<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Daily Dave</title>
    <link>http://seclists.org/#dailydave</link>
    <atom:link href="http://seclists.org/rss/dailydave.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by &lt;a href=&quot;http://www.immunitysec.com/&quot;&gt;ImmunitySec&lt;/a&gt; founder Dave Aitel and many security luminaries participate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.</description>
    <pubDate>Tue, 22 May 2012 13:45:03 GMT</pubDate>
    <lastBuildDate>Tue, 22 May 2012 13:45:03 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>zeus plug-in</title>
    <link>http://seclists.org/dailydave/2012/q2/48</link>
    <description>&lt;p&gt;Posted by dan on May 22&lt;/p&gt;Has anyone here analyzed the Leprechaun(sp?) plug-in for Zeus?&lt;br&gt;
&lt;br&gt;
--dan&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 13:39:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/48</guid>
  </item>


  <item>
    <title>Tool of the day!</title>
    <link>http://seclists.org/dailydave/2012/q2/47</link>
    <description>&lt;p&gt;Posted by Dave Aitel on May 21&lt;/p&gt;So every sub-genre of hacker has their own set of specialized knowledge.&lt;br&gt;
And in the sub-genre that &amp;quot;sees a lot of mailspools&amp;quot; (which you could&lt;br&gt;
label &amp;quot;Unix Hackers&amp;quot;) you often have this problem where you have a lot&lt;br&gt;
of email, and you want to quickly distill it down to &amp;quot;files that are&lt;br&gt;
interesting&amp;quot;. Of course, emails come in all shapes and sizes and are all&lt;br&gt;
decoded differently and it&amp;apos;s a bit annoying to figure out...&lt;br&gt;</description>
    <pubDate>Mon, 21 May 2012 19:18:02 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/47</guid>
  </item>


  <item>
    <title>Howard Schmidt</title>
    <link>http://seclists.org/dailydave/2012/q2/46</link>
    <description>&lt;p&gt;Posted by Dave Aitel on May 18&lt;/p&gt;&amp;quot;As for getting into the power grid, I can&amp;apos;t see that that&amp;apos;s realistic,&amp;quot;&lt;br&gt;
Schmidt said. &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.wired.com/threatlevel/2010/03/schmidt-cyberwar/&quot;&gt;http://www.wired.com/threatlevel/2010/03/schmidt-cyberwar/&lt;/a&gt;&amp;gt;&lt;br&gt;
&lt;br&gt;
Likewise as that Threat Point article from the start of his time in the&lt;br&gt;
White House points out: &lt;br&gt;
&lt;br&gt;
&amp;quot;People have to recognize that when we close the door and go home, we&lt;br&gt;
are just normal netizens like anyone else,&amp;quot; Schmidt said. &amp;quot;I&amp;apos;ve been in&lt;br&gt;
the internet...&lt;br&gt;</description>
    <pubDate>Fri, 18 May 2012 14:03:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/46</guid>
  </item>


  <item>
    <title>Ten years.</title>
    <link>http://seclists.org/dailydave/2012/q2/45</link>
    <description>&lt;p&gt;Posted by Dave Aitel on May 17&lt;/p&gt;Immunity is ten years old now - and like any ten year old, it is&lt;br&gt;
interested mostly in shiny things that bleep and bloop. :&amp;gt;&lt;br&gt;
&lt;br&gt;
But also like any ten year old we are growing and always hungry, and so&lt;br&gt;
if you&amp;apos;re interested in working in the new DC office or Miami Beach HQ,&lt;br&gt;
please let me know. We only have one perk and that is this: We&amp;apos;ll keep&lt;br&gt;
you entirely focused on breaking into things in one way or another.&lt;br&gt;
&lt;br&gt;
-dave&lt;br&gt;</description>
    <pubDate>Thu, 17 May 2012 14:34:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/45</guid>
  </item>


  <item>
    <title>New INFILTRATE 2012 Movie is up! With surprise	introduction by Halvar!</title>
    <link>http://seclists.org/dailydave/2012/q2/44</link>
    <description>&lt;p&gt;Posted by Dave Aitel on May 14&lt;/p&gt;OH: &amp;quot;So....static analysis! Let&amp;apos;s talk about it!&amp;quot; (Long pause follows.)&lt;br&gt;
&lt;br&gt;
That&amp;apos;s pretty much straight out of most parties I go to! Luckily, there&lt;br&gt;
are a few people who can go into static analysis to great levels of&lt;br&gt;
depth, and some of them give talks at INFILTRATE. :&amp;gt;&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.immunityinc.com/infiltratemovies/movies/JulienVanegue.mp4&quot;&gt;http://www.immunityinc.com/infiltratemovies/movies/JulienVanegue.mp4&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
-dave&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 19:11:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/44</guid>
  </item>
  <item>
    <title>Re: Mobile Phone Security Survey</title>
    <link>http://seclists.org/dailydave/2012/q2/43</link>
    <description>&lt;p&gt;Posted by Hamid on May 14&lt;/p&gt;There were some issues regarding some optional questions that has been&lt;br&gt;
marked as mandatory mistakenly. Thanks to quick feedbacks they are&lt;br&gt;
fixed now.&lt;br&gt;
&lt;br&gt;
Hamid&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 14:10:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/43</guid>
  </item>


  <item>
    <title>Mobile Phone Security Survey</title>
    <link>http://seclists.org/dailydave/2012/q2/42</link>
    <description>&lt;p&gt;Posted by Hamid on May 11&lt;/p&gt;Hello DD!&lt;br&gt;
&lt;br&gt;
Few weeks ago I had a writeup about (in)security trends in mobile phones&lt;br&gt;
and now I&amp;apos;ve reached to a point that I need results of a survey to&lt;br&gt;
validate and confirm some facts that are going to be covered in paper.&lt;br&gt;
&lt;br&gt;
I would appreciate your help by participating in this survey, or be even&lt;br&gt;
more awesome and spread it among your friends that are not security geeks!&lt;br&gt;
&lt;br&gt;
Survey link:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://goo.gl/pQO02&quot;&gt;http://goo.gl/pQO02&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Thank you!&lt;br&gt;
Hamid&lt;br&gt;</description>
    <pubDate>Fri, 11 May 2012 18:15:54 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/42</guid>
  </item>


  <item>
    <title>With a real team, it&apos;s not about the numbers</title>
    <link>http://seclists.org/dailydave/2012/q2/41</link>
    <description>&lt;p&gt;Posted by Dave Aitel on May 01&lt;/p&gt;I find articles like the recent one in Forbes &lt;br&gt;
&amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/&quot;&gt;http://www.forbes.com/sites/andygreenberg/2012/03/21/meet-the-hackers-who-sell-spies-the-tools-to-crack-your-pc-and-get-paid-six-figure-fees/&lt;/a&gt;&amp;gt;&lt;br&gt;
 quite funny in a way - and likewise talks about &amp;quot;rootite&amp;quot; and bug mining and so forth. Part of this is because &lt;br&gt;
philosophically I know that teams who focus on the money tend to lose. Obviously you need a lot of money to get things &lt;br&gt;
done in...&lt;br&gt;</description>
    <pubDate>Tue, 01 May 2012 14:15:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/41</guid>
  </item>


  <item>
    <title>72 hours</title>
    <link>http://seclists.org/dailydave/2012/q2/40</link>
    <description>&lt;p&gt;Posted by Shari Bermudez on Apr 26&lt;/p&gt;Just a reminder that there are only 72 business hours remaining before&lt;br&gt;
registration closes for the WebHacking and Master training classes.&lt;br&gt;
Sign up today. Call 786-220-0600 or email training () immunityinc com &lt;br&gt;
The 20% discount offer for re-tweeting still stands.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://immunityinc.com/education-currentschedule.shtml&quot;&gt;http://immunityinc.com/education-currentschedule.shtml&lt;/a&gt;&lt;br&gt;</description>
    <pubDate>Thu, 26 Apr 2012 21:24:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/40</guid>
  </item>
  <item>
    <title>Spooked at RSA 2012</title>
    <link>http://seclists.org/dailydave/2012/q2/39</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Apr 26&lt;/p&gt;So we put my RSA 2012 talk up, along with the comments from the viewers that RSA collected. &lt;br&gt;
&lt;br&gt;
I 100% agree with every comment in the feedback form, which include such bon mots such as &amp;quot;You reek of pride&amp;quot;. Frankly, &lt;br&gt;
I am quite proud of what the offensive community has been able to do over the last ten years. And I was a bit hurried &lt;br&gt;
during the actual talk (the one below is from my 6am-dry-run-in-hotel-room since they didn&amp;apos;t record...&lt;br&gt;</description>
    <pubDate>Thu, 26 Apr 2012 14:22:23 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/39</guid>
  </item>


  <item>
    <title>What&apos;s happening at SyScan&apos;12 Singapore</title>
    <link>http://seclists.org/dailydave/2012/q2/38</link>
    <description>&lt;p&gt;Posted by Thomas Lim on Apr 25&lt;/p&gt;Dear Dailydave readers&lt;br&gt;
&lt;br&gt;
Do you know what&amp;apos;s going to happen at SyScan&amp;apos;12 Singapore next week?&lt;br&gt;
&lt;br&gt;
BEER, BEER, BEER, BEER, BEER, BEER, BEER, BEER....&lt;br&gt;
&lt;br&gt;
13 AWESOME SPEAKERS:&lt;br&gt;
a. Stefan Esser (i0n1c)&lt;br&gt;
b. Chris Valasek (nudeaberdasher)&lt;br&gt;
c. Tarjei Mandt (kernelpool)&lt;br&gt;
d. Alex Ionescu&lt;br&gt;
e. Edgar Barbosa (0pC0de)&lt;br&gt;
f. Jon Oberheide&lt;br&gt;
g. Brett Moore (antic0de)&lt;br&gt;
h. James Burton (Jayji)&lt;br&gt;
i. Seung Jin Lee (Beist)&lt;br&gt;
j. Ryan MacArthur (Backpacker)&lt;br&gt;
k. Loukas (snare)&lt;br&gt;
l....&lt;br&gt;</description>
    <pubDate>Wed, 25 Apr 2012 14:46:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/38</guid>
  </item>


  <item>
    <title>Save yourself 20% by tweeting</title>
    <link>http://seclists.org/dailydave/2012/q2/37</link>
    <description>&lt;p&gt;Posted by Shari Bermudez on Apr 23&lt;/p&gt;Want to come to our June Master or WebHacking class but do not want to&lt;br&gt;
pay full price?  You can save yourself 20% in ~5 minutes by following&lt;br&gt;
these simple steps:&lt;br&gt;
&lt;br&gt;
(1) If you are not already doing so, follow us on Twitter @immunityinc&lt;br&gt;
and/or @infiltratecon.&lt;br&gt;
&lt;br&gt;
(2) ReTweet this tweet from today: &amp;quot;RT and receive 20% off June&lt;br&gt;
training classes when you sign up before 4/27! ow.ly/asvSG e-mail&lt;br&gt;
admin () immunityinc for info!&amp;quot;&lt;br&gt;
&lt;br&gt;
(3) Email training...&lt;br&gt;</description>
    <pubDate>Mon, 23 Apr 2012 19:48:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/37</guid>
  </item>


  <item>
    <title>TIME IS RUNNING OUT</title>
    <link>http://seclists.org/dailydave/2012/q2/36</link>
    <description>&lt;p&gt;Posted by Shari Bermudez on Apr 20&lt;/p&gt;Time is running out to sign up for our June WebHacking and Master&lt;br&gt;
Training Classes.   If you are thinking about reserving your seat but&lt;br&gt;
have not done so, the time to sign up is now.&lt;br&gt;
&lt;br&gt;
_June 4-6, 2012 - WebHacking Class:  _&lt;br&gt;
Immunity&amp;apos;s WebHacking course focuses on understanding common web&lt;br&gt;
hacking techniques by having students exploit vulnerable systems.&lt;br&gt;
Security professionals with some hands on web hacking experience will&lt;br&gt;
get the most out of...&lt;br&gt;</description>
    <pubDate>Fri, 20 Apr 2012 14:29:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/36</guid>
  </item>


  <item>
    <title>RIT!</title>
    <link>http://seclists.org/dailydave/2012/q2/35</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Apr 18&lt;/p&gt;Chris and Miguel are heading up to RIT today and will be around tomorrow&lt;br&gt;
recruiting for Immunity. If you&amp;apos;re at or near RIT and you want to hear&lt;br&gt;
about the fun stuff they&amp;apos;re working (which you can help work on!) then&lt;br&gt;
send admin () immunityinc com &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:admin&quot;&gt;mailto:admin&lt;/a&gt; () immunityinc com&amp;gt; a quick email&lt;br&gt;
and they&amp;apos;ll vector you in! I hear there will be real wings served the&lt;br&gt;
way only upstate NY knows how. I miss those wings, I have to say....&lt;br&gt;</description>
    <pubDate>Wed, 18 Apr 2012 16:34:49 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/35</guid>
  </item>
  <item>
    <title>Re: CISPA == MAPP</title>
    <link>http://seclists.org/dailydave/2012/q2/34</link>
    <description>&lt;p&gt;Posted by Richard Bejtlich on Apr 18&lt;/p&gt;Hi Allison,&lt;br&gt;
&lt;br&gt;
I have a different view -- I&amp;apos;ll try not to step on too many toes. :)&lt;br&gt;
&lt;br&gt;
The problem is people are approaching this as a technical problem.&lt;br&gt;
It&amp;apos;s a trust problem.&lt;br&gt;
&lt;br&gt;
The incentive is to not share.  There is no incentive for a company to&lt;br&gt;
tell anyone that they&amp;apos;ve been breached.&lt;br&gt;
&lt;br&gt;
The bill in question doesn&amp;apos;t say the government is entitled to your&lt;br&gt;
information.  They&amp;apos;re trying to improve the incentives for companies&lt;br&gt;
to...&lt;br&gt;</description>
    <pubDate>Wed, 18 Apr 2012 16:28:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2012/q2/34</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

