cjchamberland.com
Joomla index.php redirects to lyblynoski.isa-geek.com - CJ Chamberland
http://cjchamberland.com/joomla-index-php-redirects-lyblynoski-isa-geek-com
Web Security and Malware Research. Raquo; Malware Analysis. Raquo; Joomla index.php redirects to lyblynoski.isa-geek.com. Joomla index.php redirects to lyblynoski.isa-geek.com. January 15, 2014. Laquo; Zopim.com compromised – using social engineering. Clickjacking and Frame breakout. Formtoemail (free email form) – XSS. Removing Malware from your wordpress database. WordPress soaksoak.ru – swfobject.js hides a secret. I ordered my groceries from Shipt! Use my link and get $10 back when you sign up!
cjchamberland.com
August 2014 - CJ Chamberland
http://cjchamberland.com/2014/08
Web Security and Malware Research. Your Elance account is under review – what the don’t really want you to know…. So yesterday, like many others I was reading my email and got an interesting one from Elance: “Hello, We’re writing because a routine system review of your account identified an unusually high number of disputes, client concerns, poor feedback, or evidence of moving work off the platform. As. Continue reading ». August 30, 2014. Formtoemail (free email form) – XSS. August 13, 2016 1:38 am.
cjchamberland.com
Clickjacking and Frame breakout - CJ Chamberland
http://cjchamberland.com/clickjacking-frame-breakout
Web Security and Malware Research. Raquo; Malware Analysis. Raquo; Clickjacking and Frame breakout. Clickjacking and Frame breakout. There are three options for the X-Frame-Options headers:. Which will prevent ALL domains from framing the content. Only allows the current domain to frame the content. Below are some examples on how to configure this:. First – at the highest level, Apache can be configured to prevent this by adding the following by adding it to your server or local config:. Another option i...
cjchamberland.com
Decoding a Shell - CJ Chamberland
http://cjchamberland.com/decoding-a-shell
Web Security and Malware Research. Raquo; Malware Analysis. Raquo; Decoding a Shell. Original filename: zt.php. If you just executed the file, you simply see a password prompt – this indicates that it’s more than likely some type of php shell. To find out what it does, we have to de-obfuscate it. First pass with str rot13 returns the following:. So to get a little further, we do a dump of the gzinflate(base64 decode(str rot13($code) ) and get this:. December 4, 2013. Laquo; Workin on it!
cjchamberland.com
December 2013 - CJ Chamberland
http://cjchamberland.com/2013/12
Web Security and Malware Research. Zopimcom compromised – using social engineering. Yes, folks – people still get social engineered. Below is a copy of the email we received on December 11, 2013: Your personal data may have been accessed What happened? A few hours ago, one of our support staff’s workstation was compromised through a social engineering attack. The. Continue reading ». December 11, 2013. It checks to see if the user is logged in,. Continue reading ». December 10, 2013. December 4, 2013.
cjchamberland.com
Sneaky code injection - CJ Chamberland
http://cjchamberland.com/sneaky-code-injection
Web Security and Malware Research. Raquo; Malware Analysis. Raquo; Sneaky code injection. Found this nugget the other day while cleaning out a wordpress site. It was put in a file called ‘widget-footer.php’ which was a part of their wordpress theme:. So, you may be asking – what does it do? December 10, 2013. Laquo; Decoding a Shell. Zopimcom compromised – using social engineering. Formtoemail (free email form) – XSS. Removing Malware from your wordpress database. I ordered my groceries from Shipt!
cjchamberland.com
January 2014 - CJ Chamberland
http://cjchamberland.com/2014/01
Web Security and Malware Research. Clickjacking and Frame breakout. I have had a few clients ask about their sites being framed to load on other sites without their permission and if their is anything they can do about it. Attackers sometimes do this in “Phishing” attempts. Visitors think they are going to the legitimate site, when in. Continue reading ». January 26, 2014. Joomla index.php redirects to lyblynoski.isa-geek.com. Continue reading ». January 15, 2014. Formtoemail (free email form) – XSS.
cjchamberland.com
Wordpress soaksoak.ru - swfobject.js hides a secret - CJ Chamberland
http://cjchamberland.com/wordpress-soaksoak-ru-swfobject-js-hides-secret
Web Security and Malware Research. Raquo; Malware Analysis. Raquo; WordPress soaksoak.ru – swfobject.js hides a secret. WordPress soaksoak.ru – swfobject.js hides a secret. Today I came across a nasty little booger. It’s added to the wp-includes/swfobject.js file and they used the wp-includes/tempate-loader.php to load it. 8211; let the pros deal with it. December 15, 2014. Laquo; Your Elance account is under review – what the don’t really want you to know…. Removing Malware from your wordpress database.
cjchamberland.com
About Me - CJ Chamberland
http://cjchamberland.com/about-me
Web Security and Malware Research. Raquo; About Me. Nothing here to see yet. Move along young grasshopper…. January 6, 2014. Formtoemail (free email form) – XSS. Removing Malware from your wordpress database. WordPress soaksoak.ru – swfobject.js hides a secret. Your Elance account is under review – what the don’t really want you to know…. I ordered my groceries from Shipt! Use my link and get $10 back when you sign up! August 13, 2016 1:38 am. August 11, 2016 3:01 am. Went to #defcon.