Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow EH-Netarrow Special Eventsarrow Q&A for Pen Testing Perfect Storm Webcast Series: Part I
EH-Net
May 25, 2013, 02:50:31 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3]   Go Down
  Print  
Author Topic: Q&A for Pen Testing Perfect Storm Webcast Series: Part I  (Read 43649 times)
0 Members and 1 Guest are viewing this topic.
KevinInGuardians
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #30 on: October 22, 2008, 10:46:15 AM »

Quote
Options to prevent the "BeEF" attack is preventing the use of a wireless network by an admin ?

Actually, the only prevention of BEeF attacks is to fix the XSS vulnerabilities within applications.
Logged
KevinInGuardians
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #31 on: October 22, 2008, 10:48:11 AM »

Quote
What tools can be used to automate SQL injection attacks?

There are a number tools for SQL injection. 

SQLMap and Absinthe come to mind immediately.
SQLMap is available from http://sqlmap.sourceforge.net
Absinthe is available from http://www.0x90.org


I personally recommend w3af as it includes SQLMap and many other tools for web testing.
W3af is available from http://w3af.sourceforge.net
Logged
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #32 on: October 22, 2008, 12:50:33 PM »

Sorry I got here late, I'm about to watch it but I need the real player, so I headed over to get it at www.real.com/ downloaded it, uploaded it to virus total and got:
http://www.virustotal.com/analisis/78991ac2576070f4b3181865d202aa05
False Result? What you guys think?
Logged

eCPPT, GCIH, OSCP, OSWP
geekyone
Full Member
***
Offline Offline

Posts: 180



View Profile
« Reply #33 on: October 22, 2008, 07:00:40 PM »

I would guess false positive but wouldn't guarantee that.  Cheesy  On a kinda unrelated question is there a reason virustotal misspells analysis as analisis?  Or is that a correct British spelling and I am being a stupid American?
Logged

CISSP, CEH, GPEN, GCIH, GCFA
LSOChris
Guest
« Reply #34 on: October 23, 2008, 02:12:56 PM »

1/36, so its either a really good piece of malware or a false positive.  or maybe a real result considering the installer probably calls home or to the net to grab updates.

if you are really paranoid run in a VM with a sniffer and see what it does.

Logged
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #35 on: October 23, 2008, 06:33:02 PM »

Got ya, just I've seen safer files. Thanks.
Logged

eCPPT, GCIH, OSCP, OSWP
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #36 on: October 29, 2008, 11:18:28 PM »

Could we also leverage karmasploit for this type of attack to push clientside exploits, own the admin laptop, and then dump the password hashes, crack them, then use them to access other machines or the protected wireless internal network?

If that is functionally equivalent, which one of these attacks is better for a pentest? which one would be faster?

and on a side note, when is Jay going to release the middler? Wink

Thanks Inguardians crew!
Logged

rlallen
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #37 on: April 01, 2009, 09:47:21 AM »

Does anyone happen to have the full webcast (.arf file) posted somewhere? Core and SANS seem to have removed it.
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #38 on: April 15, 2009, 04:43:46 PM »

Sorry to resurrect an old topic, but has anyone gotten the AirCSRF, “Air-Sea-Surf” tool that this webcast mentioned?   I had on my list to follow up and I still can't find it.  Any word on its release?

Logged

~~~~~~~~~~~~~~
Ketchup
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #39 on: April 16, 2009, 09:00:38 PM »

Sorry to resurrect an old topic, but has anyone gotten the AirCSRF, “Air-Sea-Surf” tool that this webcast mentioned?   I had on my list to follow up and I still can't find it.  Any word on its release?

I still don't think it is available
Logged

twitter.com/timmedin | http://blog.securitywhole.com
Pages: 1 2 [3]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.