On Tuesday 21 January 2003 23:29, bishan kochher wrote:
> thanx for the advise ;-) but i don't want to get it done by someone
> outside ,nor do i want to invest some money into it,unless i'm really
> sure of that nessus can't get full penetration testing going for me

Heh. Nessus DOESN'T do penetration testing, you can be sure of that now. 
If you are actually serious about being able to demonstrate exploits on 
your *own* systems, there are tons of books, online tutorials, etc out 
there for you to read. If you don't invest time and/or money into it, 
you'll never be able to hack your way out of a wet paper bag. 

> i know with nessus we can write some scripts to really exploit and do
> something damaging on remote m/c . wat i want is some proper direction
> from ur side , regarding how to do it,

Since you seem to be hellbent on becoming a cluebie with scripts, why dont 
you check out the exploit section at packetstorm like the rest of them:

http://www.packetstormsecurity.com/

> that's wat a techie want, unless he doesn't verify something to its
> depth , he won't beleive in it, nor does he gains confidence in the
> tools..

A "techie" tends to actually do some research on the problem before 
immediately crying for help too. There is a ton of free information 
available on current vulnerabilties and what it takes to exploit them, if 
you can't manage to figure it out yourself, you probably shouldn't be 
doing it.

> so plz gimme some concrete solutions which can really make things
> crash,hang, or gain rootshell on remote host

Try pouring water into the case, it works 99% of the time. Throw a water 
baloon to demonstrate a remote attack.

> greetings,
> bish

-HD

> From: Renaud Deraison <[EMAIL PROTECTED]>
>
> >To: [EMAIL PROTECTED]
> >Subject: Re: how to gain root shell,buffer overflows using  nasl..
> >Date: Tue, 21 Jan 2003 12:10:04 +0100
> >
> >On Tue, Jan 21, 2003 at 06:55:43AM +0000, bishan kochher wrote:
> > > thanx vince, it would be great if somebody tells me how to gain a
> > > root shell using buffer overflow,integer overflow or using any
> > > other results given by nessus
> >
> >If you ask that, then I doubt you have the expertise to tweak the
> >exploits you will find so that they work on your target system -
> >sometimes they work 'out of the box', sometimes they don't.
> >
> >If you really need to _prove_ that there is a flaw by breaking into
> > the remote computer (something on which I won't elaborate but I find
> > that uterly stupid), then I suggest you either hire a pen-test team,
> > or buy a copy of Core Impact (www.corest.com).
> >
> >
> >
> >                             -- Renaud
>
> _________________________________________________________________
> Tired of spam? Get advanced junk mail protection with MSN 8.
> http://join.msn.com/?page=features/junkmail

Reply via email to