<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-10733659</id><updated>2011-12-14T21:36:50.681-05:00</updated><title type='text'>Newage Hacking labs</title><subtitle type='html'>-= Welcome to Newage Hacking Labs =-</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>62</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-10733659.post-115308496155993795</id><published>2006-07-16T17:19:00.000-04:00</published><updated>2006-12-10T05:03:42.503-05:00</updated><title type='text'>Still here!</title><content type='html'>Haha, I'm not quite dead yet. &lt;br /&gt;&lt;br /&gt;No, seriously, I'm really going to make an effort this time. And I'm going to try to keep the mount of rants down to a minimum (okay, thats probably a lie. But not intentional).&lt;br /&gt;&lt;br /&gt;Yea, so, check back soon, I'll be updating...&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-115308496155993795?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/115308496155993795/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=115308496155993795' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/115308496155993795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/115308496155993795'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/07/still-here.html' title='Still here!'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-115056496423182748</id><published>2006-06-17T13:18:00.000-04:00</published><updated>2006-06-17T13:22:44.256-04:00</updated><title type='text'>Looong time</title><content type='html'>Yea, its been a long time since I've last updated this blog. Sorry. :-/ FoodLion has kept my hours pretty full, and when I get off work, I'm too tired to do much. :-S&lt;br /&gt;&lt;br /&gt;Anyways, school's out for the summer! :-)&lt;br /&gt;&lt;br /&gt;Hmm, I can't think of anything to rant about really, so I'm going to end this post now. BTW, read kay's blog, &lt;a href="http://nulldigital.net"&gt;nulldigital&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-115056496423182748?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/115056496423182748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=115056496423182748' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/115056496423182748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/115056496423182748'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/06/looong-time.html' title='Looong time'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114832112324477975</id><published>2006-05-22T13:59:00.000-04:00</published><updated>2006-05-22T14:05:31.326-04:00</updated><title type='text'>Various things</title><content type='html'>Hey people. Sorry for the lack of updates, but I finally got foodLion to put me on the schedual, and they've had me working alot (granted, my first day was like 2 or 3 weeks ago, but...). They even called me in yestarday, asking me to work. Apperantly, they hadn't schedualed enough people. :-/&lt;br /&gt;&lt;br /&gt;Also, I've been updating &lt;a href="http://n3w7yp3.dajoob.com"&gt;n3w7yp3.dajoob.com&lt;/a&gt; alot. The index pages may look a little bare, but there is actually a good amount of code on there. I'm going to upload a few more things, and then fix up the index pages. Until then, if there's anything that you want that you know I've been working on, just ask and I'll send you the link.&lt;br /&gt;&lt;br /&gt;In my spare time this weekend (which wasn't much), I did learn multi-threading in Perl, as well as C. Its very cool. Suddenly, a whole lot of new coding opertunities have opened up to me. I'm thinking about doing some superfast stateless port scanners (a la scanrand, see &lt;a href="http://www.doxpara.com"&gt;doxpara&lt;/a&gt;), as well as maybe some password crackers. I've coded a VBulliten hash cracker, but it still needs some work. Maybe I'll multi-thread it. :-)&lt;br /&gt;&lt;br /&gt;Okay, I'm off for now. Check back soon for more updates!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114832112324477975?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114832112324477975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114832112324477975' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114832112324477975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114832112324477975'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/various-things.html' title='Various things'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114745719307506281</id><published>2006-05-12T14:02:00.000-04:00</published><updated>2006-05-12T14:06:46.190-04:00</updated><title type='text'>DoS</title><content type='html'>So, I was browsing CNet and I found &lt;a href="http://news.com.com/Teenage+e-mail+bomber+heads+back+to+court/2100-7348_3-6071227.html?tag=cd.top"&gt;this article&lt;/a&gt;. I was suprised to see that the Computer Misuse Act (in the UK) doesn't say anything about DoS attacks. They are quite prevelent these days, and can be quite destructive. &lt;br /&gt;&lt;br /&gt;Still, I find it hard to believe that a mail server was crashed by simple mail bombing. What seems more likley is that the disk space was filled up, and thats what caused the problem. But I wasn't there and will probably never see the logs, so its impossible for me to say for sure.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114745719307506281?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114745719307506281/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114745719307506281' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114745719307506281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114745719307506281'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/dos.html' title='DoS'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114719781211161017</id><published>2006-05-09T13:51:00.000-04:00</published><updated>2006-05-09T14:03:32.133-04:00</updated><title type='text'>Erm.... Frag Dolls?</title><content type='html'>So, I was browsing &lt;a href="http://www.cnetnews.com"&gt;CNet news&lt;/a&gt;, and I stumbled across an &lt;a href="http://news.com.com/Meet+the+new+Frag+Dolls/2100-1043_3-6069968.html?tag=nefd.lede"&gt;article&lt;/a&gt; about the &lt;a href="http://news.com.com/2300-1043-6069651.html"&gt;Frag Dolls&lt;/a&gt;, Ubisoft's all female gaming team. Kind of odd, kind of different, after all, most people don't usually think of girls as gamers. Ah well, its cool.&lt;br /&gt;&lt;br /&gt;My original plan was to rant about this, and complain that CNet was running pointless stories about video games (looks like they're caught up in the E3 madness just like the rest of the world), while they ignored stories about a &lt;a href="http://www.securityfocus.com/brief/204"&gt;botnet attacking a hospital&lt;/a&gt;. But then, I realized that (believe it or not), &lt;i&gt;I just didn't care&lt;/i&gt;. Hard to believe but true. I still do play video games occasionally, and am cursing Netflix for not having a copy of Final Fantasy VII: Advent Children avalible for me to rent. &lt;br /&gt;&lt;br /&gt;But about the bot master attacking a hospital, how stupid can you get? Messing with the computers in the IC unit does *not* make you a hacker, no matter how leet and badass you may feel after endangering someones life. BTW, has anyone else noticed how there are a lot of articles about botnets recently? I saw one on SecutiyFocus (linked earlier), and there was one on CNet (&lt;a href="http://news.com.com/20-year-old+botmaster+faces+years+behind+bars/2100-7348_3-6070020.html?tag=cd.top"&gt;read it&lt;/a&gt;). And then we have the &lt;a href="http://news.com.com/Fantasy+soccer+league+virus+kicks+off/2100-7349_3-6069814.html?tag=cd.top"&gt;Fantasy Soccer league&lt;/a&gt; virus. Looks like it infects Microsoft Excel spreadsheets. Doesn't seem like that big of a deal (IMO), all it does is upload a fake spread sheet and modify thier existing fantasy soccer ones. I can't really see it causing any damage at all.&lt;br /&gt;&lt;br /&gt;Okay, thats quite enough for today. I'm out.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114719781211161017?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114719781211161017/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114719781211161017' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114719781211161017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114719781211161017'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/erm-frag-dolls.html' title='Erm.... Frag Dolls?'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114711140338418990</id><published>2006-05-08T13:55:00.000-04:00</published><updated>2006-05-08T14:03:23.433-04:00</updated><title type='text'>Kuang</title><content type='html'>Hmm, so, a few months ago, I started on a project called Kuang. Kuang is a *nix log file editor (and the name of the virus in Neuromancer. I've got to stop naming my projects at 0300...) coded in Perl.&lt;br /&gt;&lt;br /&gt;Its pretty good, it can delete a log, overwriting it with random data, truncating it down to 0 bytes and then unlinking it (like &lt;i&gt;`shred'&lt;/i&gt;). It can also search for a string and then delete any lines that contain it, or replace them with something else (for instance, you could have it search for your IP address in the logs and then replace it with 127.0.0.1 or something). &lt;br /&gt;&lt;br /&gt;Kuang also uses &lt;i&gt;stat[8]&lt;/i&gt; and &lt;i&gt;stat[9]&lt;/i&gt; and &lt;i&gt;utime()&lt;/i&gt; to set the last access and modified times. &lt;br /&gt;&lt;br /&gt;The code is done, after all, its not exactly a hard thing to code string relacements in Perl. ;-)&lt;br /&gt;&lt;br /&gt;I'm gonna kick it around for a bit, and then put it up on &lt;a href="http://n3w7yp3.dajoob.com"&gt;http://n3w7yp3.dajoob.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Alrighty, I got to get back to HTML. *sigh*&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114711140338418990?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114711140338418990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114711140338418990' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114711140338418990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114711140338418990'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/kuang.html' title='Kuang'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114685040831529177</id><published>2006-05-05T13:26:00.000-04:00</published><updated>2006-05-05T13:33:28.333-04:00</updated><title type='text'>Code reuse</title><content type='html'>Was just skimming &lt;a href="http://www.securityfocus.com"&gt;SecurityFocus&lt;/a&gt;, and read an article about how malware has 'familys' (common code trends, even some exact same bits). Suppposedly, this was a big surprise to the group that did the analysis, &lt;a href="http://www.sabre-security.com/"&gt;Sabre Security&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;I don't see why this would come as a suprise, to be honest. Chances are, malware writers are not out to see if they can create the most elegant code (unless say they're developing a custom rootkit to deploy against a target, etc), but to get the most distrobution of thier malware. So, if somebody has already written a good IP generation algorithm, I can see how it would be attractive option for them to copy the code. &lt;br /&gt;&lt;br /&gt;Hmm, sorry if that didn't make much sense. I'm in class, and the girl next to me is playing some rap really loud on the computer speakers, and it's hard to concentrate with it on. :-/&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114685040831529177?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114685040831529177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114685040831529177' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114685040831529177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114685040831529177'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/code-reuse.html' title='Code reuse'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114667827466952417</id><published>2006-05-03T13:38:00.000-04:00</published><updated>2006-05-03T13:49:46.696-04:00</updated><title type='text'>XSS in 8e6 filters</title><content type='html'>Product: 8e6 R3000 web content filter (and possibly others).&lt;br /&gt;Vendor: &lt;a href="http://www.8e6.com"&gt;8e6&lt;/a&gt;.&lt;br /&gt;Attack type: XSS (cross site scripting).&lt;br /&gt;Details: This attack is possible because the filter does not properly filter HTML, which can lead to the insertion of malcious SCRIPT tags.&lt;br /&gt;PoC:&lt;br /&gt;&lt;br /&gt;Normal blocked content URL: http://192.168.1.1/cgi/block.cgi?URL=http://www.gamewinners.com/&amp;IP=10.1.44.5&amp;CAT=GGAMES&amp;USER=IPGROUP&lt;br /&gt;&lt;br /&gt;Malicious URL: http://192.168.1.1/cgi/block.cgi?URL=http://www.gamewinners.com/&amp;IP=10.1.44.5&amp;CAT=GGAMES&amp;USER=%3cscript%3ealert("XSS%20vulnerable.%20--n3w7yp3");%3c/script%3e&lt;br /&gt;&lt;br /&gt;Misc info: You can also manipulate the other fields to further warp what the users sees. For instance, if you change &amp;CAT=GGAMES to &amp;CAT=No%20real%20reason, the category field on the form will read, "No real reason."&lt;br /&gt;&lt;br /&gt;Discovered by: n3w7yp3&lt;br /&gt;&lt;br /&gt;End vulnerability info.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114667827466952417?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114667827466952417/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114667827466952417' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114667827466952417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114667827466952417'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/xss-in-8e6-filters.html' title='XSS in 8e6 filters'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114667787434385004</id><published>2006-05-03T13:26:00.000-04:00</published><updated>2006-05-03T13:37:54.373-04:00</updated><title type='text'>Proxies</title><content type='html'>Okay, I'm back. Like two seconds after I posted that last post, I was reading some article on CNet about school proxies (you can find it &lt;a href="http://news.com.com/School+filters+vs.+home+proxies/2009-1041_3-6067716.html?tag=nefd.lede"&gt;here&lt;/a&gt;), and one system administrator at a school said that he had not had a student bypass a filter ever since he installed an &lt;a href="http://www.8e6.com"&gt;8e6&lt;/a&gt; filter. That really ticked me off. I know of a few places that have 8e6 filters, and they're all vulnerable to that XSS attack that I discovered a *long* time ago (okay, so maybe it was like 2 or 3 months ago. But thats a long time). I have not disclosed the vulnerability to 8e6, mostly because I'm lazy, and its an ace in the hole, so to speak. &lt;br /&gt;&lt;br /&gt;But I really do pity that admin if he thinks that 8e6 filters will stop students. I'm willing to bet that as soon as a kid comes along who has some knowledge (and maybe malicious intentions), he'll use the XSS attack that I've discovered to mess with the filter. Speaking of which, I'm posting a vulnerability announcement next.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114667787434385004?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114667787434385004/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114667787434385004' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114667787434385004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114667787434385004'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/proxies.html' title='Proxies'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114667706535514069</id><published>2006-05-03T13:21:00.000-04:00</published><updated>2006-05-03T13:24:25.370-04:00</updated><title type='text'>Do'h!</title><content type='html'>Okay, I know, its been a while. But, I actually have a good excuse this time! You see, I have relatives over, and they're in my room, which is where my computers are. So, I've not been able to access as much as usual. &lt;br /&gt;&lt;br /&gt;Sorry about the short post, but thats all for today.&lt;br /&gt;&lt;br /&gt;Starting Thursday, things will be back to normal. :-)&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114667706535514069?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114667706535514069/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114667706535514069' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114667706535514069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114667706535514069'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/05/doh.html' title='Do&apos;h!'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114624584610144513</id><published>2006-04-28T13:34:00.000-04:00</published><updated>2006-04-28T13:38:14.286-04:00</updated><title type='text'>Google and firefox</title><content type='html'>Heh, this is prety cool actually. I was in school today, and I opened up Internet Explorer (my school is standardized on Microsoft software). They have the IE homepage set to Google. In any event, there was an ad beneath the search bar that read:&lt;br /&gt;&lt;br /&gt;"Firefox with Google Toolbar: tabbed browsing, safer surfing."&lt;br /&gt;&lt;br /&gt;Looks like google has finally realized that FireFox is much better than IE. Clicking on the ad brings you to &lt;a href="http://services.google.com/toolbar/firefox?utm_source=HPP&amp;utm_campaign=hpp-fftoolbar_en"&gt;this&lt;/a&gt; page. &lt;br /&gt;&lt;br /&gt;Pretty cool, IMO. :-)&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114624584610144513?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114624584610144513/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114624584610144513' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114624584610144513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114624584610144513'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/google-and-firefox.html' title='Google and firefox'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114599466309607705</id><published>2006-04-25T15:50:00.000-04:00</published><updated>2006-04-25T15:51:03.123-04:00</updated><title type='text'>Site</title><content type='html'>Hey, well I registered for a dajoob account, and put up a small site where I can post my code etc.&lt;br /&gt;&lt;br /&gt;Let me know what you guys think, the site is &lt;a href="http://n3w7yp3.dajoob.com"&gt;n3w7yp3.dajoob.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114599466309607705?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114599466309607705/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114599466309607705' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114599466309607705'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114599466309607705'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/site.html' title='Site'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114547679904542602</id><published>2006-04-19T15:56:00.000-04:00</published><updated>2006-04-19T15:59:59.056-04:00</updated><title type='text'>Break</title><content type='html'>Well, sorry for the lack of updates, but I've been on spring break all week. I've spent most of the time on IRC, and catching up on missed sleep during the week. &lt;br /&gt;&lt;br /&gt;Okay, thats all for now. I may put up my throughts on Microsoft silently patching vulns, if I can be bothered... :-/&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114547679904542602?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114547679904542602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114547679904542602' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114547679904542602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114547679904542602'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/break.html' title='Break'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114477730361620990</id><published>2006-04-11T13:36:00.000-04:00</published><updated>2006-04-11T13:41:43.633-04:00</updated><title type='text'>Job Interview</title><content type='html'>Well, it looks like I may be getting a job at FoodLion. I have an interview with them tommorow.&lt;br /&gt;&lt;br /&gt;Hopefully, it will all go well. Course, that will just add more stress to my load. I've got a *huge* English report due on Friday, and I'm working on that. It's about Open Source versus Propritary Software (in terms of security). I may post this one up for download, after I hand it in (I have to hand it in on &lt;a href="http://www.turnitin.com"&gt;turnitin.com&lt;/a&gt;, a website which checks for plagarism. UIf I publish it online first, and then hand it in, there is a small chance that it may be reported as 100% plagarised. And, since my english teacher doesn't know that n3w7yp3 is my nick, I could be in for a rough time). &lt;br /&gt;&lt;br /&gt;Well, that looks like its gonna be all for today. I'm writing an artcile about HP networked printer security, an article about firewall penetration, and a mini-series about Cisco device hacking. Hopefully those will be finished soon. But hey, if not, I have Spring Break start at the end of this week!! :D&lt;br /&gt;&lt;br /&gt;w00t for Spring Break!! :D&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114477730361620990?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114477730361620990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114477730361620990' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114477730361620990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114477730361620990'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/job-interview.html' title='Job Interview'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114469057678137380</id><published>2006-04-10T13:19:00.000-04:00</published><updated>2006-04-10T13:36:16.800-04:00</updated><title type='text'>The weekend</title><content type='html'>Well, I had a nice relaxing weekened. Not much happened, and I managed to get some sleep, unlike during the week. :-P&lt;br /&gt;&lt;br /&gt;I had Friday off, and Thursday night myself and a few friends got together and had an impromptu LAN party. It was pretty cool, and I was introduced to Pure Pwnage (with FPS Doug!). Its pretty funny.&lt;br /&gt;&lt;br /&gt;So, yea, I pretty much did nothing over the weekend. I was too lazy to code, and spent most of my time on IRC.&lt;br /&gt;&lt;br /&gt;Okay, thats all for today. Catch you all later. ;-)&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114469057678137380?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114469057678137380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114469057678137380' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114469057678137380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114469057678137380'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/weekend.html' title='The weekend'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114434620731722443</id><published>2006-04-06T13:35:00.000-04:00</published><updated>2006-04-18T09:29:31.803-04:00</updated><title type='text'>DHS busted?!</title><content type='html'>Wow, I can't believe this one. Some guy in the US Department of Homeland Security (DHS) was arrested for the exploitation of children online. While he thought he was talking to a 14 year old girl, he was actually talking to a detective. &lt;br /&gt;&lt;br /&gt;People can be so stupid. There was a report on NBC or CBS a while back that basically said "Child exploitation rings are getting more and more advanced. They now use live feed webcams and MSN messenger to transfer files!" All this jazz does is convince more and more people that the Internet is a bad place. Its only as bad as you make it out to be. Like, there are kids who go to my school, who put thier home phone number, cell phone number, and home address on thier myspace. Seriously, thats *really* dumb. And this isn't just the hacker paranoia talking here either. In real life, would you give that info out? Most likely not. They also post the thier class schedual in thier AIM profiles, along with their cell phone number. Again, thats pretty stupid. If people would just exercise some common sense, everything would be fine. &lt;br /&gt;&lt;br /&gt;I actually have another little anecdote on this subject (/me listens to the sighs). I'm sure that this will mean almost nothing to 99% of you, but if you do some googleing, you may find more info on the topic. Well, anyways, about 4 or 5 years ago, a gilr in my town turned up dead. She was 13 and had been meeting a 21 year old man she had met online for sex at the mall. He had killed her. It was tragic, yea, but god, who would agree to meet someone like that? Thats a really bad idea. Anyways, for the longest time, after that, my mom wouldn't let me chat online with people that I didn't know in real life (IRL). This was a minor nuscance, because she'd read my emails over my shoulder to ensure that I was not invloved in a sexual relationship with any 21 year old guys (no worries there). Now, this next part may sound a bit self serving, but us hackers, we have a natural paranoia which prevents us from doing stuff like that. And, many of us also have another skill, which I like to call common sense. ;-)&lt;br /&gt;&lt;br /&gt;So, yea back to my original point about the DHS. Not only have they taken away and restriced American civil liberties, but they now appear to have employeed a bunch of paedophiles. That can't be good...&lt;br /&gt;&lt;br /&gt;Ah, yes, the link to the original article can be found &lt;a href="http://www.securityfocus.com/brief/179"&gt;here&lt;/a&gt;. Heh, you can find all osrts of things on SecurityFocus... ;-)&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114434620731722443?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114434620731722443/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114434620731722443' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114434620731722443'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114434620731722443'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/dhs-busted.html' title='DHS busted?!'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114425933186820878</id><published>2006-04-05T13:40:00.000-04:00</published><updated>2006-04-05T13:48:51.883-04:00</updated><title type='text'>Social Engineering</title><content type='html'>Hey , I was reading &lt;a href="http://www.securityfocus.com/brief/178"&gt;this&lt;/a&gt; article on &lt;a href="http://www.securityfocus.com"&gt;SecurityFocus&lt;/a&gt;. Wow, hasn't it been known forever that end users are the problem? Jeeze, what a shocker!! :o&lt;br /&gt;&lt;br /&gt;Heh. Actually, there is a funny story in that whole "Yea, sure I'll accept the pop-up add that says I need to install this" attitude that the end users have. I was recently at a LAN party, and we all decided to play Diablo II on a LAN, via the TCP/IP game option. So, one of us had a legit copy of the game, the rest (myself included) didn't. We all installed the one copy, and then found and downloaded cracked copies of the game.exe file. Now, we all know how many popups and spywares those warez sites have, yes? Well, at the time I was on an old box that I had installed Windows 2000 on. Now, me being a Linux user, I'm not used to those popups. For a second I was actually heading towards yes, and then stopped and read it. I was laughing pretty hard (For the record, I clicked "No".). It gave the rest of the guys a laugh when I told them that I had almost voluntairly infected my box with spyware. But the end here is that I didn't. So, to any non-techincally oriented people who happen to be reading this, *don't* click yes! :-P&lt;br /&gt;&lt;br /&gt;So, erm, yea, thats my slightly funny story...&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114425933186820878?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114425933186820878/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114425933186820878' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114425933186820878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114425933186820878'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/social-engineering.html' title='Social Engineering'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114425876569543669</id><published>2006-04-05T13:36:00.000-04:00</published><updated>2006-04-05T13:39:25.720-04:00</updated><title type='text'>A week??</title><content type='html'>Yea, I know, I missed a week. :-/&lt;br /&gt;&lt;br /&gt;However, I have a good excuse. I have pretty much been sick this whole time, and just going to school has really taken it out of me. So, yea, sorry. :'(&lt;br /&gt;&lt;br /&gt;Oh yes, about Rayne, I *did* complete it, but for some reason (probably because I finished it when I had a 101 degree F fever), it will only send 3 packets and then fail with a call to the Net::RawIP module, line 550, I believe. I'll try and sort it out ASAP.&lt;br /&gt;&lt;br /&gt;If I can't work it out, I may just recode it using Net::Write, and then release that. I'll just have to see.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114425876569543669?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114425876569543669/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114425876569543669' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114425876569543669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114425876569543669'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/04/week.html' title='A week??'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114383096629023621</id><published>2006-03-31T13:43:00.000-05:00</published><updated>2006-03-31T13:49:26.316-05:00</updated><title type='text'>Rayne release draws near</title><content type='html'>Well, Rayne is almnost at completion. It will be released tonight, or tommorow early afternoon. I'm feeling sick ATM, so like I said, if its not out today, it *will* be out tommorow. &lt;br /&gt;&lt;br /&gt;In other news, I'm writing an article on firewall enumeration and penetration. And its not a copy of Hacking Exposed either. No, this is more or less an account of my first hand expirences while coding Amerex and Serenity. And yes, Amerex is still in the works. ;-) The article will be out by Sunday night (unless I get really sick).&lt;br /&gt;&lt;br /&gt;One last thing, if any here has a copy of the Microsoft DDK, or knows how to get a discount on it, can you contact me? I'm considering doing a Linux kernal rootkit (shrapnel) and its Windows counterpart (shrapnel32). I have the dev tools for the Linux version, but alas, without the DDK I can't progress any where on the Windows one. :-/&lt;br /&gt;&lt;br /&gt;And before anyone gets all excited, the rootkit idea is still a concept, nothing final.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114383096629023621?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114383096629023621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114383096629023621' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114383096629023621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114383096629023621'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/rayne-release-draws-near.html' title='Rayne release draws near'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114374574274255987</id><published>2006-03-30T13:53:00.000-05:00</published><updated>2006-03-30T14:09:02.773-05:00</updated><title type='text'>Serenity and Rayne</title><content type='html'>Howdy, sorry I missed 3 days. I know that I stated that I would be updating daily, but I have not had time. See, I usually blog from class, but we've been doing a test in Programming Class. So, no time to blog. :-/&lt;br /&gt;&lt;br /&gt;Anyways, I've started on two new projects. Rayne and Serenity. I'll detail Rayne first.&lt;br /&gt;&lt;br /&gt;Rayne is simply a tool that is designed to make an IDS go nuts. It can be used to hide your scans (or anything else) amid a flood of packets. It sends random TCP packets with a random source IP, random source port and a random payload to the host. You feed it a port range to use, and it blasts out its spoofed packets. Its really quite simple to code, and it is actually quite simple for the admins to block. But it should still help. After all, if the IDS generates 5000 alerts, its going to be much harder for them to find your nmap scan. ;-)&lt;br /&gt;&lt;br /&gt;Rayne also has the potential to be used in IDS testing. A pen-tester could use it to see if the IDS on the target is configured correctly.&lt;br /&gt;&lt;br /&gt;Serenity is a kind of like a cross between firewalk and hping3. It lets you send out custom generated TCP packets (header flags and so forth), and then it functions like firewalk, finding out the TTL of the target gateway, and then increasing it by one. While it may seem somewhat pointless, I got the idea for it one night while I was poking around. I encountered a firewall that was dropping SYN packets, but would let other packets through. I was able to scan the ACLs using hping3 and the --ttl option. So, out of that Serenity was born.&lt;br /&gt;&lt;br /&gt;Both Serenity and Rayne are written in Perl. Rayne is nearing completion (I just have one more function to code), and *will* be released this weekend. Serenity was actually started a long time before Rayne, but I'm having some trouble with the Perl interface to pcap (there's a bunch to choose from, right now I'm using Net::PcapUtils, but last night I downloaded Net::Pcap 12 off CPAN, so I may switch to that). The raw sockets for both scripts is being done through Net::RawIP, but I may change Serenity to use Net::Write instead (its much newer than Net::RawIP). Rayne may be recoded using Net::Write in future releases.&lt;br /&gt;&lt;br /&gt;Oh yes, remember dmap? Well, I've started on dmap 3.5. It will be a complete recoding of the current dmap release. It will also use Getopt::Std instead of the require 'getopts.pl' which I had been using at that time. Shortly after I made dmap public, zshzn recommended to me that I switch to Getopt::Std, and I have. Its much better, IMHO. This release of dmap will also be *pure* Perl. No more shell escapes for the reverse lookups. I may also be coding in some rules, and maybe intelligent subdomain guessing.&lt;br /&gt;&lt;br /&gt;Okay, thats all for now. More to come later.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114374574274255987?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114374574274255987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114374574274255987' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114374574274255987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114374574274255987'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/serenity-and-rayne.html' title='Serenity and Rayne'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114348520134335183</id><published>2006-03-27T13:30:00.000-05:00</published><updated>2006-03-27T13:46:41.356-05:00</updated><title type='text'>Yestarday (and a bit of today)</title><content type='html'>Yestarday was a total write off. I was dead tired the whole day, and didn't get much accomplished. I tried several times to install Fedora Core 5 (I thought that I may have foregotten to set my boot order in my BIOS), to no avail. My DVD-RW drive is well and truley dead. :-(&lt;br /&gt;&lt;br /&gt;Most of my day was spent coding a new script called Rayne. Its a small Perl script that bombards the target with random TCP packets, from a random source IP address, with random destination ports, and with a random payload in the data section. And no, its not a DoS script. Its for IDS testing, and/or it can be used to make an IDS go nuts while a penetration tester does his thing (I'm not sure how effective this will be, but it strikes me as a good way). Of course, as was pointed out by switch in #hf, if you scan correctly, there is no need to worry about IDS. Techniques like idle scanning are very sneaky and nearly impossible to detect. And if you proxy the scan, you're home free.&lt;br /&gt;&lt;br /&gt;I had filled out a systems application from from &lt;a href="http://www.cray.com"&gt;Cray&lt;/a&gt;, but they have not replied. I guess they don't give away 512 CPU XT3's... :-/&lt;br /&gt;&lt;br /&gt;Ah yes, in other news, it appears that Microsoft is giving Apple &lt;a href="http://www.securityfocus.com/news/11383"&gt;security advice&lt;/a&gt;. Hmm, sounds like a great idea, eh? Apple has had some problems with Mac OS X, and some security professionals have even went so far as to say it was an easy target. But then Windows has not had a good track record itself. After all, two days after the Bugtraq post about the msshtml.dll (I think thats the file) overflow, a 0-day exploit was written, and posted on &lt;a href="http://www.milw0rm.com"&gt;milw0rm&lt;/a&gt;. From my point of view, thats amazing. Two days is insanely fast to get a working exploit developed, especially for something like IE, with which you can only do gray box and black box audits (no source code). The even more shocking part was that the sploit was made public. An IE 0-day is worth a good amount in the underground, and to post it to milw0rm like that probably cost the guys who wrote it a few good trades. &lt;br /&gt;&lt;br /&gt;Okay, I'm out. I'll probably try and post more later.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114348520134335183?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114348520134335183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114348520134335183' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114348520134335183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114348520134335183'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/yestarday-and-bit-of-today.html' title='Yestarday (and a bit of today)'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114330479947255723</id><published>2006-03-25T11:35:00.000-05:00</published><updated>2006-03-25T11:39:59.493-05:00</updated><title type='text'>DVD Drive</title><content type='html'>Well, my DVD-RW drive is refusing to read my Fedora Core 5 install DVD. In fact, its refusing to read any DVDs. Strange part is, it will read CD's just fine. &lt;br /&gt;&lt;br /&gt;So, now its either I buy a new DVD drive, or download 5 CD's worth of ISO's to install Fedora... :-/&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114330479947255723?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114330479947255723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114330479947255723' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114330479947255723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114330479947255723'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/dvd-drive.html' title='DVD Drive'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114322744497663686</id><published>2006-03-24T14:08:00.000-05:00</published><updated>2006-03-24T14:10:44.986-05:00</updated><title type='text'>DRDoS with DNS</title><content type='html'>I'm sure this is all old news to any one reading this. Heck, we've all known about this for a long time. But, today CNET published an article talking about Distributed Reflective Denial of Service attacks that use DNS. Basically, it floods the target with DNS replies. You can read the article &lt;a href="http://news.com.com/DNS+servers+do+hackers+dirty+work/2100-7349_3-6053468.html?tag=nefd.lede"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Of course, this has been known about for a long time. The famous ihateperl.pl and drdos.pl scripts have implemented these attacks long ago. I wonder why they're just now getting noticed...&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114322744497663686?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114322744497663686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114322744497663686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114322744497663686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114322744497663686'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/drdos-with-dns.html' title='DRDoS with DNS'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114314131016168349</id><published>2006-03-23T14:09:00.000-05:00</published><updated>2006-03-23T14:15:10.163-05:00</updated><title type='text'>New sendmail hole</title><content type='html'>Well, surprise surprise, another Sendmail hole! Who'da thunk it?&lt;br /&gt;&lt;br /&gt;Seriously, at times sendmail strikes me as hopeless as WU-FTPd...&lt;br /&gt;&lt;br /&gt;Anyways, this hole has been picked up by the media. &lt;a href="http://www.cnetnews.com"&gt;CNET&lt;/a&gt; has even published an &lt;a href="http://news.com.com/Sendmail+flaw+opens+door+to+intruders/2100-1002_3-6052758.html?tag=cd.top"&gt;article&lt;/a&gt; on it.&lt;br /&gt;&lt;br /&gt;The hole itself appears to be somewhat dangerous, in fact, FrSIRT rates it as "Critical". It gives remote code execution on the target machine. It appears to effect most *nix OS's (including Linux) running the vulnerable sendmail deamon, but not Windows (at least not yet...).&lt;br /&gt;&lt;br /&gt;Supposedly, there is no vuln "in the wild", but as we all know, the blackhats will probably have something. So, yea, that was just my 0.02...&lt;br /&gt;&lt;br /&gt;Oh yes, the FrSIRT adviosery is &lt;a href="http://www.frsirt.com/english/advisories/2006/1049"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Okay, I'm out.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114314131016168349?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114314131016168349/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114314131016168349' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114314131016168349'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114314131016168349'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/new-sendmail-hole.html' title='New sendmail hole'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114314088815323648</id><published>2006-03-23T13:58:00.000-05:00</published><updated>2006-03-23T14:08:08.166-05:00</updated><title type='text'>Fedora Core 5</title><content type='html'>Howdy,&lt;br /&gt;&lt;br /&gt;Yes, I know this is old news, but Red Hat Fedora Core 5 was released on 2006-3-20 (March 20th, 2006). I plan on upgrading tommorow, so I'll post my thoughts about it then. &lt;br /&gt;&lt;br /&gt;Also, according to an article on &lt;a href="http://www.securityfocus.com"&gt;securityfocus&lt;/a&gt;, there are three main OS's,: Windows, Mac OS X and Red Hat Fedora Core. Seems like Fedora is becoming synonymous with Linux now... admitedly, it is one of the more popular and far reaching distros (and my personal favorite), but the OS is still Linux (well, actually GNU/Linux), not Fedora. I've once even heard someone on IRC remark, "Linux is the kernel, Red Hat is the OS." You can read the securityfocus article where thats mentioned &lt;a href="http://www.securityfocus.com/columnists/393"&gt;here&lt;/a&gt;. The actual quote is:&lt;br /&gt;&lt;br /&gt;"Yes, it's fast. Fast enough to give me visions of OS X native apps running alongside both Windows Vista and Fedore Core inside two virtual machines. It would make for a nice, highly portable security lab to test all three major operating systems." -- Kelly Martin &lt;a href="http://www.securityfocus.com/columnists/393"&gt;http://www.securityfocus.com/columnists/393&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Anyways, I'll post more about Red Hat's new release tommorow or the day after... I just hope that Net::RawIP will install, unlike in Fedora Core 4...&lt;br /&gt;&lt;br /&gt;BTW, for anyone looking to learn more about Fedora, the link is: &lt;a href="http://fedora.redhat.com"&gt;http://fedora.redhat.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114314088815323648?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114314088815323648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114314088815323648' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114314088815323648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114314088815323648'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/fedora-core-5.html' title='Fedora Core 5'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114305353019429297</id><published>2006-03-22T13:41:00.000-05:00</published><updated>2006-03-22T13:52:34.136-05:00</updated><title type='text'>FrSIRT and milw0rm</title><content type='html'>Well, it looks like &lt;a href="http://www.frsirt.com/english"&gt;FrSIRT&lt;/a&gt; has finally bowed to pressure from the French government and taken the exploits and PoC code off its site. It now only offers adviosories. Thats a *huge* step, considering I have several memories of them posting 0-day exploits. I'd expect that from &lt;a href="http://www.milw0rm.com"&gt;milw0rm&lt;/a&gt; but not FrSIRT. FrSIRT now offers a program where you pay them money and you are able to browse a section of the site where they do keep have the exploits. They do offer a 14 day free trial, but it is avalible only for businesses and the like. I wonder how many "small local business" will be signing up for it. In any case, its a shame to see another great security site bow to pressure and sell out like that.&lt;br /&gt;&lt;br /&gt;Also, speaking of milw0rm, str0ke has put up a section of papers. milw0rm has become much more than just a site for exploits. It now offers an MD5 and LANMAN hash database/cracker service, tutorials, videos, IRC and of course exploits and payloads. There also is a bzip2'ed tarball of the exploits avalible for download, as well as a wordlist (which I assume is the plaintext found in their hash databases). So, it looks like milw0rm is really stepping up. Who knows, one day it might even rival &lt;a href="http://www.securityfocus.com"&gt;securityfocus&lt;/a&gt; in terms of content. Of course, that wouldn't be anytime soon, but who knows what will happen in 5 years?&lt;br /&gt;&lt;br /&gt;Okay, I'm out for now.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114305353019429297?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114305353019429297/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114305353019429297' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114305353019429297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114305353019429297'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/frsirt-and-milw0rm.html' title='FrSIRT and milw0rm'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114305287076411322</id><published>2006-03-22T13:36:00.000-05:00</published><updated>2006-03-28T05:05:05.760-05:00</updated><title type='text'>Area-6</title><content type='html'>Well, It looks as though the wonderful &lt;a href="http://www.area-6.net"&gt;area-6.net&lt;/a&gt; has gone down for good. jimmyj recently tok down the IRC server, and now the website has gone down as well. Unfortuntatly, I had not recieved any notice of this from anyone. So, if any a6'ers are reading this, drop a comment, or stop by irc.hackersfoundation.org #hf. &lt;br /&gt;&lt;br /&gt;On a similar note, isn't m101's site, &lt;a href="http://www.fatetek.net"&gt;fatetek.net&lt;/a&gt; hosted by Blu-tek, which was jimmyj's hosting company? Is it going to go down as well?&lt;br /&gt;&lt;br /&gt;And is xlordt ever going to finish recoding &lt;a href="http://www.h4ckerx.net"&gt;h4ckerx.net&lt;/a&gt;?&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114305287076411322?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114305287076411322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114305287076411322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114305287076411322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114305287076411322'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/area-6.html' title='Area-6'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-114305260503575456</id><published>2006-03-22T13:35:00.000-05:00</published><updated>2006-03-22T13:36:45.046-05:00</updated><title type='text'>Daily updates</title><content type='html'>Hey all,&lt;br /&gt;&lt;br /&gt;Well, Its been quite a long time since I have updated my blog. Once again, I apologize. I will now be blogging daily, sometimes maybe even more than once.&lt;br /&gt;&lt;br /&gt;Anyways, if anybody is reading this, pass it around, okay?&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-114305260503575456?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/114305260503575456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=114305260503575456' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114305260503575456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/114305260503575456'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/03/daily-updates.html' title='Daily updates'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113899310343442207</id><published>2006-02-03T13:45:00.000-05:00</published><updated>2006-02-19T13:04:19.766-05:00</updated><title type='text'>All sorts of stuff...</title><content type='html'>Hey,&lt;br /&gt;&lt;br /&gt;I know its been some time since I last updated here, and I apologize. I've made the regionals team for swimming, and practice has been crazy. I just have not had the energy to blog much. In fact, irs been a while since I've coded much..&lt;br /&gt;&lt;br /&gt;Well, the regionals meet is next Friday, and next week I'm handing in three big projects for school. After that, its back to hacking and coding. :-)&lt;br /&gt;&lt;br /&gt;Course, just because I've been lazy for the last few weeks does not mean that I've not been keeping up with the news. I'm sure you all know by now, but it looks like a group of Russian hackers sold the WMF vuln for about $4,000 (USD), before it was public. I think I also read that it was used in the attack againist the English Parliment. Article is on &lt;a href="http://www.securityfocus.com/brief/126"&gt;securityfocus's briefs&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Also, the Kama Sutra (Blackmal, whatever) appears to have done no damage, despite the reports that it would kill half the Internet... Once again, the mass media attempted to get everyone hyped and scared... Also, Sober's relaunch did absolutley nothing. Kudos to the AV guys who worked hard to put out signitures to disinfect the vitcims, as well as everyone else who contributed.&lt;br /&gt;&lt;br /&gt;In local news, HF is *almost* up! dbr and BobbyB have been working extremly hard these past few days, getting it ready. You can view the site at &lt;a href="http://hf.dajoob.com"&gt;http://hf.dajoob.com&lt;/a&gt;. Also, #hf has moved from irc.nullnetwork.net to irc.xelix.net (channel is still the same). The reasons for the move were many, but we left on friendly terms. If you ever find yourself on nn, drop by #nullnetwork, #perl and #c for some great info and discussion. If you're on xelix, drop by #controlthesystem. &lt;br /&gt;&lt;br /&gt;One last remark about the IRC, TMC (aka The_MystiC) from humpmeg has generously agreed to give us our own server to use for IRC. The IRCd is up and ready, but there are still a few kinks to work out. It'll probably be ready soon. Server is irc.hackersfoundation.org.&lt;br /&gt;&lt;br /&gt;Okay, thats all for now. More to come soon!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113899310343442207?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113899310343442207/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113899310343442207' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113899310343442207'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113899310343442207'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/02/all-sorts-of-stuff.html' title='All sorts of stuff...'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113788356982464822</id><published>2006-01-21T17:35:00.000-05:00</published><updated>2006-01-21T17:46:09.840-05:00</updated><title type='text'>dmap</title><content type='html'>Ahoy,&lt;br /&gt;&lt;br /&gt;Well, dmap has finally been finished and released! I'd like to give a big thanks to Nemesis_mk2 for hosting the dmap tarball. &lt;br /&gt;&lt;br /&gt;If you don't know what dmap is, then you're missing out! dmap is a tool that uses DNS to discover hosts. Doesn't sound like much? Well, if you've read &lt;u&gt;Stealing the Network: How to 0wn the box&lt;/u&gt;, you'll remember the tool dnsmap that the character Dex used in chapter 5. Well, dmap is like that on steroids. dmap also beats out the DNS enumeration tools profiled in &lt;u&gt;The Penetration Testers Open Source Toolkit&lt;/u&gt;.&lt;br /&gt;&lt;br /&gt;Anyways, you can get dmap at &lt;a href="http://http://nemesismk2.freesuperhost.com/code/dmap_3.0.0_pre.tar.gz"&gt;http://nemesismk2.freesuperhost.com/code/dmap_3.0.0_pre.tar.gz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113788356982464822?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113788356982464822/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113788356982464822' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113788356982464822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113788356982464822'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/01/dmap.html' title='dmap'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113657421776283522</id><published>2006-01-06T13:55:00.000-05:00</published><updated>2006-01-06T16:50:23.630-05:00</updated><title type='text'>Ground Zero</title><content type='html'>Well, the 6th is here. Sober is going to be released today. &lt;a href="http://enterprisesecurity.symantec.com/products/products.cfm?ProductID=158&amp;EID=0"&gt;Symmantec's threat meter&lt;/a&gt; on &lt;a href="http://www.securityfocus.com"&gt;securityfocus&lt;/a&gt; is at &lt;a href="https://tms.symantec.com/threatCon_Def.asp"&gt;level 3&lt;/a&gt; (the highest I have ever seen). So, they're clearly worried. However, they were worried about the Snort vulnerability, and MS05-051, which didn't have much effect at all.&lt;br /&gt;&lt;br /&gt;I have read several articles that stated the attack has been stopped by F-Secure and thier discovery of the URLs that Sober will be updating from. Personally, I think the attack still will happen. (you can read one such article at: &lt;a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=175801644"&gt;InformationWeek&lt;/a&gt;). However, I don't know if these sources are will informed or not.&lt;br /&gt;&lt;br /&gt;An article was published today on CNet that Sober may actually come later than expected, due to all the publicity surrounding it. You can read the article &lt;a href="http://news.com.com/All+quiet+on+the+Sober+front/2100-7349_3-6021988.html?tag=cd.lede"&gt;here&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;If indeed Sober does launch today, there should be some activety by 21:00 GMT -5. So, lets just keep our fingers crossed till then. &lt;br /&gt;&lt;br /&gt;Also, a message to any end users out there: Update your AV signitures, apply OS patches, setup a firewall, and don't download ANY email attachments. Doing all these will help to stop Sober.&lt;br /&gt;&lt;br /&gt;Also, the 0-day WFM exploit has been making waves. The metasploit dev team has released an exploit module for it, making it easy for anyone to code thier own varient. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113657421776283522?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113657421776283522/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113657421776283522' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113657421776283522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113657421776283522'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2006/01/ground-zero.html' title='Ground Zero'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113563563594257748</id><published>2005-12-26T17:14:00.000-05:00</published><updated>2005-12-26T17:20:35.956-05:00</updated><title type='text'>Holidays</title><content type='html'>Ahoy,&lt;br /&gt;&lt;br /&gt;Well, I'd just like to drop all my readers a line wishing them a happy holiday season. I know that I missed christmas, but meh, still in time for new years. ;-)&lt;br /&gt;&lt;br /&gt;Still, better late then never.&lt;br /&gt;&lt;br /&gt;BTW, I've finished coding a banner grabber for the Metasploit 2.x branch. Code will be up on &lt;a href="http://www.area-6.net"&gt;www.area-6.net&lt;/a&gt; soon, but I still have a few kinks to work out (Perl appears to think that I called a subroutine at line 61, but since when is if() a subroutine?!).&lt;br /&gt;&lt;br /&gt;Next up is a connection sweeper. Now, I know you're all gonna think "Oh god, he's truning this into Nessus or Core IMPACT. When will he stop?" Well, I'm not. I'm not coding anything to automate attacks. Just a discovery suite of tools. &lt;br /&gt;&lt;br /&gt;Well, I'm out.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;br /&gt;&lt;br /&gt;PS: I'm going to publish that &lt;a href="http://www.8e6.com"&gt;8e6&lt;/a&gt; XSS exploit *soon*(ish).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113563563594257748?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113563563594257748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113563563594257748' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113563563594257748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113563563594257748'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/12/holidays.html' title='Holidays'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113519962455586750</id><published>2005-12-21T15:57:00.000-05:00</published><updated>2005-12-21T16:19:06.133-05:00</updated><title type='text'>Sober</title><content type='html'>Howdy,&lt;br /&gt;&lt;br /&gt;Well, as you may have noticed, Symantec's threat meter on &lt;a href="http://www.securityfocus.com"&gt;securityfocus&lt;/a&gt; is at a 2. I had no idea why and after asking on IRC, CdPirate reminded me that Sober is schedualed to be updated and released. &lt;br /&gt;&lt;br /&gt;F-Secure did a good job of releaseing the list of URLs (see their advisory at: &lt;a href="http://www.f-secure.com/weblog/archives/archive-122005.html#00000729"&gt;http://www.f-secure.com/weblog/archives/archive-122005.html#00000729&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Also, Sober has actually done some good. I'm sure that it is common knowledge by now, but Sober.Y (the one that sends fake emails) sent an email to a German citizen claiming to be from law enforcement. The man apperantly freaked out, and turned himself in. He apperantly had child porn on his box. You can find more info about this at &lt;a href="http://www.securityfocus.com/news/11365"&gt;securityfocus news&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So, who knows what the updated Sober will actually bring? I don't (I have not been following Sober during the last outbreak[s]), so, if you do, drop a comment enlightening me. ;-)&lt;br /&gt;&lt;br /&gt;But back to the Sober updates, it appears its going to be released on the 5th of January, 2006 (2006-1-5) (which, incidently, is the anniversary of the founding of the Nazi party. I'm sure you all know this by now, but Sober was spreading righ-wing neo-Nazi propaganda for a little while). F-secure mentioned that it would reach critical mass by the 6th of January (2006-1-6). CdPirate made a good point stating that "By the 6th, the Internet won't be online, due to all the bots spreading". Hopefully the end users out there will have updated AV definitions, a good firewall and all the latest patches for Windows, but realistically, I doubt that will be the case. If this varient is mass mailing, it could potentially (and (un?)intentionally) perform a DoS attack against the backbones, simply from the sheer volume of email being sent (remember the MyDoom Google searches?).&lt;br /&gt;&lt;br /&gt;So, I think its safe to say that it will be an eventful few weeks after the holidays, but nothing that can't be handled. And remember, don't buy into the panic that the AV vendors are spreading. Just keep a clear head and everything will be okay.&lt;br /&gt;&lt;br /&gt;Thats all for now.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;font size=1&gt;Thanks to CdPirate for providing much of the info used in this article&lt;/font&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113519962455586750?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113519962455586750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113519962455586750' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113519962455586750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113519962455586750'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/12/sober.html' title='Sober'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113477365354647923</id><published>2005-12-16T17:49:00.000-05:00</published><updated>2005-12-16T17:55:14.166-05:00</updated><title type='text'>Metasploit Portscanner Module</title><content type='html'>Ahoy all,&lt;br /&gt;&lt;br /&gt;Well, I got the alpha release of Metasploit 3.0 yesterday. I must say that I was quite impressed with it, although I was innitally uncertain about how it due to its in Ruby (and you guys know me, I'm a Perl fanatic ;-) ).&lt;br /&gt;&lt;br /&gt;I noticed that It had a new class of modules, dubbed recon moduels. One of these was a scanner. So, I created a portscanner (TCP and UDP) for the 2.x branch. The code is avalible at: &lt;A HREF="http://www.area-6.net/forums/index.php?topic=295.msg3061;topicseen#msg3061"&gt;http://www.area-6.net&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;To use it, copy and paste the code into the exploits directory on the framework root. Name the file msf_scan.pm.&lt;br /&gt;&lt;br /&gt;BTW, You may have noticed that in the comments, I put that this is in a series of modules. I also want to do a banner grabber, and a TDP/UDP connection sweeper.&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113477365354647923?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113477365354647923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113477365354647923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113477365354647923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113477365354647923'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/12/metasploit-portscanner-module.html' title='Metasploit Portscanner Module'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113415772984162879</id><published>2005-12-09T14:36:00.000-05:00</published><updated>2005-12-09T15:09:26.480-05:00</updated><title type='text'>Swim team and XSS</title><content type='html'>Ahoy,&lt;br /&gt;&lt;br /&gt;Hey, I know its been a while since I last updated, and I'm sorry for that. So, lets catch up...&lt;br /&gt;&lt;br /&gt;Well, as everybody from #hf knows, I recenlty joined swim team. Its quite fun and we have practice everyday (Monday - Friday). At our last meet, i swam 50 meters in 29.13 seconds and 100 meters in 1 minuet 8 seconds, which is a big improvement from my previous time of 1 minuet 22 seconds. Its alot of work, but I enjoy it.&lt;br /&gt;&lt;br /&gt;Back on the techincal side, i have recently discovered an XXS vuln in 8e6's R3000 Internet content filter. This is an application that serves to block "inappropriate" content from reaching users (as well as sites that the admins have black listed). While I'm not a fan of censorship, it is a security risk to have users browsing around where ever they want to at work.&lt;br /&gt;&lt;br /&gt;The vuln is quite easy to exploit. There are several parameters in the URL that correspond with fields in the resulting page. For example, the IPGROUP variable returns the IP Address of the filter machine (usually the webproxy as well). Normally it would read something like:&lt;br /&gt;&lt;br /&gt;IPGROUP=192.168.1.100&lt;br /&gt;&lt;br /&gt;However, its possible to insert any values into these fields. At first I just played with them making them say wacky things and showing it to my friends for laughs. One day, on a whim, i tried to HREF a link to Google. When it was successful, I tried playing around with "SCRIPT" tags and HREFing javascript: calls in. They all worked okay. With this vuln, its possible to get a users cookie values, and to bypass the filter entirley.&lt;br /&gt;&lt;br /&gt;Okay, I'm out. Expect more updates soon!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113415772984162879?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113415772984162879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113415772984162879' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113415772984162879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113415772984162879'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/12/swim-team-and-xss.html' title='Swim team and XSS'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-113053407992856747</id><published>2005-10-28T16:48:00.000-04:00</published><updated>2005-10-28T17:14:39.940-04:00</updated><title type='text'>Worms, a follow up</title><content type='html'>Well, it looks like my predictions were off. Symmantec lowered their threat level, and there was no Snort worm. &lt;br /&gt;&lt;br /&gt;Course, even if there was a new worm, they don't seem that bad after NIMDA, Code Red (II), Slammer, and Blaster. Those were pretty bad, but more importantly, they also got admins to patch their systems. So, maybe some good came out of it....&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-113053407992856747?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/113053407992856747/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=113053407992856747' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113053407992856747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/113053407992856747'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/10/worms-follow-up.html' title='Worms, a follow up'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112991798236711980</id><published>2005-10-21T14:02:00.000-04:00</published><updated>2005-10-21T14:09:39.926-04:00</updated><title type='text'>Possible Worms?</title><content type='html'>Ahoy people,&lt;br /&gt;&lt;br /&gt;well, we've all heard about MS05-050 (hopefully. if you have not, check it out at &lt;A HREF="http://www.microsoft.com/technet/security/Bulletin/MS05-050.mspx"&gt; MS technet MS05-050&lt;/a&gt; ).&lt;br /&gt;&lt;br /&gt;So, the big question is, "Will this be another Windows worm?" supposedly, this vuln is easy to exploit and it leads to remote code execution (remote control). It also effects nearly every version of Windows. I seem to remember that on &lt;A HREF="http://www.securityfocus.com"&gt;securityfocus&lt;/A&gt; they said it might, as well as on &lt;A HREH="www.cnetnews.com"&gt;Cnet news&lt;/A&gt;. Of course, the comapnies love to give out these adviosories as it gets tham money (point in case, Zotob. It was not bad at all). &lt;br /&gt;&lt;br /&gt;So, maybe it will and maybe it won't.&lt;br /&gt;&lt;br /&gt;There was also the recently announced snort vuln that was deemed to be wormable (&lt;A HREF="http://www.securityfocus.com/news/11349"&gt;http://www.securityfocus.com/news/11349&lt;/A&gt;). While it would cause an impact, Snort is not that widespread (unfortunalty, it is a great NIDS and i say its a great product).&lt;br /&gt;&lt;br /&gt;BTW, if you notice symmantecs world wide threat meter is at 2, which means an attack is expected. &lt;br /&gt;&lt;br /&gt;So, what are your thoughts? Is it hype or is it for real?&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112991798236711980?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112991798236711980/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112991798236711980' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112991798236711980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112991798236711980'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/10/possible-worms.html' title='Possible Worms?'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112821309819896624</id><published>2005-10-01T20:28:00.000-04:00</published><updated>2005-10-01T20:31:38.203-04:00</updated><title type='text'>Free Cisco</title><content type='html'>Ahoy,&lt;br /&gt;&lt;br /&gt;For those of you that don't know, &lt;A HREF="http://routeviews.org"&gt;routeviews.org&lt;/A&gt; offer free anonymous telnet access to their Cisco routers (see &lt;A HREF="http://routeviews.org/aaa.html"&gt;routeviews.org/aaa.html&lt;/A&gt; for more) To login, telnet to route-views.oregon-ix.net:23 and give the username rviews&lt;br /&gt;&lt;br /&gt;Then, have fun learning about cisco, hands on!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112821309819896624?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112821309819896624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112821309819896624' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112821309819896624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112821309819896624'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/10/free-cisco.html' title='Free Cisco'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112708671528796287</id><published>2005-09-18T19:33:00.000-04:00</published><updated>2005-09-18T19:39:24.816-04:00</updated><title type='text'>OpenVMS</title><content type='html'>Howdy,&lt;br /&gt;&lt;br /&gt;i just found out about a cool little machine (&lt;A HREF="http://deathrow.vistech.net"&gt;deathrow.vistech.net&lt;/A&gt;). Its an OpenVMS box that provides free shells, or if you'd rather not give out your email address or get a permenate shell, they have a demo account. to connect simply telnet to port 23 or SSH on in. further instructions are provided in the welcome banner. &lt;br /&gt;&lt;br /&gt;now, idk about you guys, but i've never messed with OpenVMS before. however, I have been playing with it, and it seems to be like mix of UNIX and Windows (the power of UNIX with some Windows style command syntaxes). The best part is, they don't mind you hacking the system (as they say "feel free to attack however gets you off, but no DoS)! &lt;br /&gt;&lt;br /&gt;this is a cool thing. i highly recommend checking it out.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112708671528796287?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112708671528796287/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112708671528796287' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112708671528796287'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112708671528796287'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/09/openvms.html' title='OpenVMS'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112708639073672246</id><published>2005-09-18T19:29:00.000-04:00</published><updated>2005-09-18T19:39:51.310-04:00</updated><title type='text'>Office Depot</title><content type='html'>Ahoy,&lt;br /&gt;&lt;br /&gt;well, today I went to office depot, and started playing with those nifty laptops that they have on display. They had a WLAN whcih was subdivided into seperate VLANs. however, host security was the worst i've ever seen. I would have done something about it (like turn on the already installed Norton Internet Security suite), but, i figured it was better not to get in trouble atm. &lt;br /&gt;&lt;br /&gt;But, i did change the screen savers a tad. now they all say stuff like "Hack the Planet!", etc. Childish i know, but no damage was caused, and imo, changing a screen saver is not blackhat. who knows, maybe this will convince them to limit the users power on the laptops?&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112708639073672246?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112708639073672246/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112708639073672246' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112708639073672246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112708639073672246'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/09/office-depot.html' title='Office Depot'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112664013385760874</id><published>2005-09-13T15:15:00.000-04:00</published><updated>2005-09-13T15:38:50.610-04:00</updated><title type='text'>Amerex</title><content type='html'>Hey people,&lt;br /&gt;&lt;br /&gt;If any of you guys have been in the Hackers Foundation IRC channel (irc.humpmeg.net #hf), you'll know that a project called Amerex is currently in the works. I have been asked many times, what is amerex? Well, here I have come forward with more details than normal. Here it is and enjoy!&lt;br /&gt;&lt;br /&gt;What is amerex?&lt;br /&gt;&lt;br /&gt;Amerex is a tool (coded in C) that is designed to enumerate hosts in order to determin if they are a firewall, penetrate the firewall, and establish a transperant connect through the firewall (if possible).&lt;br /&gt;&lt;br /&gt;How does it work?&lt;br /&gt;&lt;br /&gt;Well, amerex first gathers info about the target. It performs the following actions:&lt;br /&gt;&lt;br /&gt;&lt;UL TYPE="disc"&gt;&lt;br /&gt;&lt;LI&gt;R/DNS lookup.&lt;br /&gt;&lt;LI&gt;ICMP slam&lt;br /&gt;&lt;LI&gt;ICMP traceroute&lt;br /&gt;&lt;LI&gt;UDP traceroute&lt;br /&gt;&lt;LI&gt;Parasitic TCP traceroute&lt;br /&gt;&lt;LI&gt;Stateless SYN portscan (a la scanrand; thank you Dan Kaminsky)&lt;br /&gt;&lt;LI&gt;Active OS identiftication&lt;br /&gt;&lt;LI&gt;Passive OS identification&lt;br /&gt;&lt;LI&gt;Trys to determin the hosts role (router, gateway, etc)&lt;br /&gt;&lt;LI&gt;Makes a guess if the host is a firewall&lt;br /&gt;&lt;/UL&gt;&lt;br /&gt;&lt;br /&gt;Okay, during the ICMP slam, we'll be sending the target host every ICMP code, just to see what ICMP types they respond to. The Parasitic TCP traceroute will be used if the ICMP and/or UDP traceroutes fail. It will be run after we do the SYN scan. Once we find an open port, a full connection (SYN, SYN/ACK, ACK) would be established. Then we would preform the parasitic traceroute, a la paratrace (once again, thank you Dan Kaminsky).&lt;br /&gt;&lt;br /&gt;The reason why we do a passive OS id and an active OS id is simple: that way we can cross refernce them in an attempt to gain greater accuracy.&lt;br /&gt;&lt;br /&gt;the info will then be dumped to STDOUT in a nice neat report :-)&lt;br /&gt;&lt;br /&gt;Okay, now we're ready to start the actual firewall enumeration.&lt;br /&gt;&lt;br /&gt;First the attacks on the firewall:&lt;br /&gt;&lt;UL type="disc"&gt;&lt;br /&gt;&lt;LI&gt;Source port attacks&lt;br /&gt;&lt;LI&gt;State attacks&lt;br /&gt;&lt;LI&gt;Fragged packet slam&lt;br /&gt;&lt;LI&gt;Mangled headers&lt;br /&gt;&lt;LI&gt;Source routed packets&lt;br /&gt;&lt;LI&gt;Just general wierd packets&lt;br /&gt;&lt;LI&gt;Firewalking&lt;br /&gt;&lt;LI&gt;Protocol Tunnels&lt;br /&gt;&lt;LI&gt;Combinations of the above&lt;br /&gt;&lt;/UL&gt;&lt;br /&gt;&lt;br /&gt;Okay, those should be pretty much self explanitory.&lt;br /&gt;&lt;br /&gt;Now, if conditions look good (eg: we get a reply from one of our packets from a host behind the firewall, amerex will attempt to establish a transpertan tunnel through the firewall.&lt;br /&gt;Methods that will be used are:&lt;br /&gt;&lt;br /&gt;&lt;UL type="disc"&gt;&lt;br /&gt;&lt;LI&gt;Fragged packets&lt;br /&gt;&lt;LI&gt;ICMP tunnel&lt;br /&gt;&lt;LI&gt;UDP tunnel&lt;br /&gt;&lt;LI&gt;Source port&lt;br /&gt;&lt;LI&gt;State attacks&lt;br /&gt;&lt;LI&gt;Mangled headers&lt;br /&gt;&lt;LI&gt;Protocol tunnels&lt;br /&gt;&lt;/UL&gt;&lt;br /&gt;&lt;br /&gt;Not that protocol tunnles will only be used rarley, if everything else fails.&lt;br /&gt;&lt;br /&gt;What language is amerex written in?&lt;br /&gt;&lt;br /&gt;Amerex is being written in C.&lt;br /&gt;&lt;br /&gt;When will amerex come out?&lt;br /&gt;&lt;br /&gt;No idea. It is still in development, and is not yet ready for a beta release.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Well, thats all for today. &lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112664013385760874?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112664013385760874/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112664013385760874' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112664013385760874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112664013385760874'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/09/amerex.html' title='Amerex'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112511375754460702</id><published>2005-08-26T23:30:00.000-04:00</published><updated>2005-08-26T23:35:57.550-04:00</updated><title type='text'>Awstats.pl</title><content type='html'>Ahoy,&lt;br /&gt;&lt;br /&gt;Well, I just coded my second professional level exploit. Once again, I didn't discover the vulnerability, but the guy who did had not even submitted it to &lt;A HREF="http://www.securityfocus.com"&gt;securityfocus&lt;/A&gt;. So I did for him, taking care to enclose all his original and stressing several times that I didn't discover this and that he did. I also included my code (which I wrote). I just sent it off like 3 mins ago, but hey, I can hope, right? lol. Anyways, &lt;A HREF="http://www.area-6.net/forums/index.php?topic=232.0"&gt;here&lt;/A&gt; is my code. &lt;br /&gt;&lt;br /&gt;Hopefully there will be a link to &lt;A HREF="http://www.securityfocus.com"&gt;securityfocus&lt;/A&gt; for that code soon. But I really hope that they don't credit the discovery to me... I'd feel bad for the original dude...&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112511375754460702?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112511375754460702/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112511375754460702' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112511375754460702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112511375754460702'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/08/awstatspl.html' title='Awstats.pl'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112492938930813645</id><published>2005-08-24T20:20:00.000-04:00</published><updated>2005-08-24T20:23:21.003-04:00</updated><title type='text'>Updates</title><content type='html'>Howdy,&lt;br /&gt;&lt;br /&gt;well I finally came to a conclusion: my blog looks like it was made by a 9 year old! So, over the course of the next few days, I will be customizing my blog to fit my needs. Any advice and/or critisims are welcome.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112492938930813645?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112492938930813645/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112492938930813645' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112492938930813645'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112492938930813645'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/08/updates.html' title='Updates'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112481339588084554</id><published>2005-08-23T12:08:00.000-04:00</published><updated>2005-08-23T12:09:55.886-04:00</updated><title type='text'>CdPirate</title><content type='html'>Hey,&lt;br /&gt;&lt;br /&gt;CdPirate just got his blog up. check it out at: &lt;A HREF="http://cdpirate.blogspot.com"&gt;cdpirate.blogspot.com&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;also, &lt;A HREF="http://hackersfounation.org"&gt;hackersfoundation.org&lt;/A&gt; is almost finished getting set up!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112481339588084554?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112481339588084554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112481339588084554' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112481339588084554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112481339588084554'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/08/cdpirate.html' title='CdPirate'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112465154294130591</id><published>2005-08-21T15:07:00.000-04:00</published><updated>2005-08-21T15:12:22.946-04:00</updated><title type='text'>w00t!</title><content type='html'>Hey,&lt;br /&gt;&lt;br /&gt;I just discoverd something. The exploit code that I submitted to &lt;A HREF="http://www.securityfocus.com"&gt;www.securityfocus.com&lt;/A&gt;, was accepted! Admittidly, I didn't find this vuln, (it was discovered by Reed Arvin), but i recoded my own version, and submitted it!&lt;br /&gt;&lt;br /&gt;check out the following URLs for more info:&lt;br /&gt;&lt;br /&gt;&lt;UL TYPE="disc"&gt;&lt;br /&gt;&lt;LI&gt;&lt;A HREF="http://www.securityfocus.com/bid/13888/exploit"&gt;www.securityfocus.com/bid/13888/exploit&lt;/A&gt;&lt;br /&gt;&lt;LI&gt;&lt;A HREF="http://downloads.securityfocus.com/vulnerabilities/exploits/goodtech_dos.pl"&gt;downloads.securityfocus.com/vulnerabilities/exploits/goodtech_dos.pl&lt;/A&gt;&lt;br /&gt;&lt;/UL&gt;&lt;br /&gt;&lt;br /&gt;Heh, idk about you, but i think that this is pretty cool!&lt;br /&gt;&lt;br /&gt;NOTE: DoS is lame. dont ever do it. ever. i just wrote this script on a whim and submitted to it to &lt;A HREF="http://www.securityfocus.com"&gt;securityfocus&lt;/A&gt; just to see what would happen.&lt;br /&gt;&lt;br /&gt;heh, I got my code published! &lt;br /&gt;&lt;br /&gt;/me does a little dance&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112465154294130591?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112465154294130591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112465154294130591' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112465154294130591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112465154294130591'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/08/w00t.html' title='w00t!'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112241378554767676</id><published>2005-07-26T17:35:00.000-04:00</published><updated>2006-10-06T16:10:29.550-04:00</updated><title type='text'>Comment!</title><content type='html'>Hey if you are reading my blog could you take a second to comment? i'm trying to get s sense of how many peopel actually read this ;-)&lt;br /&gt;&lt;br /&gt;thanks in advance.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112241378554767676?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112241378554767676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112241378554767676' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112241378554767676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112241378554767676'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/07/comment.html' title='Comment!'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112241342293085746</id><published>2005-07-26T17:28:00.000-04:00</published><updated>2005-07-26T17:30:22.930-04:00</updated><title type='text'>Password cracker</title><content type='html'>hey guys i made an interesting password cracker in Perl. it'll do a dictionary attack against DES, SHA1, and MD5. check out the source here: &lt;A HREF="http://www.area-6.net/forums/index.php?topic=194.0"&gt;www.area-6.net&lt;/A&gt; (its the second one i posted). &lt;br /&gt;&lt;br /&gt;enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112241342293085746?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112241342293085746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112241342293085746' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112241342293085746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112241342293085746'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/07/password-cracker.html' title='Password cracker'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-112241326285453519</id><published>2005-07-26T17:27:00.000-04:00</published><updated>2005-07-26T17:27:42.860-04:00</updated><title type='text'>back</title><content type='html'>Well i got back from vacation a few weeks ago. Time to update!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-112241326285453519?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/112241326285453519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=112241326285453519' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112241326285453519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/112241326285453519'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/07/back.html' title='back'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111816157507297382</id><published>2005-06-07T12:25:00.000-04:00</published><updated>2005-06-07T12:26:15.073-04:00</updated><title type='text'>myspace</title><content type='html'>heh, after that last post this is starting to look like myspace...&lt;br /&gt;&lt;br /&gt;don't worry, i'm not gonna turn this into some sorta angsty place, it will remain a technical blog.. ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111816157507297382?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111816157507297382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111816157507297382' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111816157507297382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111816157507297382'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/06/myspace.html' title='myspace'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111816142936855323</id><published>2005-06-07T12:20:00.000-04:00</published><updated>2005-06-07T15:54:33.090-04:00</updated><title type='text'>Busy</title><content type='html'>hey guys,&lt;br /&gt;&lt;br /&gt;sorry about the long down time (yet again!). i have had one hell of a time...&lt;br /&gt;&lt;br /&gt;i'm tyrying to get www.hackersfoundation.org off the ground with CdPirate. hf is a site that i will be hosting (he's covering the domain name). we'll have some code and some tuts as well as a forum and maybe a tag board. i hope to make my own subsection of the site where so technical discussions can take place...&lt;br /&gt;&lt;br /&gt;wow... i just found out yestarday that a person i know committed suicide on Sunday... it's been a crazy time...&lt;br /&gt;&lt;br /&gt;hopefully after my life settles down a bit, i'll be able to update daily. who knows, this may even turn intop an actual blog ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111816142936855323?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111816142936855323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111816142936855323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111816142936855323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111816142936855323'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/06/busy.html' title='Busy'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111522405033201860</id><published>2005-05-04T12:22:00.000-04:00</published><updated>2005-05-04T12:27:41.656-04:00</updated><title type='text'>Tools</title><content type='html'>All,&lt;br /&gt;&lt;br /&gt;hey, sorry for the long down time. I have been hard at work coding some stuff (some of which you may find interesting) so i have not been able to blog much.&lt;br /&gt;&lt;br /&gt;i'll be posting the code on another site and then linking to it (beacuse if i post it here all the formatting will be messed up ;) ).&lt;br /&gt;&lt;br /&gt;anyways heres a baisc rundown of the programs:&lt;br /&gt;&lt;br /&gt;&lt;ul type="disc"&gt;&lt;br /&gt;&lt;LI&gt;dnsscan2.pl: a small idea that i had. It does DNS lookups on a domain that you find in an attempt to identify subdomains. it will find things like, mail servers, VPNs, firewalls, etc. Handy! ;)&lt;br /&gt;&lt;BR&gt;&lt;br /&gt;&lt;LI&gt;sweep.pl: A TCP/UDP sweeper, it is used to identify hosts that are alive.&lt;br /&gt;&lt;BR&gt;&lt;br /&gt;&lt;LI&gt;portscan.pl: a small port scanner. it is not stealthy at all. It supports UDP and TCP scans. &lt;br /&gt;&lt;/UL&gt;&lt;br /&gt;&lt;br /&gt;okay thats all for now. links will be up soon!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111522405033201860?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111522405033201860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111522405033201860' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111522405033201860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111522405033201860'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/05/tools.html' title='Tools'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111403620198191114</id><published>2005-04-20T18:29:00.000-04:00</published><updated>2005-04-22T22:43:23.046-04:00</updated><title type='text'>Admin issue 1</title><content type='html'>Well, here it is: Under Ground Admining Issue 1. Enjoy...:&lt;br /&gt;&lt;br /&gt;&lt;TT&gt;&lt;br /&gt;&lt;br /&gt;                   -=-{UNDERGROUND ADMINING}-=-&lt;br /&gt;             [isssue 1]&lt;br /&gt;                                                      [by: n3w7yp3]&lt;br /&gt;               [this paper can be freely distibuted as long as credit is given to me and it is whole and unchanged]&lt;br /&gt;               &lt;br /&gt;&lt;br /&gt;&lt;br /&gt; +{_INTRO_}+&lt;br /&gt;&lt;br /&gt;Okay, this is my first paper in my new _Underground__Admining_ series. This series focuses on how to effectively secure a network. It is *not* however, some super technical "end-all" book that you would buy from Borders. Instead I will point out various issues (propose fixes, too) and in general my goal here is to get the admin to think like a hacker. Lets get to it...&lt;br /&gt;&lt;br /&gt; +{_REMOTE_}+&lt;br /&gt;&lt;br /&gt;We will first be discussing remote issues. Now, you will find that I will not propose solutions for the newest 0-days, instead my goal is to address the fundamental issues in the network. Lets first look at the gateway...&lt;br /&gt;&lt;br /&gt;The gateway is basically the door into your network. It is all that stands between the untested Internet and your trusted intranet. Thus, we obviously need to take special measures when securing it. A good place to start would be the TCP/IP protocol suite...&lt;br /&gt;&lt;br /&gt;Lets look at UDP first. UDP is the *U*ser *D*atagram *P*rotocol. Unlike TCP, it is connectionless and unrealible. UDP, however, has several uses to an attacker. Because it is connectionless, it can be used to trace the route to a host (traceroute). It also has several other uses but they don't concern us at the moment. Your gateway should be set to drop all incoming UDP to the floor. If it simply ignores the packets, you are still vulnerable to a technique called _firewalking_. Bascially, this technique sends a UDP packet with a TTL 1 greater than need to to reach the remote host (in this case, your gateway). Also, a host is specified *behind* the gateway (firewalking only works agains gateways). So, the gateway would ignore the packet but would still hand it off to the remote system inside the network. Using this technique, an attacker could easily map out your whole internal network. However, if the gateway drops the packet to the floor, this technique would be rendered irrevelant. Many admins feel that having the gateway ignore incoming packets is enough. In simple terms: it is _not_ enough. Drop those packets to the floor!&lt;br /&gt;&lt;br /&gt;Next lets examine ICMP. ICMP is the *I*nternet *C*ontrol *M*essage *P*rotocol. it is used for the smooth running of networks (espically at the IP layer), and to check things like connectivety and bandwidth. However it also has (many) negative uses. Your gateway should be automatically configured to drop all incoming ICMP_ECHO_REQUEST packets to the floor. If it is not, then we might have a problem.... I don't see why you need incoming ICMP packets at all to be honest. Put 'em all on the floor! If you're still not convinced about the dangers of ICMP, lets look at ICMP tunneling. In this technique, ICMP packets are used to pierce through firewalls. Once inside, an attacker can ping your whole IP range, and get all your hosts in one grab. ICMP can also be used to nuke network connections and in a variety of D/DoS attacks. Now, I am sure that no one wants any of this happening to their network. So, drop all incoming ICMP packets to the floor.&lt;br /&gt;&lt;br /&gt;ARP is our next suspect. ARP is the *A*ddress *R*esolution *P*rotocol. It is used to convert between physical MAC (*M*edia *A*ccess *C*ontrol) addresses and IP addresses. Now I'll put this plainly: You should never receive an incoming ARP request from the Internet. Its that simple. If you do it could be a sign that a Man-in-the-Middle (MiM) attack is taking place. Again, your gateway should put all incoming ARP packets on the floor (in the unlikely event that you do get one). More serious is ARP on your intranet. It can be used in *ARP chache poisoning*. This attack ccan either be used by it self or in conjunction with a MiM attack. It is very unlikley that there will be an oppertunity for an attacker to use a MiM attack on your network; but all ARP should be handled suspiciously.&lt;br /&gt;&lt;br /&gt;DNS is a little different. Most firewalls and gateways will accept packets as long as the have port 53 (the deafult DNS port) listed as thier source port. DNS is the *D*omain *N*ame *S*ervice. It converts hostnames to IPs and vice versa. DNS is essential to the runing of a network. If you have the resources, give your network a designated DNS server and don't let any incoming request in.&lt;br /&gt;&lt;br /&gt;Now, you're probably thinking, "Wait. DNS is a service not a protocol!" And you're absolutely right. But i put it in here to illustrate an important point: Do not let packets in based on their source port. That is trival to spoof....&lt;br /&gt;&lt;br /&gt;Lets move on to TCP. TCP is the *T*ransmission *C*ontrol *P*rotocol. It is the most widely used protocol. It is connection based and reliable. Unfortunatly, there is no easy way to deal with TCP. If we drop all the packets, we won't be able to communicate with the outside Internet (not deserible). The solution is to make sure that your firewall/gateway tracks _states_. By this I mean that it will not admit a SYN/ACK from x.x.x.x unless a system on your LAN set a SYN to x.x.x.x. If you get an unsolisitated packet, you might want to drop it (espically SYNs).&lt;br /&gt;&lt;br /&gt;Following ths setup will greatly harden your network. However, security dows not stop at the peremiter. Since the internal workings of a network are so varied, there is no easy solution as we wittnessed above. Here is a short incomplete bullet list of things to think about:&lt;br /&gt; * NetBIOS. Try not to rely on it.&lt;br /&gt; * RPC. Try not to *USE* them.&lt;br /&gt; * Don't rely on "trusted" hosts.&lt;br /&gt; * Keep all systems on the latest patch level.&lt;br /&gt; * Segragate the network. Don't let hosts interact with each other if they don't have to.&lt;br /&gt; * If multiple intranets use the same IP range, and are inter-connected (like a school system), make sure that school A can't be access from school B, and vice versa.&lt;br /&gt;&lt;br /&gt;These are just a few things to think about. But, now, lets move onto local access. Physical access. Yes, even your own useres cannot be trusted....&lt;br /&gt;&lt;br /&gt; +{_LOCAL_}+&lt;br /&gt;&lt;br /&gt;Okay lets discuss local problems. These occur when a user is physically sitting in front of a terminal. to get a better sense of things, make yourself a standard user level account. If you admin a school, make it a student level account. No special privilages. Now, walk down to a computer that a normal user would use. Sit down. Login on the normal user account. Start checking things. Can you right click on the desktop? Can you right click in programs? Can you access "My Computer"? Can you start a shell from the Start menu? Most likely not. Now open Internet Explorer and type in the IP of anther host on your intranet. Can you access it? Can you access drives from IE? Again, probably not (by deafult any URL with a backslash in it is rejected). Now lets take a closer look....&lt;br /&gt;&lt;br /&gt;The next thing to do is the following:&lt;br /&gt;&lt;br /&gt; 1. Open Notepad&lt;br /&gt; 2. Type in the following:&lt;br /&gt;&lt;br /&gt; [HTML]&lt;br /&gt; [HEAD]&lt;br /&gt; [TITLE]test[/TITLE]&lt;br /&gt; [/HEAD]&lt;br /&gt; [BODY]&lt;br /&gt; [P][A HREF="file:///C:"]C:\[/A][/P]&lt;br /&gt; [/BODY]&lt;br /&gt; [/HTML]&lt;br /&gt;&lt;br /&gt; 3. Save it as test.html&lt;br /&gt; 4. Run it.&lt;br /&gt;&lt;br /&gt;NOTE: Remove the [ ] and replace them with the normal HTML tags.&lt;br /&gt;&lt;br /&gt;Now this code is nothing special. Just a *.html with a link to the C: drive. When you click on it, does the drive open? If not, good. If it does (which is more likley), then we've got a problem. Navigate to the command line (on Windows XP it is C:\WINDOWS\SYSTEM32\). Now click on cmd.exe. It should be disabled. Okay, lets try command.com. Most admins forget about command.com. If command.com opens try to use the AT command. Read the help to try to get it to open cmd.exe in one minuet or so. Notice how you're SYSTEM level now? Of course, AT is most likley disabled.&lt;br /&gt;&lt;br /&gt;Now you hopefully understand what to look for. But we'er not done yet!&lt;br /&gt; &lt;br /&gt; 1. Start Notepad.&lt;br /&gt; 2. type in the following:&lt;br /&gt;&lt;br /&gt; START [path to command.com]&lt;br /&gt; &lt;br /&gt; 3. Save it as test.bat *and* again as test.cmd.&lt;br /&gt; 4. Run it.&lt;br /&gt;&lt;br /&gt;After START, type in the path to command.com that we discovered earlier. run both files. Two nice new shells pop up. Try out the following commands:&lt;br /&gt;&lt;br /&gt; AT&lt;br /&gt; ipconfig /all&lt;br /&gt; ipconfig /displaydns&lt;br /&gt; hostname&lt;br /&gt; nslookup (set type=all. Query your name server)&lt;br /&gt; new view /domain&lt;br /&gt; net view /domain:[domain name]&lt;br /&gt; net use&lt;br /&gt; net view&lt;br /&gt; nbtstat -A [computer]&lt;br /&gt; nbtstat -a [computer]&lt;br /&gt; netstat -an&lt;br /&gt; arp -a&lt;br /&gt; route print&lt;br /&gt;&lt;br /&gt;Hopefully, most of these commands will be locked down. If not, well, now you have a list of hosts, shares and DNS info along with other other valuable information. See how easy that was? Now, if someone does get local access, pray to your religious diety of choice that they are a hacker with lots of technical knowledge. If they are not, they are more likley to cause damage accidently. Also, don't punish people with local access. Instead, find out what they did, get as much info on the problem/breach as possible, and give them a warning. Or offer them a job. Whatever...&lt;br /&gt;&lt;br /&gt; +{_CLOSING_}+&lt;br /&gt;&lt;br /&gt;As an administrator you are responsible for your network and all that it contains. Do you job well, and you will be respected. Here is a little "Admin Ethic" that I have prepared:&lt;br /&gt;&lt;br /&gt; 1. As as admin *you* are responsible for your network and all it contains.&lt;br /&gt; 2. Admining is a balance betwwen ease of use and security.&lt;br /&gt; 3. Don't insult your users.&lt;br /&gt; 4. Normal users will always prefer ease of use over security.&lt;br /&gt; 5. However, normal users want to feel secure.&lt;br /&gt; 6. There needs to be a balance between ease of use and security.&lt;br /&gt; 7. However, security is paramount and in the event of a conflict between security and ease of use, security takes priority.&lt;br /&gt;&lt;br /&gt;Well, I hope you learned something here. Remember, "Set a hacker to catch a cracker".&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;br /&gt;&lt;br /&gt;PS: For those of you who are wondering why this was Windows ony, well Windows is the numnber 1 used OS in the world. I don't like it at all. My OS of choice is Linux (it is what I run now). Future papers in this series will cover more OSs than just Windows.&lt;br /&gt;&lt;br /&gt;            -=EOF=-&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;TT&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111403620198191114?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111403620198191114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111403620198191114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111403620198191114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111403620198191114'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/04/admin-issue-1.html' title='Admin issue 1'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111403582619487583</id><published>2005-04-20T18:22:00.000-04:00</published><updated>2005-04-20T18:23:46.193-04:00</updated><title type='text'>New Series</title><content type='html'>All: i have sttarted a new series of guides. It is called &lt;I&gt;Under Ground Admining&lt;/I&gt;. I will post the first issue shortly.&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111403582619487583?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111403582619487583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111403582619487583' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111403582619487583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111403582619487583'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/04/new-series.html' title='New Series'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111245466033155356</id><published>2005-04-02T10:09:00.000-05:00</published><updated>2005-04-02T10:12:31.080-05:00</updated><title type='text'>Guide</title><content type='html'>okay here is Hack Guide Issue 1. Enjoy!&lt;br /&gt;&lt;br /&gt;&lt;TT&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;            [this guide can be freely distributed as long as it remains]&lt;br /&gt;                  [whole and unchanged and credit is given to me]&lt;br /&gt;&lt;br /&gt; +{INTRO}+&lt;br /&gt;&lt;br /&gt; well,here we have my 3rd attempt to write a hacking guide. My first one was completed but had many flaws, and alot of the info was wrong. My second attempt was good and accurate but was extremly long and i lost track of where i was when i moved and was forced to abondon it for a few weeks. So, in this attempt i have decided to take a different approach. This version will be a broken up guide, with the new issue coming out once a week (hopefully). at the end you will have a complete guide sitting on your HD, it will just be broken up into sections, thus making it eaiser to read. Or, if you prefer the long single text file type of guides, you can simply make a file called "hack_guide" and reassemble it using your version of the *nix cat command and some output redirection (for example: [bash]$ cat issue1_intro &gt;&gt; hack_guide ) okay enough explaining. lets get to it!&lt;br /&gt;&lt;br /&gt; +{THE STATE OF THE HACK}+&lt;br /&gt;&lt;br /&gt; The state of the hacking scene is so much different now than it was even a few years ago. with skript kiddies seeminly everywhere, and crackers and black-hats breaking into and defacing websites and in general causing damage, its getting to be pretty bad in the Underground. i personally hope that the scene returns to the way it was back in the earlier times. &lt;br /&gt;&lt;br /&gt;  +{INTRODUCTION TO THE UNDERGROUND}+&lt;br /&gt;&lt;br /&gt; The underground is where the hackers are. its a place that values knowledge more than anything. In it you are encouredged to ask questions and seek answers and expirement to discover new things. Probably the best description that i have ever read appeared in LOA/H's guide: &lt;br /&gt; The underground is not a physical thing; it's an essence. An essence that combines all means of communications to gain knowledge. Computers, telephones, electronics, credit cards...all communications of the present, and of the future. The very backbone of society, the computer, simply runs the world. There is no piece of data that is not stored and/or maintained somewhere on a computer. Thus, those who know how to run a computer, know how to run the world. The underground is a combintation of people, attitudes, beliefs, ideas, and cultures. No one owns it, no one controls it, it is the one truly free thing on this Earth. A means to communicate, freedom of speech and of expression...no regulations...just people, ideas, utopia. Become the owner of society, the only free human being on this planet, become the hacker.&lt;br /&gt;&lt;br /&gt;  +{HACKERS: A SHORT HISTORY}+&lt;br /&gt;&lt;br /&gt; Hackers have been around as long as there have been people who have been curious about the world around them. From the guy who first made the 3 legged stool, to the dude who discovereed that if you take sand and put it on a piece of paper it can smooth out wood. However, the first "official" hackers were the now legendary MIT model train club back in the 1950's. They took switches and made them able to recive phone calls (in effect turning them into modems), so you caould change track position remotly. Later they moved onto computers. In their programs they strove for elegance. Elegance was achived when a program preformed a function in less lines of code and in less time. The first hackers were more or less very good programmers. In the 1960's UNIX was invented at Bell Labs in Califorina. UNIX would change the face of the newly created internet. UNIX was a powerful multiuser OS, capable of doing things that less powerful OS's (MS-DOS) couldn't dream of. Also around this time a new group of people were emerging. They were called phone phreaks. phreakers were the hackers of the telephone systems. they could pretty much do anything from getting free calls to talking to outboard operators in Romania. the phreaks were influential in the development of hackers and hackerdom. in the late 1970's when computers were getting more popular, phreakers and hackers were coming together. at that time there was no such thing as HTML, so there was no World Wide Web. actually, there was no internet. It was called the ARPANet. at this time it was command line driven and unfriendly. instead of typing a URL into your browseres address bar, you would literally call sites by using their phone numbers. Also, sinde there was no WWW, there were no websites. you would log onto Bulliten Board Systems (BBSs). programs would be downloaded of a File Transfer Protocal (FTP) server. so as you can tell, it is very diffent then what we have today. it was also very expensive. at that time long distance calls even to just one state over cost a fortune. so just imagine how much it would cost to call a BBS in London from New York. so most of the time (if not all the time) hackers would phreak their way onto the ARPANet and make these calls for free. In 1984, the scene changed yet again. 2600 magazine was founded by Emmanuel Goldstein. 2600hz was the frequency used by phone phreaks to blue box and red box (methods of making free calls). Also, a young hacker whose handle was Lex Luthor founded the Legion of Doom (later called Legion of Doom/Hackers). The guys in LoD/H were pretty much widly recocgnized as sum of the best hackers around. some people in LoD/H were: Erik Bloodaxe, The Mentor, Prophet, Knight Lightning (who served a short time as the editor of PHRACK magazine; another excellent e-zine) and as best as i can tell from old txt files, Kevin Mitnick was involved in LoD/H for a while. Later, in the late 1980's/early 1990's Erik Bloodaxe had a disagreement with Phiber Optik and Phiber Optik left LoD/H and formed MoD with sum other phreaks and hackers. It is uncertain exactly as to what MoD stood for; depending on who they were talking to it was either called the Masters of Deception or the Masters of Destruction. MoD was a good hacker group and soon aquired a reputation as such. LoD/H and MoD then had a contest to see which group had the better members. It soon evolved into a full scale hacker war, with phone lines being tapped, servers being hacked, and all sorts of hackerly nonsense being perpatrated by both groups. It came to an abrupt end when Erik Bloodaxe discovered that some members of MoD were tapping the phone at his office. So he called the FBI (who were already investigating some members of MoD). At the end of the day Phiber Optik, Scorpion, Acid Phreak, and Corrupt (all of MoD) were prosecuted and jailed. in 1991 thru the mid 1990's (like till 1993) a curious cracker named Phantom Dialer (sum times abbreviated to phantomd) was taking over the internet. Phantomd was a brain damaged kid who had extrodinary patience. He was one of the most successful crackers in history. He learned from the cracker Grok, and even taught Jsz, who in turn taught Kevin Mitnick. After a small down time he changed his nick to Infomaster and took over the internet backbone using a sendmail exploit to get an account and a siniffer coded by Jsz to snare password. (Jsz could program; Infomaster could not). Eventually, Infomaster was busted byy the FBI, but they decided to to press charges for various reasons.&lt;br /&gt;&lt;br /&gt; +{CLOSING STATEMENT}+&lt;br /&gt;&lt;br /&gt; Well, that looks like enough for one issue. As you can probably tell by now, hackers hold different values and belifes than other people. Hackers belive that knowledge is power, and that knowledge is never bad to have. Its all about what you use thaet knowledge for. In the next issue I will be covering some things like; The Hacker Ethic, and hopefully some technical stuff (if i have space). okay well, untill the next issue, peace --n3w7yp3&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;           [this issue of Hack Guide was written on a RedHat Linux 9 box in vim]&lt;br /&gt;&lt;/TT&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111245466033155356?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111245466033155356/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111245466033155356' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111245466033155356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111245466033155356'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/04/guide.html' title='Guide'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111211843343197186</id><published>2005-03-29T12:43:00.000-05:00</published><updated>2005-03-29T12:47:13.433-05:00</updated><title type='text'>updates</title><content type='html'>All:&lt;br /&gt;&lt;br /&gt;i am currently in the process of writing a small guide to protecting yourself (unfourtantly my Linux paper got pushed back) and i also just re-discovered a PERL tut that i had started god-knows-how long ago. so i have 3 papers in progres, along with the new issue of Hack Guide. so i am going to have a bussy time ahead ;). also, i will be hosting CdPirates site, hackersfoundation.org. i will have a subdomain of it up for my site (newage.hackersfoundation.org). i plan to move sometime after then end of the month. look for some new papers soon!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3 (2005-3-29)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111211843343197186?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111211843343197186/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111211843343197186' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111211843343197186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111211843343197186'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/03/updates.html' title='updates'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111151138633358784</id><published>2005-03-22T12:06:00.000-05:00</published><updated>2005-03-22T12:09:46.333-05:00</updated><title type='text'>New Paper</title><content type='html'>All:&lt;br /&gt;&lt;br /&gt;after writing my guide to linux, i received some input from CdPirate on IRC requesting that i write another paper on LInux, this time detailing everyday usage. I agreed. i hope to get this paper finished this week. i go on spring break on friday (2005-3-25), so I hope to get some papers written then (and hopefully start Hack Guide issue2... which reminds me that i need to post issue 1..). So expect a paper soon!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111151138633358784?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111151138633358784/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111151138633358784' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111151138633358784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111151138633358784'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/03/new-paper.html' title='New Paper'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111119271564687357</id><published>2005-03-18T19:37:00.000-05:00</published><updated>2005-03-18T19:38:35.650-05:00</updated><title type='text'>Intro To Linux</title><content type='html'>&lt;TT&gt;&lt;br /&gt;&lt;br /&gt; +{OPENING}+&lt;br /&gt;&lt;br /&gt; i've heard alot of newbies asking questions about Linux. From the very simple "What is it?" to stuff about how to use the shell and "wtf do all these crazy symbols mean?" in here i will be answering some of those questions (hopefully). this should also help a newbie choose the right distro for their needs and will explain how to get their system up and running.&lt;br /&gt;&lt;br /&gt; +{BASIC STUFF}+&lt;br /&gt;&lt;br /&gt; lets discuss some basic points:&lt;br /&gt;&lt;br /&gt; WHAT IS LINUX?&lt;br /&gt; --------------&lt;br /&gt; &lt;br /&gt;Linux is a free Open Source Operating System. it is extremely stable. It was developed in the early 1990's by a young student. his name was Linus Travoldus. He started with the old MINIX source code (MINIX was a varient of UNIX), and crreated the Linux kernal. Linux is similar to UNIX in many ways.&lt;br /&gt;&lt;br /&gt; WHAT IS A DISTRO?&lt;br /&gt; -----------------&lt;br /&gt;&lt;br /&gt;A distro is a company distrobution of Linux. You see, Linux is not made by one single company like how Microsoft makes Windows. Linux is made by many companies. the distros all have basically the same kernal, but each have thier own special features. so company XYZ's Linux might be intended for publishing and come with Open Office and some other publishing software. By contrast, company ABC's distro might be intended for programmers and would come with gcc, g77, g++, PERL and some other programming tools. &lt;br /&gt;&lt;br /&gt; HOW DO I OBTAIN A DISTRO AND HOW MUCH DOES IT COST?&lt;br /&gt; ---------------------------------------------------&lt;br /&gt;&lt;br /&gt;Obatining a distro of Linux is very easy. there are 3 ways to obatin a distro:&lt;br /&gt;&lt;br /&gt;1) Download the distro off the companys website&lt;br /&gt;2) Order a boxed set of CD-ROMs  &lt;br /&gt;3) Buy a book that comes with distro CDs&lt;br /&gt;&lt;br /&gt;Now, as for the cost of Linux, its free (if you download it off the internet)! to download a distro just goto a companys website (e.g: if you want a RedHat distro you would goto www.redhat.com) and follow the links to the lateset build and download it. Also while you downloading the distro you should download somthing called an ISO, which is a disk image that allows you to make a boot disk. This download process can be lengthy and you should only do it if you have ADSL of faster internet (cable, T3 etc.). If you order a boxed set of CD-ROMs you will have to pay (its usually around $20[US]). then all you do is wait for them to arrive and install them. The CDs included will sometimes have more packages than the public free download will. If you buy a book that comes with the CDs (for example: The RedHat Linux Bible, by Christopher Negus) it will cost you more (this time around $50[US]), but it will alos come with even more packages. It is up to you to decide how you want to get the distro.&lt;br /&gt;&lt;br /&gt; WHAT ARE SOME COMMON DISTROS?&lt;br /&gt; -----------------------------&lt;br /&gt;&lt;br /&gt;Here are a list of some of the more common distros:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  RedHat: Prehaps one of the best known linux distros, this comapny has 2 main products, Fedora and Linux. Fedora is ment more for servers, while thier version of Linux is intended for both home and server use. Their Linux distro is pretty good, providing the ease of use that newbies need but has all the power of a distro like Gentoo. RedHat is one of my favorite distros.&lt;br /&gt;&lt;br /&gt; Mandrake: A french linux distro, this distro is designed to give the user the ease of use that windows provides. If you are a Linux newbie this distro and a KDE desktop will be one of your best bets.&lt;br /&gt;&lt;br /&gt; SuSe: A german distro, SuSe is a real power distro. this miht not be your best choice for a first distro, but you should definatly check it out later. (NOTE: SuSe has been recently aquired by Novell. Also, SuSe does not offer a free download)&lt;br /&gt;&lt;br /&gt; Slackware: this is no frills linux. it basically contains the kernal, a GNOME desktop ad not much else. if you're a newbie this is not the distro for you. go with somthing like RedHat or Mandrake.&lt;br /&gt;&lt;br /&gt; Gentoo: a linux metadistrobution. Gentoo offers a unique hyperlinked interface during the free download process that makes it very easy to build a custom system. However, it requires a little more expertise than normal to set it up. &lt;br /&gt;&lt;br /&gt; Debian: a distro that takes free software very seriously. They don't include any programs that are copyrighted or that any portions of the code may be copyrighted. It has a powerful package handeling system that makes it easy to upgrade your system. &lt;br /&gt;&lt;br /&gt; Dyn:bolic : This distro is designed to be a competetor to the Mac OS in terms of graphic design capabilities. Grerat if you like all that artsy stuff.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Okay, that list was pretty short. some distros that i did not include are: Open Linux and Caldera. There are also many others , so get on google and find out witch distro sounds good to you! &lt;br /&gt;&lt;br /&gt; INSTALLING&lt;br /&gt;  ----------&lt;br /&gt;&lt;br /&gt;Installing Linux is pretty straight forward. all you do is either make your CD's from the free download, or you just get the CD's that you ordered. Make a floppy boot disk by copying the boot images off of the CD's. then, inset the floppy in to the floppy drive, and reboot. it will come up with the Linux install screen. Insert the CD's and and follow the onscreen instructions. Congrats, you will have installed Linux very soon! see, it was that easy!&lt;br /&gt;&lt;br /&gt;peace,&lt;br /&gt;--n3w7yp3&lt;br /&gt; &lt;br /&gt;&lt;/TT&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111119271564687357?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111119271564687357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111119271564687357' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111119271564687357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111119271564687357'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/03/intro-to-linux.html' title='Intro To Linux'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111101172148232218</id><published>2005-03-16T17:16:00.000-05:00</published><updated>2005-03-16T17:22:01.483-05:00</updated><title type='text'>Paper</title><content type='html'>all:&lt;br /&gt;&lt;br /&gt;I am going to be releaasing a new paper soon. I have not planned a deadline because I am bad at keeping deadlines. also, I'm sorry abouy the lack of updates, i havnt been able to blog much latley due to circumstance...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111101172148232218?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111101172148232218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111101172148232218' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111101172148232218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111101172148232218'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/03/paper.html' title='Paper'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111030192719172849</id><published>2005-03-08T12:02:00.000-05:00</published><updated>2005-03-08T12:12:07.193-05:00</updated><title type='text'>Apology</title><content type='html'>All:&lt;br /&gt;&lt;br /&gt;Recently there was a rumor on &lt;a href="http://www.hackthissite.org"&gt;HTS&lt;/a&gt; that &lt;a href="http://www.area-6.net"&gt;area-6&lt;/a&gt; was a a honeypot for the US government. unfortunatly, i posted some extremly harsh thing on Area-6 and accidently insulted HTS. So too all the HTS members who are reading this I apologize. i have already put up apologys in the approprite threads on area-6 and HTS. i wasn't intending to insult HTS at all. in fact, i really like HTS. i hope that we can all forget about this misunderstanding.&lt;br /&gt;peace&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111030192719172849?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111030192719172849/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111030192719172849' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111030192719172849'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111030192719172849'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/03/apology.html' title='Apology'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-111021656941276102</id><published>2005-03-07T12:25:00.000-05:00</published><updated>2005-03-07T12:29:29.413-05:00</updated><title type='text'>New Policy</title><content type='html'>I have decided upon a new policy. Upon release of my telnet guide, I posted it on &lt;a href="http://www.hackthissite.org"&gt;HTS&lt;/a&gt; and &lt;a href="http://www.hackerscode.org"&gt;hackerscode&lt;/a&gt;. i was accused of having ripped it off of HTS, when i was the one who posted it! So, now i will release all my papers &lt;b&gt;here&lt;/b&gt; 2 days before any where else.  so, in order to get the latest, check back here at regular intervals.&lt;br /&gt;&lt;P&gt;&lt;br /&gt;peace&lt;br /&gt;&lt;P&gt;&lt;br /&gt;--n3w7yp3&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-111021656941276102?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/111021656941276102/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=111021656941276102' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111021656941276102'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/111021656941276102'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/03/new-policy.html' title='New Policy'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-110959931983006423</id><published>2005-02-28T08:46:00.000-05:00</published><updated>2005-04-02T10:08:03.253-05:00</updated><title type='text'>guide to telnet</title><content type='html'>okay here is my guide to telnet. i have alredy posted it on &lt;a href="http://www.hackthissite.org"&gt;HTS&lt;/a&gt; and &lt;a href="http://www.hackerscode.org"&gt;hackerscode&lt;/a&gt; enjoy!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;TT&gt;&lt;br /&gt;_______________________&lt;br /&gt;/ -=Guide to telnet=- * +by: n3w7yp3 + *&lt;br /&gt;\ /&lt;br /&gt;-----------------------&lt;br /&gt;+{OPENING}+&lt;br /&gt;&lt;br /&gt;Telnet is probablay one of the most confusing things for a newbie. You see alot of guides on it, but then still newbies post questions. Hopefully, I've created a guide that will explain telnet and aleviate the need for questions to be asked (although i doubt it). okay enough talk, lets get to it!&lt;br /&gt;&lt;br /&gt;+{TELNET}+&lt;br /&gt;&lt;br /&gt;Telnet is a terminal emulation program. You see once upon a time, terminals were hardwired next to a console. Then with the rise of the PC and the Internet, a standard was needed. so they made telnet. nowadays telnet is pretty much obsolete. with the world wide web, you just use a browser, and SSH is used to login to shell accounts. but telnet is still a good thing to know.&lt;br /&gt;&lt;br /&gt;+{USING TELNET}+&lt;br /&gt;&lt;br /&gt;there are several ways to start your telnet client. if your on windows 9x click start then programs, and then MS-DOS Prompt. once in the DOS prompt type telnet at the prompt. there that GUI windows is your telnet screen. or you can just click start&gt;run and then type telnet and press &lt;enter&gt;. either way it will be the same. on Win2K/XP you can start telnet 2 ways. the first is to start a shell (start&gt;run and type cmd and press &lt;enter&gt;) and then type telnet at the prompt. the prompt will change to somthing like:&lt;br /&gt;Microsoft telnet&gt;&lt;br /&gt;or you can do the start&gt;run and type telnet and press &lt;enter&gt;method. either way will work. on Linux start a shell and type telnet. okay now that the telnet client is open we're ready to connect. well, almost. if you're on windows we need to make some configuration changes first. for windows 9x click prefrences and check "Localecho on". on widows 2K/XP type the following at the prompt:&lt;br /&gt;&lt;br /&gt;Microsoft telnet&gt; set term vt100&lt;br /&gt;Microsoft telnet&gt; set localecho&lt;br /&gt;&lt;br /&gt;there now we're ready to go. what we just did was turn on the localecho. there is a bug(?) in MS telnet that won't display the text you type unless localecho is on. and also the telnet client in Win 2K/XP ships with the deafult term type as ANSI. but vt100 is the preferrerd term type. Linux telnet clients ship all set up and ready to go. now lets connect. for the Win 9x useres click connect&gt;remote system. then in the host box type www.google.com. in the port box type 80. for the rest of us, just type the following (NOTE: in this part of the guide to telnet we're using the HTTP port. this port is used for the Internet. its number is 80. the deamon that runs on it is called the HTTPD):&lt;br /&gt;&lt;br /&gt;telnet&gt; open www.google.com 80&lt;br /&gt;&lt;br /&gt;now hit connect or press &lt;enter&gt;and wait to connect. when your connected you will see a message like:&lt;br /&gt;&lt;br /&gt;Trying 64.233.161.104...&lt;br /&gt;Connected to www.google.com.&lt;br /&gt;Escape character is '^]'.&lt;br /&gt;&lt;br /&gt;it may be a little different. now what this all mean? well, 64.233.161.104 is google's IP. the thing about the escape character means that if you push ctrl+] it will cump you back in the shell on you machine at the telnet prompt. you can then type close to close the connection. the reason for this is because sometimes the service you connected to wont do anything when you type a command, co you need to close the connection, but quit, close, exit, and kill don't bring about a reply. so thats when you hit the escape character (win 9x useres: you dont have an escape character. to close your connection connect&gt;disconnect). now by this time the connection will have probably timed out, do we have co connect again. after connecting again let's try out some HTTP requests. the first HTTP request to learn is the GET request (NOTE: HTTP is case sensitive). to issue a GET request type the following:&lt;br /&gt;&lt;br /&gt;GET / HTTP/1.0&lt;br /&gt;&lt;br /&gt;now press &lt;enter&gt;twice. whoa look at all that stuff!! that is the codee to google's main page, just like we would get if we did a right click&gt;view source. now why did google close our connection? well its because HTTP is a stateless protocal (like UDP). so since there is no actual connection between you and the site (accept at the moment of transfer) your browser needs to reconnect every time you request a new page. however, there is a way to stay connected. did you know why you had to press &lt;enter&gt;twice after you connected? well, its because after the request (that was the GET) you are supposed to issue HTTP commands. there tell the server many things, including your user agent, browser type, and conection type (and alot more!). but before we get into those, lets take a closer look at that HTTP request we just issued:&lt;br /&gt;&lt;br /&gt;GET = The request type. there are many of these. (i've included a list later in the guide)&lt;br /&gt;/ = the page. now when you tpye in a site name (http://www.google.com/) the computer connects to that site. now even if you dont type the / after .com its still the same site. you see the / is the sites homepage.&lt;br /&gt;HTTP/1.0 = this is the protocal type. a GET request is a HTTP/1.0 request, so thats what you type.&lt;br /&gt;&lt;br /&gt;heres a list of some common requests:&lt;br /&gt;&lt;br /&gt;name usage what it does&lt;br /&gt;---- ----- ------------&lt;br /&gt;CONNECT CONNECT proxy-server HTTP/1.1 sets up a tunnel through proxys (useful&lt;br /&gt;Host: site.to.connect.to to avoid web-filters)&lt;br /&gt;&lt;br /&gt;DELETE DELETE /uri HTTP/1.1 deletes the file specified by /uri&lt;br /&gt;Host: localhost&lt;br /&gt;&lt;br /&gt;GET GET /uri HTTP/1.0 gets the file specified by /uri&lt;br /&gt;&lt;br /&gt;HEAD HEAD /uri HTTP/1.0 returns the header of /uri. used in a technique called a&lt;br /&gt;banner grab; which is used to identify the OS being ran on&lt;br /&gt;the server.&lt;br /&gt;&lt;br /&gt;OPTIONS OPTIONS * HTTP/1.1 returns info about the target host. if "*" is specified it&lt;br /&gt;Host: localhost returns info abouit the server it self. other wise it return&lt;br /&gt;-=OR=- info associated with the specified /uri&lt;br /&gt;OPTIONS /uri HTTP/1.1&lt;br /&gt;Host: localhost&lt;br /&gt;&lt;br /&gt;POST POST /uri HTTP/1.1 adds data to /uri. the request defines content length. it may&lt;br /&gt;Host: localhost include binary data.&lt;br /&gt;Content-length: N&lt;br /&gt;\n&lt;br /&gt;\n&lt;br /&gt;&lt;data post="" to=""&gt;data&lt;br /&gt;&lt;br /&gt;PUT PUT /uri HTTP/1.1 adds data in the path specified by /uri (data like a new page&lt;br /&gt;Host: localhost etc)&lt;br /&gt;Content-Length: N&lt;br /&gt;\n&lt;br /&gt;\n&lt;br /&gt;data&lt;put data=""&gt;&lt;br /&gt;&lt;br /&gt;TRACE TRACE / HTTP/1.1 causes a server to respond with all the headers contained in&lt;br /&gt;Host: localhost the original request.&lt;br /&gt;&lt;br /&gt;TRACK TRACK / HTTP/1.1 an alias for TRACE. its only used in IIS.&lt;br /&gt;Host: localhost&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;okay now you should be able to do alot of stuff but just using telnet to connect to the site. okay lets get on to those HTTP commands that i mentioned. now as i stated earlier, these comamnds do lost of stuff. the most useful would probably be the&lt;br /&gt;Connection: keep-alive command. this makes the connection stay alive so you can pump through command after comamnd. lets try it:&lt;br /&gt;&lt;br /&gt;telnet&gt; open www.google.com 80&lt;br /&gt;Trying 64.233.161.99...&lt;br /&gt;Connected to www.google.com.&lt;br /&gt;Escape character is '^]'.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;oaky, now lets try out the HEAD request combined with the Connection: Keep-alive command:&lt;br /&gt;&lt;br /&gt;HEAD / HTTP/1.0&lt;br /&gt;Connection: Keep-alive&lt;br /&gt;&lt;br /&gt;HTTP/1.0 200 OK&lt;br /&gt;Cache-Control: private&lt;br /&gt;Content-Type: text/html&lt;br /&gt;Set-Cookie: PREF=ID=752b22c0c0526756:TM=1109357543:LM=1109357543:S=ntZTEgMD7QQDP6cP; expires=Sun, 17-Jan-2038 19:14:07 GMT; path=/; domain=.google.com&lt;br /&gt;Server: GWS/2.1&lt;br /&gt;Content-Length: 0&lt;br /&gt;Date: Fri, 25 Feb 2005 18:52:23 GMT&lt;br /&gt;Connection: Keep-Alive&lt;br /&gt;&lt;br /&gt;kewl, the connection didn't drop. so now we can issue more requests with out having to reconnect. however to keep the connection alive, we need to specifiy this after every request. another common HTTP command sets your user-agent. the user-agent is used to identify the OS and browser that the client (you) is running. heres a log of a telnet session to google in which I issue a full HTTP request and specify all the parameters:&lt;br /&gt;&lt;br /&gt;telnet&gt; open www.google.com 80&lt;br /&gt;Trying 64.233.161.99...&lt;br /&gt;Connected to www.google.com.&lt;br /&gt;Escape character is '^]'.&lt;br /&gt;HEAD / HTTP/1.0&lt;br /&gt;Connectiion: Keep-Alive&lt;br /&gt;Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*&lt;br /&gt;Accept-Charset: iso-8859-1,*,utf-8&lt;br /&gt;Accept-Language: en&lt;br /&gt;Host: localhost&lt;br /&gt;User-Agent: User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.3) Gecko/20040913&lt;br /&gt;&lt;br /&gt;HTTP/1.0 200 OK&lt;br /&gt;Cache-Control: private&lt;br /&gt;Content-Type: text/html&lt;br /&gt;Set-Cookie: PREF=ID=2e727971cb330368:TM=1109358158:LM=1109358158:S=IpSi5XsS1Eqo7hby; expires=Sun, 17-Jan-2038 19:14:07 GMT; path=/; domain=.google.com&lt;br /&gt;Server: GWS/2.1&lt;br /&gt;Content-Length: 0&lt;br /&gt;Date: Fri, 25 Feb 2005 19:02:38 GMT&lt;br /&gt;Connection: Keep-Alive&lt;br /&gt;&lt;br /&gt;okay there, that was a proper session, just like your browser would do. but we mostly dont bother with all that stuff, just a Connection: Keep-Alive will do just fine ;). anyways; here are some HTTP response headers:&lt;br /&gt;&lt;br /&gt;name what it means&lt;br /&gt;---- -------------&lt;br /&gt;&lt;br /&gt;Accept-Ranges The server indicates it will accept partial requests (requests within the accepted range) for the resource.&lt;br /&gt;&lt;br /&gt;Age the servers guess in seconds of how old the cached object is&lt;br /&gt;&lt;br /&gt;ETag Entity Tag. Used in cache control when the server doesnt track time-stamps. a strong&lt;br /&gt;validator when the browser is deciding if it should refresh a cached object&lt;br /&gt;&lt;br /&gt;Location Redirects the client to a different source to a URI&lt;br /&gt;&lt;br /&gt;Proxy-Authenticate carrys authentication creditals for proxy servers&lt;br /&gt;&lt;br /&gt;Referer Specifies the URI from which the request was generated. it shouldnt be relied upon for&lt;br /&gt;security testing.&lt;br /&gt;&lt;br /&gt;Server identify the server product, OS, and other info. usually modded to block unsofisticated&lt;br /&gt;attacks and incompetent attackers.&lt;br /&gt;&lt;br /&gt;Vary used to control the caching of objects&lt;br /&gt;&lt;br /&gt;WWW-Authenticate Get user Authentication&lt;br /&gt;&lt;br /&gt;so now you know what all that stuff in the servers reply means. now you may wonder what the "HTTP/1.0 200 OK" means. well this is called the status code. 200 indicates a successful transfer. heres what the ranges mean:&lt;br /&gt;&lt;br /&gt;1xx: i'm not sure what this means; its rarley used&lt;br /&gt;2xx: successful completion of the HTTP request&lt;br /&gt;3xx: unsuccessful due to moving of ducuments (URIs)&lt;br /&gt;4xx: client side error (an error on your end)&lt;br /&gt;5xx: server side error&lt;br /&gt;&lt;br /&gt;the 2 most common status codes returned are 200 OK (you get this every time a connection works and you successfuly retreive a page) and 404 which means file not found (you clicked on a bad link, etc). well now that you know a good deal about HTTP and port 80 in general, lets duscuss the most common use of these commands proxy tunneling. have you ever been at school and you try to show your friend a cool website and its blocked for sum bogus reason? wouldn't you like to get around that damn web-content filter? well trust me you can. the first thing to do is open up internet explorer. then click tools&gt;&gt;internet options&gt;&gt;LAN settings. (or sumthing similar) now you should see somthing like 'Address: webproxy Port: 80'. this is the arddress of your web proxy that the school makes you pipe all your requests through. but what if it wont let you access the tools tab in IE? what then? the first thing to do in that case is to open a shell (use you imagination on how to do this). later i will make a paper on how to get command line access when your not supposed to have it ;). now type netstat -n at the prompt. you should get some results. one of them will look something like this:&lt;br /&gt;&lt;br /&gt;10.1.44.5:80 ESTABLISHED&lt;br /&gt;&lt;br /&gt;the IP will probably not be the same at your school as it is at mine, but it does not matter. the important part is what comes after the colon. thats the port number. in this case it is the standard HTTP port (80). but what if you dont see one that has the port as 80? well look for 8080. thats a common proxy port. if you are absolutly stumped, you can simply telnet yo all the ports on all the computers that you are connected to under the netstat -n screen and issue a HEAD request. when you get a positive reply, you're in business! now that we have identified the webproxy lets tunnel out. issue the follow commands after connection:&lt;br /&gt;&lt;br /&gt;CONNECT http://www.blockedsite.com HTTP/1.1&lt;br /&gt;Host: localhost&lt;br /&gt;&lt;br /&gt;now press enter.&lt;br /&gt;&lt;br /&gt;you should see "HTTP/1.1 200 OK Connection established" from the proxy. and boom we're connected to www.blockedsite.com. now just use the different requests discussed earlier to get the HTML source code of the site and its various pages and compy and paste them into notepad. save it as a .html file, open up 'My Computer' and click on the newly created .html file to view the site as you normally would. when you want to click on a link (lets say its called 'hacking') reconnect to the proxy, tunnel out and request the source of the hacking link (for instance: GET /hacking HTTP/1.0). there, now that annoying web filter cant stop us!! of course we can connect to any port on a computer not just 80. so lets look at another one of my personal favorites, port 25 (SMTP).&lt;br /&gt;port 25 is the port used to send email. it runs the Simple Mail Transfer Protocal Deamon (SMTPD). with this port we can do lots of kewl stuff, including:&lt;br /&gt;&lt;br /&gt;1) verifying user accounts on the system&lt;br /&gt;2) preforming a banner grab to determin the OS being run on the system&lt;br /&gt;3) sending forged email&lt;br /&gt;&lt;br /&gt;now the most exciting one for you right now would be sending forged email. haven't you ever wanted to send an email to someone but wanted to use a fake name? well its pretty easy to do! the first thing to do is to connect to a mail server over port 25 (NOTE: because most sysadmins don't like people abuing thier mail servers to send fake email, i'm not using any real mail servers in this section. you'll have to find some on your own. [well, i'll tell you in a minuet how to find a vulnerable mail server]. also don't even consider using hotmail.com or gmail.google.com or another big company for this purpose. if you do you will get into deep dark shit! period). the hard part is finding a mail server to connect to. however there are ways:&lt;br /&gt;the first thing to do is to type nslookup at the prompt. then type "set type=all". okay now consider your friend email addres. it is split up into 2 parts the user name and the host. say you wanna send a fake email to buddy@yahoo.com . so now we know that we wanna goto yahoo.com over port 25 (NOTE: that warning i gave earlier was just my attempt at getting you tto read the part on nslookup. you can relax now :) . but seriously, pls dont use the expan and verfy commands! they get logged as suspicious!) so now type "yahoo.com" (no quotes). see all those entries? well if you see one like: mx1.yahoo.com thats a mail server. generally if its mail.example.com or mx.example.com its a mail server.&lt;br /&gt;&lt;br /&gt;NOTE: for those of us who use linux, our nslookup uses different commands to get the right resource record use the type&lt;br /&gt;"set type=any" and then yahoo.com&lt;br /&gt;&lt;br /&gt;okay so now we know the mail server. time to fire up telnet. this time though point it at port 25.&lt;br /&gt;&lt;br /&gt;NOTE: theres an even eaiser way to telnet. just open up a shell and type "telnet www.site.com XX" where www.site.com is a hostname or IP and XX is a port number to connect to.&lt;br /&gt;&lt;br /&gt;So to telnet to the mail server using our new method we would type the following at the prompt: telnet mx1.yahoo.com 25&lt;br /&gt;yay now we're connected. so now the kewl thing about the SMTP deamon is that you can ask it for help (unlike the HTTPD). for this paper i set up a sendmail server on my home LAN (its not connected to the internet!!). sendmail is probably the buggiest deamon, and one of the most helpful. nowadays, sendmail isnt that common, but hey just look around and you might find a sendmail deamon around. okay so after connection, we see somthing like:&lt;br /&gt;&lt;br /&gt;220-localhost.localdomain sendmail 8.6.12/8.9.6&lt;br /&gt;ready at Fri, 25Feb 2005 19:34:53 GMT&lt;br /&gt;220 ESMTP spoken here&lt;br /&gt;&lt;br /&gt;what is all this? it is called the deamon banner. it tells us what version of sendmail the server is running and with a littel hunting on google we can use this info to identify the OS of the server. okay lets ask it for help:&lt;br /&gt;&lt;br /&gt;HELP&lt;br /&gt;214- Commands:&lt;br /&gt;214- HELO EHLO MAIL RCPT DATA&lt;br /&gt;214- RSET NOOP QUIT HELP VRFY&lt;br /&gt;214- EXPN VERB&lt;br /&gt;214- for more info use "HELP &lt;topic&gt;"&lt;br /&gt;214- to report bugs &lt;snip&gt;&lt;br /&gt;214- for &lt;snip&gt;&lt;br /&gt;214- end of help info&lt;br /&gt;&lt;br /&gt;there now we no what commands are avalible. the second to last and the third to last lines i snipped their output, because i felt like it :). oaky again heres the commands along with what they do:&lt;br /&gt;&lt;br /&gt;SMTP command What it does&lt;br /&gt;------------ ------------&lt;br /&gt;HELO/EHLO greets the server&lt;br /&gt;RCPT specifies the recipent of the mail&lt;br /&gt;MAIL specifies the sender of mail&lt;br /&gt;DATA body of email&lt;br /&gt;VERB turn on verbose mode&lt;br /&gt;EXPN expand and email alias to full list of recipents&lt;br /&gt;VRFY verify that the account exists&lt;br /&gt;HELP display a help message&lt;br /&gt;QUIT exit the server&lt;br /&gt;NOOP do nothing&lt;br /&gt;&lt;br /&gt;now that we kno the commands faking the email should be easy as pie. heres a sample session in which i'll forge an email:&lt;br /&gt;&lt;br /&gt;HELO whitehouse.gov&lt;br /&gt;MAIL FROM: dhs@whitehouse.gov&lt;br /&gt;RCPT TO: n3w7yp3@localhost.localdomain&lt;br /&gt;DATA&lt;br /&gt;We're on to you you punk kid!!&lt;br /&gt;.&lt;br /&gt;QUIT&lt;br /&gt;&lt;br /&gt;there that was really choppy. i cut off all the server replies because i felt like it :) (seriously though it's late and i'm tired ;) ). now when i check my mail box on my computer sure enough, an email for dhs@whitrhouse.gov (DHS is an acronym for Department of Homeland Security)! however sometime the header wil give it away. but mostly the email client doesnt show the full hader so it does not really matter. plus, normal people don't/can't red email headers. well, good luck and stay outta trouble! ;).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+{CLOSING}+&lt;br /&gt;&lt;br /&gt;well, i hope that somebody out there learned something from this guide. also, please dont be a black-hat/cracker and mess up stuff with the knowledge you will obtain in the future. well, good luck and happy hacking! --n3w7yp3&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;-=EOF=-&lt;br /&gt;&lt;/TT&gt;&lt;br /&gt;&lt;/snip&gt;&lt;/snip&gt;&lt;/topic&gt;&lt;/put&gt;&lt;/data&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-110959931983006423?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/110959931983006423/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=110959931983006423' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/110959931983006423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/110959931983006423'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/02/guide-to-telnet.html' title='guide to telnet'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10733659.post-110798945724351134</id><published>2005-02-09T17:50:00.000-05:00</published><updated>2007-02-10T12:56:56.346-05:00</updated><title type='text'>hello world</title><content type='html'>[CODE]&lt;br /&gt;#!/usr/bin/perl&lt;br /&gt;&lt;br /&gt;print "hello world";&lt;br /&gt;exit;&lt;br /&gt;[/CODE]&lt;br /&gt;&lt;br /&gt;there now that ive gotten that over with, this blog is pretty much a hacking/coding/phreaking/what ever the hell u wanna post blog. ill be posting sum white papers and tuts later. anyone is welcome to contribute. also feel free to post sum code (i'm gonna post sum)&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10733659-110798945724351134?l=n3w7yp3.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://n3w7yp3.blogspot.com/feeds/110798945724351134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10733659&amp;postID=110798945724351134' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/110798945724351134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10733659/posts/default/110798945724351134'/><link rel='alternate' type='text/html' href='http://n3w7yp3.blogspot.com/2005/02/hello-world.html' title='hello world'/><author><name>n3w7yp3</name><uri>http://www.blogger.com/profile/17847362836998800743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
