{"id":222,"date":"2012-09-21T06:11:29","date_gmt":"2012-09-21T06:11:29","guid":{"rendered":"http:\/\/www.gironsec.com\/blog\/?p=222"},"modified":"2016-03-14T17:56:53","modified_gmt":"2016-03-14T17:56:53","slug":"updates-and-stuff","status":"publish","type":"post","link":"https:\/\/www.gironsec.com\/blog\/2012\/09\/updates-and-stuff\/","title":{"rendered":"Updates and stuff"},"content":{"rendered":"<p>Wow, what a crazy month. I&#8217;ve been up to a lot of things. For starters, I applied to Nessus for a part time vuln research analyst position, beat the phone screen and beat the 3 app challenges they sent me, but didn&#8217;t get the job and they gave me no real answer, even when I emailed the head guy and asked for some semblance of an idea as to why I was rejected. The challenge front page asked nicely in the challenge not to publish findings, however I asked nicely for a reason why I wasnn&#8217;t picked. Two wrongs don&#8217;t make a right, but 3 rights make a left. Spoilers for whoever applies at nessus coming soon.<\/p>\n<p>Aside from that I got accepted for ToorCon to do a talk on my Keepass snarfer app I was going on about last month.<br \/>\n<a href=\"http:\/\/sandiego.toorcon.org\/index.php?option=com_content&#038;task=section&#038;id=2&#038;Itemid=10\">Check it:<\/a><\/p>\n<p>As for the snarfer itself, its done. I even made a nice front end for it:<br \/>\n<a href=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/keepasssnarfer.png\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/keepasssnarfer.png\" alt=\"\" title=\"keepasssnarfer\" width=\"293\" height=\"299\" class=\"alignnone size-full wp-image-224\" \/><\/a><\/p>\n<p>As for showing off the code itself, <a href=\"http:\/\/www.gironsec.com\/code\/Casctuscon_password_snarfer_code.tgz\">Here it is<\/a>.<\/p>\n<p>Today at work it was rather slow. I decided to write my own HTTP Brute Forcer since Brutus shows up on every AV scanner from here to china. I named the program Brutus 2 &#8211; Electric Boogaloo. If you get that reference, you are awesome. Here it is side by side with the old one:<\/p>\n<p><a href=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/checkmeout.png\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/checkmeout-300x158.png\" alt=\"\" title=\"checkmeout\" width=\"300\" height=\"158\" class=\"alignnone size-medium wp-image-223\" srcset=\"https:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/checkmeout-300x158.png 300w, https:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/checkmeout-1024x539.png 1024w, https:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/checkmeout.png 1462w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>I love .net. It allows for cranking out apps an an alarming rate. As for source code \/ downloads, I&#8217;ve only worked on this app today so I need more time. As it stands, only basic http auth works and its NOT multithreaded (yet). Expect updates soon as well for that. <\/p>\n<p>So what is that, 4 updates in the future? The keepass snarfer, the brute forcer, spoiling Nessus \/ Tenable&#8217;s hack tests, and what am I missing? Oh right, the 0day. I&#8217;ve been so busy I forgot to even submit. I do plan on showing it off, but I wanted to go into depth about how I found it, so I&#8217;m being rather lazy about it.<\/p>\n<p>Thats it for now. Have some random pic like usual:<br \/>\n<a href=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/1272727032069.png\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2012\/09\/1272727032069.png\" alt=\"\" title=\"1272727032069\" width=\"386\" height=\"1444\" class=\"alignnone size-full wp-image-225\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wow, what a crazy month. I&#8217;ve been up to a lot of things. For starters, I applied to Nessus for a part time vuln research analyst position, beat the phone screen and beat the 3 app challenges they sent me, but didn&#8217;t get the job and they gave me no real answer, even when I [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[4],"tags":[],"_links":{"self":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/222"}],"collection":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/comments?post=222"}],"version-history":[{"count":6,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/222\/revisions"}],"predecessor-version":[{"id":1227,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/222\/revisions\/1227"}],"wp:attachment":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/media?parent=222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/categories?post=222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/tags?post=222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}