tag:blogger.com,1999:blog-25010298.post8751472383097417778..comments2009-01-06T18:54:53.772-08:00Comments on Metasploit: A root shell in my pocket (and maybe yours)hdmhttp://www.blogger.com/profile/02163635320992069812noreply@blogger.comBlogger15125tag:blogger.com,1999:blog-25010298.post-48238723607542078432008-04-22T03:32:00.000-07:002008-04-22T03:32:00.000-07:00/private/var/preferences/SystemConfiguration/com.a.../private/var/preferences/SystemConfiguration/com.apple.wifi.plistAnonymous cowardnoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-26954056374277001812008-03-17T14:29:00.000-07:002008-03-17T14:29:00.000-07:00Matthew: ignorance is not safe. Computers are by d...Matthew: ignorance is not safe. <BR/>Computers are by design flawed... <BR/>they need to know what to run. <BR/><BR/>And there will always be people that wants/needs to know what's going on under the hood. And thank God, else you would throw away anything that stops working! <BR/><BR/>And what about making something work better / make it more capable... <BR/><BR/>well if it can be done, (like jailbreaking the ipod touch/iphone) then IT SHOULD BE DONE! (ie: Apple, as soon as you heared of installer.app, you should have bought them big time and provided the solution... but that's not getting money in, so f*ck it! .... .<BR/>... .... ... money... ... yeah .. <BR/><BR/>) ... enough said about that!<BR/><BR/>HD: great article! <BR/>I need to know something: <BR/>you talk about modifying the "network preference file" to allow for weaker networks to pop up .. <BR/>humm .. do you mind doing a tutorial on that ? I couldnt find this info on google ! Thanks! <BR/>-MadlogikM@DL0G!Khttp://www.blogger.com/profile/15349342144030268966noreply@blogger.comtag:blogger.com,1999:blog-25010298.post-48799722577290099392008-01-29T15:46:00.000-08:002008-01-29T15:46:00.000-08:00Matthew, did you just throw insults at the legenda...Matthew, did you just throw insults at the legendary HDM? I don't think you even realize what you've just done.<BR/><BR/>Its actually quite the opposite, its better a credible person such as HD finds this stuff out so something can be done about it rather than the people who really want to do damage..Adamhttp://www.blogger.com/profile/07185538787727562863noreply@blogger.comtag:blogger.com,1999:blog-25010298.post-39105266574552575862008-01-21T00:20:00.000-08:002008-01-21T00:20:00.000-08:00i have been thinking about getting an n800 or mayb...i have been thinking about getting an n800 or maybe the n810, or maybe the Asus Eee - but I am coming from my trustworthy zaurus sl-5500 that I have had many years. My problem is, the zaurus is old and maybe a little slower, but it does everything I want it to do with auditing/pen testing....I did get metasploit up to 2.7 to work on it, but could never get 3 to work - lots of info on it at edwiget.name if anyone finds this useful. I never could find any gps + cable or 10/100 ethernet card for it...but wireless works great. I love the zaurus so much, I would love to trick it out with all its options and then just put it away....so if anyone has any stuff for it...contact me.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-66242883861067699952007-10-23T03:48:00.000-07:002007-10-23T03:48:00.000-07:00nice work bro :)I agree with n800_User tho .. n800...nice work bro :)<BR/><BR/>I agree with n800_User tho .. n800 is a better choice for a handheld hacking device.rdhttp://vnsecurity.netnoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-77924166293373967832007-10-18T15:10:00.000-07:002007-10-18T15:10:00.000-07:00as ceo of apple...i would hire you instantly:)as ceo of apple...i would hire you instantly:)Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-67278332436094837032007-10-18T12:01:00.000-07:002007-10-18T12:01:00.000-07:00Matthew, its people like you who make this all wor...Matthew, its people like you who make this all worthwhile :-)hdmhttp://www.blogger.com/profile/02163635320992069812noreply@blogger.comtag:blogger.com,1999:blog-25010298.post-71114307211293618952007-10-18T10:20:00.000-07:002007-10-18T10:20:00.000-07:00its people like you who fuck it up for the rest of...its people like you who fuck it up for the rest of us....get a life beyond trying endlessly to hack into other peoples phones... hey, there is a knock on the door, mom wants her basement back and she wants you to join the human world. <BR/>Anarchy is a pain in the ass, you asswipe.<BR/>if you have any ego, you will answer to this rather than delete..which i assume you will..Matthewhttp://www.blogger.com/profile/01707298041740943623noreply@blogger.comtag:blogger.com,1999:blog-25010298.post-35399847046919155062007-10-16T05:05:00.000-07:002007-10-16T05:05:00.000-07:00Amazing job HDM.Having a network-based root shell ...Amazing job HDM.<BR/>Having a network-based root shell in my pocket does feel good, especially after reading your blog.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-22120016855727694342007-10-05T15:57:00.000-07:002007-10-05T15:57:00.000-07:00Actually, n800 is a hacker's choice :)Of course 33...Actually, n800 is a hacker's choice :)<BR/>Of course 330MHz is smaller than 400.Actually in n800 there is way to use 400 too BUT then second DSP core should be down-clocked, sort of trade-off.But 330 MHz are pretty enough to have bunch of fun. What n800 can do?<BR/>- The screen is 800x480.A way better for the web.And for entering text to the terminals :)<BR/>- EDGE\3G goes via external device and can be a way better than EDGE.<BR/>- Wi-Fi is both fast and consumes very small power in idle mode while keeping link alive.<BR/>- Great bluetooth connectivity.Low powered as well and yes, it copes with dozens of connections easily.<BR/>- Dozen of tools are ported.Like nmap, kismet, aircrack, curl\wget, ... and much more.Due to official SDK which making porting just a joke:)<BR/>- You can even wardrive using gpsd to learn what and where.<BR/>- There is openvpn to get to anywhere.No matter you're using EDGE and lame local IP, etc.<BR/>- There is even nginx and php-fastcgi so your server is with you :)<BR/>- Bluetooth utils to ... er... to audit these remote devices :)<BR/>- Real mc filemanager, sshing to your pocket and dealing with files on device and it's cards is a real fun.<BR/>- TCPDump allows to know what's going up.<BR/>- Some GUI fun.On n800 you can run full-featured Liunx apps.Like mplayer to watch let's say .FLV file.Or Pidgin to chat via ICQ,MSN,Jabber.Or maybe xchat to hang on IRC.Or MaemoMapper to navigate via maps like google streets optionally using GPS reciever.Some VNC and RemoteDesktop fun as well.You're ruling your world :-).Decent VoIP features.Including SIP (a whole dozen of operators like Gizmo) and Skype.MythTV is also here.And well, it runs Firefox.To be exact, reduced version of great browser based on Gecko 1.9.Yes, this Gecko is beta which will be used by Firefox 3, but even today it can easily beat any other pocket browser just jokingly (on Ajax-based sites, or YouTube, he-he).<BR/>- We can mess with our OS as we wish.If we want to, we can rebuild kernel and other parts like initfs.Allowing device to boot up from cards, have unusual kernel features not available out of the box (like various filesystems support added, or advanced SDHC patches for fast speeds, or whatever else kernel does).<BR/><BR/>What n800 can not?<BR/> - It can't be cell phone.Yes.Kinda unique for Nokia.But in exchange you're getting FREEDOM.Device is not locked to any carrier.No strings attached.No restrictions.Nothing crippled.Real Debian linux inside.You can even apt-get something instead of using app manager, result is same :-).You're getting real unrestricted pocket computer from beginning.iPhone is just a dialer and player by design.So you're hacking to take your rights and Apple can always stop you with updates.We're using our rights.Nokia will not stop us.Because their device created to be FREE and give you some FREEDOM.<BR/><BR/>- Yes, n800 can not limit you as well.It's perfectly hackable.You do not have to fight with dumb barriers.You do not have to afraid updates.Just have fun :-)<BR/><BR/>- And yes, n800 can't be such buzzword.It rather intended for thinking people while iPhone is dumb dialer with player targeted on dumb people by design (so it is a way more restrictive without hacking).<BR/><BR/>Of course you can break'n'enter.But Apple may decide to prevent "homebrew" apps with updates.So this way can be just headache.<BR/><BR/>As for me, looks like some people are not seeking simple way but rather their own.That's good, too.ARM shellcode... users should tremble since there is so much ARM devices today =).Great work!Did I mentioned ARM asm rocks compared to x86 one? ;)n800_Usernoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-30648198024028181712007-09-28T07:00:00.000-07:002007-09-28T07:00:00.000-07:00Regarding the Syngress book on Metasploit -- we ch...Regarding the Syngress book on Metasploit -- we chose not to be part of the project for quite a few reasons. The biggest one is the fact that Metasploit was (and is) a moving target. Syngress wanted to start writing the book while we were transitioning between 2.7 and 3.0. The book they released this week has over half of its content dedicated to an obsolete version of the Framework. Personally, I am not a fan of Syngress's style, quality, editing skills, or marketing abilities. We DO have a community book that is in the works and any help you want to provide would be useful:<BR/><BR/>http://en.wikibooks.org/wiki/Metasploithdmhttp://www.blogger.com/profile/02163635320992069812noreply@blogger.comtag:blogger.com,1999:blog-25010298.post-38394019173497809502007-09-28T03:08:00.000-07:002007-09-28T03:08:00.000-07:00hd, got to say it: metasploit rocksjust curious wh...hd, <BR/><BR/>got to say it: metasploit rocks<BR/><BR/>just curious why you were not part of the new syngress metasploit book. do you have something coming out book wise, or is that what the documentation is for? ;)<BR/><BR/>good stuffAnonymousnoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-63922575378306263912007-09-27T14:45:00.000-07:002007-09-27T14:45:00.000-07:00you f^cking Rock!!! cant wait to see the versions...you f^cking Rock!!! cant wait to see the versions develope.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-25010298.post-34001781086407647982007-09-26T11:32:00.000-07:002007-09-26T11:32:00.000-07:00Darn smart!You're contribution will surely help th...Darn smart!<BR/>You're contribution will surely help the iPhone dev-team and who knows, even inspire some other smarties to assist in the hunting.<BR/>Thanks!mokum von Amsterdamhttp://www.blogger.com/profile/03801346660588264367noreply@blogger.comtag:blogger.com,1999:blog-25010298.post-87694179060096344222007-09-26T07:38:00.000-07:002007-09-26T07:38:00.000-07:00Nice One :)Nice One :)Anonymousnoreply@blogger.com