Better Together Community
Join
Sign in
Search Options
Search Everything
Search Blogs
Home
Events
Forums
Blogs
Wiki
More ...
Home
»
Blogs
»
Daniel Weis
Blogs
A description has not yet been added to this group.
Get this RSS feed
Home
Blogs
Options
Email Blog Author
RSS for Posts
OK
Daniel Weis
All about Pentesting & IT security
RSS for Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Daniel Weis
IPv6 Link Local surface analyzer
Posted
21 hours ago
by
Daniel Weis
0
Comments
Ben Akrin has released a new IPv6 discovery tool that looks promising. Available from here: ipv6_surface_analyzer_1.0.tar.gz Purpose With more devices coming IPv6 ready out of the box, a shadow network is emerging that nobody is paying attention to. There’s...
Daniel Weis
Disabling Local Administrators through GPO on Server 2008
Posted
22 hours ago
by
Daniel Weis
0
Comments
One of the common techniques I generally use during a penetration test is often referred to as pivoting or leap frogging. Essentially, when you compromise one machine, the information on the single server often yields a second or multiple compromises...
Daniel Weis
Social Engineer Toolkit 3 released!!!!
Posted
02-22-2012
by
Daniel Weis
0
Comments
The new version of set 3.0 is finally out! https://www.secmaniac.com/blog/2012/02/20/the-social-engineer-toolkit-set-3-0-wethrowbaseballs-has-been-released/ It is awesome to see we now have windows support, can’t wait to get cracking with it! new...
Daniel Weis
Gateway-finder
Posted
02-17-2012
by
Daniel Weis
0
Comments
Gateway-finder is a scapy script that will help you determine which of the systems on the local LAN has IP forwarding enabled and which can reach the Internet. This can be useful during Internal pentests when you want to quickly check for unauthorised...
Daniel Weis
Finding IP Addresses of Other Network Interfaces on Linux
Posted
02-17-2012
by
Daniel Weis
0
Comments
The scenario for this post is that you’re connected to the local LAN of the systems you’re pentesting – possibly in a DMZ or multi-tiered architecture. If you’re on an externally-facing LAN, you may find that there aren’t...
Daniel Weis
Dumping Cleartext Credentials with Mimikatz
Posted
02-17-2012
by
Daniel Weis
0
Comments
awesome post by Tim Tomes on paul.dot that I will definately be adding to my arsenal, see below: Ever have that moment where hashes just aren’t good enough? Where you don’t have time or power to brute force a 15 character NTLM password? Well...
Daniel Weis
10 Pentesting Linux Distributions You Should Try
Posted
02-17-2012
by
Daniel Weis
0
Comments
Great post form shipcode here http://blog.rootcon.org/2012/02/10-pentesting-linux-distributions-you.html about the different pentesting distro’s out there.
Daniel Weis
Cloudcracker.com
Posted
02-16-2012
by
Daniel Weis
0
Comments
As a pentester I frequently find time is my biggest enemy for assessments, I am always running out of it, and if you don’t have a multi GPU password cracking machine like I have Cloudcracker.com may be your answer. https://www.cloudcracker.com A...
Daniel Weis
Cisco Security BP’s
Posted
02-15-2012
by
Daniel Weis
0
Comments
In case you didn’t already know, cisco have some fantastic Security Design Guides for the different solutions that you can implement, basically security BP’s for different network devices/layouts/designs. They have sample router/asa config’s...
Daniel Weis
Security & Real world threats presentation
Posted
02-15-2012
by
Daniel Weis
1
Comments
Hi Everyone, I will be delivering a new presentation called ‘Security & real world threats’ at a Kiandra IT breakfast event on Wednesday 7th March. Detail below… If you are interested in attending, please drop me an email at securityservices...
Daniel Weis
Building a Better Castle: Hardening the Squishy Center of your Network
Posted
02-15-2012
by
Daniel Weis
0
Comments
For several years, companies and consultants pushed very heavily on enhancing perimeter security through the use of firewalls and other network defense technologies intended to prevent unwanted traffic from entering the network. While this hardened outer...
Daniel Weis
Just that easy: real world pentesting attack vectors
Posted
02-15-2012
by
Daniel Weis
0
Comments
Although conferences, news articles, and everyday conversations make attacks on large organizations seem so simple, it may be hard to believe that these things work. The goal of this series of blog posts is to demonstrate the closest thing to getting...
Daniel Weis
shmoocon 2012 presentations now available for download
Posted
02-13-2012
by
Daniel Weis
0
Comments
You can find them here http://www.shmoocon.org/presentations to make your lives easier, I have compiled the list of them all for you just save the below into a text file, and in linux use wget –i and point it to the file… too easy! http:...
Daniel Weis
THC-Hydra v7.2 is out!
Posted
02-13-2012
by
Daniel Weis
1
Comments
The latest version of THC-Hydra came out a few days, if you haven’t already tried Hydra, you don’t know what you are missing. Hydra is my choice hands down when it comes to a lot of the password cracking I do, in particular web based forms...
Daniel Weis
Sophos Threat Report 2012 is now available
Posted
02-10-2012
by
Daniel Weis
0
Comments
We should start to see all the stats for 2011 come out soon, here is the first major one for the year… http://www.sophos.com/en-us/security-news-trends/reports/security-threat-report.aspx
Daniel Weis
Internet Explorer dominates browser security as Google faces accusations
Posted
02-08-2012
by
Daniel Weis
0
Comments
Long Live IE! IE9 has again proved to be the most secure web browser.. see the post here , see below…. IE 9 proves 96-plus percent effective in blocking malware, while Chrome, Firefox, and Safari all lag Internet Explorer 9 should be the go-to...
Daniel Weis
Maltego 3.1 available!
Posted
02-08-2012
by
Daniel Weis
0
Comments
Maltego 3.1 is the new flagship product from the guys at Paterva and offers a range of fantastic new features and enhancements to the already phenomenal product. If you haven’t tried Maltego , you don’t know what you are missing. Some of the...
Daniel Weis
BT5 Fix-it script
Posted
02-08-2012
by
Daniel Weis
0
Comments
Are you using BT5-Gnome and find that many of the tools are either missing or out of date? If the answer is yes then use this bt5-fixit.sh script to add many missing tools and replace the installed tools with their svn counter parts. You can find the...
Daniel Weis
Automating the Hack. From Exploit to Domain Admin, Complete Enterprise P0wnage.
Posted
02-06-2012
by
Daniel Weis
0
Comments
I thought I would share a combination of Metasploit scripts I use to eviscerate networks on a large scale. These post-exploitation tools will make short work of controlling as many targets as possible and leverage work by Joshua “Jabra” Abraha...
Daniel Weis
Metasploit Pentest Plugin part 2
Posted
02-02-2012
by
Daniel Weis
0
Comments
darkoperator.com has released his next post on the metasploit pentest plugin he created for people like me! keep up the good work.. http://www.darkoperator.com/blog/2012/1/29/metasploit-pentest-plugin-part-2.html you can find the original part 1 with...
Daniel Weis
psexec fail? upload and exec instead
Posted
02-02-2012
by
Daniel Weis
0
Comments
I ended up having to use the smb/upload_file module on a pentest. I was able to get the local admin hashes but for some reason the psexec module wouldn’t get code execution, it would act like it would work but wasn’t. So we decided to push...
Daniel Weis
Paypass, time to buy yourself an RFID blocking wallet..
Posted
01-31-2012
by
Daniel Weis
0
Comments
Great post here on just how easy it is for paypass cards to be read and forged… a great read. http://www.forbes.com/sites/andygreenberg/2012/01/30/hackers-demo-shows-how-easily-credit-cards-can-be-read-through-clothes-and-wallets/
Daniel Weis
Routerpwn..A new way to exploit low end routers & embedded devices
Posted
01-31-2012
by
Daniel Weis
0
Comments
Pedro Joaquin, Chief Security Officer of Websec, has released a tool to facilitate penetration testers with the exploitation of vulnerabilities in embedded devices. This tool is Routerpwn and can be found at www.routerpwn.com Routerpwn is a web application...
Daniel Weis
A Backdoor in the Next Generation Active Directory
Posted
01-27-2012
by
Daniel Weis
0
Comments
At the beginning of the last year, Dmitry EvTeev Ha raised the issue of post-exploitation in a Microsoft Active Directory domain. The brought forward approach addressed the variant aimed mostly at the case of the loss of admin privileges rather than their...
Daniel Weis
SQL, WordPress & PHBB3 Backdoors
Posted
01-27-2012
by
Daniel Weis
0
Comments
Great howto on SQL backdooring, WordPress & PHBB3 Examples here: http://www.blackhatacademy.org/security101/SQL_Backdoors worth the read
Page 1 of 4 (100 items)
1
2
3
4