Changing the ClieOp3 file and the hash totals with the elfproef
Several financial applications can generate batch payment files, which can be used in electronic banking applications. In the Netherlands these files are in the ClieOp3 format and contains the approved payments from the company account to other accounts. The ClieOp3 file will be saved in a folder (which can be a network share). The clieOp3 file will be uploaded to the electronic banking applicatio (read article) TLS & SSLv3 renegotiation vulnerability
This paper describes how to test for the TLS & SSLv3 renegotiation vulnerability:
The toolset provided by Openssl offers the simplest way to test whether a server allows for client-side renegotiation in the established tunnel.
Note: This doesn't necessarily mean that the application beneath is vulnerable to attacks over this channel, but indicates the server allows attacks to happen (read article) A description on how to use the Firewalk network tool
Firewalk is an active reconnaissance network security tool that attempts to determine what layer 4 protocols a given IP forwarding device will pass. Firewalk works by sending out TCP or UDP packets with a TTL one greater than the targeted gateway. If the gateway allows the traffic, it will forward the packets to the next hop where they will expire and elicit an ICMP_TIME_EXCEEDED message. If the g (read article) Installing the tools on Ubuntu
To install the tools on this site on Ubuntu or Kubuntu, you will need to add the following packages:
build-essentiallibgtk2.0-devlibncurses5-devflexbisonlibperl-devtcllib
libreadline5-devrubylibopenssl-rubylibpq-devsqlite
On my test system the following packages are installed:
acpi
acpi-support
acpid
adduser
alacarte
alsa-base
alsa-utils
anacron
apmd
app--data
app--data-commercial
a (read article) Citrix google dorks
We all know the Google Hacking Database from the Johnny ihackstuff website. He has a huge collection of security related search queries on Google. The most famous one being able to search for password files. Google indexes everything it comes across, so having password files available on your web server is probably not the best thing to do.
I came across a post from gnucitizen where the concept (read article) FireCAT for Firefox
An amazing collection of Firefox tools has been composed into a document. The document contains plugins that can be installed into Firefox, which can be used for pentesting and also of course for web development. These extentions have replaced a lot of self written tools and scripts for me and I hope you find them as useful as I do. The FireCAT collection consists of the following categories:
P (read article) | |
