<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Cатсн²² (in)sесuяitу</title>
	<atom:link href="http://blog.c22.cc/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.c22.cc</link>
	<description>Because we&#039;re damned if we do, and we&#039;re damned if we don&#039;t!</description>
	<lastBuildDate>Tue, 31 Aug 2010 15:42:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.c22.cc' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/1b6c05a022094e3a7342e6b645c9cfce?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Cатсн²² (in)sесuяitу</title>
		<link>http://blog.c22.cc</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.c22.cc/osd.xml" title="Cатсн²² (in)sесuяitу" />
	<atom:link rel='hub' href='http://blog.c22.cc/?pushpress=hub'/>
		<item>
		<title>3 Years in the making&#8230;</title>
		<link>http://blog.c22.cc/2010/08/31/3-years-in-the-making/</link>
		<comments>http://blog.c22.cc/2010/08/31/3-years-in-the-making/#comments</comments>
		<pubDate>Tue, 31 Aug 2010 13:50:09 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[General Life]]></category>
		<category><![CDATA[anniversary]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[stats]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1916</guid>
		<description><![CDATA[Back on the 21st August 2007 I was sitting at home in Austria writing my first ever blog post. It wasn&#8217;t well thought out (I&#8217;m sure most things I write aren&#8217;t), but it signified a big turning point that has &#8230; <a href="http://blog.c22.cc/2010/08/31/3-years-in-the-making/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1916&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Back on the 21st August 2007 I was sitting at home in Austria writing my<a title="First..." href="http://wp.me/p6I7X-5" target="_blank"> first</a> ever blog post. It wasn&#8217;t well thought out (<em>I&#8217;m sure most things I write aren&#8217;t</em>), but it signified a big turning point that has changed my life in so many different ways.</p>
<p>So many things happened 3 years ago, most of which readers to this blog won&#8217;t really be interested in. I quit my job as a SysAdmin in Germany. I moved to Austria. I started to <span style="text-decoration:underline;">REALLY</span> learn German (finally)&#8230;. oh, and I went to India for 6 weeks.</p>
<p>The one thing I really remember from that time though, was getting back into things that I&#8217;d long forgotten. I spent a lot of time as a kid programming from books (<em>just copying BASIC code from magazines and playing with it mostly</em>). I also spent a lot of time early on in my career really playing with technology, seeing what it could do and how to make things do other more interesting things. Somewhere along the road though, I lost that drive and started to just accept things as they were. I guess using Microsoft technology for too long will force that realization on you. Wow, how depressing&#8230;</p>
<p><a href="http://www.flickr.com/photos/c22/4791432314/in/photostream/"><img class="alignright size-medium wp-image-1919" style="margin:5px;" title="4791432314_659db13195" src="http://c22blog.files.wordpress.com/2010/08/4791432314_659db13195.jpg?w=199&#038;h=300" alt="" width="199" height="300" /></a>So what really turned me around and made me love technology again. I attended my first Hacker con&#8230;. and yes, it was a REAL hacker con, and not a security conference. I spent a glorious week in a field near Berlin at the Chaos Computer Camp. It was without a doubt the best thing I&#8217;ve ever done. Scary as hell&#8230; very little German language skill, no friends in the &#8220;community&#8221;, and no idea where I was going to sleep even (<em>that was sorted by the every friendly Nick &#8220;Hackers on a Plane&#8221; Farr however&#8230;. and for that I&#8217;m forever thankful</em>). Even though I came back thinking negative about everything (<em>I realized how little I really knew</em>), I picked myself back up and started on this journey into security.</p>
<p>A little more than 3 years and 267 blog posts on (<em>3 or 4 of which might actually be categorized as &#8220;reasonable&#8221;</em>), and I still feel like I don&#8217;t know anything&#8230; but at least I know <span style="text-decoration:underline;">why</span> now. There&#8217;s just too much for 1 person to learn. Security is just such a big field, that you need to pick and choose your targets. Yeah, I&#8217;m still not good at that, as can be seen at how much the blog contents twists and turns between topics depending on my mood and interest at the time. Still, people seem to like it. At least the blog stats for the last few years are encouraging.</p>
<p style="text-align:left;"><a href="http://c22blog.files.wordpress.com/2010/08/stats.png"><img class="size-medium wp-image-1918 aligncenter" style="margin-top:5px;margin-bottom:5px;" title="stats" src="http://c22blog.files.wordpress.com/2010/08/stats.png?w=300&#038;h=130" alt="" width="300" height="130" /></a></p>
<p style="text-align:left;">It still mystifies me somewhat that people come here to read things I write. I&#8217;m not the most experienced writer, and sometimes I look back on things I&#8217;ve written and feel an overwhelming urge to just click the &#8220;Move to Trash&#8221; icon. Still, things can only get better&#8230; after all, the way I write, they couldn&#8217;t get much worse could they <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p style="text-align:left;">So what was this post all about? Well, nothing really. I just didn&#8217;t want to let another anniversary slip past without telling that story&#8230; oh and next year is the return of the Chaos Computer Camp (<em>it runs on a 4 year cycle</em>). Lets hope I come back feeling more positive this time eh <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="text-align:left;">So here&#8217;s to another 3 years. Lets hope I can keep up the pace&#8230;</p>
<br />Filed under: <a href='http://blog.c22.cc/category/general-life/'>General Life</a> Tagged: <a href='http://blog.c22.cc/tag/anniversary/'>anniversary</a>, <a href='http://blog.c22.cc/tag/blog/'>blog</a>, <a href='http://blog.c22.cc/tag/projects/'>projects</a>, <a href='http://blog.c22.cc/tag/stats/'>stats</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1916/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1916/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1916/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1916/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1916/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1916/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1916/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1916/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1916/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1916/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1916/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1916/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1916/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1916/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1916&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/31/3-years-in-the-making/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/4791432314_659db13195.jpg?w=199" medium="image">
			<media:title type="html">4791432314_659db13195</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/stats.png?w=300" medium="image">
			<media:title type="html">stats</media:title>
		</media:content>
	</item>
		<item>
		<title>HTTP Strict Transport Security</title>
		<link>http://blog.c22.cc/2010/08/27/http-strict-transport-security/</link>
		<comments>http://blog.c22.cc/2010/08/27/http-strict-transport-security/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 22:50:03 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[HSTS]]></category>
		<category><![CDATA[Strict Transport Security]]></category>
		<category><![CDATA[HTTPS]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1905</guid>
		<description><![CDATA[If you&#8217;re a sad geek like me you&#8217;ve probably already heard of HSTS (HTTP Strict Transport Security). HSTS is designed to solve an issue where you access a web server using HTTP and are automatically redirected to the HTTPS equivalent (usually &#8230; <a href="http://blog.c22.cc/2010/08/27/http-strict-transport-security/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1905&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-medium wp-image-1911" style="margin:5px;" title="Screen shot 2010-08-28 at 12.47.51 AM" src="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-28-at-12-47-51-am.png?w=166&#038;h=240" alt="" width="166" height="240" />If you&#8217;re a sad geek like me you&#8217;ve probably already heard of HSTS (<em>HTTP Strict Transport Security</em>). HSTS is designed to solve an issue where you access a web server using HTTP and are automatically redirected to the HTTPS equivalent (<em>usually through a 301 or 302 response and a new location header</em>).</p>
<p>To most this seems like a perfectly acceptable solution, until you start thinking about the Man in the Middle issues of this kind of redirection. Most users don&#8217;t type http<span style="color:#ff0000;"><span style="text-decoration:underline;"><span style="color:#ff0000;">s</span></span></span>://mybank.com after all. They just type mybank.com and expect the browser and server to sort it out themselves&#8230;. and to be honest, they should. Users shouldn&#8217;t need to understand security to <span style="text-decoration:underline;">BE</span> secure. It&#8217;s something that the server architects, web designers, and programmers of the world need to get together to solve.</p>
<p>So, the first step in securing this hole is finally beginning to be implemented. HSTS is still a way off yet (<em>it&#8217;s just been implemented into the Firefox 4 nightly builds, and appears to be supported in Chromium</em>), but it&#8217;s already looking promising.</p>
<p>HTTP Strict Transport Security works by allowing servers to return an additional header along with their 301 or 302 redirection. This Strict-Transport-Security: header allows the server to set a max-age (<em>and optionally an includeSubDomains parameter</em>) which is read by a compatible browser (<em>currently limited</em>).</p>
<div id="attachment_1906" class="wp-caption aligncenter" style="width: 310px"><a href="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-27-at-11-34-46-pm.png"><img class="size-medium wp-image-1906" title="Screen shot 2010-08-27 at 11.34.46 PM" src="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-27-at-11-34-46-pm.png?w=300&#038;h=179" alt="" width="300" height="179" /></a><p class="wp-caption-text">Strict-Transport-Security Header</p></div>
<p>The browser will then remember the setting and next time it&#8217;s asked to connect to the server (<em>even if it&#8217;s entered as an http:// address</em>) the browser will request the http<span style="text-decoration:underline;"><span style="color:#ff0000;">s</span></span>:// version.</p>
<div id="attachment_1907" class="wp-caption aligncenter" style="width: 310px"><a href="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-27-at-11-36-15-pm.png"><img class="size-medium wp-image-1907" title="Screen shot 2010-08-27 at 11.36.15 PM" src="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-27-at-11-36-15-pm.png?w=300&#038;h=148" alt="" width="300" height="148" /></a><p class="wp-caption-text">Type http:// get https://</p></div>
<p>A couple of issues:</p>
<ul>
<li>An initial HTTP request still needs to be made (<em>opening for </em><em>MitM</em>)</li>
<li>Sub-domains need to be included to ensure everything is secured (<em>addition of the includeSubDomains parameter</em>)</li>
<li>How is Private browsing (<em>i.e porn mode</em>) handled? I see 2 possibilities here:
<ul>
<li>HSTS info is deleted along with everything else (<em>reduced security</em>)</li>
<li>HSTS info is retained (<em>secure, but breaks privacy</em>)</li>
</ul>
</li>
</ul>
<p>I&#8217;m looking forward to HSTS being implemented across a broader range of browsers, although this is going to take a long time (<em>IE6 has only just started to die after all</em>). Still, anything we can do to solve part of the problem is worthwhile doing.</p>
<p><strong>UPDATE</strong>: I looked briefly into the private browsing situation (<em>at least with Firefox 4 nightly</em>) and as I thought, it forgets the HSTS settings. Preferring privacy and protection of your visited sites over the security offered by HSTS. I guess this makes sense&#8230; Still, it renders HSTS mute for many of us who run in private browsing mode all the time (<em>for privacy reasons!</em>). I&#8217;d like to see an option to retain these. Maybe in the next nightly?</p>
<p><strong>Links</strong>:</p>
<ul>
<li>Firefox 4: HTTP Strict Transport Security (force HTTPS) &#8211;&gt; <a href="http://hacks.mozilla.org/2010/08/firefox-4-http-strict-transport-security-force-https" target="_blank">LINK</a></li>
<li>Firefox nightly builds (<em>with HSTS support</em>) &#8211;&gt; <a href="http://nightly.mozilla.org/" target="_blank">LINK</a></li>
<li>HSTS Draft &#8211;&gt; <a href="http://tools.ietf.org/html/draft-hodges-strict-transport-sec-02" target="_blank">LINK</a></li>
<li>Chromium Strict Transport Security &#8211;&gt; <a href="http://www.chromium.org/sts" target="_blank">LINK</a></li>
</ul>
<p><strong>Test Sites</strong> (<em>sites supporting HSTS</em>):</p>
<ul>
<li>www.paypal.com</li>
<li>www.ssllabs.com</li>
<li>www.defcon.org</li>
<li>www.elanex.biz</li>
<li>jottit.com</li>
<li>sunshinepress.org</li>
<li>www.noisebridge.net</li>
</ul>
<br />Filed under: <a href='http://blog.c22.cc/category/security/'>Security</a>, <a href='http://blog.c22.cc/category/technology/'>Technology</a> Tagged: <a href='http://blog.c22.cc/tag/firefox/'>firefox</a>, <a href='http://blog.c22.cc/tag/hsts/'>HSTS</a>, <a href='http://blog.c22.cc/tag/https/'>HTTPS</a>, <a href='http://blog.c22.cc/tag/ssl/'>SSL</a>, <a href='http://blog.c22.cc/tag/strict-transport-security/'>Strict Transport Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1905/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1905/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1905/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1905/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1905/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1905/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1905/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1905/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1905/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1905/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1905/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1905/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1905/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1905/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1905&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/27/http-strict-transport-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-28-at-12-47-51-am.png?w=208" medium="image">
			<media:title type="html">Screen shot 2010-08-28 at 12.47.51 AM</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-27-at-11-34-46-pm.png?w=300" medium="image">
			<media:title type="html">Screen shot 2010-08-27 at 11.34.46 PM</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/screen-shot-2010-08-27-at-11-36-15-pm.png?w=300" medium="image">
			<media:title type="html">Screen shot 2010-08-27 at 11.36.15 PM</media:title>
		</media:content>
	</item>
		<item>
		<title>Deutsche Post &#124; Security Cup</title>
		<link>http://blog.c22.cc/2010/08/27/deutsche-post-security-cup/</link>
		<comments>http://blog.c22.cc/2010/08/27/deutsche-post-security-cup/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 10:45:28 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Penetration Test]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[deutsche post]]></category>
		<category><![CDATA[security cup]]></category>
		<category><![CDATA[bugs]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1896</guid>
		<description><![CDATA[A friend of mine (thanks Wim) posted this on Twitter. Normally if Deutsche Post  announce the release of a new service, it&#8217;s nothing to write home about. Certainly when it comes to security. However Deutsche Post have come up with &#8230; <a href="http://blog.c22.cc/2010/08/27/deutsche-post-security-cup/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1896&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.deutschepost.de"><img class="alignright size-full wp-image-1897" style="margin:5px;" title="logo_deutschepost" src="http://c22blog.files.wordpress.com/2010/08/logo_deutschepost.gif?w=153&#038;h=34" alt="" width="153" height="34" /></a>A friend of mine (<em>thanks <a title="Deutsche Post &gt; Security Cup" href="http://www.deutschepost.de/dpag?tab=1&amp;skin=hi&amp;check=yes&amp;lang=de_EN&amp;xmlFile=link1022792_1022790" target="_blank">Wim</a></em>) posted this on Twitter. Normally if Deutsche Post  announce the release of a new service, it&#8217;s nothing to write home about. Certainly when it comes to security. However Deutsche Post have come up with an interesting competition in the build-up to the release of their E-Postbrief service.</p>
<p>Working with some well-respected members of the Security Community, they&#8217;ve come up with the Security Cup, and are offering some nice prizes for people/teams who find vulnerabilities in their web application or infrastructure.</p>
<p>As you can imagine the scope is limited, no client-side attacks for example, but with the prizes on offer (<em>Major bugs are awarded with EUR 5,000,  normal bugs are awarded with EUR 1,000</em>) it looks like it&#8217;ll draw a crowd.</p>
<p><a href="http://www.deutschepost.de/dpag?tab=1&amp;skin=hi&amp;check=yes&amp;lang=de_EN&amp;xmlFile=link1022792_1022790"><img class="alignleft size-full wp-image-1903" title="stoerer_application_185_blk" src="http://c22blog.files.wordpress.com/2010/08/stoerer_application_185_blk.png?w=171&#038;h=72" alt="" width="171" height="72" /></a>If you want to find out more information, head over to the <a title="Deutsche Post &gt; Security Cup" href="http://www.deutschepost.de/dpag?tab=1&amp;skin=hi&amp;check=yes&amp;lang=de_EN&amp;xmlFile=link1022792_1022790" target="_blank">Deutsche post Security Cup</a> web-page and sign-up (<em>via email</em>). The sign-up phase runs through September, so there&#8217;s plenty of time!</p>
<br />Filed under: <a href='http://blog.c22.cc/category/penetration-test/'>Penetration Test</a>, <a href='http://blog.c22.cc/category/security/'>Security</a> Tagged: <a href='http://blog.c22.cc/tag/bugs/'>bugs</a>, <a href='http://blog.c22.cc/tag/deutsche-post/'>deutsche post</a>, <a href='http://blog.c22.cc/tag/hacking/'>hacking</a>, <a href='http://blog.c22.cc/tag/penetration-testing/'>penetration testing</a>, <a href='http://blog.c22.cc/tag/security-cup/'>security cup</a>, <a href='http://blog.c22.cc/tag/testing/'>testing</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1896/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1896/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1896/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1896&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/27/deutsche-post-security-cup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/logo_deutschepost.gif" medium="image">
			<media:title type="html">logo_deutschepost</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/stoerer_application_185_blk.png" medium="image">
			<media:title type="html">stoerer_application_185_blk</media:title>
		</media:content>
	</item>
		<item>
		<title>Eurotrash’s 1st Birthday</title>
		<link>http://blog.c22.cc/2010/08/25/eurotrashs-1st-birthday/</link>
		<comments>http://blog.c22.cc/2010/08/25/eurotrashs-1st-birthday/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 08:57:17 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[anniversary]]></category>
		<category><![CDATA[brucon]]></category>
		<category><![CDATA[eurotrash]]></category>
		<category><![CDATA[podcast]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1891</guid>
		<description><![CDATA[Well who would thunk it&#8230;almost a year after the creation of Eurotrash and we&#8217;re still going strong! It&#8217;s been a wild and interesting ride, filled with great guests and good discussions. Not to mention the funny accents! Almost a year &#8230; <a href="http://blog.c22.cc/2010/08/25/eurotrashs-1st-birthday/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1891&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well who would thunk it&#8230;almost a year after the creation of Eurotrash and we&#8217;re still going strong! It&#8217;s been a wild and interesting ride, filled with great guests and good discussions. Not to mention the funny accents!</p>
<p style="text-align:center;"><a href="http://www.eurotrashsecurity.eu"><img class="aligncenter" src="http://www.eurotrashsecurity.eu/images/eurotrash.jpg" alt="" width="368" height="88" /></a></p>
<p>Almost a year ago, I sat down at <a href="http://brucon.org" target="_blank">BruCON</a> with Dale, Craig and Wim to talk about maybe possibly starting a European podcast. As with many things it started off as an innocnet comment on twitter, which soon snowballed into an idea, and from there into a real podcast.</p>
<p>Listening back to the first episodes it&#8217;s easy to see we weren&#8217;t seasoned professionals. The ummms and errrrs have hopefully lessened a bit over time, but we&#8217;re still working to make things better behind the scenes. I always love looking back at things I&#8217;ve written, coded, or said in years past. It reminds me that even though you think you&#8217;re standing stillm you&#8217;re really not. Things can only get better from here&#8230; face it, they couldn&#8217;t get much worse <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>We&#8217;ve had so many great guests on the podcast in the last year it&#8217;s hard to remember them all. I&#8217;d like to thank everybody that&#8217;s been on the podcast as a guest, but most of all I&#8217;d like to thank <a href="https://twitter.com/wimremes" target="_blank">Wim</a>, <a href="https://twitter.com/craigbalding" target="_blank">Craig</a>, and <a href="https://twitter.com/daleapearson" target="_blank">Dale</a> for taking this unmolded idea and really making it into something we can be proud of. I&#8217;d also like to thank <a href="http://blog.rootshell.be/" target="_blank">Xavier</a> for being so generous with his time (sorting the website, hosting and being there when we needed him) and <a href="http://www.dualcoremusic.com" target="_blank">DualCore</a>&#8230;. for just being excellent, and giving us a song when nobody had even heard of us.</p>
<p>If you&#8217;ve not had the joy of hearing us head over to <a href="http://itunes.apple.com/at/podcast/eurotrash-security-podcast/id343212779" target="_blank">iTunes</a> or take a look at the Eurotrash <a href="http://www.eurotrashsecurity.eu/episodes/eurotrash.xml" target="_blank">RSS feed</a>. I&#8217;m promise you, it&#8217;ll at least be entertaining, if not informative <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Rumours are already spreading of the plans for this years BruCON <a href="http://www.eurotrashsecurity.eu/index.php/Brucon_meetup" target="_blank">podcasters meetup</a>. All I can say, is if Wim gets his way, it&#8217;s going to be an event to be remembered!</p>
<p>Here&#8217;s to another year of Eurotrash&#8230; may the trash be with you!</p>
<br />Filed under: <a href='http://blog.c22.cc/category/security/'>Security</a> Tagged: <a href='http://blog.c22.cc/tag/anniversary/'>anniversary</a>, <a href='http://blog.c22.cc/tag/brucon/'>brucon</a>, <a href='http://blog.c22.cc/tag/eurotrash/'>eurotrash</a>, <a href='http://blog.c22.cc/tag/podcast/'>podcast</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1891/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1891/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1891/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1891/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1891/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1891/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1891/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1891/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1891/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1891/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1891/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1891/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1891/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1891/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1891&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/25/eurotrashs-1st-birthday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://www.eurotrashsecurity.eu/images/eurotrash.jpg" medium="image" />
	</item>
		<item>
		<title>Underground pricelist</title>
		<link>http://blog.c22.cc/2010/08/23/underground-pricelist/</link>
		<comments>http://blog.c22.cc/2010/08/23/underground-pricelist/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 19:48:13 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Strange]]></category>
		<category><![CDATA[cc dump]]></category>
		<category><![CDATA[carder]]></category>
		<category><![CDATA[dump]]></category>
		<category><![CDATA[underground]]></category>
		<category><![CDATA[market]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1879</guid>
		<description><![CDATA[I was shifting through some blog comments last night, and came across one that was more than a little interesting (no, not death threats again&#8230; been there, done that) I&#8217;m not usually a follower of underground sites or forums, and &#8230; <a href="http://blog.c22.cc/2010/08/23/underground-pricelist/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1879&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_1881" class="wp-caption alignright" style="width: 267px"><img class="size-full wp-image-1881 " style="margin:5px;" title="photo by Neubie (source: Flickr Creative Commons)" src="http://c22blog.files.wordpress.com/2010/08/no-money.jpg?w=257&#038;h=257" alt="photo by Neubie (source: Flickr Creative Commons)" width="257" height="257" /><p class="wp-caption-text">photo by Neubie (source: Flickr).</p></div>
<p>I was shifting through some blog comments last night, and came across one that was more than a little interesting (no,  not <a href="http://blog.c22.cc/2010/06/17/threats/" target="_blank">death threats</a> again&#8230; been there, done that)</p>
<p>I&#8217;m not usually a follower of underground sites or forums, and I certainly don&#8217;t go digging about to get price lists of interesting info (<em>bank accounts, paypals, etc..</em>) . So it was more than a little surprising that it came to me&#8230; and in response to a blog entry I wrote about <a href="http://twitter.com/iiamit" target="_blank">Ian Iftach Amit&#8217;s</a><a href="http://blog.c22.cc/2010/04/14/blackhat-europe-cybercrimewar-charting-dangerous-waters-2/" target="_blank"> Cybercrime|war talk</a> from Blackhat of all things.</p>
<p>The comment below was posted from <a href="http://www.afrinic.net/cgi-bin/whois?searchtext=41.210.30.66" target="_blank">41.210.30.66</a>, an IP in Ghana (<em>owned by Ghana Telecom ADSL DYNAMIC ADDRESS POOL</em>). Maybe it&#8217;ll be an interesting tid-bit for some of you. For others, it&#8217;s an interesting reminder that our info isn&#8217;t worth hardly anything anymore!</p>
<p>Something I took away from this is the big difference in price between a US CVV $3, and an EU CVV $10. I&#8217;m not sure for the 3x increase in price, any thoughts?</p>
<p>The post below is slightly edited to cover some numbers and remove some FULL dumps&#8230; to protect the hopelessly 0wn3d!</p>
<blockquote><p>Author : paypal1 (IP: 41.210.30.66 , <a href="http://41-210-30-adsl-dyn.4u.com.gh/" target="_blank">41-210-30-adsl-dyn.4u.com.gh</a>)<br />
E-mail : <a href="mailto:paypal.bank1@yahoo.com">paypal.bank1@yahoo.com</a></p>
<p><strong>PRICELIST OF STUFFS</strong><br />
Logins<br />
Halifax 10K TO 85K<br />
Hsbc 10K TO 80K<br />
Wells 10K TO 90K<br />
Rbc 10 TO 90K<br />
10K TO 90K<br />
Boa 10K TO 90K<br />
Barclays 10K TO 90K<br />
Citi 10K TO 80K<br />
ALL TYPES OF LOGIN ASLO AVAILABLE…</p>
<p><strong>PAYPAL(COUNTRY)</strong><br />
PAYPAL 10K TO 50K</p>
<p>LEADS(ALL COUNTRY)<br />
MILLINOS LEAD WITH UNLIMITED SMTP FOR INBOX DELIVERY=100$</p>
<p><span style="text-decoration:underline;">1 US CVV=3$<br />
1 UK CVV=5$<br />
1 EU CVV=10$</span><br />
FULL CC with mmn,ssn,dob,pin=pm me for price<br />
PHP Mailers inbox=15$<br />
Webmailer=10$</p>
<p>1 US Fullz=30$<br />
1 UK Fullz=35$<br />
1 EU FULLZ=50$</p>
<p><strong>Dump Writer and Reader Machine</strong><br />
MSR206 Reader/Writer 400$</p>
<p><strong>US Dumps</strong> (101)(201)<br />
US Mix (20Gold/20Plats/20Biz&amp;Corp/40MCstandard&amp;Classic)<br />
bin of my choice 20$<br />
US Classic 40$<br />
US Debit Classic 50$<br />
US MC Standard 60$<br />
US Gold 100$<br />
US Platinum 120$<br />
US Business/Corporate 120$<br />
US Purchasing/Signature 150$<br />
US MC World 120$</p>
<p><strong>Canada Dumps</strong> (101)(201)<br />
Canada Classic 60$<br />
Canada MC Standard 70$<br />
Canada Gold 120$<br />
Canada Platinum 150$<br />
Canada MC WorlD 120$</p>
<p><strong>Europe Dumps</strong> (101)(201)<br />
EU Classic 120$<br />
EU MC Standard 100$<br />
EU Gold 140$<br />
EU Platinum 150$<br />
EU Business/Corporate 150$<br />
EU Infinite 200$</p>
<p><strong>ASIA DUMPS</strong> (101)(201)<br />
Asia Classic 50$<br />
Asia MC Standard 60$<br />
Asia GolD 120$<br />
Asia Platinum/Business/Corporate 150$</p>
<p><strong>ITALY DUMPS</strong> (101)(201)<br />
ITALY CLASSIC 50 $<br />
ITALY PLATIUM 150 $<br />
ITALYINFINIT 200 $<br />
ITALY MC STANDAR =60$</p>
<p><strong>GERMANY DUMPS</strong> (101)(201)<br />
GERMANY classic=50 $<br />
GERMANY BUSINESS/CORPORATE/PLATIUM=150 $<br />
GERMANY GOLD=120<br />
GERMANY MC STANDARD=60$</p>
<p><strong>SPAIN DUMPS</strong> (101)(201)<br />
SPAIN CLASSIC=50$<br />
SPAIN PLATIUM=150$<br />
SPAIN MC STANDARD=60$<br />
SPAIN BUSINESS=150$<br />
SPAIN INFINITY=200$</p>
<p><strong>MEXICO DUMPS</strong>(101)(201)<br />
MEXICO CLASSIC=50$<br />
MEXICO BUSINESS/CORPORATE/PLATIUM=150$<br />
MEXICO GOLD=120$<br />
MEXICO MC STANDARD=60$</p>
<p>!!!! I HAVE ALL COUNTRIES DUMPS +PIN+BIN!!!!</p>
<p>Transfers WESTERN UNION(w u t r f) AND BANK TRANSFER<br />
WU Transfer 10% upfront of whatever amount you want me to transfer for you…<br />
BANK Transfer 10% upfront of whatever amount you want me to transfer for you…<br />
eg: if you want $1000 you will have to pay $100 upfront.</p>
<p>SAMPLE DUMPS+PIN!!!!!!!!!!<br />
Track1 : Xx2176531046971xx^AMY/HILTON M^xx0610127352005210000xx ,<br />
Track2 : xx176531046971xx=xx03101383678xx<br />
Pin : 18xx</p>
<p>Track1=xx325560610187xxWYATT/ROBERTSONxx071011714100002710000xx<br />
Track2=xx325560610187xx=xx0710110000424000xx<br />
pin:56xx</p>
<p>CVV ALL COUNTRY SAMPLE</p>
<p><strong>Demo US</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p><strong>Demo UK</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p><strong>Demo CA</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p><strong>Demo au</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p><strong>demo FR</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p><strong>demo japan</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p><strong>demo italy</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p><strong>demo ger</strong><br />
&lt;STRIPPED DEMO DUMPS&gt;</p>
<p>Weeds also Available</p>
<p>SSN SOCIAL SECURITY NUMBER<br />
DOB DATE OF BIRTH<br />
DL DRIVING LINCENSE<br />
MMN MOTHER MAIDEN NAME</p>
<p>CONTACT INFORMATION</p>
<p>CONTACT US IF YOU DONT UNDERSTAND ANYTHING ABOUT THIS STUFFS AND ALSO  IF YOU WANT TO BUY MORE YOU CAN CALL THE NUMBER BELOW OR EMAIL ME:</p>
<p>YAHOO:paypal.bank1@xxxxx.com<br />
ICQ:604716xxx</p>
<p>VALID AND FRESH INFO FOR SELLE PM ME<br />
WE MAKE SURE YOU ARE SATISFIED WITH WHATEVER YOU ARE BUYING AND YOU GET  IMMIDIATE DELIVERY OF STUFFS AFTER PAYMENT………WE DONT GIVE DEMO NOR  SAMPLES NOR TEST ….. EVERY STUFFS 100% FRESH AND LIVE.</p></blockquote>
<p>* Sorry about the long post&#8230; Contact me for the unedited version (<em>if you have good reason obviously!</em>)</p>
<br />Filed under: <a href='http://blog.c22.cc/category/security/'>Security</a>, <a href='http://blog.c22.cc/category/strange/'>Strange</a> Tagged: <a href='http://blog.c22.cc/tag/carder/'>carder</a>, <a href='http://blog.c22.cc/tag/cc-dump/'>cc dump</a>, <a href='http://blog.c22.cc/tag/dump/'>dump</a>, <a href='http://blog.c22.cc/tag/market/'>market</a>, <a href='http://blog.c22.cc/tag/underground/'>underground</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1879/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1879/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1879/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1879&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/23/underground-pricelist/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/no-money.jpg" medium="image">
			<media:title type="html">photo by Neubie (source: Flickr Creative Commons)</media:title>
		</media:content>
	</item>
		<item>
		<title>New Advanced Penetration Testing Class from SANS</title>
		<link>http://blog.c22.cc/2010/08/18/new-advanced-penetration-testing-class-from-sans/</link>
		<comments>http://blog.c22.cc/2010/08/18/new-advanced-penetration-testing-class-from-sans/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 22:51:00 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Study]]></category>
		<category><![CDATA[GPEN]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[SANS London]]></category>
		<category><![CDATA[SEC560]]></category>
		<category><![CDATA[SEC660]]></category>
		<category><![CDATA[Stephen Sims]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1870</guid>
		<description><![CDATA[Back in 2008, SANS released their Network Penetration Testing and Ethical Hacking class (SEC560). At the time it was listed as &#8220;SANS Security 560 is one of the most technically rigorous courses offered by the SANS Institute&#8221;. I had the &#8230; <a href="http://blog.c22.cc/2010/08/18/new-advanced-penetration-testing-class-from-sans/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1870&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1873" style="margin:5px;" title="sans_trim" src="http://c22blog.files.wordpress.com/2010/08/sans_trim.png?w=110&#038;h=71" alt="" width="110" height="71" />Back in 2008, SANS released their Network Penetration Testing and Ethical Hacking class (<em>SEC560</em>). At the time it was listed as &#8220;SANS Security 560 is one of the most technically rigorous courses offered by the SANS Institute&#8221;. I had the pleasure of taking the class with John Strand back in 2008 and it was a great class, with a lot of great pointers for a penetration tester getting into the business. It was certainly head and shoulders above the other classes on offer.</p>
<p>Since then, the industry has been all about certification. New certs and classes have popped up all over the place. Just over 2 years later, and SANS have just released their new Advanced Penetration Testing, Exploits, and Ethical Hacking class (<em>SEC660</em>). Incorporating new techniques that build on the previous class. The new class will be given boot camp style (<em>with evening sessions</em>), to maximize the content.</p>
<p>SANS will be running the SEC660 class with Stephen Sims at the December SANS London event&#8230; Make sure to book early, if the SEC560 class is anything to go by, then this ones going to be popular!</p>
<p><strong>Links</strong> :</p>
<ul>
<li>SANS - <a href="http://www.sans.org/london-2010/description.php?tid=4582&amp;utm_source=web&amp;utm_medium=blog&amp;utm_content=Course_Marketing_Chris_Riley&amp;utm_campaign=SANS_London_2010&amp;ref=64223http://www.sans.org/london-2010/description.php?tid=4582&amp;utm_source=web&amp;utm_medium=blog&amp;utm_content=Course_Marketing_Chris_Riley&amp;utm_campaign=SANS_London_2010&amp;ref=64223" target="_blank">Security 660 &#8211; Advanced Penetration Testing, Exploits, and Ethical Hacking</a></li>
<li>SANS <a href="http://www.sans.org/info/64223" target="_blank">London 2010</a></li>
</ul>
<br />Filed under: <a href='http://blog.c22.cc/category/security/'>Security</a>, <a href='http://blog.c22.cc/category/study/'>Study</a> Tagged: <a href='http://blog.c22.cc/tag/gpen/'>GPEN</a>, <a href='http://blog.c22.cc/tag/sans/'>SANS</a>, <a href='http://blog.c22.cc/tag/sans-london/'>SANS London</a>, <a href='http://blog.c22.cc/tag/sec560/'>SEC560</a>, <a href='http://blog.c22.cc/tag/sec660/'>SEC660</a>, <a href='http://blog.c22.cc/tag/security/'>Security</a>, <a href='http://blog.c22.cc/tag/stephen-sims/'>Stephen Sims</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1870/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1870/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1870/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1870&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/18/new-advanced-penetration-testing-class-from-sans/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/sans_trim.png" medium="image">
			<media:title type="html">sans_trim</media:title>
		</media:content>
	</item>
		<item>
		<title>Bigger, Better, Faster, More!</title>
		<link>http://blog.c22.cc/2010/08/10/bigger-better-faster-more/</link>
		<comments>http://blog.c22.cc/2010/08/10/bigger-better-faster-more/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 08:01:13 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[#BSidesLV]]></category>
		<category><![CDATA[blackhat]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1815</guid>
		<description><![CDATA[Las Vegas &#8211; The entertainment capital of the world. Where your every desire is catered for, and you never have to go without. If there&#8217;s another place on earth with so many flashy lights, then I&#8217;ve certainly never heard about &#8230; <a href="http://blog.c22.cc/2010/08/10/bigger-better-faster-more/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1815&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="size-medium wp-image-1817 alignright" style="margin:6px;" title="lights" src="http://c22blog.files.wordpress.com/2010/08/lights.jpg?w=207&#038;h=138" alt="" width="207" height="138" />Las Vegas &#8211; The entertainment capital of the world.</p>
<p>Where your every desire is catered for, and you never have to go without. If there&#8217;s another place on earth with so many flashy lights, then I&#8217;ve certainly never heard about it!</p>
<p>Still, When I saw that this year Blackhat had gone to 11 tracks, I couldn&#8217;t help but think they&#8217;d were going a little bit too far, even for Vegas!</p>
<p>There&#8217;s a fine line between offering good content and swamping visitors with just too much choice&#8230;  and no matter how much I try, I just can&#8217;t help but get the feeling that Blackhat Las Vegas just <a href="http://en.wikipedia.org/wiki/Jumping_the_shark" target="_blank">jumped the shark</a>!</p>
<p style="text-align:left;">I go to more than my fair share of conferences, and one thing that connects them all for me is the excitement and anticipation I get when looking over the list of speakers and talks. Picking out the ones I really want to see, the people I want to meet and the things I want to learn about, are one of the highlights of a conference for me. The build-up is almost as important as the event after all. When I saw the schedule for this years Blackhat however, I didn&#8217;t feel excited. It wasn&#8217;t because there were no good talks, because there were a lot of great talks and great speakers. It was just too much. In my mind Blackhat had hit that point where it just didn&#8217;t matter what talks people went to anymore. It was just too big, too complex, and too confusing to me. I couldn&#8217;t help but get the feeling that no matter what talk I saw, I&#8217;d always be thinking about the other 10 tracks and what I was missing out on!</p>
<p style="text-align:center;"><img class="size-medium wp-image-1816 aligncenter" style="margin-top:8px;margin-bottom:8px;" title="11tracks" src="http://c22blog.files.wordpress.com/2010/08/11tracks.png?w=344&#038;h=48" alt="" width="344" height="48" /></p>
<p style="text-align:left;">Maybe it&#8217;s just me, maybe everybody else thinks this was the best Blackhat ever. Everybody has his/her own opinion, and mine is that Blackhat <em>(at least in Vegas)</em> is dead to me. I doubt I&#8217;ll be attending next year for the new improved 12 track program <em>(they have to make it more impressive next year after all&#8230; there&#8217;s no backing down now!)</em>. If you want to find me, I&#8217;ll be sitting by the pool at <a href="http://www.securitybsides.com/BSidesLasVegas" target="_blank">BSides</a> talking to people who do this for the love of it, and not the money.</p>
<br />Filed under: <a href='http://blog.c22.cc/category/conference/'>Conference</a>, <a href='http://blog.c22.cc/category/security/'>Security</a> Tagged: <a href='http://blog.c22.cc/tag/bsideslv/'>#BSidesLV</a>, <a href='http://blog.c22.cc/tag/blackhat/'>blackhat</a>, <a href='http://blog.c22.cc/tag/conference/'>Conference</a>, <a href='http://blog.c22.cc/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1815/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1815/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1815/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1815/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1815/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1815/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1815/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1815/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1815/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1815/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1815/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1815/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1815/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1815/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1815&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/10/bigger-better-faster-more/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/lights.jpg?w=300" medium="image">
			<media:title type="html">lights</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/08/11tracks.png?w=300" medium="image">
			<media:title type="html">11tracks</media:title>
		</media:content>
	</item>
		<item>
		<title>[Defcon] SHODAN for Penetration Testers</title>
		<link>http://blog.c22.cc/2010/08/02/defcon-shodan-for-penetration-testers/</link>
		<comments>http://blog.c22.cc/2010/08/02/defcon-shodan-for-penetration-testers/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 00:43:53 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[shodan]]></category>

		<guid isPermaLink="false">https://c22blog.wordpress.com/?p=1805</guid>
		<description><![CDATA[SHODAN for Penetration Testers – Michael &#8220;theprez98&#8243; Schearer What is SHODAN SHODAN is a search engine designed to crawl server and gathering banner information from specific ports. A search engine of banners instead of content. We can use this information &#8230; <a href="http://blog.c22.cc/2010/08/02/defcon-shodan-for-penetration-testers/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1805&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:12px;color:#494949;line-height:20px;"> </span></p>
<p style="margin:.6em 0 1.2em;padding:0;"><img style="margin-left:auto;vertical-align:middle;display:block;margin-right:auto;border:initial none initial;" src="http://c22blog.files.wordpress.com/2010/07/dc-18-logo_smsq.png?w=150&amp;h=150&#038;h=150" alt="" width="150" height="150" /></p>
<p style="margin:.6em 0 1.2em;padding:0;"><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;"><span style="border-collapse:collapse;font-size:13px;line-height:19px;"><strong>SHODAN for Penetration Testers</strong></span></span><span style="font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:13px;border-collapse:collapse;color:#444444;line-height:19px;"> – Michael &#8220;theprez98&#8243; Schearer</span></p>
<p style="margin:.6em 0 1.2em;padding:0;"><strong>What is SHODAN</strong></p>
<p style="margin:.6em 0 1.2em;padding:0;">SHODAN is a search engine designed to crawl server and gathering banner information from specific ports.</p>
<p style="margin:.6em 0 1.2em;padding:0;">A search engine of banners instead of content.</p>
<p style="margin:.6em 0 1.2em;padding:0;">We can use this information to fingerprint the type and/or version of system</p>
<p style="margin:.6em 0 1.2em;padding:0;">
<p style="margin:.6em 0 1.2em;padding:0;"><strong>Basic Operations</strong></p>
<p style="margin:.6em 0 1.2em;padding:0;">Accessible through the website &#8211;&gt; www.shodanhq.com</p>
<p style="margin:.6em 0 1.2em;padding:0;">There are also a number of browser add-ons that allow you to search directly from a browser without using the main interface.</p>
<p style="margin:.6em 0 1.2em;padding:0;">
<p style="margin:.6em 0 1.2em;padding:0;">The search engine supports standard things such as boolean operators, as you&#8217;d expect</p>
<p style="margin:.6em 0 1.2em;padding:0;">Login &#8211;&gt; Either a free access search (a few features restricted) or create an account for full access.</p>
<p style="margin:.6em 0 1.2em;padding:0;"><em><strong>Filters</strong></em></p>
<p style="margin:.6em 0 1.2em;padding:0;">Typing &#8220;CISCO&#8221; into SHODAN will come up with a lot of results. To filter this, you can use specific filtering values.</p>
<ul>
<li>after/before
<ul>
<li>Limit results by date</li>
</ul>
</li>
<li>country
<ul>
<li>2 letter country code</li>
</ul>
</li>
<li>hostname
<ul>
<li>Filters by text in the hostname or domain</li>
</ul>
</li>
<li>net
<ul>
<li>Specific IP range or subnet</li>
</ul>
</li>
<li>os</li>
<li>port</li>
<li>SSL</li>
</ul>
<p style="margin:.6em 0 1.2em;padding:0;">Filters can be specified through the interface using the map/checkboxes. Alternatively, you can directly enter the filter text into the search box.</p>
<p style="margin:.6em 0 1.2em;padding:0;">The map is also interactive, showing the number of scanned hosts when you mouseover a country.</p>
<p style="margin:.6em 0 1.2em;padding:0;"><em>example</em>: apache country:CH &#8211;&gt; search for all systems in CH with the match on apache</p>
<p style="margin:.6em 0 1.2em;padding:0;">Knowing what the banner returns is very helpful for finding systems you want to locate.</p>
<p style="margin:.6em 0 1.2em;padding:0;"><em>Other Examples</em> :</p>
<ul>
<li>apache hostname:.nist.gov</li>
<li>iss-5.0 hostname:.edu</li>
</ul>
<p style="margin:.6em 0 1.2em;padding:0;"><strong><em>Port filtering</em></strong></p>
<ul>
<li>FTP 21</li>
<li>SSH 22</li>
<li>Telnet 23</li>
<li>HTTP 80</li>
<li>SNMP 161</li>
<li>HTTPS 443 &#8211;&gt; Requires an SSL add-on</li>
</ul>
<p style="margin:.6em 0 1.2em;padding:0;">The SSL/HTTPS searches requires an add-on. More information on the SHODAN homepage.</p>
<p style="margin:.6em 0 1.2em;padding:0;">Search history is optional and disabled by default</p>
<p style="margin:.6em 0 1.2em;padding:0;">By creating an account you can have personal history and save searches that you wish to repeat.</p>
<p style="margin:.6em 0 1.2em;padding:0;"><strong><em>Export</em></strong></p>
<p style="margin:.6em 0 1.2em;padding:0;">Can export up to 1,000 results in XML format</p>
<p style="margin:.6em 0 1.2em;padding:0;">Requires an account, and add-on</p>
<p style="margin:.6em 0 1.2em;padding:0;">
<p style="margin:.6em 0 1.2em;padding:0;">New section called Network Radar that shows newly added data.</p>
<p style="margin:.6em 0 1.2em;padding:0;">Extended searches available with add-ons</p>
<p style="margin:.6em 0 1.2em;padding:0;">
<p style="margin:.6em 0 1.2em;padding:0;"><strong>Penetration Testing</strong></p>
<p style="margin:.6em 0 1.2em;padding:0;">Originally a marketing and research tool. However things have changed.</p>
<p style="margin:.6em 0 1.2em;padding:0;">Basic knowledge of banners and status codes is important to be able to make sense of results and configure filters.</p>
<p style="margin:.6em 0 1.2em;padding:0;">When searching for web-servers or domains, a 200 OK message is the best result as no further authentication is required to access the page.</p>
<p style="margin:.6em 0 1.2em;padding:0;">
<p style="margin:.6em 0 1.2em;padding:0;"><strong>CASE Studies</strong></p>
<ul>
<li>CISCO Devices
<ul>
<li>By searching for CISCO with a 200 OK, you will find devices without authentication</li>
<li>Some of these are probably test labs&#8230;.. but not ALL of them!</li>
<li>5-6,000 of such systems on the internet</li>
</ul>
</li>
<li>Default Passwords
<ul>
<li>Search for the words &#8220;default password&#8221;</li>
<li>Find&#8230; a printer accessible from the web using the default password as displayed in the headers</li>
</ul>
</li>
<li>HAUWEI
<ul>
<li>Exclusion of all 4XX codes &#8211;&gt; We just want 200 OK</li>
<li>Most responses where all in the same Subnet</li>
<li>Lots and lots of VoIP phones public facing</li>
<li>However&#8230;. they needed a password. Most hauwei have easy to guess default passwords</li>
<li>Able to reconfigure the device&#8230;. even change the URL for software updates (want to load new firmware?)</li>
</ul>
</li>
<li>Infrastructure Exploitation&#8230; or &#8220;How to pwn an ISP&#8221;
<ul>
<li>A number of CISCO devices discovered in the earlier section</li>
<li>Allow LEVEL 15 access (full admin)</li>
<li>Included 2x CISCO 3750 and direct access to a Cisco 7606 router!</li>
<li>ISP located in the US (small regional)</li>
<li>VLAN IDs for internal networks, hotels, apartments, convention center, public backbone, etc&#8230;</li>
<li>SNMP server IP address and community strings</li>
</ul>
</li>
</ul>
<p>Other interesting info</p>
<ul>
<li>Some IIS searches
<ul>
<li>iis/5 &#8211;&gt; 362695</li>
<li>iis/4 &#8211;&gt; 9977</li>
<li>iis/3 &#8211;&gt; 381</li>
<li>iis/2 &#8211;&gt; 42</li>
<li>iis/1 &#8211;&gt; 152</li>
</ul>
</li>
<li>Wireless network cameras&#8230; with movement features
<ul>
<li>In Firefox you can do snapshots..</li>
<li>In IE you get an extra feature &#8211;&gt; CONFIG!</li>
</ul>
</li>
</ul>
<p><strong>Conclusions</strong></p>
<p>Aggregates a lot of information not already available</p>
<p style="padding-top:0;padding-right:0;padding-bottom:0;margin:.6em 0 1.2em;">Allows for some passive vulnerability analysis &#8211;&gt; based on banner version information</p>
<p style="padding-top:0;padding-right:0;padding-bottom:0;margin:.6em 0 1.2em;">Not going to take over the world, but a good tool for penetration testers</p>
<p style="padding-top:0;padding-right:0;padding-bottom:0;margin:.6em 0 1.2em;">
<p style="margin:.6em 0 1.2em;padding:0;"><span style="font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:13px;border-collapse:collapse;color:#444444;line-height:19px;"><span style="border-collapse:separate;color:#494949;font-family:Verdana, Arial, Helvetica, sans-serif;line-height:20px;font-size:12px;"> </span></span></p>
<p style="margin:.6em 0 1.2em;padding:0;"><span style="font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:13px;border-collapse:collapse;color:#444444;line-height:19px;"><strong>Links</strong>:</span></p>
<ul style="margin:.5em 0 1em;padding:0;">
<li style="margin:.4em 0 .4em 1.5em;"><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;"><span style="border-collapse:collapse;font-size:13px;line-height:19px;">Twitter –&gt; <a href="http://twitter.com/theprez98" target="_blank">@theprez98</a></span></span></li>
<li style="margin:.4em 0 .4em 1.5em;"><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;">Theprez98 slides –&gt; <a style="color:#5a0c07;text-decoration:none;" href="http://www.scribd.com/theprez98" target="_blank">LINK</a></span></li>
<li style="margin:.4em 0 .4em 1.5em;"><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;">SHODAN –&gt; <a style="color:#5a0c07;text-decoration:none;" href="http://www.shodanhq.com" target="_blank">LINK</a></span></li>
</ul>
<br />Filed under: <a href='http://blog.c22.cc/category/conference/'>Conference</a>, <a href='http://blog.c22.cc/category/security/'>Security</a> Tagged: <a href='http://blog.c22.cc/tag/conference/'>Conference</a>, <a href='http://blog.c22.cc/tag/defcon/'>defcon</a>, <a href='http://blog.c22.cc/tag/security/'>Security</a>, <a href='http://blog.c22.cc/tag/shodan/'>shodan</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1805/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1805/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1805/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1805/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1805/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1805/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1805/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1805/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1805/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1805/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1805/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1805/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1805/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1805/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1805&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/02/defcon-shodan-for-penetration-testers/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/07/dc-18-logo_smsq.png?w=150&#38;h=150&#38;h=150" medium="image" />
	</item>
		<item>
		<title>[Defcon] You Spent All That Money And You Still Got Owned&#8230;</title>
		<link>http://blog.c22.cc/2010/08/02/defcon-you-spent-all-that-money-and-you-still-got-owned/</link>
		<comments>http://blog.c22.cc/2010/08/02/defcon-you-spent-all-that-money-and-you-still-got-owned/#comments</comments>
		<pubDate>Sun, 01 Aug 2010 23:36:38 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[defcon]]></category>

		<guid isPermaLink="false">https://c22blog.wordpress.com/?p=1803</guid>
		<description><![CDATA[You Spent All That Money And You Still Got Owned&#8230; &#8211; Joe McCray You often run up against all sorts of defensive measures when penetration testing (Firewalls, IDs/IPS, WAF, &#8230;) and the testers still get in! Often you get in, only &#8230; <a href="http://blog.c22.cc/2010/08/02/defcon-you-spent-all-that-money-and-you-still-got-owned/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1803&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img style="vertical-align:middle;display:block;margin-left:auto;margin-right:auto;" src="http://c22blog.files.wordpress.com/2010/07/dc-18-logo_smsq.png?w=150&amp;h=150&#038;h=150" alt="" width="150" height="150" /></p>
<p><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;"><span style="border-collapse:collapse;font-size:13px;line-height:19px;"><strong>You Spent All That Money And You Still Got Owned&#8230;</strong></span></span><span style="font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:13px;border-collapse:collapse;color:#444444;line-height:19px;"> &#8211; Joe McCray</span></p>
<p>You often run up against all sorts of defensive measures when penetration testing (Firewalls, IDs/IPS, WAF, &#8230;) and the testers still get in!</p>
<p>Often you get in, only to find that the company is already owned (enter Incident Handling mode)</p>
<p>More and more security measures are being implemented on company networks.</p>
<ul>
<li>Firewalls are commonplace (perimeter and host based)</li>
<li>Anti-virus is smarter</li>
<li>Intrusion Detection / Prevention systems are hard to detect, let alone bypass</li>
<li>NAC Solutions are making their way into networks</li>
<li>IT Hardware / Software vendors are integrating security into their SDLC</li>
</ul>
<p>Still. Companies get owned.</p>
<p>Comments like &#8220;We can&#8217;t patch those! Those are our development servers&#8221; don&#8217;t help.</p>
<p>&#8220;Always go for the quick shell&#8221; &#8211;&gt; Google dork search for anything that hints at SQL Injection, remote/local file includes.</p>
<p><strong>Identify Load-Balancers</strong></p>
<p>Figure out if it&#8217;s load balanced</p>
<p>DNS or IP load balanced &#8211;&gt; it makes a difference</p>
<p>Check the returned headers to see if things are different</p>
<ul>
<li>Server Header</li>
<li>Time/Date</li>
<li>&#8230;</li>
</ul>
<p>Use DNS queries and Netcraft.com</p>
<p>Tools to do this</p>
<ul>
<li>Load Balancer Detection &#8211; lbd.sh</li>
<li>Halberd</li>
</ul>
<p><strong>Identifying Intrusion Prevention Systems</strong></p>
<p>Most are still in detection only mode</p>
<p>See if it&#8217;s blocking&#8230;. break out CURL and try ../../../../winnt/system32/cmd.exe?d</p>
<p>Did you get blocked, is your IP banned &#8211;&gt; If so it&#8217;s an IPS in blocking mode</p>
<p>Look for RST and other hints</p>
<p>Does the IPS monitor SSL traffic &#8211;&gt; Many don&#8217;t</p>
<p><strong>Attacking through TOR</strong></p>
<p>Push attacks through TOR to help with IP-Banning</p>
<p>Clients should be blocking TOR proxies</p>
<p><strong>Identifying WAFs</strong></p>
<p>Due to PCI, there are a lot of WAFs being implemented</p>
<p>Send almost any special character it will respond</p>
<p>Often easy to identify</p>
<p>Check in return headers for hints and information.</p>
<p>Tools like wafwoof can also be used &#8211;&gt; waffun is a project being worked on currently</p>
<p>Examine / Request all possible std return codes (200, 404, 301, ..) and then see what gets returned if you try an XSS attack&#8230; are they identical?</p>
<p>Encoding is sometimes dealt with by a WAF&#8230; double encoding not so often.</p>
<p><em>Example</em>:</p>
<p>DotDefender WAF &#8211;&gt; Simple unencoded SQLi gets through. Blacklist on specific words and commands</p>
<p>Blocking the word SELECT &#8211;&gt; Easy to bypass using UNICODE</p>
<p>FIXED by the vendor &#8211;&gt; Only blocks unicode &#8211;&gt; FAIL</p>
<p><strong>SQL Injection to Metasploit</strong></p>
<p><em>SQLNinja</em></p>
<ul>
<li>Written in Perl, but still good.</li>
<li>Great from going from SQLi to shell</li>
</ul>
<p><em>SQLMAP</em></p>
<ul>
<li>Written in Python</li>
<li>Allows you to drop to a shell</li>
</ul>
<p><strong>Filter Evasion</strong></p>
<p>Client-Side filtering == BAD</p>
<p>Do not use JavaScript that does filtering without server-side checks</p>
<p>&#8220;You&#8217;re going to put all the security on the hackers laptop!&#8221;</p>
<p><strong>Restrictive Blacklist</strong></p>
<p>Blocking things like = sign doesn&#8217;t stop SQLi</p>
<p>Encoding things bypasses these blacklists</p>
<p>Rules in IDS/IPS are sometimes looking for specifics like 1=1</p>
<p>Wait&#8230; doesn&#8217;t 2=2 as well!</p>
<p>Blacklist rule-sets are a loosing proposition as encoding can bypass the rules</p>
<p><strong>Practice your kung-fu</strong></p>
<p>PHPIDS</p>
<ul>
<li>Smoketest
<ul>
<li>check your encoding and bypass techniques</li>
<li>find something that will bypass a lot of the rules</li>
</ul>
</li>
</ul>
<p>MOD_Security</p>
<ul>
<li>Also now offers a smoketest</li>
<li>Implements core ruleset, PHPIDS and Snort</li>
</ul>
<p>Lots of companies have IDS&#8230; how many actually look at it though?</p>
<p><strong>Getting in via the Client-Side</strong></p>
<p>Email a client-side exploit exported from Metasploit</p>
<p>Use reverse HTTPS to bypass some detections</p>
<p><em>SET (Social Engineering Toolkit)</em></p>
<p>&#8220;Real hackers aren&#8217;t scanning your network anymore&#8221;</p>
<p><strong>Pivoting into the LAN</strong></p>
<p>Metasploit offers a pivot</p>
<p>Compile programs so they don&#8217;t need an install, upload to remote system and run</p>
<p><strong>Common LAN Security Solutions</strong></p>
<p>No DHCP</p>
<ul>
<li>Use Static</li>
</ul>
<p>DHCP MAC Address REservations</p>
<ul>
<li>Find a system, steal MAC</li>
</ul>
<p>Port Security</p>
<ul>
<li>Find a printer&#8230;.</li>
</ul>
<p>NAC Solutions</p>
<ul>
<li>Find a non-NAC supported system</li>
</ul>
<p>See a pattern here</p>
<p>Tools like VOIPhopper are perfect for going from one VLAN to another.</p>
<p><strong>Looking around the network for a user</strong></p>
<ul>
<li>net commands on Windows are great for finding network information</li>
<li>Script output and find the Administrators</li>
<li>Escalate to SYSTEM/Administrator</li>
<li>Run commands using psexec, pskill, &#8230;</li>
<li>Kill protections, stop services</li>
</ul>
<p>Certain AV/HIDS have blacklist filenames that aren&#8217;t checked&#8230; not hashes&#8230; filenames!</p>
<p>Use the new getsystem in Metasploit</p>
<p><strong>Owning the Domain</strong></p>
<p>Use token stealing (in Metasploit / Incognito)</p>
<p>Find an admin, steal the token, win!</p>
<p><span style="font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:13px;border-collapse:collapse;color:#444444;line-height:19px;"><strong>Links</strong>:</span></p>
<ul>
<li><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;"><span style="border-collapse:collapse;font-size:13px;line-height:19px;">Twitter &#8211;&gt; <a href="http://twitter.com/j0emccray" target="_blank">@j0emccray</a></span></span></li>
<li><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;">Talk Information &#8211;&gt; <a href="https://www.defcon.org/html/defcon-18/dc-18-speakers.html#McCray" target="_blank">LINK</a></span></li>
<li><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;">Learn Security Online &#8211;&gt; <a href="http://www.learnsecurityonline.com/" target="_blank">LINK</a></span></li>
</ul>
<br />Filed under: <a href='http://blog.c22.cc/category/conference/'>Conference</a>, <a href='http://blog.c22.cc/category/security/'>Security</a> Tagged: <a href='http://blog.c22.cc/tag/conference/'>Conference</a>, <a href='http://blog.c22.cc/tag/defcon/'>defcon</a>, <a href='http://blog.c22.cc/tag/penetration-testing/'>penetration testing</a>, <a href='http://blog.c22.cc/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1803/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1803/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1803/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1803/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1803/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1803/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1803/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1803/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1803/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1803/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1803/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1803/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1803/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1803/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1803&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/08/02/defcon-you-spent-all-that-money-and-you-still-got-owned/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/07/dc-18-logo_smsq.png?w=150&#38;h=150" medium="image" />
	</item>
		<item>
		<title>[Defcon] Hacking Oracle From Web Apps</title>
		<link>http://blog.c22.cc/2010/07/31/defcon-hacking-oracle-from-web-apps/</link>
		<comments>http://blog.c22.cc/2010/07/31/defcon-hacking-oracle-from-web-apps/#comments</comments>
		<pubDate>Sat, 31 Jul 2010 00:49:12 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[oracle]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[web applications]]></category>

		<guid isPermaLink="false">https://c22blog.wordpress.com/?p=1800</guid>
		<description><![CDATA[Hacking Oracle From Web Apps &#8211; Sumit Siddharth Exploitation techniques for exploit SQL Injection attacks on Web Applications with Oracle databases Because it&#8217;s Defcon&#8230; and we love SQL Injection! No free tools for hacking Oracle Databases from the web Even &#8230; <a href="http://blog.c22.cc/2010/07/31/defcon-hacking-oracle-from-web-apps/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1800&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img style="vertical-align:middle;display:block;margin-left:auto;margin-right:auto;" src="http://c22blog.files.wordpress.com/2010/07/dc-18-logo_smsq.png?w=150&amp;h=150&#038;h=150" alt="" width="150" height="150" /></p>
<p><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;"><span style="border-collapse:collapse;font-size:13px;line-height:19px;"><strong>Hacking Oracle From Web Apps</strong></span></span><span style="font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:13px;border-collapse:collapse;color:#444444;line-height:19px;"> &#8211; Sumit Siddharth</span></p>
<p>Exploitation techniques for exploit SQL Injection attacks on Web Applications with Oracle databases</p>
<p>Because it&#8217;s Defcon&#8230; and we love SQL Injection!</p>
<p>No free tools for hacking Oracle Databases from the web</p>
<ul>
<li>Even commercial tools like Pangolin have outdated techniques</li>
</ul>
<p><strong>Oracle Privileges</strong></p>
<p>Oracle comes with a number of default packages. This has reduced a lot with the latest 11g release</p>
<p>By default these packages run with the privileges of the definer</p>
<p>This can be changed to the caller of the function, but must be set in the function/procedure (AUTHID CURRENT_USER)</p>
<p><em>Owning from the network is easy</em></p>
<ul>
<li>Enumerate SID</li>
<li>Enumerate common users</li>
<li>Connect to the Oracle DB</li>
<li>Exploit SQL Injection in a procedure owned by SYS</li>
<li>Become DBS</li>
<li>Execute OS Code</li>
</ul>
<p>Demonstrated by Chris Gates last year using a number of Metasploit plugins</p>
<p>In Oracle there are 2 classes of Injection</p>
<ul>
<li>PL/SQL</li>
<li>SQL
<ul>
<li>Limited</li>
<li>Doesn&#8217;t allow chained statements</li>
</ul>
</li>
</ul>
<p>OS Code execution is also not as simple as it is in Microsoft SQL Server</p>
<p>PL/SQL Injection</p>
<ul>
<li>Injection in Anonymous PL/SQL Block</li>
<li>No Restriction</li>
<li>Execute DDL/DML</li>
</ul>
<p>SQL</p>
<ul>
<li>Common SQL Injection</li>
<li>Limited capabilities</li>
<li>No chained statements</li>
</ul>
<p><strong>eExploitating </strong><strong>PL/SQL Injection</strong></p>
<p><strong> </strong>Using David Litchfield&#8217;s exploit from Blackhat DC 2010 &#8211;&gt; Enable JAVA IO Permissions</p>
<p><strong> </strong></p>
<p>OS Command Injection can then be obtained by calling a JAVA function (DBMS_JAVA_TEST) and calling a command on the local system</p>
<p><strong>Exploiting SQL Injection</strong></p>
<p>This could mean many thing&#8230; do you want data from the DB or a shell &#8211;&gt; depends on the goals of a test/attacker</p>
<p>Extraction of Data</p>
<ul>
<li>Error Messages Enabled</li>
<li>Error Messages Disabled
<ul>
<li>Union Query</li>
<li>Blind injection</li>
<li>Time delay / Heavy queries</li>
<li>Out-of-band channels</li>
</ul>
</li>
<li>Privilege escalation</li>
<li>OS Command Execution</li>
</ul>
<p>Is your SQL Injection Privileged or unprivileged?</p>
<p>Are you executing with DBA privileges or something else</p>
<ul>
<li>Privileged SQL Injection
<ul>
<li>Happens more often when the application connects to a database with DBA privs</li>
<li>SQL Injection is in a procedure owned by the DBA (regardless of the connection string)</li>
</ul>
</li>
<li>Unprivileged SQL Injection</li>
</ul>
<p>To exploit the Os we need Functions executable by public and vulnerable to :</p>
<ul>
<li>PL/SQL Injection</li>
<li>Allows PL/SQL execution as a feature</li>
<li>Buffer overflow</li>
</ul>
<p>There are a few functions known but the exploit is not publicly available</p>
<p>e.g. DBMS_JAVA_TEST (10g) buffer overflow</p>
<p>Of those known the following are popular:</p>
<ul>
<li>DBMS_EXPORT_EXTENSION</li>
<li>GET_DOMAIN_INDEX_TABLES()
<ul>
<li>Function vulnerable to PL/SQL Injection</li>
<li>Runs with definer (SYS) privileges</li>
<li>Allows privilege escalation</li>
<li>OS Command Execution</li>
</ul>
</li>
</ul>
<p>Privileges needed to execute code on the OS</p>
<ul>
<li>DBA Privileges</li>
<li>JAVA IO Privileges</li>
</ul>
<p>Versions prior to CPU April 2006 there are a number of exploits in Pangolin and CoreImpact</p>
<p>Functions to execute code on the OS</p>
<ul>
<li>DBMS_JAVA.RUNJAVA()</li>
<li>DBMS_JAVA_TEST.FUNCALL()</li>
</ul>
<p>These take an Oracle class as input and cannot be executed without JAVA IO Privileges.</p>
<p>DBA can grant himself the required privileges, however even without he can use the SYS.KUPP$PROC.CREATE.MASTER_PROCESS() function on 10g/11g to execute code on the remote OS.</p>
<p><strong>Bsqlbf 2.6</strong></p>
<p>Supports these new attack types and can be downloaded from Google Code.</p>
<p>Includes the ability to upload and execute a Metasploit payload through these vulnerabilities</p>
<p>Supports JAVA IO and DBA execution as required</p>
<p>Has a cleanup mode for nice penetration testers <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><strong>Non-interactive second order injections</strong></p>
<p>Even if a field is not injectable it could be that the code is executed if for example, an administrator views the injected code through a second vulnerable application (for example a logging tool, or administration screen).</p>
<p>The malicious user will never see the response however, as the secondary user is running the injection. This means any output will be returned to the secondary user and not the malicious user.</p>
<p>Another possible scenario is a trigger or automated nightly process that acts on the injected code when run.</p>
<p>So how can we make these non-interactive attack vectors interactive ?</p>
<p>Encode and upload a binary (Metasploit payload) to the remote server and wait for the secondary user/process to trigger the exploit &#8211;&gt; Shell &#8211;&gt; WIN</p>
<p>webraider tool implements this style of attack to upload a Metasploit module</p>
<p><strong>You&#8217;ve been hacked&#8230; so what?</strong></p>
<p>PCI compliance mandates the card data must be stored encrypted &#8211;&gt; So the output is encrypted</p>
<p>PCI doesn&#8217;t specific if the encryption happens at the DB or App level</p>
<p>If it&#8217;s at the DB level, then the App decrypts the data when requesting &#8211;&gt; Passing the encryption key means an attacker could extract them</p>
<ul>
<li>v$sql table logs statistics on shared SQL area</li>
<li>Typically stores last 500 queries &#8211;&gt; including the encryption details</li>
</ul>
<p><strong><br />
</strong></p>
<p><span style="font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:13px;border-collapse:collapse;color:#444444;line-height:19px;"><strong>Links</strong>:</span></p>
<ul>
<li><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;"><span style="border-collapse:collapse;font-size:13px;line-height:19px;">Blog &#8211;&gt; <a href="http://www.notsosecure.com" target="_blank">LINK</a></span></span></li>
<li><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;"><span style="border-collapse:collapse;font-size:13px;line-height:19px;">Twitter &#8211;&gt; <a href="http://twitter.com/notsosecure" target="_blank">@notsosecure</a></span></span></li>
<li><span style="color:#444444;font-family:'Segoe UI', 'Lucida Grande', Arial;font-size:small;">bsqlbf &#8211;&gt; <a href="http://code.google.com/p/bsqlbf-v2/" target="_blank">LINK</a></span></li>
<li>webraider &#8211;&gt; <a href="http://code.google.com/p/webraider/" target="_blank">LINK</a></li>
</ul>
<br />Filed under: <a href='http://blog.c22.cc/category/conference/'>Conference</a>, <a href='http://blog.c22.cc/category/security/'>Security</a> Tagged: <a href='http://blog.c22.cc/tag/conference/'>Conference</a>, <a href='http://blog.c22.cc/tag/defcon/'>defcon</a>, <a href='http://blog.c22.cc/tag/oracle/'>oracle</a>, <a href='http://blog.c22.cc/tag/security/'>Security</a>, <a href='http://blog.c22.cc/tag/sql/'>sql</a>, <a href='http://blog.c22.cc/tag/web-applications/'>web applications</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c22blog.wordpress.com/1800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c22blog.wordpress.com/1800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c22blog.wordpress.com/1800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c22blog.wordpress.com/1800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1800/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&amp;blog=1599597&amp;post=1800&amp;subd=c22blog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/07/31/defcon-hacking-oracle-from-web-apps/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/07/dc-18-logo_smsq.png?w=150&#38;h=150" medium="image" />
	</item>
	</channel>
</rss>