Re: Intro To Hacking

From: Andrew Smith (stfunub_at_gmail.com)
Date: 10/18/04

  • Next message: Atul Gosain: "XML Soap reporting support in security devices"
    Date: Mon, 18 Oct 2004 15:48:57 +0100
    To: Jason Dusek <jason-dusek@uiowa.edu>
    
    

    Well, basically you want to find a vulnerability in the machine that
    you can exploit,
    have a look on www.securityfocus.com,www.packetstormsecurity.org,www.zone-h.org,www.k-oitk.com
    for exploits.

    On Sun, 17 Oct 2004 14:35:52 -0500, Jason Dusek <jason-dusek@uiowa.edu> wrote:
    > Well, I do own it. It would be dumb for me to ask for an intro to hacking and
    > then make my first attempt on someone else's machine - I'd more than likely get
    > caught.
    >
    > As far as googling, google what? Even some nice keywords would help.
    >
    > _jason
    >
    >
    >
    > Andrew Smith wrote:
    > > Read, Google. Security updates, exploits, etc.
    > >
    > > I doubt you will get any specific advice here, your post sounds very
    > > much to me like you're trying to crack a server you don't actually
    > > own.
    > >
    > > Good Luck, Have Fun.
    > >
    > > On Fri, 15 Oct 2004 14:11:57 -0500, Jason Dusek <jason-dusek@uiowa.edu> wrote:
    > >
    > >>Hi,
    > >>
    > >>I have built a web server and I would like to practice hacking it remotely. Are
    > >>there any tutorials or a good introductory book that takes one step by step
    > >>through the process of 'owning' an unsecured box? Here are the stats:
    > >>
    > >> FreeBSD 4.10 (not updated for about a month)
    > >> Default security profile
    > >> Apache 2
    > >> PHP 4.3.8
    > >> No SSI
    > >> No firewall
    > >> On a university network
    > >>
    > >>_jason
    > >>
    >


  • Next message: Atul Gosain: "XML Soap reporting support in security devices"

    Relevant Pages

    • RE: Consulting Question
      ... The information is in Google, ... 2 Market Street Sydney NSW 2000 ... Subject: Consulting Question ... go about informing the company about this vulnerability without them ...
      (Security-Basics)
    • Re: [Full-disclosure] Re: Google Talk cleartext credentials in processmemory
      ... >> already been patched by Google. ... >> The vulnerability would allow anyone with access to the client system ... >> vulnerability could also be exploited by fooling the user to execute ...
      (Full-Disclosure)
    • Re: zooms zooming againZZZZZZZZZZZZZZ
      ... net about being in Viet Nam. ... Check google you dumb shit,not hardly ... flounting anything. ...
      (rec.aviation.homebuilt)
    • Re: [Full-disclosure] Overtaking Google Desktop
      ... Matan Gillon discovered a vulnerability in Internet ... danger of the IE vulnerability by attacking Google Desktop. ... Google Desktop's security was successful - because a link is maintained ... The attack, which is fully presented in a new Watchfire research paper ...
      (Full-Disclosure)
    • Re: I know that no one here uses pirated software, however....
      ... They do not mean the operating system. ... Google knows it, Microsoft knows it. ... dictionary is dumb. ... we are still in the opening phases of the technology. ...
      (misc.invest.stocks)