Showing posts with label Google Chrome. Show all posts
Showing posts with label Google Chrome. Show all posts

8/29/2013

Use Google Chrome For Hacking

Pentesters သို ့မဟုတ္ Hacker အမ်ားစုဟာ သူတို ့အတြက္ အသံုး၀င္တဲ့ plugin ေတာ္ေတာ္မ်ားမ်ား အသံုးျပဳ လို ့ရတဲ့ Mozilla Firefox Browser ကို အသံုးျပဳၾကတာမ်ားပါတယ္။
ဒါက အရင္တုန္းကပါ အခုဆိုရင္ေတာ့ Chrome Browser မွာ Pentesters ေတြ အသံုး၀င္တဲ ့ extension ေတြ ေတာ္ေတာ္မ်ားမ်ားရွိေနပါျပီ။
အဲ့ဒီ အထဲကမွ အသံုး၀င္မယ္ ထင္တာေလးေတြနဲ ့မိတ္ဆက္ေပးခ်င္ပါတယ္။

XSS Rays

XSS Rays မွာ Scanner, Reverser နဲ ့ DOM inspection tool ေတြပါ၀င္ပါတယ္။

XSS Rays ရဲ ့ Official Description ထဲမွာ ေရးထားတာေတြကေတာ့

Official DescriptionXSS Rays is a security tool to help pen test large web sites. It's core features include a XSS scanner, XSS Reverser and object inspection. Need to know how a certain page filters output? Don't have the source? No problem. XSS Rays will blackbox reverse a XSS filter without needing the source code


Websecurify Scanner


Web application attacks ေတြေတာ္ေတာ္မ်ားမ်ားကို detect လုပ္ေပးႏိုင္တဲ့ scanner ျဖစ္ပါတယ္။ ျပီးေတာ့ fully automated ျဖစ္ျပီး user friendly ျဖစ္ပါတယ္။

အသံုးျပဳပံုအဆင့္ဆင့္
- websecurify scanner ကို ေအာက္က link ကေန download လုပ္လိုက္ပါ။
https://suite.websecurify.com/foundation 

- Scan ဖတ္ခ်င္တဲ့ URL ကို ရိုက္ထည့္လိုက္တာနဲ automatic scanning လုပ္သြားမွာျဖစ္ပါတယ္။

HTTP Finder

HTTP Finder ကေတာ့ Http Parameter Pollution attacks ကို အလြယ္တကူ detect လုပ္ႏိုင္ပါတယ္။ HTTP Parameter Pollution ဆိုတာ ေနာက္ဆံုးေပၚ web application attacks တစ္မ်ိဳးပဲျဖစ္ပါတယ္။

HTTP Finder ရဲ ့ Official Description ထဲမွာ ေရးထားတာေတြကေတာ့

HTTP Parameter Pollution (HPP) is a recently discovered web exploitation technique. Please read the NDSS 2010 paper for more details about the technique. HPP Finder is a Chrome extension designed for detecting HPP attempts. HPP Finder can detect URLs and HTML forms that might be susceptible of parameter pollution, but it is not a complete solution against HPP.

XSS CHEF

XSS CHEF  ဆိုတာ google chrome အတြက္ BEEF (Browser Exploitation Framework) ကို အေကာင္းဆံုး replacement လုပ္ေပးႏုိင္ျပီးေတာ့ exploitation process ေတြကိုလည္း လြယ္ကူေစပါတယ္။

Cookie Editor

Cookie Editor ကလည္း Google Chrome မွာ Hacker ေတြအတြက္ အလြန္ အသံုး၀င္တဲ့ extension တစ္ခုပါပဲ။ အမ်ားအားျဖင့္ session hijacking attacks အတြက္ အသံုးျပဳၾကပါတယ္။
Session Hijacking နဲ ့ပတ္သတ္လို ့က်ေနာ္ introduction သေဘာမ်ိဳးေရးထားတဲ့ ပိုစ့္ရွိပါတယ္ မဖတ္ရေသးရင္ ဒီမွာ သြားဖတ္ႏိုင္ပါတယ္။
Credit: www.koalpha.blogspot.com
Read more »

7/13/2013

CMS Detector for Google Chrome

ကြ်န္ေတာ္ ခုရက္ပုိင္း Firefox က crash ခဏခဏျဖစ္တာနဲ႔ Google Chrome ဖက္ခဏေျပာင္းသုံးပါတယ္။ MCA Extension သြင္းရင္းနဲ႔ ေနာက္ထပ္ Extension တစ္ခုကုိေတြ႕ထားပါတယ္။ အဲဒါကေတာ့ Chrome Sniffer လုိ႔ေခၚပါတယ္။ ဒီ Extension ကေတာ့ ဘာလုပ္ေပးႏုိင္သလဲဆုိေတာ့ ဆုိဒ္တစ္ခုရဲ႕ CMS လုိ႔ေခၚတဲ့ ဘယ္ဟာနဲ႔ Run သလဲဆုိတာကုိ Auto Detect လုပ္ေပးႏုိင္ပါတယ္။ ဥပမာ PHP လား Joomla လား Wordpress လားေပါ့။ တခါတည္း Icon ေလးနဲ႔ပါေသခ်ာျပေပးတယ္ေနာ္ :D ဒါဆုိ ဆုိဒ္ကုိဝင္လုိက္တာနဲ႔အေထြအထူးလုပ္စရာမလုပ္ဘဲ အဲဒီဆုိဒ္ဘာနဲ႔ Run ထားတယ္ဆုိတာ တန္းသိႏုိင္မွာျဖစ္ပါတယ္။ Chrome Sniffer ကုိေအာက္က မူရင္း Chrome Web Store ကေနသြားျပီး အင္စေတာ့လုပ္ႏုိင္ပါတယ္။ Official Web Store ျဖစ္တာမုိ႔ စိတ္ခ်စြာ သြင္းႏုိင္ပါတယ္။ :) ဘယ္လုိလုပ္ရတယ္ဆုိတာမေျပာေတာ့ဘူးေနာ္။ :D သူကေတာ့ ခုေလာေလာဆယ္ Popular ျဖစ္ေနတဲ့ CMS 100 ေက်ာ္ကုိ Detect လုပ္ေပးႏုိင္ပါသတဲ့။
Read more »

4/14/2013

Google Chrome မွာ Addon ထည့္ခ်င္ရင္

ကဲ ဒါေလးကေတာ့ တကယ္လြယ္ကူတဲ့ နည္းေလးပါ။ မသိေတာ့ ခက္တယ္။ Google Chrome က Firefox မွာလုိ extension ေတြကုိ တုိက္ရုိက္ Open လုပ္ျပီး အင္စေတာ့လုိ႔မရပါဘူး။ ကြ်န္ေတာ္လည္းအစက ေၾကာင္သြားတယ္။ ဘယ္လုိ လုပ္ရပါ့ဆုိျပီး တုိင္ပတ္ေနတာ။ အမွန္ကေတာ့ လြယ္လြယ္ေလးပါ။ :D ကဲ စရေအာင္ Google Chrome ရဲ Setting ေတြဆီသြားတဲ့ မ်ားေလးကုိႏွိပ္
ေတြ႕ျပီဆုိရင္ ေအာက္ကပုံအတုိင္း Tools>Extensions ဆုိျပီး အဆင့္ဆင့္သြားလုိက္ပါ။ Extensions ေနရာေရာက္ရင္ မိမိေဒါင္းလုတ္ လုပ္ထားတဲ့ Addon (eg Myanmar.crx :D) ကုိ အဲဒီ Extensions(Tab) ေနရာမွာ Drag and Drop ဆြဲထည့္လုိက္ရုံပါပဲ။
Read more »