HAK.5 Jacket

Just received my jacket from HAK.5, It’s freaking awesome although I should’ve listened and bought a larger size, still its not that its small, just snug. I’m a bigger guy so I buy shirts 1x larger than I actually need to make me look slimer…. shut up! lol :)

No Comments

OsmocomBB | Phone Hacking

So I was looking around on the archives over at HackADay and found some information on hacking a pre-paid cell phones baseband to intercept data on the gsm cellphone network. Apparently with a 1TB rainbow table you can crack the encryption keys in 20 seconds (sounds off to me but ok) and once you’ve done that you can intercept and record phone calls or even make calls using that persons number. This project will also allow you to modify your phones location on the gsm network, the older phone not having a gps would have to tell the tower where it is at and this would alow you to change that data and appear to be somewhere your not…

Even more interesting you can locate other phones in your area and generate a kml file and load up a map or google earth and view their position… XD Phone phreaking is here to stay.

I of course have purchased a hackable phone, datacable, RS232/USB adapter, and have begun creating a distro based on ubuntu in virtualbox that will contain all the tools I need so I can dig in once it gets here.. It’s even rumored you could perform dos attacks and shutdown service, but of course you don’t want to do that unless your looking for jail time.

No Comments

Offensive Security Wireless Professional

After 3 long months of studying, on top of my school work for my actual college classes I took my oswp exam on Oct 1, 2011. I had to wait a couple of days, I had been worried that I wouldn’t pass even though I managed to crack every access point. On Oct 3, 2011 I received my confirmation email stating that I had passed my OSWP exam!

So here is my little review of what is was like and what I though of the whole course.

Registration to actually take the class was interesting, you had to register with a non-free domain, in other words it had to be an email address that was alloted from a .gov, .edu, etc. This way they could ensure they knew that I was the person I said I was before they handed over the keys to the castle pre-say.

I hadn’t started college when I joined up but luckly had been issued my email account already and was able to complete my registration.

I was emailed a time expiring link, this link gave me 24 hours to download my lab videos and .pdf lab guide, If I didn’t download them in the time allotted they would be deleted and I would have to pay a fee to receive my material. The reasoning for this is that all of the course ware has your name, address, email, and your assigned id for example OS-xxxx os.

The PDF is very extensive but I had issues reading it on the computer, just due to the fact that I didn’t want to be bound to a PC to study, I spend about $48 to have fed ex office print the manual into a binder.

The first few chapters teach you the basics, not stuff that is on the exam but information on how the technology and security methods work. The course is around 802.11x in other words it based on wifi hence the name of the course WiFu. Unfortunately you do not learn about other devices in the 2.4GHz spectrum like cameras or Bluetooth but the course is still very useful and in-depth.

You have to do you own lab work which means you’ll need to have a wireless router that you can use on the exam as well as a wireless card that can do packet injection, they lab guide does give you a nice list of compatible devices.

I did my studies on an Asus eee 1005HA on a custom linux distro I built called Corrosive Linux. That may have been a mistake to an extnet, you see the exam is on Back|Track 3 and I was using a linux distro, it did have the same tools but some of the commands did vary a bit from the exam. Alot of people have a problem with the fact that Back|Track 3 is used on the exam but the fact is when your working on the wireless portion of Back|Track the tool set remains the same in version 4 and 5 so using the newer distro just means you’re bogging down your system or you’ll have to use a live dvd vs a cd to carry tools you don’t know how to use.

The exam as its listed is a [challenge], I didn’t really think much of it going it, I had done basic pentests on my network before I it wasn’t the first time I had broken into a wep or wpa network. But my god, it was exactly as stated, a challenge.

To do your exam you connect to your exam pc over an ssh connection, you can do this over windows or mac but I do not recommend it, the fact is you had to practice on linux, you should do the exam on linux. I personally dual booted my windows 7 box with ubuntu just so I had a real linux terminal to work from, if you don’t know how to use ssh you should look up a quick tutorial because you’ll need to in order to pass. I was able to open 4 instances via ssh so you have 4 terminals that you can work from, This is more than enough, I tend to use 3 on average.

1 terminal for airodump, 1 terminal for aireplay, packetforage, etc and 1 terminal for aircrack and removing old captures, dumps, etc… The 3rd terminal is my multi-function one if you will.. I use it for everything else.

You are given 4 hours to complete your exam, I thought I could do it in an hour and a half because others have said they did it in that time frame.. I ran right up to the mark and spent the full 4 hours the exam.

All in all the exam is very good and was alot of fun, I had never enjoyed something while being so stressed out.

During the exam you’ll have 2 or 3 cards to work with, I would recommend you know how to use them both, this way you can multi-task or you can inject with one card and monitor with another, this is what I did during my exam although I don’t want to give out too many details.

You should know everything they teach you the videos, wireshark and viewing packet dumps is important but you can pass without it. you’ll have to break into 3 networks all with different configurations and you’ll have to email a report of what you did to get your end result. Sometimes an attack does not work as planned, in that case you may have to try a different attack, that is one difference between learning from a youtube and being a certified professional, you learn to adapt and if one thing doesn’t work than doing another might.

The difference between offensive security certifications and ALL other certifications is that enstead of a short response and 500 multiple choice questions you have to actually perform and do it hands on… This is a pass/fail exam you either get 100% or 0%

I wish the best of luck to anyone who goes for this certification, you will not regret it.

, , , ,

No Comments

Just Took The OSWP Exam

We’ll it was long, hard, and painful… oh god!
lol, I swear it wasn’t supposed to sound like that.

I had four hours to crack 3 access points and amazingly it actually took me the entire 4 hours!
I was able to get keys and pass phrases for each one, I’m just waiting for the official word :) Wish me luck.
I’ll do a review assuming I pass.

Edit: The Review Here: http://thecorrosiveone.com/2011/10/03/offensive-security-wireless-professional/

No Comments

xBoot

xBoot is some amazing little bit of software, I love it.
It allows you to easily create a boot disc with all the software you could want.
Mine has Kon-boot V1.1 (yes I paid for it) as well as DBAN (boot and nuke), Disc Copy, AVG Boot Disc, etc..

Give it a good look sometime, its very easy to use, just drag and drop, easy downloader and you can install it to a flash drive or create an iso image and you could then burn it of to a disc, my favorite software for that is ‘imgburn‘.

No Comments

Goodbye Linux

Well my 32GB solid state drive that I paid $100 for as an early adopter (yay!, not) just died on me…. :/
So I lost my linux install along with all my dev tools for android… ugh.

Well I needed to be running windows and office for college anyway and lets be honest here, I do miss my games, don’t get me wrong linux has some solid games too, but you cannot tell me that windows does not own that market. Hello Windows7 my good’ol infected friend.

No Comments

I Eat Beacon Frames For Breakfast!

Thought of something that I figured would make a funny t-shirt.

“I Eat Beacon Frames For Breakfast!” A beacon frame is a data frame/packet sent from a wireless access point to notify other computers and devices of its existence and security status which contain its SSID allowing users a way to find it.

http://hackingisnotacrime.spreadshirt.com/men-s-heavyweight-t-shirt-A8060527/customize/color/2

No Comments

DeAuthThis | Android App!

Download the new DeAuthThis IPTV App, This is my first creation and its in the android market

Watch my IPTV show DeAuthThis from the freedom of your android phone or device!

No Comments

Linux: Remove Win7/NT Passwords

1) Boot backtrack
2) Find the windows drive(partiton)
a) fdisk -l        (the larger drive is prob windows, example: /dev/sda2)

3) Create a directory to mount it to
a) mkdir /mnt/win   (makes a folder under /mnt/win, windows will be there)

4) Mount the windows drive to your new directory
a) mount -t ntfs-3g /dev/sda2 /mnt/win -o force  (this mounts /dev/sda2 to /mnt/win)      (if your doing this on a disto other than backtrack and this command doesn’t work do “apt-get update” then “apt-get install ntfs-3g”

5) Goto the location of the sam file, CASE specific, run ls after every cd change
a) location is: /mnt/sda2/windows/system32/config

6 ) Run CHNTPW
a: chntpw -l SAM SYSTEM  (Case of sam and system is important)
b: This lists the users, so pick your user

7) chntpw -u USERNAMEHERE SAM SYSTEM
8) SAY NO TO DISABLE SYSKEY!
9) Now just run your command to either unlock the acct or blank password
10) Safe HIVE and reboot.
11) Shutdown via command
a: shutdown -h now

2 Comments

Lagg Switch Improvement

So, I was looking around for xbox jtag kits on ebay and came acrossed lag switches.
They are quite interesting and simple.

aka : http://www.se7ensins.com/forums/topic/46897-how-to-make-and-use-a-lag-switch-halo3-cod4-gears-of-war/

The thing that interests me is that if you hold your switch for more than 3-4 secs you’ll get kicked, this is no supprise but its also a challenge, I’m curious, what could be done to make a button so that no matter how long you hold it you only get 2-3 sec per press?

This would prevent kicking and make them easier to use aka ID10T proof (I hope you all got that lol)

Anyway for all the cheating flamers, I’m not bringing this up to encourage cheating nor do I intend to cheat. But I would like to see how to prefect this tool. It is simply a challenge and now I have to try and complete one.

I’ve taken an electronics class so between me and my old classmates I’m sure we can figure something out.

No Comments