# Thursday, November 13, 2008

I just found a new tool on OWASP site webslayer, this tool is only w32 right now, which bites but the tool is AWESOME!

the payload generator is awesome, as well as the complex rules you can quickly define to test a site. 31337

posted on Thursday, November 13, 2008 10:00:17 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Tuesday, October 28, 2008

Im sure we all know of slurping by now but I just came across this site for windows command ninja skills. with that I took the time to update my slurp tool with some hacks I just didnt think about using. As well as some uses for NET that I didnt know about.

I have attached a copy of one of the slurp scripts I run, your milage will vary but you should get a lots of Ideas from it if you know whats going down. (I also just fixed that my server wasnt serving up batch files)

File Attachment: slurp.bat (14 KB)


posted on Tuesday, October 28, 2008 9:51:11 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Friday, October 03, 2008
Here is a fun thing I just ran into. Kiosk with usb port but a custom keyboard with no buttons to get into things (no start alt ctl del etc) and no explorer.exe shell so I cant "hack" this kiosk.. haha

why try the hard things to get into the device, BYOUSBK that is bring your own usb keyboard, I like the roll up ones plug it in and have some fun haha.

posted on Friday, October 03, 2008 2:48:27 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Wednesday, September 24, 2008

ShoreTel Phone system 8.0 recently put L16/256 "Linear Broadband 256kbps" as the default #1 codec to use phone to phone, However the newest copy of Cain will not identify this as a call - I assume its because of the bandwidth used. Now you can change the server to not use this bandwidth and keep on the 128k but for my current classroom material and pentesting this isn't a plausible case. I would like cain to auto-magically detect and dump the 256k stream.

Name/ Clock/ Bandwidth/ Description
L16 256/ 16000/ 256 Kbps/ Linear 16-bit Audio 256 Kbps

update: here is the handshake data with info

t=0 0
m=audio 5004 RTP/AVP 110
a=rtpmap:110 LRWB/16000
a=sendrecv
a=ptime:20

update2: cain now supports this codec, wireshark get this on the dev I cant find anywhere to request this.

I also put the notes into NetworkObserver


posted on Wednesday, September 24, 2008 2:34:44 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Thursday, August 21, 2008

here is a fun site that keeps a record of all the speed traps, cameras, and red light cameras

you can export the data into a CVS file that you can then put into your various device (garmen, blackberry …) anything with a GPS ability. even the uniden scanners have a hack nifty…

posted on Thursday, August 21, 2008 4:31:11 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Saturday, July 12, 2008
So if you didnt know, over the holiday weekend I fell off a 15ft clif and messed up my foot real good. Well as I was sitting on the couch all weekend I wanted to make a script to convert robots.txt files that are on webservers inito a nice little clickable HTML map for reporting and pen-testing. A little bash hacking and I Have a nice little working script. so I present - I think the worlds first robots.txt to HTML page converter.

update: changed the raw code to a file as Im tired of google hits with linux commands

robotReporter.sh (1.73 KB)
posted on Saturday, July 12, 2008 11:41:00 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Monday, June 30, 2008
so to update on a few fun tools I have found lately..

If you didnt know Backtrack3 is out get a copy
a strange search tool http://www.rapleaf.com\
PEBKAC - a fun tool to pull out the fat finger users

posted on Monday, June 30, 2008 6:59:34 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
I have to sit at a traffic flow system every day, you know the ramp meter system. So today I just noticed that they are easy to hack. If you give a car length away from a car infront of you (keep off the Tar filler for the sensor in the pavment) and the other car in traffic, and then once they get the green light and it turns red again pull foward over the sensor and bam green light. I assume they all work the same or close to it. give it a try and mess up the traffic a little more.

posted on Monday, June 30, 2008 6:50:58 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [1] Trackback
# Wednesday, June 04, 2008
posted on Wednesday, June 04, 2008 11:27:46 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Wednesday, May 21, 2008
So lets pose a problem, you have a computer with encrypted HDD and you cant reboot the PC. Or a comptuer has something worth getting in memory (encryption key) and you want it. But the computer is locked. well you can now hack this.

winlockpwn - tool to connect to windows with firewire and inject a dll hack into memory to bypass passwords on the "windows lock screen" and allow you access to windows with no password when locked.

if your not a linux power user, or just want to cheat here is a setup quide and if you use backtrack here is a post about it.

So a lot of people say it works, I agree that it will - it uses dll hacking for passwords, you can do this with the computer powered off or just hack it

so what did I get, nothing...

i get this error

IOError: [Errno 22] Invalid argument

from firewire.py, line 693: "If a node doesn't feel like fulfilling a request, it will raise an IOError."

now if you unplug the fw and plug it back in repeatedly running the script it will start scanning memory only to end with a device busy

seems that the "money time" is when the device is detected as a "Hard Drive" you start scanning the memory at that point. then the ipod comes in and all work ends

same issue on two computers

but who's to say Im just odd.

UPDATE: May22

I got it to work, who knows if I was sleepy or a reboot fixed it. But when I powered up. Started from "step 5" and followed steps exactly.

Dell630 fully patched on the domain and it worked! I had full access as advertised.

something I noticed was that this morning businfo has 1 on the node 0 and not 0 for all the data it spits out on what will and wont work.


posted on Wednesday, May 21, 2008 9:43:17 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Monday, May 12, 2008

So I got hooked into LinkedIn as I went crazy adding all my co-workers to get a friend base, I thought… I have been here before. I remember back in 2002 Adding friends to MySpace account. This is funny, adult myspace for the working professional. You can even upload a picture of yourself for what, to date?

All the funny social aside, this is a gold mine for social engineering. You have CxO level people all over the place adding each other and making connections.

Hello Mr.Thompson, My Name is Kelly I got your contact from John Doe who referred me to you for a security audit. I was wondering if i could find some time to meet with you next week. “Sure”

// or “yes kelly what is your last employer …google google”

…awesome

posted on Monday, May 12, 2008 3:36:02 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Thursday, February 21, 2008

I was just in the conference trying to swipe the memory from a laptop someone left there. Problem is that I had to remove the keyboard, then I broke my little screwdriver and when I did all this I realized I forgot my can of air. Then it was too late my memory had gone muy loco

 

This isn’t a "holy crap my shit is 3137 h4xor pwnd" but a "wow that’s a cool hack" sort of like Xbox running Linux or an oscilloscope that can print vector graphics from pong. This would be a cool Spy trick or uber 31337 bad guy. But if you wanted to get around it. You just use encrypted file mounts. I woudl imagine that the protection on the temporary mounts is protected or you just time out unmount the encrypted mount.

 

A elementary way to do this is the old keylogger. Works every time. I bet you arnt checking your docking station keyboard every morning? (thankyou centas for the use of the building custodial jumpsuit for access to your office)

 

I think the big thing here is dont let bad guys finger your ram!

 

Did you see all the things that will cause problems....

http://citp.princeton.edu/memory/faq/

 

I do want a copy of the RAM2USB boot application they have, as that would be handy in uses other then just hacking "secret keys"

 

or be totally insane and check this out

posted on Thursday, February 21, 2008 10:24:10 PM (Pacific Standard Time, UTC-08:00)  #    Comments [2] Trackback
# Friday, February 15, 2008

Things are very slow in the security world, I havent seen anything that is interesting lately. However in hardware hacking there is this way coool scope hack.

http://blog.makezine.com/archive/2007/08/youscope_oscilloscope_dem.html

 

posted on Friday, February 15, 2008 2:17:27 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Monday, January 07, 2008
if I ever helped you with your xbox1 there are a lot of updates you should find me for.

posted on Monday, January 07, 2008 11:13:47 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Thursday, January 03, 2008

Some Sites and things to hack in the new year…

WarGames

De-ICE Penetration Distro

OWASP Web Application hacking

You can do all this with the new Beta of BackTrack3 (late news post but better then never)

 

posted on Thursday, January 03, 2008 8:49:21 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
if you live under a rock and get all your security news from me, last month backtrack3 was released, if your 31337 then you allready know and have this installed.
posted on Thursday, January 03, 2008 2:57:13 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Thursday, December 13, 2007

here is a fun hack for website robot.txt files.

site:google.com "robots.txt" "disallow" filetype:txt

run that in a search string and you will get back the disallow strings for forced browsing, you can drop the site: modifier to get more data or change it to your target site.

posted on Thursday, December 13, 2007 12:21:27 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Wednesday, December 05, 2007

Here is a cool tool (OWASP WegGoat) that will test you on your hacker skills, from 31337 to nub3 you can see where you rank, I got to the last 4 modules and I didn’t have the skillz to continue (mostly the time to keep going)

I strongly recommend that if your interested in security / web security that you check out this project and run around the site to get learned. BTW a lot of my browser plug-ins will help you pass the quizzes.

Other things to hack, wargames, de-ice distro

posted on Wednesday, December 05, 2007 2:49:23 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Tuesday, December 04, 2007
So running around the interwebs today is a site form lifehacker to find people, Its actually a good site, there is some powerful information here that is quite usable. For instance I just found a interview i did but didn't think got published, but it did –here I am in print being quoted about the Atari 2600 hacking days.
posted on Tuesday, December 04, 2007 11:29:27 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Monday, December 03, 2007

damn, someone beat me to this, I have been working on this for a long time. I hope to get the source so that I can see where I was wrong…

Wireless Keyboard DeCryption

posted on Monday, December 03, 2007 9:36:50 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Thursday, November 29, 2007

I wanted to make a list of browser plug-ins that I use and find quite important to security and daily ops work.

First, for IE (I accidently upgraded to 7.0 and didn't feel like un-installing the behemoth)

  • Bayden Systems' TamperIE offers HTTPS form-tampering
    • sort of a mac-daddy tamper application to change your post data on the fly, must have.
  • Microsoft's IE Developer Toolbar
    • Change values on the fly also get header info and more right away
  • Microsoft's IE Powertoys for WebDevs
    • was cool but appears the highlight and show source dont work with IE7, however still works for DOM data so I keep it.

Now the giant list for FireFox (where all the 31337 users are)

  • AdBlockPlus
    • This is like going from dial up to DSL, the internet all the sudden becomes “sweet”
  • BlogJet
    • This is also in my IE, its my blogger application
  • DOM Inspector
    • handy for webdev and de-construction
  • DownloadThemAll
    • I dont like to click and this is a price-less tool for saving clicks.
  • GoogleBrowserSynch
    • I dont like how big google is and I dont like the idea of google watching what I browse, this was just an interesting tool since I am on lots of computers, I just dont have the guts to sign-in yet.
  • GoogleToolBar
    • this is a must, duh.
  • HttpHeaders
    • handy for webdev and de-construction
  • ModifyHeaders
    • handy for webdev and de-construction, and user-agent mods
  • NoScript
    • The only “security” leo laporte knows with out steve giving him a script. Handy for hacking things.
  • RefControl
    • spoof the referrer to the server.
  • PDF Download
    • sometime I like to download pdf’s sometimes I like to view them live, this lets me choose.
  • Tamper Data
    • same as TemperIE but for zilla
  • ULRParms
    • Different type of TamperData type plugin
  • User Agent Switcher
  • WebDev
    • This tools is mostly a must for anyone, you can quickly shut on and off and mod parts of sites.
Update June2008:
some good hack tools
http://www.securitycompass.com/exploitme.shtml
posted on Thursday, November 29, 2007 6:25:23 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Friday, August 31, 2007
a co-worker pointed out that shopping carts now have anti-theft. Further ideas about locking them while people were shopping are too funny, but leave it to the internet. Someone has allready done the shopping card lock. Great use of radio waves with the coil to pick up the data and replay it.
posted on Friday, August 31, 2007 2:28:33 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Wednesday, August 22, 2007
a cool book that I need to buy about Lego’s and Hacked products you can make with them
posted on Wednesday, August 22, 2007 2:58:25 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Friday, June 15, 2007

Im not saying hack a hotel for porn. But I will say you can hack it for free pay per view hbo movies they have. BYOTV (bring your own tv) poor Marriott, you must not enjoy the web. I dont know what's worse people that pay for porn. or that people actually watch hotel porn. yuck.

posted on Friday, June 15, 2007 4:17:07 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Thursday, June 14, 2007

this site get grandpas files will help you write letters to make some paper pusher mail you back FBI records of dead people. Most interesting is the fact that you can just prove someone is dead  no reference that you must be related. So you have a neighbor that died years ago and you can drum up some information on him or find on wikipedia that he is dead? better yet, you happen to come across a death record in the trash? find out if they were dooin bad things. Or just mail letters off and see what happens.

posted on Thursday, June 14, 2007 12:40:07 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Wednesday, June 13, 2007

I was browsing a pile of stuff in my room the other day to come across a package of sea-monkeys, I was reading the back of the package about a 2 year guarantee they have on those brine shrimp. The guarantee states that if you mail one dollar to the address shown they will replace your seeds for free (minus the handling of course) At no time the notice states that you must provide proof of purchase of the original monkey pack. So it stands to reason that if you mail one dollar you get what they state is a six dollar value. So I investigated sea monkey guarantee on line turns out they have the same deal on line however you must mail three dollars. The online version also states that you get some free literature about the monkeys. Im not saying that anyone should exploit the financial stability of the brine shrimp business, but its a good example of what you can find if you bend rules. So its up to you, pay 1–3 dollars and see what they mail back to you. Or buy it in the store.

posted on Wednesday, June 13, 2007 10:47:13 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [1] Trackback
# Tuesday, May 01, 2007

(Access Point)——Irongeek Ettercap Script———Gateway

This is something sort of fun that I just installed on my home wireless. Its actually very educational you can learn what type of code sends clear text passwords and what will not. Most interesting is using sites that attempt to prevent this type of attack and put fun data in the password fields. I installed ettercap in bridge mode so I have layer1 access to the data. (granted that ettercap did this all along this is just a fun way to show it off)

posted on Tuesday, May 01, 2007 8:44:44 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Sunday, April 29, 2007

a simple trick to get elevated command line from the screen saver, there are many ways to enter this data one fast trick is to use a linux reg editor its simple as making the logon script the command window. also works to do a command line of “copy cmd.exe logon.scr” this will work anywhere  but on domain controllers not booted in recovery mode. This is preventable with PGP disk encryption.

Windows Registry Editor Version 5.00

[HKEY_USERS\.DEFAULT\Control Panel\Desktop]
"ScreenSaverIsSecure"="0"
"ScreenSaveTimeOut"="15"
"ScreenSaveActive"="1"
"SCRNSAVE.EXE"="cmd.exe"

OEM data you changed

Windows Registry Editor Version 5.00

[HKEY_USERS\.DEFAULT\Control Panel\Desktop]
"ScreenSaverIsSecure"="0"
"ScreenSaveTimeOut"="600"
"ScreenSaveActive"="1"
"SCRNSAVE.EXE"="C:\\WINDOWS\\System32\\logon.scr"

posted on Sunday, April 29, 2007 1:46:29 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Monday, April 16, 2007
i posted a while back about swearing at the automated caller menus, that works a lot. But if not here is a great site keep this handy when you call a major corporation - get a human caller list
posted on Monday, April 16, 2007 10:24:25 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [1] Trackback
# Tuesday, April 03, 2007
I was browsing the FCC database today, the information in this database is insane. go look up a fcc ID today. Combined with the Patent Office search and you have all you need to hack things.
posted on Tuesday, April 03, 2007 11:33:27 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Tuesday, February 06, 2007

not hacking like warez

http://pinouts.ru

posted on Tuesday, February 06, 2007 4:07:37 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Thursday, December 14, 2006

google added patent search to the engine. this is just cool to refresh and look at random patents.

here are some weird ones

wetting doll   shark suit   underwear   brain cooler   skateboard   pocket protector   skunk

posted on Thursday, December 14, 2006 11:31:49 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Friday, July 28, 2006

haha this is a funny idea, proxy someones internet and just be mean. this is an example where they just flip images.

http://www.ex-parrot.com/~pete/upside-down-ternet.html

posted on Friday, July 28, 2006 1:43:52 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Thursday, June 08, 2006

there is something I hate as much as the RIAA now-a-days its this automated phone menu systems. whichever moron thought up the idea to talk to a computer rather then press 1,2,3 can get kicked. here is a healthy alternative to dealing with the computers, swear at them.

 

posted on Thursday, June 08, 2006 8:40:28 PM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Friday, March 31, 2006

some moron at Thoshiba thought it would be nice to light up the front of the SD-4980 DVD unit with a bright blue LED. Thats nice, I came to watch a movie not be distracted by your annoying DVD player. So as lame as this hack is, its a hack all the same. I haven't posted any hardware-mods for a while and I read on digg all the time how people get credit for putting a laptop HDD in a NES Game and thats lame. This is at least useful. idea is easy open it up and chop out the blue LED’s (red arrow) I included a picture for the fun of it.

Dvdhack

A simple yet needed hardware hack for the Toshiba SD-4980 DVD Player

posted on Friday, March 31, 2006 5:32:20 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Tuesday, February 28, 2006
i will have a hidden room in my house. http://www.hiddenpassageway.com/
posted on Tuesday, February 28, 2006 9:11:55 AM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Saturday, January 07, 2006

if you pretend to cancel with game fly you get this message

We'd really like to retain you as a GameFly subscriber and realize that not having the games available you wanted can be frustrating. To make this up to you, please let us offer you a special one time only one-month deal for $9.95. We are sure you will find renting our wide selection of games at GameFly a great experience over time.

 This was a FYI from KellyKeeton.com for gamefly discount coupon code or money saver what ever you want to call it.

 

posted on Saturday, January 07, 2006 3:16:10 PM (Pacific Standard Time, UTC-08:00)  #    Comments [0] Trackback
# Friday, November 11, 2005

So as you might know i have a large movie set up in my room allowing for Big Screen movie watching. Well this is very nice except there is a street light out my window. If you have a street light you know that its nice and a pain. Its only a pain when I don't want light. So I thought – what if i could turn off my street light at will?

Thats what I went to work doing. First one night I went out and broke open the service panel for the light, I then voltage tested the wires to figure out if I was working with 220v which I wasn't (this is good)

First step was obtaining a remote device such as this requirements are needed to be RF and able to handle 15 amps (not wanting to ever have it fry) I found one on ebay for $5

Then cutting off all the plastic and getting just the guts I tested to see if it shut off each leg of power or just the Hot (it was just the hot) so I chopped it up and ended up with this.

Light

Now was the tricky part late one night I went in and wired this into the circuit. Be aware – I cant shut off the mains so if you do this at home, your actually wiring this into a hot circuit. Don't be dumb and watch your tools and watch where the wires run when you arnt using them (cap them when your not working with the hot wires so you don't hit them)

after I had the unit plugged in and tested for voltage I covered it with waterproofing spray on wax then electrical tape. (all while hot)

Then since it was night I tested (boo yea it works) I then went to my house and it didn't work. Well after opening up the remote and finding the antenna lead (the obvious output from the RF modulator circuit) I soldered a two inch wire (antenna) on the unit to extend the ability for output. That fixed my range issue. Now I can watch movies or have fun with local kids playing soccer!

Don't try this at home.

posted on Friday, November 11, 2005 8:44:38 AM (Pacific Standard Time, UTC-08:00)  #    Comments [2] Trackback
# Friday, May 20, 2005

today i finished up a “draft” install of my stereo still have a few large bugs to work out but its coming along. here is a photo of the most noticeable features.

Video

posted on Friday, May 20, 2005 1:18:17 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Wednesday, May 11, 2005

uh oh Real-ID Passes U.S. Senate 100-0

anyone else have this long agreement for hotmail today? looks like new pasport services. make sure when you log into hotmail you go to the “security settings” then look for Marketing preferences and opt out of all the advertisment

fun of the day – hack your honda/acura Nav.

posted on Wednesday, May 11, 2005 6:01:18 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Friday, May 06, 2005

been a slow week. time to start the “kelly to days” countdown again 2 weeks and counting now. 10 days for those of you who operate on a 5day week. I will be travelling to WWU(b-ham) this weekend for a Disco party so look for the pictures later, they should be good.

Go hack something this weekend.

IIS6

Pepsi machine

coke machine

posted on Friday, May 06, 2005 5:07:33 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [0] Trackback
# Sunday, May 01, 2005

another night on the town. Fernando came to town and we went and had some fun in belltown. it was fun evening. started off at erin’s bro’s then went and paid 10 cover (damn Seattle) Chris and i danced so much that i was sweaty as high school PE. then we found a purse and i put my business card in the wallet in the purse. no idea whos it was. then i took some artsy pictures. then chris and i danced like mad men and we owned the club. crazy chicks would stare but they dug us. one girl told me i wasn't for real. not sure what she ment. i told her i usta back up dance for shakeria. seriously we rocked. i should be 3 lbs lighter form all the dancing. out of 5 stars this gets a 3 star evening. even got a cream cheese hot dog… mmmmmm.

also finished a very successful Fiberglas job to modify the factory sob box in my car to fit a 10” diamond sub. i am very happy with this

posted on Sunday, May 01, 2005 5:57:29 AM (Pacific Daylight Time, UTC-07:00)  #    Comments [1] Trackback