TorryCrass.com

  • About
  • Gallery

Linux

Security

Locate PHP Web Shells on a Linux Web Server

A while ago I had put together a quick script to check files in a web directory for possible web shells. I was in a training class and looking for my information on this last week and it seems I've lost it. As such, it's time to put it up again Read more…

By Torry Crass, 11 years11 years ago
Scripting

Check if Linux Needs a Reboot

One of the best parts of a Linux OS is that you can often patch on the fly without a need for reboot afterwards. The only thing that does definitively need a reboot is after a kernel patch. Sometimes, it isn't possible to issue the reboot right away, so the system Read more…

By Torry Crass, 11 years11 years ago
Scripting

FindMyHash Output Capture Script Hash Brown

FindMyHash is a great utility for checking hashes across various sites for pre-determined hash values, accepting both single hashes and hash files with support for a large variety of hash types (MD4, MD5, SHA1, SHA256, RMD160, LM, NTLM, MYSQL, CISCO7 or JUNIPER). Unfortunately, the native tool doesn't currently offer the Read more…

By Torry Crass, 11 years11 years ago
Scripting

Log Parsing Script for Shell Shock

The released script will take a given log directory, normally your website log directory, and search it for attempts to exploit the server using the recently released GNU Bourne Again Shell (bash) vulnerability also known as Shell Shock.  Once it identifies these entries, it will output them into a separate Read more…

By Torry Crass, 11 years ago
Security

Bash and Shell Shock Today, The Good, But Mostly Just Bad

A few days ago I posted about a nasty vulnerability pertaining to GNU Bourne Again Shell, otherwise known as bash,  The vulnerabilities still exist in unpatched systems and the scope of what could be affected is still expanding. The good news is a few vendors have provided updates clarifying that Read more…

By Torry Crass, 11 years11 years ago
Security

Holey Bash Batman! No Really, It Has Holes (CVE-2014-6271)

UPDATED: 09/26/2014 – 01:14 EST – Added vulnerability validation code This exploit may have bigger holes than even the Bat Cave.  CVE-2014-6271 (Credit to Stephane Chazelas for discovery) was publicly announced yesterday, September, 24th and some articles are already calling this bug a larger security hole than the recent Heartbleed SSL Read more…

By Torry Crass, 11 years11 years ago
Helpful Commands

List Locked Accounts in Linux

So you’re facing a system or security audit and you need to quickly print a list of accounts for the auditor as well as their statuses. Depending on your setup, this could be a trivial task. In other cases, especially with a passwd instance that doesn’t support the -a option, Read more…

By Torry Crass, 11 years11 years ago

Posts navigation

Previous 1 2 3 4 … 8 Next
Categories
  • Business (1)
  • Helpful Commands (23)
  • Notes (2)
  • Poetry (38)
  • Quips (3)
  • Scripting (6)
  • Security (19)
  • Technical (73)
  • Updates & News (9)
Valuable Products

Affordable Linode VPS

Help Others With Kiva

0.5GB Extra Storage with OneDrive

2GB Free Storage With Dropbox

 

Copyright & Image Usage
Content and images on this site are property of Torry Crass or their respective owners where cited or referenced.
Some images used through public domain licensing and obtained via http://www.publicdomainpictures.net/

© 2010 - 2018 TorryCrass.com

  • Gallery
  • NMP License v1.0
Hestia | Developed by ThemeIsle