<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Penetration Testing</title>
    <link>http://seclists.org/#pen-test</link>
    <atom:link href="http://seclists.org/rss/pen-test.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
    <pubDate>Mon, 08 Feb 2010 07:45:03 GMT</pubDate>
    <lastBuildDate>Mon, 08 Feb 2010 07:45:03 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>RE: SMS Banking</title>
    <link>http://seclists.org/pen-test/2010/Feb/35</link>
    <description>&lt;p&gt;Posted by Craig S. Wright on Feb 07&lt;/p&gt;The solution needs to be based on risk.&lt;br&gt;
&lt;br&gt;
Where a system uses an SMS response with a separate system (such as a web&lt;br&gt;
page), the probability that the banking user is compromised and a fraud is&lt;br&gt;
committed, P(Compromise), can be calculated as:&lt;br&gt;
        P(Compromise) =  P(C.SMS) x P(C.PIN)&lt;br&gt;
&lt;br&gt;
Where:  P(C.SMS) is the probability of compromising the SMS function and &lt;br&gt;
                P(C.PIN) is the compromise of the user authentication method&lt;br&gt;
&lt;br&gt;
The user can...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 07:42:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/35</guid>
  </item>
  <item>
    <title>Tools Update - Fist week of February 2010</title>
    <link>http://seclists.org/pen-test/2010/Feb/34</link>
    <description>&lt;p&gt;Posted by SD List on Feb 07&lt;/p&gt;Hello&lt;br&gt;
&lt;br&gt;
Here is the site's newsletter &amp;quot;Security Database Tools Watch&amp;quot;&lt;br&gt;
(&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.security-database.com/toolswatch&quot;&gt;http://www.security-database.com/toolswatch&lt;/a&gt;).&lt;br&gt;
This letter summarizes the articles and news items published since 7 days.&lt;br&gt;
&lt;br&gt;
         New articles&lt;br&gt;
         --------------------------&lt;br&gt;
&lt;br&gt;
** Acunetix WVS v6.5 build 20100203 released **&lt;br&gt;
by  ToolsTracker&lt;br&gt;
- 3 February 2010&lt;br&gt;
&lt;br&gt;
Acunetix Web Vulnerability Scanner (WVS) is an automated web application&lt;br&gt;
security testing tool that...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 07:15:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/34</guid>
  </item>
  <item>
    <title>NEMESIS linux packet injection command line tool - IP options file as 	input argument</title>
    <link>http://seclists.org/pen-test/2010/Feb/33</link>
    <description>&lt;p&gt;Posted by woman on Feb 07&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
NEMESIS linux packet injection command line tool:&lt;br&gt;
================================================&lt;br&gt;
I am looking for some document or website that explains by example the&lt;br&gt;
content of the file that is used as input argument in IP/TCP OPTIONS&lt;br&gt;
&lt;br&gt;
nemesis ip -O file&lt;br&gt;
&lt;br&gt;
There is no details about it in the MAN pages or nemesis website.&lt;br&gt;
What file format is used: text, ASCII, hex?&lt;br&gt;
&lt;br&gt;
Thanks,&lt;br&gt;
woman...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 07:09:55 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/33</guid>
  </item>
  <item>
    <title>Re: pentesting voip network-please help</title>
    <link>http://seclists.org/pen-test/2010/Feb/32</link>
    <description>&lt;p&gt;Posted by Yiannis Koukouras on Feb 07&lt;/p&gt;Unfortunately not. Cain is basic in this category.&lt;br&gt;
It's true, if you want it to be done seriously....Backtrack is the answer...&lt;br&gt;
&lt;br&gt;
Ioannis (Yiannis) Koukouras&lt;br&gt;
CISSP, CISA, CISM&lt;br&gt;
MSc in Computer Systems Security&lt;br&gt;
BEng in Electronic Engineering&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.linkedin.com/in/ikoukouras&quot;&gt;http://www.linkedin.com/in/ikoukouras&lt;/a&gt;&lt;br&gt;
---&lt;br&gt;
The information contained in this communication is intended solely&lt;br&gt;
for  the  use  of the individual or entity to whom it is addressed&lt;br&gt;
and others authorized to receive...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 07:02:44 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/32</guid>
  </item>
  <item>
    <title>Re: SMS Banking</title>
    <link>http://seclists.org/pen-test/2010/Feb/31</link>
    <description>&lt;p&gt;Posted by Markus Matiaschek on Feb 07&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
I'd just like to make some comments, i didn't think about a solution&lt;br&gt;
for your problem.&lt;br&gt;
&lt;br&gt;
First of all i think that my Budi wibowo got something wrong regarding&lt;br&gt;
who is sending the PIN.&lt;br&gt;
&lt;br&gt;
Second, GSM is cracked: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://reflextor.com/trac/a51&quot;&gt;http://reflextor.com/trac/a51&lt;/a&gt; and can be&lt;br&gt;
intercepted and decrypted. You should take this into account.&lt;br&gt;
&lt;br&gt;
Third i think the only farely safe way to make money transfers is with&lt;br&gt;
transaction numbers, TANs. German banks send mobileTANs to...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 06:56:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/31</guid>
  </item>
  <item>
    <title>Dradis Framework v2.5 is out!</title>
    <link>http://seclists.org/pen-test/2010/Feb/30</link>
    <description>&lt;p&gt;Posted by etd on Feb 07&lt;/p&gt;Hi all,&lt;br&gt;
&lt;br&gt;
We have pushed a new major release of Dradis (an open source framework&lt;br&gt;
to enable effective information sharing), and it comes with a few new&lt;br&gt;
features [i]:&lt;br&gt;
&lt;br&gt;
 * Improved Note editor: bigger, easier to use and supports formatting!&lt;br&gt;
 * New First Time User Wizard&lt;br&gt;
 * Keep track of all the activity with the built-in RSS feed&lt;br&gt;
 * More plugins:&lt;br&gt;
   o New HTML Export reporting plugin.&lt;br&gt;
   o New Burp Upload plugin so you can use Burp Scanner output....&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 06:48:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/30</guid>
  </item>
  <item>
    <title>RE: SMS Banking</title>
    <link>http://seclists.org/pen-test/2010/Feb/29</link>
    <description>&lt;p&gt;Posted by Thor (Hammer of God) on Feb 07&lt;/p&gt;SMS based solutions are inherently insecure; not just from the application level, but from the carrier level.  You're &lt;br&gt;
assuming the carrier media is secure, which is not the case as Karsten showed at the CCC when he cracked GSM.  &lt;br&gt;
&lt;br&gt;
I think you would be far better served to create a client side application (client specific of course) where you could &lt;br&gt;
build security into the application itself, use SSL, etc for client-to-server inquiries and...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 06:44:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/29</guid>
  </item>
  <item>
    <title>Re: pentesting voip network-please help</title>
    <link>http://seclists.org/pen-test/2010/Feb/28</link>
    <description>&lt;p&gt;Posted by Todd Haverkos on Feb 07&lt;/p&gt;Yiannis Koukouras &amp;lt;ikoukouras () gmail com&amp;gt; writes:&lt;br&gt;
&lt;br&gt;
Does it work in Cisco environments though?  I honestly don't know.&lt;br&gt;
&lt;br&gt;
Absent a way to get onto the VOIP vlan , it's nice features would be&lt;br&gt;
sadly useless.  In most Cisco deployments, the phones themselves and&lt;br&gt;
all the call traffic are on a dedicated VLAN.&lt;br&gt;
&lt;br&gt;
When I've done such assessments, I've used voiphopper under Linux to&lt;br&gt;
dot he CDP dissection to find the VLAN and create the virtual...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 06:37:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/28</guid>
  </item>
  <item>
    <title>RE: Flash Web Application</title>
    <link>http://seclists.org/pen-test/2010/Feb/27</link>
    <description>&lt;p&gt;Posted by PortSwigger on Feb 07&lt;/p&gt;With Burp, you can get rid of the browser certificate warnings if you wish,&lt;br&gt;
by installing Burp's CA certificate in your browser. Burp generates a new CA&lt;br&gt;
certificate on installation, and creates a valid certificate for each domain&lt;br&gt;
you visit, signed by the CA cert. &lt;br&gt;
&lt;br&gt;
Further details, and instructions for installing the CA cert, can be found&lt;br&gt;
here:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://portswigger.net/proxy/servercerts.html&quot;&gt;http://portswigger.net/proxy/servercerts.html&lt;/a&gt; &lt;br&gt;
&lt;br&gt;
Cheers&lt;br&gt;
PortSwigger&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
From:...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 06:30:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/27</guid>
  </item>


  <item>
    <title>Re: Nessus, Harmful?</title>
    <link>http://seclists.org/pen-test/2010/Feb/26</link>
    <description>&lt;p&gt;Posted by Kevin Shaw on Feb 05&lt;/p&gt;I'm likely preaching to the choir here; but something I would advise &lt;br&gt;
with Nessus or any other vulnerability, configuration, patch or port &lt;br&gt;
scanning tool: know your target environment.  I work with a different &lt;br&gt;
network or communications medium - satellite, microwave - every week.  &lt;br&gt;
You tune your assessment for the equipment you are looking at - one &lt;br&gt;
setting may not break a fiber channel SAN while it will wreak havoc on a &lt;br&gt;
small office worth of...&lt;br&gt;</description>
    <pubDate>Fri, 05 Feb 2010 18:12:02 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/26</guid>
  </item>
  <item>
    <title>Re: SMS Banking</title>
    <link>http://seclists.org/pen-test/2010/Feb/25</link>
    <description>&lt;p&gt;Posted by Doug Farre on Feb 05&lt;/p&gt;Mobile phone numbers can be spoofed. My piece of advice is that all&lt;br&gt;
transactions must be acknowledged by the user. For instance, user&lt;br&gt;
makes a request, system asks the user if for confirmation, then the&lt;br&gt;
system proceeds.&lt;br&gt;
&lt;br&gt;
Also, keep in mind that a lost cell phone can mean the user's pin is&lt;br&gt;
compromised as the sms msgs are all stored in plain text.&lt;br&gt;</description>
    <pubDate>Fri, 05 Feb 2010 18:03:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/25</guid>
  </item>
  <item>
    <title>Re: SMS Banking</title>
    <link>http://seclists.org/pen-test/2010/Feb/24</link>
    <description>&lt;p&gt;Posted by Budi wibowo on Feb 05&lt;/p&gt;instead of using sms for putting the pin, please use flash sms.&lt;br&gt;
Safe and will not give any log on mobile phone.&lt;br&gt;
&lt;br&gt;
Regards&lt;br&gt;
Budi wibowo&lt;br&gt;
-----Original Message-----&lt;br&gt;
From: &amp;quot;M.D.Mufambisi&amp;quot; &amp;lt;mufambisi () gmail com&amp;gt;&lt;br&gt;
Date: Thu, 4 Feb 2010 18:20:22 &lt;br&gt;
To: &amp;lt;pen-test () securityfocus com&amp;gt;; &amp;lt;security-basics () securityfocus com&amp;gt;&lt;br&gt;
Subject: SMS Banking&lt;br&gt;
&lt;br&gt;
Hi All,&lt;br&gt;
&lt;br&gt;
Im designing an SMS baking application but i need to research on the...&lt;br&gt;</description>
    <pubDate>Fri, 05 Feb 2010 17:29:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/24</guid>
  </item>
  <item>
    <title>Re: Flash Web Application</title>
    <link>http://seclists.org/pen-test/2010/Feb/23</link>
    <description>&lt;p&gt;Posted by Zaki Akhmad on Feb 05&lt;/p&gt;There's no problem on the certificate. After I use webscarab as proxy,&lt;br&gt;
I can't click the flash application :( So I can't proceed.&lt;br&gt;</description>
    <pubDate>Fri, 05 Feb 2010 17:03:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/23</guid>
  </item>
  <item>
    <title>Re: pentesting voip network-please help</title>
    <link>http://seclists.org/pen-test/2010/Feb/22</link>
    <description>&lt;p&gt;Posted by YGN Ethical Hacker Group on Feb 05&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.tacticalvoip.com/tools.html&quot;&gt;http://www.tacticalvoip.com/tools.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
YGN Ethical Hacker Group&lt;br&gt;
Yangon, Myanmar&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://yehg.net&quot;&gt;http://yehg.net&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
This list is sponsored by: Information Assurance Certification Review Board&lt;br&gt;
&lt;br&gt;
Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT &lt;br&gt;
and CEPT certs require a full practical examination in order to become certified....&lt;br&gt;</description>
    <pubDate>Fri, 05 Feb 2010 16:21:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/22</guid>
  </item>
  <item>
    <title>SMS Banking</title>
    <link>http://seclists.org/pen-test/2010/Feb/21</link>
    <description>&lt;p&gt;Posted by M.D.Mufambisi on Feb 05&lt;/p&gt;Hi All,&lt;br&gt;
&lt;br&gt;
Im designing an SMS baking application but i need to research on the&lt;br&gt;
security risks involved first. Im thinking of subscribing mobile phone&lt;br&gt;
number along with a pin. eg Number 222-222-222 PIN 20029. So when the&lt;br&gt;
individual wants to enquire his balance, he sends a text messgae like&lt;br&gt;
Bal 20029 i.e. BAL PINNUMBER. The control here is that the sms and pin&lt;br&gt;
has to come from the subscribed number and only that number. I also&lt;br&gt;
want to be able to...&lt;br&gt;</description>
    <pubDate>Fri, 05 Feb 2010 16:16:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2010/Feb/21</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
