accept no compromises
Showing 1 - 25 of 27 RSS Feed

Files from Andrew Horton (urbanadventurer)

First Active2008-10-01
Last Active2011-09-23
WordPress Clickjacking
Posted Sep 23, 2011
Authored by Andrew Horton (urbanadventurer) | Site security-assessment.com

This advisory is the result of research into how clickjacking can be leveraged and is the first published clickjacking exploit against a popular web application to gain OS command execution. WordPress is a web application used to create a website or blog. The WordPress Admin panel can be clickjacked to install an arbitrary plugin from the WordPress plugin archive which leads to arbitrary PHP code installation and subsequently OS command execution. Versions of WordPress prior to 3.1.3 are vulnerable to clickjacking. WordPress has had clickjacking protection since May, 2011 with the release of version 3.1.3, however no specific threat or exploit has been published.

tags | advisory, web, arbitrary, php
MD5 | e2abac98d6f8c708eef84b5e166ca4e1
WordPress 3.1.2 Clickjacking
Posted Sep 22, 2011
Authored by Andrew Horton (urbanadventurer) | Site security-assessment.com

WordPress versions 3.1.2 and below clickjacking exploit that was part of an OWASP presentation on September 20th, 2011 in Wellington, New Zealand.

tags | exploit
MD5 | 1688b6eaa86b161c91dd0d6b4158f460
Clickjacking For Shells
Posted Sep 21, 2011
Authored by Andrew Horton (urbanadventurer) | Site security-assessment.com

Whitepaper called Clickjacking for Shells. Two years after the world was warned about clickjacking, popular web apps are still vulnerable and no web app exploits have been published. With many security pros considering clickjacking to have mere nuisance value on social networks, the attack is grossly underestimated. In this presentation, the author demonstrates step by step how to identify vulnerable applications, how to write exploits that attack web apps and also how to protect against clickjacking.

tags | paper, web, shell
MD5 | 92e4924002079bb3c456c65201f796ab
URLCrazy Domain Name Typo Tool 0.4
Posted Sep 15, 2011
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

URLCrazy enables the study of domainname typos and URL hijacking. URLCrazy is a domainname typo generator that generates 13 types of typos, knows over 8000 common misspellings, supports multiple keyboard layouts, can check if a typo is a valid domain, tests if domain typos are in use, and estimates the popularity of a typo.

Changes: It now also supports bit flipped domains. Urlcrazy is written in Ruby.
tags | tool, web
systems | unix
MD5 | 3393672839100e9ba0d1c3ee6f039cf0
GGGooglescan 0.4
Posted May 12, 2011
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

GGGooglescan is a Google scraper which performs automated searches and returns results of search queries in the form of URLs or hostnames. Datamining Google's search index is useful for many applications. Despite this, Google makes it difficult for researchers to perform automatic search queries. The aim of GGGooglescan is to make automated searches possible by avoiding the search activity that is detected as bot behavior.

tags | tool, scanner
systems | unix
MD5 | 63316923251b7dbc84d7455f7fdd9515
WhatWeb Scanner 0.4.7
Posted Apr 6, 2011
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb is a next-generation web scanner. It recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 900 plugins, identifies version numbers, email addresses, account ID's, web framework modules, SQL errors, and more. WhatWeb can be stealthy and fast, or thorough but slow. WhatWeb supports an aggression level to control the trade off between speed and reliability.

Changes: Performance enhancements and bug fixes.
tags | tool, web, scanner, javascript
systems | unix
MD5 | c1bdbc4a6d757f2aa3172b2c8c8c8be9
WhatWeb Scanner 0.4.6
Posted Mar 26, 2011
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb is a next-generation web scanner. It recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 900 plugins, identifies version numbers, email addresses, account ID's, web framework modules, SQL errors, and more. WhatWeb can be stealthy and fast, or thorough but slow. WhatWeb supports an aggression level to control the trade off between speed and reliability.

Changes: Over 900 plugins, performance improvements, new log formats (JSON, MongoDB, MagicTree), custom headers, basic authentication, nmap-style ip ranges, and much more.
tags | tool, web, scanner, javascript
systems | unix
MD5 | 5a8714352496703d61c87da0b2ad24a3
WhatWeb Scanner 0.4.5
Posted Aug 17, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 300 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
MD5 | 87c63c591654687a22528083df043d04
WhatWeb Scanner 0.4.4
Posted Jul 3, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 80 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
MD5 | 416c645fb4fca7f2bcc489f321576dcb
WhatWeb Scanner 0.4.3
Posted May 25, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 80 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
MD5 | 6150f6a4fabd058a47a5b08fd145874a
WhatWeb Scanner 0.4.2
Posted Apr 30, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb is a next generation web scanner that identifies what websites are running. Flexible plugin architecture with over 80 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner
systems | unix
MD5 | e622cb2806821268938f92106b8416da
WhatWeb Scanner 0.4.1
Posted Apr 28, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 70 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner, ruby
systems | linux, unix
MD5 | b74e3f7eb1c8f6f67596aa3d5e5fedad
Next Generation Web Scanning Presentation
Posted Apr 16, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

This is the Next Generation Web Scanning Presentation. It includes a methodology to scan the webspace of an entire nation using some new tools and techniques. WhatWeb, bing-ip2hosts, gggooglescan and basedomainname are open source security tools developed by MorningStar Security that were published during the first presentation of this at the KIWICON III conference in December, 2009.

tags | paper, web
MD5 | 090485e6b4862cdca4def67149177914
Bing.com Hostname / IP Enumerator 0.2
Posted Apr 3, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

Changes: Can enter a hostname or IP eg. bing-ip2hosts foo.com, option to change temporary directory, optional CSV output of IP:hostname, optional http:// prefix.
tags | tool, scanner, bash
systems | linux, unix
MD5 | bd1e9d1c26d6e72311d2d11d93f376b6
How To Develop WhatWeb Plugins
Posted Mar 30, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

Document on how to research and develop plugins for WhatWeb to identify content management systems, web application frameworks, etc. As an example it includes how to research and write a plugin for the SilverStripe CMS. The document covers passive plugin development only and is accurate for WhatWeb version 0.4.

tags | paper, web
MD5 | d331823d3f9e09966b74a115e985316c
WhatWeb Scanner 0.4
Posted Mar 16, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 70 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner, ruby
systems | linux, unix
MD5 | e1e415bb7cb2c76ff4489232fff5a668
GeoIPGen IP By Country Generator 0.4
Posted Mar 8, 2010
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

GeoIPgen is a country-to-IPs generator. It's a geographic IP generator for IPv4 networks that uses the MaxMind GeoLite Country database. Geoipgen is the first published use of a geographic ip database in reverse to translate from country-to-IPs instead of the usual use of IP-to-country. Features: Random or sorted order, unique or repeating IPs, skips broadcast addresses, one, many or all countries.

Changes: Faster and smaller memory usage. It now uses the fast-random algorithm by default instead of the bit-field method, Re-wrote README file, Simplified usage instructions.
tags | tool, scanner
systems | unix
MD5 | edae9618c3413be8e380f1e10b5b91dd
WhatWeb Scanner 0.3
Posted Dec 1, 2009
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand. Written in Ruby for Linux. Flexible plugin architecture with over 60 plugins so far. Passive plugins use information in the headers, cookies, HTML body and URL. Aggressive plugins can identify versions of Joomla, phpBB, etc by making extra requests to the webserver.

tags | tool, web, scanner, ruby
systems | linux, unix
MD5 | c46b1945dcd5539244f36eaea1e3940d
Top Level Domain Extractor 0.1
Posted Dec 1, 2009
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

This tool can extract TLD (Top Level Domain), domain extensions (Second Level Domain + TLD), domain name, and hostname from fully qualified domain names. Written in Ruby for Unix. Recognizes all countries, top level domains and second level domains.

tags | tool, ruby
systems | unix
MD5 | 39866a94872ae4c8ca2613704b6731c9
Google.com Hostname / URL Enumerator
Posted Dec 1, 2009
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

This tool enumerates hostnames and URLs from Google. It features antibot avoidance, search within a country, custom search appliance, output either hostnames or URLs, and custom search depth. Written in Bash for Linux.

tags | tool, scanner, bash
systems | linux, unix
MD5 | e53dab2a6f19c40c475aedb99e3d6166
Bing.com Hostname / IP Enumerator
Posted Dec 1, 2009
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

This tool enumerates hostnames from Bing.com for an IP address. Bing.com is Microsoft's search engine which has an IP: search parameter. Written in Bash for Linux. Requires wget.

tags | tool, scanner, bash
systems | linux, unix
MD5 | 95a86caabda6489b1620a72b85f4fc8f
Cute News XSS / LFI / Bypass
Posted Nov 17, 2009
Authored by Andrew Horton (urbanadventurer)

Cute News version 1.4.6 and UTF-8 Cute News suffer from cross site request forgery, cross site scripting, file path disclosure, local file inclusion, authentication bypass, and php command injection vulnerabilities.

tags | exploit, local, php, vulnerability, xss, file inclusion, csrf
MD5 | 5dcec16d5b818f21db12e4efcd7d78a0
Open Auto Classifieds 1.5.9 File Upload
Posted Aug 26, 2009
Authored by Andrew Horton (urbanadventurer)

Open Auto Classifieds versions 1.5.9 and below remote file upload exploit.

tags | exploit, remote, file upload
MD5 | 60be759a5fa90e8d8b62337c4b81eea7
Open Auto Classifieds 1.5.9 SQL Injection
Posted Aug 26, 2009
Authored by Andrew Horton (urbanadventurer)

Open Auto Classifieds versions 1.5.9 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
MD5 | 0046f36c4f6db5ecfbf3953e01d02b90
URLCrazy Domain Name Typo Tool 0.2
Posted Apr 1, 2009
Authored by Andrew Horton (urbanadventurer) | Site morningstarsecurity.com

UrlCrazy is for the study of domainname typos and URL hijacking. It generates domainname typo permutations then tests them to learn if they are in use, estimates their popularity and more. Typo types supported are: Character Omission, Adjacent Character Swap, Adjacent Character Replacement, Adjacent Character Insertion, Missing Dot, Strip Dashes, Singular or Pluralise. Urlcrazy is written in Ruby.

tags | tool, web, ruby
MD5 | 76e29d066377625acb84ab32096ae538
Page 1 of 2
Back12Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close