EH-Net
May 24, 2013, 10:13:34 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3]   Go Down
  Print  
Author Topic: Q&A for Pen Testing Perfect Storm Webcast Series: Part I  (Read 43638 times)
0 Members and 1 Guest are viewing this topic.
KevinInGuardians
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #30 on: October 22, 2008, 10:46:15 AM »

Quote
Options to prevent the "BeEF" attack is preventing the use of a wireless network by an admin ?

Actually, the only prevention of BEeF attacks is to fix the XSS vulnerabilities within applications.
Logged
KevinInGuardians
Newbie
*
Offline Offline

Posts: 15


View Profile
« Reply #31 on: October 22, 2008, 10:48:11 AM »

Quote
What tools can be used to automate SQL injection attacks?

There are a number tools for SQL injection. 

SQLMap and Absinthe come to mind immediately.
SQLMap is available from http://sqlmap.sourceforge.net
Absinthe is available from http://www.0x90.org


I personally recommend w3af as it includes SQLMap and many other tools for web testing.
W3af is available from http://w3af.sourceforge.net
Logged
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #32 on: October 22, 2008, 12:50:33 PM »

Sorry I got here late, I'm about to watch it but I need the real player, so I headed over to get it at www.real.com/ downloaded it, uploaded it to virus total and got:
http://www.virustotal.com/analisis/78991ac2576070f4b3181865d202aa05
False Result? What you guys think?
Logged

eCPPT, GCIH, OSCP, OSWP
geekyone
Full Member
***
Offline Offline

Posts: 180



View Profile
« Reply #33 on: October 22, 2008, 07:00:40 PM »

I would guess false positive but wouldn't guarantee that.  Cheesy  On a kinda unrelated question is there a reason virustotal misspells analysis as analisis?  Or is that a correct British spelling and I am being a stupid American?
Logged

CISSP, CEH, GPEN, GCIH, GCFA
LSOChris
Guest
« Reply #34 on: October 23, 2008, 02:12:56 PM »

1/36, so its either a really good piece of malware or a false positive.  or maybe a real result considering the installer probably calls home or to the net to grab updates.

if you are really paranoid run in a VM with a sniffer and see what it does.

Logged
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #35 on: October 23, 2008, 06:33:02 PM »

Got ya, just I've seen safer files. Thanks.
Logged

eCPPT, GCIH, OSCP, OSWP
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #36 on: October 29, 2008, 11:18:28 PM »

Could we also leverage karmasploit for this type of attack to push clientside exploits, own the admin laptop, and then dump the password hashes, crack them, then use them to access other machines or the protected wireless internal network?

If that is functionally equivalent, which one of these attacks is better for a pentest? which one would be faster?

and on a side note, when is Jay going to release the middler? Wink

Thanks Inguardians crew!
Logged

rlallen
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #37 on: April 01, 2009, 09:47:21 AM »

Does anyone happen to have the full webcast (.arf file) posted somewhere? Core and SANS seem to have removed it.
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #38 on: April 15, 2009, 04:43:46 PM »

Sorry to resurrect an old topic, but has anyone gotten the AirCSRF, “Air-Sea-Surf” tool that this webcast mentioned?   I had on my list to follow up and I still can't find it.  Any word on its release?

Logged

~~~~~~~~~~~~~~
Ketchup
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #39 on: April 16, 2009, 09:00:38 PM »

Sorry to resurrect an old topic, but has anyone gotten the AirCSRF, “Air-Sea-Surf” tool that this webcast mentioned?   I had on my list to follow up and I still can't find it.  Any word on its release?

I still don't think it is available
Logged

twitter.com/timmedin | http://blog.securitywhole.com
Pages: 1 2 [3]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.106 seconds with 20 queries.