正在加载...
 
    Kismet For Win32  

    下载地址:http://h4k.b4n.googlepages.com/kiswin_setup.rar
    安装的时候希望大家要确定自己的设备是不是Linksys WRT54G 而且Fireware是否已经安装了OpenWRT我的WAP54G来的啊!晕死
    OWRT官方说WAP54G支持度不是很高啊~气死我啊

    kiswin32 - Kismet for Windows users - Joshua Wright/jwright@hasborg.com, with GPSD added by RenderMan/render@renderlab.net

    INTRODUCTION

    kiswin32 is a Cygwin-compiled build of Kismet for Win32 systems.  Since Windows systems cannot capture traffic in monitor mode without the assistance of commercial drivers, an alternate mechanism is necessary to provide the raw 802.11 packets Kismet needs for analysis.

    A Linksys WRT54G access point running OpenWRT firmware and the kismet_drone software is a great alternative for Windows users to leverage Kismet without much Linux experience.  An excellent resource for setting up a spare Linksys WRT54G to run Kismet is available at http://www.renderlab.net/projects/wrt54g/openwrt.html.


    After setting up the WRT54G and starting the kismet_drone software, follow the simple installation instructions in the INSTALL.txt file.


    After completing the INSTALL instructions, run the "kismet.vbs" script and provide the IP address of the WRT54G access point and the com port of your GPS.  This script will launch 3 windows - a kismet_server instance to collect packets from the WRT54G, and instance of GPSD and a few seconds later, the kismet_client interface.  When you are done with Kismet, press "Q" to quit the kismet_client software, the press "CTRL/C" to quit the kismet_server instance and GPSD instance.


    IMPORTANT NOTES

    NOTE: My Symantec Personal Firewall software generates a warning when the kismet.vbs script is executed due to how it calls an external executable (kismet_server, then kismet_client).  The code is simple if you want to take a look, but I assure you I have no malicious intent in distributing this code.  Select "Allow Always" to continue.  If someone is kind enough to donate the $400 for me to buy a code-signing digital certificate from Verisign, my PayPal account is jwright@hasborg.com.

    NOTE: If you enter an invalid IP address or if the WRT54G is not running the kismet_drone software on standard port 3501, the script will fail.  If someone wants to write a better VBScript, please send me a copy.

    NOTE: The Kismet configuration files have been edited to work for this unintended use of Kismet.  Data files are stored in the kiswin32 "data/" directory.  Only edit the configuration files if you know what you are doing.  If you are editing them, make sure they are saved in the Unix file format (e.g. edit with vi and use "set ff:unix", do not attempt to edit these files with Notepad or Wordpad!).

    NOTE: If you do nott need/want to use GPSD, just enter a bogus com port.  GPSD will throw up an error, but will not interfere with the rest of Kismet operations.

    CONTACT

    Questions, comments or concerns with kiswin32 should be directed to Joshua Wright/jwright@hasborg.com.  Do NOT contact the author of Kismet with questions regarding kiswin32!

    Questions regarding configuring the WRT54G to run the kismet_drone software or GPSD should be directed to the author of the HOWTO, referenced with the URL above.

    标签:共享,无线应用,网络安全 | 浏览数(1758) | 评论数(0) | 2007-03-17
    一次小型的WarDriving  

    今天约了废铁过来家里看看本本能不能换一个比较好的无线网卡,谁知道机器新,硬件更加新!没有办法的情况下只好打消有关更换网卡的念头转向AP的搜索!
    我家是10楼,所以在高空搜索到的AP大概到120个左右!废铁变态说要拿着本本去楼下看看有没有好点的信号,两个白痴就这样子扛着手提下去楼下了。
    10楼下来发现我的AP信号竟然覆盖到楼下,虽然不是很强,但还是在楼下搜索到!而且发现之前估计的Guangzhou Infocell 128的设备的确是在对面大楼的
    不知道为什么在对面大楼楼下搜索AP的时候,发现的AP会比较少,大概只有60个左右!而废铁的才有30多个!坐在银行的门口打算连接Infocell Ap时,Net Stumbler竟然一下子狂暴几十个没有SSID的AP(MAC地址前段是相同的)!但是无线网卡无法连接!

    另外就是在银行门口发现网件的AP~~~因为程序的原因没有测试~~~~
    问问大家是否知道Guangzhou infocell 128代表什么吗!?

    标签:网络安全 | 浏览数(1415) | 评论数(1) | 2007-03-15
    DVBBS <= 7.1.0 sp1 (BokeManage.asp) Remote SQL Injection  

    最近发现有人突然发布了有关动网论坛博客模块的注入漏洞使用方式,因为对于现有程序来说并没有发布任何安全信息以及补丁,所以Bug.Center.Team发布了非官方的安全补丁


    摘要:
    DVBBS是由海口动网先锋网络科技有限公司开发的网络社区软件。因为在论坛附带的博客模块当中存在着远程注入漏洞,导致恶意用户借此入侵网站

    影响版本:
    DVBBS 7.1.0 SP1

    不受影响版本:
    DVBBS 5.0
    DVBBS 6.0

    细节:
    因博客模块当中的关键词处没有进行严格的处理导致注入漏洞的产生

    建议:
    关闭博客功能或安装我方提过的补丁

    厂商补丁:
    目前厂商暂无提供补丁下载


    补丁下载地址:www.cnbct.org/BokeManage.rar

    标签:网络安全 | 浏览数(1677) | 评论数(0) | 2007-03-12
    TAS(地御)网站第三方身份认证系统/服务  

    TAS(地御)网站第三方身份认证系统/服务,是我们Bug.Center.Team的产品,最近没事就把产品的技术白皮书写了出来,虽然不知道是否正确和专业,不过也算是第一次的东西了,希望大家给个意见!

    晕死不知道怎么加的附件,看来i170还真的比较麻烦啊

    PDF下载
    演示录像下载

    单一认证下的安全隐患

    单一认证登陆模式受到嗅探攻击

    TAS双因素认证技术模式

    TAS双因素认证技术下受到攻击

    标签:网络安全 | 浏览数(1835) | 评论数(2) | 2007-02-11

      Powered by Haiwit