full-disclosure] Netgear DG632 Router Remote DoS Vulnerability

2009-06-17 Thread Adrian P
3APA3A, I was actually *agreeing* with you! lols. I think something got lost in translation! Sorry if I confused anyone really. Good luck. 2009/6/17 Vladimir '3APA3A' Dubrovin 3ap...@security.nnov.ru: Adrian,  If  you  can execute javascript - what is a reason to wait for user to  click  

Re: [Full-disclosure] Universal Website Hijacking by Exploiting Firewall Content Filtering Features + SonicWALL firewalls 0day

2008-10-31 Thread Adrian P
. 2008/10/31 Adrian P [EMAIL PROTECTED]: Hello folks, Yesterday, I presented for the first time [1] a new method to perform universal website hijacking by exploiting content filtering features commonly supported by corporate firewalls. I briefly discussed [2] the finding on GNUCITIZEN

Re: [Full-disclosure] Universal Website Hijacking by Exploiting Firewall Content Filtering Features + SonicWALL firewalls 0day

2008-10-31 Thread Adrian P
just said it was a recent (or as you might put it, *recent*) example of this type of vulnerability. I've this sort of vuln myself with client software and so has a number of other people I know. Glad to see the majority of your email is completely irrelevant. 2008/11/1 Adrian P [EMAIL

[Full-disclosure] Universal Website Hijacking by Exploiting Firewall Content Filtering Features + SonicWALL firewalls 0day

2008-10-30 Thread Adrian P
Hello folks, Yesterday, I presented for the first time [1] a new method to perform universal website hijacking by exploiting content filtering features commonly supported by corporate firewalls. I briefly discussed [2] the finding on GNUCITIZEN in the past without giving away the details, but

Re: [Full-disclosure] www.dia.mil

2008-10-29 Thread Adrian P .
Welcome to the web! 1 website = content retrieved from dozens/hundreds of sites. Much more than what the browser's address bar shows ;) Think of ad banners, analytics JS (legit spyware), static content served from high-speed embedded httpds, etc ... And yes, there are security implications

Re: [Full-disclosure] Exploring the UNKNOWN: Scanning the Internet via SNMP!

2008-03-04 Thread Adrian P
, Adrian P wrote: * Exploring the UNKNOWN: Scanning the Internet via SNMP! * http://www.gnucitizen.org/blog/exploring-the-unknown-scanning-the-internet-via-snmp/ Hacking is not only about coming up with interesting solutions to problems, but also about exploring the unknown

[Full-disclosure] Exploring the UNKNOWN: Scanning the Internet via SNMP!

2008-03-03 Thread Adrian P
* Exploring the UNKNOWN: Scanning the Internet via SNMP! * http://www.gnucitizen.org/blog/exploring-the-unknown-scanning-the-internet-via-snmp/ Hacking is not only about coming up with interesting solutions to problems, but also about exploring the unknown. It was this drive for knowledge

[Full-disclosure] BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP

2008-01-10 Thread Adrian P
http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-5 It's known that UPnP [1] is inherently insecure for a very simple reason: administrative tasks can be performed on a Internet Gateway Device (IGD) without needing to know the admin password whatsoever! This on its own is quite

Re: [Full-disclosure] authentic hackers still do it for the love ... (was: Hell Camp: It never pays enough)

2007-12-03 Thread Adrian P
Hi folks! Just wanted to say that it IS possible to make good money and have fun breaking security. Lots of security researchers out there are offered very generous positions which sometimes allows them to work from home. In many of these positions the researcher chooses what to break, and the

Re: [Full-disclosure] Wordpress Cookie Authentication Vulnerability

2007-11-21 Thread Adrian P
comment inline ;) On Nov 20, 2007 8:23 PM, Steven Adair [EMAIL PROTECTED] wrote: Right this problem has existed for a long time, but it's not the end of the world for someone to point it out again I suppose. I think it's obvious that there's another main issue here and that's the way

[Full-disclosure] BT Home Flub: Pwnin the BT Home Hub - Vulnerabilities details published

2007-11-11 Thread Adrian P
Remote assistance now appears to be disabled. That definitively gets rid of the worst threat: backdooring the Home Hub router by enabling remote access permanently (could be done by editing the config file). Telnet has also been disabled, and the contents of the config file is now

Re: [Full-disclosure] Gmail 0day

2007-11-09 Thread Adrian P
Hello Juergen, With all my respect, is it that hard to see that gaining access to a Gmail session can lead to your identity being stolen? Nowadays your webmail account means your online life/presence. Let's have a walk through attack shall we? 1. Your Gmail session is hijacked (i.e.: via the

Re: [Full-disclosure] gnucitizen bt home hub latest, attacks wide spread, outages reported

2007-10-12 Thread Adrian P
Hi guys, I just have a few comments for the sake accuracy. On 10/12/07, Valery Marchuk [EMAIL PROTECTED] wrote: gnucitizen may be responible for bt being under a massive attack right now. Oh my God, people stop talking nonsense! Have you seen the video provided by gnusitizen.org with

[Full-disclosure] BT Home Flub: Pwnin the BT Home Hub

2007-10-08 Thread Adrian P
http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub The BT Home Hub, which is probably the most popular home router in the UK, is susceptible to critical vulnerabilities. BT's plan is to sneak one of this boxes into every UK home. Not only does the BT Home Hub support broadband but

[Full-disclosure] Owning Big Brother: How to Crack into Axis IP cameras

2007-09-27 Thread Adrian P.
We found multiple vulnerabilities on Axis 2100 IP cameras affecting both old firmware versions and the latest firmware (2.43). The research is made of two components: a purple paper and a video. The research doesn't just cover boring PoCs, but actual Hollywood-style exploits :-). Yes, this

[Full-disclosure] 2 vanilla XSS on Wordpress ‘ wp-register.php’

2007-09-21 Thread Adrian P
There are two vanilla XSS on 'wp-register.php'. Only versions =2.0.1 appear to be affected. More info can be found on GNUCITIZEN's BlogSecurity: http://blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/ Regards, -- pagvac gnucitizen.org, ikwt.com