Archive for the ‘DNS’ Category

Call for testers: nbtool-0.05 and dnscat-0.05

Filed under: DNS, Tools

Hey all,
I just released the second alpha build of nbtool (0.05alpha2), and I'm hoping to get a few testers to give me some feedback before I release 0.05 proper. I'm pretty happy with the 0.05 release, but it's easy for me to miss things as the developer.
I'm hoping for people to test:

Through different DNS [...]

Read More
Permalink Comments (1) Ron Bowes Jul 7, 2010

Stuffing Javascript into DNS names

Filed under: DNS, Hacking, Tools

Greetings!
Today seemed like a fun day to write about a really cool vector for cross-site scripting I found. In my testing, this attack is pretty specific and, in some ways, useless, but I strongly suspect that, with resources I don't have access to, this can trigger stored cross-site scripting in some pretty nasty places. [...]

Read More
Permalink Comments (5) Ron Bowes Apr 20, 2010

Weaponizing dnscat with shellcode and Metasploit

Filed under: DNS, Hacking, Tools

Hey all,
I've been letting other projects slip these last couple weeks because I was excited about converting dnscat into shellcode (or "weaponizing dnscat", as I enjoy saying). Even though I got into the security field with reverse engineering and writing hacks for games, I have never written more than a couple lines of x86 at [...]

Read More
Permalink Comments (10) Ron Bowes Mar 18, 2010

DNS Backdoors with dnscat

Filed under: DNS, Hacking, Tools

Hey all,
I'm really excited to announce the first release of a tool I've put a lot of hard work into: dnscat.
It's being released, along with a bunch of other tools that I'll be blogging about, as part of nbtool 0.04.

Read More
Permalink Comments (3) Ron Bowes Feb 23, 2010