<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ed Smiley&#039;s Blog</title>
	<atom:link href="http://edsmiley.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://edsmiley.com</link>
	<description>IT and Infosec Security Ramblings</description>
	<lastBuildDate>Thu, 05 Aug 2010 18:01:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Bookmarks for June 30th through August 5th</title>
		<link>http://edsmiley.com/?p=437</link>
		<comments>http://edsmiley.com/?p=437#comments</comments>
		<pubDate>Thu, 05 Aug 2010 18:01:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=437</guid>
		<description><![CDATA[These are my links for June 30th through August 5th: Programatically Setting Password Policies &#124; Krypted &#8211; Mac OS X, like many operating systems has a robust password policy engine. One that is not leveraged by default on either Mac OS X client or on Mac OS X Server. In Mac OS X Server, when [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=95' rel='bookmark' title='Permanent Link: Bookmarks for August 30th through September 5th'>Bookmarks for August 30th through September 5th</a></li>
<li><a href='http://edsmiley.com/?p=338' rel='bookmark' title='Permanent Link: Bookmarks for June 24th through August 11th'>Bookmarks for June 24th through August 11th</a></li>
<li><a href='http://edsmiley.com/?p=329' rel='bookmark' title='Permanent Link: Bookmarks for June 5th through June 22nd'>Bookmarks for June 5th through June 22nd</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for June 30th through August 5th:</p>
<ul>
<li><a href="http://krypted.com/mac-os-x/programatically-setting-password-policies/">Programatically Setting Password Policies | Krypted</a> &#8211; Mac OS X, like many operating systems has a robust password policy engine.  One that is not leveraged by default on either Mac OS X client or on Mac OS X Server.  In Mac OS X Server, when using Open Directory, you can easily click on Open Directory in the SERVERS sidebar list of Server Admin and then click on the Settings icon in the Server Admin toolbar.  Here, if you click on Policies you&rsquo;ll see the available Policies for Open Directory accounts.</li>
<li><a href="http://blindelephant.sourceforge.net/">BlindElephant Web Application Fingerprinter</a> &#8211; The BlindElephant Web Application Fingerprinter attempts to discover the version of a (known) web application by comparing static files at known locations against precomputed hashes for versions of those files in all all available releases. The technique is fast, low-bandwidth, non-invasive, generic, and highly automatable.</li>
<li><a href="https://www.defcon.org/html/links/dc-speakerscorner.html#lockpick-towne">DEF CON&reg; Hacking Conference &#8211; Speaker&#8217;s Corner</a> &#8211; Among the first questions you hear when teaching anyone to pick a lock is some variant of &quot;What is this pick for?&quot; I&#039;ve heard it a dozen ways, &quot;Which one should I use for this lock?&quot;, &quot;Which one will open it fastest?&quot; and &quot;How does this one work?&quot; I know that answering this question in print won&#039;t keep me from having to answer it a million more times, but at the very least it will help me collect my thoughts and hopefully serve as a primer to new pickers who come across it.</li>
<li><a href="http://adammuntner.blogspot.com/2010/07/updated-web-application-security.html">Adam Muntner&#8217;s Weblog: Updated Web Application Security Testing Collection for Firefox</a> &#8211; </li>
<li><a href="http://grandstreamdreams.blogspot.com/2009/11/sexy-usb-boots-win-pe-style.html">grand stream dreams: Sexy USB Boots (Win PE style)</a> &#8211; </li>
<li><a href="http://isc.sans.org/diary.html?storyid=9091&amp;rss">Vulnerability Assessment Testing Automation Part I, (Tue, Jun 29th)</a> &#8211; described how and why to automate parts of the security testing process.</li>
<li><a href="http://intellavis.com/blog/?p=168">Demonstrating XSS with BeEF</a> &#8211; Cross-site scripting (XSS) is a type of web application vulnerability that enables malicious attackers to inject client-side script into web pages viewed by other users. The idea is that in a vulnerable page, you can include your own code that runs in other people&rsquo;s browsers. The non-persistent, or reflected, cross-site scripting vulnerability is the most common and easily detected type. These holes show up when the data provided by a web client, most commonly in HTTP query parameters or in HTML form submissions, is used immediately by server-side scripts to generate a page of results for that user without properly sanitizing the response.</li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=95' rel='bookmark' title='Permanent Link: Bookmarks for August 30th through September 5th'>Bookmarks for August 30th through September 5th</a></li>
<li><a href='http://edsmiley.com/?p=338' rel='bookmark' title='Permanent Link: Bookmarks for June 24th through August 11th'>Bookmarks for June 24th through August 11th</a></li>
<li><a href='http://edsmiley.com/?p=329' rel='bookmark' title='Permanent Link: Bookmarks for June 5th through June 22nd'>Bookmarks for June 5th through June 22nd</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=437</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bookmarks for June 26th through June 30th</title>
		<link>http://edsmiley.com/?p=436</link>
		<comments>http://edsmiley.com/?p=436#comments</comments>
		<pubDate>Thu, 01 Jul 2010 03:00:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=436</guid>
		<description><![CDATA[These are my links for June 26th through June 30th: UATester Alpha &#8211; A number of high-profile sites (twitter, facebook, google, and even Microsoft) offer mobile versions of their sites and functionality. Normally this wouldn&#8217;t be something you&#8217;d care about, but as a penetration tester or security researcher, you need to make sure you&#8217;re covering [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=437' rel='bookmark' title='Permanent Link: Bookmarks for June 30th through August 5th'>Bookmarks for June 30th through August 5th</a></li>
<li><a href='http://edsmiley.com/?p=434' rel='bookmark' title='Permanent Link: Bookmarks for May 28th through June 9th'>Bookmarks for May 28th through June 9th</a></li>
<li><a href='http://edsmiley.com/?p=319' rel='bookmark' title='Permanent Link: Bookmarks for May 15th through June 3rd'>Bookmarks for May 15th through June 3rd</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for June 26th through June 30th:</p>
<ul>
<li><a href="http://blog.c22.cc/2010/06/20/uatester-alpha/">UATester Alpha</a> &#8211; A number of high-profile sites (twitter, facebook, google, and even Microsoft) offer mobile versions of their sites and functionality. Normally this wouldn&rsquo;t be something you&rsquo;d care about, but as a penetration tester or security researcher, you need to make sure you&rsquo;re covering all the bases and getting full coverage when looking at web applications.</li>
<li><a href="http://holisticinfosec.blogspot.com/2010/06/csrf-flaws-that-pack-punch.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Holisticinfosecorg+(HolisticInfoSec.org)">HolisticInfoSec.org: CSRF flaws that pack a punch</a> &#8211; </li>
<li><a href="http://infond.blogspot.com/2010/06/tutorial-sql-injection-lampsecurity-ctf.html">infond: tutorial SQL injection &#8211; LampSecurity CTF 6</a> &#8211; </li>
<li><a href="http://infosecevents.net/">Infosec Events &#8211; Covering the Information Security Economy</a> &#8211; </li>
<li><a href="http://static.chrisbray.com/bookmarklets/#delicious">Adding Bookmarklets on iPad and iPhone</a> &#8211; </li>
<li><a href="http://www.forensiccontrol.com/fcresources.php">Forensic Control &#8211; Computer misuse and dispute specialists</a> &#8211; The table below lists a selection of free software which may be of use to professional computer forensic practitioners. It is the end user&#039;s responsibility to check the licensing agreements of each one before use.</li>
<li><a href="http://code.google.com/p/andiparos/">andiparos &#8211; Project Hosting on Google Code</a> &#8211; Andiparos is a fork of the famous Paros Proxy. It is an open source web application security assessment tool that gives penetration testers the ability to spider websites, analyze content, intercept and modify requests, etc.&lt;br /&gt;<br />
&lt;br /&gt;<br />
The advantage of Andiparos is mainly the support of Client Certificates on Smartcards. Moreover it has several small interface enhancements, making the life easier for penetration testers&#8230;</li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=437' rel='bookmark' title='Permanent Link: Bookmarks for June 30th through August 5th'>Bookmarks for June 30th through August 5th</a></li>
<li><a href='http://edsmiley.com/?p=434' rel='bookmark' title='Permanent Link: Bookmarks for May 28th through June 9th'>Bookmarks for May 28th through June 9th</a></li>
<li><a href='http://edsmiley.com/?p=319' rel='bookmark' title='Permanent Link: Bookmarks for May 15th through June 3rd'>Bookmarks for May 15th through June 3rd</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=436</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bookmarks for June 10th through June 23rd</title>
		<link>http://edsmiley.com/?p=435</link>
		<comments>http://edsmiley.com/?p=435#comments</comments>
		<pubDate>Wed, 23 Jun 2010 20:00:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=435</guid>
		<description><![CDATA[These are my links for June 10th through June 23rd: FoxAnalysis &#8211; Firefox 3 Forensics &#8211; FoxAnalysis is a software tool enabling analysis of internet history data generated using Mozilla Firefox 3. This tool was developed to assist in forensic examinations. neXCSer &#8211; DigiNinja &#8211; neXCSer was originally going to be a way to allow [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=282' rel='bookmark' title='Permanent Link: Bookmarks for April 13th through April 23rd'>Bookmarks for April 13th through April 23rd</a></li>
<li><a href='http://edsmiley.com/?p=436' rel='bookmark' title='Permanent Link: Bookmarks for June 26th through June 30th'>Bookmarks for June 26th through June 30th</a></li>
<li><a href='http://edsmiley.com/?p=338' rel='bookmark' title='Permanent Link: Bookmarks for June 24th through August 11th'>Bookmarks for June 24th through August 11th</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for June 10th through June 23rd:</p>
<ul>
<li><a href="http://forensic-software.co.uk/foxanalysis.aspx">FoxAnalysis &#8211; Firefox 3 Forensics</a> &#8211; FoxAnalysis is a software tool enabling analysis of internet history data generated using Mozilla Firefox 3. This tool was developed to assist in forensic examinations.</li>
<li><a href="http://www.digininja.org/projects/nexcser.php">neXCSer &#8211; DigiNinja</a> &#8211; neXCSer was originally going to be a way to allow multiple auditors to merge their Nessus results into a single file that could then be parsed through by hand or in a spreadsheet to help with further testing or report writing, however once I started writing it I realised that it could help more than that by allowing different sections of the results file to be broken down into their own parts.</li>
<li><a href="http://www.tombom.co.uk/blog/?p=166">ICCIDs IMSIs and iPads, Oh My! &laquo; Chris Paget&#8217;s Blog</a> &#8211; A few days ago Apple suffered a security breach &ndash; the ICCIDs and email adresses for 114,000 iPad users were hacked, leading to widespread press coverage and speculation. The general consensus seems to be that the ICCID (being the serial number that&rsquo;s printed onto the SIM card) has no real security consequences to its disclosure, and that the bigger problem is the associated email addresses. The consensus is badly wrong &ndash; here&rsquo;s why.</li>
<li><a href="http://www.cryptolife.org/index.php/Spsa">Spsa &#8211; Cryptolife</a> &#8211; Here you can find the Snorby preconfigured security applications, this make effortless for anyone to use Snorby, the new and modern Snort IDS front-end. With (SPSA) Snorby Preconfigured Security Applications, it is possible to get Snorby and Snort up and running out of the box within a few minutes. Feedbacks and info are welcome by email at:</li>
<li><a href="http://uninformed.org/index.cgi?v=10&amp;a=3#SECTION00310000000000000000">Uninformed &#8211; vol 10 article 3 &#8211; Exploiting Tomorrow&#8217;s Internet Today Penetration Testing with IPv6</a> &#8211; Exploiting Tomorrow&#039;s Internet Today Penetration Testing with IPv6</li>
<li><a href="http://www.csoonline.com/article/print/596512">Social engineering techniques: 4 ways criminal outsiders get inside</a> &#8211; Your security plan goes from locked down to wide open when a social engineer pulls off these techniques to gain insider access</li>
<li><a href="http://www.storefrontbacktalk.com/securityfraud/complying-with-visas-july-1-pa-dss-mandate/2/">StorefrontBacktalk &raquo; Blog Archive &raquo; Complying With Visa&rsquo;s July 1 PA-DSS Mandate</a> &#8211; PA-DSS applies to third-party applications that store, process or transmit cardholder data as part of the authorization and settlement process. Importantly, this definition includes both standalone applications and payment modules of larger enterprise resource planning (ERP) systems. In all cases, though, you license and host these applications internally.</li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=282' rel='bookmark' title='Permanent Link: Bookmarks for April 13th through April 23rd'>Bookmarks for April 13th through April 23rd</a></li>
<li><a href='http://edsmiley.com/?p=436' rel='bookmark' title='Permanent Link: Bookmarks for June 26th through June 30th'>Bookmarks for June 26th through June 30th</a></li>
<li><a href='http://edsmiley.com/?p=338' rel='bookmark' title='Permanent Link: Bookmarks for June 24th through August 11th'>Bookmarks for June 24th through August 11th</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=435</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bookmarks for May 28th through June 9th</title>
		<link>http://edsmiley.com/?p=434</link>
		<comments>http://edsmiley.com/?p=434#comments</comments>
		<pubDate>Wed, 09 Jun 2010 20:00:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=434</guid>
		<description><![CDATA[These are my links for May 28th through June 9th: Tactical Web Application Security: Zone-H Defacement Statistics Report for Q1 2010 &#8211; Web defacements are a serious problem and are a critical barometer for estimating exploitable vulnerabilities in websites. Unfortunately, most people focus too much on the impact or outcome of these attacks (the defacement) [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=329' rel='bookmark' title='Permanent Link: Bookmarks for June 5th through June 22nd'>Bookmarks for June 5th through June 22nd</a></li>
<li><a href='http://edsmiley.com/?p=437' rel='bookmark' title='Permanent Link: Bookmarks for June 30th through August 5th'>Bookmarks for June 30th through August 5th</a></li>
<li><a href='http://edsmiley.com/?p=122' rel='bookmark' title='Permanent Link: Bookmarks for September 29th through October 9th'>Bookmarks for September 29th through October 9th</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for May 28th through June 9th:</p>
<ul>
<li><a href="http://tacticalwebappsec.blogspot.com/2010/06/zone-h-defacement-statistics-report-for.html">Tactical Web Application Security: Zone-H Defacement Statistics Report for Q1 2010</a> &#8211; Web defacements are a serious problem and are a critical barometer for estimating exploitable vulnerabilities in websites. Unfortunately, most people focus too much on the impact or outcome of these attacks (the defacement) rather than the fact that their web applications are vulnerable to this level of exploitation. People are forgetting the standard Risk equation -&lt;br /&gt;<br />
&lt;br /&gt;<br />
RISK = THREAT x VULNERABILITY x IMPACT&lt;br /&gt;<br />
&lt;br /&gt;<br />
The resulting risk of a web defacement might be low because the the impact may not be deemed a high enough severity for particular organizations. What most people are missing, however, is that the threat and vulnerability components of the equation still exist. What happens if the defacers decided to not simply alter some homepage content and instead decided to do something more damaging such as adding malicious code to infect clients?</li>
<li><a href="http://sourceforge.net/projects/defraser/">NFI Defraser | Download NFI Defraser software for free at SourceForge.net</a> &#8211; Defraser is a forensic analysis application that can be used to detect full and partial multimedia files in datastreams. It is typically used to find (and restore) complete or partial audio/video files in datastreams (for instance, unallocated diskspace)</li>
<li><a href="http://pentest.cryptocity.net/careers">Penetration Testing and Vulnerability Analysis &#8211; Careers &#8211; Information Security Careers&nbsp;Cheatsheet</a> &#8211; These are my views on careers in information security careers based on the experience I&#39;ve had and your mileage may vary. The information below will be most appropriate if you live in New York City, you&#39;re interested in application security, pentesting, or reversing, and you are early on in your career in information security.</li>
<li><a href="http://blogs.sans.org/computer-forensics/2010/06/04/wmic-draft/">WMIC for incident response</a> &#8211; Earlier this week, I posted about using psexec during incident response. I mentioned at the end of that post that I&rsquo;ve been using WMIC in place of psexec and that I&rsquo;d have more on that later. This post, is a follow up to the psexec post.</li>
<li><a href="http://thedigitalstandard.blogspot.com/2010/05/crack-lacka.html">The Digital Standard: Crack-a-Lacka</a> &#8211; OK&hellip;so you may have heard that&rsquo;s it pretty easy to crack SAM hives using tools like Cain &amp; Able or Ophcrack, but, you have never done it before, you don&rsquo;t know where to start looking, and you feel like a dolt. No worries my friend, I am here to help.</li>
<li><a href="https://addons.mozilla.org/en-US/firefox/addon/46698/">Groundspeed :: Add-ons for Firefox</a> &#8211; Groundspeed is an add-on that allows security testers to manipulate the application user interface to eliminate annoying limitations and client-side controls that interfere with the web application penetration tests.</li>
<li><a href="http://blog.sipvicious.org/2010/05/new-tool-in-works-tftptheft.html">SIPVicious: New tool in the works: TFTPTheft</a> &#8211; Most sysadmins just love the idea of switching on a box that just works automatically. In the case of IP phones that is typically possible by setting up the right DHCP config and a TFTP server hosting firmware and configuration.</li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=329' rel='bookmark' title='Permanent Link: Bookmarks for June 5th through June 22nd'>Bookmarks for June 5th through June 22nd</a></li>
<li><a href='http://edsmiley.com/?p=437' rel='bookmark' title='Permanent Link: Bookmarks for June 30th through August 5th'>Bookmarks for June 30th through August 5th</a></li>
<li><a href='http://edsmiley.com/?p=122' rel='bookmark' title='Permanent Link: Bookmarks for September 29th through October 9th'>Bookmarks for September 29th through October 9th</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=434</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bookmarks for May 20th through May 27th</title>
		<link>http://edsmiley.com/?p=433</link>
		<comments>http://edsmiley.com/?p=433#comments</comments>
		<pubDate>Fri, 28 May 2010 00:00:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=433</guid>
		<description><![CDATA[These are my links for May 20th through May 27th: WebCruiser &#8211; Web Security &#8211; WebCruiser &#8211; Web Vulnerability Scanner, a compact but powerful web security scanning tool that will aid you in auditing your site! It has a Vulnerability Scanner and a series of security tools.&#60;br /&#62; &#60;br /&#62; It can support scanning website [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=249' rel='bookmark' title='Permanent Link: Bookmarks for February 17th through March 3rd'>Bookmarks for February 17th through March 3rd</a></li>
<li><a href='http://edsmiley.com/?p=155' rel='bookmark' title='Permanent Link: Bookmarks for November 20th through November 25th'>Bookmarks for November 20th through November 25th</a></li>
<li><a href='http://edsmiley.com/?p=91' rel='bookmark' title='Permanent Link: Bookmarks for August 27th from 14:11 to 14:17'>Bookmarks for August 27th from 14:11 to 14:17</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for May 20th through May 27th:</p>
<ul>
<li><a href="http://sec4app.com/">WebCruiser &#8211; Web Security</a> &#8211; WebCruiser &#8211; Web Vulnerability Scanner, a compact but powerful web security scanning tool that will aid you in auditing your site! It has a Vulnerability Scanner and a series of security tools.&lt;br /&gt;<br />
&lt;br /&gt;<br />
It can support scanning website as well as POC( Prooving of concept) for web vulnerabilities: SQL Injection, Cross Site Scripting, XPath Injection etc. So, WebCruiser is also an automatic SQL injection tool, a XPath injection tool, and a Cross Site Scripting tool!</li>
<li><a href="http://nullpointer.dk/?q=node/50">Stealing a photo from remote webcam | nullpointer.dk</a> &#8211; Ever wanted to capture a photo from a remote webcam? Like from one of your friends perhaps. Probably if you&#39;ve a little hacker in your belly.. This is another demonstration of the use of Metasploit like I did in my previous article Exploiting SMB on Windows. Therefore, I won&#39;t talk about installing the framework and running the supplied program msfconsole.</li>
<li><a href="http://pauldotcom.com/2010/04/using-meterpreter-to-control-n.html">PaulDotCom: Archives</a> &#8211; Metasploit has A LOT of exploits, but from time to time you will very likely need to use exploits that are not part of the framework. Whether it is an exploit from www.exploit-db.com that spawns a shell or a netcat listener you can still use the framework to control the host. As long as you have a shell bound to a TCP port you can use metasploit to interact with that victim. What&#39;s more, you can upgrade that shell to a meterpreter session so you can benefit from the full power of the framework.</li>
<li><a href="http://blog.tenablesecurity.com/2010/05/common-platform-enumeration-cpe-with-nessus.html">Tenable Network Security: Common Platform Enumeration (CPE) with Nessus</a> &#8211; Recently a Nessus plugin (and associated library) was developed that includes CPE information about supported targets. If no entry exists in the CPE database, the plugin will attempt to create one and apply all of the appropriate information in the CPE defined format. I ran a scan against my test network and then filtered for CPE entries:</li>
<li><a href="http://security.crudtastic.com/?p=215">security.crudtastic.com &raquo; Test Lab Version 1.0</a> &#8211; </li>
<li><a href="http://www.dailymotion.com/video/22460067">Dailymotion &#8211; Practical Exploitation &#8211; Null Session Enum &#8211; a College video</a> &#8211; 3 tools that do enumeration using null sessions</li>
<li><a href="http://www.skullsecurity.org/blog/?p=820">SkullSecurity &raquo; Blog Archive &raquo; Defeating expensive lockdowns with cheap shellscripts</a> &#8211; Recently, I was given the opportunity to work with an embedded Linux OS that was locked down to prevent unauthorized access. I was able to obtain a shell fairly quickly, but then I ran into a number of security mechanisms. Fortunately, I found creative ways to overcome each of them.</li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=249' rel='bookmark' title='Permanent Link: Bookmarks for February 17th through March 3rd'>Bookmarks for February 17th through March 3rd</a></li>
<li><a href='http://edsmiley.com/?p=155' rel='bookmark' title='Permanent Link: Bookmarks for November 20th through November 25th'>Bookmarks for November 20th through November 25th</a></li>
<li><a href='http://edsmiley.com/?p=91' rel='bookmark' title='Permanent Link: Bookmarks for August 27th from 14:11 to 14:17'>Bookmarks for August 27th from 14:11 to 14:17</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=433</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bookmarks for April 19th through May 19th</title>
		<link>http://edsmiley.com/?p=432</link>
		<comments>http://edsmiley.com/?p=432#comments</comments>
		<pubDate>Thu, 20 May 2010 03:00:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=432</guid>
		<description><![CDATA[These are my links for April 19th through May 19th: Dasient Blog: Q1&#8217;10 web-based malware data and trends &#8211; Each quarter we pull together data for web-based malware attacks from across the web. Our proprietary malware analysis platform allows us to monitor millions of websites and draw results from a wealth of data which we [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=431' rel='bookmark' title='Permanent Link: Bookmarks for April 2nd through April 18th'>Bookmarks for April 2nd through April 18th</a></li>
<li><a href='http://edsmiley.com/?p=430' rel='bookmark' title='Permanent Link: Bookmarks for April 1st through April 2nd'>Bookmarks for April 1st through April 2nd</a></li>
<li><a href='http://edsmiley.com/?p=293' rel='bookmark' title='Permanent Link: Bookmarks for April 26th through April 29th'>Bookmarks for April 26th through April 29th</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for April 19th through May 19th:</p>
<ul>
<li><a href="http://blog.dasient.com/2010/05/q110-web-based-malware-data-and-trends.html">Dasient Blog: Q1&#8217;10 web-based malware data and trends</a> &#8211; Each quarter we pull together data for web-based malware attacks from across the web. Our proprietary malware analysis platform allows us to monitor millions of websites and draw results from a wealth of data which we summarize in this blog. What we continue to see is that the web malware threat continues to grow significantly. Hackers are becoming increasingly sophisticated and bold in their attacks, which means that legitimate websites are more threatened than ever. Putting web site security best practices in place such as malware monitoring and containment is becoming an absolute must if businesses do not want to expose themselves and their customers to these attacks. A particularly interesting observation has been an increase in &#39;malvertising&#39; attacks in which hackers plant malicious ads on high-profile ad networks and websites</li>
<li><a href="http://www.skullsecurity.org/blog/?p=627">SkullSecurity &raquo; Blog Archive &raquo; Taking apart the Energizer trojan &#8211; Part 1: setup</a> &#8211; As most of you know, a Trojan was recently discovered in the software for Energizer&#39;s USB battery charger. Following its release, I wrote an Nmap probe to detect the Trojan and HDMoore wrote a Metasploit module to exploit it.&lt;br /&gt;<br />
&lt;br /&gt;<br />
I mentioned in my last post that it was a nice sample to study and learn from. The author made absolutely no attempt to conceal its purpose, once installed, besides a weak XOR encoding for communication. Some conspiracy theorists even think this may have been legitimate management software gone wrong &#8212; and who knows, really? In any case, I offered to write a tutorial on how I wrote the Nmap probe, and had a lot of positive feedback, so here it is!&lt;br /&gt;<br />
&lt;br /&gt;<br />
Just be sure to take this for what it is. This is *not* intended to show any new methods or techniques or anything like that. It&#39;s a reverse engineering guide targeted, as much as I could, for people who&#39;ve never opened IDA or Windbg in their lives. I&#39;d love to hear your comments!</li>
<li><a href="http://www.ncsl.org/IssuesResearch/TelecommunicationsInformationTechnology/SecurityBreachNotificationLaws/tabid/13489/Default.aspx">Security Breach Notification Laws</a> &#8211; Forty-six states, the District of Columbia, Puerto Rico and the Virgin Islands have enacted legislation requiring notification of security breaches involving personal information.</li>
<li><a href="http://www.youtube.com/watch?v=N2boa3lyC7Q">YouTube &#8211; Bogota Review</a> &#8211; </li>
<li><a href="http://www.youtube.com/watch?v=-nFV-KksseQ">YouTube &#8211; CUSTOM BOGATA LOCKPICKING INSTRUCTIONAL VIDEO</a> &#8211; CUSTOM BOGATA LOCKPICKING INSTRUCTIONAL VIDEO:&lt;br /&gt;<br />
this is a reference instructional video&lt;br /&gt;<br />
on my custom-made bogata rakes,&lt;br /&gt;<br />
made for the &quot;tutorials&quot; thread @ www.keypicking.com&lt;br /&gt;<br />
in this video i use a Titanium-shackle Wison-Bohannan,a 45mm Guard,&amp; a 50mm Garrison,as picking subjects&lt;br /&gt;<br />
NOTE: these custom rakes are entirely hand-made, and do occasionally become available through me.</li>
<li><a href="http://www.greensql.net/publications/mysql-security-best-practices">MySQL Security Best Practices (Hardening MySQL Tips) | &nbsp;GreenSQL</a> &#8211; The MySQL database has become the world&#39;s most popular open source database because of its consistent fast performance, high reliability and ease of use. MySQL is used on every continent &ndash; yes, even in Antarctica! &ndash; by individuals, Web developers, as well as many of the world&#39;s largest and fastest-growing organizations such as industry leaders Yahoo!, Alcatel-Lucent, Google, Nokia, YouTube and others to save time and money powering their high-volume websites, business-critical systems, and packaged software.&lt;br /&gt;<br />
&lt;br /&gt;<br />
As most products do, MySQL comes &quot;ready-to-work&quot; out of the box. Usually, security is not a major consideration when installing this kind of product. Often, the most important issue is to get it up and running as quickly as possible so that the organization can benefit. This document is intended as a quick security manual to help you bring an installed MySQL database server into conformity with best security practices.</li>
<li><a href="https://www.securitymetrics.com/panscan.adp">PANscan &#8211; SecurityMetrics</a> &#8211; PANscan simplifies the testing process by enabling non-technical merchants to quickly find prohibited credit card data on their systems. It will:&lt;br /&gt;<br />
&lt;br /&gt;<br />
    * Search the local system for cardholder data.&lt;br /&gt;<br />
    * Triple-check all threats to ensure they are valid.&lt;br /&gt;<br />
    * Run 10 times faster than a normal disk scan.&lt;br /&gt;<br />
    * Report summary results immediately.&lt;br /&gt;<br />
    * Allow scans to be performed as frequently as desired on any number of merchant machines.&lt;br /&gt;<br />
&lt;br /&gt;<br />
Free downloads available in May</li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=431' rel='bookmark' title='Permanent Link: Bookmarks for April 2nd through April 18th'>Bookmarks for April 2nd through April 18th</a></li>
<li><a href='http://edsmiley.com/?p=430' rel='bookmark' title='Permanent Link: Bookmarks for April 1st through April 2nd'>Bookmarks for April 1st through April 2nd</a></li>
<li><a href='http://edsmiley.com/?p=293' rel='bookmark' title='Permanent Link: Bookmarks for April 26th through April 29th'>Bookmarks for April 26th through April 29th</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=432</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bookmarks for April 2nd through April 18th</title>
		<link>http://edsmiley.com/?p=431</link>
		<comments>http://edsmiley.com/?p=431#comments</comments>
		<pubDate>Sun, 18 Apr 2010 15:00:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=431</guid>
		<description><![CDATA[These are my links for April 2nd through April 18th: Understanding Man-in-the-Middle Attacks &#8211; ARP Cache Poisoning (Part 1) &#8211; One of the most prevalent network attacks used against individuals and large organizations alike are man-in-the-middle (MITM) attacks. Considered an active eavesdropping attack, MITM works by establishing connections to victim machines and relaying messages between [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=430' rel='bookmark' title='Permanent Link: Bookmarks for April 1st through April 2nd'>Bookmarks for April 1st through April 2nd</a></li>
<li><a href='http://edsmiley.com/?p=423' rel='bookmark' title='Permanent Link: Bookmarks for March 14th through March 18th'>Bookmarks for March 14th through March 18th</a></li>
<li><a href='http://edsmiley.com/?p=434' rel='bookmark' title='Permanent Link: Bookmarks for May 28th through June 9th'>Bookmarks for May 28th through June 9th</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for April 2nd through April 18th:</p>
<ul>
<li><a href="http://www.windowsecurity.com/articles/Understanding-Man-in-the-Middle-Attacks-ARP-Part1.html">Understanding Man-in-the-Middle Attacks &ndash; ARP Cache Poisoning (Part 1)</a> &#8211; One of the most prevalent network attacks used against individuals and large organizations alike are man-in-the-middle (MITM) attacks. Considered an active eavesdropping attack, MITM works by establishing connections to victim machines and relaying messages between them. In cases like these, one victim believes it is communicating directly with another victim, when in reality the communication flows through the host performing the attack. The end result is that the attacking host can not only intercept sensitive data, but can also inject and manipulate a data stream to gain further control of its victims.</li>
<li><a href="http://www.csoonline.com/article/print/590096">Are You Making a Security Career or Working a Job?</a> &#8211; In his first column as CSO&#39;s Career Catalyst, Michael Santarcangelo outlines three essentials everyone needs to consider to make security work more than just a job</li>
<li><a href="http://vrt-sourcefire.blogspot.com/2010/04/matts-primer-for-pdf-analysis.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+Vrt+(Sourcefire+VRT+-+Vulnerability+Research,+Snort+Rules+and+Explosions)">VRT: Matt&#8217;s Primer for PDF Analysis</a> &#8211; For obvious reasons, the VRT has been spending a lot of time on the PDF format lately. While the attack researchers have been concentrating on fuzzing, reverse engineering and data flow analysis, the defense researchers have been automating the backend analysis of PDF submissions. As part of this effort, we&#39;ve had to do a very deep dive on the PDF format. I thought it might be useful to share some of what we&#39;re seeing come in our data feeds, and what you should look for when reviewing PDF files.</li>
<li><a href="http://blackbag.nl/?p=1315">More &ldquo;hotel door hacking&rdquo; and lockcon &laquo; Blackbag, Barry&rsquo;s weblog</a> &#8211; Times are pretty hectic so Charlotte and I decided to take off to one of Europe&rsquo;s nicest cities for a relaxing weekend without the kids. When we entered our hotel room I was thrilled to see it had a chain on the inside &hellip; (see my previous post on hotel doors to read why). The chain is a weak link by itself as it was obvious if had been broken and repaired many times before. In my opinion it is not necessary to use force on the chain as it can be bypassed relatively simple.</li>
<li><a href="http://securitythoughts.wordpress.com/2010/03/22/vulnerable-web-applications-for-learning/">Vulnerable Web Applications for learning &laquo; Security Thoughts</a> &#8211; Just a quick post. Someone on the &lsquo;NULL&rsquo; mailing asked for WebGoat alternatives to learning Web Application penetration testing. The reponse was amazing, with many applications being listed as vulnerable web applications designed for learning web-app pentest. I have collected  all vulnerable web applications and listed them below for reference:</li>
<li><a href="http://www.morningstarsecurity.com/research/bing-ip2hosts">bing-ip2hosts</a> &#8211; Bing-IP2hosts &ndash; Enumerate hostnames for an IP using bing.com. This is useful during the reconnaissance phase of a penetration test and for website hosting provider research.</li>
<li><a href="http://vividmachines.com/shellcoding/">vividmachines dot com &raquo; shellcode</a> &#8211; </li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=430' rel='bookmark' title='Permanent Link: Bookmarks for April 1st through April 2nd'>Bookmarks for April 1st through April 2nd</a></li>
<li><a href='http://edsmiley.com/?p=423' rel='bookmark' title='Permanent Link: Bookmarks for March 14th through March 18th'>Bookmarks for March 14th through March 18th</a></li>
<li><a href='http://edsmiley.com/?p=434' rel='bookmark' title='Permanent Link: Bookmarks for May 28th through June 9th'>Bookmarks for May 28th through June 9th</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=431</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bookmarks for April 1st through April 2nd</title>
		<link>http://edsmiley.com/?p=430</link>
		<comments>http://edsmiley.com/?p=430#comments</comments>
		<pubDate>Sat, 03 Apr 2010 03:00:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=430</guid>
		<description><![CDATA[These are my links for April 1st through April 2nd: SkullSecurity &#187; Blog Archive &#187; VM Stealing: The Nmap way (CVE-2009-3733 exploit) &#8211; If you were at Shmoocon this past weekend, you might remember a talk on Friday, done by Justin Morehouse and Tony Flick, on VMWare Guest Stealing. If you don&#39;t, you probably started [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=431' rel='bookmark' title='Permanent Link: Bookmarks for April 2nd through April 18th'>Bookmarks for April 2nd through April 18th</a></li>
<li><a href='http://edsmiley.com/?p=305' rel='bookmark' title='Permanent Link: Bookmarks for May 1st through May 14th'>Bookmarks for May 1st through May 14th</a></li>
<li><a href='http://edsmiley.com/?p=432' rel='bookmark' title='Permanent Link: Bookmarks for April 19th through May 19th'>Bookmarks for April 19th through May 19th</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for April 1st through April 2nd:</p>
<ul>
<li><a href="http://www.skullsecurity.org/blog/?p=436">SkullSecurity &raquo; Blog Archive &raquo; VM Stealing: The Nmap way (CVE-2009-3733 exploit)</a> &#8211; If you were at Shmoocon this past weekend, you might remember a talk on Friday, done by Justin Morehouse and Tony Flick, on VMWare Guest Stealing. If you don&#39;t, you probably started drinking too early. <img src='http://edsmiley.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> &lt;br /&gt;<br />
&lt;br /&gt;<br />
Anyway, somebody in the audience asked if there was a Nessus or Nmap script to detect this vulnerability. If I was the kind to yell things out, I would have yelled &quot;there will be!&quot; &#8212; and now, there is. It&#39;ll be included in the next full version of Nmap, but in the meantime here&#39;s how you can do it yourself.</li>
<li><a href="http://security-sh3ll.blogspot.com/2010/03/backendinfo-detect-website-backends.html">Security-Shell: BackendInfo &#8211; Detect Website Backends</a> &#8211; BackendInfo is a lightweight (24kb) Firefox extension that detects name and version of backends behind websites</li>
<li><a href="http://blog.c22.cc/2010/03/19/firefox-search-add-ons-for-security-nerds%E2%84%A2/">Firefox search add-ons for Security-Nerds&trade; &laquo; &copy;атсн&sup2;&sup2; (in)sесuяitу</a> &#8211; After looking over the slidedeck from Michael &ldquo;theprez98&Prime; Schearer&rsquo;s Blackhat Webcast, I decided (like a lot of people I&rsquo;m sure) to have a quick look at what Firefox add-ons were available to make penetration testing using the browser a little easier. My portable Firefox edition already has a number of extensions installed for the usual stuff. Things like FoxyProxy, Web Developer Toolbar, Fire/FlashBug and the SQL Inject Me, Access Me and XSS Me tools from Security Compass have been installed for a long time. They come in useful for specific tasks, even when I&rsquo;m not doing Web app testing. One thing I&rsquo;d not really looked at though was the possibility of adding to the search providers list (found in the upper right-hand corner).</li>
<li><a href="http://aerokid240.blogspot.com/2010/03/turning-your-laptop-into-wireless-ap.html">&quot;I&#8217;ll show you the route (root) so that you will have **command**&quot;: Turning your laptop into a wireless AP</a> &#8211; I&#39;m just gonna go over some simple code and tools that you can use to transform your laptop running linux into a wireless access point where wireless clients can connect to. The programs that i will be using are airmon-ng, airbase-ng, dhcpd-server and dnsmasq just to name a few. Other utilities will be used in my example here but they are mostly complementary tools that may not be deemed necessary.</li>
<li><a href="http://www.viruslist.com/en/weblog?weblogid=208188057">Viruslist.com &#8211; Analyst&#8217;s Diary</a> &#8211; Insightful explanation of how ZeuS wires money out bank accounts despite dongles/cards</li>
<li><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/03/30/configuration-is-half-the-battle-asp-net-and-cross-site-scripting.aspx">Configuration is Half the Battle: ASP.NET and Cross-Site Scripting &#8211; The HP Security Laboratory Blog -</a> &#8211; Although it&#39;s not a new problem, a recent advisory and BlackHat presentation have brought attention to an ASP.NET mis-configuration that can leave you wide open to Cross-Site Scripting (XSS) attacks, even if you are diligently sanitizing your other user-supplied data. If the view state is not cryptographically signed, it is possible for an attacker to overwrite properties of any of your server-side controls and modify HTML returned to the user, opening a vector for XSS.</li>
<li><a href="http://blog.lumension.com/?p=2884">iPad Security &ndash; Does the Enterprise Care?</a> &#8211; With the introduction of the iPad, Apple is again hitting the consumer market with an innovative product that may have security implications for enterprise IT teams.  Although based on the iPhone OS, the use cases identified by Apple for the iPad (especially as an electronic document reader) portend a wide range of business uses that would not be viable on the small iPhone screen.</li>
<li><a href="http://www.nirsoft.net/utils/usb_devices_view.html">USBDeview &#8211; View all installed/connected USB devices on your system</a> &#8211; USBDeview is a small utility that lists all USB devices that currently connected to your computer, as well as all USB devices that you previously used.  For each USB device, exteneded information is displayed: Device name/description, device type, serial number (for mass storage devices), the date/time that device was added, VendorID, ProductID, and more&#8230;</li>
<li><a href="http://www.sensepost.com/blog/4552.html">&#8216;Scraping&#8217; our time servers</a> &#8211; The intertubes have been humming lately around a certain NTP feature to gather lists of NTP servers&#39; clients and it naturally grabbed our attention. The humming was started by HD Moore recently where he revealed that it is possible to query NTP servers to get lists of addresses and using the information for fun and profit. He also mentioned that he will be releasing a paper describing all this and how he can create a sizable DDOS using NTP, without giving too much detail about it.</li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=431' rel='bookmark' title='Permanent Link: Bookmarks for April 2nd through April 18th'>Bookmarks for April 2nd through April 18th</a></li>
<li><a href='http://edsmiley.com/?p=305' rel='bookmark' title='Permanent Link: Bookmarks for May 1st through May 14th'>Bookmarks for May 1st through May 14th</a></li>
<li><a href='http://edsmiley.com/?p=432' rel='bookmark' title='Permanent Link: Bookmarks for April 19th through May 19th'>Bookmarks for April 19th through May 19th</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=430</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bookmarks for March 18th through March 31st</title>
		<link>http://edsmiley.com/?p=427</link>
		<comments>http://edsmiley.com/?p=427#comments</comments>
		<pubDate>Thu, 01 Apr 2010 04:00:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[del.icio.us]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=427</guid>
		<description><![CDATA[These are my links for March 18th through March 31st: Using Nessus Thorough Checks for In-depth Audits &#8211; Google, Microsoft Push Feds to Fix Privacy Laws &#124; Threat Level &#124; Wired.com &#8211; Digital Forensics Framework &#8211; Dff is a simple but powerful open source tool with a flexible module system which will help you in [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=423' rel='bookmark' title='Permanent Link: Bookmarks for March 14th through March 18th'>Bookmarks for March 14th through March 18th</a></li>
<li><a href='http://edsmiley.com/?p=249' rel='bookmark' title='Permanent Link: Bookmarks for February 17th through March 3rd'>Bookmarks for February 17th through March 3rd</a></li>
<li><a href='http://edsmiley.com/?p=268' rel='bookmark' title='Permanent Link: Bookmarks for March 16th through March 26th'>Bookmarks for March 16th through March 26th</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>These are my links for March 18th through March 31st:</p>
<ul>
<li><a href="http://blog.tenablesecurity.com/2010/03/using-nessus-thorough-checks-for-indepth-audits.html">Using Nessus Thorough Checks for In-depth Audits</a> &#8211; </li>
<li><a href="http://www.wired.com/threatlevel/2010/03/google-microsoft-ecpa/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+wired27b+(Blog+-+27B+Stroke+6+(Threat+Level))&amp;utm_content=Google+Reader">Google, Microsoft Push Feds to Fix Privacy Laws | Threat Level | Wired.com</a> &#8211; </li>
<li><a href="http://www.digital-forensic.org/">Digital Forensics Framework</a> &#8211; Dff is a simple but powerful open source tool with a flexible module system which will help you in your digital forensics works, including files recovery due to error or crash, evidence research and analysis, etc. The source code is written in C++ and Python, allowing performances and great extensibility.</li>
<li><a href="http://www.catonmat.net/blog/top-ten-one-liners-from-commandlinefu-explained/">Top Ten One-Liners from CommandLineFu Explained &#8211; good coders code, great reuse</a> &#8211; I love working in the shell. Mastery of shell lets you get things done in seconds, rather than minutes or hours, if you chose to write a program instead.</li>
<li><a href="http://www.fewt.com/2009/11/install-kindle-for-pc-application-on.html">Install the Kindle for PC application on your Linux computer</a> &#8211; Here is a quick HOW-TO to install Kindle on your Linux computer, and read books from Amazon.com without impacting your existing WINE installation. The assumption is that you are using Debian or a Debian based desktop such as Eeebuntu, Ubuntu, Mint, etc.</li>
<li><a href="https://addons.mozilla.org/en-US/firefox/collection/webappsec">Web Application Security Penetration Testing :: Add-ons for Firefox</a> &#8211; The most complete collection of pentest and hacking tools for Firefox&lt;br /&gt;<br />
&lt;br /&gt;<br />
Browser proxies, page analysis, SQL &amp; XSS injection scanners, google dorking, decoding, fuzzing</li>
<li><a href="http://blog.jimmy.schementi.com/2010/03/pycon-2010-python-in-browser.html?utm_source=twitterfeed&amp;utm_medium=twitter">jimmy.thinking: PyCon 2010: Python in the browser</a> &#8211; </li>
</ul>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=423' rel='bookmark' title='Permanent Link: Bookmarks for March 14th through March 18th'>Bookmarks for March 14th through March 18th</a></li>
<li><a href='http://edsmiley.com/?p=249' rel='bookmark' title='Permanent Link: Bookmarks for February 17th through March 3rd'>Bookmarks for February 17th through March 3rd</a></li>
<li><a href='http://edsmiley.com/?p=268' rel='bookmark' title='Permanent Link: Bookmarks for March 16th through March 26th'>Bookmarks for March 16th through March 26th</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=427</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting tidbits from this week</title>
		<link>http://edsmiley.com/?p=428</link>
		<comments>http://edsmiley.com/?p=428#comments</comments>
		<pubDate>Sat, 20 Mar 2010 02:24:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://edsmiley.com/?p=428</guid>
		<description><![CDATA[Here are some interesting articles from this week: - Google releases Skipfish &#8211; Skipfish is a open source and automated web application scanner.  It is written in C and can run on Linux, FreeBSD, Mac OS X, and Windows.  Have not had a chance to try it out yet, but appears to be similar to [...]


Related posts:<ol><li><a href='http://edsmiley.com/?p=297' rel='bookmark' title='Permanent Link: Great week for Webcasts/Podcasts or Cheap Training'>Great week for Webcasts/Podcasts or Cheap Training</a></li>
<li><a href='http://edsmiley.com/?p=16' rel='bookmark' title='Permanent Link: Download Aperture Tutorials'>Download Aperture Tutorials</a></li>
<li><a href='http://edsmiley.com/?p=423' rel='bookmark' title='Permanent Link: Bookmarks for March 14th through March 18th'>Bookmarks for March 14th through March 18th</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Here are some interesting articles from this week:</p>
<p>- <strong>Google releases <a href="http://code.google.com/p/skipfish/" target="_blank">Skipfish</a> &#8211; </strong>Skipfish is a open source and automated web application scanner.  It is written in C and can run on Linux, FreeBSD, Mac OS X, and Windows.  Have not had a chance to try it out yet, but appears to be similar to <a href="http://cirt.net/nikto2" target="_blank">Nikto</a>.  The <a href="http://redspin.com/blog" target="_blank">Redspin Blog</a> has a good initial <a href="http://www.redspin.com/blog/2010/03/19/skipfish-google-enters-the-web-scanner-fray/" target="_blank">write up</a> on the install and some basic features.</p>
<p>- <strong><a href="http://www.securityninja.co.uk/" target="_blank">The Security Ninja</a> has <a href="http://www.securityninja.co.uk/?s=burp" target="_blank">posted some great tutorials</a> on the <a href="http://www.portswigger.net/suite/" target="_blank">Burp Suite</a></strong>.  If you have not tried Burp Suite, what are you waiting for??  It allows you to attack web applications with both manual and automated techniques.  It is available for free with some higher level functionality disabled.  However, it is quite cheap for what it does at $225/year.  Anyhow, the tutorials on the SN site are excellent and cover the <a href="http://www.securityninja.co.uk/burp-suite-tutorial-the-intruder-tool" target="_blank">intruder</a>, <a href="http://www.securityninja.co.uk/burp-suite-tutorial-repeater-and-comparer-tools" target="_blank">repeater and comparer</a> tools and plans to go over the rest of the suite.  Check it out!</p>
<p>- <strong><a href="http://www.securitytube.net/" target="_blank">SecurityTube</a> Launches SecurityTube Questions -</strong><a href="http://questions.securitytube.net/" target="_blank"> SecurityTube Questions</a> has launched and <em>is aimed to helping hackers, infosec professionals, enthusiasts and students solve security related problems</em>.<em> </em>There are quite a few questions and lots of great answers.  Something to keep bookmarked and check back often.</p>
<p>- <strong>Pen Testing the Web with Firefox -</strong> <a href="http://www.scribd.com/doc/28590479/Black-Hat-Webcast-Pen-Testing-the-Web-with-Firefox" target="_blank">Slides</a> to the excellent Black Hat webinar given by <a href="http://www.twitter.com/theprez98" target="_blank">Michael &#8220;theprez98&#8243; Schaerer</a> describing lots of great plugins to allow you to Pen Test websites.  There is also a great list of Web Application Security Penetration testing plugins found <a href="https://addons.mozilla.org/en-US/firefox/collection/webappsec" target="_blank">here</a>.</p>
<p>- <strong><a href="http://windowsir.blogspot.com/2009/02/looking-for-bad-stuff-part-i.html" target="_blank">Looking for the Bad Stuff, Part 1</a> </strong>- Yet another great post from <a href="http://windowsir.blogspot.com/" target="_blank">Harlan Carvey</a> about searching Windows drives for bad things.  Gives lots of great tips on where to start, which log files to look though and many others.  Check out the comments section for some more great discussion.  As mentioned before, Harlan&#8217;s <a href="http://www.amazon.com/Windows-Forensic-Analysis-Toolkit-Second/dp/1597494224" target="_blank">Windows Forensics Analysis</a> is a MUST READ, along with his <a href="http://windowsir.blogspot.com/" target="_blank">site</a>.</p>


<p>Related posts:<ol><li><a href='http://edsmiley.com/?p=297' rel='bookmark' title='Permanent Link: Great week for Webcasts/Podcasts or Cheap Training'>Great week for Webcasts/Podcasts or Cheap Training</a></li>
<li><a href='http://edsmiley.com/?p=16' rel='bookmark' title='Permanent Link: Download Aperture Tutorials'>Download Aperture Tutorials</a></li>
<li><a href='http://edsmiley.com/?p=423' rel='bookmark' title='Permanent Link: Bookmarks for March 14th through March 18th'>Bookmarks for March 14th through March 18th</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://edsmiley.com/?feed=rss2&amp;p=428</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
