Archive for the ‘DNS’ Category

A deeper look at ms11-058

Filed under: DNS, Hacking, Reverse Engineering

Hey everybody, Two weeks ago today, Microsoft released a bunch of bulletins for Patch Tuesday. One of them - ms11-058 - was rated critical and potentially exploitable. However, according to Microsoft, this is a simple integer overflow, leading to a huge memcpy leading to a DoS and nothing more. I disagree. Although I didn't find [...]

Read More
Permalink Comments (10) Ron Bowes Aug 23, 2011

Faking demos for fun and profit

Filed under: Conferences, DNS, Hacking, Nmap, Tools

This week Last week Earlier this month Last month Last year (if this intro doesn't work, I give up trying to post this :) ), I presented at B-Sides Ottawa, which was put on by Andrew Hay and others (and sorry I waited so long before posting this... I kept revising it and not publishing). [...]

Read More
Permalink Comments (1) Ron Bowes Nov 27, 2010

Call for testers: nbtool-0.05 and dnscat-0.05

Filed under: DNS, Tools

Hey all, I just released the second alpha build of nbtool (0.05alpha2), and I'm hoping to get a few testers to give me some feedback before I release 0.05 proper. I'm pretty happy with the 0.05 release, but it's easy for me to miss things as the developer. I'm hoping for people to test: Through [...]

Read More
Permalink Comments (1) Ron Bowes Jul 7, 2010

Stuffing Javascript into DNS names

Filed under: DNS, Hacking, Tools

Greetings! Today seemed like a fun day to write about a really cool vector for cross-site scripting I found. In my testing, this attack is pretty specific and, in some ways, useless, but I strongly suspect that, with resources I don't have access to, this can trigger stored cross-site scripting in some pretty nasty places. [...]

Read More
Permalink Comments (19) Ron Bowes Apr 20, 2010

Weaponizing dnscat with shellcode and Metasploit

Filed under: DNS, Hacking, Tools

Hey all, I've been letting other projects slip these last couple weeks because I was excited about converting dnscat into shellcode (or "weaponizing dnscat", as I enjoy saying). Even though I got into the security field with reverse engineering and writing hacks for games, I have never written more than a couple lines of x86 [...]

Read More
Permalink Comments (14) Ron Bowes Mar 18, 2010

DNS Backdoors with dnscat

Filed under: DNS, Hacking, Tools

Hey all, I'm really excited to announce the first release of a tool I've put a lot of hard work into: dnscat. It's being released, along with a bunch of other tools that I'll be blogging about, as part of nbtool 0.04.

Read More
Permalink Comments (3) Ron Bowes Feb 23, 2010