Showing posts with label Appsec. Show all posts
Showing posts with label Appsec. Show all posts

Thursday, 15 March 2012

Updates to Insecurety Research - PHP Command Injection!

So, we have written an article about PHP Command Injection (Applies to other platforms too, we just covered PHP).

Read it here! PHP Command Injection - Insecurety Research

More to come...

~Insecurety Research Team.

Wednesday, 7 March 2012

[Article] Reverse shells...

Ok. So I wrote a short article yesterday showing off a few reverse shell tricks and demoing them on a vulnerable web app using a Command Injection vulnerability.

Some people were asking "why it so basic?" and here is why: The idea of the article is not to provide script kids/blackhats with new info - it is well known - but to demonstrate how one can go from a small PHP bug to a full blown reverse shell.

I will be working up SNORT IDS Signatures for them all based on how they throw a shell back, just have to get some nice .pcaps of it first. I plan to also find a way to "signature" the IDS evading shellcode I wrote - and so kind of have an "arms race" with myself...

Article on Insecurety.net

Friday, 2 March 2012

OWASP Galway Begins!

Ok, this is a very short post as I am a tad busy, but, as of today (Friday, March Second, 2012), Galway (Ireland) has its own OWASP chapter setup by infodox!

Meetings are being prepared, as are workshops, talks and such, so watch this space for updates!

I will post links to its wiki/blog/etc later on today :)

check out OWASP stuff at OWASP.ORG

Quick note regarding my last demo

Ok, my last demo the reason the LFI-RCE failed was very simple: I messed up the Apache/PHP config in LAMPP while fuzzing earlier and forgot to reset it :/

Don't worry, my next demo will be on leveraging SQLi vulns in order to gain RCE, and I have to setup a better testbox anyway.

I will be showing the manual method + SQLMap methods of doing it all, and might even get a chance to video it!