Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 185 guests and 3 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow From EXPLOIT to Advisory
EH-Net
May 23, 2013, 09:40:53 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: From EXPLOIT to Advisory  (Read 6348 times)
0 Members and 1 Guest are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« on: August 19, 2010, 01:17:59 PM »

(I had to on the subject... couldn't help it)

I don't want to re-type something I typed already Sad swamped between work + lab + play + home + etc. So copy and paste Wink


Quote
There I was minding my business listening to Frontline Assembly's Machine Slave while attacking one vendor's product via packetfuzzing when in return I stumbled upon a vulnerability for another vendor. Not a big deal, the same thing happened while fiddling around and tripping up a nasty Wireshark bug earlier this year.

What interested me the most was, the collateral damage from the tool. What a wicked little tool on my hands. Imagine running a DoS attack inside of a virtualized server and making that DoS attack disconnect EVERY single machine on the virtualized server. Doesn't seem to matter who the target is or the source address being spoofed. After about 2 minutes, the entire VMWare stack is hosed. Hosed as in, there is nothing you can do to reset the virtualized host. Restart the virtualized machine? No workie workie. Restart VMWare as a service? No workie workie. All of the virtualized machines in the server are hosed, sayanora; "you are the weakest link goodbye."

Solution? Reboot the entire server. Unsure of a public release of the tool.

(humor http://www.youtube.com/watch?v=Qm2BpI6TCDE)

Possible attack uses:

    * Insider attack on a rogue nation state's cloud infrastructure.
    * Parallel(slash)Escalation based attack where reboot is needed. (surely non working VM servers'll do that)
    * Being a script kiddiot
    * Being an "Advanced Persistent Script Kiddiot"
    * INSERT_YOUR_OWN_ATTACK_HERE

With all this said, I now present a demo on mushroom cloud in high def (1280x720). X-lation full screen viewing is best

http://www.infiltrated.net/mushroomcloud/mushroomdemo/

Step 1) Exploit
Step 2) Lallygag and debate to disclose or ZDI the thing...
Logged

sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #1 on: August 20, 2010, 11:37:18 AM »

Mushroom Cloud - The Morning After ...
http://www.infiltrated.net/mushroomcloud/morningafter/

In attempts to videoexplain what is going on... I launched mushroomcloud against itself ... Same results
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #2 on: August 20, 2010, 12:40:02 PM »

I'm gonna have to set this up, and see it for myself.  Amazingly simple...

Edit:  sil, offline, can you send my way?
« Last Edit: August 20, 2010, 12:47:54 PM by hayabusa » Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.