<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in BlackBag 0.9.1 - New link and minor fixes</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Thu, 05 Mar 2009 16:37:55 -0000</lastBuildDate><item><title>Re: BlackBag 0.9.1 - New link and minor fixes</title><link>http://www.matasano.com/log/1048/blackbag-091-new-link-and-minor-fixes/#comment-6923043</link><description>and... sorry, it's back alive now!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eric_Monti</dc:creator><pubDate>Thu, 05 Mar 2009 16:37:55 -0000</pubDate></item><item><title>Re: BlackBag 0.9.1 - New link and minor fixes</title><link>http://www.matasano.com/log/1048/blackbag-091-new-link-and-minor-fixes/#comment-6133234</link><description>And the link to blackbag is dead again.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Apneet Jolly</dc:creator><pubDate>Tue, 10 Feb 2009 01:39:34 -0000</pubDate></item><item><title>Re: BlackBag 0.9.1 - New link and minor fixes</title><link>http://www.matasano.com/log/1048/blackbag-091-new-link-and-minor-fixes/#comment-2323936</link><description>Since blackbag is resurfacing I thought I'd repost a small example of the deezee part in action: &lt;br&gt;[code]&lt;br&gt;remote un-passworded root access in IBM's totalstorage ds400 storage thingie, like this: &lt;br&gt;# download blackbag from &lt;a href="http://www.matasano.com/download/blackbag-0.9.1.tgz" rel="nofollow"&gt;http://www.matasano.com/download/blackbag-0.9.1...&lt;/a&gt;&lt;br&gt;# download firmware for totalstorage ds400 &lt;br&gt;lort# wget -q &lt;a href="http://parker.vslib.cz/MIRRORS/ftp.adaptec.com/tmp0001/oem/ibm/IBM_TotalStorage_DS_Series_FW_v4.15.zip" rel="nofollow"&gt;http://parker.vslib.cz/MIRRORS/ftp.adaptec.com/...&lt;/a&gt; &lt;br&gt;lort# unzip -q IBM_TotalStorage_DS_Series_FW_v4.15.zip &lt;br&gt;lort# rm IBM_TotalStorage_DS_Series_FW_v4.15.zip &lt;br&gt;lort# ls &lt;br&gt;Copy of IBM_TotalStorage_DS_Series_FW_v4.15.upgrade &lt;br&gt;README_Single_IBM_TotalStorage_DS_Series_FW_v4.15.txt.TXT &lt;br&gt;lort# mv Copy\ of\ IBM_TotalStorage_DS_Series_FW_v4.15.upgrade ds400.4.15.fw &lt;br&gt;lort# bkb deezee ds400.4.15.fw &lt;br&gt;Scanning file ds400.4.15.fw for compressed components &lt;br&gt;Compressed size: 21898976 bytes &lt;br&gt;Compressed segment found. Expanded to 2181580 bytes &lt;br&gt;Compressed segment found. Expanded to 16777216 bytes &lt;br&gt;Compressed segment found. Expanded to 67108864 bytes &lt;br&gt;lort# mkdir /mnt/1 /mnt/2 &lt;br&gt;lort# mdconfig -a -t vnode -f ./ds400.4.15.fw.1 -u 1 &lt;br&gt;lort# mdconfig -a -t vnode -f ./ds400.4.15.fw.2 -u 2 &lt;br&gt;lort# mount_ext2fs /dev/md1 /mnt/1 &lt;br&gt;lort# mount_ext2fs /dev/md2 /mnt/2 &lt;br&gt;&lt;br&gt;# part where you look for vulnerabilities intentionally skipped &lt;br&gt;&lt;br&gt;lort# cat /mnt/2/etc/shadow &lt;br&gt;root::11430:0:10000:::: &lt;br&gt;bin:*:8902:0:10000:::: &lt;br&gt;daemon:*:8902:0:10000:::: &lt;br&gt;ftp:*:8902:0:10000:::: &lt;br&gt;named:*:8902:0:10000:::: &lt;br&gt;nobody:*:0:0:10000:::: &lt;br&gt;user::11430:0:10000:::: &lt;br&gt;manager::11430:0:10000:::: &lt;br&gt;administrator::11430:0:10000:::: &lt;br&gt;operator::11430:0:10000:::: &lt;br&gt;lort# cat /mnt/2/etc/inetd.conf &lt;br&gt;# See "man 8 inetd" for more information. &lt;br&gt;# &lt;br&gt;# If you make changes to this file, either reboot your machine or send the &lt;br&gt;# inetd a HUP signal: &lt;br&gt;# Do a "ps x" as root and look up the pid of inetd. Then do a &lt;br&gt;# "kill -HUP ". &lt;br&gt;# The inetd will re-read this file whenever it gets that signal. &lt;br&gt;# &lt;br&gt;#        &lt;br&gt;# &lt;br&gt;# If you want telnetd not to "keep-alives" (e.g. if it runs over a ISDN &lt;br&gt;# uplink), add "-n". See 'man telnetd' for more deatails. &lt;br&gt;# &lt;br&gt;telnet stream tcp nowait root /usr/sbin/tcpd in.telnetd &lt;br&gt;cli stream tcp nowait root /usr/sbin/tcpd &lt;br&gt;in.telnetd -L /etc/eurologic/bin/cli &lt;br&gt;login stream tcp nowait root /usr/sbin/tcpd in.rlogind &lt;br&gt;shell stream tcp nowait.500 root /usr/sbin/tcpd in.rshd -Lh &lt;br&gt;# &lt;br&gt;# End. &lt;br&gt;lort# grep ^telnet /mnt/2/etc/services &lt;br&gt;telnet 6000/tcp &lt;br&gt;&lt;br&gt;# sit back and laugh at the passwordless accounts and the undocumented telnet daemon. [/code]</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">kokanin</dc:creator><pubDate>Mon, 09 Jun 2008 03:16:33 -0000</pubDate></item><item><title>Re: BlackBag 0.9.1 - New link and minor fixes</title><link>http://www.matasano.com/log/1048/blackbag-091-new-link-and-minor-fixes/#comment-2323937</link><description>I see that the README file talks about a util called sextract for reading and concatting TCP payloads which would be really cool, from the description, but is not included in blackbag.  Any chance of including it?&lt;br&gt;&lt;br&gt;Thanks,&lt;br&gt;&lt;br&gt;Martin</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Martin</dc:creator><pubDate>Sat, 24 May 2008 15:57:03 -0000</pubDate></item></channel></rss>