Find and correct WordPress vulnerabilities using WPScan

| 0 comments

If you run a WordPress based website then you should sit up, pull out your notepad, and carefully consider the idea of running WPScan on your site in order to if you have any security vulnerabilities that may require your attention. This is not to say that WordPress is vulnerable per say, but the fact is all software contains some level of vulnerabilities and the more you know, the more you will understand and be able to better protect your site. You may be surprised to learn that CVE has 177 documented vulnerabilities over the years concerning WordPress. If you …

Continue reading

Cracking MD5 using Hashcat

| 0 comments

If you are not familiar with Hashcat then you are in luck. Before I get started, Wikipedia states Hashcat is the self-proclaimed world’s fastest CPU-based password recovery tool. It is available free of charge, although it has a proprietary codebase. Versions are available for Linux, OSX, and Windows and can come in CPU-based or GPU-based variants. Hashcat currently supports a large range of hashing algorithms, including: Microsoft LM Hashes, MD4, MD5, SHA-family, Unix Crypt formats, MySQL, Cisco PIX, and many others. The MD5 message-digest algorithm is a cryptographic hash function producing a 128-bit (16-byte) hash value, typically expressed in text …

Continue reading

Digital forensics and hardware identification

| 0 comments

I thought I would sit down and begin a series of articles surrounding digital forensics with hardware identification being the lead in. The subject of forensics is one that I personally have not placed a great deal of effort and recently I took the Computer Hacking Forensic Investigator training from EC-Council. On day one, I knew I was hooked and it may not be for reason that you may suspect. I enjoy hacking from a white hat perspective and understanding the black hats is key to being successful. Ironically on day one of the training, I quickly learned that my …

Continue reading

They Live at DEFCON22

| 0 comments

Every year in August thousands upon thousands of people flock to Las Vegas, NV for the anual DEFCON conference. This is my second year attending and I knew once I attended DEFCON21 that I was forever hooked. I cannot begin to describe what the experience is like, because the experience is what you make of it. Last year, I had fun, but I did sit back and try to determine what I should and should not do. At the end of DEFCON21, I knew that I was going to jump head first into DEFCON22 and that is exactly what I …

Continue reading

Rip DEFCON videos from YouTube

| 0 comments

Have you never attended DEFCON and want to watch hours upon hours of conference talks? You could always go the the DEFCON YouTube playlist and click your way around the hundreds of videos or you could download the videos. You could go search for a addon or extension for your favorite browser or search the myriad of software options. Downloading videos from YouTube can be simple, complex, free, or costly depending upon your experience, time, and resources. Years ago, I purchased a MacBook Pro and I also started learning more about Linux distributions such as Kali and Ubuntu. Moving away …

Continue reading

Getting started with the Mark IV WiFi Pineapple

| 0 comments

The WiFi Pineapple is an amazing and fun piece of technology. To be honest, I purchased this technology late in 2013 and I never really sat down and played with it until recently. I sat down with my MacBook Pro and in no time at all I was frustrated that I was not able to get the Pineapple working properly. My issue was either I was successful at obtaining an external IP address, but I was not successful at accessing the Pineapple’s web interface of 172.16.42.1:1471 and it took a bit of research to find out the root cause. In …

Continue reading