Wednesday, October 3, 2012

Regex for PHP serialized data

This is the regex string to use when searching through a document for serialized data.

/^(i|s|a|o|d)(.*);/si

I got it from here: http://regex-test.com/library/entry/check_if_serialized/16

Tuesday, September 25, 2012

John The Ripper Formats

http://pentestmonkey.net/cheat-sheet/john-the-ripper-hash-formats

Friday, September 14, 2012

VIM commands in GUI text editor

I used textmate for quite a long time, but my biggest gripe was that i couldnt run VIM commands in it natively. Then my friend told me about MacVIM (http://code.google.com/p/macvim/). I've been enjoying it quite a bit ever since i downloaded it.

It allows me to run all the VIM commands i'm used to while still having the clickyness of a GUI.

yay.

Tuesday, August 14, 2012

Troll Tricks #2

"Let me log into the server to check my mail...ALRIGHT, WHO THE FUCK DID THAT?"
*Supressed childish giggle*

Who wouldn't want to be greeted by nyan cat when they log into their terminal? Its so cute and fluffy and pop-tarty. I think some people dont quite appreciate the grace and elegance of the whiskered space-poptart. Lets enhance their experience with the gift of NYAN.

sudo -s "echo telnet miku.acm.uiuc.edu >> /home/user/.bashrc"

Now whenever they decided to join the server, they can join the fun!

*What this basically does is telnet straight to a server that NYAN's the crap out of them until they enter the telnet escape sequence 'ctrl+[' when they then type quit + enter, it drop them back to their shell.
**this is the nice way of doing it, you can always put in an "exit" right after so it doesnt drop them to shell.

Troll Tricks #1

"Hey steve, what services are running on our server"
"Let me see here, wait...what the fuck? we are running LOLCATS and LOLDONGS and ftp?"
* suppressed childish giggle*


In our first installment of troll tricks, I shall teach you how to modify the port descriptions in linux. Typically when you run a command like "netstat -tlp" or "ss", it will give you the actual name of the port that the number is associated with. 22=ssh, 23=telnet, 25=smtp, and so on. What a bunch of people dont realize is that you can change the text of the reported port, so that 22=LOLCATS, 23=LOLDONGS, and whatever else you'd like. The best part is the changes take place immediately and have no real impact on the server whatsoever.

The secret key to the whole troll is a certain file:
/etc/services

This is the file that holds all the corresponding associations. Simply run:
sudo vi /etc/services

and modify whatever entries you'd like. Now, the next time someone runs a command that interprets port number to port name, it will give the new port name.

It's just that simple. Change back when you are done and everything is back to normal.

Monday, August 13, 2012

Test Internet Bandwidth via command line

Got this from a stackoverflow article:

wget --output-document=/dev/null http://speedtest.wdc01.softlayer.com/downloads/test500.zip

Tuesday, August 7, 2012

How to bridge two linux interfaces

Create the bridge table:
brctl addbr bridgename

then add the interfaces to the bridge
brctl addif eth1
brctl addif eth2

Wednesday, July 18, 2012

List entire directory paths for remote FTP directory

I use this all the time to quickly search for fancy filenames in FTP servers that allow for anonymous logins. It basically is a for loop to log into each server, run the find command which outputs absolute paths for directories and files, and outputs that to a file with a name as the IP.
for i in `cat ftp_anon_hosts`; do echo FTP LIST $i; lftp -e "find;QUIT" anonymous:anonymous@$i > ftp/$i; done

Tuesday, July 17, 2012

Rainbow Tables for rcracki

Download links are all right here:

http://www.freerainbowtables.com/tables2/

Thursday, July 12, 2012

Empty/null hashump (LM/NTLM)

aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0

is the LM/NTLM hash pair for blank passwords. You can create this pair by running

"net user kittens /add"

and it will result in:

"kittens:1005:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::"

This is an easy way to tell if the hash you have is actually a password or not.