mailing list archives
Stuff you might have missed in the CANVAS Ecosystem
From: Dave Aitel <dave () immunityinc com>
Date: Tue, 14 Oct 2008 12:35:33 -0400
-----BEGIN PGP SIGNED MESSAGE-----
D2's latest exploit pack has a couple cool tools in it:
1. a malicious PDF file creator
2. a malicious Java Applet
If you're doing client side penetration tests, sometimes no exploit is
the best exploit. Both of these are "one click to own" things.
Immunity uses the D2 pack against our clients when we do penetration
tests. No one can write everything!
And of course Gleg continues to produce interesting remotes in things
like J2EE servers. Luckily no one uses those, right? At this point
they have 280 additional modules for CANVAS which almost doubles the
size of CANVAS's standard exploit modules.
And there are more third-party packs on the way! The value of these
tools is in the content built on top of them.
(hahaha () me at using the word ecosystem. Such a Microsofty word!)
P.S. Everyone should have the cojones to post their static analysis
responses to the list!
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
-----END PGP SIGNATURE-----
Dailydave mailing list
Dailydave () lists immunitysec com
- Stuff you might have missed in the CANVAS Ecosystem Dave Aitel (Oct 14)