DefCon 20 Social Engineering CTF

Ett kommande event på DefCon 20, det är heller inte den första gången :) Så det nedanstående är en ”kass översättning” efter översättningen kan det komma en eller annan fundering ;) The Original Article http://www.social-engineer.org/defcon-sponsorship/ —-Snipe—- Social-Engineer.Org Team meddelar att de kommer att  hålla Social Engineering CTF och Social Engineering CTF för barn igen på Defcon 20. Vi söker fortfarande företag som vill bli sponsorer av ett eller av båda våra evenemang. EventetVårt Social-Engineering CTF är inte ett traditionell Capture the Flag Event. I denna är CTFlaggorna oskyldiga bitar av information som vi ber de tävlande att få. Hur? Varje deltagare tilldelas ett målföretag. De tävlande får två veckor … Continue reading

Linux is safe? Linux security?

Linux is a safe system…….. When talking about IT security often people mention that Linux security is the highest/best one ;) Yeah it is, most of the time. Some bugs do at time pop up. This one is a ”old” one but probably alot of systems do still run the exploitable versions :) rofl I got this from a colleague after some Linux / patching discussions. ———————————————————————- Phenoelit Advisory <wir-haben-auch-mal-was-gefunden #0815 +–++> [ Authors ] … Continue reading

VSSadmin

 Qute stuff to do when running ShadowCopy (VVS) :)  Comments from notepad while watching a online capture from some haxxor show. Prolly abit mixed, but a kewl thing it is ;pLinux Common Directory Names:-space/dotspace/dotdotspace/namespace -mkdir ´.[space]` -mv malware /path/.\[space]/ -/path/.\[space]/malvaremkdir `temp[space]´Windows Alternate Data Streams (ADS) type malware.exe > harmless.txt:evil.exe start c:\path\to\harmless.txt:evil.exe dir /r will find it. (vista and later)  sysinternals Streams list alternate data streams (LADS) fairly easy to eradicate ADS on Steroids echo anything > … Continue reading

Utility NC

A short NC thing! NC or NetCat is often described as a swiss-armyknife of networking utilities. I basically agree allthough there could be things you won´t be able to do. If you haven´t got it installed just fire up  your browser and point it to google.com and do a quick search for it. DL and Install. Upon completion of the above task, at your cli (command line interface) type: nc <enter> and you hopefully get … Continue reading

Securing SCADA

Securing scada A pondering upon things within security and SCADA/ICS, do´s and don´ts for a safer everyday operational environment  SCADA Security With the latest newsbuzz, not many have missed out on the fact that our dear SCADA/ICS are under pontentially massive attack. And I could have understood parts of this back in the ”good old days” when there was HackForFame, who wouldnt be g0d-like pwning a powerplant?  but now…. Terrorists: by either religious or political reasons, are … Continue reading

Patching is fun.

Here are a few thoughts and pointers about patching and updating systems… Have you ever thought about the fact that security thing that is a somewhat ”point of view´ish”? Security bulletins and misc things pound out their newly found flaws and patch info daily. It is frankly a fulltime job to just keep up to it all. But some of the flaws are flagged as minor impcations and some are Important while the ”must have” … Continue reading

USBThief tool or evil

USBThief!! No, it didn´t get stolen. This a kewt lil solution for doing badstuff with a USB. The ”application” consists of a rar file which you download from the internet, as usual with things like this they state: – ”some antiviral software will naggabout it being a virus, but trust us it isnt” (And as usual on this blog I ain´t responsible for the things you do with my information) So search http://www.google.com for USBThief … Continue reading

Metaspl0it

Metaspl0it Framework. Ripped this from their site: —Snipe— The Metasploit® Framework is a free, open source penetration testing solution developed by the open source community & Rapid7. The Metasploit Framework is the de-facto standard for penetration testing with more than one million unique downloads per year and the world’s largest, public database of quality assured exploits. —Snipe— Find it here Using BackTrack will most certainly drag you into metasploit since it contains it ;) BackTrack, … Continue reading

Found this on some site

**** Disclaimer **** Do not ever do this crap, you could get into a heap of shit for doing it. This ”article” is for educational/informational use only. ***********   This is just a show on how fewlity excists on the BBI (big bad Internet) I have edited some of it but basically this isnt my work :) Gmail hacking? Or rather, Hijack another users Gmail account. Log in to your own gmail. *Note: Your account … Continue reading