יום שישי, 25 במרץ 2011

IPHONE4 AND METASPLOIT 3.7.0 INSTALL GUIDE 




בשבוע האחרון קיבלתי 4 IPHONE אחד הדברים הראשונים שחשבתי שחשוב

שיהיה לי עליו הוא 3.7.0 Metasploit חיפשתי קצת ב – Web ולא מצאתי מדריך מלא

ומוצלח להתקנתו.

אז התקנתי OPENSSH ופשוט חיברתי את כל מה שאני מכיר עם מה שמצאתי באינטרנט.

ובניתי מדריך מסודר להתקנתו.

נ.ב מומלץ לאחר התקנת ה - OPENSSH לבצע הכול דרך SSH פשוט נוח יותר.

(סיסמאת ברירת מחדל alpine)

-------------------------------------------------------------------------------------------------
install 'OpenSSH','APT 0.7 Strict' using cydia
cd /private/var
apt-get install subversion nano wget python
apt-get remove ruby rubygems
wget http://apt.saurik.com/dists/tangelo-0.9/main/binary-iphoneos-arm/debs/ruby_1.8.6-p111-5_iphoneos-arm.deb
dpkg -i ruby_1.8.6-p111-5_iphoneos-arm.deb
wget http://apt.saurik.com/dists/tangelo-0.9/main/binary-iphoneos-arm/debs/rubygems_1.2.0-3_iphoneos-arm.deb
dpkg -i rubygems_1.2.0-3_iphoneos-arm.deb
rm ruby*
wget http://updates.metasploit.com/data/releases/framework-3.6.0.tar.bz2
tar jxpf framework-3.6.0.tar.bz2
cd msf3
svn update
msf3
-------------------------------------------------------------------------------------------------

יום שישי, 11 במרץ 2011

Blogspot השתלטות על כל

ניר גולדשלגר חבר בצוות התקיפה של אבנת מציג תהליך השתלטות מלא

על כל בלוג ברשת השייך ל - GOOGLE -blogspot.com.




נ.ב כחלק מבדיחה פנימית שלנו חשבנו מה היה קורה אם הוא היה משתלט על הבלוג הראשי של

גוגל :) היה יכול להיות מעניין.


יום שישי, 25 בפברואר 2011

Patriot NG Host IDS v2.0


Patriot NG is a Host IDS‟ tool that allows real-time monitoring changes in Windows systems. According to Wikipedia, an IDS is defined as “a program used to detect unauthorized access to a computer or a network”.

Prerequisites.

You need to have installed correctly Winpcap (http://www.winpcap.org/install/default.htm) to be fully functional Patriot 2.0.


Patriot monitors:

  • Changes in Registry keys: Indicating whether any sensitive key (autorun, internet explorer settings…) is altered.
  • New files in ‘Startup’ directories
  • New Users in the System
  • New Services installed
  • Changes in the hosts file
  • New scheduled jobs
  • Alteration of the integrity of Internet Explorer: (New BHOs, configuration changes, new toolbars)
  • Changes in ARP table (Prevention of MITM attacks)
  • Installation of new Drivers
  • New Netbios shares
  • TCP/IP Defense (New open ports, new connections made by processes, PortScan detection…)
  • Files in critical directories (New executables, new DLLs…)
  • New hidden windows (cmd.exe / Internet Explorer using OLE objects)
  • Netbios connections to the System
  • ARP Watch (New hosts in your network)
  • NIDS (Detect anomalous network traffic based on editable rules)

Download







יום חמישי, 10 בפברואר 2011

RDP


קיימים לא מעט ארגונים אשר משתמשים בגישת ההפרדה

בין רשת ה - DMZ לבין הרשת הפנימית, וברשת הפנימית בין סיגמנט השרתים

לבין סיגמנט המשתמשים , שימוש בהפרדה בין סיגמנטים

ורק גישה ב - RDP ובשימוש ב - Policy מוקשח על השרת הם חשיבה נכונה

ואבטחתית אשר בד"כ מצמצמות את הסיכונים הקיימים.

כאשר אנחנו מגבילים את המשתמש אך ורק לפורט RDP-3389 ומקשיחים את

השרת כראוי מתקיימת סביבת הגנה טובה.

לאחרונה יצא לי להיתקל בכלי שקצת שובר את תפיסת האבטחה שציינתי

הכלי מנצל את פרוטוקול ה - RDP ומאפשר למשתמש "לרכוב" על צינור ה -

RDP בשירותים שונים, אז איך זה נראה:


ואיפה מורידים את זה את בטח שואלים:


עלמנת להתקין את צד ה - Server אנחנו עדיין צריכים לשבור

חלק מהקשחה שמבוצעת אבל מניסיון זה תמיד אפשרי בצורה

כזאת או אחרת.

יום שישי, 14 בינואר 2011

Online Hash Crackers Web Sites

חשבתי לרכז לעצמי ולאחרים רשימה מסודרת של

online hash crackers web sites

MD5

(IRC Bots)
plain-text.info (irc.Plain-Text.info #rainbowcrack - irc.rizon.net #rainbowcrack)
md5.overclock.ch (irc.rizon.net #md5)
c0llision.net (irc.after-all.org #md5crack - ircd.hopto.org #md5crack - ix.dal.net #md5crack)

NTLM

LM

SHA1

SHA 256-512

MySQL

WPA-PSK (free)
(costs $$$)

מקור


יום שישי, 24 בדצמבר 2010

Wifi Hot Spot איך להפוך את המחשב שלנו ל

הרבה פעמים אנו רוצים לגלוש דרך הטלפון בצורה מאובטחת אבל

לא תמיד יש לנו רשת Wifi שניתן לסמוך עליה.

במקרה שלי יש לי 3G אבל מה קורה אם אין לנו את זה ובכל זאת אנו

רוצים את היכולת לגלוש מאובטח אך דרך הטלפון.

את האמת לספר הכל התחיל שרציתי לקחת את ה - windows 7 שלי להפוך

אותו ל - hot spot ולראות בעזרת sniffer מה אנשים עושים עם האינטרנט שלי :).

היום כבר אני עושה את הכל בעזרת ה - Android שלי כלומר גם פותח hotspot וגם

מאזין לתעבורה.

אבל נחזור לאפליקציה, virtualrouter :

לינק להורדה


חיסרון אחד קיים:

The Wireless Network create/shared with Virtual Router uses WPA2 Encryption, and there is not way to turn off that encryption. This is actually a feature of the Wireless Hosted Network API's built into Windows 7 and 2008 R2 to ensure the best security possible.

כמו כן למחשב הנייד שלכם חייב להיות קישור לאינטרנט חוטי או סלולארי.

יום חמישי, 25 בנובמבר 2010

ScreenSpy meterpreter script

Hi guys

just finished writing a great meterpreter script for metasploit

i was looking for a long time for a script that will give me the ability

to get interactive view of remote desktops when using meterperter,

but didn't find any script that can be used for this task.

so i decided to meet the challenge and create my own script.

hope you like it :)

i would love to hear your comments or any suggestions that you might have

link for downloading the script