<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>Ask a Pentester - Recent questions and answers</title>
<link>http://www.ask-a-pentester.com/index.php/qa</link>
<description>Powered by Question2Answer</description>
<item>
<title>Answered: How to know which CVEs affect my application?</title>
<link>http://www.ask-a-pentester.com/index.php/158/how-to-know-which-cves-affect-my-application#a159</link>
<description>&lt;p&gt;
	Hello,&lt;/p&gt;
&lt;p&gt;
	That is not that easy. You might want to find a vulnerability database which allows to find weaknesses affecting a specific product/version. The following databases allow a filter of this kind:&lt;/p&gt;
&lt;ul&gt;
	&lt;li&gt;
		&lt;a rel=&quot;nofollow&quot; href=&quot;http://www.securityfocus.com/bid/&quot;&gt;http://www.securityfocus.com/bid/&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;
		&lt;a rel=&quot;nofollow&quot; href=&quot;http://osvdb.org/search/advsearch&quot;&gt;http://osvdb.org/search/advsearch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
	If you lookup your software in these databases, you might be able to get a list of all known vulnerabilities. Extracting IDs - and CVE too - is possible.&lt;/p&gt;
&lt;p&gt;
	The limitations are, that not all vulnerability databases and/or contributors are providing the exact data. OSVDB is a good example: Althought the database structure is supporting clear identification of product name and version, most entries don't use these fields. This will cause a lot of false-negatives.&lt;/p&gt;
&lt;p&gt;
	Regards,&lt;/p&gt;
&lt;p&gt;
	Marc&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/158/how-to-know-which-cves-affect-my-application#a159</guid>
<pubDate>Wed, 25 Jan 2012 20:09:40 +0000</pubDate>
</item>
<item>
<title>Answered: Club Mate or Jolt Cola for Pen Testing?</title>
<link>http://www.ask-a-pentester.com/index.php/35/club-mate-or-jolt-cola-for-pen-testing#a157</link>
<description>&lt;div class=&quot;qa-a-item-content&quot;&gt;
	&lt;span class=&quot;entry-content&quot;&gt;Club Mate for sure.&lt;/span&gt;&lt;/div&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/35/club-mate-or-jolt-cola-for-pen-testing#a157</guid>
<pubDate>Wed, 25 Jan 2012 05:05:11 +0000</pubDate>
</item>
<item>
<title>Answered: What methodology you use in a pentest?</title>
<link>http://www.ask-a-pentester.com/index.php/70/what-methodology-you-use-in-a-pentest#a156</link>
<description>I use &lt;A HREF=&quot;http://www.pentest-standard.org/index.php/Main_Page&quot; rel=&quot;nofollow&quot;&gt;http://www.pentest-standard.org/index.php/Main_Page&lt;/A&gt;</description>
<category>Frameworks</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/70/what-methodology-you-use-in-a-pentest#a156</guid>
<pubDate>Wed, 25 Jan 2012 04:57:35 +0000</pubDate>
</item>
<item>
<title>Answered: What lab setup do you recommend real machines or virtual ones?</title>
<link>http://www.ask-a-pentester.com/index.php/143/what-lab-setup-do-you-recommend-real-machines-or-virtual-ones#a155</link>
<description>See my slide:&lt;br /&gt;
&lt;br /&gt;
&lt;A HREF=&quot;http://www.slideshare.net/firebits/c0c0n2010&quot; rel=&quot;nofollow&quot;&gt;http://www.slideshare.net/firebits/c0c0n2010&lt;/A&gt;</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/143/what-lab-setup-do-you-recommend-real-machines-or-virtual-ones#a155</guid>
<pubDate>Wed, 25 Jan 2012 04:52:08 +0000</pubDate>
</item>
<item>
<title>Answered: LFI exploration files</title>
<link>http://www.ask-a-pentester.com/index.php/148/lfi-exploration-files#a154</link>
<description>I'm a big fan of the web fuzzing lists from the Fuzzdb:&lt;br /&gt;
&lt;br /&gt;
&lt;A HREF=&quot;http://code.google.com/p/fuzzdb/&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/fuzzdb/&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;A HREF=&quot;http://code.google.com/p/fuzzdb/source/browse/#svn%2Ftrunk%2Fattack-payloads%2Flfi&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/p/fuzzdb/source/browse/#svn%2Ftrunk%2Fattack-payloads%2Flfi&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
also try this:&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&lt;A HREF=&quot;http://pastie.org/840199&quot; rel=&quot;nofollow&quot;&gt;http://pastie.org/840199&lt;/A&gt;</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/148/lfi-exploration-files#a154</guid>
<pubDate>Wed, 21 Dec 2011 10:21:54 +0000</pubDate>
</item>
<item>
<title>Answered: Do you have any classes online you could recommend? Also, is there any certain degree in college I should get if I want to be a pentester?</title>
<link>http://www.ask-a-pentester.com/index.php/152/classes-online-recommend-certain-degree-college-pentester#a153</link>
<description>I think you should have a look at the online training of Offensive Security (&lt;A HREF=&quot;http://www.offensive-security.com).&quot; rel=&quot;nofollow&quot;&gt;http://www.offensive-security.com).&lt;/A&gt; They have the WLAN training - WiFu, the typical pentesting training - PWB and one very advanced pentesting training CTB. If you have the possibility to choin them in the US you could also attend the most advanced training in exploit devel - AWE. You can also find lots of quite good trainings on the SANS webseite - &lt;A HREF=&quot;https://www.sans.org/.&quot; rel=&quot;nofollow&quot;&gt;https://www.sans.org/.&lt;/A&gt; have phun and good luck m-1-k-3</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/152/classes-online-recommend-certain-degree-college-pentester#a153</guid>
<pubDate>Thu, 10 Nov 2011 07:13:35 +0000</pubDate>
</item>
<item>
<title>Answered: Entry level to Pen tester help</title>
<link>http://www.ask-a-pentester.com/index.php/149/entry-level-to-pen-tester-help#a151</link>
<description>Thanks very much for your reply . I will take CCNA --&amp;gt; OSCP and then see how it goes from there , thanks agian appreciate it .</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/149/entry-level-to-pen-tester-help#a151</guid>
<pubDate>Fri, 21 Oct 2011 23:55:51 +0000</pubDate>
</item>
<item>
<title>Answered: Could you recommend a ressource for images which have weak spots to learn more about Pentesting?</title>
<link>http://www.ask-a-pentester.com/index.php/145/recommend-ressource-images-which-spots-learn-about-pentesting#a147</link>
<description>Wow, thank you, looks very good... :)</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/145/recommend-ressource-images-which-spots-learn-about-pentesting#a147</guid>
<pubDate>Fri, 09 Sep 2011 16:59:51 +0000</pubDate>
</item>
<item>
<title>Answered: Can u suggest good exploit for Windows 7, like &quot;ms08_067_netapi &quot; in xp?</title>
<link>http://www.ask-a-pentester.com/index.php/124/can-suggest-good-exploit-for-windows-like-ms08_067_netapi#a142</link>
<description>There's no magic exploit like the ms08_067_netaspi in Windows 7 or Vista. Even most of the Windows XP SP2 and above have got it patched these days . &lt;br /&gt;
&lt;br /&gt;
What i try to do while pentesting is to look at the services running at the ports and try finding some of the exploits, if available for them. &lt;br /&gt;
&lt;br /&gt;
Also, you could try focussing on Client Level Vuln while pentesting such as vulns in the flash player version, or &amp;nbsp;adobe pdf reader or anything else your client is running. &lt;br /&gt;
&lt;br /&gt;
Its not the path that matters more, all that matters is finding a way to get in.&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Good Luck. :)</description>
<category>Exploit devel.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/124/can-suggest-good-exploit-for-windows-like-ms08_067_netapi#a142</guid>
<pubDate>Sun, 14 Aug 2011 10:19:57 +0000</pubDate>
</item>
<item>
<title>Answered: Do pentest tools slow down internet</title>
<link>http://www.ask-a-pentester.com/index.php/138/do-pentest-tools-slow-down-internet#a140</link>
<description>Hello,&lt;br /&gt;
&lt;br /&gt;
It depends on what kind of requests and responses are provoked by these tools. An high amount of data and/or connections may slow down certain network elements. For example my cheap D-Link router doesn't like a lot of concurrent connections (but has no problem with a single connection with a lot of bandwith usage). ZyWALL has a similar problem but only if QoS is enabled.&lt;br /&gt;
&lt;br /&gt;
The best way would be to reproduce the problem by running the scanning utilities and analyzing the network traffic with a tool like Wireshark or tcpdump. If you see a slowdown, you might be able to determine the cause for this.&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Marc</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/138/do-pentest-tools-slow-down-internet#a140</guid>
<pubDate>Tue, 19 Jul 2011 11:23:41 +0000</pubDate>
</item>
<item>
<title>Does Scapy support the LDAP protocol?</title>
<link>http://www.ask-a-pentester.com/index.php/139/does-scapy-support-the-ldap-protocol</link>
<description>&lt;p&gt;
	I'm new to &lt;a rel=&quot;nofollow&quot; href=&quot;http://www.secdev.org/projects/scapy/&quot;&gt;Scapy&lt;/a&gt;&amp;nbsp;and I can't find support for the LDAP protocol on it. Does anybody know if it's supported?&lt;/p&gt;
&lt;p&gt;
	Maybe I need to install another package?&lt;/p&gt;
&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
	Thanks in advance!&lt;/p&gt;</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/139/does-scapy-support-the-ldap-protocol</guid>
<pubDate>Thu, 07 Jul 2011 16:42:30 +0000</pubDate>
</item>
<item>
<title>what can we do with Local file download/ File download vuln. Windows ?</title>
<link>http://www.ask-a-pentester.com/index.php/137/what-can-with-local-file-download-file-download-vuln-windows</link>
<description>hi i want to know what are the security files which are imp. which lead it to hack the Server and get acess to CMD &amp;nbsp;its on Server=Apache-Coyote/1.1&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
and i am able to download all files but not admin locked files so can anybody help me ?</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/137/what-can-with-local-file-download-file-download-vuln-windows</guid>
<pubDate>Sat, 02 Jul 2011 10:17:41 +0000</pubDate>
</item>
<item>
<title>Answered: What to learn first?</title>
<link>http://www.ask-a-pentester.com/index.php/130/what-to-learn-first#a136</link>
<description>&lt;p&gt;
	&lt;strong&gt;wow thanks, i have been learning python but just wante to make sure it was the right one. that python for grey hats is just what i need&lt;/strong&gt;&lt;/p&gt;</description>
<category>Programming</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/130/what-to-learn-first#a136</guid>
<pubDate>Mon, 27 Jun 2011 10:46:06 +0000</pubDate>
</item>
<item>
<title>Answered: Vulnerable Ports?</title>
<link>http://www.ask-a-pentester.com/index.php/131/vulnerable-ports#a135</link>
<description>&lt;p&gt;
	&lt;strong&gt;thanks very much, i saw the script earlier and tried it out its very good&lt;/strong&gt;&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/131/vulnerable-ports#a135</guid>
<pubDate>Mon, 27 Jun 2011 10:44:09 +0000</pubDate>
</item>
<item>
<title>Answered: What if you pentest someone who unkowingly to you lies that they have authority?</title>
<link>http://www.ask-a-pentester.com/index.php/123/what-pentest-someone-unkowingly-lies-that-they-have-authority#a132</link>
<description>&lt;p&gt;
	&lt;strong&gt;one thing you would expect is that he gives the the password first. then they try crack&lt;/strong&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt; it. they shouldnt be giving anyone a password if they are not 100% sure they own the system in discussion. and a signed contract doesnt prove he owns it.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
	&lt;span style=&quot;font-weight: bold;&quot;&gt;so i would say if thats how pentest companies work its their fault&lt;/span&gt;&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/123/what-pentest-someone-unkowingly-lies-that-they-have-authority#a132</guid>
<pubDate>Mon, 27 Jun 2011 08:46:10 +0000</pubDate>
</item>
<item>
<title>Can any one help me to how to exploit windows 7?</title>
<link>http://www.ask-a-pentester.com/index.php/129/can-any-one-help-me-to-how-to-exploit-windows-7</link>
<description>hi cany any body help me how to exploit windows 7 ? i have tried it for last 3 months but no luck, i am new bee to metasploit pls help&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
thanx in advance!!</description>
<category>Exploit devel.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/129/can-any-one-help-me-to-how-to-exploit-windows-7</guid>
<pubDate>Tue, 21 Jun 2011 07:39:46 +0000</pubDate>
</item>
<item>
<title>Answered: Identify HTTP or SSL running on non-standard ports</title>
<link>http://www.ask-a-pentester.com/index.php/106/identify-http-or-ssl-running-on-non-standard-ports#a128</link>
<description>&lt;p&gt;
	Hello,&lt;/p&gt;
&lt;p&gt;
	We use the following Nmap NSE script to identify HTTP services[1]:&lt;/p&gt;
&lt;p style=&quot;margin-left: 40px;&quot;&gt;
	&lt;span style=&quot;font-family: Courier New,Courier,monospace;&quot;&gt;author = &amp;quot;Marc Ruef&amp;quot;&lt;br /&gt;
	license = &amp;quot;(c) 2010 by Marc Ruef&amp;quot;&lt;br /&gt;
	version = &amp;quot;1.0&amp;quot;&lt;br /&gt;
	categories = {&amp;quot;default&amp;quot;, &amp;quot;safe&amp;quot;, &amp;quot;scip&amp;quot;}&lt;br /&gt;
	&lt;br /&gt;
	require(&amp;quot;http&amp;quot;)&lt;br /&gt;
	&lt;br /&gt;
	description = [[]]&lt;br /&gt;
	&lt;br /&gt;
	portrule = function(host, port)&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;if port.service == &amp;quot;http&amp;quot; and port.service ~= &amp;quot;ssl/http&amp;quot; and port.service ~= &amp;quot;https&amp;quot; and port.version.service_tunnel ~= &amp;quot;ssl&amp;quot; then&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return true&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;elseif port.protocol == &amp;quot;tcp&amp;quot; and (port.number == 80 or port.number == 81) then&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return true&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;else&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; return false&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;end&lt;br /&gt;
	end&lt;br /&gt;
	&lt;br /&gt;
	action = function(host, port)&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;local response = http.get(host, port, &amp;quot;/&amp;quot;)&lt;br /&gt;
	&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;if response.rawheader ~= nil then&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sOutput = &amp;quot;Header:\n\n&amp;quot; .. stdnse.format_output(true, response.rawheader)&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;elseif response.body ~= nil then&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if response.body ~= &amp;quot;&amp;quot; then&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; sOutput = &amp;quot;Body:\n\n&amp;quot; .. response.body&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; else&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; sOutput = &amp;quot;&amp;quot;&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; end&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;else&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sOutput = &amp;quot;It was not possible to fetch a resource with a common http get request. This might be a false positive.&amp;quot;&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;end&lt;br /&gt;
	&lt;br /&gt;
	&amp;nbsp;&amp;nbsp; &amp;nbsp;return sOutput&lt;br /&gt;
	end&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
	If you save this script in the scripts folder of your Nmap installation as webdetect.nse, you might want to use &lt;strong&gt;&lt;span style=&quot;font-family: Courier New,Courier,monospace;&quot;&gt;nmap -sS -sV --script=webdetect &amp;lt;target&amp;gt;&lt;/span&gt;&lt;/strong&gt; to identify http servcies as quickly and accurate as possible.&lt;/p&gt;
&lt;p&gt;
	Regards,&lt;/p&gt;
&lt;p&gt;
	Marc&lt;/p&gt;
&lt;p&gt;
	[1] &lt;a rel=&quot;nofollow&quot; href=&quot;http://www.scip.ch/?labs.20101119&quot;&gt;http://www.scip.ch/?labs.20101119&lt;/a&gt;&lt;/p&gt;</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/106/identify-http-or-ssl-running-on-non-standard-ports#a128</guid>
<pubDate>Fri, 17 Jun 2011 13:38:29 +0000</pubDate>
</item>
<item>
<title>Answered: What is the best book for learning Malware RE?</title>
<link>http://www.ask-a-pentester.com/index.php/3/what-is-the-best-book-for-learning-malware-re#a120</link>
<description>I think malware analyst's cookbook must be one of the best book for what you are looking.&lt;br /&gt;
&lt;br /&gt;
But if you want much more sources to learn malware RE, you should seek informations about windows debugging, windows internals, or subjects like cracking software. All theses domains will bring you knowledge which is very usefull for malware RE</description>
<category>Reverse Eng.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/3/what-is-the-best-book-for-learning-malware-re#a120</guid>
<pubDate>Thu, 12 May 2011 16:13:06 +0000</pubDate>
</item>
<item>
<title>Answered: Can I scan for vulnerabilities with nmap?</title>
<link>http://www.ask-a-pentester.com/index.php/1/can-i-scan-for-vulnerabilities-with-nmap#a119</link>
<description>&lt;p&gt;
	&amp;nbsp;&lt;/p&gt;

&lt;p&gt;
	&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; color: #000000;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;&gt;As other people said, nmap NSE scripts are usefull to do vuln scanning.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
	But I think it's useless to do a huge base of NSE scripts just for trying to do vuln scanning, nmap is not a vuln scanning tool, just try to use another product (like nessus) to do this.&lt;/p&gt;
&lt;p&gt;
	I think you should use each tool for what they have been created, instead of waiting for a lot of NSE scripts that reinvent the wheel.&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/1/can-i-scan-for-vulnerabilities-with-nmap#a119</guid>
<pubDate>Thu, 12 May 2011 16:09:45 +0000</pubDate>
</item>
<item>
<title>Answered: Defensive Programming--Second Steps?</title>
<link>http://www.ask-a-pentester.com/index.php/117/defensive-programming--second-steps#a118</link>
<description>Hi,&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
I would say... ABSOLUTELY. Although a good start, it's not enough just the theory behind it.&lt;br /&gt;
&lt;br /&gt;
By having compromised a system exploiting a programming error, your fingers will burn the moment you write a similar piece of code :)&lt;br /&gt;
&lt;br /&gt;
This way could you not only reactively patch your code but spot some possible weakness before this code goes to production.&lt;br /&gt;
&lt;br /&gt;
It's always better to have been on both sides of the fence... but you know this already :)&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Hope this helps and good luck with your CS study!</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/117/defensive-programming--second-steps#a118</guid>
<pubDate>Wed, 04 May 2011 12:38:05 +0000</pubDate>
</item>
<item>
<title>Answered: How can I protect myself against Firesheep?</title>
<link>http://www.ask-a-pentester.com/index.php/6/how-can-i-protect-myself-against-firesheep#a103</link>
<description>I leave my Wireless Network Connection disabled unless it's in use. When in use, I always tether to my Android phone, which provides a WPA2 connection that only I know the 52 character &amp;quot;graph&amp;quot; password to (and I change it every few days when it's convienient or I'm feeling compromised).&lt;br /&gt;
&lt;br /&gt;
I don't connect to other networks, such as local networks or coffee shops (my Local Ethernet Connection is permanently disabled), and I find ways to access networks that I need access to in other ways.</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/6/how-can-i-protect-myself-against-firesheep#a103</guid>
<pubDate>Tue, 05 Apr 2011 22:59:02 +0000</pubDate>
</item>
<item>
<title>Answered: has anyone ever done some sort of &quot;Active Directory&quot; forensics?</title>
<link>http://www.ask-a-pentester.com/index.php/14/has-anyone-ever-done-some-sort-of-active-directory-forensics#a102</link>
<description>&lt;p&gt;
	You could also utilize network signatures in an IDS such as Suricata (I prefer it over Snort and commercial ones).&lt;/p&gt;
&lt;p&gt;
	You would need to build custom signatures. Have a look at this nmap NSE script (and the others it references) --&amp;nbsp;&lt;a href=&quot;http://nmap.org/nsedoc/scripts/ldap-rootdse.html&quot; rel=&quot;nofollow&quot;&gt;http://nmap.org/nsedoc/scripts/ldap-rootdse.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;
	If you could build a signature that captures these sorts of events, you'd be able to tell the src traffic that queries your AD infrastructure.&lt;/p&gt;
&lt;p&gt;
	*** UPDATE ***&lt;/p&gt;
&lt;p&gt;
	Oh crap -- check this out! --&amp;nbsp;&lt;a rel=&quot;nofollow&quot; href=&quot;http://ptresearch.blogspot.com/2011/04/backdoor-in-active-directory.html&quot;&gt;http://ptresearch.blogspot.com/2011/04/backdoor-in-active-directory.html&lt;/a&gt;&lt;/p&gt;</description>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/14/has-anyone-ever-done-some-sort-of-active-directory-forensics#a102</guid>
<pubDate>Tue, 05 Apr 2011 22:55:53 +0000</pubDate>
</item>
<item>
<title>Answered: Best (and updated) fuzzing tools?</title>
<link>http://www.ask-a-pentester.com/index.php/25/best-and-updated-fuzzing-tools#a101</link>
<description>PaiMei supports file fuzzing (along with code coverage!) and iSec Partners has a few file fuzzing tools (e.g. FileP and FileH) available on their website.&lt;br /&gt;
&lt;br /&gt;
Microsoft also released one called MiniFuzz.&lt;br /&gt;
&lt;br /&gt;
Symantec has built one called SEEAS, but it was never released to the public.</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/25/best-and-updated-fuzzing-tools#a101</guid>
<pubDate>Tue, 05 Apr 2011 22:52:11 +0000</pubDate>
</item>
<item>
<title>Answered: Tool / Method for unknown network binary protocol analysis?</title>
<link>http://www.ask-a-pentester.com/index.php/30/tool-method-for-unknown-network-binary-protocol-analysis#a100</link>
<description>&lt;p&gt;
	Using Autodafe is described in &amp;quot;Gray Hat Hacking, Third Edition&amp;quot; (recently just came out!) under the SCADA hacking section.&lt;/p&gt;
&lt;p&gt;
	There is also a great guide that discusses how to use The Peach Fuzzing Frameworks' peachshark along with Wireshark in the book &amp;quot;Hacking Exposed Windows, Third Edition&amp;quot;.&lt;/p&gt;
&lt;p&gt;
	If the protocol is MSRPC, it may be a little more difficult, but there are tools out there such as this one:&amp;nbsp;&lt;a href=&quot;http://wiki.austinhackers.org/2006-11-29-0x0003&quot; rel=&quot;nofollow&quot;&gt;http://wiki.austinhackers.org/2006-11-29-0x0003&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;
	You may want to try the ProxyFuzz script included with taof before anything else, as it if finds something -- then you are golden right away with almost no configuration or advanced fuzzing. If not, then you might want to move to reversing the application on both sides (client and server) and establishing your own rules about their protocol use. EFS (as shown in the last chapter of &amp;quot;Open-Source Fuzzing Tools&amp;quot;) is a great way to utilize PIDA (Python IDA) files to do a lot of this work for you, as is CatchConv (a Valgrind plugin), also described in that chapter.&lt;/p&gt;
&lt;p&gt;
	Ideally, you would want to understand both the runtime and static (i.e. deadlist) views of the target apps including their infrastructure. Different tools call for different measures. You can dump your DRAM. You can hook system or library calls that access the network. You can locally proxy a network connection. You can attach debuggers, software/system-call/library-call tracers, or fault-monitors of various types. You can run it through emulation, or inside a virtual machine. You can watch CPU registers. You can trace instructions or functions. You can implement dynamic binary instrumentation to insert your own code into the code, in order to understand the baseline code better.&lt;/p&gt;
&lt;p&gt;
	Some of this is dependent on the level of indirection you're working with. Is it managed code? Does it implement its own virtual machine or p-code? Is it a PE or ELF file? Can you identify how the program is installed, and what files and registry settings it affects when installed? Does it install any protocol handlers (ViewPlgs.exe may help)? Does it register or call any services? What libraries does it depend on? Does it contain any strings in the binary that appear to be banned functions (you can do this using BinScope under Windows)? Do you have debugging info, or is the binary stripped? Do you have a symbol table, or can you identify them or download/import them? Does the code contain any easily identifiable or interesting components (you can use signsrch to help with this)? Can you inject shared libraries and what is their affect? Is the binary or its source code using any self-modifying or self-checking code (again, signsrch may help here)? Is there an underlying protocol with a known specification (e.g. IETF RFC) available, or can it be elicited or reverse engineered easily?&lt;/p&gt;
&lt;p&gt;
	If you've come this far with a few conclusions (but no results), you will need to design a methodology for code audting. I suggest checking out chapter 4 of &amp;quot;The Art of Software Security Assessment&amp;quot; in order to learn about external flow sensitivity and tracing direction. You'll probably want to consume all of the information available here --&amp;nbsp;&lt;a href=&quot;http://pentest.cryptocity.net/reverse-engineering/&quot; rel=&quot;nofollow&quot;&gt;http://pentest.cryptocity.net/reverse-engineering/&lt;/a&gt;&lt;/p&gt;</description>
<category>Reverse Eng.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/30/tool-method-for-unknown-network-binary-protocol-analysis#a100</guid>
<pubDate>Tue, 05 Apr 2011 22:50:39 +0000</pubDate>
</item>
<item>
<title>Answered: hey guys....is their any documentation on XSSF for metasploit?</title>
<link>http://www.ask-a-pentester.com/index.php/59/hey-guys-is-their-any-documentation-on-xssf-for-metasploit#a99</link>
<description>&lt;p&gt;
	This is the best resource about how to accomplish installing XSSF with Metasploit:&lt;/p&gt;
&lt;p&gt;
	&lt;a rel=&quot;nofollow&quot; href=&quot;http://securitystreetknowledge.com/?p=445&quot;&gt;http://securitystreetknowledge.com/?p=445&lt;/a&gt;&lt;/p&gt;</description>
<category>Frameworks</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/59/hey-guys-is-their-any-documentation-on-xssf-for-metasploit#a99</guid>
<pubDate>Tue, 05 Apr 2011 22:45:23 +0000</pubDate>
</item>
<item>
<title>Answered: SVN update via a web proxy?</title>
<link>http://www.ask-a-pentester.com/index.php/66/svn-update-via-a-web-proxy#a98</link>
<description>You can setup your own rouge git or svn server inside a company/organization that has a pedantic firewall configuration by using chownat</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/66/svn-update-via-a-web-proxy#a98</guid>
<pubDate>Tue, 05 Apr 2011 22:43:46 +0000</pubDate>
</item>
<item>
<title>Answered: Wget download ONLY PHP file</title>
<link>http://www.ask-a-pentester.com/index.php/78/wget-download-only-php-file#a97</link>
<description>The easiest way to grab a PHP file if you do not already have access to the web server is to either brute-force SSH/etc access (depending on open ports available on that server) or to find a file read inclusion vulnerability, PHP eval vulnerability, or a SQL injection vulnerability that allows for, say, a MySQL load file operation.&lt;br /&gt;
&lt;br /&gt;
Shortcuts:&lt;br /&gt;
&lt;br /&gt;
./fimap.py -v 3 -u &amp;quot;&lt;A HREF=&quot;http://owaspbwa/mutillidae/index.php?page=index.php&quot; rel=&quot;nofollow&quot;&gt;http://owaspbwa/mutillidae/index.php?page=index.php&lt;/A&gt;&amp;quot; -b -x&lt;br /&gt;
&lt;br /&gt;
./wapiti.py http://owaspbwa/peruggia/ -v 2 -b folder -f txt -o p2.txt -m &amp;quot;-all,blindsql,sql&amp;quot;&lt;br /&gt;
&lt;br /&gt;
./sqlmap.py -v 6 --delay=0 --predict-output --keep-alive --null-connection --dbms=MySQL -u &amp;quot;&lt;A HREF=&quot;http://owaspbwa/peruggia/index.php?action=comment&amp;amp;pic_id=1&quot; rel=&quot;nofollow&quot;&gt;http://owaspbwa/peruggia/index.php?action=comment&amp;amp;pic_id=1&lt;/A&gt;&amp;quot; -p pic_id --level 5 --risk 3 --sql-query=&amp;quot;load_file('/var/www/peruggia/index.php')&amp;quot;&lt;br /&gt;
&lt;br /&gt;
./sqlmap.py -v 6 --delay=0 --predict-output --keep-alive --dbms=MySQL -u &amp;quot;&lt;A HREF=&quot;http://owaspbwa/peruggia/index.php?action=login&amp;amp;check=1&quot; rel=&quot;nofollow&quot;&gt;http://owaspbwa/peruggia/index.php?action=login&amp;amp;check=1&lt;/A&gt;&amp;quot; --data &amp;quot;username=a&amp;quot; -p username --level 5 --risk 3 --sql-query=&amp;quot;load_file('/var/www/peruggia/index.php')&amp;quot;</description>
<category>Tools</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/78/wget-download-only-php-file#a97</guid>
<pubDate>Tue, 05 Apr 2011 22:40:57 +0000</pubDate>
</item>
<item>
<title>Answered: THE question: CEH or OSCP?</title>
<link>http://www.ask-a-pentester.com/index.php/71/the-question-ceh-or-oscp#a96</link>
<description>CREST Team Leader / Team Member</description>
<category>Career, Certs, etc.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/71/the-question-ceh-or-oscp#a96</guid>
<pubDate>Tue, 05 Apr 2011 22:33:14 +0000</pubDate>
</item>
<item>
<title>Answered: Which guide would you recommend to understand Backtrack</title>
<link>http://www.ask-a-pentester.com/index.php/39/which-guide-would-you-recommend-to-understand-backtrack#a94</link>
<description>&lt;p&gt;
	There is a book coming out soon on BackTrack --&amp;nbsp;&lt;a rel=&quot;nofollow&quot; href=&quot;http://www.amazon.com/BackTrack-Assuring-Security-Penetration-Testing/dp/1849513945/&quot;&gt;http://www.amazon.com/BackTrack-Assuring-Security-Penetration-Testing/dp/1849513945/&lt;/a&gt;&lt;/p&gt;</description>
<category>Distros</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/39/which-guide-would-you-recommend-to-understand-backtrack#a94</guid>
<pubDate>Tue, 05 Apr 2011 22:23:03 +0000</pubDate>
</item>
<item>
<title>SAP security research, first steps?</title>
<link>http://www.ask-a-pentester.com/index.php/53/sap-security-research-first-steps</link>
<description>Hi everyone,&lt;br /&gt;
&lt;br /&gt;
I would like to start learning and experimenting with SAP security because... well, because one can do a lot of money in the field, I've heard ;)&lt;br /&gt;
&lt;br /&gt;
Unfortunately I find it quite difficult to get either SAP software or documentation.&lt;br /&gt;
&lt;br /&gt;
Could anyone please give me some advice?&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
I would appreciate it very much!&lt;br /&gt;
&lt;br /&gt;
Rey Misterio</description>
<category>Web Hacking</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/53/sap-security-research-first-steps</guid>
<pubDate>Tue, 18 Jan 2011 09:17:46 +0000</pubDate>
</item>
<item>
<title>Could anybody explain me how does a &quot;bit flipping&quot; attack work?</title>
<link>http://www.ask-a-pentester.com/index.php/22/could-anybody-explain-me-how-does-a-bit-flipping-attack-work</link>
<description>Hi,&lt;br /&gt;
&lt;br /&gt;
I'm auditing a custom web application for a customer, concretely the crypto part of it. I've managed to get some encrypted data in transit from a client browser to the webserver. Since I know the format of the cleartext (it's documented) a colleague suggested that we could try a &amp;quot;bit flipping&amp;quot; attack.&lt;br /&gt;
&lt;br /&gt;
I've read about it online but I don't quite grasp it.&lt;br /&gt;
&lt;br /&gt;
Could anybody please explain it to me (with as little algebra as possible? ;))&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Thanks in advance!&lt;br /&gt;
&lt;br /&gt;
Rey Misterio</description>
<category>Programming</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/22/could-anybody-explain-me-how-does-a-bit-flipping-attack-work</guid>
<pubDate>Wed, 05 Jan 2011 13:29:11 +0000</pubDate>
</item>
<item>
<title>About &quot;NOP&quot; slides in JS Heap Overflows</title>
<link>http://www.ask-a-pentester.com/index.php/9/about-nop-slides-in-js-heap-overflows</link>
<description>I don't understand how 0x0c0c can be used as a &amp;quot;NOP&amp;quot; slide in Javascript's Heap Overflows. Can anybody please explain it to me?&lt;br /&gt;
&lt;br /&gt;
Thanks in advance! :)</description>
<category>Exploit devel.</category>
<guid isPermaLink="true">http://www.ask-a-pentester.com/index.php/9/about-nop-slides-in-js-heap-overflows</guid>
<pubDate>Sun, 12 Dec 2010 14:55:06 +0000</pubDate>
</item>
</channel>
</rss>
