<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Abeon Tech &#187; Exploit</title>
	<atom:link href="http://abeontech.com/tag/exploit/feed" rel="self" type="application/rss+xml" />
	<link>http://abeontech.com</link>
	<description>Abeon Techs Geeky blog for Coders, Gamers, Webmasters and Tech Addicts!</description>
	<lastBuildDate>Thu, 28 Jul 2011 18:50:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Bypass iPhones screen lock (iOS 4.1)</title>
		<link>http://abeontech.com/419-security-bypass-iphones-screen-lock-ios-4-1</link>
		<comments>http://abeontech.com/419-security-bypass-iphones-screen-lock-ios-4-1#comments</comments>
		<pubDate>Tue, 02 Nov 2010 15:15:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[iPhone]]></category>

		<guid isPermaLink="false">http://abeontech.com/?p=419</guid>
		<description><![CDATA[A recent security flaw in Apple&#8217;s iOS allows access to the device while the phone is &#8220;locked&#8221;. iOS is used in the iPhone 4, 3G and 3GS models so the attack has a high possible reach. With a few key presses you can make calls, listen to voicemail, browse the call history and address book! [...]]]></description>
			<content:encoded><![CDATA[<p>A recent security flaw in Apple&#8217;s iOS allows access to the device while the phone is &#8220;locked&#8221;.<br />
iOS is used in the iPhone 4, 3G and 3GS models so the attack has a high possible reach.<br />
With a few key presses you can make calls, listen to voicemail, browse the call history and address book!</p>
<p>This short article details how the attack works.<br />
<span id="more-419"></span></p>
<p>Enabling the passcode lock on your iPhone is, for now, not enough to prevent someone using your device and adding to your bill!<br />
This should worry you if your concerned about iPhone security.</p>
<h3>How the vulnerability works</h3>
<p><strong>1.</strong> Hit &#8220;emergency call&#8221;<br />
<strong>2.</strong> Type in a random number.<br />
<strong>3.</strong> Hit the call button.<br />
<strong>4. </strong>Shortly after, press the lock button on top of the phone.<br />
<strong>4.1</strong> That&#8217;s it! Your now an uber l33t haxor -_-</p>
<p>This isn&#8217;t a major security risk (yet) as full access to the phone&#8217;s operations isn&#8217;t granted, but it does point out yet another fundamental flaw in Apple&#8217;s iPhone software.<br />
Let&#8217;s hope the team working on security for iOS have a good look through the crappy code their producing to iron out any more surprises.</p>
<p>The video below shows how simple and quick this can be.</p>
<p><object width="500" height="290"><param name="movie" value="http://www.youtube.com/v/hq8Dok2Th2s&#038;hl=en_GB&#038;feature=player_embedded&#038;version=3"></param><param name="allowFullScreen" value="true"></param><param name="allowScriptAccess" value="always"></param><embed src="http://www.youtube.com/v/hq8Dok2Th2s&#038;hl=en_GB&#038;feature=player_embedded&#038;version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="500" height="290"></embed></object></p>
<p>There is no fix for this hack yet and will probably only be patched on the next iOS update, 4.2.<br />
If you use an iPhone with iOS version 4.1 the only real way to keep it safe is to be careful who you let use it.</p>
]]></content:encoded>
			<wfw:commentRss>http://abeontech.com/419-security-bypass-iphones-screen-lock-ios-4-1/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Legends of Norrath free cards</title>
		<link>http://abeontech.com/418-gaming-legends-of-norrath-free-cards-workaround</link>
		<comments>http://abeontech.com/418-gaming-legends-of-norrath-free-cards-workaround#comments</comments>
		<pubDate>Tue, 07 Sep 2010 20:58:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Guide]]></category>

		<guid isPermaLink="false">http://abeontech.com/?p=418</guid>
		<description><![CDATA[A simple way to get more cards in Legends of Norrath for free.
Unluck the scenarios to get a better feel of the game!]]></description>
			<content:encoded><![CDATA[<p>I jumped into the EverQuest 2 Extended (Free-2-Play) Beta last week and saw that it was linked to a collectable card game called &#8220;Legends of Norrath&#8221;.</p>
<p>The card game in question is similar in nature to Magic: The Gathering.<br />
Unless you want to pay to play you are stuck with 11 tutorials, culminating in a match against a computer opponent.</p>
<p>This seems very limited to me and I wanted a little more before I decided to shell out any of my hard earned cash on a game I may never play!<br />
So&#8230; I messed about a little bit and found a way to get a free deck, 2 booster packs and many other cards (including &#8220;foils&#8221;) without spending a penny / cent.<br />
<span id="more-418"></span></p>
<p>I&#8217;m not sure this if this is how <abbr title="Sony Online Entertainment">SOE</abbr> wanted the system to work, but I&#8217;m going to share my findings anyway.</p>
<p>As the scenario button from the homepage is greyed out and clicking the scenario button at the end of the tutorial gives an error similar to:</p>
<blockquote><p>&#8220;You must purchase a deck to play the scenarios&#8221;</p></blockquote>
<p>It would seem they didn&#8217;t intend this to be possible.</p>
<ul>
<li>Log into Everquest 2 (you can use a <a href="http://everquest2.com/free_to_play">free-2-play</a> account) and type &#8220;/claim&#8221;</li>
<li>Claim the &#8220;OathBreaker Starter Deck and booster pack&#8221; and the &#8220;Kurnak Reward&#8221; (another booster pack)</li>
<li>Quit EverQuest and log into Legends of Norrath</li>
<li>Click &#8220;Casual Games&#8221; and join any room</li>
<li>Click &#8220;Fippy&#8217;s Revenge&#8221; (on the right) and select a scenario to play from the complete list!</li>
<li>You can play Boots of Zorash but won&#8217;t win any cards, but all the others I&#8217;ve played have given free cards so far</li>
</ul>
<p>You can get three cards by winning each scenario.<br />
1 for easy, 1 for medium and a foil card (shiny shiny) for hard.<br />
Completing hard mode will mean you get all three cards without the need to repeat each scenario.</p>
<p>Obviously, every card you win won&#8217;t fit perfectly into your deck, but it&#8217;s free&#8230;<br />
If you really want to play Legends of Norrath, by some damn cards!</p>
<p>It&#8217;s worth remembering that EverQuest 2 Extended is still in Beta, so this may change.</p>
]]></content:encoded>
			<wfw:commentRss>http://abeontech.com/418-gaming-legends-of-norrath-free-cards-workaround/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Arcade BugFix – XSS Exploit</title>
		<link>http://abeontech.com/324-security-avarcade-xss-exploit-patch</link>
		<comments>http://abeontech.com/324-security-avarcade-xss-exploit-patch#comments</comments>
		<pubDate>Tue, 06 Jan 2009 13:43:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[AV Arcade]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.abeontech.com/?p=324</guid>
		<description><![CDATA[While registering, user names can get be entered so to show a live link on the members page.
It's not a major problem as addslashes is used to stop XSS, but is still annoying and bound to be abused by spammers.
This article fixes this small issue.]]></description>
			<content:encoded><![CDATA[<h2>The Problem:</h2>
<p><strong>EDITED::&#8230;</strong><br />
This was originally reported as link spam, but could easily be a lot worse.</p>
<p>When registering, the user name field is open to possible attack.<br />
Code will be processed on the members page.<br />
The code can be overflown to the homepage fairly easily.<br />
XSS can be used.</p>
<p>I would now consider this as a serious exploit.<br />
I would suggest fixing this bug A.S.A.P</p>
<p><span id="more-324"></span></p>
<h2>The Fix:</h2>
<ul>
<li>Backup then open yoursite.com/register.php</li>
<li>Find:
<div class="codecolorer-container php default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:500px;"><div class="php codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #000088;">$info2</span> <span style="color: #339933;">=</span> <span style="color: #990000;">htmlspecialchars</span><span style="color: #009900;">&#40;</span><span style="color: #000088;">$info</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span></div></div>
</li>
<li>Add below:
<div class="codecolorer-container php default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:500px;"><div class="php codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #000088;">$username</span> <span style="color: #339933;">=</span> <span style="color: #990000;">htmlspecialchars</span><span style="color: #009900;">&#40;</span><span style="color: #000088;">$username</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span></div></div>
</li>
<li>Backup then open yoursite.com/admin/manage_users.php</li>
<li>Find:</li>
<li>
<div class="codecolorer-container php default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:500px;"><div class="php codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #b1b100;">while</span><span style="color: #009900;">&#40;</span><span style="color: #000088;">$row</span> <span style="color: #339933;">=</span> <span style="color: #990000;">mysql_fetch_array</span><span style="color: #009900;">&#40;</span><span style="color: #000088;">$sql</span><span style="color: #009900;">&#41;</span><span style="color: #009900;">&#41;</span><span style="color: #009900;">&#123;</span></div></div>
</li>
<li>Add below:</li>
<li>
<div class="codecolorer-container php default" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:500px;"><div class="php codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #000088;">$username</span> <span style="color: #339933;">=</span> <span style="color: #990000;">htmlspecialchars</span><span style="color: #009900;">&#40;</span><span style="color: #000088;">$username</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span></div></div>
</li>
<li>Save and upload all files.</li>
<li>Search your members list for any user names shown as code and delete (You could also I.P. ban them).</li>
<p>This function could easily be expanded for further validation.</ol>
]]></content:encoded>
			<wfw:commentRss>http://abeontech.com/324-security-avarcade-xss-exploit-patch/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Easy Game Cheating</title>
		<link>http://abeontech.com/309-gaming-easy-game-cheating-guide</link>
		<comments>http://abeontech.com/309-gaming-easy-game-cheating-guide#comments</comments>
		<pubDate>Wed, 17 Dec 2008 04:19:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.abeontech.com/?p=309</guid>
		<description><![CDATA[There are many ways to cheat PC while playing games.
If you're looking to increase your health to beat a boss or get infinite cash to build an empire, there will usually be many ways to make your game time easier!

This article will cover the easiest method and how to implement it on most games...]]></description>
			<content:encoded><![CDATA[<p>There are many ways to cheat PC games while playing.<br />
If you&#8217;re looking to increase your health to beat a boss or get infinite cash to build an empire, there will usually be many ways to make your game time easier!</p>
<p>This article will cover the easiest method and how to implement it on most games&#8230;</p>
<p><span id="more-309"></span></p>
<h2>Why Cheat?</h2>
<p>I have always been an RPG fan, which can be time consuming. I have played most RPGs worth noting and usually decide to replay at a later date. I always try to complete a game before I try cheating but</p>
<p>When I restart a game, I don&#8217;t need to do every little quest or pickup every item needed to know where to go next.</p>
<p>On the other hand, if I ever get really stuck on (or bored with) a game &#8211; I tend to skip ahead to save time and hassle.</p>
<p>I don&#8217;t agree on cheating without being stuck or used as a time saving device. So, let&#8217;s continue&#8230;</p>
<h2>Game Cheat Tools</h2>
<p>As with most niche software groups, game cheating (commonly referred to as &#8220;Trainer Making&#8221;) has several tools which can make the process easier.</p>
<p>A huge amount of skill isn&#8217;t required to start cheating your own games. But if you want to make a game loader or trainer, you will need to learn at least the basics of programming.</p>
<p>The tools below are some of my favourite for the task at hand:</p>
<ul>
<li><a href="http://www.timsvault.com/cheattools/tsearch.zip">TSearch</a> &#8211; Find and alter information stored in memory.</li>
<li><a href="http://www.timsvault.com/cheattools/usged.zip">Universal Save Game Editor</a> &#8211; Modify saved games, surprisingly enough!</li>
<li><a href="http://www.hhdsoftware.com/Family/hex-editor.html">Hex Editor Neo</a> &#8211; Simple file editing.</li>
<li><a href="http://www.megaupload.com/?d=CY1XGLPX">Game Trainer Studio</a> &#8211; Make &#8220;Game Trainers&#8221;. Programs to allow other people to use your cheats.</li>
<li><a href="http://www.ollydbg.de/version2.html">OllyDbg</a> &#8211; 32 Bit disassembler used for many purposes. Not for beginners!</li>
</ul>
<h2>Cheat the easy way</h2>
<p>I recently started playing Fallout Tactics, eagerly awaiting Fallout 3&#8242;s release (which I now have, but doesn&#8217;t work -_-)&#8230; Anyway, this seems like a good example to start with.</p>
<p>I knew from the reviews that I wouldn&#8217;t play Fallout Tactics all the way through.<br />
I had about 5 days to complete it before Fallout 3 was released, so I need a way to get more ammo, health and experience.</p>
<p>Run Fallout: Tactics and start a new game. Create a new character or pick a pre-made one.<br />
Make a note of some info you want to change. Let&#8217;s take the ammo counter as an example.</p>
<p>Open the inventory and note the number of bullets available, as shown below:<br />
&nbsp; &nbsp; &nbsp; <img src="http://i35.tinypic.com/ja83ee.gif" alt="Ammo Count" /></p>
<p>Run TSearch then open the process you want to modify (BOS.exe for Fallout: Tactics):<br />
&nbsp; &nbsp; &nbsp; <img src="http://i35.tinypic.com/2h3sv2s.gif" alt="Open Process" /></p>
<p>Click <strong>Init New Search</strong> Search using the settings below:<br />
&nbsp; &nbsp; &nbsp; <img src="http://i35.tinypic.com/fl8y8n.gif" alt="Search Game" /></p>
<p>The first search will produce a huge amount of unwanted results. So go back to the game and change the number by shooting a few rounds into the ground.</p>
<p>Then switch back to TSearch and continue the search by subtracting the amount of bullets you shot:<br />
&nbsp; &nbsp; &nbsp; <img src="http://i35.tinypic.com/311uywy.gif" alt="Search More Games" /></p>
<p>This time, only one result is shown. So add it to the right hand side.<br />
&nbsp; &nbsp; &nbsp; <img src="http://i38.tinypic.com/vsomqa.gif" alt="Game Result" /></p>
<p>Edit the number and switch back to the game to see if it has any effect.<br />
&nbsp; &nbsp; &nbsp; <img src="http://i35.tinypic.com/15dxefc.gif" alt="Hack Ammo" /></p>
<p><strong>It worked!</strong> So we know simple using TSearch will work on this game.<br />
We could, in theory, edit most other items in the game using the same process.</p>
<p>The change will not always be instant. Sometimes you will need to force a change from within the game before it will register the changes made outside. The character generation process of the Fallout games doesn&#8217;t show the edited numbers until you add or take a point to each attribute.</p>
<p>This method can be used on many, many games because of the way they utilize windows memory.<br />
There is one obvious drawback; Don&#8217;t expect to power level your <abbr title="World of Warcraft">WoW</abbr> character. I can imagine they have a system in place to ban you as fast as you can say Memory Debug!</p>
]]></content:encoded>
			<wfw:commentRss>http://abeontech.com/309-gaming-easy-game-cheating-guide/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SockStress &#8211; TCP/IP Vulnerability</title>
		<link>http://abeontech.com/147-security-sockstress-tcp-ip-vulnerability</link>
		<comments>http://abeontech.com/147-security-sockstress-tcp-ip-vulnerability#comments</comments>
		<pubDate>Thu, 09 Oct 2008 19:30:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploit]]></category>

		<guid isPermaLink="false">http://www.abeontech.com/?p=147</guid>
		<description><![CDATA[Outpost24's Senior Security Researcher, Jack C. Louis has discovered a generic issue that affects the availability of TCP services. This issue could be used to create a Denial of Service attack. Vendors have been notified. Details are not available to the public at this point, but will be disclosed at an appropriate future date.]]></description>
			<content:encoded><![CDATA[<p>A serious TCP/IP Vulnerability known as “<strong>SockStress</strong>” has been found, exploited, and information released by a Security group called Outpost24.</p>
<p>This latest vulnerability not only has severe implications for many web masters, designers and programmers, but also affects routing servers and any system with TCP stack processes exposed to the outside world.</p>
<p>After the latest DNS poisoning vulnerability, webmasters seem on edge about how insecure the very foundations of the internet are (mainly due to being created before security was even thought of).</p>
<p><strong>Sockstress</strong> is the name of the tool created by Outpost24, which they are still testing before releasing it. They have, however, walked through how the attack could be achieved in great detail. Some security experts have showed concern over how they handled the information released.</p>
<p>The <em>sockstress</em> attack seems to be limited to the <strong>TCP stack</strong>, but mixes several techniques to allow a very low-bandwidth hacker to deplete local resources (memory, swap file and even kernel file abuse). Just a few packets a second and a little amount of time are needed to take down a server. As little as nine packets and a few minutes are all that is suggested to be needed!</p>
<p><span id="more-147"></span></p>
<p>Lack of timing of the TCP/IP stack and, more specifically, kernel&#8217;s response seems to be the most deciding factor. A &#8220;Badly designed TCP stack&#8221; is referred to and <em>after</em> the 3-way handshake (syn cookie verification and acknowledgment) has completed, resources can be exploited!&#8230;<br />
&#8220;The worst thing we ever had happen, was, we had Windows reboot and say &#8216;Operating system not found&#8217;&#8221;</p>
<p>In theory, a syn cookie validation process could be cycled. Sending for verification and acknowledgment, then a &#8220;no buffer space&#8221; response could be sent from the attackers end. This would force the target to allocate more resources to the attackers cycled process, with severe consequences.<br />
Please bear in mind that this is not a syn packet attack attack! (the magic happens after the syn ack)</p>
<p>This can result in a denial of service (Dos) by TCP servers (www, ftp, tftp, smtp, pop, etc.) running on Windows, Linux, BSD, certain routing servers, and other Internet applications and protocols!</p>
<p>An excerpt from Outpost24&#8242;s website, claims:</p>
<blockquote><p>Outpost24&#8242;s Senior Security Researcher, Jack C. Louis has discovered a generic issue that affects the availability of TCP services. This issue could be used to create a Denial of Service attack. Vendors have been notified. Details are not available to the public at this point, but will be disclosed at an appropriate future date.</p></blockquote>
<blockquote><p>Jack C. Louis, along with Outpost24&#8242;s Chief Security Officer Robert E. Lee, will be speaking at the T2 conference in Helsinki, Finland on October 16 &#8211; 17.</p></blockquote>
<p>You can read more about the <strong>Sock stress</strong> talks here:<br />
<a href="http://www.t2.fi/schedule/2008/#speech8">T2 Schedule</a> or <a href="http://www.t2.fi/2008/08/27/jack-c-louis-and-robert-e-lee-to-talk-about-new-dos-attack-vectors/">T2&#8242;s 08 Conference</a>.</p>
<blockquote><p>I want to know if there is anyone who can write a program that performs the operation described in this audio podcast.</p>
<p>http://debeveiligingsupdate.nl/audio/bevupd_0003.mp3</p>
<p>Please note, that the English portion of the audio starts about 4 minutes into the segment.<br />
This program must be testable prior to paying for it.</p></blockquote>
<p><strong><a href="http://www.getafreelancer.com/projects/Visual-Basic-NET/Build-SockStress-Application.html">Get A Freelancer</a> has a project asking for the tools creation.</strong> How long until someone makes it public?</p>
<h2>Podcast Downloads</h2>
<p><strong>You can listen to the security podcast in various formats. The Sockstress MP3 files are listed below:</strong></p>
<p>The wonderful guys at <a href="http://www.grc.com/intro.htm">GRC</a> (proud Twit army addict myself) have have hosted the interview, just in case the original goes down.<br />
Thanks Steve!<br />
<a href="http://debeveiligingsupdate.nl/audio/bevupd_0003.mp3">Entire Interview</a><br />
44 min, 10 sec &#8211; 128 kbps &#8211; 41.1 MB<br />
<a href="http://media.grc.com/mp3/Whole_SockStress_Mono_16kbps.mp3">Entire Interview</a><br />
44 min, 10 sec &#8211; 16 kbps &#8211; 5.3 MB<br />
<a href="http://media.grc.com/mp3/Trimmed_SockStress_Mono_64kbps.mp3">Trimmed Interview</a><br />
38 min, 59 sec &#8211; 64 kbps &#8211; 18.7 MB<br />
<a href="http://media.grc.com/mp3/Trimmed_SockStress_Mono_16kbps.mp3">Trimmed Interview</a><br />
38 min, 59 sec &#8211; 16 kbps &#8211; 4.7 MB</p>
<p>A full transcript is available from CurbRisk.com :<br />
<a href="http://www.curbrisk.com/security-blog/outpost24-tcp-denial-of-service-vulnerability-interview-transcript.html">Outpost24&#8242;s TCP &#8211; Denial Of Service vulnerability interview transcript</a></p>
<p>At time of posting, there is currently no known work around or fix for this issue. The authors seem to be white hat and want to help vendors resolve the issues. But, like the rest of us, know the internet has a long way to go before being secure.</p>
<p><strong>Sockstress has now also been entered into the <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4609">NIST CVE</a> database. The list of affected platforms is staggering!</strong></p>
<p>It is widely accepted that &#8220;the community&#8221; prefers to find workarounds for the flawed foundations of the internet and associated protocols. But would it not be better if, knowing as much about security as we do now, the internet was written from the ground up?<br />
Yes, it is impossible. But I think it would be the only way to make serious, major exploits like this and the recent DNS poisoning exploits avoidable.</p>
]]></content:encoded>
			<wfw:commentRss>http://abeontech.com/147-security-sockstress-tcp-ip-vulnerability/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
<enclosure url="http://media.grc.com/mp3/Whole_SockStress_Mono_16kbps.mp3" length="5301290" type="audio/mpeg" />
<enclosure url="http://media.grc.com/mp3/Trimmed_SockStress_Mono_64kbps.mp3" length="18716212" type="audio/mpeg" />
<enclosure url="http://media.grc.com/mp3/Trimmed_SockStress_Mono_16kbps.mp3" length="4679262" type="audio/mpeg" />
<enclosure url="http://debeveiligingsupdate.nl/audio/bevupd_0003.mp3" length="43176073" type="audio/mpeg" />
		</item>
		<item>
		<title>Flash Game Hacked?</title>
		<link>http://abeontech.com/81-security-flash-game-hacked</link>
		<comments>http://abeontech.com/81-security-flash-game-hacked#comments</comments>
		<pubDate>Wed, 10 Sep 2008 19:09:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://www.abeontech.com/?p=81</guid>
		<description><![CDATA[A friend of mine just sent me the URL to a flash game (for obvious reasons I will not share the link) which is part of a number of games with a price of 10.000 EUR in the end. One would believe that a game with such a price money is secure.]]></description>
			<content:encoded><![CDATA[<p>A friend of mine just sent me the URL to a flash game (for obvious reasons I will not share the link) which is part of a number of games with a price of 10.000 EUR in the end. One would believe that a game with such a price money is secure. Especially when the organising party is an internet provider.</p>
<p><span id="more-81"></span></p>
<p>But guess what&#8230; At the end of the flash game you can optionally submit your score to the highscore server, which results in a POST to the file submithigh.php with several parameters, one parameter saying score=XXXX. And of course you can submit whatever score you want. So now I lead the highscore with 10000 of about 900 possible points. I set it that high to ensure that the guys at the ISP will realize that this is faked, but imagine I had just increased the current highscore by 10. I seriously doubt anyone would have noticed and I would have won the competition without even decompiling the flash.</p>
<p>[ Original Post From <a href="http://blog.php-security.org/archives/95-Flash-Game-10000-of-900-possible-points!!.html" title="PHP Security">php-security.org</a> ]</p>
<p>======<br />
Even simple mistakes can cause a lot of trouble.<br />
Think if all the top scores on every game game were hacked to show obscene comments!<br />
It&#8217;s best to try and think like a hacker when creating public content <img src='http://abeontech.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://abeontech.com/81-security-flash-game-hacked/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

