PenTest

Syndicate content
While this list is intended for "professionals", participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.
Updated: 11 weeks 1 day ago

Re: Bluetooth testing...

Thu, 2008-08-07 12:37
Posted by Joshua Wright on Aug 07

Serg B wrote:
| Thanks for all replies so far, just a quick update with more detail...
| I am planning to be using a Linux based laptop with a USB bluetooth
| dongle...
|
| Not sure if the equipment is right or not, so any feedback on that
| front is also appreciated.

The tools mentioned...

Categories: Mailing Lists

Re: Bluetooth testing...

Thu, 2008-08-07 10:39
Posted by Taras P. Ivashchenko on Aug 07

Thanks for link, it is realy useful!

Nikhil Wagholikar wrote:
| Hello Serg B,
|
| You can have a look at Bluetooth Penetration Testing framework at the
| URL http://bluetooth-pentest.narod.ru/
|
| This framework contains everything about Bluetooth, right from its
| working, technology,...

Categories: Mailing Lists

Re: Bluetooth testing...

Thu, 2008-08-07 08:45
Posted by Orlin Gueorguiev on Aug 7

Hi Serg,
apparently there will be something about security in Black Hat 2008.
http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1324335,00.html?track=sy160

Cheers,
Orlin

On Thursday 07 August 2008 01:45:26 Serg B wrote:
> Could somebody please point me to some...

Categories: Mailing Lists

SQL injection ( and being a pen tester means being good in every area)

Thu, 2008-08-07 07:46
Posted by mark mark on Aug 7

Hi,

I'm doing a pentest for a client's web app:

Vulnerable URL:
 http://www.client.com/email.asp?id=1

So far I have enumerated the following by appending the corresponding queries:

1. databases: or 1=convert(int,(SELECT DB_NAME(0toN)))
2. users: or 1=convert(int, (SELECT TOP 1 name...

Categories: Mailing Lists

Re: Bluetooth testing...

Thu, 2008-08-07 06:39
Posted by Mark Owen on Aug 7

I've had decent luck with Bluediving. Some of the tools that come
with it is broken, but a little research you can easily find the
working binaries or source.
http://bluediving.sourceforge.net/

On Wed, Aug 6, 2008 at 7:45 PM, Serg B <sergeslists_at_gmail.com> wrote:
> Could...

Categories: Mailing Lists

Re: Bluetooth testing...

Thu, 2008-08-07 01:13
Posted by Serg B on Aug 7

Hi All,

Thanks for all replies so far, just a quick update with more detail...
I am planning to be using a Linux based laptop with a USB bluetooth
dongle...

Not sure if the equipment is right or not, so any feedback on that
front is also appreciated.

   Thanks,
...

Categories: Mailing Lists

RE: Bluetooth testing...

Thu, 2008-08-07 00:06
Posted by Roni Bachar on Aug 7

Hi serg

Try bloover - on your phone.

Bluesnarfer- linux

Read:
http://www.thebunker.net/resources/bluetooth

Roni Bachar
Penetration Team Manager
www.avnet.co.il

-----Original Message-----
From: listbounce_at_securityfocus.com [mailto:listbounce_at_securityfocus.com] On Behalf Of...

Categories: Mailing Lists

Re: Bluetooth testing...

Wed, 2008-08-06 23:47
Posted by Robin Wood on Aug 7

2008/8/7 Serg B <sergeslists_at_gmail.com>:
> Could somebody please point me to some resources about Bluetooth
> security and penetration testing.

Josh Wright has done some good stuff:

http://www.youtube.com/watch?v=1c-jzYAH2gw
...

Categories: Mailing Lists

Re: Bluetooth testing...

Wed, 2008-08-06 23:40
Posted by Luca.carettoni on Aug 07

Here you have: http://bluetooth-pentest.narod.ru/
You can find docs as well as exploits for well-known vulnerabilities.

Cheers,
Luca "ikki"

-----Original message-----
From: "Serg B" sergeslists_at_gmail.com
Date: Thu, 07 Aug 2008 01:45:26 +0200
To:...

Categories: Mailing Lists

Re: Bluetooth testing...

Wed, 2008-08-06 23:39
Posted by the.soylent on Aug 07

hi,
maybe this helps:
http://wiki.thc.org/BlueMaho
http://www.nruns.com/_en/security_tools.php

/soylent

Serg B schrieb:
> Could somebody please point me to some resources about Bluetooth
> security and penetration testing.
>
>
> Thanks
> Serg
>
>...

Categories: Mailing Lists

Re: web app pentest report

Wed, 2008-08-06 22:44
Posted by Jason on Aug 6

I don't have a template however the report must have the standards. At
the basic level, exec summary, breakdown of areas assessed as per
OWASP with the number of issues found in each as kind of a summary,
and then detailed list. Here's the key, and one which will make a
difference... for each...

Categories: Mailing Lists

Re: Bluetooth testing...

Wed, 2008-08-06 21:05
Posted by Nikhil Wagholikar on Aug 7

Hello Serg B,

You can have a look at Bluetooth Penetration Testing framework at the
URL http://bluetooth-pentest.narod.ru/

This framework contains everything about Bluetooth, right from its
working, technology, specification till its security and relevant
tools list.

Best of Luck !!

---...

Categories: Mailing Lists

Re: Bluetooth testing...

Wed, 2008-08-06 20:51
Posted by Angel Garcia Moreno on Aug 7

http://trifinite.org/ is a good site where you can find a lot of resources

2008/8/7 Serg B <sergeslists_at_gmail.com>:
> Could somebody please point me to some resources about Bluetooth
> security and penetration testing.
>
>
> Thanks
> Serg
>
>...

Categories: Mailing Lists

Bluetooth testing...

Wed, 2008-08-06 15:45
Posted by Serg B on Aug 7

Could somebody please point me to some resources about Bluetooth
security and penetration testing.

Thanks
    Serg

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in
Securing Web...

Categories: Mailing Lists

web app pentest report

Wed, 2008-08-06 15:37
Posted by ChElAnO on Aug 6

hi guys.
This is one of my first posts but i've been reading the list for a
long time now. I have learned a lot just from reading the questions
and answers posted in this list, its great.
I am a computer science student and i'm very into computer security
for a time now. Thanks to the little...

Categories: Mailing Lists