<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <generator>RSS Builder by B!Soft</generator>
    <title>Irongeek's Security Site</title>
    <link>http://www.irongeek.com/</link>
    <description>Irongeek.com, Adrian Crenshaw's Information Security site (along with a bit about weightlifting and other things that strike my fancy).  Home of my articles and videos on computer security. As I write articles and tutorials I will be posting them here. If you would like to republish one of the articles from this site on your webpage or print journal please e-mail me. Enjoy the site and write us if you have any good ideas for articles or links. </description>
    <language>en-us</language>
    <managingEditor>irongeek@irongeek.com</managingEditor>
    <webMaster>irongeek@irongeek.com</webMaster>
    <copyright>2009 Irongeek (Adrian Crenshaw)</copyright>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/IrongeeksSecuritySite" type="application/rss+xml" /><feedburner:emailServiceId>IrongeeksSecuritySite</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
      <title>Compiling Nmap form source on Ubuntu</title>
      <pubDate>Sat, 18 Jul 2009 14:27:19 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/4Tr6uYFYx1U/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/nmap-from-source"&gt;Compiling Nmap form source on Ubuntu&lt;/a&gt;&lt;br/&gt;Along the way to making a video on Ncat I needed to compile Nmap 5 from source, so I figured I might as well do a video on that as well. There are many reasons why you might want to compile Nmap from source instead of just using the package manager, so enjoy.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/lqinzVIsGg55FEV-DDqjkkrq-TA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/lqinzVIsGg55FEV-DDqjkkrq-TA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/lqinzVIsGg55FEV-DDqjkkrq-TA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/lqinzVIsGg55FEV-DDqjkkrq-TA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/4Tr6uYFYx1U" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/nmap-from-source</feedburner:origLink></item>
    <item>
      <title>Windows 7: Copy A Modified User Profile Over The Default Profile</title>
      <pubDate>Fri, 17 Jul 2009 21:05:52 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/f4dDvH7GHH4/i.php</link>
      <category>article</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/windows-7-copy-default-profile"&gt;
Windows 7: Copy A Modified User Profile Over The Default Profile&lt;/a&gt;&lt;br&gt;
While this is not directly security related, it should be helpful to those who 
are testing Windows 7. I'm posting it to help those who are searching the 
Internet for details on copying user profiles in Windows 7.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/BgZZ5Q7dumiztS057HI_hd3EQ9o/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BgZZ5Q7dumiztS057HI_hd3EQ9o/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/BgZZ5Q7dumiztS057HI_hd3EQ9o/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/BgZZ5Q7dumiztS057HI_hd3EQ9o/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/f4dDvH7GHH4" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/windows-7-copy-default-profile</feedburner:origLink></item>
    <item>
      <title>NDiff: Comparing two Nmap 5 scans to find changes in your network</title>
      <pubDate>Thu, 16 Jul 2009 12:20:34 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/-61qQBsIR0w/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/ndiff-nmap-5"&gt;NDiff: 
Comparing two Nmap 5 scans to find changes in your network&lt;/a&gt;&lt;br&gt;
Fyodor gave me a heads up that Nmap 5 was coming out, so I figured I'd do a 
couple of videos on useful new features that come with Nmap 5 and later. For a 
better understanding of Nmap in general, check out my older videos which I will 
link to after the presentation. In this video I will cover the basics of using 
NDiff to compare two seperate Nmap scans. This is really useful for change 
management, where you want to know what new devices have appeared on your 
network or about ones that have disappeared for some reason. You could easily 
schedule Nmap to run on your network weekly, and then compare the differences 
with NDiff to see what has changed.&lt;p&gt;As a side note, looks like I'm going to 
Defcon. Thanks to &lt;a href="http://twitter.com/haxorthematrix"&gt;Haxorthematrix&lt;/a&gt;, 
Sereyna, Minoad, Mr. Bradshaw, George and anyone else who donated to my
&lt;a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=6834371"&gt;
Paypal&lt;/a&gt; so I could go.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TMErFhuDUuo3Lki9lnP-rQzQQso/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TMErFhuDUuo3Lki9lnP-rQzQQso/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TMErFhuDUuo3Lki9lnP-rQzQQso/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TMErFhuDUuo3Lki9lnP-rQzQQso/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/-61qQBsIR0w" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/ndiff-nmap-5</feedburner:origLink></item>
    <item>
      <title>Exotic Liability Episode 25: Irongeek sits in</title>
      <pubDate>Sat, 11 Jul 2009 22:58:20 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/1ysqOHkBKxQ/</link>
      <category>podcast</category>
      <description>Link:&lt;a href="http://www.exoticliability.com/"&gt;Exotic Liability Episode 25: Irongeek sits in&lt;/a&gt;&lt;br/&gt;I came in as a guest of the Exotic Liability podcast, episode 25. I've not listened to it yet, hope I came off ok. Some of the things we discussed include: Incident response switchblade, Tiger Team: The Whole Story, Our neighborhood memories, Kon-boot, Cool tools for data collection, P/W cracker speed test challenge, Look at my thumb, Olympic games, Louisville Info Sec Conference, Anti-forensics and Legalities. Thanks for having me on. 
&lt;p&gt;As a sidenote, I may be going to Defcon after all but nothing is confirmed yet. I'll need to find someone's floor to crash on Wednesday night as I think I'll be arriving a day before the person I'm staying with the rest of the con.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/RQ0KMrwPCFi9kXVWhHCsjgj7RGg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RQ0KMrwPCFi9kXVWhHCsjgj7RGg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/RQ0KMrwPCFi9kXVWhHCsjgj7RGg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RQ0KMrwPCFi9kXVWhHCsjgj7RGg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/1ysqOHkBKxQ" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.exoticliability.com/</feedburner:origLink></item>
    <item>
      <title>Incident Response U3 Switchblade From TCSTool</title>
      <pubDate>Thu, 9 Jul 2009 20:59:55 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/-nRw8n7aOCg/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/incident-response-u3-switchblade"&gt;Incident Response U3 Switchblade From TCSTool&lt;/a&gt;&lt;br/&gt;In Russell's own words: "The U3 incident response switchblade is a tool designed to gather forensic data from a machine in an automated, self-contained fashion without user intervention for use in an investigation. The switchblade is designed to be very modular, allowing the investigator/IR team to add their own tools and modify the evidence collection process quickly." This video shows you how to setup u3ir, and modify it.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HWDLjCQZ5LsvWXs17OunMKRR_yY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HWDLjCQZ5LsvWXs17OunMKRR_yY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HWDLjCQZ5LsvWXs17OunMKRR_yY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HWDLjCQZ5LsvWXs17OunMKRR_yY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/-nRw8n7aOCg" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/incident-response-u3-switchblade</feedburner:origLink></item>
    <item>
      <title>Using Kon-Boot from a USB Flash Drive: Bypass those pesky Windows and Linux login passwords completely</title>
      <pubDate>Wed, 8 Jul 2009 00:48:10 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/nGNwZKCPUPA/i.php</link>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/kon-boot-from-usb"&gt;Using Kon-Boot from a USB Flash Drive: Bypass those pesky Windows and Linux login passwords completely&lt;/a&gt;&lt;br/&gt;Kon-Boot is a neat little tool that you can boot from a CD or a floppy, change memory before booting a full OS, and then login to Windows or Linux without knowing a proper password. The above link contains my notes and config files to get Kon-Boot to work from a bootable USB drive.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/e5-szpREwlxNugmNAgYsSGe9hqA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e5-szpREwlxNugmNAgYsSGe9hqA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/e5-szpREwlxNugmNAgYsSGe9hqA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e5-szpREwlxNugmNAgYsSGe9hqA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/nGNwZKCPUPA" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/kon-boot-from-usb</feedburner:origLink></item>
    <item>
      <title>PHPIDS Install Notes and Test Page </title>
      <pubDate>Tue, 7 Jul 2009 20:06:19 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/a9Ptewx7jyE/i.php</link>
      <category>article</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/phpids-install-notes"&gt;PHPIDS Install Notes and Test Page&lt;/a&gt; &lt;br/&gt;I've been playing around with PHPIDS and have posted my notes on installing it as well as details on the kinds of attacks by web site gets. Interesting, I get a lot of attacks, mostly RFI.
&lt;p&gt;As a side note, GFI was kind enough to sponsor my site for two months, show our appreciation by trying out some of their &lt;a href="http://www.gfi.com/lannetscan/?adv=966&amp;amp;loc=2"&gt;log and vulnerability scanning software&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vWP-LldNpBEBHH3_0b9uu-xdZAA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vWP-LldNpBEBHH3_0b9uu-xdZAA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vWP-LldNpBEBHH3_0b9uu-xdZAA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vWP-LldNpBEBHH3_0b9uu-xdZAA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/a9Ptewx7jyE" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/phpids-install-notes</feedburner:origLink></item>
    <item>
      <title>How to change your MAC address article updated, added information on OS X 10.5.6 and latter</title>
      <pubDate>Mon, 29 Jun 2009 20:39:49 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/5kkzRj7uoOI/i.php</link>
      <category>article</category>
      <description>Apparently there are some problems changing your &lt;a href="http://www.irongeek.com/i.php?page=security/changemac"&gt;MAC address in versions of OS X 10.5.6 and latter&lt;/a&gt;. Stefan Person sent me a note about it, so I added it to the article. 
&lt;p&gt;Also, &lt;a href="http://www.room362.com/"&gt;Mubix&lt;/a&gt; recently did a presentation for &lt;a href="http://www.dojosec.com/?page_id=14"&gt;Dojo Sec on getting a job in information security&lt;/a&gt;. In it he mentions my article on &lt;a href="http://www.irongeek.com/i.php?page=security/how-to-cyberstalk-potential-employers"&gt;how to cyber stalk potential employers&lt;/a&gt;. Thank much Rob! &lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HPC7juK7ls6lVoknMJFNeKDKCaI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HPC7juK7ls6lVoknMJFNeKDKCaI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HPC7juK7ls6lVoknMJFNeKDKCaI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HPC7juK7ls6lVoknMJFNeKDKCaI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/5kkzRj7uoOI" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/changemac</feedburner:origLink></item>
    <item>
      <title>OWASP Top 5 and Mutillidae: Intro to common web vulnerabilities like Cross Site Scripting (XSS), SQL/Command Injection Flaws, Malicious File Execution/RFI, Insecure Direct Object Reference and Cross Site Request Forgery (CSRF/XSRF)</title>
      <pubDate>Sat, 20 Jun 2009 00:00:44 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/NCxLIvo64VU/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/owasp-top-5-louisville"&gt;OWASP Top 5 and Mutillidae: Intro to common web vulnerabilities like Cross Site Scripting (XSS), SQL/Command Injection Flaws, Malicious File Execution/RFI, Insecure Direct Object Reference and Cross Site Request Forgery (CSRF/XSRF)&lt;/a&gt;&lt;br/&gt;This is a recording of the presentation I gave to the Louisville Chapter of OWASP about the Mutillidae project. A while back I wanted to start covering more web application pen-testing tools and concepts in some of my videos and live classes. Of course, I needed vulnerable web apps to illustrate common web security problems. I like the WebGoat project, but sometimes it's a little hard to figure out exactly what they want you to do to exploit a given web application, and it's written in J2EE (not a layman friendly language). In an attempt to have something simple to use as a demo in my videos and in class, I started the Mutillidae project. This is a video covering the first 5 of the OWASP Top 10.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/j-mWuju1GhcYs5BV2VuAaLamH8Q/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/j-mWuju1GhcYs5BV2VuAaLamH8Q/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/j-mWuju1GhcYs5BV2VuAaLamH8Q/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/j-mWuju1GhcYs5BV2VuAaLamH8Q/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/NCxLIvo64VU" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/owasp-top-5-louisville</feedburner:origLink></item>
    <item>
      <title>Louisville Infosec Conference Looking For Sponsors/Speakers</title>
      <pubDate>Fri, 12 Jun 2009 23:18:08 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/aos05xEgmEE/</link>
      <category>link</category>
      <description>As many of you know, I'm involved with the local ISSA group here in the Louisville area. They are looking for sponsors for the upcoming Louisville Infosec conference (Thursday, October 8, 2009 at Churchill Downs). We had about 250 attendees last year, so it could be a good spot for advertising your company via a booth.&amp;nbsp; One of our keynotes this year is Johnny Long. John Strand and Eugene Schultz should also be presenting. If you are interested in being a sponsor email marketing (at) issa-kentuckiana.org and let them know Adrian sent you. We also may have a few speaker slots open for the breakout sessions, contact chair (at) louisvilleinfosec.com if you have a proposal. For more information, check out the &lt;a href="http://louisvilleinfosec.com/"&gt;Louisville Infosec Conference site&lt;/a&gt;.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/9--KIoPGJCeM-E-FC4I9tiGsO18/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9--KIoPGJCeM-E-FC4I9tiGsO18/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/9--KIoPGJCeM-E-FC4I9tiGsO18/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9--KIoPGJCeM-E-FC4I9tiGsO18/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/aos05xEgmEE" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://louisvilleinfosec.com/</feedburner:origLink></item>
    <item>
      <title>Speaking at the OWASP Louisville meeting, June 19th 2009</title>
      <pubDate>Wed, 10 Jun 2009 06:19:10 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/oYaCCuWPMIs/Louisville</link>
      <category>event</category>
      <description>Hi all, the local OWASP chapter has asked me to speak about the &lt;a href="http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10"&gt;Mutillidae&lt;/a&gt; project. While I'd like to cover all of the OWASP Top 10 that it implements, I think there will only be time for the top 5. The description as posted on their site follows: 
&lt;BLOCKQUOTE&gt;
&lt;p&gt;The second OWASP meeting will feature a presentation from Adrian Crenshaw of Irongeek. Adrian is a Louisville based Security professional that has worked in the IT industry for the last twelve years.&lt;br/&gt;&lt;br/&gt;Adrian runs the information security website Irongeek.com, which specializes in videos and articles that illustrate how to use various pen-testing and security tools. He's currently working on an MBA, but is interested in getting a network security/research/teaching job in academia. Please see the description from Adrian on his presentation on the 19th.&lt;br/&gt;&lt;br/&gt;Title: Mutillidae: Using a deliberately vulnerable set of PHP scripts to illustrate the OWASP Top 10 Description: A while back I wanted to start covering more web application pen-testing tools and concepts in some of my videos and live classes. Of course, I needed vulnerable web apps to illustrate common web security problems. I like the WebGoat project, but sometimes it's a little hard to figure out exactly what they want you to do to exploit a given web application, and it's written in J2EE (not a layman friendly language). In an attempt to have something simple to use as a demo in my videos and in class, I started the Mutillidae project.&lt;br/&gt;&lt;br/&gt;Mutillidae is a deliberately vulnerable set of PHP scripts meant to illustrate the OWASP Top 10. This talk will cover installing Mutillidae in a test environment, and how to use it to illustrate the OWASP Top 10 web vulnerabilities in easy to understand terms.&lt;br/&gt;&lt;br/&gt;Our meeting location will be at Memorial Auditorium, located at 970 S. 4th Street (Corner of 4th Street and Kentucky Street).&lt;/p&gt;&lt;/BLOCKQUOTE&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vAcUblA74Pvnj64wL4Kq-7oGChg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vAcUblA74Pvnj64wL4Kq-7oGChg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vAcUblA74Pvnj64wL4Kq-7oGChg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vAcUblA74Pvnj64wL4Kq-7oGChg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/oYaCCuWPMIs" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.owasp.org/index.php/Louisville</feedburner:origLink></item>
    <item>
      <title>ARPFreeze: A tool for Windows to protect against ARP poisoning by setting up static ARP entries</title>
      <pubDate>Sun, 7 Jun 2009 00:02:25 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/-BmPG1E3kWM/i.php</link>
      <category>app</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=security/arpfreeze-static-arp-poisoning"&gt;ARPFreeze: A tool for Windows to protect against ARP poisoning by setting up static ARP entries&lt;/a&gt;&lt;br/&gt;As many of you know, I've created quite a bit of content about ARP poisoning, such as:&lt;br/&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=security/AQuickIntrotoSniffers"&gt;A Quick Intro to Sniffers&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=security/arpspoof"&gt;Intro to ARP poisoning&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/using-cain-to-do-a-man-in-the-middle-attack-by-arp-poisoning"&gt;Using Cain to do a man in the middle attack by ARP poisoning&lt;/a&gt; 
&lt;p&gt;I've even done some work on detection:&lt;br/&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=security/decaffeinatid-simple-ids-arpwatch-for-windows"&gt;Decaffeinatid: A Simple IDS/arpwatch for Windows&lt;/a&gt; &lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/finding-promiscuous-and-arp-poisoning-sniffers-on-your-network-with-ettercap"&gt;Finding promiscuous and ARP poisoners and sniffers on your network with Ettercap&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;This tool is for prevention.&amp;nbsp;&lt;a href="http://www.irongeek.com/i.php?page=security/arpfreeze-static-arp-poisoning"&gt;ARPFreeze&lt;/a&gt; lets you setup static ARP tables so that attackers (using Cain, Ettercap, Arpspoof or some other tool) can't pull off an ARP poisoning attack against you.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/y5MWnzABrqQGF5AOwict1r6wmws/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/y5MWnzABrqQGF5AOwict1r6wmws/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/y5MWnzABrqQGF5AOwict1r6wmws/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/y5MWnzABrqQGF5AOwict1r6wmws/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/-BmPG1E3kWM" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/arpfreeze-static-arp-poisoning</feedburner:origLink></item>
    <item>
      <title>XSS, Command and SQL Injection vectors: Beyond the Form</title>
      <pubDate>Wed, 3 Jun 2009 19:59:10 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/d8R_9cQXlUg/i.php</link>
      <category>article</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/xss-sql-and-command-inject-vectors"&gt; XSS, Command and SQL Injection vectors: Beyond the Form&lt;/a&gt;&lt;br/&gt;We are all familiar with XSS via a form field in a web application, but what about other vectors? The article talks about using User Agent strings, even logs, object properties and other odd alternative vectors for XSS, SQL and command injection. What other vectors can you think of?
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZnMGoFEtCFB4ayMwWH12p3W2nSg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZnMGoFEtCFB4ayMwWH12p3W2nSg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZnMGoFEtCFB4ayMwWH12p3W2nSg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZnMGoFEtCFB4ayMwWH12p3W2nSg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/d8R_9cQXlUg" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/xss-sql-and-command-inject-vectors</feedburner:origLink></item>
    <item>
      <title>Another book for the list</title>
      <pubDate>Tue, 2 Jun 2009 19:42:28 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/qUKSftKAqto/i.php</link>
      <category>books</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=books"&gt;Another book for the list&lt;/a&gt;&lt;br/&gt;Looks like my site has been mentioned in another book, Security+ Guide to Network Security Fundamentals by Mark Ciampa. Thanks Mark. 
&lt;p&gt;In other news, Irongeek.com was a nominee for &lt;a href="https://365.rsaconference.com/docs/DOC-1884"&gt;“Best Technical Blog” at the recent RSA Conference&lt;/a&gt;. Congratulations to &lt;a href="http://www.pauldotcom.com/"&gt;PaulDotCom&lt;/a&gt; for winning the best security podcast award. And while I'm on the subject of great podcasts for infosec folks to listen to, check these out:&lt;br/&gt;&lt;a href="http://securabit.com/"&gt;http://securabit.com/&lt;/a&gt;&lt;br/&gt;&lt;a href="http://securityjustice.com/"&gt;http://securityjustice.com/&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.exoticliability.com/"&gt;http://www.exoticliability.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/o0CHsFLeaPWJnTyYtUCVrk8JTIg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/o0CHsFLeaPWJnTyYtUCVrk8JTIg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/o0CHsFLeaPWJnTyYtUCVrk8JTIg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/o0CHsFLeaPWJnTyYtUCVrk8JTIg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/qUKSftKAqto" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=books</feedburner:origLink></item>
    <item>
      <title>802.11 Wireless Security Class for the Louisville ISSA Part 1</title>
      <pubDate>Sun, 24 May 2009 19:10:40 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/HbaEfe8tIrI/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/802-11-wireless-security-class-part-1"&gt;802.11 Wireless Security Class for the Louisville ISSA Part 1&lt;/a&gt;&lt;br/&gt;Originally, this was going to be one 4hr class, but Jeff had something come up so he could not cover WEP/WPA cracking, and my section took so long that Brian never got a chance to present his material on DD-WRT. I'm hoping to get them back to do a part 2 of this video. In this section I cover the basics of WiFi, good chipsets, open file shares, monitor mode, war driving tools, testing injection, deauth attacks and the evil twin attack. Some of this comes out as kind of a stream of consciousness, but hopefully you can find some useful nuggets from my brain dump of what I've learned about 802.11a/b/g/n hacking. As far as classes goes this is the mostly complicated one I've set up, and for a wireless class Brian and I had to run a lot of wires. :)
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_o0ne6kufH_sa2vvppQDJ-jdYPM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_o0ne6kufH_sa2vvppQDJ-jdYPM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_o0ne6kufH_sa2vvppQDJ-jdYPM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_o0ne6kufH_sa2vvppQDJ-jdYPM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/HbaEfe8tIrI" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/802-11-wireless-security-class-part-1</feedburner:origLink></item>
  </channel>
</rss>
