Darren shows off some nifty tricks for Netcat and a targeted brute force attack dictionary generator. Matt continues his series on Virtualization with redundancy and Shannon pimps the blog with her WordPress plugin picks. Plus the results of our Monkey Contest, the Code Challenge and this weeks easter egg hunt 😉

Download HD Download MP4 Download XviD Download WMV

Show Notes

Common User Password Profiler

The Common User Password Profiler from Remote-Exploit is a password/passphrase generator specifically targeted as an individual user. Feed it some info like names, birth dates, spouce, children and pets and it will generate individually, or along with an existing dictionary, thousands of potential passwords. Just add water, feed to your favorite brute forcer and enjoy.

From personal experience I can vouch that, while simple sounding, this would have a HIGH success rate on some of my _former_ (L)users. Administrators take note and enforce BOFH password requirements 😉

netcat – “The Swiss-army knife for TCP/IP”

When it comes to sending and receiving TCP and UDP any which way from the console nothing is more versatile or easy to use than netcat.

With a few simple commands you can use netcat to initiate chat, file transfer or even shell access in either direction between a “server” and a “client”.

The tool can be set to listen or broadcast on any port and tied together with some shell-fu almost anything is possible.

Some listener favorites include cloning hard drives over a network with dd and netcat, tailing a log across the network, port scanning, IP redirecting, or even spoofing user-agents and referrers. Internet Explorer 22 anyone?

Digininja points to this great netcat cheat sheet (PDF 128K).

What kind of crazy stuff have you done with netcat? Feedback@hak5.org

Shannon’s WordPress Plugin Picks


This plugin allows you to automatically post your new posts on the twitter website. This is good because the iPod and iPhone for example have a large amount of twitter clients to pick from. Your blog posts will arrive to people while they are walking the streets.


Socialite allows your WordPress posts to publish to Twitter, Facebook, and MySpace. Each social networking site can be enabled or disabled for publishing, and each is configured separately with their own options. Support for Short URL services such as zz.gd and Tinyurl.com is also supported.


Automatically add links to your favorite social bookmarking sites on your posts, pages and in your RSS feed. You can choose from 99 different social bookmarking sites!


MobilePress is a WordPress plugin that will render your WordPress blog on mobile handsets, with the ability to use customized themes. The plugin also allows specific themes for specific devices / mobile browsers, such as iPhone, Opera Mini, Windows CE Mobile and other generic handset browsers.

Resize at Upload Plus

The plugin will automatically resize an image upon upload, depending on the maximum width and height that you define. Gone are the days when you, or your client, will ruin a site’s layout by uploading a huge file with 25 megapixels. Be advised: there is no backup, no copy of the originally uploaded image.

WP-Cache 2.0

WP-Cache is an extremely efficient WordPress page caching system to make your site much faster and responsive. It works by caching Worpress pages and storing them in a static file for serving future requests directly from the file rather than loading and compiling the whole PHP code and then building the page from the database. WP-Cache allows to serve hundred of times more pages per second, and to reduce the response time from several tenths of seconds to less than a millisecond.

WordPress Backup

Backup the upload directory (images), current theme directory, and plugins directory to a zip file. Zip files optionally sent to email.

WP Security Scan

Scans your WordPress installation for security vulnerabilities and suggests corrective actions.

WP Ban

It will display a custom ban message when the banned IP, IP range, host name or referer url trys to visit you blog. You can also exclude certain IPs from being banned. There will be statistics recordered on how many times they attemp to visit your blog. It allows wildcard matching too.


Count every viewer and every article view for each blog entry, no matter how and where it is read: pixelstats tracks views of each blog post or page, not only on a single article page but also on each other page where the complete article is shown, i.e. the blog front page, category pages, search result page, archive pages and even RSS fee

Thanks for watching, subscribing, and most of all supporting the show. Custom commissioned WiFi Pineapples running Jasager are still available.

Leave a Reply

Your email address will not be published. Required fields are marked *



  • goarilla 6 years ago

    omg backtrack is now debian based

    it used to be slackware :(

    just like SuSE

    i’m sorry but it seems they just
    want it to go the easy route here
    and take all those repositories with them eg
    install backtrack and get all the debian
    apt-get goodness

    OK then

    but don’t come questioning me when you return into
    circular dependency hell

  • fuckdoom 6 years ago

    Ssh already supports reverse tunneling .
    You can’t really do that with NC in a NAT environment.
    Matt did a good job on the vmware.

    I don’t know too many tricks with nc anymore. I haven’t use it in a while, but you can
    send tor traffic with netcat. In case you are curious what are happening. There are many fake
    tor servers around the net.

    Instead of vmotion, have you though about integrating Bewoulf with OpenVZ or Xen?
    I never tried it, but I thought about it. I need buy some hardware for home, so I can try it.
    Most companies are grounded to Vmware for their virtualization.

    matt:2 darren:0

  • CyberSaint 6 years ago

    Hi Guys,

    As far as I can recall Microsoft licensing is based per CPU, does this mean I can install one copy of, let’s say – Windows XP Pro over and over on the VM? Or would I need a fresh license per installation?

    Awesome show!

  • @CyberSaint, Windows XP does not have the same virtual licensing considerations that Server 2003 / 2008 have.

    With Server 200X you can install 5 virtual machines with a single license.

    @fuckdoom, OpenVZ and free versions of Xen do not have the live migration, automatic load balancing, nor the High Availability monitoring.

    Most companies use VMware because it’s a tried and true production ready virtualization platform.

  • fuckdoom 6 years ago

    Hey Matt. I know that, but if you implemented SAN, you can load balance all the processes with Bewoulf with 5 to 10 old PCs. There is a possibility of making your own load balancing. High Availability monitoring is something some people can live without. If all the processes are spread out throughout the network that will give you some load balancing. It also doesn’t require any live migration, because every machines will assume they are one machine.

  • char_guerilla 6 years ago

    @Matt – I like the career advice! Get a lot of emails about ‘shortcuts’ to success, I take it? ‘How can I learn hacking/IT security/coding/network administration… in three weeks?’

  • sep332 6 years ago

    Posting here because webmaster@hak5.org doesn’t work:
    On you rhomepage, the link to download HD version of latest ep starts with “ttp://” instead of “http://”. This only happens on the main page http://hak5.org/, not on http://www.hak5.org/episodes/episode-511 .

  • Darren…always talking about the size of his dictionary…

  • Great show!

  • #1 backtrack was slax now ubuntu I am pissed

    #2 more wordpress

    #3 more shell-fu please

  • dennis 6 years ago

    everything is nooBuntu based nowadays! What were they thinking changing the best pentesting distro from trusty slackware to noob friendly ubuntu after 3 releases?

    Ah well, thats unrelated to Hak5 :) Great show again! Looking forward to the DIY virtualisation segment, as I’ve just set up my virtual servers and i’ll be waiting to see the mistakes I have made (if any ::whistle::)

    Keep up the great shows!

  • dennis 6 years ago

    Oh yeah, two things I forgot:

    1. Can someone make the damn videos stop auto-buffering as soon as the page is loaded?! Its *VERY* annoying especially as I am bandwidth limited at certain hours of the day (V.Media, UK) Quit stealing my megabytes plz!!!111one122

    2. Darren – what was the purpose of the ‘touch tinafey’ command in your netcat segment (@12:01)? from my memory, touch updates a timestamp on a file access time – so it seemed of little or no use in this case. Maybe i’m missing something obvious, but the echo and redirect works fine to create a file with contents. /shrug

  • @dennis

    Unless I’m mistaken it doesn’t start buffering until you press play.

    Touch creates the file if it doesn’t already exist. Also it’s fun to type in that context. :p

  • bloodrunsblack 6 years ago

    what do you mean “boo” debian?
    debian is awesome, and i can say that, because i actually used other linux distros that were not debian based. the fact that you try to use slackware as your argument isnt great as well, because if im not mistaken slackware has a pretty “easy route” packaging system as well

  • bloodrunsblack 6 years ago

    oh, and if im not mistaken as well, debian and debian based distros are just as stable as slackware and slackware based distros. point is I think the switch the developers of back track took to make BT4B and upcoming BT4F debian based was a mature decision. Also, the fact that many people like debian based distros has nothing to do with noobness, because people like me are out there who are also fluent with many other flavors of linux. just so happens i got lazy with distro hopping. hell as we speak im using gentoo on my laptop, and have ubuntu 9.04 on my desktop, and on my old laptop i have pardus installed. along with what I stated, i have also tried a ton more distros in my day. be it said, i havent used windows in about 4-6 years now.

    backtrack didn’t go ubuntu based it went debian based lol

  • Michaels 6 years ago

    Whats up with the top 10 for pimp’n out wp? Pretty lamo

  • dennis 6 years ago


    Yeah it does start buffering on both the main page and this contents page. (without going near the play button)

    I am currently looking at my firewall activity bars bobbing up and down, and my ethernet switch lights going crazy, and my firefox status bar “Transferring data from bitcast-a.bitgravity.com…”

    It’s buffering without me asking it to for sure.

  • dennis 6 years ago

    oops, by “contents” I meant “comments” 😛

    anyway, I must close this page, its eating all my bandwidth!

  • dennis 6 years ago



    it is ubuntu based, not “genuine” debian – ‘cat /etc/apt/sources.list’

  • @dennis

    I have confirmed this behavior with wireshark. The flash player does in fact prebuffer before any sort of interaction. I have sent a note to Revision3’s tech team and hopefully we can have this sorted soon.

    Sorry for the inconvenience!

  • fuckdoom 6 years ago

    hey dennis..
    just install no script or disable javascript…
    the player seems like javascript based. it will prevent from starting.

  • I found the Pimp my WordPress section very useful. As WordPress becomes a nice easy way to maintain certain types of sites, I like to learn about useful plugins that I may have not stumbled across yet. So, I actually vote for more WordPress segments!

  • I go out of town and fall behind and doh… http://phpreferencebook.com gets bottom 3rd’d as phpreferebook.com

    Doh! Well, the winner will still get a copy of the book, so that’s good. Hopefully others will grab the free PDF or a copy themselves when the winner is announced from the website.

  • Bah, delete above and this, commented as I was catching up. Glad the code challenge went so well, two copies are going out! Grats!

  • eduardo 6 years ago

    where can i download a free netcat i love this!!!!

  • eduardo 6 years ago

    send me an email if you know how this is my email mexico_mexican@hotmail.com thanks:)

  • eduardo 6 years ago

    can any body email me some more cool freeware i can use to hack :)

  • @eduardo

    Here is 101 hack for you. Hack Google like this:

    Type in name of software your interested in, and add download to it.

    Example “Netcat Download”

    It will hack you right into the download links of interest.

    J/k Seriously thou Google is your friend.

  • so lame!!!!

  • Thanks for sharing your thoughts on Episodes. Regards

  • Spot on with this write-up, I seriously feel this site needs far more attention. I’ll probably be back again to read more, thanks for the info!

  • This blog was… how do I say it? Relevant!! Finally I’ve found something which helped me.
    Thank you!

  • bf20h4r3ff 2 days ago

    fitflops singapore outlet Offecct has 42 people employed with sales of SEK 115 million Automotive partners include Autosport Designs, Biener Audi, Jaguar of Great Neck, Long Island Sports Cars, Manhattan Motorcars, Maserati of Long Island, Long Island Sports Cars and Roslyn Porsche Throughout the month of October, boutiques in San Francisco, Houston, Las Vegas and Maui will be showcasing the limited edition pieces as part of an event dubbed the American Icon Celebration michael kors online outlet

    fitflops on sale With over 120 offices worldwide Servcorp aims to provide an executive service to businesses and corporations alike.# # #Chanel Overtakes Louis Vuitton As Most Sought-After Global Luxury Brand in Digital Luxury Group’s World Luxury Index??? China – 2nd Edition Faddi Abboud For the finest in Louis Vuitton, Chanel, Prada, Gucci, St toms shoes store

    fitflop sale Making special solo appearances, the Ladies will be on hand at each location to promote Hennessy and be available to fans for autographs and pictures."We’re thrilled to announce the launch of the Lady Hennessy tour and to have six exceptionally beautiful, smart and diverse women on board to represent our brand," said Andy Glaser, SVP, Business at Hennessy USA All of their services are exclusively online giving their clients true flexibility and control over running their business.Servcorp is selective in choosing only the best office space in major cities worldwide Wang obtained her degree in English Literature at Fu Jen Catholic University in Taiwan and her AAS Fashion Design and Merchandising at FIT, New York fitflop factory outlet singapore

    karen millen jassen
    toms shoes for cheap
    toms shoes free shipping

  • yq21l4d1qy 2 days ago

    [url=http://tomsca.movingimagementors.org/]toms shoes sales[/url] Le siège social du Groupe est situé à Bethesda, Maryland, USA, et employait environ 146,000 personnes à fin 2008 A splendid, delicate ballet composed for the exhibition by Cao Shuci, an award winning ballerina from the National Ballet of China, was performed at the opening ceremony, captivating the guests with an artistic world of fantasy and awakening the memory of the most cherished moments in the lives of every woman.François Delage, CEO of De Beers Diamonds Jewellers, commented, We are proud to support and collaborate with these specially selected talented women and to showcase their special moments in light and more, visit RDR online at or 888 697 3725.Also find shopRDR at:Facebook: facebook/shopRDRTwitter: twitter/shopRDR YouTube: youtube/ shopRDRPinterest: pinterest/shopRDRRodeo Drive Resale (shopRDR)1 888 697 3725service(at)shopRDR(dot)comSave Big This Season with Special Package at Hotel 57 in Midtown Manhattan With Advanced Purchase [url=http://tomsca.movingimagementors.org/]sale on toms shoes[/url]

    [url=http://mcmsingapore.icanri.org/]mcm handbags sale[/url] The film will see its official release in September According to an article published by First Chair on September 16th titled TREND ALERT: Blonde Hair Trends for Fall 2013, summer blonde hair is on its way out and fall blonde trends are popping up See site for terms and conditions.About eLUXURY:Launched in June 2000, eLUXURY is the premier online fashion retailer, featuring the hottest designers, must have trends, online exclusives, accessories, beauty and children’s collections [url=http://toms.dardenplannedgiving.org/]toms canada free shipping[/url]

    [url=http://www.seofilter.org/]toms shoes singapore store[/url] Burberry ?€? 5:493 We supply guests with the most exciting products in the fashion industry "The Internet is definitely the most critical invention in this world [url=http://kmjurken.csubrotaract.org/]karen millen jas[/url]

    [url=http://tomssingapore.easttexasscore.org/]toms shoes online[/url]
    [url=http://michaelkorsbagssingapore.blogspot.com/]michael kors outlet online[/url]
    [url=http://tomsaustralia.wosba.org/]toms shoes in stores[/url]

  • ld18u8w9jl 2 days ago

    [url=http://fitflopsg.snohomishparks.org/]fitflop outlet in singapore[/url] FNO, considered the largest retail event ever, was created by Vogue, the Council of Fashion Designers of America, NYC & Company and the City of New York Couture offers a wide selection of designer handbags, jewelry, shoes, and accessories and features top name designers that include Chanel, Louis Vuitton, Hermes, Gucci, and David Yurman With a special Advanced Purchase midtown Manhattan hotel package, guests who prepay their stay will receive discounts and complimentary breakfast during their vacation in Manhattan [url=http://fitflopsaustralia.pathood.org/]fitflop mukluk sale[/url]

    [url=http://tomsca.movingimagementors.org/]toms shoes on sale[/url] By staying on the cutting edge of the trade show and exhibit industry, Condit can design and build multi dimensional exhibitions, structures, environments, studios, and digital spaces.Headquartered in Denver, Colorado and with offices around the USA and Europe, Condit’s goal is to help create lasting experiences for you and your customers Nom d’utilisateur: int02, mot de passe: int02 We all have memories of special moments that have marked the greatest emotions of our lives [url=http://tomssingapore.easttexasscore.org/]toms singapore outlet[/url]

    [url=http://fitflopmalaysia.sfcpa.org/]fitflop malaysia sale 2014[/url] 100 company and is ranked as the #1 fastest growing woman owned business and the fifteenth fastest growing business overall within the inner cities of the United States We are always open to suggestions for how to improve and develop our service, website, and product range Burberry ?€? 5:493 [url=http://mcmsingapore.icanri.org/]vintage mcm handbags[/url]

    [url=http://tomsaustralia.wosba.org/]toms shoes online australia[/url]
    [url=http://tomsaustralia.wosba.org/]toms australia store[/url]
    [url=http://tomsca.movingimagementors.org/]toms shoes online[/url]

  • bf13n6p0pj 1 day ago

    [url=http://www.seofilter.org/]toms singapore online[/url] For more information visit their website or contact a representative via email, info@studiocodency While holiday shoppers stake out the local mall or area outlet store, shopRDR invites fashion fans to purchase quality pieces from the comfort of their own home, with deals that are tough to beat.Rodeo Drive Resale (shopRDR) has built a reputation of providing amazing deals on handbags, clothing and accessories from the top designers of upscale fashion and more, visit RDR online at or 888 697 3725.Also find shopRDR at: Facebook: facebook/shopRDRTwitter: twitter/shopRDR YouTube: youtube/ shopRDRPinterest: pinterest/shopRDRRodeo Drive Resale (shopRDR) 1 888 697 3725service(at)shopRDR(dot)comTop Bloggers Choose Their Dream De Beers Diamond Engagement Rings [url=http://fitflopsingapore.sfcpa.org/]buy fitflops online[/url]

    [url=http://fitflopsingapore.sfcpa.org/]where to buy fitflop in singapore[/url] (many of which offer personal shoppers and private consultations), combined with unique décor and finishes that accentuate the Mall’s upscale atmosphere Greenstone also advises individuals to treat hair in between color sessions at the salon This summer, America’s Cup winner Oracle Team USA will defend their title when the world’s fastest sailing boats race on San Francisco Bay [url=http://fitflopsaustralia.pathood.org/]fitflop shoes clearance[/url]

    [url=http://toms.dardenplannedgiving.org/]toms shoes sale[/url] Our laptop bag is just the right size and has many easy access features like Velcro pockets The new store will feature a variety of gently used designer and high end brand clothing and accessories including designers Louis Vuitton, Prada, Gucci, Burberry, Valentino and more This piece is composed of 14kt gold with gold sundial and band [url=http://fitflopsingapore.sfcpa.org/]fitflop sandals sale[/url]

    [url=http://tomsaustralia.wosba.org/]toms shoes store[/url]
    [url=http://tomsaustralia.wosba.org/]toms shoes sale australia[/url]
    [url=http://tomsaustralia.wosba.org/]toms shoes for cheap[/url]

  • uq35r7n6pw 1 day ago

    [url=http://mcmtw.waumcph.org/]mcm台灣價格[/url] 像飛度響聲,鞋子有健康的好處。 鞋墊部分可以是真皮也可以是紡織布料。 MBT提醒你一定要注重腳步的健康。 像大多數偉大的想法,那是自私的結果。 他們以創新的設計,有利於促進更多的熱量燃燒和更柔和的肌肉一個比較新的系列鞋類產品。 [url=http://waumcph.org/]mbt鞋價格[/url]

    [url=http://mcmtw.com.tw/]mcm 包[/url] 同一個研究小組最近剛剛完成的又一項研究進一步表明,穿這種鞋可以減輕一些關節炎患者的膝部疼痛。 然而,隨著時間的逐漸過渡,該鞋的穿用者將用於它與相應行走的速度可以提高。 此外當時的MBT鞋子使用的是皮革鞋底,MBT 鞋,這種MBT工藝之今仍被廣泛使用。 [url=http://fitfloptw.cabotalpost71.com/]fitflop官網[/url]

    [url=http://fitfloptw.cabotalpost71.com/]fitflop鞋門市[/url] 鞋墊部分可以是真皮也可以是紡織布料。 因為這雙鞋產生的不穩定也是他們能幫助加強弱勢腳的肌肉,同時也可能有助於提高你的平衡。 所以在這個時刻MBT可能沒有直接的幫助你減肥,調你的身體;然而,這些製鞋企業一直在做新的研究,也許不久的某個時候,他們會產生一種鞋,實際上確實有助於增強你的腿。 [url=http://timberlandtw.verecondos.com/]timberland 登山鞋[/url]

    [url=http://timberlandtw.verecondos.com/]timberland 包包[/url]

  • yz25g4d4sa 6 hours ago

    [url=http://fitflopsaustralia.pathood.org/]fitflops online australia[/url] His work experience covers Fashion Design, Textile Design, Forecasting, Brand Development, and Marketing for such clients as Alexander McQueen, Givenchy, Paul Smith, and Versace eLUXURY boasts a prestigious brand line up that includes Louis Vuitton, Dior, Fendi, Marc Jacobs, Dolce & Gabbana, Versace, and Maison Martin Margiela ShopRDR suggests having fun experimenting with pieces such as rings, earrings and bracelets to discover the perfect outfit/accessory combination [url=http://fitflopsg.snohomishparks.org/]buy fitflop online[/url]

    [url=http://fitflopmalaysia.sfcpa.org/]fitflop sale online malaysia[/url] According to an article published by First Chair on September 16th titled TREND ALERT: Blonde Hair Trends for Fall 2013, summer blonde hair is on its way out and fall blonde trends are popping up Late summer is an ideal time for taking a wine tour, if the customer wants to experience the exquisite beauty of wineries and taste the wines Now we have complete confidence in the provenance and quality of the materials, and we’ve kept the price point accessible to a diverse audience." The company’s personalized touch is apparent, even in the names of the designs [url=http://tomsca.movingimagementors.org/]toms canada free shipping[/url]

    [url=http://karenmillen.lzsnap.org/]karen millen outlet nederland[/url] Membership to the site will range from $9.99 per month to $14.99 per month with special member discounts being offered Qualified orders are shipped for free and customers are provided tracking numbers and have access to company staff to see where their order is at all times from the point of sale to delivery HyperStream Live has also recently expanded its support of automated streaming directly from the Newtek TriCaster, extending the reach of the TriCaster to audiences on any device and enhancing streaming quality through the application of adaptive bitrate streaming [url=http://www.seofilter.org/]toms shoes online singapore[/url]

    [url=http://fitflopsingapore.sfcpa.org/]fitflop sales[/url]
    [url=http://mcmsingapore.icanri.org/]mcm backpack cheap[/url]
    [url=http://fitflopsg.snohomishparks.org/]buy fitflop online singapore[/url]

  • Saved as a favorite, I really like your web site!