Showing posts with label Domains. Show all posts
Showing posts with label Domains. Show all posts

May 24, 2008

Wordpress SQL injection

Today it came out that there is yet another SQL injection in WordPress Blogs.


This code exploits the Wordpress Plugin Upload File, and allows an attacker to execute an arbitrary command on the hosting machine. If you host your Blog Locally, this is an enormous problem! The exploit (Discovered by a russian hacker http://eserg.ru ) ,  is one of a myriad of security issues recently exposed by Hackers- leaving bloggers worldwide vulnerable.  

What is a Arbitrary Command?
   This is when an attacker is able to exploit a security vulnerability in a program, to execute commands on YOUR computer. For example, in this case, By simply executing this SQL query
null/**/union/**/all/**/select/**/concat(user_login,0x3a,user_pass)/**/from/**/wp_users/*
On your server- he is able to add/remove users, Delete Files, and install any number of viruses.

Be on the lookout in the next week for a patch from www.wordpress.com/www.wordpress.org

April 28, 2008

Sweet Tools Suite

Recently I came across a very versatile tool developed by the Crazy Germans over at http://www.gaijin.at/. The Name of the suite is E-Toolz. Basically, It is a web-developers dream.
Ping,Tracert,DNS,HTTP-Header, Domain Dossier, Mail-Checker, And Time Server Check.
Forget the days of spending 30-45 minutes jumping between sites, with E-Toolz- Its all at your fingertips.

Also- As a sidenote: Google Translate has some issues with German Emails.

The programme eToolz are the main Internet and network programs such as Nazi lookup, Ping, Traceroute and Whois united.

Wow! German Emails Are Now Nazis?!