[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Backtrack. Tampilkan semua postingan
Tampilkan postingan dengan label Backtrack. Tampilkan semua postingan

25/09/12

Urlcrazy Tool On Backtrack 5 R3



Description: URLCrazy is a tool that can generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage. It generates 15 types of domain variants, knows over 8000 common misspellings, supports multiple keyboard layouts, can check if a typo is a valid domain, tests if domain typos are in use, and estimates the popularity of a typo.  

Read More...

Vega Web Scanner On Backtrack 5 R3

  
Description: Vega is an open source platform to test the security of web applications. Vega can help you find and validate SQL Injections, Cross-Site Scripting (XSS), inadvertently disclosed sensitive information, and other vulnerabilities. It is written in Java, GUI based, and runs on Linux, OS X, and Windows. 


Read More...

23/09/12

Tab-Nabbing With Dns Spoofing Using Backtrack

 

Description: In this Tutorial I have Explained how to use SET ( Social Engineering tool kit) for Tab nabbing and DNS Spoofing using Ettercap to make it more effective in LAN.......

In next tutorial I will Explain How to do it using port 443 of attacker machine instead of using port 80. So that even if victim type https://url instead of http then also he/she get attacked.

Read More...

14/10/11

Fuzzing In Backtrack 5 R1- Part 4 - FInal [video]

Read More...

Fuzzing In Backtrack 5 R1- Part 3 [video]

 
Description: Fuzzing is a process of sending deliberately malformed data to a program in order to generate failures, or errors in the application. When performed by those in the software exploitation community, fuzzing usually focuses on discovery of bugs that can be exploited to allow an attacker to run their own code, and along with binary and source code analysis fuzzing is one of the primary ways in which exploitable software bugs are discovered.

There are a number of popular and free software based fuzzers available, but during this article we will focus on one of the first fuzzers to become popular within the Information Security community -- SPIKE.

In this part.. i have used pearl to exploit the victim... and used metasploit to investigate the cause of the crash... using the offset finder.. and other cool tools..

Test done on Backtrack 5 R1 and Windows XP SP3.
Read More...

Fuzzing In Backtrack 5 R1- Part 2 [video]

 
Description: Fuzzing is a process of sending deliberately malformed data to a program in order to generate failures, or errors in the application. When performed by those in the software exploitation community, fuzzing usually focuses on discovery of bugs that can be exploited to allow an attacker to run their own code, and along with binary and source code analysis fuzzing is one of the primary ways in which exploitable software bugs are discovered.

There are a number of popular and free software based fuzzers available, but during this article we will focus on one of the first fuzzers to become popular within the Information Security community -- SPIKE.

In this part.. i have used wireshark to analyse what caused it to crash the .exe file..

Test done on Backtrack 5 R1 and Windows XP SP3.

Music-
Forever Winter - Antim Grahan

Video by ChriAdlr.. enjoy
Read More...

Fuzzing In Backtrack 5 R1- Part 1 [video]

Read More...