<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; hack</title>
	<atom:link href="http://www.darknet.org.uk/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>US Subway Stores POS Hacked For $3Million Dollars</title>
		<link>http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/</link>
		<comments>http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 16:19:44 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Cezar Iulian Butu]]></category>
		<category><![CDATA[credit card hack]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking credit cards]]></category>
		<category><![CDATA[stealing credit card details]]></category>
		<category><![CDATA[subway]]></category>
		<category><![CDATA[subway credit card fraud]]></category>
		<category><![CDATA[subway hack]]></category>
		<category><![CDATA[subway hacked]]></category>
		<category><![CDATA[subway security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3243</guid>
		<description><![CDATA[Honestly there hasn&#8217;t been much news over the holiday period, well maybe there was but no one bothered reporting it. There was the Stratfor case of course, which Anonymous is saying wasn&#8217;t anything to do with them. The scale of this incident somehow reminds me of the whole TJ MAXX fiasco a few years back. [...]]]></description>
			<content:encoded><![CDATA[<p>Honestly there hasn&#8217;t been much news over the holiday period, well maybe there was but no one bothered reporting it. There was the Stratfor case of course, which <a href="http://www.darknet.org.uk/tag/anonymous/">Anonymous</a> is saying wasn&#8217;t anything to do with them.</p>
<p>The scale of this incident somehow reminds me of the whole <a href="http://www.darknet.org.uk/tag/tjx/">TJ MAXX</a> fiasco a few years back.</p>
<p>Anyway, this whole scheme sounds like a case of people installed VNC with weak passwords and someone finding it by accident &#8211; it doesn&#8217;t even seem to have been a targeted hack.</p>
<blockquote><p>For thousands of customers of Subway restaurants around the US over the past few years, paying for their $5 footlong sub was a ticket to having their credit card data stolen. In a scheme dating back at least to 2008, a band of Romanian hackers is alleged to have stolen payment card data from the point-of-sale (POS) systems of hundreds of small businesses, including more than 150 Subway restaurant franchises and at least 50 other small retailers. And those retailers made it possible by practically leaving their cash drawers open to the Internet, letting the hackers ring up over $3 million in fraudulent charges.</p>
<p>In an indictment unsealed in the US District Court of New Hampshire on December 8, the hackers are alleged to have gathered the credit and debit card data from over 80,000 victims.</p>
<p>&#8220;This is the crime of the future,&#8221; said Dave Marcus, director of security research and communications at McAfee Labs in an interview with Ars. Instead of coming in with guns and robbing the till, he said, criminals can target small businesses, &#8220;root them from across the planet, and steal digitally.&#8221;</p>
<p>The tools used in the crime are widely available on the Internet for anyone willing to take the risks, and small businesses&#8217; generally poor security practices and reliance on common, inexpensive software packages to run their operations makes them easy pickings for large-scale scams like this one, Marcus said.</p>
<p>While the scale of this particular ring may be significant, the methods used by the attackers were hardly sophisticated. According to the indictment, the systems attacked were discovered through a targeted port scan of blocks of IP addresses to detect systems with a specific type of remote desktop access software running on them. The software provided a ready-made back door for the hackers to gain entry to the POS systems. The PCI Security Standards Council, which governs credit card and debit card payment systems security, requires two-factor authentication for remote access to POS systems—something the applications used by these retailers clearly didn&#8217;t have. </p></blockquote>
<p>It seems like there&#8217;s a pretty large ring behind this operation, just due to the sheer number of locations compromised and the amount of time it must have taken to install all the malware and logging software.</p>
<p>Plus the network infrastructure that was build to receive the logs via FTP upload, the criminals were pretty smart too &#8211; they even &#8216;backed up&#8217; their stolen data to sendspace just in case their hosting got taken down.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Once they were in, the hackers then deployed a collection of hacking tools to the POS systems, including logging software that recorded all the input into the systems—including credit card scans. They also installed a trojan, xp.exe, onto the systems to provide a back door to reconnect to the systems to allow the installation of additional malware, and prevent any security software updates.</p>
<p>Collected data from the loggers was posted by the malware to FTP &#8220;dump&#8221; sites on a number of Web servers in the US created with domains they registered through GoDaddy.com using stolen credit card data. In addition to using the stolen data to register their own domains and pay for hosting service, the hackers periodically rounded up the dumped transaction data and moved it to sendspace.com, a file transfer site. Richard James of sendspace.com says that his company cooperated with the FBI in the investigation of the hack. &#8221; Sendspace [is] a file hosting and transfer site used by millions every single day,&#8221; he said in an email to Ars Technica,&#8221;and as such can indeed be used for activities which are against our TOS and that we do not condone.&#8221;</p>
<p>Some of the data was used to print counterfeit credit cards using blank plastic cards and embossing machines. One of the alleged hackers, Cezar Iulian Butu, was generating counterfeit cards with an embossing machine out of a house in Belgium in October of 2010, and working with a group, used the cards &#8220;among other uses [to] place bets at local French &#8216;tobacco&#8217; shops,&#8221; the Justice Department said in its filing. The rest of the stolen data was sold in blocks to other criminals from the Sendspace server.</p>
<p>According to a report by Schuman, Subway&#8217;s corporate IT and a credit card company discovered the data breach &#8220;almost simultaneously.&#8221; Subway Corporate Press Relations Manager Kevin Kane told Ars that &#8220;the tech guys who dealt with this moved and put steps in place [to block the theft of data] as soon as they discovered it.&#8221; He said the company wouldn&#8217;t discuss the measures taken, as &#8220;we don&#8217;t want to give away the blueprint&#8221; to other potential attackers. And Kane added that Subway had been asked by the Justice Department not to comment on other details of the case, as it is part of an ongoing investigation.</p></blockquote>
<p>It&#8217;ll be a pretty interesting case to watch either way, we&#8217;ll have to see what else gets discovered (and more importantly released to the public).</p>
<p>Subway corporate IT has taken some measures against this, but as it was franchisee stores that got owned &#8211; I don&#8217;t honestly see how much they can do. Unless they implement a complete new POS system (which is secure and preferably doesn&#8217;t run Windows and connect to the Internet).</p>
<p>POS in this case should well stand for Piece of Shit.</p>
<p>Source: <a href="http://arstechnica.com/business/news/2011/12/how-hackers-gave-subway-a-30-million-lesson-in-point-of-sale-security.ars">Ars Technica</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=US+Subway+Stores+POS+Hacked+For+%243Million+Dollars+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3243+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/&amp;t=US+Subway+Stores+POS+Hacked+For+%243Million+Dollars" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/&amp;title=US+Subway+Stores+POS+Hacked+For+%243Million+Dollars" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/&amp;title=US+Subway+Stores+POS+Hacked+For+%243Million+Dollars" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/&amp;title=US+Subway+Stores+POS+Hacked+For+%243Million+Dollars" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/&amp;title=US+Subway+Stores+POS+Hacked+For+%243Million+Dollars" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fus-subway-stores-pos-hacked-for-3million-dollars%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/us-subway-stores-pos-hacked-for-3million-dollars/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Boom Post 9/11</title>
		<link>http://www.darknet.org.uk/2006/10/security-boom-post-911/</link>
		<comments>http://www.darknet.org.uk/2006/10/security-boom-post-911/#comments</comments>
		<pubDate>Sun, 01 Oct 2006 23:48:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[9-11]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[homeland]]></category>
		<category><![CDATA[Information-Security]]></category>
		<category><![CDATA[morgan-keegan]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security-boom]]></category>
		<category><![CDATA[terror]]></category>
		<category><![CDATA[terrorism]]></category>
		<category><![CDATA[terrorist]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/10/security-boom-post-911/</guid>
		<description><![CDATA[It makes sense really, the paranoia that quickly infected every corner of the &#8216;Western&#8217; world had to be cashed in on by somebody, tada! The security industry of course. During the Cold War, Canada&#8217;s National Optics Institute developed a system to detect which type of enemy tank or fighter jet was approaching. After the Soviet [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It makes sense really, the paranoia that quickly infected every corner of the &#8216;Western&#8217; world had to be cashed in on by somebody, tada! The security industry of course.</p>
<blockquote><p>During the Cold War, Canada&#8217;s National Optics Institute developed a system to detect which type of enemy tank or fighter jet was approaching. After the Soviet Union&#8217;s demise, such threats were deemed less likely, and the technology sat on the shelf.</p>
<p>Until 2003, when entrepreneur Eric Bergeron toured the institute with Sept. 11 on his mind.</p>
<p>&#8220;The flash I had was that we no longer look for Russian planes in the sky, but we do look for bad things in luggage,&#8221; Bergeron said.</p>
<p>The X-ray analysis company that emerged, Quebec-based Optosecurity, is only on the verge of putting its devices in real-life checkpoints. But its hopes are emblematic of the massive homeland security technology industry spawned by Sept. 11.</p></blockquote>
<p>At least some interesting new technological solutions and ideas have popped up, not just the stupid crap that the George Bush administration usually comes up with..</p>
<blockquote><p>Spending on domestic security across all U.S. federal agencies is expected to reach $58 billion in fiscal 2007 &#8212; up from $16.8 billion in 2001, according to the Office of Management and Budget. States and cities are annually contributing $20 billion to $30 billion more, Gartner Vice President T. Jeff Vining estimates.</p>
<p>Much of it lands with large defense contractors and systems integrators with long government ties and the heft to tackle huge projects. For example, Unisys got a $1 billion contract to set up computers, cell phones, websites and other network technology for airport security staff. BearingPoint won a $104 million deal in August to provide secure identification cards to federal employees and contractors.</p>
<p>Still, a lot of no-names are angling for a piece. Even a tiny slice could be revolutionary for them.</p></blockquote>
<p>Ah hyper-vigilance, that&#8217;s a good term.</p>
<blockquote><p>Brian Ruttenbur, homeland security analyst for Morgan Keegan &#038; Co., is also watching companies that help analyze intercepted communications and those that manage video surveillance.</p>
<p>Of course, even as technologies improve, none is likely to end the post-Sept. 11 era of hyper vigilance. &#8220;We can&#8217;t catch everything,&#8221; Ruttenbur said. &#8220;I don&#8217;t know of any single technology that can be right 100 percent of the time.&#8221;</p></blockquote>
<p>Let&#8217;s hope things can relax again with some of the good new technological controls in place rather than all of us who travel frequently being controlled by the fear or terrorism.</p>
<p></p>
<p>Source: <a href="http://www.wired.com/news/wireservice/0,71716-0.html?tw=rss.index">Wired</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Security+Boom+Post+9%2F11+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D334+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/10/security-boom-post-911/&amp;t=Security+Boom+Post+9%2F11" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/10/security-boom-post-911/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/10/security-boom-post-911/&amp;title=Security+Boom+Post+9%2F11" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/10/security-boom-post-911/&amp;title=Security+Boom+Post+9%2F11" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/10/security-boom-post-911/&amp;title=Security+Boom+Post+9%2F11" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/10/security-boom-post-911/&amp;title=Security+Boom+Post+9%2F11" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F10%2Fsecurity-boom-post-911%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/10/security-boom-post-911/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Biggest Web Defacement Ever</title>
		<link>http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/</link>
		<comments>http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/#comments</comments>
		<pubDate>Sat, 20 May 2006 04:18:46 +0000</pubDate>
		<dc:creator>Tiago Faria</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[biggest-hack]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[gouki]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[turkish-hacker]]></category>
		<category><![CDATA[zone-h]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/</guid>
		<description><![CDATA[A Turkish hacker using the handle iSKORPiTX was able to breach the security of a group of web servers, containing more than 38.500 web sites in less than a day! Iskorpitx is believed to be 45 years old, sometimes being helped for minor defacement activities by another Turkish &#8220;senior cracker&#8221; (42) going by the handle [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>A Turkish hacker using the handle iSKORPiTX was able to breach the security of a group of web servers, containing more than 38.500 web sites in less than a day!</p>
<blockquote><p>Iskorpitx is believed to be 45 years old, sometimes being helped for minor defacement activities by another Turkish &#8220;senior cracker&#8221; (42) going by the handle of Metlak .</p></blockquote>
<p>Apparently he doesn&#8217;t like a couple of countries:</p>
<blockquote><p>&#8220;HACKED BY iSKORPiTX</p>
<p>(TURKISH HACKER)</p>
<p>FUCKED ARMANIAN-FUCKED FRANCE-FUCKED GREECE-FUCKED PKK TERROR</p>
<p>iscorpitx, marque du monde, presente ses salutations tout le monde. &#8220;</p></blockquote>
<p><a href="http://www.zone-h.org/defacements/mirror/id=4018877/">Defacement mirror</a> &#8211; example</p>
<p>I gotta say: </p>
<p>Script kiddie hack or not, a defacement will always be a &#8216;cool&#8217; hack to do.</p>
<p>Zone-H is keeping everyone posted of his actions and has compiled a <a href="http://www.zone-h.org/defaced/list.txt">full list</a> of the 21.549 sites he was able to deface. </p>
<p>You can also keep updated with iSKORPiTX latest actions <a href="http://www.zone-h.org/en/en/defacements/filter/filter_defacer=iskorpitx/">here</a>.</p>
<p>Of all the sites iSKORPiTX was able to hack, 95% of them were using Windows <em>(big part of those same sites, Windows 2003)</em> and running IIS 6. New exploit?</p>
<p>No doubt, the biggest hack ever.</p>
<p></p>
<p>Source: <a href="http://www.zone-h.org">Zone-H</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=The+Biggest+Web+Defacement+Ever+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D203+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/&amp;t=The+Biggest+Web+Defacement+Ever" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/&amp;title=The+Biggest+Web+Defacement+Ever" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/&amp;title=The+Biggest+Web+Defacement+Ever" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/&amp;title=The+Biggest+Web+Defacement+Ever" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/&amp;title=The+Biggest+Web+Defacement+Ever" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F05%2Fthe-biggest-web-defacement-ever%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/05/the-biggest-web-defacement-ever/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Information about the Internet Explorer Exploit createTextRange Code Execution</title>
		<link>http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/</link>
		<comments>http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/#comments</comments>
		<pubDate>Mon, 27 Mar 2006 05:52:03 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[poc]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/</guid>
		<description><![CDATA[Internet Storm Center&#8217;s always informative Diary has some good information. At the urging of Handler Extraordinaire Kyle Haugsness, I tested the sploit on a box with software-based DEP and DropMyRights&#8230; here are the results: Software-based DEP protecting core Windows programs: sploit worked Software-based DEP protecting all programs: sploit worked DropMyRights, config&#8217;ed to allow IE to [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Internet Storm Center&#8217;s always informative Diary has some good information.</p>
<blockquote><p>At the urging of Handler Extraordinaire Kyle Haugsness, I tested the sploit on a box with software-based DEP and DropMyRights&#8230; here are the results:</p>
<p>Software-based DEP protecting core Windows programs: sploit worked<br />
Software-based DEP protecting all programs: sploit worked<br />
DropMyRights, config&#8217;ed to allow IE to run (weakest form of DropMyRights protection): sploit worked<br />
Active Scripting Disabled: sploit failed</p>
<p>So, go with the last one, if you are concerned.  By the way, you should be concerned.</p></blockquote>
<p>It didn&#8217;t take long for the exploits to appear for that IE vulnerability.  One has been making the rounds that pops the calculator up (no, I&#8217;m not going to point you to the PoC code, it is easy enough to find if you read any of the standard mailing lists), but it is a relatively trivial mod to turn that into something more destructive.  For that reason, SANS is raising Infocon to yellow for the next 24 hours.</p>
<p>Microsoft recommends you turn Active Scripting OFF to protect against this vulnerability.</p>
<p>Source: <a href="http://isc.sans.org/diary.php?storyid=1212">ISC</a></p>
<p>Yah I know, yet another reason to dump Internet Explorer and grab Firefox, not that anyone reading this site would be using Internet Exploder..</p>
<p>The code is along the lines of:</p>
<p>&lt;code&gt;&lt;input type=&#8221;checkbox&#8221; id=&#8217;c'&gt;<br />
&lt;script&gt;<br />
	r=document.getElementById(&#8220;c&#8221;);<br />
	a=r.createTextRange();<br />
&lt;/script&gt;&lt;/code&gt;</p>
<p>You can find the <a href="http://www.bleedingsnort.com/cgi-bin/viewcvs.cgi/sigs/EXPLOIT/EXPLOIT_IE_Vulnerabilities?view=markup">Bleeding Snort rule for the IE Exploit here</a>.</p>
<p><a href="http://computerworld.co.nz/news.nsf/news/E637038E81642345CC25713B0015F841">Microsoft has now confirmed this.</a></p>
<blockquote><p>&#8220;We&#8217;re still investigating, but we have confirmed this vulnerability and I am writing a Microsoft Security Advisory on this,&#8221; writes Lennart Wistrand, security program manager with the Microsoft Security Response Center, in a blog posting. &#8220;We will address it in a security update.&#8221;</p></blockquote>
<p></p>
<p>There is also a <a href="http://news.com.com/Third%20party%20offers%20temporary%20IE%20fix/2100-1002_3-6054583.html?tag=nefd.top">3rd party fix for this from eEye</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D135+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;t=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F03%2Finformation-about-the-internet-explorer-exploit-createtextrange-code-execution%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Download youtube.com videos?</title>
		<link>http://www.darknet.org.uk/2006/03/download-youtubecom-videos/</link>
		<comments>http://www.darknet.org.uk/2006/03/download-youtubecom-videos/#comments</comments>
		<pubDate>Sat, 25 Mar 2006 06:44:33 +0000</pubDate>
		<dc:creator>evilfoo</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[download-video]]></category>
		<category><![CDATA[flash-video]]></category>
		<category><![CDATA[flv]]></category>
		<category><![CDATA[general-hack]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[youtube]]></category>
		<category><![CDATA[youtube-download]]></category>
		<category><![CDATA[youtube.com]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/download-youtubecom-videos/</guid>
		<description><![CDATA[Ever wanted to download those cool videos from youtube.com? (Its an online video storage site similar to imageshack.us for storing images) and can&#8217;t because those peeps made it difficult for you to just download them offline? Well now you can !! Go to fileleecher.com and follow the instructions on how to copy the youtube.com video [...]]]></description>
			<content:encoded><![CDATA[<p>Ever wanted to download those cool videos from <a href="http://www.youtube.com">youtube.com</a>? (Its an online video storage site similar to <a href="http://www.imageshack.us">imageshack.us</a> for storing images) and can&#8217;t because those peeps made it difficult for you to just download them offline? Well now you can !!  </p>
<p>Go to <a href="http://www.fileleecher.com">fileleecher.com</a> and follow the instructions on how to copy the youtube.com video link and download the video.  Once you&#8217;ve download the video you&#8217;ll have to rename to .flv if doesn&#8217;t already have the extension.  Then you&#8217;ll need to download the encoder to covert the .flv file format into other formats.  For that you&#8217;ll need <a href="http://www.download.com/Riva-FLV-Encoder/3000-2140-10320097.html">Riva FLV Encoder</a>.  The installation includes the player for FLV and the encoder for converting it to mpeg or avi.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<p>After all that you can do what ever you want with the videos.  Put it into your iPod video, PSP or even convert it to .3GP for putting it into your mobile phone.</p>
<p>Many thanks to <em>CYBERAXIS SG</em> for this site.</p>
<p><a href="http://digg.com/movies/Easy_way_to_download_youtube.com_Video">Digg This Article</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Download+youtube.com+videos%3F+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D132+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/03/download-youtubecom-videos/&amp;t=Download+youtube.com+videos%3F" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/03/download-youtubecom-videos/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/03/download-youtubecom-videos/&amp;title=Download+youtube.com+videos%3F" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/03/download-youtubecom-videos/&amp;title=Download+youtube.com+videos%3F" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/03/download-youtubecom-videos/&amp;title=Download+youtube.com+videos%3F" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/03/download-youtubecom-videos/&amp;title=Download+youtube.com+videos%3F" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F03%2Fdownload-youtubecom-videos%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/03/download-youtubecom-videos/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
	</channel>
</rss>

