Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 57 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 22, 2013, 09:06:06 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / Control Systems / Re: Video: Hacking Industrial Control & Building Automation on: January 07, 2013, 11:31:09 AM
At present we now have an integrated architecture where Industrial Control Systems are no longer isolated from traditional networking equipment. In fact, a quick search using the SHODAN search engine will reveal thousands of NiagaraAX devices accessible over the Internet. A weakness within this system could allow an attacker access to critical environmental controls.

This revelation motivated him to do a little ‘vulnerability research’ on the NiagaraAX Framework. To share his findings, he decided to create a short VIDEO CLIP illustrating how an attacker can leverage multiple weaknesses to hack into a buildings’ automation system.

sskblog.com/?p=926
2  Ethical Hacking Discussions and Related Certifications / Control Systems / Video: Hacking Industrial Control & Building Automation on: December 26, 2012, 11:22:22 AM
QJax has shared a great hacking video showing Tridium NiagaraAX Industrial Control and Building Automation at Risk! http://vimeo.com/56069427.

Do you think these videos help raise awareness to a known security issue?

Follow him on Twitter @SSKblog
3  Ethical Hacking Discussions and Related Certifications / Malware / RunForestRun web tool to predict malicious domains on: July 22, 2012, 09:44:02 AM
This blog post discusses the RunForestRun hack.  The tool is code that will allow you to predict the pseudo random malicious domains generated by the obfuscated script uploaded to compromised websites.

Vulnerable websites are being exploited first via the Plesk Panel vulnerability.  After a victim visits a compromised website, they will also be redirected to a malicious site and the Blackhole Exploit Kit will attempt to exploit the unsuspecting victim.

The goal of the tool is to generate the domains ahead of time and then setup URL web filters to block access.

Read the Post and enjoy the tool! http://sskblog.com/?p=771
4  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: XSS Attack - Busting Browsers to Root! on: July 23, 2011, 08:48:48 PM
ding! ding! ding! and Maxe the cyborg takes the lead!

#2 - Patch Management (Staying updated and patched from known vulnerabilities.)

Updating to the latest browser versions like IE8 has a built-in XSS filter.  It was disabled for the video.

#3 - Enforced Proxy (Filters malicious data, similar to an IPS system somewhat.)
Use the proxy to block outbound access to a known "Evil_IP" or Egress Filtering? So technically your proxy server answer should do the trick.

5  Ethical Hacking Discussions and Related Certifications / Web Applications / XSS Attack - Busting Browsers to Root! on: July 23, 2011, 08:22:08 AM
This video will demonstrate how a simple XSS vulnerability can be leveraged to gain complete control of your web-browser and eventually lead to a complete system compromise.

1) We will use a cross-site scripting vulnerability as the initial attack vector
2) Exploit XSS by redirecting the user’s browser to the Evil_IP with a JavaScript loop (every 2 secs)
3) Exploit the victim’s browser to gain system ‘root’ or ‘shell’ access
4) Elevate our privileges to system-level

QUIZ: There is at least 6 security controls that could prevent several steps in the video including vulnerabilities or user errors.  Can you spot them all? 

FREEBIE: DVWA web server & IE8 browser security settings allow unencrypted XSS attack string to be sent during an SSL session.  "Submit non-encrypted form data- ENABLED"
What else? Huh

http://vimeo.com/26751019

6  EH-Net / News Items and General Discussion About EH-Net / Pass Policy, Over Regulation, Through Vulnerabilities, Nothing but NET! on: February 24, 2011, 08:00:52 PM
Pass Policy, Over Regulation, Through Vulnerabilities, Nothing but NET!

“use complex password / frequently change”

“patch that so-called critical system” – maybe that’s why it keeps crashing FOOL!

“don’t use the same password for your personal twitter account that you use for your company Admin access” – DUMMY!

“Stop browsing the Internet from your server, especially since you are so afraid to update your IE browser to the latest version” – Mr. Fandango Movie Surfer!

“It doesn’t matter if you passed your Audit” – ASK HACKERS IF THEY GIVE A F@#$!

“Stop! Don’t spend any more money until you fix the problem from 3 years ago, which can be done with the Interns you already have…” – FOR FREE!

“Why don’t you just pay us more money so we can feel better about not caring” – OOPS SORRY THAT SLIPPED


UPDATED LINK FOR THOSE PARANOID HACKERS
http://securitystreetknowledge.com/?p=557
7  Ethical Hacking Discussions and Related Certifications / Web Applications / Add XSSF into Metasploit Framework on Ubuntu on: January 28, 2011, 02:15:14 PM
This is a tutorial to help you get the Cross-site Scripting Framework (XSSF) installed into MetaSploit on an Ubuntu distro.  These are excellent notes to help you get around those annoying errors like MySQL not started, incorrect version of Ruby, where to find the XSSF.zip  I hope this saves someone a few CPU cycles. 

If you have not heard of XSSF then do a GTS (Google That $hit!)

http://bit.ly/hNYgI3
8  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hacking using tor? on: January 22, 2011, 08:08:34 AM
Sorry but I do not know of a Windows solution yet.  I will let you know when I come across one.

I must warn you that even if you use SSL through Tor it can be stripped off.  So if you are hacking i wouldn't be so worried about a bad guy seeing your traffic but rather big brother.  If you look at some of the fastest ExitNodes they tend to be located in areas near state-owned cyber defense establishments.(Do a GeoIP on the ExitNode IP address)  If you read a lot of blogs you will hear authors say how they capture this or that attack in the wild.  Then they get credit for the exploit.  It is my guess they are monitoring their own Tor ExitNode.
9  EH-Net / News Items and General Discussion About EH-Net / Another EH blog on: January 21, 2011, 02:08:39 PM
I like this site very much. It has a very good list of daily RSS feeds and video selections.

http://securitystreetknowledge.com/
10  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hacking using tor? on: January 21, 2011, 02:01:01 PM
In certain circumstances I would use Tor for an authorized PenTest.  If anything use it to test how effective the administrators are with reviewing logs and finding offending IPs. 

Anyway, look at this recent post that will walk you through setting up your box to use Tor for a Pentesting.

http://securitystreetknowledge.com/?p=283

Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.077 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.