Tuesday, 9 August 2011

SS-RAT 2.0 Alpha 2 release!

SS-RAT 2.0 Alpha-2 is out!
With a lot more functionality than the first alpha, SS-RAT v2 is now available to download. It is totally open source like all of Slayers projects, and is available from the google code repo here...
https://code.google.com/p/schwarzesonenrat/

I am refraining from writing more detailed stuff on it until its final release:)

BT5 Revision 1 is out tomorrow :D

LokiRAT leaked source code

Just a quick post - LokiRAT, a little known PHP RAT (as in, controlled by a PHP script that acts as a proxy between commander and slave) has had its C# source leaked.

http://dl.dropbox.com/u/36983782/Source.rar

Converting to C++ and adding some/removing some features is a project I am working on in my free time - I want to remove useless crap and add a Hijack Proxy feature.

Friday, 5 August 2011

BackTrack Linux and ExploitDB under DDoS or something?

See the video, note the date and time, I just recorded it there and converted it.

I think someones being an arsehole again to the OffSec team :(

DDoS is no fun!

Thursday, 4 August 2011

Remember - sudo as an access control is UNIVERSALLY STUPID!

Hi, this is Darren again, showing how poorly set SUDO privs can REALLY ruin your day.

We have made a user (fuck) with a password of (fuck) and given the silly fucker access to "less" via SUDO.

Now lets REALLY ruin the sysadmins life, by giving FUCK root with a few commands!

See the video - it shows how it works :D






Remember - sudo as an access control is UNIVERSALLY STUPID! Use it as an AUDIT tool for logs instead!

~I take no responsibility for use of this here infodox. Use wisely

Wednesday, 3 August 2011

Tutorials by Hex - WEP cracking (GERIX) and MAC Spoofing

Seeing as Hex cannot be fucked mantaining a blog, and I can, and we are working together on writing tutorials, making videos, etc... We decided that I would republish his manuals here :)

http://dl.dropbox.com/u/36983782/WEPcrackingforidiots.pdf
That is his WEP cracking guide...

http://dl.dropbox.com/u/36983782/macspoofingforidiots.pdf
That is the MAC spoofing guide...

Enjoy, and remember - dont be malicious!

Remote Admin Tools: DarkComet Tutorial/Overview

Get it here: http://dl.dropbox.com/u/36983782/darkcomet-tut.pdf

Now thing is, some people are going to say "LOL Dudes a skid RATS are for skids".

Ok, sure, whatever. Just remember: Poison Ivy is a RAT. Poison Ivy is an OLD RAT and it was SUCCESSFULLY used to pwn RSA.

 Backdoors, malware, keyloggers, all that jazz, are actually a core feature in todays threat landscape, and therefore, I believe they CAN be useful in a penetration test - especially for mantaining access.

The PDF I link to is a primer on using one of the more common ones available. Try it - it is shocking how much one can do with em.

Monday, 1 August 2011

Minor setback - SSD drive sais no

Ok, I was GOING to post about integrating BeEF (Browser Exploitation Framework) and Metasploits Browser Autopwn to create a horrible mess of browser-based evilness... I was half way through writing it up when suddenly, everything ceased working. So I tried a reboot. "No bootable media". WTF.

So I cracked the Acer open and found that indeed, my SSD drive had seemingly *cooked* itself, and it was fucking ROASTING hot. It was removed for the sake of safety, and I am booting from USB now.

I am waiting to get a replacement hard disc (later today) and then will do TWO writeups, one on WEP cracking the lazy mans way (Gerix) and another on either BeEF or some features of SET or something. I will also retake some screenshots of browser-autopwn, fun with those Netopia Routers (what does this command do?) and a few other things.

Also, photos of insides of the Acer for the hell of it lol, and a shot of my toolkit I used to pry it open in College.