<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Penetration Testing (pen-test) Mailing List</title>
<link>http://seclists.org/#pen-test</link>
<atom:link href="http://seclists.org/rss/pen-test.rss" rel="self" type="application/rss+xml" />
<description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by SD List on Jul 1&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
Definitively, a large number of tools and scanners are able to identify
&lt;br /&gt;
such files.
&lt;br /&gt;
&lt;p&gt;Take a look here, we provide a list of tools (guyz in this list already
&lt;br /&gt;
enumerated the best) you may need
&lt;br /&gt;
(http://www.security-database.com/toolswatch/+-Application-Scanner-+.html)
&lt;br /&gt;
&lt;p&gt;Cheers
&lt;br /&gt;
&lt;p&gt;N.
&lt;br /&gt;
&lt;p&gt;&amp;gt;...</description>
<link>http://seclists.org/pen-test/2009/Jul/0005.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jul/0005.html</guid>
<pubDate>Wed, 1 Jul 2009 18:11:57 +0200 (CEST)</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by Nikhil Wagholikar on Jul 1&lt;p&gt;


&lt;p&gt;
Hello Juan Kinunt,
&lt;br /&gt;
&lt;p&gt;May be you can have a look at &#39;IntelliTamper&#39;.
&lt;br /&gt;
&lt;p&gt;IntelliTamper is able to scan a website for unlisted files and folders
&lt;br /&gt;
with a dictionary based scan.
&lt;br /&gt;
&lt;p&gt;More Info: http://www.intellitamper.com/
&lt;br /&gt;
Or Email to : tamper_at_engineer&amp;#46;com
&lt;br /&gt;
&lt;p&gt;Hope this helps!!
&lt;br /&gt;
&lt;p&gt;
---
Nikhil Wagholikar...</description>
<link>http://seclists.org/pen-test/2009/Jul/0004.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jul/0004.html</guid>
<pubDate>Wed, 1 Jul 2009 08:46:19 +0530</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by Jeremy Brown on Jul 2&lt;p&gt;


&lt;p&gt;
I think I may find an alternative than touch IntelliTamper...
&lt;br /&gt;
&lt;p&gt;http://www.milw0rm.com/search.php?dong=intellitamper
&lt;br /&gt;
&lt;p&gt;On Tue, Jun 30, 2009 at 11:16 PM, Nikhil
&lt;br /&gt;
Wagholikar&amp;lt;visitnikhil_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Hello Juan Kinunt,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; May be you can have a look at &#39;IntelliTamper&#39;.
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2009/Jul/0003.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jul/0003.html</guid>
<pubDate>Thu, 2 Jul 2009 12:34:55 -0400</pubDate></item>
<item><title>SOURCE Barcelona Speaker Line-Up</title><description>Posted by Christian Martorella on Jul 1&lt;p&gt;


&lt;p&gt;
SOURCE Barcelona 2009 Announcement
&lt;br /&gt;
----------------------- ----------------------------------
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;www.sourceconference.com
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;September 21-22, 2009
&lt;br /&gt;
EARLY BIRD RATE EXPIRES...</description>
<link>http://seclists.org/pen-test/2009/Jul/0002.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jul/0002.html</guid>
<pubDate>Wed, 1 Jul 2009 22:14:55 +0200</pubDate></item>
<item><title>RE: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by Tal Argoni on Jul 1&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
Wikto is the perfect tool for this kind of job
&lt;br /&gt;
http://www.sensepost.com
&lt;br /&gt;
&lt;p&gt;-----Original Message-----
&lt;br /&gt;
From: listbounce_at_securityfocus&amp;#46;com [mailto:listbounce_at_securityfocus&amp;#46;com] On Behalf Of Juan Kinunt
&lt;br /&gt;
Sent: Tuesday, June 30, 2009 3:47 PM
&lt;br /&gt;
To: pen-test_at_securityfocus&amp;#46;com
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2009/Jul/0001.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jul/0001.html</guid>
<pubDate>Wed, 1 Jul 2009 17:01:32 +0300</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by Todd Haverkos on Jun 30&lt;p&gt;


&lt;p&gt;
Juan Kinunt &amp;lt;kinunt_at_gmail&amp;#46;com&amp;gt; writes:
&lt;br /&gt;
&lt;p&gt;&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I would like to know if anyone knows a tool that first spiders the web
&lt;br /&gt;
&amp;gt; in order to enumerate al files and scripts it detects and then look
&lt;br /&gt;
&amp;gt; for this same files but with another extension. For example, first
&lt;br /&gt;
&amp;gt;...</description>
<link>http://seclists.org/pen-test/2009/Jun/0174.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0174.html</guid>
<pubDate>Tue, 30 Jun 2009 11:27:55 -0500</pubDate></item>
<item><title>Payloads for Burp Suite</title><description>Posted by Benjamin Greenfield on Jun 30&lt;p&gt;


&lt;p&gt;
Does anyone know of a source of free and legal attack payloads for the
&lt;br /&gt;
Burp Intruder?
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;I&#39;m particularly interested in payloads for SQL injection where the
&lt;br /&gt;
environment isn&#39;t known in advance.  Having a predefined list of
&lt;br /&gt;
payloads would be very helpful for me.
&lt;br /&gt;
&lt;p&gt;Thanks,
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/pen-test/2009/Jun/0173.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0173.html</guid>
<pubDate>Tue, 30 Jun 2009 12:53:43 -0400</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by pUm on Jun 30&lt;p&gt;


&lt;p&gt;
checkout the metasploit wmap extension. it is exactly what you&#39;re looking for.
&lt;br /&gt;
&lt;p&gt;2009/6/30 Juan Kinunt &amp;lt;kinunt_at_gmail&amp;#46;com&amp;gt;:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I would like to know if anyone knows a tool that first spiders the web
&lt;br /&gt;
&amp;gt; in order to enumerate al files and scripts it detects and then...</description>
<link>http://seclists.org/pen-test/2009/Jun/0172.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0172.html</guid>
<pubDate>Tue, 30 Jun 2009 16:37:41 +0100</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by Rogan Dawes on Jun 30&lt;p&gt;


&lt;p&gt;
Juan Kinunt wrote:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt; 
&lt;br /&gt;
&amp;gt; I would like to know if anyone knows a tool that first spiders the web
&lt;br /&gt;
&amp;gt; in order to enumerate al files and scripts it detects and then look
&lt;br /&gt;
&amp;gt; for this same files but with another extension. For example, first
&lt;br /&gt;
&amp;gt; spiders the web and enumerate:
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2009/Jun/0171.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0171.html</guid>
<pubDate>Tue, 30 Jun 2009 18:05:23 +0200</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by rajat swarup on Jun 30&lt;p&gt;


&lt;p&gt;
On Tue, Jun 30, 2009 at 8:47 AM, Juan Kinunt&amp;lt;kinunt_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I would like to know if anyone knows a tool that first spiders the web
&lt;br /&gt;
&amp;gt; in order to enumerate al files and scripts it detects and then look
&lt;br /&gt;
&amp;gt; for this same files but with another...</description>
<link>http://seclists.org/pen-test/2009/Jun/0170.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0170.html</guid>
<pubDate>Tue, 30 Jun 2009 13:56:23 -0400</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by jason_jones98_at_hotmail.com on Jun 30&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
Hi.
&lt;br /&gt;
&lt;p&gt;Paros proxy does this well, if you view the scan policy you will see settings you require to enable. Also you could create your own list and input that into owasp directory buster.
&lt;br /&gt;
&lt;p&gt;JJ
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/pen-test/2009/Jun/0169.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0169.html</guid>
<pubDate>30 Jun 2009 14:56:12 -0000</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by John Lampe on Jun 30&lt;p&gt;


&lt;p&gt;
Juan Kinunt wrote:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I would like to know if anyone knows a tool that first spiders the web
&lt;br /&gt;
&amp;gt; in order to enumerate al files and scripts it detects and then look
&lt;br /&gt;
&amp;gt; for this same files but with another extension. For example, first
&lt;br /&gt;
&amp;gt; spiders the web and enumerate:
&lt;br /&gt;
...</description>
<link>http://seclists.org/pen-test/2009/Jun/0168.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0168.html</guid>
<pubDate>Tue, 30 Jun 2009 11:56:01 -0500</pubDate></item>
<item><title>Re: Scanner for old files (.bak, ~, .old, etc.)</title><description>Posted by Sandro Gauci on Jun 30&lt;p&gt;


&lt;p&gt;
I guess this is a feature of many web application vulnerability
&lt;br /&gt;
scanners (not Nikto but the XSS/SQLi etc type). I&#39;ve used Acunetix&#39;s
&lt;br /&gt;
WVS and it does exactly what you describe.
&lt;br /&gt;
&lt;p&gt;- sandro
&lt;br /&gt;
w: http://enablesecurity.com/
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;&lt;p&gt;On Tue, Jun 30, 2009 at 2:47 PM, Juan Kinunt&amp;lt;kinunt_at_gmail&amp;#46;com&amp;gt;...</description>
<link>http://seclists.org/pen-test/2009/Jun/0167.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0167.html</guid>
<pubDate>Tue, 30 Jun 2009 17:23:13 +0200</pubDate></item>
<item><title>Fwd: South Carolina amp Alaska Privacy Breach Notice Laws Go Into  Effect July 1</title><description>Posted by Jeffrey Walton on Jun 30&lt;p&gt;


&lt;p&gt;
&amp;gt;From the folks at Attrition and the Dataloss DB.
&lt;br /&gt;
&lt;p&gt;The other 44 sates and terrirories can be found at
&lt;br /&gt;
http://www.ncsl.org/?tabid=13481.
&lt;br /&gt;
&lt;p&gt;---------- Forwarded message ----------
&lt;br /&gt;
From: security curmudgeon &amp;lt;jericho_at_attrition&amp;#46;org&amp;gt;
&lt;br /&gt;
Date: Tue, Jun 30, 2009 at 2:45 AM
&lt;br /&gt;
Subject: South...</description>
<link>http://seclists.org/pen-test/2009/Jun/0166.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0166.html</guid>
<pubDate>Tue, 30 Jun 2009 16:41:27 -0400</pubDate></item>
<item><title>Re: Firewall Scan</title><description>Posted by Chris Brenton on Jun 30&lt;p&gt;


&lt;p&gt;
Greets,
&lt;br /&gt;
&lt;p&gt;Actually, I believe Fydor dropped the Echo-Request probe in 4.x. nmap
&lt;br /&gt;
simply hits TCP/80 with a SYN or ACK, depending on the version. Either
&lt;br /&gt;
way, don&#39;t think this is nmap getting confused as hping produces similar
&lt;br /&gt;
results and it never probes first.
&lt;br /&gt;
&lt;p&gt;IPv7,
&lt;br /&gt;
&lt;p&gt;Try setting some TCP...</description>
<link>http://seclists.org/pen-test/2009/Jun/0165.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2009/Jun/0165.html</guid>
<pubDate>Tue, 30 Jun 2009 14:48:08 -0400</pubDate></item>
</channel></rss>