<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1218691256658225538</id><updated>2011-11-29T16:21:33.433-08:00</updated><title type='text'>Hacking with iPhone</title><subtitle type='html'>Aimed at providing an HQ so to speak for iPhone talk with pen-testing intent.  Yes it does exist, yes we are making it happen.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pwntalk.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1218691256658225538/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://pwntalk.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>BooCocky</name><uri>http://www.blogger.com/profile/17985517293564534423</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://1.bp.blogspot.com/-bfgAEfn3Js0/TWo_g9G5W9I/AAAAAAAAAAM/Sr4JdckNx8E/s220/index.jpeg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1218691256658225538.post-1648979230966898524</id><published>2011-05-04T06:42:00.000-07:00</published><updated>2011-05-04T06:42:12.166-07:00</updated><title type='text'>iPwN How-To</title><content type='html'>&lt;b style="color: red;"&gt;&lt;span style="font-size: x-large;"&gt;What is iPwN&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;"Own the network" iPwN's motto so to speak lol.&amp;nbsp; The idea is, you already carry your iPhone around everywhere you go anyway. My goal is to sort transform your iPhone into a hacking machine.&amp;nbsp; That can be used by a monkey.&amp;nbsp; iPwN is not intimidating at all. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;span style="color: red; font-size: large;"&gt;Text Bombing!&lt;/span&gt;&lt;/u&gt; &lt;br /&gt;&lt;br /&gt;Well, im sure by now everyone knows how to sms bomb.&amp;nbsp; All you need is a gmail account.&amp;nbsp; Here's the catch though, gmail will disable your account after 500 texts for 24 hours.&amp;nbsp; This is a nuisance and could be avoided if I implemented a paid text service.&amp;nbsp; They do exist, but like I say they are paid.&amp;nbsp; If you need to send someone more than the daily 500, than get a few friends on the internet together and organize a mass attack ;)&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;u&gt;&lt;span style="font-size: large;"&gt;Packet Sniffing!&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So what I did here, initially, was I made a Pirni and Derv implementation.&amp;nbsp;&amp;nbsp; I get alot of emails saying that it doesn't work.&amp;nbsp; Well, it does work, its just not finding anything useful.&amp;nbsp; The log.pcap file gets deleted as it is read by derv.&amp;nbsp; Most likely the user-names and passwords are encrypted and are dropped.&amp;nbsp;&amp;nbsp; However, I recently added fr0gger, which is a *modified* version of dsniff fr0g.&amp;nbsp; This will provide a real live feed, even let you target a specific machine on the network.&amp;nbsp; If you cant get that to show anything, well then my friend, "victim" is not using the internet.&amp;nbsp; Try again. &lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;&lt;u&gt;&lt;span style="font-size: large;"&gt;Exp0its!?!!?&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Yep, well, these are written in python.&amp;nbsp; Have a very simple code base but as I search through exploit-db.com or shodanhq.com I find exploits compatible with iPwN's intentions of easy interaction.&amp;nbsp; I cant really describe them as they are all different, and I add new ones quite instantaneously.&amp;nbsp;&amp;nbsp; Will add documentation on each individual exploit in the README file of each iPwN update.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;u&gt;&lt;span style="color: red;"&gt;Metasploit Attack Vectors&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;u&gt;&lt;span style="color: red;"&gt; &lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;u&gt;&lt;span style="color: red;"&gt; &lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;u&gt;&lt;span style="color: red;"&gt; &lt;/span&gt;&lt;/u&gt;&lt;/span&gt;This is very early stages, but is what I really wanted iPwN to be in the first place.&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1218691256658225538-1648979230966898524?l=pwntalk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pwntalk.blogspot.com/feeds/1648979230966898524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://pwntalk.blogspot.com/2011/05/ipwn-how-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1218691256658225538/posts/default/1648979230966898524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1218691256658225538/posts/default/1648979230966898524'/><link rel='alternate' type='text/html' href='http://pwntalk.blogspot.com/2011/05/ipwn-how-to.html' title='iPwN How-To'/><author><name>BooCocky</name><uri>http://www.blogger.com/profile/17985517293564534423</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://1.bp.blogspot.com/-bfgAEfn3Js0/TWo_g9G5W9I/AAAAAAAAAAM/Sr4JdckNx8E/s220/index.jpeg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1218691256658225538.post-7198127857543138647</id><published>2011-05-04T05:23:00.000-07:00</published><updated>2011-05-04T05:36:26.619-07:00</updated><title type='text'>What are the best cydia repos for pentesting tools?</title><content type='html'>&lt;div style="color: white;"&gt;#1, the original and the best&lt;/div&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;http://cydia.theworm.tw&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="color: white;"&gt;This repository contains the network-cmds package, that includes a modified ifconfig binary.&amp;nbsp; This ifconfig, thanks to Wim Verreyckedn and TheWorm, will allow for promiscuous mode.&amp;nbsp; Very important for dnsspoof attacks.&lt;/div&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;http://boococky.hostei.com/cydia&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="color: white;"&gt;This is my repository, yes it has errors.&amp;nbsp; Yes it still works.&amp;nbsp; I still update it regularly.&amp;nbsp; Trying to keep up with all the latest tools that are of use on an iDevice, and ofcoarse iPwN ;) &amp;nbsp; I even took a shot at developing a native iOS X11 desktop.&amp;nbsp; Got as far as FVWM and Xterm.&amp;nbsp; Pretty cool, but&amp;nbsp; this repository&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&amp;nbsp;&lt;span style="color: blue;"&gt;http://fenyx.x10.mx/&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;&lt;span style="color: black;"&gt;&lt;span style="color: white;"&gt;Fenyx's repository.&amp;nbsp; She has managed to build things such as window maker, GTK, cairo, even Ettercap GUI, that actually works on an iDevice under X11. She even compiled the newest Ruby 1.9.2, which is now recommended over the version I have on my repository.&amp;nbsp; Especially if your using Metasploit on an older device.&amp;nbsp; As it allocates memory better than the 1.8.6 version I have. &amp;nbsp;&lt;/span&gt; &lt;/span&gt;&lt;span style="color: black;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;&lt;span style="color: blue;"&gt;http://trcx.site50.net/cydia&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="color: white;"&gt;TRCX is a devoted developer and a friend.&amp;nbsp; Grab this repository for opendns, adds an important resolv.conf to your /etc path.&amp;nbsp; He also has iAHT which has some automated attack scripts and makes using most tools alot easier.&amp;nbsp; You might also want to grab iForum for great support.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1218691256658225538-7198127857543138647?l=pwntalk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pwntalk.blogspot.com/feeds/7198127857543138647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://pwntalk.blogspot.com/2011/05/what-are-best-cydia-repos-for.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1218691256658225538/posts/default/7198127857543138647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1218691256658225538/posts/default/7198127857543138647'/><link rel='alternate' type='text/html' href='http://pwntalk.blogspot.com/2011/05/what-are-best-cydia-repos-for.html' title='What are the best cydia repos for pentesting tools?'/><author><name>BooCocky</name><uri>http://www.blogger.com/profile/17985517293564534423</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://1.bp.blogspot.com/-bfgAEfn3Js0/TWo_g9G5W9I/AAAAAAAAAAM/Sr4JdckNx8E/s220/index.jpeg'/></author><thr:total>5</thr:total></entry></feed>
