Posts

Showing posts with the label windows xp

From XSS to NT AUTHORITY

Image
A lot of times i have seen Cross-site scripting vulnerabilities classified as low impact or not significant. Thus, this time i want to show you how an attacker can get administration privileges through a simple XSS. A couple of months ago i discovered an XSS vulnerability affecting the uk website of Orange http://www.orange.co.uk . I've emailed them a month ago (and two weeks ago) regarding this vulnerability, but i haven't received any response yet. From wikipedia: Orange is the flagship brand of the France Telecom group for mobile, landline and Internet businesses, with 226 million customers as of December 2011 and, under the brand Orange Business Services, is one of the world. How i found this XSS ? When you read an article, for example this one obesity_levels_could_be_cut_with_20_fat_tax , you can see  the users comments at the bottom of the page. If a user want to leave a comment, he must log in via google, facebook etc.... Once logged, the website create a profil...

OsCommerce Malware Infection

Image
Three months ago is started a huge site infection campaign with lens oscommerce, a famous cms for medium/little on-line stores. This cms suffers of few vulnerabilities that can lead an attacker to upload files and execute remote code. Vulnerabilities: -   osCommerce 2.2 Remote File Upload Vulnerability -   osCommerce authentication bypass -   osCommerce 2.2 Arbitrary PHP Code Execution -   osCommerce 2.3.1 Remote File Upload Vulnerability Today (4/10/2011) the total number of infected sites is 830,000 but two months ago was 8 million. In some compromised sites the attacker has left the webshell. After uploading a backdoor the attacker edit the home page and add a script/iframe tag that load multiple browser exploits. Exploits used: - IE 6 Remote Code Execution - Java Runtime Environment Remote Code Execution Vulnerability - Microsoft Windows Help - Adobe Reader and Acrobat 8.x After successful exploitation a malware is downloaded...