<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Linux Hacking</title>
	<atom:link href="http://www.darknet.org.uk/category/linux-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Thu, 19 Nov 2009 10:29:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>FRHACK OS v1 alpha1 &#8211; Pentesting/Security LiveCD</title>
		<link>http://www.darknet.org.uk/2009/09/frhack-os-v1-alpha1-pentestingsecurity-livecd/</link>
		<comments>http://www.darknet.org.uk/2009/09/frhack-os-v1-alpha1-pentestingsecurity-livecd/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 09:41:35 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[fr hack]]></category>
		<category><![CDATA[frhack]]></category>
		<category><![CDATA[frhack os]]></category>
		<category><![CDATA[live-cd]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[pen testing live cd]]></category>
		<category><![CDATA[pen testing os]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[pen-testing-livecd]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[pentesting livecd]]></category>
		<category><![CDATA[security live cd]]></category>
		<category><![CDATA[security os]]></category>
		<category><![CDATA[security-livecd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2084</guid>
		<description><![CDATA[FRHACK OS is an updated/modified version of the latest BackTrack 4 ISO with many updated tools and fixes.
This means it&#8217;s a fully fledged linux pen-testing/security environment.



Some included tools &#038; Updates

gcc-4.2
sun-java6-jre sun-java6-plugin
spoonwep-wpa-rc3.deb
airsnort-0.2.7e.tar.gz
wepbuster-1.0_beta_0.6
jbrofuzz-jar-15
wfuzz-1.4
tor-0.2.1.19
privoxy-3.0.8-stable-src      
ophcrack-3.3.1
vncrack_src-1.21
fuzzgrind_090622




A new version (coming with bug fixes, included rainbow tables, wordlists, extras etc.) will be available for FRHACK 01, [...]]]></description>
			<content:encoded><![CDATA[<p>FRHACK OS is an updated/modified version of the latest <a href="http://www.darknet.org.uk/tag/backtrack/">BackTrack</a> 4 ISO with many updated tools and fixes.</p>
<p>This means it&#8217;s a fully fledged linux pen-testing/security environment.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><strong>Some included tools &#038; Updates</strong></p>
<ul>
<li>gcc-4.2</li>
<li>sun-java6-jre sun-java6-plugin</li>
<li>spoonwep-wpa-rc3.deb</li>
<li>airsnort-0.2.7e.tar.gz</li>
<li>wepbuster-1.0_beta_0.6</li>
<li>jbrofuzz-jar-15</li>
<li>wfuzz-1.4</li>
<li>tor-0.2.1.19</li>
<li>privoxy-3.0.8-stable-src      </li>
<li>ophcrack-3.3.1</li>
<li>vncrack_src-1.21</li>
<li>fuzzgrind_090622</li>
</ul>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>A new version (coming with bug fixes, included rainbow tables, wordlists, extras etc.) will be available for FRHACK 01, so you&#8217;ll be able to use it for the<a href="http://www.frhack.org"> FRHACK Wargame</a>.</p>
<p>You can download FRHACK OS v1 alpha1 (1.4GB) here:</p>
<p><a href="https://www.securinfos.info/frhack/frhack-os.iso">frhack-os.iso</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=FRHACK+OS+v1+alpha1+%E2%80%93+Pentesting%2FSecurity+LiveCD+http://bit.ly/jE43t+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/09/frhack-os-v1-alpha1-pentestingsecurity-livecd/&amp;title=FRHACK+OS+v1+alpha1+%E2%80%93+Pentesting%2FSecurity+LiveCD" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/09/frhack-os-v1-alpha1-pentestingsecurity-livecd/&amp;title=FRHACK+OS+v1+alpha1+%E2%80%93+Pentesting%2FSecurity+LiveCD" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/09/frhack-os-v1-alpha1-pentestingsecurity-livecd/&amp;t=FRHACK+OS+v1+alpha1+%E2%80%93+Pentesting%2FSecurity+LiveCD" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/09/frhack-os-v1-alpha1-pentestingsecurity-livecd/&amp;title=FRHACK+OS+v1+alpha1+%E2%80%93+Pentesting%2FSecurity+LiveCD" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/09/frhack-os-v1-alpha1-pentestingsecurity-livecd/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>FreeBSD Local Root Escalation Vulnerability</title>
		<link>http://www.darknet.org.uk/2009/09/freebsd-local-root-escalation-vulnerability/</link>
		<comments>http://www.darknet.org.uk/2009/09/freebsd-local-root-escalation-vulnerability/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 10:46:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[freebsd kqueue bug]]></category>
		<category><![CDATA[freebsd null pointer]]></category>
		<category><![CDATA[freebsd root exploit]]></category>
		<category><![CDATA[freebsd root vulnerability]]></category>
		<category><![CDATA[freebsd security]]></category>
		<category><![CDATA[local root escalation]]></category>
		<category><![CDATA[null pointer deference]]></category>
		<category><![CDATA[race condition]]></category>
		<category><![CDATA[root escalation]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2124</guid>
		<description><![CDATA[It&#8217;s been a long time since we&#8217;ve heard about a problem with FreeBSD, partially because the mass of people using it isn&#8217;t that large and secondly because BSD tends to be pretty secure as operating systems go.
It&#8217;s a pretty serious flaw this time with root escalation, thankfully it&#8217;s only a local exploit though and not [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a long time since we&#8217;ve heard about a problem with FreeBSD, partially because the mass of people using it isn&#8217;t that large and secondly because BSD tends to be pretty secure as operating systems go.</p>
<p>It&#8217;s a pretty serious flaw this time with root escalation, thankfully it&#8217;s only a local exploit though and not remotely exploitable.</p>
<p>Although a user could get user access on the system through an exploit in a web facing application, and use some kind of PHP/Python web shell to exploit and get root.</p>
<p><!--adsense#New468--></p>
<blockquote><p>A security researcher has uncovered a security bug in the FreeBSD operating system that allows users with limited privileges to take full control of underlying systems.</p>
<p>The bug in FreeBSD&#8217;s kqueue notification interface makes it trivial for those with local access to a vulnerable system to gain full root privileges, Przemyslaw Frasunek, an independent security consultant in Poland, told The Register. It affects versions 6.0 through 6.4 of the operating system, the last two versions of which enjoy wide use and continue to be supported by the FreeBSD Foundation.</p>
<p>Versions 7.1 and and beyond are not vulnerable.</p></blockquote>
<p>With a lot of people still using FreeBSD 6.3 and 6.4, amongst the FreeBSD community I&#8217;d say this could be quite a widespread problem.</p>
<p>A lot of BSD boxes are used for web hosting too, so I&#8217;d imagine a lot have SSH access enabled giving people local access and the capability of executing this exploit.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Those exploiting the bug must first have local access to a vulnerable system, either as a legitimate user or by exploiting some other flaw (say, a vulnerable PHP script) that gives an attacker a toe-hold in to the targeted system. Frasunek said the vulnerability is trivial to exploit, as a video he <a href="http://www.vimeo.com/6554787">posted here suggests</a>.</p>
<p>The bug is the result of a race condition in the FreeBSD kqueue that leads to a NULL pointer dereference in kernel mode. Attackers can cause vulnerable systems to run malware by putting the code in a memory page mapped to address 0&#215;0.</p>
<p>Frasunek said he notified FreeBSD officials on August 29 and has yet to get a response. Robert Watson, a FreeBSD Core Team member, told El Reg that it appeared the email had gotten &#8220;lost in the slew&#8221; and he expected an advisory to be issued soon.</p></blockquote>
<p>If you&#8217;re using the latest production release (at this time 7.2) you aren&#8217;t vulnerable to this problem, I hope to see them backport the patch to the previous versions as they still have a sizable following.</p>
<p>You should see an advisory hitting the mailing lists soon, and I&#8217;d expect it to be fixed pretty quickly too.</p>
<p>Beware if you are using FreeBSD and have users with local access you don&#8217;t trust.</p>
<p>Source: <a href="http://www.theregister.co.uk/2009/09/14/freebsd_security_bug/">The Register</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=FreeBSD+Local+Root+Escalation+Vulnerability+http://bit.ly/6hkPx+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/09/freebsd-local-root-escalation-vulnerability/&amp;title=FreeBSD+Local+Root+Escalation+Vulnerability" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/09/freebsd-local-root-escalation-vulnerability/&amp;title=FreeBSD+Local+Root+Escalation+Vulnerability" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/09/freebsd-local-root-escalation-vulnerability/&amp;t=FreeBSD+Local+Root+Escalation+Vulnerability" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/09/freebsd-local-root-escalation-vulnerability/&amp;title=FreeBSD+Local+Root+Escalation+Vulnerability" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/09/freebsd-local-root-escalation-vulnerability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Apache.org Hacked Using Remote SSH Key</title>
		<link>http://www.darknet.org.uk/2009/09/apache-org-hacked-using-remote-ssh-key/</link>
		<comments>http://www.darknet.org.uk/2009/09/apache-org-hacked-using-remote-ssh-key/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 07:18:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[apache ssh remote key]]></category>
		<category><![CDATA[apache.org]]></category>
		<category><![CDATA[apache.org patched]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking apache.org]]></category>
		<category><![CDATA[hacking-apache]]></category>
		<category><![CDATA[ssh remote key]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2073</guid>
		<description><![CDATA[Apache.org has been hacked quite a number of this times, last week it happened again and the whole infrastructure was down for a few hours while they sorted out what had happened and how to remedy it.
Apparently one the remote SSH keys was compromised allowed attacked to upload code, the scary part is they could [...]]]></description>
			<content:encoded><![CDATA[<p>Apache.org has been hacked quite a number of this times, last week it happened again and the whole infrastructure was down for a few hours while they sorted out what had happened and how to remedy it.</p>
<p>Apparently one the remote SSH keys was compromised allowed attacked to upload code, the scary part is they could upload a trojaned version of Apache, which over a few days could be downloaded by thousands of people.</p>
<p>Very little seems to be known about what damage was done and no-one is claiming responsibility for it.</p>
<p><!--adsense#New468--></p>
<blockquote><p>The website of Apache was taken offline for several hours on Friday after the SSH remote administration key on one of its servers was compromised.</p>
<p>SSH is a widely used technology for remote administration, so in the worst scenario the compromise created a means for hackers to upload Trojanised code onto the download section of Apache&#8217;s website. Around 50 per cent of webservers run Apache, according to the latest stats from Netcraft, so any problem would be extremely widely felt.</p>
<p>It&#8217;s unclear at present whether any code on the Apache website was actually modified. Nor do we know how the attack was carried out or who was behind it.</p></blockquote>
<p>According to the Apache Infrastructure Team, in their own words:</p>
<p>&#8220;To the best of our knowledge at this time, no end users were affected by this incident,  and the attackers were not able to escalate their privileges on any machines.&#8221;</p>
<p>You can read their initial report <a href="https://blogs.apache.org/infra/entry/apache_org_downtime_initial_report">here</a>.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Apache&#8217;s web site was restored after DNS records were changed so that servers based in Europe rather than at the main US site were carrying the load.</p>
<p>Rik Ferguson, a security researcher at Trend Micro, notes that the same type of compromised SSH key problem led to attacks that attempted to install rootkits on Linux based systems in August 2008.</p>
<p>Screenshots of Apache&#8217;s statement on the incident, since removed, have been preserved for posterity in a blog posting by Trend Micro <a href="http://countermeasures.trendmicro.eu/apache-ssh-key-compromised/">here</a> and F-Secure <a href="http://www.f-secure.com/weblog/archives/00001757.html">here</a>. ®</p></blockquote>
<p>They have restored all the servers from back-up images and I hope they&#8217;ve changed all the SSH keys, we can keep an eye on the progress and see if any more details crop up.</p>
<p>It&#8217;d be interesting to know the motives behind the attack, was it political or for money?</p>
<p>Apache currently scores about 47% of all global web-servers, so we better hope there isn&#8217;t a backdoor slipped in.</p>
<p>Source: <a href="http://www.theregister.co.uk/2009/08/28/apache_hack/">The Register</a> (<em>Thanks Droope</em>)</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Apache.org+Hacked+Using+Remote+SSH+Key+http://bit.ly/Qd8qM+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/09/apache-org-hacked-using-remote-ssh-key/&amp;title=Apache.org+Hacked+Using+Remote+SSH+Key" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/09/apache-org-hacked-using-remote-ssh-key/&amp;title=Apache.org+Hacked+Using+Remote+SSH+Key" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/09/apache-org-hacked-using-remote-ssh-key/&amp;t=Apache.org+Hacked+Using+Remote+SSH+Key" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/09/apache-org-hacked-using-remote-ssh-key/&amp;title=Apache.org+Hacked+Using+Remote+SSH+Key" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/09/apache-org-hacked-using-remote-ssh-key/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Serious Linux Kernel Vulnerability For ALL 2.4 &amp; 2.6 Kernels</title>
		<link>http://www.darknet.org.uk/2009/08/serious-linux-kernel-vulnerability-for-all-2-4-2-6-kernels/</link>
		<comments>http://www.darknet.org.uk/2009/08/serious-linux-kernel-vulnerability-for-all-2-4-2-6-kernels/#comments</comments>
		<pubDate>Wed, 19 Aug 2009 02:00:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[kernel bug]]></category>
		<category><![CDATA[linux 2.4 kernel exploit]]></category>
		<category><![CDATA[linux 2.6 kernel exploit]]></category>
		<category><![CDATA[linux kernel bug]]></category>
		<category><![CDATA[linux null pointer]]></category>
		<category><![CDATA[linux vulnerability]]></category>
		<category><![CDATA[linux-exploit]]></category>
		<category><![CDATA[linux-kernel-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2032</guid>
		<description><![CDATA[This is a serious bug, it effects all Kernel versions released since May 2001! That goes all the way back to the early 2.4 versions.
It&#8217;s also exploitable according to the report &#8211; This issue is easily exploitable for local privilege escalation. In order to exploit this, an attacker would create a mapping at address zero [...]]]></description>
			<content:encoded><![CDATA[<p>This is a serious bug, it effects all Kernel versions released since May 2001! That goes all the way back to the early 2.4 versions.</p>
<p>It&#8217;s also exploitable according to the report &#8211; This issue is easily exploitable for local privilege escalation. In order to exploit this, an attacker would create a mapping at address zero containing code to be executed with privileges of the kernel (which I would assume to be root).</p>
<p>At least it only allows local priveledge escalation, if was a remote root exploit in the kernel..it would be a disaster.</p>
<p>Imagine all the Linux boxes out there connected to the net where the admin doesn&#8217;t update or read security resources.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Linux developers have issued a critical update for the open-source OS after researchers uncovered a vulnerability in its kernel that puts most versions built in the past eight years at risk of complete takeover.</p>
<p>The bug involves the way kernel-level routines such as sock_sendpage react when they are left unimplemented. Instead of linking to a corresponding placeholder, (for example, sock_no_accept), the function pointer is left uninitialized. Sock_sendpage doesn&#8217;t always validate the pointer before dereferencing it, leaving the OS open to local privilege escalation that can completely compromise the underlying machine.</p>
<p>&#8220;Since it leads to the kernel executing code at NULL, the vulnerability is as trivial as it can get to exploit,&#8221; security researcher Julien Tinnes writes here. &#8220;An attacker can just put code in the first page that will get executed with kernel privileges.&#8221;</p></blockquote>
<p>A patch has been released, so if you have untrusted local users on your system UPDATE YOUR KERNEL NOW!</p>
<p>This is the second time this year there has been a serious exploit in the Linux Kernel, which in a way is good because it means people are looking at it critically.</p>
<p>The more bugs that get exposed, the more secure the Kernel and our operating systems become.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Tinnes and fellow researcher Tavis Ormandy released proof-of-concept code that they said took just a few minutes to adapt from a previous exploit they had. They said all 2.4 and 2.6 version since May 2001 are affected.</p>
<p>Security researchers not involved in the discovery were still studying the advisory at time of writing, but at least one of them said it appeared at first blush to warrant an immediate action.</p>
<p>&#8220;This passes my it&#8217;s-not-crying-wolf test so far,&#8221; said Rodney Thayer, CTO of security research firm Secorix. &#8220;If I had some kind of enterprise-class Linux system like a Red Hat Enterprise Linux&#8230;I would really go check and see if this looked like it related, and if my vendor was on top of it and did I need to get a kernel patch.&#8221;</p></blockquote>
<p>I wonder if any more major bugs will be disclosed before the end of the year? The less Kernel updates that need to be carried out the better in my books.</p>
<p>Full technical details of the bug can be found here:</p>
<p><a href="http://archives.neohapsis.com/archives/fulldisclosure/2009-08/0174.html">Linux NULL pointer dereference due to incorrect proto_ops initializations</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2009/08/14/critical_linux_bug/">The Register</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Serious+Linux+Kernel+Vulnerability+For+ALL+2.4+%26+2.6+Kernels+http://bit.ly/MF8Sz+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/08/serious-linux-kernel-vulnerability-for-all-2-4-2-6-kernels/&amp;title=Serious+Linux+Kernel+Vulnerability+For+ALL+2.4+%26+2.6+Kernels" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/08/serious-linux-kernel-vulnerability-for-all-2-4-2-6-kernels/&amp;title=Serious+Linux+Kernel+Vulnerability+For+ALL+2.4+%26+2.6+Kernels" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/08/serious-linux-kernel-vulnerability-for-all-2-4-2-6-kernels/&amp;t=Serious+Linux+Kernel+Vulnerability+For+ALL+2.4+%26+2.6+Kernels" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/08/serious-linux-kernel-vulnerability-for-all-2-4-2-6-kernels/&amp;title=Serious+Linux+Kernel+Vulnerability+For+ALL+2.4+%26+2.6+Kernels" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/08/serious-linux-kernel-vulnerability-for-all-2-4-2-6-kernels/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>MultiISO LiveDVD v1.0 &#8211; BackTrack, Knoppix &amp; Ophcrack</title>
		<link>http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/</link>
		<comments>http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 11:05:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[byzantine os]]></category>
		<category><![CDATA[dsl]]></category>
		<category><![CDATA[dvl]]></category>
		<category><![CDATA[gexbox]]></category>
		<category><![CDATA[knoppix]]></category>
		<category><![CDATA[live dvd]]></category>
		<category><![CDATA[live security dvd]]></category>
		<category><![CDATA[livedvd]]></category>
		<category><![CDATA[mpentoo]]></category>
		<category><![CDATA[multi iso dvd]]></category>
		<category><![CDATA[multiiso]]></category>
		<category><![CDATA[Ophcrack]]></category>
		<category><![CDATA[puppy linux]]></category>
		<category><![CDATA[security live dvd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1917</guid>
		<description><![CDATA[MultiISO LiveDVD is an integrated Live DVD technology which combines some of the very popular Live CD ISOs already available on the internet. It can be used for security reconnaissance, vulnerability identification, penetration testing, system rescue, media center and multimedia, system recovery, etc. It&#8217;s a all-in-one multipurpose LiveDVD put together. There&#8217;s something in it for [...]]]></description>
			<content:encoded><![CDATA[<p>MultiISO LiveDVD is an integrated Live DVD technology which combines some of the very popular Live CD ISOs already available on the internet. It can be used for security reconnaissance, vulnerability identification, penetration testing, system rescue, media center and multimedia, system recovery, etc. It&#8217;s a all-in-one multipurpose LiveDVD put together. There&#8217;s something in it for everyone.</p>
<p><!--adsense#New468--></p>
<p>MultiISO LiveDVD Version 1.0 consists of:</p>
<ul>
<li>Backtrack 3</li>
<li>Damn Small Linux (DSL) 4.2.5</li>
<li>GeeXboX 1.1</li>
<li>Damn Vulnerable Linux (Strychnine) 1.4 edition</li>
<li>Knoppix 5.1.1, MPentoo 2006.1</li>
<li>Ophcrack 1.2.2 (remastered to contain SSTIC04-5k [720MB] table sets)</li>
<li>
Puppy Linux 3.01</li>
<li>Byzantine OS i586-20040404</li>
</ul>
<p><!--adsense#New468--></p>
<p>You can download MultiISO LiveDVD here (to conserve bandwidth only a Torrent link is available, please seed after downloading):</p>
<p>Torrent: <a href="http://badfoo.net/linux/EmErgEs_MultiBOOT_ISO.torrent.torrent">EmErgEs_MultiBOOT_ISO.torrent</a> (4.03GB)</p>
<p>MD5SUM: 1b1f37ed6b6f958cde0529a8a1f06637<br />
SHA1SUM: 593ffbfa3c4b665220dcd63b2e4b77bacde5237d</p>
<p>Or read more <a href="http://badfoo.net/emerge/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=MultiISO+LiveDVD+v1.0+%E2%80%93+BackTrack%2C+Knoppix+%26+Ophcrack+http://bit.ly/qceoW+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/&amp;title=MultiISO+LiveDVD+v1.0+%E2%80%93+BackTrack%2C+Knoppix+%26+Ophcrack" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/&amp;title=MultiISO+LiveDVD+v1.0+%E2%80%93+BackTrack%2C+Knoppix+%26+Ophcrack" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/&amp;t=MultiISO+LiveDVD+v1.0+%E2%80%93+BackTrack%2C+Knoppix+%26+Ophcrack" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/&amp;title=MultiISO+LiveDVD+v1.0+%E2%80%93+BackTrack%2C+Knoppix+%26+Ophcrack" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/07/multiiso-livedvd-v1-0-backtrack-knoppix-ophcrack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Kon-Boot &#8211; Reset Windows &amp; Linux Passwords</title>
		<link>http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/</link>
		<comments>http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 09:06:30 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[forgot linux password]]></category>
		<category><![CDATA[forgot windows password]]></category>
		<category><![CDATA[kon boot]]></category>
		<category><![CDATA[konboot]]></category>
		<category><![CDATA[lost linux password]]></category>
		<category><![CDATA[lost root password]]></category>
		<category><![CDATA[lost windows password]]></category>
		<category><![CDATA[password reset]]></category>
		<category><![CDATA[password reset tool]]></category>
		<category><![CDATA[reset linux password]]></category>
		<category><![CDATA[reset linux root password]]></category>
		<category><![CDATA[reset windows password]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1900</guid>
		<description><![CDATA[Kon-Boot is an prototype piece of software which allows to change contents of a Linux kernel (and now Windows kernel also!!!) on the fly (while booting). 
In the current compilation state it allows to log into a Linux system as ’root’ user without typing the correct password or to elevate privileges from current user to [...]]]></description>
			<content:encoded><![CDATA[<p>Kon-Boot is an prototype piece of software which allows to change contents of a Linux kernel (and now Windows kernel also!!!) on the fly (while booting). </p>
<p>In the current compilation state it allows to log into a Linux system as ’<em>root</em>’ user without typing the correct password or to elevate privileges from current user to root. For Windows systems it allows to enter any password protected profile without any knowledge of the password. </p>
<p><!--adsense#New468--></p>
<p>It was mainly created for Ubuntu, later the author has made a few add-ons to cover some other Linux distributions.</p>
<p>Entire Kon-Boot was written in pure x86 assembly, using old grandpa-geezer TASM 4.0.</p>
<p><strong>Latest Updates – Kon-Boot for Windows</strong></p>
<p>Kon-Boot was moved to Windows platforms. So now it provides support for Microsoft Windows systems and also the Linux systems listed below. Kon-Boot for Windows enables logging in to any password protected machine profile without without any knowledge of the password. This tool changes the contents of Windows kernel while booting, everything is done virtually – without any interferences with physical system changes. So far following systems were tested to work correctly with Kon-Boot:</p>
<ul>
<li>Windows Server 2008 Standard SP2 (v.275)</li>
<li>Windows Vista Business SP0</li>
<li>Windows Vista Ultimate SP1</li>
<li>Windows Vista Ultimate SP0</li>
<li>Windows Server 2003 Enterprise</li>
<li>Windows XP</li>
<li>
Windows XP SP1</li>
<li>Windows XP SP2</li>
<li>Windows XP SP3</li>
<li>Windows 7</li>
</ul>
<p><!--adsense#New468--></p>
<p>No special usage instructions are required for Windows users, just boot from Kon-Boot CD/Floppy, select your profile and put any password you want. You lost your password? Now it doesnt matter at all.</p>
<p>It has been tested with the following Linux distributions:</p>
<ul>
<li>Gentoo 2.6.24-gentoo-r5 	GRUB 0.97</li>
<li>Ubuntu 2.6.24.3-debug 	GRUB 0.97</li>
<li>Debian 2.6.18-6-6861 	GRUB 0.97</li>
<li>Fedora 2.6.25.9-76.fc9.i6862 	GRUB 0.97</li>
</ul>
<p>You can download Kon-Boot here:</p>
<p>Floppy Image &#8211; <a href="http://www.piotrbania.com/all/kon-boot/data/FD0-konboot-v1.1-2in1.zip">FD0-konboot-v1.1-2in1.zip</a><br />
CD ISO Image &#8211; <a href="http://www.piotrbania.com/all/kon-boot/data/CD-konboot-v1.1-2in1.zip">CD-konboot-v1.1-2in1.zip</a></p>
<p>Or read more <a href="http://www.piotrbania.com/all/kon-boot/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Kon-Boot+%E2%80%93+Reset+Windows+%26+Linux+Passwords+http://bit.ly/PZGKc+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/&amp;title=Kon-Boot+%E2%80%93+Reset+Windows+%26+Linux+Passwords" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/&amp;title=Kon-Boot+%E2%80%93+Reset+Windows+%26+Linux+Passwords" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/&amp;t=Kon-Boot+%E2%80%93+Reset+Windows+%26+Linux+Passwords" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/&amp;title=Kon-Boot+%E2%80%93+Reset+Windows+%26+Linux+Passwords" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/kon-boot-reset-windows-linux-passwords/feed/</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>BackTrack 4 Pre Release Available For Download</title>
		<link>http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/</link>
		<comments>http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 10:43:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[backtrack 4]]></category>
		<category><![CDATA[backtrack 4 pre release]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[linux-livecd]]></category>
		<category><![CDATA[network security livecd]]></category>
		<category><![CDATA[pen test livecd]]></category>
		<category><![CDATA[penetration testing livecd]]></category>
		<category><![CDATA[security-livecd]]></category>
		<category><![CDATA[wireless security livecd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1876</guid>
		<description><![CDATA[You may remember back in February the BETA of BackTrack 4 was released for download, the team have made many changes and have now released BackTrack 4 Pre Release.

For those that don&#8217;t know BackTrack is the top rated linux live distribution focused on penetration testing. With no installation whatsoever, the analysis platform is started directly [...]]]></description>
			<content:encoded><![CDATA[<p>You may remember back in February the <a href="http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/">BETA of BackTrack 4</a> was released for download, the team have made many changes and have now released BackTrack 4 Pre Release.</p>
<p><!--adsense#New468--></p>
<p>For those that don&#8217;t know BackTrack is the top rated linux live distribution focused on penetration testing. With no installation whatsoever, the analysis platform is started directly from the CD-Rom and is fully accessible within minutes.</p>
<p>It&#8217;s evolved from the merge of the two wide spread distributions &#8211; Whax and Auditor Security Collection. By joining forces and replacing these distributions, BackTrack has gained massive popularity and was voted in 2006 as the #1 Security Live Distribution by insecure.org. Security professionals as well as new-comers are using BackTrack as their favorite toolset all over the globe. </p>
<p><!--adsense#New468--></p>
<p>The new version has busted the 700mb file size though so it&#8217;d DVD or USB, it&#8217;s recommended to use a USB drive to run it or install it on your HDD as running from a CD isn&#8217;t exactly speedy.</p>
<p>Full details available in the PDF guide:</p>
<p><a href="http://www.offensive-security.com/backtrack4-guide-tutorial.pdf">BackTrack 4 Guide</a> [PDF]</p>
<p>You can download BackTrack 4 Pre Release ISO here:</p>
<p><a href="http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-prefinal-iso">bt4-pre-final.iso</a></p>
<p>Or read more <a href="http://www.remote-exploit.org/backtrack.html">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=BackTrack+4+Pre+Release+Available+For+Download+http://bit.ly/aoO2K+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/&amp;title=BackTrack+4+Pre+Release+Available+For+Download" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/&amp;title=BackTrack+4+Pre+Release+Available+For+Download" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/&amp;t=BackTrack+4+Pre+Release+Available+For+Download" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/&amp;title=BackTrack+4+Pre+Release+Available+For+Download" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/backtrack-4-pre-release-available-for-download/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Lynis 1.2.6 Released &#8211; UNIX System &amp; Security Auditing Tool</title>
		<link>http://www.darknet.org.uk/2009/04/lynis-126-released-unix-system-security-auditing-tool/</link>
		<comments>http://www.darknet.org.uk/2009/04/lynis-126-released-unix-system-security-auditing-tool/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 05:31:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[auditing tool]]></category>
		<category><![CDATA[hacking unix]]></category>
		<category><![CDATA[hacking-linux]]></category>
		<category><![CDATA[linux auditing tool]]></category>
		<category><![CDATA[linux-security]]></category>
		<category><![CDATA[lynis]]></category>
		<category><![CDATA[unix auditing tool]]></category>
		<category><![CDATA[unix security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1654</guid>
		<description><![CDATA[Lynis is an auditing tool for Unix (specialists). It scans the system and available software, to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes.

This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems. It can [...]]]></description>
			<content:encoded><![CDATA[<p>Lynis is an auditing tool for Unix (specialists). It scans the system and available software, to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes.</p>
<p><!--adsense#New468--></p>
<p>This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems. It can be run without prior installation, so inclusion on read only storage is no problem (USB stick, cd/dvd).</p>
<p>Lynis assists auditors in performing Basel II, GLBA, HIPAA, PCI DSS and SOX (Sarbanes-Oxley) compliance audits.</p>
<p>A lot of new checks and controls have been added in this latest release (<a href="http://www.rootkit.nl/files/lynis-changelog.html">Full Changelog</a>). Do note Lynix is not a hardening tool, it won&#8217;t make any changes &#8211; only suggestions.</p>
<p><strong>Intended audience:</strong><br />
Security specialists, penetration testers, system auditors, system/network managers.</p>
<p><!--adsense#New468--></p>
<p><strong>Examples of audit tests:</strong></p>
<ul>
<li>Available authentication methods</li>
<li>Expired SSL certificates</li>
<li>Outdated software</li>
<li>User accounts without password</li>
<li>Incorrect file permissions</li>
<li>
Firewall auditing</li>
</ul>
<p>You can download Lynix 1.2.6 here:</p>
<p><a href="http://www.rootkit.nl/files/lynis-1.2.6.tar.gz">lynis-1.2.6.tar.gz</a></p>
<p>Or read more <a href="http://www.rootkit.nl/projects/lynis.html">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Lynis+1.2.6+Released+%E2%80%93+UNIX+System+%26+Security+Auditing+Tool+http://bit.ly/27se6j+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/04/lynis-126-released-unix-system-security-auditing-tool/&amp;title=Lynis+1.2.6+Released+%E2%80%93+UNIX+System+%26+Security+Auditing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/04/lynis-126-released-unix-system-security-auditing-tool/&amp;title=Lynis+1.2.6+Released+%E2%80%93+UNIX+System+%26+Security+Auditing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/04/lynis-126-released-unix-system-security-auditing-tool/&amp;t=Lynis+1.2.6+Released+%E2%80%93+UNIX+System+%26+Security+Auditing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/04/lynis-126-released-unix-system-security-auditing-tool/&amp;title=Lynis+1.2.6+Released+%E2%80%93+UNIX+System+%26+Security+Auditing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/04/lynis-126-released-unix-system-security-auditing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BackTrack BETA 4 Released for Public Download</title>
		<link>http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/</link>
		<comments>http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 05:53:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[backtrack 4]]></category>
		<category><![CDATA[bactrack beta 4]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[linux-livecd]]></category>
		<category><![CDATA[network security livecd]]></category>
		<category><![CDATA[pen test livecd]]></category>
		<category><![CDATA[penetration testing livecd]]></category>
		<category><![CDATA[security-livecd]]></category>
		<category><![CDATA[wireless security livecd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1491</guid>
		<description><![CDATA[The Remote Exploit Development Team is happy to announce the release of BackTrack 4 Beta. In this latest version of BackTrack 4 there have been some conceptual changed and some new and exciting features. The most significant of these changes is the expansion from the realm of a Pentesting LiveCD towards a full blown &#8220;Distribution&#8221;.
Now [...]]]></description>
			<content:encoded><![CDATA[<p>The Remote Exploit Development Team is happy to announce the release of BackTrack 4 Beta. In this latest version of BackTrack 4 there have been some conceptual changed and some new and exciting features. The most significant of these changes is the expansion from the realm of a Pentesting LiveCD towards a full blown &#8220;Distribution&#8221;.</p>
<p>Now based on Debian core packages and utilizing the Ubuntu software repositories, BackTrack 4 can be upgraded in case of update. When syncing with the BackTrack repositories, you will regularly get security tool updates soon after they are released.</p>
<p><!--adsense#New468--></p>
<p>If you don&#8217;t know what BackTrack is &#8211; it&#8217;s the result of merging the two innovative penetration testing live linux distributions Auditor and Whax. Backtrack provides a thorough pentesting environment which is bootable via CD, USB or the network (PXE). The tools are arranged in an intuitive manner, and cover most of the attack vectors. Complex environments are simplified, such as automatic Kismet configuration, one click Snort setup, precompiled Metasploit lorcon modules, etc. BackTrack has been dubbed the #1 Security Live CD by Insecure.org, and #36 overall.</p>
<p><strong>New Features</strong></p>
<ul>
<li>Kernel 2.6.28.1 with better hardware support.</li>
<li>
Native support for Pico e12 and e16 cards is now fully functional, making BackTrack the first pentesting distro to fully utilize these awesome tiny machines.</li>
<li>Support for PXE Boot &#8211; Boot BackTrack over the network with PXE supported cards!</li>
<li>SAINT EXPLOIT &#8211; kindly provided by SAINT corporation for our users with a limited number of free IPs.</li>
<li>
MALTEGO &#8211; The guys over at Paterva did outstanding work with Maltego 2.0.2 &#8211; which is featured in BackTrack as a community edition.</li>
<li>The latest mac80211 wireless injection patches are applied, with several custom patches for rtl8187 injection speed enhancements. Wireless injection support has never been so broad and functional.</li>
<li>Unicornscan &#8211; Fully functional with postgress logging support and a web front end.</li>
<li>RFID support</li>
<li>Pyrit CUDA support&#8230;</li>
<li>New and updated tools &#8211; the list is endless!</li>
</ul>
<p><!--adsense#New468--></p>
<p>This BETA release is considered stable and usable. Some tools were kept back from this version, and will be soon added to the repositories. Some minor bugs have been discovered and will be fixed with updated packaged.</p>
<p>It would also be appreciated if you could use this latest release and give some feedback to the development team to improve it and ensure it works with your specific hardware config (especially the wireless features).</p>
<p>You can download BackTrack BETA 4 here:</p>
<p>DVD ISO Image &#8211; <a href="http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-iso">bt4-beta.iso</a><br />
VMware Image &#8211; <a href="http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-beta-vm">bt4-beta-vm-6.5.1.rar</a></p>
<p>Or read more <a href="http://www.remote-exploit.org/news.html">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=BackTrack+BETA+4+Released+for+Public+Download+http://bit.ly/4tXJwx+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/&amp;title=BackTrack+BETA+4+Released+for+Public+Download" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/&amp;title=BackTrack+BETA+4+Released+for+Public+Download" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/&amp;t=BackTrack+BETA+4+Released+for+Public+Download" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/&amp;title=BackTrack+BETA+4+Released+for+Public+Download" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/02/backtrack-beta-4-released-for-public-download/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>nUbuntu Development Kicking Off Again &#8211; Security LiveCD</title>
		<link>http://www.darknet.org.uk/2008/07/nubuntu-development-kicking-off-again-security-livecd/</link>
		<comments>http://www.darknet.org.uk/2008/07/nubuntu-development-kicking-off-again-security-livecd/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 09:44:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[network ubunutu]]></category>
		<category><![CDATA[nubuntu]]></category>
		<category><![CDATA[nubuntu livecd]]></category>
		<category><![CDATA[security-livecd]]></category>
		<category><![CDATA[security-tools]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=910</guid>
		<description><![CDATA[We did mention nUbuntu long ago in our famous 10 Best Security Live CD Distros (Pen-Test, Forensics &#038; Recovery) article.
After that it stopped development for quite some time, thankfully some new blood has picked it up and development has started again!

With over a year of inactivity, the latest alpha of nUbuntu 8.04 has finally surfaced.
With [...]]]></description>
			<content:encoded><![CDATA[<p>We did mention <a href="http://www.darknet.org.uk/tag/nubuntu/">nUbuntu</a> long ago in our famous <a href="http://www.darknet.org.uk/2006/03/10-best-security-live-cd-distros-pen-test-forensics-recovery/">10 Best Security Live CD Distros (Pen-Test, Forensics &#038; Recovery)</a> article.</p>
<p>After that it stopped development for quite some time, thankfully some new blood has picked it up and development has started again!</p>
<p><!--adsense#New468--></p>
<p>With over a year of inactivity, the latest alpha of nUbuntu 8.04 has finally surfaced.</p>
<p>With this comes many new bug fixes and updates. All of the latest security and penetration tools are included to make this you&#8217;re primary pentesting livecd.</p>
<p>The main goal of nUbuntu is to create a distribution which is derived from the Ubuntu distribution, and add packages related to security testing, and remove unneeded packages, such as Gnome, Openoffice.org, and Evolution. nUbuntu is the result of an idea two people had to create a new distribution for the learning experience.</p>
<p>Many people ask, &#8220;What makes it better than X?&#8221;, or &#8220;Why should I use this over Y&#8221;. Our answer to this question is, we do not think about whether people are using it or not. We are more concerned about the learning process. If you want to try something with a clean interface, fast, and an excellent range of programs please don&#8217;t hesitate to download nUbuntu.</p>
<p><!--adsense#New468--></p>
<p>You can download nUbuntu 8.04 here:</p>
<p><a href="http://nubuntu.org/downloads/click.php?id=9">nUbuntu &#8211; 8.04 (x86)</a> (Torrent)<br />
<a href="http://nubuntu.org/downloads/click.php?id=4">nUbuntu &#8211; 8.04 (x86)</a> (Direct)</p>
<p>Or read more <a href="http://nubuntu.org/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=nUbuntu+Development+Kicking+Off+Again+%E2%80%93+Security+LiveCD+http://bit.ly/42S2cS+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/07/nubuntu-development-kicking-off-again-security-livecd/&amp;title=nUbuntu+Development+Kicking+Off+Again+%E2%80%93+Security+LiveCD" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/07/nubuntu-development-kicking-off-again-security-livecd/&amp;title=nUbuntu+Development+Kicking+Off+Again+%E2%80%93+Security+LiveCD" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/07/nubuntu-development-kicking-off-again-security-livecd/&amp;t=nUbuntu+Development+Kicking+Off+Again+%E2%80%93+Security+LiveCD" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/07/nubuntu-development-kicking-off-again-security-livecd/&amp;title=nUbuntu+Development+Kicking+Off+Again+%E2%80%93+Security+LiveCD" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/07/nubuntu-development-kicking-off-again-security-livecd/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>
