SS-RAT 2.0 Alpha-2 is out!
With a lot more functionality than the first alpha, SS-RAT v2 is now available to download. It is totally open source like all of Slayers projects, and is available from the google code repo here...
https://code.google.com/p/schwarzesonenrat/
I am refraining from writing more detailed stuff on it until its final release:)
BT5 Revision 1 is out tomorrow :D
Tuesday, 9 August 2011
LokiRAT leaked source code
Just a quick post - LokiRAT, a little known PHP RAT (as in, controlled by a PHP script that acts as a proxy between commander and slave) has had its C# source leaked.
http://dl.dropbox.com/u/36983782/Source.rar
Converting to C++ and adding some/removing some features is a project I am working on in my free time - I want to remove useless crap and add a Hijack Proxy feature.
http://dl.dropbox.com/u/36983782/Source.rar
Converting to C++ and adding some/removing some features is a project I am working on in my free time - I want to remove useless crap and add a Hijack Proxy feature.
Friday, 5 August 2011
BackTrack Linux and ExploitDB under DDoS or something?
See the video, note the date and time, I just recorded it there and converted it.
I think someones being an arsehole again to the OffSec team :(
DDoS is no fun!
I think someones being an arsehole again to the OffSec team :(
DDoS is no fun!
Thursday, 4 August 2011
Remember - sudo as an access control is UNIVERSALLY STUPID!
Hi, this is Darren again, showing how poorly set SUDO privs can REALLY ruin your day.
We have made a user (fuck) with a password of (fuck) and given the silly fucker access to "less" via SUDO.
Now lets REALLY ruin the sysadmins life, by giving FUCK root with a few commands!
See the video - it shows how it works :D
Remember - sudo as an access control is UNIVERSALLY STUPID! Use it as an AUDIT tool for logs instead!
~I take no responsibility for use of this here infodox. Use wisely
We have made a user (fuck) with a password of (fuck) and given the silly fucker access to "less" via SUDO.
Now lets REALLY ruin the sysadmins life, by giving FUCK root with a few commands!
See the video - it shows how it works :D
Remember - sudo as an access control is UNIVERSALLY STUPID! Use it as an AUDIT tool for logs instead!
~I take no responsibility for use of this here infodox. Use wisely
Wednesday, 3 August 2011
Tutorials by Hex - WEP cracking (GERIX) and MAC Spoofing
Seeing as Hex cannot be fucked mantaining a blog, and I can, and we are working together on writing tutorials, making videos, etc... We decided that I would republish his manuals here :)
http://dl.dropbox.com/u/36983782/WEPcrackingforidiots.pdf
That is his WEP cracking guide...
http://dl.dropbox.com/u/36983782/macspoofingforidiots.pdf
That is the MAC spoofing guide...
Enjoy, and remember - dont be malicious!
http://dl.dropbox.com/u/36983782/WEPcrackingforidiots.pdf
That is his WEP cracking guide...
http://dl.dropbox.com/u/36983782/macspoofingforidiots.pdf
That is the MAC spoofing guide...
Enjoy, and remember - dont be malicious!
Remote Admin Tools: DarkComet Tutorial/Overview
Get it here: http://dl.dropbox.com/u/36983782/darkcomet-tut.pdf
Now thing is, some people are going to say "LOL Dudes a skid RATS are for skids".
Ok, sure, whatever. Just remember: Poison Ivy is a RAT. Poison Ivy is an OLD RAT and it was SUCCESSFULLY used to pwn RSA.
Backdoors, malware, keyloggers, all that jazz, are actually a core feature in todays threat landscape, and therefore, I believe they CAN be useful in a penetration test - especially for mantaining access.
The PDF I link to is a primer on using one of the more common ones available. Try it - it is shocking how much one can do with em.
Now thing is, some people are going to say "LOL Dudes a skid RATS are for skids".
Ok, sure, whatever. Just remember: Poison Ivy is a RAT. Poison Ivy is an OLD RAT and it was SUCCESSFULLY used to pwn RSA.
Backdoors, malware, keyloggers, all that jazz, are actually a core feature in todays threat landscape, and therefore, I believe they CAN be useful in a penetration test - especially for mantaining access.
The PDF I link to is a primer on using one of the more common ones available. Try it - it is shocking how much one can do with em.
Monday, 1 August 2011
Minor setback - SSD drive sais no
Ok, I was GOING to post about integrating BeEF (Browser Exploitation Framework) and Metasploits Browser Autopwn to create a horrible mess of browser-based evilness... I was half way through writing it up when suddenly, everything ceased working. So I tried a reboot. "No bootable media". WTF.
So I cracked the Acer open and found that indeed, my SSD drive had seemingly *cooked* itself, and it was fucking ROASTING hot. It was removed for the sake of safety, and I am booting from USB now.
I am waiting to get a replacement hard disc (later today) and then will do TWO writeups, one on WEP cracking the lazy mans way (Gerix) and another on either BeEF or some features of SET or something. I will also retake some screenshots of browser-autopwn, fun with those Netopia Routers (what does this command do?) and a few other things.
Also, photos of insides of the Acer for the hell of it lol, and a shot of my toolkit I used to pry it open in College.
So I cracked the Acer open and found that indeed, my SSD drive had seemingly *cooked* itself, and it was fucking ROASTING hot. It was removed for the sake of safety, and I am booting from USB now.
I am waiting to get a replacement hard disc (later today) and then will do TWO writeups, one on WEP cracking the lazy mans way (Gerix) and another on either BeEF or some features of SET or something. I will also retake some screenshots of browser-autopwn, fun with those Netopia Routers (what does this command do?) and a few other things.
Also, photos of insides of the Acer for the hell of it lol, and a shot of my toolkit I used to pry it open in College.
Subscribe to:
Posts (Atom)