<rss version="2.0"><channel><title>Penetration Testing (pen-test) Mailing List</title>
<link>http://seclists.org/#pen-test</link>
<description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: How do VA scans work technically</title><description>Posted by Zed Qyves on Jul 19&lt;p&gt;


&lt;p&gt;
&amp;nbsp;hello,
&lt;br /&gt;
Last time i checked nmap -sV was doing what ask as well  as amap (or
&lt;br /&gt;
vmap - i have a bad memory ).
&lt;br /&gt;
&lt;p&gt;Best regards,
&lt;br /&gt;
Z
&lt;br /&gt;
&lt;p&gt;On 7/9/08, Aseem Kumar &amp;lt;kumaraseem_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Thanks for all the gr8 replies.
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Showing of already remediated...</description>
<link>http://seclists.org/pen-test/2008/Jul/0104.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0104.html</guid>
<pubDate>Sat, 19 Jul 2008 14:33:52 +0300</pubDate></item>
<item><title>VoIP Attacks</title><description>Posted by contebral_at_web.de on Jul 18&lt;p&gt;


&lt;p&gt;
Hello Folks,
&lt;br /&gt;
&lt;p&gt;Classical Attacks vectors against VoIP like SPIT (VOIP SPAM) and VoIP 
&lt;br /&gt;
Phishing are well known and documented. i&#39;m curious if there exists 
&lt;br /&gt;
other client side  attacks against voip that may compromise confidential 
&lt;br /&gt;
calls e.g. Telephon Banking or similar applications.
&lt;br /&gt;
&lt;p&gt;THX
&lt;br /&gt;</description>
<link>http://seclists.org/pen-test/2008/Jul/0103.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0103.html</guid>
<pubDate>Fri, 18 Jul 2008 23:49:23 +0200</pubDate></item>
<item><title>How to get the list of domain admins</title><description>Posted by Shankar Arjunan on Jul 18&lt;p&gt;


&lt;p&gt;
Hi all,
&lt;br /&gt;
&lt;p&gt;Can anyone tell me how to get list of users who are having domain admin 
&lt;br /&gt;
rights in a domain.  I vaguely remember using it through command line 
&lt;br /&gt;
utility net use or net localgroup ..
&lt;br /&gt;
&lt;p&gt;Thanks in advance
&lt;br /&gt;
Shankar 
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;------------------------------------------------------------------------
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2008/Jul/0102.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0102.html</guid>
<pubDate>Fri, 18 Jul 2008 15:22:47 +1000</pubDate></item>
<item><title>Moderator Vacation and pen-test list submissions</title><description>Posted by Erin Carroll on Jul 17&lt;p&gt;


&lt;p&gt;
All,
&lt;br /&gt;
&lt;p&gt;Pete Herzog&#39;s recent email about security vacations reminds me...
&lt;br /&gt;
&lt;p&gt;I will be on vacation from 7/18 - 7/27. While I will occasionally check
&lt;br /&gt;
email for submissions, please be aware that response time may be slow and
&lt;br /&gt;
your pen-test list submissions may time out or not go through. It really
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2008/Jul/0101.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0101.html</guid>
<pubDate>Thu, 17 Jul 2008 16:57:29 -0700</pubDate></item>
<item><title>Security Vacation Guide</title><description>Posted by Pete Herzog on Jul 17&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;We&#39;re feeling summer pretty hard here at ISECOM and thought
&lt;br /&gt;
summer/hacking/vacation - so we put it all together.  So we made a security
&lt;br /&gt;
vacation guide!  Based on all that stuff we hackers loop about when we
&lt;br /&gt;
worry about our stuff! So ISECOM presents: the Home Security Methodology
&lt;br /&gt;
Vacation...</description>
<link>http://seclists.org/pen-test/2008/Jul/0100.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0100.html</guid>
<pubDate>Thu, 17 Jul 2008 23:37:12 +0200</pubDate></item>
<item><title>OSSTMM 3.0 LITE</title><description>Posted by Pete Herzog on Jul 17&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;We have created OSSTMM 3.0 LITE for the DefCon attendees.  It is a smaller, 
&lt;br /&gt;
simpler version of the OSSTMM 3.0 but does include the Data Networking 
&lt;br /&gt;
tests as well as instructions on how to use it.  We will release it 
&lt;br /&gt;
publicly on Aug. 1st on the ISECOM website to coincide with that...</description>
<link>http://seclists.org/pen-test/2008/Jul/0099.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0099.html</guid>
<pubDate>Thu, 17 Jul 2008 19:04:49 +0200</pubDate></item>
<item><title>Re: Wired captive portal pen-test</title><description>Posted by Mario Spinthiras on Jul 17&lt;p&gt;


&lt;p&gt;
I am not sure what kind of captive portal it was. I know for sure that
&lt;br /&gt;
if the administrator limited the dns traffic or performed DPI
&lt;br /&gt;
(cleverly) they could avoid NSTX bypasses. NSTX relies on dns queries
&lt;br /&gt;
solely to be able to bypass CP. However by limiting the amount of DNS
&lt;br /&gt;
queries per IP to a...</description>
<link>http://seclists.org/pen-test/2008/Jul/0098.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0098.html</guid>
<pubDate>Thu, 17 Jul 2008 10:08:29 +0300</pubDate></item>
<item><title>Re: Wired captive portal pen-test</title><description>Posted by Cedric Blancher on Jul 17&lt;p&gt;


&lt;p&gt;
And what about trying to break the web application ? Tons of captive
&lt;br /&gt;
portals fails at web application level, with very simple tricks such as
&lt;br /&gt;
altering parameters on the fly...
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;</description>
<link>http://seclists.org/pen-test/2008/Jul/0097.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0097.html</guid>
<pubDate>Thu, 17 Jul 2008 07:40:36 +0200</pubDate></item>
<item><title>Re: Auditing a Firewall rulebase</title><description>Posted by Meenal Mukadam on Jul 17&lt;p&gt;


&lt;p&gt;
Hello Edgar,
&lt;br /&gt;
&lt;p&gt;Our tool Firesec (http://www.niiconsulting.com/products/Firesec.html) has a
&lt;br /&gt;
feature specifically to convert Cisco PIX configurations to Netscreen. It
&lt;br /&gt;
does this for Cisco ACLs and Objects, and using the Zone Names that you
&lt;br /&gt;
inform us, but we could also tweak it to work with conduit...</description>
<link>http://seclists.org/pen-test/2008/Jul/0096.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0096.html</guid>
<pubDate>Thu, 17 Jul 2008 10:53:56 +0530</pubDate></item>
<item><title>ekoparty security trainings (2008) announcement</title><description>Posted by ekoparty on Jul 17&lt;p&gt;


&lt;p&gt;
ekoparty 4th edition - www.ekoparty.com.ar
&lt;br /&gt;
Information Security/Insecurity Conference.
&lt;br /&gt;
October 2 and 3, 2008
&lt;br /&gt;
Ciudad Autonoma de Buenos Aires - Argentina 
&lt;br /&gt;
&lt;p&gt;What is ekoparty?
&lt;br /&gt;
&lt;p&gt;It&#39;s a one of a kind event in South America; an annual security conference held in Buenos Aires
&lt;br /&gt;
where security...</description>
<link>http://seclists.org/pen-test/2008/Jul/0095.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0095.html</guid>
<pubDate>Thu, 17 Jul 2008 01:28:22 -0300</pubDate></item>
<item><title>RE: Wired captive portal pen-test</title><description>Posted by Sergio Castro on Jul 16&lt;p&gt;


&lt;p&gt;
What I mean is that if he&#39;s not seeing ARP requests, it means there&#39;s a
&lt;br /&gt;
switch-router there, and not a hub.
&lt;br /&gt;
&lt;p&gt;As to MITM, if the switch-router is FULLY secured, it is correct, you cannot
&lt;br /&gt;
launch such attack. But if it has a standard, medium security configuration,
&lt;br /&gt;
such attacks are possible; I do...</description>
<link>http://seclists.org/pen-test/2008/Jul/0094.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0094.html</guid>
<pubDate>Wed, 16 Jul 2008 19:23:44 -0500</pubDate></item>
<item><title>Re: Wired captive portal pen-test</title><description>Posted by Roman Medina-Heigl Hernandez on Jul 17&lt;p&gt;


&lt;p&gt;
Jos&#142;&eacute; M. Palaz&oacute;n Romero escribi&oacute;:
&lt;br /&gt;
&amp;gt; Anyway, I still think they are probably not filtering at layer 2.
&lt;br /&gt;
&lt;p&gt;They are (I think). I had a look to some public computer at the hotel and I 
&lt;br /&gt;
saw its IP. It was in the same subnet used by room&#39;s port. Nevertheless, 
&lt;br /&gt;
when I launched a MAC scan with Cain...</description>
<link>http://seclists.org/pen-test/2008/Jul/0093.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0093.html</guid>
<pubDate>Thu, 17 Jul 2008 00:44:06 +0200</pubDate></item>
<item><title>Re: Wired captive portal pen-test</title><description>Posted by Roman Medina-Heigl Hernandez on Jul 17&lt;p&gt;


&lt;p&gt;
Mario Spinthiras escribi&oacute;:
&lt;br /&gt;
&lt;p&gt;&amp;gt; I managed to successfully beat captive portal with NSTX. As far as
&lt;br /&gt;
&lt;p&gt;Which kind/&amp;quot;brand&amp;quot; of captive portal? As I previously said, NSTX or similar 
&lt;br /&gt;
can be defeated.
&lt;br /&gt;
&lt;p&gt;&amp;gt; vlans are concerned , by default catalysts have auto for trunk modes.
&lt;br /&gt;
&amp;gt; If you...</description>
<link>http://seclists.org/pen-test/2008/Jul/0092.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0092.html</guid>
<pubDate>Thu, 17 Jul 2008 00:32:59 +0200</pubDate></item>
<item><title>Re: Wired captive portal pen-test</title><description>Posted by Jos M. Palazn Romero on Jul 16&lt;p&gt;


&lt;p&gt;
Sergio Castro escribi&oacute;:
&lt;br /&gt;
&amp;gt; So yes, if you only see broadcast ARP requests from the router, the switch
&lt;br /&gt;
&amp;gt; is very likely securely configured.
&lt;br /&gt;
&lt;p&gt;This is incorrect, Sergio. ARP replies are not broadcast, so it&#39;s 
&lt;br /&gt;
perfectly ok that he doesn&#39;t see them.
&lt;br /&gt;
&lt;p&gt;&amp;gt; 
&lt;br /&gt;
&amp;gt; Did you try using Cain? You...</description>
<link>http://seclists.org/pen-test/2008/Jul/0091.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0091.html</guid>
<pubDate>Wed, 16 Jul 2008 09:28:19 +0100</pubDate></item>
<item><title>Re: Auditing a Firewall rulebase</title><description>Posted by econtreras_at_fibertel.com.ar on Jul 16&lt;p&gt;


&lt;p&gt;
hi all..somebody known about a tools o parser for old version of pix software, I need something to see a lots of conduit...or something to translate configuration from pix to netscreen firewall...
&lt;br /&gt;
&lt;p&gt;thank..
&lt;br /&gt;
&lt;p&gt;Edgar Carlos Alberto Contreras
&lt;br /&gt;
&lt;p&gt;----- Mensaje original -----
&lt;br /&gt;
De: arvind doraiswamy...</description>
<link>http://seclists.org/pen-test/2008/Jul/0090.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Jul/0090.html</guid>
<pubDate>Wed, 16 Jul 2008 14:58:44 -0300</pubDate></item>
</channel></rss>