<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>Dissecting</title>
	
	<link>http://disse.cting.org</link>
	<description>rough networking, insecurities and dirty sources</description>
	<lastBuildDate>Thu, 26 Jan 2012 19:21:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Dissecting" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="dissecting" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Backbox 2.01</title>
		<link>http://disse.cting.org/blog/2012/01/03/backbox-2.01/</link>
		<comments>http://disse.cting.org/blog/2012/01/03/backbox-2.01/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 08:19:12 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[backbox]]></category>
		<category><![CDATA[distribution]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[Weevely]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1498</guid>
		<description><![CDATA[Aprofitto di questo lento inizio di 2012 per annunciare l&#8217;uscita della nuova BackBox 2.01, la cui community ha da subito adottato Weevely e ha contribuito a farla crescere. Riporto il sommario dal sito ufficiale: The BackBox team is proud to announce the release 2.01 of BackBox Linux.The new release include features such as Ubuntu 11.04, [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2012/01/03/backbox-2.01/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Weevely 0.5.1 – NIDS evasion, cookies and SQL shell</title>
		<link>http://disse.cting.org/blog/2011/12/28/weevely-0.5-nids-evasion-cookies-and-sql-shells/</link>
		<comments>http://disse.cting.org/blog/2011/12/28/weevely-0.5-nids-evasion-cookies-and-sql-shells/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 14:04:41 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[How to]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Weevely]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[nids evasion]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sql]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1449</guid>
		<description><![CDATA[Weevely 0.5.1 torna più nascosta e utile di prima, qua il sito ufficiale e il download diretto dell&#8217;archivio .tar o del pacchetto .deb per Ubuntu/BackBox/Debian. Dopo la lettura di due ottime analisi atte a rilevare Weevely via auditing del codice o con NIDS rules di Snort, ho riscritto e il codice backdoor e il protocollo [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/12/28/weevely-0.5-nids-evasion-cookies-and-sql-shells/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Weevely 0.4 OUT</title>
		<link>http://disse.cting.org/blog/2011/10/20/weevely-0.4-out/</link>
		<comments>http://disse.cting.org/blog/2011/10/20/weevely-0.4-out/#comments</comments>
		<pubDate>Thu, 20 Oct 2011 20:37:41 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[Weevely]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1407</guid>
		<description><![CDATA[Weevely da semplice simulatore di terminale diventa uno strumento essenziale per il post exploiting di un server web, o per chi desidera semplicemente gestire il proprio spazio web come se avesse accesso telnet/ssh alla macchina remota. E&#8217; sufficiente caricare la parte server di Weevely su una installazione HTTP e accedere via client alla macchina remota. [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/10/20/weevely-0.4-out/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Modular Weevely</title>
		<link>http://disse.cting.org/blog/2011/08/28/modular-weevely/</link>
		<comments>http://disse.cting.org/blog/2011/08/28/modular-weevely/#comments</comments>
		<pubDate>Sun, 28 Aug 2011 19:14:59 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[Weevely]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[modules]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1335</guid>
		<description><![CDATA[Ho approfittato della calma di fine estate per applicare alcune modifiche a weevely che avevo in mente da tempo. D&#8217;altra parte la creatura è stata inclusa nelle maggiori distribuzioni di pentesting: prima BackBox, poi BlackBuntu e Backtrack 5, e si merita qualche attenzione. &#160; Il nuovo Weevely è modulare e crea un layer tra utente [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/08/28/modular-weevely/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Link: Clickjacking Attacks Unresolved</title>
		<link>http://disse.cting.org/blog/2011/07/21/link-clickjacking-attacks-unresolved/</link>
		<comments>http://disse.cting.org/blog/2011/07/21/link-clickjacking-attacks-unresolved/#comments</comments>
		<pubDate>Thu, 21 Jul 2011 12:27:17 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1330</guid>
		<description><![CDATA[Ottima analisi dei metodi di clickjacking compresa di POC su come deanonimizzare gli utenti Facebook, Twitter e Google (Oauth). Link.]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/07/21/link-clickjacking-attacks-unresolved/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forumfree &amp; Forumcommunity stored XSS</title>
		<link>http://disse.cting.org/blog/2011/06/07/forumfree-forumcommunity-html-injection/</link>
		<comments>http://disse.cting.org/blog/2011/06/07/forumfree-forumcommunity-html-injection/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 13:36:10 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[forumcommunity]]></category>
		<category><![CDATA[forumfree]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1273</guid>
		<description><![CDATA[Aggiornamento del 12/6/11: il bug è stato fixato. Sulla sezione advisories della comunità di backbox è stato pubblicato un paper che descrive una vulnerabilità stored XSS scoperto da bl4k3 e system_overide per iniettare del codice HTML nei forum del circuito forumfree e forumcommunity. &#160; Nei suddetti forum è volontariamente permesso utilizzare il tag &#60;embed&#62; nella [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/06/07/forumfree-forumcommunity-html-injection/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Fastweb Myfastpage authentication control bypass</title>
		<link>http://disse.cting.org/blog/2011/06/03/fastweb-myfastpage-panel-control-hack/</link>
		<comments>http://disse.cting.org/blog/2011/06/03/fastweb-myfastpage-panel-control-hack/#comments</comments>
		<pubDate>Fri, 03 Jun 2011 11:39:44 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[fastweb]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[myfastpage]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1213</guid>
		<description><![CDATA[Aggiornamento 12/06/11 : la vulnerabilità XSS è stata fixata. Aggiornamento 08/06/11 : i pannelli sono stati riorganizzati, e ora l&#8217;utente può imporre l&#8217;autenticazione per accedere alla configurazione dell&#8217;abbonamento. L&#8217;XSS è ancora presente, ora è anche possibile configurare ESSID e password della wifi. La configurazione di default rimane comunque vulnerabile. &#160; Un utente Fastweb che visita [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/06/03/fastweb-myfastpage-panel-control-hack/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>LSB image and audio steganography</title>
		<link>http://disse.cting.org/blog/2011/05/30/lsb-image-and-audio-steganography/</link>
		<comments>http://disse.cting.org/blog/2011/05/30/lsb-image-and-audio-steganography/#comments</comments>
		<pubDate>Mon, 30 May 2011 21:35:14 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[How to]]></category>
		<category><![CDATA[Snippets]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[C]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[steganography]]></category>
		<category><![CDATA[tunneling]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1155</guid>
		<description><![CDATA[&#160; I formati multimediali digitali tendono a essere particolarmente inaccurati poiché non necessitano di precisione: l&#8217;orecchio umano non coglie le minime differenze di suono. Un&#8217;orchestra registrata da due dispositivi diversi produce un segnale digitale sensibilmente diverso, ma una volta riprodotti suonano al nostro orecchio allo stesso modo. &#160; In molti formati digitali di immagini e [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/05/30/lsb-image-and-audio-steganography/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tunneling IP over RTP</title>
		<link>http://disse.cting.org/blog/2011/05/18/tunneling-ip-over-rtp/</link>
		<comments>http://disse.cting.org/blog/2011/05/18/tunneling-ip-over-rtp/#comments</comments>
		<pubDate>Wed, 18 May 2011 18:38:54 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[StegoSIP]]></category>
		<category><![CDATA[encapsulation]]></category>
		<category><![CDATA[IP over RTP]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[rtp]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sip]]></category>
		<category><![CDATA[steganography]]></category>
		<category><![CDATA[tunneling]]></category>
		<category><![CDATA[voip]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1094</guid>
		<description><![CDATA[Per integrare una tesi di laurea svolta in Erasmus in Spagna, mi è stato chiesto di scrivere un programma che implementasse la steganografia sul protocollo SIP, allo scopo di offuscare dati all&#8217;interno di una comune chiamata VoIP. Ho fatto di più e ho scritto un framework modulare che supporta il tunneling di traffico IP all&#8217;interno [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/05/18/tunneling-ip-over-rtp/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Kusaba X CSRF XSS vulnerabilites</title>
		<link>http://disse.cting.org/blog/2011/05/12/kusaba-x-xsscsrf-vulnerabilites/</link>
		<comments>http://disse.cting.org/blog/2011/05/12/kusaba-x-xsscsrf-vulnerabilites/#comments</comments>
		<pubDate>Thu, 12 May 2011 21:42:09 +0000</pubDate>
		<dc:creator>norby</dc:creator>
				<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[/b/]]></category>
		<category><![CDATA[4chan]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[csrf]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://disse.cting.org/?p=1031</guid>
		<description><![CDATA[Ultimamente mi affascina il penetration testing di applicazioni web, scoperto in ritardo visto il mio retaggio primi anni 2000, più dedicato a *nix, raw sockets e C. Armato di un buon proxy server per il pentest web mi sono dedicato all&#8217;auditing di alcune web applications di mia conoscenza. Ho trovato diverse vulnerabilità, tra le quali [...]]]></description>
		<wfw:commentRss>http://disse.cting.org/blog/2011/05/12/kusaba-x-xsscsrf-vulnerabilites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

