Penetration Testing mailing list archives

IRAX 0.1 is on Freshmeat


From: "DokFLeed" <dokfleed () dokfleed net>
Date: Sat, 24 Dec 2005 09:55:23 +0400

What is IRAX ?
IRAX, is a PHP Gateway, it can be integrated in any Web Application to stop known Attacks . it prevents,SQL injections, XSS, and many other known Attacks . It depends mainly on PHP CLIENT/SERVER socket scripting

How does it work?
You setup the Client script on your website, and include it in your scripts.
in case of any Attack on your website, a socket with the Attack information will be directed to our server and stopped. It can display the attack information to the attacker, or can work in a silent mode.


Freshmeat: http://freshmeat.net/projects/irax/
IRAX home: http://www.dokfleed.net/irax/

Proof of Concept.
PHPNuke on dokfleed.net/duh/ is vulnerable
http://www.dokfleed.net/duh/banners.php?op=EmailStats&name=sex&bid=[vulnerable]
now try to exploit he vulnerability i.e.
http://www.dokfleed.net/duh/banners.php?op=EmailStats&name=sex&bid=<script>alert('boo');</script>



Happy Holidays,
DokFLeed

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: