<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; payload</title>
	<atom:link href="http://www.darknet.org.uk/tag/payload/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WebRaider &#8211; Automated Web Application Exploitation Tool</title>
		<link>http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/</link>
		<comments>http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 09:41:24 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[automated web application exploitation tool]]></category>
		<category><![CDATA[automated web application security testing]]></category>
		<category><![CDATA[automated web hacking]]></category>
		<category><![CDATA[ferruh mavituna]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[mesut timur]]></category>
		<category><![CDATA[one click ownage]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[reverse shell]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[web exploitation]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-hacking-tool]]></category>
		<category><![CDATA[webraider]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2587</guid>
		<description><![CDATA[WebRaider is a plugin based automated web application exploitation tool which focuses to get a shell from multiple targets or injection point Idea of this attack is very simple. Getting a reverse shell from an SQL Injection with one request without using an extra channel such as TFTP, FTP to upload the initial payload. It&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>WebRaider is a plugin based automated web application exploitation tool which focuses to get a shell from multiple targets or injection point</p>
<p>Idea of this attack is very simple. Getting a reverse shell from an SQL Injection with one request without using an extra channel such as TFTP, FTP to upload the initial payload.</p>
<ul>
<li>It&#8217;s only one request therefore faster,</li>
<li>Simple, you don&#8217;t need a tool you can do it manually by using your browser or a simple MITM proxy,</li>
<li>Just copy paste the payload,</li>
<li>CSRF(able), It&#8217;s possible to craft a link and carry out a CSRF attack that will give you a reverse shell,</li>
<li>It&#8217;s not fixed, you can change the payload,</li>
<li>It&#8217;s short, Generally not more than 3.500 characters,</li>
<li>Doesn&#8217;t require any application on the target system like FTP, TFTP or debug.exe,</li>
<li>Easy to automate.</li>
</ul>
<p><strong>Dependencies</strong></p>
<p>Internally WebRaider uses <a href="http://www.darknet.org.uk/tag/metasploit/">Metasploit</a>. The authors use a specific version of Metasploit, they trimmed the fat from Metasploit to launch it faster and make it smaller. You can change the paths and make it work with the latest Metasploit of your own setup. </p>
<p>Also note due to the reverse shells and Metasploit components this software will be detected a virus by AV software.</p>
<p>You can download WebRaider here:</p>
<p><a href="http://webraider.googlecode.com/files/WebRaider-0.2.3.8.zip">WebRaider-0.2.3.8.zip</a></p>
<p></p>
<p>Or read more <a href="http://code.google.com/p/webraider/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2587+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;t=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/&amp;title=WebRaider+%E2%80%93+Automated+Web+Application+Exploitation+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F03%2Fwebraider-automated-web-application-exploitation-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/03/webraider-automated-web-application-exploitation-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Metasploit 3.0 Beta 3 Released</title>
		<link>http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/</link>
		<comments>http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/#comments</comments>
		<pubDate>Tue, 05 Dec 2006 17:21:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[automated-hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[metasploit-framework]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/</guid>
		<description><![CDATA[The Metasploit Framework is an advanced open-source exploit development platform. The 3.0 tree represents a complete rewrite of the 2.0 codebase and provides a scalable and extensible framework for security tool development. The 3.0 Beta 3 release includes support for exploit automation, 802.11 wireless packet injection, and kernel-mode payloads. Windows users are now presented with [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>The Metasploit Framework is an advanced open-source exploit development platform. The 3.0 tree represents a complete rewrite of the 2.0 codebase and provides a scalable and extensible framework for security tool development. The 3.0 Beta 3 release includes support for exploit automation, 802.11 wireless packet injection, and kernel-mode payloads.</p>
<p>Windows users are now presented with a RXVT console and an updated Cygwin environment, which greatly improves the usability of the 3.0 interface on the Windows platform. </p>
<p>The Metasploit Web Interface is still in development, but this release includes a preview of what the end functionality will look like. The web interface provides a &#8220;webtop&#8221; interface for interacting with the framework and uses aynschronous javascript to provide live searching. A early version of Metasploit IDE is also included with the web interface.</p>
<p>Downloads for all platforms can be found here:<br />
 &#8211; <a href="http://metasploit.com/projects/Framework/msf3/#download">http://metasploit.com/projects/Framework/msf3/#download</a></p>
<p>The latest version can be pulled directly from Subversion:</p>
<pre><code> $ svn co http://metasploit.com/svn/framework3/trunk/</code></pre>
<p>Unix users may need to install the openssl zlib and dl ruby modules for the Framework to load. If you are using Ubuntu you will need to run the following commands:</p>
<pre><code># apt-get install libzlib-ruby
# apt-get install libopenssl-ruby
# apt-get install libdl-ruby</code></pre>
<p>Unix users who wish to try the new web interface will need to install the &#8216;rubygems&#8217; package and the &#8216;rails&#8217; gem. Please see <a href="http://www.rubyonrails.com">www.rubyonrails.com</a> for more information and platform-specific installation instructions.</p>
<p>Users of other distributions or Unix flavors may want to grab the latest version of ruby from <a href="http://www.ruby-lang.org">www.ruby-lang.org</a> and build it from source. We highly recommend using Ruby version 1.8.4 or newer.Windows users will need to exit out of any running Cygwin-based applications before running the installer or using the Framework. The old 3.0 installation should be uninstalled prior to installing and using this version.</p>
<p>The release packages include Subversion repository information allowing you to synchronize your Beta 3 installation with the live development tree. The Windows installer includes a &#8220;MSFUpdate&#8221; menu item that uses Subversion to download the latest updates.Unix users will need to install the Subversion client change into the framework directory and execute &#8216;svn update&#8217;.</p>
<p>On Unix systems, Subversion will complain about the self-signed certificate in use at metasploit.com. Please verify that the fingerprint matches the one below before accepting it:</p>
<p></p>
<blockquote><p>- Hostname: metasploit.com<br />
- Valid: from Jun 3 06:56:22 2005 GMT until Mar 31 06:56:22 2007 GMT<br />
- Issuer: Development The Metasploit Project San Antonio Texas US<br />
- Fingerprint: 1f:a2:8e:ad:14:57:53:75:b7:ab:de:67:e8:fa:17:49:76:f2:ee:ad</p></blockquote>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Metasploit+3.0+Beta+3+Released+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D388+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/&amp;t=Metasploit+3.0+Beta+3+Released" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/&amp;title=Metasploit+3.0+Beta+3+Released" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/&amp;title=Metasploit+3.0+Beta+3+Released" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/&amp;title=Metasploit+3.0+Beta+3+Released" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/&amp;title=Metasploit+3.0+Beta+3+Released" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F12%2Fmetasploit-30-beta-3-released%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/12/metasploit-30-beta-3-released/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Metasploit 2.7 Released &#8211; Automated Hacking</title>
		<link>http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/</link>
		<comments>http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/#comments</comments>
		<pubDate>Mon, 27 Nov 2006 05:27:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[automated-hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[metasploit-framework]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/</guid>
		<description><![CDATA[The Metasploit Framework is an advanced open-source exploit development platform. The 2.7 release includes three user interfaces, 157 exploits and 76 payloads.The Framework will run on any modern operating system that has a working Perl interpreter. The Windows installer includes a slimmed-down version of the Cygwin environment. Windows users are encouraged to update as soon [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>The Metasploit Framework is an advanced open-source exploit development platform. The 2.7 release includes three user interfaces, 157 exploits and 76 payloads.The Framework will run on any modern operating system that has a working Perl interpreter. The Windows installer includes a slimmed-down version of the Cygwin environment. </p>
<p>Windows users are encouraged to update as soon as possible. A number of improvements were made that should make the Windows experience a little less painful and a lot more reliable. All updates to 2.6 have been rolled into 2.7, along with some new exploits and minor features. </p>
<p>You can download the new metasploit here:</p>
<p>  &#8211; Unix:  <a href="http://metasploit.com/tools/framework-2.7.tar.gz">http://metasploit.com/tools/framework-2.7.tar.gz</a><br />
  &#8211; Win32: <a href="http://metasploit.com/tools/framework-2.7.exe">http://metasploit.com/tools/framework-2.7.exe</a></p>
<p>A demonstration of the msfweb interface is running live from:</p>
<p>  &#8211; <a href="http://metasploit.com:55555/">http://metasploit.com:55555/</a></p>
<p>This may be the LAST 2.x version of the Metasploit Framework. All development resources are now being applied to version 3.0. More information about version 3.0 can be found online at:</p>
<p>  &#8211; <a href="http://metasploit.com/projects/Framework/msf3/">http://metasploit.com/projects/Framework/msf3/</a></p>
<p>Exploit modules designed for the 2.2 through 2.6 releases should maintain compatibility with 2.7. If you run into any problems using older modules with this release, please let us know.</p>
<p>For more information about the Framework and this release in general, please refer to the online documentation, particularly the User Guide:</p>
<p></p>
<p>  &#8211; <a href="http://metasploit.com/projects/Framework/documentation.html">http://metasploit.com/projects/Framework/documentation.html</a></p>
<p>Enjoy!</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Metasploit+2.7+Released+%E2%80%93+Automated+Hacking+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D387+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/&amp;t=Metasploit+2.7+Released+%E2%80%93+Automated+Hacking" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/&amp;title=Metasploit+2.7+Released+%E2%80%93+Automated+Hacking" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/&amp;title=Metasploit+2.7+Released+%E2%80%93+Automated+Hacking" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/&amp;title=Metasploit+2.7+Released+%E2%80%93+Automated+Hacking" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/&amp;title=Metasploit+2.7+Released+%E2%80%93+Automated+Hacking" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F11%2Fmetasploit-27-released-automated-hacking%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/11/metasploit-27-released-automated-hacking/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

