logisticslog.blogspot.com
Logistics Log: 4/12/09 - 4/19/09
http://logisticslog.blogspot.com/2009_04_12_archive.html
Friday, April 17, 2009. Tidal-Power System Hits Record Output. Http:/ link.brightcove.com/services/player/bcpid1827871101? Tidal-Power System Hits Record Output. Marine Current Turbines' SeaGen system quadruples the world tidal-turbine power record. Tuesday, January 06, 2009. MCT's power peak is four times the global record for a tidal-stream system set by the company in 2004, according to U.K.-based renewables journal. An artist's impression of MCT's SeaGen. Meanwhile, the U.K. While at a considerably e...
securedeath.com
SecureDeath[d0t]com: phpBB.com 0wn3d!!!
http://www.securedeath.com/2009/02/phpbbcom-0wn3d.html
What You Dont Know May Hurt You :. Monday, February 2, 2009. Message from phpBB.com :. We are sorry to report that we have been attacked through a vulnerability in an outdated PHPList installation. phpBB.com and related sites will remain unavailable while we work to recover. No vulnerabilities have been found in the phpBB software itself. You can download phpBB here: http:/ www.ohloh.net/p/phpbb. You can get support at the temporary support forums. Or on IRC: chat.freenode.net #phpbb. 8211; the phpBB team.
securedeath.com
SecureDeath[d0t]com: April 2009
http://www.securedeath.com/2009_04_01_archive.html
What You Dont Know May Hurt You :. Wednesday, April 22, 2009. Format string and .dtors section. وطريقه استغلالها بشكل متطور format string بتكلم اليوم عن ثغرات. Printf ثغرات الفورمات سترينق تكون في دوال. Printf, fprintf, sprintf, snprintf, vprintf, vfprintf, vsprintf, vsnprintf. المستخدم في داله stringوهي عباره عن غلطات او هفوات المبرمجين , عند استخدامهم لهذي الدوال من غير تعريف ال. هناك انواع كثيره من الفورمات باراميترز مثل:. Unsigned hexadecimal للقرائه من الميموري بصيغة x%. للكتابه على الميموري n%.
securedeath.com
SecureDeath[d0t]com: April 2010
http://www.securedeath.com/2010_04_01_archive.html
What You Dont Know May Hurt You :. Tuesday, April 13, 2010. Bypass PlayStation 3 update for linux users. Sony release PS3 frimware update 3.21 which remove OtherOS feature, may PS3 users install linux on their PS3, if they install this FW update they will not be able to use their linux, but if they didn't install the update they will not be able to login to PSN (PlayStation Network) and play online games. So we are going to bypass this update and login to PSN with the old FW 3.15. Dest=83;CompatibleSyste...
securedeath.com
SecureDeath[d0t]com: Format string & .dtors section
http://www.securedeath.com/2009/04/format-string-dtors-section.html
What You Dont Know May Hurt You :. Wednesday, April 22, 2009. Format string and .dtors section. وطريقه استغلالها بشكل متطور format string بتكلم اليوم عن ثغرات. Printf ثغرات الفورمات سترينق تكون في دوال. Printf, fprintf, sprintf, snprintf, vprintf, vfprintf, vsprintf, vsnprintf. المستخدم في داله stringوهي عباره عن غلطات او هفوات المبرمجين , عند استخدامهم لهذي الدوال من غير تعريف ال. هناك انواع كثيره من الفورمات باراميترز مثل:. Unsigned hexadecimal للقرائه من الميموري بصيغة x%. للكتابه على الميموري n%.
armyz.wordpress.com
La chiave privata di PayPal? Pubblica! | ArMyZ's
https://armyz.wordpress.com/2009/10/09/la-chiave-privata-di-paypal-pubblica
Laquo; IE: nuovi allarmi zero day. La chiave privata di PayPal? 9 October 2009 by armyz. Man in the middle – fonte OWASP –. Dopo alcuni mesi ( Moxie Marlinspike. Defcon e Blackhat) si riparla di una vulnerabilità alle implementazioni SSL (API crittografiche) che, di fatto, prestano il fianco ad un attacco di tipo man in the middle nonchè a tecniche di phishing. Perchè se ne riparla. Dopo poco più di due mesi? E’ proprio di questi giorni la pubblicazione di un certificato (e chiave privata). Se tale firma...
securedeath.com
SecureDeath[d0t]com: Create your own socks5 proxy
http://www.securedeath.com/2009/01/create-your-own-socks5-proxy.html
What You Dont Know May Hurt You :. Sunday, January 18, 2009. Create your own socks5 proxy. Do you know that you can create your own socks5 proxy with just one command:. Ssh -f -N -D 5050. F -N option is just to run ssh in background, the important option is -D. Specifies a local "dynamic" application-level port forwarding. This works by allocating a socket to listen to port on the local side. For windows users they can do it with putty. C: putty.exe -ssh. USERNAME"@SSHserver.com -pw "PASSWORD". I am very...
securedeath.com
SecureDeath[d0t]com: January 2009
http://www.securedeath.com/2009_01_01_archive.html
What You Dont Know May Hurt You :. Thursday, January 29, 2009. Some Hackers they gain root privilege on a secure server but they can't install rootkit or backdoor, so what to do? Actually they can login any time to the server without known the root password! By using RSA or DSA private key to login. Copy the public key " /etc/ssh/ssh host dsa key.pub. To " /.ssh/authorized keys. Cp /etc/ssh/ssh host dsa key.pub /.ssh/authorized keys. Chmod 600 /.ssh/authorized keys. To your machine with chmod 600. P 22 -...
securedeath.com
SecureDeath[d0t]com: مخاطر SUID & syscall
http://www.securedeath.com/2009/04/suid-syscall.html
What You Dont Know May Hurt You :. Tuesday, April 14, 2009. مخاطر SUID and syscall. هناك غلطات برمجيه يقع فيها كثير من المبرمجين , وهي انهم يقومون بوضع الملفات التنفيذيه في دوال. بدون تحديد مسارها " System Call. مثلا عندنا هذا الكود. للوهله الاولى بتقول الكود سليم ومافيه شي, ومافي مجال لاستغلاله. بس كل شي ممكن في اللينكس, الثغره هذي انك ممكن تلعب على مسارات البحث. بتشوف المسارات الي يبحث فيها الشل الي انته تستخدمه مثلا "الباش" عن البرامج والملفات. مثلا اذا كتبت الامر. بتشوف مساره , مثلا. Sys exp.c -o.