Thursday, March 31, 2011

Ice Cream Oxidizing Emulsion Cream

Blind MySQL Faster Bit Shifting Using Injection SQL Injection Attack



This news came out yesterday in the journal of "A day" and really made me laugh xD So I reply here.
 




attack the MySQL website through a SQL injection


The MySQL website has been under attack through a vulnerability Blind SQL injection. This is a bug in the web application code and not the database.

 MySQL database is a popular open source database. MySQL is owned by Oracle after the acquisition of Sun, its former owner. 


The attack is attributed to TinKode and Ne0h Slacker.Ro Romanian group. The extracted data have been published on the site pastebin.com, something usual in this type of exploit.

addition
attackers main site countered the attack in localized versions of MySQL.com. In particular the French, German, Italian and Japanese.

The data presented correspond to the credentials of the users of the MySQL server and dump the database of the site. Among the credentials can be seen usernames, hashed passwords, emails and addresses.

Some of the hashes have also been published in the clear because they were so simple that the attackers probably took them little time to find your mail using brute force with rainbow tables. Surprisingly (or not) seen as weak passwords as a simple 4 digit number for the administrator account.

It so happens that the MySQL site already contained a vulnerability to cross-site scripting is active. This vulnerability was made public via twitter last January and still not be solved.
Source:
http://www.hispasec.com/unaaldia/4538 uploads data to pastebin that mention can be found here:
 
http://pastebin.com/BayvYdcP

A greeting ... soon.

Tuesday, March 29, 2011

Ap Bio Hardy-weinberg Lab

the MySQL Web Spam blogger

Hi, I want to tell you about something that probably has happened to everyone from the first day we connect to the Internet: SPAM!
Yes, there is nothing new. It so happens that today, while checking whether there were any new comment on the blog, I found they had two different people and published around the same time (a few minutes after the other). Where only expressed what they had found useful information. Oops ... What is not cool?
 

I find it strange, because normally there is a comment every 2 weeks and exaggerating. So I started to see the profile of those who commented. I clicked on the user's name and great was my surprise when I opened the website of a company that manufactures plastic bags "Weird no? Then I did the same thing with the other comments and this time he knocked on the website of another company that a. .. How well do you understand this?

"... is a Colombian company with over 18 years of experience in the field of Computer Systems. For over 6 years we advise our clients in the design and assembly of its Web sites, and now we have specialized in administration, Positioning, Promotion and Marketing Web pages (SEO). " A and ... SEO ... the note to increase the pagerank of a website and that ... And how do ah?
 
I took a look at your client list ... and what happened was the company that makes plastic: O

was evident, were using the comments in this blog to add links to other pages and improve your ranking in search engines. That's what is known as Spamdexing . http://es.wikipedia.org/wiki/Spamdexing
The question is: How did they do that? Blogger allows 4 ways to restrict who can and can not comment on a blog: only members, Google account users, registered users and any user. As you can see the first 3 options require that the user is registered or log on to something while the latter does not. In order not to embarrass his followers, many bloggers use the last option, that is, anyone can comment. When a blog is configured with this option, when posting a comment will show the following:
 


Fig 1. - Options for comment.
 


If you select the option "Name / URL" will appear with a form to put any name and a URL to be referenced by that name.
 


Fig. 2 - Option Name / URL. Then we just have to write something like "very good info ..."," excellent post ... " etc. xD The source code of the commentary would be like this:
 


Fig. 3 - source code comment.
 

Although, as you can see, is marked with
attribute rel = 'nofollow'
used to that search engines do not take into account the link, no SEO experiments confirm that Google actually If you follow those links though probably not the same value. Read more at:

http://www.visitas-web.com/2008/02/nofollow.html

Now, if I wanted to do this to help rank web somewhere, ask me How do I find blogs with these settings ? For in this also helps Google. It happens that along with the "Name / URL" is set to discuss other anonymous user. This option makes the comment
start with something like "Anonymous said ..."


Fig. 4 - Búsqueda en español.



Fig. 5 - Búsqueda en inglés.


Y no son pocos los resultados...

No he encontrado ninguna opción que permita desactivar los comentarios por "Nombre/URL" sin desactivar los del usuario anónimo. Supongo que son cuestiones de diseño que solo Google sabrá.

Es todo por hoy... un saludo.

Monday, March 28, 2011

Why Teeth Tips See Through

, El Cid.

Al Review Weekly and the Great Speeches in History have the honor of joining the illustrious English periodic input. Throughout these entries talk about fellow citizens throughout history shaped or otherwise worked to make Spain what it is today. The first character we have the pleasure of glorifying here is Rodrigo Diaz de Vivar, El Cid. Much has been written about this character but I here discover that there is truth in the story, discovering the man and not the character.

seems that the young man entered the service Rodrigo Sancho II of Castile being that in this period he learned swordplay and pen equally. Also apparently formed in subjects taking part in several legal disputes. The service of King Sancho's brothers fought against the Spaniards and rebels to unify the kingdom, conquering Galicia, León, Zamora City etc for King, being that he died by treachery at the hands of a traitor. After this episode Alfonso VI took the throne, being that El Cid found some harmony with the new King although they say the songs that made him swear Santa Gadea had not been involved in death the former and, despite having fought against him in the past. It was apparently carrying out their obligations to their new king when attacked in retaliation to the Taifa of Toledo, which led to real anger, seeing El Cid forced to flee to Zaragoza. From Zaragoza began fighting under the command of lord of the manor against the threats of the Catalans and Aragonese counts to which he defeated in all matches. Continue to strengthen the Taifa of Zaragoza until the invasion of the Almoravids fans was forced to re-enter the service of Alfonso VI (or Alfonso VI was forced to ask for their services.) However, in the struggles against the Almoravids to correctly saw the importance of Valencia, being that disobeying Alfonso walked with their retinues of Muslims and Christians in the conquest of the city, facing for them to Mr. Catalan, Aragonese and Muslims who face planted. Finally, after a long siege, managed to gain control of the city and all its adjacent area, starting from that time to be considered as "Prince Rodrigo, the Cid." But anyway if you remained loyal to King being his only son, Diego, died serving this battle. Finally El Cid died in Valencia after having married his daughters with great masters and have the gratitude of the entire kingdom.

We see in the person of Rodrigo Diaz joins the devotion and stubbornness to not give in to discouragement, loyalty to sound principles and a disembodied idea still further evolve in Spain in which we live ... It was through that Valencia did not fall into the hands Almoravids, which prevented them have stopped the reconquest ending with the birth of our country as we know it today. That is why thank you very much Mio Cid.

Afro Hairdressers In Kilburn

bull's skin. Weekly review


"Spain and Portugal are so close to each other at some point, as in Olivenza are the same thing." With this simple sentence, the teacher summarized the Marcelino Ortiz Blasco general feeling that many people in the bull's skin, feel the Iberian Peninsula. He wanted the Goddess Fortuna in the seventeenth century Spain batten against our crowd of avatars that led the once mighty empire to the near extinction and dismemberment. Could stand and endure the ups and downs but one of its parts, Portugal, had come away from their parent tree will be the men violated the laws of history. Ask the reader to look at the photo accompanying this article and see which is the natural link that should be in the Peninsula. And now I wonder, how would a bull's hide together?.

Imagine a country of sixty million inhabitants and an extension that will become the second largest in Europe. These are not empty words because this would allow Spain to have 78 MEPs to be on equal terms with France, UK and Italy. Many will argue to the language as a problem but I will say that aside from the illogical to use a tool to unite as something distinctive, Portuguese, English shares with a lexical similarity Eighty-nine percent more than Catalan. Single country would also simplify the actions in infrastructure able to present an adequate and strong voice to all the inhabitants of the Iberian Peninsula.

With this in head wonder ... Is it possible or just a nice dream?. History will tell.

Sunday, March 27, 2011

Adult Arcades Near L Puente Ca

2.

movidito We had a week but otherwise nothing new in Ciudad Lineal, with sunny days and cloudy days ... to see if spring arrives it seems entirely although still not do all the little sun we want if it will be true about the spring alters blood. And in the PSOE has been the week revolt accounts to see who takes the reins of the party (and see who is not) when people finally kick to the most inept presidents who has been Spain, whose name I do not remember.

On the other hand we can not lose view the intervention in Libya by democratic countries. Gaddafi seems that every time you have less time while the Libyan people is increasingly looking to finally see real democracy in their country (possibly in a parliamentary monarchical system as in our country?). In Spain there have been several comments on behalf of our intervention. On the one hand we have the PP has given its full support to the PSOE on the subject, with a true sense of status and demonstrating many differences with the "No War" zapateril, being that the English polls say that Gaddafi and Saddam are the same. Regarding the military operation to refer to rainfall in the deployment that been referred from military means, also defending the idea that the English contribution should be higher.

As for Japan, we remain attentive to the evolution of their nuclear reactors. Stand out as the situation appears to be gradually brought back under control and all the prejudices and alarmist predictions are coming down on the issue of nuclear energy. Finally

congratulate the treatment of the democratic state is giving Sortu oppressors, we hope that eventually this will continue and keep the terrorists away from the municipalities. In fact on the issue of ETA are leaving certain information that each became great and if true would show serious charges of treason against the government, as this role in their desire to have helped the terrorists to go free.

This presents the week, we'll see how it ends.

Saturday, March 26, 2011

Christina Agulera Breasts

Week



Hola de nuevo... hoy fui con unos amigos al
Linux Week
(A free software event organized by the group of Catholic Linux IDES) where, throughout this week, lectures are taking place on various topics related to free software and its applications. Today he played about computer security and networking.
The first talk, "Injecting Payloads on the Net" , I did not leave time as well with some delay, too much traffic at Iron Maiden concert. But apparently dealt with Metasploit. The second talk was entitled
"+ + pentesting Opensource tools"
and was quite entertaining. They talked about the attacks to end users through Social Engineering and SET used for their demos.

The talks that I liked were the next two.

The third, discussed a draft Grid Computing
called "Legion" to solve the processing problems of research departments PUCP. The fourth and last attempted something similar to the above: "Implementation of a Computer Cluster using Free Software for Scientific Computing" . Concerned a system for managing a cluster that processes information from the Jicamarca Observatory. There was also

awards. Between talk and talk the organizers were asking questions and lavished something the first to answer correctly. So, a friend won a pole in Firefox and I some stickers of Gnome and 90% discount on hosting

xD For those who are interested in attending the remainder of the week can enter: http:/

/ tuxpuc.pucp.edu.pe/evento/linux-week-2011-software-libre-y-abierto-en-la-pucp
Regards, see you soon.

Wednesday, March 23, 2011

How To Build A Rc Boat Weedeater






Hi all ... I just heard on the facebook, the next Saturday 19 will be a WORKSHOP with very interesting topics on computer security. This event is organized by the Institute of Forensic Research - See Peru. workshop addition there will be a challenge of hacking called "Hack Me If You Can" (hackeame if you can) so be sharpening their laptop (no additional registration is required for the challenge).
Well I leave a copy & paste of what is posted on his facebook page

WORKSHOP II Digital Spy Forum Attacking

Synopsis: students, professionals and technical systems engineering, information security and interested in computer security and safety standards.
Prime Attacking the Digital Spy forum was developed in 2008, to offer those interested in computer security, knowledge and tools protection against computer attacks and intrusions. 3 years later, we will develop the II Forum Attacking Digital Spy as part of the Computer Security Course
To:

Objectives: Provide
specialists and computer security in general, knowledge on protection techniques and computer incident response.

- Intrusion and digital espionage 12:00 - social engineering and reverse social engineering
PROGRAM 09:00 - Registration participants 09:45 - 10:00 Opening
11:00 - Removal and masking fingerprints
13:00 - Break
14:00 - Detection of subliminal messages in open access systems 15:00 - Expert computer forensic digital evidence management

16:00 - Diagnostic analysis in network security 17:00 - Information Protection prevention and confidential data leakage

18:00 - 18:15 Closing
- Delivery of Certificates
DAY:
Saturday March 19, 2011 TIME: From 09:00 to 18:00 Universidad Nacional Mayor de San Marcos - College of Law and Political Science, Room 345 FREE ENTRY - PRE REGISTRATION
PLACE:

Certification: Students Computer Security Course: 15 soles General public: 30 soles Organizers: Institute Sponsor: Omni System's SAC
banker: BANK OF THE NATION Current Account No.: 00-015-009950 Head / Head: Forensic Research Institute
Forensic Research - See Peru

Registration:

http://www.facebook.com/sedeforense
http://www.twitter.com/sedeforense
Information and registration: sedeforense@hotmail.com
eventos@sedeforense.edu.pe
Phone: 2705163 Mobile Phone
: 991435643 (Opening hours Monday to Friday from 10:00 a.m. to 17:00 hours)

Do You Go On Dialysis For Liver Problems

Down with skyscrapers. Thomas Gomez

Collect The World in an article by Sanchez Drago before the possible closure of nuclear reply to an expert from the University of Foreign Studies, Kyoto, saying: "No, no ... That would be like giving up skyscrapers claiming that Bin Laden may attack them. What you need to do is strengthen them and avoid, as far as possible, they are in locations exposed to earthquakes. "And this phrase is probably best summarized as now cool heads should prevail and rationality against demagogy and prejudice.

We start with the facts. Japan is a place that brings together ten percent of global seismic activity with dozens of volcanoes with much more awake and asleep. In this nightmarish landscape apparent rates of light and the phone are very cheap. In fact, many analysts say is thanks to the fifty-five nuclear reactors in Japan are so this has had economic growth, social etc so impressive in the past, which is summarized in the "Japanese miracle" after end of the Second World War. And in Japan there has been an uncontrolled panic at the grave crisis they face is largely a cool head without giving priority to being carried out on the line promises to seek end to nuclear as the public is aware of the benefits obtained.

Meanwhile in Europe, and without removing its current and future importance of renewable energy, we continue with the limits of political correctness in the Old Continent. Here we have the reverse of Merkel in Germany, the European commissioner "anti-nuclear", etc.. I personally, and I think that anyone knows the risks inherent in nuclear reactors, but also a dangerous car, a skyscraper is dangerous, all human creations involve risks and what we have to do is minimize those risks and pull forward. And I say this because although there is no alternative to nuclear power that does not affect the country's backwardness and into the pockets of consumers (with the added difficulty that for example in Spain, we are forced to buy power France, which is produced from nuclear). Earlier I said that Japanese citizens understand the benefits of nuclear ... English Do you know the disadvantages of lack? I think not.

options are clear, go ahead with the flight was trying to close eyes to an energetic reality feasible or will take the reins once our destiny and stop being afraid of the risks minimal, since all we do is to lose opportunities. And is that as the old saying goes, "Chance favors the bold.

Monday, March 21, 2011

Sweet 16 Gothic Cakes

confused Muammar Al-Terrorist

Thomas enters
cholera occurred this Saturday in our district, during a visit he had scheduled the socialist candidate to the occupational therapy center in our district.

As by law, a visit to a center like this should be guided by a regional manager, in this case will play the Regina Family Viceconsejera Planiol, found in the position of having to correct data wrong Thomas in his speech:

- Only thirteen occupational centers.
- We actually have 78, one in Parla as you should know.

Unable to release data harangues as he drowned, Thomas and his team set up in anger and left the visit. Senor Gomez

Do you not insist on the importance of the debates? Will provide data when you do not prefer to avoid them like

Sunday, March 20, 2011

Where To Watch Digital Playground For Free



In 1969 a group of young soldiers a coup d'etat against the decadent dictatorship of King Idriss of Libya. At that time, Libya was a huge country at the same deserted, ruled by various tribes that are not characterized by good relations. Among this group of soldiers that led to regime change in Libya was Muammar Al-Gaddafi, Gaddafi not belong to any of the big tribes of the country, which facilitated his rise to the head of state.
Shortly after gaining power, the new dictator crushed the hopes and dreams of millions of Libyans who had been in Gaddafi the change his country needed. Muammar took care to eliminate all those who might overshadow him in the army and government, and began to place their children in numerous positions of increasing responsibility State, shortly after beginning ; to abuse his poor people, as we have seen these days also.
Remember that although many times the Libyan regime has been the darling of the West, Gadhafi has toyed with peorcito of each house, has worked with the IRA, Al-Qaeda, Eta ... forming and financing terrorist attacks that killed innocent people in our countries.
Nearly 50 years later, the Libyan people shouting from the rooftops FREEDOM; demanding justice and democracy for their country and I am sure that sooner or later achieve their objectives as well as their neighbors in Egypt and Tunisia. Gaddafi now sees in his people to their worst enemy and will not shake the hand of exterminating its citizens by the armed forces of the West fail to unseat him.
Our country has the obligation and moral duty to work with its allies to end the regime of Gadhafi and his gadafis, and help the Libyan people to move towards a democracy. I hope the government of Zapatero, who cried for 7 years the "No to war" this time known to rise for the first time and willing to fulfill its international responsibilities .

Brazilian Wax Peep Cam

WEEKLY REVIEW

We leave a week ago and we hope you enjoyed the spring weekend we had in Madrid. We release this new section in our blog so that you may be a little more informed about what has happened in the world and in Spain during the week.
During this week we have witnessed the chaos experienced in Japan, a tsunami and an earthquake has caused a catastrophe unprecedented in the country at the same time Japan has set off panic in the world nuclear. Zapatero's government used the disaster to get Japanese to debate in Spain the use of nuclear energy and use it as a smokescreen.
we have seen in Libya that Gaddafi did not have any feeling at the time of slaughtering its own people but on this occasion, the European countries led by the Republic of France have coordinated to curb the atrocities of the dictator Libyan and stop the crimes being committed by the murderers in the pay that the Government has put at your service. We have also lived, 7 years later the paris picture, "a meeting of European leaders coordinated by Sarkozy who have declared war to a bloody regime, with the difference that the" No to war "President Zapatero in this case has fallen on deaf ears and our country as allies serving all military means necessary, it should be.
In our district, we saw at last opened the new stations, including the Las Rosas. The President Esperanza Aguirre opened the new stretch of underground to join this part of Madrid city center. VIDEO
And to end this review, from Generations of Ciudad Lineal has taken this week a video in which our President, Alberto Mora, criticizes the road after the energy savings carried out by the Government of ZP. Www.nnggclineal.org
I hope you have a good week and see you next Sunday at psarlo well.
Greetings.

Saturday, March 19, 2011

Why My Iphone Alarm Is Silent?

Photo of Paris.


seems that Zapatero tries to remove the layer of incompetent and incapable he has earned over the years, and it does displaying a fold that has not known since the time equal cambiacapas other famous Borgia Pope. And is that Zapatero, in order to get the public support, this denying her past the "No War" to slip into the outfits and go to Paris to portray Sarkozy (who masterfully led his country on this subject, being envy for anyone who wants to have the head of his nation to a true statesman), Cameron and Clinton.

Eight years and three days have passed since that March 16, 2003, the day on which Aznar, Blair, Bush, Barroso to the host, met in the Azores and staged it to the inefficiency and slowness of UN (remember that Gaddafi takes nearly a month attacking his own people) are not going to resign to Saddam oppress their people remains a threat to the international community. This was the best president attack the PSOE Spain has had with the "No War" with the results we already know. And is that the attacks were not just posturing Popular Party, the country itself, but also were genuine lack of respect for our allies, we must not forget the withdrawal (if not flight) of Iraq or the rudeness to the flag American by ZP. Given the damage that occurred in recent times we have seen a new variable timonazo in foreign policy as has this government. Timonazo which resulted in over 1500 English in Afghanistan.
And now we timonazo that this was more pronounced than we thought and our president, the champion of peace and the Alliance of Civilizations, has become one of the main drivers of the "War on Libya", being that while Aznar there was only support operations, with no English soldier involved in the campaign against Saddam, we meet with Zapatero the English soldiers will be in front line combat faithfully fulfilling their duties. So I do not subtract from here wish nothing but good luck to the sailors of our ship and crew of our aircraft, so do your duty without us having to regret any Unfortunately.

Songs Played In Jc Penny

Dosbox, an emulator for old games (DOS)

recently tried Dosbox, a DOS emulator, with the idle to test or re-playing old games (some of which I that fail to video games and stay in, well, "games"). Well, this emulator seems to work pretty well, I tried it on windows xp and ubuntu, installation is quick and I use the classic console to run DOS games listed. It's free, apart from being free software, and can be downloaded by clicking HERE , or if they use Linux can use a software package to download and install. It is available for various systems, from what I read also for PSP and Wii.

Once installed and running, you have to mount the directory where the files (games) we want to run. If you're in XP, create a folder called "games" inside the folder where the files of Dosbox. Then in the emulator console write:
  1. games mount c
  2. c: cd
  3. juego1
  4. juego1.bat
If you are working in Ubuntu, you can create a folder to a location like this "/ home / Diego / games" and just change the first command by:
  1. mount c / home / Diego / games
A good place where you can find games for DOS is Abandonia . You can visit the page on this link . You have to watch that on the compatibility is the icon of Dosbox, there are also games that can run on XP without the emulator. Have fun with older games.

Monday, March 14, 2011

Maxi Degeneration Clitoris

against the oppressors. ZP



appeared a few days ago the news in the tabloids as seventy fanatics (and fanatics) had assaulted the Capilla de la Universidad Complutense de Madrid, foul language, violating facilities and showing a total disrespect to all Catholics, and more particularly, to their own classmates, it seems that they should apologize for being Catholic. I think you ought to say that I personally am not a fervent religious believer, but I must say that I believe in something that seems so antithetical to these characters as the religious, and that's what you think is freedom. It is unacceptable that in the XXI century, in a parliamentary democracy such as the English will allow these acts to be right up against these characters so that the state acts against them. And this action is possible, the above words are not empty words. Here we have the Criminal Code Articles 523 and 524 that would give rise to act against these undesirables. But it served a humble question do you do something against this bunch of unpresentable? I think not, starting with the Rector of the Complutense (which has characterized its mandate by a leftward latent sunk to their university) and ending with the Government, which will wash their hands as these actions may the cubs have been made. And the reality is that years of ZP are characterized by a pursuit of society that do not share the "progesí" the division between the English and the groups fighting each other to get through the disqualification and the ridicule of others revenues all kinds. But no, we say enough is enough, we must begin to address these acts, we must answer to the emptiness and indifference to those who oppress citizens simply because they do not share the socialist dictates and will not return to electoral. And I say this because I wonder what would have been government action if it had been a lack of respect for these features in a mosque. In short, it is shameful to see how the leader of the Alliance of Civilizations "does not respect its own civilization, western and reviled his basic axiom, freedom.

Sunday, March 13, 2011

Low Profile Foundation Bed Skirt

going to war.


ironic, surprising, and sad to observe the fold that the Socialist Party and the Left in general, can deploy to gain power and settle in it. Over recent years we have suffered in our flesh the eccentricities of ZP and his cohort. Typically, due to the economic crisis all the criticisms are directed towards this issue and forget about other important areas which, remember classical liberalism, are a priority for the state, as is international relations.
When ZP was elected in 2004 as one of promises (unfortunately, the few fulfilled, because the unemployment ...) was to withdraw our troops from Iraq in a unilateral decision that marked the beginning the collapse of Spain in the international arena. This occurred to us we had to look atypical "allies" in no way benefit our country. And we would still stranded in misery until Obama in the White House and foreign policy failed after the observation of the inability of Spain fit with countries Second, at last our "Premier" decided to take the path of international sense (or something) at a price of more than lackeys become important actors. And it was not something premeditated, but rather bound by the continuing failures we experienced with the "goodism" where we were. Here we have the "Alliance of Civilizations" when the dead body of Mediterranean Summit starts to rot.
is in this picture, limping internationally, when we've found to cope with increasing violence in the Arab world. It is at this point ZP, despite wanting to be a "Hippie institution "is doomed to meet with English obligations to NATO. Step and support the "guerrabuena" Obama in Afghanistan is being enclosed within it, remains to be seen what will happen in Libya. And is that a few days ago agreed policy ISAF, the NATO mission in Afghanistan, which all partners will come together in the country, being so, despite the declarations of Chacon is not going to repeat again absurdity of Kosovo. With regard to Libya, in theory unless the UN to create a mandate there will be no intervention by Spain, as that was the basis of the speech of our president trying to oust Aznar. However, before the genocide of Europe part of the Libyan people is raising a clear voice, Cameron, Sarkozy etc have driven within NATO the creation of an entire deployment in the area in which Spain has been to participate (that if, in minimum) by sending only a submarine. And it seems that NATO and Europe are committed to arms if there was no other solution, no matter what the UN says, shuffling several days to start a no-fly zone over Libya. If the facts go to more, what will Zapatero? Ever be able to stop lying to our allies and leave again the word of Spain on the floor, or does will take on all the "liberals" of not to etc. war and behave like a true statesman? Only time will tell us what our "corporate hippie."

Saturday, March 12, 2011

Short Poofy Pink Dresses Fpr A Sweet 16

Linux Forum Attacking WORKSHOP II Digital Spy


Today I want to tell you about a configuration error I found in the DNS servers at a private university.
is that the DNS, the university, to allow a zone transfer. But what is a zone transfer? It is a process whereby the authoritative DNS server for a domain gives the complete list of its records (domain names and IP addresses associated with, among others), usually, their secondary DNS servers.


The detail is that in this case, it allows you to transfer to anyone who asks. While this "vulnerability" does not allow us to access the system will do much for us to get all this information we can get a good idea of \u200b\u200byour network, find hosts did not know, new ranges of IPs, email servers, servers virtual hosting, etc ...
Now let's see how to do a zone transfer using the dig command of linux. The first is to find out the name of the domain's DNS servers
??????. edu.pe
(or whatever you tested)

$ dig ns edu.pe ??????.



Fig. 1 - Check the DNS servers of a domain.


In the "ANSWER SECTION"
we can see that there are 3 DNS servers for this domain. I have highlighted in blue.
Now we take any we obtained the names and resolve it and know your IP: $ dig


ns3 .??????. edu.pe



Fig. 2 - Resolve DNS name.

The DNS IP is 200 .???. 34.??
. Now ask you to transfer your area:
$ dig @ 200 .???. 34.?? ??????. axfr edu.pe


  • Fig. 3 - Transfer of area.
  • And there you have ... area full domain;) (in the picture are only a few records)
  • If the server does not allow zone transfers indicate to us a message:
  • "Transfer failed"
  • . In that case we could try with the other DNSs found in the first step.
  • 's all for now ... A greeting.

Does Yaz Work As Plan B?

not just us ... [Part III]

Continuing with the bugs in other universities ... Now we'll see a couple of errors in the website ... Well, I'm not saying that college xD
The first error is a typical SQL Injection. The vulnerable URL is:

http://palestra.??????.edu.pe/index.php?id =
Where is
vulnerable variable "id"
. First I tried putting a single quote to see if error occurred. The result was this:







Figure 1 - The web filters quotes.


As noted, the application has been charged with escape quote a prepending "\\"
therefore does not change the SQL command and no error occurs. But not always necessary to alter a quotation mark syntax. The numerical values \u200b\u200bneed not be in quotes in an SQL statement and we are dealing with this case;)
Using a test by contradiction we can see that yes we interfere in the query.






Fig. 2 - When an error is false.






Fig. 3 - When true shows the item.


When injected
"and 1 = 0" the condition will always be false and did not select any items so the application displays an error message. But when injected "and 1 = 1" condition
does not change and shows us the article with id 423.
 Well, I discovered the vulnerability ... Now let's play a little. 

After some time flirting with ORDER BY we can conclude that 17 columns are selected. The truth was somewhat confusing because the id variable is used in 2 queries with different number of columns. Thus, while an error does not in the other self. Fortunately, the error of the second query does not prevent the first show the result;)
already knowing the number of columns in the next step is to see which fields are displayed on the website. We will do a UNION SELECT well:
/ index.php? Id = null + union + select +1,2,3,4,5,6,7,8,9,10,11,12 , 13,14,15,16,17% 23



 Fig. 4 - Distribution of the fields shown. 

Pictured in the fields shown are 2, 3 and 5. We can use any of these to extract information from the database;) "information_schema" well: / index.php? Id = null + union + select +1,2,3,4, schema_name, 6, 7,8,9,10,11,12,13,14,15,16,17 + from + information_schema.schemata% 23
A test mode will we get the name of the databases that exist in the server. To do this we query the table "schemata" of


 

Fig. 5 - Only show the first result. But note that only displays the first result. To view the other results we have the following choices: request one by one all the names using the LIMIT clause
. Make a
"Serialized SQL Injection"
and display many of the names in a single query;)
Lo LIMIT
we have already explained before so it will be an excuse to learn something new. Serialized
SQL Injection is a technique that allows us to show many results of a query in one field visible. This is done using different methods according to the manager database (Oracle, SQL Server, MySQL, etc.) In the case of MySQL you use the "GROUP_CONCAT" that concatenates the results to the same group belong to one string .
The consultation would be serialized like this:


/ index.php? Id = null + union + select +1,2,3,4, GROUP_CONCAT (schema_name + +0 x20 separator), 6,7,8,9, 10,11,12,13,14,15,16,17 + from + information_schema.schemata% 23


GROUP_CONCAT function lets you specify a separator. In this case, use as a separator that is just a blank encoded in hexadecimal, not to use the quotes;)
Fig. 6 - Consultation serialized.
"0x20"
The second vulnerability found on this site is an LFI. Yes, the same vuln which are explained in the first half. And you know SQLi + LFI is a very dangerous combination. Fortunately, for the admin site, the user of the database does not have the permission
"FILE"
that is what allows use "INTO OUTFILE" to inject the code. I leave

an image showing the
file "/ etc / passwd" proof of concept
: Fig. 7 - PoC of LFI.

's all ... for today. Hello ... for those who could not attend for any reason and for those who want to see again talks with some more patience I will leave this post the videos of all LimaHack @ UNMSM conference.
Greetings.

Thursday, March 10, 2011

How To Get Rid Of Broken Cappilaries

Need reasons? Presentation



surprising us all the hype that is being mounted in social networks etc before the starting gun that was given at headquarters. Little I can say about those who criticize us, because their own words they are describing themselves very well ... these threats, this attempt to shut up or ousted by rediculización so merely because it forces us the most are the ones we are supporting those who are putting their two cents.
But perhaps there are people who need reasons to join, that are missing a empujonncito to convince, I hope that will convince you the following lines.

Affiliates to PP:

Why is a party that has its feet on the ground, avoiding radical ideas.

Why do not we a nation of unemployed, but we want a country of entrepreneurs, people who work.

Because people are the focus of policy.

Because we do not accept "that the socialist international policy has led Spain to the third division of Europe. I am not resigned to that, a tiny percentage of votes, the Nationalists English end up dictating policy. "

Because we want to discover the truth about the 11-M, negotiating with ETA etc being

that we do not give quarter to the murderers.

Why Spain defends progress, freedom and equality, the Spain of solidarity, tolerance, cutting-edge individual stimulus.

Why do not we resign ourselves to "stop denouncing sectarianism Tinell Pact and profoundly undemocratic attitude of the PSOE which policy has, in the Basque elections of 2001, the sole aim to stigmatize our Party and its members, supporters and voters. "

Why do not we want our country to be a hindrance to Europe, but we want to be part of the locomotive.

For this and much more, if you believe in individual autonomy and equality of citizenship, Afliate! In NNGG many young people like you. And of course, feel free to visit afiliatealPP.com

Wednesday, March 9, 2011

How To Get Kew Gardens 120-55 Queens Blvd



New Generation submitted its campaign Ciudad Lineal membership on March 10, 2011 with a large attendance at district headquarters, highlighting the presence of Alcayde Germain, Secretary of NNGG Madrid.

This campaign, which has already harvested many fruits, is to get young people in the district to mobilize and participate in the improvement and maintenance of district and city, showing that young people are not "liberals" that are made with a closed fist by defending the Republic.

In the coming weeks we will show that young people are not with the Che, Chavez or ZP. No, young people are with those who take people as the basis of its policies, in the case of Madrid, Esperanza Aguirre and Alberto Ruiz Gallardon.

Indeed, as Germain has told us in the wonderful evening that has taken us chairing our Executive Committee, now more than ever is the time to mobilize youth for municipalities to be the beginning of the end of ZP stale and socialism that has plunged the country into a crisis that will have to remove the Partido Popular.

But the evening did not remain there alone. It has also been realized so far the performance of the executive committee, submitting all the platforms that have NNGG fully operational to meet the goal of being present in all places in a serious and determined. Thus we have presented the new face that look the website (http://www.nnggclineal.org/) and blog (http://clineal.blogspot.com/) as well as detailing the presence we have in most important social networks (Tuenti, Facebook, Twitter ...).

After all the presentation has been open question time where perhaps we should highlight the involvement of a member, who asked to Germain on immigrants in Madrid and the party's performance in this problem. It actually reminded as the Community of Madrid was the first region of Spain that created an immigration counseling etc. He also explained as concern the party was immigrants is evident, and can be seen in the case of our district with the coordination that exists by our president Sonsoles with associations of foreigners in Ciudad Lineal

Tuesday, March 8, 2011

My Husband Wants Me To Wear A Girdle

not just us ... [Part II]


I'll update the post as I upload more videos. PhD in Metasploit exploitation






Mom: In Reverse Engineer wants to be




Lockpicking 101


toppling Tux ... Creating exploits for Linux