ads

Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Saturday, 29 June 2013

SHODAN FOR PENETRATION TESTERS

shodan interface!!


SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability analysis including default passwords, descriptive banners, and complete pwnage. For penetration testers, SHODAN is a game-changer, and a goldmine of potential vulnerabilities.

Download the PDF presentation by Michael Schearer ("theprez98")
HERE

The talk includes the following:
  • What is SHODAN?
  • Basic Operations
  • Penetration Testing
  • Case Study 1: Cisco Devices
  • Case Study 2: Default Passwords
  • Case Study 3: Infrastructure Exploitation
  • Other Examples
  • The Future
  • Conclusions

Saturday, 25 August 2012

XSS Persistence Demo [video]

Penjelesan dan video mengenai XSS Persistence Demo


Thursday, 23 August 2012

BoNeSi- A New DDoS Botnet Simulator Tool Available For Download

 
After Armageddon now we got BoNeSi, the DDoS Botnet Simulator is a Tool to simulate Botnet Traffic in a testbed environment on the wire. It is designed to study the effect of DDoS attacks. BoNeSi generates ICMP, UDP and TCP (HTTP) flooding attacks from a defined botnet size (different IP addresses). BoNeSi is highly configurable and rates, data volume, source IP addresses, URLs and other parameters can be configured. There are plenty of other tools out there to spoof IP addresses with UDP and ICMP, but for TCP spoofing, there is no solution. BoNeSi is the first tool to simulate HTTP-GET floods from large-scale bot networks. BoNeSi also tries to avoid to generate packets with easy identifiable patterns (which can be filtered out easily).
It is highly recommend to run BoNeSi in a closed testbed environment. However, UDP and ICMP attacks could be run in the internet as well, but you should be carefull. HTTP-Flooding attacks can not be simulated in the internet, because answers from the webserver must be routed back to the host running BoNeSi. A demo video of BoNeSi in action can be found here.
 
To Download BoNeSi Click Here

BT5 R3 preview was released!!

 
BT5 R3 preview was released  in BlackHat 2012 Las Vegas for the enjoyment of conference attendees. The main aim of that pre-release was to figure out their last bug reports and tool suggestions from the BH / Defcon crowds. This final release mainly focuses on bug-fixes as well as the addition of over 60 new tool. A whole new tool category was populated – “Physical Exploitation”, which now includes tools such as the Arduino IDE and libraries, as well as the Kautilya Teensy payload collection.
As usual KDE and GNOME, 32/64 bit ISOs, have been released a single VMware Image (Gnome, 32 bit). 
We would also like to give to reminder that the first release candidate (R1) of BackTrack 5 was released in August last year. Later in March this year we got the second release candidate (R2) of BT 5. 
For those requiring other VM flavors of BackTrack If you want to build your own VMWare image then instructions can be found in the BackTrack Wiki. Direct ISO downloads will be available once all our HTTP mirrors have synched. But still you can download BackTrack 5 R3 via torrent from the below links. 

sumber

Wednesday, 13 June 2012

Gmail Hacked!! State-Sponsored Attackers Accessing Millions of Gmail Accounts Illegally

This year cyber criminals became very busy while penetrating security systems of many leading Industries. Last week we have seen hackers had managed to steal more than 6.5 million passwords of LinkedIn users. Also this week we have seen popular dating site eHarmony faced cyber attacks which causes serious damages. Now its the turn for Internet giant Google. Hackers have managed to breach the tight security system of Google Mail I mean Gmail. According to last report state-sponsored attackers are accessing millions of Gmail accounts illegally. Google unveiled a new warning system to alert Gmail users when it suspects “state-sponsored” attackers are attempting to compromise their accounts or computers using malicious software.



Monday, 11 June 2012

Reason to be careful if 'PayPal' says you have changed your email address

 Have you received a notification claiming that your PayPal email address has changed?
Messages like the following have been spammed out to internet users:

Sunday, 10 June 2012

Understanding Different Types of Malware

You may have probably heard of the term malware, virus, Trojan, key-logger, worm, backdoor, bot, root-kit, ransom-ware, ad-ware, spyware and dialer but wonder what are the differences as you may probably only know about virus. Basically malware is short for Malicious Software where all of the terms above falls into this category because they are all malicious. The different term being used instead of just plain virus is to categorize what the malicious software is capable of doing. For example, a keylogger steals whatever that is typed on your keyboard and sends it to the hacker, a trojan opens up a backdoor allowing the hacker to gain full access to your computer and etc.

Saturday, 9 June 2012

Dating Site eHarmony Hacked, 1.6 Million Password Stolen


After LinkedIn now cyber criminals targeted one of the famous dating site eHarmony and stolen more than 1.6 millions of passwords from the database. The authority has admitted that its password database has been compromised, with around 1.5 million hashed passwords being found in the wild. The leaked database that appeared in public contained unsalted MD5 hashed passwords and was reported to not contain any identifying user-names or email addresses. According to the sources all the password hashes has been

Friday, 8 June 2012

Flamer/Skywiper Stuxnet

SALAM..
kebelakangan ini, Ace tengok kebanyakkan media sosial banyak Update mengenai Flame malware. So, Ace nak gak menyebok wat 1 post mengenai ni. hehehe.Selepas "Duqu" kini The Iranian Computer Emergency Response Team (IRCert) mendakwa telah menemui Stuxnet baru yang disasarkan untuk menyerang sistem dalaman negara.Stuxnet yang baru dijumpai nie telah digelar Flame (juga dikenali sebagai Flamer atau Skywiper). Nama "Flamer" datang dari modul serangan,

6.5 Million of LinkedIn Passwords Stolen By Cyber Criminals

security compromised
Very popular social networking site LinkedIn are currently running through a massive cyber attacks. It has been allegedly reported that more than six million passwords belonging to LinkedIn users have been compromised among them more than 300,000 passwords has already been cracked and published as plain text. A file containing 6,458,020 SHA-1 unsalted password hashes has been posted on the internet, and hackers

Thursday, 7 June 2012

[tuto]How to Upload Shell in Wordpress

wordpress logo
ok.let us learn together.
this tutorial will be in dual language
- english
+ bahasa melayu

Wednesday, 6 June 2012

Hacker Evolution Duality Game

Hacker Evolution Duality is the upcoming hacking simulation game, developed by exosyphen studios. Based on the successful Hacker Evolution game series, it has been completely redesigned to offer an impressive and new gaming experience.
Hacker Evolution Duality starts in the early days of Brian Spencer when he was nothing more than a brilliant programmer. It then fast forwards to the future, where he has to stop an Artificial Intelligence he has created, unknowingly and take back control of a giant company he once used to own.

Related Posts Plugin for WordPress, Blogger...