New User, Welcome!     Login

Next Page >>

Ethical Hacker

Jcow CMS 4.x:4.2 <= , 5.x:5.2 <= | Arbitrary Code Execution

8. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.


9. DISCLOSURE TIME-LINE

2010-06-03: notified vendor

Elgg 1.7.9 <= | Multiple Cross Site Scripting Vulnerabilities

8. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.


9. DISCLOSURE TIME-LINE

2011-06-09: vulnerability reported

McAfee SecurityCenter Privacy Service HTML Execution Vulnerability

http://www.hackerscenter.com/public/images/2.jpg
http://www.hackerscenter.com/public/images/3.jpg



Only becoming a Ethical Hacker, you can stop Black Hat Hackers. Learn with out 
having to pay thousands!- http://kit.hackerscenter.com - The most comprehensive 
security pack you will ever find on the net!



GWExtranet Script Injections & Privilege Escalation Vulnerability

Google: GWExtranet calendar


Only becoming a Ethical Hacker, you can stop Black Hat Hackers. Learn with out having to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security pack you will ever find on the net!



Bitweaver XSS & SQL Injection Vulnerability

Google Dork: Powered by bitweaver



Only becoming a Ethical Hacker, you can stop Black Hat Hackers. Learn with out
having to pay thousands!- http://kit.hackerscenter.com - The most comprehensive
security pack you will ever find on the net!



Omnistar Live Software Cross-Site Scripting Vulrnability

result of code by going /users/tickets.php and "Submit New Ticket"




Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



Default key algorithm in Thomson and BT Home Hub routers

http://conference.hitb.org/hitbsecconf2008dubai/materials/D2T1%20-%20Adrian%20Pastor%20-%20Cracking%20Into%20Embeded%20Devices%20and%20Beyond.zip
(located on the "\BT Home Hub\demo_exploits\Default WEP key cracking\" folder)

* About GNUCITIZEN *

GNUCITIZEN is a Cutting Edge, Ethical Hacker Outfit, Information Think
Tank, which primarily deals with all aspects of the art of hacking.
Our work has been featured in established magazines and information
portals, such as Wired, Eweek, The Register, PC Week, IDG, BBC and
many others. The members of the GNUCITIZEN group are well known and
well established experts in the Information Security, Black Public

Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability

8. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.


9. DISCLOSURE TIME-LINE

2011-01-03: notified Joomla! Security Strike Team regardless of EOL status

Hacking The Interwebs

 http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-5
http://www.gnucitizen.org/blog/hacking-with-upnp-universal-plug-and-play



GNUCITIZEN is a Cutting Edge, Ethical Hacker Outfit, Information Think
Tank, which primarily deals with all aspects of the art of hacking.
Our work has been featured in established magazines and information
portals, such as Wired, Eweek, The Register, PC Week, IDG, BBC and
many others. The members of the GNUCITIZEN group are well known and
well established experts in the Information Security, Black Public

InterWorx-CP Multiple HTML Injections Vulnerabilitie

/siteworx/httpd.php/<Evil-Code>




Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



Default key algorithm in Thomson and BT Home Hub routers

http://conference.hitb.org/hitbsecconf2008dubai/materials/D2T1%20-%20Adrian%20Pastor%20-%20Cracking%20Into%20Embeded%20Devices%20and%20Beyond.zip
(located on the "\BT Home Hub\demo_exploits\Default WEP key cracking\" folder)

* About GNUCITIZEN *

GNUCITIZEN is a Cutting Edge, Ethical Hacker Outfit, Information Think
Tank, which primarily deals with all aspects of the art of hacking.
Our work has been featured in established magazines and information
portals, such as Wired, Eweek, The Register, PC Week, IDG, BBC and
many others. The members of the GNUCITIZEN group are well known and
well established experts in the Information Security, Black Public

Smart-Shop Shopping Cart Cross-Site Scripting Vulrnability

/index.php?page=home&component=basket&command=%3Cscript%3Ealert(document.cookie);%3C/script%3E




Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



phpMyAdmin 3.3.5 / 2.11.10 <= Cross Site Scripting (XSS) Vulnerability

9. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.


10. DISCLOSURE TIME-LINE

08-09-2010: vulnerability discovered

MegaBBS ASP Forum Cross-Site Scripting

Solution: Upgrade to version 2.2



By becoming an Ethical Hacker, you can stop Black Hat Hackers. Learn with out
having to pay thousands! - The most comprehensive security pack you will ever
find on the net! - http://kit.hackerscenter.com



Moovida Media Player version 2.0.0.15 Insecure DLL Hijacking Vulnerability (libc.dll,quserex.dll)

9. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.


10. DISCLOSURE TIME-LINE

08-28-2010: vulnerability discovered

Jcow CMS 4.2 <= | Cross Site Scripting

8. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.


9. DISCLOSURE TIME-LINE

2010-06-03: notified vendor

IPortalX Forums Cross-Site Scripting Vulnerability

http://www.google.com/search?hl=en&q=%2Fforum%2Flogin_user.asp%3FRedirect%3D%2F&btnG=Google+Search



Only becoming an Ethical Hacker, you can stop a hacker. Were can you learn with out 
having to pay thousands!- http://kit.hackerscenter.com - The most comprehensive  
security pack you will ever find on the net!




CFP for HITBSecConf2008 - Dubai now open

The CFP for HITBSecConf2008 - Dubai is now open.

Our 2008 event is expected to attract over 300 attendees from around the
EMEA region and will see keynote speakers Bruce Schneier (Founder and
CTO, BT Counterpane) and Jeremiah Grossman (Founder and CTO, White Hat
Security). The event is supported and endorsed by the UAE
Telecommunications and Regulatory Authority.

Being a deep-knowledge technical conference, talks that are more
technical or that discuss new and never before seen attack methods are

DeskPRO Admin Panel Multiple HTML Injections

/admincp/fields_faq.php

/admincp/user_help.php


Only becoming an Ethical Hacker, you can stop a Hacker. Learn Security with out
having to pay thousands!- http://kit.hackerscenter.com - The most comprehensive
security pack you will ever find on the net!



eGov Content Manager Cross Site Scripting Vulrnability

Google Search: (Center.exe) 

http://www.google.com/search?hl=en&q=ext%3Aexe+inurl%3A%28center%29&btnG=Search


Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



[HSC] Dokeos Multiple Cross-Site Scripting Vulnerabilities

google:allinurl:"/auth/lostPassword.php"



Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



Boinc Forum Cross Site Scripting Vulrnability

http://www.google.com/search?hl=en&q=Powered+by+BOINC&btnG=Search




Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



Re: 2Wire Broadband Router Session Hijacking Vulnerability

This should show the firmware/router manufactures the need for more real
world testing before deployment as well as allowing for patching via the
ISP or at least allow the user to update the firmware easily.

Thanks for all the hard work, YGN Ethical Hacker Group. Good job and
keep it up.

Mike Duncan
ISSO, Application Security Specialist
Government Contractor with STG, Inc.

Maxthon Browser version 2.5.15.1000 Insecure DLL Hijacking Vulnerability (dwmapi.dll)

9. CREDIT

This vulnerability was discovered by Aung Khant, http://yehg.net, YGN
Ethical Hacker Group, Myanmar.


10. DISCLOSURE TIME-LINE

08-28-2010: vulnerability discovered

PHP-Nuke 8.x <= "chng_uid" Blind SQL Injection Vulnerability

http://phpnuke.org/


8. CREDIT

Aung Khant, http://yehg.net, YGN Ethical Hacker Group, Myanmar.


9. DISCLOSURE TIME-LINE

2011-01-01: contacted author through emails

DNewsWeb Softwares Cross Site Scripting Vulrnability

http://www.google.com/search?hl=en&q=ext%3Aexe+inurl%3A%28%7Cdnewsweb.exe%7C%29&btnG=Search



Only becoming a Ethical Hacker, you can stop a Hacker. Learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



Default key algorithm in Thomson and BT Home Hub routers

http://conference.hitb.org/hitbsecconf2008dubai/materials/D2T1%20-%20Adrian%20Pastor%20-%20Cracking%20Into%20Embeded%20Devices%20and%20Beyond.zip
(located on the "\BT Home Hub\demo_exploits\Default WEP key cracking\" folder)

* About GNUCITIZEN *

GNUCITIZEN is a Cutting Edge, Ethical Hacker Outfit, Information Think
Tank, which primarily deals with all aspects of the art of hacking.
Our work has been featured in established magazines and information
portals, such as Wired, Eweek, The Register, PC Week, IDG, BBC and
many others. The members of the GNUCITIZEN group are well known and
well established experts in the Information Security, Black Public

[ACM, Ariadne Content Manager] unauth. SQL injection + user enumeration

Best whises for a happy and secure new year ;)
-- 
Andrea Purificato
Ethical Hacker & Security Specialist
http://www.purificato.org
http://rawlab.mindcreations.com



Oracle Portal XSS fixed by CPU July 2008

Regards,
-- 
Andrea Purificato

Ethical Hacker @ Unidata S.p.A.
http://rawlab.mindcreations.com



CFP for HITBSecConf2008 - Dubai now open

The CFP for HITBSecConf2008 - Dubai is now open.

Our 2008 event is expected to attract over 300 attendees from around the
EMEA region and will see keynote speakers Bruce Schneier (Founder and
CTO, BT Counterpane) and Jeremiah Grossman (Founder and CTO, White Hat
Security). The event is supported and endorsed by the UAE
Telecommunications and Regulatory Authority.

Being a deep-knowledge technical conference, talks that are more
technical or that discuss new and never before seen attack methods are

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!