文章列表
 
您正在查看 "网络渗透技术" 分类下的文章

2012-02-28 13:42

What is this post?

Today we present a free plugin, developed by me, so you can use thesqlmap from BurpSuite so really comfortable.

Why this plugin?

Almost always we audit a website the first thing we usually do is put an intermediate proxy to have more control over what we send to it. For some reasons I use as a proxy BurpSuite.

 
2011-11-28 10:25

Wireshark can export SMB objects.
This feature is inplemented in Wireshark in version 1.6.0.

You can download the latest stable release of Wireshark

 
2011-06-24 17:20

 

https://h4cker.cn/pentest/82.html

 
2011-06-09 11:52

While on a penetration test it is sometimes necessary to pull hash files from windows systems to crack weak passwords.  You could easily do this with a Metasploit meterpreter session, but sometimes I like to do it without exploiting the box.  Also doing it remotely over the network without a user’s knowledge is always a big plus.  This method isn’t always usable and available, but in the right situation we can use an NMAP script called pw-dump.nse to do this.

 
2011-03-15 14:07

http://www.youtube.com/watch?v=AdIWl0gkynk&feature=player_detailpage

大家可以站在墙头观摩... 顺便注意下最后一秒!

 
2011-01-06 15:47

      HTTP(HyperTextTransferProtocol)是超文本传输协议的缩写,它用于传送WWW方式的数据,关于HTTP协议的详细内容请参考RFC2616。HTTP协议采用了请求/响应模型。客户端向服务器发送一个请求,请求头包含请求的方法、URI、协议版本、以及包含请求修饰符、客户信息和内容的类似于MIME的消息结构。服务器以一个状态行作为响应,相应的内容包括消息协议的版本,成功或者错误编码加上包含服务器信息、实体元信息以及可能的实体内容。
  通常HTTP消息包括客户机向服务器的请求消息和服务器向客户机的响应消息

 
2010-12-21 12:35
DOM Hacking was presented at BlackHat and going to present at next HackInTheBox. Here is the paper and Tools (DOMScan and DOMTracer). It helps during scanning, assessments and pen-testing. Enjoy!

Paper on DOM Hacking

Download
PDF document from here [BlackHat site]

Presentation slides from here

 
2010-12-21 10:47

Oftentimes during a penetration test engagement, a bit of finesse goes a long way. One of the most effective ways to capture the clear-text user password from a compromised Windows machine is through the "keylogrecorder" Meterpreter script. This script can migrate into the winlogon.exe process, start capturing keystrokes, and then lock the user's desktop (the -k option). When the user enters their password to unlock their desktop, you now have their password. This, while funny and

 
2010-12-21 10:45

This was one of the newer topics that I covered at BlackHat Abu Dhabi. HTML5 has two APIs for making cross domain calls - Cross Origin Requests and WebSockets. By using them JavaScript can make connections to any IP and to any port(apart from blocked ports), making them ideal candidates for port scanning.


 
2010-08-17 11:14

Metasploit 3.4.2 on the iPhone 4

Just a quick update on getting your favorite tools on iOS 4 – Metasploit and SET. You need to have a Jailbroken iPhone with SSH access for this. You will also need to install nano and APT 0.7 Strict via Cydia. Getting everything up and ru

 
2010-07-26 15:17

WebEnum is a tool to enumerate http responses to dynamically generated queries.

It is a flexible universal tool useful to perform penetration testing to web servers. It is useful to

  • Bruteforce web accounts and passwords
  • Discovery directories, files and users with ~user Apache method
  • Guess table names and columns size in SQL injection
  • Fuzz HTTP requests i
 
2010-04-22 14:03

/index.php?app=../../../../../../../../etc/passwd%00.

http://shop.guoqishequ.com/index.php?app=../../../../../../../../etc/passwd%00.

 
2009-12-25 17:20
 
2009-07-29 2:40

作者:zwell

reDuh最开始是由SensePost在BlackHat USA 2008会议上发表的一个议题中的一部分。它的出现是针对当前Web安全渗透测试经常会面临的一个问题,同时也是Web服务器加固方面一个很重要的部分, 那就是Web服务器对外只开放一个80端口。Web服务器的安全防护可以是操作系统的端口定制或者是网管防火前的端口定制。这时渗透测试人员如果想进一步 测试内网的话必须先拿下目标服务器并拥有一定的控制权限。

 
2009-07-19 1:46

开源网络安全扫描工具Nmap正式发布了5.00版,这是自1997年以来最重要的发布,代表着Nmap从简单的网络连接端扫描软件变身为全方面的安全和网络工具组件。

Nmap于1997年9月推出,支持Linux、Windows、Solaris、BSD、Mac OS X、AmigaOS系统,采用GPL许可证,最初用于扫描开放的网络连接端,确定哪服务运行在那些连接端,它是评估网络系统安全的重要软件,也是黑客常用的工具之一。新的Nmap 5.00版大幅改进了性能,增加了

 
   
 
 
文章分类
 
   
 
文章存档
 
     
 
最新文章评论
  

>-<~ 表示放出来都不会玩
 

我连求都不带求 对我没用
 

明显1楼被怀疑过
 

回复silentxman:嗯,你思维很跳跃!
 

按照中国人的思维,一定会怀疑放火的就是那个提出问题的村民...
   
帮助中心 | 空间客服 | 投诉中心 | 空间协议
©2012 Baidu