Tuesday, July 13, 2010

Metasploit 3.4.1 Released!

Metasploit - One of the most widely used penetration testing framework has released the Version 3.4.1 with adding 16 exploits, 22 auxiliary modules, and 11 meterpreter scripts. All 587 exploit modules have been updated to include the Disclosure Date field. Major features added since 3.4.0 include the RAILGUN meterpreter extension by Patrick HVE and the PHP Meterpreter payload by egypt. The Windows installer now ships with support for PostgreSQL database backends.

Get it from: http://www.metasploit.com/

v3.4.1 Release notes (copied from the above site):

Statistics
  • Metasploit now has 567 exploits and 283 auxiliary modules (up from 551 and 261 in v3.4)
  • Over 40 community reported bugs were fixed and numerous interfaces were improved
General
  • The Windows installer now ships with a working Postgres connector
  • New session notifications now always print a timestamp regardless of the TimestampOutput setting
  • Addition of the auxiliary/scanner/discovery/udp_probe module, which works through Meterpreter pivoting
  • HTTP client library is now more reliable when dealing with broken/embedded web servers
  • Improvements to the database import code, covering NeXpose, Nessus, Qualys, and Metasploit Express
  • The msfconsole "connect" command can now speak UDP (specify the -u flag)
  • Nearly all exploit modules now have a DisclosureDate field
  • HTTP fingerprinting routines added to some exploit modules
  • The psexec module can now run native x64 payloads on x64 based Windows systems
  • A development style guide has been added in the HACKING file in the SVN root
  • FTP authentication bruteforce modules added
Payloads
  •  Some Meterpreter scripts (notably persistence and getgui) now create a resource file to undo the changes made to the target system.
  • Meterpreter scripts that create logs and download files now save their data in the ~.msf3/logs/scripts folder.
  • New Meterpreter Scripts:
    • enum_firefox - Enumerates Firefox data like history, bookmarks, form history, typed URLs, cookies and downloads databases.
    • arp_scanner - Script for performing ARP scan for a given CIDR.
    • enum_vmware - Enumerates VMware producst and their configuration.
    • enum_powershell - Enumerates powershell version, execution policy, profile and installed modules.
    • enum_putty - Enumerates recent and saved connections.
    • get_filezilla_creds - Enumerates recent and saved connections and extracts saved credentials.
    • enum_logged_on_users - Enumerate past users that logged in to the system and current connected users.
    • get_env - Extracts all user and system environment variables.
    • get_application_lits - Enumerates installed applications and their version.
    • autoroute - Sets a route from within a Meterpreter session without the need to background the sessions.
    • panda_2007_pavsrv53 - Panda 2007 privilege escalation exploit.
  • Support for a dns bypass list added to auxiliary/server/fakedns. It allows the user to specify which domains to resolve externally while returning forged records for everything else. Thanks to Rudy Ruiz for the patch.
  • Railgun - The Meterpreter "RAILGUN" extension by Patrick HVE has merged and is now available for scripts.
  • PHP Meterpreter - A protocol-compatible port of the original Meterpreter payload to PHP. This new payload adds the ability to pivot through webservers regardless of the native operating system
  • Token impersonation now works with "execute -t" to spawn new commands with a stolen token.

Known Issues
  •  Interacting with a meterpreter session during a migration will break the session. See #1360.
  • There is no simple way to interrupt a background script started by AutoRunScript
  • Command interaction on Windows causes a PHP Meterpreter session to die. See #2232 

Using NK2Edit to edit Oulook Autocomplete entries

When Outlook is used as an email client, at times, there might arise a need to edit the auto complete entries while selecting users. If any of the attributes needs to be changed in the selected email addresses or if an old entry needs to be removed, Microsoft has not provided any direct method. In such cases Nirsoft's NK2Edit comes in handy.
It can be used to edit the outlook's .NK2 files for any duplicate entries, stale entries, or for modifying any existing entries.
It can be downloaded from : http://www.nirsoft.net/utils/outlook_nk2_edit.html page.

Information from the site:

Every time that you type an email address or name in the message window of MS-Outlook, it automatically offer you a list of users and email address that you can choose. This feature is known as 'AutoComplete' and Outlook automatically build this emails list according to user activity and save it into a file with .NK2 extension.

In some circumstances, you may need to repair or modify the values appeared in the AutoComplete list, or you may want to remove unwanted email addresses and/or to add new email addresses. MS-Outlook doesn't provide any ability to edit this AutoComplete list, so this is where NK2Edit software can help you.

NK2Edit Features
Easily modify or fix all information stored in the NK2 file, including the display name, the email address, the exchange string, the Drop-Down display name, and the search string.
Easily remove unwanted single quote characters from the display name and from the Drop-Down list.
Delete unwanted emails, as well as add new emails, by typing them manually, or by choosing them from the address book of Outlook.
Copy NK2 records from one NK2 file to another - simply by copy and paste !
Build a completely new NK2 file and add the desired emails into it, by typing them manually, by adding them from your address book, or by copying records from another NK2 file.
Extract data from corrupted NK2 files that Outlook cannot read anymore (When Outlook AutoComplete stopped working) and even repair them so Outlook will be able to read them again.
Export all data stored in the NK2 file into a special Unicode text file in a stucture similar to .ini file of Windows. You can open it any text editor you like, make the changes you need, and then convert it back into NK2 file that Outlook can use.
Export the emails information stored inside NK2 file into HTML/Text/csv/xml file.
Copy the selected NK2 records in tab-delimited format and then paste the information into Excel.
Change the order of the records in the NK2 file, which also affects the order they appear in the drop-down. You can also sort the list in alphabetical order of the Drop-Down display names. (However, be aware that Outlook change the order again when the user send emails)
Command-Line Support: Write simple scripts that can add, remove, or modify records inside the NK2 file, without displaying any user interface.
NK2Edit is a portable application that can be used from any computer with Windows operating system (Starting from Windows 2000) without need of any installation process, and without making changes in the Registry.

System Requirements
NK2Edit works on any version of Windows, starting from Windows 2000 and up to Windows 7/2008. NK2Edit is a Unicode based application, and thus it cannot work under Windows 95/98/ME.
NK2Edit can read, write, and create NK2 files for Outlook 2003, Outlook 2007, and Outlook 2010 Beta.
Outlook installation is not required on the computer that you run NK2Edit, except of "Add Records From Address Book" feature, which cannot work without Outlook. NK2Edit can also be used to open, edit, and save NK2 files on remote computers in your network, as long as you have read/write permission to the remote NK2 file.

Thursday, June 24, 2010

X-Setup Pro: RIP! and a last GIVEAWAY!

Many a times, X-Setup professional (X-Setup Pro) has helped in identifying and addressing computer problems. Due to an insolvency, the company has stopped updates to this wonderful tool. As a gesture, the tool is offered free!

An excerpt from the website. http://www.x-setup.net/

All comes to an end ...

Dear Customers,
Because of the insolvency of WUG all operations regarding X-Setup Pro have been shut down.
We thank all customers, partner and friends for their support during this time. We hope you had as much fun using X-Setup Pro as we had making it.
We wish you all the best,
TeX and Eric

P.S.:
You can still download the last version from MajorGeeks or BetaNews. The portable edition and the U3 version are available from MajorGeeks as well.
In case you lost your serial number use this one instead: XSA092-11TA9R-8K12YT

-
May god show some light on the souls!

WebCruiser - Simple and effective Web Vulnerability Scanner

When you need a simple and effective tool with a very minimal footprint for performing web vulnerability testing, WebCruiser comes in handy! It makes a very valuable tool for the on the go toolkit arsenal either on a USB Kit or on a custom DVD Vulnerability Kit.

More on the tool from the developers!

WebCruiser - Web Vulnerability Scanner, a compact but powerful web security scanning tool that will aid you in auditing your site! It has a Vulnerability Scanner and a series of security tools.


It can support scanning website as well as POC( Prooving of concept) for web vulnerabilities: SQL Injection, Cross Site Scripting, XPath Injection etc. So, WebCruiser is also an automatic SQL injection tool, a XPath injection tool, and a Cross Site Scripting tool!
Key Features:
  • Crawler(Site Directories And Files);
  • Vulnerability Scanner(SQL Injection, Cross Site Scripting, XPath Injection etc.);
  • POC(Proof of Concept): SQL Injection, Cross Site Scripting, XPath Injection etc.;
  • GET/Post/Cookie Injection;
  • SQL Server: PlainText/Union/Blind Injection;
  • MySQL: PlainText/Union/Blind Injection;
  • Oracle: PlainText/Union/Blind/CrossSite Injection;
  • DB2: Union/Blind Injection;
  • Access: Union/Blind Injection;
  • Post Data Resend;
  • Administration Entrance Search;
  • Time Delay For Search Injection;
  • Auto Get Cookie From Web Browser For Authentication;
  • Report Output.
System Requirement: .Net FrameWork 2.0 or higher.
If you can not run WebCruiser, please Download .NET FrameWork V2.0 From Microsoft:
http://www.microsoft.com/downloads/details.aspx?FamilyID=0856EACB-4362-4B0D-8EDD-AAB15C5E04F5&displaylang=en

Application Download:
User Guide:



SQL Injection Introduction(PDF): http://sec4app.com/download/SqlInjection.pdf
XPath Injection Introduction(PDF): http://sec4app.com/download/XPathInjection.pdf

Friday, May 28, 2010

Opera browser does not erase all the tracks while clearing history

People who use opera, just be(a)ware!

Clearing the history completely does not erase all the readily available tracks. Opera caches the site icons from almost every visited site and it remains on the system forever!

Clearing the history and deleting all the cookies does not clear these files.

Check it out yourselves if using opera.

In a normal desktop installation of the opera browser, the favicon files cache is available at "C:\Documents and Settings\\Local Settings\Application Data\Opera\Opera\icons" folder. This is applicable for Windows XP Operating systems and for Windows 7 this folder location will be different. The folder can be easily accessed using "%HOMEFOLDER%\Local Settings\Application Data\Opera\Opera\icons\" string typed at the RUN dialog box. If the folder cannot be located, type, opera:config#UserPrefs

OperaDirectory which will contain the location of the User Preferences directory for the opera installation.
 
The folder contains the http location and favicon files of almost all the sites ever visited by a user. If not to get a glimpse of the history or for forensic purposes, the folder can be looked at to know when the user has visited a particular website. Though there is no way of telling if the user has visited a site more than once, but at least one can clearly get a list of visited websites. This is of great help while performing forensics.

The above is applicable to Opera browser v9.x and above.

Thursday, May 27, 2010

Google's SSL Search Compromises security

Well, Well, Well! Google's SSL search compromises the user's desktop security to a large extent.

When a user searches using google, user's local desktop security applications such as McAfee's Site Protector or such similar suites will not have any clue on the content of the results. And the links cannot be verified for genuine and security. This is applicable for all such applications and it can be overridden as the applications are local, but would McAfee care to release an updated version to the existing suite? And all other applications which provides link security would really care to release an update? If at all it can be overridden. ( I have not done any research on IE8 to validate the claim if it can be overridden, but on older versions of IE, it can be.)

So, if a malicious site is returned by Google, (Well, Google is not too good in site classification / user protection. Are they? :)), the user is at risk of getting the infection. In case of any 0-day exploits getting a chance to infect the user's system via Google's "secure" search results, the user is doomed. For what? Using the Google's secure search?

I can clearly visualise the long term monopoly google is going to have on everything that is connected! :D

Do you?

Goggle's introduction of SSL to search has been a deliberate move to curb third party access it contents. Though they can talk about privacy issues, sniffing, blah blah blah, any one who relied on the referrer information is doomed when the site gets redirected. Any non-google analytics will not have any data on the referrer/search terms which the user has used to get to the site.

As long as you stay with google, you will have access to a wealth of information. But once you are out of it, there might practically be nothing!

A recent comment from one of the netizen, I thought it is nice to be quoted here! :D

"GOOGLE IS NOT BE TRUSTED, INVESTIGATIONS IN THE USA STATES GOOGLE IS PURCHASING KNOWLEDGE , BOOKS , ETC. COPYRIGHTS . WITH A VIEW OF HAVING FUTURE GENERATIONS TO ACCESS OF ANY COPY RIGHT MATERIAL. WHICH MEANS A PRICE WILL BE PLACED ON KNOWLEDGE.???
STUDENTS, RESEARCHERS , IF FACT ALL WILL HAVE PAY FOR ACCESS.
MEAN WHILE GOOGLE IS SELLING EMAIL ADDRESSES, PLUS ANY INFORMATION RECEIVED. HOME LAND SECURITY AND OTHER GOVERNMENT AGENCIES ARE INVESTIGATING. ZERO CONCLUSIONS WILL BE REACHED , DUE TO THE ENORMOUS SUMS GOOGLE GIVES TO POLITICAL PARTIES AND LOBBYISTS."

I do not make any claim or support of the above quoted, bold comments as it is not mine, but forewarned, the above is true and already in the making.

Thought for time?

Monday, May 24, 2010

Search and Replace across multiple files

Some times, it becomes a tedious process to do a string search and replace across multiple files. If one is comfortable with Regular Expressions or not, V-Grep from http://www.vgrep.aionel.net/ can be used for the operations.

It is very fast and small standalone application which can be used to perform search and replace across multiple text files with ease.

Check it out!