Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 81 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow From EXPLOIT to Advisory
EH-Net
May 25, 2012, 11:15:57 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: From EXPLOIT to Advisory  (Read 5308 times)
0 Members and 2 Guests are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 536



View Profile WWW
« on: August 19, 2010, 01:17:59 PM »

(I had to on the subject... couldn't help it)

I don't want to re-type something I typed already Sad swamped between work + lab + play + home + etc. So copy and paste Wink


Quote
There I was minding my business listening to Frontline Assembly's Machine Slave while attacking one vendor's product via packetfuzzing when in return I stumbled upon a vulnerability for another vendor. Not a big deal, the same thing happened while fiddling around and tripping up a nasty Wireshark bug earlier this year.

What interested me the most was, the collateral damage from the tool. What a wicked little tool on my hands. Imagine running a DoS attack inside of a virtualized server and making that DoS attack disconnect EVERY single machine on the virtualized server. Doesn't seem to matter who the target is or the source address being spoofed. After about 2 minutes, the entire VMWare stack is hosed. Hosed as in, there is nothing you can do to reset the virtualized host. Restart the virtualized machine? No workie workie. Restart VMWare as a service? No workie workie. All of the virtualized machines in the server are hosed, sayanora; "you are the weakest link goodbye."

Solution? Reboot the entire server. Unsure of a public release of the tool.

(humor http://www.youtube.com/watch?v=Qm2BpI6TCDE)

Possible attack uses:

    * Insider attack on a rogue nation state's cloud infrastructure.
    * Parallel(slash)Escalation based attack where reboot is needed. (surely non working VM servers'll do that)
    * Being a script kiddiot
    * Being an "Advanced Persistent Script Kiddiot"
    * INSERT_YOUR_OWN_ATTACK_HERE

With all this said, I now present a demo on mushroom cloud in high def (1280x720). X-lation full screen viewing is best

http://www.infiltrated.net/mushroomcloud/mushroomdemo/

Step 1) Exploit
Step 2) Lallygag and debate to disclose or ZDI the thing...
Logged

sil
Hero Member
*****
Offline Offline

Posts: 536



View Profile WWW
« Reply #1 on: August 20, 2010, 11:37:18 AM »

Mushroom Cloud - The Morning After ...
http://www.infiltrated.net/mushroomcloud/morningafter/

In attempts to videoexplain what is going on... I launched mushroomcloud against itself ... Same results
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #2 on: August 20, 2010, 12:40:02 PM »

I'm gonna have to set this up, and see it for myself.  Amazingly simple...

Edit:  sil, offline, can you send my way?
« Last Edit: August 20, 2010, 12:47:54 PM by hayabusa » Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.