BackTrack successor Kali Linux launched

Outwardly, Kali looks the same as the previous version of BackTrack. But dig a little deeper, according to founder Mati Aharoni, and that’s where the similarities end.

“It boots like BackTrack, but when you look deeper into Kali, you see all these amazing new features that just weren’t available in BackTrack,” Aharoni told SC speaking ahead of the launch in Amsterdam.

via BackTrack successor Kali Linux launched – Applications – SC Magazine Australia – Secure Business Intelligence.

From Kali’s site comes this:

What’s New in Kali Linux

From an end user perspective, the most obvious change would be the switch to Debian and an FHS-compliant system. What this means is that instead of having to navigate through the /pentest tree, you will be able to call any tool from anywhere on the system as every application is included in the system path. However, there’s much hidden magic in that last sentence. I’ll quickly list some of the new benefits of this move.

Backtrack has been a very useful resource for me and prominently listed in the Tools section on this site.  One of the main features that I gleaned from this release is support for ARM.   I haven’t poked around the site or created a Kali VM to play with yet.  Will report whatever I observe later.

Belkin WeMo remote shell and rapid state change exploit

Published on Jan 29, 2013

Belkin WeMo with latest firmware. Able to gain full root access and send commands including changing the state of connected device via flaw in UPnP implementation. Chose a small desk lamp and simple on/off sequence due to safety concerns. Real world this could be a fan or space heater and rapidly turn on/off without limitation. Updates with PoC soon to come.

via Belkin WeMo remote shell and rapid state change exploit – YouTube.

Stuff like this amaze me.  Again.  Just because you can put an IP stack on something doesn’t mean you should!  Below is a video showing how to break in to this device that simply controls an electric outlet.  He uses Backtrack 5 to break in.   Backtrack is a very useful set of security research tools.  The video inspires me to fire up my copy and break into something.  🙂