|------------------------------------------| | _ _ _____ | Who I am? I'm No-Trace a guy from Germany. I'm interested in web security || \ | | ___ |_ _| __ __ _ ___ ___ | lockpicking, cracking wlans,... . I don't like those fucking kids who deface/delete/ || \| |/ _ \ _____| || '__/ _` |/ __/ _ \ | destroy any sites. || |\ | (_) |_____| || | | (_| | (_| __/ | I'm not against those portals like milw0rm,secunia,... , but vulnerabilities should not ||_| \_|\___/ |_||_| \__,_|\___\___| | be released as exploits only as a Poc! | | |------------------------------------------| Contact: admin[at]no-trace.cc
Just some of my notes/source codes / ... :> ~~~~~~~~~~~Projects~~~~~~~~~~~~~ Exploit Search: http://exploit.no-trace.cc/ Mail forwarding: http://mail.no-trace.cc/ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~Posts~~~~~~~~~~~~~~~ Uploading a shell to a ftp(stealer) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~Scripts~~~~~~~~~~~~~~ Challenge Level 1: http://webctf.kilu.de/ctf_level1.php Hex-Dec Converter: http://no-trace.cc/hex-dec.php ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~News~~~~~~~~~~~~~~~ 29.08.09 : - mail service online! 27.08.09 : - mail service in progress 22.08.09 : - challenge added 18.08.09 : - Links added - Description added - Added small "post" area 17.08.09 : - Blog deleted - pasted some notes ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~Wlan cracking~~~~~~~~~~ - aircrack airmon-ng airmon-ng start rausb0 airodump-ng rausb0 airodump-ng -c [channel] -w [network.out] –bssid [bssid] rausb0 aireplay-ng -1 0 -a [bssid] -h 00:11:22:33:44:66 -e [essid] [device] airodump-ng -w /root/Desktop/dump rausb0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~Web hacking~~~~~~~~~~~ rfi & lfi: ../ %00 encoded null byte sql injection: union+select+ /**/union/**/select +--+ --+ +-- f /* +--+# version() @@version or '=' Text to Hex : http://www.swingnote.com/tools/texttohex.php Hex to Text : http://www.string-functions.com/hex-string.aspx Sql Injection Cheat Sheet: http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/ http://pentestmonkey.net/blog/mysql-sql-injection-cheat-sheet/ http://pentestmonkey.net/blog/oracle-sql-injection-cheat-sheet/ http://pentestmonkey.net/blog/mssql-sql-injection-cheat-sheet/ http://pentestmonkey.net/blog/postgres-sql-injection-cheat-sheet/ http://pentestmonkey.net/blog/ingres-sql-injection-cheat-sheet/ http://pentestmonkey.net/blog/db2-sql-injection-cheat-sheet/ http://pentestmonkey.net/blog/informix-sql-injection-cheat-sheet/ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~Challenges~~~~~~~~~~~~ http://h0yt3rstuff.phpnet.us/ctf1.php http://h0yt3rstuff.phpnet.us/ctf2.php?count=1 http://84.23.65.183/hackit/ http://www.mibs-challenges.de/index.php ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~Interesting stuff & people~~~ https://security-shell.ws/forum.php (English) http://eddy14.freeunix.net/blog/ (German) http://novusec.com/ (English / German) http://www.hackersenigma.com/ (English) http://netzpolitik.org/ (German) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~To do~~~~~~~~~~~~~~ - delete milw0rm profile !? - slap h0yt3r ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~