|
|||||||||||
|
For Indian Tiger - Pen test lab
From: Sam <sangthomas(at)rediffmail.com>
Date: Fri Apr 25 2003 - 03:26:32 EDT
I've been following your posts right from the penetration lab set up phase. Would it be possible for you to share your experience so that others can shorten their learning curve? Again, if not too much of a trouble, can I contact you over your mail id (mail sent to your id stated here bounces back ;))- as I'm in the starting throes of setting up a penetration lab, and your recent experience and guidance would be valuable for me.
Thanks,
-----Original Message-----
Hey Everybody,
First of all thank you very much to Robert, Rogan, Steve, Nicolas and
Leah
Now I can transfer victim’s cookie to another location successfully. I
have
1. Using document.location 2. Using Image src 3. Using hidden fields
The cookie, which I am getting, is of current application only mean If I
am
Now how can I steal all cookies stored on the victim’s machine? or how
to
Some sites converts < and > tags into < and > to protect them
selves
I was testing some trojan execution using XSS. In this process I was
able to
As per IDefence’s Article on “Brute forcing Session ID” some time
session ID
In my research of six sites, four sites were using ASP session variable
to
I was able to hijack ASP sessions using session IDs. In my testing,
first I
Any help on this would be highly appreciated.
Thanking You.
Indian Tiger, CISSP --- Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the world's premier event for IT and network security experts. The two-day Training features 6 hand-on courses on May 12-13 taught by professionals. The two-day Briefings on May 14-15 features 24 top speakers with no vendor sales pitches. Deadline for the best rates is April 25. Register today to ensure your place. http://www.securityfocus.com/BlackHat-pen-test Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the world's premier event for IT and network security experts. The two-day Training features 6 hand-on courses on May 12-13 taught by professionals. The two-day Briefings on May 14-15 features 24 top speakers with no vendor sales pitches. Deadline for the best rates is April 25. Register today to ensure your place. http://www.securityfocus.com/BlackHat-pen-test Received on Sun Apr 27 12:24:29 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:35 EDT |
||||||||||
|
|||||||||||