2 Where information should stop

I often stay away from political and economical sources, why? well due to my job and research I believe I should not be involved in any of them, is my job not to be bias against nobody that could potentially be my client, so I just shut up, even with close relatives, friends and relationships.

As the release of trapper was getting closer I started thinking what good would the complete release of the software will do, and I came up with this answers:
- Nothing, nobody would use it
- Some people would use it for kicks, mostly to hack their own networks or hack work
- It could be used to crack something large and big
- Other people would use it on their audits, call me I’m finished and keep on using my research and work.
- Man in black would seize my server (since it’s on the US) and force the app to be erased after magically appearing with a copy of it.

While the last one appears definitely far fetched the third one got me thinking seriously, not only because of the nature of my research has gone definitely into Hydras and AI / Neural Networks / Expert Systems but because potentially sooner or later it could be pushed into the light and someone will do something that would compromise the years I’ve work on the security field.

I’m not calling that a reporter, as the ones I know they have been always fair to me in developing at story, but today as I unleashed the third rewrite of trapper (yes I had to rewrite 2 times already due to redesign of the objects) someone at the starbucks checked their email via pop, in less than 5 minutes all his email was parsed, loged into facebook, found, friends found, had his avatar picture and was searching who he was talking to in MSN. At that second I realized I stupidly left the domain into * and not localhost, definitely my mistake but … it suddenly hit me, am I making stuff secure or insecure releasing this?
Continuar leyendo »

1 Trapper from sniffer to hydra

This is the presentation I’m going to push in Campus Party and in Sec-T in Sweden in september.

This is a complete recode of trapper, even changing the language for ruby, having namespaces on it and the capabilities to attack and exploit miss-configurations.

I’m going to be exporting a git repository the first week of August with the public version of Trapper 1.0 in git.security-dojo.com (It’s not setup yet so don’t even try) and version 1.1 should hit around september in Sec-T.

What stuff is being coded or tested now?

- Sniffing
- Cracking the hashes
- Using hashes to bring more hosts into the game
- Reading emails
- Reading applications
- SSH and telnet into hosts
- Start other sniffer heads in different OS (This is going to take time but oh well)
- More to come!

If you are interested in beta testing Trapper drop me an email, you might not get the chance since I’m really picky on who betas my stuff but you can try :P

0 Nahual goes to Cali!

YES! I’m getting my behind to California (Client shall remain nameless) to go there have fun around 1 or 2 weeks and go climbing and ruby coding, I’ll probably be very prolific since .. well no I won’t LoL!

I will soon release trapper 1.0 (recoded on python for the framework I’m coding)

0 Whitehat, Blackhat or .. CowHat?

Thinking today a bit i tried to ask myself in which part of the “hats” i would go into, or most ppl go into?

I’ve never been a really fan of saying you can be a “pure” color hat, so i came up with this:

Yep .. whitehat with spots of black! juuuuust like my conscience!!

0 And the XML weird parsing award goes to …

Well, yesterday I was contacted by someone and asked me to go visit a web page, I’m actually not fond of doing that at all, but him being a trustworthy person I clicked on the link and found myself looking at a alert script, “Well sure having a web page you control with java script is not a great triumph” but then I started to check exactly what was being done and executed.

Opened my IExplorer (ugh) and visited the same page, and I just saw a normal XML:

So I came back to Firefox and revisited the webpage:

Continuar leyendo »

0 [Your Worst Enemy] Your Web Scanner

Recently I saw an article about web scanners, I personaly don’t like them, why? well

1. They are slow
2. They don’t have a sense of “weight” on the exploits
3. They miss half of the complex stuff

Couple of weeks ago we lost a bid based on the fact that the client tought we did everything automatic (Errr LoL! apparently they don’t read the blog, didn’t read my resume and didn’t reaaaaally understood some facts but then again who can blame the girl that was in charge?) this was hilarious but posed a very good question:

Why all scanners SUCK ARE BAD?

Continuar leyendo »

1 Muerte al RunPE…

Bien aki mi ultima creacion para matar todos esos crypters chafas okupados por gran cantidad de malware

para ser indetectables a los AV’s

Continuar leyendo »

2 whitehats.com.mx

Hoy termine de dar de alta whitehats.com.mx un “facebook” (red social) de personas que les interese en seguridad tanto en Mexico como en el mundo, pero mas enfocado a Mexico, intentando poner cada vez mas apenfra y nhacker listo para poder hacer publish de los tools.

1 Machancando AV’s

Bien ahora para iniciar en este blog

el log de una charla ke di en un canarl irc sobre las firmas de los av’s

y como kitarselas a nuestros juguetitos experimentales xP

Continuar leyendo »

0 Problemas en mi Dell 640m con Ubuntu en kernel 2.6.24-23-generic

Bueno mi Dell 640m tiene una tarjeta de red broadcom (lo recuerdo por la flojera de tener que bajar el driver cuando instalo windows para jugar) y nunca me habia pasado nada interesante sobre el ubuntu que uso para las pruebas de volumen y desarrollo de aplicaciones.

Sin embargo hice el update y luego apague la maquina y cambie el disco, y ayer tuve que usar ese disco (pueden ver mi excelente aventura con el disco aqui) y me ocurrio algo muy interesante, perdia muchisimos paquetes pero a intervales medianamente regulares.

Esto me puso a pensar seriamente que fuera el cable, cambie el cable, igual, pense que podria ser el nodo de red, cambie de nodo fue igual de hecho cambie con alguienq ue no tuvo problemas, y luego cambie de OS, boote en Windows XP, me dije “si esta cosa se conecta hasta un gansito se conecta” y se conecto sin problemas.

Inicie en el kernel 2.6.24-22-generic y no tuve problemas, que tipo de problemas habra? a verdad no tuve tiempo de debugear pero este fin de semana o hago en el inter si tienen intermitencia bajen una version minima de kernel (de todos modos no le dan shell a nadie y usan grsec no?)