<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Penetration Testing</title>
    <link>http://seclists.org/#pen-test</link>
    <atom:link href="http://seclists.org/rss/pen-test.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
    <pubDate>Thu, 05 Nov 2009 18:45:03 GMT</pubDate>
    <lastBuildDate>Thu, 05 Nov 2009 18:45:03 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Metasploit</title>
    <link>http://seclists.org/pen-test/2009/Nov/32</link>
    <description>&lt;p&gt;Posted by admin on Nov 05&lt;/p&gt;Jon Kibler wrote:&lt;br&gt;
&lt;br&gt;
Thanks for the heads up. I have only scanned the first few chapters so far, I will make time for this.&lt;br&gt;
&lt;br&gt;
Thanks again&lt;br&gt;
Dave&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 18:34:12 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/32</guid>
  </item>
  <item>
    <title>Re: Brief Analysis of inj3ct0r.com</title>
    <link>http://seclists.org/pen-test/2009/Nov/31</link>
    <description>&lt;p&gt;Posted by Jon Kibler on Nov 05&lt;/p&gt;djamel djamel wrote:&lt;br&gt;
&lt;br&gt;
Milw0rm will be back soon. See: &amp;quot;Milw0rm / Str0ke Not Dead&amp;quot; from yesterday.&lt;br&gt;
&lt;br&gt;
Jon&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 18:28:56 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/31</guid>
  </item>
  <item>
    <title>Re: Pen Tester Scripting</title>
    <link>http://seclists.org/pen-test/2009/Nov/30</link>
    <description>&lt;p&gt;Posted by Robin Wood on Nov 05&lt;/p&gt;2009/11/3 infosec posts &amp;lt;infosec.posts () gmail com&amp;gt;:&lt;br&gt;
&lt;br&gt;
The project is just starting up so we don't have much on there at the&lt;br&gt;
moment but the number of people offering to submit scripts is growing&lt;br&gt;
so hopefully it won't be long till we get to a point of having&lt;br&gt;
something for everyone.&lt;br&gt;
&lt;br&gt;
If you have something you'd like to submit please send it to&lt;br&gt;
scripts () pentesterscripting com . These don't have to be hardcore, l33t&lt;br&gt;
scripts just anything you...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 18:21:38 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/30</guid>
  </item>
  <item>
    <title>Re: SQL passwords</title>
    <link>http://seclists.org/pen-test/2009/Nov/29</link>
    <description>&lt;p&gt;Posted by Martin Rublik on Nov 05&lt;/p&gt;Well if you use 2005 SQL server it would be definitely faster to&lt;br&gt;
attack an uppercase hash. The complexity will reduce significantly.&lt;br&gt;
For example if you have n character password then there are 2^n&lt;br&gt;
possibilities for mixcase password for every uppercase password.&lt;br&gt;
&lt;br&gt;
As for the worst case it is quite simple, it depends on how many&lt;br&gt;
characters you will use :), if you use Cain for password cracking it&lt;br&gt;
will show you how much time is remaining.&lt;br&gt;
&lt;br&gt;
Best...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 18:06:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/29</guid>
  </item>
  <item>
    <title>Analyzing Shellcode</title>
    <link>http://seclists.org/pen-test/2009/Nov/28</link>
    <description>&lt;p&gt;Posted by cAs on Nov 05&lt;/p&gt;Good evening everybody,&lt;br&gt;
&lt;br&gt;
i am trying to analyze the shellcode used in this exploit:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.milw0rm.com/exploits/7477&quot;&gt;http://www.milw0rm.com/exploits/7477&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
If i echo the unescaped shellcode i only get wierd chinese (i think)&lt;br&gt;
letters.&lt;br&gt;
&lt;br&gt;
What's the right way to analyze what kind of shellcode is beeing used&lt;br&gt;
and what command is beeing executed by it.&lt;br&gt;
&lt;br&gt;
Greetings,&lt;br&gt;
cAs&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
This list is sponsored by: Information...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 18:00:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/28</guid>
  </item>
  <item>
    <title>Re: Brief Analysis of inj3ct0r.com</title>
    <link>http://seclists.org/pen-test/2009/Nov/27</link>
    <description>&lt;p&gt;Posted by djamel djamel on Nov 05&lt;/p&gt;is there any GOOD alternative other than packet storm???&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
This list is sponsored by: Information Assurance Certification Review Board&lt;br&gt;
&lt;br&gt;
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT &lt;br&gt;
and CEPT certs require a full practical examination in order to become certified. &lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.iacertification.org&quot;&gt;http://www.iacertification.org&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Thu, 05 Nov 2009 18:00:16 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/27</guid>
  </item>


  <item>
    <title>Re: True Source Code Analysis for Security</title>
    <link>http://seclists.org/pen-test/2009/Nov/26</link>
    <description>&lt;p&gt;Posted by Jason Ross on Nov 04&lt;/p&gt;Agreed, it feels &amp;quot;slimy&amp;quot;. That was my first reaction to this thread as well.&lt;br&gt;
But then I tried to identify what exactly it was that cause me to feel that way.&lt;br&gt;
&lt;br&gt;
   * The white paper itself doesn't try to market their product that I&lt;br&gt;
could see.&lt;br&gt;
   * The web site it's available from doesn't require an email address or any&lt;br&gt;
      other form of information before allowing you to download the document.&lt;br&gt;
   * The original post does not attempt to...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 23:04:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/26</guid>
  </item>
  <item>
    <title>Milw0rm / Str0ke Not Dead</title>
    <link>http://seclists.org/pen-test/2009/Nov/25</link>
    <description>&lt;p&gt;Posted by Jon Kibler on Nov 04&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
I know by now that many of you have seen the story at...&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://bl4cksecurity.blogspot.com/2009/11/str0ke-milworms-funeral-is-this-friday.html&quot;&gt;http://bl4cksecurity.blogspot.com/2009/11/str0ke-milworms-funeral-is-this-friday.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
I know this because MANY of you have written me off-list with the message &amp;quot;have&lt;br&gt;
you heard the news?&amp;quot;... If I did not personally reply, I am sorry, but my inbox&lt;br&gt;
has been swamped today.&lt;br&gt;
&lt;br&gt;
Well, good news and bad news here.&lt;br&gt;
&lt;br&gt;
Bad news first. The above story is a hoax. Str0ke is alive, well, and...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 22:52:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/25</guid>
  </item>
  <item>
    <title>MITM attack report on smartphones</title>
    <link>http://seclists.org/pen-test/2009/Nov/24</link>
    <description>&lt;p&gt;Posted by Mayank Aggarwal on Nov 04&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
I thought of sharing this report which we recently posted on the following link:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://threatcenter.smobilesystems.com/?cat=4&quot;&gt;http://threatcenter.smobilesystems.com/?cat=4&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Abstract:&lt;br&gt;
According to a survey conducted by a mobile advertising researcher, AdMob, smartphone users are driving up the use of &lt;br&gt;
Wi-Fi hotspots. The result of the survey indicates that there were 550 million smartphone Wi-Fi requests in Western &lt;br&gt;
Europe alone in 2008, a 132% increase for the year. AdMob said that 42%...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 22:36:16 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/24</guid>
  </item>
  <item>
    <title>Re: Get a Clue! WAS: Re: Metasploit</title>
    <link>http://seclists.org/pen-test/2009/Nov/23</link>
    <description>&lt;p&gt;Posted by Eric Milam on Nov 04&lt;/p&gt;Although I agree with some of what Jon states below.  I think it was &lt;br&gt;
rude not to include the link.  It did only take me about 5 seconds with &lt;br&gt;
Google.  (Although I got the info in Sept through the Offsec Blog...and &lt;br&gt;
you guys should sign up for the newsletter!)&lt;br&gt;
&lt;br&gt;
In the immortal words of muts -&amp;gt; Try Harder!&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.offensive-security.com/metasploit-unleashed/&quot;&gt;http://www.offensive-security.com/metasploit-unleashed/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Best of luck!&lt;br&gt;
&lt;br&gt;
Eric&lt;br&gt;
OSCP!&lt;br&gt;
&lt;br&gt;
Jon Kibler wrote:...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 22:28:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/23</guid>
  </item>
  <item>
    <title>Re: port scan to juniper fw</title>
    <link>http://seclists.org/pen-test/2009/Nov/22</link>
    <description>&lt;p&gt;Posted by aditya mukadam on Nov 04&lt;/p&gt;Yes, I have verified and also have the relevant logs with me from the&lt;br&gt;
'flow filter' .&lt;br&gt;
&lt;br&gt;
Thanks,&lt;br&gt;
Aditya Govind Mukadam&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
This list is sponsored by: Information Assurance Certification Review Board&lt;br&gt;
&lt;br&gt;
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT &lt;br&gt;
and CEPT certs require a full practical examination in order to...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 21:02:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/22</guid>
  </item>
  <item>
    <title>Re: port scan to juniper fw</title>
    <link>http://seclists.org/pen-test/2009/Nov/21</link>
    <description>&lt;p&gt;Posted by Chris Brenton on Nov 04&lt;/p&gt;Have you verified this? Last time I tested their anti-spoofing it didn't&lt;br&gt;
actually drop the packet. It would pass it through and then follow it up&lt;br&gt;
with a host unreachable (to the target) in order to kill the session.&lt;br&gt;
&lt;br&gt;
What was odd was the TTL would get decremented by 2. My best guess is it&lt;br&gt;
was the single honed IPS code dealing with the spoofing and that was&lt;br&gt;
introducing an extra routing hop.&lt;br&gt;
&lt;br&gt;
I have not tested this for a few years, so they may have...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 20:57:54 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/21</guid>
  </item>
  <item>
    <title>Get a Clue! WAS: Re: Metasploit</title>
    <link>http://seclists.org/pen-test/2009/Nov/20</link>
    <description>&lt;p&gt;Posted by Jon Kibler on Nov 04&lt;/p&gt;Jon Kibler wrote:&lt;br&gt;
&amp;lt;SNIP!&amp;gt;&lt;br&gt;
&lt;br&gt;
&amp;lt;SNIP!&amp;gt;&lt;br&gt;
&lt;br&gt;
I hate to reply to my own email, BUT...&lt;br&gt;
&lt;br&gt;
&amp;lt;rant&amp;gt;&lt;br&gt;
I received dozens of (mostly off-list) messages, &amp;quot;I cannot find the course, will&lt;br&gt;
you please send me a link&amp;quot;? Folks, get a clue! How can you call yourself a pen&lt;br&gt;
tester if you cannot find an online course hiding in plain site? How do you&lt;br&gt;
expect to be able to penetrate systems through obscure weaknesses when you miss&lt;br&gt;
the 6,500Kgm gorilla...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 20:52:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/20</guid>
  </item>
  <item>
    <title>winAUTOPWN 2.0 - Introducing winAUTOPWN GUI - Now you can sleep</title>
    <link>http://seclists.org/pen-test/2009/Nov/19</link>
    <description>&lt;p&gt;Posted by QUAKER DOOMER on Nov 04&lt;/p&gt;Dear all,&lt;br&gt;
&lt;br&gt;
After a long break and a lot of Unpolished SITA releases of the previous version, I am finally releasing &lt;br&gt;
winAUTOPWN version 2.0&lt;br&gt;
&lt;br&gt;
winAUTOPWN or WINDOWS AUTOPWN version 2.0 now has a GUI (winAUTOPWN_GUI.exe) to initiate the main &lt;br&gt;
console winAUTOPWN.exe&lt;br&gt;
winAUTOPWN now supports all console arguments which can also be fed interactively.&lt;br&gt;
This version covers almost all remote exploits from 2009 start uptill October 2009. Though a few are...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 20:43:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/19</guid>
  </item>
  <item>
    <title>Re: Metasploit</title>
    <link>http://seclists.org/pen-test/2009/Nov/18</link>
    <description>&lt;p&gt;Posted by jfvanmeter on Nov 04&lt;/p&gt;How well do you know metasploit?&lt;br&gt;
&lt;br&gt;
I thought I knew it fairly well. Turns out, I do know half of what I thought I&lt;br&gt;
knew about metasploit. I am really surprised at how much metasploit can do that&lt;br&gt;
I did not know about.&lt;br&gt;
&lt;br&gt;
I am currently working through Offensive Security's Metasploit Unleashed online&lt;br&gt;
course. It is currently a &amp;quot;donate to HFC&amp;quot;-ware course. It is a great course, and&lt;br&gt;
I highly recommend it! I have learned a lot and I am only about...&lt;br&gt;</description>
    <pubDate>Wed, 04 Nov 2009 20:26:16 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2009/Nov/18</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
