hi group
thanx for the advise ;-) but i don't want to get it done by someone outside ,nor do i want to invest some money into it,unless i'm really sure of that nessus can't get full penetration testing going for me
i know with nessus we can write some scripts to really exploit and do something damaging on remote m/c . wat i want is some proper direction from ur side , regarding how to do it,
that's wat a techie want, unless he doesn't verify something to its depth , he won't beleive in it, nor does he gains confidence in the tools..
so plz gimme some concrete solutions which can really make things crash,hang, or gain rootshell on remote host
greetings,
bishan
From: Renaud Deraison <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: Re: how to gain root shell,buffer overflows using nasl.. Date: Tue, 21 Jan 2003 12:10:04 +0100On Tue, Jan 21, 2003 at 06:55:43AM +0000, bishan kochher wrote: > thanx vince, it would be great if somebody tells me how to gain a root > shell using buffer overflow,integer overflow or using any other results > given by nessus If you ask that, then I doubt you have the expertise to tweak the exploits you will find so that they work on your target system - sometimes they work 'out of the box', sometimes they don't. If you really need to _prove_ that there is a flaw by breaking into the remote computer (something on which I won't elaborate but I find that uterly stupid), then I suggest you either hire a pen-test team, or buy a copy of Core Impact (www.corest.com). -- Renaud
_________________________________________________________________
Tired of spam? Get advanced junk mail protection with MSN 8. http://join.msn.com/?page=features/junkmail
