Archive | Imprint | Privacy
25th March 2007
Nerd 2.0

SFT-Loader with FritzBox sniff!

Who knows the "SFT-Loader", not just when it comes to legal downloads is not quite of this highly regarded tool.

"The task of the SFT Loader is primarily there to stop the direct link of download sources somewhere else (known as Linkstealing)," it says on the homepage of the developer .

Protected by encryption and Sniffer Detection

The approach that the developers have chosen (the encryption of links), but has a big disadvantage, because there are still all unencrypted data sent over the network.

So far what I thought, just because the tool has a built-in sniffer detection, the sniffer detects all the mainstream that one of the "SFT-Loader" but can confidently entrust their links.

FritzBox shows FTP files and directories

One method to circumvent this whole local Schutmaßnahmen is obviously a step into the network. So far, we still needed a second PC, since they act as a gateway between the Internet and had to ask to read the network traffic.

But this time is over now, there have been such a router are the functions implemented. So it might appear as the AVM Fritz box, where you can be in the web interface a recording of all data that have gone on the Fritz, download.

Course are in the process and the data in one download per SFT file (*. sft), and one can now handle it as you wish.

Warning on foreign networks

From this one can only learn that you can not be too careful. Until now, such a recording FritzBox can not store it locally, not far away, this time at today's price declines to be more.

In the future, one must carefully observe even more aware of what it sends its data to the network.

Welcome encryption!

Body-Snatch

This insight should be smaller, not an invitation to the DELETE (which I own in any way Eighth / cheap), but a glimpse of what all is possible with today's technology and what you should be prepared: PS.

4th March 2007
Nerd 2.0

WordPress, WordPress Oh!

The "worst case":
A quick look at the update checker, just like every other day, but just because it is something.

Properly, a new update for wordpress is out! But why so fast?

You remember, of course, a major security flaw that was installed by mistake while programming, but that was not provided one takes into consideration not really.

Exactly what's happened, because a cracker has managed to create for itself access to the servers and the WordPress.org WordPress 2.1.1 modify download.

Although not all downloads were affected, but the team of WordPress it safe and released a new version to import everyone should at all times.

Innovations, there is time, therefore, unfortunately, rather less.

So long, Body-Snatch

Downloads: De-version (" update "," WordPress "), original .

Sources: WordPress.de (" Worst Case "," 2.1.2 "), WordPress.org .

PS: The U.S. version of WordPress was apparently affected by the modifications at any time.

1st February 2007
Nerd 2.0

Chop out of boredom

Yet another site was "hacked" from my network .... The gang called itself quite large "TheWorldsHackeR" and apparently came from a Turkish-speaking country.

To collapse, they used a vulnerability in PHP and inserted into the cache / folder of a file name phpBB "attach_config.php", but only the "embellished" a bit.

Further changes are still not recognized until now.

Mfg. BODY-Snatch

PS: The appendix of course, by NEN few pictures ;-)

20th December 2006
Nerd 2.0

The first time hacked.

Yesterday I could do on my side www.sek-2.de a very interesting experience.

Parts of my site have been hacked.

Great was not changed, only the bbc_box_tags.php has been edited.

Possible this was most likely an old version of IRC Hacks for phpBB.

How exactly did this I can not say yet. In any case, the hack was first updated, and still ran a few security enhancements.

Let's hope that something is not as fast again occurs.

Mfg. BODY Snatch.

PS: In the appendix there are a few pictures about it.