ph

Building A Simple Proxy Fuzzer For THe MQTT Protocol Using The Polymorph Framework

Whitepaper that shows how easy you can build a fuzzer for the MQTT protocol by using the Polymorph framework.






ph

phrack63.tar.gz

Phrack Magazine Issue 63 - The last issue of Phrack! In this issue: Phrack Prophile on Tiago, OSX heap exploitation techniques, Hacking Windows CE, Games with kernel Memory...FreeBSD Style, Raising The Bar For Windows Rootkit Detection, Embedded ELF Debugging, Hacking Grub for Fun and Profit, Advanced antiforensics : SELF, Process Dump and Binary Reconstruction, Next-Gen. Runtime Binary Encryption, Shifting the Stack Pointer, NT Shellcode Prevention Demystified, PowerPC Cracking on OSX with GDB, Hacking with Embedded Systems, Process Hiding and The Linux Scheduler, Breaking Through a Firewall, Phrack World News.





ph

SSH/SSL RSA Private Key Passphrase Dictionary Enumerator

This is a script to perform SSH/SSL RSA private key passphrase enumeration with a dictionary attack.






ph

Apple iPhone 4 Passphrase Disclosure

Apple iPhone 4 with iOS 4.3 (8F190) suffers from a passphrase disclosure vulnerability that allows all local processes access to it.




ph

Checkview 1.1 For iPhone / iPod Touch Directory Traversal

Checkview version 1.1 for iPhone / iPod Touch suffers from a directory traversal vulnerability.




ph

iPhone/iPad Phone Drive 1.1.1 Directory Traversal

iPhone/iPad Phone Drive version 1.1.1 suffers from a directory traversal vulnerability.




ph

iPhone Forensics On iOS 5

This is a brief whitepaper discussing how to perform forensics on iOS 5 on the iPhone.




ph

IPhone TreasonSMS HTML Injection / File Inclusion

IPhone TreasonSMS suffers from html injection and file inclusion vulnerabilities.




ph

Forensic Analysis Of iPhone Backups

This article explains the technical procedure and challenges involved in extracting data and artifacts from iPhone backups.




ph

Air Transfer Iphone 1.3.9 Arbitrary File Download

Air Transfer Iphone version 1.3.9 suffers from remote denial of service and unauthenticated file access vulnerabilities.




ph

WordPress Windows Desktop And iPhone Photo Uploader File Upload

WordPress Windows Desktop and iPhone Photo Uploader plugin suffers from a remote shell upload vulnerability.




ph

Symantec Mobile Encryption For iPhone 2.1.0 Denial Of Service

Symantec Mobile Encryption for iPhone version 2.1.0 suffers from a denial of service vulnerability.




ph

Visual Voicemail For iPhone IMAP NAMESPACE Use-After-Free

Visual Voicemail for iPhone suffers from a use-after-free vulnerability in IMAP NAMESPACE processing.




ph

iPhone iMessage Malformed Message Bricking

An issue exists where a malformed iMessage can brick an iPhone. A method in IMCore can throw an NSException due to a malformed message containing a property with key IMExtensionPayloadLocalizedDescriptionTextKey with a value that is not a NSString.





ph

Pytacle Alpha2

pytacle is a tool inspired by tentacle. It automates the task of sniffing GSM frames of the air, extracting the key exchange, feeding kraken with the key material and finally decode/decrypt the voice data. All You need is a USRP (or similar) to capture the GSM band and a kraken instance with the berlin tables (only about 2TB).




ph

WifiPhisher Phishing Tool

Wifiphisher is a security tool that mounts fast automated phishing attacks against WPA networks in order to obtain the secret passphrase. It is a social engineering attack that unlike other methods it does not include any brute forcing. It is an easy way for obtaining WPA credentials.




ph

Imperva SecureSphere 13.x PWS Command Injection

This Metasploit module exploits a command injection vulnerability in Imperva SecureSphere version 13.x. The vulnerability exists in the PWS service, where Python CGIs did not properly sanitize user supplied command parameters and directly passes them to corresponding CLI utility, leading to command injection. Agent registration credential is required to exploit SecureSphere in gateway mode. This module was successfully tested on Imperva SecureSphere 13.0/13.1/13.2 in pre-ftl mode and unsealed gateway mode.




ph

Will mobile phone penetration maintain African momentum?

Sub-Saharan Africa is the world’s fastest growing mobile phone market, but how can telecoms companies make the most of the huge opportunities the region provides?





ph

fDi's European Cities and Regions of the Future 2020/21 - FDI Strategy: North Rhine-Westphalia takes regional crown

North Rhine-Westphalia is fDi's top large region for FDI Strategy, with the Basque Country topping the table for mid-sized regions and Ireland South East first among small regions. 






ph

Global pharmaceutical FDI on an upward trend

The global pharmaceutical sector has seen consistent growth since 2014, with western Europe a major beneficiary.




ph

Mara's Phones makes African manufacturing a priority

Having opened new production facilities in Rwanda and South Africa, Mara Phones is looking to alter Africa's mindset from being a 'consumer' to being a 'manufacturer'. 




ph

Floating solar photovoltaic plant to be installed at Kruonis pumped-storage plant in Lithuania

The Lithuanian Business Support Agency (LSBA) has granted €235,000 (US$267,500) to support development of an experimental floating solar photovoltaic power plant at the existing 900-MW Kruonis pumped-storage hydroelectric plant in Lithuania.




ph

Phasing out coal in Denmark via bioenergy-based CHP

Denmark in many ways is the poster child for the generation mix of the future. It led the way for decades in wind generation. It has continued to set ever-more ambitious targets for renewable penetration. And it has shown in the real world how to make a grid work that includes a heavy presence of renewable assets. Along the way, though, it has faced many challenges.




ph

China adds 5.2 GW of photovoltaic capacity in Q1 2019

In the first quarter of this year, China added 5.2 gigawatts (GW) of installed photovoltaic (PV) capacity, according to the National Energy Administration. The figure is a drop from the 9.65 GW in the same period of 2018, due to the new policy on the construction of PV facilities for 2019 having been issued later in the year than similar policies issued in earlier years.




ph

Porsche 718 Cayman GT4 RS, Brabham BT62, Genesis G70: This Week's Top Photos

The rumor mill has been going into overdrive with news that a Porsche 718 Cayman GT4 RS is coming. Giving some credence to the rumors is a prototype spied this week of a Cayman even more hardcore than the GT4. Another prototype we spied was what appeared to be a new performance flagship for the M5 range. Word on the street is that the car, which...



  • Photos Of The Week

ph

Google Cloud VM Instance Setup with Ubuntu and XAMPP PHP Server

Google cloud platform is a cloud computing service and a perfect alternate for Amazon Webservices. Nowadays most of the top companies are moving towards Google services for better results. Google cloud platform is offering a $300 free trial for one year. This post is about how to set up VM instances with firewall rules in addition to creating a XAMPP server with Ubuntu operation system. This is almost similar to my previous article about the Amazon EC2 setup. Try this and enrich your side projects.





ph

Microsoft Azure Virtual Machines Setup with Ubuntu and XAMPP PHP Server

Microsoft Azure is another great alternate cloud service and it is offering a one-year free trial with $200 credit. This post is almost similar to my previous Cloud service article. This will explain to you how to set up a virtual machine instance with secure firewall rules and setting up a XAMPP(PHP Maria DB Server) using the Ubuntu operating system. Microsoft Azure has lots of free project management services. This is very useful for your side projects.





ph

Report: $2.4 Trillion Clean Energy Investment Needed To Avoid Climate Catastrophe

The world must invest $2.4 trillion in clean energy every year through 2035 and cut the use of coal-fired power to almost nothing by 2050 to avoid catastrophic damage from climate change, according to scientists convened by the United Nations.




ph

What Does the Nuclear Power Phase-Out Mean for Energy Storage?

The power industry is facing a nuclear power dilemma, according to a report published by The Union of Concerned Scientists. UCS assessed the economic viability and performance of nuclear power plants operating in the United States and concluded that the retirement of these plants will likely result in the adoption of coal and natural gas for baseload power generation, two energy sources that contribute to carbon dioxide emissions.




ph

California municipal utility will phase out three natural gas power plants in favor of renewables

This week, Los Angeles Mayor Eric Garcetti announced that rather than investing in the Haynes, Harbor and Scattergood natural gas power plants to meet the requirements of a 2010 law related to a practice known as once through cooling, the Los Angeles Department of Water and Power (LADWP) will phase them out in favor of renewable energy.




ph

Clinical trials success showcases Korea–Australia pharma collaboration

Korean biopharma company, PharmAbcine, is commencing full-scale clinical trials of a brain cancer treatment in the United States, following pioneering early phase trials in Australia.