Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 44 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Non-Framework Exploits in Professional Tests?
EH-Net
May 21, 2013, 11:57:24 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Non-Framework Exploits in Professional Tests?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Non-Framework Exploits in Professional Tests? (Read 5786 times)
0 Members and 1 Guest are viewing this topic.
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Non-Framework Exploits in Professional Tests?
«
on:
August 11, 2010, 07:42:29 PM »
I'm just curious how often anyone else uses stand-alone exploits from sources such as Exploit DB in professional tests. I think I've only done so once.
If so, do you expect to have internet (unfiltered) access while on site?
Do you maintain an archive that you bring with you?
Or do you primarily stick to Metasploit, Canvas, Core Impact, etc.?
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Ketchup
Hero Member
Offline
Posts: 1021
Re: Non-Framework Exploits in Professional Tests?
«
Reply #1 on:
August 11, 2010, 09:01:43 PM »
I use non-framework exploits. I use any exploit I can reasonably verify won't do too much damage. The way I look at it is the bad guys will use anything available to them.
I usually have an archive or two on my laptop, but they are almost always too outdated. I just forget to update them. What I usually do is maintain an SSH account on a standard port and some odd port. Part of pen testing is to see what egress filtering and content filtering is present on the network. If I can't get to a site like exploit-db.com, I use my SSH account to proxy out. This is actually another good test to see what outbound services are permitted.
Just my thoughts.
Logged
~~~~~~~~~~~~~~
Ketchup
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Non-Framework Exploits in Professional Tests?
«
Reply #2 on:
August 11, 2010, 11:23:56 PM »
Thanks for the response. I do the same thing
I have an OpenBSD VPS ($10/mo with ARP Networks - They ROCK), and I have SSH listening on 443, amongst others. It's pretty nasty as I only get stopped if they're doing application-level inspection or are a deny-all shop and are only allowing specific IPs/URLs.
I used to do port-redirection to TinyProxy until I found out about the ssh -D option. That's been working out great. It's nice for keeping away from eavesdroppers on Hilton's network too.
If all else fails, I can often just get back online once I return to the hotel and prepare for the next day. It'd be nice if work would spring for some sort of air card though.
I think the issue I run into is simply a lack of time. Like this week, I had to perform social engineering, a security assessment with physical inspection, and a pen test in three days. I'm not even going to be able to get all the low-hanging fruit on this one, let alone go after anything more obscure.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Ketchup
Hero Member
Offline
Posts: 1021
Re: Non-Framework Exploits in Professional Tests?
«
Reply #3 on:
August 12, 2010, 01:37:28 PM »
I hear you! Budget and time constraints are probably one of the biggest challenges. Three days isn't much time.
Logged
~~~~~~~~~~~~~~
Ketchup
sil
Hero Member
Offline
Posts: 549
Re: Non-Framework Exploits in Professional Tests?
«
Reply #4 on:
August 12, 2010, 03:10:07 PM »
Quote from: dynamik on August 11, 2010, 11:23:56 PM
Thanks for the response. I do the same thing
If all else fails, I can often just get back online once I return to the hotel and prepare for the next day. It'd be nice if work would spring for some sort of air card though.
Shame on you!...
mkdir /usr/work/exploits/{linux,bsd,solaris,windows}
mkdir /usr/work/exploits/bsd/{open,net,free}
mkdir /usr/worl/exploits/windows/{xp,vista,nt,9x,2003,2008}
I have a large repository of stuff not found on typical sites (exploit-db, packetstorm, etc) stored in both compiled and uncompiled modes for both x86 and 64bits under as many operating systems as it's portable to get it running on. I try to find as much exploit code as I can and further divide it into remote/local folder inside the operating system folders. It's a pain but definitely handy in tight situations.
Just make sure you hit
It pays to put together a sandbox of most operating systems to test against, I have most operating systems with the exception of things like z/OS, Tru64 and a few others. Each sandbox (VMWare by the way) has a snapshot so I can download w/e I want, unhook the sandbox from network to avoid it cooking my network/malware(reversed)exploits, run it, fix it if need be, then throw it into the tool kit if it accomplishes what I need.
PITA it is, but it will save you time in the long run. When you need them, plop them on a USB key... Re-writeable DVD/CD and instamagic access
Who cares if you have no connectivity to download. The downside is sorting them out and trying to fix toasty sploits (ones that don't work for those unaccustomed to slang).
http://www.0xdeadbeef.info/
(Solaris stuff rocks)
http://inj3ct0r.com/
(wanna be milw0rm)
http://rawlab.mindcreations.com/#exploit
http://www.exploit-db.com/
http://triviasecurity.net/exploits
Best bet to find hardcore PoC's and exploits, follow the coder or mesh another coder's work into your own. Why reinvent wheels
Prematurely hit the save button...
Just make sure you hit "Take Snapshot" ALL the time
I've learned this the hard way.
«
Last Edit: August 12, 2010, 03:12:37 PM by sil
»
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Non-Framework Exploits in Professional Tests?
«
Reply #5 on:
August 12, 2010, 03:30:08 PM »
So you're an exploit whore with OCD?
I figured that was the route I was going to have to go. I was just wondering if there was an easier way to acquire and manage everything since that is a major PITA.
I <3 snapshots. I'm a VMware junkie, without a doubt!
I appreciate the response. Also, ISACA *said* they will be email results out today or tomorrow.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
hayabusa
Hero Member
Offline
Posts: 1631
Re: Non-Framework Exploits in Professional Tests?
«
Reply #6 on:
August 12, 2010, 03:36:06 PM »
Kind of have to hit the main sites, and download to your heart's content, dynamik, archiving those sploits for rainy days. I do the same, as time and resources permit. Saves a whole lot of time and energy, in the end. Make sure you understand what you're playing with, anytime you're using someone else's sploits from a site you're not used to, however, as I've seen a few people do serious damage because of malware, fronted as a sploit. I've been called in after the fact, on quite a few occasions, to explain what someone (not working with me) had done to hork up someone's servers... Nothing like knowing the competition isn't on the ball, though!
It's just like having rainbow tables for windows password security, etc. The more you have, even when you don't need them immediately, the better off you'll be, when you DO need them.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Ketchup
Hero Member
Offline
Posts: 1021
Re: Non-Framework Exploits in Professional Tests?
«
Reply #7 on:
August 13, 2010, 01:31:17 PM »
Quote from: sil on August 12, 2010, 03:10:07 PM
Shame on you!...
mkdir /usr/work/exploits/{linux,bsd,solaris,windows}
mkdir /usr/work/exploits/bsd/{open,net,free}
mkdir /usr/worl/exploits/windows/{xp,vista,nt,9x,2003,2008}
You are absolutely correct. I need more up to date archives. I am going to try to make this a project. I can't tell you how many times I have searched long and hard for some exploit code for a weird service. Next time I needed to use the same exploit, I ended up searching again.
Logged
~~~~~~~~~~~~~~
Ketchup
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Non-Framework Exploits in Professional Tests?
«
Reply #8 on:
August 16, 2010, 03:18:15 PM »
I just noticed that Exploit DB provides an Archive. That simplifies things a bit. I really should pay more attention to navigational menus...
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Non-Framework Exploits in Professional Tests?
«
Reply #9 on:
August 16, 2010, 03:46:12 PM »
If I'm not mistaken, the archive gets updated with an 'apt-get upgrade' in BT4. You'll also notice a nifty little script to search through your local copy of the archive in /pentest/exploits/exploitdb.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: De-ICE 1.140 released!
(0) by
Grendel
Programming
: Finished Python Course in Codecademy now what?
(12) by
3xban
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.