<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Linux Hacking</title>
	<atom:link href="http://www.darknet.org.uk/category/linux-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>CAINE (Computer Aided INvestigative Environment) &#8211; Digital Forensics LiveCD</title>
		<link>http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/</link>
		<comments>http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 13:15:23 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[caine]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[digital forensics livecd]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[forensics livecd]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[linux forensics]]></category>
		<category><![CDATA[linux forensics livecd]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[mounter]]></category>
		<category><![CDATA[rbfstab]]></category>
		<category><![CDATA[security-livecd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3188</guid>
		<description><![CDATA[CAINE (Computer Aided INvestigative Environment) is an Italian GNU/Linux live distribution created as a project of Digital Forensics. CAINE offers a complete forensic environment that is organized to integrate existing software tools as software modules and to provide a friendly graphical interface. The main design objectives that CAINE aims to guarantee are the following: an [...]]]></description>
			<content:encoded><![CDATA[<p>CAINE (Computer Aided INvestigative Environment) is an Italian GNU/Linux live distribution created as a project of Digital Forensics. CAINE offers a complete forensic environment that is organized to integrate existing software tools as software modules and to provide a friendly graphical interface.</p>
<p>The main design objectives that CAINE aims to guarantee are the following:</p>
<ul>
<li>        an interoperable environment that supports the digital investigator during the four phases of the digital investigation</li>
<li>        a user friendly graphical interface</li>
<li>        a semi-automated compilation of the final report</li>
</ul>
<p><strong>New Features/Tools</strong></p>
<ul>
<li>    New NAUTILUS SCripts</li>
<li>    ataraw</li>
<li>    bloom</li>
<li>    fiwalk</li>
<li>    xnview</li>
<li>    NOMODESET in starting menu</li>
<li>    xmount</li>
<li>    sshfs</li>
<li>    Reporting by Caine Interface fixed</li>
<li>    xmount-gui</li>
<li>    nbtempo</li>
<li>    fileinfo</li>
<li>    TSK_Gui</li>
<li>    Raid utils e bridge utils</li>
<li>    SMBFS</li>
<li>    BBT.py</li>
<li>    Widows Side:</li>
<li>    Wintaylor updated &#038; upgraded</li>
</ul>
<p>    <strong>“rbfstab”</strong> is a utility that is activated during boot or when a device is plugged.  It writes read-only entries to /etc/fstab so devices are safely mounted for forensic imaging/examination.  It is self installing with ‘rbfstab -i’ and can be disabled with ‘rbfstab -r’.  It contains many improvements over past rebuildfstab incarnations.  Rebuildfstab is a traditional means for read-only mounting in forensics-orient distributions.</p>
<p>    <strong>“mounter”</strong> is a GUI mounting tool that sits in the system tray.  Left clicking the system tray drive icon activates a window where the user can select devices to mount or un-mount.  With rbfstab activated, all devices, except those with volume label “RBFSTAB”, are mounted read-only.  Mounting of block devices in Nautilus (file browser) is not possible for a normal user with rbfstab activated making mounter a consistent interface for users.</p>
<p>You can download CAINE 2.5/Supernova here:</p>
<p><a href="http://www.caine-live.net/Downloads/caine2.5.iso">caine2.5.iso</a></p>
<p>Or read more <a href="http://www.caine-live.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3188+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;t=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Fcaine-computer-aided-investigative-environment-digital-forensics-livecd%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>NfSpy &#8211; ID-spoofing NFS Client &#8211; Falsify NFS Credentials</title>
		<link>http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/</link>
		<comments>http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 07:44:41 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[hack nfs]]></category>
		<category><![CDATA[hacking nfs]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[linux hacking tool]]></category>
		<category><![CDATA[linux-security]]></category>
		<category><![CDATA[mount nfs]]></category>
		<category><![CDATA[nfs]]></category>
		<category><![CDATA[nfs hacking]]></category>
		<category><![CDATA[nfs hacking tool]]></category>
		<category><![CDATA[nfs mount]]></category>
		<category><![CDATA[nfs security]]></category>
		<category><![CDATA[nfspy]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3154</guid>
		<description><![CDATA[NfSpy is a FUSE filesystem written in Python that automatically changes UID and GID to give you full access to any file on an NFS share. Use it to mount an NFS export and act as the owner of every file and directory. Vulnerability Exploited NFS before version 4 is reliant upon host trust relationships [...]]]></description>
			<content:encoded><![CDATA[<p>NfSpy is a FUSE filesystem written in Python that automatically changes UID and GID to give you full access to any file on an NFS share. Use it to mount an NFS export and act as the owner of every file and directory.</p>
<p><strong>Vulnerability Exploited</strong></p>
<p>NFS before version 4 is reliant upon host trust relationships for authentication. The NFS server trusts any client machines to authenticate users and assign the same user IDs (UIDS) that the shared filesystem uses. This works in NIS, NIS+, and LDAP domains, for instance, but only if you know the client machine is not compromised, or faking its identity. This is because the only authentication in the NFS protocol is the passing of the UID and GID (group ID). There are a few things that can be done to enhance the security of NFS, but many of them are incomplete solutions, and even with them implemented, it could still be possible to circumvent the security measures.</p>
<p><strong>Features</strong></p>
<ul>
<li>Use filehandles from packet captures instead of asking mountd.</li>
<li>Hide from sysadmins by immediately &#8220;unmounting&#8221; while retaining access</li>
<li>Specify port/protocol for NFS or Mountd if you don&#8217;t have access to the portmapper </li>
</ul>
<p>You can download NfSpy here:</p>
<p><a href="https://github.com/bonsaiviking/NfSpy/zipball/master">NfSpy.zip</a></p>
<p>Or read more <a href="https://github.com/bonsaiviking/NfSpy">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3154+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;t=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/&amp;title=NfSpy+%E2%80%93+ID-spoofing+NFS+Client+%E2%80%93+Falsify+NFS+Credentials" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fnfspy-id-spoofing-nfs-client-falsify-nfs-credentials%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/nfspy-id-spoofing-nfs-client-falsify-nfs-credentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BackTrack 5 Released &#8211; The Most Advanced Linux Security Distribution &amp; LiveCD</title>
		<link>http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/</link>
		<comments>http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/#comments</comments>
		<pubDate>Wed, 18 May 2011 09:12:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[backtrack 5]]></category>
		<category><![CDATA[backtrack 64-bit]]></category>
		<category><![CDATA[backtrack destiny]]></category>
		<category><![CDATA[backtrack forensics mode]]></category>
		<category><![CDATA[backtrack livecd]]></category>
		<category><![CDATA[destiny]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[linux security livecd]]></category>
		<category><![CDATA[linux-livecd]]></category>
		<category><![CDATA[penetration testing livecd]]></category>
		<category><![CDATA[security-livecd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3112</guid>
		<description><![CDATA[We have of course been following BackTrack since the very early days, way back in 2006 when it was just known as BackTrack – A merger between WHAX and Auditor. They&#8217;ve come a long way and BackTrack is now a very polished and well rounded security distro, most of the others have dropped off the [...]]]></description>
			<content:encoded><![CDATA[<p>We have of course been following BackTrack since the very early days, way back in 2006 when it was just known as <a href="http://www.darknet.org.uk/2006/02/backtrack-a-merger-between-whax-and-auditor/">BackTrack – A merger between WHAX and Auditor</a>. They&#8217;ve come a long way and BackTrack is now a very polished and well rounded security distro, <a href="http://www.darknet.org.uk/2006/03/10-best-security-live-cd-distros-pen-test-forensics-recovery/">most of the others</a> have dropped off the map leaving BackTrack as the giant in the security LiveCD space.</p>
<p>The last major release was <a href="http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/">BackTrack Final 4 Released – Linux Security Distribution &#8211; back in January 2010</a>.</p>
<p>The BackTrack Dev team has worked furiously in the past months on BackTrack 5, code name “revolution” &#8211; they released it on May 10th. This new revision has been built from scratch, and boasts several major improvements over all our previous releases. It&#8217;s based on Ubuntu Lucid LTS &#8211; Kernel 2.6.38, patched with all relevant wireless injection patches. Fully open source and GPL compliant.</p>
<p align="center"><iframe src="http://player.vimeo.com/video/23347352?title=0&amp;byline=0&amp;portrait=0&amp;color=ff9933" width="550" height="310" frameborder="0"></iframe>
<p><a href="http://vimeo.com/23347352">BackTrack 5  &#8211; Penetration Testing Distribution</a> from <a href="http://vimeo.com/offsec">Offensive Security</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
</p>
<p>The interesting part for me is that the new .ISO downloads offer multiple versions, including a choice between GNOME and KDE desktops and the images include ARM, 32-Bit and 64-Bit versions.</p>
<p><strong>New in Version 5</strong></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Based on Ubuntu 10.04 LTS;</li>
<li>Linux kernel 2.6.38 (with wireless injection patches);</li>
<li>KDE 4.6;</li>
<li>GNOME 2.6;</li>
<li>32-bit and 64-bit support;</li>
<li><a href="http://www.darknet.org.uk/tag/metasploit/">Metasploit</a> 3.7.0;</li>
<li><a href="http://www.darknet.org.uk/category/forensics/">Forensics</a> mode (a forensically sound instance);</li>
<li>Stealth mode (without generating network traffic);</li>
<li>Initial ARM image of BackTrack (for Android-powered devices);</li>
<li>All support for Backtrack 4 will end on May 10th, 2011 and BackTrack 4 will not be available for download from our official mirrors from that date onwards.</li>
</ul>
<p>As for the ARM image, they have had some joy getting BackTrack running on a Motorola Xoom tablet &#8211; check it out <a href="http://www.offensive-security.com/backtrack/backtrack-5-on-a-motorola-xoom/">here</a>.</p>
<p>You can download BackTrack version 5 here:</p>
<p><a href="http://www.backtrack-linux.org/downloads/">http://www.backtrack-linux.org/downloads/</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=BackTrack+5+Released+%E2%80%93+The+Most+Advanced+Linux+Security+Distribution+%26+LiveCD+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3112+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/&amp;t=BackTrack+5+Released+%E2%80%93+The+Most+Advanced+Linux+Security+Distribution+%26+LiveCD" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/&amp;title=BackTrack+5+Released+%E2%80%93+The+Most+Advanced+Linux+Security+Distribution+%26+LiveCD" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/&amp;title=BackTrack+5+Released+%E2%80%93+The+Most+Advanced+Linux+Security+Distribution+%26+LiveCD" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/&amp;title=BackTrack+5+Released+%E2%80%93+The+Most+Advanced+Linux+Security+Distribution+%26+LiveCD" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/&amp;title=BackTrack+5+Released+%E2%80%93+The+Most+Advanced+Linux+Security+Distribution+%26+LiveCD" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F05%2Fbacktrack-5-released-the-most-advanced-linux-security-distribution-livecd%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/05/backtrack-5-released-the-most-advanced-linux-security-distribution-livecd/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Google Removes &#8216;DroidDream&#8217; Malware From Android Devices</title>
		<link>http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/</link>
		<comments>http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/#comments</comments>
		<pubDate>Mon, 07 Mar 2011 15:06:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[android malware]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[dreamdroid]]></category>
		<category><![CDATA[dreamdroid malware]]></category>
		<category><![CDATA[droiddream]]></category>
		<category><![CDATA[droiddream malware]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google android]]></category>
		<category><![CDATA[google android security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3060</guid>
		<description><![CDATA[Android must be getting popular! It&#8217;s always a test of a new platform or OS, when does it start getting serious malware targeting it? It seems like the time for Android is now, the news lately has been buzzing about the DroidDream malware that has been flooding the Android Market. Google pulled a number of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/android/">Android</a> must be getting popular! It&#8217;s always a test of a new platform or OS, when does it start getting serious malware targeting it?</p>
<p>It seems like the time for Android is now, the news lately has been buzzing about the DroidDream malware that has been flooding the Android Market. <a href="http://www.darknet.org.uk/tag/google/">Google</a> pulled a number of malicious apps (rumoured to be more than 50) on March the 1st but kept hush &#8211; they later blogged about it on March 5th outlining some details about the malware and the vulnerability involved.</p>
<p><a href="http://googlemobile.blogspot.com/2011/03/update-on-android-market-security.html">An Update on Android Market Security</a></p>
<blockquote><p>Google has acknowledged that it removed &#8220;a number&#8221; of malicious malware applications from the Android Market on March 1, and it has now reached out over the airwaves to remove the apps from end users devices as well.</p>
<p>Last week, reports indicated that more than 50 Android apps had been loaded with info-pilfering software known as DroidDream. Google immediately responded by pulling the apps from the Market, but the company remained silent on the matter until tossing up a blog post on Saturday evening.</p>
<p>According to Google, the malware exploited known vulnerabilities that had been patched in Android versions 2.2.2 and higher. Google &#8220;believes&#8221; the attacker or attackers was only able to gather device-specific information, including unique used to identify mobile devices and the version of Android running on the device. But the company added that attackers could have accessed other data.</p>
<p>In addition to removing the apps from the Android Market, Google suspended the accounts of the developers involved and contacted law enforcement about the attack, and as it did on one previous occasion, the company used the &#8220;kill switch&#8221; that lets it remotely remove mobile apps that have already been installed by end users.</p></blockquote>
<p>So Google does have a kill switch for software already installed on end user devices, some may complain &#8211; but honestly it&#8217;s only responsible to have such a thing (<a href="http://www.darknet.org.uk/category/apple-hacking/">Apple</a> has one for iOS of course).</p>
<p>And it&#8217;s all well and good saying it only effects phones with <a href="http://www.darknet.org.uk/tag/android/">Android</a> versions lower than 2.2.2&#8230;but sadly that is still the majority of phones. Only the phones directly pushed out by Google get the most recent version of Android, all the other (HTC, Samsung, Motorola etc.) models out there still have older (vulnerable) versions.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Google maintains a persistent connection to Android phones that let the company not only remotely remove applications from devices but remotely install them as well. The remote install tool is used when Android owners purchase apps via the new web incarnation of the Android Market. The Android Market Web Store lets you browse and purchase applications via a browser, as opposed to Android client loaded on handsets.</p>
<p>Apple maintains its own &#8220;kill switch&#8221; for the iPhone. In 2008, an iPhone hacker told the world that Apple had added an app kill switch to the iPhone, and Steve Jobs later confirmed its existence. &#8220;Hopefully, we never have to pull that lever,&#8221; Jobs said, &#8220;but we would be irresponsible not to have a lever like that to pull.&#8221;</p>
<p>On Saturday, Google also said that it is pushing a security update to all Android devices affected by the malware in question. If your device was affected, the company said, you will receive an email from android-market-support@google.com, and you&#8217;ll get a notification on your phone that a package called “Android Market Security Tool March 2011” has been installed. You may also receive a notification that the offending apps have been removed.</p>
<p>The company is taking additional measures to stop such attacks in the future, but it did not provide specifics. &#8220;We are adding a number of measures to help prevent additional malicious applications using similar exploits from being distributed through Android Market and are working with our partners to provide the fix for the underlying security issues,&#8221; the blog post read.</p></blockquote>
<p>Google will also be pushing out a security update to all Andoird hansets that were affected, if you&#8217;re an Android user you&#8217;ll see package called &#8220;Android Market Security Tool March 2011&#8243; installed which combats the malware. </p>
<p>Apparently it was quite easy to foil the <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/">malware</a> if you were handy on the command line, all you needed to do was a create a file at /system/bin/profile/ using the terminal and the touch command then chmod 644 and you&#8217;re done.</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/03/07/google_remotely_kills_android_malware_apps/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Google+Removes+%E2%80%98DroidDream%E2%80%99+Malware+From+Android+Devices+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3060+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/&amp;t=Google+Removes+%E2%80%98DroidDream%E2%80%99+Malware+From+Android+Devices" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/&amp;title=Google+Removes+%E2%80%98DroidDream%E2%80%99+Malware+From+Android+Devices" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/&amp;title=Google+Removes+%E2%80%98DroidDream%E2%80%99+Malware+From+Android+Devices" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/&amp;title=Google+Removes+%E2%80%98DroidDream%E2%80%99+Malware+From+Android+Devices" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/&amp;title=Google+Removes+%E2%80%98DroidDream%E2%80%99+Malware+From+Android+Devices" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fgoogle-removes-droiddream-malware-from-android-devices%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/google-removes-droiddream-malware-from-android-devices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Java Based Cross Platform Malware Trojan (Mac/Linux/Windows)</title>
		<link>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/</link>
		<comments>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/#comments</comments>
		<pubDate>Thu, 20 Jan 2011 07:45:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[cross platform malware]]></category>
		<category><![CDATA[cross platform trojan]]></category>
		<category><![CDATA[cross platform virus]]></category>
		<category><![CDATA[java based malware]]></category>
		<category><![CDATA[java based trojan]]></category>
		<category><![CDATA[jnanabot]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[linux malware]]></category>
		<category><![CDATA[linux trojan]]></category>
		<category><![CDATA[mac malware]]></category>
		<category><![CDATA[mac trojan]]></category>
		<category><![CDATA[mac-virus]]></category>
		<category><![CDATA[macbook-pro]]></category>
		<category><![CDATA[osx trojan]]></category>
		<category><![CDATA[osx.koobface]]></category>
		<category><![CDATA[trojan.jnanabot]]></category>
		<category><![CDATA[windows-virus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3031</guid>
		<description><![CDATA[It&#8217;s pretty rare to read about malware on the Linux or Mac OSX platforms and even more rare to read about cross-platform malware which targets both AND Windows by using Java. A neat piece of coding indeed, it targets vulnerabilities in all 3 operating systems &#8211; the sad thing? The malware itself is vulnerable to [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s pretty rare to read about malware on the <a href="http://www.darknet.org.uk/category/linux-hacking/">Linux</a> or <a href="http://www.darknet.org.uk/category/apple-hacking/">Mac OSX</a> platforms and even more rare to read about cross-platform malware which targets both AND Windows by using Java.</p>
<p>A neat piece of coding indeed, it targets vulnerabilities in all 3 operating systems &#8211; the sad thing? The malware itself is vulnerable to a basic <a href="http://www.darknet.org.uk/tag/directory-traversal/">directory traversal</a> exploit, which means rival gangs can actually commandeer the infected targets.</p>
<p>They went to lengths to keep it secure and unseen (encrypted communications etc) &#8211; but didn&#8217;t program the malware itself securely&#8230;</p>
<blockquote><p>From the department of cosmic justice comes this gem, spotted by researchers from Symantec: a trojan that targets Windows, Mac, and Linux computers contains gaping security vulnerabilities that allow rival criminal gangs to commandeer the infected machines.</p>
<p>Known as Trojan.Jnanabot, or alternately as OSX/Koobface.A or trojan.osx.boonana.a, the bot made waves in October when researchers discovered its Java-based makeup allowed it to attack Mac and Linux machines, not just Windows PCs as is the case with most malware. Once installed, the trojan components are stored in an invisible folder and use strong encryption to keep communications private.</p>
<p>The bot can force its host to take instructions through internet relay chat, perform DDoS attacks, and post fraudulent messages to the victim&#8217;s Facebook account, among other things.</p>
<p>Now, Symantec researchers have uncovered weaknesses in the bot&#8217;s peer-to-peer functionality that allow rival criminals to remotely steal or plant files on the victim&#8217;s hard drive. That means the unknown gang that took the trouble to spread the infection in the first place risks having their botnet stolen from under their noses.</p>
<p>“Even though it&#8217;s encrypted and even though it was written in Java to make it cross-platform, it was still vulnerable to basically a directory transversal exploit,” Dean Turner, director of Symantec&#8217;s Global Intelligence Network, told The Reg. “From a technical perspective, it goes to show that even if you have all those things where you&#8217;re building in a secure platform, if you&#8217;re not building application security into your malware, other bad guys will probably take advantage of it.”</p></blockquote>
<p>It&#8217;s somewhat of an odd decision though, in terms of numbers obviously Windows machines far outnumber Linux and OSX desktop installations. On the web-server front perhaps Linux is a valuable target &#8211; but on consumer desktops? Is it really worth the effort for malware creators to make cross-platform trojans? Personally I don&#8217;t think it is, maybe it was just an experiment.</p>
<p>The number of Apple machines is certainly growing, the next big market we are going to see is tablets and smartphones I believe. I&#8217;d be on the lookout for more <a href="http://www.darknet.org.uk/tag/ios/">iOS</a> and <a href="http://www.darknet.org.uk/tag/android/">Android</a> worms/trojans in coming months.</p>
<p>A self-replicating stealthy Android trojan with a previously unpatched zero-day remote root exploit could be devastating.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Jnanabot&#8217;s P2P feature is designed to make botnets harder to take down by providing multiple channels of communication. After sending an infected machine a single GET request, a website can discover all the information needed to upload any file to any location on the host&#8217;s file system. Attackers can then install a simple backdoor on a user&#8217;s machine by, for instance, writing a malicious program to a computer&#8217;s startup directory.</p>
<p>Attackers can use the same vulnerability to steal files on infected machines.</p>
<p>Turner said the number of Jnanabot infections so far is “measured in the thousands,” rather than the hundreds of thousands for some of the better-known trojans. Still, infection statistics gathered by Symantec in December are surprising. They show that about 16 per cent of infections hit Macs. They didn&#8217;t show any infections on Linux machines. Turner said that Jnanabot attacks on the open source platform weren&#8217;t able to survive a reboot.</p>
<p>The bot was discovered spreading over Facebook posts that planted the following message on infected users&#8217; Facebook pages: “As you are on my friends list I thought I would let you know I have decided to end my life.” An included link leads recipients to a cross-platform JAR, or Java Archive file that can run on Windows, Mac, or Linux. Once the recipient is infected, his Facebook page carries the same dire warning.</p></blockquote>
<p>It seems like the trojan theoretically can attack Linux, but so far hasn&#8217;t been seen in the wild and it can&#8217;t survive a reboot. Not that it really matters as from my experience most Linux users never reboot anyway except for kernel upgrades (which isn&#8217;t that often).</p>
<p>Perhaps it just doesn&#8217;t work that well on Linux, or Linux users don&#8217;t believe in installing JVM &#8211; it doesn&#8217;t usually come standard with OS installs as it&#8217;s considered non-free software.</p>
<p>The chosen vector for replication seems to be <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> and a rather dramatic faux-suicide note &#8211; which sadly I think will be very effective.</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/01/19/mac_linux_bot_vulnerabilities/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3031+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;t=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/&amp;title=Java+Based+Cross+Platform+Malware+Trojan+%28Mac%2FLinux%2FWindows%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F01%2Fjava-based-cross-platform-malware-trojan-maclinuxwindows%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/01/java-based-cross-platform-malware-trojan-maclinuxwindows/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Katana v2 (y0jimb0) &#8211; Portable Multi-Boot Security Suite</title>
		<link>http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/</link>
		<comments>http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 09:53:20 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[caine]]></category>
		<category><![CDATA[forensics livecd]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[multi-boot livecd]]></category>
		<category><![CDATA[Ophcrack]]></category>
		<category><![CDATA[puppy linux]]></category>
		<category><![CDATA[security-livecd]]></category>
		<category><![CDATA[trinity-rescue-kit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2994</guid>
		<description><![CDATA[Katana is a portable multi-boot security suite which brings together many of today&#8217;s best security distributions and portable applications to run off a single Flash Drive. It includes distributions which focus on Pen-Testing, Auditing, Forensics, System Recovery, Network Analysis, and Malware Removal. Katana also comes with over 100 portable Windows applications; such as Wireshark, Metasploit, [...]]]></description>
			<content:encoded><![CDATA[<p>Katana is a portable multi-boot security suite which brings together many of today&#8217;s best security distributions and portable applications to run off a single Flash Drive. It includes distributions which focus on Pen-Testing, Auditing, Forensics, System Recovery, Network Analysis, and Malware Removal. Katana also comes with over 100 portable Windows applications; such as Wireshark, Metasploit, NMAP, Cain &#038; Able, and many more. </p>
<p><strong>New in V2</strong></p>
<p>This version has a bunch of new stuff all around. One major addition to the project is Forge. This tool facilitates a simple point-and-click installation for adding even more distributions to Katana Bootable. This new version also adds the Computer Aided Investigative Environment (CAINE) for a live forensics environment and Kon-Boot for bypassing password. Much effort was placed on the installation of additional applications to the Katana Tool Kit. These new applications include Metasploit, NMAP, Cain &#038; Able, John the Ripper, Cygwin, and more. </p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p><strong>Bootable</strong></p>
<ul>
<li><a href="http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/">BackTrack</a></li>
<li>the Ultimate Boot CD</li>
<li>CAINE</li>
<li>Ultimate Boot CD for Windows</li>
<li><a href="http://www.darknet.org.uk/2006/03/ophcrack-22-password-cracker-released/">Ophcrack Live</a></li>
<li>Puppy Linux</li>
<li><a href="http://www.darknet.org.uk/2007/06/trinity-rescue-kit-free-recovery-and-repair-for-windows/">Trinity Rescue Kit</a></li>
<li>Clonezilla</li>
<li>Darik&#8217;s Boot and Nuke (DBAN)</li>
<li><a href="http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/">Kon-Boot</a></li>
</ul>
<p>A full list of the tools available is <a href="http://www.hackfromacave.com/portableapps.html">here</a>.</p>
<p>You can download Katana v2 here:</p>
<p>Torrent &#8211; <a href="http://www.hackfromacave.com/torrents/katana-v2.0.torrent">katana-v2.0.torrent</a><br />
Direct &#8211; <a href="http://sourceforge.net/projects/katana-usb/files/v2.0/katana-v2.0.rar/download">katana-v2.0.rar</a></p>
<p>Or read more <a href="http://www.hackfromacave.com/katana.html">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Katana+v2+%28y0jimb0%29+%E2%80%93+Portable+Multi-Boot+Security+Suite+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2994+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/&amp;t=Katana+v2+%28y0jimb0%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/&amp;title=Katana+v2+%28y0jimb0%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/&amp;title=Katana+v2+%28y0jimb0%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/&amp;title=Katana+v2+%28y0jimb0%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/&amp;title=Katana+v2+%28y0jimb0%29+%E2%80%93+Portable+Multi-Boot+Security+Suite" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F11%2Fkatana-v2-y0jimb0-portable-multi-boot-security-suite%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/11/katana-v2-y0jimb0-portable-multi-boot-security-suite/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Weaknet Linux &#8211; Penetration Testing &amp; Forensic Analysis Linux Distribution</title>
		<link>http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/</link>
		<comments>http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:32:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[forensics-tools]]></category>
		<category><![CDATA[hacking-live-cd]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[linux forensics distro]]></category>
		<category><![CDATA[linux forensics livecd]]></category>
		<category><![CDATA[pen testing tools]]></category>
		<category><![CDATA[penetration testing linux distro]]></category>
		<category><![CDATA[penetration testing livecd]]></category>
		<category><![CDATA[security-distro]]></category>
		<category><![CDATA[security-livecd]]></category>
		<category><![CDATA[weakerthan]]></category>
		<category><![CDATA[weaknet]]></category>
		<category><![CDATA[weaknet linux]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2791</guid>
		<description><![CDATA[WeakNet Linux is designed primarily for penetration testing, forensic analysis and other security tasks. WeakNet Linux IV was built from Ubuntu 9.10 which is a Debian based distro. All references to Ubuntu have been removed as the author completely re-compiled the kernel, removed all Ubuntu specific software which would cause the ISO to bloat, and [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>WeakNet Linux is designed primarily for penetration testing, forensic analysis and other security tasks. WeakNet Linux IV was built from Ubuntu 9.10 which is a Debian based distro. All references to Ubuntu have been removed as the author completely re-compiled the kernel, removed all Ubuntu specific software which would cause the ISO to bloat, and used a non-Ubuntu-traditional Window Manager, with no DM. To start X11 (Fluxbox) simply type “startx” at the command line as root.</p>
<p>The tools selected are those that the developer feels are used most often in pen-tests. A sample of those included are:</p>
<ul>
<li>BRuWRT-FORSSE v2.0</li>
<li>
Easy-SSHd</li>
<li>Web-Hacking-Portal v2.0</li>
<li>Perlwd</li>
<li>
Netgh0st v3.0</li>
<li>YouTube-Thief!</li>
<li>Netgh0st v2.2</li>
<li>DomainScan</li>
<li>ADtrace</li>
<li>
Admin-Tool</li>
<li>Tartarus v0.1</li>
</ul>
<p>A full list of applications is here:</p>
<p><a href="http://weaknetlabs.com/main/?page_id=276">WeakNet Linux Applications List</a></p>
<p>You can also get the guide here:</p>
<p><a href="http://weaknetlabs.com/multimedia/papers/WNLA_SAg.pdf">Official WeakNet Linux WEAKERTHAN System Administration Guide</a> [PDF]</p>
<p><strong>Hardware Requirements</strong></p>
<p>This distro boots to a command line by default, so they are quite minimal. For Fluxbox, the recommended specs are:</p>
<ul>
<li>256 MiB of system memory (RAM)</li>
<li>2 GB of disk space</li>
<li>Graphics card and monitor capable of 800×600 resolution</li>
</ul>
<p>You can download Weaknet Linux here:</p>
<p><a href="http://weaknetlabs.com/linux/releases/WEAKERTHAN4.1k.ISO">WEAKERTHAN4.1k.ISO</a></p>
<p></p>
<p>Or read more <a href="http://weaknetlabs.com/main/?page_id=18">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Weaknet+Linux+%E2%80%93+Penetration+Testing+%26+Forensic+Analysis+Linux+Distribution+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2791+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/&amp;t=Weaknet+Linux+%E2%80%93+Penetration+Testing+%26+Forensic+Analysis+Linux+Distribution" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/&amp;title=Weaknet+Linux+%E2%80%93+Penetration+Testing+%26+Forensic+Analysis+Linux+Distribution" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/&amp;title=Weaknet+Linux+%E2%80%93+Penetration+Testing+%26+Forensic+Analysis+Linux+Distribution" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/&amp;title=Weaknet+Linux+%E2%80%93+Penetration+Testing+%26+Forensic+Analysis+Linux+Distribution" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/&amp;title=Weaknet+Linux+%E2%80%93+Penetration+Testing+%26+Forensic+Analysis+Linux+Distribution" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F08%2Fweaknet-linux-penetration-testing-forensic-analysis-linux-distribution%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/08/weaknet-linux-penetration-testing-forensic-analysis-linux-distribution/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Metasploit Framework 3.4.1 Released &#8211; 16 New Exploits, 22 Modules &amp; 11 Meterpreter Scripts</title>
		<link>http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/</link>
		<comments>http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 09:03:37 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[automated-hacking]]></category>
		<category><![CDATA[automatic hacking]]></category>
		<category><![CDATA[download metasploit]]></category>
		<category><![CDATA[exploit payload]]></category>
		<category><![CDATA[exploit techniques]]></category>
		<category><![CDATA[exploit-framework]]></category>
		<category><![CDATA[exploitation-framework]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[metasploit 3.4]]></category>
		<category><![CDATA[metasploit 3.4.1]]></category>
		<category><![CDATA[metasploit express]]></category>
		<category><![CDATA[metasploit-exploit-framework]]></category>
		<category><![CDATA[metasploit-framework]]></category>
		<category><![CDATA[meterpreter]]></category>
		<category><![CDATA[security-tools]]></category>
		<category><![CDATA[shellcode]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2801</guid>
		<description><![CDATA[The Metasploit Project is proud to announce the release of the Metasploit Framework version 3.4.1. This release sees the first official non-Windows Meterpreter payload, in PHP as discussed last month here. Rest assured that more is in store for Meterpreter on other platforms. A new extension called Railgun is now integrated into Meterpreter courtesy of [...]]]></description>
			<content:encoded><![CDATA[<p>The Metasploit Project is proud to announce the release of the Metasploit Framework version 3.4.1. This release sees the first official non-Windows Meterpreter payload, in PHP as discussed last month <a href="http://blog.metasploit.com/2010/06/meterpreter-for-pwned-home-pages.html">here</a>. </p>
<p>Rest assured that more is in store for Meterpreter on other platforms.  A new extension called Railgun is now integrated into Meterpreter courtesy of Patrick HVE, giving you scriptable access to Windows  APIs and an unprecedented amount of control over post-exploitation.</p>
<p>For those of you wishing to contribute to the framework, a new file called HACKING has been introduced that lays out a few guidelines to make it easier.</p>
<p>This release contains 16 new exploits, 22 new auxiliary modules and 11 new Meterpreter scripts for your pwning enjoyment.  The major changes in terms of numbers were:</p>
<ul>
<li>567 exploits and 283 auxiliary modules (up from 551 and 261 in v3.4)</li>
<li>Over 40 community reported bugs were fixed and numerous interfaces were improved</li>
</ul>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<p>For more in-depth information about this release, see the 3.4.1 release notes here:</p>
<p><a href="https://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_341">Metasploit 3.4.1 Release Notes</a></p>
<p>You can download Metasploit 3.4.1 <a href="http://www.metasploit.com/framework/download/">here</a>:</p>
<p>Windows &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.1.exe">framework-3.4.1.exe</a><br />
Linux (32-Bit) &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.1-linux-i686.run">framework-3.4.1-linux-i686.run</a></p>
<p>Or read more <a href="http://www.metasploit.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2801+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;t=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/&amp;title=Metasploit+Framework+3.4.1+Released+%E2%80%93+16+New+Exploits%2C+22+Modules+%26+11+Meterpreter+Scripts" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Fmetasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/metasploit-framework-3-4-1-released-16-new-exploits-22-modules-11-meterpreter-scripts/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Metasploit 3.4.0 Hacking Framework Released &#8211; Over 100 New Exploits Added</title>
		<link>http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/</link>
		<comments>http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/#comments</comments>
		<pubDate>Thu, 20 May 2010 10:00:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[automated-hacking]]></category>
		<category><![CDATA[automatic hacking]]></category>
		<category><![CDATA[exploit payload]]></category>
		<category><![CDATA[exploit techniques]]></category>
		<category><![CDATA[exploit-framework]]></category>
		<category><![CDATA[exploitation-framework]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[metasploit 3.4]]></category>
		<category><![CDATA[metasploit express]]></category>
		<category><![CDATA[metasploit-exploit-framework]]></category>
		<category><![CDATA[metasploit-framework]]></category>
		<category><![CDATA[rapid7]]></category>
		<category><![CDATA[rapid7 metasploit]]></category>
		<category><![CDATA[security-tools]]></category>
		<category><![CDATA[shellcode]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2695</guid>
		<description><![CDATA[Metasploit provides useful information and tools for penetration testers, security researchers, and IDS signature developers. This project was created to provide information on exploit techniques and to create a functional knowledgebase for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only. Update [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Metasploit provides useful information and tools for penetration testers, security researchers, and IDS signature developers. This project was created to provide information on exploit techniques and to create a functional knowledgebase for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only.</p>
<p><strong>Update Summary</strong></p>
<ul>
<li>Metasploit now has 551 exploit modules and 261 auxiliary modules (from 445 and 216 respectively in v3.3)</li>
<li>Metasploit is still about twice the size of the nearest Ruby application according to Ohloh.net (400K lines of Ruby)</li>
<li>Over 100 tickets were closed since the last point release and over 200 since v3.3</li>
</ul>
<p>After five months of development, version 3.4.0 of the Metasploit Framework has been released. Since the last major release (<a href="http://www.darknet.org.uk/2009/11/metasploit-3-3-released-exploitation-framework/">Metasploit 3.3</a>) over 100 new exploits have been added and over 200 bugs have been fixed.</p>
<p>This release includes massive improvements to the Meterpreter payload; both in terms of stability and features, thanks in large part to Stephen Fewer of Harmony Security. The Meterpreter payload can now capture screenshots without migrating, including the ability to bypass Session 0 Isolation on newer Windows operating systems. This release now supports the ability to migrate back and forth between 32-bit and 64-bit processes on a compromised Windows 64-bit operating system. The Meterpreter protocol now supports inline compression using zlib, resulting in faster transfers of large data blocks. A new command, &#8220;getsystem&#8221;, uses several techniques to gain system access from a low-privileged or administrator-level session, including the exploitation of Tavis Ormandy&#8217;s KiTrap0D vulnerability. Brett Blackham contributed a patch to compress screenshots on the server side in JPG format, reducing the overhead of the screen capture command. The pivoting backend of Meterpreter now supports bi-directional UDP and TCP relays, a big upgrade from the outgoing-only TCP pivoting capabilities of version 3.3.3.</p>
<p>This is the first version of Metasploit to have strong support for bruteforcing network protocols and gaining access with cracked credentials. A new mixin has been created that standardizes the options available to each of the brute force modules. This release includes support for brute forcing accounts over SSH, Telnet, MySQL, Postgres, SMB, DB2, and more, thanks to Tod Bearsdley and contributions from Thomas Ring.</p>
<p>Metasploit now has support for generating malicious JSP and WAR files along with exploits for Tomcat and JBoss that use these to gain remote access to misconfigured installations. A new mixin was creating compiling and signing Java applets on fly, courtesy of Nathan Keltner. Thanks to some excellent work by bannedit and Joshua Drake, command injection of a cmd.exe shell on Windows can be staged into a full Meterpreter shell using the new &#8220;sessions -u&#8221; syntax.</p>
<p><a href="http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_34">Full Metasploit 3.4.0 Release Notes</a></p>
<p>You can download Metasploit 3.4.0 here:</p>
<p>Windows &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.0.exe">framework-3.4.0.exe</a><br />
Linux &#8211; <a href="http://www.metasploit.com/releases/framework-3.4.0-linux-i686.run">framework-3.4.0-linux-i686.run</a></p>
<p></p>
<p>Or read more <a href="http://www.metasploit.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2695+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;t=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/&amp;title=Metasploit+3.4.0+Hacking+Framework+Released+%E2%80%93+Over+100+New+Exploits+Added" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fmetasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/metasploit-3-4-0-hacking-framework-released-over-100-new-exploits-added/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>BackTrack Final 4 Released &#8211; Linux Security Distribution</title>
		<link>http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/</link>
		<comments>http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 05:50:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[backtrack 4]]></category>
		<category><![CDATA[backtrack linux]]></category>
		<category><![CDATA[backtrack livecd]]></category>
		<category><![CDATA[bt]]></category>
		<category><![CDATA[bt4]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[linux security distribution]]></category>
		<category><![CDATA[linux-livecd]]></category>
		<category><![CDATA[linux-security]]></category>
		<category><![CDATA[pen-testing-livecd]]></category>
		<category><![CDATA[penetration testing livecd]]></category>
		<category><![CDATA[security-livecd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2450</guid>
		<description><![CDATA[BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking. Regardless if you’re making BackTrack your primary operating system, booting from a LiveDVD, or using your favorite thumbdrive, BackTrack has been customized down to every package, kernel configuration, script and [...]]]></description>
			<content:encoded><![CDATA[<p>BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking.</p>
<p>Regardless if you’re making BackTrack your primary operating system, booting from a LiveDVD, or using your favorite thumbdrive, BackTrack has been customized down to every package, kernel configuration, script and patch solely for the purpose of the penetration tester.</p>
<p>BackTrack is intended for all audiences from the most savvy security professionals to early newcomers to the information security field. BackTrack promotes a quick and easy way to find and update the largest database of security tool collection to-date.</p>
<p>I&#8217;m sure many of you have been using the <a href="http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/">BackTrack 4 Pre Release</a> which was pushed out in June last year, finally BackTrack Final 4 is available for download!</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<p><strong>New in BackTrack Final 4</strong></p>
<p>This release includes a new kernel, a larger and expanded toolset repository, custom tools that you can only find on BackTrack, and more importantly, fixes to most major bugs that were known of.</p>
<p>You can download BackTrack Final 4 here:</p>
<p><a href="http://www.backtrack-linux.org/downloads/">http://www.backtrack-linux.org/downloads/</a></p>
<p>Due to massive demand and lack of capacity I would suggest download the <a href="http://www.backtrack-linux.org/bt4-final.iso.torrent">Torrent version</a>.</p>
<p></p>
<p>Or read more <a href="http://www.backtrack-linux.org/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=BackTrack+Final+4+Released+%E2%80%93+Linux+Security+Distribution+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2450+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/&amp;t=BackTrack+Final+4+Released+%E2%80%93+Linux+Security+Distribution" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/&amp;title=BackTrack+Final+4+Released+%E2%80%93+Linux+Security+Distribution" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/&amp;title=BackTrack+Final+4+Released+%E2%80%93+Linux+Security+Distribution" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/&amp;title=BackTrack+Final+4+Released+%E2%80%93+Linux+Security+Distribution" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/&amp;title=BackTrack+Final+4+Released+%E2%80%93+Linux+Security+Distribution" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F01%2Fbacktrack-final-4-released-linux-security-distribution%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/01/backtrack-final-4-released-linux-security-distribution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

