<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DamianGrace.com</title>
	<atom:link href="http://www.damiangrace.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.damiangrace.com</link>
	<description>Behind the scenes</description>
	<lastBuildDate>Wed, 17 Feb 2010 04:24:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Core Impact Pro with Metasploit Integration</title>
		<link>http://www.damiangrace.com/2010/02/core-impact-pro-with-metasploit-integration/</link>
		<comments>http://www.damiangrace.com/2010/02/core-impact-pro-with-metasploit-integration/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 04:21:32 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[Core Impact]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Core]]></category>
		<category><![CDATA[db-autopwn]]></category>
		<category><![CDATA[Impact]]></category>
		<category><![CDATA[integration]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[Pro]]></category>
		<category><![CDATA[Rapid]]></category>
		<category><![CDATA[RPT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Technologies]]></category>
		<category><![CDATA[Test]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=224</guid>
		<description><![CDATA[Core Security Technologies have just announced that the next version of Core Impact Pro (due out in April) will support Metasploit integration. It&#8217;s not a bad list of things you will be able to do too.
*  Bring a system compromised during testing with Metasploit into the IMPACT environment and deploy an IMPACT Pro Agent. The [...]]]></description>
			<content:encoded><![CDATA[<p>Core Security Technologies have just announced that the next version of Core Impact Pro (due out in April) will support Metasploit integration. It&#8217;s not a bad list of things you will be able to do too.</p>
<blockquote><p>*  Bring a system compromised during testing with Metasploit into the IMPACT environment and deploy an IMPACT Pro Agent. The Agent is a patented, syscall proxy payload that allows users to:</p>
<p>1. Launch IMPACT Pro’s full range of automated penetration testing capabilities from the compromised system.<br />
2. Leverage IMPACT’s broad selection of commercial-grade exploits, plus multiple pre- and post-exploitation capabilities for in-depth, comprehensive attack replication.<br />
3. Pivot penetration tests to other systems, mimicking an attacker’s attempts at identifying and exploiting paths of weakness to backend systems and data.</p>
<p>* Use IMPACT Pro’s automated Rapid Penetration Test (RPT) to exploit vulnerabilities, then launch Metasploit’s db-autopwn feature and subsequently upload the results back into IMPACT Pro. This allows users with less training and expertise to view Metasploit testing information within the IMPACT environment.</p></blockquote>
<p>I for one am looking forward to playing with this <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a title="Press Release" href="http://www.coresecurity.com/content/core-impact-metasploit-project" target="_blank">Press Release</a></p>
<p><a title="Blog" href="http://blog.coresecurity.com/2010/02/16/integrating-core-impact-pro-with-metasploit/" target="_blank">Blog Announcement </a></p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2010%2F02%2Fcore-impact-pro-with-metasploit-integration%2F&amp;linkname=Core%20Impact%20Pro%20with%20Metasploit%20Integration"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2010/02/core-impact-pro-with-metasploit-integration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where have I gone???</title>
		<link>http://www.damiangrace.com/2010/02/where-have-i-gone/</link>
		<comments>http://www.damiangrace.com/2010/02/where-have-i-gone/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 23:03:41 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=221</guid>
		<description><![CDATA[I know I&#8217;ve been a bit quite lately and I figured I owe you all an explanation&#8230;
But you&#8217;re not going to get one&#8230; well not a full one anyway.
I have had some pretty dramatic changes happening this year thus far. These are causing a re-evaluation to what I do and what has become my primary [...]]]></description>
			<content:encoded><![CDATA[<p>I know I&#8217;ve been a bit quite lately and I figured I owe you all an explanation&#8230;</p>
<p>But you&#8217;re not going to get one&#8230; well not a full one anyway.</p>
<p>I have had some pretty dramatic changes happening this year thus far. These are causing a re-evaluation to what I do and what has become my primary focus. There will be some big announcements this year, but I can&#8217;t give you anything just yet.</p>
<p>So I&#8217;m still here and I haven&#8217;t forgotten about you. I am just busier than ever trying to organize some stuff that I hope you will like <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2010%2F02%2Fwhere-have-i-gone%2F&amp;linkname=Where%20have%20I%20gone%3F%3F%3F"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2010/02/where-have-i-gone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Great Australian Internet Blackout</title>
		<link>http://www.damiangrace.com/2010/01/the-great-australian-internet-blackout/</link>
		<comments>http://www.damiangrace.com/2010/01/the-great-australian-internet-blackout/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 06:20:14 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[australia]]></category>
		<category><![CDATA[black out]]></category>
		<category><![CDATA[blackout]]></category>
		<category><![CDATA[censorship]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[internetblackout]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=217</guid>
		<description><![CDATA[In protest of the Australian governments plans to impose internet censorship, I will be taking part in the Great Australian Internet Blackout.
This site will be blacked out between now and the 29th of January 2010.
If you would also like to support the cause, visit www.internetblackout.com.au to find out how to black out your site.
]]></description>
			<content:encoded><![CDATA[<p>In protest of the Australian governments plans to impose internet censorship, I will be taking part in the Great Australian Internet Blackout.</p>
<p>This site will be blacked out between now and the 29th of January 2010.</p>
<p>If you would also like to support the cause, visit www.internetblackout.com.au to find out how to black out your site.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2010%2F01%2Fthe-great-australian-internet-blackout%2F&amp;linkname=The%20Great%20Australian%20Internet%20Blackout"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2010/01/the-great-australian-internet-blackout/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pentesting with Backtrack &#8211; An OSCP course review</title>
		<link>http://www.damiangrace.com/2009/12/pentesting-with-backtrack-an-oscp-course-review/</link>
		<comments>http://www.damiangrace.com/2009/12/pentesting-with-backtrack-an-oscp-course-review/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 04:44:08 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[Offensive Security Certified Professional (OSCP)]]></category>
		<category><![CDATA[Access]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[course]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[exam]]></category>
		<category><![CDATA[GWAPT]]></category>
		<category><![CDATA[Ironport]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[modules]]></category>
		<category><![CDATA[Offensive Security]]></category>
		<category><![CDATA[OSCP]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=204</guid>
		<description><![CDATA[I got the news this morning that I have successfully completed the OSCP exam. It has been a hard 4 month of exams, training and study for me with my CISSP, OSCP and GWAPT and this was most certainly the icing on the cake. It is without a doubt the hardest, most realistic, most valuable [...]]]></description>
			<content:encoded><![CDATA[<p>I got the news this morning that I have successfully completed the OSCP exam. It has been a hard 4 month of exams, training and study for me with my CISSP, OSCP and GWAPT and this was most certainly the icing on the cake. It is without a doubt the hardest, most realistic, most valuable course/exam I have ever taken.</p>
<p>I found it so worthwhile I’ve decided to give it a review. So let’s start from the start and I&#8217;ll give you as much detail as I think I am legally allowed.</p>
<p><strong>Getting Access</strong></p>
<p>First of all the sign up process is not quite what I have experienced with other certifications. I psyched myself up, sat down with my bosses’ credit card and was all ready to spend some of his money&#8230; but no&#8230; The guys at offensive-security don’t want your money straight off. Instead they email you with an openVPN configuration attachment with the purpose confirming that you can actually connect to their labs before taking your (or your bosses <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ) hard earned money.</p>
<p>Now a point of note for those located behind an Ironport Mail Gateway: I waited days for the response email and heard nothing. I was actually starting to get a rather cranky at their (lack of) service. I mean, I had employer dollars to spend. I managed to get in contact with them and deduced that Ironport* have given the Offensive-Security mail server IP a reputation of -3 which is well under our drop by reputation thresholds. After rearranging with them to send all correspondence to my Gmail account we were away.</p>
<p><strong>The Course</strong></p>
<p>So with email working and the VPN confirmed operational we arranged payment for the course (which again was a problem due to the credit card not being in my name&#8230; but we won’t go into that) and I got my material and 60 days lab time. What you actually get for your $700USD is quite impressive.</p>
<ul>
<li>One PDF containing the course lessons.</li>
<li>One set of SWF video files where Muts walks you through all but the last few of the course modules.</li>
<li>24/7 access to the Labs for 60 days via VPN which is full of vulnerable devices to attack; and,</li>
<li>Hours of guaranteed pain, suffering, joy, frustration and exhilaration.</li>
</ul>
<p>The combination of these materials creates a very comprehensive learning environment. Overall there are 16 modules of delightfully wicked goodness. The PDF covers each of them in fair detail but the videos are the real meat of the course. Each module covers a specific aspect of penetration testing.  These range from the information gathering stage, all the way to keeping access and rootkits.</p>
<p>Muts, through the videos, keeps you company as you make your way through the course material. He pushes you to learn more and he provides links to more information in case you would like to expand your knowledge in any of the areas that can’t be covered in depth through a 5 minute presentation. I found him to be very articulate and the videos are of quite high quality.</p>
<p>The videos only cover from chapters 1 – 13 and then you are left with the PDF to guide you through the rest. This turns out ok however as the last 3 modules are more of a brief and require more external reading through the provided links rather than the total immersion that is the previous modules.</p>
<p>Most modules allow for hands on practice through the labs. This was of the most benefit to me as this is how I learn best. Often I find you can read something that sounds simple and easy but when it comes to actually putting it into practice things just don’t go according to plan. Hours were spent by me working through the exercises and trying to smooth out the lumps and bumps and believe me&#8230; there were plenty of lumps and bumps <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Lastly once you have finished the modules you are free to (and actively encouraged to) attack the rest of the lab network with the exception of the other student machines. A list of final challenges is set upon you and the goal is simply to get root or admin access to each device. This is quite a lot of fun, and far from easy.</p>
<p><strong>The Exam</strong></p>
<p>The first thing I have to say about this exam is that it’s a <strong>really</strong> tough exam. You are given 24 hours to gain root or admin access on 5 devices. From what I have seen in the field, these devices are as close to the real deal as you can get.</p>
<p>It was a lot of fun when I wasn’t stressing to the hilt. The different ways to break into these devices was very good and bound to stretch your mind.</p>
<p>What else can I say about this exam&#8230; well not much. I’m not allowed to&#8230; sorry <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>After you successfully pass the exam you are given access to a forum just for OSCP’s where you are free to discuss all aspects of the exam and course. I found it interesting that students worked out multiple different ways to get into the same devices. This brings on my only real point of angst about this course. I was unable to crack one device, so as soon as I got access to the forums I jumped in to find out how to crack this nut. It turns out everyone before me (that posted) had done it using a particular exploit that works on a particular port (could I be any more obscure <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> ).  So moving back to my pain point&#8230; That port was not even open on that device during my exam!!! So, I still have no idea how to get into this device.</p>
<p><strong>Conclusion</strong></p>
<p>This is a brilliant course!</p>
<p>I have done many courses both from vendors and course providers such as SANS and the Offensive-Security. While a lot of the other courses have been great, the Pentesting with Backtrack (OSCP) has easily provided me with the most value. I walk away from this course actually feeling like I have achieved something solid. This is both due to the time it takes to work through the course at your own pace and the quality of the content.</p>
<p>This course is by no means for beginners into IT. It works through some very complex topics and concepts. It is recommended that you have at least some coding experience as well as an operational knowledge of Windows and Linux.</p>
<p>For $700USD I think it’s a must for anyone in the IT security industry to work towards and I expect to see the certification gain serious traction and the respect it deserves in the near future. I know I’d be looking for an OSCP if I was hiring.</p>
<address>*Ironport is an awesome product and this is the first time I have any real issues with it in 2+ years.</address>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2009%2F12%2Fpentesting-with-backtrack-an-oscp-course-review%2F&amp;linkname=Pentesting%20with%20Backtrack%20%26%238211%3B%20An%20OSCP%20course%20review"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2009/12/pentesting-with-backtrack-an-oscp-course-review/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>CISSP certification in three  easy  months</title>
		<link>http://www.damiangrace.com/2009/11/cissp-certification-in-three-easy-months/</link>
		<comments>http://www.damiangrace.com/2009/11/cissp-certification-in-three-easy-months/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 08:35:42 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[CISSP]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=190</guid>
		<description><![CDATA[2.5 months of near continuous study, 6 hours and 250 torturous multiple choice questions, 3 weeks of nervously waiting for the exam results while freaking out every time I read my emails and 3 long months of having no life. This is what it took me to get through the CISSP certification. 
But I did [...]]]></description>
			<content:encoded><![CDATA[<p>2.5 months of near continuous study, 6 hours and 250 torturous multiple choice questions, 3 weeks of nervously waiting for the exam results while freaking out every time I read my emails and 3 long months of having no life. This is what it took me to get through the CISSP certification. </p>
<p><strong>But I did it!!!</strong> I received confirmation this morning that I passed the CISSP exam. <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I&#8217;ll send off my Endorsement form and CV tomorrow and then I should be <strong>officially CISSP Certified</strong>. </p>
<p>I have to say a big thanks to my wonderful wife and boys for putting up with me, and the lack of time I could dedicate to them while I was studying&#8230; although strangely, they seem to be happier <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> . </p>
<p>Hey, only two more exams to go before Christmas&#8230; maybe I&#8217;ll be able to spend Christmas Day with the family <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2009%2F11%2Fcissp-certification-in-three-easy-months%2F&amp;linkname=CISSP%20certification%20in%20three%3Cdel%20datetime%3D%222009-11-17T07%3A53%3A43%2B00%3A00%22%3E%20%20easy%20%3C%2Fdel%3E%20months"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2009/11/cissp-certification-in-three-easy-months/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Update: pattern2code.v.03</title>
		<link>http://www.damiangrace.com/2009/11/update-pattern2code-v-03/</link>
		<comments>http://www.damiangrace.com/2009/11/update-pattern2code-v-03/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 00:51:54 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[Coding]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=184</guid>
		<description><![CDATA[Last week I had it pointed out to me by Jamie Gadd that v.02 was fatally flawed and, in fact, did not work at all.
Due to this embarrassing incident I have recoded pattern2code based on some code that Jamie provided. He is somewhat of a stella coder so this version looks much nicer than anything [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I had it pointed out to me by Jamie Gadd that v.02 was fatally flawed and, in fact, did not work at all.</p>
<p>Due to this embarrassing incident I have recoded pattern2code based on some code that Jamie provided. He is somewhat of a stella coder so this version looks much nicer than anything I have provided thus far.</p>
<p>The new code can be downloaded from the <a href="http://www.damiangrace.com/toolspage/" target="_blank">tools section</a> and more information about the script can be found <a href="http://www.damiangrace.com/2009/11/metasploit-pattern_create-rb-code-creator/" target="_blank">here</a>.</p>
<p>Special thanks to Jamie for the feedback and showing my some new coding tricks.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2009%2F11%2Fupdate-pattern2code-v-03%2F&amp;linkname=Update%3A%20pattern2code.v.03"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2009/11/update-pattern2code-v-03/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pattern2Code V.02 &#8211; Update</title>
		<link>http://www.damiangrace.com/2009/11/pattern2code-v-02-update/</link>
		<comments>http://www.damiangrace.com/2009/11/pattern2code-v-02-update/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 11:05:30 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[Coding]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[pattern2code]]></category>
		<category><![CDATA[pattern_create.rb]]></category>
		<category><![CDATA[python]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=162</guid>
		<description><![CDATA[UPDATE: Jamie Gadd has nicely pointed out that the version 0.02 of this code is so flawed that it doesn&#8217;t even come close to working. I am at a loss to explain how I managed to upload such dysfunctional code. This code has now been removed from the site. The current version can be found [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE: Jamie Gadd has nicely pointed out that the version 0.02 of this code is so flawed that it doesn&#8217;t even come close to working. I am at a loss to explain how I managed to upload such dysfunctional code. This code has now been removed from the site. The current version can be found <a href="http://www.damiangrace.com/toolspage/">here</a>.</strong><br />
While the first version of Pattern2Code was functional, I was far from happy with the actual code. This version doesn&#8217;t add any new features, but the code is somewhat nicer. I have updated this <a href="http://www.damiangrace.com/2009/11/metasploit-pattern_create-rb-code-creator/">post</a> with v.02 and both versions can now be downloaded from the <a href="http://www.damiangrace.com/toolspage/">tools section</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2009%2F11%2Fpattern2code-v-02-update%2F&amp;linkname=Pattern2Code%20V.02%20%26%238211%3B%20Update"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2009/11/pattern2code-v-02-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Metasploit pattern_create.rb 2 Code Creator</title>
		<link>http://www.damiangrace.com/2009/11/metasploit-pattern_create-rb-code-creator/</link>
		<comments>http://www.damiangrace.com/2009/11/metasploit-pattern_create-rb-code-creator/#comments</comments>
		<pubDate>Sun, 01 Nov 2009 08:53:20 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[Coding]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[c]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[create]]></category>
		<category><![CDATA[creator]]></category>
		<category><![CDATA[framework]]></category>
		<category><![CDATA[pattern]]></category>
		<category><![CDATA[pattern2code]]></category>
		<category><![CDATA[pattern_offset.rb]]></category>
		<category><![CDATA[patter_create.rb]]></category>
		<category><![CDATA[Perl]]></category>
		<category><![CDATA[python]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=120</guid>
		<description><![CDATA[UPDATE: Pattern2Code is now at V.03. This page has been updated with that version of code.
Pattern_create.rb is a great little tool that can be found in the /tools directory of your Metasploit framework. It is used to create a pattern of characters to a specified length which you can then inject into applications as a [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE: Pattern2Code is now at V.03. This page has been updated with that version of code.</strong></p>
<p>Pattern_create.rb is a great little tool that can be found in the /tools directory of your Metasploit framework. It is used to create a pattern of characters to a specified length which you can then inject into applications as a buffer overflow. Its sister script, pattern_offset.rb, is then  used to identify how many bytes from the start of the string a particular part of the pattern occurred.</p>
<p>pattern2code.py is a script I created to save me manually modifying the pattern_create.rb patterns to fit into my fuzzing code. Its simple to use and will output the pattern into either Python, Perl or C code.</p>
<p>Running the script is as simple as piping the output from pattern_create.rb into the pattern2code.py and specifying a name for the buffer, a length of each split, and the language output.</p>
<p>The instructions below can also be found in the script if required;</p>
<p>[+] Usage: ./pattern2code.py &lt;buffername&gt; &lt;length&gt; &lt;languagename&gt; &lt;input&gt;<br />
[+] &lt;buffername&gt; = Custom buffer name<br />
[+] &lt;length&gt; = Length of each split<br />
[+] &lt;languagename&gt; = Perl, Python or C<br />
[+] &lt;input&gt; piped input from pattern_create.rb</p>
<p>Output examples:</p>
<blockquote><p><strong># ./pattern_create.rb 180 | ./splitter.py overflowbuff 50 python</strong></p>
<p>overflowbuff = &#8220;Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab&#8221;<br />
overflowbuff += &#8220;6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2A&#8221;<br />
overflowbuff += &#8220;d3Ad4Ad5Ad6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9&#8243;<br />
overflowbuff += &#8220;Af0Af1Af2Af3Af4Af5Af6Af7Af8Af9&#8243;</p></blockquote>
<p><span style="color: #999999;">^ Python code output with a 50 character split.</span></p>
<p><span style="color: #999999;"><br />
</span></p>
<blockquote><p><strong># ./pattern_create.rb 260 | ./splitter.py newbuffer 40 perl</strong></p>
<p>my $newbuffer =<br />
&#8220;Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2A&#8221; .<br />
&#8220;b3Ab4Ab5Ab6Ab7Ab8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac&#8221; .<br />
&#8220;6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad6Ad7Ad8Ad9&#8243; .<br />
&#8220;Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2A&#8221; .<br />
&#8220;f3Af4Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag&#8221; .<br />
&#8220;6Ag7Ag8Ag9Ah0Ah1Ah2Ah3Ah4Ah5Ah6Ah7Ah8Ah9&#8243; .<br />
&#8220;Ai0Ai1Ai2Ai3Ai4Ai5Ai&#8221;;</p></blockquote>
<p><span style="color: #999999;">^ Perl code output with 40 a character split</span></p>
<p><span style="color: #999999;"><br />
</span></p>
<blockquote><p><strong># ./pattern_create.rb 260 | ./splitter.py newbuffer 55 c</strong></p>
<p>unsigned char newbuffer[] =<br />
&#8220;Aa0Aa1Aa2Aa3Aa4Aa5Aa6Aa7Aa8Aa9Ab0Ab1Ab2Ab3Ab4Ab5Ab6Ab7A&#8221;<br />
&#8220;b8Ab9Ac0Ac1Ac2Ac3Ac4Ac5Ac6Ac7Ac8Ac9Ad0Ad1Ad2Ad3Ad4Ad5Ad&#8221;<br />
&#8220;6Ad7Ad8Ad9Ae0Ae1Ae2Ae3Ae4Ae5Ae6Ae7Ae8Ae9Af0Af1Af2Af3Af4&#8243;<br />
&#8220;Af5Af6Af7Af8Af9Ag0Ag1Ag2Ag3Ag4Ag5Ag6Ag7Ag8Ag9Ah0Ah1Ah2A&#8221;<br />
&#8220;h3Ah4Ah5Ah6Ah7Ah8Ah9Ai0Ai1Ai2Ai3Ai4Ai5Ai&#8221;;</p></blockquote>
<p><span style="color: #999999;">^ C code output with a 55 character split.</span></p>
<p>Here is the code for your enjoyment <img src='http://www.damiangrace.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="codecolorer-container python default" style="overflow:auto;white-space:nowrap;border: 1px solid #9F9F9F;width:550px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br />17<br />18<br />19<br />20<br />21<br />22<br />23<br />24<br />25<br />26<br />27<br />28<br />29<br />30<br />31<br />32<br />33<br />34<br />35<br />36<br />37<br />38<br />39<br />40<br />41<br />42<br />43<br /></div></td><td><div class="python codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap"><span style="color: #808080; font-style: italic;">#!/usr/bin/env python</span><br />
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">sys</span><br />
<br />
<span style="color: #ff7700;font-weight:bold;">if</span> <span style="color: #008000;">len</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#41;</span> <span style="color: #66cc66;">!</span>= 4:<br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;++++++++++++++++++++++++++++++++++++++++++++++++++++++++&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;+ &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;+&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;+ &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; pattern2code.py V0.03 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;+&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;+ Created by Damian Grace - http://www.damiangrace.com +&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;+ &nbsp; &nbsp; &nbsp; Restructure based on code by Jamie Gadd&nbsp; &nbsp; &nbsp; &nbsp; +&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;+ &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;+&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;++++++++++++++++++++++++++++++++++++++++++++++++++++++++<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] Usage: ./pattern2code.py &lt;buffername&gt; &lt;length&gt; &lt;languagename&gt; &lt;input&gt;&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] &lt;buffername&gt; = Custom buffer name&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] &lt;length&gt; = Length of each split&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] &lt;languagename&gt; = Perl, Python or C&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] &lt;input&gt; piped input from pattern_create.rb<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] This program is for use with pattern_create.rb which comes&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] bundled with Metasploit in the tools directory.&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] To make it executable: chmod 755 ./pattern2code.py&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] While its in the tools directory run it like so:&quot;</span><br />
&nbsp; &nbsp; <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;[+] ./pattern_create.rb 2000 | ./pattern2code.py buffer python<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><br />
&nbsp; &nbsp; <span style="color: #dc143c;">sys</span>.<span style="color: black;">exit</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">2</span><span style="color: black;">&#41;</span><br />
<br />
<span style="color: #808080; font-style: italic;"># read buffer name and split length</span><br />
buffername = <span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#91;</span>1<span style="color: black;">&#93;</span><br />
splitlength = <span style="color: #008000;">int</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#91;</span><span style="color: #ff4500;">2</span><span style="color: black;">&#93;</span><span style="color: black;">&#41;</span><br />
<br />
<span style="color: #808080; font-style: italic;"># read pattern and remove newline</span><br />
pattern = <span style="color: #dc143c;">sys</span>.<span style="color: black;">stdin</span>.<span style="color: black;">read</span><span style="color: black;">&#40;</span><span style="color: black;">&#41;</span><span style="color: black;">&#91;</span>:-<span style="color: #ff4500;">1</span><span style="color: black;">&#93;</span><br />
<br />
<span style="color: #808080; font-style: italic;"># language options</span><br />
language = <span style="color: black;">&#123;</span><span style="color: #483d8b;">&quot;perl&quot;</span>:<span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;my $&quot;</span>+buffername+<span style="color: #483d8b;">&quot; = <span style="color: #000099; font-weight: bold;">\t</span><span style="color: #000099; font-weight: bold;">\&quot;</span>&quot;</span>+pattern<span style="color: black;">&#91;</span>:splitlength<span style="color: black;">&#93;</span>, <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\&quot;</span> .<span style="color: #000099; font-weight: bold;">\n</span><span style="color: #000099; font-weight: bold;">\t</span><span style="color: #000099; font-weight: bold;">\t</span><span style="color: #000099; font-weight: bold;">\&quot;</span>&quot;</span>, <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\&quot;</span>;<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><span style="color: black;">&#41;</span>, <br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span style="color: #483d8b;">&quot;python&quot;</span>:<span style="color: black;">&#40;</span>buffername+<span style="color: #483d8b;">&quot; = <span style="color: #000099; font-weight: bold;">\t</span><span style="color: #000099; font-weight: bold;">\&quot;</span>&quot;</span>+pattern<span style="color: black;">&#91;</span>:splitlength<span style="color: black;">&#93;</span>,<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\&quot;</span><span style="color: #000099; font-weight: bold;">\n</span>&quot;</span>+buffername+<span style="color: #483d8b;">&quot; += <span style="color: #000099; font-weight: bold;">\&quot;</span>&quot;</span>,<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\&quot;</span><span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><span style="color: black;">&#41;</span>,<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span style="color: #483d8b;">&quot;c&quot;</span>:<span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;unsigned char &quot;</span>+buffername+<span style="color: #483d8b;">&quot;[] = <span style="color: #000099; font-weight: bold;">\&quot;</span>&quot;</span>+pattern<span style="color: black;">&#91;</span>:splitlength<span style="color: black;">&#93;</span>,<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\&quot;</span> <span style="color: #000099; font-weight: bold;">\\</span><span style="color: #000099; font-weight: bold;">\n</span><span style="color: #000099; font-weight: bold;">\t</span><span style="color: #000099; font-weight: bold;">\t</span><span style="color: #000099; font-weight: bold;">\&quot;</span>&quot;</span>, <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\&quot;</span>;<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><span style="color: black;">&#41;</span><span style="color: black;">&#125;</span><br />
<br />
<span style="color: #808080; font-style: italic;"># parse args</span><br />
start,mid,end = language.<span style="color: black;">get</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#91;</span><span style="color: #ff4500;">3</span><span style="color: black;">&#93;</span>, <span style="color: black;">&#40;</span><span style="color: #483d8b;">''</span>,<span style="color: #483d8b;">''</span>,<span style="color: #483d8b;">''</span><span style="color: black;">&#41;</span><span style="color: black;">&#41;</span><br />
<br />
<span style="color: #808080; font-style: italic;"># main</span><br />
<span style="color: #dc143c;">sys</span>.<span style="color: black;">stdout</span>.<span style="color: black;">write</span><span style="color: black;">&#40;</span>start<span style="color: black;">&#41;</span><br />
<span style="color: #ff7700;font-weight:bold;">for</span> x <span style="color: #ff7700;font-weight:bold;">in</span> <span style="color: #008000;">xrange</span><span style="color: black;">&#40;</span>splitlength,<span style="color: #008000;">len</span><span style="color: black;">&#40;</span>pattern<span style="color: black;">&#41;</span>,splitlength<span style="color: black;">&#41;</span>:<br />
&nbsp; &nbsp; <span style="color: #dc143c;">sys</span>.<span style="color: black;">stdout</span>.<span style="color: black;">write</span><span style="color: black;">&#40;</span>mid+pattern<span style="color: black;">&#91;</span>x:x+splitlength<span style="color: black;">&#93;</span><span style="color: black;">&#41;</span><br />
<span style="color: #dc143c;">sys</span>.<span style="color: black;">stdout</span>.<span style="color: black;">write</span><span style="color: black;">&#40;</span>end<span style="color: black;">&#41;</span></div></td></tr></tbody></table></div>
<p>The code can also be downloaded <a title="pattern2code" href="http://www.damiangrace.com/tools/pattern2code/pattern2code.v.03.tar" target="_self">here</a></p>
<p>Enjoy!</p>
<p>P.S. I would love to hear feedback on how to improve my code so please leave a comment&#8230;</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2009%2F11%2Fmetasploit-pattern_create-rb-code-creator%2F&amp;linkname=Metasploit%20pattern_create.rb%202%20Code%20Creator"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2009/11/metasploit-pattern_create-rb-code-creator/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Web App Hacking &#8211; SANS Sydney 2009</title>
		<link>http://www.damiangrace.com/2009/10/web-app-hacking-sans-sydney-2009/</link>
		<comments>http://www.damiangrace.com/2009/10/web-app-hacking-sans-sydney-2009/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 21:28:51 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[advanced]]></category>
		<category><![CDATA[app]]></category>
		<category><![CDATA[australia]]></category>
		<category><![CDATA[cole]]></category>
		<category><![CDATA[eric]]></category>
		<category><![CDATA[essentials]]></category>
		<category><![CDATA[ethical]]></category>
		<category><![CDATA[facilitator]]></category>
		<category><![CDATA[gsec]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[johannes]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sydney]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[ullrich]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=113</guid>
		<description><![CDATA[Well my payment is in and I have now officially been confirmed as the facilitator for the &#8220;Web App Penetration Testing and Ethical Hacking&#8221; (what a mouthful) course at this years SANS Sydney event. This year it&#8217;s being taught by Johannes Ullrich who is an amazingly knowledgable man in this area and it is the [...]]]></description>
			<content:encoded><![CDATA[<p>Well my payment is in and I have now officially been confirmed as the facilitator for the &#8220;Web App Penetration Testing and Ethical Hacking&#8221; (what a mouthful) course at this years SANS Sydney event. This year it&#8217;s being taught by Johannes Ullrich who is an amazingly knowledgable man in this area and it is the first time it has been run as a 6 day course in Australia so I am really looking forward to it.</p>
<p>There is another interesting track being run in Australia for the first time. &#8220;Advanced Security Essentials &#8211; Enterprise Defender&#8221; being taught by Eric Cole is the next step up from the GSEC (Security Essentials) course. It looks really interesting, and being taught by Eric Cole is sure to be fun.</p>
<p>Kick off is in less than two weeks (9th &#8211; 14th Nov) so if you haven&#8217;t already booked you&#8217;d better hurry.</p>
<p>For those that are going, i&#8217;ll see you there!</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2009%2F10%2Fweb-app-hacking-sans-sydney-2009%2F&amp;linkname=Web%20App%20Hacking%20%26%238211%3B%20SANS%20Sydney%202009"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2009/10/web-app-hacking-sans-sydney-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Privilege Escalation Techniques</title>
		<link>http://www.damiangrace.com/2009/10/windows-privilege-escalation-techniques/</link>
		<comments>http://www.damiangrace.com/2009/10/windows-privilege-escalation-techniques/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 04:49:06 +0000</pubDate>
		<dc:creator>Damian</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[Administrator]]></category>
		<category><![CDATA[Domain]]></category>
		<category><![CDATA[Escalation]]></category>
		<category><![CDATA[Local]]></category>
		<category><![CDATA[pass the hash]]></category>
		<category><![CDATA[Privilege]]></category>
		<category><![CDATA[Standard]]></category>
		<category><![CDATA[User]]></category>

		<guid isPermaLink="false">http://www.damiangrace.com/?p=101</guid>
		<description><![CDATA[During one of my tours through the deep dark net this afternoon, I stumbled across a couple of very interesting blog posts by Scott Sutherland at NetSPI.com. Scott explains 10 different ways to move in Windows from Standard User to Local Administrator and then from Local Administrator to Domain Admin. Interesting stuff, and well worth [...]]]></description>
			<content:encoded><![CDATA[<p>During one of my tours through the deep dark net this afternoon, I stumbled across a couple of very interesting blog posts by Scott Sutherland at NetSPI.com. Scott explains 10 different ways to move in Windows from Standard User to Local Administrator and then from Local Administrator to Domain Admin. Interesting stuff, and well worth the read.</p>
<p><a href="http://www.netspi.com/blog/2009/10/05/windows-privilege-escalation-part-1-local-administrator-privileges/">Local Administrator Privilege Escalation Techniques</a></p>
<p><a href="http://www.netspi.com/blog/2009/10/05/windows-privilege-escalation-part-2-domain-admin-privileges/">Domain Admin Privilege Escalation Techniques</a></p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.damiangrace.com%2F2009%2F10%2Fwindows-privilege-escalation-techniques%2F&amp;linkname=Windows%20Privilege%20Escalation%20Techniques"><img src="http://www.damiangrace.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.damiangrace.com/2009/10/windows-privilege-escalation-techniques/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
