Results for "vulnerable"
Wordpress Plugin Easy Comment Uploads Vulnerability
Wordpress as you might know is one of the most widely used blogging platforms, As a reason of which it has became the favorite target of hackers. Wordpress itself is quite secure, however the plugins make it unsecure resulting in hack attacks, data loss etc, when they are created the developers do not think of the security or do not know how to write the secure code, hence skipping lots of necessary checks making the plugins vulnerable to attacks like SQLInjetion, Remote File inclusion etc.

One of those popular vulnerable plugin is Easy Comment Upload plugin, The version 0.61 and prior versions are affected with Arbitrary File Upload Vulnerability. The plugin fails to check the upload file type as a reason of which it can be exploited by uploading a Phtml file.


Easy Comment Upload plugin

Wordpress Plugin Easy Comment Uploads Vulnerability

There are thousands of wordpress blogs still vulnerable to this attack. The vulnerability can be fixed by updating the wordpress easy comments plugin to version 0.71.

If you want to know more about Protecting your wordpress blog from hackers you can refer the following posts, If you still think your blog is vulnerable drop me an email and I will perform a security assessment on your blog. via | rafayhackingarticles

takecy 1/20/2012
DNS Cache Poisoning Attack on Google, Yahoo, Apple
DNS Cache Poisoning Attack on Google,  Yahoo, Apple

Hacker with nickname AlpHaNiX deface Google, Gmail, Youtube, Yahoo, Apple etc domains of Democratic Republic of Congo. Hacker use strategy so-called DNS cache poisoning.

DNS cache poisoning is a security or data integrity compromise in the Domain Name System (DNS). The compromise occurs when data is introduced into a DNS name server's cache database that did not originate from authoritative DNS sources. It may be a deliberate attempt of a maliciously crafted attack on a name server.

DNS Cache Poisoning Attack

Hacked websites are :

  • http://apple.cd/
  • http://yahoo.cd/
  • http://gmail.cd/
  • http://google.cd/
  • http://youtube.cd/
  • http://linux.cd/
  • http://samsung.cd/
  • http://hotmail.cd/
  • http://microsoft.cd/

takecy 12/06/2011
ExploitMe Mobile Vulnerable Android and iPhone
The application contains both mobile web and mobile programming defects and we've outlined a set of labs and solutions online to guide you. This tool will help both mobile QA and mobile web developers to learn the kinds of weaknesses that exist in the mobile app space. 

What you're able to learn using ExploitMe Mobile: 

[+] Parameter manipulation of traffic
[+] Insecure communications
[+] Weak password lock screens
[+] Insecure memory management
[+] Weak file system permissions
[+] Insecure storage of files
[+] Insecure logging of information

You can find the full blog overview here with source code links: 

ExploitMe Android Lab setup and walkthroughs:

ExploitMe iPhone Lab setup and walkthroughs:

ExploitMe Mobile Vulnerable Android and iPhone (via)

takecy 10/26/2011
Nod32 Eset Website Hacked
Nod32 Eset website hacked
Nod32 Eset Website Hacked |Nod32 and Eset Thailand Websites hacked by Turkey Cyber Army . ESET NOD32 Antivirus, commonly known as NOD32, is an antivirus software package made by the Slovak company ESET. ESET NOD32 Antivirus is sold in two editions, Home Edition and Business Edition. The Business Edition packages add ESET Remote Administrator allowing for server deployment and management, mirroring of threat signature database updates and the ability to install on Microsoft Windows Server operating systems.You Can see the Defaced websites Mirror : Nod32 and Eset. (via)

Unknown 10/14/2011
New XSS Vulnerability found on Sony PlayStation
New XSS Vulnerability found on Sony PlayStation

New XSS Vulnerability found on Sony PlayStation by c7-elixir - The C7 Crew | YES ! Sony is still Vulnerable to various bugs like XSS. Today a hacker c7-elixir from The C7 Crew has expose new XSS attack on Sony PlayStation's Website as shown. Sony got hacked 20 times in last two months by number of hackers from all over world. One more REQUEST to Sony : FIX IT BOSS !

Vulnerable Link

Unknown 6/22/2011