pen-test
[Top] [All Lists]

RE: Penetration Testing Framework 0.24 released

To: <pen-test@securityfocus.com>
Subject: RE: Penetration Testing Framework 0.24 released
From: "Melissa" <missy.augustine@gmail.com>
Date: Mon, 26 Feb 2007 22:38:33 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:from:to:references:in-reply-to:subject:date:mime-version:content-type:content-transfer-encoding:x-mailer:thread-index:content-language:message-id; b=BMmovJ3d6n4YKg/7BELxswpDSF0MCdfxusolQFtNjc/G7h6GdtirA4Dlea/noKWGgrAi+GoGI+t8DqNVMIaHIyLH4vyUZ7RFESW9YT0QcrjFTOsPOjMXabBHV9UDSToWHyUviTgPoSqI1I78ibPseCKnMhR2tFgys8vKEwHxC9I=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:from:to:references:in-reply-to:subject:date:mime-version:content-type:content-transfer-encoding:x-mailer:thread-index:content-language:message-id; b=FXTxa4TjKkRRITz2SsDmIAYPvfJyxUudKZSevp966UVJrSPjLclkWuSSNG2XoPYsTqdOvC+y2Ov7NXflOsJlKXLj/Y7uR+yrJl4BeU88XhhrJdanmQbDcnmh60Mr6TN1sN1mV/S2/rAylL7jEp6hh8DYOZA/0+IswUjV77C/Ho0=
In-reply-to: <41011d980702250547v552e20ddl76035621772c2a42@mail.gmail.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <20070223114322.21458.qmail@securityfocus.com> <41011d980702240658x17ed6d3bu7011e6a66f8bb8d@mail.gmail.com> <27565945.1172408798819.JavaMail.itadmin@PSPOSTX1> <41011d980702250547v552e20ddl76035621772c2a42@mail.gmail.com>
Resent-date: Wed, 28 Feb 2007 09:33:09 -0700 (MST)
Resent-from: pen-test-return-1078483647@securityfocus.com
Resent-message-id: <20070228163309.CEE24237BFC@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thread-index: AcdZ8Y4j0uvwFZ6KQ5aa8jcF17joYwALxpQw
Might not be the exact article, but its strange as I just cited it for a
paper this morning :)

http://www.darkreading.com/document.asp?doc_id=95556&WT.svl=column1_1

-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] On
Behalf Of crazy frog crazy frog
Sent: Sunday, February 25, 2007 8:47 AM
To: Liam Downward
Cc: toggmeister@vulnerabilityassessment.co.uk; pen-test@securityfocus.com
Subject: Re: Penetration Testing Framework 0.24 released

yeah,i read about this attack somewhere.

On 2/25/07, Liam Downward <ldownward@pervasivesolutions.net> wrote:
> A possible addition for Social Engineering is to gain entrance to a
> network via "Human curiosity" with the use of USB thumb drives that can
> be of any size (64mb, 512mb etc), that can be strategically dropped in
> employee area's like, kitchens, parking lots, and or doctor lounges
> etc...
>
> The USB thumb drive contains a simple application that is hidden and it
> can capture simple information of the network or you can have the
> application install a keylogger to capture usernames/passwords etc... to
> show the company in question how simple it is to gather information
> about the network for an attack or to turn machines into bots
>
> The application is initiated when an employee has found a USB thumb
> drive and their curiosity gets the better of them. Then they plug the
> USB thumb drive into their workstation or laptop to see what is on the
> USB thumb drive. This is when the hidden application on the USB thumb
> drive is executed via two methods:
>
> 1. If the machine in which the USB thumb drive is plugged into has
> AutoRun enabled the app will execute.
> 2. If AutoRun is not enabled then there is shortcuts on the USB thumb
> drive to entice the employee to click, which will  execute the hidden
> application. Below are some examples of embedded shortcuts:
>
>               Resume.doc
>               Company Payscale.xls
>               Johnny Cash (I Walk the Line).mp3
>
> The application will encrypt the information captured and email to the
> testers for review, then the application along with the embedded
> shortcuts will delete themselves from the USB thumb drive.
>
>
> Liam Downward
>
> -----Original Message-----
> From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com]
> On Behalf Of crazy frog crazy frog
> Sent: Saturday, February 24, 2007 9:58 AM
> To: toggmeister@vulnerabilityassessment.co.uk
> Cc: pen-test@securityfocus.com
> Subject: Re: Penetration Testing Framework 0.24 released
>
> good work :)
>
> On 23 Feb 2007 11:43:22 -0000,
> toggmeister@vulnerabilityassessment.co.uk
> <toggmeister@vulnerabilityassessment.co.uk> wrote:
> > Hi all,
> >   The latest version of the Penetration Test Framework has been
> released and can be found at:
> >
> > http://www.vulnerabilityassessment.co.uk/Penetration%20Test.html
> >
> > (Pdf version also available)
> >
> > Any additions/ suggestions would be gratefully received.
> >
> > The next release 0.25 should include a Wireless Pen Test add-on, with
> the assistance from the guys at http://www.wirelessdefence.org and
> hopefully a much extended cisco section that Lee is busy putting
> together.
> >
> > Rgds
> >
> > Toggmeister a.k.a Kev Orrey
> > http://www.vulnerabilityassessment.co.uk
> >
> > ----------------------------------------------------------------------
> > --
> > This List Sponsored by: Cenzic
> >
> > Need to secure your web apps?
> > Cenzic Hailstorm finds vulnerabilities fast.
> > Click the link to buy it, try it or download Hailstorm for FREE.
> >
> > http://www.cenzic.com/products_services/download_hailstorm.php?camp=70
> > 1600000008bOW
> > ----------------------------------------------------------------------
> > --
> >
> >
>
>
> --
> ---------------------------------------
> http://www.secgeeks.com
> get a blog on secgeeks :)
> register here:-
> http://secgeeks.com/user/register
> rss feeds :-
> http://secgeeks.com/node/feed
> Submit you security articles,send them to secgeek@secgeeks.com
>
> http://www.newskicks.com
> Submit and kick for new stories from all around the world.
> ---------------------------------------
>
> ------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Need to secure your web apps?
> Cenzic Hailstorm finds vulnerabilities fast.
> Click the link to buy it, try it or download Hailstorm for FREE.
>
> http://www.cenzic.com/products_services/download_hailstorm.php?camp=7016
> 00000008bOW
> ------------------------------------------------------------------------
>
>


-- 
---------------------------------------
http://www.secgeeks.com
get a blog on secgeeks :)
register here:-
http://secgeeks.com/user/register
rss feeds :-
http://secgeeks.com/node/feed
Submit you security articles,send them to secgeek@secgeeks.com

http://www.newskicks.com
Submit and kick for new stories from all around the world.
---------------------------------------

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=70160000
0008bOW
------------------------------------------------------------------------


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>