<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="0.92">
<channel>
	<title>Security Aegis</title>
	<link>http://www.securityaegis.com</link>
	<description>Life, Liberty, and the pursuit of root...</description>
	<lastBuildDate>Mon, 23 Aug 2010 03:23:51 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0.1" -->

	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/xml" href="http://feeds.feedburner.com/securityaegis/igXu" /><feedburner:info uri="securityaegis/igxu" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Hacking with your Browser</title>
		<description>Today I rebuilt my Windows 7 partition. Amidst flurry of backing up I forgot to save my Firefox profiles. I figured this was a good time to review what I use addons-wise for all my day to day hacking needs. First things first, most of these addons will have compatibility issues. To update a Firefox [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/lYvhiv_-zYM" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/lYvhiv_-zYM/</link>
			<feedburner:origLink>http://www.securityaegis.com/hacking-with-your-browser/</feedburner:origLink></item>
	<item>
		<title>Blackhat and Defcon Parties</title>
		<description>Every year we head to the desert to learn the newest attack/defenses in the world, to share groundbreaking ideas&amp;#8230; but not least of all, to have some fun! &amp;#160;&amp;#160; &amp;#160;&amp;#160; Who? When? (July) Time Where? Link/RSVP Why? ModSecurity Happy Hour Wednesday 28th 4-6pm munchbar @ Caesar&amp;#39;s Palace open to anyone modsecurity is awesome MAD &amp;#38; [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/K_24RuMqyxg" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/K_24RuMqyxg/</link>
			<feedburner:origLink>http://www.securityaegis.com/blackhat-and-defcon-parties/</feedburner:origLink></item>
	<item>
		<title>smpCTF – 2010 Hacker Olympics</title>
		<description>I just finished playing in the yearly smpCTF with team MRL. MRL is Midnight Research Labs based out of Boston, who do some really cool research/presentations/tools. You might remember them from their release of SEAT (Search Engine Assessment (Tool) a year or so back.&amp;#160; smpCTF is a yearly top tier CTF, akin to the Defcon [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/1C_8gXrqdnE" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/1C_8gXrqdnE/</link>
			<feedburner:origLink>http://www.securityaegis.com/smpctf-2010-hacker-olympics/</feedburner:origLink></item>
	<item>
		<title>OSINT, because knowing is half the battle…</title>
		<description>Profiling, or OSINT (open source intelligence), is an art. Private investigators have been doing it for years now but, it has just started to show real promise in application to Penetration Testing and Red Team Testing.&amp;#160; A lot of work has been done recently by&amp;#160; Chris Gates and Chris Nickerson on bringing it into the [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/koc0rh1bnk8" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/koc0rh1bnk8/</link>
			<feedburner:origLink>http://www.securityaegis.com/osint-because-knowing-is-half-the-battle/</feedburner:origLink></item>
	<item>
		<title>Interview: Hakin9, Ferruh Mavituna on Web Security</title>
		<description>A new interview with Ferruh focusing less on Netsparker and more on web security in general. Published in Hakin9 Magazine, Pages 56-58 =) Download the issue! http://download.hakin9.org/en/hakin9_04_2010_EN.pdf Also, Since it was con-time near deadline-time, Ferruh might expand a bit here on some of the questions he didn&amp;#39;t get to cover, so stay tuned.&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/x33GlQHOwgA" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/x33GlQHOwgA/</link>
			<feedburner:origLink>http://www.securityaegis.com/interview-hakin9-ferruh-mavituna-on-web-security/</feedburner:origLink></item>
	<item>
		<title>Review: eLearnSecurity’s Penetration Testing Pro</title>
		<description>My original review appeared over at http://www.ethicalhacker.net/content/view/307/24/ &amp;#160; &amp;#160; &amp;#160; eLearnSecurity&amp;#8217;s Penetration Testing Pro -&amp;#160;What&amp;#160;CEH Should Have Been &amp;#160; Recently the web has been abuzz with pentest training options. The CEH received new life as it was added to&amp;#160; DoD Directive 8570 as well as revamped its courseware in version 6.0, Offensive Security rolled out [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/5QcYd33Ypnc" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/5QcYd33Ypnc/</link>
			<feedburner:origLink>http://www.securityaegis.com/review-elearnsecuritys-penetration-testing-pro/</feedburner:origLink></item>
	<item>
		<title>Netsparker Community Edition – “The Sparkler”</title>
		<description>Believe me when i say that we&amp;#8217;ve used a lot of tools. We love scripts, we love things that free up our time to do the real analysis on a web application assessment. We have used w3af, nikto, Grendel Scan, etc, etc&amp;#8230; We are really happy to see a new tool we have used in [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/w8QCs4FwBBw" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/w8QCs4FwBBw/</link>
			<feedburner:origLink>http://www.securityaegis.com/netsparker-community-edition-%e2%80%93-%e2%80%9cthe-sparkler%e2%80%9d/</feedburner:origLink></item>
	<item>
		<title>Finding Social Security Numbers in packet captures with grep and ngrep</title>
		<description>From @ap3r on the Redspin Labs Blog by Nathan Drier on Apr.16, 2010: I&amp;#8217;ve been spending a lot of time lately working with packet captures. &amp;#160;I&amp;#8217;ve been stringing together a long list of silly one-liners to make a very rough pcap vulnerability scanner of sorts. &amp;#160;This is one of those one-liners. One of the main [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/f1zvYy87fjo" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/f1zvYy87fjo/</link>
			<feedburner:origLink>http://www.securityaegis.com/finding-social-security-numbers-in-packet-captures-with-grep-and-ngrep/</feedburner:origLink></item>
	<item>
		<title>Release: Burp Proxy to XML – BURP2XML</title>
		<description>With the incorporation of Burp Suite Professional into our audit processes, we (the redspin engineers) discovered that there was not an easy method to extract results from Burp&amp;#8217;s session file without having to manually re-run Burp. In order to automate this process, we have developed a standalone Python script to process Burp&amp;#8217;s session files into [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/Lv0KM2953CI" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/Lv0KM2953CI/</link>
			<feedburner:origLink>http://www.securityaegis.com/release-burp-proxy-to-xml-burp2xml/</feedburner:origLink></item>
	<item>
		<title>Skipfish, Google Enters the Web Scanner Fray</title>
		<description>Just wrote a quick review and jotted down some insights to Google&amp;#39;s new web application security scanner. Skipfish. Read the whole thing at the link or just check out the &amp;#34;skinny&amp;#34;&amp;#160; The Skinny: We like it. As Google says, its not an end-all-be-all for web application scanners, but it definitely has some great logic, features, [...]&lt;img src="http://feeds.feedburner.com/~r/securityaegis/igXu/~4/_M1hxck4vOM" height="1" width="1"/&gt;</description>
		<link>http://feedproxy.google.com/~r/securityaegis/igXu/~3/_M1hxck4vOM/</link>
			<feedburner:origLink>http://www.securityaegis.com/skipfish-google-enters-the-web-scanner-fray/</feedburner:origLink></item>
</channel>
</rss>
