Quantcast
Channel: Pax Pentest » Exploit
Browsing index pages (51 articles)
↧

Is Tcl programming language the best kept secret in hacking?

Actually the Tcl (Tool Command Language) developers website says: Many have called it the “best-kept secret in the software industry”. They also say: Tcl (Tool Command Language) is a very powerful but...

View Article


The odd paucity of Cisco exploit research

It’s a strange thing. I can find voluminous exploit research in books and online on every topic under the sun; on every platform, covering all manner of software and hardware, with the exception of...

View Article


Hacking the Hackers: How FinFisher was Breached

I first came across Gamma International on the Enemies of the Internet website: Gamma International offers advanced spyware, which has repeatedly been discovered in countries who mistreat journalists,...

View Article

Breaking Bad cybercrime

Thought I’d highlight an informative and entertaining blog post written by Dave Waterson using the springboard of the TV crime drama series Breaking Bad to draw comparisons between the underground drug...

View Article

Markets for Cybercrime Tools and Stolen Data Hackers’ Bazaar

Thought I’d share a PDF on research relating to the characteristics of cyber criminal activity and black (and Grey) markets. This was part of the recommended reading for my Malware course and makes for...

View Article


@BSidesLondon YouTube Vidoes

Videos are being posted on YouTube of the recent BSidesLondon conference, which are well watching. I’m halfway through: Rafal Wojtczuk – Lol Layers on Layers Bypassing Security for Fun and Profit Over...

View Article

Mutillidae II: SQLMAP with WebScarab

Having completed my incursion into Metasploiitable 2 I’m beginning my foray into Mutillidae II. This is my first time using SQLmap and I thought you could simply aim it at a known vulnerable web page...

View Article

Metasploitable 2: The Roundup

It has been rather enjoyable and satisfying hacking my way through Metasploitable 2. The process has consolidated some rather disparate knowledge in my brain and I’ve learned loads. I thoroughly...

View Article


Metasploitable 2: Port 8787 Open and Unknown

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 8787/tcp  open  unknown As we can see this Nmap scan did not recognise the service signature running on port 8787 and so...

View Article


Metasploitable 2: UnreaIRCD IRC daemon

The Nmap scan of Metasploitable 2 revealed: PORT STATE SERVICE VERSION 6667/tcp open irc Unreal ircd 6697/tcp open irc Unreal ircd UnreaIRCD is an Internet Relay Chat service. This exploit has been...

View Article

Metaspolitable 2: Port 6000 – X11 Server

It’s worth noting at the outset of this post that I was unsuccessful in exploiting this X11 service, but will document my efforts nonetheless. The Nmap scan of Metasploitable 2 revealed: PORT STATE...

View Article

Image may be NSFW.
Clik here to view.

Metasploitable 2: Port 5900 – VNC

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 5900/tcp  open  vnc         VNC (protocol 3.3) The information online pertaining to exploiting this VNC service all use...

View Article

Metasploitable 2: Port 5432 – PostgreSQL

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 5432/tcp  open  postgresql  PostgreSQL DB 8.3.0 – 8.3.7 This exploit is straight forward brute force using Metasploit:...

View Article


Metasploitable 2: Port 3632 distccd Exploit and Privilege Escalation

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 3632/tcp  open  distccd? What is distccd? Distcc is a program to distribute builds of C, C++, Objective C or Objective...

View Article

Metasploitable 2: Port 3306 MySQL

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 3306/tcp  open  mysql       MySQL 5.0.51a-3ubuntu5 The Nessus report on this port was very revealing; here is some of the...

View Article


Metasploitable 2: Port 2121 – ProFTPD 1.3.1

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 2121/tcp  open  ftp         ProFTPD 1.3.1 The Nessus report on Port 2121 had this to say: 2121/tcp FTP Supports Clear...

View Article

Metasploitable 2: Port 1524 ingreslock Backdoor

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 1524/tcp  open  ingreslock? Ingreslock was popular for adding a backdoor on to a compromised server. The Nessus report...

View Article


Metasploitable 2: Java RMI (Remote Method Invocation) Server

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 1099/tcp  open  rmiregistry GNU Classpath grmiregistry From Wiki: The Java Remote Method Invocation (Java RMI) is a Java...

View Article

Metasploitable 2: Remote Access Ports 512, 513 & 514

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 512/tcp   open  exec? 513/tcp   open  login 514/tcp   open  tcpwrapped All of these ports are running “r” services. These...

View Article

Metasploitable 2: Samba Server

The Nmap scan of Metasploitable 2 revealed: PORT      STATE SERVICE     VERSION 139/tcp   open  netbios-ssn Samba smbd 3.X (workgroup: WORKGROUP) 445/tcp   open  netbios-ssn Samba smbd 3.X (workgroup:...

View Article
Browsing index pages (51 articles)


Latest Images