Before login

Greyhat-Security is Back!!!

Welcome back everyone! After approximately 8 months, Greyhat-Security.com has finally returned! It took us such a long time due to the fact that I'm working and studying pretty much all the time, which makes it more difficult to work on the site, as well as the fact that I had to do two major things:

a) Redesign the entire look of the site, the way it runs, and the server it was running it

b) Filter through all the content to find the well polished articles, and sift out the illegal ones (or rewrite them)

Read on to find out about the new features!

Microsoft Releases Workaround for WebDAV Exploit

 Yesterday, Microsoft released a FixIt tool for the WebDAV DLL Vulnerability that was discovered a few weeks back. This tool builds upon a registry entry fix that Microsoft released last week, which allows system administrators to control and define the Search DLL Path Algorithm.

Fo Shizz: Rapping about Malware to meet Snoop Dogg?

 Who ever would have seen this coming? Symantec has teamed up with Snoop Dogg to set up a rapping contest on the topic of malware and cybercrime. Participants are invited to break out their mic's, and start rapping on the topic of cybercrime, malware, botnets, hacking, and the like, all for a chance to win an "all expenses paid" trip to see Snoop Dogg live, meet some of "his people", and possibly meet the Dogg himself. Also, as an added bonus, the winning entry will receive a Toshiba laptop outfitted with the latest Norton Internet Security 2011.

Acunetix 7 Released Today

 London, 1st September 2010 – Acunetix, a market leader in web application security scanning technology, today announced version 7 of its popular Web Vulnerability Scanner. With the new human like vulnerability verifying techniques, revolutionary scanning engine and support for a wider variety of web applications, Acunetix re-establishes its technology lead in web application security. Acunetix WVS Version 7 also features improved performance, less false positives and detection of a wide range of new web vulnerability types.

Crooks Steal Church Cash for Sex Crime Victims

 Scammers in late August made just over $600,000 after breaking into the bank accounts of a Catholic Diocese, claiming the funds are for victims of paedophile priests. The scammers took advantage of people to use as money mules, stealing the money from the Catholic Diocese of Des Moines, Iowa. The scammers posed as a New-York based international finance firm, "the Impeccable Group", and offered the mules a bogus work-at-home job.

Algerian Web Hackers in Embarrassing Mixup

 A group of Algerian Web Pirates/Hacker was in an embarrassing mixup yesterday, mistakingly hacking the website of a Castle which hosts Teddy Bear Picnics, instead of a Crusaders fortress. The hackers targeted and compromised the web page of Belvoir Castle, which is the home of the family seat of the 11th Duke of Rutland, instead of the website they were instead supposed to attack, which was that of Belvoir Fortress in Israel.

Exploit DLL Vulnerability with Autorun and Metasploit on Windows

 Basically, what's going to happen in this tutorial, is you're going to use Metasploit to generate a reverse_tcp payload into a DLL, and you're also going to create a blank "VCF" file, which is a Windows Address Book contact file. We're then going to create an autorun.inf file which gets the USB drive/CD Drive to tell WAB to open the blank VCF, and when it does so, it will automatically load the DLL file as well (the malicious one you generate beforehand). So let's get to it, hey?

Pro-Palestinian Hacker Defaces National Skills Academy Website

 A UK based Government training organisation, known as the "National Skills Academy", had it's homepage hacked and defaced, being replaced with a pro-Palestinian message stating "Virtual Protests will continue..! Everything for PALESTINE! JaCKal Ownz Your System. I came challengeing to the world THE END." It was also accompanied by an image showing a container ship, with the word "Gaza" on the side.

CAO Website Crashes Due to "Malicious Attack"

Thousands of Irish Leaving Cert students were left devastated as they tried to access their college offers on Monday 23rd August 2010, as the Central Applications Office website was the victim of a "malicious attack by an unknown source".

The first round of college offers were uploaded on the website at 6am on Monday morning, but at 6:10am the website was crashed due to a Denial of Service (DoS) attack. The website was flooded with tens of thousands of false requests, and the server was simply overwhelmed by the amount of simultaneous requests.

Exploiting the WebDAV Vulnerability

 In order to exploit or test applications for the new WebDAV vulnerability, which we've covered here: http://greyhat-security.com/40-220-windows-exes-vulnerable-remote-code-execution-so-far, you will need to fire up your copy of Metasploit, and type the following...