<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link rel="hub" href="http://tumblr.superfeedr.com/" xmlns:atom="http://www.w3.org/2005/Atom"/><description>We aren’t here to talk about theoretical hacks, or “If” scenarios. Call bullshit on us for anything you can’t get working or don’t think actually happens.

Want a white paper put into perspective? Can’t quite figure out how a tool or exploit works? or works into a pen test? Thats what we do, shoot a comment, tweet, facebook update our way and we’ll feature it on a show. You can also post a question right here: 

Ask a Question






FB.init("37c3a6d20504d79bfdd7ca342688425e");Practical Exploitation on Facebook </description><title>Practical Exploitation</title><generator>Tumblr (3.0; @practicalexploitation)</generator><link>http://practicalexploitation.com/</link><item><title>Simple Framework Domain Token Scanner</title><description>&lt;a href="http://blog.pentestify.com/simple-framework-domain-token-scanner"&gt;Simple Framework Domain Token Scanner&lt;/a&gt;: &lt;p&gt;This is so much more than the title…&lt;/p&gt;</description><link>http://practicalexploitation.com/post/12227214743</link><guid>http://practicalexploitation.com/post/12227214743</guid><pubDate>Tue, 01 Nov 2011 23:11:11 -0400</pubDate></item><item><title>is this site shutdown?  You have not posted anything to Practical Exploitation for a while, love the vids wish you would post more.</title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;Sorry, I will be picking things back up soon.&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/2427790319</link><guid>http://practicalexploitation.com/post/2427790319</guid><pubDate>Thu, 23 Dec 2010 01:50:09 -0500</pubDate><category>formspring.me</category></item><item><title>Revenge of the Bind Shell - Using Meterpreter and Teredo to make...</title><description>&lt;iframe src="http://player.vimeo.com/video/15243189" width="400" height="300" frameborder="0"&gt;&lt;/iframe&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;Revenge of the Bind Shell - Using Meterpreter and Teredo to make your perimeter useless.&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1177078129</link><guid>http://practicalexploitation.com/post/1177078129</guid><pubDate>Fri, 24 Sep 2010 00:10:00 -0400</pubDate></item><item><title>Hello Mubix, hey have my blog up and rolling now which you are following on here but do you know any other good security tutorial based blogs you suggest on tumblr?</title><description>&lt;p&gt;On Tumblr? Not that I know of&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171383033</link><guid>http://practicalexploitation.com/post/1171383033</guid><pubDate>Thu, 23 Sep 2010 00:43:32 -0400</pubDate></item><item><title>Dear Rob,&lt;br /&gt;&#13;
&lt;br /&gt;&#13;
I've always wanted to learn the Spike fuzzing framework well enough to write my own fuzz scripts for whatever protocol I want. Although the documentation is difficult to understand and there seems to be none to very little tutorials/documentation on the web. Please help.&lt;br /&gt;&#13;
&lt;br /&gt;&#13;
Sincerely,&lt;br /&gt;&#13;
&lt;br /&gt;&#13;
Matt</title><description>&lt;p&gt;Added to the list of videos to do.&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171381378</link><guid>http://practicalexploitation.com/post/1171381378</guid><pubDate>Thu, 23 Sep 2010 00:43:08 -0400</pubDate></item><item><title>A step-by-step how to on the popular Dan kaminsky DNS Cache Poisioning Attack would be nice. :)</title><description>&lt;p&gt;I’ll see what I can dig up as far as servers are concerned. But I’ll definitely add it to the list&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171379098</link><guid>http://practicalexploitation.com/post/1171379098</guid><pubDate>Thu, 23 Sep 2010 00:42:36 -0400</pubDate></item><item><title>This isn't really a question, but I did my own malware analysis research recently and thought I could help with the metasploit encoding for AV evasion. I tested 8 payloads and 7 encoders with and without multiple encoding iterations. (up to 10 iterations as some payloads don't seem to work correctly with more.) AVG was the only oddball out of the 7 Anti-virus's tested. It found some payloads but not others. The generic encoder was not flagged at all. The strange part is some of the more advanced encoders such as shikata-ga-nai we're flagged dirty on almost all payloads.&lt;br /&gt;&#13;
&lt;br /&gt;&#13;
Kaspersky Internet Security 2010, Mcafee Security Suite, and Microsoft Security Essentials flagged all payloads as dirty.&lt;br /&gt;&#13;
&lt;br /&gt;&#13;
Avast free, Avira free, and Norton Internet Security 2010 flagged none as dirty.&lt;br /&gt;&#13;
&lt;br /&gt;&#13;
I hope this helps, and if you want I can send my spreadsheet covering each AV in depth as metasploit payloads weren't the only "dirty" programs that I tested.&lt;br /&gt;&#13;
Hope this helps!&lt;br /&gt;&#13;
-hhmatt@live.com</title><description>&lt;p&gt;Nice! Thanks for the info.&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171358740</link><guid>http://practicalexploitation.com/post/1171358740</guid><pubDate>Thu, 23 Sep 2010 00:37:47 -0400</pubDate></item><item><title>Wonderful down-to-earth website on vulnerability testing!  I tried the php shell demo verbatim and against a system that should have been vulnerable, but only receive "bad request in header" from burp.</title><description>&lt;p&gt;Did you ever find out why?&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171355867</link><guid>http://practicalexploitation.com/post/1171355867</guid><pubDate>Thu, 23 Sep 2010 00:37:10 -0400</pubDate></item><item><title>How do you automatically activate a session in metasploit when you are using a generic/shell_reverse_tcp as for in, example, the java_signed_applet exploit? User interaction is required to actually type: sessions -i 1, whereas in the meterpreter/reverse_tcp the session can be automatically kicked off.  Do you know of any method of sending that command -- sessions -i 1 -- to the keyboard so the attacker does not have to sit around all day and interact with the session? Thanks.</title><description>&lt;p&gt;You don’t &lt;em&gt;have&lt;/em&gt; to interact with a session to have it active. Why would you want to interact with a shell if you weren’t there?&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171354053</link><guid>http://practicalexploitation.com/post/1171354053</guid><pubDate>Thu, 23 Sep 2010 00:36:45 -0400</pubDate></item><item><title>Hi,&lt;br /&gt;&#13;
I just recently got into exploits. Can you give us some insights which web pages you track for new exploits? Or in general what your main IT security "channels" are. I haven't found the right place for up-to-date information. &lt;br /&gt;&#13;
&lt;br /&gt;&#13;
Regards, &lt;br /&gt;&#13;
JD</title><description>&lt;p&gt;I get information from all over. Blogs, Twitter, OSVDB, CVEDetails, PacketStorm, Exploit-DB, Full Disclosure. You never know where that information will hit first, or if it will make a wave enough to carry over to other media. Just got to keep an eye out.&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171344702</link><guid>http://practicalexploitation.com/post/1171344702</guid><pubDate>Thu, 23 Sep 2010 00:34:38 -0400</pubDate></item><item><title>more on ipv6! joe klein has an interesting presentation on the dojosec blog (july), what are you working on?</title><description>&lt;p&gt;Will do. I’ll be showing off the THC tools in some coming videos&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171338259</link><guid>http://practicalexploitation.com/post/1171338259</guid><pubDate>Thu, 23 Sep 2010 00:33:07 -0400</pubDate></item><item><title>Thanks for doing this. Great job!&lt;br /&gt;&#13;
One thing - can you make the name of your postings match the title of the post. As it is, when I bookmark one, the name of the bookmark name is "Practical Exploitation" rather than the title of the post.&lt;br /&gt;&#13;
Thanks!&lt;br /&gt;&#13;
Keep up the great work!</title><description>&lt;p&gt;Working on it. Thanks for the heads up!&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171312613</link><guid>http://practicalexploitation.com/post/1171312613</guid><pubDate>Thu, 23 Sep 2010 00:27:24 -0400</pubDate></item><item><title>Mubix, thx for all the precious knowledge and tech you share with us.  &lt;br /&gt;&#13;
Lot of a videos i came a cross on net are about point to point attacks or similar, very simple demonstrations. &lt;br /&gt;&#13;
What i realy wanna see is a little bit complicated attacks with tunneling and proxy implementation on zombie host. And then attack vector thru zombie. Can u do some video about MSF and tunneling, proxy implementation&gt;&lt;br /&gt;&#13;
Thx,</title><description>&lt;p&gt;Definitely. I’ll work on getting it set up. Expect a bunch of videos starting in October.&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1171251418</link><guid>http://practicalexploitation.com/post/1171251418</guid><pubDate>Thu, 23 Sep 2010 00:14:09 -0400</pubDate></item><item><title>Here goes. Do you know why spoonwep was dropped from Backtrack 4? Also is it easy to install?</title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;@purehate_ could probably answer that question a lot better since he is a BT dev. Also, I’ve used spoonwep before but it’s been a while. I would expect it to be a pretty easy install.&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1082090412</link><guid>http://practicalexploitation.com/post/1082090412</guid><pubDate>Tue, 07 Sep 2010 14:19:59 -0400</pubDate><category>formspring.me</category></item><item><title>1+1
</title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;That inquiry is superior to my abilities of deduction. Please ask Wolfram Alpha.&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1081300091</link><guid>http://practicalexploitation.com/post/1081300091</guid><pubDate>Tue, 07 Sep 2010 10:36:09 -0400</pubDate><category>formspring.me</category></item><item><title>If you only had exactly 24 hours left to live, no matter what, what would you do?</title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;Sit and talk with all of my closest friends and family.&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1077515929</link><guid>http://practicalexploitation.com/post/1077515929</guid><pubDate>Mon, 06 Sep 2010 17:44:14 -0400</pubDate><category>formspring.me</category></item><item><title>Hey Mubix! I was the guy who asked about CDC tool recommendations on Twitter for blue teams/defenders. Any strong suggestions there? Flint by Matasano looks wicked cool, but it turns out it's ASA and PIX only.</title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;My best suggestion for Blue Teamers in an event such as CCDC is teamwork and preparation. Nothing beats practice.&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1009592901</link><guid>http://practicalexploitation.com/post/1009592901</guid><pubDate>Wed, 25 Aug 2010 13:08:10 -0400</pubDate><category>formspring.me</category></item><item><title>Hello! I'm trying to find a free packer for my compiled program. The problem is that some AV software recognizes my app as a suspicious file, and I'd like them not to. My goal would is to pass all the virustotal tests. UPX does not help ;)</title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;It really depends on what you want it to do. But definitely check out Polypack @ &lt;a href="http://polypack.eecs.umich.edu" target="_blank" rel="nofollow" class="nofollow"&gt;&lt;a href="http://polypack.eecs.umich.edu"&gt;http://polypack.eecs.umich.edu&lt;/a&gt;&lt;/a&gt;/&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1009587198</link><guid>http://practicalexploitation.com/post/1009587198</guid><pubDate>Wed, 25 Aug 2010 13:06:38 -0400</pubDate><category>formspring.me</category></item><item><title>Have you ever run a portable version of spyware remover through logon scripts i have few machines infected with a nasty spyware and  our anti virus does not have e updates to detect this virus at this moment so  i was thinking to silently run &amp; remove it</title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;All *-ware removers are only halfway decent at their job, they try but it’s just too hard to keep up. So, normally I just reimage the machine. I keep pretty decent nLite scripts for each host I’ll need to set up.&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1009582541</link><guid>http://practicalexploitation.com/post/1009582541</guid><pubDate>Wed, 25 Aug 2010 13:05:23 -0400</pubDate><category>formspring.me</category></item><item><title>Hi Rob ,
this is a noob question How do i update metaspoilt on backtrack 4 ? can i get the command in doing so . . </title><description>&lt;p&gt;&lt;p class="formspringmeAnswer"&gt;Change directory into the “framework3” directory and run `svn up` that will update you to the latest SVN version. While this puts you on the cutting edge of updates to the framework, somethings may be broken, so always keep another copy of the framework a few revisions old.&lt;/p&gt;

&lt;p class="formspringmeFooter"&gt;
    &lt;a href="http://formspring.me/mubix?utm_medium=social&amp;utm_source=tumblr&amp;utm_campaign=shareanswer"&gt;Ask me anything&lt;/a&gt;
&lt;/p&gt;&lt;/p&gt;</description><link>http://practicalexploitation.com/post/1009225363</link><guid>http://practicalexploitation.com/post/1009225363</guid><pubDate>Wed, 25 Aug 2010 11:25:14 -0400</pubDate><category>formspring.me</category></item></channel></rss>

