Mafiaundergr0und’s Blog

March 8, 2008

Another Google Redirect Bug

Filed under: Uncategorized — mafiaundergr0und @ 5:21 am

Well, another Google redirect bug that allow you redirect whatever you want to redirect for your victim ;)

here’s the redirect bug that redirect Google pages to my blog …

it’s interesting and the most interesting part of this bug is that you know this is unpatched yet :-P

you can use this bug to redirect any pages you want to another one :-D

interesting, huh ?

feedback :D

iPhone Software development Kit ( SDK )

Filed under: Uncategorized — mafiaundergr0und @ 4:53 am

original post at F-Secure Blog,

So, the eagerly awaited SDK for iPhone and iTouch is now publicly available over at the iPhone Developer Program. The SDK is free but you can also join the Apple Developer Network which will cost you $99.

The security model is based on signed applications. The idea is that if someone attempts to develop something bad, Apple can pull the certificate and make the application unusable. This is the same approach as Symbian uses and while it’s a great idea in theory, we’ve seen bad applications such as spy-tools for phones being able to get their applications signed by claiming that they’re a backup tool.

 

Once you have developed an application, you upload it to the newly created App Store. The App Store is an application that will run on your iPhone/iTouch and enables you to download and install third party applications on your phone. Some apps will be free, others you’ll have to pay for and for that Apple will take a 30% share of the price.

While we haven’t yet had time to look closer at the SDK to see what’s possible and if it could potentially be used by malware writers for malicious purposes; what is great is that you now don’t have to JailBreak your iPhone to be able to run apps coming from third party developers. We’ve already seen one trojan targeting those who’ve used this approach to run applications not coming from Apple.

One interesting thing about all this, you have to have a Mac to be able to use the SDK, it doesn’t support Windows.

We’ll post more on this topic once we’ve had a closer look at the SDK.

Update: The Apple developer site seem to be under a very high load at the moment. Seems like we’re not the only ones trying to download the SDK.  “

 

and in my opinion the interesting part of this post is here :

The security model is based on signed applications. The idea is that if someone attempts to develop something bad, Apple can pull the certificate and make the application unusable. This is the same approach as Symbian uses and while it’s a great idea in theory, we’ve seen bad applications such as spy-tools for phones being able to get their applications signed by claiming that they’re a backup tool.”

 

what’s your suggestion !?

leave it now, ;)

March 4, 2008

New release of Cult Of Dead Cow / cDc Hacking Group

Filed under: Uncategorized — mafiaundergr0und @ 11:07 pm

today I saw a program called ” Google Scanner ” which is designed for automated vulnerability discovery search engine with google dorks .

as you know cDc is one of the famoust hacking groups that created famous Backdoor named : “Back Orifice (bo2k)” .

now this group come with new idea and their new idea is great ;)

more information about cDc Google Scanner available here

you can download it by hit this .

system administrators , web masters , network administratos can use this useful program for patching their unwanted / untrusted .

check it out and don’t forget feed back ;-)

till next … :-D

Blog at WordPress.com.