Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Hacking SSH and Certificate Based Authentication - Hak5

Loading...

Sign in or sign up now!
10,215
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Dec 9, 2009

SSH Feedback
After bantering about our upcoming travels to Waynesville, Missouri and Toronto, Ontario and a little griping about zipit segmentation faults, we get into your feedback on recent SSH segments.

Dzaztur recommends Gnome SSH Tunnel Manager. It's a sleek front-end for managing SSH tunnels, port redirects and more. Tunnel configuration is stored in a simple XML formal, great for portability, and the tunnels can be managed individually through one simple GUI. Thanks for the tip Dzaztur

Lozo points out that Mac OS-X has SSH built into the terminal, much like Linux. So true. We banter with Paul-the-camera-guy about the Mac OS-X kernel, which turns out is XNU -- an accronym for X is Not Unix. So there ya go!

Sp4m says if you're running Firefox over SSH you might want to look into remote DNS lookups. By default DNS lookups aren't done through the proxy. This can be resolved by typing about:config in the address bar, and enabling the network.proxy.socks_remote_dns setting. Thanks Sp4m.

And Finally Post_Break from IamTheKiller.net points us to Secret Socks -- a SSH Socks Proxy GUI front-end for Mac OS-X that he likes a ton more than SSHTunnel 1.6. [Edit: We made a mistake and called it Secure Socks in the segment]

And finally we go kitteh before moving on...

00:36

Play
Certificate Authentication for SSH
In this segment Darren explains why certificate authentcation is a bajillion times better than password authentcation and demonstrates the configuration using Ubuntu 9.10 and an Interceptor running OpenWRT Kamikaze. This forum thread details setting up authorized_keys with Dropbear -- the SSH daemon that comes standard on OpenWRT.

Next week we'll be breaking this down with a little Man-in-the-middle action. Until then send your feedback to darren@hak5.org

09:30

Play
Build a Free Linux Live USB Key in Minutes
When it comes to finding the right Linux distribution for you it's best to try a bunch out. And what better way then to make some bootable Live Linux USB keys? Shannon demonstrates Linux Live USB -- a Windows tool that makes it super simple to build a Linux USB key in minutes. It features automatic distribution downloading AND Persistence!

22:08

Play
Questions on Wordpress Theme Hacking
Ricky writes:

I just recently started using wordpress, and I am having alot of trouble trying to design a layout for it, I was wondering if you had any references or anything to help me learn how to do this, I understand HTML and only know a little of PHP. Any help would be greatly Appreciated.
Darren recommends setting up a local LAMP stack, that is to say the web server, database and scripting language to support a Wordpress install. The easiest way to get started is with either WAMP on Windows or XAMPP on just about any platform.

The Wordpress install is dead simple.

Mostly I use PHP.net as my go to resource, but we'll also be hooking you up with a copy of Mario Lurig's PHP Reference: Beginner to Intermediate PHP5. Hope that helps. :)

The Wordpress Codex is also an invaluable resource when you really get your hands dirty when theme code. Things like the loop and trim_excerpt are well detailed. Once you start learning the Wordpress functions you'll realize what a powerful content management platform it really is.

And finally we recommend Wordpress.org/Support for their forums. If you know of a better forum for Wordpress Theme Hacking please let us know!

  • likes, 10 dislikes

Link to this comment:

Share to:

Top Comments

  • Nice tits as well lol

  • she is so cute ;)

see all

All Comments (36)

Sign In or Sign Up now to post a comment!
  • OMG I am in love with shannon she soooo cute. A girl that luvs technology u can get bettet than that

  • I am disappointed by this video. What the anchor did was a KEY-BASED-USER-AUTHENTICATION and not CERTIFICATE-BASED-AUTHENTICATI­ON. And we have to remember authentication is needed for for Host and User and both can be certificate based. Now unless you want to challange the various types of certificates..I am referring to x509.V3 certificates.

    Please correct this video.

    As far as passwordless authentication goes, there are many ways ... Kerberos is another nice way.

  • @m00sicman89 : yeah,...! exactly...! :)

  • Ever wonder why most women think most men are pigs? It's because of the jerks who make comments like these... Grow up.

  • Pause at 05:54 and look at darrens face

  • Whats that goto express song from!!

  • all you guys are sick pervs!!

  • She is my sister and become naughty benaughtyman.info

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more