Downloads
Downloads
Downloads Home » Blackpapers
DocumentsDate added
-
Microsoft Access Trojan VBA: The overlooked Macro Virushot!
- 14.06.2000
- Everyone got all excited about viruses like the Melissa virus which relied on macros in Microsoft Word. As a result, Microsoft got all "safe" and decided to ban untrusted macro execution in all their office products, except one: Microsoft Access. Although this exploit leverages something similar to a macro, turning off this feature in Access well, BREAKS Access. Go figure.
- Hits: 7769
-
Windows NT Assessment Techniqueshot!
- 01.12.2000
- Similar in purpose to the Netware Guide, this document chronicled my learning process in NT Assessments. It is similar to Rhino9's wardoc, but was done independantly, around the same timeframe. I haven't updated it in a long time, but it served it's purpose.
- Hits: 11331
-
The URL and the URIhot!
- 04.03.2002
- A history and overview of these two items. c'mon... you know URI's.. http:// or aim:// or ftp://.. those things you put before your address in your browser. I wrote this beacuse of eeye's cool post entitled "Windows Shell Overflow" at http://www.eeye.com/html/Research/Advisories/AD20020308.html
- Hits: 15008
-
The Google Hacker's Guidehot!
- 19.03.2004
- The Google search engine found at www.google.com offers many different features including language and document translation, web, image, newsgroups, catalog and news searches and more. These features offer obvious benefits to even the most uninitiated web surfer, but these same features allow for far more nefarious possibilities to the most malicious Internet users including hackers, computer criminals, identity thieves and even terrorists. This paper outlines the more nefarious applications of the Google search engine, techniques that have collectively been termed "Google hacking". The intent of this paper is to educate web administrators and the security community in the hopes of eventually securing this form of information leakage. This was the early predecessor to Google Hacking For Penetration Testers.
- Hits: 109047
-
DNS Prediction With Googlehot!
- 25.03.2005
- It's possible to use Google to help find hosts that Google doesn't even KNOW about! This paper outlines a technique we'll call DNS name prediction with Google. This technique can help a security auditor locate hosts, targets, and subdomains that exist on a target network via Google queries, name expansion with Google sets, and DNS lookups. A neat topic, outlined with working examples.
- Hits: 12552