header image
Home
Incognito Integrated Into Metasploit
Blog
May 07, 2008 at 07:43 PM

I just read a brilliant blog post on Carnal0wnage.  Luke Jennings' Incognito has been integrated into metasploit.  Check out Luke's recent paper if you missed it.

In a nutshell, if you get SYSTEM level access to a box (e.g. MSSQL database) and a domain user is logged into that box, then you can use meterpreter (or the original incongnito tools if your prefer) to impersonate that user.   Equivalently, if you want to be a domain admin then find out where he is logged in, and if you can own that box, then you can become a domain admin.

CG walks you through exactly how to use new features of incognito.  You might also want to check out his first post on this topic too. 

Last Updated ( May 07, 2008 at 07:57 PM )
SQL Injection Where You Wouldn't Have Thought It Possible
Blog
Apr 24, 2008 at 08:23 PM

David Litchfield just released a new paper: "A New Class of Vulnerability in Oracle: Lateral SQL Injection".

It's a quick read at only 4 pages and very well explained if you're a pentesting-type.  Well worth a read.

Last Updated ( Apr 24, 2008 at 08:24 PM )
Yaptest Update: v0.1.1
Blog
Apr 20, 2008 at 05:39 PM

Version 0.1.1 of yaptest is now available.

There are some improvements to the API, bug fixes for Linux users, enhanced support for bannergrab, sslscan and ldapsearch.

See below for the full change log... 

Last Updated ( Apr 20, 2008 at 05:44 PM )
Read more...
<< Start < Previous 1 2 3 4 Next > End >>