Archiv der Kategorie hacking

Hacking: Post exploitation

Hello folks,

Came across a nice tool for uploading to a compromised system:

http://blog.gentilkiwi.com/mimikatz/inject

There is a nice method of getting the local password, without cracking any hashes or passing on hashes.

All to do with the SSO implementation in windows. Really nice and works in seconds.

Also cool to inject DLLs into all processes and get it to communicate with the process.

So no reason not to put it into once arsenal…

Cheers,

Matti

Hacking: SQL Injection tools for free

Hello again,

It might be worth to test your applications for SQL Injection.
Here a list of tools:

Sqlninja ( http://sqlninja.sourceforge.net/ )
sqlmap ( http://sqlmap.sourceforge.net/ )
Pangolin 3.2.3 free edition ( http://down3.nosec.org/pangolin_free_edition_3.2.3.1105.zip )
Havij v1.14 Advanced SQL Injection – free version ( http://www.itsecteam.com/files/havij/Havij1.14Free.rar )
SQL Power Injector ( http://www.sqlpowerinjector.com/ )
Marathon Tool ( http://www.codeplex.com/marathontool )
Absinthe ( http://www.0×90.org/…inthe/index.php )
pysqlin ( http://code.google.c…source/checkout )
BSQL Hacker ( http://labs.portcull…on/bsql-hacker/ )
SQL Injection digger (SQLID) ( http://sqid.rubyforge.org/#download)
WITOOL ( http://witool.sourceforge.nSQL, Oracle, Microsoft SQL Server and Microsoft Access.et/ )
sqlus ( http://sqlsus.sourceforge.net/ )
DarkMySQLi16.py ( http://vmw4r3.blogspot.com/ )
mySQLenum ( http://sourceforge.n…ects/mysqlenum/ )
PRIAMOS ( http://www.priamos-project.com/ )
FJ-Injector Framework ( http://sourceforge.net/projects/injection-fwk/files/)
Bobcat SQL Injection Tool ( http://www.northern-…pub/bobcat.html )
SQLIer 0.8.2b  ( http://bcable.net/releases.php?sqlier )
bsqlbf-v2 ( http://code.google.com/p/bsqlbf-v2/ )
Safe3 Sql Injector ( http://sourceforge.net/projects/safe3si/)
ExploitMyUnion ( http://sourceforge.n…exploitmyunion/ )Laudanum ( http://sourceforge.n…jects/laudanum/ )
WebRaider ( http://code.google.com/p/webraider/ )
Toolza 1.0 ( http://bug-track.ru/prog/toolza1.0.rar )
SCRT Mini-MySqlat0r (http://www.scrt.ch/attaque/telechargements/mini-mysqlat0r)
SFX-SQLi ( http://www.kachakil.com/ )
DarkMySQL ( http://vmw4r3.blogspot.com/ )
ProMSiD Premium ( http://forum.web-def…02&postcount=15 )
yInjector ( http://y-osirys.com/…-softwares/id10 )
Hexjector ( http://sourceforge.n…ects/hexjector/ )

Happy hacking…

Cheers,
Matti

Hacking: Tools

I am sometimes quite surprised of how many web security tools start with a single guy coding something up.

Here is such an example of a really cool tool written by guy from London Royal Holloway University, Anastasios Laskos:

http://arachni.segfault.gr

Really impressed by the high rate and accuracy of issues it discovers…

So thanks for that tool

Cheers,
Matti

Hacking: Traces on the Internet

I was having a look at certain sites and tools that are good for finding things out about other people on the Internet.

Not for stalking :-) but for Social Engineering.

Here are some of which I thought where quite useful….

Social Network Search Sites:

http://www.keotag.com/

http://www.howsociable.com/

http://monitter.com/

http://www.samepoint.com/

http://topsy.com/

http://attentio.com/products

http://tweetpsych.com/

http://tweetscan.com/

http://twitrratr.com/

http://www.neoformix.com/Projects/TwitterStreamGraphs/view.php

http://twendz.waggeneredstrom.com/

http://twittermap.appspot.com/

http://spy.appspot.com/

http://socialmention.com/

http://whostalkin.com/

Those might be good as well:

http://twittercounter.com/ (needs twitter account)
http://www.ubervu.com/ (demo must be requested)
http://www.alterian.com/socialmedia/products/sm2/ (demo must be requested)

People Search Sites:

http://namechk.com/

http://www.peekyou.com/

http://com.lullar.com/

http://www.google.de

People Search Tools

http://www.paterva.com/web5/

http://ilektrojohn.github.com/creepy/

http://code.google.com/p/fbpwn/

Exploiting

http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_%28SET%29

http://www.sptoolkit.com/documentation/001-the-spt-framework/

Cheers,

Matti

Hacking: Passwords again

A lot of the testing nowadays goes back to do some account hacking.
The hope of a password being in a dictionary is long gone.
Too many security policies hindering people to chose weak passwords.

But users still have to be able to remember passwords.
So we do mutations and other things:

http://www.randomstorm.com/rsmangler-security-tool.php

http://www.remote-exploit.org/Wyd/

http://awlg.org/index.gen

So if you want to check your own password:

http://www.passwordmeter.com/

Hacking: All in one DVD

http://www.hackfromacave.com/katana.html

During Blackhat there has been an update to version two

Fun to have everything along….

Cheers,

Matti

Browser Malware

Just a quick one…

There is a nice service for testing flash and javascripts of websites:

http://wepawet.cs.ucsb.edu/index.php

If you feel brave enough to test for yourself or want to get to the source of some javascript stuff:

http://malzilla.sourceforge.net/

Cheers,

M

Hacking: Tools

I had a network test lately and was using some newer tools….

Ncrack:

http://nmap.org/ncrack/man.html

Medusa (after two years a new version):

http://www.foofus.net/jmk/medusa/medusa.html

Nsploit (nmap with metasploit)

http://trac.happypacket.net/

Happy hacking everyone…

Security: ISMS

I have kind of developed a 13 step program to an ISMS….

ISMS - An information security management system

 

 

13 Steps Program:

 

 

  1. Purchase a copy of the ISO/IEC standards

  2. Obtain Management Support

  3. Determine the Scope of the ISMS

  4. Identify Applicable Legislation

  5. Define a Method of Risk Assessment

  6. Create an Inventory of Information Assets to Protect

  7. Identify Risks

  8. Assess the Risks

  9. Identify Applicable Objectives and Controls

  10. Set up Policy and Procedures to Control Risks

  11. Allocate Resources and train the Staff

  12. Monitor the Implementation of the ISMS

  13. Prepare for Certification Audit

 

  Den Rest des Eintrags lesen »

Pre-loaded picture frames…

Just in case you don’t read slashdot… as revealed on http://seattlewireless.net/~casey/?p=13 , the Kodak EasyShare Wireless Digital Picture Frames contain a lovely security issue.

As well as displaying pictures from an SD card, you can point the device at any RSS feed and have it display the contents. You just set up a FrameChannel account using the secret code that comes with the frame, and configure the feeds accordingly. However in the Advanced Settings of this interface there’s a URL that shows a feed of everything being displayed on your frame. This is a very predictable URL, based on the device’s MAC address, So you can see what other Frame owners are downloading to their device…

…and if you look through the comments at that URL,  you’ll see that a lot of “informal assessment” of the service has taken place; it’s possible to reset to activation code for frames, determine the RSS feeds used by devices that have yet to be sold… and there’s some code in the comments to do that for you too.

As “Mike” aptly put it: “So Kodak has essentially built a system for letting complete strangers (a) browse your family photos, and (b) beam shock porn directly into your living-room?”

See also http://yro.slashdot.org/story/10/01/05/0413228/Kodak-Wireless-Picture-Frames-Open-To-Public

( on a side-note I was considering another posting, refuting the comments on http://www.altaware.com/articles/pentest.html, which I stumbled across recently.  In the end I decided that was best left as an exercise for the reader, as the only retort I have that won’t take me an evening to write is “you’re not very familiar with pentesting are you?” )