<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Infosec Events &#187; Vendor News</title>
	<atom:link href="http://infosecevents.net/category/vendor-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecevents.net</link>
	<description>Covering the Information Security Economy</description>
	<lastBuildDate>Mon, 21 May 2012 05:28:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Week 19 In Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/05/16/week-19-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/05/16/week-19-in-review-2011/#comments</comments>
		<pubDate>Mon, 16 May 2011 18:40:58 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[Club Hack]]></category>
		<category><![CDATA[Hakin9 magazine]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1668</guid>
		<description><![CDATA[Resources Hakin9 Magazine Cloud Security Issue &#8211; mytalkoot.com Comprehensive cloud-centric resources and articles now available for download. Club Hack Magazine May Issue On browser Security &#8211; professionalsecuritytesters.org Here we are again with the latest issue of ClubHack Magazine. This time also the issue is dedicated to Browser security. Hacking Illustrated &#8211; irongeek.com In this section [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Resources</strong></p>
<ul>
<li><a href="http://mytalkoot.com/12all/lt.php?c=1324&amp;m=813&amp;nl=9&amp;s=9d0e4bfe38aa8227a38977fb6919e4a5&amp;lid=40722&amp;l=-http--hakin9.org/category/magazine/">Hakin9 Magazine Cloud Security Issue</a> &#8211; mytalkoot.com<br />
Comprehensive cloud-centric resources and articles now available for download.</li>
<li><a href="http://chmag.in/issue/may2011.pdf">Club Hack Magazine May Issue On browser Security</a> &#8211; professionalsecuritytesters.org<br />
Here we are again with the latest issue of ClubHack Magazine. This time also the issue is dedicated to Browser security.</li>
<li><a href="http://www.irongeek.com/i.php?page=security%2Fhackingillustrated&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+IrongeeksSecuritySite+%28Irongeek%27s+Security+Site%29">Hacking Illustrated</a> &#8211; irongeek.com<br />
In this section I&#8217;ll be posting AVIs and Flash files that show step by step how to execute various pen-testing tools. Since most of these videos are 640&#215;480 it would be best if you use a screen resolution that is 1024&#215;768 or better. If you have any requests or comments please let me know.</li>
<li><a href="http://www.felipemartins.info/2011/05/pentesting-vulnerable-study-frameworks-complete-list/?utm_source=twitterfeed&amp;utm_medium=twitter">Pentesting Vulnerable Study Frameworks Complete List</a> &#8211; felipemartins.info<br />
It’s very difficult for the beginner security analyst, mainly the ones  interested in the area of pentesting, to find good study pentesting  resources. Starting from the principle that in pentesting there are many  other sub areas of study, it becomes more and more difficult to choose and then find a proper pentesting study application.</li>
<li><a href="http://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview">25 Questions To Ask During An Information Security Interview</a> &#8211; danielmiessler.com<br />
What follows is a list of questions for use in vetting candidates for  positions in Information Security. Many of the questions are designed to  get the candidate to think, and to articulate that thought process in a  scenario where preparation was not possible. Observing these types of  responses is often as important as the actual answers.</li>
<li><a href="http://arxiv.org/abs/1104.4843v1">Secuirty Through Amnesia: A Software-Based Solution to the Cold Boot Attack On Disk Encryption</a> &#8211; arvix.org<br />
Disk encryption has become an important security measure for a multitude of clients, including governments, corporations, activists, security-conscious professionals, and privacy-conscious individuals. Unfortunately, recent research has discovered an effective side channel attack against any disk mounted by a running machine\cite{princetonattack}.</li>
<li><a href="http://rdist.root.org/2011/05/09/encrypted-google-docs-done-well/">Encrypted Google Docs Done Well</a> &#8211; rdist.root.org<br />
There’s a nice new paper out called “Private Editing Using Untrusted Cloud Services” by Yan Huang and David Evans. They also provide a Firefox extension that implements their scheme. I like their approach for a few reasons.</li>
<li><a href="http://resources.infosecinstitute.com/haroon-meer/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+infosecResources+%28InfoSec+Resources%29">Haroon Meer Reveals His Process For Security Research</a> &#8211; resources.infosecinstitute.com<br />
In our ongoing series of interviews, this week Haroon Meer answered a  few questions and pulled back the curtain a bit on the methods, tools  and motivation for the work he does.</li>
<li><a href="http://resources.infosecinstitute.com/virtual-server-security/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+infosecResources+%28InfoSec+Resources%29">Microsoft Virtual Server Security: 10 Tips And Settings</a> &#8211; resources.infosecinstitute.com<br />
Virtualization brings significant value to business managers and  engineers attempting to keep pace with business pressure for additional  servers. It enables maximum use of hardware resources while introducing  an increased flexibility in how organizations design and implement new  solutions. However, it also introduces new security concerns.</li>
<li><a href="http://www.cisco.com/en/US/prod/collateral/vpndevc/cisco_global_threat_report_1Q2011.pdf">Cisco 1Q11 Global Threat Report</a> &#8211; cisco.com/en/US/<br />
The Cisco 1Q11 Global Threat Report has been released. The report covers the period from 1 January 2011 through 31 March 2011 and features data from Cisco Security Intelligence Operations. This quarter’s contributors includes Cisco Intrusion Prevention System (IPS), IronPort, Remote Management Services (RMS), Security Research and Operations (SR&amp;O), and ScanSafe.</li>
<li><a href="http://r00tsec.blogspot.com/2011/05/assembley-lanugage-for-penetration.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+r00tsecblog+%28Computer+Security+Blog%29">Assembly Language for Penetration Tester</a> &#8211; r00tsec.blogspot.com<br />
Below are the useful resources to learn Assembley Language for pentesters to start learning Exploit writing.</li>
<li><a href="http://www.scadahacker.com/igss-video.html">Quickdraw IDS in Action</a> &#8211; scada-hacker.com/igss-video.html<br />
Joel Langill of SCADAhacker.com has an excellent 18-minute video showing an example of an exploit of the IGSS SCADA HMI and then the Quickdraw IDS signatures. Most of the recently disclosed Luigi vulnerabilities resulted in denial of service, but the IGSS vulnerability he exploits in the video is a directory traversal file execution vulnerability.</li>
<li><a href="http://www.gnucitizen.org/blog/exploit-development-framework-design/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+gnucitizen+%28GNUCITIZEN%29">Exploit Development Framework Design</a> &#8211; gnucitizen.org<br />
Metasploit is great but there are three things that makes the framework sometimes inconvenient: it’s size, it’s dependency of the ruby platform and of course it’s speed. It will be great if for example we can take a single exploit (or a set of exploits) out of the framework and compile it into a standalone executable.</li>
<li><a href="https://www.immunityinc.com/infiltrate/presentations/Android_Attacks.odt.pdf">Beating Up On Android: Practical Android Attacks</a> &#8211; immunityinc.com/presentations/Android_Attacks.odt.pdf</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li>Backtrack 5<br />
The BackTrack Dev team has worked furiously in the past months on   BackTrack 5, code name “revolution”. Today, we are proud to release our   work to the public, and then rest for a couple of weeks.This new   revision has been built from scratch, and boasts several major   improvements over all our previous releases.</p>
<ul>
<li><a href="http://www.backtrack-linux.org/downloads/">Backtrack 5 Is Released Today!</a> &#8211; backtrack-linux.org</li>
<li><a href="http://www.infosecramblings.com/2011/05/14/backtrack-5-full-disk-encryption-how-to-published/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+InfosecRamblings+%28Infosec+Ramblings%29">Backtrack 5 full disk encryption how-to published</a> &#8211; infosecramblings.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://www.attackvector.org/files/ZeuS.tar.bz2">ZeuS source code anyone?</a> &#8211; attackvector.com/viles/ZeuS.tar.bz2<br />
If you’d like to take a look at the ZeuS/SpyEye botnet source code and  see how it ticks, you can download it below.  I’m not sure how long this  will be up (for obvious reasons), so get it while it’s hot.</li>
<li><a href="http://www.the-interweb.com/serendipity/index.php?/archives/137-Release-of-SWFRETools-1.1.0.html">Release of SWFRet Tools 1.1.0</a> &#8211; the-interweb.com<br />
Two weeks ago I gave a presentation at SOURCE Boston where I released a new collection of open-source tools for Adobe Flash SWF file reverse engineering. I am developing these tools, called SWFRETools, to help reverse engineers like vulnerability researchers and malware analysts that have to deal with SWF files regularly.</li>
<li><a href="http://www.darkoperator.com/blog/2011/5/10/virtualizing-junos-on-vmware.html">Virtualizing Junos On VMWare</a> &#8211; darkoperator.com<br />
Many times when working with a client network or working on our own we  have the need to test, document and validate certain networks  configurations in a test environment. Sadly not many have the money to  have one so as to test different scenarios so as to gage the impact that  this changes might have on the production network.</li>
<li><a href="http://code.google.com/p/skipfish/downloads/list">UPDATE: Skipfish-1.87b!</a> &#8211; code.google.com/p/skipfish/downloads/list<br />
Skipfish is a fully automated, active web application security reconnaissance tool. Its key features: High speed, Ease of use, Cutting-edge security logic.</li>
<li><a href="http://www.irongeek.com/i.php?page=security%2Fmutillidae-deliberately-vulnerable-php-owasp-top-10&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+IrongeeksSecuritySite+%28Irongeek%27s+Security+Site%29">Mutillidae: A Deliberately Vulnerable Set Of PHP Scripts That Implement The OWASP Top 10</a> &#8211; irongeek.com<br />
As I figure most people reading this know, I make infosec video  tutorials for my site Irongeek.com. I wanted  to start covering more web application pen-testing tools and concepts in some of  these videos. Of course, I needed a vulnerable web app or two to use for these  demos.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li>The Buby Script Crash Course<br />
For those of you who are new to Buby, it is a platform to write Ruby   based extensions for the Burp Suite API and I’m going to attempt to   cover some of the basics.</p>
<ul>
<li><a href="http://cktricky.blogspot.com/2011/05/buby-script-basics-part-1.html">Buby Script Basics Part 1</a> – cktricky.blogspot.com</li>
<li><a href="http://cktricky.blogspot.com/2011/05/buby-script-basics-part-2.html">Buby Script Basics Part 2</a> &#8211; cktricky.blogspot.com</li>
<li><a href="http://cktricky.blogspot.com/2011/05/buby-script-basics-part-3.html">Buby Script Basics Part 3</a> &#8211; cktricky.blogspot.com</li>
<li><a href="http://cktricky.blogspot.com/2011/05/buby-script-basics-part-4.html">Buby Script Basics Part 4</a> &#8211; cktricky.blogspot.com</li>
<li><a href="http://cktricky.blogspot.com/2011/05/buby-script-basics-part-5.html">Buby Script Basics Part 5</a> &#8211; cktricky.blogspot.com</li>
</ul>
</li>
<li><a href="http://blog.recurity-labs.com/archives/2011/05/12/druby_for_penetration_testers/index.html">dRuby For Penetration Testers</a> &#8211; blog.recurity-labs.com<br />
I like Ruby somehow, a nice and shiny programming language. At some  point last year, I decided to have a closer look at &#8216;Distributed Ruby&#8217;  (also called dRuby). dRuby is all about easily usable objects and method  invocations over the network.</li>
<li><a href="http://www.securityaegis.com/journey-into-exploitation-awbo2-exe/?">Journey Into Exploitation: Awbo2.exe</a> &#8211; securityaegis.com<br />
In this series of blog posts, I will be documenting my journey into the  art of exploitation.  My goal for this series is to experiment with some  of the challenges that are out there and hopefully provide some  guidance for others in my shoes.  I am targeting those of you with  moderate amount experience in exploitation.  Hopefully, I will further  my own knowledge and yours (the reader).</li>
<li><a href="http://intrepidusgroup.com/insight/2011/05/hijacking-nfc-intents-on-android/">Hijacking NFC Intents On Android</a> &#8211; intrepidusgroup.com<br />
Google IO had a “How to NFC” session today where they demoed and described using NFC on Android. One of the items they pointed out was the desire to use NFC for instant gratification and zero-click interactions. The only default application on the Nexus S that I’ve seen this in before today was Google Maps, but the desire is that other applications will incorporate this feature as well.</li>
<li><a href="https://github.com/Neohapsis/Keychain-Dumper">Keychain Dumper</a> &#8211; github.com/Neohapsis/Keychain-Dumper<br />
In order to build keychain_dumper you must first create two symbolic  links to the appropriate iOS SDK directories. At the time the tool was  developed the iOS 4.2 SDK was current and you may need to update the  target directories based on the current SDK that is installed.</li>
<li><a href="http://www.lovemytool.com/blog/2011/05/bittwiste-pcap-capture-file-editor-by-joke-snelders.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+lovemytool+%28LoveMyTool+-+Open+Community+for+Network+Management+and+Monitoring%29">Bittwiste: pcap Capture File Editor</a> &#8211; lovemytool.com<br />
In this article I will show you how to replace portnumbers, IP and MAC addresses.</li>
<li><a href="http://bittwist.sourceforge.net/">Bit-Twist</a> &#8211; bittwist.sourceforge.net<br />
Bit-Twist is a simple yet powerful libpcap-based Ethernet packet generator. It is designed to complement tcpdump, which by itself has done a great job at capturing network traffic.</li>
<li><a href="http://www.packetstan.com/2011/05/sorting-packet-captures-with-scapy.html">Sorting Packet Captures With Scapy</a> &#8211; packetstan.com<br />
Today I spent a little time looking into a packet capture supplied by Vivek Ramachandran at SecurityTube. This packet capture is part of a series of WiFi hacking challenges he is putting together, and immediately after opening it I got freaked out.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li>Adobe Flash Update<br />
Today, Adobe has released Flash Player 10.3, which includes several    important new privacy and security features for our customers.</p>
<ul>
<li><a href="http://blogs.adobe.com/flashplayer/2011/05/adobe-flash-player-10-3-for-desktop-and-android-devices-now-available-including-android-3-1-support.html">Advancing Flash Player Privacy and Security</a> &#8211; blogs.adobe.com</li>
<li><a href="http://krebsonsecurity.com/2011/05/critical-flash-player-update-plugs-11-holes/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29">Critical Flash Player Update Plugs 11 Holes</a> &#8211; kresonsecurity.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://isc.sans.edu/diary.html?storyid=10855&amp;rss">May 2011 Microsoft Black Tuesday Overview</a> &#8211; isc.sans.edu<br />
Chart breakdown of upcoming MS patch.</li>
</ul>
<p><strong>Vulnerabilities</strong></p>
<ul>
<li>The Skype Crisis<br />
Skype has been acquired by Microsoft few days ago and suddenly it   inherited Microsoft&#8217;s weakness&#8230; I &#8216;m just kidding, of course. As   many of you already know, a pretty big problem has been identified on   all Skype versions running on Mac OS X pltaforms.</p>
<ul>
<li><a href="http://marcoramilli.blogspot.com/2011/05/skype-vulnerability.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+blogspot%2FCqwP+%28Marco+Ramilli%27s+Blog%29">Skype Vulnerability</a> &#8211; marcoramilli.blogspot.com</li>
<li><a href="http://www.tgdaily.com/security-features/55823-skype-bug-lets-hackers-take-over-macs">Skype Bug Lets Hackers Take Over Macs</a> &#8211; tgdaily.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://blog.acrossecurity.com/2011/05/silently-pwning-protected-mode-ie9-and.html">Silently Pwning Protected-Mode IE9 And Innocent Windows Applications</a> &#8211; blog.acrosssecurity.com<br />
Those familiar with Windows COM servers know that they come in two types, in-process and out-of-process. For this post, the former type is of interest: an in-process COM server is a dynamic link library (DLL) that a COM client instantiates when needed, usually by calling the CoCreateInstance function with the class identifier (CLSID) of the said COM server.</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li>The SCADA Problem<br />
The U.S.&#8217;s Computer Emergency Response Team (CERT) issued a warning to    critical infrastructure firms on Wednesday about a serious security  hole   in products from Massachusetts firm Iconics that could leave  critical   systems vulnerable to remote attacks.</p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/serious-scada-security-flaw-affects-critical-infrastructure-firms-051211">Serious SCADA Security Flaw Affects Critical Infrastructure Firms</a> &#8211; threatpost.com</li>
<li><a href="http://www.veracode.com/blog/2011/05/buffer-overflows-in-scada-activex-controls-put-critical-infrastructure-at-risk/">Buffer Overflows In SCADA ActiveX Controls Put Critical Infrastructure At Risk</a> &#8211; veracode.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://www.scmagazine.com.au/News/257265,auscert-cisco-ip-phones-prone-to-hackers.aspx">AusCERT: Cisco IP phones prone to hackers</a> &#8211; scmagazine.com.au<br />
Contact centres and businesses using a popular make of internet phone  were at risk of having their communications intercepted and confidential  information leaked, a hacking group demonstrated.</li>
<li><a href="http://www.wired.com/threatlevel/2011/05/gps-gallery/?">FBI vehicle Tracking Device: the Teardown</a> &#8211; wired.com<br />
The FBI&#8217;s use of GPS vehicle tracking devices is becoming a contentious  privacy issue in the courts, with the Obama administration seeking  Supreme Court approval for its use of the devices without a warrant, and  a federal civil rights lawsuit targeting the Justice Department for  tracking the movements of an Arab-American student.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/453">Frameworks and how I hack currently (and how I don&#8217;t) </a>- carnal0wnage.attackresearch.com<br />
I got involved with HDM, skape, spoonm, et all and the metasploit project quite a long time ago, probably around msf 1ish time frame. It was an exciting time and metasploit was one of the best open source infosec (if not the best) projects out there.</li>
<li><a href="http://krebsonsecurity.com/2011/05/security-group-claims-to-have-subverted-google-chromes-sandbox/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29">Security Group Claims To Have Subverted Google Chrome&#8217;s Sandbox</a> &#8211; krebsonsecuirty.com<br />
A French security research firm boasted today that it has discovered a two-step process for defeating Google Chrome‘s sandbox, the security technology designed to protect the browser from being compromised by previously unknown security flaws.</li>
<li><a href="http://www.computerworld.com/s/article/9216438/Catch_a_clue_from_an_EDU_Universities_that_get_security_right?source=rss_security&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+computerworld%2Fs%2Ffeed%2Ftopic%2F82+%28Computerworld+Cybercrime+and+Hacking+News%29">Catch A Clue From An EDU: Universities That Get Security Right</a> &#8211; computerworld.com<br />
Professor Corey Schou was working in his  school&#8217;s library when he realized his computer was picking up a  particularly strong Wi-Fi signal.    Normally that would be welcome news. But Schou knew that spot was usually a dead zone, which meant something was probably amiss.</li>
<li><a href="http://blog.acrossecurity.com/2011/05/binary-planting-vs-dll-hijacking-vs.html">&#8220;Binary Planting&#8221; vs. &#8220;DLL Hijacking&#8221; vs. &#8220;Insecure Library Loading&#8221;</a> &#8211; blog.acrosssecurity.com<br />
When a new thing occurs or is invented, or when a previously obscure thing becomes popular, a need emerges to give it a name so we can talk and write about it. It was no different with binary planting, DLL hijacking, DLL preloading, insecure library loading, DLL load hijacking and DLL spoofing.</li>
<li><a href="http://www.darkreading.com/security/news/229500136/white-house-proposes-cybersecurity-bill.html">Whitehouse Proposes Cybersecurity Bill</a> &#8211; darkreading.com<br />
The White House today proposed new cybersecurity legislation that would  improve the protection of critical infrastructure, expand the sharing of  security data, and impose national requirements for disclosing  breaches.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1668&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/05/16/week-19-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 15 In Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/04/18/week-15-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/04/18/week-15-in-review-2011/#comments</comments>
		<pubDate>Tue, 19 Apr 2011 06:07:47 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[BSides]]></category>
		<category><![CDATA[ClubHack]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Hackito Ergo Sum]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1613</guid>
		<description><![CDATA[Events Related: OWASP threat modeling project &#8211; myappsecurity.blogspot.com We are starting an OWASP threat modeling project to standardize a threat modeling approach which can be used by various companies. Resources: Neil Daswani Reveals His Process for Security Research &#8211; resources.infosecinstitute.com In our ongoing series of interviews, this week Neil Daswani answered a few questions and [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://myappsecurity.blogspot.com/2011/04/owasp-threat-modeling-project.html">OWASP threat modeling project</a> &#8211; myappsecurity.blogspot.com<br />
We are starting an OWASP threat modeling project to standardize a threat modeling approach which can be used by various companies.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://resources.infosecinstitute.com/neil-daswani/">Neil Daswani Reveals His Process for Security Research</a> &#8211; resources.infosecinstitute.com<br />
In our ongoing series of interviews, this week Neil Daswani answered a few questions and pulled back the curtain a bit on the methods, tools and motivation for the work he does.</li>
<li><a href="http://www.ethicalhack3r.co.uk/security/ethical-hacking-degrees-the-good-the-bad-the-ugly/">Ethical Hacking Degrees – the good, the bad, the ugly</a> &#8211; ethicalhack3r.co.uk<br />
Ethical Hacking or Information Security or Computer Security or Network Security… are all included within titles of university level undergraduate degrees within the UK. No matter what they title their courses or whether or not you agree with the use of certain terms within their titles is irrelevant as they are all attempting to teach the same things.</li>
<li><a href="http://www.networkworld.com/community/blog/security-researchers-exploit-logic-flaws-shop">Security Researchers Exploit Logic Flaws to Shop for Free Online</a> &#8211; networkworld.com<br />
Security researchers from Indiana University Bloomington and Microsoft Research published a very interesting paper called How to Shop for Free Online.</li>
<li><a href="http://www.reddit.com/r/netsec/comments/go8i3/creating_an_assecureaspossible_laptop_ideas/">creating an as-secure-as-possible laptop &#8212; ideas?</a> &#8211; reddit.com<br />
I&#8217;m interested in creating a laptop (though a desktop would be fine, too) with a big emphasis on security. what types of treatments would reddit recommend?</li>
<li><a href="http://www.reddit.com/r/netsec/comments/gpaei/we_have_started_a_security_group_at_my_university/">We have started a security group at my University and we are trying to build up a database of tests, competitions, papers, etc</a> &#8211; reddit.com<br />
Any relevant links and content are welcome! We have a dozen of tests taken from previous competitions we attended this year, but we would like to get more if possible.</li>
<li><a href="http://www.cgisecurity.com/2011/03/nist-publishes-50kish-vulnerable-code-samples-in-javacc-is-officially-krad.html#">NIST publishes 50kish vulnerable code samples in Java/C/C++, is officially krad</a> &#8211; cgisecurity.com<br />
NIST has published a fantastic project (its been out since late December, but I only just became aware of it) where they&#8217;ve created vulnerable code test cases for much of MITRE&#8217;s CWE project in Java and c/c++.</li>
<li><a href="http://www.terminal23.net/2011/04/chubhack_15_available.html">ClubHack Issue 15</a> &#8211; terminal23.net<br />
New issue available.</li>
<li><a href="http://fismapedia.org/index.php?title=Main_Page">FISMApedia</a> &#8211; fismapedia.org<br />
FISMApedia is a collection of documents and discussions focused on Federal IT security. This site is a database of current guidance, laws and directives on how the Federal government secures its IT assets.</li>
<li><a href="http://www.securityaegis.com/burp-hacking-slides-bsides-chicago/">Burp Hacking Slides – Bsides Chicago</a> &#8211; securityaegis.com<br />
Download the padding oracle vuln plugin for forms authentication (thats a mouthful) from Joel’s site: beersec.org.</li>
<li><a href="http://www.slideshare.net/event/hackito-ergo-sum-2011/slideshows">Hackito Ergo Sum 2011 Presentation Dump &#8211; slideshare.net<br />
</a>A collection of everything from this security event</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://www.netresec.com/?page=Blog&amp;month=2011-04&amp;post=RawCap-sniffer-for-Windows-released">RawCap sniffer for Windows released</a> &#8211; netresec.com<br />
We are today proude to announce the release of RawCap, which is a free raw sockets sniffer for Windows.</li>
<li><a href="http://sourceforge.net/projects/spooftooph/">Spooftooph: The Bluetooth Spoofer</a> &#8211; sourceforge.net/projects/spooftooph/<br />
Spooftooph is designed to automate spoofing or cloning Bluetooth device information. Make a Bluetooth device hide in plain site.</li>
<li><a href="http://sourceforge.net/projects/sqlmap/">sqlmap 0.9</a> &#8211; sourceforge.net/projects/sqlmap/<br />
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers.</li>
<li><a href="http://hackxor.sourceforge.net/cgi-bin/index.pl">hackxor</a> &#8211; hackxor.sourceforge.net<br />
Hackxor is a webapp hacking game where players must locate and exploit vulnerabilities to progress through the story. Think WebGoat but with a plot and a focus on realism&amp;difficulty. Contains XSS, CSRF, SQLi, ReDoS, DOR, command injection, etc.</li>
<li><a href="http://www.mavitunasecurity.com/blog/svn-digger-better-lists-for-forced-browsing/">SVN Digger &#8211; Better Wordlists for Forced Browsing</a> &#8211; mavitunasecurity.com<br />
DirBuster ships with several wordlists, these wordlists generated via one big crawler which visited tons of websites, collected links and created most common directory / file names on the Internet.</li>
<li><a href="http://www.security-projects.com/?Patriot_NG">Patriot NG</a> &#8211; security-projects.com<br />
Patriot is a &#8216;Host IDS&#8217; tool which allows real time monitoring of changes in Windows systems or Network attacks.</li>
<li><a href="http://cvechecker.sourceforge.net/">CVE Checker 3.1</a> &#8211; cvechecker.sourceforge.net<br />
cvechecker reports about possible vulnerabilities on your system by scanning the installed software and matching the results with the CVE database.</li>
<li><a href="http://www.ollydbg.de/version2.html">OllyDbg 2.01 Alpha 3</a> &#8211; ollydbg.de<br />
OllyDbg is a 32-bit assembler level analysing debugger for Microsoft Windows. Emphasis on binary code analysis makes it particularly useful in cases where source is unavailable.</li>
<li><a href="http://threatpost.com/en_us/blogs/microsoft-pushes-out-two-new-security-tools-041211">Microsoft Pushes Out Two New Security Tools</a> &#8211; threatpost.com<br />
In parallel with its release of 17 bulletins on Patch Tuesday this month, Microsoft also unveiled two new tools that are meant to help make a couple of common exploitation scenarios more difficult for attackers.</li>
<li><a href="http://bailey.st/blog/smooth-sec/">smooth-sec</a> &#8211; bailey.st<br />
Smooth-Sec is a ready to-go  IDS/IPS (Intrusion Detection/Prevention System) linux distribution based on the multi threaded Suricata IDS/IPS engine and Snorby, the top notch web application for network security monitoring.</li>
<li><a href="https://code.google.com/p/bodgeit/">BodgeIt Store</a> &#8211; code.google.com/p/bodgeit/<br />
The BodgeIt Store is a vulnerable web application which is currently aimed at people who are new to penetration testing.</li>
<li><a href="http://qubes-os.org/Home.html">Qubes OS</a> &#8211; qubes-os.org<br />
Qubes is an open source operating system designed to provide strong security for desktop computing. Qubes is based on Xen, X Window System, and Linux, and can run most Linux applications and utilize most of the Linux drivers. In the future it might also run Windows apps.</li>
<li><a href="http://www.mcafee.com/us/downloads/free-tools/sharescan.aspx">McAfee ShareScan</a> &#8211; mcafee.com<br />
ShareScan is a free utility that enables IT security personnel to identify open Windows file shares available on the internal network. This tool can help administrators identify systems that have wide open permissions or no permissions — potential vulnerabilities that should be remediated.</li>
<li><a href="http://jessekornblum.livejournal.com/273084.html">md5deep version 3.8</a> &#8211; jessekornblum.livejournal.com<br />
This version adds two new features. First, you can now use a file to indicate the input files to process. For example, you can make a file, foo.txt.</li>
<li><a href="http://www.dueyesterday.net/system/files/openCVSS.py.txt">Common Vulnerability Scoring System Version 2 Calculator </a> &#8211; dueyesterday.net<br />
Allows for the creations of enums. Thanks to norvig.com/python-iaq.html</li>
<li><a href="http://bernardodamele.blogspot.com/2011/04/ms10-070-padding-oracle-applied-to-net.html">MS10-070: Padding Oracle applied to .NET framework</a> &#8211; bernardodamele.blogspot.com<br />
I followed the research closely and way before vulnerability scanners like Nessus could detect the security vulnerability on .NET applications anonymously and remotely, I coded a small script to test for the flaw based on Juliano Rizzo&#8217;s details. You might still find it useful, so I thought about publishing it on GitHub.</li>
<li><a href="http://blogs.technet.com/b/fdcc/archive/2011/04/14/iezoneanalyzer-v3.aspx">IEZoneAnalyzer v3</a> &#8211; technet.com<br />
IEZoneAnalyzer is a utility for viewing and comparing Internet Explorer security zone settings. It is particularly valuable on systems controlled through Group Policy, on which the standard security settings dialog does not allow viewing of settings.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://hmsec.tumblr.com/post/4519775665/full-disclosure-barracuda-networks-hacking-via-sql">Full Disclosure:Barracuda Networks Hacking via SQL Injection</a> &#8211; hmsec.tumblr.com/<br />
The company’s expansive product portfolio includes offerings for protection against email, Web and IM threats as well as products that improve application delivery and network access, message archiving, backup and data protection.</li>
<li><a href="http://www.darkoperator.com/blog/2011/4/11/parsing-cdp-packets-with-scapy.html">Parsing CDP Packets With Scapy</a> &#8211; darkoperator.com<br />
In this blog post I will cover how to use one of the new parsers  to parse CDP packets included in version 2.2 of scapy. Cisco Discovery Protocol (CDP) is a proprietary Layer 2 Data Link Layer network protocol used to share device information with devices connected on the same subnet.</li>
<li><a href="http://chmag.in/article/apr2011/mozilla-firefox-internals-attack-strategies">Mozilla Firefox Internals &amp; Attack Strategies</a> &#8211; chmag.in<br />
This paper aims to detail some of the techniques and methods that exist to subvert a fully patched and functioning browser Firefox.</li>
<li><a href="http://www.offensive-security.com/backtrack/backtrack-5-on-a-motorola-xoom/?utm_campaign=backtrack-5-on-a-motorola-xoom">BackTrack 5 on a Motorola Xoom</a> &#8211; offensive-security.com<br />
In the past few days we have been toying with some Motorola hardware, and have managed to get a basic build of BackTrack 5 (+ toolchain) on a Motorola Xoom.</li>
<li><a href="http://www.freedom-to-tinker.com/blog/dwallach/things-overheard-wifi-my-android-smartphone">Things overheard on the WiFi from my Android smartphone</a> &#8211; freedom-to-tinker.com<br />
Today in my undergraduate security class, we set up a sniffer so we could run Wireshark and Mallory to listen in on my Android smartphone. This blog piece summarizes what we found.</li>
<li><a href="http://bernardodamele.blogspot.com/2011/04/execute-metasploit-payloads-bypassing.html">Execute Metasploit payloads bypassing any anti-virus</a> &#8211; bernardodamele.blogspot.com<br />
Most of the shellcode launchers out there, including proof of concepts part of many security books, detail how to allocate a memory page as readable/writable/executable on POSIX systems, copy over your shellcode and execute it. This works just fine. However, it is limited to POSIX, does not necessarily consider 64-bit architecture and Windows systems.</li>
<li><a href="http://g0tmi1k.blogspot.com/2011/04/video-playing-with-traffic-squid.html">[Video] Playing With Traffic (Squid)</a> &#8211; g0tmi1k.blogspot.com<br />
The attacker installs Squid3 cache proxy via the Operating System (Backtrack 4 R2) repository. Squid is the “backbone” to this attack and after configuring it to work on the Local Area Network (LAN) and to be transparent (the proxy “works” without any configuration to the browser), the attacker chooses which script to first try out (asciiImages.pl is the first one) and adds it to the configuration file.</li>
<li><a href="http://intrepidusgroup.com/insight/2011/04/pulling-and-finding-apks-without-root-on-android/">Pulling and finding APKs without root on Android</a> &#8211; intrepidusgroup.com<br />
Since we’re not root, we can’t list the /data/app directory to locate the name of the APK file we want to pull. There’s a few ways you can tackle finding the name of the APK file, but what I find is the quickest way for me is to pull the packages.xml file.</li>
<li><a href="http://bernardodamele.blogspot.com/2011/04/reverse-connection-icmp-shell.html">Reverse connection: ICMP shell</a> &#8211; bernardodamele.blogspot.com<br />
Allowing traffic only onto known machines, ports and services (ingress filtering) and setting strong egress access control lists is one of these cases. In such scenarios when you have owned a machine part of the internal network or the DMZ (e.g. in a Citrix breakout engagement or similar), it is not always trivial to get a reverse shell over TCP, not to consider a bind shell.</li>
<li><a href="http://blog.eset.com/2011/04/15/kb2506014-kills-tdl4-on-x64">KB2506014 kills TDL4 on x64</a> &#8211; eset.com<br />
Not so long ago, Microsoft released a security patch addressing the way Windows x64 operating systems check integrity of the loaded modules. In our recent report (The Evolution of TDL4: Conquering x64) we described a method used by the TDL4 bootkit to load its malicious unsigned driver on 64-bit systems, even though those systems have an enforced kernel-mode code signing policy.</li>
<li><a href="http://www.ragestorm.net/blogs/?p=336">Uh Ah! I Happened To Use POP ESP</a> &#8211; ragestorm.net<br />
I had to call a C++ function from my Assembly code and keep the return value untouched so the caller will get it. Usually return values are passed on EAX, in x86 that is. But that’s not the whole truth, they might be passed on EDX:EAX, if you want to return 64 bits integer, for instance.</li>
<li><a href="http://rdist.root.org/2011/04/15/more-certs-may-indicate-less-security/">More certs may indicate less security</a> &#8211; rdist.root.org<br />
If a website has a multiple servers with different certs, the browser may often generate spurious errors for that site. But could this be a symptom of a genuine security problem?</li>
<li><a href="http://r00tsec.blogspot.com/2011/04/filejacking-how-to-make-file-server.html">Filejacking: How to make a file server from your browser (with HTML5 of course)</a> &#8211; r00tsec.blogspot.com<br />
How can a website access user&#8217;s files? Traditionally, user has to upload the file. Users commonly share photos, videos upload their files for online conversion tools etc. You could (theoretically) be tricked into uploading a sensitive file into a malicious website (&#8220;please submit your private key for checking it&#8217;s strength&#8221;), but, seriously, who falls for that?</li>
<li><a href="http://www.zonbi.org/archives/541">Proxmark3/RFID Goodness</a> &#8211; zonbi.org<br />
There are two “types” of RFID in common use. High frequency runs at the 13.56MHz range. The MiFare stuff is in this range, although it’s slightly different to the ISO14443 A and B standard used in the CSC stuff floating around ie. $train card.</li>
<li><a href="http://beersec.org/">Padding Oracle Post-Explotation: Abusing ASP.NET Forms Authentication with Burp</a> &#8211; beersec.org<br />
So you found an web site vulnerable to the ASP.NET Padding Vulnerability, used Minded Security&#8217;s web.config bruter and now you have the applications web.config file. Now what?</li>
<li><a href="http://r00tsec.blogspot.com/2011/04/payload-bypass-av-with-encoding.html">Payload bypass AV. with encoding</a> &#8211; r00tsec.blogspot.com<br />
This script and the relevant project files (Makefile and Visual Studio files) allow you to compile the tool once then run your shellcode across different architectures and operating systems.</li>
</ul>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Another day, another Flash 0-day attack<br />
Hackers are embedding malicious Flash Player files in Microsoft Word documents to launch targeted attacks against select businesses, according to a warning from Adobe.</p>
<ul>
<li><a href="http://www.zdnet.com/blog/security/adobe-warns-of-new-flash-player-zero-day-attack/8524">Adobe warns of new Flash Player zero-day attack</a> &#8211; zdnet.com</li>
<li><a href="http://www.computerworld.com/s/article/9215721/Adobe_confirms_critical_Flash_zero_day_bug">Adobe confirms critical Flash zero-day bug</a> &#8211; computerworld.com</li>
<li><a href="http://krebsonsecurity.com/2011/04/time-to-patch-your-flash/">Time to Patch Your Flash</a> &#8211; krebsonsecurity.com</li>
</ul>
</li>
<li><a href="http://blogs.technet.com/b/mmpc/archive/2011/04/13/msrt-april-11-win32-afcore.aspx">MSRT April ‘11: Win32/Afcore</a> &#8211; technet.com<br />
Win32/Afcore comprises two components, a dropper and installed malware that runs as a backdoor. The backdoor component is injected into running processes and connects to a remote server to retrieve commands that are executed on the affected system. Commands could include instructions to steal passwords, attack other computers and so on.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Patch Tuesday!<br />
Microsoft has released its April Patch Tuesday fixes, a large group of patches that includes updates for several critical holes in Internet Explorer as well as a patch that finally fixes the SMB client bug that disclosed publicly in February.</p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/april-patch-tuesday-fixes-critical-ie-smb-bugs-041211">April Patch Tuesday Fixes Critical IE, SMB Bugs</a> &#8211; threatpost.com</li>
<li><a href="http://nakedsecurity.sophos.com/2011/04/12/april-2011-ms-patch-tuesday-17-patches-64-vulnerabilities/">April 2011 MS Patch Tuesday &#8211; 17 patches, 64 vulnerabilities</a> &#8211; nakedsecurity.sophos.com</li>
<li><a href="http://www.symantec.com/connect/de/blogs/microsoft-patch-tuesday-april-2011">Microsoft Patch Tuesday &#8211; April 2011</a> &#8211; symantec.com</li>
</ul>
</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://krebsonsecurity.com/2011/04/atm-skimmers-hacking-the-cash-machine/">ATM Skimmers: Hacking the Cash Machine</a> &#8211; krebsonsecurity.com<br />
Most of the ATM skimmers I’ve profiled in this blog are comprised of parts designed to mimic and to fit on top of existing cash machine components, such as card acceptance slots or PIN pads. But sometimes, skimmer thieves find success by swapping out ATM parts with compromised look-alikes.</li>
<li>SSL Issues: Solutions, Opinions and News<br />
What lies ahead for SSL? The recent Comodo hack taught us that what we thought was a robust security protocol is nothing but a house of cards.</p>
<ul>
<li><a href="http://www.theregister.co.uk/2011/04/11/state_of_ssl_analysis/">How is SSL hopelessly broken? Let us count the ways</a> &#8211; theregister.co.uk</li>
<li><a href="http://www.terminal23.net/2011/04/ssl_certs_just_enough_security.html">ssl certs: just enough security?</a> &#8211; terminal23.net</li>
<li><a href="http://blog.thoughtcrime.org/ssl-and-the-future-of-authenticity">SSL And The Future Of Authenticity</a> &#8211; blog.thoughtcrime.org</li>
</ul>
</li>
<li><a href="http://www.h-online.com/security/news/item/Apple-s-AirTunes-AirPlay-private-key-extracted-and-published-1225337.html">Apple&#8217;s AirTunes/AirPlay private key extracted and published</a> &#8211; h-online.com<br />
Developer James Laird has extracted the AirTunes/AirPlay private key from an Apple Airport Express, opening the way for third-party applications to play back iTunes streams.</li>
<li><a href="http://blog.makezine.com/archive/2011/04/breaking-news-sonys-war-on-hackers-tinkerers-and-innovators-settlement-in-george-hotz-case.html">BREAKING NEWS: Sony’s War On Hackers, Tinkerers And Innovators “Settlement In George Hotz Case”</a> &#8211; blog.makezine.com<br />
Sony Computer Entertainment America (“SCEA”) and George Hotz (“Hotz”) today announced the settlement of the lawsuit filed by SCEA against Hotz in federal court in San Francisco, California. The parties reached an agreement in principle on March 31, 2011. As part of the settlement, Hotz consented to a permanent injunction.</li>
<li><a href="http://threatpost.com/en_us/blogs/how-phishers-will-use-epsilon-data-against-you-041211">How Phishers Will Use Epsilon Data Against You</a> &#8211; threatpost.com<br />
There has been a lot of online venting and hand-wringing in the week since customers of email services provider Epsilon began informing millions of individuals in North America and Europe that their name and e-mail address had  been stolen in a massive data breach.</li>
<li><a href="http://research.zscaler.com/2011/04/uspsgov-website-infected-with-blackhole.html">USPS.gov Website Infected with Blackhole Exploit Kit</a> &#8211; research.zscaler.com<br />
As we&#8217;ve discussed previously, the Blackhole Exploit kit, a commercial exploit kit developed by Russian hackers, is being seen in an increasing number of attacks.</li>
<li><a href="https://greyhat-security.com/milw0rm-and-inj3ct0r-merge-1337daycom">Milw0rm and inj3ct0r Merge Into 1337day.com</a> &#8211; greyhat-security.com<br />
Less than an hour ago, a message was sent out via the Milw0rm.com Facebook group, announcing both a merger for milw0rm.com and inj3ct0r.com, and simultaneously, a move for inj3ct0r.com into a new domain, 1337day.com.</li>
<li><a href="http://www.readwriteweb.com/enterprise/2011/04/government-agrees-with-microso.php">Government Agrees With Microsoft: Google Wasn&#8217;t Certified [Update]</a> &#8211; readwriteweb.com<br />
Today, the U.S. government agreed with <a href="http://www.readwriteweb.com/archives/microsoft_accuses_google_of_misleading_security_ce.php">Microsoft&#8217;s accusation</a> that Google had provided misleading information about whether or not its Google Apps for Government is certified under the Federal Information Security Management Act (FISMA).</li>
<li><a href="http://www.itworld.com/security/155773/doj-gets-court-permission-attack-botnet">DOJ gets court permission to attack botnet</a> &#8211; itworld.com<br />
The U.S. Department of Justice and U.S. Federal Bureau of Investigation have obtained a temporary restraining order allowing them to disrupt a computer virus that created an international botnet controlling more than 2.3 million computers as of early 2010, the DOJ announced Wednesday.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1613&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/04/18/week-15-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 14 In Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/04/11/week-14-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/04/11/week-14-in-review-2011/#comments</comments>
		<pubDate>Tue, 12 Apr 2011 04:13:47 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[CanSecWest]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1600</guid>
		<description><![CDATA[Resources CanSecWest Vancouver 2011 Presentation Files &#8211; cansecwest.com Comprehensive list of presentations during the recently concluded CanSecWest 2011 The Symantec Internet Secuirty Threat Report Volume 16 Is Here! - symantec.com We are pleased to announce that Volume 16 of the Symantec Internet Security Threat Report (ISTR) is now available. Jeremiah Grossman Reveals His Process For [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Resources</strong></p>
<ul>
<li><a href="http://cansecwest.com/csw11archive.html">CanSecWest Vancouver 2011 Presentation Files</a> &#8211; cansecwest.com<br />
Comprehensive list of presentations during the recently concluded CanSecWest 2011</li>
<li><a href="http://www.symantec.com/connect/de/Internet_Security_Threat_Report_16_Now_Here">The Symantec Internet Secuirty Threat Report Volume 16 Is Here! </a>- symantec.com<br />
We are pleased to announce that Volume 16 of the Symantec Internet Security Threat Report (ISTR) is now available.</li>
<li><a href="http://resources.infosecinstitute.com/jeremiah-grossman/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+infosecResources+%28InfoSec+Resources%29">Jeremiah Grossman Reveals His Process For Security Research</a> &#8211; resources.infosecinstitute.com<br />
In our ongoing series of interviews, this week Jeremiah Grossman answered  a few questions and pulled back the curtain a bit on the methods, tools  and motivation for the work he does.</li>
<li><a href="http://blogs.cisco.com/security/securing-ipv6/#utm_campaign=securing-ipv">Securing IPv6</a> &#8211; cisco.com<br />
In this post, we’ll talk about some of the things to consider when securing IPv6 compared to IPv4.</li>
<li><a href="http://chrissanders.org/2011/04/my-review-of-sans-for610-reverse-engineering-malware/">My Review of SANS FOR610: Reverse Engineering Malware</a> &#8211; chrissanders.org<br />
I had the opportunity to take the SANS FOR610: Reverse Engineering Malware course in Orlando a couple of weeks ago and I wanted to write about my experience with the course.</li>
<li><a href="http://www.room362.com/blog/2011/4/6/ipv6-attacks.html">Rick Hayes &#8211; Assessing and Pen-Testing IPv6 Networks</a> &#8211; vimeo.com<br />
IPv6 attack video discussion.</li>
<li><a href="http://run-virtual.com/?p=704">vSphere 4.1 Hardening Guide released</a> &#8211; run-virtual.com<br />
The guide covers topics from VMX parameters (special VM configuration settings), ESX host settings, vCenter setup and Virtual Networking guidelines.</li>
</ul>
<p><strong>Tools </strong></p>
<ul>
<li><a href="http://wappalyzer.com/about/#list">Wappalyzer Web Technology Identifier</a> &#8211; darknet.org.uk<br />
Wappalyzer is an add-on for Firefox that uncovers the technologies used on websites.</li>
<li><a href="https://www.secuobs.com/usbsploit/usbsploit-0.6-BETA-linux-i686.tar.gz">USBsploit v0.6b!</a> &#8211; secuobs.com<br />
<em> </em>USBsploit is a PoC to generate Reverse TCP backdoors, malicious PDF or LNK files.</li>
<li><a href="http://sourceforge.net/projects/moscrack/files/">MOSCRACK-2.04b!</a> &#8211; sourceforge.net/projects/moscrack/<br />
Moscrack is a perl application designed to facilitate cracking WPA keys on a cluster of computers.</li>
<li><a href="http://pages.eeye.com/RetinaCommunity.html">RETINA Community</a> &#8211; eeye.com<br />
Retina Community is a completely free tool powered by eEye&#8217;s renowned Retina Network Security Scanner technology. For up to 32 IPs, the product identifies vulnerabilities (including zero day), configuration issues, and missing patches across operating systems, applications, devices, and virtual environments.</li>
<li><a href="http://sourceforge.net/projects/peachfuzz/files/">Peach v2.3.8</a> &#8211; sourceforge.net/projects/peachfuzz/<br />
Peach is a SmartFuzzer that is capable of performing both generation and mutation based fuzzing.</li>
<li><a href="http://freeworld.thc.org/releases/hydra-6.2-src.tar.gz">THC-HYDRA v6.2</a> &#8211; thc.org<br />
THC-HYDRA is a very fast network logon cracker which support many different services.</li>
<li><a href="http://code.google.com/p/skipfish/downloads/list">Skipfish-1.86b</a> &#8211; code.google.com/p/skipfish/<br />
Skipfish is a fully automated, active web application security reconnaissance tool.</li>
<li><a href="http://www.oxid.it/downloads/ca_setup.exe">Cain &amp; Abel v4.9.40 released</a> &#8211; oxid.it<br />
This update includes an added Proxy support for Cain&#8217;s Certificate Collector, the ability to specify custom proxy authentication credentials for Certificate Collector, and others.</li>
<li><a href="http://www.secmaniac.com/download/">The Social-Engineer Toolkit v1.3.3</a> &#8211; secmaniac.com<br />
The Social Engineering Toolkit (SET) is a python-driven suite of custom tools which solely focuses on attacking the human element of penetration testing.</li>
<li><a href="http://www.kismetwireless.net/download.shtml">Kismet-2011-03-R2</a> &#8211; kismetwireless.net<br />
Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system.</li>
<li><a href="http://www.hex-rays.com/idapro/61/index.html">IDA Pro 6.1 Disassemble Android Bytecode</a> &#8211; hex-rays.com<br />
The new version can disassemble Android bytecode (Dalvik). An IDA user kindly contributed the processor module and file loader.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://gallery.technet.microsoft.com/scriptcenter/56962f03-0243-4c83-8cdd-88c37898ccc4">Remotely execute edm.exe commands on multiple computers</a> &#8211; gallery.technet.microsoft.com<br />
This script invokes whatever command you can use in cmd.exe on one or more computers you input the command you&#8217;d like to run as a screen input when you run the script.</li>
<li><a href="http://dsecrg.blogspot.com/2011/04/smbrelay-bible-5-smbrelay-attacks-on.html">SMBRelay Bible 5: SMBRelay attacks on corporate users</a> &#8211; dsecrg.blogspot.com<br />
Today we will talk about client-side attacks. An attack of a network  is a progressive action. Usually, we escalate our rights step-by-step  from nothing to a domain administrator.</li>
<li><a href="http://www.golubev.com/blog/?p=210">Another Big One</a> &#8211; golubev.com<br />
Ivan Golubev tests out the new Radeon HD6990 and compares it to the 5970.</li>
<li><a href="http://resources.infosecinstitute.com/slaac-attack/">Slack Attack 0Day Windows Network Interception network Vulnerability</a> &#8211; resources.infosecinstitute.com<br />
This article describes a proof of concept of an interesting application of IPv6.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li><a href="http://intrepidusgroup.com/insight/2011/04/apple-ios-4-3-adds-additional-ipv6-user-security/">Apple iOS 4.3 adds additional IPv6 user security</a> &#8211; intrepidusgroup.com<br />
In IPv4, there is a requirement to have an external entity handle IP address assignments.</li>
<li><a href="http://blog.sucuri.net/2011/04/wordpress-3-1-1-is-available-security-fixes.html">WordPress 3.1.1 is available (security fixes)</a> &#8211; sucuri.net<br />
Some security hardening to media uploads, performance improvements, fixes for IIS6 support and fixes for taxonomy and PATHINFO (/index.php/) permalinks.</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li>Comodo Hack Fallout<br />
Some opinions on the recent Comodo hack</p>
<ul>
<li><a href="http://news.cnet.com/8301-31921_3-20050255-281.html">Comodo Hack May Reshape Browser Security</a> &#8211; news.cnet.com</li>
<li><a href="https://www.threatpost.com/en_us/blogs/problem-issuing-certs-unqualified-names-040611">The Problem of Issuing Certs For Unqualified Names</a> &#8211; threatpost.com</li>
</ul>
</li>
<li>Epsilon Spear Phishing Crisis<br />
Security experts are warning consumers to be especially alert for targeted email scams in the coming weeks and months.</p>
<ul>
<li><a href="http://krebsonsecurity.com/2011/04/epsilon-breach-raises-specter-of-spear-phishing/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29">Epsilon breach Raises Specter of Spear Phishing</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://threatpost.com/en_us/blogs/list-companies-hit-epsilon-breach-040511">List of Companies Hit By Epsilon Breach</a> &#8211; threatpost.com</li>
<li><a href="http://threatpost.com/en_us/blogs/epsilon-data-breach-expands-include-capital-one-disney-others-040411">Epsilon Data Breach Expands To Inlcude Capital One, Disney, Others </a>- threatpost.com</li>
</ul>
<ul>
<li><a href="http://garwarner.blogspot.com/2011/04/epsilon-phishing-model.html">The Epsilon Phishing Model</a> &#8211; garwarner.blogspot.com</li>
<li><a href="http://www.net-security.org/secworld.php?id=10783">Playcom customers receiving malicious emails, Silverpop blamed</a> &#8211; net-security.org</li>
<li><a href="http://krebsonsecurity.com/2011/04/after-epsilon-avoiding-phishing-scams-malware/">After Epsilon: Avoiding Phishing Scams &amp; Malware</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://www.readwriteweb.com/archives/your_email_address_was_stolen_now_what.php">Your Email Address Was Stolen. Now What?</a> &#8211; readwriteweb.com</li>
<li><a href="http://erratasec.blogspot.com/2011/04/how-to-protect-yourself-from-future.html">How to protect yourself from future Epsilon breach</a> &#8211; erratasec.blogspot.com</li>
</ul>
</li>
<li>EMC (RSA) Buys NetWitness<br />
It is no surprise that EMC has acquired Netwitness. Looks like they are serious about this security stuff.</p>
<ul>
<li><a href="http://spiresecurity.com/?p=1236">EMC (RSA) Acquires NetWitness</a> &#8211; spiresecurity.com</li>
<li><a href="http://securosis.com/blog/fool-us-once-emc-rsa-buys-netwitness">Fool us once… EMC/RSA Buys NetWitness</a> &#8211; securosis.com</li>
</ul>
</li>
<li><a href="http://darkreading.com/vulnerability-management/167901026/security/vulnerabilities/229401012/symantec-logged-286-million-threats-in-2010.html">Symantec Logged 286 Million New Threats In 2010</a> &#8211; darkreading.com<br />
Unique malware and variants galore, and more than 40 percent more mobile vulnerabilities than a year ago.</li>
<li><a href="http://www.wired.com/threatlevel/2011/04/condenast-hooked-by-spear-phisher/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired27b+%28Blog+-+27B+Stroke+6+%28Threat+Level%29%29">Conde Nast Got Hooked On $8 Million Spear Phishing Campaign</a> &#8211; wired.com<br />
The alleged swindler failed to withdraw any funds before federal authorities intervened and froze the money, but the case highlights how little effort a scammer needs to invest in order to get a big payday.</li>
<li><a href="http://rdist.root.org/2011/04/06/fixing-the-ssl-cert-nightmare/">Fixing the SSL cert nightmare</a> &#8211; root.org<br />
In response to this compromise, many people are recommending drastic changes.</li>
<li>More Spearphishing: RSA breach news<br />
Security firm RSA announced in March that it had been the victim of a hack that it described as &#8220;extremely sophisticated.&#8221;</p>
<ul>
<li><a href="http://terminal23.net/2011/04/biggest_lesson_from_rsa_securi.html">Biggest Lesson From Rsa: Security Really Is Hard</a> &#8211; terminal23.net</li>
<li><a href="http://arstechnica.com/security/news/2011/04/spearphishing-0-day-rsa-hack-not-extremely-sophisticated.ars">Spearphishing + 0day: RSA hack not &#8220;extremely sophisticated&#8221;</a> &#8211; arstechnica.com</li>
</ul>
</li>
<li><a href="https://eff.org/deeplinks/2011/04/unqualified-names-ssl-observatory">Unqualified Names in the SSL Observatory</a> &#8211; eff.org<br />
Using data in EFF&#8217;s SSL Observatory, we have been able to quantify the extent to which CAs engage in the insecure practice of signing certificates for unqualified names.</li>
<li><a href="https://threatpost.com/en_us/blogs/pandora-mobile-app-transmits-gobs-personal-data-040611">Pandora Mobile App Transmits Gobs Of Personal Data</a> &#8211; threatpost.com<br />
The analysis was conducted by application security firm Veracode and found that Pandora&#8217;s free mobile application for Android phones tracked and submitted a range of data, including the user&#8217;s gender, geographic location and the unique ID of their phone, according to an entry on Veracode&#8217;s blog.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1600&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/04/11/week-14-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 6 In Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/02/14/week-6-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/02/14/week-6-in-review-2011/#comments</comments>
		<pubDate>Mon, 14 Feb 2011 10:32:22 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Local Meetings]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[ShmooCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1463</guid>
		<description><![CDATA[Events Related ShmooCon CTF 2011 Ghost In the Shellcode &#8211; ghostintheshellcode.com Congratulations to ppp for winning the second GitS CTF! The game board as it was when the contest ended is now live, though answers are not accepted, nor are any of the exploitable services running. Just like the real thing - blog.uncommonsensesecurity.com The goal is [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li><a href="http://www.mediafire.com/?a6cj7atbp2j2bo7">ShmooCon CTF 2011 Ghost In the Shellcode</a> &#8211; ghostintheshellcode.com<br />
Congratulations to ppp for winning the second GitS CTF! The game board as it was when the contest ended is now live, though answers are not accepted, nor are any of the exploitable services running.</li>
<li><a href="http://blog.uncommonsensesecurity.com/2011/02/just-like-real-thing.html">Just like the real thing </a>- blog.uncommonsensesecurity.com<br />
<span style="font-family: 'Trebuchet MS', Trebuchet, Verdana, sans-serif; color: #cccccc;"><span style="line-height: 20px;"><span style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; line-height: 19px; color: #000000;">The goal is to build a truly &#8220;enterprise class&#8221; network, and they pull it off every year.</span></span></span></li>
<li>RSA 2011<br />
Last year we produced a pretty detailed Guide to the Conference and it was well received, so – gluttons for punishment that we are – we’re doing it again</p>
<ul>
<li><a href="http://securosis.com/blog/rsa-guide-2011-key-themes">RSA Guide 2011: Key Themes</a> &#8211; securosis.com</li>
<li><a href="http://www.darkreading.com/vulnerability-management/167901026/security/application-security/229209624/researchers-to-hit-major-website-in-drive-by-at-rsa.html">Researchers To Hit Major Website In Drive-By At RSA</a> &#8211; darkreading.com</li>
</ul>
</li>
</ul>
<p><strong>Resources</strong></p>
<ul>
<li>USB Attacks On Linux<br />
Many people think that Linux is immune to the type of Autorun attacks that have plagued Windows systems with malware over the years.</p>
<ul>
<li><a href="http://linux.slashdot.org/story/11/02/07/1742246/USB-Autorun-Attacks-Against-Linux?from=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Slashdot/slashdot+(Slashdot)">USB Autorun Attacks Against Linux</a> &#8211; linux.slashdot.org</li>
<li><a href="http://blogs.iss.net/archive/Shmoocon2011.html">ShmooCon 2011 Presentation </a>- blog.iss.net</li>
<li><a href="http://www.itnews.com.au/News/247616,microsoft-says-rip-windows-xp-autorun.aspx">Microsoft says RIP Windows XP AutoRun for USB</a> &#8211; itnews.com.au</li>
</ul>
</li>
<li><a href="http://resources.infosecinstitute.com/common-infosec-jobs-certifications/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+infosecResources+(InfoSec+Resources)">Some common infosec job roles and related certifications</a> &#8211; resources.infosecinstitute.com<br />
Most people hear the term Infosec, and they automatically associate that with network and telecom security, but in reality it’s much broader than that.</li>
<li><a href="http://www.shmoocon.org/2011/videos/Ossmann-Bluetooth.m4v">Project Ubertooth: Building A Better Bluetooth Adapter</a> &#8211; ossman.blogspot.com<br />
Video of my presentation,Project Ubertooth: Building a Better Bluetooth Adapter, at ShmooCon 2011 is now online.</li>
<li><a href="https://blogs.sans.org/appsecstreetfighter/2011/02/07/apple-ios-push-notifications-security-implications-abuse-scenarios-and-countermeasures/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=apple-ios-push-notifications-security-implications-abuse-scenarios-and-countermeasures">Apple iOS Push Notifications: Security Implications, Abuse Scenarios, and Countermeasures</a> &#8211; blogs.sans.org<br />
In this article, I will briefly introduce details of how APN works and present scenarios of how insecure implementations can be abused by malicious parties.</li>
<li><a href="http://blogs.cisco.com/security/cisco-4q10-global-threat-report/#utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=cisco-4q10-global-threat-report">Cisco 4Q10 Global Threat Report </a>- blogs.cisco.com<br />
The Cisco 4Q10 Global Threat Report is now available for download. The report showcases data from the 4th calendar quarter (October 1, 2010 – December 31, 2010).</li>
<li><a href="http://blog.fortinet.com/shmoocon-2011-debriefing/">ShmooCon 2011 Debriefing </a>- blog.fortinet.com<br />
First, just like in BlackHat DC 2011, this year’s conference had several talks on smart phones. Good news! I was however slightly surprised they all concerned Android.</li>
<li><a href="https://blogs.sans.org/appsecstreetfighter/2011/02/10/five-key-design-decisions-that-affect-security-in-web-applications/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=five-key-design-decisions-that-affect-security-in-web-applications">Five Key Design Decisions That Affect Security In Web Applications </a>- blogs.sans.org<br />
Senior developers and architects often make decisions related to application performance or other areas that have significant ramifications on the security of the application for years to come.</li>
<li><a href="http://www.risky.biz/">What netsec-like podcasts do you listen to? </a>- risky.biz<br />
I&#8217;m having a hard time getting my fill of security related news and discussion. I&#8217;m down to two podcasts that I listen to weekly.</li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;"><a href="http://www.securelist.com/en/analysis/204792160/Exploit_Kits_A_Different_View">Exploit Kits &#8211; A Different View</a> &#8211; securelist.com<br />
Exploit kits are packs containing malicious programs that are mainly used to carry out automated ‘drive-by’ attacks in order to spread malware.</span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;"><a href="http://www.room362.com/blog/2009/9/18/password-word-lists.html">Password/Word Lists</a> &#8211; room362.com<br />
Brute force, even though it&#8217;s gotten so fast, is still a long way away from cracking long complex passwords.</span></li>
<li>
<div id="_mcePaste"><a href="http://www.msisac.org/apps/dashboard/howto/">Multi-State Information Sharing &amp; Analysis Center CyberSecurity Digital Dashboard</a> &#8211; msisac.org</div>
<div id="_mcePaste">I stumbled upon this and was kind of impressed.</div>
</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://labs.m86security.com/2011/02/pdf-exploit-disguised-as-a-xerox-scanned-document/">PDF Exploit Disguised As A Xerox Scanned Document </a>- labs.m86security.com<br />
Most office network printers and scanners have a feature that sends scanned documents over email. Cyber crooks however, have imitated email templates used by these devices for malicious purposes</li>
<li><a href="http://chuvakin.blogspot.com/2011/02/honeynet-project-releases-new-tool.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+AntonChuvakinPersonalBlog+(Anton+Chuvakin+Personal+Blog)">The Honeynet Project Releases New Tool: PhoneyC </a>- chuvakin.blogspot.com<br />
As promised, I will be reposting some of the cool new announcements from The Honeynet Project here on my blogsince I now serve as Project’s Chief PR Officer.</li>
<li><a href="http://blog.metasploit.com/2011/02/metasploit-framework-352-released.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+metasploit/blog+(Metasploit+Blog)">MetaSploit Framework 3.5.2 Released</a> &#8211; blog.metasploit.com<br />
On February 1st, Eduardo Prado of Secumania notified us of a privilege escalation vulnerability on multi-user Windows installations of the Metasploit Framework.</li>
<li><a href="http://www.open-scap.org/page/Download">Open SCAP v0.6.8 released</a> &#8211; open-scap.org<br />
The OpenSCAP Project was created to provide an open-source frameworkto the community which enables integration with the Security Content Automation Protocol (SCAP) suite of standards and capabilities.</li>
<li><a href="http://sourceforge.net/projects/ssldiagnos/files/">SSL Diagnosis v0.8.1a released</a> &#8211; sourceforge.net<br />
<span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;">SSL Diagnos is used to get information about SSL usage (protocols ssl2, ssl3, tls, dtls, and ciphers). It can also be used for testing and rating ciphers on SSL clients.</span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif; line-height: 22px;"><a href="http://www.terminal23.net/2011/02/passwords_shared_between_rootk.html">Passwords shared between rootkit.com and gawker</a> &#8211; terminal23.net<br />
This is a classic journo case of an editor-sensationalized title for an article that doesn&#8217;t really get reasonable until the last two paragraphs where it kinda puts the brakes on calling password reuse &#8220;endemic.&#8221; </span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif;"><span style="line-height: 22px;"><a href="http://nmap.org/download.html">UPDATE: Nmap 5.51!</a> &#8211; nmap.org<br />
Wow! In about two weeks time, another Nmap release! We now have Nmap version 5.51! The last release was <em>Nmap 5.50</em>, which we wrote about here.</span></span></li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif;"><span style="line-height: 22px;"><span style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; line-height: 19px;"><a href="http://www.vulnerabilitydatabase.com/toolswatch/2011/02/09/eeye-to-release-free-vulnerability-scanner-with-zero-day-identification-and-configuration-auditing/">eEye to Release Free Vulnerability Scanner with Zero -Day Identification and Configuration Auditing</a> &#8211; eeye.com<br />
<span style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 14px; line-height: 22px;">eEye Digital Security, a provider of IT security and unified vulnerability management solutions, today announced the pre-release of Retina Community.</span></span></span></span></li>
<li><span style="font-family: Georgia, serif; color: #333333;"><span style="line-height: 20px;"><a href="http://www.fiddler2.com/Fiddler2/version.asp">UPDATE: Fiddler v2.3.2.3! </a>- fiddler2.com</span></span><br />
<span style="font-family: Georgia, serif; color: #333333;"><span style="line-height: 20px;">Our first post regarding Fiddler, the web debugger can be found here. On the 13th of February, an update was released.</span></span><span style="font-family: Verdana, sans-serif; color: #111111;"><span style="line-height: 18px;"><br />
</span></span></li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://blog.kaffenews.com/?p=2119">A Python Domains Extractor From IPs</a> &#8211; blog.kaffenews.com<br />
I developed it in 5 mins just because I had to do a PT on a list of IP Addresses and it was needed to get the Domains from IPs.</li>
<li>TrueCrypt<br />
After I read the documentation and some reviews I realize that it is a very secure piece of software that implements many high level features so I knew I will not be easy, at least in theory.</p>
<ul>
<li><a href="http://www.shortinfosec.net/2009/02/cracking-truecrypt-container.html">Cracking a TrueCrypt Container </a>- shortinfosec.net</li>
<li><a href="http://www.q-protex.com/software/password-recovery/truecrypt-self-bruteforce">TrueCrypt Self-Bruteforce </a>- q-protex.com</li>
</ul>
</li>
<li><a href="http://www.perihel.at/sec/mz/">What is Mausezahn?</a> &#8211; peripheral.at<br />
Mausezahn is a free fast traffic generator written in C which allows you to send nearly every possible and impossible packet.</li>
<li>Proxocket
<ul>
<li><a href="http://sethioz.co.uk/mediawiki/index.php5/Proxocket">Proxocket </a>- sethioz.co.uk</li>
<li><a href="http://www.darknet.org.uk/2011/02/proxocket-dll-proxy-for-winsock/">Proxocket &#8211; DLL Proxy For Winsock</a> &#8211; darknet.org.uk</li>
<li><a href="http://www.netresec.com/?page=Blog&amp;month=2011-01&amp;post=Proxocket---A-Winsock-Proxy-Sniffer">Proxocket &#8211; A Winsock Proxy Sniffer </a>- netresec.com</li>
</ul>
</li>
</ul>
<ul>
<li><a href="http://carnal0wnage.attackresearch.com/node/444">Move over tsgrinder/tscrack hello ncrack</a> &#8211; carnalOwnage.attackresearch.com<br />
So thanks to mubix for telling me that ncrack now supports RDP. very cool stuff.</li>
<li><a href="http://www.justanotherhacker.com/2011/02/left-or-right-handed-passwords.html">Left or right handed passwords </a>- justanotherhacker.com<br />
Are you left or right handed? How about your password? English based passwords seem to be predominantly left handed.</li>
<li><a href="http://www.symantec.com/connect/de/blogs/hidden-bandit-inside-neosploit">Hidden bandit Inside NeoSploit </a>- symantec.com<br />
Over the last few years, Symantec has observed a substantial rise in the use of exploit kits.</li>
<li><a href="http://net-ninja.net/blog/?p=553">Breaking web security &#8211; it&#8217;s all about RCS</a> &#8211; net-ninja.net<br />
I will be discusing ways in which we can include error handling, anonymimity and how we can build the exploit so that the auditor has a reliable and flexible weapon.</li>
<li><a href="http://research.zscaler.com/2011/02/in-depth-analysis-decoding-html-style.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+zscaler/research+(Zscaler+Research)">Decoding HTML Style tag based malicious frames </a>- research.zscaler.com<br />
Injecting clear text or obfuscated malicious Iframes has become a common attack vector.</li>
<li><a href="http://reverse.put.as/">Universe&#8217;s best and legal Mac OS X reversing tutorial for newbies</a> &#8211; reverse.put.as<br />
I have decided to re-release my beginners tutorial, this time based on a crackme, so it deserves the upgrade to Universe instead of World.</li>
<li><a href="http://spareclockcycles.org/2011/02/11/android-gmail-app-stealing-emails-via-xss/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=android-gmail-app-stealing-emails-via-xss">Android Gmail App: Stealing Emails via XSS </a>- spareclockcycles.org<br />
This post documents an XSS vulnerability that I discovered in the default Gmail app (v1.3) provided by Google in Android 2.1 and prior.</li>
<li><a href="http://thomascannon.net/projects/android-reversing/">Android Reverse Engineering</a> &#8211; thomascannon.net<br />
This project all started when I was asked tot ake a look at a software product that was under evaluation.</li>
<li><a href="http://dfsforensics.blogspot.com/2011/02/forensic-examination-of-pointsec.html">Forensic Examination of Pointsec Encrypted Drives </a>- dfsforensics.blogspot.com<br />
Many organizations use Pointsec (Check Point) full disk encryption in order to keep their data secure, especially in the case of laptops.</li>
<li><span style="font-family: Georgia, 'Times New Roman', Times, serif;"><span style="line-height: 22px;"><a href="http://research.zscaler.com/2011/02/blackhole-exploits-kit-attack-growing.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+zscaler/research+(Zscaler+Research)">Blackhole exploits kit attack growing </a>- research.zscaler.com</span></span><br />
<span style="font-family: Georgia, serif; color: #333333;"><span style="line-height: 20px;">Recently, we have seen an increase in Blackhole exploit kit attacks. Blackhole is yet another web exploit kit developed by Russian hackers.</span></span></li>
<li><a href="http://blog.wearpants.org/better-passwords-in-under-200-characters?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+iwearpants+(I+Wear+Pants)">Better Passwords In Under 200 Characters </a>- blog.wearpants.org<br />
Good password security is a pain in the neck. Done properly, it requires a different password for every site.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li><a href="http://isc.sans.edu/diary.html?storyid=10375&amp;rss">February 2011 Microsoft Black Tuesday Summary</a> &#8211; isc.sans.edu<br />
Here are the February 2011 Black Tuesday patches.  Enjoy!</li>
<li>Adobepatch<br />
Adobe released updates for Reader for 9.4.2 and 10.0.1.  While this page on Adobe&#8217;s site doesn&#8217;t actually list them correctly, if you drill down into the actual product and OS, you&#8217;ll see the updates listed for 2/8/2011.</p>
<ul>
<li><a href="http://isc.sans.edu/diary.html?storyid=10378&amp;rss">Adobe Reader 9.4.2 and 10.0.1 Updates are out </a>- isc.sans.edu</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=10390&amp;rss">Adobe patches for Shockwave, Flash, Reader, and Cold Fusion</a> &#8211; isc.sans.edu</li>
</ul>
</li>
<li><a href="http://krebsonsecurity.com/2011/02/adobe-microsoft-wordpress-issue-security-fixes/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+KrebsOnSecurity+(Krebs+on+Security)">Adobe, Microscoft, WordPress Issue Security Fixes</a> &#8211; krebsonsecurity.com<br />
Talk about Patch Tuesday on steroids! Adobe, Microsoft and WordPress all issued security updates for their products yesterday. In addition, security vendorTipping Point released advisories detailing 21 unpatched vulnerabilities in products made by CA, EMC, HP, Novell and SCO.</li>
<li><a href="http://www.vmware.com/security/advisories/VMSA-2011-0002.html">VMWare Security Advisory </a>- vmware.com<br />
Updated versions of the Cisco Nexus 1000V virtual switch address a denial of service in VMware ESX/ESXi.</li>
</ul>
<p><strong>Vulnerabilities</strong></p>
<ul>
<li><a href="http://dvlabs.tippingpoint.com/blog/2011/02">Last August, TippingPoint said they will enforce a six-month disclosure on bought bugs that haven&#8217;t been patched. Today, TippingPoint rolled out 22 </a>- dvlabs.tippingpoint.com<br />
These vulnerabilities are being published as per the ZDI disclosure changes announced in August of 2010.</li>
<li><a href="http://www.exploit-db.com/exploits/16123/">Comcast DOCSIS 3.0 Business gateways Multiple Vulnerabilities</a> &#8211; exploit-db.com<br />
With these default credentials, internal attackers can modify deviceconfigurations to leverage more significant attacks, including redirection of DNS requests.</li>
</ul>
<p><strong><strong>Other News</strong></strong></p>
<ul>
<li>Anonymous vs. Aaron Barr/HBGary<br />
A security researcher claims to have infiltrated the higher echelons of the Anonymous organisation and identified key leaders&#8217; names and addresses.</p>
<ul>
<li><a href="http://i.imgur.com/em14R.jpg">Anonymous infiltrates the HBGary security company, which was tasked with infiltrating Anonymous by the FBI</a> &#8211;  reddit.com</li>
<li><a href="http://www.v3.co.uk/v3/news/2274613/anonymous-hbgary-federal-ft#ixzz1DuVUSDl0">Researcher claims to have infiltrated Anonymous high command </a>- v3.co.uk</li>
<li><a href="http://krebsonsecurity.com/2011/02/hbgary-federal-hacked-by-anonymous/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+KrebsOnSecurity+(Krebs+on+Security)">HBGary Federal Hacked by Anonymous</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://www.readwriteweb.com/archives/anonymous_hacks_security_company_hbgary_dumps_5000.php?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+readwriteweb+(ReadWriteWeb)">Anonymous hacks security company HBGary, Dumps 50,000 emails online </a>- readwriteweb.com</li>
<li><a href="http://www.lightbluetouchpaper.org/2011/02/09/measuring-password-re-use-empirically/">Measuring password re-use empirically </a>- lightbluetouchpaper.org</li>
<li><a href="http://www.guardian.co.uk/technology/2011/feb/07/anonymous-attacks-us-security-company-hbgary">Anonymous Attacks US Security Company</a> &#8211; guardian.co.uk</li>
<li><a href="http://dazzlepod.com/rootkit/">rootkit.com cleartext passwords</a> &#8211; dazzlepod.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/02/anonymous/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))">How One Man Tracked Down Anonymous &#8211; And Paid A Heavy Price</a> &#8211; wired.com</li>
<li><a href="http://uiu.me/cia.zip">HBGary&#8217;s conversations with Feds</a> &#8211; uiu.me</li>
<li><a href=" http://uiu.me/dhs.zip">HBGary&#8217;s conversations with the Feds pt. 2 </a>- uiu.me</li>
<li><a href="http://dazzlepod.com/site_media/txt/rootkit.com.txt">blow by blow of how Anonymous gained root access on rootkit.com</a> &#8211; dazzlepod.com</li>
<li><a href="http://cryptome.org/0003/anonymous-barr.pdf">The Report on Anonymous by Aaron Barr </a>- cryptome.org</li>
</ul>
</li>
<li><a href="http://stfu.cc/rootkit_com_mysqlbackup_02_06_11.gz">Rootkit.com&#8217;s MySQL database leaked</a> &#8211; stfu.cc<br />
Come on, I know it&#8217;s /r/netsec, so we should be familiar with checking URLs before clicking, but I&#8217;d expect at least a warning before clicking a direct download of a company&#8217;s database.</li>
<li><a href="http://1raindrop.typepad.com/1_raindrop/2011/02/hatfields-and-mccoys-2011-style.html">Hatfields and McCoys 2011 Style</a> &#8211; 1raindrop.typepad.com<br />
By itself its an derisive, throw away comment that security people make about developers all the time, and of course developers are not averse to throwing haymakers back at security people.</li>
<li><a href="http://twitpic.com/3xwe6h">Sony Marketing Man Tweets PS3 Master Key </a>- twitpic.com<br />
My life is complete. Sue yourself, Sony.</li>
<li>iPhone Password Hack<br />
Researchers in Germany say they&#8217;ve been able to reveal passwords stored in a locked iPhone in just six minutes and they did it without cracking the phone&#8217;s passcode.</p>
<ul>
<li><a href="http://www.techworld.com.au/article/376245/iphone_attack_reveals_passwords_six_minutes/">iPhone Attack Reveals Password In 6 Minutes </a>- techworld.com.au</li>
<li><a href="http://cyberarms.wordpress.com/2011/02/10/iphone-hacked-and-passwords-stolen-in-just-6-minutes/">iPhone Hacked and Passwords Stolen In Just 6 Minutes </a>- cyberarms.wordpress.com</li>
<li><a href="http://nakedsecurity.sophos.com/2011/02/10/video-how-to-steal-passwords-locked-iphone/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+NakedSecurityGrahamCluley+(Sophos+Naked+Security+%C2%BB+Graham+Cluley)">How to steal passwords from a locked iPhone </a>- nakedsecurity.sophos.com</li>
<li><a href="http://www.engadget.com/2011/02/10/researchers-steal-lost-iphone-passwords-in-6-minutes-video/">Researches steal iPhone password in 6 minutes</a> &#8211; engadget.com</li>
</ul>
</li>
<li><a href="http://wikileaks.ch/IMG/pdf/WikiLeaks_Response_v6.pdf">Secret Plan To Kill WikiLeaks With FUD Leaked</a> &#8211; wikileaks.ch<br />
Three information security consultancies with links to US spy agencies cooked up a dirty tricks campaign late last year to destroy Wikileaks by exploiting its perceived weaknesses.</li>
<li><a href="http://www.bbc.co.uk/news/technology-12416580">Hackers hit &#8216;at least five oil and gas firms&#8217;</a> &#8211; bbc.co.uk<br />
Hackers have run rampant through the networks of at least five oil and gas firms for years, reveals a report.</li>
<li><a href="http://nakedsecurity.sophos.com/2011/02/11/night-dragon-attacks-myth-or-reality/">Night Dragon attacks: myth or reality</a> &#8211; nakedsecurity.sophos.com<br />
Many readers will have seen the press around a series of hacking attacks that have been labelled the &#8216;Operation Night Dragon&#8217; attacks by McAfee.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1463&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/02/14/week-6-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.shmoocon.org/2011/videos/Ossmann-Bluetooth.m4v" length="838736213" type="video/mp4" />
		</item>
		<item>
		<title>Week 3 in Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/01/24/week-3-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/01/24/week-3-in-review-2011/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 09:36:41 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[ShmooCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1422</guid>
		<description><![CDATA[Events Related: A Shmoocon Preview &#8211; blogs.macafee.com At about a third of the size of a larger conference like Black Hat, it’s much easier to talk to the speakers without fighting with a crowd. Past years have had good presentations on mobile phone security and this year is no exception. Black Hat DC 2011 We are [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://blogs.mcafee.com/enterprise/mobile/a-shmoocon-preview">A Shmoocon Preview</a> &#8211; blogs.macafee.com<br />
At about a third of the size of a larger conference like Black Hat, it’s much easier to talk to the speakers without fighting with a crowd. Past years have had good presentations on mobile phone security and this year is no exception.</li>
<li>Black Hat DC 2011<br />
We are currently at the awesome BlackHat DC event, with hundreds of attendees coming from many different countries worldwide.</p>
<ul>
<li><a href="http://www.blackhat.com/html/bh-dc-11/bh-dc-11-archives.html">Black Hat itinerary </a>- blackhat.com</li>
<li><a href="http://blog.tehtri-security.com/2011/01/blackhat-dc-2011-inglourious-hackerds.html">Black Hat DC 2011: Inglourious Hackerds </a>- blog.tehtri-security.com</li>
<li><a href="http://threatpost.com/en_us/blogs/mobile-attacks-reign-black-hat-dc-012011">Mobile Attacks reign At Black Hat DC</a> &#8211; threatpost.com</li>
<li><a href="http://www.networkworld.com/news/2011/011911-black-hat-trick-iphones.html">Fake GSM base station trick targets iPhone</a> &#8211; networkworld.com</li>
<li><a href="http://www.networkworld.com/news/2011/012011-black-hat-quirky-moments.html">Quirky moments at Black Hat DC 2011</a> -networkworld.com</li>
</ul>
</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.reddit.com/r/netsec/comments/f5msi/cisco_2010_annual_security_report/">Cisco 2010 Annual Security Report </a>- reddit.com<br />
The Tipping Point: Cybercriminals Targeting Mobile Platforms</li>
<li>Dress For Success In the Corporate Setting<br />
If your organization truly judges you based on what you wear, and not what you know and what you do, then you are working for the wrong organization.</p>
<ul>
<li><a href="http://www.terminal23.net/2011/01/from_lee_mike_common_traits_of.html">Common traits of future Infosec leaders</a> &#8211; terminal23.net</li>
<li><a href="http://securosis.com/blog/the-appearance-myth/">The Appearance Myth</a> &#8211; securosis.com</li>
<li><a href="http://www.infosecleaders.com/2011/01/career-advice-tuesday-%E2%80%93-%E2%80%9Cfashion-advice-from-infosecleaders%E2%80%9D/?">Fashion Advice from Infosec Leaders</a> &#8211; infosecleaders.com</li>
</ul>
</li>
<li><a href="http://www.schneier.com/blog/archives/2011/01/the_legality_of.html">The Legality of the Certificate Authority  Trust Model</a> &#8211; schneier.com<br />
We looked at the standard legal documents issued by the certificate authorities or &#8220;CAs,&#8221; including exemplar Subscriber Agreements (agreements between CAs and website operators).</li>
<li><a href="http://www.redspin.com/blog/2011/01/21/getting-started-with-corporate-ipad-and-iphone-mobile-security/?">Getting Started With Corporate iPad and iPhone Mobile Security</a> &#8211; redspin.com<br />
Mobile devices like the iPhone and iPad are a top security concern for 2011. The first step to addressing this risk is to put a security policy in place that addresses mobile devices.</li>
<li><a href="http://www.readwriteweb.com/enterprise/2011/01/-cisco-released-its-2010.php?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+readwriteweb+(ReadWriteWeb)">Cisco Explains the 7 Deadly Weaknesses of Social network Users and More in Security Report </a>- readwriteweb.com<br />
Cisco released its 2010 Annual Security Report yesterday. The report covers criminals&#8217; slow shift from targeting Windows PCs to targeting other operating systems and devices, the importance of exploiting users&#8217; trust in their social network friends and the rise of Java exploits, and more.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2011/01/top-ten-web-hacking-techniques-of-2010.html?">Top 10 Web Hacking Techniques of 2010</a> &#8211; jeremiahgrossman.blogspot.com<br />
Now in its fifth year the Top Ten Web Hacking Techniques list encourages information sharing, provides a centralized knowledge-base, and recognizes researchers who contribute excellent work.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://blog.rapid7.com/?p=5845">w3af: Better, Stronger, Faster</a> &#8211; blog.rapid7.com<br />
By downloading this release you’ll be able to enjoy new vulnerability checks, more stable code and a about 15% performance boost in the overall speed of your scan.</li>
<li><a href="http://chaptersinwebsecurity.blogspot.com/2011/01/r-u-dead-yet-version-22.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+ChaptersInWebSecurity+(Chapters+In+Web+Security)">R-U-Dead-Yet version 2.2</a> &#8211; chaptersinwebsecurity.blogspot.com<br />
I forgot the fact that people develop hunger for features and bug fixes even when software is open-source and free. Oh well, I guess that&#8217;s a responsibility that comes with the will to satisfy your end users.</li>
<li><a href="http://marcoramilli.blogspot.com/2011/01/autodiff-online.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+blogspot/CqwP+(Marco+Ramilli's+Blog)">AutoDiff Online</a> &#8211; marcoramilli.blogspot.com<br />
AutoDiff is a project which performs automated binary differential analysis between two executable files.</li>
<li>MS Attack Surface Analyzer Release<br />
Microsoft unveiled a new tool this week in conjunction with the Blackhat DC conference — the Attack Surface Analyzer.</li>
</ul>
<ul>
<li>
<ul>
<li><a href="http://www.digitalbond.com/index.php/2011/01/18/ms-attack-surface-analyzer-my-first-take-and-why-you-should-know-about-it/">MS Attack Surface Analyzer</a> &#8211; digitalbond.com</li>
<li><a href="http://blogs.msdn.com/b/sdl/archive/2011/01/17/announcing-attack-surface-analyzer.aspx">New Tool: Announcing Attack Surface Analyzer</a> &#8211; blogs.msdn.com</li>
</ul>
</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://www.troyhunt.com/2011/01/whos-who-of-bad-password-practices.html">Who&#8217;s who of bad password practices</a> &#8211; troyhunt.com<br />
But what happens when the website won’t allow you to create a secure password? Or at least when they severely constrain your ability to create long, random, unique passwords?</li>
<li><a href="http://www.reddit.com/r/netsec/comments/f43yh/share_your_nmap_parameters/">Share your nmap parameters!</a> &#8211; reddit.com<br />
What parameters do you usually use in your nmap scans? Any interesting combinations? I usually go with: nmap -v -A -p1-65535 -O2 -T4 ipaddress</li>
<li><a href="http://blog.didierstevens.com/2011/01/18/quickpost-checking-aslr/">Quickpost: Checking ASLR</a> &#8211; blog.didierstevens.com<br />
Some people asked me for a simple way to check shell extensions for their ASLR support. You can do this with Process Explorer.</li>
<li><a href="http://lifehacker.com/5736101/how-to-crack-just-about-any-mac-app-and-how-to-prevent-it?">Finding AES keys </a>- jessekornblum.livejournal.com<br />
Today I&#8217;m publishing a little utility to search for AES keys. It was originally intended for searching memory images, but you can use it to search anything really.</li>
<li><a href="http://lifehacker.com/5736101/how-to-crack-just-about-any-mac-app-and-how-to-prevent-it?">How To Crack Just About Any Mac App</a> &#8211; lifehacker.com<br />
By walking through how I can hack your app with only one Terminal shell, I hope to shed some light on how this is most commonly done, and hopefully convince you to protect yourself against me.</li>
<li><a href="http://pauldotcom.com/wiki/index.php/Episode226">Episode 266</a> &#8211; pauldotcom.com<br />
PaulDotCom Security Weekly &#8211; Episode 226 &#8211; for Thursday January 13th, 2011.</li>
<li><a href="http://www.h-online.com/security/features/Return-of-the-sprayer-exploits-to-beat-DEP-and-ASLR-1171463.html">Return of the Sprayer </a>- h-online.com<br />
If they jumped to code injected onto the stack or heap, &#8220;just like in the good old days&#8221;, data execution prevention (DEP) would trigger an interrupt and the system would terminate the carefully pwned process before it could cause any damage.</li>
<li><a href="http://research.zscaler.com/2011/01/exploit-in-wild-for-ms06-014-five-year.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+zscaler/research+(Zscaler+Research)">Exploit in the wild for MS06-014</a> &#8211; research.zscaler.com<br />
Although 0day vulnerabilities receive all the attention, it’s not unusual to see attackers still taking advantage of old vulnerabilities to attack end users</li>
<li><a href="http://soroush.secproject.com/blog/2011/01/unrestricted_file_download_v1_0/">Unrestricted File Download V1.0</a> &#8211; soroush.secproject.com<br />
I do not want to talk about Insecure Direct Object References without any protection as they are obviously exploitable; Instead, I want to talk about bypassing the protected ones!</li>
<li><a href="https://docs.google.com/gview?url=http://www.cs.gmu.edu/~astavrou/research/acsac10.pdf&amp;pli=0">Exploiting Smartphone-USB connectivity for fun and profit </a>- docs.google.com<br />
Unfortunately, these new capabilities  coupled with the inherent trust users place on the USB physical connectivity and the lack of any protection mechanisms render the USb an insecure link, prone to exploitation.</li>
<li><a href="http://blog.metasploit.com/2011/01/mobile-device-security-and-android-file.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+metasploit/blog+(Metasploit+Blog)">Mobile Device Security and Android File Disclosure</a> &#8211; blog.metasploit.com<br />
Specifically, he found that it was possible to obtain the contents of files on an Android device by simply persuading its owner to visit a web site under attacker control. The issue only garners a 3.5 CVSS score, but yet it’s still fairly serious.</li>
</ul>
<p><strong>Vulnerabilities:<br />
</strong></p>
<ul>
<li><span style="font-weight: normal;"><a href="http://www.securityfocus.com/bid/45801/discuss">IBM WebSphere MQ Invalid Message Remote Buffer Overflow Vulnerability</a> &#8211; securityfocus.com<br />
IBM WebSphere MQ is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.</span></li>
<li><span style="font-weight: normal;"><a href="http://blog.sucuri.net/2011/01/malware-update-co-cc.html">Malware update: .co.cc malicious entries</a> &#8211; blog.sucuri.net<br />
For the last weeks (actually months), we’ve been tracking a large number of malware from .co.cc domains. It seems that every .co.cc domain we find is being used to host either malware or spam.</span></li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Oracle Black Tuesday Patch<br />
If you are an Oracle user, get ready for your very own Patch Tuesday, which comes tomorrow.</p>
<ul>
<li><a href="http://nakedsecurity.sophos.com/2011/01/18/patch-tuesday-oracle/?">Patch Tuesday &#8211; now for 28 products in the Oracle stable</a> &#8211; nakedsecurity.sophos.com</li>
</ul>
<ul>
<li><a href="http://www.h-online.com/security/news/item/Oracle-patches-66-vulnerabilities-1171660.html">Oracle patches 66 vulnerabilities </a>- h-online.com</li>
<li><a href="http://blog.imperva.com/2011/01/perspective-on-the-latest-oracle-patches.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Imperviews+(ImperViews)">Perspective on the latest Oracle patche</a>s &#8211; blog.imperva.com</li>
</ul>
</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://reviews.cnet.com/8301-13746_7-20028539-48.html?part=rss&amp;tag=feed&amp;subj=TheCarTechblog">Keyless cars vulnerable to hack, theft </a>- cnet.com<br />
Keyless car entry and start systems make it easy to get on the road, but they could also make it easier for criminals to take off with your car. And strong encryption won&#8217;t solve the problem.</li>
<li>Stuxnet vs. Iran nuclear enrichment<br />
Rather than being proud of its stealth and targeting, the authors should be embarrassed at their amateur approach to hiding the payload.</p>
<ul>
<li><a href="http://rdist.root.org/2011/01/17/stuxnet-is-embarrassing-not-amazing/">Stuxnet is embarrassing not amazing</a> &#8211; rdist.root.org</li>
<li><a href="http://www.f-secure.com/weblog/archives/00002083.html">New info on Stuxnet</a> &#8211; f-secure.com</li>
<li><a href="http://www.wired.com/threatlevel/2011/01/inl-and-stuxnet/?">Did a U.S. Government Lab Help Israel Develop Stuxnet?</a> &#8211; wired.com</li>
</ul>
</li>
<li><a href="http://krebsonsecurity.com/2011/01/atm-skimmers-up-close/?">ATM Skimmers, Up Close</a> &#8211; krebsonsecurity.com<br />
Recently, I found a guy on an exclusive online scammer forum who has been hawking a variety of paraphernalia used in ATM skimmers.</li>
<li><a href="http://www.itworld.com/personal-tech/133796/coming-soon-new-way-hack-your-smartphone">Coming soon: a new way to hack into your smartphone </a>- itworld.com<br />
More than three years after the iPhone was first hacked, computer security experts think they&#8217;ve found a whole new way to break into mobile phones &#8212; one that could become a big headache for Apple, or for smartphone makers using Google&#8217;s Android software.</li>
<li><a href=" http://www.wired.com/threatlevel/2011/01/att-hack/?">Two Charged in AT&amp;T hack of iPad Customer Data </a>- wired.com<br />
Two suspects have been charged with federal crimes for allegedly hacking AT&amp;T’s website last year to obtain the personal data of more than 100,000 iPad owners.</li>
<li><a href="http://arstechnica.com/gadgets/guides/2011/01/why-you-should-always-encrypt-your-smartphone.ars">Why you should always encrypt your smartphone</a> &#8211; arstechnica.com<br />
Last week, California&#8217;s Supreme Court reached a controversial 5-2 decision in <em>People v. Diaz </em>(PDF)<em>, </em>holding that police officers may lawfully search mobile phones found on arrested individuals&#8217; persons without first obtaining a search warrant.</li>
<li>Hacking with USBs<br />
Two researchers have figured out a way to attack laptops and smartphones through an innocent-looking USB cable.</p>
<ul>
<li><a href="http://www.reddit.com/r/netsec/comments/f5msi/cisco_2010_annual_security_report/">Researchers turn USB cable into attack tool </a>- cnet.com</li>
<li><a href="http://www.h-online.com/security/news/item/Hacking-with-USB-keyboard-emulators-1172612.html">Hacking with USB keyboard emulators</a> &#8211; h-online.com</li>
</ul>
</li>
<li><a href="http://www.h-online.com/security/news/item/Online-banking-trojan-developing-fast-1172452.html">Online banking trojan developing fast</a> &#8211; h-online.com<br />
Trojan construction kit Carberp, which first emerged in the autumn, appears to be undergoing rapid development, according to reports from sources that include security services provider Seculert.</li>
<li><a href="http://www.thinq.co.uk/2011/1/20/android-trojan-captures-credit-card-details/#ixzz1BwSTpZD4">Android Trojan captures credit card details</a> &#8211; thinq.co.uk<br />
The team, comprised of Roman Schlegel from the City University of Hong Kong and Kehuan Zhang, Xiaoyong Zhou, Mehool Intwala, Apu Kapadia, and Xiao Feng Wang from the Indiana University Bloomington, call their creation &#8216;Soundminer&#8217; &#8211; and its implications are far-reaching.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1422&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/01/24/week-3-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 2 in Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/01/19/week-2-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/01/19/week-2-in-review-2011/#comments</comments>
		<pubDate>Wed, 19 Jan 2011 10:35:57 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1414</guid>
		<description><![CDATA[Events Related Shmoocon CTF Warm up Contest &#8211; JavaScrimpd &#8211; blog.stalkr.net Last week-end was ShmooCon CTF Warmup Contest. Three challenges, the last one being an ELF binary + hostname of a server. Tools OWASP Zed Attack Proxy 1.2.0 Released - vulnerabilitydatabase.com/toolswatch/2011 The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related</strong></p>
<ul>
<li><a href="http://blog.stalkr.net/2011/01/shmoocon-ctf-warmup-contest-javascrimpd.html">Shmoocon CTF Warm up Contest &#8211; JavaScrimpd</a> &#8211; blog.stalkr.net<br />
Last week-end was ShmooCon CTF Warmup Contest. Three challenges, the last one being an ELF binary + hostname of a server.</li>
</ul>
<p><strong>Tools</strong></p>
<ul>
<li><a href="http://www.vulnerabilitydatabase.com/toolswatch/2011/01/12/owasp-zed-attack-proxy-1-2-0-released/">OWASP Zed Attack Proxy 1.2.0 Released </a>- vulnerabilitydatabase.com/toolswatch/2011<br />
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.</li>
</ul>
<p><strong>Techniques</strong></p>
<ul>
<li><a href="http://www.mrspeaker.net/2011/01/06/mac-hacking/">Beginning Mac Hacking</a> &#8211; mrspeaker.net<a href="http://www.mrspeaker.net/2011/01/06/mac-hacking/"><br />
</a>He was a very mystical fellow, and spoke about reverse engineering with a sense of grand importance and just a pinch of spiritually – all very enticing to a nerdy youngster like myself.</li>
<li><a href="http://thesauceofutterpwnage.blogspot.com/2011/01/waking-up-sleeping-dragon.html">Waking up the Sleeping Dragon -</a> thesauceofutterpwnage.blogspot.com<br />
On September 28, 2010 I notified Beijing based WellinControl Technology Development Co.,Ltd and CN-CERT that one of Wellintech&#8217;s products had a very serious security vulnerability, and that if properly leveraged would allow an attacker to exploit the bug and execute arbitrary code.</li>
<li><a href="http://research.zscaler.com/2011/01/alexa-illustrates-web-security-risks.html?">Alexa Illustrates Web Securities Risks (part 1)</a> &#8211; research.zscaler.com<br />
I recently needed to look at some Alexa data related to their tracking of the top web domains visited for a side project that I was working on.</li>
<li><a href="http://blog.c22.cc/2011/01/13/sudo-g-privilege-escalation-cve-2011-0010/">Sudo -g privilege escalation (CVE-2011-0010)</a> &#8211; blog.c22.cc<br />
I noticed this bug come across the wire earlier today and thought I’d take a few minutes to take a look.</li>
<li><a href="http://www.swende.se/index.php/2010/12/dumping-the-rmi-registry-with-nmap/">Dumping the RMI Registry with NMAP</a> &#8211; www.swende.se<br />
A while ago, I wrote a NSE script to a Java RMI Registry and dump out information about the objects in the registry. This is a blog-post to shed some light on NSE-development in general and that script in particular.</li>
<li><a href="http://www.troyhunt.com/2011/01/continuous-web-application-security.html">Continuous Web Application Security Scanning With Netsparker and TeamCity</a> &#8211; troyhunt.com<br />
One of the problems with software security is that it’s easy for it to appear a bit like black magic, or at least like an entirely foreign industry to software development.</li>
<li><a href="http://blog.didierstevens.com/2011/01/12/heaplocker-nop-sled-detection/">HeapLocker: NOP Sled Detector</a> &#8211; blog.didierstevens.com<br />
When you enable NOP sled monitoring, HeapLocker will create a new thread to periodically check (every second) newly committed virtual pages that are readable and writable.</li>
</ul>
<p><strong>Vendor/Software Patches</strong></p>
<ul>
<li>Microsoft Black Tuesday
<ul>
<li><a href="http://www.ghacks.net/2011/01/12/microsoft-security-bulletin-overview-january-2011/">Microsoft Security Bulletin Overview</a> &#8211; ghacks.net<br />
The second Tuesday of a month is Microsoft’s patch day where the software company releases security patches and fixes for its products.</li>
<li><a href="http://isc.sans.edu/diary.html?storyid=10252">January 2011 Microsoft Black Tuesday Summary</a> &#8211; isc.sans.edu<br />
Happy New Year Everyone!   Here is the 2011 Black Tuesday kick off with only two patches.  Enjoy!</li>
</ul>
</li>
</ul>
<p><strong>Other News</strong></p>
<ul>
<li><a href="http://io9.com/5731328/10-devious-new-ways-that-computer-hackers-can-control-your-machines-or-fix-them">10 Devious New Ways That Computer Hackers Can Take Control of Your Machines or Fix Them</a> &#8211; i09.com<br />
Straight from CCC, here are ten ways hackers will subvert your computer, phone, bank card, and life in 2011.</li>
<li><a href="http://www.wired.com/threatlevel/2011/01/dancho-danchev-missing/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))">Security researcher, Cybercrime Foe Goes Missing</a> &#8211; wired.com<br />
A well-known security researcher and cybercrime foe appears to have gone missing in Bulgaria and is feared harmed, according to a news organization that hosts a blog the researcher co-writes.</li>
</ul>
<ul>
<li><a href=" http://krebsonsecurity.com/2011/01/exploit-packs-run-on-java-juice/?">Exploit Packs Run On Java Juice</a> &#8211; krebsonsecurity.com<br />
Today, I’ll highlight a few more recent examples of this with brand new exploit kits on the market, and explain why even fully-patched Java installations are fast becoming major enablers of browser-based malware attacks.<a href="http://krebsonsecurity.com/2011/01/exploit-packs-run-on-java-juice/?"></a></li>
<li><a href="http://jeremiahgrossman.blogspot.com/2011/01/application-security-spending-conundrum.html?">The Application Security Spending Conundrum</a> &#8211; jeremiahgrossman.blogspot.com<br />
To obtain a quote, the online insurer asked my age, where I lived, how much I drive and where, the year, make, and model of my cars, about my driving record, and how much coverage I wanted.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1414&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/01/19/week-2-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 1 in Review &#8211; 2011</title>
		<link>http://infosecevents.net/2011/01/10/week-1-in-review-2011/</link>
		<comments>http://infosecevents.net/2011/01/10/week-1-in-review-2011/#comments</comments>
		<pubDate>Mon, 10 Jan 2011 11:28:10 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Hacking Contests]]></category>
		<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[DerbyCon]]></category>
		<category><![CDATA[ShmooCon]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1408</guid>
		<description><![CDATA[Events Related: Derbycon I will admit there is limited spacing, we rented the entire second floor of the Hyatt and tickets will go fast. new hacker con, hell of speaker list: DerbyCon &#8211; reddit.com Derbycon Teaser Video and website launch date announced &#8211; secmaniac.com ShmooCon CTF Warmup 2011 &#8211; cylab.cmu.edu A couple of PPP members [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li>Derbycon<a href="http://www.reddit.com/r/netsec/comments/evh17/a_new_hacker_con_hell_of_speaker_list_derbycon/"><br />
</a> I will admit there is limited spacing, we rented the entire second floor of the Hyatt and tickets will go fast.</p>
<ul>
<li><a href="http://www.reddit.com/r/netsec/comments/evh17/a_new_hacker_con_hell_of_speaker_list_derbycon/">new hacker con, hell of speaker list: DerbyCon</a> &#8211; reddit.com</li>
<li><a href="http://www.secmaniac.com/january-2011/derbycon-teaser-video-and-website-launch-date-announced/">Derbycon Teaser Video and website launch date announced</a> &#8211; secmaniac.com</li>
</ul>
</li>
<li>
<div id="_mcePaste"><a href="http://ppp.cylab.cmu.edu/wordpress/?p=410">ShmooCon CTF Warmup 2011</a> &#8211; cylab.cmu.edu</div>
<div id="_mcePaste">A couple of PPP members (awesie, tylerni7) participated in the ShmooCon CTF Warmup. It was lots of fun and awesie got the prize! We also figured we should post a write-up for #3.</div>
</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://ossmann.blogspot.com/2011/01/ubertooth-video-and-news.html">Ubertooth video and news</a> &#8211; ossman.blogspot.com<br />
This will be a longer presentation telling the complete story of the development of Project Ubertooth and demonstrating new capabilities of the platform (hopefully with working Ubertooth One prototypes).</li>
<li><a href="http://www.readwriteweb.com/cloud/2011/01/how-to-deploy-ipv6-securely.php">How To Deploy IPv6 Securely</a> &#8211; readwriteweb.com<br />
The number of available IPv4 addresses is expected to run out in less than a year, as we&#8217;ve reported before.</li>
<li><a href="http://www.iphonedevwiki.net/index.php/MobileSubstrate">MobileSubstrate wiki </a>- iphonedevwiki.net<br />
MobileSubstrate consists of 3 major components: MobileHooker, MobileLoader and safe mode.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://sourceforge.net/projects/ssldiagnos/">SSL Diagnos is used to get information about SSL usage</a> &#8211; sourceforge.net/projects/ssldiagnos/<br />
It can also be used for testing and rating ciphers on SSL clients. It has also specific support for pop3s, sip, smtp and explicit ftps.</li>
<li><a href="http://www.vulnerabilitydatabase.com/toolswatch/2011/01/07/nessus-viewer-v1-0-0-released/">Nessus Viewer v1.0.0 released</a> &#8211; vulnerabilitydatabase.com<br />
Nessus Viewer enables IT Security auditors and penetration testers to quickly navigate inside Nessus reports by sorting and filtering each entry.</li>
<li><a href="http://chaptersinwebsecurity.blogspot.com/2011/01/r-u-dead-yet-version-21.html">R-U-Dead-Yet Version 2.1 </a>- chaptersinwebsucirity.blogspot.com<br />
The forms and their post action url&#8217;s are now parsed correctly. So here comes v2.1 with the bug fix.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://www.secmaniac.com/january-2011/windows-uac-bypass-now-in-metasploit/">Windows UAC Bypass now in Metasploit!</a> &#8211; secmaniac.com<br />
The Windows UAC bypass was committed to the Metasploit Framework today.</li>
<li>Flash Player Sandbox bypass<br />
Unfortunately, these restrictions are not the same as, “cannot communicate with the network in any way” which is what is stated in the documentation.</p>
<ul>
<li><a href="http://xs-sniper.com/blog/2011/01/04/bypassing-flash%E2%80%99s-local-with-filesystem-sandbox/">Bypassing Flash’s local-with-filesystem Sandbox</a> &#8211; xs-sniper.com</li>
<li><a href="http://www.h-online.com/security/news/item/Flash-Player-sandbox-can-be-bypassed-1164376.html">Flash Player sandbox can be bypassed</a> &#8211; h-online.com</li>
</ul>
</li>
<li><a href="http://blog.c22.cc/2011/01/09/metasploit-sap-management-console-aux-modules/">Metasploit SAP Management Console AUX Modules</a> &#8211; blog.c22.cc<br />
I see no ethical issue in releasing the information gathering modules that take advantage of this bug, as quite honestly, anybody with an SAP system and tcpdump could find this in a few minutes.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="Apple releases Mac OS X 10.6.6 update - Update">Apple releases Mac OS X 10.6.6 update</a> &#8211; h-online.com<br />
Apple has now posted its detailed About the Mac OS X v10.6.6 Update knowledge base article.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>Dell Acquisition of Secureworks<br />
Dell announced they are acquiring SecureWorks, the MSSP, for an undisclosed sum.</p>
<ul>
<li><a href="http://securosis.com/blog/hpens-envy-dell-buys-secureworks/">HP(en!s) Envy: Dell Buys SecureWorks</a> &#8211; securosis.com</li>
<li><a href="http://www.h-online.com/security/news/item/Dell-to-acquire-SecureWorks-1163365.html">Dell to acquire SecureWorks</a> &#8211; h-online.com</li>
</ul>
</li>
<li>Car Theft thru hacking<br />
Car thieves of the future might be able to get into a car and drive away without forced entry and without needing a physical key.</p>
<ul>
<li><a href="http://www.technologyreview.com/computing/27037/?p1=A1&amp;a=f">Car Theft by Antenna</a> &#8211; technologyreview.com</li>
<li><a href="http://snosoft.blogspot.com/2011/01/hacking-your-car-for-fun-and-profit.html">Hacking your car for fun and profit</a> &#8211; snosoft.blogspot.com</li>
</ul>
</li>
<li><a href="http://www.networkworld.com/community/blog/us-revamps-science-technology-standard-settin">US revamps science, technology standard-setting efforts</a> &#8211; networkworld.com<br />
The NIST has been given new marching orders: expand work with the private sector to develop standards for a range of key technologies such as cloud computing, emergency communications and tracking, green manufacturing and high performance green building construction.</li>
<li><a href="http://www.securityweek.com/researchers-hack-internet-enabled-tvs-discover-multiple-security-vulnerabilities?fb">Researchers Hack Internet Enabled TVs, Discover Multiple Security Vulnerabilities</a> &#8211; securityweek.com<br />
Security researchers have discovered several security flaws in one of the best-selling brands of Internet-connected HDTVs, and believe it’s likely that similar security flaws exist in other Internet TVs.</li>
<li><a href="http://www.readwriteweb.com/cloud/2011/01/researcher-developbrute-force.php">Researcher Develops Password Hacking Software for Wi-Fi Networks Using Amazon Web Services</a> &#8211; readwriteweb.com<br />
A researcher has developed software for breaking password protections used for wireless networks.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1408&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2011/01/10/week-1-in-review-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Week 50 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/12/20/week-50-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/12/20/week-50-in-review-2010/#comments</comments>
		<pubDate>Mon, 20 Dec 2010 10:59:30 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[BayThreat]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[DojoCon]]></category>
		<category><![CDATA[RUXCON]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1379</guid>
		<description><![CDATA[Events Related: RSnake, Web Security and a few beers &#8211; andlabs.org Reminiscing Black Hat Abu Dhabi. DojoCon Follow-Up &#8211; novainfosecportal.com Although there was a formal CFP, everything else followed a traditional unconference format. SANS SEC660: Post Mortem &#8211; c22.cc The class is designed to cover the ground between the SEC560 Network Penetration Testing class and [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://blog.andlabs.org/2010/12/rsnake-web-security-and-few-beers.html">RSnake, Web Security and a few beers</a> &#8211; andlabs.org<br />
Reminiscing Black Hat Abu Dhabi.</li>
<li><a href="http://www.novainfosecportal.com/2010/12/15/dojocon-follow-up/">DojoCon Follow-Up</a> &#8211; novainfosecportal.com<br />
Although there was a formal CFP, everything else followed a traditional unconference format.</li>
<li><a href="http://blog.c22.cc/2010/12/19/sans-sec660-post-mortem/">SANS SEC660: Post Mortem</a> &#8211; c22.cc<br />
The class is designed to cover the ground between the SEC560 Network Penetration Testing class and the SEC709/710 that Stephen Sims has been running for a while now (Exploit development).</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://xs-sniper.com/blog/2010/12/17/will-it-blend/">Will it Blend?</a> &#8211; xs-sniper.com<br />
I’m always humbled when I learn of what others are doing in the security community and even more humbled when asked to present.</li>
<li><a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos">DOJOCON 2010 Videos</a> &#8211; irongeek.com<br />
Below are the videos from the conference, at least the ones I can show <img src='http://infosecevents.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> , enjoy.</li>
<li><a href="http://cir.recurity.com/wiki/Default.aspx?Page=MainPage&amp;AspxAutoDetectCookieSupport=1">IOS Crash Analysis and Rootkit Wiki</a> &#8211; recurity.com<br />
Almost everything you need to know about Cisco IOS Forensics</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://research.microsoft.com/pubs/141930/tr.pdf">Zozzle: Low-overhead Mostly Static JavaScript Malware Detection</a> &#8211; microsoft.com<br />
In this paper, we propose ZOZZLE, a low-overhead solution for detecting and preventing JavaScript malware that can be deployed in the browser.</li>
<li><a href="http://code.google.com/p/websecurify/downloads/list">Websecurify 0.8Alpha4</a> &#8211; code.google.com/p/websecurify/<br />
Websecurify is a powerful web application security testing platform designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies.</li>
<li>All about Heaplocker<br />
HeapLocker allows you to set a maximum to the amount of private virtual memory a process is using. If the maximum is exceeded, HeapLocker will suspend the process and inform the user.</p>
<ul>
<li><a href="http://blog.didierstevens.com/2010/12/14/heaplocker-private-memory-usage-monitoring/">HeapLocker: Private Memory Usage Monitoring</a> &#8211; didierstevens.com</li>
<li><a href="http://threatpost.com/en_us/blogs/heaplocker-tool-protects-against-heap-spray-attacks-121410">HeapLocker Tool Protects Against Heap-Spray Attacks</a> &#8211; threatpost.com</li>
</ul>
</li>
<li><a href="http://www.netglub.org/">Netglub</a> &#8211; netglub.org<br />
Really Open Source Information Gathering</li>
<li><a href="http://google-gruyere.appspot.com/">Gruyere</a> &#8211; google-gruyere.appspot.com<br />
This codelab is built around Gruyere &#8211; a small, cheesy web application that allows its users to publish snippets of text and store assorted files.</li>
<li><a href="http://blog.metasploit.com/2010/12/metasploit-framework-351-released.html">Metasploit Framework 3.5.1 Released!</a> &#8211; metasploit.com<br />
This minor version release adds 47 new modules, including exploit covereage for recent bugs in the news: Exim4, Internet Explorer, and ProFTPd.</li>
<li><a href="http://www.getmantra.com/download/index.html">Mantra Security Toolkit</a> &#8211; getmantra.com<br />
The Mantra is a powerful set of tools to make the attacker&#8217;s task easier. The alpha version of Mantra contains following tools built into it.</li>
<li><a href="https://github.com/koto/squid-imposter/archives/master">Squid-Imposter</a> &#8211; github.com/koto/squid-imposter/<br />
Squid-imposter makes it easy to create Squid based proxy injecting your own content to chosen website URLs.</li>
<li><a href="http://i8jesus.com/?p=191">pwnshell – a better jsp shell</a> &#8211; i8jesus.com<br />
The world needs a JSP shell that really helps a blackbox attacker pivot to important assets, so I took a stab at it. It’s called quite lamely called pwnshell.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://blog.andlabs.org/2010/12/port-scanning-with-html5-and-js-recon.html">Port Scanning with HTML5 and JS-Recon</a> &#8211; andlabs.org<br />
Since even closed ports can be identified we can extend this technique to perform network scanning as well as internal IP detection.</li>
<li><a href="http://blog.metasploit.com/2010/12/capturing-windows-logons-with.html">Capturing Windows Logons with Smartlocker</a> &#8211; metasploit.com<br />
One of the most effective ways to capture the clear-text user password from a compromised Windows machine is through the &#8220;keylogrecorder&#8221; Meterpreter script.</li>
<li><a href="http://www.sectechno.com/2010/12/14/attacking-windows-operating-system-over-powershell/">Attacking Windows Operating System over PowerShell</a> &#8211; sectechno.com<br />
Now if you are on a penetration testing mission you start by running nmap searching for the live windows hosts on the network basically with 1433 active port (Mssql).</li>
<li><a href="http://www.skullsecurity.org/blog/2010/watch-out-for-exim">Watch out for exim!</a> &#8211; skullsecurity.org<br />
My strategy was to keep running ‘make’ and fixing what it complained about until it shut up and compiled.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/438">Conducting a Phishing Campaign in Metasploit Pro</a> &#8211; carnal0wnage.attackresearch.com<br />
Only gripe is the lack of configuration ability in the exploit payload section. I&#8217;ve been told this will be addressed shortly even though a lot of work has been put into smart defaults the ability to change it when necessary would be nice.</li>
<li><a href="http://intrepidusgroup.com/insight/2010/12/mallory-and-me-setting-up-a-mobile-mallory-gateway/">Mallory and Me: Setting up a Mobile Mallory Gateway</a> &#8211; intrepidusgroup.com<br />
Improving the user experience from the initial code checkout to helping users “Mallorize” traffic is a key goal for the project.</li>
<li><a href="http://carnal0wnage.attackresearch.com/node/439">Metasploit and VNC Password Bruteforcing</a> &#8211; carnal0wnage.attackresearch.com
<div id="_mcePaste">You probably missed it but jduck recently snuck in a VNC mixin and vnc_login module to the trunk.</div>
</li>
</ul>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Ouch! HP Storage Device Admin Credentials Hardcoded, Security Experts Facepalm<br />
Hewlett Packard said in a statement that it has identified a &#8220;potential security issue&#8221; with one of its storage area networking (SAN) products and is readying a fix for the issue.</p>
<ul>
<li><a href="http://isc.sans.edu/diary.html?storyid=10090">HP StorageWorks P2000 G3 MSA hardcoded user</a> &#8211; sans.edu</li>
<li><a href="http://threatpost.com/en_us/blogs/hp-storage-hardware-harbors-secret-back-door-121510">HP Storage Hardware Harbors Secret Back Door</a> &#8211; threatpost.com</li>
</ul>
</li>
<li>MS Bulletins
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-090.mspx?pubDate=2010-12-14">Microsoft Security Bulletin MS10-090 &#8211; Critical</a> &#8211; microsoft.com</li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-091.mspx?pubDate=2010-12-14">Microsoft Security Bulletin MS10-091 &#8211; Critical</a> &#8211; microsoft.com</li>
</ul>
</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li>Patch Tuesday cometh<br />
As part of our usual cycle of monthly security updates, today Microsoft is releasing 17 bulletins addressing 40 vulnerabilities in Microsoft Windows, Office, Internet Explorer, SharePoint Server and Exchange.</p>
<ul>
<li><a href="http://blogs.technet.com/b/msrc/archive/2010/12/14/december-2010-security-bulletin-release.aspx">December 2010 Security Bulletin Release</a> &#8211; technet.com</li>
<li><a href="http://www.symantec.com/connect/de/blogs/microsoft-patch-tuesday-december-2010">Microsoft Patch Tuesday &#8211; December 2010</a> &#8211; symantec.com</li>
<li><a href="http://krebsonsecurity.com/2010/12/microsoft-patches-40-security-holes/">Microsoft Patches 40 Security Holes</a> &#8211; krebsonsecurity.com</li>
<li><a href="http://threatpost.com/en_us/blogs/microsoft-closes-door-stuxnet-december-patch-121410">Microsoft Closes Door on Stuxnet with December Patch</a> &#8211; threatpost.com</li>
</ul>
</li>
<li><a href="http://www.h-online.com/security/news/item/Over-500-patches-for-SAP-1153061.html">Over 500 patches for SAP</a> &#8211; h-online.com<br />
On Tuesday, SAP – one of the largest manufacturers of business applications and enterprise software – released a huge number of so-called Security Notes.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li>Gawker hacked linked to Acai berry spam in Twitter<br />
Over the weekend, up to 1.3 million passwords were stolen off of Gawker&#8217;s servers by a hacker group called Gnosis and then publicly shared on torrent site The Pirate Bay, for anyone and everyone to download.</p>
<ul>
<li><a href="http://nakedsecurity.sophos.com/2010/12/13/acai-berry-spam-gawker-password-hack-twitter/">Acai Berry spam attack connected with Gawker password hack, says Twitter</a> &#8211; sophos.com</li>
<li><a href="http://latimesblogs.latimes.com/technology/2010/12/gawker-websites-and-twitter-hacked-and-spammed-by-gnosis.html">Gawker websites, Twitter hacked and spammed by &#8216;Gnosis&#8217;</a> &#8211; latimes.com</li>
<li><a href="http://www.wired.com/threatlevel/2010/12/gawker-hacked/">Gawker Media Websites Hacked, Staff and User Passwords Leaked</a> &#8211; wired.com</li>
<li><a href="http://www.readwriteweb.com/archives/twitter_spam_attack_tied_to_gawker_security_breach.php">Twitter Spam Attack Tied to Gawker Security Breach</a> &#8211; readwriteweb.com</li>
<li><a href="http://lifehacker.com/5712785/faq-compromised-commenting-accounts-on-gawker-media">FAQ: Compromised Commenting Accounts on Gawker Media</a> &#8211; lifehacker.com</li>
<li><a href="http://www.google.com/fusiontables/DataSource?dsrcid=350662">Gawker hacked, 1.3m passwords stolen, 540k w/email addresses, check this table for yours: http://bit.ly/gYMsr</a> &#8211; @hdmoore, twitter.com</li>
<li><a href="http://blogs.wsj.com/digits/2010/12/13/the-top-50-gawker-media-passwords/">The Top 50 Gawker Media Passwords</a> &#8211; wsj.com</li>
<li><a href="http://blog.metasploit.com/2010/12/semipublic-password-dumps.html">Semipublic Password Dumps</a> &#8211; metasploit.com</li>
<li><a href="http://intrepidusgroup.com/insight/2010/12/gawker-des-crypt-fun-using-john-the-ripper-with-mpi/">Gawker: DES crypt fun using John the Ripper with MPI</a> &#8211; intrepidusgroup.com</li>
<li><a href="http://www.reddit.com/r/netsec/comments/elsur/how_can_i_encrypt_my_own_passwords_so_they_look/">How can I encrypt my own passwords so they look like the gawker full_db.txt dump, so I know what password the internet has of mine?</a> &#8211; reddit.com</li>
</ul>
</li>
<li><a href="https://threatpost.com/en_us/blogs/major-ad-networks-found-serving-malicious-ads-121210">Major Ad Networks Found Serving Malicious Ads</a> &#8211; threatpost.com<br />
Two major online ad networks&#8211;DoubleClick and MSN&#8211;were serving malware via drive-by download exploits over the last week, experts say, after a group of attackers was able to trick the networks into displaying their ads by impersonating an online advertising provider.</li>
<li><a href="http://intrepidusgroup.com/insight/2010/12/jailbreaks-iphone-ipad-and-mdm/">Jailbreaks, iPhone, iPad, and MDM</a> &#8211; intrepidusgroup.com<br />
This article will start with device security and gradually focus outward to a discussion on MDM. Today we will also make some comments on the thorny issue of jailbroken iOS devices.</li>
<li><a href="http://asert.arbornetworks.com/2010/12/the-internet-goes-to-war/">The Internet Goes to War</a> &#8211; arbornetworks.com<br />
In general, getting accurate data about Internet attacks can be a challenge. Namely, a) companies avoid publicly discussing most attacks and b) the attacks can be difficult to measure or at least consistently compare.</li>
<li><a href="http://www.net-security.org/secworld.php?id=10333">NSA considers its networks compromised</a> &#8211; net-security.org<br />
The problem with cyber defense &#8211; especially when it comes to attacks backed by governments and intelligence organizations &#8211; is that attackers are usually highly motivated and often very well funded.</li>
<li><a href="http://www.itnews.com.au/News/242051,un-mulls-internet-regulation-options.aspx">UN mulls internet regulation options</a> &#8211; itnews.com.au<br />
The United Nations is considering whether to set up an inter-governmental working group to harmonise global efforts by policy makers to regulate the internet.</li>
<li><a href="http://www.zeropaid.com/news/91588/why-the-us-government-attacking-wikileaks-is-a-bad-idea/">Why the US Government Attacking Wikileaks is a Bad Idea</a> &#8211; zeropaid.com<br />
Whatever your take on this hot button topic is, few would argue that this story hasn’t caught a huge amount of international attention and draws a seemingly unprecedented amount of attention to the internet.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/12/why-speed-frequency-of-software.html">Why Speed &amp; Frequency of Software Security Testing Matter, A LOT</a> &#8211; jeremiahgrossman.blogspot.com<br />
Therefore the speed and frequency of the testing process whether going with dynamic scanning, binary analysis, pen-testing, static analysis, line-by-line source code review, etc. matters a great deal.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1379&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/12/20/week-50-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Week 49 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/12/13/week-49-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/12/13/week-49-in-review-2010/#comments</comments>
		<pubDate>Mon, 13 Dec 2010 15:17:40 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Conferences]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[BayThreat]]></category>
		<category><![CDATA[CanSecWest]]></category>
		<category><![CDATA[Confidence]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[OWASP Benelux]]></category>
		<category><![CDATA[SOURCE]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1370</guid>
		<description><![CDATA[Events Related: OWASP BeNeLux Day 2010 Wrap Up &#8211; rootshell.be Yesterday, the three OWASP Benelux chapters organized together their annual OWASP BeNeLux day. Ok folks, secwest11@cansecwest.com is live and the countdown timer goes to December 29th for entries to CanSecWest 2011 Call For Papers &#8211; twitter.com, @dragosr BayThreat was awesome, do it again! &#8211; mckeay.net Which [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Events Related:</strong></p>
<ul>
<li><a href="http://blog.rootshell.be/2010/12/03/owasp-benelux-day-2010-wrap-up/">OWASP BeNeLux Day 2010 Wrap Up</a> &#8211; rootshell.be<br />
Yesterday, the three OWASP Benelux chapters organized together their annual OWASP BeNeLux day.</li>
<li><a href="http://twitter.com/dragosr/statuses/13377375387516928">Ok folks, secwest11@cansecwest.com is live and the countdown timer goes to December 29th for entries to CanSecWest 2011 Call For Papers</a> &#8211; twitter.com, @dragosr</li>
<li><a href="http://www.mckeay.net/2010/12/12/baythreat-was-awesome-do-it-again/">BayThreat was awesome, do it again!</a> &#8211; mckeay.net<br />
Which is why smaller, local events like BayThreat, DojoCon and BSides are becoming so important to security professionals around the globe; the ability to go to a small, local event far outstrips the cost to value ratio of any of the big cons and it’s so much easier to actually see the speakers you want to see.</li>
</ul>
<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.ethicalhacker.net/content/view/342/24/">Course Review: Cracking the Perimeter by Offensive Security</a> &#8211; ethicalhacker.net<br />
Building on material in the earlier course, Pentesting with Backtrack (PWB &#8211; Read Review), this offering provides intermediate students with a learning platform that can be used to become advanced practitioners of certain exploit methodologies.</li>
<li><a href="http://www.iseclab.org/papers/bilge-ndss11.pdf">EXPOSURE: Finding Malicious Domains Using Passive DNS Analysis</a> &#8211; iseclab.org<br />
Our paper on detecting malicious domains by passively analyzing DNS is now online.</li>
<li><a href="http://www.renesys.com/tech/presentations/DNS-Tampering-and-Root-Servers.pdf">DNS Tampering and Root Servers</a> &#8211; renesys.com<br />
Enable DNSSEC. Don&#8217;t pass your queries across the GFW (if you can help it). If your government requires DNS-based technical controls, install them at the resolver.</li>
<li><a href="http://www.securityaegis.com/neurosurgery-with-meterpreter/">Neurosurgery with Meterpreter</a> &#8211; securityaegis.com<br />
Really thought provoking talk by Colin Ames from Attack Research on meterpreter manipulation of memory and processes (SOURCE Boston 2010).</li>
<li><a href="http://www.verizonbusiness.com/resources/whitepapers/wp_escapingmicrosoftprotectedmodeinternetexplorer_en_xg.pdf">Escaping from Microsoft’s Protected Mode Internet Explorer</a> &#8211; verizonbusiness.com<br />
The level of protection offered by Protected Mode Internet Explorer ® is not well understood and there are common misconceptions about its status as a security feature.</li>
<li><a href="https://websec.wordpress.com/2010/12/04/sqli-filter-evasion-cheat-sheet-mysql/">SQLi filter evasion cheat sheet (MySQL)</a> &#8211; websec.wordpress.com<br />
This week I presented my experiences in SQLi filter evasion techniques that I have gained during 3 years of PHPIDS filter evasion at the CONFidence 2.0 conference.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://blog.didierstevens.com/2010/12/01/runasil/">Runasil</a> &#8211; didierstevens.com<br />
Because I didn’t find a program to start an application with a given integrity level from “Image File Execution Options”, I wrote runasil.</li>
<li><a href="http://i8jesus.com/?p=227">JavaSnoop 1.0 FINAL released!</a> &#8211; i8jesus.com<br />
After 6 release candidates, roughly a thousand bugs fixed, dozens of improvements and features added, I finally think the tool is ready for general availability.</li>
<li><a href="http://code.google.com/p/j0llydmper/">j0llydmper</a> &#8211; code.google.com/p/j0llydmper/<br />
j0llydmper is a windows service that allows you to dump furtively and automaticaly some content of USB disks just plugged in your computer.</li>
<li><a href="http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project">OWASP Zed Attack Proxy Project</a> &#8211; owasp.org<br />
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.</li>
<li><a href="http://www.fastandeasyhacking.com/download">Armitage 12.06.10</a> &#8211; fastandeasyhacking.com<br />
Armitage is a graphical cyber attack management tool for Metasploit that visualizes your targets, recommends exploits, and exposes the advanced capabilities of the framework.</li>
<li><a href="http://code.google.com/p/skipfish/">skipfish-1.82b</a> &#8211; code.google.com/p/skipfish<br />
A fully automated, active web application security reconnaissance tool.</li>
<li><a href="http://blog.kaffenews.com/?p=1700">Zozzle (Microsoft’s Javascript-Malware Analysis Tool)</a> &#8211; kaffenews.com<br />
In a sentence Zozzle is a static web-page analyzer for detecting ‘Heap-Spray Exploits’.</li>
<li><a href="http://www.digifail.com/software/bluelog.shtml">Bluelog v0.9.8</a> &#8211; digifail.com<br />
Bluelog is a Linux Bluetooth scanner written to do a single task, log devices that are in discoverable mode. It is intended to be used as a site survey tool, determining how many discoverable Bluetooth devices there are in a given environment.</li>
<li><a href="http://sourceforge.net/projects/hyenae/">Hyenae v0.35-3</a> &#8211; sourceforge.net/projects/hyenae<br />
Hyenae is a highly flexible platform independent network packet generator. It allows you to reproduce several MITM, DoS and DDoS attack scenarios, comes with a clusterable remote daemon and an interactive attack assistant.</li>
<li><a href="http://www.vmware.com/support/developer/ovf/">OVF Tool Documentation</a> &#8211; vmware.com<br />
VMware OVF Tool is a command-line utility that allows you to import and export OVF packages to and from a wide variety of VMware platform products.</li>
<li><a href="http://blog.layeredsec.com/2010/12/vidigger-v10-vmware-configuration.html">VIDigger v1.0</a> &#8211; layeredsec.com<br />
VIDigger is designed to help administrators check the configuration of ESX server and the virtual machines hosted on ESX server against the VMware Infrastructure Hardening guide and other best practices.&#8221;</li>
<li><a href="http://code.google.com/p/beef/">Browser Exploitation Framework v.0.4.2</a> &#8211; code.google.com/p/beef/<br />
It allows the experienced penetration tester or system administrator additional attack vectors when assessing the posture of a target.</li>
<li><a href="http://code.google.com/p/owasp-dos-http-post/">owasp-dos-http-post</a> &#8211; code.google.com/p/owasp-dos-http-post/<br />
This tool was created and released GPLv3 Open Source for performance testing of systems and controls.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://spareclockcycles.org/2010/11/21/the-usb-stick-o-death/">The USB Stick O&#8217; Death</a> &#8211; spareclockcycles.org<br />
I&#8217;ve recently been researching and experimenting with USB malware, and I wanted to take a shot at developing my own malicious USB stick.</li>
<li><a href="http://spareclockcycles.org/2010/11/27/avoiding-av-detection/">Avoiding AV Detection</a> &#8211; spareclockcycles.org<br />
My main goal in this research was to see how much effort it would take to become undetectable again, and the answer was &#8216;virtually none&#8217;.</li>
<li><a href="http://www.acunetix.com/blog/web-security-zone/articles/dom-xss/">DOM based Cross-site Scripting vulnerabilities</a> &#8211; acunetix.com<br />
Like server-side scripts, client-side scripts can also accept user input which can contain malicious code.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/12/internet-explorer-9-ad-blocking-via.html">Internet Explorer 9 ad blocking via &#8220;Tracing Protection&#8221; &#8212; no means yes.</a> &#8211; jeremiahgrossman.blogspot.com<br />
User configurations will also be persistent across sessions, even when the browser is restarted, which is opposite to how InPrivate mode behaves. This is huge!</li>
<li><a href="http://www.digitalbond.com/index.php/2010/12/08/quick-and-easy-oracle-default-password-enumeration/">Quick and Easy Oracle Default Password Enumeration</a> &#8211; digitalbond.com<br />
For the purpose of this post, the SID enumeration and default account/password auditing are the most important features of oscanner.</li>
<li><a href="http://blog.crackpassword.com/2010/12/blackberry-password-cracking-multi-threaded-with-hardware-accelerated-aes/">BlackBerry password cracking: multi-threaded, with hardware-accelerated AES</a> &#8211; crackpassword.com<br />
The reason is pretty simple: we are not able to generate passwords that fast, especially when we perform all those nice mutations of wordlists passwords (changing the letter case, adding or replacing symbols etc).</li>
<li><a href="http://lcamtuf.blogspot.com/2010/12/firefox-3613-damn-you-corner-cases.html">Firefox 3.6.13: damn you, corner cases</a> &#8211; lcamtuf.blogspot.com<br />
As you may recall, one of the more significant shortcomings of the same-origin policy is that it does not give any guidance on handling documents with no inherent origin associated &#8211; that is, it fails to account for all the content coming from about:, data:, file:, and similar pseudo-URLs.</li>
<li><a href="http://blogs.technet.com/b/srd/archive/2010/12/08/on-the-effectiveness-of-dep-and-aslr.aspx">On the effectiveness of DEP and ASLR</a> &#8211; technet.com<br />
DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization) have proven themselves to be important and effective countermeasures against the types of exploits that we see in the wild today.</li>
<li><a title="Permalink to More updates (including RAR)" href="http://www.golubev.com/blog/?p=166">More updates (including RAR)</a> &#8211; golubev.com<br />
Obviously it isn’t possible to reach with 83.5% utilization, so I’ve made some tests with 5xMD5 again and this time speed-up is here.</li>
</ul>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://www.elcomsoft.com/canon.html?r1=pr&amp;r2=canon">Canon Original Data Security System Vulnerability</a> &#8211; elcomsoft.com<br />
The credibility of photographic evidence becomes vital in numerous situations for insurance companies and courts, as they may accept digital image as indisputable evidence if it can be proven genuine.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/New-version-of-OpenSSL-fixes-two-vulnerabilities-1150044.html">New version of OpenSSL fixes two vulnerabilities</a> &#8211; h-online.com<br />
A flaw in an older workaround for Netscape browsers and servers can be remotely exploited to make an OpenSSL server downgrade the ciphersuite to a weaker one for subsequent connections.</li>
</ul>
<p><strong>Other News: </strong></p>
<ul>
<li><a href="http://nakedsecurity.sophos.com/2010/11/30/large-us-hosting-provider-hit-in-web-attack/">Large US hosting provider hit in web attack</a> &#8211; sophos.com<br />
When innocent users browse these sites, the injected JavaScript adds an iframe element to the page in order to load further malicious content from a remote site.</li>
<li><a href="http://www.securelist.com/en/blog/208188038/Lab_Matters_The_Dark_Side_of_Jailbreaking_iPhones">Lab Matters: The Dark Side of Jailbreaking iPhones</a> &#8211; securelist.com<br />
In this Q&amp;A with Ryan Naraine, Raiu talks about the Jailbreakme.com vulnerability and exploit and the social engineering techniques used to take advantage of the popularity of jailbreaking utilities.</li>
<li>History stealing by ad networks has got everyone afluster<br />
Researchers have discovered that dozens of Web sites are using simple Javascript tricks to snoop into visitors’ Web browsing history.</p>
<ul>
<li><a href="http://www.h-online.com/security/news/item/History-stealing-for-ad-networks-1147735.html">History stealing for ad networks</a> &#8211; h-online.com</li>
<li><a href="http://krebsonsecurity.com/2010/12/what-you-should-know-about-history-sniffing/">What You Should Know About History Sniffing</a> &#8211; krebsonsecurity.com</li>
</ul>
</li>
<li><a href="http://gizmodo.com/5687689/how-anyone-can-fake-an-atm-and-steal-your-money">How Anyone Can Fake an ATM and Steal Your Money</a> &#8211; gizmodo.com<br />
But skimmers don&#8217;t exactly have an aisle at Wal-Mart. In this Gizmodo investigation, we take a look at the scary internet black market where fraudsters get their tools.</li>
<li><a href="http://research.zscaler.com/2010/12/top-abuses-of-open-web-proxies.html">Top Abuses of Open Web Proxies</a> &#8211; zscaler.com<br />
While there is nothing new or Earth-shattering in this post, I thought I&#8217;d share what I have seen as the top abuses of open web proxies &#8211; as this is an everyday occurrence involving a large volume of web transactions and is a constant annoyance on the Internet.</li>
<li><a href="http://owasp.blogspot.com/2010/12/owasp-40.html">OWASP 4.0</a> &#8211; owasp.blogspot.com<br />
The time has come to measure our success not by the number of members, projects, and conferences, but by whether we are succeeding at making the world’s software more secure.</li>
<li><a href="http://www.networkworld.com/news/2010/120710-chinese-internet-traffic-fix.html?hpg1=bn">Fix to Chinese Internet traffic hijack due in January</a> &#8211; networkworld.com<br />
Policymakers disagree about whether the recent Chinese hijacking of Internet traffic was malicious or accidental, but there&#8217;s no question about the underlying cause of this incident: the lack of built-in security in the Internet&#8217;s main routing protocol.</li>
<li><a href="http://threatpost.com/en_us/blogs/dhs-nist-financial-services-group-form-security-research-partnership-120910">DHS, NIST, Financial Services Group Form Security Research Partnership</a> &#8211; threatpost.com<br />
As the finger-pointing and name-calling surrounding the WikiLeaks issue continue in Washington, the White House this week facilitated a cooperative agreement among several key public and private organizations designed to spur joint information security research projects.</li>
<li><a href="http://www.itworld.com/legal/129947/net-censorship-dns-alternative">Gov&#8217;t crackdown spurs initiatives to route around DNS</a> &#8211; itworld.com<br />
The Net interprets censorship as damage and routes around it.</li>
<li><a href="http://www.veracode.com/blog/2010/12/veracode-research-team-gives-5-predictions-for-2011/">Veracode Research Team Gives 5 Predictions for 2011</a> &#8211; veracode.com<br />
As we close out an security eventful 2010, the Veracode research team though it would be a good idea to think about what we are likely to see happen in 2011.</li>
<li><a href="http://techcrunch.com/2010/12/09/us-military-bans-physical-media-to-curb-leaks/">US Military Bans Physical Media To Curb Leaks</a> &#8211; techcrunch.com<br />
Ironically, the news comes via a leaked memo obtained by Wired’s Danger Room that insists that everyone from grunts to techs “immediately cease use of removable media on all systems, servers, and stand alone machines residing on SIPRNET,” under pain of court-martial.</li>
<li><a href="http://gawker.com/5705461/23+year+old-russian-hacker-responsible-was-for-one+third-of-global-spam">23-Year-Old Russian Hacker Responsible Was for One-Third of Global Spam</a> &#8211; gawker.com<br />
It&#8217;s probably because of Oleg Nikolaenko, a 23-year-old who was recently arrested for flooding the world with 10 billion spam emails a day.</li>
<li><a href="http://gizmodo.com/5711788/apple-ditches-jailbreak-detection-api-in-ios">Apple Ditches Jailbreak Detection API in iOS</a> &#8211; gizmodo.com<br />
In a move that has been left totally unexplained, Apple has ditched its jailbreak detection API that it introduced to iOS about six months ago.</li>
<li><a href="http://www.networkworld.com/community/blog/apple-and-google-make-department-defense-jump">Apple and Google Make the Department of Defense Jump Through Hoops for Mobile Device Security</a> &#8211; networkworld.com<br />
Lack of cooperation forces DISA to find security workarounds in order to provide Android and iPhone support for soldiers.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1370&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/12/13/week-49-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Week 48 in Review &#8211; 2010</title>
		<link>http://infosecevents.net/2010/12/06/week-48-in-review-2010/</link>
		<comments>http://infosecevents.net/2010/12/06/week-48-in-review-2010/#comments</comments>
		<pubDate>Mon, 06 Dec 2010 14:27:44 +0000</pubDate>
		<dc:creator>Glenn Santos</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Security Vulnerabilities]]></category>
		<category><![CDATA[Security Workshops]]></category>
		<category><![CDATA[Vendor News]]></category>
		<category><![CDATA[7Safe]]></category>
		<category><![CDATA[EICAR]]></category>
		<category><![CDATA[RUXCON]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://infosecevents.net/?p=1360</guid>
		<description><![CDATA[Resources: Impersonating The Domain Administrator via SQL Server &#8211; commonexploits.com A recent presentation I gave for 7Safe. It demonstrates how it is possible to fully compromise the domain using a fully patched Microsoft SQL server that has a firewall enabled. RuxCon 2010 Materials &#8211; ruxcon.org.au Talk PDFs now posted. Nuff said. New SANS Course &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Resources:</strong></p>
<ul>
<li><a href="http://www.commonexploits.com/?p=238">Impersonating The Domain Administrator via SQL Server</a> &#8211; commonexploits.com<br />
A recent presentation I gave for 7Safe. It demonstrates how it is possible to fully compromise the domain using a fully patched Microsoft SQL server that has a firewall enabled.</li>
<li><a href="http://www.ruxcon.org.au/archive/2010-materials/">RuxCon 2010 Materials</a> &#8211; ruxcon.org.au<br />
Talk PDFs now posted. Nuff said.</li>
<li><a href="http://blog.layeredsec.com/2010/11/new-sans-course-advanced-penetration.html">New SANS Course &#8211; Advanced Penetration Testing, Exploits, and Ethical Hacking (SEC660)</a> &#8211; layeredsec.com<br />
I&#8217;m excited to announce a brand new course that Stephen Sims, Joshua Wright and myself have just completed. It is running for the first time in London this week and will be on the schedule in 2011 in numerous locations.</li>
<li><a href="http://www.ethicalhacker.net/content/view/341/2/">Tutorial: John the Ripper &#8211; Why You Are Doing It Wrong</a> &#8211; ethicalhacker.net<br />
In a professional penetration test, we don&#8217;t always have the time to allow JTR to run to completion, and we must rely on some additional techniques to speed things up including the use of wordlists or dictionaries.</li>
<li><a href="http://blog.sucuri.net/2010/11/yet-another-wordpress-security-post-part-one.html">Yet Another WordPress Security Post – Part One</a> &#8211; sucuri.net<br />
Information security is everyone’s responsibility, which means It starts with you. If you’re doing everything in your power to mitigate risk from your end, you’re less likely to end up with a website serving Viagra ads on Google.</li>
</ul>
<p><strong>Tools:</strong></p>
<ul>
<li><a href="http://www.sectechno.com/2010/11/30/two-new-http-post-attack-tools-released/">Two New HTTP POST Attack Tools Released</a> &#8211; sectechno.com<br />
Currently there is two free utility that may perform this attack d “R U Dead Yet?” and OWASP HTTP POST Tool tool offers unattended execution by providing the necessary parameters within a configuration file.</li>
<li><a href="https://github.com/SpiderLabs/thicknet">thicknet</a> &#8211; github.com/SpiderLabs/thicknet
<div id="_mcePaste">thicknet is a TCP session manipulation and take-over tool. The tool is</div>
<div id="_mcePaste">initially aimed at downgrading Oracle sessions and issuing SQL queries</div>
<div id="_mcePaste">using an already-established session. This is an early proof-of-concept,</div>
<div id="_mcePaste">version, but the basic concepts are there to write modules and do MITM</div>
<div id="_mcePaste">against a variety of protocols.</div>
</li>
<li><a href="http://grep8000.blogspot.com/2010/12/meterpreter-scripts-for-runas-privilege.html">Meterpreter scripts for RunAs privilege escalation &amp; other mischief</a> &#8211; grep8000.blogspot.com<br />
send_keystrokes.rb: Meterpreter script to interactively send keystrokes to an open application window using the vbscript SendKeys method. Can be used to escalate privileges into RunAs-invoked command shells on XP.</li>
<li><a href="http://code.google.com/p/sqlinject-finder/">sqlinject-finder</a> &#8211; code.google.com/p/sqlinject-finder/<br />
Simple python script that parses through a pcap and looks at the GET and POST request data for suspicious and possible SQL injects. Rules to check for SQL injection can be easily added. Output can be printed neatly on the command line or in tab delimited format.</li>
<li><a href="http://cvechecker.sourceforge.net/">cvechecker 2.0</a> &#8211; cvechecker.sourceforge.net/<br />
Version 2.0 is now available for this vulnerability  detection tool.</li>
<li><a href="http://code.google.com/p/javasnoop/">Javasnoop</a> &#8211; code.google.com/p/javasnoop/<br />
JavaSnoop attempts to solve this problem by allowing you attach to an existing process (like a debugger) and instantly begin tampering with method calls, run custom code, or just watch what&#8217;s happening on the system.</li>
<li><a href="http://grey0.wordpress.com/2010/12/04/social-engineering-ninja-v0-4-is-out/">Social-Engineering Ninja v0.4 is out!</a> &#8211; grey0.wordpress.com<br />
This is the new release of ninja phishing framework.</li>
</ul>
<p><strong>Techniques:</strong></p>
<ul>
<li><a href="http://blog.commandlinekungfu.com/2010/11/episode-123-bad-connections.html">Episode #123: Bad Connections</a> &#8211; commandlinekungfu.com<br />
Similar to last week, this week&#8217;s challenge comes from Tim&#8217;s friend who is mentoring a CCDC team. The mentor was interested in creating some shell fu that lets them monitor all network connections in and out of a system and get information about the executable that&#8217;s handling the local side of the connection.</li>
<li><a href="http://www.packetstan.com/2010/11/packet-payloads-encryption-and-bacon.html">Packet Payloads, Encryption and Bacon</a> &#8211; packetstan.com<br />
Over the years I’ve used a couple of techniques to evaluate the content of packet captures to determine if the traffic is encrypted or just obfuscated.</li>
<li><a href="http://blog.stalkr.net/2010/11/login-notifications-pamexec-scripting.html">Login notifications, pam_exec scripting</a> &#8211; stalkr.net<br />
If you like monitoring, you might want to receive notifications at every (or only root) login, in addition to logs.</li>
<li><a href="http://blog.fortinet.com/all-your-drives-are-belong-to-us/">All your drives are belong to us</a> &#8211; fortinet.com<br />
A new Ransomware module was recently discovered by Fortiguard Labs. When a machine infected with this Ransomware is restarted, the user is greeted with the following boot screen.</li>
<li><a href="http://grep8000.blogspot.com/2010/12/javascript-obfuscation-of-metasploit.html">JavaScript Obfuscation of Metasploit Browser Exploits for AV bypass</a> &#8211; grep8000.blogspot.com<br />
Bam. 0-day with AV bypass? Yeah, you&#8217;re on the pwnie express. :} Thanks to Will Metcalf for pointing me in the right direction!</li>
<li><a href="http://marcoramilli.blogspot.com/2010/12/windows-pe-header.html">Windows PE Header</a> &#8211; marcoramilli.blogspot.com<br />
Each executable file has a Common Object File Format COFF which is used from the OS loader to run the program. Windows Portable Executable (PE) is one of the COFF available in todays OS. For example the Executable Linking File (ELF) is the main Linux COFF.</li>
<li><a href="http://www.stratumsecurity.com/blog/2010/12/03/shearing-firesheep-with-the-cloud/">Shearing FireSheep with the Cloud</a> &#8211; stratumsecurity.com<br />
Enjoy surfing open wireless networks or hostile wired network securely!</li>
<li><a href="http://spl0it.wordpress.com/2010/12/02/internal-port-scanning-via-crystal-reports/">Internal Port Scanning via Crystal Reports</a> &#8211; spl0it.wordpress.com<br />
This is faster than using BeEF’s JavaScript internal portscanning functionality and it doesn’t require client interaction. Pwn dem v0hns!</li>
</ul>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li><a href="http://threatpost.com/en_us/blogs/exploit-code-out-new-windows-kernel-flaw-112910">Exploit Code Out For New Windows Kernel Flaw</a> &#8211; threatpost.com<br />
The new Windows kernel bug is considered a critical vulnerability, even though it can&#8217;t be exploited remotely, thanks to the fact that an attacker could use it gain powerful credentials on a compromised system and take complete control of the machine.</li>
</ul>
<p><strong>Vendor/Software Patches:</strong></p>
<ul>
<li><a href="http://www.darkreading.com/database-security/167901020/security/application-security/228400237/new-tool-patches-offline-vms.html">New Tool Patches Offline VMs</a> &#8211; darkreading.com<br />
Nuwa, named after the Chinese goddess who patched a hole in the sky, aims to fix cloud computing security hole.</li>
</ul>
<p><strong>Other News:</strong></p>
<ul>
<li><a href="http://blog.sucuri.net/2010/11/savannah-gnu-org-hacked-and-currently-offline.html">Savannah.gnu.org hacked and currently offline</a> &#8211; sucuri.net<br />
There’s been a SQL injection leading to leaking of encrypted account passwords, some of them discovered by brute-force attack, leading in turn to project membership access.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2010/11/calling-all-security-researchers-submit.html">Calling all security researchers! Submit your new 2010 Web Hacking Techniques</a> &#8211; jeremiahgrossman.blogspot.com<br />
To keep track of all these discoveries and encourage information sharing, the Top Web Hacking Techniques acts as both a centralized knowledge base and a way to recognize researchers who contribute excellent work.</li>
<li><a href="http://krebsonsecurity.com/2010/12/fbi-identifies-russian-mega-d-spam-kingpin/">FBI Identifies Russian ‘Mega-D’ Spam Kingpin</a> &#8211; krebsonsecurity.com<br />
Federal investigators have identified a 23-year-old Russian man as the mastermind behind the notorious “Mega-D” botnet, a network of spam-spewing PCs that once accounted for roughly a third of all spam sent worldwide.</li>
<li><a href="http://infoworld.com/t/intrusion-detection-and-prevention/attack-the-trojan-printers-331">Attack of the Trojan printers</a> &#8211; infoworld.com<br />
Enterprising security testers dress rogue access points up as common office hardware to gain inside access to networks.</li>
<li><a href="http://globalthreatcenter.com/?p=2010">Spyware threat invades BlackBerry App World</a> &#8211; globalthreatcenter.com<br />
In summary, threats posed by mobile applications exist –even if an application is hosted by Apple’s App Store or RIM’s App World both known for vetting submitted applications to ensure that the applications meet guidelines.</li>
<li><a href="http://blog.imperva.com/2010/11/us-sees-937-drop-in-data-breaches-from-2009-to-2010.html">U.S. Sees 93.7% Drop in Data Breaches from 2009 to 2010</a> &#8211; imperva.com<br />
An analysis that used data from the Privacy Clearinghouse, a public database that records all breaches of U.S. citizens’ personal and sensitive information, showed 230M data records taken in 2009 and 13M taken in 2010.</li>
<li><a href="http://blog.eset.com/2010/12/01/simulation-testing-and-the-eicar-test-file">Simulation Testing and the EICAR test file</a> &#8211; eset.com<br />
At the EICAR 2010 conference in Paris, an interesting student paper was presented that used the EICAR file to make some points about the ways in which AV software works (or is presumed to work).</li>
<li><a href="http://blogs.forbes.com/kashmirhill/2010/11/30/history-sniffing-how-youporn-checks-what-other-porn-sites-youve-visited-and-ad-networks-test-the-quality-of-their-data/">History Sniffing: How YouPorn Checks What Other Porn Sites You’ve Visited and Ad Networks Test The Quality of Their Data</a> &#8211; forbes.com<br />
When a visitor surfs into the YouPorn homepage, a script running on the website checks to see what other porn sites that person has been to.</li>
<li><a href="http://news.cnet.com/8301-1009_3-20024236-83.html">BlackBerry wins U.S. government security approval</a> &#8211; cnet.com<br />
RIM announced today that its BlackBerry 6 operating system is now FIPS 140-2 certified.</li>
</ul>
<img src="http://infosecevents.net/?ak_action=api_record_view&id=1360&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://infosecevents.net/2010/12/06/week-48-in-review-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

