Forum latest

HD Moore to demenstrate hacking techniques
General
Written by Daniel   
Thursday, 26 July 2007 12:40
Hacking Without Exploits
— Kelly Jackson Higgins, Senior Editor, Dark Reading

JULY 25, 2007 | Renowned researcher HD Moore next week at Black Hat USA and Defcon will demonstrate powerful hacking techniques that neither exploit unpatched vulnerabilities nor zero-day bugs.

Moore says automated penetration testing tools alone can't find all vulnerabilities -- it takes a combination of in-the-trenches hands-on hacking and tools, he says. "People should use their brains to hack things, not just some program," Moore says. "Too many penetration testers rely on automated exploit tools to do their jobs for them." (See HD Moore Unplugged and Now Playing: Metasploit 3.0.)



When penetration testers focus only on exploits and security bugs, they typically miss more basic holes in their infrastructure, says Moore, who created the popular Metasploit hacking/penetration testing tool. "Pen-tests should always be targeted attacks against specific services, applications, and people. A quick scan followed by an exploit tool should not be considered a pen-test."

Moore, who is also director of security research at BreakingPoint Systems, and researcher Valsmith, co-founder of offensive-computing.net and also a Metasploit developer, will show in their "Tactical Exploitation" sessions in Las Vegas some tactical methods of attack that don't use your typical exploit code. They'll also release new modules for Metasploit as well as some other tools that help make this type of hacking easier.

"It's about breaking in without exploiting standard vulnerabilities," Moore says. "For example, abusing trust relationships, profiling a service to determine when an action is performed, and then attacking a weakness in the protocol.... MORE

Comments in the Forums. 

 

See also

None found.


Hardware | Windows | Linux | Security | Mobile Devices | Gaming
Tech Business | Editorial | General News | folding@home

Forum | Download Files

Copyright ©2001 - 2012, AOA Forums.  All rights reserved.

Alliance of Overclocking Arts

Links monetized by VigLink

Don't Click Here Don't Click Here Either