RIT 2009 Intellectual Pwnership

12
By Rob Fuller

Transcript of RIT 2009 Intellectual Pwnership

Page 1: RIT 2009 Intellectual Pwnership

By Rob Fuller

Page 2: RIT 2009 Intellectual Pwnership
Page 3: RIT 2009 Intellectual Pwnership
Page 4: RIT 2009 Intellectual Pwnership
Page 5: RIT 2009 Intellectual Pwnership

http://www.metasploit.com/

Page 6: RIT 2009 Intellectual Pwnership

Failing is learning. Pen-Testers prove fail.

Page 7: RIT 2009 Intellectual Pwnership
Page 8: RIT 2009 Intellectual Pwnership
Page 9: RIT 2009 Intellectual Pwnership

HOCUS POCUSHOCUS POCUS MS08_067_NETAPI – AKA OL' FAITHFUL

BUILDING A BINARY (IEXPRESS FTW)

PASS THE HASH / TOKEN STEALING

Page 10: RIT 2009 Intellectual Pwnership

The Framework can be used to: Testing & Fuzzing during Exploit

Development Make tool development FAST! and EASY!

(shoosh you college people!) Scripting Tasks (Resource Files /

Meterperter Scripts) Not just sofware! (Wireless, Web, VOIP, etc) REX! AND MUCH MORE!

196 AUXILIARY MODULES!

Page 11: RIT 2009 Intellectual Pwnership

MS 08_067 - http://bit.ly/1o4Ul3 PASS THE HASH - http://bit.ly/3fMlM5 TOKEN STEALING - http://bit.ly/LROoe USE THE SVN!! - http://bit.ly/4iXe0e GET INVOLVED! Mailing List, IRC etc: LEARN MORE

Metasploit Unleashed: http://bit.ly/1VlKLm

Page 12: RIT 2009 Intellectual Pwnership

Rob Fuller – mubix [at] hak5 [dot] org http://www.room362.com/ http://twitter.com/mubix .. anything /mubix