JPEG & PNG Stripper – Exif and Metadata Removal

March 1, 2009 – 8:24 AM

JPEG & PNG Stripper is a Windows only tool for stripping/cleaning/removing unnecessary metadata (junk) from JPG/JPEG/JFIF & PNG files. The image quality IS NOT AFFECTED. Includes command line support as well.

Before:

JPEG and PNG Stripper

JPEG and PNG Stripper

Just drag the files that you want to strip onto the application:

stripper3

After:

stripper4

stripper5

Download:
http://www.steelbytes.com/?mid=30&cmd=download&pid=15

CCleaner 2.17.853 Released

February 28, 2009 – 11:19 AM

CCleaner is a freeware system optimization, privacy and cleaning tool. It removes unused files from your system – allowing Windows to run faster and freeing up valuable hard disk space. It also cleans traces of your online activities such as your Internet history. Additionally it contains a fully featured registry cleaner. But the best part is that it’s fast (normally taking less than a second to run) and contains NO Spyware or Adware!

What’s new:

  • Added wiping of disk free space.
  • Progress bar changed to go from 0 to 100%.
  • Improved Apple Safari history cleaning.
  • Improved speed of Uninstaller Tool.
  • Interface string changes and fixes.
  • Added Ukranian translation.
  • Installer language tweaks.
  • Minor architecture changes.
  • Minor bug fixes.

Download:
http://www.ccleaner.com/download

PHP 5.2.9 Released

February 27, 2009 – 5:46 AM

The PHP development team would like to announce the immediate availability of PHP 5.2.9. This release focuses on improving the stability of the PHP 5.2.x branch with over 50 bug fixes, several of which are security related. All users of PHP are encouraged to upgrade to this release.

Security Enhancements and Fixes in PHP 5.2.9:

  • Fixed security issue in imagerotate(), background colour isn’t validated correctly with a non truecolour image. Reported by Hamid Ebadi, APA Laboratory (Fixes CVE-2008-5498). (Scott)
  • Fixed a crash on extract in zip when files or directories entry names contain a relative path. (Pierre)
  • Fixed explode() behavior with empty string to respect negative limit. (Shire)
  • Fixed a segfault when malformed string is passed to json_decode(). (Scott)

Source:
http://www.php.net/releases/5_2_9.php

SSLstrip – HTTPS Stripping Attack Tool

February 26, 2009 – 5:41 AM

This tool provides a demonstration of the HTTPS stripping attacks that was presented at Black Hat DC 2009. It will transparently hijack HTTP traffic on a network, watch for HTTPS links and redirects, then map those links into either look-alike HTTP links or homograph-similar HTTPS links. It also supports modes for supplying a favicon which looks like a lock icon, selective logging, and session denial.

To get this running:

  • Flip your machine into forwarding mode.
  • Setup iptables to redirect HTTP traffic to sslstrip.
  • Run sslstrip.
  • Run arpspoof to convince a network they should send their traffic to you.

That should do it.

How does this work?

First, arpspoof convinces a host that our MAC address is the router’s MAC address, and the target begins to send us all its network traffic. The kernel forwards everything along except for traffic destined to port 80, which it redirects to $listenPort (10000, for example).

At this point, sslstrip receives the traffic and does its magic.

Download:
http://www.thoughtcrime.org/software/sslstrip/sslstrip-0.2.tar.gz

Source:
http://www.thoughtcrime.org/software/sslstrip/

Comments Are Now Open

February 25, 2009 – 6:39 PM

I just turned off the option that required users to register an account before they could comment on this site.  I originally turned this on when I first moved to WordPress in hopes of avoiding all the comment SPAM.  But there are now some great SPAM prevention options that are available for WordPress so I will be using them instead and opening the comments up to anybody who wants to contribute to the topic.  I would much rather have quality discussions or debates than to just close the doors and block all the people that do not want to register.  I’ll deal with the false-positives and missed SPAM as they occur.