Archive for May, 2009

WebDAV Detection, Vulnerability Checking and Exploitation

Filed under: Hacking, Tools

Ahoy! My name is Andrew and I've been playing with the recent IIS WebDAV authentication bypass vulnerability (CVE-2009-1676) and helping Ron with writing the nmap detection script (http-iis-webdav-vuln.nse) and testing it in the lab. Ron is in a meeting today so I thought I'd jump in where he left off and post a bit about [...]

Read More
Permalink Comments (49) Andrew May 20, 2009

WebDAV Scanning with Nmap

Filed under: Hacking, Tools

Greetings! This morning I heard (from the security-basics mailing list, of all places) that there's a zero-day vulnerability going around for WebDAV on Windows 2003. I always like a good vulnerability early in the week, so I decided to write an Nmap script to find it!

Read More
Permalink Comments (20) Ron Bowes May 19, 2009

Bypassing AV over the Internet with Metasploit

Filed under: Hacking, Tools

I performed all of this to learn more about data exfiltration, remote control, etc... over a tightly controlled corp environment. It was depressing actually.... It's far too easy to gain control of a corp network even one that is conscientious. This work is built on the info at metasploit.com. Oh, let me just say thanks [...]

Read More
Permalink Comments (5) Matt Gardenghi May 15, 2009

Nmap 4.85beta9 released

Filed under: Tools

In case you haven't heard, Fyodor released Nmap 4.85beta9 this week. This is the first release in awhile that wasn't related to my code (or, most properly, mistakes :) ). It looks like the new stable version will be here soon, so give this one a shot and report your bugs. Here's the download page.

Read More
Permalink Comments (0) Ron Bowes May 15, 2009