<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; exploit</title>
	<atom:link href="http://www.ghacks.net/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 16:29:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New Attack: Combine Files With Jar Scripts</title>
		<link>http://www.ghacks.net/2008/08/01/new-attack-combine-files-with-jar-scripts/</link>
		<comments>http://www.ghacks.net/2008/08/01/new-attack-combine-files-with-jar-scripts/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 16:22:34 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[gifar]]></category>
		<category><![CDATA[jar]]></category>
		<category><![CDATA[jar gif]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[java applets]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=5782</guid>
		<description><![CDATA[A new attack, dubbed Gifar by their creators named after the two file types that they mixed to create the attack (Gif and Jar), was mentioned in a Black Hat Sneak Preview article over at ZDnet. While not everything was revealed in that preview article it mentioned that the developers were able to combine two [...]]]></description>
			<content:encoded><![CDATA[<p>A new attack, dubbed Gifar by their creators named after the two file types that they mixed to create the attack (Gif and Jar), was mentioned in a Black Hat Sneak Preview article over at <a href="http://blogs.zdnet.com/security/?p=1619">ZDnet</a>. While not everything was revealed in that preview article it mentioned that the developers were able to combine two file types like the previously mentioned gif and jar files so that the first, container file type, would be shown normally in the browser but that the Java applet would be executed at the same time.</p>
<p>Many file and image hosts filter dangerous file types. If you tried to upload a Jar file to most of them you would get an error message stating that the file type was not supported. Many however fail to analyze the file itself and simply reject files based on their extension which opens the door for this attack.</p>
<p>That&#8217;s a pretty dangerous exploit. Imagine someone who uses this to upload a new avatar to popular websites like <a href="http://www.ghacks.net/2009/10/17/facebook-login/">Facebook</a> or Myspace (two examples, I have not checked if the two use advanced upload filters). He could do all sorts of things with the Java Applet once users open up his profile page.</p>
<p><span id="more-5782"></span>The only valid defense against this type of attack is to disable Java on the computer for the moment. Sun is already working on a fix although the researchers say that it is not Sun&#8217;s fault that this vulnerability exists.</p>

	Tags: <a href="http://www.ghacks.net/tag/browser/" title="browser" rel="tag">browser</a>, <a href="http://www.ghacks.net/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a href="http://www.ghacks.net/tag/gifar/" title="gifar" rel="tag">gifar</a>, <a href="http://www.ghacks.net/tag/jar/" title="jar" rel="tag">jar</a>, <a href="http://www.ghacks.net/tag/jar-gif/" title="jar gif" rel="tag">jar gif</a>, <a href="http://www.ghacks.net/tag/java/" title="java" rel="tag">java</a>, <a href="http://www.ghacks.net/tag/java-applets/" title="java applets" rel="tag">java applets</a>, <a href="http://www.ghacks.net/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2007/03/31/send-windows-to-nirvana-with-an-animated-cursor/" title="Send Windows to Nirvana with an animated cursor (March 31, 2007)">Send Windows to Nirvana with an animated cursor</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/06/27/you-better-stop-using-internet-explorer-for-now/" title="You better stop using Internet Explorer for now (June 27, 2008)">You better stop using Internet Explorer for now</a> (18)</li>
	<li><a href="http://www.ghacks.net/2009/03/06/windows-xp-default-internet-browser-per-user-profile/" title="Windows XP: Default Internet Browser Per User Profile (March 6, 2009)">Windows XP: Default Internet Browser Per User Profile</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/06/13/which-will-it-be-opera-firefox-ie/" title="Which will it be ? Opera ? Firefox ? IE ? (June 13, 2008)">Which will it be ? Opera ? Firefox ? IE ?</a> (38)</li>
	<li><a href="http://www.ghacks.net/2009/03/13/web-browser-firefox-31-beta-3/" title="Web Browser: Firefox 3.1 Beta 3 (March 13, 2009)">Web Browser: Firefox 3.1 Beta 3</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/08/01/new-attack-combine-files-with-jar-scripts/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>User Data Stolen from The Pirate Bay</title>
		<link>http://www.ghacks.net/2007/05/11/user-data-stolen-from-the-pirate-bay/</link>
		<comments>http://www.ghacks.net/2007/05/11/user-data-stolen-from-the-pirate-bay/#comments</comments>
		<pubDate>Fri, 11 May 2007 12:12:48 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[P2p]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[piratebay hacked]]></category>
		<category><![CDATA[the piratebay]]></category>
		<category><![CDATA[userbase]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/05/11/user-data-stolen-from-the-pirate-bay/</guid>
		<description><![CDATA[Two hours ago bkp made an announcement on the official The Pirate Bay blog confirming that some hackers have been able to use a security hole in the blog software to get access to the user database of The Pirate Bay. Information stored in there are the username, the password and the email address of the user who signed up. The password and the email address are encrypted which means that the hacker is most likely unable to receive any valuable information from the data.]]></description>
			<content:encoded><![CDATA[<p>Two hours ago <a href="http://thepiratebay.org/blog" target="_blank">bkp</a> made an announcement on the official The Pirate Bay blog confirming that some hackers have been able to use a security hole in the blog software to get access to the user database of The Pirate Bay. Information stored in there are the username, the password and the email address of the user who signed up. The password and the email address are encrypted which means that the hacker is most likely unable to receive any valuable information from the data.</p>
<p>Bkp also said that they know who did this but does not say how they know. He could be referring to IP addresses that they found, other traces or confidential information. They ask every user to change the password during their next login which is apparently happening automatically at the very moment. It remains to be seen if the encryption used to encrypt the email addresses is strong enough to withstand decryption. </p>
<p><span id="more-1537"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a href="http://www.ghacks.net/tag/hack/" title="hack" rel="tag">hack</a>, <a href="http://www.ghacks.net/tag/hacking/" title="Hacking" rel="tag">Hacking</a>, <a href="http://www.ghacks.net/tag/piratebay-hacked/" title="piratebay hacked" rel="tag">piratebay hacked</a>, <a href="http://www.ghacks.net/tag/the-piratebay/" title="the piratebay" rel="tag">the piratebay</a>, <a href="http://www.ghacks.net/tag/userbase/" title="userbase" rel="tag">userbase</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/05/19/spy-tech-i-see-what-you-write/" title="Spy Tech: I see what you write (May 19, 2008)">Spy Tech: I see what you write</a> (6)</li>
	<li><a href="http://www.ghacks.net/2007/03/27/weak-passwords/" title="Weak Passwords (March 27, 2007)">Weak Passwords</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/05/27/use-netflix-watch-now-on-more-than-3-pcs/" title="Use Netflix Watch Now on more than 3 PCs (May 27, 2008)">Use Netflix Watch Now on more than 3 PCs</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/01/23/use-a-magnet-to-protect-your-pc/" title="Use a Magnet to protect your PC (January 23, 2008)">Use a Magnet to protect your PC</a> (10)</li>
	<li><a href="http://www.ghacks.net/2009/07/17/the-piratebay-to-introduce-paid-subscriptions/" title="The Piratebay To Introduce Paid Subscriptions (July 17, 2009)">The Piratebay To Introduce Paid Subscriptions</a> (14)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/05/11/user-data-stolen-from-the-pirate-bay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Send Windows to Nirvana with an animated cursor</title>
		<link>http://www.ghacks.net/2007/03/31/send-windows-to-nirvana-with-an-animated-cursor/</link>
		<comments>http://www.ghacks.net/2007/03/31/send-windows-to-nirvana-with-an-animated-cursor/#comments</comments>
		<pubDate>Sat, 31 Mar 2007 07:23:34 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[ani-vulnerability]]></category>
		<category><![CDATA[animated-cursor]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/03/31/send-windows-to-nirvana-with-an-animated-cursor/</guid>
		<description><![CDATA[One of the many disadvantages of every new Windows edition is the fact that the operating system becomes more and more bloated. Microsoft adds new features to Windows which could then be used to exploit the system.Instead of concentrating on fast efficient systems they produce heavy systems that look shiny but have problems under the surface. Recently a vulnerability in Windows Animated Cursor Handling was discovered. In order for this attack to be carried out, a user must either visit a Web site that contains a Web page that is used to exploit the vulnerability or view a specially crafted e-mail message or email attachment sent to them by an attacker.]]></description>
			<content:encoded><![CDATA[<p>One of the many disadvantages of every new Windows edition is the fact that the operating system becomes more and more bloated. Microsoft adds new features to Windows which could then be used to exploit the system. Instead of concentrating on fast efficient systems they produce heavy systems that look shiny but have problems under the surface. Recently a <a href="http://www.avertlabs.com/research/blog/?p=233" target="_blank">vulnerability</a> in Windows Animated Cursor Handling was discovered. In order for this attack to be carried out, a user must either visit a Web site that contains a Web page that is used to exploit the vulnerability or view a specially crafted e-mail message or email attachment sent to them by an attacker.</p>
<p>You might be interested in which Windows editions are effected and which are not. It would also be nice to know if your browsers and e-mail clients are vulnerable and can be used to exploit the system. <a href="http://www.microsoft.com/technet/security/advisory/935423.mspx" target="_blank">Vulnerable</a> are Windows Vista, Windows XP SP2 and Windows 2000 SP4. Several other Microsoft operating systems are affected as well like Windows Server 2003 but I think the first three cover most Windows editions that my readers use. Exploitation happens completely silently.</p>
<p><span id="more-1365"></span></p>
<p>Take a look at the demonstration video below. It shows how Windows Vista enters a endless Crash-Restart loop caused by a malicious ani file which was dropped on the desktop. Attacks will most likely occur over the Internet.</p>
<p><object width="425" height="350"><param name="movie" value="http://www.youtube.com/v/hf0S0Vk7j6I"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/hf0S0Vk7j6I" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"></embed></object></p>
<p>A security company has released a <a href="http://research.eeye.com/html/alerts/zeroday/20070328.html" target="_Blank">temporary fix</a> for the solution until an official Microsoft patch gets released.</p>

	Tags: <a href="http://www.ghacks.net/tag/ani-vulnerability/" title="ani-vulnerability" rel="tag">ani-vulnerability</a>, <a href="http://www.ghacks.net/tag/animated-cursor/" title="animated-cursor" rel="tag">animated-cursor</a>, <a href="http://www.ghacks.net/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/vista/" title="vista" rel="tag">vista</a>, <a href="http://www.ghacks.net/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/xp/" title="xp" rel="tag">xp</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/07/25/vista-part-3/" title="Vista Part 3 (July 25, 2008)">Vista Part 3</a> (19)</li>
	<li><a href="http://www.ghacks.net/2006/11/14/triple-boot-vista-xp-and-ubuntu/" title="Triple Boot Vista, XP and Ubuntu (November 14, 2006)">Triple Boot Vista, XP and Ubuntu</a> (5)</li>
	<li><a href="http://www.ghacks.net/2006/12/06/things-to-check-before-switching-to-vista-part-1/" title="Things to check before switching to Vista Part 1 (December 6, 2006)">Things to check before switching to Vista Part 1</a> (1)</li>
	<li><a href="http://www.ghacks.net/2007/03/18/superfast-shutdown-for-xp-and-vista/" title="Superfast Shutdown for XP and Vista (March 18, 2007)">Superfast Shutdown for XP and Vista</a> (4)</li>
	<li><a href="http://www.ghacks.net/2006/12/07/security-and-privacy-complete/" title="Security and Privacy Complete (December 7, 2006)">Security and Privacy Complete</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/03/31/send-windows-to-nirvana-with-an-animated-cursor/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
