LokiSec.com

LokiSec.com
  • Security
    • Security Tools
    • Website Defense
    • Personal Security
    • Standards
  • Books
    • Technical

Posts Tagged tutorial

Archive

April 15, 2012 by CyberRad

Google Hacking

Google Dorks are advanced search parameters that you can use with Google’s search engine to narrow down a search.  Google Hacking is the art of using Google Dorks to find specific information on Google’s databases.  For example finding a known vulnerable version of a web application. 
Posted in Security Tools, Website Defense · Tagged default, dorks, file, google, hacking, page, password, Pentest, scan, security, tools, tutorial, username, web · Leave a Reply ·

Archive

January 17, 2012 by CyberRad

Going Phishing with the Social Engineering Toolkit

Social Engineering Toolkit (SET) is a social engineering pen testing framework created by Dave (ReL1K) Kennedy.  SET contains numerous tools to help pen testers test the human element during a security engagement.
Posted in Security Tools · Tagged Backtrack, hacker, metasploit, meterpreter, Pentest, security, SET, Social Engineering Toolkit, tools, tutorial · 16 Replies ·

Archive

December 17, 2011 by CyberRad

What to do after your *nix web server has been compromised

I thought it would be nice to write about what you should do when your *nix server is compromised.  The idea came from a conversation that was sparked on the Full Disclosure List.
Posted in Website Defense · Tagged apache, CentOS, iptables, Linux, log, netstat, php, Red Hat, security, Suse, tutorial, Ubuntu, Unix, web, website · Leave a Reply ·

Archive

October 26, 2011 by CyberRad

Using Rel1K’s Artillery To Protect Your Server

If you are looking for a way to secure your linux server from some of the most common attacks being carried out today against linux servers then look no further then Rel1K’s Artillery program. Artillery is a combination of a honeypot, file monitoring and integrity, alerting, and brute force prevention tool.
Posted in Website Defense · Tagged apache, Dave, Derbycon, free hugs, Linux, rel1K, scan, security, SET, tools, tutorial, web, website · Leave a Reply ·

Archive

September 26, 2011 by CyberRad

How to perform a SQL Injection Attack

SQL Injection (SQLi) is an attack vector that is extremely easy to carry out.  Most of the breaches you see today are perpetrated this way yielding huge payloads of data.  Understanding this attack will help you defend against this type of attack.
Posted in Security, Website Defense · Tagged asp, audit, coldfusion, Injection, php, SQL, SQL Injection, SQLi, tutorial, vulnerability, web, website · 2 Replies ·

Archive

August 12, 2011 by CyberRad

Cracking the wireless network using aircrack-ng

Aircrack-ng is a suite of programs that allow for auditing of IEEE 802.11 networks.  Below I will go over using the Aircrack-ng suit in Backtrack 5 to capture and crack WEP and WPA.
Posted in Security Tools · Tagged 802.11, aircrack-ng, Backtrack, network, Pentest, tools, tutorial, WEP, wireless, WPA, WPA2 · 1 Reply ·

Archive

June 30, 2011 by CyberRad

Deter unwanted scanners/crawlers using Weblabyrinth

Weblabyrinth is a dynamic maze of web pages written in PHP.  The main goal of Weblabyrinth is to delay and occupy malicious web scanners to give incident handlers time to investigate and respond to threats.  Weblabyrinth is designed to show a 404 error to legitimate web crawlers based on the crawlers user-agent.  Here is how [...]
Posted in Website Defense · Tagged aliases, apache, No, php, Snort, tutorial, user-agent, weblabyrinth · Leave a Reply ·

Archive

June 17, 2011 by CyberRad

Audit your site using w3af

Maintaining a website can be a large task.  On the security side of the day to day tasks for the site you usually patch the web server and check the logs for potential issues.  There are many automated tools that are out there scanning the internet for vulnerable web servers to compromise.  Typically a compromised [...]
Posted in Security Tools · Tagged apache, audit, Backtrack, iis, scan, security, tools, tutorial, vulnerability, w3af, web, website · Leave a Reply ·

Archive

May 16, 2011 by CyberRad

Using Armitage, An attack management tool for Metasploit

Armitage is a great attack management tool for Metasploit.  Armitage shows a graphical representation of your attack as you are putting it in motion.  Armitage also allows for Red Teaming by allowing your team a way to collaborate an attack in the same Metasploit session.
Posted in Security Tools · Tagged armitage, Backtrack, GUI, metasploit, meterpreter, Pentest, tools, tutorial · Leave a Reply ·

Archive

May 5, 2011 by CyberRad

Using Netcat, the TCP/IP swiss army knife

Netcat has been called the TCP/IP swiss army knife and rightfully so.  It can act as a service by listening for a connection, a client and connect to open ports, a port scanner, a tool used to fingerprint a connectable service, and much more.  In this article I will touch on handful of these abilities.
Posted in Security Tools · Tagged Backtrack, netcat, network, Pentest, swiss army knife, tools, tutorial · 2 Replies ·
← Older posts

Recent Posts

  • Backtrack 5 r3 has been released!
  • Metasploit: The Penetration Tester’s Guide
  • Google Hacking
  • Backtrack 5 r2 has been released!
  • Going Phishing with the Social Engineering Toolkit

Twitter Feed

  • RT @smhack1: The Space is open for the members hangout. Become a dues paying member and hangout with us. 5 days ago

  • RT @smhack1: We are participating in the Extra Life 2013 event http://t.co/aqg6mWYllF 1 week ago

  • I'm supporting @CMNHospitals through @ExtraLife4Kids! http://t.co/BtApLZUBx9 via @DonorDrive Help me reach my goal! 1 week ago

Archives

  • August 2012
  • June 2012
  • April 2012
  • March 2012
  • January 2012
  • December 2011
  • October 2011
  • September 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • March 2011

Tags

802.11 aircrack-ng aliases apache armitage audit Backtrack cree.py creepy flicker geolocation GUI hacker iis Linux metasploit meterpreter netcat network Nmap No Pentest php PTES Quality scan security SET Snort SQLi swiss army knife tools tutorial twitter Uber user-agent vulnerability w3af web weblabyrinth website WEP wireless WPA WPA2

Search

Spread the word!

Blogroll

  • Carnal0wnage
  • Darknet
  • DigiNinja
  • McGrew Security
  • mubix
  • PaulDotCom
  • SpyLogic
  • TaoSecurity

© 2011-2013 LokiSec.com All Rights Reserved