WAVSEP 2014 Web Application Scanner Benchmark
DefCamp 2013
Over 300 security experts, researchers, and enthusiasts from Romania and neighboring countries are expected to take part in the event. Between 29 - 30th of November the Crystal Palace Ballroom is hosting one of the most mesmerizing events of hacking & information security in Romania, Defcamp. Now in its fourth year, the event continues to impress its audience with knowledge sharing, competition with varying levels of difficulty, romanian and foreign speakers, surprises and fun.
"We have awaited the 48 hours of DefCamp 2013 since the closing moment of the last edition. It is hypnotizing to exchange ideas, to compete, to expand your knowledge and to meet people who you know only from the virtual world. DCTF (DefCamp Capture the Flag) - our main competition of the conference, Hack the Machine, App2Own, Spot the Cop, Wall of Sheep are just a few of the activities that will try to captivate your attention at Defcamp 2013. Sometimes I wish I could participate for me to fully enjoy these moments!", said Andrei Avadanei founder and coordinator of the Defcamp conference.
The conference that will take place this fall will engage participants in discussions about 0days, PRISM, mobile security problems, DDOS, networking, P2P networks, D&D APT�s, social engineering. camera surveillance, application security research, lock picking, secure system administration with key industry specialist from Romania and abroad holding presentations. Everyone can apply to be a speaker at the conference, DefCamp 2013 being the first edition where we officially launched a Call for Papers.
The DCTF ( DefCamp Capture the Flag ) will have an on line qualifying round followed by a death defying duel during the event between the teams that enter the finals. The competition challenges are extremely provocative and various - exploits, cryptography, programming, steganography, forensics, reverse engineering etc, these subjects being dealt with in 25 problems from the first round. Similar activities, like DCTF, but dedicated directly to the participants of the event are Hack the Machine and App2Own where everyone will have at their disposal different services and services to put their skills to the test and win awards.
DefCamp managed to, in just 3 editions, be the most awaited conference in the entire information security and hacking scene in Romania. Its the perfect time to join and feel the vibes. For more details you can access the conferences website or you can contact us directly at the address contact@defcamp.ro
OWASP Europe Tour - Bucharest 2013
- Apart from OWASP's Top 10, most OWASP Projects are not widely used and understood. In most cases this is not due to lack of quality and usefulness of those Document & Tool projects, but due to a lack of understanding of where they fit in an Enterprise's security ecosystem or in the Web Application Development Life-cycle.
Date: Wednesday 5th of June
Venue Location: University "Politehnica" of Bucharest
Venue Address: Splaiul Independentei nr. 313, sector 6, Bucuresti, ROMANIA; Rectorship Building, Senate Hall Postal cod: RO-060042
Source: https://www.owasp.org
Metasploit v.4.4 Released
Metasploit 4.4 has had 101 modules added since Metasploit 4.3: 68 exploits, 22 auxiliary modules, 9 post modules, 1 payload, and 1 encoder.Metasploit Pro now features enhanced vulnerability verification, extended anti-virus evasion techniques for compromised hosts, and an array of back-end performance enhancements.
Release Notes https://community.rapid7.com
Download: http://www.metasploit.com
The 2012 Web Application Scanner Benchmark has been Published!
Will a contest suffice?
How would you like to see a comparison that covers the vast majority of aspects of numerous web application scanners, and furthermore, even contains a price vs. feature comparison for all the products?
Well, it might just be your lucky day, since the 2012 benchmark was just published, and currently covers the following subjects:
� Price & Feature Comparison (New!)
� Scanner Versatility Score (New!)n
� Path Traversal/LFI Detection Accuracy (New! - 824 test cases!)m
� Remote File Inclusion Detection Accuracy (New! - 114 test cases!)
� SQL Injection Detection Accuracy - Updated
� Cross Site Scripting Detection Accuracy - Updated
� Audit Feature Comparison - Updated
� WIVET score for scanners with crawling features (New!)
� Scanner Adapatability, Authentication, and a variaty of other comparisons
� New Products!
� A step by step guide for how to select the best scanner for each task.
The benchmark can be accessed through the following address:
http://sectooladdict.blogspot.co.il
The benchmark statistics can be viewed in greater detail in sectoolmarket:
http://sectoolmarket.com
Updates: NotMyFault, Process Monitor v3.01 and TestLimit v 5.2
Process Monitor v3.01: This update to Process Monitor, a real-time file, registry, process and network monitor, adds decoding of several new Windows 8 file system control codes, including offload read and write, and now obtains image version information for 32-bit DLLs when run on 64-bit Windows.
TestLimit v5.2: Testlimit, a demonstration tool used in the Windows Internals books to illustrate resource usage concepts, has minor enhancements including filling memory that it allocates with an identifiable string.
source: http://blogs.technet.com
Dynamic (Direct) AJAX CSRF
The limitation with "static" CSRF was always the fact the it was a shot in the dark - the attack enabled attackers to redirect browsers to links that perform operations on behalf of the user, but the attack could not analyze the content that returned in response to these redirections. Even partially Dynamic CSRF attack vectors relied on indirect information that might be disclosed from the user activities.
But let's assume that somehow, CSRF attacks could analyze the response.. what could the attacker do if the content that returned from redirected requests could be analyzed by the redirector, even if the redirection target was a different domain?
This new technique is based on existing intranet policies and the effect they have on AJAX same origin policies, which causes these policies to be less restrictive, as long as certain conditions are met.
The uses of the new Direct, AJAX based Dynamic CSRF attack vector are numerous:
� Attackers no longer need to know in advance what is the structure of the application they are trying to perform CSRF on (!), especially since the code can dynamically locate the CSRF target entry points and send notifications on the application structure to the remote attacker, creating an HTTP "command line" scenario!
� Attackers can use this vector to bypass any CSRF prevention mechanism which is based on non-consistent form-specific tokens or custom header requirements, by locating anti-CSRF tokens in pages that precede a CSRF protected entry point, by mimicking complex content delivery methods (JSON, XML, etc) and by forging headers to bypass server side custom headers verification.
� Attackers can obtain sensitive information on the user by analyzing the server responses.
� Attackers can use this attack to replay obligatory dynamic fields such as VIEWSTATE, EVENTTARGET and EVENTARGUMENT; fields that might have prevented simpler CSRF attacks.
� Attackers that managed to inject this code in an internal vulnerable off-the-shelf product (via persistent XSS or similar methods) can use this vector to map (some of) the structure of an organization internal network (!), with certain restrictions which are based on origin port and protocol.
Additional resources:
This attack is also explained in a short, informative and cool online prezi presentation: http://prezi.com/6vnl6so07b-c/ajax-hammer/
A demonstration of this attack was uploaded to Hacktics youtube channel: http://www.youtube.com/watch?v=JHJ1WW4Fcvw
The attack is further explained in the following whitepaper: http://hasc-research.googlecode.com/files/AJAX%20Hammer%20-%20Harnessing%20AJAX%20for%20%28Direct%29%20Dynamic%20CSRF.pdf
The following POC code can be used to understand simple AJAX based Dynamic CSRF scenarios: http://hasc-research.googlecode.com/files/AJAX-CSRF-Demo-Code.zip
The mitigation for the new attack vector are provided in the whitepaper.
Thanks to my friend Shay-Chen for this awesome article http://sectooladdict.blogspot.com
"Enter at your own Risk" Cyber Security Awareness Campaign
Coming this January , For the First time in Cyber History the Best, The Brightest & the Most Daring Come Together For an Information Extravaganza that will blow your Cyber Mind ! It�s a time for us to offer education that increases online security for everyone.
The Hacker News & 6 Other Top IT Security Sites are Sponsoring a Special Edition January 2012 Magazine, That Features Articles & Commentaries on Cyber Security From :
1.) The Hacker News
2.) Stop Malvertising
3.) SecManiac
4.) Korben
5.) Security-Shell
6.) SecTechno
7.) Security-FAQs
Our goal is to provide the most up-to-date information on a wide variety of topics that address the tricky and complicated world of hackers and hacking. Cyber security is our Shared Responsibility. Everyone has the potential to make a difference and educate others. You can raise awareness within your community, no matter what your role is. We plan to provide useful information for our Readers who want to get educated by have a ready set of awareness tips.
More Info: http://thehackernews.com
Top 10 HTML5 threats and attack vectors
HTML5 applications are also supported by mobile devices. Hence, you can create your application once and run it on several devices and browsers. Each time, every new technology stack throws up new security challenges and vulnerabilities. HTML 5, though very promising, is no different. There are security concerns that need to be addressed when creating applications. Let us look at the top 10 possible attack vectors associated with HTML5 and modern browser architecture.
Full article: http://www.net-security.org
DOMAIN UNTUK PARA BLOGGER

Posting ini sengaja dibuat untuk teman2 bloger semua..
bagi teman-teman yang ingin skali merubah blognya yang hanya dari bloger ke domain prabayar silahkan ikuti sayembara yang saya buat khusus buat teman2 semua..
saya hanya ingin berbagi sedikit kepada teman2 yang membutuhkan domain berbayar seperti .com .org .net .info
contoh sayembara nya gak aneh2 kok...
- cuman yang punya template blog bagus dan menarik bakalan dapat domain (hasil jerih payah sendiri lo.. :D )
- bisa desain nama saya : AbheLink <<< cuman tulisan itu aja :D :D (ane gak bisa desain soalnya)
Buat Indo Contact WWW.ABHE.ME
Khatulistiwa Net PointBlank Tournament
buat para pecinta game pointblank, khatulistiwa net akan mengadakan turnamen pointblank pertama di u.batu. bagi yang berminat berikut infonya:Cerita Ayu Ting Ting Soal Asal Namanya
Cerita Ayu Ting Ting Soal Asal Namanya
Jagad musik dangdut Indonesia kembali naik setelah sebuah lagu berjudul Alamat Palsu meledak di pasaran. Perhatian pun tertuju pada penyanyi lagu tersebut, yakni Ayu Ting Ting. Saat dihubungi lewat telepon, Jumat (30/9), Ayu bersedia bercerita mengenai namanya yang lucu tersebut."Saya kan masih ting-ting, hahahaha. Awalnya saya itu punya album pertama dengan judul Dilanjut Aja, ada judulnya yang Ting Ting juga. Liriknya saya masih ting-ting, dan dijamin ting-ting. Produser dulu bilang kenapa nama saya gak ditambahi itu, kan unik, dan gampang diingat, aku juga suka," jelasnya.
Bahkan, berkat lagu dan namanya yang unik tersebut, kini Ayu memiliki jadwal yang begitu banyak untuk show, dirinya pun mengaku bersyukur dan tidak menyangka.
"Waktu tampil di TV, temen-temen suka nonton, mereka hapal lagunya, bilang ke saya. Saya kurang percaya, waktu saya lihat, eh ternyata ada Olga, om Sule nyanyi itu. Ini kayak mimpi, seneng banget. Ini lagu dari 2007 dan baru meledak sekarang. Ada lagu yang penyanyinya gak tahu, tapi ini Alhamdulilah tahu saya," jelas Ayu senang. (kpl/ato/aia)
Musuh Apple pun Ikut Berduka
BEBAN BERAT. Sepeninggal Steve Jobs, Apple CEO Tim Cook mengemban beban berat mempertahankan akselerasi Apple.
MENJADI perusahaan teknologi paling gemilang, Apple di kelilingi pesaing. Mereka kerap saling gugat di ranah bisnis. Tapi, kepergian Steve Jobs membuat para rival berduka. Mereka sepakat kepergian Jobs adalah kehilangan besar bagi dunia teknologi.
Samsung yang sedang bersaing sengit di ranah hukum, tak lupa memuji jasa Jobs. Melalui Wall Street Journal, Kamis 6 Oktober, pihak Samsung melalui Chief Executive, Choi Gee-sung menyatakan, Chairman Steve Jobs memperkenalkan sejumlah perubahan revolusioner untuk industri teknologi informasi dan adalah seorang entrepreneur besar. Semangat inovatifnya dan pencapaiannya yang hebat akan selamanya dikenang oleh masyarakat di seluruh dunia.
Lenovo melalui Chief Executive, Yuanqing Yang menegaskan, dunia kehilangan salah satu inovator dan pioner terbesar dengan wafatnya Steve Jobs. Meski kami akan merasakan kehilangan yang sangat besar, saya yakin industri ini akan mengambil ilmu yang diajarkan Steve pada kami mengenai inovasi".
Sony tak ketinggalan. "Zaman digital telah kehilangan cahaya pemimpinnya, namun inovasi dan kreatifitas Steve akan menginspirasi para pemimpi dan pemikir dari generasi ke generasi," tegas Chief Executive, Howard Stringer.
Acer juga mengakui, Steve Jobs adalah orang dengan visi, inovasi dan kepemimpinan besar dan memiliki pengaruh besar bagi industri ICT dalam 10 tahun terakhir.
RIM (Research in Motion) melalui co chiefs RIM, Mike Lazaridis & Jim Balsillie, memastikan Steve Jobs adalah visioner besar dan kompetitor yang dihormati. "Duka mendalam kami sampaikan untuk keluarganya dan seluruh karyawan Apple," kata mereka.
Bahkan, CEO Facebook, Mark Zuckerberg tak luput dengan sedihnya ditinggal Steve. "Steve, terimakasih telah menjadi pembimbing sekaligus teman. Terimakasih telah menunjukkan bahwa apa yang kau bangun mampu mengubah dunia. Saya akan merindukanmu."
Ucapan belasungkawa yang diposting melalui status Facebook itu lalu direspons ribuan orang yang turut berduka. Kalimat-kalimat inspiratif yang pernah diucapkan Jobs semasa hidupnya pun menghiasi status sebagian Facebooker sebagai tanda penghormatan terakhir pada sosok kharismatik di balik kesuksesan Apple tersebut.
Di ranah Twitter, lima topik yang berkaitan dengan tutup usianya Jobs menghiasi trending topic. #RIP Steve Jobs, #ThankYouSteve, #iSad, STAY HUNGRY dan Apple II menjadi topik yang mengenang kepergian Jobs.
Tak ketinggalan, Google pun mempersembahkan penghormatan terakhirnya. Di halaman pencarian Google, di bawah kotak pencarian tertera tulisan "Steve Jobs, 1955-2011." Saat diklik, tulisan ini adalah link yang mengarahkan pengguna ke situs Apple. Sebagai bentuk rasa duka yang mendalam, situs Apple memajang foto Steve Jobs yang berefek hitam putih. Selamat jalan Steve Jobs. (*/ysd)
Menkominfo: Hacker Kreatif, Tapi Negatif
"Hacker itu kan berarti meretas, menyusup ke tempat seseorang," kata Tifatul, usai meresmikan Indonesia ICT Award 2011 di Jakarta Convention Center, Selasa (4/10/2011).
Tifatul menganggap, hacker sejatinya memiliki kreativitas yang cukup beragam. Hanya saja tindakan mereka cenderung merusak atau bahkan merugikan orang lain.
"Hacker itu memang kreatif, tapi negatif," tukasnya kepada sejumlah wartawan.
Pun demikian, ketimbang menghakimi, Tifatul sejatinya masih berharap agar pemerintah bisa merangkul para peretas tersebut untuk memperkuat lembaga keamanan virtual Tanah Air.
"Kami sangat welcome kalau mereka ingin bergabung dalam pertahanan, khususnya untuk mempertahankan diri dari perang cyber," pungkasnya.
Menteri Tifatul Ditanya DPR Soal Penyedot Pulsa
Priyo sedih mendengar maraknya kasus pencurian pulsa ilegal yang diberitakan belakangan ini. Penyedia layanan telekomunikasi seharusnya memberikan perlindungan kepada masyarakat. Apalagi dalam banyak kasus, yang dirugikan adalah masyarakat kelas bawah sampai menengah. "Kami merasa sedih karena ini menyangkut masyarakat yang selama ini tidak terlindungi sehingga banyak kasus yang terungkap dan tidak terungkap. Terutama yang prabayar. Masyarakat, terutama kecil dan menengah, sangat terugikan," kata dia.
DPR akan memastikan pemerintah mengambil tindakan tegas soal ini. Modus pencurian pulsa ini merupakan kejahatan sistematis dan sudah berlangsung sejak lama. Karena itu, ia meminta Menteri Tifatul berkoordinasi dengan aparat penegak hukum dalam mengusut kasus ini. "Menkominfo harus mencari solusi dalam waktu yang tidak terlalu lama, termasuk koordinasi dengan pihak Bareskrim Mabes Polri," dia menandaskan.
Politikus Partai Golkar ini mengkhawatirkan jika kejadian seperti ini tidak terungkap, maka akan terjadi pembiaran dan pembiasaan praktek ini. "Saya khwawatir kalau tidak diungkap, para operator seperti membiarkan," ujarnya. Karena itu, ia juga akan meminta Menkominfo memanggil perusahaan-perusahaan penyedia jasa telekomunikasi.
"Kalau ada operator yang melakukan pembiaran, harus ada tindakan. Harus ada langkah perlindungan terhadap warga negara. Saya juga meminta konten provider yang melakukan itu di-blacklist secara massal dan diumumkan," tandasnya.
Google Tarik Aplikasi 'Apakah Anak Anda Gay?'
Aplikasi Android yang ditarik Google (Foto: Google)
PARIS - Setelah mengalami banyak kontroversi, aplikasi Android yang dapat memberitahukan orangtua apakah anak mereka gay atau normal akhirnya ditarik dari peredaran.
Pengembang teknologi Prancis, Emmene Moi yang diterjemahkan menjadi "Bring Me," telah merilis aplikasi ini, seperti dikutip TG Daily, Jum'at (7/10/11).
Aplikasi bernama "Mon Fils-Il Est Gay?" ini menyediakan 20 pertanyaan, yang selanjutnya dijawab dengan "ya" atau "tidak", dan hasil dari pertanyaan tersebut dapat menyimpulkan apakah anak Anda gay atau normal.
Beberapa contoh pertanyaan streotip homoseksual yang diajukan oleh aplikasi ini, seperti " Sebelum anak Anda dilahirkan, apakah Anda berharap dia menjadi seorang perempuan?" "Apakah Anda ingin dia pandai berdandan?" dan "Apakah dia sudah memperkenalkan pacarnya pada anda?". Setelah menjawab pertanyaan-pertanyaan tersebut maka akan diketahui jawabannya.
Namun Google menarik aplikasi ini tanpa alasan yang jelas. Ada ketentuan yang harus diikuti di pasaran Android yaitu tidak boleh ada unsur rasa kebencian kepada ras, etnis tertentu, ataupun orientasi seksual.
Kelompok aktivis gay memuji keputusan Google tersebut. "Kami sangat senang bahwa Google telah mendengar suara dari komunitas LGBT dan menarik aplikasi tersebut," kata pendiri LGBT, Bank Andre.
Menurutnya aplikasi itu keterlaluan dan hanya berfungsi untuk memberikan stereotip negatif dan homophobia.
Steve Jobs meninggal
Pendiri Apple Inc, Steve Jobs, meninggal dunia di usia 56 tahun. Mantan CEO Apple yang dikenang sebagai salah satu CEO terbaik Amerika ini meninggal pada Rabu 5 Oktober 2011 setelah bertahun-tahun berperang melawan penyakit kanker dan sejumlah problem kesehatannya.
Kematian Jobs diumumkan Apple dalam pengumuman Rabu malam.
Ikon Lembah Silikon ini dikenang atas jasanya menghibur dunia dengan iPod dan iPhone. Agustus lalu, dia baru saja menyerahkan posisi CEO kepada Tim Cook.
Jobs yang telah lama bergulat dengan Kanker Pankreas merupakan nyawa dan ruh bagi perusahaan yang menandingi Exxon Mobil sebagai perusahaan paling berharga di Amerika Serikat.
TSRC - Another New Application level attack
A few months ago I published a paper about Session Puzzling, a new application level attack vector of critical severity and numerous uses, but for some bizarre reasons, most of the responses I got was that the attack was too complicated to comprehend all it once.
Temporal Session Race Conditions (TSRC) is yet another a new application level vulnerability (presented in September 15, 2011, in local OWASP chapter meeting) that extends the capabilities of session puzzling, enables the exploitation of race conditions without latency and provides a new purpose for application denial of service attack.
The attack generally extends the lifespan of temporary session variables (session calculations and assignments with a lifespan of milliseconds) by increasing the latency of the following lines of code through the use of specific layer targeted denial of service attacks.
This time I have created several demonstration movies in order to properly explain the exposures (The new TSRC exposure and Session Puzzling), and in addition, published a presentation, a test assisting tool and a new version of the training kit.
The following movies demonstrate a few simple TSRC attacks:
Exploiting Temporal Session Race Conditions via Connection Pool Consumption:
http://www.youtube.com/watch?v=woWECWwrsSk
Exploiting Temporal Session Race Conditions via RegEx DoS:
http://www.youtube.com/watch?v=3k_eJ1bcCro
The following short movies demonstrate a few simple session puzzling sequences:
Authentication Bypass via Session Puzzling (Abusing common session variables):
http://www.youtube.com/watch?v=-DackF8HsIE
User Impersonation via Session Puzzling (Abusing common session variables):
http://www.youtube.com/watch?v=ikIyInm0wAg
Session Puzzling via Redirection Prevention (Abusing Premature Session Population):
http://www.youtube.com/watch?v=iTcOooHbgog
Bypassing Restrictions in Multiphase Processes via Session Puzzling (Abusing Common Session Flags)
http://www.youtube.com/watch?v=HeP54b52IeQ
Source: http://sectooladdict.blogspot.com
thx to Shay Chen @sectooladdict
Vulnerabilities in DNS Server Could Allow Remote Code Execution
Affected DNS configuration
Unlikely to be exploited for code execution
More detail about the attack vector
Answers to common questions
This vulnerability affects DNS servers that allow attackers to issue lookup requests for another domain name in a way that would cause the DNS server to request the answer from a malicious DNS server. Specifically, if an attacker can cause a DNS server to request a DNS NAPTR resource record from a malicious DNS server, the attacker could potentially trigger the vulnerability described by CVE-2011-1966 on the DNS server of which the attacker is making the request.
One common affected configuration is a caching or relay DNS server on a corporate network where a malicious user is lurking. Less likely to be affected are authoritative DNS servers hosting zones exposed to the Internet, where recursion is often disabled. For example, anyone on the Internet can connect to the microsoft.com authoritative DNS server, but that server will not relay requests to a malicious DNS server.
More Info: http://blogs.technet.com
The Scanning Legion - An Assessment & Comparison of 60 Web Application Scanners
The benchmark focused on testing commercial & open source tools that are able to detect (and not necessarily exploit) security vulnerabilities on a wide range of URLs, and thus, each tool tested was required to support the following features:
� The ability to detect Reflected XSS and/or SQL Injection vulnerabilities.
� The ability to scan multiple URLs at once (using either a crawler/spider feature, URL/Log file parsing feature or a built-in proxy).
� The ability to control and limit the scan to internal or external host (domain/IP).
The testing procedure of all the tools included the following phases:
� The scanners were all tested against the latest version of WAVSEP (v1.0.3), a benchmarking platform designed to assess the detection accuracy of web application scanners. The purpose of WAVSEP�s test cases is to provide a scale for understanding which detection barriers each scanning tool can bypass, and which vulnerability variations can be detected by each tool. The various scanners were tested against the following test cases (GET and POST attack vectors):
o 66 test cases that were vulnerable to Reflected Cross Site Scripting attacks.
o 80 test cases that contained Error Disclosing SQL Injection exposures.
o 46 test cases that contained Blind SQL Injection exposures.
o 10 test cases that were vulnerable to Time Based SQL Injection attacks.
o 7 different categories of false positive RXSS vulnerabilities.
o 10 different categories of false positive SQLi vulnerabilities.
Full article: http://sectooladdict.blogspot.com


