<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <generator>RSS Builder by B!Soft</generator>
    <title>Irongeek's Security Site</title>
    <link>http://www.irongeek.com/</link>
    <description>Irongeek.com, Adrian Crenshaw's Information Security site (along with a bit about weightlifting and other things that strike my fancy).  Home of my articles and videos on computer security. As I write articles and tutorials I will be posting them here. If you would like to republish one of the articles from this site on your webpage or print journal please e-mail me. Enjoy the site and write us if you have any good ideas for articles or links. </description>
    <language>en-us</language>
    <managingEditor>irongeek@irongeek.com</managingEditor>
    <webMaster>irongeek@irongeek.com</webMaster>
    <copyright>2012 Irongeek (Adrian Crenshaw)</copyright>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/IrongeeksSecuritySite" /><feedburner:info uri="irongeekssecuritysite" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>IrongeeksSecuritySite</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
      <title>ShmooCon Firetalks 2012 Videos</title>
      <pubDate>Sun, 5 Feb 2012 16:50:53 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/6DDRgGLLSwo/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2012"&gt;http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2012&lt;/a&gt;&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Night 1&lt;br/&gt;&amp;nbsp;“How Do You Know Your Colo Isn’t “Inside” Your Cabinet, A Simple Alarm Using Teensy” by David Zendzian&lt;br/&gt;&amp;nbsp;“Bending SAP Over &amp;amp; Extracting What You Need!” by Chris John Riley&lt;br/&gt;&amp;nbsp;“ROUTERPWN: A Mobile Router Exploitation Framework” by Pedro Joaquin&lt;br/&gt;&amp;nbsp;“Security Is Like An Onion, That’s Why it Makes You Cry” by Michele Chubirka&lt;br/&gt;&amp;nbsp;“Five Ways We’re Killing Our Own Privacy” by Michael Schearer&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Night 2&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;“Cracking WiFi Protected Setup For Fun and Profit” by Craig Heffner&lt;br/&gt;&amp;nbsp;“Passive Aggressive Pwnage: Sniffing the Net for Fun &amp;amp; Profit” by John Sawyer&lt;br/&gt;&amp;nbsp;“Ressurecting Ettercap” by Eric Milam&lt;br/&gt;&amp;nbsp;“Security Onion: Network Security Monitoring in Minutes” by Doug Burks&lt;br/&gt;&amp;nbsp;“Remotely Exploiting the PHY Layer” by Travis Goodspeed
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/6DDRgGLLSwo" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2012</feedburner:origLink></item>
    <item>
      <title>ShmooCon Epilogue 2012 Talks</title>
      <pubDate>Sun, 5 Feb 2012 16:25:11 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/XUKGmkmO3Qk/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/shmoocon-epilogue-2012"&gt; http://www.irongeek.com/i.php?page=videos/shmoocon-epilogue-2012&lt;/a&gt;&lt;br/&gt;&amp;nbsp;Includes: &lt;br/&gt;&amp;nbsp;Resurrection of Ettercap: easy-creds, Lazarus &amp;amp; Assimilation&lt;br/&gt;&amp;nbsp;Eric Milam - (Brav0Hax) &amp;amp;&lt;br/&gt;&amp;nbsp;Emilio Escobar &lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Media Hype and Hacks that Never Happened&lt;br/&gt;&amp;nbsp;Space Rouge&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;More than one way to skin a cat: identifying multiple paths to compromise a target through the use of Attach Graph Analysis&lt;br/&gt;&amp;nbsp;Joe Klein &lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Proper Depth / Breadth testing for Vulnerability Analysis and fun with tailored risk reporting metrics.&lt;br/&gt;&amp;nbsp;Jason M Oliver &lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Extending Information Security Methodologies for Personal User in Protecting PII.&lt;br/&gt;&amp;nbsp;John Willis&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Stratfor Password Analysis&lt;br/&gt;&amp;nbsp;Chris Truncer&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Intro To Bro&lt;br/&gt;&amp;nbsp;Richard Bejtlich&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Javascript obfuscation&lt;br/&gt;&amp;nbsp;Brandon Dixon
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/XUKGmkmO3Qk" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/shmoocon-epilogue-2012</feedburner:origLink></item>
    <item>
      <title>Unix File Permissions and Ownership (CHOWN, CHMOD, ETC) </title>
      <pubDate>Sat, 21 Jan 2012 12:39:01 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/-QCtx-_s7Xg/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/unix-file-permissions-and-ownership-chown-chmod-etc"&gt;http://www.irongeek.com/i.php?page=videos/unix-file-permissions-and-ownership-chown-chmod-etc&lt;/a&gt;&lt;br/&gt;I'm taking a security class were we had a lab on Unix/Linux file system permissions. I decided I might as well record it, and the steps taken, along with explanations as to what I was doing to set the permissions such as read, write, execute, SetUID, SetGID and the Stickybit. Kevin Benton created the lab, so I'd like to give him credit for inspiring me to do this video.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/-QCtx-_s7Xg" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/unix-file-permissions-and-ownership-chown-chmod-etc</feedburner:origLink></item>
    <item>
      <title>Basic Setup of Security-Onion: Snort, Snorby, Barnyard, PulledPork, Daemonlogger </title>
      <pubDate>Sun, 15 Jan 2012 22:23:18 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/ZERvRJhgL7Y/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/basic-setup-of-security-onion-snort-snorby-barnyard-pulledpork-daemonlogger"&gt;http://www.irongeek.com/i.php?page=videos/basic-setup-of-security-onion-snort-snorby-barnyard-pulledpork-daemonlogger&lt;/a&gt;&lt;br/&gt;Thanks to Doug Burks for making building a Network Security Monitoring Server much easier. I mentioned Snort, Snorby, Barnyard, PulledPork and Daemonlogger in the title, but there is a lot more on the distro than that. This is a nice way to get an IDS up and running featuring pretty frontends without going into dependency hell.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/ZERvRJhgL7Y" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/basic-setup-of-security-onion-snort-snorby-barnyard-pulledpork-daemonlogger</feedburner:origLink></item>
    <item>
      <title>Pen-Testing Web 2.0: Stealing HTML5 Storage &amp; Injecting JSON Jeremy Druin</title>
      <pubDate>Sat, 7 Jan 2012 11:02:02 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/wyImVh3lOTI/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/pen-testing-web-2-stealing-html5-storage-injecting-json-jeremy-druin"&gt;Pen-Testing Web 2.0: Stealing HTML5 Storage &amp;amp; Injecting JSON Jeremy Druin&lt;/a&gt;&lt;br/&gt;This is &lt;a href="https://twitter.com/#!/webpwnized"&gt;Jeremy's&lt;/a&gt; talk from a recent &lt;a href="http://www.issa-kentuckiana.org/"&gt;ISSA&lt;/a&gt; meeting. In it he covers what the title says, showing off stealing of HTML 5 storage, injecting JSON, using Burp Suite, &lt;a href="http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10"&gt;Muttillidae&lt;/a&gt; and some XSS attack fun. Sorry about the noise in the first bit, I had to set the camera up a ways off and it picked up my bag of chips better than it did Jeremy's talk. &lt;a href="https://twitter.com/#!/webpwnized"&gt;@webpwnized&lt;/a&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/wyImVh3lOTI" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/pen-testing-web-2-stealing-html5-storage-injecting-json-jeremy-druin</feedburner:origLink></item>
    <item>
      <title>Video Posted and Code Updated for Homemade Hardware Keylogger</title>
      <pubDate>Mon, 2 Jan 2012 00:29:07 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/bSxvHzxXKcc/i.php</link>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/homemade-hardware-keylogger-phukd"&gt;http://www.irongeek.com/i.php?page=security/homemade-hardware-keylogger-phukd&lt;/a&gt;&lt;br/&gt;My video from &lt;a href="http://www.neoisf.org/"&gt;NeoISF&lt;/a&gt; is now posted: &lt;a href="http://www.irongeek.com/i.php?page=videos/phukd-keylogger-hybrid"&gt;PHUKD/Keylogger Hybrid&lt;/a&gt;. 
&lt;p&gt;The code has been updated in the following ways:&lt;/p&gt;
&lt;p&gt;On the PIC side: Updated Firmware for the USB Host Module - PIC24FJ256GB106 to work with more keyboards.&lt;/p&gt;
&lt;p&gt;On the Teensy side:&lt;/p&gt;
&lt;p&gt;0.04:&lt;br/&gt;* If a keyboard was plugged in after the keylogger was already powered on, it would type "i7-". I added code&lt;br/&gt;to fix this problem.&lt;br/&gt;* Fixed RAW serial debug mode not to print key&lt;br/&gt;* Changed name of variable "lasttenletters" to "lastfewletters" and expanded it to 60.&lt;br/&gt;* Ctrl+Alt+Y is now used for typing more debugging details.&lt;br/&gt;* Implemented likely to fail code for unlocking workstation using captured password.&lt;br/&gt;* I had some problems with running out of SRAM because of all of my static strings. I started using the F() &lt;br/&gt;function to pull these strings from flash memory to solve this issue.&lt;br/&gt;* Fixed a case issue with lastfewletters. I did not know the method changed it in place.&lt;br/&gt;* Fixed a bug in HIDtoASCII that made it top row of number keys not work right.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/bSxvHzxXKcc" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/homemade-hardware-keylogger-phukd</feedburner:origLink></item>
  </channel>
</rss>

