Carnal0wnage Blog
Friday, September 30, 2011

ncrack with domain creds

›
little post on using ncrack to brute/check domain creds user@ubuntu:~/pentest/msf3$ ncrack 192.168.1.52:3389,CL=2 --user=username@domain --p...
Thursday, September 22, 2011

My Personal War Against Overuse of Memory Corruption Bugs

›
I remember many years ago writing my first buffer overflow, a standard stack bug privilege escalation in I think RedHat 7x which I thought w...
6 comments:
Thursday, September 15, 2011

Where have you been!?

›
I've been busy... :-( But i do have some upcoming conference speaking engagements coming up. So. If you are heading to BruCon catch me a...
2 comments:
Monday, August 29, 2011

Using ncrack to test for servers vuln to Morto worm

›
Looks like the Morto worm is floating around. I frequently run into just seeing 3389 open on pentests and if the local admin account is ...
Monday, July 11, 2011

Abusing Password Resets

›
Dave Ferguson has beaten up on forgotten/reset password functionality for some time and recently participated in an OWASP podcast where he d...
3 comments:
Tuesday, July 5, 2011

Facebook Forensics

›
Hi dudes, we have got a studies over facebook forensics, please feel free to reference and enjoy it from here. Special thanks to Captain...
Friday, July 1, 2011

Process Injection Outside of Metasploit

›
You may find yourself needing to do process injection outside of metasploit/meterpreter. A good examples is when you have a java meterpreter...
8 comments:
Friday, June 24, 2011

Welcome Ken "cktricky" Johnson!

›
Ken "cktricky" Johnson has agreed to join the carnal0wnage/attackresearch blog and I cant be more excited. Ken brings tons of weba...
1 comment:
Thursday, June 23, 2011

Restricted Citrix Excel Application Escapes

›
SynJunkie has a couple good posts on citrix escapes: http://synjunkie.blogspot.com/search/label/Citrix and of course iKat http://ikat.ha.cke...
3 comments:
Sunday, June 19, 2011

Strategic Security -- Exploit Development Course

›
Joe McCray with Strategic Security is running a two week exploit dev course. Course Description & Instructor Information: http://strateg...
‹
›
Home
View web version
Powered by Blogger.

Contributors

  • CG
  • Javuto
  • cktricky