Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 27 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
December 01, 2008, 04:45:18 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Accidentially comprimised bebo's Music on: October 16, 2007, 12:16:56 PM
Firstly, it would have been nice to point me in the direction of an IT law that explains it. Instead of giving a lecture. I'm not a hacker black/white in any means, i'm just an I.T student who likes web security. This site is based upon ethics, isn't it not?


about a month now.

The audio is controlled by a flash object which in turns streams the mp3 from a directory within a sub domain. this call is controlled by a java script. And from what i can tell there seems to be no fault. It does what it is suppose to do. I'm not prepared to enter the script here or anywhere. I have no right to.

Quote
From what your saying, it sounds like its only a misconfiguration of his webserver, allowing users to traverse directories and obtain files illegally. Is that correct?
  If it was a misconfiguration, then the flash mp3 player wouldn't be able to be embedded on another website, but it. And from research it always was.

I was going to tell him to write the following .htaccess  But as im not to fimilar with Resin server and from what you just said. Im staying away from the topic.


RewriteEngine on
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(www\.)?websiteaddresshere(.com(/)?.*$ [NC]
RewriteRule .*\.(mp3|MP3)$ [F,NC]

 
2  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Accidentially comprimised bebo's Music on: October 16, 2007, 05:19:18 AM
I was bored, and i was doing some leeching attacks on my own community website, i wanted to test out the new java script and htaccess that i put in place so the divx player could not be embedded on another site and for the videos to be leeched.  Everything worked out well, even with attacks against tamper data.

But in the process i found a dangerous exploit in the community website 

by using tamper data when loading any of the songs on bebo, it should up the sub domain in which the mp3's are loading from, and just be removing a few characters from the end of the absolute url, i was able to get the mp3. I informed  (owner of) but I got no response. 

What other steps would be advisable to take?

Maybe  doesn't believe me or maybe he is just worried now that his "Music" side to has been completely compromised.
3  Resources / Tutorials / Re: MD5 with salt encryption on: October 13, 2007, 08:39:48 AM
Hey Morpheus,

Ya i noticed the string within the table. a combination of a-z A-Z 0-9 and a symbol

is there a way to decrypt the MD5 hash even if it is further encrypted with slat?
4  Resources / Tutorials / MD5 with salt encryption on: October 13, 2007, 05:22:05 AM
I currently run a VBulletin community forum.

I only started to use cain, but it will not decrypt any of the MD5 hashes, even a very simple 5 dictionary character that i purposely added as a test.

is it because vbulletin uses salt along with the MD5?

Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 22 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.