Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 26 guests online
 
Advertisement

You are here: Home
EH-Net
May 23, 2013, 02:22:17 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2] 3
16  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: VMware workstation Hangs & freez Guest O.S on: August 26, 2012, 01:29:27 PM
yeah you are right, i think 1GB ram for backtrack & 512 for xp should sound better i guess, coz , running  nessus, metasploit, or sometimes metasploit community edition may use more cpu.

But totally Vmware is much better than VBox its much more advanced
17  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: VMware workstation Hangs & freez Guest O.S on: August 26, 2012, 01:25:37 PM
Oh sorry about that, systems CPU is Intel core i5 2430M CPU @2.40 GHz, Yes i installed vmware tools, i never forget that part.



for me knowing your computer's RAM and HDD is not enough you must tell me what is the system's CPU? Did you installed Vmware tools on both virtual systems?

i think Vmware needs more system resources than Vbox and as you have windows seven its better to dedicate 2GB of ram to your real PC it means 1GB for backtrack and 1GB for XP

i extremely suggest you to use VMWare 8 and i dedicated 512mb OF ram for Backtrack and 256 MB for XP i dont have any problem about performance.

and VMware 7.1 is much more better than 7. If you coouldnt resolve the problem disable you AV before you start the VMs and its better to run Game booster programs like Game Fire (its great)
18  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / VMware workstation Hangs & freez Guest O.S on: August 26, 2012, 09:59:51 AM
I have a vmware workstation 7 running backtrack 5r2 & windows xp, backtrack uses 2GB of ram & xp uses 1GB, the host O.S system is HP with 4GB Ram, 320 GB HDD, windows 7 ultimate. the virtual machine hangs & freez the guest & host while i practice penetration testing, before i used virtual box everything ran super fine, are there any settings to be applied ? please suggest me if you have any any idea regarding this issue.

Regards

skorpinok.

         
19  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / VMWARE Network Settings For Pentest Lab Help ? on: July 22, 2012, 09:24:31 AM
Hello,
          I have Backtrack 5R2, Windows XP & Metasploitable-2  inside the VMWARE Workstation, i need Backtrack machine to communicate with other two vm's & download updates,surf internet, so what will be the network setup in this case ? please suggest me..


Regards.
20  Resources / Mass Media / Re: Reboot - A Film by Joe Kawasaki on: July 16, 2012, 10:17:54 AM
Thank you for this info, its a short film right 35 min..

http://www.imdb.com/title/tt2090594/


Joe Kawasaki wrote and directed this hacker-themed film described as:

Quote

Set within a dystopian world that is a collision between technology and humanity, "Reboot" touches upon many of the current social and political concerns that arise from becoming more and more intertwined with the virtual.

In contemporary Los Angeles, a young female hacker (Stat) awakens from unconsciousness to find an iPhone glued to her hand and a mysterious countdown ticking away on the display. Suffering from head trauma, and with little recollection of who she is or what is happening, Stat races against time to figure out what the code means, and what unknown event the pending zero-hour will bring.


Check out trailer here:

http://www.rebootfilm.com/trailer

Special Sneak Preview of REBOOT hosted by Hak5's Darren Kitchen in SF on Friday March 30. Get details here:

http://www.rebootfilm.com/sneakpeak

Don
21  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How to enable port 80 on windows xp? on: July 13, 2012, 02:27:25 AM
Great thanks guy's for all your's really helpful suggestions,  i will try with webgoat..& how about Mutillidae ? is that any good for practice ? can i install it on windows xp ?

Best Regards
Skorpinok.
22  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: How to enable port 80 on windows xp? on: July 09, 2012, 02:22:30 PM
Thank you..
23  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / How to enable port 80 on windows xp? on: July 09, 2012, 10:31:01 AM
Hello,
          How to enable port 80 in windows xp sp2 virtual machine, i have bactrack 5R2 & when i run an nmap scan against my xp machine i dont see port 80, please help me with this.

Nmap scan report for 192.168.56.102
Host is up (0.00052s latency).
Not shown: 997 closed ports
PORT    STATE SERVICE
135/tcp open  msrpc
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds
MAC Address: 08:00:27:3C:9B:C3 (Cadmus Computer Systems)

Regards
skorpinok
24  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: SET Error on port 80 on: June 26, 2012, 10:17:25 AM
I would just grab a fresh copy of both and start there.

now i see that metasploit works on Spear-Phishing Attack Vectors,but not in java applet attack method..well said .. better if i would reinstall O.S itself...

25  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: SET Error on port 80 on: June 26, 2012, 10:03:03 AM
Yep, hell_razor is right. I was going off memory. Just checked and they did drop the 3. However, I thought SET threw an error when it used the wrong dir.

sorry bro.. i did what mr. razor told tried each one of them  /pentest/exploits/framework & /opt/metasploit/msf3, its out of luck, its same again, updated metasploit & SET too before this. well i'll try to reinstall Backtrack 5R2 O.S... guess this would work..

here is the brief info regarding my set_config..

DEFINE THE PATH TO METASPLOIT HERE, FOR EXAMPLE /pentest/exploits/framework3
METASPLOIT_PATH= /opt/metasploit/msf3

METASPLOIT_DATABASE=postgresql
 HOW MANY TIMES SET SHOULD ENCODE A PAYLOAD IF YOU ARE USING STANDARD METASPLO
ENCOUNT=4
AUTO_MIGRATE=OFF
BACKDOOR_EXECUTION=ON
METASPLOIT_IFRAME_PORT=8080
DSNIFF=OFF
AUTO_DETECT=OFF
SENDMAIL=ON
EMAIL_PROVIDER=GMAIL
WEBATTACK_EMAIL=ON
APACHE_SERVER=ON
SELF_SIGNED_APPLET=ON
WEBATTACK_SSL=OFF
OSX_REVERSE_PORT=8080
AUTOMATIC_LISTENER=ON
SET_SHELL_STAGER=OFF
METASPLOIT_MODE=ON

26  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: SET Error on port 80 on: June 25, 2012, 10:13:05 PM
Dont point it to the msfconsole binary, point it to the path. It should be

/pentest/exploits/framework3

ok i changed it to
/pentest/exploits/framework3

its same thing again msf just wont load at all..

here is the brief info.. i go to ...

  Website Attack Vectors -> Java Applet Attack Method--> Site Cloner
Are you using NAT/Port Forwarding [yes|no]: no

IP address for the reverse connection:192.168.56.101 (backtrack ip)


  • Cloning the website: http://www.gmail.com
  • This could take a little bit...
  • Injecting Java Applet attack into the newly cloned website.
  • Filename obfuscation complete. Payload name is: 84hPykFDDtYIJKx
  • Malicious java applet website prepped for deployment

What payload do you want to generate: Windows Reverse_TCP Meterpreter

Payload : Backdoored Executable (BEST)

set:payloads> PORT of the listener [443] ( i press enter default)

  • Generating x64-based powershell injection code...
  • Generating x86-based powershell injection code...
  • Finished generating shellcode powershell injection attack and is encoded to bypass execution restriction policys...
  • [-] Backdooring a legit executable to bypass Anti-Virus. Wait a few seconds...
  • Backdoor completed successfully. Payload is now hidden within a legit executable.
  • UPX Encoding is set to ON, attempting to pack the executable with UPX encoding.
  • [-] Packing the executable and obfuscating PE file randomly, one moment.
  • Digital Signature Stealing is ON, hijacking a legit digital certificate
  • Generating OSX payloads through Metasploit...
  • Generating Linux payloads through Metasploit...
  • Apache appears to be running, moving files into Apache's home

***************************************************
Web Server Launched. Welcome to the SET Web Attack.
***************************************************

[--] Tested on IE6, IE7, IE8, IE9, Safari, Opera, Chrome, and FireFox [--]
[--] Apache web server is currently in use for performance. [--]

  • Moving payload into cloned website.
  • The site has been moved. SET Web Server is now listening..
  • [-] Launching MSF Listener...
    [-] This may take a few to load MSF...

27  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: SET Error on port 80 on: June 25, 2012, 01:56:48 PM
I'm not sure I see where the error is. Double check the set_config that it is pointed to the correct msf directory.

Well in set_config previously was default /pentest/exploits/framework3, which i later changed to cd /opt/metasploit/msf3/ after this still same problem, then i located msfconsole through terminal

root@bt:~# locate msfconsole
/opt/metasploit/app/msfconsole
/opt/metasploit/apps/pro/msf3/msfconsole
/opt/metasploit/apps/pro/msf3/test/functional/framework/msfconsole_spec.rb
/opt/metasploit/msf3/msfconsole
/opt/metasploit/msf3/.svn/prop-base/msfconsole.svn-base
/opt/metasploit/msf3/.svn/text-base/msfconsole.svn-base
/opt/metasploit/msf3/documentation/msfconsole_rc_ruby_example.rc
/opt/metasploit/msf3/documentation/.svn/text-base/msfconsole_rc_ruby_example.rc.svn-base
/opt/metasploit/msf3/external/source/armitage/resources/msfconsole.style
/opt/metasploit/msf3/external/source/armitage/resources/.svn/text-base/msfconsole.style.svn-base
/opt/metasploit/msf3/test/functional/framework/msfconsole_spec.rb
/opt/metasploit/msf3/test/functional/framework/.svn/text-base/msfconsole_spec.rb.svn-base
/pentest/exploits/framework2/msfconsole
/pentest/exploits/framework2/docs/QUICKSTART.msfconsole
/usr/local/bin/msfconsole
/usr/share/applications/backtrack-metasploit-msfconsole.desktop

then once again i configure in SET DEFINE THE PATH TO METASPLOIT HERE, FOR EXAMPLE /pentest/exploits/framework3
METASPLOIT_PATH= /pentest/exploits/framework2/msfconsole.

still not working anymore, where could be the problem, i use Backtrack 5R2, metasploit v4.4.0-dev. any ideas ?
28  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: SET Error on port 80 on: June 25, 2012, 10:56:44 AM
Or, just configure SET to use apache in set_config:


# USE APACHE INSTEAD OF STANDARD PYTHON WEB SERVERS, THIS WILL INCREASE SPEED OF
# THE ATTACK VECTOR
APACHE_SERVER=ON


Thanks now it works without any problem, did exactly as you said, however , in the mean while iam faced with another problem, metasploit wont load in SET (waited for minutes )when i use java applet attack method,any idea what could be causing this ?

info...

--] Tested on IE6, IE7, IE8, IE9, Safari, Opera, Chrome, and FireFox [--]
[--] Apache web server is currently in use for performance. [--]

  • Moving payload into cloned website.
  • The site has been moved. SET Web Server is now listening..
  • [-] Launching MSF Listener...
    [-] This may take a few to load MSF...

    Press
[return] when finished.

Thank you
29  Ethical Hacking Discussions and Related Certifications / Social Engineering / Re: SET Error on port 80 on: June 24, 2012, 09:24:30 PM
If you're using Backtrack, you probably have apache set to start automatically, which is probably where the conflict is.

netstat -antp will tell you what the problem is.


I'm using backtrack 5r2, a netstat -antp reveals me this,

root@bt:~# netstat -antp

Active Internet connections (servers and established)

Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name

tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN      1127/apache2   

tcp        0      0 127.0.0.1:5432          0.0.0.0:*               LISTEN      786/postgres   

tcp6       0      0 ::1:5432                :::*                    LISTEN      786/postgres   

30  Ethical Hacking Discussions and Related Certifications / Social Engineering / SET Error on port 80 on: June 24, 2012, 02:15:07 PM
Hello
           When i run social engineering tool kit i get this error   :Something is running on port 80. Seeing if it's a stale SET process.
i used Java Applet Attack Method-Site - site cloner. i restarted SET & still the problem persists,please suggest me how to solve this ?

Thank you

set:payloads> PORT of the listener [443]:
  • Done, moving the payload into the action.
  • [-] Targetting of OSX/Linux (POSIX-based) as well. Prepping posix payload...
  • Stager turned off, prepping direct download payload...
  • Please note that the SETSHELL and RATTE are not compatible with the powershell injection technique. Disabling the powershell attack.
  • [!] ERROR:Something is running on port 80. Seeing if it's a stale SET process...
    [!] If you want to use Apache, edit the config/set_config
    [!] Exit whatever is listening and restart SET

Pages: 1 [2] 3
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.086 seconds with 21 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.