<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.92">
<channel>
     <title>Penetration Testing at insecure.org</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/date.html</link>
     <description>Latest posts to pen-test with detailed descriptions</description>
     <managingEditor>fyodor@NOSPAMinsecure.org (fyodor)</managingEditor>
     <webMaster>djeaux@NOSPAMdjeaux.com (djeaux)</webMaster>
     <generator>Scythe 2.10</generator>
     <lastBuildDate>Thu, 24 Jul 2008 01:50:03 PDT</lastBuildDate>
     <image>
          <url>http://www.djeaux.com/images/scraped_88x31.png</url>
          <title>pen-test at insecure.org</title>
          <link>http://www.seclists.org/lists/pen-test/2008/Jul</link>
          <description>Penetration Testing scraped from insecure.org</description>
     </image>
     <language>en-us</language>

<item>
     <title>Re: How do VA scans work technically</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0104.html</link>
     <author>zqyves.spamtrap@NOSPAMgmail.com (Zed Qyves)</author>
     <pubDate>Sat, 19 Jul 2008 14:33:52 +0300</pubDate>
     <description>hello, Last time i checked nmap -sV was doing what ask as well as amap (or vmap - i have a bad memory ). Best regards, Z On 7&#47;9&#47;08, Aseem Kumar &lt;kumaraseematgmail&#46;com&gt; wrote: &gt; Hi, &gt; &gt; Thanks for all the gr8 replies. &gt; ...</description>
</item>
 
<item>
     <title>VoIP Attacks</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0103.html</link>
     <author>contebral@NOSPAMweb.de (contebral_at_web.de)</author>
     <pubDate>Fri, 18 Jul 2008 23:49:23 +0200</pubDate>
     <description>Hello Folks, Classical Attacks vectors against VoIP like SPIT (VOIP SPAM) and VoIP Phishing are well known and documented. i'm curious if there exists other client side attacks against voip that may compromise confidential calls e.g. Telephon Banking or similar applications. THX ...</description>
</item>
 
<item>
     <title>How to get the list of domain admins</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0102.html</link>
     <author>shankar.arjunan@NOSPAMgmail.com (Shankar Arjunan)</author>
     <pubDate>Fri, 18 Jul 2008 15:22:47 +1000</pubDate>
     <description>Hi all, Can anyone tell me how to get list of users who are having domain admin rights in a domain. I vaguely remember using it through command line utility net use or net localgroup .. Thanks in advance Shankar This list is sponsored by: Cenzic ...</description>
</item>
 
<item>
     <title>Moderator Vacation and pen-test list submissions</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0101.html</link>
     <author>amoeba@NOSPAMamoebazone.com (Erin Carroll)</author>
     <pubDate>Thu, 17 Jul 2008 16:57:29 -0700</pubDate>
     <description>All, Pete Herzog's recent email about security vacations reminds me... I will be on vacation from 7&#47;18 - 7&#47;27. While I will occasionally check email for submissions, please be aware that response time may be slow and ...</description>
</item>
 
<item>
     <title>Security Vacation Guide</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0100.html</link>
     <author>lists@NOSPAMisecom.org (Pete Herzog)</author>
     <pubDate>Thu, 17 Jul 2008 23:37:12 +0200</pubDate>
     <description>Hi, We're feeling summer pretty hard here at ISECOM and thought summer&#47;hacking&#47;vacation - so we put it all together. So we made a security vacation guide! Based on all that stuff we hackers loop about when we worry about our stuff! So ISECOM presents: the Home Security Methodology ...</description>
</item>
 
<item>
     <title>OSSTMM 3.0 LITE</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0099.html</link>
     <author>lists@NOSPAMisecom.org (Pete Herzog)</author>
     <pubDate>Thu, 17 Jul 2008 19:04:49 +0200</pubDate>
     <description>Hi, We have created OSSTMM 3.0 LITE for the DefCon attendees. It is a smaller, simpler version of the OSSTMM 3.0 but does include the Data Networking tests as well as instructions on how to use it. We will release it ...</description>
</item>
 
<item>
     <title>Re: Wired captive portal pen-test</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0098.html</link>
     <author>mspinthiras@NOSPAMgmail.com (Mario Spinthiras)</author>
     <pubDate>Thu, 17 Jul 2008 10:08:29 +0300</pubDate>
     <description>I am not sure what kind of captive portal it was. I know for sure that if the administrator limited the dns traffic or performed DPI (cleverly) they could avoid NSTX bypasses. NSTX relies on dns queries ...</description>
</item>
 
<item>
     <title>Re: Wired captive portal pen-test</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0097.html</link>
     <author>blancher@NOSPAMcartel-securite.fr (Cedric Blancher)</author>
     <pubDate>Thu, 17 Jul 2008 07:40:36 +0200</pubDate>
     <description>And what about trying to break the web application ? Tons of captive portals fails at web application level, with very simple tricks such as altering parameters on the fly... -- PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE &gt;&gt; Hi! I'm your friendly neighbourhood signature virus. ...</description>
</item>
 
<item>
     <title>Re: Auditing a Firewall rulebase</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0096.html</link>
     <author>meenal.mukadam@NOSPAMgmail.com (Meenal Mukadam)</author>
     <pubDate>Thu, 17 Jul 2008 10:53:56 +0530</pubDate>
     <description>Hello Edgar, Our tool Firesec () has a feature specifically to convert Cisco PIX configurations to Netscreen. It does this for Cisco ACLs and Objects, and using the Zone Names that you inform us, but we could also tweak it to work with conduit statements. Email ...</description>
</item>
 
<item>
     <title>ekoparty security trainings (2008) announcement</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0095.html</link>
     <author>no-reply@NOSPAMekoparty.com.ar (ekoparty)</author>
     <pubDate>Thu, 17 Jul 2008 01:28:22 -0300</pubDate>
     <description>ekoparty 4th edition - www.ekoparty.com.ar Information Security&#47;Insecurity Conference. October 2 and 3, 2008 Ciudad Autonoma de Buenos Aires - Argentina What is ekoparty? It's a one of a kind event in South America; an annual security conference held in Buenos Aires ...</description>
</item>
 
<item>
     <title>RE: Wired captive portal pen-test</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0094.html</link>
     <author>sergio.castro@NOSPAMunicin.net (Sergio Castro)</author>
     <pubDate>Wed, 16 Jul 2008 19:23:44 -0500</pubDate>
     <description>What I mean is that if he's not seeing ARP requests, it means there's a switch-router there, and not a hub. As to MITM, if the switch-router is FULLY secured, it is correct, you cannot launch such attack. But if it has a standard, medium security configuration, ...</description>
</item>
 
<item>
     <title>Re: Wired captive portal pen-test</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0093.html</link>
     <author>roman@NOSPAMrs-labs.com (Roman Medina-Heigl Hernandez)</author>
     <pubDate>Thu, 17 Jul 2008 00:44:06 +0200</pubDate>
     <description>José M. Palazón Romero escribió: &gt; Anyway, I still think they are probably not filtering at layer 2. They are (I think). I had a look to some public computer at the hotel and I saw its IP. It was in the same subnet used by room's port. Nevertheless, ...</description>
</item>
 
<item>
     <title>Re: Wired captive portal pen-test</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0092.html</link>
     <author>roman@NOSPAMrs-labs.com (Roman Medina-Heigl Hernandez)</author>
     <pubDate>Thu, 17 Jul 2008 00:32:59 +0200</pubDate>
     <description>Mario Spinthiras escribió: &gt; I managed to successfully beat captive portal with NSTX. As far as Which kind&#47;&quot;brand&quot; of captive portal? As I previously said, NSTX or similar can be defeated. &gt; vlans are concerned , by default catalysts have auto for trunk modes. ...</description>
</item>
 
<item>
     <title>Re: Wired captive portal pen-test</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0091.html</link>
     <author>josem.palazon@NOSPAMgmail.com (José M. Palazón Romero)</author>
     <pubDate>Wed, 16 Jul 2008 09:28:19 +0100</pubDate>
     <description>Sergio Castro escribió: &gt; So yes, if you only see broadcast ARP requests from the router, the switch &gt; is very likely securely configured. This is incorrect, Sergio. ARP replies are not broadcast, so it's perfectly ok that he doesn't see them. &gt; ...</description>
</item>
 
<item>
     <title>Re: Auditing a Firewall rulebase</title>
     <link>http://www.seclists.org/lists/pen-test/2008/Jul/0090.html</link>
     <author>econtreras@NOSPAMfibertel.com.ar (econtreras_at_fibertel.com.ar)</author>
     <pubDate>Wed, 16 Jul 2008 14:58:44 -0300</pubDate>
     <description>hi all..somebody known about a tools o parser for old version of pix software, I need something to see a lots of conduit...or something to translate configuration from pix to netscreen firewall... thank.. Edgar Carlos Alberto Contreras Mensaje original De: arvind doraiswamy &lt;arvind.doraiswamyatgmail&#46;com&gt; ...</description>
</item>
 
</channel>
</rss>
