<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0" 
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">

<channel>
<title>The Professional Security Testers Warehouse for the CEH GPEN QISP Q/ISP OPST CPTS</title>
<link>http://www.professionalsecuritytesters.org</link>
<description>You need more than tools to defeat the adversary!</description>
<dc:language>en-us</dc:language>
<dc:creator>admins@cccure.org</dc:creator>
<dc:date>2009-07-04T00:38:59-04:00</dc:date>

<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2009-07-04T00:38:59-04:00</sy:updateBase>

<item>
<title>EC-Council Awarded More NSA CNSS Certifications</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1042</link>
<description><![CDATA[<p>EC-Council Awarded More NSA CNSS Certifications</p>
<p style="text-align: justify;">EC-Council Courseware for Certified Ethical Hacker (C|EH), Computer Hacking Forensics Investigator (C|HFI), Disaster Recovery Professional (E|DRP), Certified Security Analyst (E|CSA) and Licensed Penetration Tester (L|PT) Courseware has been certified at the highest national level by the Committee of National Security Systems (CNSS).</p>
<p style="text-align: justify;">The CNSS is a federal government entity under the U.S. Department of Defense that provides procedures and guidance for the protection of national security systems. The NSA certified these programs as meeting the CNSS 4012, 4013A, 4014, 4015 and 4016 training standards for information security professionals in the federal government.</p>
<p>Read more <a href="http://www.eccouncil.org/zone/r.aspx?u=/zone/content/File/CNSS2.pdf">HERE</a>.</p>]]></description>
<guid isPermaLink="false">1042@http://www.professionalsecuritytesters.org</guid>
<dc:subject>CEH_IN_THE_NEWS</dc:subject>
<dc:date>2009-07-03T23:42:22-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Official Study Guide for the CEH exam</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1041</link>
<description><![CDATA[<p><strong>Product Description</strong><br> Prepare for the CEH certification exam with this official review guide and learn how to identify security risks to networks and computers. This easy-to-use guide is organized by exam objectives for quick review so you&#8217;ll be able to get the serious preparation you need for the challenging Certified Ethical Hacker certification exam 312-50. As the only review guide officially endorsed by EC-Council, this concise book covers all of the exam objectives and includes a CD with a host of additional study tools. <br><br> <strong>From the Back Cover</strong><br> <strong>Prepare for the CEH certification exam with this official review guide</strong></p>
<p>Learn how to identify security risks to networks and computers and get the serious preparation you need for the challenging Certified Ethical Hacker certification exam 312-50. The only review guide officially endorsed by EC-Council, this concise book covers all of the exam objectives and includes a CD with a host of additional study tools.</p>
<ul>
<li>Easy-to-use book is organized by exam objectives for quick review </li>
<li>Flexible review guide goes hand-in-hand with any learning tool on the market </li>
<li>"Exam Essentials" in each chapter helps you zero in on what you need to know </li>
<li>Book includes over 300 review questions and practice tools </li>
</ul>
<p><strong>Look inside for complete review coverage of all exam objectives for CEH exam 312-50.</strong></p>
<p><strong>Featured on the CD</strong></p>
<p>SYBEX TEST ENGINE<br> Test your knowledge with advanced testing software. Includes bonus exams and glossary.</p>
<p>ELECTRONIC FLASHCARDS<br> Reinforce your understanding with flashcards that can run on your PC, Pocket PC, or Palm handheld.</p>
<p style="text-align: center;"><img title="CEH Offical Certified Ethical hacker book" src="images/cehbook.jpg" alt="Officiel CEH study book" width="200" height="251"></p>
<p>&#160;</p>
<p style="text-align: center;"><strong><a href="http://www.amazon.com/gp/product/0782144373?ie=UTF8&#38;tag=thecisspopens-20&#38;linkCode=as2&#38;camp=1789&#38;creative=9325&#38;creativeASIN=0782144373">Click Here for more information or to buy from Amazon.com</a><img style="border:none !important; margin:0px !important;" src="http://www.assoc-amazon.com/e/ir?t=thecisspopens-20&#38;l=as2&#38;o=1&#38;a=0782144373" border="0" alt></strong></p>]]></description>
<guid isPermaLink="false">1041@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Books_CEH</dc:subject>
<dc:date>2009-07-03T23:18:47-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>The Security-Database Watch Newsletter -- v20090628</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1040</link>
<description><![CDATA[<p>---------- Forwarded message ----------<br>From: <strong>SD List</strong> <br>Date: Sun, Jun 28, 2009 at 06:51<br>Subject: [Tools update] The Security-Database Watch Newsletter -- v20090628<br><br>Hello<br> <br> Here is the site's newsletter "Security Database Tools Watch"<br> (<a href="http://www.security-database.com/toolswatch">http://www.security-database.com/toolswatch</a>).<br> This letter summarizes the articles and news items published since 7 days.<br> <br> I also want to thank Sebastien Gioria (OWASP France Local Chapter), Sucuriteam, Mubix (Rob Fuller) and Billy Austin (CSO Saint Corporation) for submitting us new releases of tools.<br> <br> In loving memory of Michael Jackson.<br> <br> <br><strong>New articles<br>--------------------------</strong><br> <br> <br> ** SAINT version 7.0 is now available ** by &#160;Tools Tracker Team - 26 June 2009<br> <br> SAINT is the Security Administrator&#8217;s Integrated Network Tool. It is used to non-intrusively detect security vulnerabilities on any remote target, including servers, workstations, networking devices, and other types of nodes. It will also gather information such as operating system types and open ports. The SAINT graphical user interface provides access to SAINT&#8217;s data management, scan configuration, scan scheduling, and data analysis capabilities through a web browser. Different aspects of (...) -&#62;<br> <a href="http://www.security-database.com/toolswatch/SAINT-version-7-is-now-available.html">http://www.security-database.com/toolswatch/SAINT-version-7-is-now-available.html</a><br> <br> <br> ** NBIM (Network-Based Integrity Monitor) v2 released **<br> by &#160;Tools Tracker Team<br> - 26 June 2009<br> <br> NBIM is a Network-based Integrity monitor, that detects unauthorized changes on Web sites and domains.<br> <br> It constantly monitors multiple blacklist databases, whois information, DNS and the web site content to detect changes in the integrity (just like a HIDS, but applied to network assets).<br> <br> Tool Submitted by dd (from <a href="http://sucuri.net/">sucuri.net</a>) -&#62;<br> <a href="http://www.security-database.com/toolswatch/NBIM-Network-Based-Integrity.html">http://www.security-database.com/toolswatch/NBIM-Network-Based-Integrity.html</a><br> <br> <br> ** Xprobe-NG announced for July 2009 **<br> by &#160;Tools Tracker Team<br> - 21 June 2009<br> <br> xprobe: Remote OS identification using ICMP packets Xprobe allows you to determine what operating system is running on a remote host. It sends several packets to a host and analyses the returned ICMP packets. The tool automates a logic of OS fingerprinting methods called "X"<br> <br> The release of Xprobe-NG, aka Xprobe2++ is scheduled on 7 of July After we present our tool at DSN 2009 . Meanwhile, if you want to test current bleeding edge code, please use instructions bellow to sync with GIT (...) -&#62;<br> <a href="http://www.security-database.com/toolswatch/Xprobe-NG-announced-for-July-2009.html">http://www.security-database.com/toolswatch/Xprobe-NG-announced-for-July-2009.html</a><br> <br> <br> N.OUCHN<br> Security-Database.com<br> Keep a vigilant eye of your defenses</p>]]></description>
<guid isPermaLink="false">1040@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Inthenews</dc:subject>
<dc:date>2009-06-30T11:51:52-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Official release of &quot;Keykeriki&quot; open source wireless keyboard sniffer</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1039</link>
<description><![CDATA[<p style="text-align: justify;">Hi everyone, i just like to announce officially the release of our wireless keyboard sniffer Keykeriki.<br> <br> An addition to the official press release;</p>
<p style="text-align: justify;">Website: <a href="http://www.remote-exploit.org/Keykeriki.html">http://www.remote-exploit.org/Keykeriki.html</a></p>
<p style="text-align: justify;">Video with some demonstration available on website as well Contact: <a href="mailto:hardhack@remote-exploit.org">hardhack@remote-exploit.org</a></p>
<p style="text-align: justify;">The first lot of pre-fab PCBs will arrive until the end of this week.<br> <br> Stay tuned... Max Moser<br> <br> So here is our press release:<br> <br> &#8220;Keykeriki&#8221; &#8211; Dreamlab Technologies and <a href="http://remote-exploit.org/">remote-exploit.org</a> develop the first open 27Mhz wireless keyboard sniffer. It sniffs and records the signal of wireless keyboards and demonstrates their security<br> risk level. And it can be used to demonstrate hacking-attacks for educational purpose.</p>
<p style="text-align: justify;"><br> Wireless keyboards are very popular in many offices and private homes.&#160; Even in the front office section of banks, they are frequently used.&#160; But they represent a big security risk &#8211; as dreamlab technologies already pointed out in a white paper published 2007.</p>
<p style="text-align: justify;">Wireless keyboards are risky, because they transmit a radio signal that is not enough protected. The newly developed portable universal receiver sniffs and records the signal of wireless keyboards and demonstrates their security risk level.</p>
<p style="text-align: justify;">The keykeriki-software and construction plans for hardware are freely available online at:</p>
<p style="text-align: justify;">[<a href="http://www.remote-exploit.org/">www.remote-exploit.org</a>].<br> <br> Hardware<br> <br>The hardware needs to be portable and small and to be able to adapt to future needs. Keykeriki is therefore built around a Texas Instruments TRF7900 chip controlled by an ATMEL ATMEGA microcontroller. <br><br>For logging abilities an SDCard-interface is built into the board layout, as well as an additional USART channel for future hardware extensions (&#8220;backpacks&#8221;). The whole board can be powered directly via the USB-bus or a stable 5V power source. <br><br>When connected to a computer&#8217;s USB-port, one can use either a decent terminal application or the keykeriCTL software which is included in the software package of this project.&#160; All the schematics can be<br>downloaded in eagle- and PDF-format as part of the project&#8217;s software package. <br><br>Fully equipped boards will be provided in the near future.<br> <br> Software<br><br> Because of the flexible hardware design, most features can be built in by software. This first release contains (among other features) radio frequency switching, signal strength display, deciphering of encryptions, sniffing and decoding of keystrokes of Microsoft 27Mhz based keyboards.<br> <br> Extensions<br><br> Hardware extensions are easy to realize because two different interfaces, a second USART, I&#178;C/TWI and SPI, are externalized. Therefore so called Backpacks e. g. an LCD display controller can be connected using the USART Interface.<br> <br> The Future<br><br> Future extensions include amplification for antennas, support of other Microsoft keyboards and products of other producers, the constant amelioration of hard and software and the parallel handling of several keyboards. <br><br> Furthermore, a keykeriki able to send mouse and keyboard signals is intended.<br><br> Technical details can be found online: <a href="http://www.remote-exploit.org/">www.remote-exploit.org</a>.<br> <br> About Dreamlab<br> Dreamlab Technologies AG is an internationally operating company specialized in IT-Security. Established in<br> 1997, Dreamlab Technologies performs high-end security test, consulting and education, and realizes solutions based on &#8220;best-in-class&#8221; open standard technologies. <br><br>Dreamlab Technologies is an official education partner and representative of ISECOM (Institute for Security and Open Methodologies) for France, Germany and Switzerland.<br><br> ISECOM is the editor of OSSTMM, today&#8217;s most popular security audit methodology.</p>]]></description>
<guid isPermaLink="false">1039@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Wireless_Vuln</dc:subject>
<dc:date>2009-06-16T14:03:12-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>EC-Council | Security Channel - The Education Channel for Security Professionals</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1038</link>
<description><![CDATA[<p>Breaking News</p>
<p>Subscribe to the EC-Council | Security Channel and learn about some of the hottest topics and latest trends in the security space, via webcast.</p>
<p>To subscribe to the Channel, click <a href="http://www.brighttalk.com/channels/2305/view" target="_blank">HERE</a>.</p>
<p>You will get automatic updates and reminders on the webcasts that are scheduled.</p>
<p>Webcast Schedule for June 2009  June 4, 2009  <a href="http://www.brighttalk.com/webcasts/4316/play" target="_blank">View HERE</a>.<br />Topic: Harnessing SIEM for More Effective Investigations Presenter: Eric Knight, CEH | LogRhythm Inc  <br /><br />June 11, 2009  <a href="http://www.brighttalk.com/webcasts/4523/attend" target="_blank">Register HERE</a>.  <br />Topic: Steps to Implementing ISO 27001 Presenter: Eric Lachapelle, CEO | Veridion Inc  <br /><br />June 18, 2009  <a href="http://www.brighttalk.com/webcasts/4468/attend" target="_blank">Register HERE</a>.  <br />Topic: Importance of Risk Management in Governance &#38; Compliance Presenter: Sanjay Anand, Chair | The GRC Group (aka SOX Institute)  <br /><br />June 25, 2009  <a href="http://www.brighttalk.com/webcasts/4509/attend" target="_blank">Register HERE</a>.  <br />Topic: Conficker - Why it Happened? And How We Can Prevent It From Happening Again? Presenter: Mark Harris, Director | Sophos Labs</p>
<p style="text-align: center;"><strong>EC-Council Certified Members attending these webcasts will earn 1 ECE credit</strong></p>]]></description>
<guid isPermaLink="false">1038@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Training</dc:subject>
<dc:date>2009-06-11T00:17:12-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>WEPBuster 1.0 has been released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1037</link>
<description><![CDATA[<p>WEPBuster 1.0</p>
<p>This small utility was written for Information Security Professionals to&#160; aid in conducting &#160;Wireless &#160;Security &#160;Assessment. &#160;The program executes&#160; various utilities included in the &#160;aircrack-ng suite, a set of tools for&#160; auditing wireless networks, in order to obtain the WEP encryption key of<br>&#160;a wireless access point. aircrack-ng can be obtained from&#160; http://www.aircrack-ng.org</p>
<p><strong>Features:</strong></p>
<p>WEPBuster Cracks all access points within the range in one go!!</p>
<p>Supports:</p>
<p>- Mac address filtering bypass (via mac spoofing)<br> - Auto reveal hidden SSID<br> - Client-less Access Point injection<br> - Shared Key Authentication <br> - WEP Decloacking (future version)<br> - whitelist (crack only APs included in the list)<br> - blacklist (do not crack AP if it's included in the list)</p>
<p>&#160;</p>
<p><strong>USAGE:</strong></p>
<p>WEPBuster_1.0"&#62;&#160; perl wepbuster [1 | 6 | 11] (or any combination, space separated)<br> perl wepbuster (sort | connect) [HOST | IP] Defaults to: gateway)</p>
<p>Typically, one would invoke the program without any arguments. Doing this will set the mode to 'crack' and will try to crack all wep-enabled access points within the range on each of those 3 non-overlapping channels(1,6,11)</p>
<p>Given an argument of numbers (1, 6, or 11 only), mode will be set to 'crack' and will crack all APs on that particular channel/s specified.</p>
<p>If passed with a 'sort' argument, followed by an optional IP address or a hostname, the program will try to sort the list of cracked access points (obtained after running 'crack' mode) in the order of decreasing ping round trip time to the gateway or to the IP address or hostname specified.</p>
<p>If passed with a 'connect' argument, followed by an optional IP address or a hostname, the program will try to connect to each access point included in the list of cracked access points.</p>
<p>The program exits once connection is made to an access point and verified, e.g, if it can successfully ping the gateway or the IP address or hostname specified.</p>
<p><strong>RECOMMENDED MODIFICATIONS (aircrack-ng):</strong></p>
<p>The following modifications to the source and header file of the two aircrack-ng utilities (aircrack-ng, airodump-ng), are not required but will make the decryption of WEP key more accurate (in terms of number of IVs needed in order to obtain the key.</p>
<p>1.) Instead of 5000, change PTW_TRY_STEP to 100 to make cracking more accurate (in terms of number of IVs needed to crack the key) Look for this line below in "aircrack-ng.h"</p>
<p>PTW_TRY_STEP &#160;#5000</p>
<p>2.) The script relies heavily on reading and parsing the .csv file output of airodump-ng. As such, instead of airodump-ng waiting for 20 seconds before writing the .csv text output, it is recommended that you make it 2 seconds.</p>
<p>If not changing this line below, you should set $airodumpwait to at least more than 20 to avoid getting errors. A value of 23 should be safe.  Look for this line below in "airodump-ng.c"</p>
<p>if( time( NULL ) - tt1 &#62;= 20)</p>
<p><strong>REQUIRED PERL MODULES:</strong></p>
<p>The only module used in this script is the module "Term::ReadKey". This module is used when the 'Enter' key is pressed, e.g, if the user wants to skip injecting into a particular Access Point.</p>
<p>This module can be obtained from "http://search.cpan.org".</p>
<p>A typical installation procedure of any perl module consists of the following steps:</p>
<p>perl Makefile.PL <br> make install</p>
<p>On Debian systems, this can be installed using apt-get e.g:</p>
<p>"apt-get install libterm-readkey-perl"</p>
<p><strong>REQUIRED APPLICATION:</strong></p>
<p>macchanger (http://www.alobbs.com/macchanger)<br> This tool is used for spoofing the macaddress when the AP is using mac address filtering.</p>
<p><strong>TESTING PLATFORM:</strong></p>
<p>During the development, this program was tested inside an Ubuntu Linux installation, using Alfa AWUS036H with R8187 driver. The access points tested were Aztech DSL605EW and Linksys WAG54G2</p>
<p><strong>WARNINGS:</strong></p>
<p>Other linux platforms, were not tested. The wireless card mentioned above is the only card that was used, others are not guaranteed to work without making any changes. I don't have all the necessary hardwares to test.</p>
<p>I'm leaving this work to the community. Please contribute so that everyone can benefit. =)</p>
<p><br><strong>WHERE TO GET IT?</strong></p>
<p>Please visit the project page at <a href="http://code.google.com/p/wepbuster/">http://code.google.com/p/wepbuster/</a>&#160; where you can download the script, and find the link to the video demo.</p>
<p><strong>FINAL THOUGHTS:</strong></p>
<p>This is the first program I have provided to the opensource community.</p>
<p>I hope you'll find it useful. Donations are welcome if you do =). Send them to my paypal account: markjayson.alvarez_AT_gmail.com</p>
<p>Please use this program in a good way and remember:  "Morality works best when chosen not when mandated" - Larry Wall</p>]]></description>
<guid isPermaLink="false">1037@http://www.professionalsecuritytesters.org</guid>
<dc:subject>WarDriving</dc:subject>
<dc:date>2009-06-02T22:29:10-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>L0phtCrack 6 has been Released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1036</link>
<description><![CDATA[<p><a href="http://security-sh3ll.blogspot.com/2009/05/l0phtcrack-6-released.html"><br></a></p>
<p><a href="http://4.bp.blogspot.com/_xJ5LrusWfss/Sh2hGkL6j5I/AAAAAAAAAEo/8Z6ie2YS6es/s1600-h/11.png"><img id="BLOGGER_PHOTO_ID_5340601867296214930" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 309px;" src="http://4.bp.blogspot.com/_xJ5LrusWfss/Sh2hGkL6j5I/AAAAAAAAAEo/8Z6ie2YS6es/s320/11.png" border="0" alt height="239"></a><br>L0phtCrack is Back <br> <br>L0phtCrack 6 is packed with powerful features such as scheduling, hash extraction from 64 bit Windows versions, multiprocessor algorithms, and networks monitoring and decoding. Yet it is still the easiest to use password auditing and recovery software available.<br><br>Password Scoring<br>L0phtCrack 6 provides a scoring metric to quickly assess password quality. Passwords are measured against current industry best practices, and are rated as Strong, Medium, Weak, or Fail.<br><br>Pre-computed Dictionary Support<br>Pre-computed password files is a must have feature in password auditing. L0phtCrack 6 supports pre-computed password hashes. Password audits now take minutes instead of hours or days.<br><br>Windows &#38; Unix Password Support<br>L0phtCrack 6 imports and cracks Unix password files. Perform network audits from a single interface.<br><br>Remote password retrieval<br>L0phtCrack 6 has a built-in ability to import passwords from remote Windows, including 64-bit versions of Vista, Windows 7, and Unix machines, without requiring a third-party utility.<br><br>Scheduled Scans<br>System administrators can schedule routine audits with L0phtCrack 6. Audits can be performed daily, weekly, monthly, or just once, depending on the organization's auditing requirements.<br><br>Remediation<br>L0phtCrack 6 offers remediation assistance to system administrators on how to take action against accounts that have poor passwords. Accounts can be disabled, or the passwords can be set to expire from within the L0phtCrack 6 interface. Remediation works for Windows user accounts only.<br><br>Updated Vista/Windows 7 Style UI<br>The user interface is improved and updated. More information is available about each user account, including password age, lock-out status, and whether the account is disabled, expired, or never expires. Information on L0phtCrack 6's current session is provided in an "immediate window" with a reporting tab providing up-to-the-minute status of the current auditing session <br><br><a href="http://www.l0phtcrack.com/index.html">More Info and Download</a></p>]]></description>
<guid isPermaLink="false">1036@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Passwords</dc:subject>
<dc:date>2009-05-27T22:06:23-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>sqlmap version 0.7rc1 has been released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1035</link>
<description><![CDATA[<p>Hi,<br><br>I am glad to release sqlmap version 0.7rc1.</p>
<p>WARNING: This release is a candidate, it only works on Linux so please do not complain that it does not work on your Windows or Mac OS X systems.<br><br><strong>Introduction<br>============</strong><br><br>sqlmap is an open source command-line automatic SQL injection tool.&#160; Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.<br><br><br><strong>Changes<br>=======</strong><br><br>Some of the new features include:<br><br>* Added support to execute arbitrary commands on the database server underlying operating system either returning the standard output or not via UDF injection on MySQL and PostgreSQL and via xp_cmdshell()<br>stored procedure on Microsoft SQL Server;<br><br>* Added support for out-of-band connection between the attacker box and the database server underlying operating system via stand-alone payload stager created by Metasploit and supporting Meterpreter, shell<br>and VNC payloads for both Windows and Linux;<br><br>* Added support for out-of-band connection via Microsoft SQL Server 2000 and 2005 'sp_replwritetovarbin' stored procedure heap-based buffer overflow (MS09-004) exploitation with multi-stage Metasploit payload support;<br><br>* Added support for out-of-band connection via SMB reflection attack with UNC path request from the database server to the attacker box by using the Metasploit smb_relay exploit;<br><br>* Added support to read and write (upload) both text and binary files on the database server underlying file system for MySQL, PostgreSQL and Microsoft SQL Server;<br><br>* Added database process' user privilege escalation via Windows Access Tokens kidnapping on MySQL and Microsoft SQL Server via either Meterpreter's incognito extension or Churrasco stand-alone executable.<br><br>Complete list of changes at <a href="http://sqlmap.sourceforge.net/doc/ChangeLog">http://sqlmap.sourceforge.net/doc/ChangeLog</a>.<br><br><strong>Download<br>========</strong><br><br>You can download it in two formats:<br><br>* Source gzip compressed,<br><a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7rc1.tar.gz">http://downloads.sourceforge.net/sqlmap/sqlmap-0.7rc1.tar.gz</a><br><br>* Source zip compressed,<br><a href="http://downloads.sourceforge.net/sqlmap/sqlmap-0.7rc1.zip">http://downloads.sourceforge.net/sqlmap/sqlmap-0.7rc1.zip</a><br><br><br><strong>Documentation<br>=============</strong><br><br>* sqlmap user's manual: <a href="http://sqlmap.sourceforge.net/doc/README.pdf">http://sqlmap.sourceforge.net/doc/README.pdf</a><br><br>* "Advanced SQL injection to operating system full control" whitepaper[1] and slides[2] presented at Black Hat Europe 2009 in Amsterdam (The Netherlands) on April 16, 2009<br><br>[1] <a href="http://sqlmap.sourceforge.net/doc/BlackHat-Europe-09-Damele-A-G-Advanced-SQL-injection-whitepaper.pdf">http://sqlmap.sourceforge.net/doc/BlackHat-Europe-09-Damele-A-G-Advanced-SQL-injection-whitepaper.pdf</a><br><br>[2] <a href="http://www.slideshare.net/inquis/advanced-sql-injection-to-operating-system-full-control-slides">http://www.slideshare.net/inquis/advanced-sql-injection-to-operating-system-full-control-slides</a><br><br><br>Happy hacking!</p>
<p>-- <br>Bernardo Damele A. G.<br><br>E-mail / Jabber: bernardo.damele (at) gmail.com<br>Mobiles: +447788962949 (UK), +393493821385 (IT)<br>PGP Key ID: 0x05F5A30F</p>]]></description>
<guid isPermaLink="false">1035@http://www.professionalsecuritytesters.org</guid>
<dc:subject>SQL</dc:subject>
<dc:date>2009-05-21T07:13:47-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>WarVOX phone analysis suite</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1034</link>
<description><![CDATA[<p>Version 1.0.1 of the WarVOX phone analysis suite has been released. Notable changes since 1.0.0:<br> <br> &#160;- License changed to BSD, no restrictions on commercial use<br> &#160;- Support number exclusion lists / black lists (regex based)<br> &#160;- Support for phone number ranges in addition to masks<br> &#160;- Support for multiple ranges and masks per job<br> &#160;- Numerous bug fixes and stability improvements<br> &#160;- Command line script for exporting dial results (bin/export_list.rb)<br> <br> Download:<br> &#160;<a href="http://warvox.org/releases/warvox-1.0.1.tar.gz">http://warvox.org/releases/warvox-1.0.1.tar.gz</a><br> <br> Background:<br> &#160;<a href="http://warvox.org/">http://warvox.org/</a><br> <br> WarVOX is a suite of tools for exploring, classifying, and auditing telephone systems. Unlike normal wardialing tools, WarVOX works with the actual audio from each call and does not use a modem directly. This model allows WarVOX to find and classify a wide range of interesting lines, including modems, faxes, voice mail boxes, PBXs, loops, dial tones, IVRs, and forwarders. WarVOX provides the unique ability to classify all telephone lines in a given range, not just those connected to modems, allowing for a comprehensive audit of a telephone system.<br> <br> WarVOX requires no telephony hardware and is massively scalable by leveraging Internet-based VoIP providers. A single instance of WarVOX on a residential broadband connection, with a typical VoIP account, can scan over 1,000 numbers per hour. The speed of WarVOX is limited only by downstream bandwidth and the limitations of the VoIP service. Using two providers with over 40 concurrent lines we have been able to scan entire 10,000 number prefixes within 3 hours.<br> <br> -HD</p>]]></description>
<guid isPermaLink="false">1034@http://www.professionalsecuritytesters.org</guid>
<dc:subject>VOIP</dc:subject>
<dc:date>2009-05-20T23:40:01-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>SamuraiWTF Web Application testing Virtual Machine</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1033</link>
<description><![CDATA[<p>Hello everyone, <br> <br>The SamuraiWTF project team is proud to announce the immediate release of SamuraiWTF 0.6.&#160; This release is available at <a href="http://samurai.inguardians.com/">http://samurai.inguardians.com</a>.</p>
<p>The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function                 as a web pen-testing environment.  The CD contains the best of the open source and free tools that focus on                 testing and attacking websites.  In developing this environment, we have based our tool selection on the                 tools we use in our security practice.  We have included the tools used in all four steps of a web pen-test.</p>
<p>Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.<br> <br>We have updated and fixed a number of issues with the environment as well as improved performance of the java based tools.&#160; We have also included a virtual machine of the environment.&#160; This VM requires VMWare. <br> <br>If there are any questions, please either send them to <a href="mailto:samurai@inguardians.com">samurai@inguardians.com</a> or join the developers mailing list on sourceforge.net. <br> <br>Thank you <br>Kevin and the project team <br> <br>Kevin Johnson <br>Senior Security Analyst <br>InGuardians, Inc. <br>office: 202.448.8958 <br>cell: 904.403.8024</p>]]></description>
<guid isPermaLink="false">1033@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Web_App_Sec</dc:subject>
<dc:date>2009-05-20T20:28:49-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

</channel>
</rss>
