<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6549631640472379526</id><updated>2011-07-07T21:12:47.732-03:00</updated><category term='linux'/><category term='scanner'/><category term='desempenho'/><category term='grub'/><category term='java'/><category term='exploit-db'/><category term='Rails'/><category term='SQL Server'/><category term='nmap'/><category term='compact framework'/><category term='explorer'/><category term='tortoise'/><category term='aurora'/><category term='metasploit'/><category term='thread'/><category term='scan'/><category term='segurança'/><category term='backtrack'/><category term='port scan'/><category term='ferramentas'/><category term='Ruby'/><category term='kernel'/><category term='RoR'/><category term='internet'/><category term='log'/><category term='.net'/><category term='performance'/><category term='windows mobile'/><category term='exploit'/><category term='svn'/><category term='.svn'/><title type='text'>Giorge Henrique Abdala</title><subtitle type='html'>Blog com comentários e notícias sobre programação, segurança da informação e afins...</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>15</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-5538389833711383995</id><published>2010-03-23T17:10:00.013-03:00</published><updated>2010-03-23T17:44:19.291-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RoR'/><category scheme='http://www.blogger.com/atom/ns#' term='java'/><category scheme='http://www.blogger.com/atom/ns#' term='thread'/><category scheme='http://www.blogger.com/atom/ns#' term='Ruby'/><category scheme='http://www.blogger.com/atom/ns#' term='Rails'/><title type='text'>Ruby on Rails para Javaneses</title><summary type='text'>Há pouco tempo entrei em um projeto voluntário para Web com Ruby on Rails. Legal né?? O problema é que nunca tinha mexido com RoR ou qualquer coisa parecida. Meu forte sempre foi Java, C# e outras linguagens "estáticas". Para quem vem do Java, Ruby é assustador. De cara já tive uma sensação do tipo: "aqui pode tudo", muito diferente do "quase tudo é proibido" do Java. Passado o perído do "nossa! </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/5538389833711383995/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/03/ruby-on-rails-para-javaneses.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/5538389833711383995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/5538389833711383995'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/03/ruby-on-rails-para-javaneses.html' title='Ruby on Rails para Javaneses'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-6264178789780284165</id><published>2010-03-21T16:57:00.007-03:00</published><updated>2010-03-21T20:07:35.522-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='log'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>Apagando arquivos de Log</title><summary type='text'>Recentemente precisei escrever um script simples para apagar logs de acesso de um sistema debian. Não é nada comparado com qualquer log cleaner, mas, deu pro gasto.
Segue código:

 #!/bin/bash

USUARIO=$1
IP=$2

MESSAGES=/var/log/messages
FTP=/var/log/vsftpd.log
LOGIN=/var/log/wtmp
AUTH=/var/log/auth.log


if [ $# -lt 1 ] ; then
    echo "uso: clean usuario [arquivo]"
    exit;
fi


if [ $USUARIO</summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/6264178789780284165/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/03/apagando-arquivos-de-log.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/6264178789780284165'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/6264178789780284165'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/03/apagando-arquivos-de-log.html' title='Apagando arquivos de Log'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-4176652043178073590</id><published>2010-02-11T21:09:00.003-02:00</published><updated>2010-02-11T21:25:53.207-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='.svn'/><category scheme='http://www.blogger.com/atom/ns#' term='tortoise'/><category scheme='http://www.blogger.com/atom/ns#' term='svn'/><title type='text'>Apagar todas as pastas .svn</title><summary type='text'>Quando queremos mudar nosso repositório SVN de lugar, ou ainda quando o tortoise (ou outras ferramentas similares) gera aqueles erros "sinistros" que nem um "cleanup" resolve, precisamos apagar todos as pastas .svn de nosso projeto. Obviamente, dependendo do tamanho do projeto, é inviável entrar pasta por pasta e apagar todos .svn. Para resolver esse problema tem uma linha de comando que faz todo</summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/4176652043178073590/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/02/apagar-todas-as-pastas-svn.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/4176652043178073590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/4176652043178073590'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/02/apagar-todas-as-pastas-svn.html' title='Apagar todas as pastas .svn'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-2678137565843241340</id><published>2010-01-22T08:31:00.002-02:00</published><updated>2010-01-22T08:32:35.752-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='scanner'/><category scheme='http://www.blogger.com/atom/ns#' term='scan'/><category scheme='http://www.blogger.com/atom/ns#' term='nmap'/><category scheme='http://www.blogger.com/atom/ns#' term='port scan'/><title type='text'>Lançado Nmap 5.20</title><summary type='text'>Confira as novidades:

30 novos engine scripts adicionados.
melhor desempenho e consumo de memória reduzido.
Protocolo específico de payload para scanners UDP mais efetivos.
engine traceroute completamente reescrita.
Update das assinaturas para detecção de versões de SO e Bancos de dados (mais de 10.000 assinaturas)

Download aqui.


Giorge Henrique Abdala </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/2678137565843241340/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/lancado-nmap-520.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/2678137565843241340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/2678137565843241340'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/lancado-nmap-520.html' title='Lançado Nmap 5.20'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-3628289183919165430</id><published>2010-01-22T07:21:00.004-02:00</published><updated>2010-01-28T00:40:42.974-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='performance'/><category scheme='http://www.blogger.com/atom/ns#' term='windows mobile'/><category scheme='http://www.blogger.com/atom/ns#' term='compact framework'/><category scheme='http://www.blogger.com/atom/ns#' term='.net'/><category scheme='http://www.blogger.com/atom/ns#' term='desempenho'/><title type='text'>Dicas para melhorar a performance do .Net Compact Framework</title><summary type='text'>Neste artigo veremos algumas dicas para resolver problemas comuns de desempenho em aplicações para Windows Mobile com o .Net compact framework. Devido às limitações de hardware, quando desenvolvemos para dispositivos móveis, precisamos nos preocupar com a performance da aplicação  e evitar as "bad pratices".  A maioria das orientações foram oferecidas diretamente pelo time de desenvolvimento do </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/3628289183919165430/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/dicas-para-melhorar-performance-do-net.html#comment-form' title='2 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3628289183919165430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3628289183919165430'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/dicas-para-melhorar-performance-do-net.html' title='Dicas para melhorar a performance do .Net Compact Framework'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-3841033027873800303</id><published>2010-01-21T06:15:00.003-02:00</published><updated>2010-01-21T06:19:42.057-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ferramentas'/><category scheme='http://www.blogger.com/atom/ns#' term='segurança'/><title type='text'>Lançado novo ProcNetMonitor</title><summary type='text'>
 ProcNetMonitor é uma ferramenta gratuita que monitora a atividade de todos os processos em execução no sistema, exibe todas as portas abertas e todas conexões ativas para cada processo.  Essa nova versão também possui o recurso "Port Finder" que torna fácil a busca por processos com conexões ativas em uma determinada porta. Além do mais, também vem com um recurso de exportação para HTML o que </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/3841033027873800303/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/lancado-novo-procnetmonitor.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3841033027873800303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3841033027873800303'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/lancado-novo-procnetmonitor.html' title='Lançado novo ProcNetMonitor'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_xJ5LrusWfss/S1c8KPPuHaI/AAAAAAAAASw/YTR2DTRkDD0/s72-c/procnetmonitor_screenshot_main.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-1828152338345579614</id><published>2010-01-19T00:54:00.005-02:00</published><updated>2010-01-20T04:16:13.793-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='aurora'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit-db'/><category scheme='http://www.blogger.com/atom/ns#' term='explorer'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>Internet Explorer Aurora Exploit</title><summary type='text'>Dia 17/01/2009 a galera da Offensive Security disponibilizou um exploit que explora a vulnerabilidade aurora (CVE-2010-0249) encontrada no Internet Explorer  6, 6 SP1, 7 em várias versões do windows.


O exploit disponibilizado é desenvolvido em phyton e executa a calculadora do windows no alvo.
O download pode ser feito em: http://www.exploit-db.com/exploits/11167.

para usa é fácil. É </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/1828152338345579614/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/internet-explorer-aurora-exploit.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/1828152338345579614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/1828152338345579614'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/internet-explorer-aurora-exploit.html' title='Internet Explorer Aurora Exploit'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-696136003331124800</id><published>2010-01-14T21:45:00.007-02:00</published><updated>2010-01-20T01:51:44.382-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>TCC Metasploit</title><summary type='text'>Esse achei na net há pouco tempo. É um TCC produzido pelo Julio Cesar Liviero Della Flora para a UniFil de londrina. É um trabalho muito bem estruturado, com explicações e várias imagens. Ponto de partida para qualquer um que deseja iniciar na área de testes de vulnerabilidades.

http://www.4shared.com/file/164179969/d59dfd55/TCC_JULIO.html 

PS: não é pirataria. O trabalho foi disponibilizado na</summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/696136003331124800/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/tcc-metasploit.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/696136003331124800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/696136003331124800'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/tcc-metasploit.html' title='TCC Metasploit'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-3848116877190745793</id><published>2010-01-14T17:02:00.001-02:00</published><updated>2010-01-14T17:04:52.322-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='grub'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='segurança'/><title type='text'>Impedindo o Acesso sem senha</title><summary type='text'>Este é um artigo meu publicado no Dicas-l em 20 de dezembro de 2005. O objetivo é impedir o acesso sem senha à um sistema Linux gerenciado pelo grub/lilo.
Não sei como estão as coisas hoje, mas, lembro que na época com esses passos a única maneira de de acessar seu sistema, sem possuir uma senha,  era abrindo a máquina e retirando da bateria da BIOS.
Reproduzo aqui o artigo da mesma forma que foi</summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/3848116877190745793/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/impedindo-o-acesso-sem-senha.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3848116877190745793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3848116877190745793'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/impedindo-o-acesso-sem-senha.html' title='Impedindo o Acesso sem senha'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-4236199514903680074</id><published>2010-01-14T03:25:00.003-02:00</published><updated>2010-01-14T05:09:33.345-02:00</updated><title type='text'>Novo repositório de exploits</title><summary type='text'>Após a infeliz "queda" do milw0rm muita gente ficou sem uma "referência" para buscar exploits, mas felizmente, parece que o pessoal da Offensive Security "adotou" o banco de dados do milw0rm e o transformou em um novo site.
O novo repositório contém as mesmas categorias que o milw0rm (remote, local, web, dos e shellcode) e, aparentemente, está bem atualizado, contando, hoje, com 10309 exploits.

</summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/4236199514903680074/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/novo-repositorio-de-exploits.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/4236199514903680074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/4236199514903680074'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/novo-repositorio-de-exploits.html' title='Novo repositório de exploits'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-3743723127390893983</id><published>2010-01-13T22:46:00.040-02:00</published><updated>2010-01-14T05:05:22.748-02:00</updated><title type='text'>Enviando um trojan para o IIS - Upload de arquivos</title><summary type='text'>Há pouco mais de um mês o metasploit, a partir do msfencode, permite geração de scripts ASP contendo um payload metasploit, ou seja, você pode facilmente criar uma página ASP que quando executado pelo navegador irá rodar uma backdoor ou coisa do gênero.
Isso expõe muitas páginas WEB que permitem o upload de fotos, imagens e outros "arquivos seguros". Normalmente as aplicações web que fazem upload</summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/3743723127390893983/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/ha-pouco-mais-de-um-mes-o-metasploit.html#comment-form' title='1 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3743723127390893983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3743723127390893983'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/ha-pouco-mais-de-um-mes-o-metasploit.html' title='Enviando um trojan para o IIS - Upload de arquivos'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-3841698885244991972</id><published>2010-01-13T20:54:00.005-02:00</published><updated>2010-01-14T04:15:05.705-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='backtrack'/><title type='text'>Lançado Backtrack 4 final</title><summary type='text'> 
Depois do beta do ano passado, uma longa espera e o apoio massivo da comunidade, finalmente saiu a versão final do backtrack 4.
Segundo os desenvolvedores, essa versão inclui novo kernel, mais ferramentas, suporte à novos dispositivos e correção de todos os bugs descobertos.


Download: http://www.backtrack-linux.org/downloads/


 Giorge Henrique Abdala </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/3841698885244991972/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/apos-o-beta-do-ano-passado-uma-longa.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3841698885244991972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/3841698885244991972'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/apos-o-beta-do-ano-passado-uma-longa.html' title='Lançado Backtrack 4 final'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-8404219154220134456</id><published>2010-01-09T20:51:00.022-02:00</published><updated>2010-01-14T05:07:36.300-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='kernel'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>Kernel Linux exploit - Local root</title><summary type='text'>Esse exploit explora uma falha no Sock_sendpage e dá poderes de root para qualquer usuário local. Essa é uma falha, muito grave, que afeta todos os linux kernel 2.4 e 2.6 em todas as arquiteturas desde 2001, é provavelmente uma das maiores falhas já vista no mundo linux.
Já foram produzidos vários exploits para variadas arquiteturas. O exploit que testei foi desenvolvido por um brasileiro (Ramon </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/8404219154220134456/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/kernel-linux-exploit-local-root.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/8404219154220134456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/8404219154220134456'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/kernel-linux-exploit-local-root.html' title='Kernel Linux exploit - Local root'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-1404221885559316164</id><published>2010-01-08T20:50:00.006-02:00</published><updated>2010-01-14T04:03:24.641-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL Server'/><title type='text'>Mssqlfp - Microsoft SQL Server Fingerprint Tool</title><summary type='text'>Mssqlfp é uma ferramenta que realiza fingerprints sobre SQL Server 2000, 2005 e 2008, usando técnicas baseadas em diversas ferramentas públicas de identificação do  SQL Server. Usa algoritimos probabilísticos para a identificação do serviço MSSQL  e pode ser usado para identificar versões vulnerávis do Sql Server.


 
Segue resultado de um teste que fiz:


Windows:$ mssqlfp-BETA4 -d HOST

MSSQLFP</summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/1404221885559316164/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/mssqlfp-microsoft-sql-server.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/1404221885559316164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/1404221885559316164'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2010/01/mssqlfp-microsoft-sql-server.html' title='Mssqlfp - Microsoft SQL Server Fingerprint Tool'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6549631640472379526.post-224776866753205972</id><published>2008-11-25T20:46:00.013-02:00</published><updated>2010-01-14T05:08:41.739-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='backtrack'/><title type='text'>Repositórios Backtrack</title><summary type='text'>Para quem já utiliza uma distribuição mais amigável, seja via Virtual Box ou Boot, é muito chato ficar trocando de distribuição sempre que quiser usar uma ferramenta de segurança. Pensando nisso fui procurar na net e achei 3 repositórios que resolveram o meu problema. 

É só adicionar isso ao seu /etc/apt/sources.list que você podera utilizar qualquer ferramenta do Backtrack 4 em sua sua </summary><link rel='replies' type='application/atom+xml' href='http://giorgeabdala.blogspot.com/feeds/224776866753205972/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://giorgeabdala.blogspot.com/2008/11/repositorios-backtrack.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/224776866753205972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6549631640472379526/posts/default/224776866753205972'/><link rel='alternate' type='text/html' href='http://giorgeabdala.blogspot.com/2008/11/repositorios-backtrack.html' title='Repositórios Backtrack'/><author><name>Giorge Henrique</name><uri>http://www.blogger.com/profile/00600217586980177564</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
