DNS Despoof(er)
These days I was playing with some well-known tools to perform DNS spoofing in both *nix and windows environment: Dnsspoof (part of the dsniff suite) and WinDNSSpoof, of which I learned only recently....
View ArticleNetDiscover (libnet purge)
Many of you know netdiscover (http://nixgeneration.com/~jaime/netdiscover/), which is, according to the site: “Netdiscover is an active/passive address reconnaissance tool, mainly developed for those...
View ArticleFlux-for-back… Awesome!
Thanks to the time spent by Brigante on the project “Fluxbox for BackTrack“, a new desktop environment will be soon available for your favorite distribution. Results are not bad at all: As you know,...
View ArticleExploiting Arm Linux Systems
Wow, this last month has been pretty intense. Between trips, new articles and projects I haven’t had much free time (although I enjoyed this month). Exploiting Arm Linux Systems This was my first...
View ArticleHexinject 1.2 released
HexInject version 1.2 has been released (http://hexinject.sourceforge.net/). Evvai! The release includes some minor fixes and a new feature: now the various length fields of IP, UDP, TCP, ICMP headers...
View ArticleFun with HexInject and USB protocols
Did you know that pcap (http://www.tcpdump.org/) libraries can capture raw USB traffic? I had noticed several times the presence of various USB interfaces in wireshark but so far I’ve never tried to...
View ArticleLetDown and HTTP DoS attacks
These days much attention has turned to certain denial of service attacks that plague HTTP, also due to inherent vulnerabilities of the protocol itself. I’ve read some nice pages and tools on various...
View ArticleIn-memory-fuzzing in Linux (with GDB and Python)
Probably, if you’re reading this article, you already know what fuzzing means. In short, fuzz testing is a technique for testing software and searching vulnerabilities: targeted software is feeded with...
View ArticleThe invisible woman and the axis camera
1 This post follows the original “philosophy” of this blog. Sometimes, when I think about a technique or a skill I consider interesting, I also imagine a real-life scenario where this technique can be...
View Article