Web

How to Fake the http Refferer

Fadıl

This is used in some scripts to check for security. You mustn’t use this as a security check, as it is very easily spoofed. See here for how to secure your Perl scripts.
Anyway, just telnet to the server where you want to download the file from, eg.
www.multiproxy.org
on port 80 (as usual) then issue the get command to retrieve the file you want as usual eg:
get /env_check.htm
But then ratehr then pressing enter twice, instead press enter, then type:
Referer: http://madeup.com/fake/referer.html
Then press enter.
This is how easy it is to spoof http_referrer.
PHP scripts can be written to fake the referrer, allowing you to fake the referrer in php. This is done by using the simple PHP fopen statement.

How Web Pages Are Hacked

Fadıl

Stopping the most common attack:

Ok well, one of the easiest ways of getting superuser access is through anonymous ftp access into a webpage. This can easily be secured against. First, you need to learn a little about the password file…

root:User:d7Bdg:1n2HG2:1127:20:Superuser 
TomJones:p5Y(h0tiC:1229:20:Tom Jones,:/usr/people/tomjones:/bin/csh 
BBob:EUyd5XAAtv2dA:1129:20:Billy Bob:/usr/people/bbob:/bin/csh

This is an example of a regular encrypted password file. The Superuser is the part that gives you root. That’s the main part of the file.

Firefox: 10 Tips to Bolster Your Privacy

Fadıl

Web browsers are leaky faucets that are revealing email address, web sites you’ve entered, search queries and other information. This absolute invasion of your privacy is actually pretty common and there are several different ways you can take control and increase your privacy.

In this hack, we’re going to highlight 10 tips to bolster your privacy when surfing the Internet with Firefox. You can use any of these tips to add an extra layer of privacy to your browsing at work, on public computers or just on a shared computer at home.

Secure Browsing With Squid and SSH

Secure Browsing With Squid and SSH

Fadıl

Public areas that offer access to the Internet (airports, open wireless networks, etc.) have no security in place. If you’re at a public WiFi spot, your personal information can be sniffed by other malicious users. This hack will show you a way to secure your web browser when using public networks.

In a nutshell, we’re going to setup a proxy server (Squid) on a trusted SSH server and create a secure connection from our laptop, over a public network to a secure remote server. We’ll tell the browser to use the secure SSH tunnel as an HTTP proxy.

Untidy: Python-Based XML Fuzzer

Fadıl

Untidy is a Python-based XML fuzzer. It takes XML data as input and generates a set of modified, potentially invalid XML data based on the source input.

In a nutshell, fuzzing testing is a software testing technique that sends random inputs to an application. If the target application contains a vulnerability that can lead to a crash, or a server error (in case of web applications), it can be determined and be noted.