pen-test
[Top] [All Lists]

Re: Most Successful Exploits/Tools to use against windows & Linux?

To: "Pen Testee" <pentestee@mac.com>
Subject: Re: Most Successful Exploits/Tools to use against windows & Linux?
From: nnp <version5@gmail.com>
Date: Sat, 26 May 2007 06:20:02 -0700
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=Xsjl6mAmT5U+d/RQIGqU0uvybyZdMp/adV+hyikaLMnflg+eED6VWsi7Fswke8dqcxwsNvvNQza5n/FIV4dnNJUgUoYkUAd5O61np8kZK0x8q+L/FVBkxzErmGkppMhac4GQKXFugO4uSJKVCfRAChO9uyuGwhq6hxw/t4tEB0Y=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=qny+yl2EU1TbYTimIjuGEU8rhY+c3Chn8+B3Y/s8SO5GAoRLzd3S7cve08bQ1rLlQfqaPjrcJ/i4RfmvY8NeT0eoSsAyJJ47FCLYfAVUskssz80i3DLHE+erb4yLakPX2LiRZhMBFG544MsY4stFblacd/NeKLJXYMtyM2OiKJc=
In-reply-to: <927D1BBB-0112-1000-9EE2-C55BB7B3E6BC-Webmail-10015@mac.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <927D1BBB-0112-1000-9EE2-C55BB7B3E6BC-Webmail-10015@mac.com>
Resent-date: Sun, 27 May 2007 09:15:35 -0600 (MDT)
Resent-from: pen-test-return-1078484264@securityfocus.com
Resent-message-id: <20070527151535.86FA01436FA@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Free useful tools that I use include metasploit (exploit framework),
nmap (network scanner), nessus (automated vulnerability assessment
type thing) and backtrack (linux live cd, useful if you dont have your
laptop or whatever with you. Contains _lots_ of tools).  There are
loads really for different types of things whether its recon or
exploiting or whatever. The ones i've mentioned are, in their basic
usage, fire-and-forget type tools which seem to be what you're after.

For exploits milw0rm.com is good, most things find their way there
once they become public. Also subscribing to bugtraq and
full-disclosure could help.

I would give you the 'learn how to find vulns yourself...blah.. blah..
blah use your brain... blah blah blah or you'll be a script kiddy
forever' speech but to be honest I don't care :P All I will say is,
your own 0days are far more useful than public stuff.

Later,
nnp

On 5/25/07, Pen Testee <pentestee@mac.com> wrote:
I am just getting started with Pen Testing and there is soooo much information 
available.
I am trying to get the most bang for my time spent in getting up to speed.
What are the best exploits to start with so that I am likely to have the most 
success.
I am looking for suggestions from both within a network and from an external 
test...please label internal or external when providing your response.

What are the best links that list tools to use against exploits or exploits to 
try and tool to use.
A chart would be ideal.

Are there better cmd line?

Thanks!
On the hunt!

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------




--
http://www.smashthestack.org
http://www.mastersofthewang.com

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>