Windows XP Users: Careful With That F1 Button!
Microsoft is investigating new public reports of a vulnerability in VBScript that is exposed on supported versions of Microsoft Windows 2000, Windows XP, and Windows Server 2003 through the use of Internet Explorer. Our investigation has shown that the vulnerability cannot be exploited on Windows 7, Windows Server 2008 R2, Windows [...]
Continue reading »Security Alert to www.mtv.co.kr, MySQL Injection
Hi, http://www.mtv.co.kr Webmaster
This is PlanetCreator’s Security Te@am & Hackers Group, PlanetCreator has reported Critical SQL Injection vulnerability on http://www.mtv.co.kr/ Website.
Informed to mtvkorea@mtv.co.kr
Some of your Web’s Data Information are as follow,
Applications: ———- PlanetCreator’s_Universal_Advanced_Internet_Security_T00L
System Time: ———(UTC+08:00) Kuala Lumpur, Singapore, 03/01/2010 5:56:19 AM
Host IP: 222.122.55.12
Web Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.10 with Suhosin-Patch mod_ssl/2.2.8 OpenSSL/0.9.8g
Powered-by: PHP/5.2.4-2ubuntu5.10
DB Server: MySQL [...]
Chinese schools deny Google cyber-attack links
Two Chinese schools have denied the New York Times inform which they were involved in the much-discussed cyber attacks upon Google as good as during slightest 33 alternative outfits sometime last year.
On Thursday, The Times reported which the attacks had been traced to Shanghai Jiaotong University as good as Lanxiang Vocational School, claiming which the [...]
Several avast sites were defaces
Last month, eight sites at once well-known anti-virus solutions avast! Were defaces:
http://www.avast.co.za/ (mirror; date: 2010-01-22 15:06:28)
http://awast.org/ (mirror; date: 2010-02-18 18:57:27)
http://www.avast.de/ (mirror; date: 2010-02-18 18:58:01)
http://shop.avast.de/ (mirror; date: 2010-02-18 18:58:24)
http://www2.avast.de/ (mirror; date: 2010-02-18 18:59:51)
http://partner.avast.de/ (mirror; date: 2010-02-18 19:03:59)
http://demoshop.avast.de/ (mirror; date: 2010-02-18 19:03:14)
http://forum.avast.de/ (mirror; date: 2010-02-18 19:01:33)
Breaking these sites was done by a group of hackers “HcJ & [...]
Selection of tools to automate an attack SQL Injection
sqlmap (http://sqlmap.sourceforge.net/)
Full support: MySQL, Oracle, PostgreSQL and Microsoft SQL Server.
Partially supported: Microsoft Access, DB2, Informix, Sybase and Interbase.
SQL Power Injector (http://www.sqlpowerinjector.com/)
Implemented support for: Microsoft SQL Server, Oracle, MySQL, Sybase / Adaptive Server and DB2.
Absinthe (http://www.0×90.org/releases/absinthe/index.php)
Implemented support for: Microsoft SQL Server, MSDE, Oracle, and Postgres.
bsqlbf-v2 (http://code.google.com/p/bsqlbf-v2/)
Implemented support: MySQL, Oracle, PostgreSQL and Microsoft SQL [...]
Malaysia Government DBKL Web Vulnerability (2nd)
PlanetCreator has reported Critical XSS vulnerability on Official Portal of Kuala Lumpur, Malaysia Web Site,
http://www.planetcreator.net/2009/09/criti…aysia-web-site/
and
http://www.xssed.com/mirror/64058/
but nobody takes action ~~~ How come?
Hello, DBKL’s Staffs! Are you just looking for your license fees? (Yeah- I paid 300RM for my company and 100RM for your Teh Tarik (Coffe` Fees), cos if you don’t pay [...]
Burmese Hackers Hacked Georgia Government’s Web www.moh.gov.ge
Burmese Hackers Group! Named (“BurmeseHackers” or “UnderGround Hackers Group @ ughackersgroup{at}gmail.com”), Hacked Georgia Gorvernment’s Web www.moh.gov.ge ,
Really rare event, cos i’ve never heard about this hackers group before!
They attacked till server’s root, and they put some more screenshots as follow,
Open University Malaysia (OUM)’s Web Vulnerability
PlanetCreator had informed OUM’s XSS Vulnerability
CODE
http://www.planetcreator.net/2009/11/critical-xss-vulnerability-on-open-university-malaysia/
But nobody cares
, How come they all wana do like this so shit! Where is OUM’s Wemaster? Sleeping @ Camp?
Yeah, Hello OUM’s Webmaster!!! Let me remind you again that your Web has MsSQL Vulnerability! Don’t you believe or Don’t you know that?
Let me [...]
Malaysia mymasjid.net.my’s Web Vulnerability, MySQL Injection
PlanetCreator has reported another critical MySQL Injection (vulnerability) on www.mymasjid.net.my
This vulnerability has been alerted to :- Webmaster : azrul.alwi@gmail.com
Applications: ———— PlanetCreator’s_Universal_Advanced_Internet_Securi ty_T00L
System Time: ———— (UTC+08:00) Kuala Lumpur, Singapore, 2/01/2010 10:01:56 PM
Host IP: 202.75.48.131
Web Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 [...]
Download Execution with Java
This tutorial will show you how to use java applets within your website which automatically download and execute your malware onto the visitor’s computer. Some people may of heard about it, some people may know how to do it, but none the less I’m still writing a tutorial for those who [...]
Continue reading »