House of Hackers

dev0id
  • Male
  • Moscow
  • Russian Federation
Share 

Dev0id's Friends

Latest Activity

isen izen joined dev0id's group
Vulnerabilities, Exploits, Weaknesses
September 17
nice story but not informative..sire : )
August 14
RodHelm joined dev0id's group
Vulnerabilities, Exploits, Weaknesses
June 30
tom joined dev0id's group
Vulnerabilities, Exploits, Weaknesses
June 23

Music

Loading…

dev0id's Groups

dev0id's Discussions

RSS

Loading feed

 

Auditor's notes

Profile Information

Real Name:
dev0id
Blog:
http://houseofhackers.ning.com/profiles/blog/list?user=1ry8xj94ys8fs
Website:
http://www.google.com
Description:
Professional security auditor.

Security and everything related

Interested in security assessments, audits and compliance testings.

penetration testing
programming
bugs hunting

Everything.

Do not leave unwanted comments

Dev0id's Blog

dev0id

Substantive procedures (part I)

The purpose of this articel to describe substantive audit procedure related to IT audit. This article will cover the following areas:


* The objective of substantive procedures
* The risk factors
*

Continue

Posted on July 4, 2008 at 7:30pm — 2 Comments

dev0id

Online banking: Controls to be implemented

For those who read my article Cracking access to Bank this paper may be interesting from the securing transactions point of view.
As we identified that that the m

Continue

Posted on June 9, 2008 at 4:38pm —

dev0id

Script-Kiddies

Why hackers do not like script-kiddeis ? May be you think that hackers hate tham just because guys do not know how to intrude the system or do not know how to craft an exploit... may be... some of kiddies really annoying. However, nobody was born clever. And if we ju

Continue

Posted on June 9, 2008 at 10:00am — 4 Comments

dev0id

Cracking access to Bank

The purpose of this article is to show the real threat for banks' clients that use on-line banking services for processing bank documents and transactions in "real-time". On-line banking services are used in our days by 99% of legal entities. In my practice I have see

Continue

Posted on June 7, 2008 at 7:00pm — 4 Comments

dev0id

TrendMicro HOUSECALL_ACTIVEXLib Multiple vulnerabilities

Be careful! Once you scanned your workstation using TrendMicro HOUSECALL this ActiveX component will stay in your system. That means that anyone can exploit this vulnerability. The vulnerable methods are listed below:
showAlert()
setOption()
isOptionAvail

Continue

Posted on June 6, 2008 at 4:30am —

dev0id

Bank clients are under attack?

Do you know what is Client-Bank application ? That is electronic transaction system that allows to work with bank account through the Internet. The on of the types of Client-Bank applications is the web-based client bank, that check signatures and e-tokens data using the ActiveX control. I reviewed the one (http://bssys.com/eng).

The result was (integer overflow):



Exception Code: ACCESS_VIOLATION
Disasm: 1D0BB96 MOV EDI,[ESI+3C] (

Continue

Posted on June 6, 2008 at 4:00am —

dev0id

Operational vulnerability in Aeroflot tickets sales business process

Yesterday I was really surprised to know that Aeroflot has operational vulnerability in reservation of tickets process (the part of tickets sales). As it happens Aeroflot allows to perform tickets reservations via WEB and this reservations include desired s

Continue

Posted on June 4, 2008 at 4:00am — 2 Comments

dev0id

Controls VS Risks

What are the risks and why we always looking for controls? How can we pass controls over and what do we need it for? These questions are normal! I am going to describe simplified audit procedures related to Information Technologies and Information Security audits.

Continue

Posted on June 2, 2008 at 8:30am —

dev0id

Vulnerability in RegWizCtrl

Fuzzing the ActiveX components installed in my operating system i discovered vulnerability in RegWizCtrl ActiveX



The first vulnerability identified in this component was in InvokeRegWizard method; however, this vulnerability identified by mine was in IsRegistered pr… Continue

Posted on May 31, 2008 at 2:00pm —

dev0id

Hacking Flash

Guys!
I am going to give a mouth about the cheating in flash. Talking about the flash you may think only about flash games since they are still popular; however, flash is used for WEB design and you should remember the following:
*The main engine of the flash can be built on flash
*Flash always runs on clients machine - not server.
*Flash could be decompiled.

Ok. Let's start. Talking about flash we always look back and see where it is used, what kind of sites. First of all - that are the sites… Continue

Posted on May 31, 2008 at 1:11pm — 1 Comment

Comment Wall (2 comments)

You need to be a member of House of Hackers to add comments!

Join this Ning Network

At 6:39pm on April 18, 2009, w1r3 said…
how do you do man??
At 1:35am on June 25, 2008, /\/\єтαlKιทg said…
Nice page!
 
 

About

pdp pdp created this Ning Network.
 

© 2009   Created by pdp on Ning.   Create a Ning Network!

Badges  |  Report an Issue  |  Privacy  |  Terms of Service

Sign in to chat!