Tuesday, August 11, 2009

Vmware Virtual Machine Image Files Unauthorized Usage

For those who use the CEH/ECSA/LPT and CHFI Vmware virtual machine image files "Created by Semi", please do not hesitate to inform me as I'm tracking the usage of those files. Any illegal or unauthorized usage detected should not be tolerate as I was creating them for the purpose of my delivery in EC-Council security related courses/training.

- Semi

Thursday, July 23, 2009

Sample EC-Council Exam Questions

Those who would like to get some samples of the EC-Council exam questions (with answers) can request directly to me. Just email me and get a free samples of CEH, CHFI, EDRP and ECSA questions and answers for your practice or exercise purposes.

- Semi

Wednesday, July 22, 2009

Nmap 5.0 Released

Nmap by Fyodor is one of my favourites Hacking and Penetration Tools, besides hping2, scanline, unicorn scan and xprobe2.

Recently the latest Nmap 5.0 has just released by insecure.org. It has more than 600 significant changes. The top 5 improvement in Nmap includes: Ncat, Ndiff and NSE.

For more info, refer to: http://www.insecure.org

- Semi

Monday, June 15, 2009

IIS 6.0 WebDav Vulnerability Scan with Nmap

The latest Nmap 4.85BETA released and now supports scanning the recent IIS 6.0 WebDav Vulnerability.

Syntax:
nmap --script http-iis-webdav-vuln -p80,8080

Output example:
80/tcp open http syn-ack-- _ http-iis-webdav-vuln: WebDAV is ENABLED. Vulnerable folders discovered: /secret, /webdav

Metasploit Framework 3.3 also added their auxiliary module for the same function.

To update your MSF, ensure that you have the Internet connection then type:

cd /pentest/exploit/framework3
svn update

Check the latest auxiliary:

show auxiliary

- Semi

Wednesday, April 1, 2009

iFrame Injection Attack

Recently, I found several websites were attacked by "JS/Kryptik.B.Trojan", injecting iFrame to the html and php files.

Visit this site more info:
http://www.diovo.com/2009/03/hidden-iframe-injection-attacks

One of our partner has appointed us to cleanup the infected files. We provide this kind of services upon request.

- Semi

Penetration Testing and Vulnerability Assessment

A good website for those who are interested in Penetration Testing and Vulnerability Assessment:
http://www.vulnerabilityassessment.co.uk

- Semi

Monday, March 23, 2009

Speaking Engagement

If you are interested on inviting us for seminars or workshops, please directly contact us via email. The schedule should be informed at least 2 weeks before the commercing date.

Topics includes:
1. Network Security & Digital Forensics
2. Security Awarness Programme
3. Ethical Hacking
4. Penetration Testing
6. Microsoft, Cisco, Novell and CIW related topics

- Semi