Archive for November, 2010
Nov
28

Armitage – Metasploit Free Management GUI

I came across something very cool today for Metasploit. Armitage has released a very nice gui management system to control Metasploit and make life easier to manage to exploit systems. Although I like to use non gui products, this is really something good and is like an open source Core Impact style system. It allows […]

Nov
26

Impersonating The Domain Administrator via SQL Server

A recent presentation I gave for 7Safe. It demonstrates how it is possible to fully compromise the domain using a fully patched Microsoft SQL server that has a firewall enabled. Using the SQL server I impersonate the domain administrator account without any passwords or password hashes being known or extracted. It also demonstrates the risk […]

Nov
4

Top 5 Common Issues – Article

A recent article I wrote for 7Safe (November 2010). It is a management level summary of the top 5 most common ways into networks I find when conducting internal infrastructure testing. Click the image below to read the full article. Tweet