haaaaah..i love it! ----- Original Message ----- From: "H D Moore" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, January 21, 2003 9:47 PM Subject: Re: how to gain root shell,buffer overflows using nasl..
> On Tuesday 21 January 2003 23:29, bishan kochher wrote: > > thanx for the advise ;-) but i don't want to get it done by someone > > outside ,nor do i want to invest some money into it,unless i'm really > > sure of that nessus can't get full penetration testing going for me > > Heh. Nessus DOESN'T do penetration testing, you can be sure of that now. > If you are actually serious about being able to demonstrate exploits on > your *own* systems, there are tons of books, online tutorials, etc out > there for you to read. If you don't invest time and/or money into it, > you'll never be able to hack your way out of a wet paper bag. > > > i know with nessus we can write some scripts to really exploit and do > > something damaging on remote m/c . wat i want is some proper direction > > from ur side , regarding how to do it, > > Since you seem to be hellbent on becoming a cluebie with scripts, why dont > you check out the exploit section at packetstorm like the rest of them: > > http://www.packetstormsecurity.com/ > > > that's wat a techie want, unless he doesn't verify something to its > > depth , he won't beleive in it, nor does he gains confidence in the > > tools.. > > A "techie" tends to actually do some research on the problem before > immediately crying for help too. There is a ton of free information > available on current vulnerabilties and what it takes to exploit them, if > you can't manage to figure it out yourself, you probably shouldn't be > doing it. > > > so plz gimme some concrete solutions which can really make things > > crash,hang, or gain rootshell on remote host > > Try pouring water into the case, it works 99% of the time. Throw a water > baloon to demonstrate a remote attack. > > > greetings, > > bish > > -HD > > > From: Renaud Deraison <[EMAIL PROTECTED]> > > > > >To: [EMAIL PROTECTED] > > >Subject: Re: how to gain root shell,buffer overflows using nasl.. > > >Date: Tue, 21 Jan 2003 12:10:04 +0100 > > > > > >On Tue, Jan 21, 2003 at 06:55:43AM +0000, bishan kochher wrote: > > > > thanx vince, it would be great if somebody tells me how to gain a > > > > root shell using buffer overflow,integer overflow or using any > > > > other results given by nessus > > > > > >If you ask that, then I doubt you have the expertise to tweak the > > >exploits you will find so that they work on your target system - > > >sometimes they work 'out of the box', sometimes they don't. > > > > > >If you really need to _prove_ that there is a flaw by breaking into > > > the remote computer (something on which I won't elaborate but I find > > > that uterly stupid), then I suggest you either hire a pen-test team, > > > or buy a copy of Core Impact (www.corest.com). > > > > > > > > > > > > -- Renaud > > > > _________________________________________________________________ > > Tired of spam? Get advanced junk mail protection with MSN 8. > > http://join.msn.com/?page=features/junkmail > >
