Parsero: The tool to audit the Robots.txt automatically
When I was writing Using robots.txt to locate your targets, I felt the necessity of developing a tool to make automatic the task of auditing the Robots.txt file of the web servers.Now, I am really...
View ArticleCVE-2016-3978 Open Redirect & XSS in FortiOS (Fortinet)
IntroductionSome months ago, I reported to the Fortinet PSIRT team two vulnerabilities which affect different Fortigate firmware versions. You probably know that "Fortinet is a leading provider of fast...
View ArticleA Network Traffic Analysis Exercise
Network forensics is something we should practice as much as possible to become faster at detecting supicious activies in our networks. This website http://malware-traffic-analysis.net/ shares network...
View ArticleWho is trying to get the public IP address inside your network?
In this blog post I would like to share some tricks to detect suspicious activities that could end with finding compromised hosts inside a network. I´ve noticed (I guess you too) that there are some...
View ArticleCVE-2014-9218 phpMyAdmin DoS Proof of Concept
Assuming that time enough has happened since the security update was released by phpMyAdmin, we want to share our researches. As you already know, we believe in Responsible Disclosure and that is the...
View ArticleWhen cookies lead to a DoS in phpMyAdmin CVE-2014-9218
Introduction"phpMyAdmin is a free software tool written in PHP, intended to handle the administration of MySQLover the Web. phpMyAdmin supports a wide range of operations on MySQL, MariaDB and Drizzle....
View ArticleCVE-2014-9016 and CVE-2014-9034 Proof of Concept
Assuming that time enough has happened since the security update was released by Wordpress and Drupal, we want to share our researches. As you already know, we believe in Responsible Disclosure and...
View ArticleWordpress Denial of Service Responsible Disclosure - Attacking with long...
IntroductionWordpress is the CMS most used Worldwide. According to w3techs.com WordPress is used by 61.1% of all the websites whose content management system they know. This is 23.2% of all websites.My...
View ArticleDrupal Denial of Service Responsible Disclosure - Attacking with long passwords
Introduction First of all, let me introduce you to my partner @cor3dump3d from www.devconsole.info We have written this post together and we hope you enjoy it. More technical information about this...
View ArticleParsero v0.75 has been included in the Kali Linux repository
Some days ago a friend told me, "Ey! Why you didn't write a post talking about how Parsero has been included in the Kali Linux repository?""Seriously? I forgot it..." So here it is...As you already...
View ArticleHave I bought these clothes? Another spread malware campaign.
When I was reading one of the last FireEye's post, I was struck by the binary they said it came in the form of phished email (MD5:7c00ba0fcbfee6186994a8988a864385) purportedly from Armani regarding an...
View ArticleLooking for a job in the security field in a different way
You already know what the most common way of getting a job is. You usually look for vacancies in a job web portal and when you think you could be selected, you apply for it... Then, most of the...
View ArticleOpenSSH User Enumeration Time-Based Attack with Osueta
Introduction In this post I'd like to introduce you to an awesome tool focused on taking advantage of an OpenSSH vulnerability. I'd like to thank @cor3dump3d for letting me participate in his project....
View ArticleXSS-game by Google exercises 4, 5 and 6.
In the previous post we talked about how to resolve the exercises 1, 2 and 3 of the XSS-game proposed by Google. Now, we are going to resolve the latest ones. Exercise 4 This exercise is similar to the...
View ArticleXSS-game by Google exercises 1, 2 and 3.
As Google say, "Cross-site scripting (XSS) bugs are one of the most common and dangerous types of vulnerabilities in Web applications. These nasty buggers can allow your enemies to steal or modify user...
View ArticleParsero 0.75 is out!!!!
At the beginning of this month, Parsero v0.71 was presented by ToolsWatch Hacker Arsenal in their blog. That is something that I really appreciate...Today, I would like to introduce Parsero v0.75....
View ArticleOpenSSL Heartbleed, what the hell has happened here?
Just one day before of Windows XP end of life, the vulnerability withCVE-2014-0160 was published. A lot of blogs have talked about the OpenSSL vulnerability called "Heartbleed Bug". A lot of security...
View ArticleWhy you shouldn't open files directly from a ZIP file
A few days ago I read this post: WinRar File extension spoofing ( 0DAY ). Here, the author describes for example, how to create a ZIP file with a file inside it which has a JPG extension but when it is...
View ArticleMicrosoft XP has died but millions of Zombies-XP are out there
Introduction After 12 years, support for Windows XP ends today, April 8, 2014. That means there will be no more security updates or technical support for Windows XP. So XP has officially died but...
View ArticleSiesta Campaign - Nothing is what it seems
Introduction A few weeks ago Trend Micro published in their blog the post below: The Siesta Campaign: A New Targeted Attack Awakens. Here they share their research about a targeted attack suffered by...
View Article