<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: decrypt]]></title>
    <link>http://securityratty.com/tag/decrypt</link>
    <description></description>
    <pubDate>Wed, 30 Apr 2008 09:54:37 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Anti-theft Protocols]]></title>
      <link>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</link>
      <guid>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</guid>
      <description><![CDATA[At last Fridays Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong
Examples include
GSM mobile phones have...]]></description>
      <content:encoded><![CDATA[<p>At last Friday&#8217;s Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong.</p>
<p>Examples include:</p>
<ul>
<li>GSM mobile phones have an identifier for the phone (separate from the identifier for the user) that can be blacklisted when the phone is stolen.</li>
<li>Some car radios will stop working when the battery is disconnected, and only start working again when a numeric code is entered. This is intended to deter theft of the radio.</li>
<li>In Windows Vista, Bitlocker can be used to encrypt files. One of  the intended applications for this is that if someone steals your laptop, it will be difficult for them to gain access to your encrypted files.</li>
</ul>
<p>Ross told a story of what happened when he needed to disconnect the battery on his car: the radio stopped working, and the code he had been given to reactivate it didn&#8217;t work - it was the wrong code.<br />
Ross argues that these reactivation codes are unecessary, because other measures taken by the car manufacturers - such as making radios non-standard sizes, and hence not refittable in other car models - have made them redundant.</p>
<p>I described how the motherboard on a laptop had needed to be replaced recently. The motherboard contains the TPM chip, which contains the encryption keys needed to decrypt files protected with Bitlocker. If you replace the motherboard, the files on your hard disk will become unreadable, even if the disk is physically OK. Domain-joined Vista machines can be configured so that a sysadmin somewhere within your organization is able to recover the keys when this happens.</p>
<p>Both of these situations suffer from classic usability problems: the recovery procedures are invoked rarely (so users may not know what they&#8217;re supposed to do), and, if your system is configured incorrectly, you only find out when it is <i>too late</i>: you key in the code to your radio and it remains a doorstop; the admin you hoped was escrowing your keys turns out not to have the private key corresponding to the public key you were encrypting under (or, more subtly: the person with the authority to ask for your laptop&#8217;s key to be recovered is not you, because the appropriate admin has the <i>wrong name</i> for the laptop&#8217;s owner in their database).</p>
<p>I also described what happens when an XBox 360 is stolen. When you buy XBox downloadable content, you buy <i>two</i> licenses: one that&#8217;s valid on any XBox, as long as you&#8217;re logged in to XBox live; and one that&#8217;s valid on just your XBox, regardless of who&#8217;s logged in. If a burglar steals your Xbox, and you buy a new one, you need to get another license of the <i>second</i> type (for all the other people in your household who make use of it). The software makes this awkward, because it knows that you already have a license of the <i>first</i> type, and assumes that you couldn&#8217;t possibly want to buy it again. The work-around is to get a new email address, a new Microsoft Live Account, and a new Gamer Tag, and use these to repurchase the license. You can&#8217;t just change the gamertag, because XBox live doesn&#8217;t let the same Microsoft Live account have two gamertags. And yes, I know, your buddies in the MMORPG you were playing know you by your gamertag, so you don&#8217;t want to change it.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:18:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xbox">xbox</category>
      <category domain="http://securityratty.com/tag/xbox downloadable content">xbox downloadable content</category>
      <category domain="http://securityratty.com/tag/wrong code">wrong code</category>
      <category domain="http://securityratty.com/tag/xbox live">xbox live</category>
      <category domain="http://securityratty.com/tag/wrong">wrong</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/car radios">car radios</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/microsoft live account">microsoft live account</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/03/anti-theft-protocols/">Anti-theft Protocols</source>
    </item>
    <item>
      <title><![CDATA[Skype won't say if it decrypts VoIP calls]]></title>
      <link>http://securityratty.com/article/389aba2e3aca7e86ca4e583f3e4db646</link>
      <guid>http://securityratty.com/article/389aba2e3aca7e86ca4e583f3e4db646</guid>
      <description><![CDATA[Skype has reportedly taken extreme measures to prevent reverse engineering of its client software to determine the details of its encrypted network traffic and whether or not keys are available to...]]></description>
      <content:encoded><![CDATA[Skype has reportedly taken extreme measures to prevent reverse engineering of its client software to determine the details of its encrypted network traffic and whether or not keys are available to decrypt and listen in on phone calls -- although one report says Austrian officials have had no problem in legally tapping in on some calls.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=XvuYhG"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=XvuYhG" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/356531733" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/calls">calls</category>
      <category domain="http://securityratty.com/tag/phone calls">phone calls</category>
      <category domain="http://securityratty.com/tag/network traffic">network traffic</category>
      <category domain="http://securityratty.com/tag/client software">client software</category>
      <category domain="http://securityratty.com/tag/extreme measures">extreme measures</category>
      <category domain="http://securityratty.com/tag/prevent reverse">prevent reverse</category>
      <category domain="http://securityratty.com/tag/austrian officials">austrian officials</category>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/determine">determine</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/356531733/article.do">Skype won't say if it decrypts VoIP calls</source>
    </item>
    <item>
      <title><![CDATA[Data security and the "chasm of protection"]]></title>
      <link>http://securityratty.com/article/4d8814123796ce17262a597ce9e74198</link>
      <guid>http://securityratty.com/article/4d8814123796ce17262a597ce9e74198</guid>
      <description><![CDATA[I was thinking a bit more about the notion of data-centric or information-centric security and why this is absolutely the future of data protection

Say you are a retailer. You have data in your POS...]]></description>
      <content:encoded><![CDATA[I was thinking a bit more about the notion of data-centric or information-centric security and why this is absolutely the future of data protection...<br /><br />Say you are a retailer. You have data in your POS devices, encrypted with the POS application as cards are read in. As this data is required by another application, it has to be first decrypted so this in-store application can read it. It may then encrypt it again as it stores on in-store servers. Now assume you have another application in the data centers that is used for card settlement. Another decrypt-encrypt cycle from the store to the data-center!<br /><br />This scenario is not limited to a retail environment. Consider a similar cycle repeating itself in most companies as data is moved from location to location, analyzed and processed by multiple applications and on multiple devices and multiple internal and external networks - each time being decrypted, stored or transfered in the clear till it gets encrypted again. Each time this cycle repeats, there is a weakness that can be exploited - since there is a gap in the consistent protection of data.<br /><br />Being data-centric however, brings in persistence and consistency in the protection of that data element, thereby removing this "chasm".<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=QfKJCI"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=QfKJCI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=xy1hui"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=xy1hui" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=RpA5rI"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=RpA5rI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/313804028" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 09:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data protection">data protection</category>
      <category domain="http://securityratty.com/tag/data centers">data centers</category>
      <category domain="http://securityratty.com/tag/data element">data element</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/pos application">pos application</category>
      <category domain="http://securityratty.com/tag/data-centric">data-centric</category>
      <category domain="http://securityratty.com/tag/in-store application">in-store application</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/313804028/data-security-and-chasm-of-protection.html">Data security and the "chasm of protection"</source>
    </item>
    <item>
      <title><![CDATA[Are we going to need TSA backdoors to encryption]]></title>
      <link>http://securityratty.com/article/34a9617ec1117ace01a60bf08dd172a2</link>
      <guid>http://securityratty.com/article/34a9617ec1117ace01a60bf08dd172a2</guid>
      <description><![CDATA[I was reading an article in Information Week tonight about a case going to the 9th Circuit Court of Appeals about the governments right to search, seize and copy laptops and other electronic devices...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=500,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/06/14/tsa_gif.gif"><img title="Tsa_gif" height="200" alt="Tsa_gif" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/06/14/tsa_gif.gif" width="200" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></a>I was reading an <a href="http://www.informationweek.com/news/security/client/showArticle.jhtml;jsessionid=0OJGJHNEJVRQYQSNDLPCKH0CJUNN2JVN?articleID=208403992">article in Information Week</a> tonight about a case going to the <a class="zem_slink" title="United States Court of Appeals for the Ninth Circuit" href="http://en.wikipedia.org/wiki/United_States_Court_of_Appeals_for_the_Ninth_Circuit" rel="wikipedia">9th Circuit Court of Appeals</a> about the governments right to search, seize and copy laptops and other electronic devices at our borders.&nbsp; Two groups that don't often find themselves on the same side of issues, the <a class="zem_slink" title="Electronic Frontier Foundation" href="http://www.eff.org/" rel="homepage">Electronic Frontier Foundation</a> (EFF) and the <a class="zem_slink" title="Association of Corporate Travel Executives" href="http://en.wikipedia.org/wiki/Association_of_Corporate_Travel_Executives" rel="wikipedia">Association of Corporate Travel Executives</a> (ACTE) have filed briefs with the court asking them to strike down a lower courts ruling that granted the government these broad powers to confiscate laptops. </p>

<p>As the article points out here in the US there was quite an uproar about China &quot;slurping&quot; laptops from people on travel there, but we seem to think it is OK for our government to do it.&nbsp; Well at least our government is telling people they are doing it.&nbsp; What they are not telling us is what they are doing with the data after they search or copy it.&nbsp; How do we know, no US security but nevertheless confidential data is being secured and or destroyed promptly?&nbsp; The government telling us &quot;trust me&quot; just doesn't cut it.</p>

<p>However, I think technology is going to pose a bigger problem for the government regardless of whether the court upholds the governments position. I think any terrorist or other bad guy would never have confidential data on their laptop that is not encrypted.&nbsp; In fact with <a class="zem_slink" title="Full disk encryption" href="http://en.wikipedia.org/wiki/Full_disk_encryption" rel="wikipedia">full disk encryption</a> coming to the masses from the likes of <a href="http://www.investors.com/editorial/IBDArticles.asp?artsec=17&amp;artnum=1&amp;issue=20080612">McAfee</a> and others, what will the government do?&nbsp; Sure they can take the encrypted data to the <a class="zem_slink" title="National Security Agency" href="http://en.wikipedia.org/wiki/National_Security_Agency" rel="wikipedia">NSA</a> and let them brute force the keys, but that sounds impractical.&nbsp; Perhaps, the <a class="zem_slink" title="Transportation Security Administration" href="http://www.dhs.gov/xabout/structure/biography_0127.shtm" rel="homepage">TSA</a> will demand encryption vendors to put in a back door or secret key that will allow the TSA to decrypt the data similar to what they do with the special luggage locks now.</p>

<p>I know what they can do. Perhaps they can go back to Checkpoint and find out for sure about those back doors that they always suspected was in their software and see if it is there for sure. If so the government can appoint Checkpoint the official encryption vendor for laptops ;-)&nbsp; Just kidding of course, but really guys.&nbsp; What self-respecting bad guy is not going to encrypt their data knowing the government has a right to search their laptop.&nbsp; I think it makes this whole case much ado about nothing.</p>

<fieldset class="zemanta-related"><legend>Related articles</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a title="Open in new window" href="http://arstechnica.com/news.ars/post/20080613-eff-others-fighting-privacy-invading-border-laptop-searches.html">EFF, others fighting privacy-invading border laptop searches</a> [via Zemanta] </li>

<li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.infoworld.com/article/08/06/12/Groups_ask_court_to_review_laptop_searches_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/06/12/Groups_ask_court_to_review_laptop_searches_1.html">Groups ask court to review laptop searches</a> [via Zemanta] </li>

<li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9081358&amp;source=rss_topic84">Travel group warns: Corporate data at risk from laptop searches at border</a> [via Zemanta] </li>

<li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.theregister.co.uk/2008/05/01/electronic_searches_at_us_borders/">Your personal data just got permanently cached at the US border</a> [via Zemanta]</li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/b3d4a62d-49a0-41e1-850c-b66d8a6605b7/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=b3d4a62d-49a0-41e1-850c-b66d8a6605b7" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Sun, 15 Jun 2008 06:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/confidential data">confidential data</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/court">court</category>
      <category domain="http://securityratty.com/tag/border laptop">border laptop</category>
      <category domain="http://securityratty.com/tag/9th circuit court">9th circuit court</category>
      <category domain="http://securityratty.com/tag/border">border</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/are-we-going-to.html">Are we going to need TSA backdoors to encryption</source>
    </item>
    <item>
      <title><![CDATA[Are we going to need TSA backdoors to encryption]]></title>
      <link>http://securityratty.com/article/0ab5682f7ef222e5d625f7a5a92d5112</link>
      <guid>http://securityratty.com/article/0ab5682f7ef222e5d625f7a5a92d5112</guid>
      <description><![CDATA[I was reading an article in Information Week tonight about a case going to the 9th Circuit Court of Appeals about the governments right to search, seize and copy laptops and other electronic devices...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=500,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/06/14/tsa_gif.gif"><img title="Tsa_gif" height="200" alt="Tsa_gif" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/06/14/tsa_gif.gif" width="200" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px" /></a>I was reading an <a href="http://www.informationweek.com/news/security/client/showArticle.jhtml;jsessionid=0OJGJHNEJVRQYQSNDLPCKH0CJUNN2JVN?articleID=208403992">article in Information Week</a> tonight about a case going to the <a class="zem_slink" title="United States Court of Appeals for the Ninth Circuit" href="http://en.wikipedia.org/wiki/United_States_Court_of_Appeals_for_the_Ninth_Circuit" rel="wikipedia">9th Circuit Court of Appeals</a> about the governments right to search, seize and copy laptops and other electronic devices at our borders.&nbsp; Two groups that don't often find themselves on the same side of issues, the <a class="zem_slink" title="Electronic Frontier Foundation" href="http://www.eff.org/" rel="homepage">Electronic Frontier Foundation</a> (EFF) and the <a class="zem_slink" title="Association of Corporate Travel Executives" href="http://en.wikipedia.org/wiki/Association_of_Corporate_Travel_Executives" rel="wikipedia">Association of Corporate Travel Executives</a> (ACTE) have filed briefs with the court asking them to strike down a lower courts ruling that granted the government these broad powers to confiscate laptops. </p>

<p>As the article points out here in the US there was quite an uproar about China &quot;slurping&quot; laptops from people on travel there, but we seem to think it is OK for our government to do it.&nbsp; Well at least our government is telling people they are doing it.&nbsp; What they are not telling us is what they are doing with the data after they search or copy it.&nbsp; How do we know, no US security but nevertheless confidential data is being secured and or destroyed promptly?&nbsp; The government telling us &quot;trust me&quot; just doesn't cut it.</p>

<p>However, I think technology is going to pose a bigger problem for the government regardless of whether the court upholds the governments position. I think any terrorist or other bad guy would never have confidential data on their laptop that is not encrypted.&nbsp; In fact with <a class="zem_slink" title="Full disk encryption" href="http://en.wikipedia.org/wiki/Full_disk_encryption" rel="wikipedia">full disk encryption</a> coming to the masses from the likes of <a href="http://www.investors.com/editorial/IBDArticles.asp?artsec=17&amp;artnum=1&amp;issue=20080612">McAfee</a> and others, what will the government do?&nbsp; Sure they can take the encrypted data to the <a class="zem_slink" title="National Security Agency" href="http://en.wikipedia.org/wiki/National_Security_Agency" rel="wikipedia">NSA</a> and let them brute force the keys, but that sounds impractical.&nbsp; Perhaps, the <a class="zem_slink" title="Transportation Security Administration" href="http://www.dhs.gov/xabout/structure/biography_0127.shtm" rel="homepage">TSA</a> will demand encryption vendors to put in a back door or secret key that will allow the TSA to decrypt the data similar to what they do with the special luggage locks now.</p>

<p>I know what they can do. Perhaps they can go back to Checkpoint and find out for sure about those back doors that they always suspected was in their software and see if it is there for sure. If so the government can appoint Checkpoint the official encryption vendor for laptops ;-)&nbsp; Just kidding of course, but really guys.&nbsp; What self-respecting bad guy is not going to encrypt their data knowing the government has a right to search their laptop.&nbsp; I think it makes this whole case much ado about nothing.</p>

<fieldset class="zemanta-related"><legend>Related articles</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a title="Open in new window" href="http://arstechnica.com/news.ars/post/20080613-eff-others-fighting-privacy-invading-border-laptop-searches.html">EFF, others fighting privacy-invading border laptop searches</a> [via Zemanta] </li>

<li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.infoworld.com/article/08/06/12/Groups_ask_court_to_review_laptop_searches_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/06/12/Groups_ask_court_to_review_laptop_searches_1.html">Groups ask court to review laptop searches</a> [via Zemanta] </li>

<li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9081358&amp;source=rss_topic84">Travel group warns: Corporate data at risk from laptop searches at border</a> [via Zemanta] </li>

<li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.theregister.co.uk/2008/05/01/electronic_searches_at_us_borders/">Your personal data just got permanently cached at the US border</a> [via Zemanta]</li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/b3d4a62d-49a0-41e1-850c-b66d8a6605b7/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=b3d4a62d-49a0-41e1-850c-b66d8a6605b7" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=9QdPcw"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=9QdPcw" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=a8DmfI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=a8DmfI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qPN5oI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qPN5oI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=n711oI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=n711oI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=IdVxLI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=IdVxLI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DHU4Gi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DHU4Gi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=gQSH3i"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=gQSH3i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/312412818" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 15 Jun 2008 05:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/confidential data">confidential data</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/court">court</category>
      <category domain="http://securityratty.com/tag/border laptop">border laptop</category>
      <category domain="http://securityratty.com/tag/9th circuit court">9th circuit court</category>
      <category domain="http://securityratty.com/tag/border">border</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/312412818/are-we-going-to.html">Are we going to need TSA backdoors to encryption</source>
    </item>
    <item>
      <title><![CDATA[Who's Behind the GPcode Ransomware?]]></title>
      <link>http://securityratty.com/article/ca714951a7f0ed968deff599e2b3b644</link>
      <guid>http://securityratty.com/article/ca714951a7f0ed968deff599e2b3b644</guid>
      <description><![CDATA[So, the ultimate question - who's behind the GPcode ransomware? It's Russian teens with pimples, using E-gold and Liberty Reserve accounts, running three different GPcode campaigns, two of which...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SE495ZBcN4I/AAAAAAAABx4/M-eDO1J91xY/s1600-h/GPcode_decryptor.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SE495ZBcN4I/AAAAAAAABx4/M-eDO1J91xY/s200/GPcode_decryptor.JPG" alt="" id="BLOGGER_PHOTO_ID_5210169875093010306" border="0" /></a>So, the ultimate question - <a href="http://blogs.zdnet.com/security/?p=1259">who's behind the GPcode ransomware?</a> It's Russian teens with pimples, using E-gold and Liberty Reserve accounts, running three different GPcode campaigns, two of which request either $100 or $200 for the decryptor, and communicating from Chinese IPs. Here are all the details regarding the emails they use, the email responses they sent back, the currency accounts, as well their most recent IPs used in the communication :<br /><br /><span style="font-weight: bold;">Emails used by the GPcode authors where the infected victims are supposed to contact them :</span><br />content715@yahoo.com<br />saveinfo89@yahoo.com<br />cipher4000@yahoo.com<br />decrypt482@yahoo.com<br /><br /><span style="font-weight: bold;">Virtual currency accounts used by the malware authors :</span><br />Liberty Reserve - account U6890784<br />E-Gold - account - 5431725<br />E-Gold - account - 5437838<br /><br /><span style="font-weight: bold;">Sample response email :</span><br />"<span style="font-style: italic;">Next, you should send $100 to Liberty Reserve account U6890784 or E-Gold account 5431725 (www.e-gold.com) To buy E-currency you may use exchange service, see or any other.</span><span style="font-style: italic;"> In the transfer description specify your e-mail. After receive your payment, we send decryptor to your e-mail. For check our guarantee you may send us one any encrypted file (with cipher key, specified in any !_READ_ME_!.txt file, being in the  directorys with the encrypted files). We decrypt it and send to you originally decrypted file.</span><span style="font-style: italic;"> Best Regards,</span><span style="font-style: italic;"> Daniel Robertson</span>"<br /><br /><span style="font-weight: bold;">Second sample response email this time requesting $200 :</span><br />"<span style="font-style: italic;">The price of decryptor is 200 USD. For  payment you may use one of following variants: 1. Payment  to E-Gold account 5437838 (www.e-gold.com). 2. Payment  to  Liberty Reserve account U6890784 (www.libertyreserve.com). 3. If you do not make one of this variants, contact us for decision it. For check our guarantee you may send us ONE any encrypted file. We decrypt it and send to you originally decrypted file. For any questions contact us via e-mail.</span><span style="font-style: italic;"> Best regards.</span><span style="font-style: italic;"> Paul Dyke</span>"<br /><br />So, you've got two people responding back with copy and paste emails, each of them seeking a different amount of money? Weird. The John Dow-ish Daniel Robertson is emailing from <span style="font-weight: bold;">58.38.8.211 </span>(<span style="font-style: italic;">Liaoning Province Network China Network Communications Group Corporation No.156,Fu-Xing-Men-Nei Street, Beijing 100031</span>), and Paul Dyke from <span style="font-weight: bold;">221.201.2.227</span>(<span style="font-style: italic;">Liaoning Province Network China Network Communications Group Corporation No.156,Fu-Xing-Men-Nei Street, Beijing 100031</span>), both Chinese IPs, despite that these campaigners are Russians.<br /><br />Here are some comments I made regarding cryptoviral extortion two years ago - <a href="http://packetstormsecurity.org/papers/general/malware-trends.pdf">Future Trends of Malware</a> (on page 11; and page 21), worth going through.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GmnlTI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GmnlTI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=EA8UEI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=EA8UEI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ntMnXi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ntMnXi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IBBYUi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IBBYUi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=p04dRI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=p04dRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=InZL2I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=InZL2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wUefAi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wUefAi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/308816792" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 10 Jun 2008 05:44:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/e-gold account">e-gold account</category>
      <category domain="http://securityratty.com/tag/e-gold">e-gold</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/sample response email">sample response email</category>
      <category domain="http://securityratty.com/tag/txt file">txt file</category>
      <category domain="http://securityratty.com/tag/virtual currency accounts">virtual currency accounts</category>
      <category domain="http://securityratty.com/tag/liberty reserve accounts">liberty reserve accounts</category>
      <category domain="http://securityratty.com/tag/liberty reserve">liberty reserve</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/308816792/whos-behind-gpcode-ransomware.html">Who's Behind the GPcode Ransomware?</source>
    </item>
    <item>
      <title><![CDATA[BackTrack Beta 3 Man Pages]]></title>
      <link>http://securityratty.com/article/b9eb1399244230ecdd46be371f407fe7</link>
      <guid>http://securityratty.com/article/b9eb1399244230ecdd46be371f407fe7</guid>
      <description><![CDATA[I've decide to covert the man pages that come with the BackTrack Beta 3 Live CD to HTML and post them to my site. I've just done the ones in /usr/local/man, so expect a few bad links. This will make...]]></description>
      <content:encoded><![CDATA[I've decide to covert the man pages that come with the BackTrack Beta 3 Live CD to HTML and post them to my site. I've just done the ones in /usr/local/man, so expect a few bad links. This will make it easier for me to link to the man pages from my other videos and articles. Tools include in the list are:<br>
<a href="http://irongeek.com/i.php?page=backtrack-3-man/aircrack-ng">aircrack-ng</a>,
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airdecap-ng">airdecap-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airdriver-ng">airdriver-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/aireplay-ng">aireplay-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airmon-ng">airmon-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airodump-ng">airodump-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airolib-ng">airolib-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airpwn">airpwn</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airsev-ng">airsev-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airsnort">airsnort</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airtun-ng">airtun-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/amap">amap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ascii-xfr">ascii-xfr</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/atftp">atftp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/bison">bison</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/bsqldb">bsqldb</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/buddy-ng">buddy-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/cabextract">cabextract</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/catdoc">catdoc</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/catppt">catppt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/datacopy">datacopy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dcfldd">dcfldd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/decrypt">decrypt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/defncopy">defncopy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dhcpdump">dhcpdump</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dmitry">dmitry</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dos2unix">dos2unix</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dupemap">dupemap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/easside-ng">easside-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etherape">etherape</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/flex">flex</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/foremost">foremost</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/freebcp">freebcp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/gencases">gencases</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/getattach.pl">getattach.pl</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hexedit">hexedit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/httpcapture">httpcapture</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ike-scan">ike-scan</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ivstools">ivstools</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/kstats">kstats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mac2unix">mac2unix</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/macchanger">macchanger</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/magicrescue">magicrescue</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/magicsort">magicsort</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/makeivs-ng">makeivs-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mboxgrep">mboxgrep</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/minicom">minicom</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-arp">nemesis-arp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-dns">nemesis-dns</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ethernet">nemesis-ethernet</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-icmp">nemesis-icmp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-igmp">nemesis-igmp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ip">nemesis-ip</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ospf">nemesis-ospf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-rip">nemesis-rip</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-tcp">nemesis-tcp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-udp">nemesis-udp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis">nemesis</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/netcat">netcat</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nmap">nmap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nmapfe">nmapfe</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/obexftp">obexftp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/obexftpd">obexftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/p0f">p0f</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/packetforge-ng">packetforge-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/psk-crack">psk-crack</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/rain">rain</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/runscript">runscript</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-config">scrollkeeper-config</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-gen-seriesid">scrollkeeper-gen-seriesid</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sipsak">sipsak</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/socat">socat</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcptraceroute">tcptraceroute</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/truecrypt">truecrypt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tsql">tsql</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/unicornscan">unicornscan</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/vomit">vomit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wesside-ng">wesside-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wordview">wordview</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xls2csv">xls2csv</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xminicom">xminicom</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xnmap">xnmap</a>, 			<a href="http://irongeek.com/i.php?page=backtrack-3-man/gdbm">gdbm</a>, 
		<a href="http://irongeek.com/i.php?page=backtrack-3-man/etter.conf">etter.conf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper.conf">scrollkeeper.conf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudoers">sudoers</a>, 			
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper">scrollkeeper</a>,&nbsp; <a href="http://irongeek.com/i.php?page=backtrack-3-man/80211debug">80211debug</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/80211stats">80211stats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/arpspoof">arpspoof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/atftpd">atftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athchans">athchans</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athctrl">athctrl</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athdebug">athdebug</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athkey">athkey</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athstats">athstats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ath_info">ath_info</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dnsspoof">dnsspoof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dnstracer">dnstracer</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dsniff">dsniff</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap">ettercap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap_curses">ettercap_curses</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap_plugins">ettercap_plugins</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etterfilter">etterfilter</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etterlog">etterlog</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/filesnarf">filesnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fping">fping</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fragroute">fragroute</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fragtest">fragtest</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hping2">hping2</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hping3">hping3</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/in.tftpd">in.tftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/macof">macof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mailsnarf">mailsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/msgsnarf">msgsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/netdiscover">netdiscover</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/packit">packit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-preinstall">scrollkeeper-preinstall</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-rebuilddb">scrollkeeper-rebuilddb</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-update">scrollkeeper-update</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sing">sing</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sshmitm">sshmitm</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sshow">sshow</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudo">sudo</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudoedit">sudoedit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpick">tcpick</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpick_italian">tcpick_italian</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpkill">tcpkill</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpnice">tcpnice</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tinyproxy">tinyproxy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/urlsnarf">urlsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/visudo">visudo</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/webmitm">webmitm</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/webspy">webspy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wlanconfig">wlanconfig</a><p>
Enjoy.]]></content:encoded>
      <pubDate>Mon, 19 May 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nemesis">nemesis</category>
      <category domain="http://securityratty.com/tag/nemesis-ip">nemesis-ip</category>
      <category domain="http://securityratty.com/tag/nemesis-rip">nemesis-rip</category>
      <category domain="http://securityratty.com/tag/nemesis-igmp">nemesis-igmp</category>
      <category domain="http://securityratty.com/tag/nemesis-icmp">nemesis-icmp</category>
      <category domain="http://securityratty.com/tag/nemesis-arp">nemesis-arp</category>
      <category domain="http://securityratty.com/tag/nemesis-tcp">nemesis-tcp</category>
      <category domain="http://securityratty.com/tag/ettercap plugins">ettercap plugins</category>
      <category domain="http://securityratty.com/tag/ettercap">ettercap</category>
      <source url="http://irongeek.com/i.php?page=backtrack-3-man/list">BackTrack Beta 3 Man Pages</source>
    </item>
    <item>
      <title><![CDATA[BackTrack Beta 3 Man Pages]]></title>
      <link>http://securityratty.com/article/40186d92f5cac8291c8e4722ba6916a4</link>
      <guid>http://securityratty.com/article/40186d92f5cac8291c8e4722ba6916a4</guid>
      <description><![CDATA[I've decide to covert the man pages that come with the BackTrack Beta 3 Live CD to HTML and post them to my site. I've just done the ones in /usr/local/man, so expect a few bad links. This will make...]]></description>
      <content:encoded><![CDATA[I've decide to covert the man pages that come with the BackTrack Beta 3 Live CD to HTML and post them to my site. I've just done the ones in /usr/local/man, so expect a few bad links. This will make it easier for me to link to the man pages from my other videos and articles. Tools include in the list are:<br>
<a href="http://irongeek.com/i.php?page=backtrack-3-man/aircrack-ng">aircrack-ng</a>,
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airdecap-ng">airdecap-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airdriver-ng">airdriver-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/aireplay-ng">aireplay-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airmon-ng">airmon-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airodump-ng">airodump-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airolib-ng">airolib-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airpwn">airpwn</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airsev-ng">airsev-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airsnort">airsnort</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airtun-ng">airtun-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/amap">amap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ascii-xfr">ascii-xfr</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/atftp">atftp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/bison">bison</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/bsqldb">bsqldb</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/buddy-ng">buddy-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/cabextract">cabextract</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/catdoc">catdoc</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/catppt">catppt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/datacopy">datacopy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dcfldd">dcfldd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/decrypt">decrypt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/defncopy">defncopy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dhcpdump">dhcpdump</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dmitry">dmitry</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dos2unix">dos2unix</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dupemap">dupemap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/easside-ng">easside-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etherape">etherape</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/flex">flex</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/foremost">foremost</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/freebcp">freebcp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/gencases">gencases</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/getattach.pl">getattach.pl</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hexedit">hexedit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/httpcapture">httpcapture</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ike-scan">ike-scan</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ivstools">ivstools</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/kstats">kstats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mac2unix">mac2unix</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/macchanger">macchanger</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/magicrescue">magicrescue</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/magicsort">magicsort</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/makeivs-ng">makeivs-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mboxgrep">mboxgrep</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/minicom">minicom</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-arp">nemesis-arp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-dns">nemesis-dns</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ethernet">nemesis-ethernet</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-icmp">nemesis-icmp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-igmp">nemesis-igmp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ip">nemesis-ip</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ospf">nemesis-ospf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-rip">nemesis-rip</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-tcp">nemesis-tcp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-udp">nemesis-udp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis">nemesis</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/netcat">netcat</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nmap">nmap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nmapfe">nmapfe</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/obexftp">obexftp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/obexftpd">obexftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/p0f">p0f</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/packetforge-ng">packetforge-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/psk-crack">psk-crack</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/rain">rain</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/runscript">runscript</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-config">scrollkeeper-config</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-gen-seriesid">scrollkeeper-gen-seriesid</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sipsak">sipsak</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/socat">socat</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcptraceroute">tcptraceroute</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/truecrypt">truecrypt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tsql">tsql</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/unicornscan">unicornscan</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/vomit">vomit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wesside-ng">wesside-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wordview">wordview</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xls2csv">xls2csv</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xminicom">xminicom</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xnmap">xnmap</a>, 			<a href="http://irongeek.com/i.php?page=backtrack-3-man/gdbm">gdbm</a>, 
		<a href="http://irongeek.com/i.php?page=backtrack-3-man/etter.conf">etter.conf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper.conf">scrollkeeper.conf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudoers">sudoers</a>, 			
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper">scrollkeeper</a>,&nbsp; <a href="http://irongeek.com/i.php?page=backtrack-3-man/80211debug">80211debug</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/80211stats">80211stats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/arpspoof">arpspoof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/atftpd">atftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athchans">athchans</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athctrl">athctrl</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athdebug">athdebug</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athkey">athkey</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athstats">athstats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ath_info">ath_info</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dnsspoof">dnsspoof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dnstracer">dnstracer</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dsniff">dsniff</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap">ettercap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap_curses">ettercap_curses</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap_plugins">ettercap_plugins</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etterfilter">etterfilter</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etterlog">etterlog</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/filesnarf">filesnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fping">fping</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fragroute">fragroute</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fragtest">fragtest</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hping2">hping2</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hping3">hping3</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/in.tftpd">in.tftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/macof">macof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mailsnarf">mailsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/msgsnarf">msgsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/netdiscover">netdiscover</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/packit">packit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-preinstall">scrollkeeper-preinstall</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-rebuilddb">scrollkeeper-rebuilddb</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-update">scrollkeeper-update</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sing">sing</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sshmitm">sshmitm</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sshow">sshow</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudo">sudo</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudoedit">sudoedit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpick">tcpick</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpick_italian">tcpick_italian</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpkill">tcpkill</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpnice">tcpnice</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tinyproxy">tinyproxy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/urlsnarf">urlsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/visudo">visudo</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/webmitm">webmitm</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/webspy">webspy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wlanconfig">wlanconfig</a><p>
Enjoy.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=K4OapG"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=K4OapG" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/297640134" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 19 May 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nemesis">nemesis</category>
      <category domain="http://securityratty.com/tag/nemesis-ip">nemesis-ip</category>
      <category domain="http://securityratty.com/tag/nemesis-rip">nemesis-rip</category>
      <category domain="http://securityratty.com/tag/nemesis-igmp">nemesis-igmp</category>
      <category domain="http://securityratty.com/tag/nemesis-icmp">nemesis-icmp</category>
      <category domain="http://securityratty.com/tag/nemesis-arp">nemesis-arp</category>
      <category domain="http://securityratty.com/tag/nemesis-tcp">nemesis-tcp</category>
      <category domain="http://securityratty.com/tag/ettercap plugins">ettercap plugins</category>
      <category domain="http://securityratty.com/tag/ettercap">ettercap</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/297640134/i.php">BackTrack Beta 3 Man Pages</source>
    </item>
    <item>
      <title><![CDATA[BackTrack Beta 3 Man Pages]]></title>
      <link>http://securityratty.com/article/63d7f5627adffa428f0b54d6c4117e28</link>
      <guid>http://securityratty.com/article/63d7f5627adffa428f0b54d6c4117e28</guid>
      <description><![CDATA[I've decide to covert the man pages that come with the BackTrack Beta 3 Live CD to HTML and post them to my site. I've just done the ones in /usr/local/man, so expect a few bad links. This will make...]]></description>
      <content:encoded><![CDATA[I've decide to covert the man pages that come with the BackTrack Beta 3 Live CD to HTML and post them to my site. I've just done the ones in /usr/local/man, so expect a few bad links. This will make it easier for me to link to the man pages from my other videos and articles. Tools include in the list are:<br>
<a href="http://irongeek.com/i.php?page=backtrack-3-man/aircrack-ng">aircrack-ng</a>,
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airdecap-ng">airdecap-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airdriver-ng">airdriver-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/aireplay-ng">aireplay-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airmon-ng">airmon-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airodump-ng">airodump-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airolib-ng">airolib-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airpwn">airpwn</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airsev-ng">airsev-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airsnort">airsnort</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/airtun-ng">airtun-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/amap">amap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ascii-xfr">ascii-xfr</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/atftp">atftp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/bison">bison</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/bsqldb">bsqldb</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/buddy-ng">buddy-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/cabextract">cabextract</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/catdoc">catdoc</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/catppt">catppt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/datacopy">datacopy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dcfldd">dcfldd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/decrypt">decrypt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/defncopy">defncopy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dhcpdump">dhcpdump</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dmitry">dmitry</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dos2unix">dos2unix</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dupemap">dupemap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/easside-ng">easside-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etherape">etherape</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/flex">flex</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/foremost">foremost</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/freebcp">freebcp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/gencases">gencases</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/getattach.pl">getattach.pl</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hexedit">hexedit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/httpcapture">httpcapture</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ike-scan">ike-scan</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ivstools">ivstools</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/kstats">kstats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mac2unix">mac2unix</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/macchanger">macchanger</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/magicrescue">magicrescue</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/magicsort">magicsort</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/makeivs-ng">makeivs-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mboxgrep">mboxgrep</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/minicom">minicom</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-arp">nemesis-arp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-dns">nemesis-dns</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ethernet">nemesis-ethernet</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-icmp">nemesis-icmp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-igmp">nemesis-igmp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ip">nemesis-ip</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-ospf">nemesis-ospf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-rip">nemesis-rip</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-tcp">nemesis-tcp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis-udp">nemesis-udp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nemesis">nemesis</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/netcat">netcat</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nmap">nmap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/nmapfe">nmapfe</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/obexftp">obexftp</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/obexftpd">obexftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/p0f">p0f</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/packetforge-ng">packetforge-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/psk-crack">psk-crack</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/rain">rain</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/runscript">runscript</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-config">scrollkeeper-config</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-gen-seriesid">scrollkeeper-gen-seriesid</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sipsak">sipsak</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/socat">socat</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcptraceroute">tcptraceroute</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/truecrypt">truecrypt</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tsql">tsql</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/unicornscan">unicornscan</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/vomit">vomit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wesside-ng">wesside-ng</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wordview">wordview</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xls2csv">xls2csv</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xminicom">xminicom</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/xnmap">xnmap</a>, 			<a href="http://irongeek.com/i.php?page=backtrack-3-man/gdbm">gdbm</a>, 
		<a href="http://irongeek.com/i.php?page=backtrack-3-man/etter.conf">etter.conf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper.conf">scrollkeeper.conf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudoers">sudoers</a>, 			
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper">scrollkeeper</a>,&nbsp; <a href="http://irongeek.com/i.php?page=backtrack-3-man/80211debug">80211debug</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/80211stats">80211stats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/arpspoof">arpspoof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/atftpd">atftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athchans">athchans</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athctrl">athctrl</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athdebug">athdebug</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athkey">athkey</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/athstats">athstats</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ath_info">ath_info</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dnsspoof">dnsspoof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dnstracer">dnstracer</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/dsniff">dsniff</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap">ettercap</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap_curses">ettercap_curses</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/ettercap_plugins">ettercap_plugins</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etterfilter">etterfilter</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/etterlog">etterlog</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/filesnarf">filesnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fping">fping</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fragroute">fragroute</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/fragtest">fragtest</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hping2">hping2</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/hping3">hping3</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/in.tftpd">in.tftpd</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/macof">macof</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/mailsnarf">mailsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/msgsnarf">msgsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/netdiscover">netdiscover</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/packit">packit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-preinstall">scrollkeeper-preinstall</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-rebuilddb">scrollkeeper-rebuilddb</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/scrollkeeper-update">scrollkeeper-update</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sing">sing</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sshmitm">sshmitm</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sshow">sshow</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudo">sudo</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/sudoedit">sudoedit</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpick">tcpick</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpick_italian">tcpick_italian</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpkill">tcpkill</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tcpnice">tcpnice</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/tinyproxy">tinyproxy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/urlsnarf">urlsnarf</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/visudo">visudo</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/webmitm">webmitm</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/webspy">webspy</a>, 
<a href="http://irongeek.com/i.php?page=backtrack-3-man/wlanconfig">wlanconfig</a><p>
Enjoy.<img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/3lpUz1EMk4E" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 19 May 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nemesis">nemesis</category>
      <category domain="http://securityratty.com/tag/nemesis-ip">nemesis-ip</category>
      <category domain="http://securityratty.com/tag/nemesis-rip">nemesis-rip</category>
      <category domain="http://securityratty.com/tag/nemesis-igmp">nemesis-igmp</category>
      <category domain="http://securityratty.com/tag/nemesis-icmp">nemesis-icmp</category>
      <category domain="http://securityratty.com/tag/nemesis-arp">nemesis-arp</category>
      <category domain="http://securityratty.com/tag/nemesis-tcp">nemesis-tcp</category>
      <category domain="http://securityratty.com/tag/ettercap plugins">ettercap plugins</category>
      <category domain="http://securityratty.com/tag/ettercap">ettercap</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/3lpUz1EMk4E/i.php">BackTrack Beta 3 Man Pages</source>
    </item>
    <item>
      <title><![CDATA[Microsoft Has Developed Windows Forensic Analysis Tool for Police]]></title>
      <link>http://securityratty.com/article/e297067f93f6acf9398b990863e184c6</link>
      <guid>http://securityratty.com/article/e297067f93f6acf9398b990863e184c6</guid>
      <description><![CDATA[Really : The COFEE, which stands for Computer Online Forensic Evidence Extractor, is a USB &quot;thumb drive&quot; that was quietly distributed to a handful of law-enforcement agencies last June. Microsoft...]]></description>
      <content:encoded><![CDATA[<p><a href="http://seattletimes.nwsource.com/html/microsoft/2004379751_msftlaw29.html">Really<a/>:</p>

<blockquote>The COFEE, which stands for Computer Online Forensic Evidence Extractor, is a USB "thumb drive" that was quietly distributed to a handful of law-enforcement agencies last June. Microsoft General Counsel Brad Smith described its use to the 350 law-enforcement experts attending a company conference Monday.

<p>The device contains 150 commands that can dramatically cut the time it takes to gather digital evidence, which is becoming more important in real-world crime, as well as cybercrime. It can decrypt passwords and analyze a computer's Internet activity, as well as data stored in the computer.</p>

<p>It also eliminates the need to seize a computer itself, which typically involves disconnecting from a network, turning off the power and potentially losing data. Instead, the investigator can scan for evidence on site.</blockquote></p>

<p>More news <a href="http://www.news.com/8301-10784_3-9930664-7.html">here</a>.  Commentary <a href="http://techdirt.com/articles/20080429/095514977.shtml">here</a>.</p>

<p>How long before this device is in the hands of the hacker community?  Days?  Months?  They had it before it was released?</p>

<p>EDITED TO ADD (4/30):  Seems that these are not <a href="http://blog.wired.com/27bstroke6/2008/04/microsoft-gives.html">Microsoft-developed tools</a>:</p>

<blockquote>COFEE, according to forensic folk who have used it, is simply a suite of 150 bundled off-the-shelf forensic tools that run from a script. None of the tools are new or were created by Microsoft. Microsoft simply combined existing programs into a portable tool that can be used in the field before agents bring a computer back to their forensic lab.

<p>Microsoft wouldn't disclose which tools are in the suite other than that they're all publicly available, but a forensic expert told me that when he tested the product last year it included standard forensic products like Windows Forensic Toolchest (WFT) and RootkitRevealer.</p>

<p>With COFEE, a forensic agent can select, through the interface, which of the 150 investigative tools he wants to run on a targeted machine. COFEE creates a script and copies it to the USB device which is then plugged into the targeted machine.  The advantage is that instead of having to run each tool separately, a forensic investigator can run them all through the script much more quickly and can also grab information (such as data temporarily stored in RAM or network connection information) that might otherwise be lost if he had to disconnect a machine and drag it to a forensics lab before he could examine it.</blockquote></p>

<p>And it's certainly not a back door, as <a href="http://techdirt.com/articles/20080429/095514977.shtml">TechDirt</a> claims.</p>

<p>But given that a Federal court <a href="http://www.law.com/jsp/article.jsp?id=1208774513920">has</a> <a href="http://www.abajournal.com/news/9th_circuit_uphold_laptop_search">ruled</a> that border guards can search laptop computers without cause, this tool might see wider use than Microsoft anticipated.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=pknVAG"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=pknVAG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Bqm82G"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Bqm82G" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 09:54:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/investigative tools">investigative tools</category>
      <category domain="http://securityratty.com/tag/microsoft simply">microsoft simply</category>
      <category domain="http://securityratty.com/tag/off-the-shelf forensic tools">off-the-shelf forensic tools</category>
      <category domain="http://securityratty.com/tag/device">device</category>
      <category domain="http://securityratty.com/tag/tool separately">tool separately</category>
      <category domain="http://securityratty.com/tag/usb device">usb device</category>
      <source url="http://www.schneier.com/blog/archives/2008/04/microsoft_has_d.html">Microsoft Has Developed Windows Forensic Analysis Tool for Police</source>
    </item>
  </channel>
</rss>
