lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 9 Jan 2011 07:43:48 +0000
From: "Cal Leeming [Simplicity Media Ltd]"
	<cal.leeming@...plicitymedialtd.co.uk>
To: full-disclosure@...ts.grok.org.uk
Subject:  IBM DeveloperWorks Pwned and Defaced

Sorry, by point on entry, I mean the method used to attack and the entry
point for said attack.. (i.e. rfi / lfi / shitty code etc)


On Sun, Jan 9, 2011 at 7:41 AM, Shinnok <raydenxy@...oo.com> wrote:

> Yes sure, here you go:
> http://i.imgur.com/RfgbB.png
>
> Just check any subdir/html page under
> *developerworks/* since it was the case of a full deface
> if you ask me(inject the deface in every page the attacker
> has access too).
> You can also Google for:
> site:www.ibm.com/developerworks/ intitle:"Defaced by Hmei7"
> And check the caches.
>
> The admins are on to it and they are progressively fixing them,
> thus why you get that message.
> Must suck though, since it's a weekend. :-)
>
> ----- Original Message -----
> From: "Cal Leeming [Simplicity Media Ltd]" <
> cal.leeming@...plicitymedialtd.co.uk>
> To: "Shinnok" <raydenxy@...oo.com>, full-disclosure@...ts.grok.org.uk
> Sent: Sunday, January 9, 2011 9:23:57 AM
> Subject: Re: [Full-disclosure] IBM DeveloperWorks Pwned and Defaced
>
> Got a screenshot? I only see:
>
>
>        Our apologies
>
>
> The IBM developerWorks Web site is currently under maintenance.
> Please try again later.
>
>
>
> Thank you.
>
>
> On Sun, Jan 9, 2011 at 7:04 AM, Shinnok < raydenxy@...oo.com > wrote:
>
>
> http://www.ibm.com/developerworks/linux/library/l-proc.html \^^
>
> Br,
>
> Shinnok
>
> http://twitter.com/raydenxy
>
>
>
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>
>
>
>
>

Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ