Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Tool release: [evilgrade] - Using DNS cache poisoning to exploit poor update implementations |
|---|---|
| Date: | Mon, 28 Jul 2008 07:21:09 -0300 |
-- ISR - Infobyte Security Research -- | ISR-evilgrade | www.infobyte.com.ar | ISR-evilgrade: is a modular framework that allow us to take advantage of poor upgrade implementations by injecting fake updates. * How does it work? It works with modules, each module implements the structure needed to emulate a false update of specific applications/systems. Evilgrade needs the manipulation of the victim dns traffic. Attack vectors: --------------------- Internal scenary: (Internal DNS access,ARP spoofing,DNS Cache Poisoning, DHCP spoofing) External scenary: (Internal DNS access,DNS Cache Poisoning) * What are the supported OS? The framework is multiplaform, it only depends of having the right payload for the target platform to be exploited. Implemented modules: --------------------------------- - Java plugin - Winzip - Winamp - MacOS - OpenOffices - iTunes - Linkedin Toolbar - DAP [Download Accelerator] - notepad++ - speedbit ..:: DEMO Demo feature - (Java plugin + Dan Kaminsky´s Dns vulnerability) = remote pwned. http://www.infobyte.com.ar/demo/evilgrade.htm ..:: AUTHOR Francisco Amato famato+at+infobyte+dot+com+dot+ar ..:: DOWNLOAD http://www.infobyte.com.ar/developments.html ..:: MORE INFORMATION Presentation: http://www.infobyte.com.ar/down/Francisco-Amato-evilgrade-ENG.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [DSECRG-08-033] Local File Include Vulnerability in Pixelpost 1.7.1, Digital Security Research Group [DSecRG] |
|---|---|
| Next by Date: | [security bulletin] HPSBMA02353 SSRT080066 rev.1 - HP OpenView Internet Services Running Probe Builder, Remote Denial of Service (DoS), security-alert |
| Previous by Thread: | [DSECRG-08-033] Local File Include Vulnerability in Pixelpost 1.7.1, Digital Security Research Group [DSecRG] |
| Next by Thread: | [security bulletin] HPSBMA02353 SSRT080066 rev.1 - HP OpenView Internet Services Running Probe Builder, Remote Denial of Service (DoS), security-alert |
| Indexes: | [Date] [Thread] [Top] [All Lists] |