Automated Persistence with .RC scripts
A while back I did a post about persistent meterpreter. This was a way to make the system continually attempt a reverse connection back to the Metasploit multi/handler listener. Well recently I was on...
View ArticleLouisville InfoSec CTF Event – 2nd Place
Image from http://www.louisvilleinfosec.com On October 8th, I attended the 7th Annual Louisville InfoSec Conference @ Churchill Downs in Louisville, KY. During the conference I participated in the 1st...
View ArticleBrowser Exploitation with Metasploit and Ettercap
This is my first video tutorial so be kind. The purpose of this video tutorial is to demonstrate browser exploitation during pentesting. The use of Ettercap helps us to force the user to our attack...
View ArticleSSID customized rainbow tables
The people over at Offensive Security have put out a collection of rainbow tables for cowpatty that are SSID specific. http://www.offensive-security.com/wpa-tables/
View ArticleBlind SQL injection of POST vars with sqlmap
There are many How-To’s on SQL injection, but I thought I would add to the list with a quick tutorial on how to use SQLmap to automate blind SQLinjection on form POST variables. Most of the tutorials...
View ArticleNetcat is back
There is a very good white paper called Taking Back Netcat that has been circulating the blogs about how to use Ollydbg to modify the nc.exe binary in order to evade virus detection. I won’t go into...
View ArticlePersistent Backdoor w/ VBS & Meterpreter
It is not usually common that a pentester needs persistent access to a target. However, cases do arise when it becomes necessary. For instance, the target service could be unreliable or only running at...
View Article