[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Videos. Tampilkan semua postingan
Tampilkan postingan dengan label Videos. Tampilkan semua postingan

26/09/12

Fimap Tool - Local And Remote File Inclusion With Backbox Linux

 

Description: LFI ATTACK WITH FIMAP, target DVWA, arm BACKBOX LINUX.

First you need to install DVWA*, then run Apache server (comes with BackBox Linux), then read how to use FIMAP (terminal fimap -h), one c99 shell script (to find one type inurl:c99.txt in Google search box).You will need to set Apache directory permissions, for this you can use this bash script : http://www.linux.re.rs/files/scripts/dirbash.sh. I will show you how to upload shell to vulnerable server and exploit the vulnerability.

* How to install DVWA with BackBox Linux !

http://www.anonimus.re.rs/6562

Author : Nenad Marjanovic
IT nick : ZEROF
Author site : http://www.pentester.iz.rs 
Read More...

25/09/12

Urlcrazy Tool On Backtrack 5 R3



Description: URLCrazy is a tool that can generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage. It generates 15 types of domain variants, knows over 8000 common misspellings, supports multiple keyboard layouts, can check if a typo is a valid domain, tests if domain typos are in use, and estimates the popularity of a typo.  

Read More...

Vega Web Scanner On Backtrack 5 R3

  
Description: Vega is an open source platform to test the security of web applications. Vega can help you find and validate SQL Injections, Cross-Site Scripting (XSS), inadvertently disclosed sensitive information, and other vulnerabilities. It is written in Java, GUI based, and runs on Linux, OS X, and Windows. 


Read More...

30/10/11

How To Use Thc-Hydra [video]

 

Description: In this video I show how to use the brute forcer hydra.

Download: http://www.insecurestuff.in/2011/10/thc-hydra-v71-released.html

If u have any Problem then Contact me on Twitter: http://twitter.com/#!/insecurestuff
Read More...

28/10/11

Windows Password Retrieval And Cracking [video]

 
Description: In one of (hopefully) many videos I will be creating highlighting the capabilities of Volatility, a free memory analysis tool.

This video shows grabbing the windows NTLM passwords from a memory dump and then using John the Ripper to crack them.

In other videos I hope to show using a memory dump to detect rootkits and badness on a system.
Read More...

26/10/11

Howto Use Droidsheep - Tutorial [video]

 

Description: This official tutorial for DroidSheep for Android shows how to use DroidSheep to capture sessions in your local network.

DroidSheep runs on your Android device and listens to the networks traffic. If it captures a cookie, it shows a list with the cookies and the user can simply use the victims account without knowing his user credentials.

Download droidsheep: http://www.insecurestuff.in/2011/09/droidsheep.html


Read More...

5 SECONDS to bypass an iPad 2 password [video]

Video The password protection of an iPad 2 running iOS 5 can be circumvented in less than five seconds with just three simple steps.

Bypassing the unlock screen on iPad 2 can be accomplished by first pressing the power button until the power-off screen is displayed. Users then need only to close and reopen the fondleslab's 'smart cover' before, finally, pressing the cancel button to unlock the device.

After dodging the password protection, you can access the foreground application running at the time the device was locked, potentially exposing corporate email in the process. You can't use the home button, so access is limited to foreground applications. As enterprise IT blog BringYourOwnIT.com notes, one obvious workaround would be to instruct users to close any foreground application before locking their iPad.

Below is a video posted by BringYourOwnIT.com illustrating the easy unlock process.


The security weakness comes days after it emerged that locked iPhone 4S could be accessed using Siri, the voice-activated personal assistant built into the device.
There's an easy way for security-conscious users to disable Siri when their phone is locked but this option isn't applied by default, net security firm Sophos Read More...

25/10/11

So I Googled your name and found.. a Twitter phishing attack! [video]

Slumped tweetSometimes they claim to have found a funny picture of you, say that you look like you've lost weight, or that there's a horrible blog going around about you.

Whatever the nature of the disguise used by phishing attacks on Twitter, the modus operandi is always the same. Scammers will send you a message, possibly from the compromised account of one of your Twitter followers, and use a social engineering lure to trick you into clicking on the link.

And that link will, inevitably, lead to a fake Twitter login page - designed to grab your username and password which can then be used to send out more spam, or to break into your other online accounts.

Here's the latest attack, which arrives in the form of a Direct Message (DM) from one of your Twitter pals, claiming that they have searched for you on Google and found some "really funny stuff" about you.

Twitter phishing attack via Direct Message
so i googled your name and found some really funny stuff about you lol its archived here [LINK]
Would you click on the link? Well, if you were tempted to do so your web browser would end up on a fake Twitter page just waiting for you to enter your username and password.

Fake Twitter login page

And if you do enter your details, you've been phished. Ouch.
Hopefully, you're not one of the many people who use the same password on multiple websites - otherwise cybercriminals might not just be able to send spam from your Twitter account, they may also have just been handed the skeleton keys for other parts of your online existence.

That could mean that scammers can now steal your personal information for financial gain.

Password chart

If you found your Twitter account was one of those sending out the phishing messages, you shouldn't just change your password and consider if you are using the same password elsewhere. It's also a sensible time to look again at how you choose your passwords.

For instance, it's important that you don't use a word from the dictionary as your password. It's easy to understand why computer users pick dictionary words as they're much easier to remember, but as I explain in this video a good trick is to pick a sentence and just use the first letter of every word to make up your password.



(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)

Password security is becoming more important than ever. Make sure that you're taking the issue seriously, or suffer the consequences.

There's some other house-cleaning you should do on your Twitter account too. Visit the Applications tab in "Account Settings", and revoke access for any third-party application that you don't recognise.

Follow me on Twitter if you want to keep up-to-speed with the latest threats, and learn how to protect yourself.
Read More...

Aidsql: Sql Injection Penetration Testing Tool [video]



Description: This is a video showing you how to effecitvely audit your website with aidsql.

Download aidSQL: http://www.insecurestuff.in/2011/02/aidsql-tools-to-find-vulnerable-spots.html
Read More...

21/10/11

Metasploit 4.1 And Armitage: What's New? [video]

 

Description: This video shows some of the new features in Armitage for Metasploit 4.1. You'll see improved tab management features, more exploit feedback, VNC, brute forcing, token stealing, and an export data feature to aid reporting. You can learn more about Armitage at rel="nofollow">http://www.fastandeasyhacking.com/
Read More...

18/10/11

Knube Howto #1: Patch Negative One In Aircrack [video]

Description: I'm bad at make videos but my cousin help me soon and then we have audio and much more. Okay, so... This is video #1 in "Knube Howto". It is about patching your wireless drivers to work better with aircrack suite of tools. This will get rid of the annoying "channel: loacked -1" on most modern wirelss "things". As I am new to security I and others run into problems which... Plainly put the experts do not cover. So I begin a series of exploration and describing things to knubes such as myself. I hope you enjoy
Read More...

14/10/11

Fuzzing In Backtrack 5 R1- Part 4 - FInal [video]

Read More...

Fuzzing In Backtrack 5 R1- Part 3 [video]

 
Description: Fuzzing is a process of sending deliberately malformed data to a program in order to generate failures, or errors in the application. When performed by those in the software exploitation community, fuzzing usually focuses on discovery of bugs that can be exploited to allow an attacker to run their own code, and along with binary and source code analysis fuzzing is one of the primary ways in which exploitable software bugs are discovered.

There are a number of popular and free software based fuzzers available, but during this article we will focus on one of the first fuzzers to become popular within the Information Security community -- SPIKE.

In this part.. i have used pearl to exploit the victim... and used metasploit to investigate the cause of the crash... using the offset finder.. and other cool tools..

Test done on Backtrack 5 R1 and Windows XP SP3.
Read More...

Fuzzing In Backtrack 5 R1- Part 2 [video]

 
Description: Fuzzing is a process of sending deliberately malformed data to a program in order to generate failures, or errors in the application. When performed by those in the software exploitation community, fuzzing usually focuses on discovery of bugs that can be exploited to allow an attacker to run their own code, and along with binary and source code analysis fuzzing is one of the primary ways in which exploitable software bugs are discovered.

There are a number of popular and free software based fuzzers available, but during this article we will focus on one of the first fuzzers to become popular within the Information Security community -- SPIKE.

In this part.. i have used wireshark to analyse what caused it to crash the .exe file..

Test done on Backtrack 5 R1 and Windows XP SP3.

Music-
Forever Winter - Antim Grahan

Video by ChriAdlr.. enjoy
Read More...

Fuzzing In Backtrack 5 R1- Part 1 [video]

Read More...

Oscommerce Malware Infection + Internet Explorer Exploit [video]

 

Description: OsCommerce suffers of few vulnerabilities that can lead an attacker to upload files and execute remote code. What i want to show you is how probably an attacker has infected a site running an old copy of osCommerce to spread malware.
Read More...

BlackBerry outage, video apologies, a hoax and Ronnie Corbett [video]

BlackBerryMillions of BlackBerry owners around the world have been feeling the pain this week as messaging and email systems collapsed in a service outage.

With many turning to social networks to vent their anger, and even newspaper cartoonists making fun of the situation, bosses at Research in Motion (RIM) have clearly been feeling the heat.

RIM founder Mike Lazaridis has appeared on video explaining that although services are "approaching normal BlackBerry service levels in Europe, the Middle East, India and Africa" the company can not give an estimated time for systems to have recovered globally.


Lazaridis has also warned that there could be more instability to come. Clearly BlackBerry users aren't entirely out of the woods yet.

Things aren't helped, of course, when nonsensical BlackBerry-related hoax messages are spread. A message has been distributed via BlackBerry Messenger (BBM) claiming that users have to forward the message to all of their contacts, or else their BlackBerry account will be disabled.
Broadcast this message to every single contact on your BBM to reset your display picture, sorry for any inconvenience. This message is to inform all of our users, that our servers have recently been really full, so we are asking for your help to fix this problem. We need our active users to re-send this message to everyone on your contact list in order to confirm our active users that use BlackBerry Messenger, if you do not send this message to all your BlackBerry Messenger contacts then your account will remain inactive with the consequence of losing all your contacts Symbol will automatic update in your BBM ,when you broadcast this message. Your blackberry will be updated within 24 hours it will have a new lay out and a new color for chat.
Of course, the message is nonsense - and it should not be forwarded.
If you need some cheering up, and want a more humorous take on a blackberry not working, check out this sketch by British comedy veteran Ronnie Corbett:


Update: RIM is now reporting that its services are "fully restored." The BBC reports that at a press conference, RIM said they would begin a full investigation into what went wrong and caused the biggest crash in the company's history.
Read More...

06/10/11

Steve Jobs death exploited by Facebook scammers

It's impossible to express how sad many people in the technology world feel at the news of the death of Steve Jobs.

Sickeningly, as with the deaths of other figures in the public eye, there are scammers waiting to take advantage of bad news.

Here's a scam we have seen on Facebook, claiming that free iPads are being given away "in memory of Steve Jobs".


In memory of Steve, a company is giving out 50 ipads tonight. R.I.P. Steve Jobs [LINK]

The cool-sounding link sucks you in, tricking you into believing that you may get a free iPad but then goes on to get you to complete online surveys to "qualify".

The link goes through the bit.ly short url service (we have asked our friends at bit.ly to shut the link down) and we can see that over 15,000 people have already clicked on the link which was set up within hours of Steve Jobs's death first being announced.



Of course, if you were one of those people who clicked on the link you may be wondering what the chances are that you will receive a free iPad. I hate to disappoint you, but it's pretty unlikely.

The webpage you are taken to is very similar to ones we have seen pointed to by other scammers. Here's what I saw:



I am writing this article from the Virus Bulletin conference in Barcelona, and you can see that the page has automagically determined where I am in the world and adjusted its language and wording as appropriate.

Below you'll see how the survey pages look if you visit them from Sydney, Australia, for instance.

Survey site visited from Australia
If you don't click through within a few seconds, it plays an audio message urging you to do so:

You'll notice that the audio message spectacularly fails to mention the 50 free iPads, which have by this time been reduced to the promise of "an exclusive reward", whatever that might be.

My colleague Paul Ducklin captured the audio and - being a fountain of interesting but not always entirely relevant information - tells me that the speaker is an Australian who grew up in South Africa.

When Duck visited the page a second time from Sydney, this is what he saw:
Casino website
How do the scammers make money? Well, they are earning affiliate cash - in a nutshell, they make more money the more traffic they can direct to websites, driving more people to become customers, or take online surveys and competitions.

Cynically, they exploited the death of Steve Jobs in the hope of driving large numbers of internet users to websites offering content such as contests, surveys and online gambling. The fact is, of course, that they could just as easily have taken those users to a webpage containing malicious code or a phishing page designed to steal credentials.

Chances are that this won't be the only scam we see regarding the untimely death of Steve Jobs. It wouldn't be a surprise, for instance, to see scams which might try to take advantage of those moved by the loss of Apple's founder with lures like "Donate to Steve's favourite charities as a tribute".

If you do want to pay tribute to Steve Jobs, the most appropriate place it seems to me would be Apple's website itself.

The truth is that the scammers are not geniuses like Jobs, and they don't contribute anything to the world of technology or wider society as Steve Jobs did. It's a shame that they can't be inspired by speeches like the one Jobs gave at Stanford University in 2005, and make something better of their lives.



I think that's how we should remember Steve Jobs today.

Please folks - always think carefully about the links that you click on. Time and time again scammers and cybercriminals have proven themselves to have no qualms about exploiting news stories - whether it be the personal tragedy of a teenage girl committing suicide, bizarre escapades, a natural disaster or the latest salacious celebrity gossip.


Read More...

04/10/11

Facebook and Websense Partner to Protect Users from Malicious Links [video]

Starting today, we have implemented a partnership with Facebook, arguably the largest, most important platform on the globe, to better protect users against malicious links leading to malware-embedded websites and fraud.

A platform as popular as Facebook is naturally a target for attackers. We have been working with Facebook and their security teams for a number of years in order to keep their users safe, but now we have integrated directly into the platform for an unprecedented security combination.

Soon, when a user clicks on a URL that has been posted within Facebook, that link will be sent to Websense for security classification. The Websense® ThreatSeeker® Cloud, an advanced classification and malware identification platform, will then analyze the link in real time. If the destination site is considered unsafe, the user is presented with a warning page that offers the choice to continue at their own risk, return to the previous screen, or get more information on why it was flagged as suspicious.

In this way, we are helping Facebook continue their proactive fight to keep malicious links off of their platform and allow safe use for all of its members.




At Websense, we are all about innovation and changing the security game. We were the first company to promote and enable our customers to embrace safe, productive use of social with our web security gateway, the first to deliver security and anti-spam to protect companies presence within Facebook with Defensio, and now we are assisting in the protection of all users on the platform with our cloud integration.

This is the same technology that already powers our industry-leading TRITON™ solutions, and it now extends that same protection to consumers and other users of Facebook.

For more information, you can view the news release here, or check out the infographic below.
Read More...