Phocean.net

Computer Security Blog

Menu

Skip to content
  • Blog
  • Archives
  • Code
  • Docs
  • About
  • Twitter
  • RSS

Quick tip: harden your ARP table the easy way (Linux)

ARP spoofing is a good old attack on LAN and still a devastating one, leading to trafic interception (MiTM). You may want to make sure that nobody is tricking on you at office, at a security conference, at you local coffee shop, etc. Yet, most networks do not have port security and ARP inspect on…
Continue Reading

Defense, Security arp, arp spoofing, mac address, NetworkManager August 14, 2015 by phocean.

Installation of Metasploit on Fedora 21 / 22

Update 2015/08/04: Works on Fedora 22 too. I recently applied the exact same procedure with success. A quick update from a previous post for setting Metasploit on Fedora 21, the latest version. It is mainly a copy and paste, except for a few typo fixes and some changes on the Ruby part. The good news is that…
Continue Reading

Pentesting, Security Fedora, Linux, Metasploit February 10, 2015 by phocean.

Testing Heartbleed vulnerability

No fresh news, but I had been wanting to test the Heartbleed vulnerability for a while and just missed time. I used the following quick setup: Debian 7.0 virtual machine as a vulnerable host Heartleech tool. There are many other tools around, but this one was suggested to me by a coworker, who used it successfully during a…
Continue Reading

Pentesting, Security Debian, heartbleed, pentest, SSL July 14, 2014 by phocean.

Joomla brute force

I released a new tool there. It is a Ruby script that is able to brute force recent versions of Joomla. Enjoy!

Pentesting, Security bruteforce, Joomla, pentest July 12, 2014 by phocean.

RF fun with a SDR

So this post will be the first of a series on fun “hacking” hardware that I own. I just received my RTL-SDR to play with radio frequencies. This one is based on a RTL2832U chipset and a R820T tuner. My choice was in part influenced by this review. Note that this kind of device isa receiver, so it…
Continue Reading

Hardware, Security gqrx, Radio, RF, SDR April 24, 2014 by phocean.

Mimikatz offline, as a Volatility plugin!

I just tested the Mimikatz plugin for Volatility and it worked very well on a Windows 7 dump: Good job ;-)

Forensic, Pentesting, Security LSA, Mimikatz, Volatility April 19, 2014 by phocean.

Post navigation

← Older posts
Newer posts →
Proudly powered by WordPress