The BlackPage

January 20, 2006

The BlackPage highlights breaking security research submitted by leading corporate professionals, government experts, and members of the underground hacking community.


On The BlackPage: Post-Exploit Automation
by Jeff Moss posted January 20, 2006

I’m in. Now what? spoonm and company originally built a framework to research and automate advanced exploit techniques. Over time, they realized that the framework could go far beyond just the initial entrance vectors. At Black Hat Federal, spoonm and skape will talk about their new work advancing the state of the art in automated payload delivery. Watching them hide a VNC server inside your running text editor or the LSA service is pretty cool and scary at the same time.


Post-Exploitation Shellcode

by spoonm & skape posted January 20, 2006

We have recently been on a new shellcode kick, but this time it's not about making them smaller. We're currently working on building very powerful new post-exploitation shellcode and toolkits, and a very powerful unified API to expose their functionality. This will allow us to diverge from pre-canned payloads, which will in turn allow users to quickly build powerful and portable post-exploitation tools. We have built strongly upon our Windows DLL injection, and are working on extending similar functionality to the land of Unix. We're also working hard on the next version of Metasploit, which follows this same philosophy of embedability and extensibility, allowing users to build their own tools on top of our framework. Our previous work was all about exploit frameworks. In our new approach we are really building more of a hacker tool framework, allowing very strong automation and customization.

upcoming events

USA Briefings & Training 2007
July 28-August 2
Las Vegas

Japan Briefings & Training 2007
October 23-26
Tokyo

DC Briefings & Training 2008
February
Washington DC Area

Europe Briefings & Training 2008
March 25-28
Amsterdam

USA Briefings & Training 2008
August 2-7
Las Vegas

the BlackPage Archives

See past BlackPage articles.


the BlackPage archives

Black Hat Logo
(c) 1996-2007 Black Hat