[blog.rayfoo] Infosec, DFIR, tech geekery, thoughts and whatnot

5Feb/100

Installing Ubuntu 7.04 server in VirtualBox

As part of the fiddling around with Metasploit, there came the need to install a victim box to test things on (we don't want to be attacking a live site don't we?  Especially one that we don't own...), so here's a modification of the instructions found at Offensive Security's walkthrough for our needs.

I wanted to run the victim machines in VirtualBox instead of VMware Player, and after some experimentation and Googling around with the crashing issue, here're the instructions on how to get things up and running.

Host OS: Ubuntu 9.10
VirtualBox 3.1.2
Guest OS: Ubuntu 7.04 Server

3Feb/100

Time to prepare…

Reading Jeremiah Grossman's recent post on what's happening, and what's to come reminds me of what network security used to be like: attacks on the infrastructure has caused plenty of damages, and thus the effort focused on defending against them.  This has led to the current (relatively more matured) state of the network and hosts security domain.

It's hard for people to care about anticipated dangers, till it becomes true on a large scale or when it happens to them, sad but true.

Nonetheless, it's high time industries/companies/individuals start to look seriously into attacks at the web application level, because it has been the path of least resistance for the attackers for a long time already.

And time for the whitehats to really prepare the answers needed by the masses in time to come.

31Jan/100

OFFER AT NO MINIMUM COST!

Ok, I probably didn't put the point across properly previously, so let's try again:

For those who do use public WiFi, here's a good chance to protect your web traffic from sniffers at ZERO MINIMUM COST! :)

For more details contact me at secureme{@T}rayfoo[dot]info or you could read another really lengthy post here.