on Monday, 4 November 2013
The crooks behind the CryptoLocker malware seem to have introduced a second chance option.
Victims, it seems, can now change their minds about not paying up.
Assume you were a victim of this devious malware, and decided, "No! I will not pay!"
Imagine that you've done a full cleanup; removed the malware from memory, hard disk and Windows registry; and gone to see what you can recover from your backup disks.
Now imagine that you are having malware cleaner's remorse.
Perhaps paying $300 would have been the pragmatic approach?
#############################
Exploit Title : Multiple CSRF Horde Groupware Web mail Edition
Author:Marcela Benetrix
Date: 10/25/13
version: 5.1.2
  
#############################
GroupWare Web mail Edition
  
Horde Groupware Webmail Edition is a free, enterprise ready, browser based
communication suite. Users can read, send and organize email messages and
manage and share calendars, contacts, tasks, notes, files, and bookmarks 
with the standards compliant components from the Horde Project


SpearPhisher is a simple point and click Windows GUI tool designed for (mostly) non-technical people who would like to supplement the education and awareness aspect of their information security program. Not only is it useful to non-technical folks, penetration testers may find it handy for sending quick and easy ad-hoc phishing emails. The tool supports specifying different sending names and email addresses, multiple recipients via TO, CC, BCC, and allows bulk loading with one recipient email address per line in a file. It allows customization of the subject, adding one attachment, and SSL support for SMTP enabled mail servers.
Retire.js identify JavaScript libraries with known vulnerabilities in your application  


Retire.js is a command line scanner that helps you identify dependencies with known vulnerabilites in your application. Using the provided Grunt plugin you can easily include Retire.js into your build process. Retire.js also provides a chrome extension allowing you to detect libraries while surfing your website. 

To detect a given version of a given component, Retire.js uses filename or URL. If that fails, it will download/open the file and look for specific comments within the file. If that also fails, there is the possibility to use hashes for minified files.

AFFECTED PRODUCT
================
  
Quick Paypal Payments  Wordpress Plugin Version 3.0 possibly earlier
  
  
VULNERABILITY CLASS
===================
  
Cross-Site Scripting
  
  
DESCRIPTION
===========
  
  
Quick Paypal Payments suffers from a persistent Cross-Site Scripting vulnerability due to a lack
of input validation and output sanitization of the "reference" and "amount" paramaters.
Other input fields are also effective to reflective cross site scripting.
The NSA has repeatedly tried to attack people using Tor, a popular tool protecting their Internet anonymity. This is despite the fact the software is primarily funded and promoted by the government of the United States itself.

NSA-laptop-010.jpg

According to secret NSA files, disclosed by Edward Snowden, the agency successfully identified Tor users and then attacked vulnerable software on their machines.
on Sunday, 3 November 2013

EDB-ID: 29355 CVE: N/A OSVDB-ID: N/A
Author: Ali Morshedloo Published: 2013-11-01 Verified: Verified
Exploit Code:   Download Vulnerable App:   N/A

###########################
# Exploit Title : Typo3 File Disclosure
# Exploit Author : Iran Security Team
# Discovered By : Red.Eagle
# Home : WWW.IrSecTeam.org
# Dork1 : inurl:fileadmin/php/commun/download.php
# Dork2 : inurl:fileadmin/scripts/download.php

# Date: 2013 1 November
# Tested on:windows 7
# Software Link: http://typo3.org/
# Contact To Me: https://www.facebook.com/r3d.3agl3
###########################
EDB-ID: 29328 CVE: N/A OSVDB-ID: N/A
Author: LiquidWorm Published: 2013-11-01 Verified: Not Verified
Exploit Code:   Download Vulnerable App:   N/A

Vendor: ImpressPages UAB
Product web page: http://www.impresspages.org
Affected version: 3.6

Summary: ImpressPages CMS is an open source web content
management system with revolutionary drag & drop interface.
###################################################################################################
#_________            .___        _______                ___.   .__      
#\_   ___ \  ____   __| _/____    \      \   ______  _  _\_ |__ |__| ____
#/    \  \/ /  _ \ / __ |/ __ \   /   |   \_/ __ \ \/ \/ /| __ \|  |/ __ \
#\     \___(  <_> ) /_/ \  ___/  /    |    \  ___/\     / | \_\ \  \  ___/ 
# \______  /\____/\____ |\___  > \____|__  /\___  >\/\_/  |___  /__|\___  >
#        \/            \/    \/          \/     \/            \/        \/
###################################################################################################
# Exploit Title: WordPress Switchblade Themes Arbitrary File Upload Vulnerability
# Author: Byakuya
# Date: 11/01/2013
# Vendor Homepage: http://themeforest.net/
# Themes Link: http://themeforest.net/item/switchblade-powerful-wordpress-theme/761353
# Price: $50
# Affected Version: v1.3
# Infected File: php.php
# Category: webapps/php
# Google dork: inurl:/wp-content/themes/switchblade
# Tested on : Windows/Linux
###################################################################################################
################################################################################ #_________ .___ _______ ___. .__ # #\_ ___ \ ____ __| _/____ \ \ ______ _ _\_ |__ |__| ____ # #/ \ \/ / _ \ / __ |/ __ \ / | \_/ __ \ \/ \/ /| __ \| |/ __ \ # #\ \___( <_> ) /_/ \ ___/ / | \ ___/\ / | \_\ \ \ ___/ # # \______ /\____/\____ |\___ / \____|__ /\___ /\/\_/ |___ /__|\___ / # # \/ \/ \/ \/ \/ \/ \/ # ################################################################################ # Exploit Title: WordPress Curvo Themes CSRF File Upload Vulnerability # Author: Byakuya # Date: 10/26/2013 # Vendor Homepage: http://themeforest.net/ # Themes Link: http://www.wphub.com/themes/curvo-by-themeforest/ # Price: $35 # Affected Version: Unknown # Infected File: upload_handler.php # Category: webapps/php # Google dork: inurl:/wp-content/themes/curvo/ ###################################################################################################
on Monday, 28 October 2013
If you buy lots of games on the Steam gaming platform and have many of them installed on your computer system, you may have noticed that there is a first come first serve basis in regards to game installations and updates.
Updates for instance are installed one after the other, which is not that much of a problem for most users, but if you have dozens or even more than a hundred games installed, you may have noticed that the "wrong" games get updated first while you have to wait for your favorite games to be updated because of this before you can start playing them.
Valve recently introduced a new high priority update feature to Steam which resolves this for you. It enables you to set automatic updates to high priority for individual games so that their updates are prioritized over everything else.
If you’re a user of social media scheduling app Buffer, there’s a good chance that your Saturday morning has been less than relaxing. There have been numerous reports circulating today purporting that the service has been hacked, and just a few moments ago the company officially confirmed those reports in a tweet.
“Hi all. So sorry, it looks like we’ve been compromised,” the terse statement reads. “Temporarily pausing all posts as we investigate. We’ll update ASAP.”
Just who is looking over your shoulder when you browse the Internet? Tomorrow, web users will be given a new tool to shine a light on the commercial organisations which track your every movement online.
Lightbeam reveals the source of third-party adverts

Lightbeam, a download produced by Mozilla, the US free software community behind the popular Firefox browser, claims to be a “watershed” moment in the battle for web transparency.
Everyone who browses the Internet leaves a digital trail used by advertisers to discover what your interests are.
Users who activate Lightbeam will be able to see a real-time visualisation of every site they visit and every third-party that is active on those sites, including commercial organisations which might potentially be sharing your data.
Singh
Recent reports said that the U.S. National Security Agency has spied on over 35 unnamed world leaders, but Indian Prime Minister Manmohan Singh is sure he's not one of them — as he doesn't have a phone or an email address to hack.
Google is trialing an interesting new service in Jakarta, Indonesia, where WiFi Passport, anAndroid app that includes access to a variety of WiFi hotspots, has been spotted.countdown Google is testing an Android app that connects devices to city wide WiFi hotspots
It’s not easy to get speedy, reliable Internet access in cities like Jakarta so WiFi is a popular option — with even carriers offering access points. Google and partner MOGPlay have set up a range of hotspots which WiFi Passport users can access directly from the app, with no need for repeat passwords/log-in.
on Sunday, 27 October 2013

Outlook Password Dump is the free command-line tool to quickly recover lost email passwords from all versions of Microsoft Outlook.

Outlook stores passwords for all the configured mail accounts on your system. These passwords are stored in the encrypted format and only respective user can decrypt it.

SterJo Key Finder is a small and FREE application that can recover lost product keys. All you have to do is run the program and it will find the keys for you in a few seconds. The software is currently able to recover a large number of keys like SterJo Key Finder currently can recover keys for the following software and games. If you want to participate into upgrading the database with a new keys please send me a message about the software or the game and the key details.

Changelog:
-fixed socket timeout bug
-fixed small translation bugs
-added spanish/arabic/bulgarian/polish/french translation


Lynis is an auditing tool for Unix/Linux (specialists). It scans the system and available software and performs many individual security checks. It determines the hardening state of the machine and detects security issues. Beside security related information it will also scan for general system information, installed packages and possible configuration errors.
matrix
One of the more impressive projects a home-bound tinkerer can pull off is some sort of display. Not only does the final project result in a lot of blinky, glowey things, but driving hundreds of LEDs is an achievement in itself. [Fabien] decided he wanted to build his own LED display and ended up with something great.

Hey Guys I am making a Penetration Testing Linux Distro & I need a name for it could u plzz suggest me one ... so far following are the suggestions I got