View RSS Feed

Most Popular Blogs

  1. Penetration Testing Biometric System: Part 1 Local Attacks

    by , 03-02-2011 at 12:12 PM (Fb1h2s aka Rahul Sasi's Blog)


    Presented in Nullcon 2011: http://nullcon.net/
    Greetz to: B0Nd,Eberly,Wipu,Neo,Vinnu,prashant(null),sud0,Sag ar,rohith,Nishant, atul, r4scal, SmartKD, beenu, d4rkdawn and all Null Members
    Special Thanks to: the_empty, 41w4rior, d4rkest,Abishek Dutta, w3bdevil,

    PDF: http://www.fb1h2s.com/Null_Biometrics.pdf
    PPT: http://www.fb1h2s.com/nullcon-Presen...biometrics.rar


    Abstract: This paper act as a guide explaining the necessity
    ...
    Categories
    Uncategorized
  2. Penetration testing - [MSSQL P4wnage]

    by , 07-25-2010 at 08:03 PM (Fb1h2s aka Rahul Sasi's Blog)
    Well MSSQl which is my favorite DB back end which I always look for when trying to 0wn something or in an Internal or External PT, and that it has given me a high success rate always. SQl injection on MSSQL Datas base also rocks and also critical than any other Database systems. The reason is because MSSQL allows stacked queries,and much DBs will allows that.

    Ok, what are stacked queries ??
    Well they are just a functionality that allows user to append multiple queries to a ...

    Updated 07-25-2010 at 08:12 PM by fb1h2s

    Categories
    Uncategorized
  3. XSS too Root

    by , 11-12-2010 at 11:36 PM (Fb1h2s aka Rahul Sasi's Blog)
    Last week I was assigned with a WPT , where I was assigned to PT a Web Application
    Normally in WPT s you will find a lot of bugs if you spend some good time analyzing the application in and out. And Tools like Web Inspect and Appscan are also of a good help to one extend.

    But the application I was testing had some sort of filter which prevented the possibilities of any sort of normal web application attacks, and redirected all malicious request to one common error page.And ...
    Categories
    Uncategorized