Monday, June 15, 2009

IIS 6.0 WebDav Vulnerability Scan with Nmap

The latest Nmap 4.85BETA released and now supports scanning the recent IIS 6.0 WebDav Vulnerability.

Syntax:
nmap --script http-iis-webdav-vuln -p80,8080

Output example:
80/tcp open http syn-ack-- _ http-iis-webdav-vuln: WebDAV is ENABLED. Vulnerable folders discovered: /secret, /webdav

Metasploit Framework 3.3 also added their auxiliary module for the same function.

To update your MSF, ensure that you have the Internet connection then type:

cd /pentest/exploit/framework3
svn update

Check the latest auxiliary:

show auxiliary

- Semi

Wednesday, April 1, 2009

iFrame Injection Attack

Recently, I found several websites were attacked by "JS/Kryptik.B.Trojan", injecting iFrame to the html and php files.

Visit this site more info:
http://www.diovo.com/2009/03/hidden-iframe-injection-attacks

One of our partner has appointed us to cleanup the infected files. We provide this kind of services upon request.

- Semi

Penetration Testing and Vulnerability Assessment

A good website for those who are interested in Penetration Testing and Vulnerability Assessment:
http://www.vulnerabilityassessment.co.uk

- Semi

Monday, March 23, 2009

Speaking Engagement

If you are interested on inviting us for seminars or workshops, please directly contact us via email. The schedule should be informed at least 2 weeks before the commercing date.

Topics includes:
1. Network Security & Digital Forensics
2. Security Awarness Programme
3. Ethical Hacking
4. Penetration Testing
6. Microsoft, Cisco, Novell and CIW related topics

- Semi

Saturday, March 21, 2009

Customized Training

Our current customized training:

- Wireshark Network Security and Forensics
- Penetration Testing with BackTrack (BT3)
- Metasploit: Tactical Exploitation

All training are based on the Instructor Led Training (ILT).

- Semi

Friday, March 20, 2009

Important Update -- Regarding My Personal Blog

Important Update:
Due to some technical problems, I regret to inform you that my personal blog: http://semiyulianto.blogspot.com will no longer active. All future blog posting such as tutorials, news, updates and training related matters will be posted here in our official blog.

- Semi

Thursday, March 19, 2009

Recent Incidents

Just for your info:
Recently my personal Yahoo and GMail email accounts was "hijacked" by someone who I suspect was my CEH students from the previous batch in year 2008.
I believe this student was not happy due to an unknown reason. I have traced some evidences from some emails forwarded by one of my friends. I'm currently still hunting down the suspect.

If you happened to received emails from:
semi_y2000@yahoo.com and/or semi.yulianto@gmail.com
These emails are fake emails and NOT TRUSTED. Please ignore them as the perpetrator/hijacker was trying to do some bad things. So, please be AWARE!!!

- Semi