|
EH-Net
|
|
May 24, 2013, 02:58:03 AM
|
Show Posts
|
|
Pages: 1 ... 3 4 [5] 6 7 ... 25
|
|
63
|
Resources / Tools / Re: DVWA v1.0.5
|
on: September 03, 2009, 03:05:10 PM
|
|
Hey! thanks for your speedy response. I will download the official version and hopefully in the future websecurify will work against dvwa.
Keep up the good work. DVWA is a nice piece of work. Thanks again.
|
|
|
|
|
65
|
Resources / Tools / WEBSECURIFY
|
on: September 03, 2009, 02:08:31 PM
|
Websecurify is a web and web2.0 security initiative specializing in researching security issues and building the next generation of tools to defeat and protect web technologies. A new web app security tool created by the people at gnucitizen.com. Check it out: websecurify 0.3
|
|
|
|
|
66
|
Resources / Tools / Re: DVWA v1.0.5
|
on: September 03, 2009, 01:53:25 PM
|
Downloaded for the purpose to test websecurify. It looks nice and instrumental in learning web application security. I'm not sure if the XSS reflected section was or was not intentionally left out since I know you are still working on this version but just in case I wanted to let you know. And another thing, I saw it some where on the web that you have tested websecurify and I wanted to know if you used it against dvwa. I tried it but it appears that this tool needs to authenticate to dvwa to fully test it. There's no way to add login information to websecurify unless its possible to add it to the URL. Any tips you can provide? Thanks.
|
|
|
|
|
73
|
Ethical Hacking Discussions and Related Certifications / Forensics / Re: AIM attachments, NetWitness question
|
on: August 23, 2009, 06:42:09 PM
|
|
There's nothing wrong searching the magic number via Google. This is exactly what I did.
I was able to reconstruct the docx using wireshark and a Hex editor. My md5 hash matches with the one posted in SANS commentaries. The tool tcpxtract help me a lot because I was able to extract the recipe contents and made me realize that the files extracted were zipped XML. This enticed me to research on the docx office 2007 format and such.
It was a cool challenge, to bad that someone posted his answers to SANs. Overall a good learning experience.
Oh yeah, in tcpxtract there's a config file where you can add new signatures. I don't know if docx is included, got to check that out. If not, I'm going to try to create a signature and add it to the config file to see if it works.
|
|
|
|
|
Loading...
|