<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JW Network Consulting &#187; Metasploit</title>
	<atom:link href="http://www.jwnetworkconsulting.com/tag/metasploit/feed" rel="self" type="application/rss+xml" />
	<link>http://www.jwnetworkconsulting.com</link>
	<description>Watching the network so you don't have to.</description>
	<lastBuildDate>Sun, 30 Oct 2011 22:06:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Metasploit Breaks into SkyNet!</title>
		<link>http://www.jwnetworkconsulting.com/security/metasploit-breaks-into-skynet</link>
		<comments>http://www.jwnetworkconsulting.com/security/metasploit-breaks-into-skynet#comments</comments>
		<pubDate>Fri, 01 Apr 2011 14:54:14 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[april 1st]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[skynet]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=446</guid>
		<description><![CDATA[Metasploit has successfully broken into Skynet thanks to Comodo, RSA, MySQL and Stuxnet! Here is the output from msfconsole after updating today. Rock on guys. Technorati Tags: april 1st, Metasploit, skynet]]></description>
			<content:encoded><![CDATA[<p>Metasploit has successfully broken into Skynet thanks to Comodo, RSA, MySQL and Stuxnet!  Here is the output from msfconsole after updating today.  Rock on guys.</p>
<pre class="qoate-code">
(0 08:43:03 515) -&gt; ./msfconsole 

#    # ###### #####   ##    ####  #####  #       ####  # #####
##  ## #        #    #  #  #      #    # #      #    # #   #
# ## # #####    #   #    #  ####  #    # #      #    # #   #
#    # #        #   ######      # #####  #      #    # #   #
#    # #        #   #    # #    # #      #      #    # #   #
#    # ######   #   #    #  ####  #      ######  ####  #   #

       =[ metasploit v3.7.0-dev [core:3.7 api:1.0]
+ -- --=[ 673 exploits - 353 auxiliary
+ -- --=[ 217 payloads - 27 encoders - 8 nops
       =[ svn r12202 updated today (2011.04.01)

[*] Calculating new Comodo SSL CA key...
Factoring..........

-----BEGIN RSA PRIVATE KEY-----
zFBBetA9KgxVcBQB6VhJEHoLk4KL4R7tOoAQgs6WijTwzNfTubRQh1VUCbidQihV
AOWMNVS/3SWRRrcN5V2DqOWL+4TkPK522sRDK1t0C/i+XWjxeFu1zn3xXZlA2sru
OIFQvpihbLgkrfOvjA/XESgshBhMfbXZjzC1GwIDAQABAoIBAQCJoijaEXWLmvFA
thiZL7jEATCNd4PK4AyFacG8E9w8+uzR15qLcFgBTqF95R49cNSiQtP/VkGikkkc
ao25aprcu2PnNA+lpnHKajnM9G3WOHuOXHXIps08es3MmBKTxvjNph6cUlqQULrz
Zry+29DpmIN/snpY/EzLNIMptn4o6xnsjAIgJDpQfFKQztxdmZU6S6eVVn0mJ5cx
q+8TTjStaMbh+Yy73s+rcaCXzL7yqWDb1l5oQJ/DMYNfufY6lcLgZUMwFxYKjCFN
ScAPCiXFUKTzY3Hy1Z4tLndFxipyEPywDep1TB2nMb+F3OOXUs3z+kKVjGFaGnLZ
591n3x3hAoGBAOOgsb4QybjHh9+CxhUkfsqcztGGdaiI3U5R1qefXL7R47qCWfGc
FKdoJh3JwJzLOLX68ZmHz9dPhSXw6YrlLblCi6U/3g7BOMme5KRZKBTjHFo7O9II
B0laE5ISRH4OccsOC3XUf9XBkm8szzEBj95DgzB0QydPL4jp7NY0h0QrAoGBAMEv
jEFkr/JCRe2RWUAPR1LWT/DHnVLMnDb/FryN2M1fAerpMYNUc2rnndjp2cYbsGLs
cSF6Xecm3mUGqn8Y5r8QqFo0lzp5OunCFCXEJvkiU3NSs8oskCsB8QJ6vk3qmauU
-----END RSA PRIVATE KEY-----

[*] Scanning RSA tokens for usable seed.....4d416f70-5f16-0410-b530-b9f4589650da!

[*] Logging into vault.rsa.com as 'rivest'......Successful

[+] Compromised 'vault.rsa.com' via ACE backdoor...

[*] Launching SQL injection attack against MySQL.com....Done

[*] Extracting passwords hashes....Done
[+] 54,024 passwords obtained

[*] Replaying SHA1 hashes against Sun.com.......Done

[*] Attaching to Stuxnet through Oracle Command Center....!#$

#

$@#$$puTTY

!@$@vaul
t.rsa.com
# #@puTTY#$

@#

..@#$@34 m

sf&gt;.. uid=0(root) gid=0(ro
ot) groups=
0(root) @#$@#4

2 3ms

f&gt;bash-4.1# 

ERROR
NOCARRIER
[*] Welcome to SkyNet v5.23.0-BETA
[*] Launching autonomous agent...
[*] Scanning 158.95.29.10.0/22...
[*] Injecting agent code into memory...
[*]         15 Nodes Online
[*]      3,156 Nodes Online
[*]     17,024 Nodes Online
[*]  1,423,813 Nodes Online
[*]  SkyNet has been loaded
[*]  Entering command shell
msf sky-net&gt; 
</pre>
<p><!-- start wp-tags-to-technorati 1.02 --></p>
<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/april+1st' rel='tag' target='_self'>april 1st</a>, <a class='technorati-link' href='http://technorati.com/tag/Metasploit' rel='tag' target='_self'>Metasploit</a>, <a class='technorati-link' href='http://technorati.com/tag/skynet' rel='tag' target='_self'>skynet</a></p>
<p><!-- end wp-tags-to-technorati --></p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/metasploit-breaks-into-skynet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Latest Happenings and Upcoming Events</title>
		<link>http://www.jwnetworkconsulting.com/security/latest-happenings-and-upcoming-events</link>
		<comments>http://www.jwnetworkconsulting.com/security/latest-happenings-and-upcoming-events#comments</comments>
		<pubDate>Fri, 22 Oct 2010 04:47:00 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[JW Network Consulting]]></category>
		<category><![CDATA[Linux Basix Podcast]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[PFIC 2010]]></category>
		<category><![CDATA[Utah Technology Events]]></category>
		<category><![CDATA[UTOSC]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=407</guid>
		<description><![CDATA[Things have been really busy lately. First off, my Mentor session for SANS Security 504 started on September 21st.  We are at the halfway point right now and leading this has been incredible.  It seems whenever I need to present or teach something I learn more than anyone else.  Plus teaching is just fun!  Particularly [...]]]></description>
			<content:encoded><![CDATA[<p>Things have been really busy lately.  First off, my Mentor session for <a title="SANS Security 504" href="http://www.sans.org/mentor/details.php?nid=22153" target="_blank">SANS Security 504</a> started on September 21st.  We are at the halfway point right now and leading this has been incredible.  It seems whenever I need to present or teach something I learn more than anyone else.  Plus teaching is just fun!  Particularly when it is about stuff that I really enjoy.  The student reviews have been great so far, so I must be doing something right.</p>
<p>Next, the Utah Open Source Conference (UTOSC) was two weeks ago, from October 7th to the 9th.  There were a lot of great presentations and I had an absolute blast hanging out with all the technology loving folks who came.  I was somewhat surprised on how far some people came to get there.  I met people from Idaho, Wyoming, and California.  It was really fun to sit in presentations and workshops on things that aren&#8217;t necessarily security related.  It gave me some time to listen to what&#8217;s going on in other areas of technology and that&#8217;s can be really refreshing.</p>
<p>If that wasn&#8217;t enough, I also was able to speak at UTOSC again this year.  Last year I spoke on building a toolkit of open source security tools.  This year I did a presentation on Metasploit.  I picked Metasploit because I started learning how to write modules for the framework this year.  So doing a presentation on it seemed like a great way to learn even more about it.  If nothing else, it would get me to spend more time using it and that&#8217;s where things really take off.  My recording of the presentation didn&#8217;t go so well, so I&#8217;m waiting for the folks at UTOSC to release their recording.  My slides are online though and you can download them <a title="Metasploit Presentation Slides - PDF" href="http://www.jwnetworkconsulting.com/downloads/utos-msf-2010.pdf" target="_self">on this site</a> or view them at <a title="Jason Wood Presentations" href="http://www.slideshare.net/Tadaka" target="_self">SlideShare.net/Tadaka</a>.  I put the presentation slides up on SlideShare after some folks expressed their reservations about downloading a PDF file from me after I mentioned backdooring PDF files.  Go figure!</p>
<p>One offshoot of the UTOSC presentation was that one of the audience members, <a title="Joshua Williams" href="http://twitter.com/knuckleheadTech" target="_blank">Joshua Williams</a>, participates in the <a title="Linux Basix Podcast" href="http://www.linuxbasix.com/" target="_blank">Linux Basix</a> Podcast.  It turns out that Joshua does this podcast with <a title="Infolookup - Twitter" href="https://twitter.com/infolookup" target="_blank">Infolookup</a>, who is someone I know from IRC.  They were chatting about my presentation and Infolookup realized that I was the guy he knew in IRC.  One thing lead to another and I was invited to participate on last week&#8217;s Linux Basix Podcast!  We spent about an hour chatting it up about Metasploit and just covering some of the basics about it.  I really want to thank they guys for inviting me on.  I had a ton of fun and they were all extremely friendly.  You can download the podcast at <a title="Linux Basix Podcast" href="http://www.linuxbasix.com/026-LB" target="_blank">http://www.linuxbasix.com/026-LB</a>.</p>
<p>So that&#8217;s what I&#8217;ve been doing for the last month and a half or so.  Now to something still to come.  <a title="PFIC 2010" href="http://pfic2010.com/" target="_blank">Paraben&#8217;s forensics conference (PFIC)</a> will be on November 7th to 10th.  I went last year and had a great time.  Being very new to the forensics world, it was quite an interesting event.  It is in Park City, UT at The Canyons Resort.  I&#8217;m really looking forward to this year.  If you are in the Utah area and want to attend a great, inexpensive conference then check it out.  The cost is $299 and has some excellent speakers scheduled up. If you are there, let me know and we can meet somewhere.  Meeting new people is one of the really cool things about conferences like this.</p>
<p>That&#8217;s all the events at this point.  I&#8217;m hoping to get something else scheduled up in the next few months, but we will have to see how that goes.  I&#8217;m also planning on doing another SANS Mentor session next year.  I take what I learned this year and apply it to the next class.<br />
<!-- start wp-tags-to-technorati 1.02 --></p>
<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/JW+Network+Consulting' rel='tag' target='_self'>JW Network Consulting</a>, <a class='technorati-link' href='http://technorati.com/tag/Linux+Basix+Podcast' rel='tag' target='_self'>Linux Basix Podcast</a>, <a class='technorati-link' href='http://technorati.com/tag/Metasploit' rel='tag' target='_self'>Metasploit</a>, <a class='technorati-link' href='http://technorati.com/tag/PFIC+2010' rel='tag' target='_self'>PFIC 2010</a>, <a class='technorati-link' href='http://technorati.com/tag/Utah+Technology+Events' rel='tag' target='_self'>Utah Technology Events</a>, <a class='technorati-link' href='http://technorati.com/tag/UTOSC' rel='tag' target='_self'>UTOSC</a></p>
<p><!-- end wp-tags-to-technorati --></p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/latest-happenings-and-upcoming-events/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Submitted Speaking Proposal to the UTOS Conference 2010</title>
		<link>http://www.jwnetworkconsulting.com/security/submitted-speaking-proposal-to-the-utos-conference-2010</link>
		<comments>http://www.jwnetworkconsulting.com/security/submitted-speaking-proposal-to-the-utos-conference-2010#comments</comments>
		<pubDate>Tue, 15 Jun 2010 21:29:33 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Security Presentation]]></category>
		<category><![CDATA[Utah Open Source Conference]]></category>
		<category><![CDATA[UTOSC]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=363</guid>
		<description><![CDATA[Last year I was able to speak at the Utah Open Source Conference on building a security toolkit with open source software.  I just finished submitting my proposal for this year entitled &#8220;Metasploit: Free, Powerful, Flexible&#8221;.  Being able to present at UTOSC 2009 was an absolute blast and I hope that my presentation is accepted [...]]]></description>
			<content:encoded><![CDATA[<p>Last year I was able to speak at the Utah Open Source Conference on building a security toolkit with open source software.  I just finished submitting my proposal for this year entitled &#8220;Metasploit: Free, Powerful, Flexible&#8221;.  Being able to present at UTOSC 2009 was an absolute blast and I hope that my presentation is accepted this year as well.  The conference is well run and attended.  There are a ton of great topics and speakers to listen to.  Even if I don&#8217;t get accepted as a speaker, I will be there again this year.  It&#8217;s just to great to pass up on and for $35 it can&#8217;t be beat.</p>
<p><a href="http://2010.utosc.com/presentation/199/" target="_self">http://2010.utosc.com/presentation/199/</a></p>
<p>Hope to see you there!<br />
<!-- start wp-tags-to-technorati 1.02 --></p>
<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Metasploit' rel='tag' target='_self'>Metasploit</a>, <a class='technorati-link' href='http://technorati.com/tag/Security+Presentation' rel='tag' target='_self'>Security Presentation</a>, <a class='technorati-link' href='http://technorati.com/tag/Utah+Open+Source+Conference' rel='tag' target='_self'>Utah Open Source Conference</a>, <a class='technorati-link' href='http://technorati.com/tag/UTOSC' rel='tag' target='_self'>UTOSC</a></p>
<p><!-- end wp-tags-to-technorati --></p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/submitted-speaking-proposal-to-the-utos-conference-2010/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Quick Update on the Latest Activity</title>
		<link>http://www.jwnetworkconsulting.com/security/a-quick-update-on-the-latest-activity</link>
		<comments>http://www.jwnetworkconsulting.com/security/a-quick-update-on-the-latest-activity#comments</comments>
		<pubDate>Mon, 15 Feb 2010 05:57:04 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[GCIH]]></category>
		<category><![CDATA[Incident Handler]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Reconnoiter]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=320</guid>
		<description><![CDATA[It has been a busy couple of months, but my posts have been fairly quiet on the blog. Between attending the SANS Security 504 Incident Handling class, traveling for work, moving my family and the holidays things have been moving at a rapid pace.  I&#8217;m going to be trying to comment more here, but for [...]]]></description>
			<content:encoded><![CDATA[<p>It has been a busy couple of months, but my posts have been fairly quiet on the blog.  Between attending the SANS Security 504 Incident Handling class, traveling for work, moving my family and the holidays things have been moving at a rapid pace.  I&#8217;m going to be trying to comment more here, but for now a brief update.</p>
<p>First off, I took the examination for the SANS Incident Handler certification on Friday the 12th.  All the time put into preparation paid off and I passed with 96%!  It was extremely satisfying to pass this exam, since I have been spending the last several weeks studying for it.  On top of just earning the certification, my score was high enough that I can apply to become a SANS Mentor now too.  This is something that I think would be a lot of fun and I really want to do.  Time to start writing up my application and hoping for the best.</p>
<p>Last, I&#8217;ve started working on rewriting Reconnoiter to run as a Metasploit module.  I started on this late last week and have made some headway in the process.  Scrapping HTML and using the data in a script or program isn&#8217;t much fun.  The main problem I&#8217;ve run into is that Google really doesn&#8217;t want anyone doing this type of stuff.  While Yahoo! has provided a nice XML web service to aid in accessing data, Google appears to be going out of their way to make this difficult.  I&#8217;m actually a bit irritated by this since Google has taken great pains to convince everyone (with good reason on our part to do so) that we need to make it easy for Google to crawl our sites.  Just don&#8217;t expect them to return the favor.  Ah well.</p>
<p>Anyhow, I hope to have a rough module up and running by the end of this week.  Current plans are to have the ability to pull results from Google and Yahoo both.  You will be able specify an output directory to save username lists.  Plus, since this is in Metasploit, you can choose between the command line or a web interface to run the module.  That alone may be a real kicker for folks.</p>
<p>The Google query is going to be pretty buggy and a pain to maintain.  The Yahoo! query should be very solid since the script pulls from their XML web service.  The down side is that you will need an AppID to use the Yahoo! query.  So the decision is whether you want to be (relatively) anonymous but have iffy results or if you don&#8217;t mind losing some of that anominity for more accurate results.<br />
<!-- start wp-tags-to-technorati 1.02 --></p>
<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/GCIH' rel='tag' target='_self'>GCIH</a>, <a class='technorati-link' href='http://technorati.com/tag/Incident+Handler' rel='tag' target='_self'>Incident Handler</a>, <a class='technorati-link' href='http://technorati.com/tag/Metasploit' rel='tag' target='_self'>Metasploit</a>, <a class='technorati-link' href='http://technorati.com/tag/Reconnoiter' rel='tag' target='_self'>Reconnoiter</a>, <a class='technorati-link' href='http://technorati.com/tag/SANS' rel='tag' target='_self'>SANS</a></p>
<p><!-- end wp-tags-to-technorati --></p>
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/a-quick-update-on-the-latest-activity/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

