Carnal0wnage Blog
Friday, February 17, 2012

Hunting & Exploiting Directory Traversal

›
In cktricky's last post he provided a great outline on the ins and outs of leveraging burp's built in support for directory traver...
5 comments:
Sunday, February 5, 2012

Easy Directory Traversal with Burp

›
Often, I'll use Burp Suite's directory traversal Intruder payload list. A step exists that must be performed in order to effectively...
Friday, February 3, 2012

Direct Shellcode Execution via MS Office Macros with Metasploit

›
scriptjunkie recently had a post on Direct shellcode execution in MS Office macros  I didnt see it go into the metasploit trunk, but its the...
14 comments:
Monday, January 23, 2012

psexec fail? upload and exec instead

›
I ended up having to use the smb/upload_file module on a pentest.  I was able to get the local admin hashes but for some reason the psexec ...
10 comments:
Friday, January 13, 2012

"Sanitize Input"

›
When application security was still in it’s infancy, there were discussions on how to protect applications from newly discovered injection...
4 comments:
Tuesday, December 20, 2011

Insecure Object Mapping

›
Over the last two cycles of OWASP top 10, insecure direct object reference has been included as major security risk. An object reference is ...
Tuesday, December 13, 2011

Not 0wning That ColdFusion Server but Helping...

›
Stephen, @averagesecguy , wrote a post on owning a ColdFusion server. its pretty good and he wrote some code to help things along. Code: ht...
1 comment:
Sunday, December 11, 2011

Root that Motorola Xoom and Get You Some BT5

›
Rooting the Xoom and putting BT5 on it... Check out http://wiki.rootzwiki.com/Motorola_Xoom For instructions to get android sdk (adb/fastboo...
7 comments:
Friday, December 9, 2011

SQLMap -- Searching Databases for Specific Columns/Data & Extracting from Specific Columns

›
So assuming we have some sort of SQL Injection in the application (Blind in this case) and we've previously dumped all the available dat...
5 comments:
Wednesday, December 7, 2011

Aggressive Mode VPN -- IKE-Scan, PSK-Crack, and Cain

›
There hasnt been much in the way of updates on breaking into VPN servers that have aggressive mode enabled. ike-scan is probably still your...
11 comments:
‹
›
Home
View web version
Powered by Blogger.

Contributors

  • CG
  • Javuto
  • cktricky