<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Infosec Events &#187; Uncategorized</title>
	<atom:link href="http://infosecevents.net/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecevents.net</link>
	<description>Covering the Information Security Economy</description>
	<lastBuildDate>Mon, 21 May 2012 05:28:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Week 19 in Review &#8211; 2012</title>
		<link>http://infosecevents.net/2012/05/14/week-19-in-review-2012/</link>
		<comments>http://infosecevents.net/2012/05/14/week-19-in-review-2012/#comments</comments>
		<pubDate>Mon, 14 May 2012 16:48:25 +0000</pubDate>
		<dc:creator>Roxanne</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Microsoft Security Bulletin]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=2359</guid>
		<description><![CDATA[Resources Research for SharePoint (MOSS) &#8211; owasp.org This page contains research notes on Microsoft&#8217;s SharePoint MOSS and WSS MS SQL &#8211; Useful Stored Procedures for SQL Injection and Ports Info &#8211; pentesticles.com The following post lists and describes various useful stored procedures and port information for MS SQL. Portable Executable 101 &#8211; a windows executable [...]]]></description>
			<content:encoded><![CDATA[<p><strong> Resources</strong></p>
<ul>
<li><a href="https://www.owasp.org/index.php/Research_for_SharePoint_%28MOSS%29">Research for SharePoint (MOSS)</a> &#8211; owasp.org<br />
This page contains research notes on Microsoft&#8217;s SharePoint MOSS and WSS</li>
<li><a href="http://www.pentesticles.com/2012/05/ms-sql-useful-stored-procedures-for-sql.html">MS SQL &#8211; Useful Stored Procedures for SQL Injection and Ports Info</a> &#8211; pentesticles.com<br />
The following post lists and describes various useful stored procedures and port information for MS SQL.</li>
<li><a href="http://code.google.com/p/corkami/wiki/PE101?show=content">Portable Executable 101 &#8211; a windows executable walkthrough</a> &#8211; code.google.com<br />
This graphic (PDF JPG) is a walkthrough of a simple windows executable, that shows its dissected structure and explains how it&#8217;s loaded by the operating system.</li>
<li><a href="http://labs.mwrinfosecurity.com/publications/2012/04/27/sap-slapping/">SAP Slapping</a> &#8211; labs.mwrinfosecurity.com<br />
Dave Hartley delivered his “SAP Slapping” presentation at the CRESTCon and BSides London security conferences recently. The talk provides a high level overview of common SAP system vulnerabilities and misconfigurations.</li>
<li><a href="http://resources.infosecinstitute.com/scanning-with-ammonite/">Scanning the Web with Ammonite</a> &#8211; resources.infosecinstitute.com<br />
Ammonite is a Fiddler extension used to scan web applications for common vulnerabilities like verbose and blind SQL injection, OS commanding, local file inclusion, buffer overflows, format string vulnerabilities etc.</li>
<li><a href="http://esec-pentest.sogeti.com/exploiting-windows-2008-group-policy-preferences">Exploiting Windows 2008</a> &#8211; esec-pentest.sogeti.com<br />
Internal network pentesting involving domain controllers requires a few steps in order to gain domain administrator access. One of them usually requires to gain local administrator access to a workstation.</li>
</ul>
<p><strong> Tools</strong></p>
<ul>
<li><a href="http://code.google.com/p/gason/">Gason - BurpSuite Plugin&#8217;s Project &#8211; Google Project Hosting</a> - code.google.com<br />
This project contains a plugin to extend BurpSuite proxy. And know you can run gason stand alone!!</li>
<li><a href="http://code.google.com/p/skipfish/downloads/list">Skipfish version 2.06b Update</a> &#8211; code.google.com<br />
Skipfish is a fully automated, active web application security reconnaissance tool.</li>
</ul>
<p><strong> Techniques</strong></p>
<ul>
<li>Android</li>
<ul>
<li><a href="http://carnal0wnage.attackresearch.com/2012/05/android-emulator-trusted-ca-and.html">Android Emulator, Trusted CA, and Persistent Storage</a> &#8211; carnal0wnage.attackresearch.com<br />
Android periodically updates it&#8217;s SDK and somtimes when this happens, old methods for importing a Trusted CA, necessary to proxy SSL traffic, will fail and you must find a new solution.</li>
<li><a href="http://carnal0wnage.attackresearch.com/2012/05/update-android-ssl-cert.html">Update &#8211; Android &amp; SSL Cert</a> &#8211; carnal0wnage.attackresearch.com<br />
Thanks to the comments left by Zach from our last Android post here, it has been brought to my attention there is an easier way to do all of this with the latest AVD (4.0.3).</li>
</ul>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/05/08/eternal-sunshine-of-the-spotless-ram">SecurityStreet: Unsupported Browser</a> &#8211; rapid7.com<br />
The purpose of this post is to point out a little-known jewel &#8212; the -m flag to meterpreter&#8217;s execute command.</li>
</ul>
<p><strong> Vendor/Software Patches</strong></p>
<ul>
<li>Microsoft Security Bulletin</li>
<ul>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-029">MS12-029 &#8211; Critical : Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352)</a> &#8211; technet.microsoft.com<br />
This security update resolves a privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if a user opens a specially crafted RTF file. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</li>
<li><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-032">MS12-032 &#8211; Important : Vulnerability in TCP/IP Could Allow Elevation of Privilege (2688338)</a> &#8211; technet.microsoft.com<br />
This security update resolves one publicly disclosed and one privately reported vulnerability in Microsoft Windows. The more severe of these vulnerabilities could allow elevation of privilege if an attacker logs on to a system and runs a specially crafted application.</li>
<li><a href="http://blogs.technet.com/b/msrc/archive/2012/05/08/bulletin-management-process-and-the-may-2012-bulletins.aspx">Bulletin Management Process and the May 2012 Bulletins</a> - blogs.technet.com<br />
Have you ever wondered why bulletins group particular issues together? Or one set of products and not another? Well today Jonathan Ness has posted an insightful Security Research &amp; Defense (SRD) blog discussing some of the nuances and packaging decisions that went into MS12-034.</li>
<li><a href="http://www.zdnet.com/blog/security/microsoft-patches-23-windows-flaws-warns-of-risk-of-code-execution-attacks/12001">Microsoft patches 23 Windows flaws, warns of risk of code execution attacks</a> &#8211; zdnet.com<br />
The Patch Tuesday batch for May 2012 covers at least 23 documented vulnerabilities in Microsoft Office, Microsoft Windows, the Microsoft .NET Framework and Microsoft Silverlight.</li>
</ul>
<li><a href="http://krebsonsecurity.com/2012/05/adobe-microsoft-push-critical-security-fixes/">Adobe, Microsoft Push Critical Security Fixes</a> &#8211; krebsonsecurity.com<br />
Adobe and Microsoft today each issued updates to address critical security flaws in their software.</li>
<li><a href="http://blog.sucuri.net/2012/05/php-cgi-vulnerability-exploited-in-the-wild.html">PHP-CGI Vulnerability Exploited in the Wild</a> &#8211; blog.sucuri.net<br />
When the PHP-CGI vulnerability was disclosed, we knew it would be just a matter of days before it started to be exploited in the wild.</li>
</ul>
<p><strong> Vulnerabilities</strong></p>
<ul>
<li><a href="http://news.cnet.com/8301-1009_3-57430475-83/thousands-of-twitter-passwords-exposed/">Thousands of Twitter passwords exposed</a> &#8211; news.cnet.com<br />
It&#8217;s unclear who&#8217;s responsible for posting passwords for Twitter accounts to a public Web site. The exact number of accounts is also unclear, as Twitter says many are duplicates and many had already been suspended.</li>
</ul>
<p><strong> Other News</strong></p>
<ul>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/antivirus/240000174/fbi-warns-travelers-using-hotel-networks-about-new-attack.html">FBI Warns Travelers Using Hotel Networks About New Attack</a> &#8211; darkreading.com<br />
The FBI says attackers are trying to trick users into installing malware with promises of software updates.</li>
<li><a href="http://www.h-online.com/security/news/item/Sniffer-tool-displays-other-people-s-WhatsApp-messages-1574382.html">Sniffer tool displays other people&#8217;s WhatsApp messages</a> &#8211; h-online.com<br />
WhatsApp Sniffer is an app able to display messages from other WhatsApp users connected to the same network as the app user.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=2359&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2012/05/14/week-19-in-review-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 10 in Review &#8211; 2012</title>
		<link>http://infosecevents.net/2012/03/12/week-10-in-review-2012/</link>
		<comments>http://infosecevents.net/2012/03/12/week-10-in-review-2012/#comments</comments>
		<pubDate>Tue, 13 Mar 2012 01:50:11 +0000</pubDate>
		<dc:creator>Roxanne</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CanSec West]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[RSAC 2012]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=2172</guid>
		<description><![CDATA[Event Related CanSecWest CanSecWest evolving &#8211; blog.securiteam.com Let me say, right off the top, that I love CanSecWest. I am tired of “vendor” conferences, where you pay outrageous fees for the privilege of sitting through a bunch of sales pitches. At least CanSecWest has real information, as opposed to virtual information. CanSecWest Day 1 Pen [...]]]></description>
			<content:encoded><![CDATA[<p><strong> Event Related</strong></p>
<ul>
<li>CanSecWest</li>
<ul>
<li><a href="http://blogs.securiteam.com/index.php/archives/1650">CanSecWest evolving</a> &#8211; blog.securiteam.com
<p>Let me say, right off the top, that I love CanSecWest. I am tired of “vendor” conferences, where you pay outrageous fees for the privilege of sitting through a bunch of sales pitches. At least CanSecWest has real information, as opposed to virtual information.</li>
<li><a href="http://nakedsecurity.sophos.com/2012/03/08/cansecwest-day-1-pen-testing-social-authentication-apr-and-duqu/">CanSecWest Day 1 Pen testing, social authentication, APR and Duqu</a> &#8211; nakedsecurity.sophos.com<br />
A wrap-up of the news and talks from CanSecWest 2012 in Vancouver. I highlight talks on pen testing, social authentication, vulnerability mitigation and the Duqu command and control servers.</li>
<li><a href="http://nakedsecurity.sophos.com/2012/03/10/cansecwest-day-2-smartphones-mobile-security-ios-5-and-nfc/">CanSecWest Day 2 Smartphones, mobile security, iOS 5 and NFC</a> &#8211; nakedsecurity.sophos.com<br />
Day 2 at CanSecWest was dominated by mobile security talks. The highlights included anti-rooting technologies used in Android, iOS and a look at NFC enabled mobile phone security.</li>
<li><a href="http://home.regit.org/2012/03/playing-with-network-layers-to-bypass-firewalls-filtering-policy/">Playing with Network Layers to Bypass Firewalls Filtering Policy</a> &#8211; home.regit.org<br />
The slides of my CansecWest talk can now be downloaded: Playing with Network Layers to Bypass Firewalls’ Filtering Policy.</li>
</ul>
<li>RSA Conference</li>
<ul>
<li><a href="http://rants.effu.se/2012/03/B-Sides-SF-and-RSAC-2012-Summary">B-Sides SF and RSAC 2012 Summary</a> &#8211; rants.effu.se<br />
One of the consistent themes I heard from attendees of B-Sides SF and RSAC this year was &#8220;this was the best year yet!&#8221; That is a huge turn-around from the cynicism that was so prevalent last year.</li>
<li><a href="http://www.readwriteweb.com/enterprise/2012/03/invasion-of-the-risk-managers.php">Invasion of the Risk Managers: Altering the Complexion of Security&#8221;</a> &#8211; readwriteweb.com<br />
Article about the discussion panel on risk.
</li>
</ul>
</ul>
<p><strong> Resources</strong></p>
<ul>
<li><a href="https://blog.mandiant.com/archives/2326">M-Trends: The One Threat Report You Need to Read</a> &#8211; blog.mandiant.com<br />
Today is a big day. If you’ve followed us for a while you know that once a year we step back and take stock of what we’ve seen on the front lines battling targeted attacks. What is the advanced persistent threat (APT) up to?</li>
</ul>
<p><strong> Tools</strong></p>
<ul>
<li><a href="http://blog.didierstevens.com/2012/03/05/update-taskmanager-xls-v0-1-2/">TaskManager.xls V0.1.2 Update</a> &#8211; blog.didierstevens.com<br />
This is a new version of TaskManager.xls with memory usage statistics, with code given to me by sciomathman.</li>
<li><a href="http://www.zdnet.com/blog/security/zscaler-tool-can-find-unprotected-embedded-web-servers/10507">Zscaler tool can find unprotected embedded web servers</a> &#8211; zdnet.com<br />
The web-based tool can scan IP ranges to find multi-function printers and photocopiers, VOIP devices and video-conferencing systems that are currently.</li>
<li><a href="http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html">Introducing Adobe SWF Investigator</a> &#8211; adobe.com<br />
Today I am launching a beta of a tool on Adobe Labs called, Adobe SWF Investigator. This Adobe AIR-based application is a suite of tools that may be useful to SWF developers, quality engineers, and security researchers.</li>
<li><a href="http://ettercap.sourceforge.net/download.php">Ettercap v0.7.4.1 Lazarus Released</a> &#8211; ettercap.sourceforge.net<br />
Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.</li>
<li><a href="https://blog.wireshark.org/2012/03/wireshark-and-pcap-ng/">Wireshark and Pcap-ng</a> &#8211; blog.wireshark.org<br />
When Wireshark 1.8.0 is released in the next few months it will introduce two major features: the ability to capture from multiple interfaces at once and the ability to annotate packets.</li>
<li><a href="http://themole.nasel.com.ar/?q=downloads">Mole v0.3 (2012-03-02)</a> &#8211; themole.nasel.com.ar<br />
Command line sql injection tool</li>
<li><a href="http://hexale.blogspot.com/2012/03/wce-v13beta-32bit-released.html">WCE v1.3beta 32bit released</a> &#8211; hexale.blogspot.com
<p>WCE v1.3beta 32bit released.</li>
</ul>
<p><strong> Techniques</strong></p>
<ul>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/03/05/how-to-own-a-virtual-data-center">Testing the Security of Virtual Data Centers</a> &#8211; community.rapid7.com<br />
If you are doing security assessments, you are probably running into virtual servers every day. According to analyst firm Gartner, 80% of companies now have a virtualization project or program. With the recent 4.2 release of Metasploit, your next penetration test should be much more fun.</li>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/03/07/why-security-assessments-must-cover-ipv6-even-in-ipv4-networks">Why Security Assessments Must Cover IPv6, Even In IPv4 Networks</a> &#8211; community.rapid7.com
<p>What&#8217;s your company doing to prepare for IPv6? Probably not an awful lot. While 10% of the world&#8217;s top websites now offer IPv6 services, most companies haven&#8217;t formulated an IPv6 strategy for the network.</li>
<li><a href="http://www.sensepost.com/blog/6794.html">Foot printing – Finding your target&#8230;</a> &#8211; sensepost.com<br />
Network foot printing is, perhaps, the first active step in the reconnaissance phase of an external network security engagement. This phase is often highly automated with little human interaction as the techniques appear, at first glance, to be easily applied in a general fashion across a broad range of targets.</li>
</ul>
<p><strong> Vulnerabilities</strong></p>
<ul>
<li>Google Chrome Hacked</li>
<ul>
<li><a href="http://www.zdnet.com/blog/security/pwn2own-2012-google-chrome-browser-sandbox-first-to-fall/10588">Pwn2Own 2012: Google Chrome browser sandbox first to fall</a> &#8211; zdnet.com
<p>Exploit writers at VUPEN take special pleasure in attacking Google’s Chrome browser, using a pair of zero-day flaws to defeat the browser.</li>
<li><a href="http://www.zdnet.com/blog/security/cansecwest-pwnium-google-chrome-hacked-with-sandbox-bypass/10563">CanSecWest Pwnium: Google Chrome hacked with sandbox bypass</a> &#8211; zdnet.com
<p>The attack, which included a Chrome sandbox bypass, was the handiwork of Sergey Glazunov, a security researcher who regularly finds and reports Chrome.</li>
<li><a href="http://gizmodo.com/5891508/chrome-finally-breached-in-googles-1-million-hackathon">Chrome Finally Breached in Google’s $1 Million Hackathon</a>- gizmodo.com
<p>Google recently offered up prizes totaling $1 million for those capable of exploiting its browser Chrome. Now, at Google&#8217;s own competition called Pwnium, a student has walked away with one of the top prizes, earning $60,000 by hacking a PC running Chrome.</li>
<li><a href="http://arstechnica.com/business/news/2012/03/after-the-pwnage-critical-google-chrome-hole-plugged-in-24-hours.ars">After the pwnage: Critical Google Chrome hole plugged in 24 hours</a> &#8211; arstechnica.com
<p>Underscoring the nimbleness of Google&#8217;s patching cycle, Chrome developers fixed a complex series of bugs less than 24 hours after they were demoed at a hacker conference.</li>
<li><a href="http://www.wired.com/threatlevel/2012/03/zero-days-for-chrome/">Teen Exploits Three Zero-Day Vulns for $60K Win in Google Chrome Hack Contest</a> &#8211; wired.com
<p>A teenage hacker known as Pinkie Pie pokes a hole in Google&#8217;s Chrome browser, an unlikely winner who&#8217;s taking home $60K and a possible job at the search giant.</li>
<li><a href="http://www.zdnet.com/blog/security/how-google-set-a-trap-for-pwn2own-exploit-team/10641">How Google set a trap for Pwn2Own exploit team</a> &#8211; zdnet.com
<p>Here’s the story of how a unique signature was used to figure out if exploit writers would take aim at the Flash Player plugin in Google Chrome</li>
</ul>
<li>Pwn2Own Hacking Contest</li>
<ul>
<li><a href="http://www.zdnet.com/blog/security/charlie-miller-skipping-pwn2own-as-new-rules-change-hacking-game/10554">Charlie Miller skipping Pwn2Own as new rules change hacking game</a> &#8211; zdnet.com
<p>The annual Pwn2Own hacker contest kicks off today with new rules, controversy over disclosure and the absence of a regular participant.</li>
<li><a href="http://www.zdnet.com/blog/security/pwn2own-2012-ie-9-hacked-with-two-0day-vulnerabilities/10621">Pwn2Own 2012: IE 9 hacked with two 0day vulnerabilities</a> &#8211; zdnet.com
<p>The code execution attack, which required no user action beyond browsing to a rigged web site, also works on Internet Explorer v10.</li>
<li><a href="http://www.wired.com/threatlevel/2012/03/how-to-pwn-the-pwn2own-contest/">How to Pwn the Pwn2Own Contest</a> &#8211; wired.com
<p>Finding zero-day exploits to win a hacking contest can be really hard work these days. So sometimes the better strategy is just to game the game.</li>
</ul>
<li><a href="http://erratasec.blogspot.com/2012/03/rubygithub-hack-translated.html">The Ruby/GitHub hack: translated</a> &#8211; erratasec.blogspot.com<br />
The underlying issue is an “Insecure Direct Object Reference”, #4 on the OWASP Top 10 list of most important web-application vulnerabilities. It means that that a hacker can change what&#8217;s in the website database without having permission.</li>
</ul>
<p><strong> Other News</strong></p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2012/03/feds-seize-foreign-sites/all/1">Uncle Sam: If It Ends in .Com, It&#8217;s Seizable</a> &#8211; wired.com
<p>The U.S. government says it has the right to seize any .com, .net and .org domain name because the companies that have the contracts to administer them are based on United States soil, according to Nicole Navas, an Immigration and Customs Enforcement spokeswoman.</li>
<li><a href="http://nakedsecurity.sophos.com/2012/03/07/sabus-sordid-story-detailed-in-fbi-indictment/">Sabus sordid story detailed in FBI indictment</a> &#8211; nakedsecurity.sophos.com
<p>Hector Xavier Monsegur may have portrayed the exploits of Anonymous and LulzSec as a glamorous fight against &#8220;the man&#8221;, but the dark criminal realities of their exploits were exposed in his indictment. It appears he wasn&#8217;t just in it for the lulz.</li>
<li><a href="http://www.symantec.com/connect/blogs/dropbox-abused-spammers">Dropbox Abused by Spammers</a> &#8211; symantec.com
<p>Recently we noticed spammers abusing Dropbox, a popular cloud-based, file-hosting and synchronization tool, to spread spam. Dropbox accounts have a public folder where files can be placed and made publicly available. This function is useful to spammers, as it effectively turns Dropbox into a free hosting site.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=2172&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2012/03/12/week-10-in-review-2012/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Week 8 in Review &#8211; 2012</title>
		<link>http://infosecevents.net/2012/02/27/week-8-in-review-2012/</link>
		<comments>http://infosecevents.net/2012/02/27/week-8-in-review-2012/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 22:49:51 +0000</pubDate>
		<dc:creator>Roxanne</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cybersecurity act of 2012]]></category>
		<category><![CDATA[drupal]]></category>
		<category><![CDATA[iOS5]]></category>
		<category><![CDATA[Oracle]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=2123</guid>
		<description><![CDATA[Resources A look at ASLR in Android Ice Cream Sandwich 4.0 &#8211; blog.duosecurity.com For the uninitiated, ASLR randomizes where various areas of memory (eg. stack, heap, libs, etc) are mapped in the address space of a process. The Ultimate OS X Hardening Guide Collection &#8211; isc.sans.edu Many security professionals tend to use OS X systems. [...]]]></description>
			<content:encoded><![CDATA[</ul>
<p><strong> Resources</strong></p>
<ul>
<li><a href="http://blog.duosecurity.com/2012/02/a-look-at-aslr-in-android-ice-cream-sandwich-4-0/">A look at ASLR in Android Ice Cream Sandwich 4.0</a> &#8211; blog.duosecurity.com<br />
For the uninitiated, ASLR randomizes where various areas of memory (eg. stack, heap, libs, etc) are mapped in the address space of a process.
</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=12616&amp;rss">The Ultimate OS X Hardening Guide Collection</a> &#8211; isc.sans.edu<br />
Many security professionals tend to use OS X systems. Maybe for the nice and shiny looks, or the Unix under pinnings that make it a great platform to run current tools. However, the operating system itself isn&#8217;t exactly &#8220;secure out of the box&#8221; and like all operating systems can profit from some additional hardening tricks.
</li>
<li><a href="http://dankaminsky.com/2012/02/20/whitehat/">White Hat Hacker Flowchart</a> &#8211; dankaminsky.com<br />
A white hat hacker flowchart by Dan Kaminsky.
</li>
</ul>
<p><strong> Tools</strong></p>
<ul>
<li><a href="https://github.com/Rorchackh/Blue-Sky-Information-Security/blob/master/DPScan.py">DPScan: Drupal Security Scanner</a> &#8211; github.com<br />
This small tool is public and accessible for our use. It may help other auditors or penetration testers do their job faster and gather more information.
</li>
<li><a href="http://thesprawl.org/projects/dnschef/">DNSChef</a> &#8211; thesprawl.org<br />
DNSChef is a highly configurable DNS proxy for Penetration Testers and Malware Analysts. A DNS proxy (aka &#8220;Fake DNS&#8221;) is a tool used for application network traffic analysis among other uses.
</li>
<li><a href="http://blog.buguroo.com/?p=2471&amp;lang=en">Sqlmap plugin for BurpSuite</a> &#8211; blog.buguroo.com<br />
Today we present a free plugin, developed by me, so you can use the sqlmap from BurpSuite so really comfortable.
</li>
<li><a href="https://code.google.com/p/sipvicious/downloads/list">SIPVicious 0.2.7</a> &#8211; code.google.com<br />
SIPVicious suite is a set of tools that can be used to audit SIP based VoIP systems.  It currently consists of four tools.
</li>
<li><a href="http://code.google.com/p/skipfish/downloads/list">Skipfish-2.04b</a> &#8211; code.google.com<br />
Skipfish is a fully automated, active web application security reconnaissance tool.</li>
<li><a href="https://www.secmaniac.com/blog/2012/02/20/the-social-engineer-toolkit-set-3-0-wethrowbaseballs-has-been-released/">Social-Engineer Toolkit (SET) 3.0 released.</a> &#8211; secmaniac.com<br />
Greetings all. I’m excited to release the 3.0 version of the Social-Engineer Toolkit (SET) Codename “#WeThrowBaseballs”.
</li>
<li><a href="https://community.rapid7.com/community/metasploit/blog/2012/02/22/metasploit-42-released">Metasploit 4.2 Released: IPv6, VMware, and Tons of Modules!</a> &#8211; community.rapid7.com<br />
Since our last release in October, we&#8217;ve added 54 new exploits, 66 new auxiliary modules, 43 new post-exploitation modules, and 18 new payloads &#8212; that clocks in at just about 1.5 new modules per day since version 4.1.</p>
</li>
</ul>
<p><strong> Techniques</strong></p>
<ul>
<li><a href="http://pen-testing.sans.org/blog/2012/02/22/mobile-app-permissions-and-choice">Mobile App Permissions and Choice</a> &#8211; pen-testing.sans.org<br />
Recently we&#8217;ve seen a flurry of news articles identifying a weakness in the Apple iOS architecture where application developers have unrestricted access to contact book entries on your iPhone, iTouch or iPad.
</li>
<li><a href="http://resources.infosecinstitute.com/minimizing-vulnerabilities-applications/">Minimizing Vulnerabilities in Applications – Part 1</a> &#8211; resources.infosecinstitute.com<br />
During my 20+ year career, I have seen many coding virtuosos which had only one problem – they did not pay any attention to the security of their code.
</li>
<li><a href="http://dvlabs.tippingpoint.com/blog/2012/02/25/mindshare-yo-dawg-i-heard-you-like-reversing">MindshaRE: a reversing tool</a> &#8211; dvlabs.tippingpoint.com<br />
MindshaRE is our periodic look at some simple reverse engineering tips and tricks. The goal is to keep things small and discuss every day aspects of reversing. You can view previous entries by going through our blog history or querying a search engine for dvlabs mindshare.
</li>
</ul>
<p><strong> Vulnerabilities</strong></p>
<ul>
<li>iOS 5 Flaw Allows data access</li>
<ul>
<li><a href="http://www.technolog.msnbc.msn.com/technology/technolog/paperclips-pose-security-threat-iphones-157719">Paperclips pose security threat to iPhones</a> &#8211; technolog.msnbc.msn.com<br />
Under the right — though easily arranged — circumstances, a simple paperclip could allow someone to circumvent your iPhone&#8217;s passcode and access your voicemail, contacts, recent call list, and other data.
</li>
<li><a href="http://threatpost.com/en_us/blogs/ios-5-flaw-allows-unfettered-access-users-contacts-calls-022112">iOS 5 Flaw Allows Unfettered Access to User&#8217;s Contacts, Calls</a> &#8211; threatpost.com<br />
A passcode flaw in Apple’s iOS 5 could allow unauthorized access to an iPhone user’s contacts list, recent calls, voicemail, text messages and more, according to a recent blog post from CultofMac.com.
</li>
</ul>
<li><a href="http://www.darkreading.com/database-security/167901020/security/application-security/232601382/new-oracle-erp-vulnerabilities-unmasked.html">New Oracle ERP Vulnerabilities Unmasked</a> &#8211; darkreading.com<br />
Design flaws could allow attackers to access, alter, or take over ERP systems &#8212; but will enterprises do anything about the vulnerabilities?
</li>
</ul>
<p><strong> Other News</strong></p>
<ul>
<li><a href="http://arstechnica.com/business/news/2012/02/plesk-control-panel-bug-left-ftc-sites-and-thousands-more-exposed-to-anon.ars">Plesk control panel bug left FTC sites (and thousands more) exposed to Anons</a> &#8211; arstechnica.com<br />
[needs validation]A critical vulnerability in Parallels&#8217; Plesk Panel Web hosting administration tool left thousands of servers open to potential hijacking by hackers. And the recently hacked sites belonging to the Federal Trade Commission were among them, according to sources.
</li>
<li><a href="http://news.cnet.com/8301-27080_3-57385022-245/note-to-self-encrypt-data-memorize-password/">Note to self: Encrypt data, memorize password</a> &#8211; news.cnet.com<br />
In a case that serves as a reminder to: a) use encryption, and b) memorize the encryption pass-phrase, an appeals court has ruled that people have a constitutional right not to be forced to decrypt data that potentially includes evidence that could be used to prosecute them in court.</p>
<li><a href="http://threatpost.com/en_us/blogs/researchers-reveal-how-attackers-can-track-cell-phone-locations-021812">Researchers Reveal How Attackers Can Track Cell Phone Locations</a> &#8211; threatpost.com<br />
New research has found information leaked by cell towers can be used to determine your cell phone’s general location.
</li>
<li><a href="http://www.forbes.com/sites/erikkain/2012/02/22/does-the-cybersecurity-act-of-2012-mark-the-beginning-of-the-war-on-cyber-terrorism/">Does The Cybersecurity Act Of 2012 Mark The Beginning Of The War On Cyber-terrorism?</a> &#8211; forbes.com<br />
The Cybersecurity Act of 2012 is the latest effort by Congress to do something about the threat of cyber attacks and cyber crime.
</li>
<li><a href="http://threatpost.com/en_us/blogs/nist-maryland-plan-new-cybersecurity-center-022212">NIST, Maryland Plan New Cybersecurity Center</a> &#8211; threatpost.com<br />
The US National Institute of Standards and Technology (NIST) announced plans Tuesday to break ground on a new center that will be committed to cybersecurity research.
</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=2123&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2012/02/27/week-8-in-review-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 25 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/06/28/week-25-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/06/28/week-25-in-review-2010/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 13:08:24 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[EC2ND]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[Night da Hack]]></category>
		<category><![CDATA[NovaInfoSec]]></category>
		<category><![CDATA[Nuit du Hack]]></category>
		<category><![CDATA[Sharkfest]]></category>
		<category><![CDATA[SummerCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1095</guid>
		<description><![CDATA[Events Related: Who&#8217;s on&#8230;uh, at&#8230;FIRST? &#8211; windowsir.blogspot.com My employer is not a member of FIRST, but we were a sponsor, and we hosted the &#8220;Geek Bar&#8221;. La “Nuit Du Hack” in Paris &#8211; rootshell.be The event was split in two parts: a set of talks about security topics and, starting from midnight, a CTF contest. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://windowsir.blogspot.com/2010/06/whos-onuh-atfirst.html">Who&#8217;s on&#8230;uh, at&#8230;FIRST?</a> &#8211; windowsir.blogspot.com<br />
My employer is not a member of FIRST, but we were a sponsor, and we hosted the &#8220;Geek Bar&#8221;.</li>
<li><a href="http://blog.rootshell.be/2010/06/20/la-nuit-du-hack-in-paris/">La “Nuit Du Hack” in Paris</a> &#8211; rootshell.be<br />
The event was split in two parts: a set of talks about security topics and, starting from midnight, a CTF contest.</li>
<li><a href="http://www.novainfosecportal.com/resources/nova-email-lists-networking/novainfosec-twits/">NovaInfosec Twits</a> &#8211; novainfosecportal.com<br />
The Twitter account for the NovaInfosec Twits list is novainfosec.</li>
<li><a href="http://trailofbits.com/2010/06/23/hacking-at-mach-speed/">Hacking at Mach Speed!</a> &#8211; trailofbits.com<br />
The first ever NYC SummerCon last weekend was a blast and everyone seemed to have a great time.</li>
<li><a href="http://honeyblog.org/archives/61-Call-for-Papers-EC2ND10.html">Call for Papers: EC2ND&#8217;10</a> &#8211; honeyblog.org<br />
EC2ND 2010 specifically encourages submissions presenting work at an early stage with the intention to act as a discussion forum for innovative security research.</li>
<li><a href="http://taosecurity.blogspot.com/2010/06/comments-on-sharkfest-presentation.html">Comments on Sharkfest Presentation Materials</a> &#8211; taosecurity.blogspot.com<br />
This is the third year that CACE Technologies has organized this conference.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://blog.thinkst.com/2010/06/conference-on-cyber-conflict-slides.html">Conference on Cyber Conflict &#8211; Slides..</a> &#8211; thinkst.com<br />
The CCDCOE (Cooperative Cyber DefenceCentre of Excellence) held its Conference on Cyber Conflict in Tallinn, Estonia.</li>
<li><a href="http://www.securityninja.co.uk/the-talks-i%E2%80%99m-looking-forward-to-attending-in-las-vegas">The talks I’m looking forward to attending in Las Vegas</a> &#8211; securityninja.co.uk<br />
We are getting closer to the annual geek pilgrimage to Las Vegas for the BlackHat, DEF CON and SecurityBSides conferences.</li>
<li><a href="https://docs.google.com/fileview?id=0B3_AmubjewYTMmY4MDRiNTAtYmVkMi00NGQ4LTg3NjEtY2ZlNTdiYjZlYzUy&amp;hl=en">SQL Injection Anywhere White Paper</a> &#8211; docs.google.com<br />
An advanced SQL Injection exploitation technique, that allows the complete disclosure of information from (almost) any SQL Injection exposure.</li>
<li><a href="https://www.ssllabs.com/ssldb/">Public SSL Server Database / SSL Server Test</a> &#8211; ssllabs.com<br />
Public SSL Server Database is an online service that enables you to look up the configuration of any public SSL web server.</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=9073">Live CD for Remote Incident Handling</a> &#8211; sans.edu<br />
Bert Hayes is a security professional at the University of Texas.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://blog.c22.cc/2010/06/20/uatester-alpha/">UATester Alpha</a> &#8211; c22.cc<br />
This tool is designed to automatically check a given URL using a list of standard and non-standard User Agent strings provided by the user (1 per line).</li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_JBroFuzz">JBroFuzz</a> &#8211; owasp.org<br />
Its purpose is to provide a single, portable application that offers stable web protocol fuzzing capabilities.</li>
<li><a href="http://www.darknet.org.uk/2010/06/w3af-1-0-rc3-available-for-download-web-application-attack-audit-framework/">w3af 1.0-rc3 Available For Download</a> &#8211; darknet.org.uk<br />
The project’s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend.</li>
<li><a href="http://code.google.com/p/andiparos/">andiparos</a> &#8211; code.google.com/p/andiparos/<br />
Andiparos is a fork of the famous Paros Proxy.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://www.tehtri-security.com/en/news.php?id=39">TEHTRI-Security gave 13 0days against most black hats tools</a> &#8211; tehtri-security.com<br />
Today, during our humble new talk at SyScan 2010 Singapore, we have just released many 0days and new offensive concepts against most of the tools used by attackers currently, like web shells, exploit packs, etc.</li>
<li><a href="http://www.greebo.net/2010/06/21/659/">Risk Management 103 – Choosing Threat Agents</a> &#8211; greebo.net<br />
We’re talking about the attackers (threat agents) on the left today.</li>
<li><a href="http://stateofsecurity.com/?p=1056">Review of darkjumper v5.7</a> &#8211; stateofsecurity.com<br />
In continuing our research and experimentation with PHP and the threat of Remote File Inclusion (RFI), our team has been seeking out and testing various tools that have been made available to help identify web sites that are vulnerable to RFI during our penetration tests.</li>
<li><a href="http://blogs.sans.org/computer-forensics/2010/06/21/security-intelligence-knowing-enemy/">Security Intelligence: Defining APT Campaigns</a> &#8211; sans.org<br />
The “persistence” in APT intrusions is manifested in two ways: maintaining a presence on your network, as well as repeatedly attempting to gain entry to areas where presence is not established.</li>
<li><a href="http://ha.ckers.org/blog/20100621/side-channel-attacks-in-ssl/">Side Channel Attacks in SSL</a> &#8211; ha.ckers.org<br />
Initially it really upset me off that this paper was written, not because it’s not excellent, but because it’s partially what I was going to be speaking about at BlackHat.</li>
<li><a href="http://research.microsoft.com/apps/pubs/default.aspx?id=120428">How Secure are Secure Interdomain Routing Protocols?</a> &#8211; microsoft.com<br />
In response to high-profile Internet outages, BGP security variants have been proposed to prevent the propagation of bogus routing information.</li>
<li><a href="http://blog.commandlinekungfu.com/2010/06/episode-101-third-party-party.html">Episode #101: Third-Party Party</a> &#8211; commandlinekungfu.com<br />
Yes, believe it or not, there are instances where some things are really straight-forward and fun on Windows, and are inscrutably ugly on Linux.</li>
<li><a href="http://blog.portswigger.net/2010/06/comparing-web-application-scanners.html">Comparing web application scanners</a> &#8211; portswigger.net<br />
Earlier this year, Larry Suto published a paper comparing web application vulnerability scanners.</li>
<li><a href="http://www.acunetix.com/blog/web-security-zone/articles/analysis-php-attack-apple-information-disclosure/">In-depth analysis of a PHP attack that lead to Apple information disclosure</a> &#8211; acunetix.com<br />
Security experts blame this breach on “poorly designed software”.</li>
<li><a href="http://www.whitehouse.gov/blog/2010/06/25/national-strategy-trusted-identities-cyberspace">The National Strategy for Trusted Identities in Cyberspace</a> &#8211; whitehouse.gov<br />
Cyberspace has become an indispensible component of everyday life for all Americans.</li>
<li><a href="http://www.zdnet.com.au/us-interested-in-aussie-zombie-code-339304063.htm">US interested in Aussie zombie code</a> &#8211; zdnet.com<br />
Australia&#8217;s Internet Industry Association (IIA) took its e-security code of conduct to the White House, where it met with Barack Obama&#8217;s cyber-security coordinator, Howard Schmidt, to discuss it as a potential model for the US internet industry to adopt.</li>
<li><a href="http://gunslingerc0de.wordpress.com/2010/06/26/linux-buffer-overflow-tutorial/">Linux Buffer Overflow Tutorial</a> &#8211; gunslingerc0de.wordpress.com/</li>
<li><a href="http://ha.ckers.org/blog/20100622/improving-https-side-channel-attacks/">Improving HTTPS Side Channel Attacks</a> &#8211; ha.ckers.org<br />
In regards to the previous post and the impending Blackhat speech with Josh Sokol, I thought I’d spend some time enumerating some of the possibilities for reducing the chatter over SSL/TLS that the browser introduces.</li>
<li><a href="http://www.golubev.com/blog/?p=122">Yep, they broke it.</a> &#8211; golubev.com<br />
I don’t know how they test drivers or even are they test drivers at all but situation is pretty weird.</li>
<li><a href="http://www.m86security.com/labs/traceitem.asp?article=1366">Another round of Asprox SQL injection attacks</a> &#8211; m86security.com<br />
Earlier this month, we reported on a new variant of Asprox malware which was being spammed out by the Pushdo botnet.</li>
<li><a href="http://www.digitalbond.com/index.php/2010/06/24/using-killerbee-with-zigbee-devices/">Using KillerBee with ZigBee devices</a> &#8211; digitalbond.com<br />
Yesterday I received a few of the Raven ZigBee USB sticks with the KillerBee firmware loaded on it, thank you Joshua Wright.</li>
<li><a href="http://www.attackvector.org/botnet-command-and-control-methods/">Botnet Command and Control Methods</a> &#8211; attackvector.org<br />
I think probably the biggest reason would be that there would be a pretty cut and dry trail of what the bots are doing.</li>
<li><a href="http://ha.ckers.org/blog/20100625/places-to-mitm/">Places to MITM</a> &#8211; ha.ckers.org<br />
There’s a lot of places there than an attacker can get in the middle and mess things up.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/06/low-hanging-fruit-scanner-strategy-can.html">The Low Hanging Fruit scanner strategy can get you into trouble</a> &#8211; jeremiahgrossman.blogspot.com<br />
Vulnerabilities identifiable in an automated fashion, such as with a scanner, can be loosely classified as “low-hanging fruit&#8221;.</li>
<li><a href="http://invalid-packet.blogspot.com/2010/06/sqlmap-08-and-soap-based-web-services.html">SQLmap 0.8 and SOAP based Web-Services</a> &#8211; invalid-packet.blogspot.com<br />
Lately I was pen-testing SOAP Web-Services, and I came to learn that SQLmap wasn&#8217;t aware of SOAP syntax.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/new-firefox-flaw-enables-url-spoofing-code-injection-062210">New Firefox Flaw Enables URL Spoofing, Code Injection</a> &#8211; threatpost.com<br />
A prominent security researcher has identified a problem with the way that Mozilla Firefox handles links that are opened in a new browser window or tab.</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://blogs.adobe.com/psirt/2010/06/pre-notification_-_quarterly_s_3.html">Pre-Notification &#8211; Quarterly Security Updates for Adobe Reader and Acrobat</a> &#8211; adobe.com<br />
A Security Advisory has been posted in regards to the upcoming Adobe Reader and Acrobat updates scheduled for June 29, 2010.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://www.google.com/hostednews/ap/article/ALeqM5hnlGg0WbQxyqIeXJ_t7-N3aCJheAD9GDV11O0">Napolitano: US must balance liberties, security</a> &#8211; google.com<br />
Fighting homegrown terrorism by monitoring Internet communications is a civil liberties trade-off the U.S. government must make to beef up national security, the nation&#8217;s homeland security chief said Friday.</li>
<li><a href="http://www.darkreading.com/vulnerability_management/security/perimeter/showArticle.jhtml?articleID=225700674">Looking For Vulns In All The Right Places? Experts Say You Might Be Missing A Few</a> &#8211; darkreading.com<br />
Network-attached devices, paper documents, and your physical plant should be included in vulnerability scans, researchers warn.</li>
<li><a href="http://www.h-online.com/security/news/item/Malicious-code-on-Lenovo-driver-download-page-Update-1025886.html">Malicious code on Lenovo driver download page &#8211; Update</a> &#8211; h-online.com<br />
Various virus scanners issued alerts about a Java-based Trojan downloader or dropper.</li>
<li><a href="http://vrt-sourcefire.blogspot.com/2010/06/defenders-of-faith.html">Defenders of the Faith</a> &#8211; vrt-sourcefire.blogspot.com<br />
Quite recently, Tavis Ormandy released a 0-day vulnerability in a prominent piece of software.</li>
<li><a href="http://www.zdnet.com/blog/security/researchers-find-12-zero-day-flaws-targeting-5-web-malware-exploitation-kits/6752">Researchers find 12 zero day flaws, targeting 5 web malware exploitation kits</a> &#8211; zdnet.com<br />
Security researchers from TEHTRI-Security, have found 12 zero day flaws targeting 5 of the most common web malware exploitation kits.</li>
<li><a href="http://thehill.com/blogs/hillicon-valley/technology/104751-white-house-unveils-plan-to-combat-online-piracy-and-counterfeit-goods">White House unveils plan to combat online piracy and counterfeit goods</a> &#8211; thehill.com<br />
“I have a warning to you, we’re committed to putting you out of business,” Intellectual Property Enforcement Coordinator Victoria Espinel, also known as the “copyright czar,” said.</li>
<li><a href="http://www.computerworld.com/s/article/9178394/Apple_leaves_iPad_vulnerable_after_monster_iPhone_patch_job">Apple leaves iPad vulnerable after monster iPhone patch job</a> &#8211; computerworld.com<br />
However, the first-generation iPhone and iPod Touch, as well as the much newer iPad, may be vulnerable to some or all of the 65 bugs.</li>
<li><a href="http://www.aph.gov.au/house/committee/coms/cybercrime/report.htm">Inquiry into Cyber Crime</a> &#8211; aph.gov.au<br />
On Monday 21 June 2010, the Standing Committee on Communications tabled its report on the inquiry into Cyber Crime entitled Hackers, Fraudsters and Botnets: Tackling the Problem of Cyber Crime.</li>
<li><a href="http://g1.globo.com/English/noticia/2010/06/not-even-fbi-can-de-crypt-files-daniel-dantas.html">Not even FBI was able to decrypt files of Daniel Dantas</a> &#8211; g1.globo.com<br />
Hard drives were seized by the feds during Operation Satyagraha, in 2008.</li>
<li><a href="http://www.networkworld.com/community/blog/verisign-ssl-hackable-comodo-exposes-verisign">VeriSign SSL Hackable &#8211; Comodo Exposes, VeriSign Denies</a> &#8211; networkworld.com<br />
Comodo announced today that it requested an independent third-party to notify VeriSign of a security vulnerability affecting its customers’ web sites, including a major financial institution.</li>
<li><a href="http://krebsonsecurity.com/2010/06/exploiting-the-exploiters/">Exploiting the Exploiters</a> &#8211; krebsonsecurity.com<br />
Last week, French security researchers announced they had discovered a slew of vulnerabilities in several widely used “exploit packs,” stealthy tool kits designed to be stitched into hacked and malicious sites.</li>
<li><a href="http://www.darkreading.com/database_security/security/intrusion-prevention/showArticle.jhtml?articleID=225700716">Researcher &#8216;Fingerprints&#8217; The Bad Guys Behind The Malware</a> &#8211; darkreading.com<br />
Black Hat USA researcher will demonstrate how to find clues to help ID actual attackers, plans to release free fingerprinting tool.</li>
<li><a href="http://www.avertlabs.com/research/blog/index.php/2010/06/24/inside-the-carding-underworld/">Inside the Carding Underworld</a> &#8211; avertlabs.com<br />
Carder.cc is a German online forum dedicated to helping criminals in trading stolen credit card and login details obtained via their carding or phishing activities.</li>
<li><a href="http://www.dailytelegraph.com.au/news/wacky/atm-scammers-take-it-to-a-new-level/story-e6frev20-1225883371762">ATM scammers take it to a new level</a> &#8211; dailytelegraph.com.au<br />
Thieves set up a fake ATM that recorded the bank details of unsuspecting users whose accounts were later robbed, in the first such scam discovered in China.</li>
<li><a href="http://www.wired.com/threatlevel/2010/06/hacker-faces-decades-imprisonment/">Accused Hacker Who Balked at 2-Year Prison Deal Now Faces Decades</a> &#8211; wired.com<br />
An alleged hacker who declined a 2-year plea deal is facing decades behind bars after federal authorities Thursday added multiple charges, including possession and distribution of child pornography.</li>
<li><a href="http://www.darkreading.com/security/government/showArticle.jhtml?articleID=225701290">Senate Working To Consolidate Cybersecurity Bills</a> &#8211; darkreading.com<br />
There is broad agreement between key Senate committees in terms of key elements that need to be included in any comprehensive legislation.</li>
<li><a href="http://threatpost.com/en_us/blogs/android-also-gives-google-remote-app-installation-power-062510">Android Also Gives Google Remote App Installation Power</a> &#8211; threatpost.com<br />
It turns out that Android also includes a feature that enables Google to remotely install apps on users&#8217; phones as well.</li>
</ul>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1095&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/06/28/week-25-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Week 43 in Review &#8211; 2009</title>
		<link>http://infosecevents.net/2009/10/26/week-43-in-review/</link>
		<comments>http://infosecevents.net/2009/10/26/week-43-in-review/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 16:50:03 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=359</guid>
		<description><![CDATA[Events Related: S4 registration open / full agenda available &#8211; digitalbond.com The 2010 SCADA Security Scientific Symposium has opened it registration and its schedule is now available. RSA Europe 2009 &#8211; Day 1 Recap &#8211; infosecramblings.com Interesting Information Security Bits RSA Catch-up Part 1 &#8211; infosecramblings.com RSA Europe 2009 Security Bloggers Meetup Recap &#8211; infosecramblings.com [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://www.digitalbond.com/index.php/2009/10/21/s4-registration-open-full-agenda-available/">S4 registration open / full agenda available</a> &#8211; digitalbond.com<br />
The 2010 SCADA Security Scientific Symposium has opened it registration and its schedule is now available.</li>
<li><a href="http://www.infosecramblings.com/2009/10/21/rsa-europe-2009-day-1-recap/">RSA Europe 2009 &#8211; Day 1 Recap</a> &#8211; infosecramblings.com</li>
<li><a href="http://www.infosecramblings.com/2009/10/25/interesting-information-security-bits-rsa-catch-up-part-1/">Interesting Information Security Bits RSA Catch-up Part 1</a> &#8211; infosecramblings.com</li>
<li><a href="http://www.infosecramblings.com/2009/10/21/rsa-europe-2009-security-bloggers-meetup-recap/">RSA Europe 2009 Security Bloggers Meetup Recap</a> &#8211; infosecramblings.com</li>
<li><a href="http://www.infosecramblings.com/2009/10/25/rsa-europe-2009-day-3-recap/">RSA Europe 2009 &#8211; Day 3 Recap</a> &#8211; infosecramblings.com<br />
A few of summaries on the happenings at this security event.</li>
</ul>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://pentesterscripting.com/">PenTester Scripting</a> &#8211; pentesterscripting.com<br />
A site for hosting useful scripts for penetration testing</li>
<li><a href="http://www.social-engineer.org/framework/Social_Engineering_Framework">Social Engineering Framework</a> &#8211; social-engineer.org<br />
A comprehensive site detailing all things related to social engineering from attacks to defense tactics.</li>
<li><a href="http://blog.osvdb.org/2009/10/22/classification-exploit-status-overhaul">Classification: Exploit Status Overhaul</a> &#8211; osvdb.org<br />
OSVDB overhauled the exploit classification system for better categorization.</li>
<li><a href="http://blog.osvdb.org/2009/10/23/metasploit-reference-support-added-more">Metasploit Reference Support Added &amp; More</a> &#8211; osvdb.org<br />
OSVDB now supports a &#8216;Metasploit ID&#8217; that uses the corresponding OSVDB ID to link and auto-search their database.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://isc.sans.org/tools/reversehash.html">Reverse Hash Calculator</a> &#8211; isc.sans.org<br />
This uses a database of a couple million pre-compiled hash values.</li>
<li><a href="http://windowsir.blogspot.com/2009/10/free-tools.html">Free Tools</a> &#8211; windowsir.blogspot.com<br />
A very long list of tools that might be interesting to pentesters everywhere</li>
<li><a href="http://www.owasp.org/index.php?title=Category:OWASP_Vicnum_Project&amp;setlang=es">Vicnum v1.3</a> &#8211; owasp.org<br />
Helpful to IT auditors honing web security skills and setting up &#8216;capture the flag&#8217; .</li>
<li><a href="http://www.digininja.org/projects/cewl.php">CeWL &#8211; Custom Word List Generator v2.2</a> &#8211; digininja.org<br />
CeWL spiders a given url to a specified depth and returns a list of words which can be used for password crackers.</li>
</ul>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://synjunkie.blogspot.com/2009/10/bobs-double-penetration-adventure-part.html">Bob&#8217;s Double Penetration Adventure &#8211; Part 1</a> &#8211; synjunkie.blogspot.com<br />
Pardoning the adult-oriented title, this is basically a story of a simple man&#8217;s quest at hacking.</li>
<li><a href="http://chirashi.zensay.com/2009/10/phonesnoop-turn-a-blackberry-into-a-portable-bug/">PhoneSnoop &#8211; Turn a BlackBerry into a portable bug</a> &#8211; chirashi.zensay.com<br />
A hacker releases a tool to tap into phone calls undetected.</li>
<li><a href="http://blogs.zdnet.com/security/?p=4662">&#8216;Evil Maid&#8217; USB stick attack keylogs TrueCrypt passphrases</a> &#8211; zdnet.com<br />
A &#8216;plug-and-exploit&#8217; technique that can help attacker decrypt a hard drive&#8217;s content</li>
<li><a href="http://www.darkreading.com/blog/archives/2009/10/usb_attack_pres.html">Using USBs for incident response</a> &#8211; darkreading.com<br />
A brief look at how USB devices can be used for good and evil</li>
<li><a href="http://blog.red-database-security.com/2009/10/20/paul-wright-released-whitepaper-about-create-table-to-osdba-preprocessor-exploit/">Paul Wright released whitepaper about &#8220;Create Table to OSDBA&#8221; (preprocessor exploit)</a> &#8211; red-database-security.com<br />
This whitepaper shows how to escalate privileges by running OS commands using create table together with utl_file.</li>
<li><a href="http://reusablesec.blogspot.com/2009/10/analysis-of-10k-hotmail-passwords-part_18.html">Analysis of 10k Hotmail passwords Part 3 &#8211; brute force</a> &#8211; reusablesec.blogspot.com<br />
In this third installment, brute force is tested on this password subset.</li>
<li><a href="http://hexale.blogspot.com/2009/10/list-of-addresses-for-pass-hash-toolkit.html">List of addresses for the Pass-the-Hash toolkit -a switch</a> &#8211; hexale.blogspot.com<br />
A list of addresses for different versions of lsasrv.dll</li>
<li><a href="http://msinfluentials.com/blogs/jesper/archive/2009/10/20/how-delegation-privileges-are-represented-in-active-directory.aspx">How delegation privileges are represented in Active Directory</a> &#8211; msinfluentials.com<br />
Delegation rights are represented in the userAccountControl flag on the account object in AD, whether a user or a computer account.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=7420">Cyber Security Awareness Month &#8211; Day 21 &#8211; Port 135</a> &#8211; isc.sans.org<br />
When a host wants to connect to a RPC service on a remote machine,it firsts checks with the destination machine on port 135, to know which port is being used by the service it wants to connect into.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=7435">Cyber Security Awareness Month &#8211; Day 23 port 179 TCP &#8211; Border Gateway Protocol</a> &#8211; isc.sans.org<br />
There are two major concerns about the security of BGP &#8211; router table corruption and blindly resetting BGP sessions.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=7447">Cyber Security Awareness Month &#8211; Day 24 &#8211; The Small Services</a> &#8211; isc.sans.org<br />
Some discussion on ports below 20, also called &#8216;small services&#8217;</li>
<li><a href="http://labs.neohapsis.com/2009/10/21/hacker-halted-2009/">Hacker Halted 2009</a> &#8211; neohapsis.com<br />
A couple of hackers discussed a distributed password cracker they designed and implemented that utilizes redirected browsers to build a swarm of worker nodes.</li>
<li><a href="http://hexale.blogspot.com/2009/10/how-to-decrypt-coldfusion-v6-datasource.html">How to decrypt Coldfusion v6 datasource passwords</a> &#8211; hexale.blogspot.com<br />
A blogger writes a quick perl script to decrypt DataSource passwords using TwoFish encryption.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/389">Metasploit JSP Shells</a> &#8211; carnal0wnage.attackresearch.com<br />
Stephen Fewer has pushed up a jsp reverse and jsp bind shell.</li>
<li><a href="http://rdist.root.org/2009/10/23/just-another-day-at-the-office/">Just another day at the office</a> &#8211; root.org<br />
A common day at Root Labs</li>
<li><a href="http://www.projectshellcode.com/?q=node/29">Shellcode Tutorial 9: Generating Shellcode using Metasploit</a> &#8211; projectshellcode.com<br />
This tutorial is an introduction into using the Metasploit Framework to generate shellcode.</li>
<li><a href="http://blog.tenablesecurity.com/2009/10/using-nessus-to-audit-microsoft-patches.html">Using Nessus to audit Microsoft Patches</a> &#8211; tenablesecurity.com<br />
Nessus has several features, including credentialed scanning and plugins, that list missing patches and can assist in the patch verification process.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://blogs.zdnet.com/security/?p=4702">Gaping security hole in Time Warner cable routers</a> &#8211; zdnet.com<br />
A security hole in cable modems from Time Warner/Road Runner customers could potentially lead to private network access.</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/">WordPress 2.8.5: Hardening Release</a> &#8211; wordpress.org<br />
A number of security hardening changes were identified that were worth back-porting to the 2.8 branch</li>
<li><a href="http://www.h-online.com/security/news/item/VMware-patches-vulnerabilities-in-its-products-834855.html">VMware patches vulnerabilities in its products</a> &#8211; h-online.com<br />
The security announcement lists a total of 48 CVE entries which can be exploited to carry out denial-of-service (DoS) attacks or to compromise systems if left unpatched.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://voices.washingtonpost.com/securityfix/2009/10/president_obama_on_cyber_secur.html">President Obama on Cyber Security Awareness</a> &#8211; washingtonpost.com<br />
A short video from the US President discussing this important issue.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=7411&amp;rss">WASC 2008 Statistics</a> &#8211; webappsec.org<br />
A pool of website vulnerability data to get a better grasp on the web app vulnerability landscape.</li>
<li><a href="http://voices.washingtonpost.com/securityfix/2009/10/e-banking_on_a_locked_down_pc.html?wprss=securityfix">E-banking on a locked down PC, Part II</a> &#8211; washingtonpost.com<br />
A reaction to reader comments on switching to another OS other than Windows for banking online</li>
<li>Metasploit goes commercial, sells to Rapid7<br />
HD Moore joins Rapid7, presaging a commercial version of the popular pentesting tool.</p>
<ul>
<li><a href="http://blog.metasploit.com/2009/10/metasploit-rising.html">Metasploit Rising</a> &#8211; metasploit.com</li>
<li><a href="http://www.rapid7.com/metasploit-announcement.jsp">Metasploit Announcement</a> &#8211; rapid7.com</li>
<li><a href="http://blog.metasploit.com/2009/10/joining-team.html">Joining the Team</a> &#8211; metasploit.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=4708">Metasploit + Rapid7 shakes up pen-test landscape</a> &#8211; zdnet.com</li>
<li><a href="http://www.darkoperator.com/blog/2009/10/22/opinions-of-a-contributor-to-metasploit-about-the-sale-to-ra.html">Opinions of a contributor to Metasploit about the sale to Rapid7</a> &#8211; darkoperator.com</li>
</ul>
</li>
<li><a href="http://threatpost.com/en_us/blogs/apathy-creeps-cybersecurity-czar-search-drags-102109">Apathy Creeps In as Cybersecurity Czar Search Drags On</a> &#8211; threatpost.com?<br />
With five months gone since Obama&#8217;s announcement, all the optimism has been replaced by a lot of shrugging.</li>
<li><a href="http://praetorianprefect.com/archives/2009/10/dhs-responds-to-us/">DHS responds to us</a> &#8211; praetorianprefect.com<br />
The address featured the ability to ask questions of the Secretary; we sent one in and Secretary Napolitano answered it.</li>
<li><a href="http://www.wired.com/threatlevel/2009/10/vulnerable-devices/">Scan of Internet Uncovers Thousands of Vulnerable Embedded Devices</a> &#8211; wired.com<br />
Researchers scanning the internet have found nearly 21,000 routers, webcams and VoIP products open to remote attack.</li>
<li><a href="http://threatpost.com/en_us/blogs/cyberterror-not-credible-threat-102309">Report: Cyberterror Not a Credible Threat</a> &#8211; threatpost.com<br />
A new report by a Washington policy think tank dismisses the idea that terrorist groups are currently launching cyber attacks.</li>
<li>Whitehouse.gov switches to Drupal<br />
The open source CMS platform is now the backbone of the White House&#8217;s public website.</p>
<ul>
<li><a href="http://techpresident.com/blog-entry/whitehousegov-goes-drupal">WhiteHouse.gov Goes Drupal [Updated]</a> &#8211; techpresident.com</li>
<li><a href="http://ha.ckers.org/blog/20091025/whitehouse-drupal-and-the-open-source-security-model/">Whitehouse Drupal and The Open Source Security Model</a> &#8211; ha.ckers.org<br />
Some commentary on the recent switch</li>
</ul>
</li>
</ul>
</div>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=359&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2009/10/26/week-43-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 41 in Review &#8211; 2009</title>
		<link>http://infosecevents.net/2009/10/12/week-41-in-review/</link>
		<comments>http://infosecevents.net/2009/10/12/week-41-in-review/#comments</comments>
		<pubDate>Tue, 13 Oct 2009 06:33:10 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=416</guid>
		<description><![CDATA[Events Related: FRHACK01 copy of presentations &#8211; professionalsecuritytesters.org A list of the slides from the recent French conference Things I Learned at SecTor 2009 &#8211; preachsecurity.blogspot.com SecTor 2009 thoughts and insights SecTor 2009 Wrapup &#8211; spywareguide.com My Sector &#8217;09 Experience &#8211; anti-virus-rants.blogspot.com Resources: All about Website Password Policies &#8211; jeremiahgrossman.blogspot.com Some simple guidelines when implementing [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1068">FRHACK01 copy of presentations</a> &#8211; professionalsecuritytesters.org<br />
A list of the slides from the recent French conference</li>
<li><a href="http://preachsecurity.blogspot.com/2009/10/things-i-learned-at-sector-2009.html">Things I Learned at SecTor 2009</a> &#8211; preachsecurity.blogspot.com</li>
<li>SecTor 2009 thoughts and insights
<ul>
<li><a href="http://blog.spywareguide.com/2009/10/sector-2009-wrapup.html">SecTor 2009 Wrapup</a> &#8211; spywareguide.com</li>
<li><a href="http://anti-virus-rants.blogspot.com/2009/10/my-sector-09-experience.html">My Sector &#8217;09 Experience</a> &#8211; anti-virus-rants.blogspot.com</li>
</ul>
</li>
</ul>
</div>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://jeremiahgrossman.blogspot.com/2009/10/all-about-website-password-policies.html">All about Website Password Policies</a> &#8211; jeremiahgrossman.blogspot.com<br />
Some simple guidelines when implementing password protection in a site.</li>
<li><a href="http://projects.webappsec.org/Web-Application-Security-Scanner-Evaluation-Criteria">Web Application Security Scanner Evaluation Criteria v1.0</a> &#8211; webappsec.org<br />
WASSEC is a set of guidelines to evaluate web application scanners on their ability to effectively test web applications and identify vulnerabilities.</li>
</ul>
<div>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://vipervast.sourceforge.net/">VIPER Lab&#8217;s VAST Live Distro for VOIP security assessment</a> &#8211; vipervast.sourceforge.net<br />
The distro includes VoIP security assessment tools such as UCsniff, VoipHopper, and more.</li>
<li><a href="http://sfdumper.sourceforge.net/">SFDumper 2.1 has been released</a> &#8211; sfdumper.sourceforge.net<br />
This is an Open Source free computer forensics useful tool written in Bash Script for Linux systems.</li>
<li><a href="http://dvwa.co.uk/blog/?p=260">DVWA v1.0.6</a> &#8211; dvwa.co.uk<br />
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable.</li>
<li><a href="http://codecrawler.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33132">Code Crawler 2.4 Beta Release</a> &#8211; codecrawler.codeplex.com<br />
A tool aimed at assisting code review practitioners.</li>
<li><a href="http://rochakchauhan.com/blog/2008/01/10/top-15-free-sql-injection-scanners/">Top 15 free SQL Injection Scanners</a> &#8211; rochakchauhan.com<br />
A list of free SQL Injection Scanners that will be of value to both web application developers and professional security auditors.</li>
<li><a href="http://www.mavitunasecurity.com/blog/final-beta/">Netsparker &#8211; The Final Beta!</a> &#8211; mavitunasecurity.com<br />
The latest and final beta build bakes in better performance, improved engines, among others.</li>
<li><a href="http://metasm.cr0.org/">Metasm &#8211; Assembly Manipulation Suite</a> &#8211; metasm.cr0.org<br />
Metasm is a cross-architecture assembler, disassembler, compiler, linker and debugger.</li>
<li><a href="http://www.xmcopartners.com/ima/">IMA Project : Identity Management Auditor Project</a> &#8211; xmcopartners.com/ima<br />
IMA provides a simple way to audit Identity Management, is composed of several dedicated modules.</li>
<li><a href="http://releases.portswigger.net/2009/10/v1217.html">Burp v1.2.17</a> &#8211; portswigger.net<br />
Burp Scanner now allows reporting of issues in XML format, to enable easy integration with other tools.</li>
<li><a href="http://sqlmap.sourceforge.net/#news">sqlmap v0.8</a> &#8211; sqlmap.sourceforge.net<br />
Sqlmap is an open source command-line automatic SQL injection tool.</li>
<li><a href="http://www.charlesproxy.com/">Charles Proxy v3.4</a> &#8211; charlesproxy.com<br />
Charles is an HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view traffic between their machine and the Internet.</li>
<li><a href="http://www.open-scap.org/">OpenSCAP v0.5.3</a> &#8211; open-scap.org<br />
It is the goal of OpenSCAP to provide a simple, easy to use set of interfaces to serve as the framework for community use of SCAP</li>
<li><a href="http://sourceforge.net/projects/sslscan/">SSLScan &#8211; Fast SSL Scanner</a> &#8211; sourceforge.net/projects/sslscan/<br />
SSLScan queries SSL services, such as HTTPS, in order to determine the ciphers that are supported.</li>
<li><a href="http://wald.intevation.org/frs/shownotes.php?release_id=327">OpenVAS 3.0 Beta</a> &#8211; wald.intevation.org<br />
OpenVAS 3.0 introduces a new architecture where openvas-libraries is now mandatory dependency for openvas-client.</li>
<li><a href="http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/">Windd 1.3 Final! (x86 and x64)</a> &#8211; msuiche.net<br />
Windd is a free Windows utility which aims at being used as a swiss-knife to acquire physical memory.</li>
</ul>
</div>
<div>
<div>
<div>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://blog.red-database-security.com/2009/10/06/oracle-password-benchmarks/">Oracle Password Benchmarks</a> &#8211; red-database-security.com<br />
Dennis Yurichev has published details about his FPGA based Oracle (DES) password cracker.</li>
<li><a href="http://www.petefinnigan.com/weblog/archives/00001270.htm">Oracle Security Worst Practices</a> &#8211; petefinnigan.com<br />
Pete talks about how to audit for future security issues and bad practices.</li>
<li><a href="http://blog.coresecurity.com/2009/10/06/real-world-stories-how-pen-testing-compliments-vulnerability-scanning/">Real World Stories: How Pen Tests Complement Vulnerability Scans</a> &#8211; coresecurity.com<br />
Vulnerability scans when used in cooperation with penetration tests become significantly more useful in calibrating issues of risk.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/384">Creating wordlists with JTR</a> &#8211; carnal0wnage.attackresearch.com<br />
Some research on creating a word list for password brute forcing</li>
<li><a href="http://blog.metasploit.com/2009/10/smb2-351-packets-from-trampoline.html">SMB2: 351 Packets from the Trampoline</a> &#8211; metasploit.com<br />
Some code related to Trampoline and SMB 2.0</li>
<li><a href="http://www.petefinnigan.com/weblog/archives/00001269.htm">60 million password hashes/second Oracle password cracker available</a> &#8211; petefinnigan.com<br />
Dennis Yurichev has finally finished up his cracker and has added a web based front end to the hardware that is accessible from his website.</li>
<li><a href="http://www.disenchant.ch/blog/teaching-john-the-ripper-how-to-crack-md5-hashes-and-more/277">Teaching John The Ripper how to Crack MD5 Hashes and more</a> &#8211; disenchant.ch<br />
A fix to the guide on how to use John the Ripper for cracking hashes</li>
<li><a href="http://perpetualhorizon.blogspot.com/2009/10/penetration-testing-targeted-malware.html">Penetration testing, targeted malware attacks and the future</a> &#8211; perpetualhorizon.blogspot.com<br />
Some thoughts on pentesting and malware</li>
<li><a href="http://isc.sans.org/diary.html?storyid=7303">Cyber Security Awareness Month &#8211; Day 9 &#8211; Port 3389/tcp (RDP)</a> &#8211; isc.sans.org<br />
Microsoft&#8217;s RDP and its associated &#8220;terminal service&#8221; client and server apps have been widely used since Windows 2000 days for Windows server administration.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=7324">Cyber Security Awareness Month &#8211; Day 11 &#8211; RPCBind aka Portmapper</a> &#8211; isc.sans.org<br />
A review on port scanners and how to secure open ports.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=7327">Cyber Security Awareness Month &#8211; Day 12 Ports 161/162 Simple Network Management Protocol (SNMP)</a> &#8211; isc.sans.org<br />
SNMP is used to monitor network connected devices.</li>
<li><a href="http://www.radajo.com/2009/10/sqlninja-metasploit-demo.html">Sqlninja &amp; Metasploit Demo</a> &#8211; radajo.com<br />
A pentesting demo to be presented during a course lesson in London</li>
<li><a href="http://www.room362.com/blog/2009/10/10/burp-tip-of-the-day-nikto-db-import.html">Burp Tip of the Day &#8211; Nikto DB Import</a> &#8211; room362.com<br />
An export of the list of checks to a text file so that they could be used over and over in Intruder.</li>
<li><a href="http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html">Evil Maid goes after TrueCrypt!</a> &#8211; theinvisiblethings.blogspot.com<br />
The whole infection process takes about 1 minute, and it’s well suited to be used by hotel maids.</li>
</ul>
</div>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Adobe&#8217;s recent PDF flaw<br />
Another flaw has risen on Adobe&#8217;s flagship reader</p>
<ul>
<li><a href="http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html">Adobe Reader and Acrobat issue</a> &#8211; adobe.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=4568">New Adobe PDF flaw under attack; Patch coming Tuesday</a> &#8211; zdnet.com</li>
</ul>
</li>
</ul>
</div>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.computerworld.com/s/article/9139155/Microsoft_plans_monster_Patch_Tuesday_next_week">Microsoft plans monster Patch Tuesday next week</a> &#8211; computerworld.com<br />
Unlucky 13 sets record as biggest-ever patch day, includes first-ever for Windows 7 RTM.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>Hotmail passwords revealed online<br />
Over 10,000 email accounts have been posted online</p>
<ul>
<li><a href="http://news.bbc.co.uk/2/hi/technology/8291268.stm">Phishing attack targets Hotmail</a> &#8211; bbc.co.uk</li>
<li><a href="http://www.h-online.com/security/news/item/Up-to-20-000-Windows-Live-Hotmail-account-details-leaked-online-814299.html">Up to 20,000+ Windows Live Hotmail account details leaked online</a> &#8211; h-online.com</li>
<li><a href="http://news.cnet.com/8301-27080_3-10371499-245.html">Phished or not, leaked passwords show lazy habits</a> &#8211; cnet.com</li>
<li><a href="http://blogs.zdnet.com/security/?p=4538">Weak passwords dominate statistics for Hotmail&#8217;s phishing scheme leak</a> &#8211; zdnet.com</li>
<li><a href="http://www.neowin.net/news/main/09/10/06/the-anatomy-of-a-hotmail-phishing-attack">The anatomy of a Hotmail phishing attack</a> &#8211; neowin.net</li>
<li><a href="http://reusablesec.blogspot.com/2009/10/10k-hotmail-passwords.html">10k Hotmail Passwords</a> &#8211; reusablesec.blogspot.com</li>
<li><a href="http://reusablesec.blogspot.com/2009/10/analysis-of-hotmail-passwords-by-other.html">Analysis of Hotmail Passwords by Other People</a> &#8211; reusablesec.blogspot.com</li>
</ul>
</li>
<li><a href="http://www.telegraph.co.uk/news/newstopics/politics/defence/6261756/MoD-how-to-stop-leaks-document-is-leaked.html">MoD &#8216;how to stop leaks&#8217; document is leaked</a> &#8211; telegraph.co.uk<br />
The 2,400-page restricted document has found its way on to Wikileaks</li>
<li>Paypal evicts hacker for selling hacking tools<br />
PayPal suspended the account of a white-hat hacker on Tuesday after someone used his research to publish a counterfeit certificate.</p>
<ul>
<li><a href="http://www.wired.com/threatlevel/2009/10/marlinspike/">PayPal Suspends Researcher’s Account for Distributing Hacking Tools</a> &#8211; wired.com</li>
<li><a href="http://www.theregister.co.uk/2009/10/06/paypal_banishes_ssl_hacker/">Man banished from PayPal for showing how to hack PayPal</a> &#8211; theregister.co.uk</li>
</ul>
</li>
<li><a href="http://blogs.hackerscenter.com/2009/10/nist-maps-out-emerging-field-of-it.html">NIST maps out the emerging field of IT metrology</a> &#8211; hackerscenter.com<br />
Are meaningful security metrics even achievable?</li>
<li><a href="http://blogs.hackerscenter.com/2009/10/avert-labs-paper-inside-password.html">Avert Labs Paper: Inside the Password Stealing Business:the Who and How of Identity Theft</a> &#8211; hackerscenter.com<br />
The report uncovers technical details on the capabilities, level of sophistication, and inner workings of the most infamous contemporary password-stealing malware families.</li>
<li><a href="http://www.mirror.co.uk/news/top-stories/2009/09/27/conputer-meltdown-115875-21703149/">Jail chaos as lag hacker is left in charge of computer system</a> &#8211; mirror.co.uk<br />
A jailed hacker shut down a prison&#8217;s entire computer system &#8211; after bosses gave him the job of programming it.</li>
<li><a href="http://www.net-security.org/article.php?id=1314">Q&amp;A: Worldwide surveillance and filtering</a> &#8211; net-security.org<br />
In this interview, Rafal Rohozinski discusses international surveillance and filtering issues.</li>
<li><a href="http://www.internetnews.com/security/article.php/3842751/Hackers+Target+Xbox+Live.htm">Hackers Target Xbox Live</a> &#8211; internetnews.com<br />
Network security issues are now popping up for game console owners.</li>
<li><a href="http://www.itpro.co.uk/616069/the-fbi-cracks-the-largest-phishing-case-ever">Some 100 people face 20 years in jail following a two-year investigation by the FBI.</a> &#8211; itpro.co.uk<br />
US and Egyptian authorities have charged 100 people in “the largest international phishing case ever conducted”.</li>
<li><a href="http://voices.washingtonpost.com/securityfix/2009/10/fbi_director_on_internet_banki.html">Phishing Scam Spooked FBI Director Off E-Banking</a> &#8211; washingtonpost.com<br />
Not long ago, the head one of our nation&#8217;s domestic agencies received an e-mail purporting to be from his bank.</li>
<li><a href="http://gizmodo.com/5377583/3-million-in-click-fraud-over-two-weeks-just-the-beginning">$3 Million In Click Fraud Over Two Weeks? Just The Beginning</a> &#8211; gizmodo.com<br />
A recently disbanded click fraud ring in China racked up $3 million worth of clicks in two weeks.</li>
<li><a href="http://www.itworld.com/internet/80445/wikileaks-plans-make-web-a-leakier-place">Wikileaks plans to make the Web a leakier place</a> &#8211; itworld.com<br />
The new upload system will give potential whistleblowers around the world the ability to leak sensitive documents to an organization or journalist they trust over a secure connection.</li>
</ul>
</div>
</div>
</div>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=416&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2009/10/12/week-41-in-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

