Better Together Community

Blogs

A description has not yet been added to this group.

Daniel Weis

All about Pentesting & IT security
  • Daniel Weis

    IPv6 Link Local surface analyzer

    • 0 Comments
    Ben Akrin has released a new IPv6 discovery tool that looks promising. Available from here: ipv6_surface_analyzer_1.0.tar.gz Purpose With more devices coming IPv6 ready out of the box, a shadow network is emerging that nobody is paying attention to. There’s...
  • Daniel Weis

    Disabling Local Administrators through GPO on Server 2008

    • 0 Comments
    One of the common techniques I generally use during a penetration test is often referred to as pivoting or leap frogging. Essentially, when you compromise one machine, the information on the single server often yields a second or multiple compromises...
  • Daniel Weis

    Social Engineer Toolkit 3 released!!!!

    • 0 Comments
    The new version of set 3.0 is finally out! https://www.secmaniac.com/blog/2012/02/20/the-social-engineer-toolkit-set-3-0-wethrowbaseballs-has-been-released/ It is awesome to see we now have windows support, can’t wait to get cracking with it! new...
  • Daniel Weis

    Gateway-finder

    • 0 Comments
    Gateway-finder is a scapy script that will help you determine which of the systems on the local LAN has IP forwarding enabled and which can reach the Internet. This can be useful during Internal pentests when you want to quickly check for unauthorised...
  • Daniel Weis

    Finding IP Addresses of Other Network Interfaces on Linux

    • 0 Comments
    The scenario for this post is that you’re connected to the local LAN of the systems you’re pentesting – possibly in a DMZ or multi-tiered architecture. If you’re on an externally-facing LAN, you may find that there aren’t...
  • Daniel Weis

    Dumping Cleartext Credentials with Mimikatz

    • 0 Comments
    awesome post by Tim Tomes on paul.dot that I will definately be adding to my arsenal, see below: Ever have that moment where hashes just aren’t good enough? Where you don’t have time or power to brute force a 15 character NTLM password? Well...
  • Daniel Weis

    10 Pentesting Linux Distributions You Should Try

    • 0 Comments
    Great post form shipcode here http://blog.rootcon.org/2012/02/10-pentesting-linux-distributions-you.html about the different pentesting distro’s out there.
  • Daniel Weis

    Cloudcracker.com

    • 0 Comments
    As a pentester I frequently find time is my biggest enemy for assessments, I am always running out of it, and if you don’t have a multi GPU password cracking machine like I have Cloudcracker.com may be your answer. https://www.cloudcracker.com A...
  • Daniel Weis

    Cisco Security BP’s

    • 0 Comments
    In case you didn’t already know, cisco have some fantastic Security Design Guides for the different solutions that you can implement, basically security BP’s for different network devices/layouts/designs. They have sample router/asa config’s...
  • Daniel Weis

    Security & Real world threats presentation

    • 1 Comments
    Hi Everyone, I will be delivering a new presentation called ‘Security & real world threats’ at a Kiandra IT breakfast event on Wednesday 7th March. Detail below… If you are interested in attending, please drop me an email at securityservices...
  • Daniel Weis

    Building a Better Castle: Hardening the Squishy Center of your Network

    • 0 Comments
    For several years, companies and consultants pushed very heavily on enhancing perimeter security through the use of firewalls and other network defense technologies intended to prevent unwanted traffic from entering the network. While this hardened outer...
  • Daniel Weis

    Just that easy: real world pentesting attack vectors

    • 0 Comments
    Although conferences, news articles, and everyday conversations make attacks on large organizations seem so simple, it may be hard to believe that these things work. The goal of this series of blog posts is to demonstrate the closest thing to getting...
  • Daniel Weis

    shmoocon 2012 presentations now available for download

    • 0 Comments
    You can find them here http://www.shmoocon.org/presentations to make your lives easier, I have compiled the list of them all for you just save the below into a text file, and in linux use wget –i and point it to the file… too easy! http:...
  • Daniel Weis

    THC-Hydra v7.2 is out!

    • 1 Comments
    The latest version of THC-Hydra came out a few days, if you haven’t already tried Hydra, you don’t know what you are missing. Hydra is my choice hands down when it comes to a lot of the password cracking I do, in particular web based forms...
  • Daniel Weis

    Sophos Threat Report 2012 is now available

    • 0 Comments
    We should start to see all the stats for 2011 come out soon, here is the first major one for the year… http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report.aspx
  • Daniel Weis

    Internet Explorer dominates browser security as Google faces accusations

    • 0 Comments
    Long Live IE! IE9 has again proved to be the most secure web browser.. see the post here , see below…. IE 9 proves 96-plus percent effective in blocking malware, while Chrome, Firefox, and Safari all lag Internet Explorer 9 should be the go-to...
  • Daniel Weis

    Maltego 3.1 available!

    • 0 Comments
    Maltego 3.1 is the new flagship product from the guys at Paterva and offers a range of fantastic new features and enhancements to the already phenomenal product. If you haven’t tried Maltego , you don’t know what you are missing. Some of the...
  • Daniel Weis

    BT5 Fix-it script

    • 0 Comments
    Are you using BT5-Gnome and find that many of the tools are either missing or out of date? If the answer is yes then use this bt5-fixit.sh script to add many missing tools and replace the installed tools with their svn counter parts. You can find the...
  • Daniel Weis

    Automating the Hack. From Exploit to Domain Admin, Complete Enterprise P0wnage.

    • 0 Comments
    I thought I would share a combination of Metasploit scripts I use to eviscerate networks on a large scale. These post-exploitation tools will make short work of controlling as many targets as possible and leverage work by Joshua “Jabra” Abraha...
  • Daniel Weis

    Metasploit Pentest Plugin part 2

    • 0 Comments
    darkoperator.com has released his next post on the metasploit pentest plugin he created for people like me! keep up the good work.. http://www.darkoperator.com/blog/2012/1/29/metasploit-pentest-plugin-part-2.html you can find the original part 1 with...
  • Daniel Weis

    psexec fail? upload and exec instead

    • 0 Comments
    I ended up having to use the smb/upload_file module on a pentest. I was able to get the local admin hashes but for some reason the psexec module wouldn’t get code execution, it would act like it would work but wasn’t. So we decided to push...
  • Daniel Weis

    Paypass, time to buy yourself an RFID blocking wallet..

    • 0 Comments
    Great post here on just how easy it is for paypass cards to be read and forged… a great read. http://www.forbes.com/sites/andygreenberg/2012/01/30/hackers-demo-shows-how-easily-credit-cards-can-be-read-through-clothes-and-wallets/
  • Daniel Weis

    Routerpwn..A new way to exploit low end routers & embedded devices

    • 0 Comments
    Pedro Joaquin, Chief Security Officer of Websec, has released a tool to facilitate penetration testers with the exploitation of vulnerabilities in embedded devices. This tool is Routerpwn and can be found at www.routerpwn.com Routerpwn is a web application...
  • Daniel Weis

    A Backdoor in the Next Generation Active Directory

    • 0 Comments
    At the beginning of the last year, Dmitry EvTeev Ha raised the issue of post-exploitation in a Microsoft Active Directory domain. The brought forward approach addressed the variant aimed mostly at the case of the loss of admin privileges rather than their...
  • Daniel Weis

    SQL, WordPress & PHBB3 Backdoors

    • 0 Comments
    Great howto on SQL backdooring, WordPress & PHBB3 Examples here: http://www.blackhatacademy.org/security101/SQL_Backdoors worth the read
Page 1 of 4 (100 items) 1234