Great tutorial!
Just curious what you mean by this? "Antivirus detections contain BAT as platform." Meaning the AV detection is in a BAT file?

Is there money involved?

Good idea will update thread. Yes there is.

Pardon me my good Sir, but, in your opinion, what would some non-common XSS techniques consist of?

(for everyone else blindfuzzy, as is our usual banter)

I was just referring to the info posted as common knowledge. You can google XSS and find all this in better formatting with more information.

Funny his post almost looks like this one:

Anywho some less common vectors for XSS include:
1″ onmouseover=alert(“xss”); “
“onload=’confirm(“test XSS”)’
” onload=’javascript:alert(1)’

You can exploit these when the input parameter value is reflected in HTML input tag or in other HTML code.
You can also XSS the file upload functionality by uploading an html file with xss type of script. Things get more tricky with a site that is locked down with ASP and there are various fuzzing techniques to bypass the ASP xss protection.

Seeing as the team and I have put a bunch of time into getting the channel the way we want it, and setting up a streamlined process of getting videos pushed out on a near weekly basis with awesome intros now thanks to OE. I realized we need to keep growing and gather up more user interaction on the board. #security needs a graphic of its own that we can add to the youtube channel, intros, and in our weekly discussion thread here on the board.


Can't be fucking wallpaper huge in size (Although I wouldn't mind having a wallpaper version of the winner). We are looking for logo, twitter banner sizes.

Must be cyber security related.

Myself, Oe800, and thewormkill (There will be a randomly picked judge from the #security channel in lieu of a tie)

Be creative have fun with it! This graphic will represent not only #security but evilzone. This graphic will be placed in our discussion thread, youtube channel, twitter and any other public account we have for our weekly meetings.

The winner will receive $100 via paypal

I am setting a 30 day time limit on this contest. This contest WILL end March 17th at 12:00pm EST. Winner will be posted within a week of the contest ending. (Could be shorter depending on the number of submissions)

Good luck to everyone!

This weeks topic is: You can no haz mai dataz FBI

Where's the handbook? All I see is your thread with common knowledge material.

Tomorrows meeting has been cancelled. Can pm me for further details.

Ummm, GET and POST requests can be easily made through HTML forms, images, script tags etc... I'd worry less about CSRF exploitation if you are asking that question. You need to do some research.

Front page has been updated with Meeting #7 video.

This weeks topic will be on Dridex the banking trojan.

Quick resource here to spin you up on what exactly Dridex is and does...etc:

iTpHo3NiX is right. I also had problems installing it in a vm (vmware workstation). Should do it straight in your machine. In dual boot maybe?

Don't dual boot it.

Meeting #6 (maybe its 7?)

Tools are for tools:

Thank you sir! Front page has been updated with the link.

I'm getting lazy but this weeks topic was on: Tools are tools...and I don't mean that in a good way.

I pretty much bitched about how new people are coming in to the industry and relying heavily on tools and scanners and not having much manual testing skills. A big epidemic in the industry these days in my opinion.


Enumeration is going to be vital. Get your team good at it. 

