2010
09.20

Written in Python, i try to make a simple fuzzer for FTP server. This script will try to fuzz the commands like APPE, USER, LIST, CWD, etc..you can find all commands here ;)

This script is simply a modified version from muts simple ftp fuzzer during offsec training :D

Hope you like it :)

Read More >>

2010
09.08

Metasploit has released DLLHijackAuditKit v2 to determine DLL vulnerabilities that still existing in the wild. This tool will scan possible DLL vulnerability and log the result to CSV file. DLLHijackAuditKit v2 can also make a PoC (will try to hijack the DLL and running calc.exe, of course this is optional) to be sent to the vendor (if necessary).

Download here and test your self.

taken from Metasploit Blog

2010
09.07

Dengan melakukan reverse engineering dan menganalisa kode sebuah program (assembler), kita bisa melakukan patching terhadap sebuah program dengan merubah alur program tersebut sesuai dengan yang kita inginkan.

Pada tulisan kali ini, saya akan coba sedikit menjelaskan bagaimana melakukan patching tersebut.

Read More >>

2010
09.03

Hack Is Wack!

Snoop Dogg + Norton mengadakan perlombaan nge-rap dengan tema anti cybercrime… :D

2010
09.02

SQLMap is the tool to automate SQL Injection vulnerability exploitation. This tool is very popular to exploit the SQL Injection vulnerability. While most of web hacker enthusiast knew about this tool to gather information and retrieves the tables information, i try to share this information about the powerful of SQLMap rather than just as “a database dumper tool”.

I will separate this in 3 section, as a fingerprinter (we already knew this), as an enumerator (of course), and as a destroyer (hmm..?!). Check it out.

Read More >>

2010
09.01

Pada Defcon 18 tahun ini, Michael Schearer (“theprez98″), mempresentasikan Shodan sebagai “tools” bagi para pentester, lalu bagaimana memanfaatkan Shodan sebagai “tools” untuk pentesting..? untuk lebih jelasnya anda bisa membaca presentasi theprez98, atau langsung melihat video presentasinya(vimeo).

2010
09.01

Selama bulan September ini, Abysssec Security Team akan merilis berbagai 0day, termasuk analisanya beserta poc-nya. (link)