<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security Basics (basics) Mailing List</title>
<link>http://seclists.org/#basics</link>
<atom:link href="http://seclists.org/rss/basics.rss" rel="self" type="application/rss+xml" />
<description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: exploiting Microsoft IIS5 NTLM and Basic authentication bypass</title><description>Posted by abc_at_xyz.com on Jul 3&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
Check this out:
&lt;br /&gt;
&lt;p&gt;http://www.securityfocus.com/archive/1/469238
&lt;br /&gt;
&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;
Securing Apache Web Server with thawte Digital Certificate
&lt;br /&gt;
In this guide we examine the importance of...</description>
<link>http://seclists.org/basics/2009/Jul/0006.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jul/0006.html</guid>
<pubDate>3 Jul 2009 21:04:07 -0000</pubDate></item>
<item><title>exploiting Microsoft IIS5 NTLM and Basic authentication bypass</title><description>Posted by Juan B on Jul 2&lt;p&gt;


&lt;p&gt;
Hi All,
&lt;br /&gt;
&lt;p&gt;I am doing a web site pentest for a client, acunetix scanner informs that the site is vulnerable to Microsoft IIS5 NTLM and Basic authentication bypass, any Idea how to exploit it?
&lt;br /&gt;
&lt;p&gt;from where to begin ?
&lt;br /&gt;
&lt;p&gt;THanks a lot !
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;Juan
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/basics/2009/Jul/0005.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jul/0005.html</guid>
<pubDate>Thu, 2 Jul 2009 21:31:15 -0700 (PDT)</pubDate></item>
<item><title>Multi thread</title><description>Posted by Antão Miguel Chantre on Jul 2&lt;p&gt;


&lt;p&gt;
Hi
&lt;br /&gt;
I Would like to know if is possible to see the all thread in a Linix System
&lt;br /&gt;
&lt;p&gt;Thanks
&lt;br /&gt;
AMChantre
&lt;br /&gt;
&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;
Securing Apache Web Server with thawte Digital Certificate
&lt;br /&gt;
In this guide we examine the importance of Apache-SSL and who...</description>
<link>http://seclists.org/basics/2009/Jul/0004.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jul/0004.html</guid>
<pubDate>Thu, 2 Jul 2009 16:42:04 -0100</pubDate></item>
<item><title>[SuSe Linux] SecCheck tool by Marc Heuse</title><description>Posted by Andre Rodrigues on Jul 2&lt;p&gt;


&lt;p&gt;
Hi,

I need to understand some issues reported by the seccheck tool that runs on linux boxes.

I´ve searched docs and howto´s on the internet but found anything.

Here are some examples:
_______________

Changes in your daily security configuration:

* Changes (+: new entries, -: removed...</description>
<link>http://seclists.org/basics/2009/Jul/0003.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jul/0003.html</guid>
<pubDate>Thu, 2 Jul 2009 03:25:44 -0700 (PDT)</pubDate></item>
<item><title>Re: SSH Trojans</title><description>Posted by Jim Mellander on Jun 30&lt;p&gt;


&lt;p&gt;
Daniel Hood wrote:
&lt;br /&gt;
&amp;gt; List,
&lt;br /&gt;
&amp;gt; 
&lt;br /&gt;
&amp;gt; Im looking into SSH Trojans, just a general understanding of them so I
&lt;br /&gt;
&amp;gt; can hopefully someday tell the difference between an SSH Trojan and
&lt;br /&gt;
&amp;gt; the rear end of my heel and not have to make stupid &amp;quot;AM I HAX0RED?!?&amp;quot;
&lt;br /&gt;
&amp;gt; forum posts. But...</description>
<link>http://seclists.org/basics/2009/Jul/0002.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jul/0002.html</guid>
<pubDate>Tue, 30 Jun 2009 14:34:55 -0700</pubDate></item>
<item><title>RE: Blocking traffic by Country to reduce spam</title><description>Posted by Andreas Heinzelmann on Jul 1&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;IP Blocking based on country allocation is the worst you can do. Picture
&lt;br /&gt;
this: your customer is on a business tripp in India and it is not
&lt;br /&gt;
possible
&lt;br /&gt;
to access resources due to his then Indian IP.
&lt;br /&gt;
&lt;p&gt;I made the same experiences with my Bank Account in the US. At present I
&lt;br /&gt;
am located in...</description>
<link>http://seclists.org/basics/2009/Jul/0001.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jul/0001.html</guid>
<pubDate>Wed, 1 Jul 2009 14:01:21 +0200</pubDate></item>
<item><title>Re: Port question</title><description>Posted by Ansgar Wiechers on Jun 29&lt;p&gt;


&lt;p&gt;
On 2009-06-25 Marco Shaw wrote:
&lt;br /&gt;
&amp;gt;&amp;gt; And don&#39;t bother with &amp;quot;Shields Up&amp;quot;. If you want to do a portscan, use
&lt;br /&gt;
&amp;gt;&amp;gt; something like nmap.
&lt;br /&gt;
&amp;gt; 
&lt;br /&gt;
&amp;gt; Since this is a basics list...
&lt;br /&gt;
&amp;gt; 
&lt;br /&gt;
&amp;gt; Now, let&#39;s qualify that a bit...  Not everyone is technically savvy
&lt;br /&gt;
&amp;gt; enough to...</description>
<link>http://seclists.org/basics/2009/Jun/0186.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0186.html</guid>
<pubDate>Mon, 29 Jun 2009 20:21:57 +0200</pubDate></item>
<item><title>Re: Blocking traffic by Country to reduce spam</title><description>Posted by J. Oquendo on Jun 29&lt;p&gt;


&lt;p&gt;
chmod1777_at_mydotcom&amp;#46;com wrote:
&lt;br /&gt;
&amp;gt; I looked and wasn&#39;t able to find the thread in this list, but I do have the site that I mentioned (I had it bookmarked).
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; http://www.countryipblocks.net/
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; It formats the lists in whatever way your choose, depending on how you&#39;ll use...</description>
<link>http://seclists.org/basics/2009/Jun/0185.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0185.html</guid>
<pubDate>Mon, 29 Jun 2009 12:32:43 -0400</pubDate></item>
<item><title>Re: Port question</title><description>Posted by Ansgar Wiechers on Jun 29&lt;p&gt;


&lt;p&gt;
On 2009-06-26 Murda Mcloud wrote:
&lt;br /&gt;
&amp;gt;&amp;gt; If anything, you should be worried about ports that show up as
&lt;br /&gt;
&amp;gt;&amp;gt; &amp;quot;stealth&amp;quot;.
&lt;br /&gt;
&amp;gt; 
&lt;br /&gt;
&amp;gt; Hey Ansgar-do you mean because there is no way of knowing exactly what
&lt;br /&gt;
&amp;gt; your system is doing with the packet? Therefore no way of knowing...</description>
<link>http://seclists.org/basics/2009/Jun/0184.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0184.html</guid>
<pubDate>Mon, 29 Jun 2009 20:39:27 +0200</pubDate></item>
<item><title>RE: Port question</title><description>Posted by Murda Mcloud on Jun 26&lt;p&gt;


&lt;p&gt;
&amp;gt;&amp;gt;If anything, you should be worried about ports that show up as &amp;quot;stealth&amp;quot;.
&lt;br /&gt;
&lt;p&gt;Hey Ansgar-do you mean because there is no way of knowing exactly what your
&lt;br /&gt;
system is doing with the packet? Therefore no way of knowing that it has
&lt;br /&gt;
done the &#39;right&#39; thing? I suppose it could be &#39;did...</description>
<link>http://seclists.org/basics/2009/Jun/0183.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0183.html</guid>
<pubDate>Fri, 26 Jun 2009 14:11:10 +1000</pubDate></item>
<item><title>SSH Trojans</title><description>Posted by Daniel Hood on Jun 26&lt;p&gt;


&lt;p&gt;
List,
&lt;br /&gt;
&lt;p&gt;Im looking into SSH Trojans, just a general understanding of them so I
&lt;br /&gt;
can hopefully someday tell the difference between an SSH Trojan and
&lt;br /&gt;
the rear end of my heel and not have to make stupid &amp;quot;AM I HAX0RED?!?&amp;quot;
&lt;br /&gt;
forum posts. But after a couple of hours of googling though, I can&#39;t...</description>
<link>http://seclists.org/basics/2009/Jun/0182.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0182.html</guid>
<pubDate>Fri, 26 Jun 2009 14:06:54 +1000</pubDate></item>
<item><title>Designing a capture the flag event</title><description>Posted by Chris Teodorski on Jun 25&lt;p&gt;


&lt;p&gt;
Hello all,
&lt;br /&gt;
&lt;p&gt;We are in the process of launching a security user group in Pittsburgh
&lt;br /&gt;
(Pittsug -- www.pittsug.org).  For the kick-off meeting, we are going
&lt;br /&gt;
to have an offensive CTF game.  We have some ideas on how to do this
&lt;br /&gt;
(and we&#39;ve googled a good bit) but I was wondering if anyone on the
&lt;br /&gt;...</description>
<link>http://seclists.org/basics/2009/Jun/0181.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0181.html</guid>
<pubDate>Thu, 25 Jun 2009 14:14:29 -0400</pubDate></item>
<item><title>RE: Port question</title><description>Posted by Ian Bradshaw on Jun 25&lt;p&gt;


&lt;p&gt;
I think &#39;stealth&#39; means it wont respond with anything to packets sent.
&lt;br /&gt;
&lt;p&gt;&#39;closed&#39; means it will positively respond saying your not allowed to use this port.
&lt;br /&gt;
&lt;p&gt;Generally, either is fine, as they will both result in the same action .. i.e. nothing getting though.
&lt;br /&gt;
&lt;p&gt;Some people prefer to have them all...</description>
<link>http://seclists.org/basics/2009/Jun/0180.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0180.html</guid>
<pubDate>Thu, 25 Jun 2009 17:16:03 +0100</pubDate></item>
<item><title>RE: Blocking traffic by Country to reduce spam</title><description>Posted by Tom Farrar on Jun 25&lt;p&gt;


&lt;p&gt;
I&#39;ve used this method before, and it is effective. My problem with it is
&lt;br /&gt;
the risk to reliable mail delivery; who knows when someone outside of
&lt;br /&gt;
the UK/USA or with a mail relay in Paris will need to mail you. I mean,
&lt;br /&gt;
I never e-mail outside of the UK or USA, but I&#39;d go batsh!t if gmail
&lt;br /&gt;
started...</description>
<link>http://seclists.org/basics/2009/Jun/0179.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0179.html</guid>
<pubDate>Thu, 25 Jun 2009 17:15:05 +0100</pubDate></item>
<item><title>Re: Port question</title><description>Posted by Marco Shaw on Jun 25&lt;p&gt;


&lt;p&gt;
&amp;gt; And don&#39;t bother with &amp;quot;Shields Up&amp;quot;. If you want to do a portscan, use
&lt;br /&gt;
&amp;gt; something like nmap.
&lt;br /&gt;
&lt;p&gt;Since this is a basics list...
&lt;br /&gt;
&lt;p&gt;Now, let&#39;s qualify that a bit...  Not everyone is technically savvy
&lt;br /&gt;
enough to know what to do with such a statement.  Nmap requires you
&lt;br /&gt;
have a system...</description>
<link>http://seclists.org/basics/2009/Jun/0178.html</link><guid isPermaLink="true">http://seclists.org/basics/2009/Jun/0178.html</guid>
<pubDate>Thu, 25 Jun 2009 09:12:43 -0700</pubDate></item>
</channel></rss>