<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Infosec Events &#187; Hacking Contests</title>
	<atom:link href="http://infosecevents.net/category/contests/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecevents.net</link>
	<description>Covering the Information Security Economy</description>
	<lastBuildDate>Mon, 21 May 2012 05:28:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Week 13 in Review &#8211; 2012</title>
		<link>http://infosecevents.net/2012/04/02/week-13-in-review-2012/</link>
		<comments>http://infosecevents.net/2012/04/02/week-13-in-review-2012/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 10:59:28 +0000</pubDate>
		<dc:creator>Roxanne</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Hacker Con]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[OWTF]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[Skipfish]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=2275</guid>
		<description><![CDATA[Event Related Pwn2Own Lesson From Pwn2Own: Focus On Exploitability &#8211; darkreading.com The Pwn2Own contest earlier this month at the CanSecWest Conference showed off the speed with which knowledgeable security professionals can code exploits for known vulnerabilities. On the failings of Pwn2Own 2012 &#8211; scarybeastsecurity.blogspot.com This year&#8217;s Pwn2Own and Pwnium contests were interesting for many reasons. [...]]]></description>
			<content:encoded><![CDATA[<p><strong> Event Related</strong></p>
<ul>
<li>Pwn2Own</li>
<ul>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/client-security/232800006/lesson-from-pwn2own-focus-on-exploitability.html">Lesson From Pwn2Own: Focus On Exploitability</a> &#8211; darkreading.com
<p>The Pwn2Own contest earlier this month at the CanSecWest Conference showed off the speed with which knowledgeable security professionals can code exploits for known vulnerabilities.
</li>
<li><a href="http://scarybeastsecurity.blogspot.com/2012/03/on-failings-of-pwn2own-2012.html">On the failings of Pwn2Own 2012</a> &#8211; scarybeastsecurity.blogspot.com
<p>This year&#8217;s Pwn2Own and Pwnium contests were interesting for many reasons. If you look at the results closely, there are many interesting observations and conclusions to be made.
</li>
</ul>
<li><a href="http://www.irongeek.com/i.php?page=videos%2Fouterz0ne-2011-hacker-con">Outerz0ne 2011 Hacker Con (Hacking Illustrated Series InfoSec Tutorial Videos)</a> &#8211; irongeek.com
<p>The following are videos of the presentations from the Outerzone 2011 hacker conference. Thanks to Skydog, Robin, Scott, SomeNinjaMaster and the Hacker Consortium crew for the con. Also thanks to Seeblind and others for doing AV. I&#8217;m looking forward to Skydogcon and working with the guys again at Derbycon.
</li>
</ul>
<p><strong> Resources</strong></p>
<ul>
<li><a href="http://blog.opensecurityresearch.com/2012/03/sqlitespy-for-sqlite-database-analysis.html">sqlitespy for Sqlite Database Analysis</a> &#8211; blog.opensecurityresearch.com
<p>Sqlite is the ubiquitous database for iPad, iPhone and Android applications. It is also used by certain internet browsers, web application frameworks, and software products for their local storage needs. While doing penetration tests, we often see sensitive information like usernames, passwords, account numbers, SSN etc… insecurely stored in these databases. Thus, every penetration test requires comprehensive analysis of the local databases being used.
</li>
<li><a href="http://www.securelist.com/en/blog/208193425/The_mystery_of_Duqu_Part_Ten">The mystery of Duqu: Part Ten</a> &#8211; securelist.com
<p>There were virtually no traces of Duqu since then. But several days ago our colleagues in Symantec announced that they found a new &#8220;in-the-wild&#8221; driver that is very similar to known Duqu drivers. Previous modifications of Duqu drivers were compiled on Nov 3 2010 and Oct 17 2011, and the new driver was compiled on Feb 23 2012.
</li>
<li><a href="http://www.darkoperator.com/blog/2012/3/29/introduction-to-microsoft-powershellndash-basics-of-running.html">Introduction to Microsoft PowerShell Basics of RunningCmdlets</a> &#8211; darkoperator.com
<p>You will notice that for the PowerShell commands I use the word Cmdlet, that is how Microsoft calls and spells the word. In a PowerShell shell you can execute regular windows commands in addition to the cmdlets and most work without any problem some may experience problems depending on the parameters used since PowerShell uses space as a delimiter so do keep this in mind when you are running local exe files.
</li>
<li><a href="http://resources.infosecinstitute.com/skipfish-vulnerability-scanner/">Skipfish Web Vulnerability Scanner</a> &#8211; resources.infosecinstitute.com
<p>Web application security is a serious and an important topic to discuss nowadays, since hacking attacks are common. There are hundreds and thousands of tutorials available on blogs and forums that can help an attacker hack into a web application.
</li>
<li><a href="http://www.foofus.net/~percX/praeda/praeda.tgz">Praeda version 0.02.0b is now available for download</a> &#8211; foofus.net
<p>Updated release of Praeda 0.02.0b  can be downloaded from HERE . This release contains a few new modules  and an update to the dispatcher, allowing NMAP .gnmap as target input.
</li>
</ul>
<p><strong> Tools</strong></p>
<ul>
<li>OWASP Zaproxy</li>
<ul>
<li><a href="http://code.google.com/p/zaproxy/downloads/list">ZAProxy 1.4.alpha.1 update</a> &#8211; code.google.com
<p>“The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen testers toolbox. ZAProxy provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.”
</li>
<li><a href="http://code.google.com/p/zaproxy">OWASP Zaproxy v.1.3.4 released</a> &#8211; code.google.com
<p>It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen testers toolbox.
</li>
</ul>
<li><a href="https://github.com/7a/owtf/tree/master/releases">OWTF 0.13 &#8220;Trooper&#8221; update</a> &#8211; github.com
<p>The Offensive (Web, etc) Testing Framework (aka OWTF) is an OWASP+PTES-focused try to unite great tools and make penetration testing more efficient. The purpose of this tool is to automate the manual, uncreative part of penetration testing.
</li>
<li><a href="http://www.hackfromacave.com/projects/spooftooph.html">Spooftooph v0.5  Spoofing Bluetooth</a> &#8211; hackfromacave.com
<p>Spooftooph is designed to automate spoofing or cloning Bluetooth device Name, Class, and Address. Cloning this information effectively allows Bluetooth device to hide in plain site. Bluetooth scanning software will only list one of the devices if more than one device in range shares the same device information when the devices are in Discoverable Mode (specificaly the same Address).
</li>
<li><a href="http://www.wireshark.org/download.html">Wireshark v1.6.6 Released</a> &#8211; wireshark.org
<p>Wireshark is the world’s foremost network protocol analyzer. It lets you capture and interactively browse the traffic running on a computer network. It is the de facto (and often de jure) standard across many industries and educational institutions.
</li>
<li><a href="http://www.security-projects.com/?SSLCop:Download">SSLCop v1.0  Blocking CAs Released</a> &#8211; security-projects.com
<p>SSLCop is a hardening tool that can block those CAs you don’t need, based in their geographical procedence. You can disable CAs sorted from countries and leave only those which make sense to you.
</li>
<li><a href="http://code.google.com/p/kautilya/downloads/list">Kautilya v0.2.0 payloads for Teensy  Released</a> &#8211; code.google.com
<p>Kautilya is a toolkit which provides various payloads for Teensy device which may help in breaking in a computer. The toolkit is written in Ruby and currently contains all Windows payloads written mostly in powershell.
</li>
<li><a href="https://github.com/ilektrojohn/creepy">Creepy version 0.2</a> &#8211; github.com
<p>Creepy is an application that allows you to gather geolocation related information about users from social networking platforms and image hosting services. The information is presented in a map inside the application where all the retrieved data is shown accompanied with relevant information (i.e. what was posted from that specific location) to provide context to the presentation.
</li>
<li><a href="http://owasp.blogspot.com/2012/03/owasp-webgoat-12.html">OWASP WebGoat 1.2</a> &#8211; owasp.blogspot.com
<p>FYI, we released iGoat version 1.2 today. The primary change over 1.1 is the addition of a new keychain exercise, contributed by a newcomer to the team, Mansi Sheth.
</li>
</ul>
<p><strong> Techniques</strong></p>
<ul>
<li>iPhone</li>
<ul>
<li><a href="http://www.forbes.com/sites/andygreenberg/2012/03/27/heres-how-law-enforcement-cracks-your-iphones-security-code-video/">Here&#8217;s How Law Enforcement Cracks Your iPhone&#8217;s Security Code (Video)</a> &#8211; forbes.com
<p>Set your iPhone to require a four-digit passcode, and it may keep your private information safe from the prying eyes of the taxi driver whose cab you forget it in. But if law enforcement is determined to see the data you’ve stored on your smartphone, those four digits will slow down the process of accessing it by less than two minutes.
</li>
<li><a href="http://news.cnet.com/8301-1023_3-57405580-93/iphone-passcode-cracking-is-easier-than-you-think/">iPhone passcode cracking is easier than you think</a> &#8211; cnet.com
<p>A report came out last fall suggesting that repeating one number in the iPhone&#8217;s four-digit security PIN made for better protection than using all unique numbers. However, that little trick doesn&#8217;t seem to go very far with Micro Systemation, a Swedish security firm that helps police and military around the world crack digital security systems.
</li>
<li><a href="http://securitylearn.wordpress.com/2012/03/31/reading-iphone-backups/">Reading iPhone Backups</a> &#8211; securitylearn.wordpress.com
<p>When iPhone is connected to a computer for the first time, iTunes automatically creates a subfolder with device UDID as the folder name and takes a backup of everything available on the iPhone.
</li>
</ul>
<li>IPv6</li>
<ul>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/03/27/identifying-ipv6-security-risks-in-ipv4-networks-tools">Identifying IPv6 Security Risks in IPv4 Networks: Tools</a> &#8211; community.rapid7.com
<p>This post details some of the tools used in my recent IPv6 security testing webcast If you have any specific questions, please open a Discussion thread.
</li>
<li><a href="http://7bits.nl/blog/2012/03/26/finding-v6-hosts-by-efficiently-mapping-ip6-arpa">Finding v6 hosts by efficiently mapping ip6.arpa</a> &#8211; 7bits.nl
<p>A technique for quickly finding existing reverse (PTR) entries in ip6.arpa-zones occurred to me recently. A cursory internet search reveals little about the subject, suggesting nobody else may have connected these dots before.
</li>
</ul>
</ul>
<p><strong> Vendor/Software Patches</strong></p>
<ul>
<li>MS12-020</li>
<ul>
<li><a href="http://auntitled.blogspot.com/2012/03/understand-ms12-020.html">Understand MS12-020</a> &#8211; auntitled.blogspot.com
<p>I saw many misunderstanding about MS12-020 bug. Here is my quick explanation (hope it is clear). There are 2 bugs for this bulletin. One is RCE (CVE-2012-0002). Another one is DoS (CVE-2012-0152). I use the diff result from work of people in IRC (freenode#MS12-020) http://pastie.org/private/4egcqt9nucxnsiksudy5dw.
</li>
<li><a href="http://www.f-secure.com/weblog/archives/00002338.html">A Tool Exploiting MS12-020 Vulnerabilities</a> &#8211; f-secure.com
<p>Since the public release of Microsoft&#8217;s MS12-020 bulletin, there have been plenty of attempts to exploit vulnerabilities in the Remote Desktop Protocol (RDP). Last week, we received a related sample, which turned out to be a tool called &#8220;RDPKill by: Mark DePalma&#8221; that was designed to kill targeted RDP service.
</li>
</ul>
<li>DNS</li>
<ul>
<li><a href="http://www.circleid.com/posts/20120327_dns_changer/">DNS Changer</a> &#8211; circleid.com
<p>One fine night in November 2011 I got an opportunity to get my hands dirty, working on a project for the United States Federal Bureau of Investigation (FBI). They were planning to seize a bunch of computing assets in New York City that were being used as part of a criminal empire that we called &#8220;DNS Changer&#8221; since that was the name of the software this gang used to infect a half million or so computers. I work for Internet Systems Consortium (ISC), a small non-profit company headquartered in California.
</li>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/03/28/metasploit-update">Weekly Metasploit Update: DNS payloads, Exploit-DB, and More</a> &#8211; community.rapid7.com
<p>This week we&#8217;ve got a nifty new shellcode delivery scheme, we&#8217;ve normalized on Exploit-DB serial numbers, and a pile of new modules, so if you don&#8217;t have Metasploit yet, you can snag it here.
</li>
</ul>
<li><a href="http://krebsonsecurity.com/2012/03/new-java-attack-rolled-into-exploit-packs/">New Java Attack Rolled into Exploit Packs</a> &#8211; krebsonsecurity.com
<p>If your computer is running Java and you have not updated to the latest version, you may be asking for trouble: A powerful exploit that takes advantage of a newly-disclosed security hole in Java has been rolled into automated exploit kits and is rapidly increasing the success rates of these tools in attacking vulnerable Internet users.
</li>
<li><a href="http://reviews.cnet.com/8301-13727_7-57405503-263/new-exploit-uses-old-office-vulnerability-for-os-x-malware-delivery/?part=rss&amp;tag=feed&amp;subj=News-Security">New exploit uses old Office vulnerability for OS X malware delivery</a> &#8211; reviews.cnet.com
<p>While this means of exploiting Mac systems via Microsoft Office is old and has been patched, this marks the first time Office documents have been used to exploit OS X systems.
</li>
</ul>
<p><strong> Vulnerabilities</strong></p>
<ul>
<li>Microsoft</li>
<ul>
<li><a href="http://www.nytimes.com/2012/03/26/technology/microsoft-raids-tackle-online-crime.html">Microsoft Raids Tackle Internet Crime</a> &#8211; nytimes.com
<p>Microsoft employees, accompanied by United States marshals, raided two nondescript office buildings in Pennsylvania and Illinois on Friday, aiming to disrupt one of the most pernicious forms of online crime today — botnets, or groups of computers that help harvest bank account passwords and other personal information from millions of other computers.
</li>
<li><a href="http://krebsonsecurity.com/2012/03/microsoft-takes-down-dozens-of-zeus-spyeye-botnets/">Microsoft Takes Down Dozens of Zeus, SpyEye Botnets</a> &#8211; krebsonsecurity.com
<p>Microsoft today announced the execution of a carefully planned takedown of dozens of botnets powered by ZeuS and SpyEye — powerful banking Trojans that have helped thieves steal more than $100 million from small to mid-sized businesses in the United States and abroad.
</li>
<li><a href="http://blogs.technet.com/b/microsoft_blog/archive/2012/03/25/microsoft-and-financial-services-industry-leaders-target-cybercriminal-operations-from-zeus-botnets.aspx">Microsoft and Financial Services Industry Leaders Target Cybercriminal Operations from Zeus Botnets</a> &#8211; technet.com
<p>Cybercriminals have built hundreds of botnets using variants of Zeus malware. For this action – codenamed Operation b71 – we focused on botnets using Zeus, SpyEye and Ice-IX variants of the Zeus family of malware, known to cause the most public harm and which experts believe are responsible for nearly half a billion dollars in damages.
</li>
</ul>
<li>Credit Card Processor Breach</li>
<ul>
<li><a href="http://krebsonsecurity.com/2012/03/mastercard-visa-warn-of-processor-breach/">MasterCard, VISA Warn of Processor Breach</a> &#8211; krebsonsecurity.com
<p>VISA and MasterCard are alerting banks across the country about a recent major breach at a U.S.-based credit card processor. Sources in the financial sector are calling the breach “massive,” and say it may involve more than 10 million compromised card numbers.
</li>
<li><a href="http://www.wired.com/threatlevel/2012/03/global-payments-breached/">Hackers Breach Credit Card Processor; 50K Cards Compromised</a> &#8211; wired.com
<p>Global Payments Inc, an Atlanta-based processor, has been breached by hackers, leaving more than 50,000 card accounts potentially compromised.
</li>
</ul>
<li><a href="http://news.cnet.com/8301-27080_3-57404815-245/hackers-steal-passwords-from-military-dating-site/?part=rss&amp;tag=feed&amp;subj=News-Security">Hackers steal passwords from military dating site</a> &#8211; news.cnet.com
<p>Hackers broke into the database for a military dating Web site and stole passwords, e-mail addresses, and other information from nearly 171,000 accounts, according to a post on the Pastebin site this weekend</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/vulnerabilities/232700282/command-injection-attacks-automated-password-guessing-on-the-rise.html">Command Injection Attacks, Automated Password Guessing On The Rise</a> &#8211; darkreading.com
<p>Spam and several of the most common vulnerabilities are on the decline, according to a report issued this week, but there has been a marked increase in new types of attacks, such as shell command injection and automated password guessing.
</li>
<li><a href="http://www.zdnet.com/blog/security/lulzsec-hacks-css-corp/11108">LulzSec hacks CSS Corp</a> &#8211; zdnet.com
<p>LulzSec has hacked CSS Corp and released the company’s e-mail database to the public. The hacktivist group is also asking followers to join #LulzSecReborn on Anonymous’ IRC channel.
</li>
<li><a href="http://krebsonsecurity.com/2012/03/critical-security-update-for-adobe-flash-player-2/">Critical Security Update for Adobe Flash Player</a> &#8211; krebsonsecurity.com
<p>Adobe has issued a security update for its Flash Player software that fixes at least two critical vulnerabilities in the widely-used program. At long last, this latest version also includes an auto-updating mechanism designed to streamline the deployment of Flash security fixes across multiple browsers.
</li>
</ul>
<p><strong> Other News</strong></p>
<ul>
<li>China on Hacking</li>
<ul>
<li><a href="http://taosecurity.blogspot.com/2012/03/inside-commission-hearing-on-chinese.html">Inside a Commission Hearing on the Chinese Threat</a> &#8211; taosecurity.blogspot.com
<p>This morning I testified at the U.S.-China Economic and Security Review Commission at a hearing on Developments in China’s Cyber and Nuclear Capabilities. In the picture taken by Mrs Bejtlich (thanks for attending!) I&#8217;m seated at the far right. To my left is Nart Villeneuve. To his left is Jason Healey.
</li>
<li><a href="http://www.darkreading.com/advanced-threats/167901091/security/attacks-breaches/232700515/china-hacked-rsa-u-s-official-says.html">China Hacked RSA, U.S. Official Says</a> &#8211; darkreading.com
<p>Until this week, no one has ever confirmed publicly what everyone has suspected all along: that China was behind the advanced attack against RSA&#8217;s SecurID systems last year. That was the revelation by the head of the U.S. Cyber Command in a Congressional hearing on Tuesday.
</li>
</ul>
<li><a href="http://news.cnet.com/8301-27080_3-57404894-245/tsa-asks-congressional-panel-to-uninvite-critic-bruce-schneier/">TSA asks congressional panel to uninvite critic Bruce Schneier</a> &#8211; news.cnet.com
<p>Bruce Schneier, a vocal critic of security measures used by the Transportation Security Administration, was asked to testify before Congress about TSA&#8217;s security screening initiatives but then was &#8220;formally uninvited&#8221; after the agency complained.
</li>
<li><a href="http://www.wired.com/threatlevel/2012/03/nsa-malware-signature/">NSA Chief: Agency Wants to Provide Malware Signatures, Not Enter Private Networks</a> &#8211; wired.com
<p>The NSA continued to downplay its role in the cyberdefense of private networks when Gen. Keith Alexander told a Senate committee Tuesday that his intelligence agency absolutely did not want to be lurking in private networks monitoring data for threats.
</li>
<li><a href="http://arstechnica.com/science/news/2012/03/satellite-jamming-becoming-a-big-problem-in-the-middle-east.ars">Satellite-jamming becoming a big problem in the Middle East and North Africa</a> &#8211; arstechnica.com
<p>The Arab Spring has had yet another consequence—satellite jamming, and the practice is serious enough to threaten the satellite operators&#8217; business. Two operators, Arabsat and Nilesat, complained about the jamming in the Satellite 2012 Conference in Washington, D.C. last week, according to an article in Space News.
</li>
<li><a href="http://www.techweekeurope.co.uk/news/eu-cyber-crime-law-sentenc-69942">Draft EU Law Proposes 2 Year Minimum Sentence for Hackers</a> &#8211; techweekeurope.co.uk
<p>The proposed directive, which was backed by 50 votes at the European Parliament’s Civil Liberties Committee compared to one against, would mean the UK would no longer rely on the Computer Misuse Act that currently has a maximum sentence of two years for a single breach of systems.
</li>
<li><a href="http://online.wsj.com/article/SB10001424052702304177104577307773326180032.html">U.S. Outgunned in Hacker War</a> &#8211; online.wsj.com
<p>The Federal Bureau of Investigation&#8217;s top cyber cop offered a grim appraisal of the nation&#8217;s efforts to keep computer hackers from plundering corporate data networks: &#8220;We&#8217;re not winning,&#8221; he said.
</li>
<li><a href="http://www.smithsonianmag.com/history-archaeology/Richard-Clarke-on-Who-Was-Behind-the-Stuxnet-Attack.html">Richard Clarke on Who Was Behind the Stuxnet Attack</a> &#8211; smithsonianmag.com
<p>America&#8217;s longtime counterterrorism czar warns that the cyberwars have already begun—and that we might be losing.
</li>
<li><a href="http://blog.c22.cc/2012/03/29/eu-legislation-digging-below-the-fud-line/">EU legislation – Digging below the FUD line</a> &#8211; blog.c22.cc
<p>Yesterday I started to see some chatter on Twitter about new/updated EU legislation dealing with “cyber” attacks.
</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=2275&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2012/04/02/week-13-in-review-2012/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Week 10 in Review &#8211; 2012</title>
		<link>http://infosecevents.net/2012/03/12/week-10-in-review-2012/</link>
		<comments>http://infosecevents.net/2012/03/12/week-10-in-review-2012/#comments</comments>
		<pubDate>Tue, 13 Mar 2012 01:50:11 +0000</pubDate>
		<dc:creator>Roxanne</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CanSec West]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[RSAC 2012]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=2172</guid>
		<description><![CDATA[Event Related CanSecWest CanSecWest evolving &#8211; blog.securiteam.com Let me say, right off the top, that I love CanSecWest. I am tired of “vendor” conferences, where you pay outrageous fees for the privilege of sitting through a bunch of sales pitches. At least CanSecWest has real information, as opposed to virtual information. CanSecWest Day 1 Pen [...]]]></description>
			<content:encoded><![CDATA[<p><strong> Event Related</strong></p>
<ul>
<li>CanSecWest</li>
<ul>
<li><a href="http://blogs.securiteam.com/index.php/archives/1650">CanSecWest evolving</a> &#8211; blog.securiteam.com
<p>Let me say, right off the top, that I love CanSecWest. I am tired of “vendor” conferences, where you pay outrageous fees for the privilege of sitting through a bunch of sales pitches. At least CanSecWest has real information, as opposed to virtual information.</li>
<li><a href="http://nakedsecurity.sophos.com/2012/03/08/cansecwest-day-1-pen-testing-social-authentication-apr-and-duqu/">CanSecWest Day 1 Pen testing, social authentication, APR and Duqu</a> &#8211; nakedsecurity.sophos.com<br />
A wrap-up of the news and talks from CanSecWest 2012 in Vancouver. I highlight talks on pen testing, social authentication, vulnerability mitigation and the Duqu command and control servers.</li>
<li><a href="http://nakedsecurity.sophos.com/2012/03/10/cansecwest-day-2-smartphones-mobile-security-ios-5-and-nfc/">CanSecWest Day 2 Smartphones, mobile security, iOS 5 and NFC</a> &#8211; nakedsecurity.sophos.com<br />
Day 2 at CanSecWest was dominated by mobile security talks. The highlights included anti-rooting technologies used in Android, iOS and a look at NFC enabled mobile phone security.</li>
<li><a href="http://home.regit.org/2012/03/playing-with-network-layers-to-bypass-firewalls-filtering-policy/">Playing with Network Layers to Bypass Firewalls Filtering Policy</a> &#8211; home.regit.org<br />
The slides of my CansecWest talk can now be downloaded: Playing with Network Layers to Bypass Firewalls’ Filtering Policy.</li>
</ul>
<li>RSA Conference</li>
<ul>
<li><a href="http://rants.effu.se/2012/03/B-Sides-SF-and-RSAC-2012-Summary">B-Sides SF and RSAC 2012 Summary</a> &#8211; rants.effu.se<br />
One of the consistent themes I heard from attendees of B-Sides SF and RSAC this year was &#8220;this was the best year yet!&#8221; That is a huge turn-around from the cynicism that was so prevalent last year.</li>
<li><a href="http://www.readwriteweb.com/enterprise/2012/03/invasion-of-the-risk-managers.php">Invasion of the Risk Managers: Altering the Complexion of Security&#8221;</a> &#8211; readwriteweb.com<br />
Article about the discussion panel on risk.
</li>
</ul>
</ul>
<p><strong> Resources</strong></p>
<ul>
<li><a href="https://blog.mandiant.com/archives/2326">M-Trends: The One Threat Report You Need to Read</a> &#8211; blog.mandiant.com<br />
Today is a big day. If you’ve followed us for a while you know that once a year we step back and take stock of what we’ve seen on the front lines battling targeted attacks. What is the advanced persistent threat (APT) up to?</li>
</ul>
<p><strong> Tools</strong></p>
<ul>
<li><a href="http://blog.didierstevens.com/2012/03/05/update-taskmanager-xls-v0-1-2/">TaskManager.xls V0.1.2 Update</a> &#8211; blog.didierstevens.com<br />
This is a new version of TaskManager.xls with memory usage statistics, with code given to me by sciomathman.</li>
<li><a href="http://www.zdnet.com/blog/security/zscaler-tool-can-find-unprotected-embedded-web-servers/10507">Zscaler tool can find unprotected embedded web servers</a> &#8211; zdnet.com<br />
The web-based tool can scan IP ranges to find multi-function printers and photocopiers, VOIP devices and video-conferencing systems that are currently.</li>
<li><a href="http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html">Introducing Adobe SWF Investigator</a> &#8211; adobe.com<br />
Today I am launching a beta of a tool on Adobe Labs called, Adobe SWF Investigator. This Adobe AIR-based application is a suite of tools that may be useful to SWF developers, quality engineers, and security researchers.</li>
<li><a href="http://ettercap.sourceforge.net/download.php">Ettercap v0.7.4.1 Lazarus Released</a> &#8211; ettercap.sourceforge.net<br />
Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.</li>
<li><a href="https://blog.wireshark.org/2012/03/wireshark-and-pcap-ng/">Wireshark and Pcap-ng</a> &#8211; blog.wireshark.org<br />
When Wireshark 1.8.0 is released in the next few months it will introduce two major features: the ability to capture from multiple interfaces at once and the ability to annotate packets.</li>
<li><a href="http://themole.nasel.com.ar/?q=downloads">Mole v0.3 (2012-03-02)</a> &#8211; themole.nasel.com.ar<br />
Command line sql injection tool</li>
<li><a href="http://hexale.blogspot.com/2012/03/wce-v13beta-32bit-released.html">WCE v1.3beta 32bit released</a> &#8211; hexale.blogspot.com
<p>WCE v1.3beta 32bit released.</li>
</ul>
<p><strong> Techniques</strong></p>
<ul>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/03/05/how-to-own-a-virtual-data-center">Testing the Security of Virtual Data Centers</a> &#8211; community.rapid7.com<br />
If you are doing security assessments, you are probably running into virtual servers every day. According to analyst firm Gartner, 80% of companies now have a virtualization project or program. With the recent 4.2 release of Metasploit, your next penetration test should be much more fun.</li>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/03/07/why-security-assessments-must-cover-ipv6-even-in-ipv4-networks">Why Security Assessments Must Cover IPv6, Even In IPv4 Networks</a> &#8211; community.rapid7.com
<p>What&#8217;s your company doing to prepare for IPv6? Probably not an awful lot. While 10% of the world&#8217;s top websites now offer IPv6 services, most companies haven&#8217;t formulated an IPv6 strategy for the network.</li>
<li><a href="http://www.sensepost.com/blog/6794.html">Foot printing – Finding your target&#8230;</a> &#8211; sensepost.com<br />
Network foot printing is, perhaps, the first active step in the reconnaissance phase of an external network security engagement. This phase is often highly automated with little human interaction as the techniques appear, at first glance, to be easily applied in a general fashion across a broad range of targets.</li>
</ul>
<p><strong> Vulnerabilities</strong></p>
<ul>
<li>Google Chrome Hacked</li>
<ul>
<li><a href="http://www.zdnet.com/blog/security/pwn2own-2012-google-chrome-browser-sandbox-first-to-fall/10588">Pwn2Own 2012: Google Chrome browser sandbox first to fall</a> &#8211; zdnet.com
<p>Exploit writers at VUPEN take special pleasure in attacking Google’s Chrome browser, using a pair of zero-day flaws to defeat the browser.</li>
<li><a href="http://www.zdnet.com/blog/security/cansecwest-pwnium-google-chrome-hacked-with-sandbox-bypass/10563">CanSecWest Pwnium: Google Chrome hacked with sandbox bypass</a> &#8211; zdnet.com
<p>The attack, which included a Chrome sandbox bypass, was the handiwork of Sergey Glazunov, a security researcher who regularly finds and reports Chrome.</li>
<li><a href="http://gizmodo.com/5891508/chrome-finally-breached-in-googles-1-million-hackathon">Chrome Finally Breached in Google’s $1 Million Hackathon</a>- gizmodo.com
<p>Google recently offered up prizes totaling $1 million for those capable of exploiting its browser Chrome. Now, at Google&#8217;s own competition called Pwnium, a student has walked away with one of the top prizes, earning $60,000 by hacking a PC running Chrome.</li>
<li><a href="http://arstechnica.com/business/news/2012/03/after-the-pwnage-critical-google-chrome-hole-plugged-in-24-hours.ars">After the pwnage: Critical Google Chrome hole plugged in 24 hours</a> &#8211; arstechnica.com
<p>Underscoring the nimbleness of Google&#8217;s patching cycle, Chrome developers fixed a complex series of bugs less than 24 hours after they were demoed at a hacker conference.</li>
<li><a href="http://www.wired.com/threatlevel/2012/03/zero-days-for-chrome/">Teen Exploits Three Zero-Day Vulns for $60K Win in Google Chrome Hack Contest</a> &#8211; wired.com
<p>A teenage hacker known as Pinkie Pie pokes a hole in Google&#8217;s Chrome browser, an unlikely winner who&#8217;s taking home $60K and a possible job at the search giant.</li>
<li><a href="http://www.zdnet.com/blog/security/how-google-set-a-trap-for-pwn2own-exploit-team/10641">How Google set a trap for Pwn2Own exploit team</a> &#8211; zdnet.com
<p>Here’s the story of how a unique signature was used to figure out if exploit writers would take aim at the Flash Player plugin in Google Chrome</li>
</ul>
<li>Pwn2Own Hacking Contest</li>
<ul>
<li><a href="http://www.zdnet.com/blog/security/charlie-miller-skipping-pwn2own-as-new-rules-change-hacking-game/10554">Charlie Miller skipping Pwn2Own as new rules change hacking game</a> &#8211; zdnet.com
<p>The annual Pwn2Own hacker contest kicks off today with new rules, controversy over disclosure and the absence of a regular participant.</li>
<li><a href="http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621">Pwn2Own 2012: IE 9 hacked with two 0day vulnerabilities</a> &#8211; zdnet.com
<p>The code execution attack, which required no user action beyond browsing to a rigged web site, also works on Internet Explorer v10.</li>
<li><a href="http://www.wired.com/threatlevel/2012/03/how-to-pwn-the-pwn2own-contest/">How to Pwn the Pwn2Own Contest</a> &#8211; wired.com
<p>Finding zero-day exploits to win a hacking contest can be really hard work these days. So sometimes the better strategy is just to game the game.</li>
</ul>
<li><a href="http://erratasec.blogspot.com/2012/03/rubygithub-hack-translated.html">The Ruby/GitHub hack: translated</a> &#8211; erratasec.blogspot.com<br />
The underlying issue is an “Insecure Direct Object Reference”, #4 on the OWASP Top 10 list of most important web-application vulnerabilities. It means that that a hacker can change what&#8217;s in the website database without having permission.</li>
</ul>
<p><strong> Other News</strong></p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2012/03/feds-seize-foreign-sites/all/1">Uncle Sam: If It Ends in .Com, It&#8217;s Seizable</a> &#8211; wired.com
<p>The U.S. government says it has the right to seize any .com, .net and .org domain name because the companies that have the contracts to administer them are based on United States soil, according to Nicole Navas, an Immigration and Customs Enforcement spokeswoman.</li>
<li><a href="http://nakedsecurity.sophos.com/2012/03/07/sabus-sordid-story-detailed-in-fbi-indictment/">Sabus sordid story detailed in FBI indictment</a> &#8211; nakedsecurity.sophos.com
<p>Hector Xavier Monsegur may have portrayed the exploits of Anonymous and LulzSec as a glamorous fight against &#8220;the man&#8221;, but the dark criminal realities of their exploits were exposed in his indictment. It appears he wasn&#8217;t just in it for the lulz.</li>
<li><a href="http://www.symantec.com/connect/blogs/dropbox-abused-spammers">Dropbox Abused by Spammers</a> &#8211; symantec.com
<p>Recently we noticed spammers abusing Dropbox, a popular cloud-based, file-hosting and synchronization tool, to spread spam. Dropbox accounts have a public folder where files can be placed and made publicly available. This function is useful to spammers, as it effectively turns Dropbox into a free hosting site.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=2172&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2012/03/12/week-10-in-review-2012/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Information Security Events For November</title>
		<link>http://infosecevents.net/2011/11/01/information-security-events-for-november-2/</link>
		<comments>http://infosecevents.net/2011/11/01/information-security-events-for-november-2/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 01:57:11 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[Hackfest]]></category>
		<category><![CDATA[SC Congress]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1895</guid>
		<description><![CDATA[Here are information security events in North America this month: Hackfest Optimized: November 4 to November 5 in Quebec BSides DFW: November 5 to November 6 in Irving &#160; &#160; BSides Atlanta: November 4 in Atlanta &#160; BSides Delaware: November 1 to November 12 in New Castle &#160; SC Congress: November 16 in New York [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Here are information security events in North America this month:</strong></p>
<p><a href="http://www.hackfest.ca/?page_id=475"><img class="alignleft size-full wp-image-1906" title="Hackfest logo" src="http://infosecevents.net/wp-content/uploads/2011/11/Hackfest-logo.jpg" alt="Hackfest logo" width="200" height="41" /></a></p>
<p><a href="http://www.hackfest.ca/">Hackfest Optimized</a>: November 4 to November 5 in Quebec</p>
<p><a href="http://bsidesdfw2011.eventbrite.com/"><img class="alignleft size-full wp-image-1896" title="BSides DFW" src="http://infosecevents.net/wp-content/uploads/2011/11/BSides-DFW.jpg" alt="BSides DFW" width="200" height="80" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/36779575/BSidesDFW-2011">BSides DFW</a>: November 5 to November 6 in Irving</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://bsidesatl-2011.eventbrite.com/?ref=ebtn"><img class="alignleft size-full wp-image-1898" title="BSides At" src="http://infosecevents.net/wp-content/uploads/2011/11/BSides-At1.jpg" alt="BSides At" width="150" height="95" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/44893559/BSidesATL-2011">BSides Atlanta</a>: November 4 in Atlanta</p>
<p>&nbsp;</p>
<p><a href="http://bsidesde2011.eventbrite.com/"><img class="alignleft size-full wp-image-1900" title="BSides logo 02" src="http://infosecevents.net/wp-content/uploads/2011/11/BSides-logo-02.jpg" alt="BSides logo 02" width="150" height="95" /></a></p>
<p><a href="http://www.securitybsides.com/w/page/28563447/BSidesDelaware">BSides Delaware</a>: November 1 to November 12 in New Castle</p>
<p>&nbsp;</p>
<p><a href="http://www.cvent.com/d/8cqn1q/4W?refid=SCNYweb"><img class="alignleft size-full wp-image-1905" title="SC Congress logo" src="http://infosecevents.net/wp-content/uploads/2011/11/SC-Congress-logo.jpg" alt="SC Congress logo" width="230" height="61" /></a></p>
<p><a href="http://www.scmagazineus.com/sc-congress-new-york-2011/section/2286/">SC Congress</a>: November 16 in New York</p>
<p>&nbsp;</p>
<p><strong>And here are the information security events in the other parts of the world:</strong></p>
<p><a href="http://infosecevents.net/wp-content/uploads/2011/11/Kiwicon-logo.jpg"><img class="alignleft size-full wp-image-1907" title="Kiwicon logo" src="http://infosecevents.net/wp-content/uploads/2011/11/Kiwicon-logo.jpg" alt="Kiwicon logo" width="200" height="47" /></a></p>
<p><a href="https://www.kiwicon.org/b00m/">Kiwicon V</a>: November 4 to November 6 in Wellington</p>
<p>&nbsp;</p>
<p><a href="https://pacsec.jp/register.html"><img class="alignleft size-full wp-image-1916" title="PACSEC" src="http://infosecevents.net/wp-content/uploads/2011/11/PACSEC.jpg" alt="PACSEC" width="250" height="68" /></a></p>
<p><a href="http://pacsec.jp/">PACSEC Tokyo</a>: November 9 to November 10 in Tokyo</p>
<p><a href="http://www.sans.org/paris-2011-cs-508-2/reg-options.php"><img class="alignleft size-full wp-image-1901" title="SANS Paris" src="http://infosecevents.net/wp-content/uploads/2011/11/SANS-Paris.jpg" alt="SANS Paris" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/paris-2011-cs-508-2/description.php?tid=4976">SANS Paris 2011</a>: November 14 to November 18 in Paris</p>
<p>&nbsp;</p>
<p><a href="https://www.sans.org/registration/register.php?conferenceid=24884"><img class="alignleft size-full wp-image-1902" title="SANS Geneva" src="http://infosecevents.net/wp-content/uploads/2011/11/SANS-Geneva.jpg" alt="SANS Geneva" width="180" height="78" /></a></p>
<p><a href="http://www.sans.org/geneva-2011-2/description.php?tid=4162">SANS Geneva</a>: November14 to November 19 in Geneva</p>
<p><a href="http://www.regonline.com/Register/Checkin.aspx?EventID=941825"><img class="alignleft size-full wp-image-1915" title="Source Barcelona" src="http://infosecevents.net/wp-content/uploads/2011/11/Source-Barcelona.jpg" alt="Source Barcelona" width="250" height="63" /></a></p>
<p><a href="http://www.sourceconference.com/barcelona/">SOURCE Barcelona</a>: November 14 to November 17 in Barcelona</p>
<p><a href="http://www.e-crimecongress.org/india/website.asp?page=register"><img class="alignleft size-full wp-image-1903" title="ecrime India" src="http://infosecevents.net/wp-content/uploads/2011/11/ecrime-India.jpg" alt="ecrime India" width="230" height="85" /></a></p>
<p><a href="http://www.e-crimecongress.org/india/">e-Crime India</a>: November 9 in Mumbai</p>
<p><a href="http://www.e-crimecongress.org/abudhabi/pictures/registerevent.JPG"><img class="alignleft size-full wp-image-1904" title="ecrime Abu Dhabi" src="http://infosecevents.net/wp-content/uploads/2011/11/ecrime-Abu-Dhabi.jpg" alt="ecrime Abu Dhabi" width="230" height="85" /></a></p>
<p>&nbsp;</p>
<p><a href="http://www.e-crimecongress.org/abudhabi/">e-Crime Abu Dhabi</a>: November 23 in Abu Dhabi</p>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1895&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/11/01/information-security-events-for-november-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 37 In Review</title>
		<link>http://infosecevents.net/2011/09/19/week-37-in-review-2/</link>
		<comments>http://infosecevents.net/2011/09/19/week-37-in-review-2/#comments</comments>
		<pubDate>Mon, 19 Sep 2011 23:55:31 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[Rootcon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1839</guid>
		<description><![CDATA[Events Related Crack Me If You Can DefCon 2011 Insidepro team &#8211; contest.korelogic.com First of all, I must say that this year&#8217;s contest was a big improvement over last year. Not that last year was boring, far from that, but the feedbacks given last year were well understood and rectified this year. The weighted points [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li><a href="https://contest.korelogic.com/team_Insidepro_2011.html">Crack Me If You Can DefCon 2011 Insidepro team</a> &#8211; contest.korelogic.com<br />
First of all, I must say that this year&#8217;s contest was a big improvement over last year. Not that last year was boring, far from that, but the feedbacks given last year were well understood and rectified this year. The weighted points depending on the hashing algorithm made much more sense. The bonuses and the challenges added a lot more spice and need for strategies.</li>
<li><a href="http://sunbeltblog.blogspot.com/2011/09/rootcon-5-summary.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+SunbeltBlog+(GFI+Blog)">Rootcon 5: A Summary</a> &#8211; sunbeltblog.blogspot.com<br />
I&#8217;m not saying all of my trips go horribly wrong, but exploding toilets, 1984 style televisions, badges that make no sense, surprises in alleyways and emergency fuel dumps could perhaps convince you otherwise. You&#8217;ll be pleased to know Rootcon 5 went off without a hitch (well, besides the earthquake drill, the eleven hours at Guangzhou airport and the lady with the foot in her face) and a great time was had by all.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="https://github.com/orf/xcat/downloads">XCat: Exploit Boolean XPath Injections!</a> - github.com/orf/xcat/downloads<br />
Prior to getting acquainted with XCat, let’s know what an XPath Injection actually is. XPath is a language for addressing parts of an XML document, designed to be used by both XSLT and XPointer.</li>
<li><a href="http://www.room362.com/blog/2011/9/12/multiple-dictionaries-or-wordlists-using-john-the-ripper.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Room362com+(Room362.com)">Multiple Dictionaries or Wordlists Using John The Ripper</a> &#8211; room362.com<br />
John the ripper only takes one word list at a time. There are plenty of docs out there that show you how to cat all of your dictionaries into John&#8217;s stdin function but I like to run rules against my lists and I didn&#8217;t see any how-tos on doing this. Here is my way.</li>
<li><a href="http://code.google.com/p/beef/downloads/list">UPDATE: BeEF v0.4.2.9 alpha! </a>- code.google.com/p/list/downloads/list<br />
BeEF, the Browser Exploitation Framework is a professional security tool provided for lawful research and testing purposes. It allows the experienced penetration tester or system administrator additional attack vectors when assessing the posture of a target. The user of BeEF will control which browser will launch which exploit and at which target.</li>
<li><a href="http://sourceforge.net/projects/networkminer/files/networkminer/">UPDATE: NetworkMiner 1.1!</a> &#8211; sourceforge.net/projects/networkminer/files/networkminer<br />
NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files</li>
<li><a href="https://code.google.com/p/bodgeit/downloads/list">UPDATE: BodgeIT v1.2.0!</a>- code.google.com/p/bodgeit/download/list<br />
The BodgeIt Store is a vulnerable web application which is currently aimed at people who are new to pen testing.</li>
<li><a href="http://michaelhendrickx.com/wp-content/uploads/2008/11/lilith-06atar.gz">Lilith Web Application Security Tool</a> &#8211; darknet.org.uk<br />
LiLith is a tool written in Perl to audit web applications. This tool analyses webpages and looks for html form tags , which often refer to dynamic pages that might be subject to SQL injection or other flaws. It works as an ordinary spider and analyses pages, following hyperlinks, injecting special characters that have a special meaning to any underlying platform.</li>
<li><a href="http://www.h-online.com/security/news/item/Open-source-tool-enables-security-tests-for-chip-cards-1344245.html">Open Source Tool Enables Security Tests For Chip Cards</a> &#8211; h-online.com<br />
At this year&#8217;s Black Hat Conference, crypto expert Karsten Nohl of SRLabsdemonstrated the degate tool that can be used to take a closer look at applications stored on smartcards, such as credit cards and SIM cards.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://www.0x90.co.uk/2011/09/remote-windows-sam-retrieval-with.html">Remote Windows SAM retrieval with VBScript</a> &#8211; ox90.co.uk<br />
There&#8217;s no denying that PSExec and FGDump are useful tools on a infrastructure penetration test. FGDump is a problem however, in the fact that it needs to inject into a running process (lsass.dll) and therefore is often blocked by antivirus.</li>
<li><a href="http://pentesterconfessions.blogspot.com/2011/09/db2-sql-injection-select-nth-row.html">DB2 SQL Injection: Select With Nth Row Without Cursors</a> &#8211; pentesterconfessions.blogspot.com<br />
Well I&#8217;ve looked all over the net for this solution and I could not find the answer so after much trial an error I was able to build my own solution. Lets say you need to query one row at a time from DB2 and you cannot use cursors and specifically you need to query sysibm.systables. I came up with this solution and there may be a more elegant way but this worked.</li>
<li><a href="http://bernardodamele.blogspot.com/2011/09/reverse-shells-one-liners.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+BernardoDamele+(Bernardo+Damele+A.+G.)">Reverse Shell One Liner</a>s &#8211; bernardodamerle.blogspot.com<br />
Inspired by the great blog post by pentestmonkey.net, I put together the following extra methods and alternatives for some methods explained in the cheat sheet. There is nothing cutting edge, however you may find this handy during your penetration tests.</li>
<li><a href="http://intrepidusgroup.com/insight/2011/09/pentesting-wp7-apps-part-i/">Pentesting WP7 Apps Part 1</a> &#8211; intrepidusgroup.com<br />
With over 30,000 apps in the marketplace within a year of launch, Microsoft’s Windows Phone 7 platform seems to grabbing consumer attention slowly but steadily. Though the installed user base is nowhere close to that of Android or iOS,<a href="http://www.gartner.com/it/page.jsp?id=1622614"> </a>Gartner’s predictions<a href="http://www.gartner.com/it/page.jsp?id=1622614"> </a>notwithstanding, in the last few months we’ve seen an increasing interest from companies on this new mobile platform.</li>
<li><a href="http://www.room362.com/blog/2011/9/17/who-is-logged-in-a-quick-way-to-pick-your-targets.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Room362com+(Room362.com)">Who is Logged In? A Quick Way To Pick Your Targets</a> &#8211; room362.com<br />
Say you go for the 500+ shells on an internal test or your phishing exersice goes way better than you thought. Well you need to get your bearings quickly and going into each shell and doing a ps, then looking through the list for all the users logged in is a bit of a pain and defintely not ideal.</li>
<li><a href="http://spareclockcycles.org/2011/09/18/exploitring-the-wordpress-extension-repos/">Exploiting The WordpPress Extension Repos</a> &#8211; spareclockcycles.org<br />
Today&#8217;s post is kind of long, so I thought I should warn you in advance by adding an additional paragraph for you to read. I also wanted to provide download links for those who&#8217;d rather just read the code. It isn&#8217;t the cleanest code in the world, so I apologize in advance. I discuss what all of these are for and how they work later on in the post, so if you&#8217;re confused and/or curious, read on.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/Adobe-closes-14-holes-in-Reader-and-Acrobat-1342490.html">Adobe Closes 14 Holes In Reader and Acrobat</a> &#8211; h-online.com<br />
Adobe has released new versions of Reader and Acrobat to close several critical security holes. Versions 10.x, 9.x and 8.x of both products for Windows, Linux and Mac are affected. Adobe recommends that Reader X and Acrobat X users update to version 10.1.1 as this version offers added protection under Windows through its sandbox.</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li><a href="http://www.computerworld.com/s/article/9219930/Certificate_hacker_probably_paid_by_Iran_say_victimized_firms?source=rss_security&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+computerworld/s/feed/topic/82+(Computerworld+Cybercrime+and+Hacking+News)">Certificate hacker probably paid by Iran, say victimized firms</a> - computerworld.com<br />
The CEO of a certificate-issuing company that was hacked in March is even more certain now that a wave of attacks against similar firms is backed by the Iranian government.</li>
<li><a href="http://www.computerworld.com/s/article/9220017/U.S._agencies_making_progress_on_cybercrime_officials_say?source=rss_security&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+computerworld/s/feed/topic/82+(Computerworld+Cybercrime+and+Hacking+News)">U.S. Agencies Making Progress In Cybercrime</a> &#8211; computerworld.com<br />
U.S. government agencies are getting better at sharing information about cyberattacks with private companies, but cybercrime shows no signs of slowing down, cybersecurity experts told lawmakers Wednesday.</li>
<li><a href="http://www.darkreading.com/database-security/167901020/security/news/231601414/seven-ways-you-give-thieves-dibs-on-your-database.html">Seven Ways You Give Thieves Dibs On Your Database</a> &#8211; darkreading.com<br />
Every new data breach that hits the headlines snowballs the embarrassment for the IT security community, especially because this constant follies show revolves around recurring themes.</li>
<li><a href="http://news.cnet.com/8301-1009_3-20106450-83/u.s-australia-to-add-cyber-realm-to-defense-pact/?part=rss&amp;tag=feed&amp;subj=News-Security">U.S. and Australia to add cyber-realm in defense pact</a> &#8211; news.cnet.com<br />
Cyberattacks are about to carry even more weight, with the United States and Australia expected to include them in a mutual defense treaty.The two nations will declare the cyber realm to be part of the 60-year-old treaty tomorrow, Reuters reports. The inclusion will mean that a cyberattack on one country could lead to a response by both.</li>
<li><a href="http://news.cnet.com/8301-27080_3-20107611-245/italian-researcher-finds-more-scada-holes/?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">Italian Researcher Finds More SCADA Holes</a> &#8211; news.cnet.com<br />
An Italian researcher has uncovered at least a dozen security flaws in software used in utilities and other critical infrastructure systems, prompting security advisories from the U.S. government.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1839&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/09/19/week-37-in-review-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 34 In Review</title>
		<link>http://infosecevents.net/2011/08/29/week-34-in-review-2/</link>
		<comments>http://infosecevents.net/2011/08/29/week-34-in-review-2/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 22:05:11 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[DEFCON]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1815</guid>
		<description><![CDATA[Events Related DefCon 2011 Leftover notes and resources five weeks after. Crack Me If You Can teams &#8211; contest.korelogic.com Crack Me If You Can InsidePro &#8211; contest.korelogic.com Crack Me If You Can team john users &#8211; contest.korelogic.com The Art of Exploiting Lesser Known Injection Flaws Revealed At BlackHat &#8211; penetration-testing.7safe.com The audience at Black Hat, Las Vegas [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li>DefCon 2011<br />
Leftover notes and resources five weeks after.</li>
<ul>
<li><a href="http://contest.korelogic.com/teams.html">Crack Me If You Can teams</a> &#8211; contest.korelogic.com</li>
<li><a href="http://contest.korelogic.com/team_Insidepro_2011.html">Crack Me If You Can InsidePro</a> &#8211; contest.korelogic.com</li>
<li><a href="http://contest.korelogic.com/team_john-users.html">Crack Me If You Can team john users</a> &#8211; contest.korelogic.com</li>
</ul>
<li><a href="http://penetration-testing.7safe.com/the-art-of-exploiting-lesser-known-injection-flaws-revealed-at-black-hat/">The Art of Exploiting Lesser Known Injection Flaws Revealed At BlackHat</a> &#8211; penetration-testing.7safe.com<br />
The audience at Black Hat, Las Vegas were recently engaged by an interactive workshop titled ‘The Art of Exploiting Lesser Known Injection Flaws’ presented by 7Safe renowned security researchers Sumit Siddarth and Aleksander Gorkowienko.</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li><a href="https://code.google.com/p/owasp-goatdroid/">OWASP Goatdroid</a> - code.google.com/p/owasp-goatdroid/<br />
The OWASP GoatDroid Project pays homage to the OWASP WebGoat Project. It is a fully functional and self-contained environment for learning more about vulnerabilities and security issues for the Android platform.</li>
<li><a href="http://usa.visa.com/download/merchants/webinar-identifying-and-detecting-breaches-08172011.pdf?Aug202011">Identifying And Detecting Security Breaches</a> &#8211; usa.visa.com<br />
Visa has a slidedeck posted Identifying and Detecting Security Breaches. Sounds fun! If you&#8217;ve been around security for a while, nothing will be new in this deck, but it&#8217;s a nice and short to breeze through for ideas if something is missing in your enterprise security posture. Every bullet point also makes for a decent item to review or ask your team (if you have one) to describe how it is handled. (I do believe in role-playing!)</li>
<li><a href="http://www.securityaegis.com/the-big-fat-metasploit-post/">The Big Fat Metasploit Post</a> &#8211; securityaegis.com<br />
A while ago we tried to identify a core toolset that every pentester should start with or couldn’t live without. The first article focused on Nmap, The second on our list is none other than the exploit framework Metasploit. Instead of reinventing the wheel with Metasploit guides we decided to take all the disparate info on using Metasploit and put it into one place, starting from the basics all the way to advanced testing.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://code.google.com/p/zaproxy/downloads/list">The Zaproxy files</a> &#8211; code.google.com/p/zaproxy/downloads/list<br />
An easy to use penetration testing tool.</li>
<li><a href="http://hexale.blogspot.com/2011/08/wce-v12-64-bit-version-released.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Hexale+(hexale)">WCE v1.2 64-bit version released</a> &#8211; hexale.blogspot.com</li>
<li><a href="http://erpscan.com/products/erpscan-webxml-checker/">The ERPScan WEBXML Checker!</a> &#8211; erpscan.com/products<br />
As all of us know the importance of SAP (short for Systems, Applications and Products) systems. We also know that with increased exposure to new technologies, newer vulnerabilities are found. ERPScan WEBXML Checker, is a new tool from who we consider as a leading entity involved with discovering new SAP related vulnerabilities.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://www.skullsecurity.org/blog/2011/a-deeper-look-at-ms11-058">A deeper look at ms11 &#8211; 058</a> &#8211; skullsecurity.org<br />
Two weeks ago today, Microsoft released a bunch of bulletins for Patch Tuesday. One of them – ms11-058 – was rated critical and potentially exploitable. However, according to Microsoft, this is a simple integer overflow, leading to a huge memcpy leading to a DoS and nothing more. I disagree.</li>
<li><a href="http://software-security.sans.org/blog/2011/08/23/oauth-mobile-hack-password-tracking-in-malicious-ios-apps">Password Tracking In Malicious iOS Apps</a> &#8211; software-security.sans.org<br />
In this article, John Bielich and Khash Kiani introduce OAuth, and demonstrate one type of approach in which a malicious native client application can compromise sensitive end-user data.</li>
<li><a href="http://eromang.zataz.com/2011/08/24/cve-2011-3192-apache-httpd-killer-remote-denial-of-service/">Apache HTTPD Killer Remote Denial of Service</a> &#8211; eromang.zataz.com<br />
Kingcope has release, the 19 August, on Full disclosure mailing-list a perl script named “<em>killapache.pl</em>“ how can cause to Apache HTTPD Web server a remote denial of service (DoS). The DoS could be done by the attacker with a low requirement of ressources (CPU, memory and bandwidth) causing the targeted Web server to consume a big amount of ressources (CPU and memory). Apache HTTPD 2.0 and 2.2 series are affected by this vulnerability.</li>
<li><a href="http://intrepidusgroup.com/insight/2011/08/setting-up-a-persistent-trusted-ca-in-an-android-emulator/">Setting up a persistent trusted CA in an Android emulator </a>- intrepidusgroup.com<br />
Setting up a persistent trusted CA in the Android emulator is a common problem, encountered any time we assess an application within an emulator, that use SSL properly. The goal is to man-in-the-middle (MITM) traffic from an application running in the Android emulator.</li>
<li><a href="http://www.room362.com/blog/2011/8/26/iis-search-verb-directory-listing.html">IIS Search Verb Directory Listing</a> &#8211; room362.com</li>
<li><a href="http://www.l1pht.com/2011/08/my-flash-9-workflow/">My Flash 9 Workflow</a> - www.l1pht.com/2011/08/my-flash-9-workflow/<br />
Just recently I’ve tested a number of web applications that made heavy use of Adobe Flash. Considering I didn’t find a whole lot when I was searching I thought I’d document my current workflow.</li>
<li><a href="http://pentestmonkey.net/cheat-sheet/ssh-cheat-sheet?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+pentestmonkey+(pentestmonkey.net+RSS+Feed)">SSH Cheat Sheet</a> &#8211; pentestmonkey.net<br />
SSH has several features that are useful during pentesting and auditing.  This page aims to remind us of the syntax for the most useful features.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/microsoft-releases-new-versions-software-security-tools-082511">Microsoft Releases New Versions of Software Security Tools</a> &#8211; threatpost.com<br />
Microsoft has released new versions of several of its software security tools, including itsThreat Modeling Tool and a pair of fuzzers. All of the tools are part of the company&#8217;s Security Development Lifecycle program, which it has been sharing with external organizations for a few years now.</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li>BART, Anonymous, and a girl hacker<br />
The purported hacker who infiltrated the BART&#8217;s Police Officers Association website today claims to be a French girl (&#8220;Humiliating, huh?&#8221;) who executed her first hack, SF Weekly has learned. SF Weekly chatted online with someone who claimed to be the mind behind today&#8217;s attack.</li>
<ul>
<li><a href="http://blogs.sfweekly.com/thesnitch/2011/08/bart_police_site_break-in_was.php">BART Police Website Hacker Claims To Be French Girl On First Hack part 1</a> &#8211; blogs.sfweekly.com</li>
<li><a href="http://blogs.sfweekly.com/thesnitch/2011/08/bart_police_site_break-in_was.php?page=2">BART Police Website Hacker Claims To Be French Girl On First Hack part 2</a> - blogs.sfweekly.com</li>
<li><a href="http://www.lightbluetouchpaper.org/2011/08/24/randomly-generated-passwords-at-mybart/">Randomly generated passwords at myBART</a> &#8211; lightbluetouchpaper.org</li>
</ul>
<li>The Great RSA Hack<br />
The current theory is that a nation-state wanted to break in to Lockheed-Martin and Northrop-Grumman to steal military secrets. They couldn&#8217;t do it, since these companies were using RSA SecurID tokens for network authentication. So, the hackers broke into RSA with a targeted email attack.</li>
<ul>
<li><a href="http://www.f-secure.com/weblog/archives/00002226.html">How We Found The File That Was Used To Hack RSA</a> - f-secure.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/08/how-rsa-got-hacked/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))">Researchers Recover RSA Phishing Attack, Hiding In Plain Sight</a> - wired.com</li>
</ul>
<li><a href="http://www.wired.com/gadgetlab/2011/08/android-malware-explodes-ios-remains-safe/">Android Malware Explodes, iOS Remains Safe</a> &#8211; wired.com<br />
According to a report by antivirus software maker McAfee, Android is now the “most attacked mobile operating system,” with a jump in malware attacks of 76 percent in <em>the last quarter</em>. This impressive win is even more so when you consider that Android “outpaces second place Java ME threefold”.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1815&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/08/29/week-34-in-review-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 27 In Review</title>
		<link>http://infosecevents.net/2011/07/11/week-27-in-review/</link>
		<comments>http://infosecevents.net/2011/07/11/week-27-in-review/#comments</comments>
		<pubDate>Mon, 11 Jul 2011 21:35:50 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[OWASP AppSec]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1766</guid>
		<description><![CDATA[Events Related OWASP AppSec 2011 Capture The Flag briefings Capture The Flag &#8211; www.appsecusa.org/ctf.html AppSecUSA CTF! Another Write Up &#8211; notsosecure.com Resources Whitepaper &#8220;Python Arsenal For Reverse Engineering&#8221; - dsecrg.com This whitepaper (beta release) is a collection of various Python engines, extensions, libraries, shells, that aids in the job code for understanding, analyzing and sometimes breaking. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li>OWASP AppSec 2011<br />
Capture The Flag briefings</li>
<ul>
<li><a href="http://www.appsecusa.org/ctf.html">Capture The Flag</a> &#8211; www.appsecusa.org/ctf.html</li>
<li><a href="http://www.notsosecure.com/folder2/2011/07/06/appsecusa-ctf-another-write-up/">AppSecUSA CTF! Another Write Up</a> &#8211; notsosecure.com</li>
</ul>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li><a href="http://dsecrg.com/pages/pub/show.php?id=39&amp;utm_source=twitterfeed&amp;utm_medium=twitter&amp;utm_campaign=Feed:+dsecrg_pub+(Publications:+Digital+Security+Research+Group)">Whitepaper &#8220;Python Arsenal For Reverse Engineering&#8221;</a> - dsecrg.com<br />
This whitepaper (beta release) is a collection of various Python engines, extensions, libraries, shells, that aids in the job code for understanding, analyzing and sometimes breaking. The collection consists of more than 40 projects. This document is intended to show the power of Python for RE and also an attempt to systematize a knowledge of the python for RE. This document is useful for beginners and advanced professionals of RE.</li>
<li><a href="http://www.dsd.gov.au/publications/iOS_Hardening_Guide.pdf">Australian Department of Defence &#8211;  iOS Hardening Configuration Guide</a> &#8211; djtechnocrat.blogspot.com<br />
Parts of this guide refer to features that require the engagement of the technical resources of your telephony carrier, firewall vendor, or Mobile Device Management vendor. While every effort has been made to ensure content involving these third party products is correct at the time of writing, you should always check with these vendors when planning an implementation.</li>
<li><a href="http://iase.disa.mil/stigs/net_perimeter/wireless/smartphone.html">Smartphone Whitepapers</a> - iase.disa.mil/stigs/net_perimeter/wireless/smartphone.html<br />
Smartphone (iOS, Android, Blackberry, Windows)  guidance documents.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li>Skipfish<br />
Skipfish is a fully automated, active we application security reconnaissance tool. Its key features are high speed, ease of use, and cutting edge security logic.</li>
<ul>
<li><a href="http://code.google.com/p/skipfish/downloads/list">UPDATE: Skipfish 2.01b</a>! &#8211; code.google.com/p/skipfish/downloads/list</li>
<li><a href="http://code.google.com/p/skipfish/downloads/list">UPDATE: Skipfish 2.02b</a>! &#8211; code.google.com/p/skipfish/downloads/list</li>
</ul>
<li><a href="http://sourceforge.net/projects/sqlninja/files/sqlninja/">UPDATE: SQLNinja 0.2.6-rc1!</a> &#8211; sourceforge.net/projects/sqlninja/files/sqlninja/<br />
Sqlninja is a tool targeted to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal is to provide a remote access on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to help and automate the process of taking over a DB Server when a SQL Injection vulnerability has been discovered.</li>
<li><a href="https://github.com/hammackj/risu/archives/master">UPDATE: Risu v1.4.5!</a> &#8211; github.com/hammackj/risu/archives/master<br />
Risu is a Nessus parser, that converts the generated reports into a ActiveRecord database, this allows for easy report generation and vulnerability verification.</li>
<li><a href="http://code.google.com/p/beef/downloads/list">UPDATE:  BeEF v0.4.2.7-alpha!</a> &#8211; code.google.com/p/beef/downloads/list<br />
BeEF, the Browser Exploitation Framework is a professional security tool provided for lawful research and testing purposes. It allows the experienced penetration tester or system administrator additional attack vectors when assessing the posture of a target. The user of BeEF will control which browser will launch which exploit and at which target.</li>
<li><a href="http://code.google.com/p/zaproxy/downloads/list">UPDATE: ZAProxy v1.3.1!</a> - code.google.com/p/zaproxy/downloads/list<br />
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen testers toolbox. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.</li>
<li><a href="http://www.darknet.org.uk/2011/07/vega-open-source-cross-platform-web-application-security-assessment-platform/">Vega – Open Source Cross Platform Web-Application Security Assessment Platform</a> &#8211; darknet.org.uk<br />
Vega is an open source platform to test the security of web applications. Vega can help you find and validate SQL Injections, Cross-Site Scripting (XSS), inadvertently disclosed sensitive information, and other vulnerabilities. It is written in Java, GUI based, and runs on Linux, OS X, and Windows.</li>
<li><a href="http://www.taddong.com/tools/TLSSLed_v1.1.sh">TLSSLed v1.1</a> &#8211; blog.taddong.com<br />
A few weeks ago we released TLSSLed v1.0 with the goal of helping organizations to test their SSL/TLS (HTTPS) implementation for common flaws and misconfigurations. Today, we release an updated version, v1.1, that includes some additional tests.</li>
<li><a href="http://durandal-project.org/download.html">Durandal: A Distributed CPU/GPU Hashcracker!</a> &#8211; durandal-project.org/download.html<br />
Durandal is a distributed GPU/CPU computingsoftware that aims to crack passwords. Mostly written in C++ with the Boost library, it works on many systems, however it is only built for Windows and GNU/Linux for the moment x64 platforms.</li>
<li><a href="https://github.com/sirg3/Sniffer">Sniffer files</a> - github.com/sirg3/Sniffer<br />
Sniffer is an unoriginally-named packet sniffer with the unique ability of determining which application a packet is coming from (or going to). At the moment it is little more than a prototype to prove that the idea works.</li>
<li><a href="http://www.surgeonix.com/blog/downloads/websurgery/websurgery.zip">WebSurgery: A Web Application Secuity Toolkit</a> &#8211; www.surgeonix.com/blog/downloads/websurgery/websurgery.zip<br />
It is a suite of tools for security testing of web applications. It is designed for security auditors to help them with the web application planning and exploitation. Currently, it uses an efficient, fast and stable Web Crawler, File/Dir Brute forcer and Fuzzer for advanced exploitation of known and unusual vulnerabilities such as SQL Injections, Cross site scripting (XSS), Brute force for login forms.</li>
<li><a href="http://stalkr.net/files/twitter/python-twitter-tools/">Twitter Archiver </a>- blog.stalkr.net<br />
Twitter is great to get and share information, quickly. But it is all web 2.0 and you cannot use a simple cat or grep to view or search your tweets. I would like to have tweets saved in simple text format: date, user, text &#8211; one per line. So here comes Twitter Archiver, a small python script using PTT to archive any public timeline of tweets, in simple text format. Script: archiver.py, patch: archiver.diff.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li>Shellcode Anatomy<br />
Hackers are becoming more sophisticated and are investing resources to evade anti-malware detection. As recent breaches have shown, hackers are already seeing the fruits of their labor. In these spear-phishing attacks, the hacker gained access by sending out files (whether PDF, Excel or Word docs) to company employees. All that was needed was a single individual to open that file – and the attacker penetrated the organization.</li>
<ul>
<li><a href="http://blog.imperva.com/2011/07/shellcode-anatomy-part-i-of-iv.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Imperviews+(ImperViews)">Part I of IV</a> &#8211; blog.imperva.com</li>
<li>Part II of IV &#8211; coming next week!</li>
</ul>
<li><a href="https://community.rapid7.com/community/nexpose/blog/2011/07/01/detecting-ldap-injections">Detecting LDAP Injections</a> &#8211; rapid7.com<br />
It all started to go wrong when Web applications started to replace internal desktop applications in many companies around the globe and one manager proposed: &#8220;We should authenticate access to this application using our Active Directory!&#8221;</li>
<li><a href="http://intrepidusgroup.com/insight/2011/07/reversing-jailbreakme-com-4/">Reversing Jailbreakme.com 4.3.3 </a>- intrepidusgroup.com<br />
Wednesday, @comex came out with a new user-level jailbreak available on jailbreakme.com. I wanted to understand exactly how this exploit is able to get root so easily. Here is my workflow, and preliminary analysis of the exploit.</li>
<li><a href="http://crucialsecurityblog.harris.com/2011/07/06/decoding-data-exfiltration-%E2%80%93-reversing-xor-encryption/">Decoding Data Exfiltration &#8211; Reversing XOR Encryption</a> &#8211; crucialsecurityblog.herris.com<br />
One of the first and most important questions that intrusion analysts are asked after a network attack is “did they steal anything?”. And if so, “what did they take?”. Often, this is also one of the most challenging questions to answer when the analyst only has a post-intrusion forensic image to work with. Frequently, the analyst’s primary objective becomes identifying and locating data exfiltration files.</li>
<li><a href="http://www.sectechno.com/2011/07/06/csrf-exploit-for-joomla-1-6-3-or-lower/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Sectechno+(SecTechno)">SRF Exploit for Joomla 1.6.3 or Lower</a> &#8211; sectechno.com<br />
New exploit has been published that are targeting Joomla 1.6.3 or lower version the vulnerability  allow an attacker to create a specially crafted URL that would execute arbitrary script code on  victim’s browser.</li>
<li><a href="http://o2platform.wordpress.com/2011/07/07/injecting-o2-into-another-net-process-in-this-case-nunit-exe/">Injecting O2 into another .NET Process (in this case NUnit.exe)</a> &#8211; o2platform.wordpress.com<br />
Here is a pretty powerful example of what can be done with O2′s .NET reflection APIs. The objective is to start NUnit under the control of an O2 script and to add a new feature to NUnit (in this case a new error viewer)</li>
<li><a href="http://www.netspi.com/blog/2011/07/07/hacking-with-jsp-shells/">Hacking With JSP Shells</a> &#8211; netspi.com<br />
Most enterprise datacenters today house at least a few web servers that support Java Server Pages (JSP). In my experience, at least one will suffer from vulnerabilities that can be leveraged to upload JSP shells and execute arbitrary commands on the server (this especially seems to be the case with preconfigured appliances).</li>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2011/07/08/jsobfu?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+metasploit/blog+(Metasploit+Blog)">JavaScript Obfuscation in Metasploit</a> &#8211; community.rapid7.com<br />
As of this writing, Metasploit has 152 browser exploits. Of those, 116 use javascript either to trigger the vulnerability or as a means to control the memory layout of the browser process [1]. Right now most of that javascript is static. That makes it easier for anti-virus and IDS folks to signature. That makes it less likely for you to get a shell.</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li><a href="http://www.newscientist.com/article/dn20649-exclusive-first-interview-with-key-lulzsec-hacker.html?full=true&amp;print=true">Exclusive first interview with key LulzSec hacker</a> &#8211; newscientist.com<br />
It was early May when LulzSec&#8217;s profile skyrocketed after a hack on the giant Sony corporation. LulzSec&#8217;s name comes from Lulz, a corruption of LOL, often denoting laughter at the victim of a prank. For 50 days until it disbanded, the group&#8217;s unique blend of humour, taunting and unapologetic data theft made it notorious.</li>
<li><a href="http://www.h-online.com/security/features/iOpener-How-safe-is-your-iPhone-data-1266713.html">iOpener: How Safe is your iPhone data!</a> &#8211; h-online.com<br />
The greatest current risk for iPhone owners is not viruses or malicious web pages, it is the danger that the phone might fall into someone else&#8217;s hands. Although iPhones do offer elaborate security mechanisms, these mechanisms won&#8217;t stand up to an imaginative hacker.</li>
<li><a href="http://risky.biz/auscert-bind">AusCERT jumps the gun on BIND bug release</a> - risky.biz<br />
AusCERT has broken an embargo, accidentally and prematurely broadcasting a security bulletin pertaining to multiple vulnerabilities in the BIND DNS server earlier today.</li>
<li><a href="http://www.h-online.com/security/news/item/Vsftpd-backdoor-discovered-in-source-code-update-1272310.html">Vsftpd backdoor discovered in source code &#8211; update</a> &#8211; h-online.com<br />
Chris Evans, aka Scary Beasts, has confirmed that version 2.3.4 of vsftpd&#8217;s downloadable source code was compromised and a backdoor added to the code. Evans, the author of vsftpd – which is described on its web site as &#8220;probably the most secure and fastest FTP server for Unix-like systems&#8221; – was alerted on Sunday to the fact that a bad tarball had been downloaded from the vsftpd master site with an invalid GPG signature. It is not known how long the bad code had been online.</li>
<li><a href="http://www.h-online.com/security/news/item/Cracking-DES-faster-with-John-the-Ripper-1273585.html">Cracking DES faster with John the Ripper</a> &#8211; h-online.com<br />
Version 1.7.8 of John the Ripper, a free password cracker, promises to be up to 20 per cent faster when cracking the Data Encryption Standard (DES) algorithm. The increase in speed is achieved by improvements in the processing of S-box. Although AES (Advanced Encryption Standard) has long been the encryption standard of choice, encryption and decryption with (triple) DES remain useful techniques.</li>
<li><a href="http://krebsonsecurity.com/2011/07/which-banks-are-enabling-fake-av-scams/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+KrebsOnSecurity+(Krebs+on+Security)">Which Banks Are Enabling Fake AV Scams?</a> &#8211; krebsonsecurity.com<br />
Fake antivirus scams and rogue Internet pharmacies relentlessly seek customers who are willing to trade their credit card numbers for a remedy. Banks and financial institutions become partners in crime when they process payments to fraudsters.</li>
<li><a href="http://www.readwriteweb.com/archives/malware_exploit_found_for_ios_devices_by_german_re.php?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+readwriteweb+(ReadWriteWeb)">Malware Exploit Found for iOS Devices By German Researcher</a>s &#8211; readwriteweb.com<br />
Germany&#8217;s Federal Office for Information Security issued a warning today that iPhones, iPads and the iPod Touch have &#8220;critical weaknesses,&#8221; the Associated Press reports. The malware is delivered by an infected PDF that can affect the user&#8217;s device without them knowing. The same result would occur when a user visits a website with an infected PDF.</li>
<li><a href="http://www.darkreading.com/security/news/231001109/sophisticated-cyberattack-hits-pacific-northwest-national-lab.html">&#8216;Sophisticated Cyberattack&#8217; Hits Pacific Northwest National Lab</a> &#8211; darkreading.com<br />
Pacific Northwest National Labs, a research and development facility operated under contract to the Department of Energy, was attacked during the long holiday weekend and is still struggling to restore IT services.</li>
<li><a href="http://www.fastcompany.com/1765855/dhs-someones-spiking-our-imported-tech-with-attack-tools">DHS: Imported Consumer Tech Contains Hidden Hacker Attack Tools</a> &#8211; fastcompany.com<br />
A top Department of Homeland Security (DHS) official has admitted on the record that electronics sold in the U.S. are being preloaded with spyware, malware, and security-compromising components by unknown foreign parties.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1766&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/07/11/week-27-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 23 In Review</title>
		<link>http://infosecevents.net/2011/06/13/week-23-in-review/</link>
		<comments>http://infosecevents.net/2011/06/13/week-23-in-review/#comments</comments>
		<pubDate>Mon, 13 Jun 2011 18:44:15 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Defcon Quals]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1719</guid>
		<description><![CDATA[Events Related Defcon 19  Quals For the third year, I competed with team Shellphish in the Defcon quals. We pulled through with some amazing points at the end to finish in 8th place. My successful contributions, however, were really only with respect to Forensics 100 and 300 Defcon 19 Quals Forensics 100 and Forensics 300 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li>Defcon 19  Quals<br />
For the third year, I competed with team Shellphish in the Defcon quals.   We pulled through with some amazing points at the end to finish in 8th  place. My successful contributions, however, were really only with  respect to Forensics 100 and 300</p>
<ul>
<li><a href="http://www.bryceboe.com/2011/06/05/defcon-19-quals-forensics-100-and-forensics-300-solution/">Defcon 19 Quals Forensics 100 and Forensics 300 solution</a> &#8211; bryceboe.com</li>
<li><a href="http://blog.securestate.com/post/2011/06/06/Defcon-19-CTF-Pre-Quals-Binary-100-Challenge.aspx">Defcon 19 CTF Pre-Quals: Binary 100 Challenge</a> &#8211; blog.securestate.com</li>
<li><a href="http://blog.securestate.com/post/2011/06/06/DEFCON-19-CTF-Quals-Forensics-300.aspx">Defcon 19 CTF Quals: Forensic &#8211; 300</a> &#8211; blog.securestate.com</li>
<li><a href="http://leetmore.ctf.su/">Defcon CTF Quals 2011 &#8211; Retro 400</a> &#8211; leetmore.ctf.su</li>
<li><a href="http://leetmore.ctf.su/wp/defcon-ctf-quals-2011-pwnables-400/">Defcon CTF Quals 2011 &#8211; Pwnables 400</a> &#8211; leetmore.ctf.su</li>
<li><a href="http://translate.google.com/translate?hl=en&amp;sl=es&amp;u=http://nonroot.blogspot.com/2011/06/writeup-gb200-ctf-quals-defcon.html&amp;ei=rUfsTdb1LuLciALAy4ThCA&amp;sa=X&amp;oi=translate&amp;ct=result&amp;resnum=1&amp;ved=0CBwQ7gEwAA&amp;prev=/search%3Fq%3Dhttp://nonroot.blogspot.com/2011/06/writeup-gb200-ctf-quals-defcon.html%26hl%3Den%26prmd%3Divns">GB200 writeup DEFCON CTF quals</a> &#8211; nonroot.blogspot.com</li>
<li><a href="http://daxnitro.com/quals/">Quals files collection</a> &#8211; daxnitro.com/quals/</li>
<li><a href="http://rogunix.com/defconquals19.html">Defcon 19 Quals Write-up List</a> &#8211; rogunix.com/defconquals19.html</li>
<li><a href="http://auntitled.blogspot.com/2011/06/defcon-19-quals-pwntent-pwnables-200.html">Pwntent Pwnables 200 Writeup</a> &#8211; auntitled.blogspot.com</li>
<li><a href="http://repo.shell-storm.org/CTF/">Shell-Storm CTF resources</a> &#8211; repo.shell-storm.org/CTF</li>
</ul>
</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li>AppSecEU Presentations
<ul>
<li><a href="http://tmacuk.co.uk/personal/appseceu-brad-arkin-adobe-corp/">Brad Arkin of Adobe Corp</a></li>
<li><a href="http://tmacuk.co.uk/personal/appseceu-apt-in-a-nutshell-david-stubley/">David Stubley&#8217;s APT in a nutshell</a></li>
<li><a href="http://tmacuk.co.uk/personal/keynote-giles-hogben-enisa/">Giles Hogben INISA</a></li>
<li><a href="http://tmacuk.co.uk/personal/appseceu-arian-evans-whitehat-security/">Arian Evans on Whitehat Security</a></li>
</ul>
</li>
<li><a href="http://www.l1pht.com/2011/06/wordlists-from-sownage/">Wordlists from Sownage</a> &#8211; l1pht.com<br />
Here are a few cleaned up wordlists from the sownage files.  There are   more than a few throwaways in use here, but it still might be worth a  run in a few specific situations.</li>
<li><a href="http://blog.eset.com/2011/06/06/tdss-and-hacking-the-hackers">TDSS and hacking the hackers</a> &#8211; blog.eset.com<br />
If you&#8217;ve been following the research we&#8217;ve been publishing (spearheaded by my Russian colleagues Aleksandr Matrosov and Eugene Rodionov) you&#8217;ll be aware that the TDL rootkit family doesn’t make use of OS’s own file system.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li>Skipfish Update<br />
Skipfish is a fully automated, active web application security reconnaissance tool. Its key features: High speed, Ease of use, Cutting-edge security logic.</p>
<ul>
<li><a href="http://code.google.com/p/skipfish/downloads/list">UPDATE: Skipfish-1.91b!</a> &#8211; code.google.com/p/skipfish/downloads/list</li>
<li><a href="http://code.google.com/p/skipfish/downloads/list">UPDATE: Skipfish-1.92b! </a>- code.google.com/skipfish/downloads/list</li>
</ul>
</li>
<li><a href="http://nmap.org/dist/nmap-5.52.IPv6.Beta2.tar.bz2">UPDATE: Nmap 5.52.IPv6.Beta2! </a>- nmap.org<br />
Nmap (“Network Mapper”) is a free and open source utility for network exploration or security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime.</li>
<li><a href="https://github.com/sporst/SWFREtools/downloads">UPDATE: SWFRETools v1.2.0!</a> &#8211; github.com/sporst/SWFREtools/downloads<br />
The SWFRETools are a collection of tools built for vulnerability analysis of the Adobe Flash player and for malware analysis of malicious SWF files. The tools are partly written in Java and partly in Python and are licensed under the GPL 2.0 license.</li>
<li><a href="http://code.google.com/p/zaproxy/downloads/list">UDPATE: ZAProxyv1.3.0! </a>- code.google.com/zaproxy/downloads/list<br />
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen testers toolbox.</li>
<li><a href="http://radare.nopcode.org/get/radare2-0.7.tar.gz">RADARE: Reverse engineering framework</a> &#8211; radare.nopcode.org<br />
Opensource tools to disasm, debug, analyze and manipulate binary files. There are small tools also included for better deguging, graphs can be used to link and have a better idea over of the binary.</li>
<li><a href="http://portswigger.net/burp/download.html">Burpsuite free edition v1.4 released</a> &#8211; blog.portswigger.net<br />
This is a major upgrade with numerous new features, including: The ability to compare site maps, functions to help with testing access controls using your browser,support for preset request macros, session handling rules to help you work with difficult situations etc.</li>
<li><a href="http://www.securestate.com/Services/Profiling--Penetration/Pages/Recent%20Tools.aspx">SecureState Releases New Tool  For Footprinting 802.1x Wireless Networks</a> &#8211; blog.securestate.com<br />
Today, SecureState is releasing a new tool for footprinting 802.1x  wireless networks called EAPeak. EAPeak is a Python powered script that  is meant to parse useful pieces of information for a Security Assessment  of wireless networks that use the Enterprise Authentication Protocol.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li>Defcon Obfuscation Technique<br />
Feds aren&#8217;t the only ones who are  paying attention to the demonstrations at security conferences like  Black Hat and DEFCON &#8211; the folks who actually don the black hats are,  also.That point was driven home this week by Kaspersky Lab researcher  Marta Janus, who blogged about an interesting new code obfuscation  technique that she discovered while analyzing a Polish e-commerce Web  site that had been compromised.</p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/hackers-pinch-obfuscation-technique-defcon-presentation-060911">Hackers Pinch Obfuscation Technique From Defcon presentation</a> &#8211; threatpost.com</li>
<li><a href="http://www.securelist.com/en/blog/208188101/Dangerous_whitespaces">Dangerous Whitespaces</a> &#8211; securelist.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://www.cqure.net/wp/2011/06/using-nmap-for-pentesting-edirectory/">Using Nmap for Pentesting eDirectory</a> &#8211; cqure.net<br />
While  doing a security review the other day I came across Novell  eDirectory  running on Windows. It’s been a while since I looked at  eDirectory and  while it’s a lot of LDAP, the servers were also running  the Netware  Core Protocol (NCP).</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li>Microsoft Patch Tuesday (Tomorrow!)<br />
Microsoft has announced that it plans to release 16 security bulletins on Tuesday 14 June. The company rates nine of the bulletins as critical; the remaining seven are considered to be &#8220;Important&#8221;. According to Microsoft, the bulletins will patch a total of 34 vulnerabilities in its products.</p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/Microsoft-to-fix-many-critical-vulnerabilities-on-Patch-Tuesday-1258681.html">Microsoft Many Critical Vulnerabilities on Patch Tuesday</a> &#8211; h-online.com</li>
<li><a href="http://blogs.technet.com/b/msrc/archive/2011/06/09/june-advance-notification-service-and-10-immutable-laws-revisited.aspx">June Advance Notification Service And 10 Immutable Laws Revisited</a> &#8211; blogs.technet.com</li>
</ul>
</li>
<li>Flash Player Updates<br />
Adobe and VideoLAN have released security updates for some of their  software programs today. Adobe released a new version of Adobe Flash  Player which fixes a security vulnerability in the popular application.</p>
<ul>
<li><a href="http://www.ghacks.net/2011/06/06/flash-player-vlc-security-updates-released/">Flash Player, VLC Security Updates Released</a> &#8211; ghacks.net</li>
<li><a href="http://get.adobe.com/flashplayer/">Adobe Flash Player 10.3.181.22</a></li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://www.wireshark.org/download.html">Wireshark 1.6.0 Released</a> &#8211; wireshark.org<br />
Wireshark 1.6.0 has been released. Installers for Windows, Mac OS X  10.5.5 and above (Intel and PPC), and source code are now available.  Wireshark is now distributed as an installation package rather than a  drag-installer on OS X. The installer adds a startup item that should  make it easier to capture packets. Large file (greater than 2 GB)  support has been improved.</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li>RSA SecurID Revelation<br />
Lockheed Martin and RSA today each separately confirmed that the  breach  that compromised RSA&#8217;s SecurID authentication technology helped  lead to  the recent targeted attack aimed at the defense contractor.</li>
</ul>
<ul>
<li>
<ul>
<li><a href="http://www.darkreading.com/database-security/167901020/security/attacks-breaches/230200001/rsa-offers-securid-token-recall-for-customers-in-wake-of-lockheed-hack.html">RSA Offers SecurID Token Repalcement For Customers In Wake Of Lockheed Hack</a> &#8211; darkreading.com</li>
<li><a href="http://arstechnica.com/security/news/2011/06/rsa-finally-comes-clean-securid-is-compromised.ars?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+arstechnica%2Findex+%28Ars+Technica+-+Featured+Content%29">RSA Finally Comes Clean: SecurID is Compromised</a> &#8211; arstechnica.com</li>
<li><a href="http://www.darkreading.com/authentication/167901072/security/attacks-breaches/230300033/replacing-rsa-securid-tokens-not-so-simple.html">Replacing RSA SecurID Tokens Not So Simple</a> &#8211; darkreading.com</li>
<li><a href="http://stateofsecurity.com/?p=1625">Security Alert: RSA Breach and 7 Ways To Secure Your Tokens</a> &#8211; stateofsecurity.com</li>
<li><a href="http://dankaminsky.com/2011/06/09/securid/">On The RSA SecurID Compromise</a> &#8211; dankaminsky.com</li>
<li><a href="http://twitter.com/#!/hdmoore/statuses/79034896244408320">@hdmoore RSA Twitter Update </a></li>
</ul>
</li>
<li>The Ocean Bank Trial<br />
A closely-watched court battle over how far commercial banks need to go   to protect their customers from cyber theft is nearing an end. Experts   said the decision recommended by a magistrate last week — if adopted by  a  U.S. district court in Maine — will make it more difficult for   other  victim businesses to challenge the effectiveness of security   measures  employed by their banks.</p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2011/06/bank-ach-theft/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired27b+%28Blog+-+27B+Stroke+6+%28Threat+Level%29%29">Bank Not Responsible for Letting Hackers Steal $300K From Customer </a>- wired.com</li>
<li><a href="http://krebsonsecurity.com/2011/06/court-passwords-secret-questions-reasonable-ebanking-security/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29">Court: Passwords + Secret Questions = ‘Reasonable’ eBanking Security</a> &#8211; krebsonsecurity.com</li>
</ul>
</li>
<li><a href="http://krebsonsecurity.com/2011/06/java-patch-plugs-17-security-holes/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29">Java Patch Plugs 17 Security Holes </a>- krebsonsecurity.com<br />
Oracle today released an update to its ubiquitous Java software that fixes at least 17 security vulnerabilities in the program. The company is advising users to apply this update as soon as possible; it looks like most — if not all — of the vulnerabilities addressed by this new version may be exploited remotely without authentication.</li>
<li><a href="http://www.pcworld.com/businesscenter/article/230126/imf_is_victim_of_sophisticated_cyberattack_says_report.html">IMF is victim of &#8216;sophisticated cyberattack&#8217; says report</a> &#8211; pcworld.com<br />
The scope of the attack remains unknown, according to the New York Times, which broke news of the incident Saturday. But it noted that the IMF, which helps manage financial crises around the world, is &#8220;the repository of highly confidential information about the fiscal condition of many nations.&#8221;</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1719&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/06/13/week-23-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 12 In Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/03/28/week-12-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/03/28/week-12-in-review-2011/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 20:33:24 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Outerzone]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1554</guid>
		<description><![CDATA[Events Related Outerzone 2011 Hacker Con &#8211; irongeek.com The following are videos of the presentations from the Outerzone 2011 hacker conference. Resources web.config Security Analyzer This little beauty let’s you feed in a Web.config then it comes back and tells you everything you’ve done wrong in the world of security configuration. web.config Security Analyzer &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li><a href="http://www.irongeek.com/i.php?page=videos%2Fouterz0ne-2011-hacker-con&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+IrongeeksSecuritySite+%28Irongeek%27s+Security+Site%29">Outerzone 2011 Hacker Con</a> &#8211; irongeek.com<br />
The following are videos of the presentations from the  Outerzone 2011 hacker conference.</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li>web.config Security Analyzer<br />
This little beauty let’s you feed in a Web.config then it comes back and    tells you everything you’ve done wrong in the world of security    configuration.</p>
<ul>
<li><a href="http://www.wcanalyzer.com/">web.config Security Analyzer</a> &#8211; wcanalyzer.com</li>
<li><a href="http://www.troyhunt.com/2011/03/continuous-webconfig-security-analysis.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+TroyHunt+%28Troy+Hunt%29">Continuous Web.config security analysis with WCSA and TeamCity</a> &#8211; troyhunt.com</li>
</ul>
</li>
</ul>
<ul>
<li>OWASP Top 10<br />
If you’ve spent any time defending web applications as a security     analyst, or perhaps as a developer seeking to adhere to SDLC practices,     you have likely utilized or referenced the OWASP Top 10.</p>
<ul>
<li><a href="http://resources.infosecinstitute.com/owasp-top-10-tools-and-tactics/">OWASP Top 10 Tools and Tactics</a> &#8211; resources.infosecinstitute.com</li>
<li><a href="http://www.irongeek.com/i.php?page=security%2Fmutillidae-deliberately-vulnerable-php-owasp-top-10&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+IrongeeksSecuritySite+%28Irongeek%27s+Security+Site%29">A Deliberately Vulnerable Set of PHP Scripts That Implement the OWASP Top 10</a> &#8211; irongeek.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://blog.coresecurity.com/2011/03/21/focusing-on-the-spirit-of-nist%E2%80%99s-guidance-for-continuous-monitoring/">Focusing on the Spirit of NIST&#8217;s Guidance For Continuous Monitoring</a> &#8211; blog.coresecurity.com<br />
The National Institute of Standards and Technology (NIST) has regularly  recommended new guidance to help give agencies a clearer deployment path  to a more robust information security program.</li>
<li><a href="http://jps.anl.gov/Volume4_iss2/Paper3-RGJohnston.pdf">Viewpoint Paper on Threats and Vulnerabilities</a> &#8211; jps.anl.gov<br />
I would go even further and argue that understanding Vulnerabilities is more powerful than understanding Threats—regardless of the relative difficulty of TAs vs. VAs.</li>
<li><a href="http://www.thehackeracademy.com/the-key-skill-set-of-great-penetration-testers/">The Key Skill-Set of Great Penetration Testers</a> &#8211; thehackeracademy.com<br />
For me, the difference between Keatron’s list and a great penetration  tester comes down to one thing: intelligence types.   Specifically, the  difference between convergent intelligence and divergent intelligence.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://www.room362.com/blog/2011/3/20/metasploit-vnc-password-extraction.html">Metasploit VNC Password Extraction</a> &#8211; room362.com<br />
I ran into the same issue on Penetration Tests in the past but didn&#8217;t  know much about the wacked out version of DES that RFB (the VNC  protocol) was using.</li>
<li><a href="https://code.google.com/p/inspathx/source/browse/#svn%2Ftrunk">Update: Inspathx r66</a> &#8211; code.google.com<br />
Inspathx is a tool that uses local source tree to make requests to the URL and search for path inclusion error messages.</li>
<li><a href="http://sourceforge.net/projects/jbrofuzz/files/jbrofuzz/">Update: JBroFuzz 2.5!</a> &#8211; sourceforge.net<br />
JBroFuzz is a web application fuzzer for requests being made over HTTP or HTTPS. Its purpose is to provide a single, portable application that offers stable web protocol fuzzing capabilities.</li>
<li><a href="http://code.google.com/p/skipfish/downloads/list">Update: Skipfish-1.85b! </a>- code.google.com<br />
Skipfish is a fully automated, active web application security reconnaissance tool.</li>
<li><a href="http://github.com/urbanadventurer/WhatWeb">Update: WhatWeb v.0.4.6!</a> &#8211; github.com<br />
WhatWeb next generation web scanner identifies what websites are running. Released at the Kiwicon conference (kiwicon.org) in Wellington, New Zealand.</li>
<li><a href="http://www.corelan.be/index.php/2011/03/22/pastenum-pastebinpastie-enumeration-tool/">Pastenum &#8211; Pastebin/pastie enumeration tool </a>- corelan.be<br />
When conducting a pen-test, the process typically starts with the  reconnaissance phase, the process of gathering information about your  target(s) system, organization or person.</li>
<li><a href="http://www.securityaegis.com/the-open-pentest-bookmark-collection-v1-4/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+securityaegis%2FigXu+%28Security+Aegis%29">The Open Pentest Bookmark Collection v1.4</a> &#8211; securityaegis.com<br />
News, news, news… Hey guys and gals of the security community.  We are  pleased to announce the release of version 1.4 (yes 1.3 squeaked by  without a blog post) of the Open Pentest Bookmarks Collection.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/448">New SNMP Metasploit Modules </a>- carnal0wnage.attackresearch.com<br />
My new favorite modules (for today) are the snmp_enumusers and  snmp_enumshares modules that work against windows hosts that have snmp  running.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://www.willhackforsushi.com/?p=518">PenTest Perfect Storm 6: We Love Cisco!</a> &#8211; willhackforsushi.com<br />
In the webcast, hosted by CORE Security Technologies,  we discussed  attack techniques against Cisco devices, combining  wireless, network  and web app techniques to exploit common network  architectures.</li>
<li><a href="http://blog.metasploit.com/2011/03/adobe-flash-cve-2011-0609.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+metasploit%2Fblog+%28Metasploit+Blog%29">Metasploit: Adobe Flash CVE-2011 </a>- blog.metasploit.com<br />
Recently, I spent about a week and a half working on the latest 0-day  Flash vulnerability. I released a working exploit on March 22nd 2011.  The original exploit was just an attempt to get something working out  the door for all of our users.</li>
<li><a href="http://www.f-secure.com/weblog/archives/00002127.html">Attack using CVE-2011-0609</a> &#8211; f-secure.com<br />
Attackers have been taking advantage of the  situation in Japan to trick their targets into opening malicious files.  These cases have used infected Excel attachments with Flash exploits.</li>
<li><a href="http://www.packetstan.com/2011/03/extracting-ap-names-from-packet.html">Extracting AP names from Packet Captures</a> &#8211; packetstan.com<br />
Years ago, while working as a Network Engineer, I did a bit of sniffing   of our wireless access points. I noticed that some access point, mainly   Cisco, broadcast the Access Point&#8217;s name.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/Apple-releases-Mac-OS-X-10-6-7-update-1212226.html">Apple releases Mac OS x 10.6.7 update</a> &#8211; h-online.com<br />
In the software update notes, Apple also recommends the update &#8220;for all early 2011 MacBook Pro models&#8221;.</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=10597&amp;rss">Firefox 3 Updates and SSL Blacklist Extension</a> &#8211; isc.sans.edu<br />
At the heels of yesterday&#8217;s Firefox 4 release, we today got 3.6.16 and  3.5.18. As usual, Mozilla will provide security updates for some older  browsers after the release of a new major version.</li>
<li><a href="http://www.h-online.com/security/news/item/Adobe-fixes-vulnerabilities-in-Flash-AIR-and-Acrobat-1212406.html">Adobe fixes Vulnerabilities in Flash, AIR and Acrobat </a>- h-online.com<br />
Adobe has released updates to its Flash Player, Acrobat and Acrobat  Reader products to fix related security vulnerabilities in these  products that potentially allowed an attacker to compromise a  system by  means of a crafted SWF embedded in an Excel file.</li>
</ul>
<p><strong>Vulnerabilities</strong></p>
<ul>
<li>SCADA: The Luigi Auriemma files<br />
The security of critical infrastructure is in the spotlight again this      week after a researcher released attack code that can exploit several      vulnerabilities found in systems used at oil-, gas- and    water-management   facilities, as well as factories, around the world.</p>
<ul>
<li><a href="http://www.digitalbond.com/2011/03/22/interview-with-luigi-auriemma-of-34-0days-ics-vulnerabilities/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+digitalbond%2FoLPM+%28Digital+Bond%29">Interview with Luigi Auriemma of 34 0day ICS Vulnerabilities </a>- digitalbond.com</li>
<li><a href="http://www.digitalbond.com/2011/03/21/italian-researcher-publishes-34-ics-vulnerabilities/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+digitalbond%2FoLPM+%28Digital+Bond%29">Italian Researcher Publishes 34 ISC Vulnerabilities</a> &#8211; digitalbond.com</li>
<li><a href="http://seclists.org/bugtraq/2011/Mar/187">Vulnerabilities in some SCADA server software</a> &#8211; seclists.org</li>
<li><a href="http://www.wired.com/threatlevel/2011/03/scada-vulnerabilities/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired27b+%28Blog+-+27B+Stroke+6+%28Threat+Level%29%29">Attack Code For SCADA Vulnerabilities Released Online </a>- wired.com</li>
<li><a href="http://www.h-online.com/security/news/item/Another-zero-day-exploit-for-SCADA-systems-1215450.html">Another zero-day exploit for SCADA systems </a>- h-online.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://blog.fortinet.com/advanced-exploitation-of-the-recent-flash-zero-day-vulnerability-cve-2011-0609/">Advanced Exploitation of the recent Flash Zero-Day Vulnerability</a> &#8211; blog.fortinet.com<br />
Looking into it more in-depth, I was then able to confirm that this  vulnerability is a perfect real-world example of program flow validation  error.</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li>The Comodo Conspiracy<br />
Thus, while an Iranian state-sponsored attack is a plausible theory, it’s not the only one.</p>
<ul>
<li><a href="http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html">List of Fraudulently Issued Certificates </a>- comodo.com</li>
<li><a href="http://erratasec.blogspot.com/2011/03/brief-introduction-to-web-certificates.html">A brief introduction to web &#8216;certificates&#8217; </a>- erratasec.blogspot.com</li>
<li><a href="http://erratasec.blogspot.com/2011/03/no-evidence-comodo-compromise-was-from.html">No Reason to Believe Comodo Attack Came from Iranian Government</a> &#8211; erratasec.blogspot.com</li>
<li><a href="http://www.freedom-to-tinker.com/blog/sjs/web-browsers-and-comodo-disclose-successful-certificate-authority-attack-perhaps-iran">Web Browsers and Comodo Disclose A Succesful Certificate Authority Attack, Perhaps from Iran </a>- freedom-to-tinker.com</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=10603&amp;rss">Comodo RA Compromise </a>- isc.sans.edu</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=10600&amp;rss">Microsoft Advisory About Stolen SSL Crtificates</a> &#8211; isc.sans.edu</li>
<li><a href="http://www.zdnet.com/blog/security/microsoft-warns-fraudulent-digital-certificates-issued-for-high-value-websites/8488">Microsoft Warns: Fraudulent digital certificates issued for high value websites </a>- zdnet.com</li>
<li><a href="http://djtechnocrat.blogspot.com/2011/03/comodo-ca-compromised-by-iran.html">Comodo CA Compromised by Iran?</a> &#8211; djtechnocrat.blogspot.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/03/comodo-compromise/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired27b+%28Blog+-+27B+Stroke+6+%28Threat+Level%29%29">Hack Obtains 9 Certificates to prominent Websites; traced to Iran</a> &#8211; wired.com</li>
<li><a href="http://www.h-online.com/security/news/item/SSL-meltdown-forces-browser-developers-to-update-1213358.html">SSL meltdown forces browser developers to update</a> &#8211; h-online.com</li>
<li><a href="http://threatpost.com/en_us/blogs/phony-ssl-certificates-issued-google-yahoo-skype-others-032311">Phony SSL Certificates issued to Google, Yahoo, Skype and others</a> &#8211; threatpost.com</li>
<li><a href="http://nakedsecurity.sophos.com/2011/03/24/fraudulent-certificates-issued-by-comodo-is-it-time-to-rethink-who-we-trust/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29">Fraudulent Certificates Issued by Comodo, is it time to rethink who we trust?</a> &#8211; nakedsecurity.sophos.com</li>
<li><a href="http://arstechnica.com/security/news/2011/03/how-the-comodo-certificate-fraud-calls-ca-trust-into-question.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss">How the Comodo Certificate fraud calls CA trust into question </a>- arstechnica.com</li>
<li><a href="http://blog.mozilla.com/security/2011/03/25/comodo-certificate-issue-follow-up/">Comodo certificate issue follow up</a> &#8211; blog.mozilla.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://krebsonsecurity.com/2011/03/homegrown-rustock-botnet-fed-by-u-s-firms/">Homegrown: Rustock Botnet fed By U.S. Firms</a> &#8211; krebsonsecurity.com<br />
Aaron Wendel opened the doors of his business to some unexpected visitors on the morning of Mar. 16, 2011.</li>
</ul>
<ul>
<li><a href="http://resources.infosecinstitute.com/hd-moore-reveals-his-process-for-security-research/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+infosecResources+%28InfoSec+Resources%29">HD Moore Releases His Process for Security Research</a> &#8211; resources.infosecinstitute.com<br />
HD Moore is Chief Security Officer at Rapid7 and Chief Architect of   Metasploit, the leading open-source penetration testing platform.</li>
<li><a href="http://www.h-online.com/security/news/item/Industrial-Control-Systems-security-holes-galore-1212336.html">Industrial Control Systems: security holes galore </a>- h-online.com<br />
It seems that Stuxnet has given many security experts an interest in the  potential holes in industrial control and SCADA (Supervisory Control  and Data Acquisition) systems.</li>
<li><a href="http://securosis.com/blog/mcafee-acquires-sentrigo">McAfee Acquires Sentrigo</a> &#8211; securosis.com<br />
McAfee has had a partnership with Sentrigo for a couple years, and both  companies have cooperatively sold the Sentrigo solution and developed  high-level integration with McAfee’s security management software.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1554&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/03/28/week-12-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 6 In Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/02/14/week-6-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/02/14/week-6-in-review-2011/#comments</comments>
		<pubDate>Mon, 14 Feb 2011 10:32:22 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Local Meetings]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[ShmooCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1463</guid>
		<description><![CDATA[Events Related ShmooCon CTF 2011 Ghost In the Shellcode &#8211; ghostintheshellcode.com Congratulations to ppp for winning the second GitS CTF! The game board as it was when the contest ended is now live, though answers are not accepted, nor are any of the exploitable services running. Just like the real thing - blog.uncommonsensesecurity.com The goal is [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li><a href="http://www.mediafire.com/?a6cj7atbp2j2bo7">ShmooCon CTF 2011 Ghost In the Shellcode</a> &#8211; ghostintheshellcode.com<br />
Congratulations to ppp for winning the second GitS CTF! The game board as it was when the contest ended is now live, though answers are not accepted, nor are any of the exploitable services running.</li>
<li><a href="http://blog.uncommonsensesecurity.com/2011/02/just-like-real-thing.html">Just like the real thing </a>- blog.uncommonsensesecurity.com<br />
<span style="font-family: 'Trebuchet MS', Trebuchet, Verdana, sans-serif; color: #cccccc;"><span style="line-height: 20px;"><span style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; line-height: 19px; color: #000000;">The goal is to build a truly &#8220;enterprise class&#8221; network, and they pull it off every year.</span></span></span></li>
<li>RSA 2011<br />
Last year we produced a pretty detailed Guide to the Conference and it was well received, so – gluttons for punishment that we are – we’re doing it again</p>
<ul>
<li><a href="http://securosis.com/blog/rsa-guide-2011-key-themes">RSA Guide 2011: Key Themes</a> &#8211; securosis.com</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/application-security/229209624/researchers-to-hit-major-website-in-drive-by-at-rsa.html">Researchers To Hit Major Website In Drive-By At RSA</a> &#8211; darkreading.com</li>
</ul>
</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li>USB Attacks On Linux<br />
Many people think that Linux is immune to the type of Autorun attacks that have plagued Windows systems with malware over the years.</p>
<ul>
<li><a href="http://linux.slashdot.org/story/11/02/07/1742246/USB-Autorun-Attacks-Against-Linux?from=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Slashdot/slashdot+(Slashdot)">USB Autorun Attacks Against Linux</a> &#8211; linux.slashdot.org</li>
<li><a href="http://blogs.iss.net/archive/Shmoocon2011.html">ShmooCon 2011 Presentation </a>- blog.iss.net</li>
<li><a href="http://www.itnews.com.au/News/247616,microsoft-says-rip-windows-xp-autorun.aspx">Microsoft says RIP Windows XP AutoRun for USB</a> &#8211; itnews.com.au</li>
</ul>
</li>
<li><a href="http://resources.infosecinstitute.com/common-infosec-jobs-certifications/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+infosecResources+(InfoSec+Resources)">Some common infosec job roles and related certifications</a> &#8211; resources.infosecinstitute.com<br />
Most people hear the term Infosec, and they automatically associate that with network and telecom security, but in reality it’s much broader than that.</li>
<li><a href="http://www.shmoocon.org/2011/videos/Ossmann-Bluetooth.m4v">Project Ubertooth: Building A Better Bluetooth Adapter</a> &#8211; ossman.blogspot.com<br />
Video of my presentation,Project Ubertooth: Building a Better Bluetooth Adapter, at ShmooCon 2011 is now online.</li>
<li><a href="https://blogs.sans.org/appsecstreetfighter/2011/02/07/apple-ios-push-notifications-security-implications-abuse-scenarios-and-countermeasures/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=apple-ios-push-notifications-security-implications-abuse-scenarios-and-countermeasures">Apple iOS Push Notifications: Security Implications, Abuse Scenarios, and Countermeasures</a> &#8211; blogs.sans.org<br />
In this article, I will briefly introduce details of how APN works and present scenarios of how insecure implementations can be abused by malicious parties.</li>
<li><a href="http://blogs.cisco.com/security/cisco-4q10-global-threat-report/#utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=cisco-4q10-global-threat-report">Cisco 4Q10 Global Threat Report </a>- blogs.cisco.com<br />
The Cisco 4Q10 Global Threat Report is now available for download. The report showcases data from the 4th calendar quarter (October 1, 2010 – December 31, 2010).</li>
<li><a href="http://blog.fortinet.com/shmoocon-2011-debriefing/">ShmooCon 2011 Debriefing </a>- blog.fortinet.com<br />
First, just like in BlackHat DC 2011, this year’s conference had several talks on smart phones. Good news! I was however slightly surprised they all concerned Android.</li>
<li><a href="https://blogs.sans.org/appsecstreetfighter/2011/02/10/five-key-design-decisions-that-affect-security-in-web-applications/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=five-key-design-decisions-that-affect-security-in-web-applications">Five Key Design Decisions That Affect Security In Web Applications </a>- blogs.sans.org<br />
Senior developers and architects often make decisions related to application performance or other areas that have significant ramifications on the security of the application for years to come.</li>
<li><a href="http://www.risky.biz/">What netsec-like podcasts do you listen to? </a>- risky.biz<br />
I&#8217;m having a hard time getting my fill of security related news and discussion. I&#8217;m down to two podcasts that I listen to weekly.</li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;"><a href="http://www.securelist.com/en/analysis/204792160/Exploit_Kits_A_Different_View">Exploit Kits &#8211; A Different View</a> &#8211; securelist.com<br />
Exploit kits are packs containing malicious programs that are mainly used to carry out automated ‘drive-by’ attacks in order to spread malware.</span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;"><a href="http://www.room362.com/blog/2009/9/18/password-word-lists.html">Password/Word Lists</a> &#8211; room362.com<br />
Brute force, even though it&#8217;s gotten so fast, is still a long way away from cracking long complex passwords.</span></li>
<li>
<div id="_mcePaste"><a href="http://www.msisac.org/apps/dashboard/howto/">Multi-State Information Sharing &amp; Analysis Center CyberSecurity Digital Dashboard</a> &#8211; msisac.org</div>
<div id="_mcePaste">I stumbled upon this and was kind of impressed.</div>
</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://labs.m86security.com/2011/02/pdf-exploit-disguised-as-a-xerox-scanned-document/">PDF Exploit Disguised As A Xerox Scanned Document </a>- labs.m86security.com<br />
Most office network printers and scanners have a feature that sends scanned documents over email. Cyber crooks however, have imitated email templates used by these devices for malicious purposes</li>
<li><a href="http://chuvakin.blogspot.com/2011/02/honeynet-project-releases-new-tool.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+AntonChuvakinPersonalBlog+(Anton+Chuvakin+Personal+Blog)">The Honeynet Project Releases New Tool: PhoneyC </a>- chuvakin.blogspot.com<br />
As promised, I will be reposting some of the cool new announcements from The Honeynet Project here on my blogsince I now serve as Project’s Chief PR Officer.</li>
<li><a href="http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+metasploit/blog+(Metasploit+Blog)">MetaSploit Framework 3.5.2 Released</a> &#8211; blog.metasploit.com<br />
On February 1st, Eduardo Prado of Secumania notified us of a privilege escalation vulnerability on multi-user Windows installations of the Metasploit Framework.</li>
<li><a href="http://www.open-scap.org/page/Download">Open SCAP v0.6.8 released</a> &#8211; open-scap.org<br />
The OpenSCAP Project was created to provide an open-source frameworkto the community which enables integration with the Security Content Automation Protocol (SCAP) suite of standards and capabilities.</li>
<li><a href="http://sourceforge.net/projects/ssldiagnos/files/">SSL Diagnosis v0.8.1a released</a> &#8211; sourceforge.net<br />
<span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;">SSL Diagnos is used to get information about SSL usage (protocols ssl2, ssl3, tls, dtls, and ciphers). It can also be used for testing and rating ciphers on SSL clients.</span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;"><a href="http://www.terminal23.net/2011/02/passwords_shared_between_rootk.html">Passwords shared between rootkit.com and gawker</a> &#8211; terminal23.net<br />
This is a classic journo case of an editor-sensationalized title for an article that doesn&#8217;t really get reasonable until the last two paragraphs where it kinda puts the brakes on calling password reuse &#8220;endemic.&#8221; </span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif;"><span style="line-height: 22px;"><a href="http://nmap.org/download.html">UPDATE: Nmap 5.51!</a> &#8211; nmap.org<br />
Wow! In about two weeks time, another Nmap release! We now have Nmap version 5.51! The last release was <em>Nmap 5.50</em>, which we wrote about here.</span></span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif;"><span style="line-height: 22px;"><span style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; line-height: 19px;"><a href="http://www.vulnerabilitydatabase.com/toolswatch/2011/02/09/eeye-to-release-free-vulnerability-scanner-with-zero-day-identification-and-configuration-auditing/">eEye to Release Free Vulnerability Scanner with Zero -Day Identification and Configuration Auditing</a> &#8211; eeye.com<br />
<span style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 14px; line-height: 22px;">eEye Digital Security, a provider of IT security and unified vulnerability management solutions, today announced the pre-release of Retina Community.</span></span></span></span></li>
<li><span style="font-family: Georgia, serif; color: #333333;"><span style="line-height: 20px;"><a href="http://www.fiddler2.com/Fiddler2/version.asp">UPDATE: Fiddler v2.3.2.3! </a>- fiddler2.com</span></span><br />
<span style="font-family: Georgia, serif; color: #333333;"><span style="line-height: 20px;">Our first post regarding Fiddler, the web debugger can be found here. On the 13th of February, an update was released.</span></span><span style="font-family: Verdana, sans-serif; color: #111111;"><span style="line-height: 18px;"><br />
</span></span></li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://blog.kaffenews.com/?p=2119">A Python Domains Extractor From IPs</a> &#8211; blog.kaffenews.com<br />
I developed it in 5 mins just because I had to do a PT on a list of IP Addresses and it was needed to get the Domains from IPs.</li>
<li>TrueCrypt<br />
After I read the documentation and some reviews I realize that it is a very secure piece of software that implements many high level features so I knew I will not be easy, at least in theory.</p>
<ul>
<li><a href="http://www.shortinfosec.net/2009/02/cracking-truecrypt-container.html">Cracking a TrueCrypt Container </a>- shortinfosec.net</li>
<li><a href="http://www.q-protex.com/software/password-recovery/truecrypt-self-bruteforce">TrueCrypt Self-Bruteforce </a>- q-protex.com</li>
</ul>
</li>
<li><a href="http://www.perihel.at/sec/mz/">What is Mausezahn?</a> &#8211; peripheral.at<br />
Mausezahn is a free fast traffic generator written in C which allows you to send nearly every possible and impossible packet.</li>
<li>Proxocket
<ul>
<li><a href="http://sethioz.co.uk/mediawiki/index.php5/Proxocket">Proxocket </a>- sethioz.co.uk</li>
<li><a href="http://www.darknet.org.uk/2011/02/proxocket-dll-proxy-for-winsock/">Proxocket &#8211; DLL Proxy For Winsock</a> &#8211; darknet.org.uk</li>
<li><a href="http://www.netresec.com/?page=Blog&amp;month=2011-01&amp;post=Proxocket---A-Winsock-Proxy-Sniffer">Proxocket &#8211; A Winsock Proxy Sniffer </a>- netresec.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://carnal0wnage.attackresearch.com/node/444">Move over tsgrinder/tscrack hello ncrack</a> &#8211; carnalOwnage.attackresearch.com<br />
So thanks to mubix for telling me that ncrack now supports RDP. very cool stuff.</li>
<li><a href="http://www.justanotherhacker.com/2011/02/left-or-right-handed-passwords.html">Left or right handed passwords </a>- justanotherhacker.com<br />
Are you left or right handed? How about your password? English based passwords seem to be predominantly left handed.</li>
<li><a href="http://www.symantec.com/connect/de/blogs/hidden-bandit-inside-neosploit">Hidden bandit Inside NeoSploit </a>- symantec.com<br />
Over the last few years, Symantec has observed a substantial rise in the use of exploit kits.</li>
<li><a href="http://net-ninja.net/blog/?p=553">Breaking web security &#8211; it&#8217;s all about RCS</a> &#8211; net-ninja.net<br />
I will be discusing ways in which we can include error handling, anonymimity and how we can build the exploit so that the auditor has a reliable and flexible weapon.</li>
<li><a href="http://research.zscaler.com/2011/02/in-depth-analysis-decoding-html-style.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+zscaler/research+(Zscaler+Research)">Decoding HTML Style tag based malicious frames </a>- research.zscaler.com<br />
Injecting clear text or obfuscated malicious Iframes has become a common attack vector.</li>
<li><a href="http://reverse.put.as/">Universe&#8217;s best and legal Mac OS X reversing tutorial for newbies</a> &#8211; reverse.put.as<br />
I have decided to re-release my beginners tutorial, this time based on a crackme, so it deserves the upgrade to Universe instead of World.</li>
<li><a href="http://spareclockcycles.org/2011/02/11/android-gmail-app-stealing-emails-via-xss/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=android-gmail-app-stealing-emails-via-xss">Android Gmail App: Stealing Emails via XSS </a>- spareclockcycles.org<br />
This post documents an XSS vulnerability that I discovered in the default Gmail app (v1.3) provided by Google in Android 2.1 and prior.</li>
<li><a href="http://thomascannon.net/projects/android-reversing/">Android Reverse Engineering</a> &#8211; thomascannon.net<br />
This project all started when I was asked tot ake a look at a software product that was under evaluation.</li>
<li><a href="http://dfsforensics.blogspot.com/2011/02/forensic-examination-of-pointsec.html">Forensic Examination of Pointsec Encrypted Drives </a>- dfsforensics.blogspot.com<br />
Many organizations use Pointsec (Check Point) full disk encryption in order to keep their data secure, especially in the case of laptops.</li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif;"><span style="line-height: 22px;"><a href="http://research.zscaler.com/2011/02/blackhole-exploits-kit-attack-growing.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+zscaler/research+(Zscaler+Research)">Blackhole exploits kit attack growing </a>- research.zscaler.com</span></span><br />
<span style="font-family: Georgia, serif; color: #333333;"><span style="line-height: 20px;">Recently, we have seen an increase in Blackhole exploit kit attacks. Blackhole is yet another web exploit kit developed by Russian hackers.</span></span></li>
<li><a href="http://blog.wearpants.org/better-passwords-in-under-200-characters?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+iwearpants+(I+Wear+Pants)">Better Passwords In Under 200 Characters </a>- blog.wearpants.org<br />
Good password security is a pain in the neck. Done properly, it requires a different password for every site.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li><a href="http://isc.sans.edu/diary.html?storyid=10375&amp;rss">February 2011 Microsoft Black Tuesday Summary</a> &#8211; isc.sans.edu<br />
Here are the February 2011 Black Tuesday patches.  Enjoy!</li>
<li>Adobepatch<br />
Adobe released updates for Reader for 9.4.2 and 10.0.1.  While this page on Adobe&#8217;s site doesn&#8217;t actually list them correctly, if you drill down into the actual product and OS, you&#8217;ll see the updates listed for 2/8/2011.</p>
<ul>
<li><a href="http://isc.sans.edu/diary.html?storyid=10378&amp;rss">Adobe Reader 9.4.2 and 10.0.1 Updates are out </a>- isc.sans.edu</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=10390&amp;rss">Adobe patches for Shockwave, Flash, Reader, and Cold Fusion</a> &#8211; isc.sans.edu</li>
</ul>
</li>
<li><a href="http://krebsonsecurity.com/2011/02/adobe-microsoft-wordpress-issue-security-fixes/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+KrebsOnSecurity+(Krebs+on+Security)">Adobe, Microscoft, WordPress Issue Security Fixes</a> &#8211; krebsonsecurity.com<br />
Talk about Patch Tuesday on steroids! Adobe, Microsoft and WordPress all issued security updates for their products yesterday. In addition, security vendorTipping Point released advisories detailing 21 unpatched vulnerabilities in products made by CA, EMC, HP, Novell and SCO.</li>
<li><a href="http://www.vmware.com/security/advisories/VMSA-2011-0002.html">VMWare Security Advisory </a>- vmware.com<br />
Updated versions of the Cisco Nexus 1000V virtual switch address a denial of service in VMware ESX/ESXi.</li>
</ul>
<p><strong>Vulnerabilities</strong></p>
<ul>
<li><a href="http://dvlabs.tippingpoint.com/blog/2011/02">Last August, TippingPoint said they will enforce a six-month disclosure on bought bugs that haven&#8217;t been patched. Today, TippingPoint rolled out 22 </a>- dvlabs.tippingpoint.com<br />
These vulnerabilities are being published as per the ZDI disclosure changes announced in August of 2010.</li>
<li><a href="http://www.exploit-db.com/exploits/16123/">Comcast DOCSIS 3.0 Business gateways Multiple Vulnerabilities</a> &#8211; exploit-db.com<br />
With these default credentials, internal attackers can modify deviceconfigurations to leverage more significant attacks, including redirection of DNS requests.</li>
</ul>
<p><strong><strong>Other News</strong></strong></p>
<ul>
<li>Anonymous vs. Aaron Barr/HBGary<br />
A security researcher claims to have infiltrated the higher echelons of the Anonymous organisation and identified key leaders&#8217; names and addresses.</p>
<ul>
<li><a href="http://i.imgur.com/em14R.jpg">Anonymous infiltrates the HBGary security company, which was tasked with infiltrating Anonymous by the FBI</a> &#8211;  reddit.com</li>
<li><a href="http://www.v3.co.uk/v3/news/2274613/anonymous-hbgary-federal-ft#ixzz1DuVUSDl0">Researcher claims to have infiltrated Anonymous high command </a>- v3.co.uk</li>
<li><a href="http://krebsonsecurity.com/2011/02/hbgary-federal-hacked-by-anonymous/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+KrebsOnSecurity+(Krebs+on+Security)">HBGary Federal Hacked by Anonymous</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://www.readwriteweb.com/archives/anonymous_hacks_security_company_hbgary_dumps_5000.php?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+readwriteweb+(ReadWriteWeb)">Anonymous hacks security company HBGary, Dumps 50,000 emails online </a>- readwriteweb.com</li>
<li><a href="http://www.lightbluetouchpaper.org/2011/02/09/measuring-password-re-use-empirically/">Measuring password re-use empirically </a>- lightbluetouchpaper.org</li>
<li><a href="http://www.guardian.co.uk/technology/2011/feb/07/anonymous-attacks-us-security-company-hbgary">Anonymous Attacks US Security Company</a> &#8211; guardian.co.uk</li>
<li><a href="http://dazzlepod.com/rootkit/">rootkit.com cleartext passwords</a> &#8211; dazzlepod.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/02/anonymous/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))">How One Man Tracked Down Anonymous &#8211; And Paid A Heavy Price</a> &#8211; wired.com</li>
<li><a href="http://uiu.me/cia.zip">HBGary&#8217;s conversations with Feds</a> &#8211; uiu.me</li>
<li><a href=" http://uiu.me/dhs.zip">HBGary&#8217;s conversations with the Feds pt. 2 </a>- uiu.me</li>
<li><a href="http://dazzlepod.com/site_media/txt/rootkit.com.txt">blow by blow of how Anonymous gained root access on rootkit.com</a> &#8211; dazzlepod.com</li>
<li><a href="http://cryptome.org/0003/anonymous-barr.pdf">The Report on Anonymous by Aaron Barr </a>- cryptome.org</li>
</ul>
</li>
<li><a href="http://stfu.cc/rootkit_com_mysqlbackup_02_06_11.gz">Rootkit.com&#8217;s MySQL database leaked</a> &#8211; stfu.cc<br />
Come on, I know it&#8217;s /r/netsec, so we should be familiar with checking URLs before clicking, but I&#8217;d expect at least a warning before clicking a direct download of a company&#8217;s database.</li>
<li><a href="http://1raindrop.typepad.com/1_raindrop/2011/02/hatfields-and-mccoys-2011-style.html">Hatfields and McCoys 2011 Style</a> &#8211; 1raindrop.typepad.com<br />
By itself its an derisive, throw away comment that security people make about developers all the time, and of course developers are not averse to throwing haymakers back at security people.</li>
<li><a href="http://twitpic.com/3xwe6h">Sony Marketing Man Tweets PS3 Master Key </a>- twitpic.com<br />
My life is complete. Sue yourself, Sony.</li>
<li>iPhone Password Hack<br />
Researchers in Germany say they&#8217;ve been able to reveal passwords stored in a locked iPhone in just six minutes and they did it without cracking the phone&#8217;s passcode.</p>
<ul>
<li><a href="http://www.techworld.com.au/article/376245/iphone_attack_reveals_passwords_six_minutes/">iPhone Attack Reveals Password In 6 Minutes </a>- techworld.com.au</li>
<li><a href="http://cyberarms.wordpress.com/2011/02/10/iphone-hacked-and-passwords-stolen-in-just-6-minutes/">iPhone Hacked and Passwords Stolen In Just 6 Minutes </a>- cyberarms.wordpress.com</li>
<li><a href="http://nakedsecurity.sophos.com/2011/02/10/video-how-to-steal-passwords-locked-iphone/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+NakedSecurityGrahamCluley+(Sophos+Naked+Security+%C2%BB+Graham+Cluley)">How to steal passwords from a locked iPhone </a>- nakedsecurity.sophos.com</li>
<li><a href="http://www.engadget.com/2011/02/10/researchers-steal-lost-iphone-passwords-in-6-minutes-video/">Researches steal iPhone password in 6 minutes</a> &#8211; engadget.com</li>
</ul>
</li>
<li><a href="http://wikileaks.ch/IMG/pdf/WikiLeaks_Response_v6.pdf">Secret Plan To Kill WikiLeaks With FUD Leaked</a> &#8211; wikileaks.ch<br />
Three information security consultancies with links to US spy agencies cooked up a dirty tricks campaign late last year to destroy Wikileaks by exploiting its perceived weaknesses.</li>
<li><a href="http://www.bbc.co.uk/news/technology-12416580">Hackers hit &#8216;at least five oil and gas firms&#8217;</a> &#8211; bbc.co.uk<br />
Hackers have run rampant through the networks of at least five oil and gas firms for years, reveals a report.</li>
<li><a href="http://nakedsecurity.sophos.com/2011/02/11/night-dragon-attacks-myth-or-reality/">Night Dragon attacks: myth or reality</a> &#8211; nakedsecurity.sophos.com<br />
Many readers will have seen the press around a series of hacking attacks that have been labelled the &#8216;Operation Night Dragon&#8217; attacks by McAfee.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1463&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/02/14/week-6-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.shmoocon.org/2011/videos/Ossmann-Bluetooth.m4v" length="838736213" type="video/mp4" />
		</item>
		<item>
		<title>Week 5 In Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/02/07/week-5-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/02/07/week-5-in-review-2011/#comments</comments>
		<pubDate>Mon, 07 Feb 2011 10:35:56 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Local Meetings]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[US Cyber Challenge]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1451</guid>
		<description><![CDATA[Events Related ShmooCon 2011 Getting to ShmooCon each year is always challenging (as is trying to get home). Mother Nature seems to enjoy disrupting the travel to and from the conference, which is held in Washington, D.C in January or February of each year. ShmooCon 2011 &#8211; intrepidusgroup.com ShmooCon 2011 Conference Wrap Up - blog.tenablesecurity.com [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li>ShmooCon 2011<br />
Getting to ShmooCon each year is always challenging (as is trying to get home). Mother Nature seems to enjoy disrupting the travel to and from the conference, which is held in Washington, D.C in January or February of each year.</p>
<ul>
<li><a href="http://intrepidusgroup.com/insight/2011/01/shmoocon-2011/">ShmooCon 2011</a> &#8211; intrepidusgroup.com</li>
<li><a href="http://blog.tenablesecurity.com/2011/02/shmoocon-2011-conference-wrap-up.html">ShmooCon 2011 Conference Wrap Up </a>- blog.tenablesecurity.com</li>
</ul>
</li>
<li>US Cyber Challenge 2011<br />
The Center for Internet Security’s US Cyber Challenge today kicked off an online competition to identify high school students possibly interested in cybersecurity career.</p>
<ul>
<li><a href="http://itknowledgeexchange.techtarget.com/security-bytes/high-school-cybersecurity-competition-kicks-off/">High school cybersecurity competition kicks off</a> &#8211; itknowledgeexchange.techtarget.com</li>
<li><a href="http://threatpost.com/en_us/blogs/new-contest-promote-cyber-security-skills-teens-020111">New Contest To Promote Cyber Security Skills In Teens</a> &#8211; threatpost.com</li>
</ul>
</li>
<li><a href="http://diniscruz.blogspot.com/2011/02/participate-remotely-on-owasp-summit.html?">Participate remotely on the OWASP Summit </a>- diniscruz.blogspot.com<br />
The OWASP Summit is gearing up to be an amazing event. If you are not able to make it in person to Portugal, then please make the time to participate remotely.</li>
<li><a href="http://dvlabs.tippingpoint.com/blog/2011/02/02/pwn2own-2011?">Announcing Pwn2Own 2011 </a>- dvlabs.tippingpoint.com<br />
It&#8217;s that time of year again and the Zero Day Initiative (ZDI) team here at HP TippingPoint is proud to announce the 5th annual Pwn2Own competition is back.</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li><a href="http://chaptersinwebsecurity.blogspot.com/2011/01/2010-top-web-application-hack-attacks.html?">2010 Top Web Application Hack Attacks</a> &#8211; chaptersinwebsecurity.blogspot.com<br />
I must admit that I was curious just like everybody else, what 2010 will look like, retrospectively, through the eyes of the international infosec community.</li>
<li><a href="http://www.woodmann.com/TiGa/idaseries.html">TiGa&#8217;s Video Tutorial Site</a> &#8211; woodman.com<br />
TiGa&#8217;s video tutorial series on IDA Pro.</li>
<li><a href="http://www.f-secure.com/weblog/archives/00002089.html">Mobile Security Tips</a> &#8211; f-secure.com<br />
With data charges getting cheaper and technologies in mobile computing getting more powerful, mobile devices are becoming more like a small personal computer.</li>
<li>ShmooCon 2011 FireTalks
<ul>
<li><a href="http://www.vimeo.com/19410413">FireTalks at ShmooCon 2011, Night 1</a> &#8211; vimeo.com</li>
<li><a href="http://www.vimeo.com/19410439">FireTalks at ShmooCon 2011, Night 2</a> &#8211; vimeo.com</li>
<li><a href="http://www.vimeo.com/19410439">Net Neutrality, the FCC, and the end of the Internet as we know it </a>- vimeo.com</li>
</ul>
</li>
<li><a href="http://blog.fireeye.com/research/2011/02/omg-wtf-pdf-denouement.html?">OMG-WTF-PDF Denouement</a> &#8211; blog.fireeye.com<br />
I recently gave this presentation at the 27th Chaos Computer Congress in Berlin. For some reason, the slides never made it from Pentabarf to the Fahrplan.</li>
<li><a href="http://csrc.nist.gov/publications/nistpubs/800-125/SP800-125-final.pdf">Guide to Security for Full Virtualization Technologies</a> &#8211; csrc.nist.gov<br />
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation’s measurement and standards infrastructure.</li>
<li>ShmooCon 2011 Library<br />
This year I talked about my improvements to VERA over the past 6 months. Much of the talk was centered around live demos, which unfortunately did not make it to the slides. The new tracing module and updated versions of the VERA code will be posted here soon.</p>
<ul>
<li><a href="http://www.offensivecomputing.net/?q=node/1713">ShmooCon 2011: Visual Malware Reversing</a> &#8211; offensivecomputing.net</li>
<li><a href="http://www.youtube.com/watch?v=SvCbIOwblqM&amp;feature=player_embedded">ShmooCon 2011: Zigbee Security: Find, Fix, Finish</a> &#8211; youtube.com</li>
<li><a href="http://www.reddit.com/r/netsec/comments/fgetw/shmoocon_2011_video_collection/">ShmooCon 2011 video collection </a>- reddit.com</li>
</ul>
</li>
<li><a href="http://lcamtuf.blogspot.com/2011/02/so-you-think-your-capability-model-is.html">So you think your *capability* model is bad?</a> &#8211; Icamtuf.blogspot.com<br />
In his recent post, Brad Spengler mocked the Linux capability system &#8211; a somewhat ill-conceived effort to add modern access controls on top of the traditional Unix permission model.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://www.justanotherhacker.com/2011/01/password-length-matters.html">Password Length Matters </a>- justanotherhacker.com<br />
In fact, it matters so much that the term password is just plain wrong. Passphrase is better, and I did mean to start using that term instead.</li>
<li><a href="http://www.oxid.it/downloads/ca_setup.exe">UPDATE: Cain &amp; Abel v4.9.38</a> &#8211; oxid.it<br />
Our previous post regarding Cain &amp; Abel can be found here. Now, <em>oxid.it</em> has released an updated Cain &amp; Abel version 4.9.38!</li>
<li><a href="http://reverse.put.as/2011/02/03/another-update-to-gdbinit-for-ios-and-arm-support-to-ptool-pl-and-offset-pl/">Another update to gdbinit for iOS and ARM support to ptool.pl and offset.pl</a> &#8211; reverse.put.as<br />
I have fixed some of the missing stuff in gdbinit for iOS. Now the jump conditions are displayed for ARM and Thumb modes and the “stepo” command is working for ARM and semi-working for Thumb (to be fixed in the next release).</li>
<li><a href="http://www.vulnerabilitydatabase.com/toolswatch/2011/02/03/thc-hydra-v6-1-released/">THC Hydra v6.1 released</a> &#8211; vulnerabilitydatabase.com<br />
THC-Hydra – the best parallized login hacker: for Samba, FTP, POP3, IMAP, Telnet, HTTP Auth, LDAP, NNTP, MySQL, VNC, ICQ, Socks5, PCNFS, Cisco and more. Includes SSL support and is part of Nessus.</li>
<li><a href="http://www.exploit-db.com/exploits/16103/">Majordomo2- Directory Traversal (SMTP/HTTP)</a> &#8211; exploit-db.com</li>
<li>GoogleDiggity<br />
The Google Hacking Diggity Project is a research and development initiative dedicated to investigating the latest techniques that leverage search engines, such as Google and Bing, to quickly identify vulnerable systems and sensitive data in corporate networks</p>
<ul>
<li><a href="http://www.stachliu.com/tools/googlediggity20100805.zip">Exclusive!! GoogleDiggity the exclusive Google hacking project v0.2 </a>- stachliu.com</li>
<li><a href="http://www.stachliu.com/wp-content/uploads/2011/02/SharePoint_GoogleDiggity_Dictionary.txt">SharePoint &#8211; GoogleDiggity dictionary file</a> &#8211; stachliu.com</li>
</ul>
</li>
<li><a href="http://www.sourceforge.net/projects/ws-attacker/files/"><strong> </strong>Pentesting Web Services with WS-Attacker v1.0 </a>- sourceforge.net<br />
WS-Attacker is a modular framework for web services penetration testing. It is a free and easy to use software solution, which provides an all-in-one security checking interface with only a few clicks<strong>.</strong></li>
<li><a href="http://www.reddit.com/r/netsec/comments/ffei8/i_found_a_hotmail_exploit_that_allows_me_to/">I found a hotmail &#8220;exploit&#8221; that allows me to change a large percentage of people&#8217;s passwords</a> &#8211; reddit.com<br />
As the title says, I found an exploit on Hotmail that allows me to change hotmail/msn/live passwords for people using their service.</li>
<li><a href="http://www.mail-archive.com/sc-l@securecoding.org/msg03351.html">InformIT: comparing static analysis tools</a> &#8211; mail-archive.com<br />
There are cases where dynamic and static each have clear strengths. Pragmatic combination of the two has promise in solving a broad spectrum of test-cases.</li>
<li><a href="http://www.sourceforge.net/projects/networkminer/files/networkminer/">UPDATE: NetworkMiner 1.0 </a>- sourceforge.net<br />
Fresh off the compiler again! A newer version of NetworkMiner has just been released a few hours ago! The updated NetworkMiner version 1.0 is out!</li>
<li><a href="http://pypi.python.org/pypi/quickrecon">QuickRecon: A Simple Information gathering Python Script! </a>- pypi.python.org<br />
The first submission for the year 2011! We are proud to present to all of you QuickRecon. It is a simple information gathering tool.</li>
<li><a href="https://github.com/rongutierrez/GWT-Penetration-Testing-Toolset#readme">GWT-Penetration-Testing-Toolset</a> &#8211; github.com<br />
A set of tools made to assist in penetration testing GWT applications. Additional details about these tools can be found on my OWASP.</li>
</ul>
<p><strong>Technique</strong></p>
<ul>
<li><a href="http://labs.neohapsis.com/2011/01/31/cross-platform-cisco-group-password-decrypter/">Java Cisco Group Password Decrypter </a>- neohapsis.com<br />
For whatever reason I have found myself needing to “decrypt” Cisco VPN client group passwords throughout the years.</li>
<li><a href="http://asert.arbornetworks.com/2011/01/darkshell-a-ddos-bot-targetting-vendors-of-industrial-food-processing-equipment/">Darkshell: A DDos bot targeting vendors of industrial food processing equipment </a>- asert.arbornetworks.com<br />
This week, we continue our efforts to document the crowded space of Chinese DDoS bots by analyzing Darkshell.</li>
<li><a href="http://www.vnsecurity.net/2011/01/padocon-2011-ctf-karma-400-exploit-the-data-re-use-way/">Padocon 2011 CTF Karma 400 exploit: the data re-use way</a> &#8211; vnsecurity.net<br />
Karma 400 at Padocon 2011 Online CTF is a fun challenge. The binary was provided without source code, you can reach its decompiled source at disekt’s team writeup.</li>
<li><a href="http://blog.metasploit.com/2011/01/exploiting-seh-overwrites-using-rop.html?">Exploiting SEH Overwrites Using ROP </a>- blog.metasploit.com<br />
In the final days of 2010, an exploit for the Windows CreateSizedDIBSECTION vulnerability was added to the Metasploit trunk.</li>
<li><a href="http://blog.didierstevens.com/2011/02/03/taskmanager-xls/">TaskManager.xls</a> &#8211; blog.didierstevens.com<br />
TaskManager.xls is a simple taskmanager implemented in Excel/VBA. It can list the running processes; and terminate, suspend or resume selected processes.</li>
<li><a href="http://www.packetstan.com/2011/02/running-loki-on-backtrack-4-r2.html">Exploiting Networks with Loki on Backtrack 4 R2 </a>- packetstan.com<br />
Loki is the impressive layer 2/3 network manipulation tool by Daniel Mende, Rene Graf and Enno Rey of ERNW.</li>
<li><a href="http://research.zscaler.com/2011/02/unchecked-redirection-url-shortener.html?">Unchecked redirection + URL shortener = Spam</a> &#8211; research.zscaler.com<br />
Recently, I found several legitimate sites, with bad coding practices,  used to redirect users to spam sites with the help of URL shorteners.</li>
<li><a href="http://nakedsecurity.sophos.com/2011/02/03/adobe-reader-x-stops-malicious-pdf-spam/?">Adobe Reader X stops malicious PDF spam campaign dead in its tracks</a> &#8211; nakedsecurity.sophos.com<br />
A new malicious spam campaign underlines the security benefits of upgrading to the latest version of Adobe Reader &#8211; Adobe Reader X.</li>
<li><a href="http://computer-forensics.sans.org/blog/2011/02/04/mac-os-forensics-howto-simple-ram-acquisition-analysis-mac-memory-reader-part-2">Mac OS Forensics How-To: Simple RAM Acquisition and Analysis with Mac memory reader</a> &#8211; computer-forensics.sans.org<br />
In Part 1 of this post, I showed you how to acquire the contents of physical RAM of a Mac OS X computer using ATC-NY&#8217;sMac Memory Reader, and did some simple analysis using strings and grep searches.</li>
<li><a href="http://ppp.cylab.cmu.edu/wordpress/?p=448">ShmooCon Ghost in the Shellcode 2011</a> &#8211; ppp.cylab.cmu.edu<br />
Just got back from ShmooCon and it seems that some people want a writeup for the taped challenge. I highly encourage you to try it yourself first, because once you see the bug, it takes away some of the fun.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/critical-adobe-reader-x-patches-deck-020411">Critical Adobe Reader X Patches On Deck </a>- threatpost.com<br />
Adobe will join Microsoft on the security patch treadmill next Tuesday (February 8, 2011) with “critical” updates for code execution holes in its flagship Adobe Reader and Adobe Acrobat products.</li>
<li><a href="http://www.zdnet.com/blog/security/patch-tuesday-heads-up-critical-flaws-in-windows-internet-explorer/8059">Patch Tuesday heads -up: Critical flaws in Windows, Internet Explorer </a>- zdnet.com<br />
As part of this month’s Patch Tuesday schedule, Microsoft plans to ship a dozen bulletins with fixes for 22 vulnerabilities, some serious enough to allow hackers complete access to a vulnerable Windows machine.</li>
</ul>
<h2><span style="font-size: 13px; font-weight: normal;"><strong>Vulnerability</strong></span></h2>
<ul>
<li><a href="http://www.veracode.com/freeservice">Veracode Free JAVA Cross-Site Script Scanning Service </a>- veracode.com<br />
As we know – cross-site scripting(XSS) is a type of computer security vulnerability typically found in web applications that enables malicious attackers to inject client-side script into web pages viewed by other users.</li>
<li><a href="http://www.cisco.com/warp/public/707/cisco-sa-20110202-tandberg.shtml">Cisco Security Advisory: Default Credentials for Root Account on Tandberg E, EX and C Series Endpoints </a>- cisco.com<br />
Tandberg C Series Endpoints and E/EX Personal Video units that are running software versions prior to TC4.0.0 ship with a root administrator account that is enabled by default with no password. An attacker could use this account in order to modify the application configuration or operating system settings.</li>
</ul>
<h1><strong>Other News</strong></h1>
<ul>
<li><a href="http://krebsonsecurity.com/2011/01/atm-skimmers-that-never-touch-the-atm/?">ATM Skimmers That Never Touch The ATM</a> &#8211; krebsonsecurity.com<br />
Media attention to crimes involving ATM skimmers may make consumers more likely to identify compromised cash machines, which involve cleverly disguised theft devices that sometimes appear off-color or out-of-place.</li>
<li><a href="http://nakedsecurity.sophos.com/2011/02/02/facebook-flaw-websites-steal-personal-data/?">Facebook flaw allowed websites to steal user&#8217;s personal data without consent </a>- nakedsecurity.sophos.com<br />
A couple of weeks ago two students conducting security research contacted me about a vulnerability which they believed they had found with Facebook.</li>
<li><a href="http://threatpost.com/en_us/blogs/research-reveals-huge-cache-ftp-email-credentials-stolen-waledac-020211">Research Reveals Huge Cache Of FTP, Email Credentials Stolen By Waledac </a>- threatpost.com<br />
Researchers have discovered that the gang behind the once-and-future botnet Waledac has gathered nearly 500,000 stolen passwords for email accounts, along with close to 125,000 sets of pilfered credentials for FTP accounts.</li>
<li><a href="http://www.zdnet.com/blog/burnette/red-gate-we-could-not-make-the-free-model-work-for-us-as-a-commercial-company/2176">Red Gate: We could not make the free model work for us as a commercial company</a> &#8211; zdnet.com<br />
If you’re a .NET developer, chances are you’ve heard of .NET Reflector, a decompilation, debugging, and reverse engineering tool for managed code.</li>
<li><a href="http://blogs.cisco.com/security/ipv6-whats-new/#utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=ipv6-whats-new">IPv6-What&#8217;s New</a> &#8211; blogs.cisco.com<br />
IPv6 is becoming more widely deployed as the availability of IPv4 addresses continue to decline. In June, Cisco will be participating in World IPv6 Day, a 24-hour global “test drive” of IPv6 that is organized by the Internet Society.</li>
<li><a href="http://nakedsecurity.sophos.com/2011/02/04/android-market-web-store-backdoor-phone-hackers/">New Android Market web store could open backdoor for phone hackers </a>- nakedsecurity.sophos.com<br />
If you follow the Google Android operating system scene, you will probably have heard about the new, web-based Android Market store which was launched a few days ago.</li>
<li><a href="http://computer-forensics.sans.org/blog/2011/02/02/forensically-sound-mac-acquisition-target-mode">How To: Forensically Sound Mac Acquisition in Target Mode</a> &#8211; computer-forensics.mac.org<br />
It is really a matter of personal opinion, Mac&#8217;s are an engineering marvel just ask anyone that has had to remove a hard drive from a Mac for forensic imaging and then try to put it back together properly.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1451&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/02/07/week-5-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

