LokiSec.com

LokiSec.com
  • Security
    • Security Tools
    • Website Defense
    • Personal Security
    • Standards
  • Books
    • Technical

Standard

Audit your site using w3af

June 17, 2011 by CyberRad

Maintaining a website can be a large task.  On the security side of the day to day tasks for the site you usually patch the web server and check the logs for potential issues.  There are many automated tools that are out there scanning the internet for vulnerable web servers to compromise.  Typically a compromised web server is turned into a spam serving server.  What about your web application that you use to serve your content?  Can you trust that it does not allow the attacker access to your web server?  This is where w3af comes in.  w3af attempts to find vulnerabilities in your web application using known attack methods. Continue reading →

Posted in Security Tools · Tagged apache, audit, Backtrack, iis, scan, security, tools, tutorial, vulnerability, w3af, web, website · Leave a Reply ·

Standard

Using Armitage, An attack management tool for Metasploit

May 16, 2011 by CyberRad

Armitage is a great attack management tool for Metasploit.  Armitage shows a graphical representation of your attack as you are putting it in motion.  Armitage also allows for Red Teaming by allowing your team a way to collaborate an attack in the same Metasploit session. Continue reading →

Posted in Security Tools · Tagged armitage, Backtrack, GUI, metasploit, meterpreter, Pentest, tools, tutorial · Leave a Reply ·

Standard

Backtrack 5 is here!

May 12, 2011 by CyberRad

Just in case you missed it Backtrack 5 has been released.  Download it here.

Continue reading →

Posted in Security Tools · Tagged Backtrack, Pentest, tools · Leave a Reply ·

Standard

PTES – Penetration Testing Execution Standard

May 10, 2011 by CyberRad

Penetration Testing… What is it?  To most companies, that either choose or are forced to get one, the image of Uber-hackers defiling their business critical systems comes to mind.  Yes, an Uber-hacker should be expected but this isn’t always the case.  There are a number of disreputable firms out there that run a Nessus scan on your network and give you a pretty report and call it a pentest.  This is where the PTES comes in.  It is the goal of the PTES to create a standard for both Pentesters and businesses to follow/expect from a security audit or pentest.  This in turn increases the quality of a pentest.  Visit PTES and check out the massive amount of information on how to carry out a true and thorough pentest.

Posted in Standards · Tagged hacker, Pentest, PTES, Quality, Uber · Leave a Reply ·

Standard

Using Netcat, the TCP/IP swiss army knife

May 5, 2011 by CyberRad

Netcat has been called the TCP/IP swiss army knife and rightfully so.  It can act as a service by listening for a connection, a client and connect to open ports, a port scanner, a tool used to fingerprint a connectable service, and much more.  In this article I will touch on handful of these abilities.
Continue reading →

Posted in Security Tools · Tagged Backtrack, netcat, network, Pentest, swiss army knife, tools, tutorial · 2 Replies ·

Standard

Using Metasploit

April 11, 2011 by CyberRad

So you have done some recon on your potential target and now you are on the exploitation phase of your pentest.  Metasploit can connect to a database to keep track of the recon you collected on your targets.  You can import an xml report from your Nmap scan or you can use the db_nmap command in Metasploit.  That is jumping the gun a little.  We will first need to bring up Metasploit and then create a database connection to your database of choice.  All examples and commands will be done through Backtrack 4 R2. Continue reading →

Posted in Security Tools · Tagged Backtrack, metasploit, network, Pentest, tools, tutorial · Leave a Reply ·

Standard

Using Nmap for network intel gathering

April 6, 2011 by CyberRad

Nmap was created by Gordon “Fyodor” Lyon.  Nmap is an extremely versatile network scanning tool.  It has a vast user base from System Administrators to Penetration Testers to malicious hackers.  In this article I hope to get you, the reader, more comfortable with using Nmap as well as inspire you to really check out this tool a little more in depth.  We will go over scanning a local network to see what targets are available as well as issues you may run into with newer operating systems.  We will also go over detecting open ports and how to detect the services that are running on them.  Check out the Nmap website, Nmap.org, for examples and a higher level look at this great tool. Continue reading →

Posted in Security Tools · Tagged network, Nmap, Pentest, tools, tutorial · Leave a Reply ·

Standard

Creepy

March 31, 2011 by CyberRad

Cree.py is an interesting and simple to use program that highlights the dangers of using geolocation while using social networking. All that is needed is a target’s twitter account or flicker account username and you can map out their movements based on the time and location of their tweet or image.

Posted in Personal Security · Tagged cree.py, creepy, flicker, geolocation, tools, twitter · Leave a Reply ·
Newer posts →

Recent Posts

  • Backtrack 5 r3 has been released!
  • Metasploit: The Penetration Tester’s Guide
  • Google Hacking
  • Backtrack 5 r2 has been released!
  • Going Phishing with the Social Engineering Toolkit

Twitter Feed

  • RT @smhack1: The Space is open for the members hangout. Become a dues paying member and hangout with us. 1 week ago

  • RT @smhack1: We are participating in the Extra Life 2013 event http://t.co/aqg6mWYllF 1 week ago

  • I'm supporting @CMNHospitals through @ExtraLife4Kids! http://t.co/BtApLZUBx9 via @DonorDrive Help me reach my goal! 1 week ago

Archives

  • August 2012
  • June 2012
  • April 2012
  • March 2012
  • January 2012
  • December 2011
  • October 2011
  • September 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • March 2011

Tags

802.11 aircrack-ng aliases apache armitage audit Backtrack cree.py creepy flicker geolocation GUI hacker iis Linux metasploit meterpreter netcat network Nmap No Pentest php PTES Quality scan security SET Snort SQLi swiss army knife tools tutorial twitter Uber user-agent vulnerability w3af web weblabyrinth website WEP wireless WPA WPA2

Search

Spread the word!

Blogroll

  • Carnal0wnage
  • Darknet
  • DigiNinja
  • McGrew Security
  • mubix
  • PaulDotCom
  • SpyLogic
  • TaoSecurity

© 2011-2013 LokiSec.com All Rights Reserved