Blog Archives

Nmap NSE Howto: MySQL Auth Bypass

A recently disclosed critical vulnerability in MySQL authentication on some platforms gave me just the excuse I needed to write my first Nmap NSE script. @jcran produced a metasploit module to find and exploit the MySQL bug so I thought I’d

Tagged with: , , , , ,
Posted in Networks, Security, Tools

ssh-agent: Abusing the trust – Part 2

In part 1 of this blog post I discussed common issues with using ssh-agent forwarding in an untrusted environment. Despite the risks it remains prevalent in my experience and ripe for some exploitation. There are tools out there to help

Tagged with: , ,
Posted in Security, Tools

Tool – bingip – CLI Virtual Host checker

Google rocks right? Well, there’s still one feature it lacks compared to Bing – the ability to search by IP address.  On bing.com you can use ip:<IP address> and it will return pages indexed from that IP address which, as

Tagged with: , ,
Posted in Security, Tools
GitHub Projects
Recent Tweets
Archives