<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <generator>RSS Builder by B!Soft</generator>
    <title>Irongeek's Security Site</title>
    <link>http://www.irongeek.com/</link>
    <description>Irongeek.com, Adrian Crenshaw's Information Security site (along with a bit about weightlifting and other things that strike my fancy).  Home of my articles and videos on computer security. As I write articles and tutorials I will be posting them here. If you would like to republish one of the articles from this site on your webpage or print journal please e-mail me. Enjoy the site and write us if you have any good ideas for articles or links. </description>
    <language>en-us</language>
    <managingEditor>irongeek@irongeek.com</managingEditor>
    <webMaster>irongeek@irongeek.com</webMaster>
    <copyright>2012 Irongeek (Adrian Crenshaw)</copyright>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/IrongeeksSecuritySite" /><feedburner:info uri="irongeekssecuritysite" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>IrongeeksSecuritySite</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
      <title>Intro to Scanning: Nmap, Hping, Amap, TCPDump, Metasploit, etc. Jeremy Druin</title>
      <pubDate>Sat, 12 May 2012 14:41:08 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/MMAGn680dro/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/intro-to-scanning-nmap-hping-amap-tcpdump-metasploit-jeremy-druin"&gt;http://www.irongeek.com/i.php?page=videos/intro-to-scanning-nmap-hping-amap-tcpdump-metasploit-jeremy-druin&lt;/a&gt;&lt;br/&gt;This is the 2nd in a line of classes Jeremy Druin will be giving on pen-testing and web app security featuring &lt;a href="http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10"&gt;Mutillidae&lt;/a&gt; for the &lt;a href="http://www.issa-kentuckiana.org/"&gt;Kentuckiana ISSA&lt;/a&gt;. This one covers scanning Nmap, Hping, Amap, TCPDump, Metasploit, etc.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-vUQQj2hag4tWQ4FXArLIgigQ3k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-vUQQj2hag4tWQ4FXArLIgigQ3k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-vUQQj2hag4tWQ4FXArLIgigQ3k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-vUQQj2hag4tWQ4FXArLIgigQ3k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/MMAGn680dro" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/intro-to-scanning-nmap-hping-amap-tcpdump-metasploit-jeremy-druin</feedburner:origLink></item>
    <item>
      <title>Jeremy Druin did some more Mutillidae/Web Pen-testing videos </title>
      <pubDate>Sun, 6 May 2012 14:03:16 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/HqqO_uOHqLk/i.php</link>
      <category>videos</category>
      <description>&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-metasploit-hashdump-post-exploit-module-creds-table-and-john"&gt;Jeremy Druin did some more Mutillidae/Web Pen-testing videos &lt;/a&gt;
&lt;p&gt;At some point, I will start putting up some of my own content :) I have done some tricks that I hope will make the page load better, but I'm not sure about the browser compatibility. In the mean time, here is some more of Jeremy's work:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-metasploit-hashdump-post-exploit-module-creds-table-and-john"&gt;Using Metasploit Hashdump Post Exploit Module Creds Table And John&lt;/a&gt;&lt;br/&gt;This video shows how to have the hashdump post exploitation module automatically populate the creds table in the metasploit database, then export the credentials to a file suitible to pass to the john the ripper tool in order to audit the passwords.&lt;br/&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-metasploit-community-edition-to-determine-exploit-for-vulnerability"&gt;Using Metasploit Community Edition To Determine Exploit For Vulnerability&lt;/a&gt;&lt;br/&gt;In previous versions of Metasploit it was possible to run "db_autopwn -t -x" in the msfcomsole in order to have metasploit guess the best exploits for a given vulnerability. This video looks at alternative functionality for the depreciated "db_autopwn -t -x" option in older versions of Metasploit's msfconsole. Metasploit Community Edition has similar exploit analysis functionality accessible via the web based GUI.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/8LlR3M0v3mIvkthCIVvrRdLEtoM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8LlR3M0v3mIvkthCIVvrRdLEtoM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/8LlR3M0v3mIvkthCIVvrRdLEtoM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8LlR3M0v3mIvkthCIVvrRdLEtoM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/HqqO_uOHqLk" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-metasploit-hashdump-post-exploit-module-creds-table-and-john</feedburner:origLink></item>
    <item>
      <title>More Mutillidae/Web Pen-testing videos from Jeremy Druin</title>
      <pubDate>Fri, 4 May 2012 08:22:50 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/GK4GTo0JynY/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae&lt;/a&gt; 
&lt;p&gt;Jeremy had two more videos for you. It's beginning to become a load problem with all the iframe embedded videos :). I'm willing to take suggestions. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-hydra-to-brute-force-web-forms-based-authentication-over-http"&gt;Using Hydra To Brute Force Web Forms Based Authentication Over Http&lt;/a&gt;&lt;br/&gt;This video covers using nmap to ping sweep network then discover ports on two machines to locate a web server on which Mutillidae is running. Once the web server is running, the site is loaded into Firefox and the login page is located. Using View-Source, Burp-Suite, and the sites registration, the login process is studied. Potential usernames are gathered from using Reconnoitter, CeWL, and the sites own blog page. A password file from john the ripper is used. With the potential usernames and passwords in hand, hydra is used in http-post-form mode to search for a username and password which can log into the site.&lt;br/&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#connect-to-unreachable-web-site-through-meterpreter-port-forwarding"&gt;Connect To Unreachable Web Site Through Meterpreter Port Forwarding&lt;/a&gt;&lt;br/&gt;This video covers accessing a web site that is normally unreachable from our Backtrack 5 box. However, after gaining a session on a third box, we forward our web browser through the compromised host in order to browse the website. The port forwarding is done via a meterpreter session on the compromised host. After setting up the port forward, the browser is able to use the compromised host as a relay (almost like a web proxy) in order to browse to the "internal" web application.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/QNf-WUq6QpaVbDjW7DSbQVRYJ4o/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QNf-WUq6QpaVbDjW7DSbQVRYJ4o/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/QNf-WUq6QpaVbDjW7DSbQVRYJ4o/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QNf-WUq6QpaVbDjW7DSbQVRYJ4o/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/GK4GTo0JynY" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae</feedburner:origLink></item>
    <item>
      <title>DerbyCon tickets go on sale this today! (Friday April 27th) – CFP OPEN!</title>
      <pubDate>Fri, 27 Apr 2012 08:57:39 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/qZaZSomVJDo/</link>
      <category>news</category>
      <description>Link: &lt;a href="https://www.derbycon.com/news/"&gt;https://www.derbycon.com/news/&lt;/a&gt;&lt;br/&gt;We will be opening up ticket sales on Friday at 1:00PM EST on April 27th 2012. Both training and normal conference tickets will be going on sale at this time. We feel we have a very stable ticketing system at this point from the tests last week and don’t anticipate any major issues! We look forward to seeing everyone at DerbyCon this year… It’s going to be amazing!!!&lt;br/&gt;&lt;br/&gt;Call for papers are also open! Check out the &lt;a href="https://www.derbycon.com/call-for-papers/"&gt;CFP section&lt;/a&gt; on the DerbyCon here.
&lt;p&gt;Some of the current speakers: Jeff Moss, Dan Kaminsky, Kevin Mitnick, Martin Bos, Adrian Crenshaw, HD Moore, Dave Kennedy, Ryan Elkins, Johnny Long, Chris Nickerson, Chris Gates, Eric Smith, Paul Asadoorian, Rob Fuller, Larry Pesce, Chris Hadnagy, John Strand, Peter Van Eeckhoutte, int0x80, Thomas d’Otreppe, Jack Daniel, Jason Scott, Deviant Ollam, Jayson E. Street, James Lee, Rafal Los, Kevin Johnson, Tom Eston, Rick Hayes, Georgia Weidman and Karthik Rangarajan&lt;/p&gt;
&lt;p&gt;Check out &lt;a href="http://www.irongeek.com/i.php?page=videos/derbycon1/mainlist"&gt;videos of last year's Derbycon here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/uN8MvM0AYbzPexH4DriGgTtjmC8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uN8MvM0AYbzPexH4DriGgTtjmC8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/uN8MvM0AYbzPexH4DriGgTtjmC8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uN8MvM0AYbzPexH4DriGgTtjmC8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/qZaZSomVJDo" height="1" width="1"/&gt;</description>
    <feedburner:origLink>https://www.derbycon.com/news/</feedburner:origLink></item>
    <item>
      <title>2 more Mutillidae/Web Pen-testing videos from Jeremy Druin</title>
      <pubDate>Mon, 23 Apr 2012 10:34:21 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/GK4GTo0JynY/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae&lt;/a&gt; 
&lt;p&gt;Three more great videos from Jeremy Druin (&lt;a href="https://twitter.com/#!/webpwnized"&gt;@webpwnized&lt;/a&gt; ): &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#creating-syn-port-scan-manually-with-scapy"&gt;Creating Syn Port Scan Manually With Scapy&lt;/a&gt; &lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#contrast-nmap-and-amap-service-version-detection-scanning"&gt;Contrast Nmap And Amap Service Version Detection Scanning&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/M4i3JZuMD4qslDYEqAUj0SWXkBw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/M4i3JZuMD4qslDYEqAUj0SWXkBw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/M4i3JZuMD4qslDYEqAUj0SWXkBw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/M4i3JZuMD4qslDYEqAUj0SWXkBw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/GK4GTo0JynY" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae</feedburner:origLink></item>
    <item>
      <title>Outerz0ne 8 (2012) Videos</title>
      <pubDate>Mon, 23 Apr 2012 10:18:29 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/93FpvSXwuEU/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/mainlist"&gt;http://www.irongeek.com/i.php?page=videos/outerz0ne8/mainlist&lt;/a&gt; 
&lt;p&gt;Here is the list:&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/skydog-kickin-it-off-for-year-number-8"&gt;Kickin' it off for year number 8! Outerz0ne: The History, The Legend SkyDog &lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/halfjack-bare-metal-install-of-linux-from-a-network-server"&gt;Bare Metal Install of Linux from a Network Server Halfjack&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/irongeek-how-to-cyberstalk-potential-employers"&gt;How To Cyberstalk Potential Employers IronGeek&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/tyler-pitchford-complex-litigation-in-america"&gt;Complex Litigation in America Tyler Pitchford&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/chris-silvers-hook-line-and-syncer-outerz0ne-remix"&gt;Hook, Line and Syncer: Outerz0ne Remix Chris Silvers&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/jeremy-schmeichel-slimjim-ipv4-to-ipv6-service-providers-challenges"&gt;IPv4 -to- IPv6 Service Providers Challenges Jeremy Schmeichel &amp;amp; SlimJim&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/scott-moulton-your-camera-is-worth-300000-to-microsoft"&gt;Your Camera is Worth $300,000 to Microsoft Scott Moulton&lt;/a&gt; &lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne8/outerz0ne-closing-and-award-skydog-and-crew"&gt;Outerz0ne Closing and Awards Skydog and Crew&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fnmaRzGt1lnctEr647Y2KbVif5k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fnmaRzGt1lnctEr647Y2KbVif5k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fnmaRzGt1lnctEr647Y2KbVif5k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fnmaRzGt1lnctEr647Y2KbVif5k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/93FpvSXwuEU" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/outerz0ne8/mainlist</feedburner:origLink></item>
    <item>
      <title>Notacon 9 (2012) Videos</title>
      <pubDate>Mon, 16 Apr 2012 12:42:17 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/Ei3UOjk2jJQ/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/mainlist"&gt;http://www.irongeek.com/i.php?page=videos/notacon9/mainlist&lt;/a&gt;&lt;br/&gt;These are the videos from the 9th &lt;a href="http://www.notacon.org"&gt;Notacon&lt;/a&gt; conference held April 12th-15th, 2012. Not all of them are security related, but&amp;nbsp; I hope my viewers will enjoy them anyway. Thanks to Froggy and Tyger for having me up, and to the video team: SatNights, Widget, Securi-D, Purge, Bunsen, Fry Steve and myself. Sorry about the sound issues, but there is only so much pain I want to go through in post. Also for some videos we only have the slides or the live video, but not both.&lt;br/&gt;List:&lt;br/&gt;&amp;nbsp; 
&lt;p&gt;&lt;B&gt;Track 1&lt;br/&gt;Day 1&lt;/B&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/game-maker-crash-course-chris-sanyk"&gt;Game Maker: Crash Course&lt;br/&gt;Chris Sanyk&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/minute-man-all-i-need-is-60-seconds-rick-deacon"&gt;Minute Man: All I Need is 60 Seconds&lt;br/&gt;Rick Deacon&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/get-your-kicks-on-route-ipv6-mike-andrews"&gt;Get your kicks on route IPv6&lt;br/&gt;Mike Andrews&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/we-lit-ipv6-this-is-what-happened-jeff-goeke-smith"&gt;We lit IPv6. This is what happened.&lt;br/&gt;Jeff Goeke-Smith&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/civic-hacking-jeff-schuler-beth-sebian"&gt;Civic Hacking&lt;br/&gt;Jeff Schuler, Beth Sebian&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/vulnerabilities-of-control-systems-in-drinking-water-utilities-john-mcnabb"&gt;Vulnerabilities of Control Systems in Drinking Water Utilities&lt;br/&gt;John McNabb&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/hacking-for-freedom-peter-fein"&gt;Hacking for Freedom&lt;br/&gt;Peter Fein&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/building-a-game-for-the-ages-well-the-young-ages-anyway-bill-sempf"&gt;Building a Game for the Ages (well, the young ages anyway)&lt;br/&gt;Bill Sempf&lt;/a&gt; 
&lt;p&gt;&lt;B&gt;Day 2&lt;/B&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/mo-data-mo-problems-mick-douglas"&gt;Mo data? Mo problems!&lt;br/&gt;Mick Douglas&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/what-if-max-zoran-succeeded-living-without-silicon-valley-movax"&gt;What if Max Zoran Succeeded? Living without Silicon Valley&lt;br/&gt;movax&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/how-to-totally-suck-at-information-security-christopher-payne-doug-nibbelink"&gt;How to totally suck at Information Security&lt;br/&gt;Christopher Payne, Doug Nibbelink&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/just-about-everything-you-think-you-know-about-wilderness-survival-is-wrong-mark-lenigan"&gt;(Just About) Everything you think you know about Wilderness Survival is Wrong&lt;br/&gt;Mark Lenigan&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/baking-in-security-jeff-ghostnomad-kirsch"&gt;Baking in Security&lt;br/&gt;Jeff “ghostnomad” Kirsch&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/your-hacker-class-is-bullsh1t-christopher-payne"&gt;Your Hacker Class is Bullsh1t&lt;br/&gt;Christopher Payne&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/refactoring-the-revolution-occupy-as-an-agile-project-some-guy-on-bridge"&gt;REFACTORING THE REVOLUTION (Occupy as an Agile project)&lt;br/&gt;Some Guy On Bridge&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/custom-distributions-via-package-aliasing-release-of-the-pentest-repository-ryan-holeman"&gt;Custom Distributions Via Package Aliasing: release of The Pentest Repository&lt;br/&gt;Ryan Holeman&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/numbers-from-merely-big-to-unimaginable-brian-makin"&gt;Numbers, From Merely Big to Unimaginable&lt;br/&gt;Brian Makin&lt;/a&gt; 
&lt;p&gt;Whose Slide Is It Anyway?&lt;br/&gt;nicolle “rogueclown” neulist&lt;br/&gt;(Sorry, I can't post this one since we did not get permission from everyone) 
&lt;p&gt;&lt;B&gt;Track 2&lt;br/&gt;Day 1&lt;/B&gt;&lt;/p&gt;
&lt;p&gt;
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/im-a-hacker-and-im-a-qsa-hacking-pci-requirement-66-why-your-web-applications-are-still-not-secure-david-sopata-gary-mccully"&gt;I’m a Hacker…and I’m a QSA (Hacking PCI Requirement 6.6. Why Your Web Applications are Still Not Secure)&lt;br/&gt;David Sopata, Gary McCully&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/neurohacking-from-the-bottom-up-meecie"&gt;Neurohacking: from the bottom up&lt;br/&gt;meecie&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/code-that-sounds-good-music-theory-and-algorithmic-composition-nicolle-rogueclown-neulist"&gt;Code That Sounds Good: Music Theory and Algorithmic Composition&lt;br/&gt;nicolle “rogueclown” neulist&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/collaboration-you-keep-using-that-word-angela-harms"&gt;Collaboration. You keep using that word…&lt;br/&gt;Angela Harms&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/kinetic-security-knuckles-jeff-ghostnomad-kirsch-ghostnomadjr"&gt;Kinetic Security&lt;br/&gt;Knuckles, Jeff “ghostnomad” Kirsch, Ghostnomadjr&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/milkymist-video-synthesizers-at-the-cutting-edge-of-open-source-hardware-sebastien-bourdeauducq"&gt;Milkymist: video synthesizers at the cutting edge of open source hardware&lt;br/&gt;Sébastien Bourdeauducq&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/development-operations-take-back-your-infrastructure-mark-stanislav"&gt;Development Operations: Take Back Your Infrastructure&lt;br/&gt;Mark Stanislav&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/exercise-your-mind-and-body-suellen-walker-joe-walker"&gt;Exercise Your Mind and Body&lt;br/&gt;Suellen Walker, Joe Walker&lt;/a&gt; 
&lt;p&gt;&lt;B&gt;Day 2&lt;/B&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/how-to-market-the-morally-broken-and-sociologically-depraved-a-guide-to-selling-your-local-hacker-conference-to-the-public-jaime-payne"&gt;How to Market the Morally Broken and Sociologically Depraved: A Guide to Selling Your Local Hacker Conference to the Public&lt;br/&gt;Jaime Payne&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/geocaching-101-jon-peer"&gt;Geocaching 101&lt;br/&gt;Jon Peer&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/notacon-9-network"&gt;Notacon 9 Network&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/1984-2012-legal-privacy-trends-nick-merker"&gt;1984 2012 Legal Privacy Trends&lt;br/&gt;Nick Merker&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/the-sword-is-mightier-than-the-pentest-an-introduction-to-fencing-brian-stone-amy-clausen"&gt;The Sword is Mightier than the Pen(test): an Introduction to Fencing&lt;br/&gt;Brian Stone, Amy Clausen&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/what-locksport-can-teach-us-about-security-bill-sempf"&gt;What Locksport Can Teach Us About Security&lt;br/&gt;Bill Sempf&lt;/a&gt; 
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/notacon9/octodad-building-a-better-tentacle-ragdoll-devon-scott-tunkin"&gt;Octodad: Building a Better Tentacle Ragdoll&lt;br/&gt;Devon Scott-Tunkin&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/pvOPgM7od5uDJmtzDhhKoqfuKoE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pvOPgM7od5uDJmtzDhhKoqfuKoE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/pvOPgM7od5uDJmtzDhhKoqfuKoE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pvOPgM7od5uDJmtzDhhKoqfuKoE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/Ei3UOjk2jJQ" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/notacon9/mainlist</feedburner:origLink></item>
    <item>
      <title>More Mutillidae/Web Pen-testing videos from Jeremy Druin</title>
      <pubDate>Sun, 15 Apr 2012 19:30:58 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/Hun8Xt19E1Y/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#detailed-look-at-linux-traceroute"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#detailed-look-at-linux-traceroute&lt;/a&gt; 
&lt;p&gt;Three more great videos from Jeremy Druin (&lt;a href="https://twitter.com/#!/webpwnized"&gt;@webpwnized&lt;/a&gt; ): &lt;/p&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#detailed-look-at-linux-traceroute"&gt;Detailed Look At Linux Traceroute&lt;/a&gt; 
&lt;p align="left"&gt;This video takes a detailed look at the traceroute program in Linux. The newer traceroute is used (version 2.0.18). The later versions have the ability to send packets of different protocols (i.e. TCP) to the target. This feature was previously found in the LFT (Layer Four Traceroute) tool but not found in the Linux traceroute. While LFT still is more feature-rich than the traceroute built into Linux, the new features in Linux traceroute make the tool very useful and quite capible. It helps to understand how the traceroute tool forms the packets, to what ports the packets are sent, and what protocols can be used to send the packets. This information can be used to get traceroute commands to work through firewalls and HIPS systems when ICMP and/or UDP and/or most TCP ports are blocked. 
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#introduction-to-tcpdump-network-sniffer"&gt;Introduction To TCPDump Network Sniffer&lt;/a&gt; 
&lt;p align="left"&gt;This video is an introduction to the tcpdump network packet sniffer/capture tool. The video is relatively long because of the demo used required "building up" to the HTTP capture. The video only covers the basics but is meant to be a good introduction to practical use of tcpdump. 
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-using-the-maltego-reconnaissance-graphing-tool"&gt;Basics Of Using The Maltego Reconnaissance Graphing Tool&lt;/a&gt; 
&lt;p align="left"&gt;This video looks at using Maltego to both gather and organize information in a customer pen-test. Maltego is a GUI-based tool for Linux which is included in the Backtrack 5 R2 release. The tool is able to gather information from public sources on entities. The Community Edition (used in this video) is free. There is a paid-version with more features. The site used in this video is irongeek.com and was used with written permission from the owner. If following along, please use a domain for which you have permission.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/cDnhYh4Bpv7LpYtKi_5nZfGeWOo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/cDnhYh4Bpv7LpYtKi_5nZfGeWOo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/cDnhYh4Bpv7LpYtKi_5nZfGeWOo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/cDnhYh4Bpv7LpYtKi_5nZfGeWOo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/Hun8Xt19E1Y" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#detailed-look-at-linux-traceroute</feedburner:origLink></item>
    <item>
      <title>Finding Comments And File Metadata Using Multiple Techniques </title>
      <pubDate>Sun, 8 Apr 2012 15:40:34 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/BWUsYhfXIic/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#finding-comments-and-file-metadata-using-multiple-techniques"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#finding-comments-and-file-metadata-using-multiple-techniques&lt;/a&gt;&lt;br/&gt;Jeremy Druin has made a new video:&lt;br/&gt;This video has two related parts. The first part discusses finding the comments in Mutillidae related to the "comments challenge". This is an easy challenge in Mutillidae but the techniques can be extended to search entire sites for comments. The second part of the video looks at finding metadata in general using a variety of tools.&lt;br/&gt;&lt;br/&gt;The tools used are Firefox "View Source", W3AF, grep, wget, Burp Suite, exiftool and strings. The demo site used is Mutillidae, which is a free open-source fully functional PHP site with a MySQL database. The site runs on localhost or it can be run in a virtual network as a practice target or capture the flag target. It is not a good idea to run Mutillidae publically because it will get hacked. Mutillidae is available at Sourceforge and Irongeek.com. Along with the project is several documents and an installation guide for Windows 7.
&lt;p&gt;Also, I updated the &lt;a href="http://www.irongeek.com/i.php?page=videos/pen-testing-practice-in-a-box-how-to-assemble-a-virtual-network"&gt;Pen-testing practice in a box: How to assemble a virtual network&lt;/a&gt; post to fix an audio issue (it was cutting out after a certain amount of time).&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zy8f4UXUkSd7-fqAkQE5SFeYDRM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zy8f4UXUkSd7-fqAkQE5SFeYDRM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zy8f4UXUkSd7-fqAkQE5SFeYDRM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zy8f4UXUkSd7-fqAkQE5SFeYDRM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/BWUsYhfXIic" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#finding-comments-and-file-metadata-using-multiple-techniques</feedburner:origLink></item>
    <item>
      <title>Pen-testing practice in a box: How to assemble a virtual network</title>
      <pubDate>Sat, 7 Apr 2012 12:55:44 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/EZMJk1O5kKw/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/pen-testing-practice-in-a-box-how-to-assemble-a-virtual-network"&gt;http://www.irongeek.com/i.php?page=videos/pen-testing-practice-in-a-box-how-to-assemble-a-virtual-network&lt;/a&gt;&lt;br/&gt;This is the first in a line of classes Jeremy Druin will be giving on pen-testing and web app security featuring &lt;a href="http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10"&gt;Mutillidae&lt;/a&gt; for the &lt;a href="http://www.issa-kentuckiana.org/"&gt;Kentuckiana ISSA&lt;/a&gt;. Topics: Virtual Box Installation, Installing virtual machines, Configuring virtual networks - bridged, nat, hostonly, USB devices in virtual machines, Wireless networks in virtual machines, Installing Guest Additions, How to install Mutillidae in Windows on XAMPP, How to install Mutillidae in Linux Samurai
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/H6m2HmEWTcu2w1dijAdzHUQhB1Q/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H6m2HmEWTcu2w1dijAdzHUQhB1Q/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/H6m2HmEWTcu2w1dijAdzHUQhB1Q/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H6m2HmEWTcu2w1dijAdzHUQhB1Q/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/EZMJk1O5kKw" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/pen-testing-practice-in-a-box-how-to-assemble-a-virtual-network</feedburner:origLink></item>
    <item>
      <title>Mutillidae How To Use Dradis To Organize Nmap And Nessus Scan Results</title>
      <pubDate>Thu, 5 Apr 2012 08:37:50 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/cBQyweOY04c/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-use-dradis-to-organize-nmap-and-nessus-scan-results"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-use-dradis-to-organize-nmap-and-nessus-scan-results&lt;/a&gt;&lt;br/&gt;New video from Jeremy Druin:&lt;br/&gt;The latest version of Dradis (2.9) has excellent import speed compared to version 2.7. This video looks at using the import features of Dradis to organize the scan results from an nmap scan and a Nessus 5 scan. Dradis is a tool that allows pen testers, auditors, and vulnerability assessors to organize their work by server or other categories. The Dradis starts a web server which other team members can share information as well.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/8ARWE21sXM5iMpiEHDnADdDnP5w/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8ARWE21sXM5iMpiEHDnADdDnP5w/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/8ARWE21sXM5iMpiEHDnADdDnP5w/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8ARWE21sXM5iMpiEHDnADdDnP5w/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/cBQyweOY04c" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-use-dradis-to-organize-nmap-and-nessus-scan-results</feedburner:origLink></item>
    <item>
      <title>Homoglyph Attack Generator Updated</title>
      <pubDate>Tue, 3 Apr 2012 15:30:32 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/EEe6rZA-NAc/homoglyph-attack-generator.php</link>
      <category>code</category>
      <description>Link:&lt;a href="http://www.irongeek.com/homoglyph-attack-generator.php"&gt;http://www.irongeek.com/homoglyph-attack-generator.php&lt;/a&gt;&lt;br/&gt;I found a list of IDN blacklisted characters on Mozilla's site and added them. I also added a table of the homoglyphs I'm using.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qe4ccW2ufi3hb3nlGepF2K49VZU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qe4ccW2ufi3hb3nlGepF2K49VZU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qe4ccW2ufi3hb3nlGepF2K49VZU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qe4ccW2ufi3hb3nlGepF2K49VZU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/EEe6rZA-NAc" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/homoglyph-attack-generator.php</feedburner:origLink></item>
    <item>
      <title>Two More Web Security Videos From Jeremy Druin </title>
      <pubDate>Sun, 1 Apr 2012 20:03:22 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/66405OsIMjU/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-upgrade-to-nessus-5-on-backtrack-5-r2"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-upgrade-to-nessus-5-on-backtrack-5-r2&lt;/a&gt; 
&lt;p&gt;Jeremy Druin has made two more videos:&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-upgrade-to-nessus-5-on-backtrack-5-r2"&gt;How To Upgrade To Nessus 5 On Backtrack 5 R2&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;This video looks at upgrading Nessus 4 to Nessus 5. The operating system used in the video is Backtrack 5 R2. Nessus 4 was successfully registered and running on this OS prior to attempting to upgrade to Nessus 5. If a fresh Nessus install is needed, the process is different.&lt;br/&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#creating-reports-and-metasploit-db-importable-reports-with-nmap-xml-output"&gt;Creating Reports And Metasploit Db Importable Reports With Nmap Xml Output&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Nmap reporting is excellent with the XML option but this is not used in a lot of cases. The XML output from nmap can be imported into other tools such as the Metasploit Community Edition (Import button), metasploit DB, and other tools. Also, the XML format can be opened in a web browser to produce a well-formatted report suitable for attachment to a pen-test.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/04y1lERHkSesblrSbAJIEQtBLg8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/04y1lERHkSesblrSbAJIEQtBLg8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/04y1lERHkSesblrSbAJIEQtBLg8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/04y1lERHkSesblrSbAJIEQtBLg8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/66405OsIMjU" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-upgrade-to-nessus-5-on-backtrack-5-r2</feedburner:origLink></item>
    <item>
      <title>Outerz0ne Video Move</title>
      <pubDate>Thu, 29 Mar 2012 11:02:31 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/ZbcwmoHa2Iw/i.php</link>
      <category>video</category>
      <description>&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con"&gt;Outerz0ne Video Move&lt;/a&gt;&lt;br/&gt;Still working on moving videos to YouTube to support more devices. Since &lt;a href="http://www.outerz0ne.org/"&gt;Outerz0ne&lt;/a&gt; is coming up I decided to move their videos next: 
&lt;p&gt;&lt;/p&gt;
&lt;p align="left"&gt;Outerz0ne 2011:&lt;/p&gt;
&lt;BLOCKQUOTE&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#SkyDog_-_Opening_Ceremonies/etc."&gt;SkyDog - Opening Ceremonies/etc. &lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#SkyDog_-_The_Modern_Day_Hacker"&gt;SkyDog - The Modern Day Hacker &lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#IronGeek_-_Rendering_Hacker_Con_Videos_with_AviSynth"&gt;IronGeek - Rendering Hacker Con Videos with AviSynth &lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#MadMex_-_Windows_Command_Line_Incident_Response__"&gt;MadMex - Windows Command Line Incident Response &lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#HalfJack_-Building_your_Own_Green_Home"&gt;HalfJack -Building your Own Green Home&lt;/a&gt; &lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#Beau_Woods_-_What_Companies_and_Vendors_must_know_about_securing_mobile_devices,_mobile_applications,_access_and_data."&gt;Beau Woods - What Companies and Vendors must know about securing mobile devices, mobile applications, access and data. &lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#Rick_Hayes_-_Assessing_and_Pen-Testing_IPv6_Networks"&gt;Rick Hayes - Assessing and Pen-Testing IPv6 Networks&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#Pure_Hate_-_Why_your_password_policy_sucks"&gt;Pure Hate - Why your password policy sucks&lt;/a&gt; &lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#Billy_Hoffman_-_Advice_on_starting_a_start-u"&gt;Billy Hoffman - Advice on starting a start-up&lt;/a&gt; &lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con#Contest_Prize_Giveaway,_Awards,_Closing_Ceremonies"&gt;Contest Prize Giveaway, Awards, Closing Ceremonies&lt;/a&gt;&lt;/p&gt;&lt;/BLOCKQUOTE&gt;
&lt;p align="left"&gt;Outerz0ne 2010:&lt;/p&gt;
&lt;BLOCKQUOTE&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#Intro_to_Outerzone_and_Talk_1_-_Security_People_Suck_-_Gene_Bransfield"&gt;Intro to Outerzone and Talk 1 - Security People Suck - Gene Bransfield&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#IronGeek_-_Turning_the_Zipit_2_into_a_mobile_hacking_device"&gt;IronGeek - Turning the Zipit 2 into a mobile hacking device&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#Freeside"&gt;Freeside&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#PBR90X_-_Social_Networking_FAIL"&gt;PBR90X - Social Networking #FAIL&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#Scott_Moulton_-_Hard_Drive_Kung_Fu_Magic"&gt;Scott Moulton - Hard Drive Kung Fu Magic&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#Brian_Wilson_-Docsis_Coolness"&gt;Brian Wilson -Docsis Coolness&lt;/a&gt; &lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#BobTalks"&gt;BobTalks&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#Billy_Hoffman_-_Web_Performance_Talk_Craziness"&gt;Billy Hoffman - Web Performance Talk Craziness&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2010-videos#Closing_Ceremonies"&gt;Closing Ceremonies&lt;/a&gt;&lt;/p&gt;&lt;/BLOCKQUOTE&gt;
&lt;p align="left"&gt;Outerz0ne 2009&lt;/p&gt;
&lt;BLOCKQUOTE&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/morgellon-duino-punk-manifesting-open-source-in-physical-space"&gt;Morgellon - *Duino-Punk! Manifesting Open Source in Physical Space from Outerz0ne 5&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/tyler-pitchford-they-took-my-laptop-us-search-and-seizure-explained"&gt;Tyler Pitchford - They took my laptop! - U.S. Search and Seizure Explained&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/skydog-screen-printing-primer-make-your-own-con-shirt"&gt;SkyDog - Screen Printing Primer - Make your own Con Shirt!&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/slimjim100-live-demo-of-cain-and-able-and-the-maninthemiddleattack"&gt;SlimJim100 - Live Demo of Cain &amp;amp; Able and the Man-in-the-middle-attack&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/nick-chapman-embedded-malicious-javascript"&gt;Nick Chapman - Embedded Malicious Javascript&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/makers-local-256-a-primer-on-hackerspaces"&gt;Makers Local 256 - A primer on hackerspaces&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/scott-moulton-reassembling-raid-by-sight-and-sound"&gt;Scott Moulton - Reassembling RAID by SIGHT and SOUND!&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/rob-ragan-filter-evasion-houdini-on-the-wire"&gt;Rob Ragan - Filter Evasion - Houdini on the Wire&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/acidus-billy-hoffman-offline-apps-the-future-of-the-web-is-the-client"&gt;Acidus (Billy Hoffman) - Offline Apps: The Future of The Web is the Client?&lt;/a&gt;&lt;br/&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-2009-closing"&gt;Closing&lt;/a&gt;&lt;/p&gt;&lt;/BLOCKQUOTE&gt;
&lt;p&gt;Also, a video I did about Outerz0ne and &lt;a href="http://www.notacon.org/"&gt;Notacon&lt;/a&gt; 2009: 
&lt;BLOCKQUOTE&gt;
&lt;p&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/outerz0ne-notacon-2009-hacker-cons"&gt;Outerz0ne and Notacon 2009 Hacker Cons Report &lt;/a&gt;&lt;/p&gt;&lt;/BLOCKQUOTE&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iZITf2WJlGoVAPKKx0man365HMU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iZITf2WJlGoVAPKKx0man365HMU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iZITf2WJlGoVAPKKx0man365HMU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iZITf2WJlGoVAPKKx0man365HMU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/ZbcwmoHa2Iw" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/outerz0ne-2011-hacker-con</feedburner:origLink></item>
    <item>
      <title>Manual Directory Browsing To Reveal Mutillidae Easter Egg File</title>
      <pubDate>Wed, 28 Mar 2012 10:13:42 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/vInfIp36u0g/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#manual-directory-browsing-to-reveal-mutillidae-easter-egg-file"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#manual-directory-browsing-to-reveal-mutillidae-easter-egg-file&lt;/a&gt;&lt;br/&gt;Jeremy has made another video:&lt;br/&gt;This video looks at manual testing for directory browsing misconfiguration vulnerabilities in Mutillidae. For directory browsing brute forcing, OWASP DiRBuster or Burp-Suite Intruder are great tools. However, Mutillidae gives away some of its directory paths when serving PDF and other files. These can be tested manually to reveal the Mutillidae Easter egg file. Also common directory names like "include" and "includes" can be tried quickly just using a browser before firing up the tools.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Oitwv-lj3iE4ZLf44LLgF4QGRZI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Oitwv-lj3iE4ZLf44LLgF4QGRZI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Oitwv-lj3iE4ZLf44LLgF4QGRZI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Oitwv-lj3iE4ZLf44LLgF4QGRZI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/vInfIp36u0g" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#manual-directory-browsing-to-reveal-mutillidae-easter-egg-file</feedburner:origLink></item>
    <item>
      <title>OSInt, Cyberstalking, Footprinting and Recon: Getting to know you (YouTube Migration)</title>
      <pubDate>Mon, 26 Mar 2012 11:46:30 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/zOe20PLjCDU/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/osint-cyberstalking-footprinting-recon"&gt;http://www.irongeek.com/i.php?page=videos/osint-cyberstalking-footprinting-recon&lt;/a&gt;&lt;br/&gt;I've migrated the "OSInt, Cyberstalking, Footprinting and Recon: Getting to know you" to YouTube. This should allow it to be viewed on more devices. 
&lt;p&gt;The following are videos from the Footprinting/OSInt/Recon/Cyberstalking class I did up in Fort Wayne Indiana for the Northeast Indiana Chapter of ISSA. I've split the class into three videos by subtopic, and included the text from the presentation for quick linking.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NGhdWhuQcFPs54v1D75lVPVmmoE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NGhdWhuQcFPs54v1D75lVPVmmoE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NGhdWhuQcFPs54v1D75lVPVmmoE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NGhdWhuQcFPs54v1D75lVPVmmoE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/zOe20PLjCDU" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/osint-cyberstalking-footprinting-recon</feedburner:origLink></item>
    <item>
      <title>Password Exploitation Class (YouTube Migration)</title>
      <pubDate>Mon, 26 Mar 2012 11:45:20 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/CPtM-hwudOc/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/password-exploitation-class"&gt;http://www.irongeek.com/i.php?page=videos/password-exploitation-class&lt;/a&gt;&lt;br/&gt;I've migrated the "Password Exploitation Class" to YouTube. This should allow it to be viewed on more devices. 
&lt;p&gt;This is a class we gave for the Kentuckiana ISSA on the the subject of password exploitation. The Password Exploitation Class was put on as a charity event for the Matthew Shoemaker Memorial Fund. The speakers were &lt;a href="http://www.question-defense.com/"&gt;Dakykilla,&lt;/a&gt; &lt;a href="http://www.question-defense.com/"&gt;Purehate_&lt;/a&gt; and Irongeek.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/r5AAsnsh1_Bv3bc9RMTwST8T0X4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/r5AAsnsh1_Bv3bc9RMTwST8T0X4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/r5AAsnsh1_Bv3bc9RMTwST8T0X4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/r5AAsnsh1_Bv3bc9RMTwST8T0X4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/CPtM-hwudOc" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/password-exploitation-class</feedburner:origLink></item>
    <item>
      <title>Anti-Forensics: Occult Computing Class (YouTube Migration)</title>
      <pubDate>Mon, 26 Mar 2012 11:44:46 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/2YZTEWnoIcM/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/anti-forensics-occult-computing"&gt;http://www.irongeek.com/i.php?page=videos/anti-forensics-occult-computing&lt;/a&gt;&lt;br/&gt;I've migrated the "Anti-Forensics: Occult Computing Class" to YouTube. This should allow it to be viewed on more devices. 
&lt;p&gt;This is a class I gave for the Kentuckiana ISSA on the the subject of Anti-forensics. It's about 3 hours long, and sort of meandering, but I hope you find it handy. For the record, Podge was operating the camera :) Apparently it was not on me during the opening joke, but so be it, no one seemed to get it. I spend way to much time on the Internet it seems. Also, I'm in need of finding video host to take these large files. This class video is 3 hours, 7 min and 1.2GB as captured.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/JmIS8qgi7MhAwRHPQOQjJUgvIIY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JmIS8qgi7MhAwRHPQOQjJUgvIIY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/JmIS8qgi7MhAwRHPQOQjJUgvIIY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JmIS8qgi7MhAwRHPQOQjJUgvIIY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/2YZTEWnoIcM" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/anti-forensics-occult-computing</feedburner:origLink></item>
    <item>
      <title>Mutillidae Injecting Cross Site Script Into Logging Pages Via Cookie Injection</title>
      <pubDate>Sat, 24 Mar 2012 13:20:50 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/Gn43poHjT98/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#injecting-cross-site-script-into-logging-pages-via-cookie-injection"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#injecting-cross-site-script-into-logging-pages-via-cookie-injection
&lt;/a&gt;&lt;br&gt;
Jeremy has made another video (I can't keep up):&lt;br&gt;
By setting the values of browser cookies, then purposely browsing to a web page 
that logs the value of user cookies, it may be possible to inject cross site 
scripts into the log files or the log data table of the web site. Later when the 
logs are reviewed by Administrators, the cross site scripts may execute in the 
administrators browser. The video uses the Mutillidae capture data pages as an 
example. In Mutillidae one of the capture the flag events is to poison the 
attackers browser by purposely exposes the attacker to a cross site script. This 
can be done by infecting a cookie then &amp;quot;letting&amp;quot; the attacker trick you into 
visiting the capture data page.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XKll9WwDcA0fHwwMXycN6h4AYE8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XKll9WwDcA0fHwwMXycN6h4AYE8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XKll9WwDcA0fHwwMXycN6h4AYE8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XKll9WwDcA0fHwwMXycN6h4AYE8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/Gn43poHjT98" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#injecting-cross-site-script-into-logging-pages-via-cookie-injection</feedburner:origLink></item>
    <item>
      <title>Mutillidae Generate Cross Site Scripts With SQL Injection</title>
      <pubDate>Sat, 24 Mar 2012 12:32:15 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/OGtYGxKKDhI/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#generate-cross-site-scripts-with-sql-injection"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#generate-cross-site-scripts-with-sql-injection
&lt;/a&gt;&lt;br&gt;
Jeremy has made another video:&lt;br&gt;
This video discusses an advanced SQL injection technique. The SQL injection is 
used to generate cross site scripting. This is useful when cross site scripts 
cannot be injected into a webpage from a client because web application 
firewalls or other scanners are in place. When an SQL injection can be snuck 
past the WAF, it is possible to have the SQL injection generate the Cross Site 
Script dynamically.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/EzL4Ob1Qr67O3TVwBeic6znhBAg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EzL4Ob1Qr67O3TVwBeic6znhBAg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/EzL4Ob1Qr67O3TVwBeic6znhBAg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EzL4Ob1Qr67O3TVwBeic6znhBAg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/OGtYGxKKDhI" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#generate-cross-site-scripts-with-sql-injection</feedburner:origLink></item>
    <item>
      <title>DOJOCON 2010 Videos Migrated To YouTube</title>
      <pubDate>Thu, 22 Mar 2012 09:45:25 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/3ZKjrJ9tFkI/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos"&gt;http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos&lt;/a&gt;&lt;br/&gt;I've started to migrate the con videos I record and embed on this site to YouTube. I'm doing this for a few reasons: 
&lt;p&gt;&lt;/p&gt;
&lt;p align="left"&gt;1. Vimeo took down Dave Marcus' talk because they said it was in violation of their TOS, and when I tried to explain to them what it was about they would not email me back (and I was a paying customer to their service at the time).&lt;br/&gt;2. I'm now allowed longer videos on YouTube, so why not.&lt;br/&gt;3. This should support more devices.&lt;/p&gt;
&lt;p align="left"&gt;I've started with DOJOCON 2010 to get Dave's talk back up. Below are the videos from the conference, at least the ones I can show :), enjoy. &lt;/p&gt;
&lt;p&gt;&lt;B&gt;Index:&lt;/B&gt;&lt;/p&gt;
&lt;BLOCKQUOTE&gt;
&lt;p&gt;Tiffany Strauchs Rad, @&lt;a href="http://twitter.com/#!/TiffanyRad"&gt;tiffanyrad&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#International Cyber Jurisdiction Kill Switching Cyberspace, Cyber Criminal"&gt;International Cyber Jurisdiction: "Kill Switching" Cyberspace, Cyber Criminal Prosecution &amp;amp; Jurisdiction Hopping&lt;/a&gt;&lt;br/&gt;John Strauchs, @&lt;a href="http://twitter.com/#!/Strauchs"&gt;strauchs&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Security and IT Convergence"&gt;Security and IT Convergence&lt;/a&gt;&lt;br/&gt;Richard Goldberg, @&lt;a href="http://twitter.com/#!/GoldbergLawDC"&gt;GoldbergLawDC&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Rules of Engagment: Mitigating Risk in Information Security Work"&gt;Rules of Engagment: Mitigating Risk in Information Security Work&lt;/a&gt;&lt;br/&gt;Jon McCoy: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Ninja Patching .NET"&gt;Ninja Patching .NET&lt;/a&gt;&lt;br/&gt;Marco Figueroa, @&lt;a href="http://twitter.com/#!/marcofigueroa"&gt;marcofigueroa&lt;/a&gt; &amp;amp; Kevin Figueroa: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Detecting &amp;amp; Defending You Network using Nepenthes/Shaolin Tools"&gt;Detecting &amp;amp; Defending Your Network using Nepenthes/Shaolin Tools&lt;/a&gt;&lt;br/&gt;Dave Marcus, @&lt;a href="http://twitter.com/#!/davemarcus"&gt;davemarcus&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Using Social Networks To Profile, Find and 0wn Your Victims"&gt;Using Social Networks To Profile, Find and 0wn Your Victims&lt;/a&gt;&lt;br/&gt;Brian Baskin, @&lt;a href="http://twitter.com/#!/bbaskin"&gt;bbaskin&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#P2P Forensics"&gt;P2P Forensics&lt;/a&gt;&lt;br/&gt;Jonathan Abolins, &lt;a href="http://twitter.com/#!/jabolins"&gt;@jabolins&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Internationalized Domain Names &amp;amp; Investigations in the Networked World"&gt;Internationalized Domain Names &amp;amp; Investigations in the Networked World &lt;/a&gt;&lt;br/&gt;Deviant Ollam, @&lt;a href="http://twitter.com/#!/deviantollam"&gt;deviantollam&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Don't Punch My Junk"&gt;Don't Punch My Junk&lt;/a&gt;&lt;br/&gt;Michael Shearer, @&lt;a href="http://twitter.com/#!/theprez98"&gt;theprez98&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#How to 0wn an ISP in 10 Minutes"&gt;How to 0wn an ISP in 10 Minutes&lt;/a&gt;&lt;br/&gt;Christopher Witter, @&lt;a href="http://twitter.com/#!/mr_cwitter"&gt;mr_cwitter&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Enterprise Packet Capture on Da'Cheap"&gt;Enterprise Packet Capture on Da'Cheap&lt;/a&gt;&lt;br/&gt;Ben Smith: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Printer Exploitation"&gt;Printer Exploitation&lt;/a&gt;&lt;br/&gt;Adrian Crenshaw, @&lt;a href="http://twitter.com/#!/irongeek_adc"&gt;irongeek_adc&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Malicious USB Devices: Is that an attack vector in your pocket or are you just happy to see me"&gt;Malicious USB Devices: Is that an attack vector in your pocket or are you just happy to see me?&lt;/a&gt;&lt;br/&gt;Shyaam Sundhar, @&lt;a href="http://twitter.com/#!/EvilFingers"&gt;EvilFingers&lt;/a&gt; and John Fulmer, @&lt;a href="http://twitter.com/#!/DaKahuna2007"&gt;DaKahuna2007&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Is the IDS Dead"&gt;Is the IDS Dead?&lt;/a&gt;&lt;br/&gt;Chris Nickerson, @&lt;a href="http://twitter.com/#!/indi303"&gt;indi303&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#The State of (In)Security"&gt;The State of (In)Security&lt;/a&gt;&lt;br/&gt;&lt;a name="The State of (In)Security0"&gt;Gal Shpantzer, @&lt;/a&gt;&lt;a href="http://twitter.com/#!/shpantzer"&gt;shpantzer&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#Security Outliers: Cultural Cues from High-Risk Professions"&gt;Security Outliers: Cultural Cues from High-Risk Professions&lt;/a&gt;&lt;br/&gt;Michael Smith, @&lt;a href="http://twitter.com/#!/rybolov"&gt;rybolov&lt;/a&gt;: &lt;a href="http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos#DDoS"&gt;DDoS&lt;/a&gt;&lt;/p&gt;&lt;/BLOCKQUOTE&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zr2CNg6hb7pzGVReCYczlOV8MxA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zr2CNg6hb7pzGVReCYczlOV8MxA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zr2CNg6hb7pzGVReCYczlOV8MxA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zr2CNg6hb7pzGVReCYczlOV8MxA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/3ZKjrJ9tFkI" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/dojocon-2010-videos</feedburner:origLink></item>
    <item>
      <title>Web Application Pen-testing Tutorials With Mutillidae</title>
      <pubDate>Thu, 15 Mar 2012 00:00:24 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/GK4GTo0JynY/i.php</link>
      <category>videos</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae"&gt;http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae&lt;/a&gt;&lt;br/&gt;When I started the &lt;a href="http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10"&gt;Mutillidae&lt;/a&gt; project it was with the intention of using it as a teaching tool and making easy to understand video demos. Truth be told, I never did as much with it as I intended. However, after Jeremy Druin (&lt;a href="https://twitter.com/#%21/webpwnized"&gt;@webpwnized&lt;/a&gt;) took over the development it really took off. I have since come to find out he has been doing A LOT of YouTube video tutorials with Mutillidae, which he said I could share here. I will be copying his descriptions with slight editing and embedding his videos in this page. Videos include:&lt;br/&gt;&amp;nbsp; 
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#determine-http-methods-using-netcat"&gt;Determine Http Methods Using Netcat&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#determine-server-banners-using-netcat-nikto-and-w3af"&gt;Determine Server Banners Using Netcat Nikto And W3af&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#bypass-authentication-using-sql-injection"&gt;Bypass Authentication Using SQL Injection&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-menus"&gt;Using Menus&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#bypass-authentication-via-authentication-token-manipulation"&gt;Bypass Authentication Via Authentication Token Manipulation&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#explanation-of-httponly-cookies-in-presense-of-cross-site-scripting"&gt;Explanation Of HTTPonly Cookies In Presense Of Cross Site Scripting &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#closer-look-at-cache-control-and-pragma-no-cache-headers"&gt;Closer Look At Cache Control And Pragma No Cache Headers&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#demonstration-of-frame-busting-javascript-and-x-frame-options-header"&gt;Demonstration Of Frame Busting Javascript And X-Frame Options Header&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-install-and-configure-burp-suite-with-firefox"&gt;How To Install And Configure Burp Suite With Firefox&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-web-request-and-response-interception-using-burp-suite"&gt;Basics Of Web Request And Response Interception Using Burp Suite&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#brute-force-authentication-using-burp-intruder"&gt;Brute Force Authentication Using Burp Intruder&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#automate-sql-injection-using-sqlmap-to-dump-credit-cards-table"&gt;Automate SQL Injection Using SQLMap To Dump Credit Cards Table&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#command-injection-to-dump-files-start-services-disable-firewall"&gt;Command Injection To Dump Files Start Services Disable Firewall&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-exploit-local-file-inclusion-vulnerability-using-burp-suite"&gt;How To Exploit Local File Inclusion Vulnerability Using Burp Suite&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#html-injection-to-popup-fake-login-form-and-capture-credentials"&gt;HTML Injection To Popup Fake Login Form And Capture Credentials&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#two-methods-to-steal-session-tokens-using-cross-site-scripting"&gt;Two Methods To Steal Session Tokens Using Cross Site Scripting&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-bypass-maxlength-restrictions-on-html-input-fields"&gt;How To Bypass Maxlength Restrictions On HTML Input Fields&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#two-methods-to-bypass-javascript-validation"&gt;Two Methods To Bypass Javascript Validation&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#three-methods-for-viewing-http-request-and-response-headers"&gt;Three Methods For Viewing Http Request And Response Headers&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-sql-injection-timing-attacks"&gt;Basics Of SQL Injection Timing Attacks &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-sql-injection-using-union"&gt;Basics Of SQL Injection Using Union&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-inserting-data-with-sql-injection"&gt;Basics Of Inserting Data With SQL Injection&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#inject-root-web-shell-backdoor-via-sql-injection"&gt;Inject Root Web Shell Backdoor Via SQL Injection &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-using-sql-injection-to-read-files-from-operating-system"&gt;Basics Of Using SQL Injection To Read Files From Operating System&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-locate-the-easter-egg-file-using-command-injection"&gt;How To Locate The Easter Egg File Using Command Injection &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#injecting-cross-site-script-into-stylesheet-context"&gt;Injecting Cross Site Script Into Stylesheet Context &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#introduction-to-http-parameter-pollution"&gt;Introduction To Http Parameter Pollution &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-injecting-cross-site-script-into-HTML-onclick-event"&gt;Basics Of Injecting Cross Site Script Into HTML Onclick Event &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-finding-reflected-cross-site-scripting"&gt;Basics Of Finding Reflected Cross Site Scripting &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#analyze-session-token-randomness-using-burp-suite-sequencer"&gt;Analyze Session Token Randomness Using Burp Suite Sequencer &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-nmap-to-fingerprint-http-servers-and-web-applications"&gt;Using Nmap To Fingerprint Http Servers And Web Applications &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#spidering-web-applications-with-burp-suite"&gt;Spidering Web Applications With Burp Suite &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-burp-suite-targets-tab-and-scope-settings"&gt;Basics Of Burp Suite Targets Tab And Scope Settings &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#brute-force-page-names-using-burp-intruder-sniper"&gt;Brute Force Page Names Using Burp Intruder Sniper &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-burp-intruder-sniper-to-fuzz-parameters"&gt;Using Burp Intruder Sniper To Fuzz Parameters&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#comparing-burp-intruder-modes-sniper-battering-ram-pitchfork-cluster-bomb"&gt;Comparing Burp Intruder Modes Sniper Battering RAM Pitchfork Cluster Bomb &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#demo-usage-of-burp-suite-comparer-tool"&gt;Demo Usage Of Burp Suite Comparer Tool &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#import-custom-nmap-scans-into-metasploit-community-edition"&gt;Import Custom Nmap Scans Into Metasploit Community Edition&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#using-metasploit-community-edition-to-locate-web-servers"&gt;Using Metasploit Community Edition To Locate Web Servers &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#xss-dns-lookup-page-bypassing-javascript-validation"&gt;XSS DNS Lookup Page Bypassing Javascript Validation &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#use-burp-suite-sequencer-to-compare-csrf-token-strengths"&gt;Use Burp Suite Sequencer To Compare Csrf Token Strengths&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-remove-php-errors-after-installing-on-windows-xampp"&gt;How To Remove PHP Errors After Installing On Windows Xampp&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#quickstart-guide-to-installing-on-windows-with-xampp"&gt;Quickstart Guide To Installing On Windows With Xampp&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-running-nessus-scan-on-backtrack-5-r1"&gt;Basics Of Running Nessus Scan On Backtrack 5 R1 &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-import-nessus-scans-into-metasploit-community-edition"&gt;How To Import Nessus Scans Into Metasploit Community Edition &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#basics-of-exploiting-vulnerabilities-with-metasploit-community-edition"&gt;Basics Of Exploiting Vulnerabilities With Metasploit Community Edition &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#sending-persistent-cross-site-scripts-into-web-logs-to-snag-web-admin"&gt;Sending Persistent Cross Site Scripts Into Web Logs To Snag Web Admin &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#quick-start-overview-of-useful-pen-testing-addons-for-firefox"&gt;Quick Start Overview Of Useful Pen-Testing Addons For Firefox&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#three-methods-for-viewing-javascript-include-files"&gt;Three Methods For Viewing Javascript Include Files &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#reading-hidden-values-from-html5-dom-storage"&gt;Reading Hidden Values From HTML5 Dom Storage &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#how-to-execute-javascript-on-the-urlbar-in-modern-browsers"&gt;How To Execute Javascript On The Urlbar In Modern Browsers &lt;/a&gt;&lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#adding-values-to-dom-storage-using-cross-site-scripting"&gt;Adding Values To Dom Storage Using Cross Site Scripting&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#alter-values-in-html5-web-storage-using-cross-site-script"&gt;Alter Values In Html5 Web Storage Using Cross Site Script&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#altering-html-5-web-storage-values-using-persistent-xss"&gt;Altering Html 5 Web Storage Values Using Persistent XSS&lt;/a&gt; &lt;/p&gt;
&lt;li&gt;
&lt;p align="left"&gt;&lt;a href="http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae#altering-html-5-web-storage-with-a-reflected-xss"&gt;Altering HTML 5 Web Storage With A Reflected XSS&lt;/a&gt;&lt;br/&gt;&amp;nbsp;&lt;/p&gt;&lt;/li&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1IkxBoSp6hbGcvgMAW6FFTeKrkA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1IkxBoSp6hbGcvgMAW6FFTeKrkA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1IkxBoSp6hbGcvgMAW6FFTeKrkA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1IkxBoSp6hbGcvgMAW6FFTeKrkA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/GK4GTo0JynY" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/web-application-pen-testing-tutorials-with-mutillidae</feedburner:origLink></item>
    <item>
      <title>Crypto &amp; Block Cipher Modes (OpenSSL, AES 128, ECB, CBC)</title>
      <pubDate>Tue, 13 Mar 2012 00:40:48 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/t6czhXg6UzM/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/crypto-block-cipher-modes-openssl-aes-128-ecb-cbc"&gt;http://www.irongeek.com/i.php?page=videos/crypto-block-cipher-modes-openssl-aes-128-ecb-cbc&lt;/a&gt;&lt;br/&gt;Hopefully this will give a nice visual illustration of how Electronic codebook (ECB) and Cipher-block chaining (CBC) work using AES-128 and OpenSSL. You can learn a lot from a known plain text, and repeating patterns. Inspired by labs from Kevin Benton &amp;amp; "Crypto Lab 1" SEED.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/YoQo7asQEI7xfxokDkaTuUBXiIw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YoQo7asQEI7xfxokDkaTuUBXiIw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/YoQo7asQEI7xfxokDkaTuUBXiIw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YoQo7asQEI7xfxokDkaTuUBXiIw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/t6czhXg6UzM" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/crypto-block-cipher-modes-openssl-aes-128-ecb-cbc</feedburner:origLink></item>
    <item>
      <title>Shared Hosting MD5 Change Detection Script Updated</title>
      <pubDate>Mon, 12 Mar 2012 16:36:17 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/F4rjizThQkY/i.php</link>
      <category>code</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=security/shared-hosting-md5-change-detection-script"&gt;http://www.irongeek.com/i.php?page=security/shared-hosting-md5-change-detection-script&lt;/a&gt;&lt;br/&gt;Fixed an issue with permlog.txt not being put in the $ScriptDir directory.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GyUQJCKuOZyvbE2hmv3_5TWY9V8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GyUQJCKuOZyvbE2hmv3_5TWY9V8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GyUQJCKuOZyvbE2hmv3_5TWY9V8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GyUQJCKuOZyvbE2hmv3_5TWY9V8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/F4rjizThQkY" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/shared-hosting-md5-change-detection-script</feedburner:origLink></item>
    <item>
      <title>Derbycon 2.0: The Reunion Promo Video Posted</title>
      <pubDate>Mon, 12 Mar 2012 11:47:34 -0400</pubDate>
      <link>ttps://www.derbycon.com/2012/03/12/derbycon-2-0-the-reunion-it-begins/</link>
      <description>Video:&lt;a href="https://www.derbycon.com/2012/03/12/derbycon-2-0-the-reunion-it-begins/"&gt;ttps://www.derbycon.com/2012/03/12/derbycon-2-0-the-reunion-it-begins/&lt;/a&gt;&lt;br/&gt;&lt;a href="https://www.secmaniac.com/"&gt;Dave Kennedy&lt;/a&gt; has posted a promo video form Derbycon 2012. A few prominent speakers have been announced. Hope you all can make it this year. To see what you missed from &lt;a href="http://www.irongeek.com/i.php?page=videos/derbycon1/mainlist"&gt;Derbycon 2011, go visit the video page&lt;/a&gt;.&lt;/&lt; body&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/N-35i0XQ9GBImq3UGiEvienQ5yc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/N-35i0XQ9GBImq3UGiEvienQ5yc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/N-35i0XQ9GBImq3UGiEvienQ5yc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/N-35i0XQ9GBImq3UGiEvienQ5yc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/OdDL6WE4VFM" height="1" width="1"/&gt;</description>
    </item>
    <item>
      <title>Proposal for "Out of Character: Use of Punycode and Homoglyph Attacks to Obfuscate URLs for Phishing"</title>
      <pubDate>Sat, 3 Mar 2012 03:26:08 -0400</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/PQCFUdiw-_U/i.php</link>
      <category>article</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/homoglyph-attack-project"&gt;"http://www.irongeek.com/i.php?page=security/homoglyph-attack-project&lt;/a&gt;&lt;br/&gt;Below is a project I'm doing for class. If you want to make suggestions and tell me about weird Unicode/Homoglyph security issues, &lt;a href="http://www.irongeek.com/i.php?page=contact"&gt;please email me&lt;/a&gt;. If you want to play with making homographs, look at my &lt;a href="http://www.irongeek.com/homoglyph-attack-generator.php"&gt;Homoglyph Attack Generator&lt;/a&gt;.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/GLTnPjA9WD6pj-L-ET3KgAW4TZo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GLTnPjA9WD6pj-L-ET3KgAW4TZo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/GLTnPjA9WD6pj-L-ET3KgAW4TZo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/GLTnPjA9WD6pj-L-ET3KgAW4TZo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/PQCFUdiw-_U" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/homoglyph-attack-project</feedburner:origLink></item>
    <item>
      <title>Shared Hosting MD5 Change Detection Script</title>
      <pubDate>Tue, 28 Feb 2012 00:07:01 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/F4rjizThQkY/i.php</link>
      <category>script</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=security/shared-hosting-md5-change-detection-script"&gt;http://www.irongeek.com/i.php?page=security/shared-hosting-md5-change-detection-script&lt;/a&gt;&lt;br/&gt;I was wanting a simple shell script that would monitor the files on a site, and report any changed via email. &lt;a href="https://www.secmaniac.com/download/"&gt;Dave Kennedy's Artillery&lt;/a&gt; was close to what I needed (and does a lot more), but I wanted something I could run on my shared hosting account. This is what I came up with, for better or worse. If nothing else, it was a good exercise in BASH scripting, and may come in handy for those that want to make something similar.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/OC3lFR95CXZjQkLgxyQH5Pt4-qg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OC3lFR95CXZjQkLgxyQH5Pt4-qg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/OC3lFR95CXZjQkLgxyQH5Pt4-qg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OC3lFR95CXZjQkLgxyQH5Pt4-qg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/F4rjizThQkY" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/shared-hosting-md5-change-detection-script</feedburner:origLink></item>
    <item>
      <title>Malicious USB Devices Page Updated With Videos</title>
      <pubDate>Wed, 22 Feb 2012 09:04:23 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/Qu73i3QTxtw/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=security/plug-and-prey-malicious-usb-devices#video"&gt;http://www.irongeek.com/i.php?page=security/plug-and-prey-malicious-usb-devices#video&lt;/a&gt;&lt;br/&gt;I recently found out that the &lt;a href="http://cacr.iu.edu/"&gt;CACR at Indiana University&lt;/a&gt; posted a video of a talk I did for them awhile back, so I decided to update my Malicious USB Devices page to embed it and the other versions of the talk I have.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KdSjEc76TpbljR5oJAT00nWRjJE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KdSjEc76TpbljR5oJAT00nWRjJE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KdSjEc76TpbljR5oJAT00nWRjJE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KdSjEc76TpbljR5oJAT00nWRjJE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/Qu73i3QTxtw" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/plug-and-prey-malicious-usb-devices#video</feedburner:origLink></item>
    <item>
      <title>InfoSec Daily Podcast 600 Tonight </title>
      <pubDate>Tue, 21 Feb 2012 08:35:42 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/3Eg5vtqFLNc/</link>
      <category>event</category>
      <description>Link:&lt;a href="http://www.isdpodcast.com/"&gt;http://www.isdpodcast.com/&lt;/a&gt; &lt;br/&gt;The ISD Podcast is having its 600th episode tonight, Feb 21st 2012. Come join us on the &lt;a href="http://www.isdpodcast.com/category/live-stream"&gt;live stream&lt;/a&gt; and IRC (&lt;a href="http://www.isdpodcast.com/category/webchat"&gt;#isdpodcast on Freenode&lt;/a&gt;) at 8PM EST.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XiQXIwerF_6rornnwAu9dQLIoDg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XiQXIwerF_6rornnwAu9dQLIoDg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XiQXIwerF_6rornnwAu9dQLIoDg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XiQXIwerF_6rornnwAu9dQLIoDg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/3Eg5vtqFLNc" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.isdpodcast.com/</feedburner:origLink></item>
    <item>
      <title>How I Got Pwned: Lessons in Ghetto Incident Response</title>
      <pubDate>Mon, 20 Feb 2012 09:45:59 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/a4zQcb642KM/i.php</link>
      <category>article</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/how-i-got-pwned-lessons-in-ghetto-incident-response"&gt;http://www.irongeek.com/i.php?page=security/how-i-got-pwned-lessons-in-ghetto-incident-response&lt;/a&gt;&lt;br/&gt;For those wondering about the details of my recent defacement.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0uKMEuJKZkgeVQs-oYWbWtJTbt4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0uKMEuJKZkgeVQs-oYWbWtJTbt4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0uKMEuJKZkgeVQs-oYWbWtJTbt4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0uKMEuJKZkgeVQs-oYWbWtJTbt4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/a4zQcb642KM" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/how-i-got-pwned-lessons-in-ghetto-incident-response</feedburner:origLink></item>
    <item>
      <title>ShmooCon Firetalks 2012 Videos</title>
      <pubDate>Sun, 5 Feb 2012 16:50:53 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/6DDRgGLLSwo/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2012"&gt;http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2012&lt;/a&gt;&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Night 1&lt;br/&gt;&amp;nbsp;“How Do You Know Your Colo Isn’t “Inside” Your Cabinet, A Simple Alarm Using Teensy” by David Zendzian&lt;br/&gt;&amp;nbsp;“Bending SAP Over &amp;amp; Extracting What You Need!” by Chris John Riley&lt;br/&gt;&amp;nbsp;“ROUTERPWN: A Mobile Router Exploitation Framework” by Pedro Joaquin&lt;br/&gt;&amp;nbsp;“Security Is Like An Onion, That’s Why it Makes You Cry” by Michele Chubirka&lt;br/&gt;&amp;nbsp;“Five Ways We’re Killing Our Own Privacy” by Michael Schearer&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Night 2&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;“Cracking WiFi Protected Setup For Fun and Profit” by Craig Heffner&lt;br/&gt;&amp;nbsp;“Passive Aggressive Pwnage: Sniffing the Net for Fun &amp;amp; Profit” by John Sawyer&lt;br/&gt;&amp;nbsp;“Ressurecting Ettercap” by Eric Milam&lt;br/&gt;&amp;nbsp;“Security Onion: Network Security Monitoring in Minutes” by Doug Burks&lt;br/&gt;&amp;nbsp;“Remotely Exploiting the PHY Layer” by Travis Goodspeed
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bOk2wt7RI_p8-vTg2ij2eS2I35g/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/6DDRgGLLSwo" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2012</feedburner:origLink></item>
    <item>
      <title>ShmooCon Epilogue 2012 Talks</title>
      <pubDate>Sun, 5 Feb 2012 16:25:11 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/XUKGmkmO3Qk/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/shmoocon-epilogue-2012"&gt; http://www.irongeek.com/i.php?page=videos/shmoocon-epilogue-2012&lt;/a&gt;&lt;br/&gt;&amp;nbsp;Includes: &lt;br/&gt;&amp;nbsp;Resurrection of Ettercap: easy-creds, Lazarus &amp;amp; Assimilation&lt;br/&gt;&amp;nbsp;Eric Milam - (Brav0Hax) &amp;amp;&lt;br/&gt;&amp;nbsp;Emilio Escobar &lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Media Hype and Hacks that Never Happened&lt;br/&gt;&amp;nbsp;Space Rouge&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;More than one way to skin a cat: identifying multiple paths to compromise a target through the use of Attach Graph Analysis&lt;br/&gt;&amp;nbsp;Joe Klein &lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Proper Depth / Breadth testing for Vulnerability Analysis and fun with tailored risk reporting metrics.&lt;br/&gt;&amp;nbsp;Jason M Oliver &lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Extending Information Security Methodologies for Personal User in Protecting PII.&lt;br/&gt;&amp;nbsp;John Willis&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Stratfor Password Analysis&lt;br/&gt;&amp;nbsp;Chris Truncer&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Intro To Bro&lt;br/&gt;&amp;nbsp;Richard Bejtlich&lt;br/&gt;&amp;nbsp;&lt;br/&gt;&amp;nbsp;Javascript obfuscation&lt;br/&gt;&amp;nbsp;Brandon Dixon
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tPsTKRkFHH3Ki_zS6BjuCoUf4zk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/XUKGmkmO3Qk" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/shmoocon-epilogue-2012</feedburner:origLink></item>
    <item>
      <title>Unix File Permissions and Ownership (CHOWN, CHMOD, ETC) </title>
      <pubDate>Sat, 21 Jan 2012 12:39:01 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/-QCtx-_s7Xg/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/unix-file-permissions-and-ownership-chown-chmod-etc"&gt;http://www.irongeek.com/i.php?page=videos/unix-file-permissions-and-ownership-chown-chmod-etc&lt;/a&gt;&lt;br/&gt;I'm taking a security class were we had a lab on Unix/Linux file system permissions. I decided I might as well record it, and the steps taken, along with explanations as to what I was doing to set the permissions such as read, write, execute, SetUID, SetGID and the Stickybit. Kevin Benton created the lab, so I'd like to give him credit for inspiring me to do this video.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XO2T31Rz4VdYvKQjnExxbh9q-Jg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/-QCtx-_s7Xg" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/unix-file-permissions-and-ownership-chown-chmod-etc</feedburner:origLink></item>
    <item>
      <title>Basic Setup of Security-Onion: Snort, Snorby, Barnyard, PulledPork, Daemonlogger </title>
      <pubDate>Sun, 15 Jan 2012 22:23:18 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/ZERvRJhgL7Y/i.php</link>
      <category>video</category>
      <description>Link: &lt;a href="http://www.irongeek.com/i.php?page=videos/basic-setup-of-security-onion-snort-snorby-barnyard-pulledpork-daemonlogger"&gt;http://www.irongeek.com/i.php?page=videos/basic-setup-of-security-onion-snort-snorby-barnyard-pulledpork-daemonlogger&lt;/a&gt;&lt;br/&gt;Thanks to Doug Burks for making building a Network Security Monitoring Server much easier. I mentioned Snort, Snorby, Barnyard, PulledPork and Daemonlogger in the title, but there is a lot more on the distro than that. This is a nice way to get an IDS up and running featuring pretty frontends without going into dependency hell.
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/eT4xOyX37-tWEklG0nA7YOd9mVc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/ZERvRJhgL7Y" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/basic-setup-of-security-onion-snort-snorby-barnyard-pulledpork-daemonlogger</feedburner:origLink></item>
    <item>
      <title>Pen-Testing Web 2.0: Stealing HTML5 Storage &amp; Injecting JSON Jeremy Druin</title>
      <pubDate>Sat, 7 Jan 2012 11:02:02 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/wyImVh3lOTI/i.php</link>
      <category>video</category>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=videos/pen-testing-web-2-stealing-html5-storage-injecting-json-jeremy-druin"&gt;Pen-Testing Web 2.0: Stealing HTML5 Storage &amp;amp; Injecting JSON Jeremy Druin&lt;/a&gt;&lt;br/&gt;This is &lt;a href="https://twitter.com/#!/webpwnized"&gt;Jeremy's&lt;/a&gt; talk from a recent &lt;a href="http://www.issa-kentuckiana.org/"&gt;ISSA&lt;/a&gt; meeting. In it he covers what the title says, showing off stealing of HTML 5 storage, injecting JSON, using Burp Suite, &lt;a href="http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10"&gt;Muttillidae&lt;/a&gt; and some XSS attack fun. Sorry about the noise in the first bit, I had to set the camera up a ways off and it picked up my bag of chips better than it did Jeremy's talk. &lt;a href="https://twitter.com/#!/webpwnized"&gt;@webpwnized&lt;/a&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2_vFCg6sb5cHq4QmABQISAPDU1Y/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/wyImVh3lOTI" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=videos/pen-testing-web-2-stealing-html5-storage-injecting-json-jeremy-druin</feedburner:origLink></item>
    <item>
      <title>Video Posted and Code Updated for Homemade Hardware Keylogger</title>
      <pubDate>Mon, 2 Jan 2012 00:29:07 -0500</pubDate>
      <link>http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/bSxvHzxXKcc/i.php</link>
      <description>Link:&lt;a href="http://www.irongeek.com/i.php?page=security/homemade-hardware-keylogger-phukd"&gt;http://www.irongeek.com/i.php?page=security/homemade-hardware-keylogger-phukd&lt;/a&gt;&lt;br/&gt;My video from &lt;a href="http://www.neoisf.org/"&gt;NeoISF&lt;/a&gt; is now posted: &lt;a href="http://www.irongeek.com/i.php?page=videos/phukd-keylogger-hybrid"&gt;PHUKD/Keylogger Hybrid&lt;/a&gt;. 
&lt;p&gt;The code has been updated in the following ways:&lt;/p&gt;
&lt;p&gt;On the PIC side: Updated Firmware for the USB Host Module - PIC24FJ256GB106 to work with more keyboards.&lt;/p&gt;
&lt;p&gt;On the Teensy side:&lt;/p&gt;
&lt;p&gt;0.04:&lt;br/&gt;* If a keyboard was plugged in after the keylogger was already powered on, it would type "i7-". I added code&lt;br/&gt;to fix this problem.&lt;br/&gt;* Fixed RAW serial debug mode not to print key&lt;br/&gt;* Changed name of variable "lasttenletters" to "lastfewletters" and expanded it to 60.&lt;br/&gt;* Ctrl+Alt+Y is now used for typing more debugging details.&lt;br/&gt;* Implemented likely to fail code for unlocking workstation using captured password.&lt;br/&gt;* I had some problems with running out of SRAM because of all of my static strings. I started using the F() &lt;br/&gt;function to pull these strings from flash memory to solve this issue.&lt;br/&gt;* Fixed a case issue with lastfewletters. I did not know the method changed it in place.&lt;br/&gt;* Fixed a bug in HIDtoASCII that made it top row of number keys not work right.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DyUn8iHkqOhT6d76fSFRgT7iVhM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/bSxvHzxXKcc" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://www.irongeek.com/i.php?page=security/homemade-hardware-keylogger-phukd</feedburner:origLink></item>
  </channel>
</rss>

