<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: demos]]></title>
    <link>http://securityratty.com/tag/demos</link>
    <description></description>
    <pubDate>Wed, 07 May 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Massive SQL Injection Attacks - the Chinese Way]]></title>
      <link>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</link>
      <guid>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</guid>
      <description><![CDATA[From copycats and &quot;localizers&quot; of Russian web malware exploitation kits , to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QH40puDsgXY/s1600-h/security_company_hacking_tools.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QO3L0OWKJcY/s200-R/security_company_hacking_tools.JPG" /></a>From <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">copycats</a> and <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">"localizers" of Russian web malware exploitation kits</a>, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale, and so is either filling the niches left open by other international communities, or coming up with tools setting new benchmarks for massive SQL injection attacks, like the case with this one :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/3GOnK2TsSRk/s1600-h/search_engines_mass_SQL_injection.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/pdCwjwri7LM/s200-R/search_engines_mass_SQL_injection.JPG" /></a>"<i>A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/Mm7pCwd7LT4/s1600-h/search_engines_mass_SQL_injection2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/qMaY93_QOvY/s200-R/search_engines_mass_SQL_injection2.JPG" /></a>Nothing's wrong with the marketing pitch at the first place, but going through the features, the "massive SQL injections through search engine reconnaissance" and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">search engines reconnaissance</a>, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particupar country, in this case they used French sites for one of the demos. Here are some excerpts from its CHANGE log speaking for themselves :<br />
<br />
"<i><b>2008.7.15 release version 1.3 </b><br />
&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/37LsW8yh_AE/s1600-h/chinese_SQL_injector.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/ub8OVgeWC6Y/s200-R/chinese_SQL_injector.png" /></a><i>- New powerful "automatic machine cycle" feature&nbsp;</i><br />
<i>- Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very&nbsp;</i><br />
<i>- powerful and flexible module, the main sites used for some special filtering into the hand, is almost a&nbsp;</i><br />
<i>- universal tool, you can achieve the following: <br />
&nbsp;</i><br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/xYACViJuVn4/s1600-h/chinese_SQL_injector2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/oPVCur3PMgI/s200-R/chinese_SQL_injector2.png" /></a><i>1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.&nbsp;</i><br />
<i>2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).&nbsp;</i><br />
<i>3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).&nbsp;</i><br />
<i>4. Page language does not limit the types and databases (to provide specific statements into the database).&nbsp;</i><br />
<i>5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.</i>"<br />
<br />
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/0fb6Epapby0/s1600-h/chinese_SQL_injector3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/nmrC87TeCxo/s200-R/chinese_SQL_injector3.png" /></a>"<i>- The use of the three search engine sites scans to invade the side to complete<br />
- in scanning probe into the Web site ranking points<br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site. <br />
- New "sequence document scanners" <br />
- What is the sequence document scanners role? Upload to find loopholes, some of the procedures to upload the file after the upload will be renamed, rename the way the system is usually based on time or incremental increase in the number prefix code for the upload process, if not to return after the file name, Upload files to know the url is usually very difficult to sequence the use of paper scanner can be scanned out</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/Y5mM2l7Q6K4/s1600-h/chinese_SQL_injector4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/DU7feV1pnjU/s200-R/chinese_SQL_injector4.png" /></a><i><br />
- The best reverse domain name query engine, and quasi-wide <br />
- in scanning the database of basic information, an increase of the database of information related to the process, the link has information on the database server user login (sa need permission) <br />
- control of the interface had a big adjustment, the interface process easier to understand and operate. <br />
- based on a significant site of the wrong mode of access to a comprehensive code optimization and more accurate access to the content, accuracy and access to show progress. <br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/R77obP_vxig/s1600-h/chinese_SQL_injector5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/ORo853Aicy4/s200-R/chinese_SQL_injector5.png" /></a><i><br />
- point into the types of improved detection order to improve the efficiency of detection. <br />
- improved automatic keyword detection, automatic keyword detection more accurate. <br />
- probe into the points the way to improve and increase the use of automatic detection of the keyword detection. <br />
- type of database to improve the detection, the use of the contents of the length of the failure to detect the type of database automatically switch to the probe through the keyword. <br />
- automatically save and load solution has been to guess the tree structure of the database, guess Solutions has been the content and structure of the database will automatically save and open the next time the injection point will be automatically made available, the solutions do not have to guess again, the continuity of work Greatly increased.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/DcQNU5crc5k/s1600-h/chinese_SQL_injector6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="131" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/9zGp4bsPB2U/s200-R/chinese_SQL_injector6.png" width="200" /></a><i><br />
- solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die. <br />
- increased significantly on the wrong model of ASP.NET and SQL Server2005 significant mode of dealing with mistakes, error messages can be extracted from a Web directory! <br />
- significant amendments to the wrong mode, some of the injected one by one point in the field or access to the contents of the issue can not be successful (error code in hand); for increased access to specific points table and into the field.&nbsp;</i><br />
<i><br />
- amendments to the text of a significant error patterns to detect and correct use of loopholes in the system can be used more to expand. (Text significantly in the wrong mode in version 1.1 already supported, but in the version 1.2 upgrade in the process of scanning to improve the performance of the Gaodiao careless. -_-#) <br />
- on a variety of encoded text can be significantly wrong in the right-compatible, able to correctly handle the ASP.NET page of the text marked wrong. Through custom error keyword, truly compatible with any language, any coding error message. <br />
- crack anti-improvement and enhancement. <br />
- An increase of auto-detection feature keywords.&nbsp;</i><br />
<i><br />
- Mssql database specifically for significant points into the wrong mode of detection and the use of up and down the hard work, and many other software can not detect the point of injection can also be used. <br />
- Automatic save and load access to the database, to allow manual known to add tables and fields for solutions to guess. <br />
- Can be used to amend the degree of accuracy; optimize the code to reduce memory footprint; enhance the stability of multi-threading. <br />
- Significant amendments to the wrong mode solution guess the contents of the database must be checked first field defects.</i>"<br />
<br />
The public version of the tool has been in the while for over an year, with a VIP version available to customers only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PsITM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PsITM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBO9M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBO9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owYAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owYAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LTzNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LTzNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LaPQM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LaPQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=go5fM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=go5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rYJ9m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rYJ9m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/427878843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 12:18:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyword detection">keyword detection</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database solution">database solution</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/upload process">upload process</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/load solution">load solution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/427878843/massive-sql-injection-attacks-chinese.html">Massive SQL Injection Attacks - the Chinese Way</source>
    </item>
    <item>
      <title><![CDATA[John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008]]></title>
      <link>http://securityratty.com/article/e6411fe452b9021fd4b58bf9559f9797</link>
      <guid>http://securityratty.com/article/e6411fe452b9021fd4b58bf9559f9797</guid>
      <description><![CDATA[John Strand - &quot;Advanced Hacking Techniques and Defenses&quot; (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008 John Strand gave this presentation for the Kentuckiana ISSA...]]></description>
      <content:encoded><![CDATA[<a href="http://www.irongeek.com/i.php?page=videos/john-strand-advanced-hacking-techniques-and-defenses-and-demos-of-evilgrade-passing-the-hash-msfpayload-from-louisville-infosec-2008">John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008</a><br/>John Strand gave this presentation for the <a href="http://www.issa-kentuckiana.org/">Kentuckiana ISSA</a> at the Louisville Infosec 2008 conference. He gives a fascinating talk about why "security in depth" is dead, and lives again. John then goes on to demo Evilgrade, using msfpayload and obscuring it against signature based malware detection, dumping SAM hashes with the Metasploit Meterpreter and using a patched Samba client to pass the hash and compromise a system. I'd like to thank John for letting me record his talk.
<p><a href="http://feedads.googleadservices.com/~a/0LzHo_0DHLsCQY7GkitmfnbS7Zg/a"><img src="http://feedads.googleadservices.com/~a/0LzHo_0DHLsCQY7GkitmfnbS7Zg/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/WiXcZ3wY5Ls" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 11 Oct 2008 12:08:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/john strand">john strand</category>
      <category domain="http://securityratty.com/tag/john">john</category>
      <category domain="http://securityratty.com/tag/louisville infosec">louisville infosec</category>
      <category domain="http://securityratty.com/tag/msfpayload">msfpayload</category>
      <category domain="http://securityratty.com/tag/demo evilgrade">demo evilgrade</category>
      <category domain="http://securityratty.com/tag/defenses">defenses</category>
      <category domain="http://securityratty.com/tag/samba client">samba client</category>
      <category domain="http://securityratty.com/tag/demos">demos</category>
      <category domain="http://securityratty.com/tag/sam hashes">sam hashes</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/WiXcZ3wY5Ls/i.php">John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008</source>
    </item>
    <item>
      <title><![CDATA[John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008]]></title>
      <link>http://securityratty.com/article/fd6c91a824e7a3323c2dfe7cbb90f1c6</link>
      <guid>http://securityratty.com/article/fd6c91a824e7a3323c2dfe7cbb90f1c6</guid>
      <description><![CDATA[John Strand - &quot;Advanced Hacking Techniques and Defenses&quot; (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008 John Strand gave this presentation for the Kentuckiana ISSA...]]></description>
      <content:encoded><![CDATA[<a href="http://www.irongeek.com/i.php?page=videos/john-strand-advanced-hacking-techniques-and-defenses-and-demos-of-evilgrade-passing-the-hash-msfpayload-from-louisville-infosec-2008">John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008</a><br/>John Strand gave this presentation for the <a href="http://www.issa-kentuckiana.org/">Kentuckiana ISSA</a> at the Louisville Infosec 2008 conference. He gives a fascinating talk about why "security in depth" is dead, and lives again. John then goes on to demo Evilgrade, using msfpayload and obscuring it against signature based malware detection, dumping SAM hashes with the Metasploit Meterpreter and using a patched Samba client to pass the hash and compromise a system. I'd like to thank John for letting me record his talk.]]></content:encoded>
      <pubDate>Sat, 11 Oct 2008 12:08:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/john strand">john strand</category>
      <category domain="http://securityratty.com/tag/john">john</category>
      <category domain="http://securityratty.com/tag/louisville infosec">louisville infosec</category>
      <category domain="http://securityratty.com/tag/msfpayload">msfpayload</category>
      <category domain="http://securityratty.com/tag/demo evilgrade">demo evilgrade</category>
      <category domain="http://securityratty.com/tag/defenses">defenses</category>
      <category domain="http://securityratty.com/tag/samba client">samba client</category>
      <category domain="http://securityratty.com/tag/demos">demos</category>
      <category domain="http://securityratty.com/tag/sam hashes">sam hashes</category>
      <source url="http://www.irongeek.com/i.php?page=videos/john-strand-advanced-hacking-techniques-and-defenses-and-demos-of-evilgrade-passing-the-hash-msfpayload-from-louisville-infosec-2008">John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008</source>
    </item>
    <item>
      <title><![CDATA[John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008]]></title>
      <link>http://securityratty.com/article/b46f67574af73084896129f5834a688d</link>
      <guid>http://securityratty.com/article/b46f67574af73084896129f5834a688d</guid>
      <description><![CDATA[John Strand - &quot;Advanced Hacking Techniques and Defenses&quot; (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008 John Strand gave this presentation for the Kentuckiana ISSA...]]></description>
      <content:encoded><![CDATA[<a href="http://www.irongeek.com/i.php?page=videos/john-strand-advanced-hacking-techniques-and-defenses-and-demos-of-evilgrade-passing-the-hash-msfpayload-from-louisville-infosec-2008">John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008</a><br/>John Strand gave this presentation for the <a href="http://www.issa-kentuckiana.org/">Kentuckiana ISSA</a> at the Louisville Infosec 2008 conference. He gives a fascinating talk about why "security in depth" is dead, and lives again. John then goes on to demo Evilgrade, using msfpayload and obscuring it against signature based malware detection, dumping SAM hashes with the Metasploit Meterpreter and using a patched Samba client to pass the hash and compromise a system. I'd like to thank John for letting me record his talk.
<p><a href="http://feedads.googleadservices.com/~a/0LzHo_0DHLsCQY7GkitmfnbS7Zg/a"><img src="http://feedads.googleadservices.com/~a/0LzHo_0DHLsCQY7GkitmfnbS7Zg/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/8ijtqY1YRHU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 11 Oct 2008 12:08:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/john strand">john strand</category>
      <category domain="http://securityratty.com/tag/john">john</category>
      <category domain="http://securityratty.com/tag/louisville infosec">louisville infosec</category>
      <category domain="http://securityratty.com/tag/msfpayload">msfpayload</category>
      <category domain="http://securityratty.com/tag/demo evilgrade">demo evilgrade</category>
      <category domain="http://securityratty.com/tag/defenses">defenses</category>
      <category domain="http://securityratty.com/tag/samba client">samba client</category>
      <category domain="http://securityratty.com/tag/demos">demos</category>
      <category domain="http://securityratty.com/tag/sam hashes">sam hashes</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/8ijtqY1YRHU/i.php">John Strand - "Advanced Hacking Techniques and Defenses" (and demos of evilgrade/passing the hash/msfpayload) from Louisville Infosec 2008</source>
    </item>
    <item>
      <title><![CDATA[Demos from my TechEd talks]]></title>
      <link>http://securityratty.com/article/c525b4d7a9400def81edb37ec30b0484</link>
      <guid>http://securityratty.com/article/c525b4d7a9400def81edb37ec30b0484</guid>
      <description><![CDATA[To those who came to my talks at TechEd 2008 Developers , thank you! Be sure to fill out an evaluation before you leave; scores matter a lot to the conference organizers, so let them know what you...]]></description>
      <content:encoded><![CDATA[<P>To those who came to my talks at <A href="http://www.microsoft.com/events/teched2008/developer/default.mspx">TechEd 2008 Developers</A>, thank you! Be sure to fill out an evaluation before you leave; scores matter a lot to the conference organizers, so let them know what you thought.</P>
<P><A href="http://www.pluralsight.com/keith/presentations/TimeTracker.zip">Here is the code</A> from my ADFS talk.</P>
<P><A href="http://www.pluralsight.com/keith/presentations/ClaimsDemos.zip">Here&nbsp;is the code</A> from my&nbsp;Understanding Claims talk.</P>
<P>Enjoy!</P><div style="clear:both;"></div><img src="http://pluralsight.com/community/aggbug.aspx?PostID=51105" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 09:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/adfs talk">adfs talk</category>
      <category domain="http://securityratty.com/tag/scores matter">scores matter</category>
      <category domain="http://securityratty.com/tag/conference organizers">conference organizers</category>
      <category domain="http://securityratty.com/tag/claims talk">claims talk</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/enjoy">enjoy</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <source url="http://pluralsight.com/community/blogs/keith/archive/2008/06/04/51105.aspx">Demos from my TechEd talks</source>
    </item>
    <item>
      <title><![CDATA[Demos from my TechEd talks]]></title>
      <link>http://securityratty.com/article/6be10be5d0ebb9e9b86818f4a0163395</link>
      <guid>http://securityratty.com/article/6be10be5d0ebb9e9b86818f4a0163395</guid>
      <description><![CDATA[To those who came to my talks at TechEd 2008 Developers , thank you! Be sure to fill out an evaluation before you leave; scores matter a lot to the conference organizers, so let them know what you...]]></description>
      <content:encoded><![CDATA[<P>To those who came to my talks at <A href="http://www.microsoft.com/events/teched2008/developer/default.mspx">TechEd 2008 Developers</A>, thank you! Be sure to fill out an evaluation before you leave; scores matter a lot to the conference organizers, so let them know what you thought.</P>
<P><A href="http://www.pluralsight.com/keith/presentations/TimeTracker.zip">Here is the code</A> from my ADFS talk.</P>
<P><A href="http://www.pluralsight.com/keith/presentations/ClaimsDemos.zip">Here&nbsp;is the code</A> from my&nbsp;Understanding Claims talk.</P>
<P>Enjoy!</P><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=51105" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 09:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/adfs talk">adfs talk</category>
      <category domain="http://securityratty.com/tag/scores matter">scores matter</category>
      <category domain="http://securityratty.com/tag/conference organizers">conference organizers</category>
      <category domain="http://securityratty.com/tag/claims talk">claims talk</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/enjoy">enjoy</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/06/04/51105.aspx">Demos from my TechEd talks</source>
    </item>
    <item>
      <title><![CDATA[Demos from my TechEd talks]]></title>
      <link>http://securityratty.com/article/2d7fcc39d4dadf242060ed7dd4b2335e</link>
      <guid>http://securityratty.com/article/2d7fcc39d4dadf242060ed7dd4b2335e</guid>
      <description><![CDATA[To those who came to my talks at TechEd 2008 Developers , thank you! Be sure to fill out an evaluation before you leave; scores matter a lot to the conference organizers, so let them know what you...]]></description>
      <content:encoded><![CDATA[<P>To those who came to my talks at <A href="http://www.microsoft.com/events/teched2008/developer/default.mspx">TechEd 2008 Developers</A>, thank you! Be sure to fill out an evaluation before you leave; scores matter a lot to the conference organizers, so let them know what you thought.</P>
<P><A href="http://www.pluralsight.com/keith/presentations/TimeTracker.zip">Here is the code</A> from my ADFS talk.</P>
<P><A href="http://www.pluralsight.com/keith/presentations/ClaimsDemos.zip">Here&nbsp;is the code</A> from my&nbsp;Understanding Claims talk.</P>
<P>Enjoy!</P><img src ="http://pluralsight.com/blogs/keith/aggbug/51105.aspx" width = "1" height = "1" />]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 03:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/adfs talk">adfs talk</category>
      <category domain="http://securityratty.com/tag/scores matter">scores matter</category>
      <category domain="http://securityratty.com/tag/conference organizers">conference organizers</category>
      <category domain="http://securityratty.com/tag/claims talk">claims talk</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/enjoy">enjoy</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <source url="http://pluralsight.com/blogs/keith/archive/2008/06/04/51105.aspx">Demos from my TechEd talks</source>
    </item>
    <item>
      <title><![CDATA[Network Security It Takes a Village]]></title>
      <link>http://securityratty.com/article/79f566385e2aca32d1e3fa16a2ddaf4b</link>
      <guid>http://securityratty.com/article/79f566385e2aca32d1e3fa16a2ddaf4b</guid>
      <description><![CDATA[Something that should not be a surprise it turns out that securing the worlds largest temporary network takes a variety of vendors working together
For three days, InteropNet is one of the largest...]]></description>
      <content:encoded><![CDATA[<p>Something that should not be a surprise – it turns out that securing the world’s <a href="http://www.interop.com/blog/?p=395" target="_blank">largest temporary network</a> takes a <a href="http://www.interop.com/lasvegas/exhibition/interopnet/interopnet_sponsors.php" target="_blank">variety of vendors working together</a>.</p>
<p>For three days, InteropNet is one of the largest hacking targets on the planet. Attacks and threats come from both inside and outside the network. While the external attacks are certainly more malicious in intent, most of the internal ones ended up being due to misconfiguration or just plain misunderstanding.</p>
<p>Let’s play a game. It’s called <strong>Malicious or Not</strong>.</p>
<ol>
<li>Video streaming devices flooded the network with millions of multicast packets per second. EM7 noticed a big bump in latency on that network segment at the same time that the Enterasys Dragon IDS caught the flood of packets. Both tools could tell the origin of the packets and traced them back to misconfigured video multicast devices. In this case Not Malicious, but the result was still degradation to that network segment until the problem was fixed.</li>
<li>One vendor at the show purposely scanned all other devices on the show network to model them in their product demos. They didn’t ask anyone’s permission (or at least they didn’t ask ours). They purposely used multiple community strings to see if any would work. Malicious or Not? I’ll let you guys take this one. Personally I don’t think they meant it to be malicious, but as a monitoring tool in this space, they should have known that doing all that scanning would actually degrade network and other vendors’ device performance. I wonder if this is the vendor that was telling people that it does this at every show, and this is the first time it’s been caught.</li>
</ol>
<p><strong>Connect the Vendors</strong></p>
<p>Enterasys took care of external attacks by identifying them and asking Qwest to block them. But it’s with the internal “devices behaving badly”, that the real fun began. It took a combination of vendors to identify, confirm and track down the offenders on the network.</p>
<p>First <a href="http://www.enterasys.com/products/advanced-security-apps/dragon-intrusion-detection-protection.aspx" target="_blank">Enterasys Dragon IDS</a> alerted on suspicious behaviors. Dragon identified what IP, MAC address or port on a switch was having the issue – which information was cross-checked against vendor registry info in EM7 to track down offenders to a booth, a room or a wireless access point in the facility. <a href="http://blogs.splunk.com/thebaum/2008/05/02/new-splunk-apps-launch-at-interop-and-mms/" target="_blank">Splunk was also used to look at logs and verify the source of bad behavior</a>.</p>
<p>For tracking down wireless misbehavior, <a href="http://www.arubanetworks.com/products/management_analytics_threat_prevention.php" target="_blank">Aruba Networks had a cool tool</a> that took the info from Dragon and EM7 and used it to literally triangulate the location (down to a laptop).</p>
<p>Before the show started, we played wireless security hide and seek – testing our security process by sending people out with laptops and finding them, gps-style, whether they were walking around or hiding under a desk.</p>
<p>Overall, I think the real-life multi-vendor network security solutions I’ve <a href="http://blog.sciencelogic.com/interoperability-how-networking-should-be/05/13/2008/" target="_blank">described here are great examples of why interoperability is so important</a> and why InteropNet was such a great experience.</p>
<p><a href="http://sharethis.com/item?&wp=2.3.3&amp;publisher=f8a81d13-50d0-4a5c-833d-8e5f2341e305&amp;title=Network+Security+%26ndash%3B+It+Takes+a+Village&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fnetwork-security-it-takes-a-village%2F05%2F14%2F2008%2F">ShareThis</a></p>]]></content:encoded>
      <pubDate>Wed, 14 May 2008 09:05:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/degrade network">degrade network</category>
      <category domain="http://securityratty.com/tag/temporary network takes">temporary network takes</category>
      <category domain="http://securityratty.com/tag/internal devices">internal devices</category>
      <category domain="http://securityratty.com/tag/enterasys dragon ids">enterasys dragon ids</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/enterasys">enterasys</category>
      <category domain="http://securityratty.com/tag/network segment">network segment</category>
      <category domain="http://securityratty.com/tag/dragon">dragon</category>
      <source url="http://blog.sciencelogic.com/network-security-it-takes-a-village/05/14/2008/">Network Security It Takes a Village</source>
    </item>
    <item>
      <title><![CDATA[Computerworld presents a 100% free and online security event today!]]></title>
      <link>http://securityratty.com/article/ffd68f25d9acafde081dff8dec21ef0c</link>
      <guid>http://securityratty.com/article/ffd68f25d9acafde081dff8dec21ef0c</guid>
      <description><![CDATA[Join Computerworld and hundreds of your industry peers for this exclusive online and &quot;virtual&quot; event on the current and future state of security. Visit our sponsor's booths for valuable white papers,...]]></description>
      <content:encoded><![CDATA[Join Computerworld and hundreds of your industry peers for this exclusive online and "virtual" event on the current and future state of security. Visit our sponsor's booths for valuable white papers, case studies and demos. Network with your peers. Watch our day-long agenda of webcasts featuring industry experts. Enter to win prizes!
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=EeOgqQ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=EeOgqQ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/290199677" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 14 May 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/peers">peers</category>
      <category domain="http://securityratty.com/tag/valuable white papers">valuable white papers</category>
      <category domain="http://securityratty.com/tag/industry peers">industry peers</category>
      <category domain="http://securityratty.com/tag/exclusive online">exclusive online</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/day-long agenda">day-long agenda</category>
      <category domain="http://securityratty.com/tag/join computerworld">join computerworld</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/industry experts">industry experts</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/290199677/webcast.do">Computerworld presents a 100% free and online security event today!</source>
    </item>
    <item>
      <title><![CDATA[AT&T demos disaster preparedness]]></title>
      <link>http://securityratty.com/article/2f9275bcf3270ffdfc779a5b5766c5dd</link>
      <guid>http://securityratty.com/article/2f9275bcf3270ffdfc779a5b5766c5dd</guid>
      <description><![CDATA[AT&amp;T was in Chicago recently, demonstrating to hundreds of its corporate customers how it responds to natural...]]></description>
      <content:encoded><![CDATA[AT&T was in Chicago recently, demonstrating to hundreds of its corporate customers how it responds to natural disasters.]]></content:encoded>
      <pubDate>Wed, 07 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/chicago recently">chicago recently</category>
      <category domain="http://securityratty.com/tag/natural disasters">natural disasters</category>
      <category domain="http://securityratty.com/tag/responds">responds</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/hundreds">hundreds</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://www.networkworld.com/news/2008/050808-att-disaster-preparedness.html?fsrc=rss-security">AT&amp;T demos disaster preparedness</source>
    </item>
  </channel>
</rss>
