20 January 2010
22 July 2009
"M Fucking Scanner" , o como un hacker puede ser subnormal
Esto es el colmo... mirando mi access.log del apache me he encontrado con lo siguiente:
204.***.***.*** - - [22/Jul/2009:10:01:18 +0200] "GET /phpmyadmin/INSTALL HTTP/1.1" 404 216 "-" "M Fucking Scanner."
204.***.***.*** - - [22/Jul/2009:10:01:18 +0200] "GET /myadmin/INSTALL HTTP/1.1" 404 213 "-" "M Fucking Scanner."
204.***.***.*** - - [22/Jul/2009:10:01:19 +0200] "GET /admin/INSTALL HTTP/1.1" 404 211 "-" "M Fucking Scanner."
204.***.***.*** - - [22/Jul/2009:10:01:19 +0200] "GET /phpMyAdmin/INSTALL HTTP/1.1" 404 216 "-" "M Fucking Scanner."
Ya tengo muy vistos los scanners que buscan phpmyadmins o similares y como que ya paso, pero este en especial me ha tocado la moral. ¿Si haces algo, hazlo bien no? Que es ese useragent tan CUTRE? ¿Se piensa que es el IMBA HAXXOR OF DA DEATH?
Lo primero que he hecho es ver "que tiene" con un nmap
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.0.52 ((CentOS))
|_ html-title: Apache HTTP Server Test Page powered by CentOS
1863/tcp open msnp?
5190/tcp open aol?
Ummm al abrir la direccion con un browser aparece la pagina por defecto de apache, asi que, una vez mas, han rebentado un novatillo que no securiza su sistema.
Que pasara si pongo /phpmyadmin/ ?

Al abrir la pagina de "No te sabes el login y mereces morir" pude ver la version que era (realmente antigua) y hice la visita standard a milw0rm:
http://www.milw0rm.com/exploits/8992
Este exploit parece que deberia de ir... ¿el haXX0r novato habra modificado el codigo? Me jugaria alguna parte de mi cuerpo a que no. Veamos que hace el exploit...


Ahora se me presentan un par de dudas existenciales:
¿Deberia de avisar al propietario y de que forma?
¿Seria etico que, cuando se detectan escaneos de este tipo, utilizar los exploits publicos para "rehackear" la maquina atacante y "limpiarla"?
204.***.***.*** - - [22/Jul/2009:10:01:18 +0200] "GET /phpmyadmin/INSTALL HTTP/1.1" 404 216 "-" "M Fucking Scanner."
204.***.***.*** - - [22/Jul/2009:10:01:18 +0200] "GET /myadmin/INSTALL HTTP/1.1" 404 213 "-" "M Fucking Scanner."
204.***.***.*** - - [22/Jul/2009:10:01:19 +0200] "GET /admin/INSTALL HTTP/1.1" 404 211 "-" "M Fucking Scanner."
204.***.***.*** - - [22/Jul/2009:10:01:19 +0200] "GET /phpMyAdmin/INSTALL HTTP/1.1" 404 216 "-" "M Fucking Scanner."
Ya tengo muy vistos los scanners que buscan phpmyadmins o similares y como que ya paso, pero este en especial me ha tocado la moral. ¿Si haces algo, hazlo bien no? Que es ese useragent tan CUTRE? ¿Se piensa que es el IMBA HAXXOR OF DA DEATH?
Lo primero que he hecho es ver "que tiene" con un nmap
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.0.52 ((CentOS))
|_ html-title: Apache HTTP Server Test Page powered by CentOS
1863/tcp open msnp?
5190/tcp open aol?
Ummm al abrir la direccion con un browser aparece la pagina por defecto de apache, asi que, una vez mas, han rebentado un novatillo que no securiza su sistema.
Que pasara si pongo /phpmyadmin/ ?
Al abrir la pagina de "No te sabes el login y mereces morir" pude ver la version que era (realmente antigua) y hice la visita standard a milw0rm:
http://www.milw0rm.com/exploits/8992
Este exploit parece que deberia de ir... ¿el haXX0r novato habra modificado el codigo? Me jugaria alguna parte de mi cuerpo a que no. Veamos que hace el exploit...
FWrite($Handlex, "\n[!] w00t! w00t! You should now have shell here");¿Sera posible?¿Funcionara?
FWrite($Handlex, "\n[+] ".$w00t."config/config.inc.php?c=id \n");
Ahora se me presentan un par de dudas existenciales:
¿Deberia de avisar al propietario y de que forma?
¿Seria etico que, cuando se detectan escaneos de este tipo, utilizar los exploits publicos para "rehackear" la maquina atacante y "limpiarla"?
10 July 2009
Psicologia - Hacking
Lenguaje corporal - Nmap
PNL - Exploits
Anclajes - Troyanos
Despues de unos dias hackeando "wetware" empiezo a sentir lo que senti en su dia al leer los primeros textos sobre las bluebox, telnets y similares. La emocion de modificar creaciones de otros y ver como hace lo que TU quieres. La seguridad de saber como funciona esa masa de materia gris y predecir sus actos...
PNL - Exploits
Anclajes - Troyanos
Despues de unos dias hackeando "wetware" empiezo a sentir lo que senti en su dia al leer los primeros textos sobre las bluebox, telnets y similares. La emocion de modificar creaciones de otros y ver como hace lo que TU quieres. La seguridad de saber como funciona esa masa de materia gris y predecir sus actos...
02 June 2008
Paranoia en los aviones...
Acabo de leer una noticia bastante curiosa:
EU project scans air passengers for terrorist tendencies
"An EU aviation safety project is testing a camera-based passenger surveillance system intended to spot terrorists poised to rush the cockpit."
"Each camera tracks passengers’ facial expressions, with the footage then analysed by software to detect developing terrorist activity or potential air rage."
No estoy seguro pero, diria que me es familiar... como si hace un tiempo hubiera visto una peli con algo parecido... Minority Report
En ella, la policia utiliza unos humanos psiquicos para poder predecir cuando alguien "teoricamente" va a cometer un crimen. El problema que tenemos aqui es que estas juzgando a alguien antes de que haga nada.
Imaginemos que viajo con una persona y discuto con ella durante el vuelo por una causa random... ¿soy un terrorista por tener la cara de asesino en ese momento? ¿No se supone que somos inocentes hasta que se demuestre lo contrario?
Welcome 1984.
EU project scans air passengers for terrorist tendencies
"An EU aviation safety project is testing a camera-based passenger surveillance system intended to spot terrorists poised to rush the cockpit."
"Each camera tracks passengers’ facial expressions, with the footage then analysed by software to detect developing terrorist activity or potential air rage."
No estoy seguro pero, diria que me es familiar... como si hace un tiempo hubiera visto una peli con algo parecido... Minority Report
En ella, la policia utiliza unos humanos psiquicos para poder predecir cuando alguien "teoricamente" va a cometer un crimen. El problema que tenemos aqui es que estas juzgando a alguien antes de que haga nada.
Imaginemos que viajo con una persona y discuto con ella durante el vuelo por una causa random... ¿soy un terrorista por tener la cara de asesino en ese momento? ¿No se supone que somos inocentes hasta que se demuestre lo contrario?
Welcome 1984.
27 May 2008
XAMPP
When you look at the XAMPP documentation, you can read the following:
"The default configuration is not good from a securtiy point of view and it's not secure enough for a production environment - please don't use XAMPP in such environment."
I don't know why people still use it on LANs, without securing it...
Phpmyadmin without password

Ummmm a wordpress instaled on "my" machine? WTF?!!!

What would happen if we play a little bit with those hashes? O:)

Pure ownage!

Remember: 70% of successful hacks come from an insider, so, secure those servers! Don't be lazy and enter those passwords, for god's sake!
"The default configuration is not good from a securtiy point of view and it's not secure enough for a production environment - please don't use XAMPP in such environment."
I don't know why people still use it on LANs, without securing it...
Phpmyadmin without password
Ummmm a wordpress instaled on "my" machine? WTF?!!!
What would happen if we play a little bit with those hashes? O:)
Pure ownage!
Remember: 70% of successful hacks come from an insider, so, secure those servers! Don't be lazy and enter those passwords, for god's sake!
Fucking again with Bcbot....
O:)
imac:bcbot3 madgoblin$ ./bcbot.rb
BCBot 3 (build 300)
http://api.search.yahoo.com/WebSearchService/V1/webSearch?appid=************************************************
ANA LAURA ALÁEZ => http://www.analauraalaez.net/BIO.html
CURRICULUM VITAE => http://www.nber.org/vitae/vita094.htm
Curriculum Vitae => http://louisville.edu/medschool/neuro/academics/faculty/Litvan.CV-2007.pdf
Curriculum Vitae -- Roberto Torretti => http://plato.stanford.edu/entries/geometry-19th/vita.html
CURRICULUM VITAE => http://www.unm.edu/~spanport/faculty/clements/clementscv.pdf
imac:bcbot3 madgoblin$
I find really disturbing how easily the people put persona data on the tubes... anyway it's gonna be fun to mess again with those things ;)
imac:bcbot3 madgoblin$ ./bcbot.rb
BCBot 3 (build 300)
http://api.search.yahoo.com/WebSearchService/V1/webSearch?appid=************************************************
ANA LAURA ALÁEZ => http://www.analauraalaez.net/BIO.html
CURRICULUM VITAE => http://www.nber.org/vitae/vita094.htm
Curriculum Vitae => http://louisville.edu/medschool/neuro/academics/faculty/Litvan.CV-2007.pdf
Curriculum Vitae -- Roberto Torretti => http://plato.stanford.edu/entries/geometry-19th/vita.html
CURRICULUM VITAE => http://www.unm.edu/~spanport/faculty/clements/clementscv.pdf
imac:bcbot3 madgoblin$
I find really disturbing how easily the people put persona data on the tubes... anyway it's gonna be fun to mess again with those things ;)
