July 16, 2010

Penetration-Test Plan (Farsi)

First of all, I've made some changes to blog and added few items. Hope these changes make the blog more user-friendly for non-rss visitors :) 

During long weeks that I was passing my conscription, I had a lot of free times beside the usual and daily works I could/had-to do in the research lab I was working in. These free times were good opportunities for studying and also writing. I wrote few papers and articles during those times and have already published some of them in this blog. Here`s another output from those days :)

This is kind of guidline, plan, framework or whatever you name it, to help novice users plan for a pen-test/assessment project. It is by no mean a complete/standard compliance/revised source, but just one of hundreds of available materials and refrences, available about the topic.



Also, this is NOT entirely provided by me. I've just grabbed a good source, and tried to translate/modify it for persian users, so the credit goes for vulnerabilityassessment.co.uk guys and others who've contributed to original work. Maybe the next time my students in pen-test training classes ask for the big easy to use how-to, this piece of information satisfy them for some days. 

File should be opened with Xmind, which is available free for download. Xmind is not my favorite brain-storming software, but using persian fonts forced me to switch to xmind, and now I`m happy with it. download it through below link. Ah, and please do not ask for an image export of the map. current version of Xmind is buggy and do not allow exporting of a map in this size. export simply fails! I've contacted developers few months ago about the case, but honestly forgot to investigate the case with them. So feel free to contact them, ask for a fix, export entire map in JPEG and let me know to upload it here ;)

Download the pen-test/assessment map
[updated: Finally could find a trick to make an image export!]
Click for full-size map



I`m releasing the complete source of plan , in easy to re-distribute form and with no restriction, BUT using this material without mentioning it`s source (vulnerabilityassessment.co.uk & me) is not allowed. A lot of friends has blamed me for sharing too much through what I write and release in persian, but I still believe in freedom and flow of information and hope to help some real looking minds, as I've learned what I know the same way, by reading from others...

June 24, 2010

تمام شد

دیروز بالاخره خدمت سربازی تمام شد و کارت منحوس پایان خدمت را گرفتم. بماند که که اولین و مفید ترین استفاده ایی که میتوان از این کارت کرد را در همان 45 دقیقه اول بعد از کارت انجام دادم...
خوشحال نیستم. نارحت هم نیستم. فقط کمی از این کلافه و عصبی هستم که 18 ماه از عمر ما چرا باید بیخود و به این شکل و البته بصورت کاملآ اجباری تلف شود؟  حتی برای من که بجز چند ماه اول، کل دوره خدمت ام  و نوع کاری که انجام می دادم نیز کاملآ با علاقه و تخصص و کاری که پیش از آن و در کنار آن انجام می دادم یکی بود، اما باز هم شدیدآ احساس می کنم که این مدت جز استهلاک  فکری هیچ خروجی مفیدی برای من نداشت. البته تغییر مهمی در من ایجاد کرد. پیش از سربازی روزانه حداقل 10-12 ساعت کار مفید می کردم اما این روزها حتی اگر تمام تلاش خودم را هم کرده باشم این خروجی مفید به 3-4 ساعت نخواهد رسید. مودبانه این مشکل را برخی به اسم سندورم کالیبر تحتانی می شناسند که امیدوارم هر چه زود تر در من درمان شود!
بعد از خدمت هم منتظر به نتیجه رسیدن یکسری تغییر و تحولات نیمه-اساسی هستم که امیدوارم تا یکی دو ماه آینده به نتیجه برسد و بعد از آن به سمع و نظر بینندگان و خوانندگان محترم خواهم رساند.
فعلآ قصد دارم بصورت حاد از سندرومی که به آن مبتلا هستم لذت ببرم و دکان نیز تا اطلاع ثانوی تعطیل است، حتی برای شما دوست گرامی!

June 12, 2010

2 New {old!} Articles

Trying to cleanup some of old pending works, I found two articles I've authored before that are not published publicly in blog. Both of them are written in Farsi.

First one is about foot-printing, talking about some basic and usual methods for information gathering phase of a penetration-test. This has been part of a larger write-up, but this is the only section that I'm authorized to release. I also warn about this article and note that I`m NOT responsible for how readers use these contents. As I've used real-world samples in this article, I though about masking them before release. But, considering all of gathered information being already public, I decided to leave it as it is. So DO NOT blame me why I've not masked samples.

Second and much dated one, is about hardening Microsoft SQL Server 2000 and is was written back in 2006. Considering SQL 2005 it`s kind ouf out-dated. but anyway, releasing it won`t hurt  and some people may find it useful. 

Third one...Nah, let`s leave third one for later post ;) watch for another release, maybe in next week.

you can download them from below links. Comments are welcome & appreciated, as always :)