Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 62 guests and 5 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow EH-Netarrow Special Eventsarrow Q&A for Pen Testing Perfect Storm Webcast Series: Part I
EH-Net
February 09, 2012, 07:59:41 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3]   Go Down
  Print  
Author Topic: Q&A for Pen Testing Perfect Storm Webcast Series: Part I  (Read 36893 times)
0 Members and 1 Guest are viewing this topic.
KevinInGuardians
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #30 on: October 22, 2008, 10:46:15 AM »

Quote
Options to prevent the "BeEF" attack is preventing the use of a wireless network by an admin ?

Actually, the only prevention of BEeF attacks is to fix the XSS vulnerabilities within applications.
Logged
KevinInGuardians
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #31 on: October 22, 2008, 10:48:11 AM »

Quote
What tools can be used to automate SQL injection attacks?

There are a number tools for SQL injection. 

SQLMap and Absinthe come to mind immediately.
SQLMap is available from http://sqlmap.sourceforge.net
Absinthe is available from http://www.0x90.org


I personally recommend w3af as it includes SQLMap and many other tools for web testing.
W3af is available from http://w3af.sourceforge.net
Logged
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #32 on: October 22, 2008, 12:50:33 PM »

Sorry I got here late, I'm about to watch it but I need the real player, so I headed over to get it at www.real.com/ downloaded it, uploaded it to virus total and got:
http://www.virustotal.com/analisis/78991ac2576070f4b3181865d202aa05
False Result? What you guys think?
Logged

OSCP, OWSP, eCPPT
geekyone
Full Member
***
Offline Offline

Posts: 175



View Profile
« Reply #33 on: October 22, 2008, 07:00:40 PM »

I would guess false positive but wouldn't guarantee that.  Cheesy  On a kinda unrelated question is there a reason virustotal misspells analysis as analisis?  Or is that a correct British spelling and I am being a stupid American?
Logged

CISSP, CEH, GPEN, GCIH, GCFA
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1166


View Profile WWW
« Reply #34 on: October 23, 2008, 02:12:56 PM »

1/36, so its either a really good piece of malware or a false positive.  or maybe a real result considering the installer probably calls home or to the net to grab updates.

if you are really paranoid run in a VM with a sniffer and see what it does.

Logged

...tests i took go here...

http://carnal0wnage.attackresearch.com/
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #35 on: October 23, 2008, 06:33:02 PM »

Got ya, just I've seen safer files. Thanks.
Logged

OSCP, OWSP, eCPPT
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #36 on: October 29, 2008, 11:18:28 PM »

Could we also leverage karmasploit for this type of attack to push clientside exploits, own the admin laptop, and then dump the password hashes, crack them, then use them to access other machines or the protected wireless internal network?

If that is functionally equivalent, which one of these attacks is better for a pentest? which one would be faster?

and on a side note, when is Jay going to release the middler? Wink

Thanks Inguardians crew!
Logged

rlallen
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #37 on: April 01, 2009, 09:47:21 AM »

Does anyone happen to have the full webcast (.arf file) posted somewhere? Core and SANS seem to have removed it.
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #38 on: April 15, 2009, 04:43:46 PM »

Sorry to resurrect an old topic, but has anyone gotten the AirCSRF, “Air-Sea-Surf” tool that this webcast mentioned?   I had on my list to follow up and I still can't find it.  Any word on its release?

Logged

~~~~~~~~~~~~~~
Ketchup
timmedin
Sr. Member
****
Offline Offline

Posts: 470



View Profile WWW
« Reply #39 on: April 16, 2009, 09:00:38 PM »

Sorry to resurrect an old topic, but has anyone gotten the AirCSRF, “Air-Sea-Surf” tool that this webcast mentioned?   I had on my list to follow up and I still can't find it.  Any word on its release?

I still don't think it is available
Logged

twitter.com/timmedin | http://blog.securitywhole.com
Pages: 1 2 [3]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.105 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.