<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Penetration Testing</title>
    <link>http://seclists.org/#pen-test</link>
    <atom:link href="http://seclists.org/rss/pen-test.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
    <pubDate>Wed, 16 May 2012 21:15:04 GMT</pubDate>
    <lastBuildDate>Wed, 16 May 2012 21:15:04 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Securing Citrix</title>
    <link>http://seclists.org/pen-test/2012/May/9</link>
    <description>&lt;p&gt;Posted by Adrián Puente Z. on May 16&lt;/p&gt;Hi everyone!&lt;br&gt;
&lt;br&gt;
I am looking for a good reference to secure a Citrix server to avoid a user to gain acces to the operating system. So &lt;br&gt;
far I have some ideas like restricting the execution of the cmd.exe and (maybe) explorer.exe from with a group policy &lt;br&gt;
in the domain. &lt;br&gt;
&lt;br&gt;
If you know about any document I can look at or have any experience about this that want to share I will be very &lt;br&gt;
thankful. Thanks in advance. &lt;br&gt;
&lt;br&gt;
Regards, &lt;br&gt;
&lt;br&gt;
---&lt;br&gt;
Adrián Puente Z....&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 21:05:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/9</guid>
  </item>
  <item>
    <title>Re: Question of Likelihood</title>
    <link>http://seclists.org/pen-test/2012/May/8</link>
    <description>&lt;p&gt;Posted by Pete Herzog on May 16&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
Have you looked into the OSSTMM ravs- attack surface classification &lt;br&gt;
and metrics? It would help you categorize the order in the way you &lt;br&gt;
want here- by what they do and not some guessed weighting or priority &lt;br&gt;
system. Basically it would let you prioritize by 5 vulnerability &lt;br&gt;
classifications and that way if something provides access in any way &lt;br&gt;
it&amp;apos;s classified as a higher priority than something that just gives an &lt;br&gt;
exposure.&lt;br&gt;
&lt;br&gt;
Sincerely,...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 19:01:34 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/8</guid>
  </item>


  <item>
    <title>sslcaudit 1.0 released</title>
    <link>http://seclists.org/pen-test/2012/May/7</link>
    <description>&lt;p&gt;Posted by Alexandre Bezroutchko on May 15&lt;/p&gt;Hello,&lt;br&gt;
&lt;br&gt;
I would like to announce the release of sslcaudit 1.0.&lt;br&gt;
&lt;br&gt;
The goal of sslcaudit project is to develop a utility to automate &lt;br&gt;
testing SSL/TLS clients for&lt;br&gt;
resistance against MITM attacks. It is useful for testing thick clients, &lt;br&gt;
mobile applications,&lt;br&gt;
appliances, pretty much anything communicating over SSL/TLS over TCP.&lt;br&gt;
&lt;br&gt;
PDF user-guide is available here: &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.gremwell.com/sslcaudit_files/doc/sslcaudit-user-guide-1.0.pdf&quot;&gt;http://www.gremwell.com/sslcaudit_files/doc/sslcaudit-user-guide-1.0.pdf&lt;/a&gt;&lt;br&gt;
Download and...&lt;br&gt;</description>
    <pubDate>Tue, 15 May 2012 10:30:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/7</guid>
  </item>


  <item>
    <title>Re: Question of Likelihood</title>
    <link>http://seclists.org/pen-test/2012/May/6</link>
    <description>&lt;p&gt;Posted by Justin Rogosky on May 14&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
Carnal 0wnage is  doing a blog series about this very subject.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://carnal0wnage.attackresearch.com/2012/04/from-low-to-pwned-0-intro.html&quot;&gt;http://carnal0wnage.attackresearch.com/2012/04/from-low-to-pwned-0-intro.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
My opinion is that if you are doing a report, it would be of more&lt;br&gt;
value to list the vulnerabilities separately with the reformatted tool&lt;br&gt;
output (or other methodology you are applying to list them as &amp;quot;low&amp;quot;).&lt;br&gt;
But add a separate section that shows how the various &amp;quot;enabling&amp;quot;...&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 20:03:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/6</guid>
  </item>
  <item>
    <title>Question of Likelihood</title>
    <link>http://seclists.org/pen-test/2012/May/5</link>
    <description>&lt;p&gt;Posted by Pen Testar on May 14&lt;/p&gt;I&amp;apos;m testing an app with sensitive information that is full of holes. Reflected and persisted XSS, CRSF, various &lt;br&gt;
injection attacks… you name it. &lt;br&gt;
&lt;br&gt;
You also have a bunch of vulns that aren’t typically of high likelihood, but in the presence of the other vulns above &lt;br&gt;
(I’ll call them the “enabling” vulns), some of these lows are easier to exploit. When you rank, do you rank each vuln &lt;br&gt;
independently or in context of others? &lt;br&gt;
&lt;br&gt;
I can see...&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 18:46:27 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/5</guid>
  </item>


  <item>
    <title>t2&apos;12: Call for Papers 2012 (Helsinki / Finland)</title>
    <link>http://seclists.org/pen-test/2012/May/4</link>
    <description>&lt;p&gt;Posted by Tomi Tuominen on May 12&lt;/p&gt;                  # t2&amp;apos;12 - Call For Papers #&lt;br&gt;
                      Helsinki, Finland&lt;br&gt;
                    October 25 - 26, 2012&lt;br&gt;
&lt;br&gt;
We are pleased to announce the annual t2&amp;apos;12 infosec conference, which&lt;br&gt;
will take place in Helsinki, Finland, from October 25 to 26, 2012.&lt;br&gt;
&lt;br&gt;
We are looking for original, preferably technical presentations in the&lt;br&gt;
fields of information security. Presentations should last a minimum of&lt;br&gt;
60 minutes and a maximum of two...&lt;br&gt;</description>
    <pubDate>Sun, 13 May 2012 00:05:55 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/4</guid>
  </item>


  <item>
    <title>A survey on web application attacks</title>
    <link>http://seclists.org/pen-test/2012/May/3</link>
    <description>&lt;p&gt;Posted by Hannes Holm on May 11&lt;/p&gt;Hi pen-test subscribers,&lt;br&gt;
&lt;br&gt;
I am researching the domain consensus regarding the effectiveness of different web application firewalls (WAF)s and &lt;br&gt;
would be glad if you could spare a few minutes of your time to answer a survey on the topic. &lt;br&gt;
&lt;br&gt;
By completing this survey you will:&lt;br&gt;
&lt;br&gt;
  * Help build valuable domain consensus on the topic of WAF effectiveness.&lt;br&gt;
  * Be able to compare your answers to the answers of others.&lt;br&gt;
  * Have the chance to win a 100...&lt;br&gt;</description>
    <pubDate>Sat, 12 May 2012 00:34:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/3</guid>
  </item>


  <item>
    <title>Announce: Italian Hacker Game Cracca al Tesoro - Crack  A Treasure</title>
    <link>http://seclists.org/pen-test/2012/May/2</link>
    <description>&lt;p&gt;Posted by Aspy on May 04&lt;/p&gt;It is the 6 th edition of the game.&lt;br&gt;
&lt;br&gt;
It &amp;apos;s very much like a treasure hunt but more... hight tech!&lt;br&gt;
The team need to find five hidden access point within a city, crack&lt;br&gt;
them, then find the servers behind them, hack  them  to find clues to&lt;br&gt;
the next target ...&lt;br&gt;
&lt;br&gt;
Next date: Genoa, Italy, May 12&lt;br&gt;
Joining is free.&lt;br&gt;
&lt;br&gt;
Web Site&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.wardriving.it&quot;&gt;http://www.wardriving.it&lt;/a&gt;&lt;br&gt;</description>
    <pubDate>Fri, 04 May 2012 17:01:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/2</guid>
  </item>


  <item>
    <title>nullcon Delhi 2012 Call for Paper/Call for Event</title>
    <link>http://seclists.org/pen-test/2012/May/1</link>
    <description>&lt;p&gt;Posted by nullcon on May 01&lt;/p&gt;Hi All,&lt;br&gt;
&lt;br&gt;
For the very first time nullcon now comes to Delhi - to showcase cutting&lt;br&gt;
edge security technologies and discuss new attack vectors and security&lt;br&gt;
threats among the  Corporate world and the Government sector. The event&lt;br&gt;
brings together thought leaders,Corporates, Government and security&lt;br&gt;
professionals all under one roof.&lt;br&gt;
&lt;br&gt;
Prototype:&lt;br&gt;
-------------&lt;br&gt;
We are introducing a new sub-event - Prototype at nullcon Delhi 2012. The&lt;br&gt;
event provides...&lt;br&gt;</description>
    <pubDate>Wed, 02 May 2012 04:22:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/1</guid>
  </item>


  <item>
    <title>xSQL Scanner 1.6 - Released</title>
    <link>http://seclists.org/pen-test/2012/May/0</link>
    <description>&lt;p&gt;Posted by Rodrigo Matuck on May 01&lt;/p&gt;Hi&lt;br&gt;
&lt;br&gt;
Everyone&lt;br&gt;
&lt;br&gt;
New version of xSQL Scanner is available with following features:&lt;br&gt;
&lt;br&gt;
- PostgreSQL support added;&lt;br&gt;
- SQL PortScan updated;&lt;br&gt;
- Exceptions fixed;&lt;br&gt;
- Progressbar bug fixed;&lt;br&gt;
- MSSQL 7 DoS module added.&lt;br&gt;
- MSSQL Empty password exploit module added.&lt;br&gt;
- Session support added&lt;br&gt;
- Visual modified&lt;br&gt;
- Minor Bugs fixed&lt;br&gt;
- Auto-detect feature fixed&lt;br&gt;
&lt;br&gt;
Also i uploaded the xTSCrack with bugs fixed.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.4shared.com/zip/4YrGt7hG/xsqlscanner-16.html&quot;&gt;http://www.4shared.com/zip/4YrGt7hG/xsqlscanner-16.html&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Tue, 01 May 2012 16:48:52 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/May/0</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>[Tool update] VoIP Hopper 2.04 released</title>
    <link>http://seclists.org/pen-test/2012/Apr/15</link>
    <description>&lt;p&gt;Posted by Jason Ostrom on Apr 29&lt;/p&gt;VoIP Hopper 2.04 security tool is released:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://voiphopper.sourceforge.net&quot;&gt;http://voiphopper.sourceforge.net&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
New Avaya, Alcatel-Lucent, and LLDP-MED spoofing support.  Thanks to Nicolas Roux of France for his Alcatel source &lt;br&gt;
contribution and debugging help.  The Alcatel support has only been partially tested on a production network - I&amp;apos;m &lt;br&gt;
requesting the help from anyone who has access to Alcatel-Lucent to test the three new modes of VoIP Hopper, and please &lt;br&gt;
let me know....&lt;br&gt;</description>
    <pubDate>Sun, 29 Apr 2012 17:40:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/Apr/15</guid>
  </item>


  <item>
    <title>Anti-fingerprinting techniques</title>
    <link>http://seclists.org/pen-test/2012/Apr/14</link>
    <description>&lt;p&gt;Posted by cr0hn on Apr 25&lt;/p&gt;Hello everybody!&lt;br&gt;
&lt;br&gt;
I just released the slides of a course about anti-fingerprinting&lt;br&gt;
techniques. The course talking about:&lt;br&gt;
– A brief introduction of FreeBSD.&lt;br&gt;
– How fingerprinting works.&lt;br&gt;
– How defeat the fingerprinting test.&lt;br&gt;
– Practical examples for evade the test for some services:&lt;br&gt;
+ Web server.&lt;br&gt;
+ FTP server.&lt;br&gt;
+ SSH server.&lt;br&gt;
- A long section dedicated for WordPress.&lt;br&gt;
+ Fingerprinting methods.&lt;br&gt;
+ Tools to test it.&lt;br&gt;
+ Protection techniques.&lt;br&gt;
&lt;br&gt;
I...&lt;br&gt;</description>
    <pubDate>Wed, 25 Apr 2012 14:34:55 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/Apr/14</guid>
  </item>


  <item>
    <title>[HITB-Announce] HITB Magazine Issue 008 (now with print edition!)</title>
    <link>http://seclists.org/pen-test/2012/Apr/13</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Apr 23&lt;/p&gt;The 8th issue of the HITB Quarterly Magazine is now available for download!&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://magazine.hitb.org/&quot;&gt;http://magazine.hitb.org/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
This edition is a little bit &amp;apos;lighter&amp;apos; than previous issues as the&lt;br&gt;
editorial team is busy working on an extra special release for our 10th&lt;br&gt;
year anniversary conference in October, HITBSecConf2012 - Malaysia.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://conference.hitb.org/hitbsecconf2012kul/&quot;&gt;http://conference.hitb.org/hitbsecconf2012kul/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
For the first time ever though, we&amp;apos;re making print editions of the&lt;br&gt;
magazine...&lt;br&gt;</description>
    <pubDate>Tue, 24 Apr 2012 02:40:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/Apr/13</guid>
  </item>


  <item>
    <title>[New tool] - Exploit Pack - Web Security</title>
    <link>http://seclists.org/pen-test/2012/Apr/12</link>
    <description>&lt;p&gt;Posted by noreply () exploitpack com on Apr 23&lt;/p&gt;Exploit Pack - Web Security Edition&lt;br&gt;
&lt;br&gt;
This tool allows you to take control of remote browsers, steal social&lt;br&gt;
network credentials, obtain persistence on it, DDoS and more.&lt;br&gt;
Demo: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.youtube.com/watch?v=B_AYyRFNokI&quot;&gt;http://www.youtube.com/watch?v=B_AYyRFNokI&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Main features:&lt;br&gt;
- Hacking of Gmail, Yahoo, Facebook, Live, Linkedin&lt;br&gt;
- Session persistence&lt;br&gt;
- 0day exploits included&lt;br&gt;
- Remote browser control&lt;br&gt;
- DDoS by creating botnets&lt;br&gt;
- Launch remote exploits&lt;br&gt;
- Steal credentials&lt;br&gt;
&lt;br&gt;
Questions? support...&lt;br&gt;</description>
    <pubDate>Mon, 23 Apr 2012 22:17:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/Apr/12</guid>
  </item>


  <item>
    <title>Ruxcon 2012 Call For Papers</title>
    <link>http://seclists.org/pen-test/2012/Apr/11</link>
    <description>&lt;p&gt;Posted by cfp on Apr 19&lt;/p&gt;Ruxcon 2012 Call For Papers&lt;br&gt;
&lt;br&gt;
The Ruxcon team is pleased to announce the call for papers for the 2012 annual Ruxcon conference.&lt;br&gt;
&lt;br&gt;
This year the conference will take place over the weekend of 20th and 21st of October at the CQ Function Centre, &lt;br&gt;
Melbourne, Australia.&lt;br&gt;
&lt;br&gt;
The deadline for submissions is the 15th of July.&lt;br&gt;
&lt;br&gt;
* What is Ruxcon?&lt;br&gt;
&lt;br&gt;
Ruxcon is the premier technical computer security conference in the Australia. The conference aims to bring...&lt;br&gt;</description>
    <pubDate>Thu, 19 Apr 2012 10:50:52 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/pen-test/2012/Apr/11</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

