<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-28132916</id><updated>2011-08-16T03:44:01.502-04:00</updated><title type='text'>Muts' Blog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://secmaniac.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>19</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-28132916.post-6050611361327075016</id><published>2009-05-26T19:05:00.002-04:00</published><updated>2009-05-26T19:06:01.116-04:00</updated><title type='text'>Goodbye Blog, Hello BackTrack 4</title><content type='html'>I've consolidated all my blogs at :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/blog"&gt;http://www.offensive-security.com/blog&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This new blog will keep you updated with the latest and greatest in the world of BackTrack.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-6050611361327075016?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/6050611361327075016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/6050611361327075016'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2009/05/goodbye-blog-hello-backtrack-4.html' title='Goodbye Blog, Hello BackTrack 4'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-975370582878185587</id><published>2009-03-28T19:31:00.006-04:00</published><updated>2009-03-29T13:41:19.593-04:00</updated><title type='text'>Offensive-Security.com Cowpatty Rainbow Table Collection</title><content type='html'>We've finally gotten up to uploading and hosting our massive Offensive Security Cowpatty WPA rainbow tables.&lt;br /&gt;&lt;br /&gt;We've crunched the top 200 SSIDs, with a 49 million password WPA optimised dictionary file. The list will be updated as we continue uploading new files....&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/wpa-tables/"&gt;http://www.offensive-security.com/wpa-tables/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please help seeding these files if possible. Pushing hundreds of GBs across the internet is not a simple task :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-975370582878185587?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/975370582878185587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/975370582878185587'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2009/03/cowpatty-rainbow-table-collection.html' title='Offensive-Security.com Cowpatty Rainbow Table Collection'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-5795207747483601491</id><published>2009-01-30T13:27:00.007-05:00</published><updated>2009-01-30T19:29:02.746-05:00</updated><title type='text'>Cracking WPA at the speed of pico</title><content type='html'>We're building a new WPA Rainbow Table cracking collection, using a 40 million long password list.&lt;br /&gt;Each table is 1.9 GB, created per SSID. We're crunching through the top 500 SSIDs for this project, with David from Pico Computing leading the way.&lt;br /&gt;&lt;br /&gt;The tables will be used in a contest at shmoo, and later on be available on torrents. We presently have over 350 GB of tables, and still counting.&lt;br /&gt;&lt;br /&gt;This is what aircrack-ng looks like when connected to an array of 35 E16 picos:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_rar6qXehJDE/SYNHlJb4QqI/AAAAAAAAACo/CKLV08lKgo0/s1600-h/aircrack-ng-35cards.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 250px;" src="http://2.bp.blogspot.com/_rar6qXehJDE/SYNHlJb4QqI/AAAAAAAAACo/CKLV08lKgo0/s400/aircrack-ng-35cards.JPG" alt="" id="BLOGGER_PHOTO_ID_5297156290231419554" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-5795207747483601491?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/5795207747483601491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/5795207747483601491'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2009/01/cracking-wpa-at-speed-of-pico.html' title='Cracking WPA at the speed of pico'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_rar6qXehJDE/SYNHlJb4QqI/AAAAAAAAACo/CKLV08lKgo0/s72-c/aircrack-ng-35cards.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-1295532400986275354</id><published>2009-01-30T01:14:00.003-05:00</published><updated>2009-01-30T01:51:08.295-05:00</updated><title type='text'>BackTrack 4 Beta almost out of the oven!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_rar6qXehJDE/SYKeFV2yeFI/AAAAAAAAACU/WuHzS7D30l0/s1600-h/origin2.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 400px; height: 250px;" src="http://4.bp.blogspot.com/_rar6qXehJDE/SYKeFV2yeFI/AAAAAAAAACU/WuHzS7D30l0/s400/origin2.jpg" alt="" id="BLOGGER_PHOTO_ID_5296969926344603730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Once again, it's that time of the year... we are working hard on BackTrack 4 and it will be released in the very near future...&lt;br /&gt;&lt;br /&gt;I've set up a small blog where I'll be able to post BT4 related information, until our wiki is fully functional.  Check it out here : &lt;a href="http://backtrack4.blogspot.com/"&gt;http://backtrack4.blogspot.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-1295532400986275354?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/1295532400986275354'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/1295532400986275354'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2009/01/backtrack-4-almost-out-of-oven.html' title='BackTrack 4 Beta almost out of the oven!'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_rar6qXehJDE/SYKeFV2yeFI/AAAAAAAAACU/WuHzS7D30l0/s72-c/origin2.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-2655338847281164765</id><published>2008-12-10T14:15:00.007-05:00</published><updated>2008-12-10T17:01:26.896-05:00</updated><title type='text'>MS Internet Explorer XML Parsing Remote Buffer Overflow Exploit</title><content type='html'>Just downloaded it from:&lt;br /&gt;&lt;a href="http://milw0rm.com/exploits/7403"&gt;http://milw0rm.com/exploits/7403&lt;/a&gt;&lt;br /&gt;Played around with it, got code exec in Vista SP1:&lt;br /&gt;&lt;a href="http://www.offensive-security.com/0day/iesploit-vista.rar"&gt;http://www.offensive-security.com/0day/iesploit-vista.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img id="BLOGGER_PHOTO_ID_5278243919440344354" style="margin: 0px auto 10px; display: block; width: 400px; height: 251px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_rar6qXehJDE/SUAW4SAbdSI/AAAAAAAAAB4/iiNWeqc_w2o/s400/vista-calc.jpg" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;Updated my Vista Box:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_rar6qXehJDE/SUAXty0uFCI/AAAAAAAAACA/pQWWM07Qktg/s1600-h/vista-updates.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 78px;" src="http://4.bp.blogspot.com/_rar6qXehJDE/SUAXty0uFCI/AAAAAAAAACA/pQWWM07Qktg/s400/vista-updates.jpg" alt="" id="BLOGGER_PHOTO_ID_5278244838782669858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After fully patching my box, the exploit was still working, giving full code exec. Yikes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-2655338847281164765?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/2655338847281164765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/2655338847281164765'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2008/12/ms-internet-explorer-xml-parsing-remote.html' title='MS Internet Explorer XML Parsing Remote Buffer Overflow Exploit'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rar6qXehJDE/SUAW4SAbdSI/AAAAAAAAAB4/iiNWeqc_w2o/s72-c/vista-calc.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-6231102752419781585</id><published>2008-07-01T20:16:00.010-04:00</published><updated>2008-07-01T21:40:15.703-04:00</updated><title type='text'>Metasploit 3 on an iPhone</title><content type='html'>The idea of getting Metasploit 3 on an iPhone has been bugging me for a while.&lt;br /&gt;We've already put it on a &lt;a href="http://remote-exploit.org/research/OpenWRTvsMetasploit.html"&gt;WRT54g&lt;/a&gt;, so having it on an iphone was a must.&lt;br /&gt;The Ruby package in the iPhone installer is broken, and recompiling it... just didn't seem like fun.&lt;br /&gt;I haven't had too much background with installing iPhone firmwares, so i called on my trustworthy friend, Jacky.&lt;br /&gt;&lt;br /&gt;I read that the Cydia installer was a better environment (BSD Subsystem replacement) for these games...so after a painful process of bricking my iPhone, being saved by Jacky,&lt;span style="font-weight: bold;"&gt; installing Cydia, ruby, wget, mobile terminal, svn and downloading metasploit&lt;/span&gt; - we got it to work!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;iPwn&lt;/span&gt; takes on a whole new meaning :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.offensive-security.com/images/iphone01.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px;" src="http://www.offensive-security.com/images/iphone01.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.offensive-security.com/images/iphone02.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px;" src="http://www.offensive-security.com/images/iphone02.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.offensive-security.com/images/iphone03.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px;" src="http://www.offensive-security.com/images/iphone03.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/images/iphone01.jpg"&gt;http://www.offensive-security.com/images/iphone01.jpg&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/images/iphone02.jpg"&gt;http://www.offensive-security.com/images/iphone02.jpg&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/images/iphone03.jpg"&gt;http://www.offensive-security.com/images/iphone03.jpg&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/images/iphone04.jpg"&gt;http://www.offensive-security.com/images/iphone04.jpg&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/images/iphone05.jpg"&gt;http://www.offensive-security.com/images/iphone05.jpg&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS - Just to later find out that Metasploit 3 is already included in the Cydia installer...ugh.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-6231102752419781585?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/6231102752419781585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/6231102752419781585'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2008/07/metasploit-3-on-iphone.html' title='Metasploit 3 on an iPhone'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-1374941044844436431</id><published>2008-06-10T03:10:00.022-04:00</published><updated>2008-06-18T22:07:07.942-04:00</updated><title type='text'>BackTrack 3 Final - Release Information</title><content type='html'>It's finally happening....BackTrack 3 Final is being released....Finally!&lt;br /&gt;Max, Martin and I have slaved for weeks and months, together with the help of many remote-exploit'ers to bring you this fine release. As usual, this version overshadows the previous ones with extra cool things.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Saint&lt;/span&gt;&lt;br /&gt;SAINT has provided BackTrack users with a functional version of SAINT, pending a free request for an IP range license through the SAINT website, valid for 1 year. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Maltego&lt;/span&gt;&lt;br /&gt;The guys over at Paterva have created a special version of Maltego v2.0 with a community license especially for BackTrack users. We would like to thank Paterva for co-operating with us and allowing us to feature this amazing tool in BackTrack. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Nessus&lt;/span&gt;&lt;br /&gt;Tenable would not allow for redistribution of Nessus.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Kernel&lt;/span&gt;&lt;br /&gt;2.6.21.5. Yes, yes, stop whining....We had serious deliberations concerning the BT3 kernel. We decided not to upgrade to a newer kernel as wireless injection patches were not fully tested and verified. We did not want to jeopardize the awesome wireless capabilities of BT3 for the sake of sexiness or slightly increased hardware compatibilities. All relevant security patches have been applied.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tools&lt;/span&gt;&lt;br /&gt;As usual, updated, sharpened, SVN'ed and armed to the teeth. This release we have some special features such as spoonwep, fastrack and other cool additions.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Availability&lt;/span&gt;&lt;br /&gt;We will be releasing an internal "IRC pre release" version of BT3F for final testing and identification of  possible blunders...and shortly after that we will have a full blown release.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Final Requests&lt;/span&gt;&lt;br /&gt;We request the community to not mirror or torrent this release, or otherwise distribute it online without our knowledge. We are trying to gather statistics about          bt3 downloads. If you would like to mirror BT3 then please:&lt;br /&gt;1) Think again! Traffic generated by BT3 downloads is CRAZY.&lt;br /&gt;2) Please contact us before doing so.&lt;br /&gt;3) Send us monthly statistics of downloads for the iso.&lt;br /&gt;&lt;br /&gt;If you would like to add a link to BackTrack downloads to your website, please use:&lt;br /&gt;&lt;br /&gt;http://www.remote-exploit.org/backtrack_download.html as the download link.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Rants&lt;/span&gt;&lt;br /&gt;Problems, fixes, bugs, opinions - should all end up in our Remote Exploit community forums, and our wiki:&lt;br /&gt;&lt;br /&gt;http://forums.remote-exploit.org&lt;br /&gt;http://wiki.remote-exploit.org&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Over and out, &lt;br /&gt;&lt;br /&gt;Muts, Max, MjM&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-1374941044844436431?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/1374941044844436431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/1374941044844436431'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2008/06/backtrack-3-final-release-information.html' title='BackTrack 3 Final - Release Information'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-6541432257638953177</id><published>2007-12-13T23:47:00.000-05:00</published><updated>2007-12-14T01:09:44.188-05:00</updated><title type='text'>BackTrack 3 Beta out!</title><content type='html'>Max Martin and I are ecstatically happy to announce that Backtrack 3 Beta is available for download.&lt;br /&gt;&lt;br /&gt;We are all suffering from lack of sleep - we will make a public announcement about this tomorrow.&lt;br /&gt;&lt;br /&gt;The images are currently being uploaded to mirrorswitch servers, and a torrent has been made available:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;BackTrack 3 Beta ISO version (Stripped Down - 700 mb)&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/bt3b141207.iso.torrent" target="_blank"&gt;http://www.offensive-security.com/bt...07.iso.torrent&lt;/a&gt;&lt;br /&gt;md5sum : 04ed8742fc8facd1ecc8c9f6f567c116&lt;br /&gt;shasum : 70c33e0aa75a978b8a87a207bf488ecec8d10a87&lt;br /&gt;&lt;br /&gt;&lt;b&gt;BackTrack 3 Beta USB version (946 mb)&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/bt3b141207.rar.torrent" target="_blank"&gt;http://www.offensive-security.com/bt...07.rar.torrent&lt;/a&gt;&lt;br /&gt;md5sum : bd0d8f507502787184b187f5a39288df&lt;br /&gt;shasum : 853b80a77e3881e8084c797ba55077ead15f84ae&lt;br /&gt;&lt;br /&gt;More info, howtos, changelogs etc will be updated on our wiki:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://backtrack.offensive-security.com/"&gt;http://backtrack.offensive-security.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We need sleep.&lt;br /&gt;&lt;br /&gt;Enjoy !&lt;br /&gt;&lt;br /&gt;Muts&lt;br /&gt;&lt;br /&gt;&lt;script src="http://slashdot.org/slashdot-it.js" type="text/javascript"&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-6541432257638953177?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/6541432257638953177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/6541432257638953177'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2007/12/backtrack-3-beta-out.html' title='BackTrack 3 Beta out!'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-4653635033180951093</id><published>2007-12-03T15:34:00.000-05:00</published><updated>2007-12-03T15:47:10.116-05:00</updated><title type='text'>BT3 Beta ETA - 14th Dec 2007</title><content type='html'>I've finally managed to pull Max Martin and me out of the proverbial work cycle we're in - we plan to release the Beta on the 14th Dec 2007.&lt;br /&gt;"Beta" means we think this version is stable and ready, and need final confirmation from the community before adding a few more modules and tweaks,  and calling it a final.&lt;br /&gt;&lt;br /&gt;There will be 2 releases of BT3 - a ~700 mb iso file, and a ~1 GB USB stick image. Compiz will NOT be included in the stock 700 mb bt3 iso. We have to fight for each MB on the iso...and compiz is far from being useful in a penetration test environment. We DO however plan to have compiz modules for download separately, and to add them to the 1 GB distribution.&lt;br /&gt;&lt;br /&gt;Hurray!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-4653635033180951093?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/4653635033180951093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/4653635033180951093'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2007/12/bt3-beta-eta-14th-dec-2007.html' title='BT3 Beta ETA - 14th Dec 2007'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-1451223877056601747</id><published>2007-09-26T11:17:00.000-04:00</published><updated>2007-11-14T17:47:05.221-05:00</updated><title type='text'>BackTrack 3 in the oven!</title><content type='html'>Max, Martin and I have started working on BackTrack 3....and boy...it's sexy. I know I've said this before about BackTrack 2...but really....it's sexy...sexier than ever before.&lt;br /&gt;New shiny kernel, new patched wifi drivers, compiz working out of the box (so we can all pwn like r0ckstarz). We are planning on new public repositories for BT3 - for better support for updates and HD installs.&lt;br /&gt;&lt;br /&gt;We still don't have an ETA for BT3...but one thing is for sure - it will be worth the wait! More info about BT3 dev to follow in the next few weeks.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.offensive-security.com/images/omg.png"&gt;&lt;img style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 400px; CURSOR: pointer; TEXT-ALIGN: center" alt="" src="http://www.offensive-security.com/images/omg.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;PS - I've updated the offsec website with this BackTrack 3 Teaser:&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.offensive-security.com/movies/bt3teaser/bt3teaser.html"&gt;http://www.offensive-security.com/movies/bt3teaser/bt3teaser.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-1451223877056601747?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/1451223877056601747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/1451223877056601747'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2007/09/backtrack-3-in-oven.html' title='BackTrack 3 in the oven!'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-2832422793024802047</id><published>2007-04-13T09:14:00.000-04:00</published><updated>2007-04-13T10:30:29.928-04:00</updated><title type='text'>Microsoft Bugs vs Features</title><content type='html'>I've been watching the developments of the "Word 2007" doc bugs fiasco. Its seems like Microsoft are calling these crashes "features" rather than bugs.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.computerworld.com.au/index.php/id;377659799;fp;2;fpid;1"&gt;http://www.computerworld.com.au/index.php/id;377659799;fp;2;fpid;1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'm not sure if this is the result of IT security media contorting the infomation they recieve and presenting it in a provocative way, or if Microsoft are really trying to blow off these bugs as part of their application design.&lt;br /&gt;&lt;br /&gt;To make things clear - The bugs that I released are proof of concepts which cause denial of service. In their current state, they do not present a real threat to Word 2007 users. However, having an application crash or consume 100% CPU on a machine due to malformed user input - is probably the most classical description of a software bug.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_rar6qXehJDE/Rh-HbQ6OxCI/AAAAAAAAABU/6w9TRonxHvU/s1600-h/wordcpu.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_rar6qXehJDE/Rh-HbQ6OxCI/AAAAAAAAABU/6w9TRonxHvU/s320/wordcpu.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5052906209398408226" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It also seems that there is no mention of the HLP heap overflow, which probably presents more danger than all 3 doc bugs combined.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-2832422793024802047?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/2832422793024802047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/2832422793024802047'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2007/04/microsoft-bugs-vs-features.html' title='Microsoft Bugs vs Features'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_rar6qXehJDE/Rh-HbQ6OxCI/AAAAAAAAABU/6w9TRonxHvU/s72-c/wordcpu.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-5645299857630632920</id><published>2007-04-11T18:00:00.000-04:00</published><updated>2007-04-11T19:44:59.845-04:00</updated><title type='text'>Microsoft DOC bugs and friends</title><content type='html'>Wow! Who thought 7 lines of python could go so far.&lt;br /&gt;&lt;br /&gt;A few days ago I released a few proof of concepts to full disclosure - &lt;a href="http://seclists.org/fulldisclosure/2007/Apr/0325.html"&gt;http://seclists.org/fulldisclosure/2007/Apr/0325.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3 doc files which crashed my Word 2007, and a hlp file which when analysed looked like a classic heap overflow, with a twist or two.&lt;br /&gt;&lt;br /&gt;It looks like there is some confusion by Microsoft - who for some reason are not able to reproduce these bugs -&lt;a href="http://www.scmagazine.com/uk/news/article/649985/post-patch-tuesday-microsoft-vulnerabilities-posted-exploit-sites/"&gt;http://www.scmagazine.com/uk/news/article/649985/post-patch-tuesday-microsoft-vulnerabilities-posted-exploit-sites/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I've recieved many mails from full disclosure members confirming the crash. Someone even mentioned Word 2004 crashing on OSX.&lt;br /&gt;&lt;br /&gt;So just to make things clear - here are some screenshots of the crashes. I fully hope that Microsoft will find the resources to figure this out.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_rar6qXehJDE/Rh1pBQ6Ow_I/AAAAAAAAAA8/1DxQudH3Fec/s1600-h/doc1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5052309827419554802" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_rar6qXehJDE/Rh1pBQ6Ow_I/AAAAAAAAAA8/1DxQudH3Fec/s320/doc1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_rar6qXehJDE/Rh1pBQ6OxAI/AAAAAAAAABE/Oe0jzU03MEo/s1600-h/doc2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5052309827419554818" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_rar6qXehJDE/Rh1pBQ6OxAI/AAAAAAAAABE/Oe0jzU03MEo/s320/doc2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;PS - The really interesting part is this... Does anyone remember the old HLP heap overflow condition ? - &lt;a href="http://www.securityfocus.com/archive/1/archive/1/430871/100/0/threaded"&gt;http://www.securityfocus.com/archive/1/archive/1/430871/100/0/threaded&lt;/a&gt; &lt;/p&gt;&lt;p&gt;It turns out, that by simply copy/pasting the OLD hlp file mentioned in the post and executing it on a fully patched XP SP2 machine one would have triggered this new heap overflow....QA anyone ?&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-5645299857630632920?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/5645299857630632920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/5645299857630632920'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2007/04/microsoft-doc-bugs.html' title='Microsoft DOC bugs and friends'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_rar6qXehJDE/Rh1pBQ6Ow_I/AAAAAAAAAA8/1DxQudH3Fec/s72-c/doc1.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-5756446702658763273</id><published>2007-02-13T08:40:00.000-05:00</published><updated>2007-02-13T08:49:31.468-05:00</updated><title type='text'>BackTrack 2.0 Final Due End of Febuary</title><content type='html'>We have been working really hard on BackTrack 2.0 Final.&lt;br /&gt;I managed to change kernels (twice), and I think I broke some sort of record in fuxxing up BT :)&lt;br /&gt;Things are looking good however, with some nice features included into v.2.0 final. These are just a few:&lt;br /&gt;&lt;br /&gt;* Updated to Kernel 2.6.19&lt;br /&gt;* Broadcom Wifi drivers +injection (bcm43xx)&lt;br /&gt;* IPW2200 Wifi drivers + injection&lt;br /&gt;* RTL8180 Wifi drivers + injection&lt;br /&gt;* RTL8187 Wifi drivers + injection&lt;br /&gt;* Support for a wider range of Wifi cards&lt;br /&gt;* Fixed BT JTR PXE Cluster Pack&lt;br /&gt;* Added Metasploit PXE ninja&lt;br /&gt;* Updated tools and packages&lt;br /&gt;&lt;br /&gt;Things are looking extremely sexy, and we hope to have a final release by the end of Febuary.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-5756446702658763273?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/5756446702658763273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/5756446702658763273'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2007/02/backtrack-20-final-due-end-of-febuary.html' title='BackTrack 2.0 Final Due End of Febuary'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-116087070250817696</id><published>2006-10-14T20:03:00.000-04:00</published><updated>2006-10-14T20:17:04.906-04:00</updated><title type='text'>BackTrack v2.0 Public Beta Has Been Released!</title><content type='html'>Released a public Beta version today. Max and I have stomped out most of the bugs, and after s short testing period, we'll release the final. Send feedback!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.offensive-security.com/downloads.html"&gt;http://www.offensive-security.com/downloads.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-116087070250817696?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/116087070250817696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/116087070250817696'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2006/10/backtrack-v20-public-beta-has-been.html' title='BackTrack v2.0 Public Beta Has Been Released!'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-115979043036229895</id><published>2006-10-02T07:56:00.000-04:00</published><updated>2006-10-02T08:00:30.373-04:00</updated><title type='text'>McAfee Epolicy Orchestrator / ProtectionPilot Buffer Overflow</title><content type='html'>I've released a PoC exploit for  McAfee Epolicy Orchestrator / ProtectionPilot  last night.&lt;br /&gt;This exploit was tested on Win2k SP4 / Win2k3 sp1.&lt;br /&gt;McAfee were notified on the 14th July, and havn't managed to get it pacthed since.&lt;br /&gt;&lt;br /&gt;Proof of concept exploit code is available at:&lt;br /&gt;&lt;a href="http://www.remote-exploit.org/exploits/mcafee_epolicy_source.pm"&gt;http://www.remote-exploit.org/exploits/mcafee_epolicy_source.pm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And a short article describing the exploit is available at :&lt;br /&gt;&lt;a href="http://www.remote-exploit.org/advisories/mcafee-epo.pdf"&gt;http://www.remote-exploit.org/advisories/mcafee-epo.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-115979043036229895?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/115979043036229895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/115979043036229895'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2006/10/mcafee-epolicy-orchestrator.html' title='McAfee Epolicy Orchestrator / ProtectionPilot Buffer Overflow'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-115917835419848427</id><published>2006-09-25T05:58:00.000-04:00</published><updated>2006-09-25T06:14:44.696-04:00</updated><title type='text'>BackTrack John the Ripper (MPI) Cluster Server</title><content type='html'>I've been working on a password cracking cluster. I will be integrating this into the next version of BackTrack (which is currently under development).  The general idea is to have a BackTrack CD with PXE capabilities. Computers can now boot from the network, and join the Cracking cluster.&lt;br /&gt;&lt;br /&gt;For more info, check this:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.remote-exploit.org/BTJTRMPI.pdf"&gt;http://www.remote-exploit.org/BTJTRMPI.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-115917835419848427?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/115917835419848427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/115917835419848427'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2006/09/backtrack-john-ripper-mpi-cluster.html' title='BackTrack John the Ripper (MPI) Cluster Server'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-114769824849337300</id><published>2006-05-15T09:00:00.000-04:00</published><updated>2006-05-18T19:50:14.756-04:00</updated><title type='text'>Back|Track Security Final Release</title><content type='html'>After spending countless hours flattening out bugs - Max and I will soon be releasing the final version of BackTrack.  Our estimated date is the 26th May, but of course, subject to change.&lt;br /&gt;&lt;br /&gt;Check &lt;a href="http://www.remote-exploit.org/index.php/BackTrack"&gt;http://www.remote-exploit.org/index.php/BackTrack&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We've decided to beta test the final release, and provide a limited download to our hardcore IRC users - just to make sure we havn't messed anything up. Several nice  people are helping us host this iso. PLEASE GIVE FEEDBACK.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://backtrack.mick27.info/iso/backtrack-final-18-5-06.iso"&gt;&lt;span style="color: rgb(51, 204, 0);font-size:100%;" &gt;&lt;span style="font-family:MS Sans Serif;"&gt;http://backtrack.mick27.info/iso/backtrack-final-18-5-06.iso&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://64.27.12.222/backtrack-final-18-5-06.iso"&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;http://64.27.12.222/backtrack-final-18-5-06.iso&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;MD5sum : 14ebbbf7f914cc547fba995c513fa4bf&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-114769824849337300?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/114769824849337300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/114769824849337300'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2006/05/backtrack-security-final-release.html' title='Back|Track Security Final Release'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-114769351825217799</id><published>2006-05-15T08:44:00.000-04:00</published><updated>2007-04-13T09:47:41.804-04:00</updated><title type='text'>Metasploit on WRTSL54GS</title><content type='html'>After mucking around with my NEW Linksys router, a managed to get Metasploit Framework to run on it. More information can be found in the remote-exploit site:&lt;br /&gt;&lt;a href="http://www.remote-exploit.org/research/OpenWRTvsMetasploit.html"&gt;http://www.remote-exploit.org/research/OpenWRTvsMetasploit.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-114769351825217799?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/114769351825217799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/114769351825217799'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2006/05/metasploit-on-wrtsl54gs.html' title='Metasploit on WRTSL54GS'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-28132916.post-114769468072427587</id><published>2006-05-15T08:03:00.000-04:00</published><updated>2006-05-15T11:50:52.120-04:00</updated><title type='text'>Unbricking a WRT54G</title><content type='html'>I bricked my WRT54G. T'was a sad day. Well, to be honest, I didn't exactly "brick" it, I had openwrt on it, with no "boot_wait", and i had forgotten the ssh password to it. It seemed like the only option I had was do build a serial console for it, and solder it to the WRT54G board - which made me shudder. After googling for a while, I found an interesting article describing an "unbricking" method which worked for me. The whole presentation can be found at &lt;a href="http://www.trilug.org/talks/2004-09-wrt54g/Hacking_The_WRT54G_Presentation.PDF"&gt;http://www.trilug.org/talks/2004-09-wrt54g/Hacking_The_WRT54G_Presentation.PDF&lt;/a&gt; .&lt;br /&gt;Apparently, this is a dangerous procedure, which can result in a completely DEAD WRT, be warned.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/2819/2975/1600/unbrick-wrt54g.0.png"&gt;&lt;img style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://photos1.blogger.com/blogger/2819/2975/320/unbrick-wrt54g.0.png" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/28132916-114769468072427587?l=secmaniac.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/114769468072427587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/28132916/posts/default/114769468072427587'/><link rel='alternate' type='text/html' href='http://secmaniac.blogspot.com/2006/05/unbricking-wrt54g.html' title='Unbricking a WRT54G'/><author><name>muts</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
