Straight from brew when you first install metasploit:
Metasploit can be updated in-place by doing:
cd `brew --prefix metasploit`/libexec/
svn up
Wednesday, June 27, 2012
Monday, June 4, 2012
My tech/infosec subreddits
Bookmark this page for good times:
http://www.reddit.com/r/commandline+cli+netsec+blackhat+bash+asknetsec+hackers+linux+linux4noobs+linuxadmin+linuxmint+networking+pwned+sysadmin+ubuntu
http://www.reddit.com/r/commandline+cli+netsec+blackhat+bash+asknetsec+hackers+linux+linux4noobs+linuxadmin+linuxmint+networking+pwned+sysadmin+ubuntu
Labels:
Just For Fun,
Web
Thursday, May 31, 2012
From LM to NTLM passwords in John the Ripper
so you dump some passwords from a machine and you see it contains LM and NTLM hashes. obviously LM is quicker to crack so you go for that one first and it gives you the uppercase plaintext password:
which provides the plaintext uppercase password "KITTENBOOTIES". Great, now we need the real password, the one with upper/lower cases. we do this easily by supplying the "KITTENBOOTIES" password as the wordlist (with mangling) to john again. so do this:
This will output the proper password of "kiTTenBooTiES"
shablam!
./john --format=lm /root/hashes
which provides the plaintext uppercase password "KITTENBOOTIES". Great, now we need the real password, the one with upper/lower cases. we do this easily by supplying the "KITTENBOOTIES" password as the wordlist (with mangling) to john again. so do this:
echo KITTENBOOTIES > wordlist1 ./john -rules --format=nt /root/hashes --wordlist=wordlist1
shablam!
Labels:
Password Cracking
Tuesday, May 29, 2012
shut bonjour up
Bonjour makes a lot of annoying noise from a mac when you are trying to do some traffic analysis. you can help that by disabling bonjour's multicasts with:
sudo defaults write /System/Library/LaunchDaemons/com.apple.mDNSResponder ProgramArguments -array-add "-NoMulticastAdvertisements"
SANs guide to basics of securing datacenters and their location
http://www.sans.org/reading_room/whitepapers/awareness/data-center-physical-security-checklist_416
Labels:
Physical
Friday, May 18, 2012
Make your bash usage/movement faster and more efficient
http://www.bigsmoke.us/readline/shortcuts
Labels:
Bash
Sudo doesnt work with "&&" and various other bash keywords
Lets say I want to run apt update and upgrade one after another. Typically you do this with:
Unfortunately, oftentimes you need root permissions to do that. So a person will usually simply type:
And if you hit enter, "apt-get update" will run successfully and "apt-get upgrade" will fail. This is do to the fact that when you hit enter, bash has to interpret the line you just submitted. And according to the rules of bash, your line was interpreted to mean three things. First run "sudo apt-get update" then if that returns an execution code of 0, then continue to "apt-get upgrade".
What you want to do is send your WHOLE line to sudo for execution. You do this with the "-s" argument of sudo. so that:
Of course my short way is usually simply typing "sudo !!" after i mess up the line, it works just fine.
apt-get update && apt-get upgradeUnfortunately, oftentimes you need root permissions to do that. So a person will usually simply type:
sudo apt-get update && apt-get upgradeAnd if you hit enter, "apt-get update" will run successfully and "apt-get upgrade" will fail. This is do to the fact that when you hit enter, bash has to interpret the line you just submitted. And according to the rules of bash, your line was interpreted to mean three things. First run "sudo apt-get update" then if that returns an execution code of 0, then continue to "apt-get upgrade".
What you want to do is send your WHOLE line to sudo for execution. You do this with the "-s" argument of sudo. so that:
sudo -s 'apt-get update && apt-get upgrade'Of course my short way is usually simply typing "sudo !!" after i mess up the line, it works just fine.
Labels:
Bash
Thursday, May 17, 2012
Learning to love the man
manpages are awesome. some people tend to think there are only manpages for programs, which is completely not true. take for example "man ascii" or "man hier" which display the ascii tables and an explanation of the purpose of each unix directory respectively. You can discover where the manpages on your system are located by executing 'manpath'. This will output a list of directories in a similar format to "echo $PATH". Look through the directories to find the 7zipped files containing the manpage data.
I've gotten into the habit of opening each one just out of curiosity. Its actually kind of fun if you have nothing to do.
I've gotten into the habit of opening each one just out of curiosity. Its actually kind of fun if you have nothing to do.
SSH Inception
I must go deeeeper -_-
I have a box on a network that is only accessible via connecting to multiple SSH boxes in succession. the "-t" option in ssh allows me to go straight through all the boxes using one line:
You literally just chain together as many ssh connections as you'd like. They just pass the arguments on and on. If you alias that to something like:
then you should be all set.
I have a box on a network that is only accessible via connecting to multiple SSH boxes in succession. the "-t" option in ssh allows me to go straight through all the boxes using one line:
ssh user@vps.com -t ssh user@homeserver -t ssh user@home-desktopYou literally just chain together as many ssh connections as you'd like. They just pass the arguments on and on. If you alias that to something like:
et-phone-home="ssh user@vps.com -t ssh user@homeserver -t ssh user@home-desktop"then you should be all set.
Subscribe to:
Posts (Atom)